A traffic analysis method, device, storage medium and program product
By generating a network topology and identifying nodes with abnormal traffic for traffic analysis, the problem of high hardware and software resource consumption in existing traffic analysis technologies is solved, and traffic anomaly identification with low resource consumption is achieved.
Patent Information
- Application Number
- CN202510026257.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-07
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2045-01-07
AI Technical Summary
In existing technologies, the difficulty in traffic analysis of network devices lies in the large amount of data and computational requirements. Existing technologies cannot effectively address the need for powerful storage and computing capabilities in network devices, resulting in high consumption of hardware and software resources.
By acquiring the network topology within a preset time period, generating traffic interaction information between network nodes based on network traffic data, identifying nodes with abnormal traffic, and performing targeted traffic analysis, the amount of data analysis is reduced, and the demand for software and hardware resources is lowered.
It enables accurate identification of abnormal traffic nodes in network traffic analysis, reducing the requirements for storage and computing power and lowering the consumption of hardware and software resources.
Smart Images

Figure CN119892446B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of network security, and in particular to a traffic analysis method and device, a storage medium and a program product. BACKGROUND
[0002] In the current network environment, the network structure and connection mode are complex, and various types of network devices emerge in endlessly, which leads to an increase in data volume. Therefore, the difficulty of the prior art in traffic data analysis lies in that the data volume is large, the computing demand is not easy to meet, and strong storage capacity and high computing capacity of software and hardware are required. SUMMARY
[0003] The present application provides a traffic analysis method, device, storage medium and program product, which can perform targeted traffic analysis and reduce the consumption of software and hardware resources.
[0004] In a first aspect, the present application provides a traffic analysis method, comprising: obtaining a network topology structure in a preset time period, the network topology structure being generated based on network traffic data in the preset time period; the network topology structure being used to reflect traffic interaction conditions between each network node in the preset time period; determining a target network node with a traffic abnormal condition based on the network topology structure; and analyzing traffic data of the target network node.
[0005] In the traffic analysis method provided by the present application, the network topology structure generated based on the network traffic data in the preset time period not only can mark each network node in the network environment and the connection between the network nodes, but also can intuitively reflect the traffic conditions between the network nodes. Therefore, the present application can accurately determine the target network node with the traffic abnormal condition according to the network topology structure, perform targeted traffic analysis on the target network node, reduce the data analysis volume, and thus has lower requirements for the storage capacity and computing capacity of software and hardware. Therefore, the traffic analysis process of the present application reduces the consumption of software and hardware resources compared with the prior art.
[0006] In a possible implementation, the traffic interaction conditions include at least one of the following: connection between network nodes, data flow direction, traffic probability, traffic risk expectation value, protocol type of traffic, traffic transmitted based on each type of protocol, and alarm weight of each type of protocol; wherein the traffic risk expectation value is used to reflect the probability of alarm traffic in the traffic between the network nodes; and the alarm weight of each type of protocol is used to reflect the probability of alarm traffic in the traffic transmitted based on each type of protocol.
[0007] In another possible implementation, the network topology includes a first network node and a second network node connected with each other, and traffic flows from the first network node to the second network node. The traffic risk expectation value between the first network node and the second network node is determined based on the following parameters: a total traffic between other network nodes connected with the first network node and the first network node, a protocol type between the first network node and the second network node, traffic transmitted based on each protocol type between the first network node and the second network node, and an alarm weight of each protocol type between the first network node and the second network node.
[0008] In another possible implementation, the traffic risk expectation value satisfies the following formula:
[0009]
[0010] wherein P ij represents the traffic risk expectation value from the first network node i to the second network node j; represents a total traffic between other network nodes k connected with the first network node i and the first network node i; w ik represents a traffic size between other network nodes k connected with the first network node i; p s represents a traffic size transmitted based on the s-type protocol between the first network node i and the second network node j; A s represents an alarm weight of the s-type protocol between the first network node i and the second network node j; m represents a number of protocol types between the first network node i and the second network node j; and n represents a number of all network nodes connected with the first network node i.
[0011] In another possible implementation, the alarm weight of each protocol type is determined based on at least one of the following: a traffic mode based on traffic transmitted based on each protocol type; wherein the traffic mode includes normal traffic and attack traffic; and an attack protection parameter configured in the security device node for the traffic of each protocol type.
[0012] In another possible implementation, the traffic anomaly includes at least one of the following: a traffic probability between network nodes is greater than a first threshold value; and a traffic risk expectation value between network nodes is greater than a second threshold value.
[0013] In another possible implementation, the target network node includes a first target network node and a second target network node connected with each other. The traffic data of the target network node includes traffic transmitted based on each protocol type between the first target network node and the second target network node. The analysis on the traffic data of the target network node includes: performing anomaly detection on the traffic transmitted based on each protocol type between the first target network node and the second target network node to obtain an anomaly detection result.
[0014] In a further possible implementation, the type of traffic protocol between the first target network node and the second target network node includes a target protocol type; and the method further includes: in a case where the anomaly detection result indicates that there is abnormal traffic and / or attack behavior in the traffic between the first target network node and the second target network node based on the target protocol type, issuing an anomaly alarm message; the alarm message is used to indicate that there is an anomaly in the traffic between the first target network node and the second target network node based on the target protocol type.
[0015] In a further possible implementation, the method further includes: sending a decision request message to a decision system based on the anomaly detection result, the decision request message being used to instruct the decision system to determine a security protection policy based on the anomaly detection result, and sending the security protection policy to a security device node, so that the security device node performs security protection based on the security protection policy.
[0016] In a further possible implementation, the type of traffic protocol between the first target network node and the second target network node includes a first protocol type and a second protocol type; in a case where the anomaly detection result includes an anomaly detection result of the first protocol type and an anomaly detection result of the second protocol type, the security protection policy includes a security protection policy of the first protocol type and a security protection policy of the second protocol type; wherein the execution priority of the security protection policy of the first protocol type and the security protection policy of the second protocol type is determined based on alarm weights of the first protocol type and the second protocol type, and the alarm weight of each protocol type is used to reflect a probability of alarm traffic occurring in the traffic transmitted based on each protocol type; the anomaly detection result of the first protocol type is an anomaly detection result of the traffic transmitted between the first target network node and the second target network node based on the first protocol type; and the anomaly detection result of the second protocol type is an anomaly detection result of the traffic transmitted between the first target network node and the second target network node based on the second protocol type.
[0017] In a second aspect, the present application provides a traffic analysis device applied to the field of network security, the device comprising: an acquisition module and a processing module; the acquisition module is configured to acquire a network topology structure in a preset time period, the network topology structure being generated based on network traffic data in the preset time period; the network topology structure is used to reflect traffic interaction conditions between network nodes in the preset time period; and the processing module is configured to determine target network nodes with traffic anomaly conditions based on the network topology structure, and analyze traffic data of the target network nodes.
[0018] In a possible implementation, the traffic interaction condition comprises at least one of the following: a connection between the network nodes, a data flow direction, a traffic probability, a traffic risk expectation value, a protocol type of the traffic, traffic transmitted based on each protocol type, and an alarm weight of each protocol type; the traffic risk expectation value is used to reflect a probability of occurrence of alarm traffic in the traffic between the network nodes; and the alarm weight of each protocol type is used to reflect a probability of occurrence of alarm traffic in the traffic transmitted based on each protocol type.
[0019] In another possible implementation, the network topology comprises a first network node and a second network node in a connection relationship, and the traffic flows from the first network node to the second network node; and the traffic risk expectation value between the first network node and the second network node is determined based on the following parameters: a total traffic between other network nodes connected to the first network node and the first network node, a protocol type between the first network node and the second network node, traffic transmitted based on each protocol type between the first network node and the second network node, and an alarm weight of each protocol type between the first network node and the second network node.
[0020] In still another possible implementation, the traffic risk expectation value satisfies the following formula:
[0021]
[0022] wherein P ij represents a traffic risk expectation value from a first network node i to a second network node j; represents a total traffic between other network nodes k connected to the first network node i and the first network node i; w ik represents a traffic size between the other network nodes k connected to the first network node i; p s represents a traffic size transmitted based on an s-type protocol between the first network node i and the second network node j; A s represents an alarm weight of the s-type protocol between the first network node i and the second network node j; m represents a number of protocol types between the first network node i and the second network node j; and n represents a number of all network nodes connected to the first network node i.
[0023] In still another possible implementation, the alarm weight of each protocol type is determined based on at least one of the following: a traffic mode of the traffic transmitted based on each protocol type; wherein the traffic mode comprises normal traffic and attack traffic; and an attack protection parameter configured in the security device node for the traffic of each protocol type.
[0024] In still another possible implementation, the traffic abnormal condition comprises at least one of the following: a traffic probability between the network nodes is greater than a first threshold value; and a traffic risk expectation value between the network nodes is greater than a second threshold value.
[0025] In a possible implementation, the target network node comprises a first target network node and a second target network node in a connection relationship; the traffic data of the target network node comprises traffic transmitted between the first target network node and the second target network node based on each type of protocol; and the processing module is specifically configured to analyze the traffic data of the target network node, including: performing anomaly detection on the traffic transmitted between the first target network node and the second target network node based on each type of protocol to obtain an anomaly detection result.
[0026] In a possible implementation, the type of the traffic protocol between the first target network node and the second target network node comprises a target protocol type; and the processing module is further configured to: in a case where the anomaly detection result indicates that there is abnormal traffic and / or attack behavior in the traffic transmitted between the first target network node and the second target network node based on the target protocol type, send an anomaly alarm message; and the alarm message is used to indicate that there is an anomaly in the traffic transmitted between the first target network node and the second target network node based on the target protocol type.
[0027] In a possible implementation, the processing module is further configured to: send a decision request message to a decision system based on the anomaly detection result, the decision request message being used to instruct the decision system to determine a security protection policy based on the anomaly detection result, and send the security protection policy to a security device node, so that the security device node performs security protection based on the security protection policy.
[0028] In a possible implementation, the type of the traffic protocol between the first target network node and the second target network node comprises a first protocol type and a second protocol type; in a case where the anomaly detection result comprises an anomaly detection result of the first protocol type and an anomaly detection result of the second protocol type, the security protection policy comprises a security protection policy of the first protocol type and a security protection policy of the second protocol type; and the execution priority of the security protection policy of the first protocol type and the security protection policy of the second protocol type is determined based on alarm weights of the first protocol type and the second protocol type, and the alarm weight of each type of protocol is used to reflect a probability of alarm traffic appearing in the traffic transmitted based on each type of protocol; the anomaly detection result of the first protocol type is an anomaly detection result of the traffic transmitted between the first target network node and the second target network node based on the first protocol type; and the anomaly detection result of the second protocol type is an anomaly detection result of the traffic transmitted between the first target network node and the second target network node based on the second protocol type.
[0029] In a third aspect, the present application provides an electronic device, comprising: a processor and a memory; the memory stores instructions executable by the processor; and the processor is configured to execute the instructions, so that the electronic device implements the method of the first aspect.
[0030] In a fourth aspect, the present application provides a chip system applied to a traffic analysis device. The chip system comprises one or more interface circuits and one or more processors. The interface circuits and the processors are interconnected through lines. The interface circuits are configured to receive signals from a memory of the traffic analysis device and send signals to the processors, the signals comprising computer instructions stored in the memory. When the processors execute the computer instructions, the electronic device is caused to perform the method of the first aspect.
[0031] In a fifth aspect, the present application provides a readable storage medium comprising software instructions. When the software instructions are run in an electronic device, the electronic device is caused to implement the method of the first aspect.
[0032] In a sixth aspect, the present application provides a computer program product. When the computer program product is run on an electronic device, the electronic device is caused to perform the steps of the method described in the first aspect, so as to implement the method of the first aspect. The beneficial effects of the second aspect to the fifth aspect are described in the corresponding description of the first aspect, and will not be described here. BRIEF DESCRIPTION OF DRAWINGS
[0033] Figure 1 A system architecture schematic diagram is provided for the present application;
[0034] Figure 2 A flowchart of a traffic analysis method is provided for the present application;
[0035] Figure 3 A network topology schematic diagram is provided for the present application;
[0036] Figure 4 Another flowchart of a traffic analysis method is provided for the present application;
[0037] Figure 5 Still another flowchart of a traffic analysis method is provided for the present application;
[0038] Figure 6 A composition schematic diagram of a traffic analysis device is provided for the present application;
[0039] Figure 7 A composition schematic diagram of an electronic device is provided for the present application. DETAILED DESCRIPTION
[0040] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work fall within the scope of protection of the present application.
[0041] It should be noted that the words "exemplary" or "for example" when used in this specification mean "serving as an instance or example," not "preferred" or "advantageous over other examples." The word "or" in context means any, several, either, and so on. Further, the terms "comprise" (and any grammatical variations thereof) and "comprising" are used in this disclosure as permissive, not as limiting and inclusive or exclusive, terms: they add description rather than restriction.
[0042] In addition, the terms "comprise(s)", "comprising", "having", "including", "contain(s)", "containing", "include(s)", "including" and the like as used herein, are specifically intended to be open-ended. For example, these terms do not exclude additional steps or elements, but rather, additional steps or elements are optional. Any process, method, article, or apparatus that "comprises", "comprising", "a", "an", "the", or "has", "having" a step or element does not, without more constraints, preclude the existence of additional steps or elements.
[0043] In order to clearly describe the technical solutions of the embodiments of the present application, in the embodiments of the present application, the terms "first", "second", etc. are used to distinguish the same or similar items with basically the same functions and effects, and those skilled in the art can understand that the terms "first", "second", etc. are not intended to limit the quantity and execution order.
[0044] In the current network environment, the network structure and connection mode are complex (a switch connects an Internet Protocol Address (IP) network, and multiple IP networks are connected by routing, devices are connected by cable or WIFI, etc.), various types of network devices (such as switches, firewalls, gateways, service servers, and Internet of Things devices, etc.) are emerging in endlessly, and the data volume is increasing.
[0045] With the increase of data volume, many difficulties are brought to the analysis of traffic data, for example, how to accurately extract the topology structure by using traffic data becomes a difficulty of traffic application; for another example, when the prior art performs traffic analysis, a large amount of data needs to be calculated, and strong storage capacity and high computing capacity of software and hardware are required to support, and the requirements for software and hardware resources are high.
[0046] To solve the above technical problems, the embodiment of the present application provides a traffic analysis method, in which the network topology structure generated based on network traffic data in a preset time period can not only mark each network node and the connection between network nodes in a network environment, but also can intuitively reflect the traffic situation between network nodes. Therefore, the present application can accurately determine the target network node with abnormal traffic according to the network topology structure, and perform traffic analysis on the target network node, thereby reducing the data analysis amount and the requirements for storage capacity and computing capacity of software and hardware. Therefore, the traffic analysis process of the present application reduces the consumption of software and hardware resources compared with the prior art.
[0047] The technical solutions provided by the embodiment of the present application will be described below with reference to the accompanying drawings.
[0048] Referring to Figure 1 , a schematic diagram of a system architecture related to the traffic analysis method provided by the embodiment of the present application is shown. As Figure 1 indicated, the system architecture related to the traffic analysis method provided by the embodiment of the present application includes a user device 100, a security device node 200-1, a security device node 200-2, a traffic analysis node 300, a decision node 400, a monitoring center 500, and a management platform 600.
[0049] The user device 100 is connected with the security device node 200-1 and the security device node 200-2 respectively; the traffic analysis node 300 is connected with the security device node 200-1 and the security device node 200-2 respectively; the decision node 400 is connected with the security device node 200-1 and the security device node 200-2 respectively; the traffic analysis node 300 is connected with the decision node 400; the traffic analysis node 300 is connected with the monitoring center 500; and the monitoring center 500 is connected with the management platform 600.
[0050] Exemplarily, the user device 100 can be a router, a switch, a mobile phone, a tablet computer, a wearable device, a vehicle-mounted device, an augmented reality (AR) / virtual reality (VR) device, a notebook computer, an ultra-mobile personal computer (UMPC), a netbook, a personal digital assistant (PDA), etc. The embodiment of the present application does not limit the specific device form of the user device 100.
[0051] The security device node 200-1 and the security device node 200-2 are used to implement security protection measures to protect network security.
[0052] In some embodiments, the security device nodes 200-1 and 200-2 can probe the user equipment 100 traffic data and send to the traffic analysis node 300.
[0053] In some embodiments, the security device node can refer to a security protection architecture design organized in a network, a host, and an application layer, including a firewall, an intrusion detection system (IDS), an intrusion prevention system (IPS), anti-virus software, a security information and event management (SIEM) device, etc. The embodiments of the present application do not limit the specific device form of the security device node.
[0054] The traffic analysis node 300 is configured to receive the traffic data of the user equipment 100 sent by the security device nodes 200-1 and 200-2, identify and analyze the received data, calculate the traffic probability and traffic risk expectation value between the user equipment, and draw a network topology structure. The traffic analysis node 300 is also configured to analyze the traffic anomaly situation in a targeted manner, send the analysis result to the decision node 400, and generate a traffic report and send it to the monitoring center 500.
[0055] For example, the traffic analysis node 300 can be a server or an electronic device in a network. Alternatively, the traffic analysis node 300 can be a software module or an application program in a server or an electronic device, for example, a software module application program with data analysis function. The embodiments of the present application do not limit the form of the traffic analysis node 300.
[0056] The decision node 400 is configured to receive the analysis result sent by the traffic analysis node 300, determine a security protection strategy based on the analysis result, and send the security protection strategy to the security device nodes 200-1 and 200-2, so that the security device nodes 200-1 and 200-2 perform security protection based on the security protection strategy.
[0057] For example, the decision node 400 can be a server or an electronic device in a network. Alternatively, the traffic analysis node 300 can be a software module or an application program in a server or an electronic device, for example, a software module application program with decision function. The embodiments of the present application do not limit the form of the decision node 400.
[0058] The monitoring center 500 is configured to receive the traffic report generated by the traffic analysis node 300, and issue an abnormal alarm information based on the abnormal analysis result in the report.
[0059] The management platform 600 is configured to receive the abnormal alarm information transmitted by the monitoring center 500, and is configured to be managed by an administrator.
[0060] It should be noted that the system architecture described in the embodiments of the application is for more clearly illustrating the technical solutions of the embodiments of the application, and does not constitute a limitation on the technical solutions provided by the embodiments of the application. Those skilled in the art can know that, with the evolution of the system architecture, the technical solutions provided by the embodiments of the application are also applicable to similar technical problems.
[0061] Referring to Figure 2 A flowchart of a traffic analysis method provided by the embodiments of the application is shown. The traffic analysis method provided by the application can be applied to Figure 1 The traffic analysis node 300 shown. As Figure 2 The method specifically includes the following steps:
[0062] S101, obtaining a network topology structure in a preset time period.
[0063] The network topology structure is generated based on network traffic data in the preset time period; and the network topology structure is used to reflect the traffic interaction between each network node in the preset time period.
[0064] In some embodiments, the above step S101 can be implemented as steps S1011-S1012.
[0065] S1011, obtaining network traffic data in a preset time period.
[0066] In some embodiments, the network traffic data in the preset time period is obtained by combining active probing and passive probing.
[0067] For example, active probing can be implemented by a packet capture library (libpcap). libpcap is a network packet capture function library under an operating system platform. libpcap is a system-independent user layer traffic packet capture API interface, which provides a portable framework for underlying network monitoring. libpcap allows users to send, scan, parse and fake networks. This capability allows the construction of tools that can probe, scan or attack networks.
[0068] For example, passive probing can obtain information in a hidden manner by monitoring a device mirror port, without affecting the existing network. Passive probing can listen to network activity for a long time in a "quiet" manner.
[0069] S1012, generating a network topology structure based on network traffic data in a preset time period.
[0070] In some embodiments, the network traffic data in a preset time period is analyzed to obtain attribute information of the network nodes and traffic interaction conditions between the network nodes, and then a network topology structure is generated based on the attribute information of the network nodes and the traffic interaction conditions between the network nodes.
[0071] Exemplarily, the network traffic data is uploaded to a data analysis software, and the data analysis software analyzes the network traffic data by using a traffic feature detection method (i.e., explicitly needing to pay attention to traffic features such as data source, data flow direction, traffic probability, traffic risk expectation value, and the like, and then calculating or detecting the traffic features needing to pay attention to) to obtain the attribute information of the network nodes and the traffic interaction conditions between the network nodes.
[0072] In some embodiments, the attribute information of the network nodes includes at least one of the following: operating system type, port number, subnet host media access control (Media Access Control, MAC) address, IP address, subnet mask, gateway, service type, and access control list (Access Control List, ACL), and the like.
[0073] Exemplarily, according to the analyzed attribute information such as operating system type, port number, MAC address, IP address, subnet mask, gateway, service type, and ACL, a basic network topology structure of the probed intranet, i.e., a network device distribution condition of the probed intranet, is drawn. According to routing information in a routing device, switch information connected to the routing can be obtained. According to virtual local area network (Virtual Local Area Network, VLAN) configuration on the switch, host information connected to the switch can be obtained. The basic network topology structure across the switches can be obtained by a way of a jump machine detection.
[0074] In some embodiments, the traffic interaction conditions between the network nodes include at least one of the following: connection between the network nodes, data flow direction, traffic probability, traffic risk expectation value, protocol type of the traffic, traffic transmitted based on each type of protocol, and alarm weight of each type of protocol. The traffic risk expectation value is used to reflect a probability of alarm traffic appearing in the traffic between the network nodes. The alarm weight of each type of protocol is used to reflect a probability of alarm traffic appearing in the traffic transmitted based on each type of protocol.
[0075] In some embodiments, the network topology includes a first network node and a second network node having a connection relationship, wherein traffic flows from the first network node to the second network node; and a traffic probability between the first network node and the second network node is determined based on a traffic size between the first network node and the second network node and a total traffic between other network nodes connected to the first network node and the first network node (here, the other network nodes refer to all network nodes connected to the first network node except the first network node).
[0076] For example, the traffic probability between the first network node and the second network node is determined by a ratio of the traffic size between the first network node and the second network node and the total traffic between the other network nodes connected to the first network node and the first network node.
[0077] In some embodiments, the protocol type of the traffic between the network nodes includes at least one of a HyperText Transfer Protocol (HTTP) type protocol, a Domain Name System (DNS) type protocol, and a MySQL type protocol. The DNS type protocol refers to protocols involved in a DNS query and response process, such as a User Datagram Protocol (UDP) protocol and a Transmission Control Protocol (TCP) protocol; and the MySQL type protocol refers to protocols involved in a Structured Query Language (SQL) query process, such as a TCP / IP protocol.
[0078] In some embodiments, an alarm weight of each type of protocol between the network nodes is determined based on at least one of a traffic mode of traffic transmitted based on each type of protocol and an attack protection parameter configured in a security device node for traffic of each type of protocol. The traffic mode includes normal traffic and attack traffic.
[0079] For example, when the traffic between the network nodes is all normal traffic, the strategy is mainly regular traffic monitoring, and the alarm weight of each type of protocol is low; when the traffic between the network nodes includes attack traffic, the alarm weight of the corresponding type of protocol increases. For example, for HTTP traffic, common attacks such as SQL injection and Cross-Site Scripting (XSS) increase the alarm weight of the HTTP protocol; for DNS traffic, DNS amplification attacks may increase the alarm weight of the DNS protocol; and for MySQL or database protocols, slow query and brute force attack increase the alarm weight of the MySQL protocol.
[0080] In some embodiments, the network topology includes a first network node and a second network node connected, wherein the traffic flows from the first network node to the second network node; the traffic risk expectation value between the first network node and the second network node is determined based on the following parameters: the total traffic between the other network nodes connected to the first network node and the first network node, the protocol type between the first network node and the second network node, the traffic transmitted based on each type of protocol between the first network node and the second network node, and the alarm weight of each type of protocol between the first network node and the second network node.
[0081] Exemplarily, the traffic risk expectation value satisfies the following formula (1):
[0082]
[0083] Wherein, P ij represents the traffic risk expectation value from the first network node i to the second network node j; represents the total traffic between the other network nodes k connected to the first network node i and the first network node i; w ik represents the traffic size between the other network nodes k connected to the first network node i; p s represents the traffic size transmitted based on the s type of protocol between the first network node i and the second network node j; A s represents the alarm weight of the s type of protocol between the first network node i and the second network node j; m represents the number of protocol types between the first network node i and the second network node j; and n represents the number of all network nodes connected to the first network node i.
[0084] For example, the network node a is connected to the network node b, and the network node a is connected to the network node c, the actual total traffic between a and b is 8 GB, and it is assumed that there are two types of protocol traffic, HTTP and DNS, wherein the HTTP protocol traffic size is 5 GB, and the DNS protocol traffic size is 3 GB. Among them, the alarm HTTP type protocol weight is 0.9, and the DNS type protocol weight is 0.1; the actual total traffic between a and c is 9 GB, and it is assumed that there are two types of protocol traffic, HTTP and DNS, wherein the HTTP type protocol traffic size is 2 GB, and the DNS type protocol traffic size is 7 GB. Among them, the alarm HTTP type protocol weight is 0.9, and the DNS type protocol weight is 0.1. Then the traffic risk expectation of a and b is: (5*0.9+3*0.1) / (8+9)=0.28235, and the traffic risk expectation of a and c is: (2*0.9+7*0.1) / (8+9)=0.14706.
[0085] Exemplarily, the network topology generated in a preset time period can be as Figure 3The form shown. From Figure 3 As can be seen from the figure, network node 1 is connected with network node 2, and the data flow direction is from network node 1 to network node 2; network node 1 is connected with network node 3, and the data flow direction is from network node 1 to network node 3; network node 1 is connected with network node 4, and the data flow direction is from network node 4 to network node 1. In addition, the figure shows the interaction between each network node and other network nodes: total traffic, traffic probability, traffic risk expectation value, protocol type of traffic, traffic based on each type of protocol transmission, and alarm weight of each type of protocol. For example, the total traffic of network node 1 to network node 3 is 5GB, the traffic probability is 30%, the traffic risk expectation value is 0.28, the protocol type of traffic is HTTP\MySQL, the traffic of HTTP type protocol is 3GB, and the traffic of MySQL type protocol is 2GB; the alarm weight of HTTP type protocol is 0.2, and the alarm weight of MySQL type protocol is 0.4.
[0086] S102, based on the network topology structure, determining a target network node with a traffic anomaly.
[0087] In some embodiments, the traffic anomaly includes at least one of the following: the traffic probability between network nodes is greater than a first threshold value; the traffic risk expectation value between network nodes is greater than a second threshold value.
[0088] For example, the traffic probability between network nodes being greater than the first threshold value includes multiple cases, for example, the current is in the user active period, causing the traffic probability between network nodes to increase; or, encountering special events (such as network live broadcast, sports events, concerts, etc.), causing a large number of users to access a website or application at the same time, thereby causing the traffic probability between network nodes related to the website or application to increase sharply.
[0089] For example, the traffic risk expectation value between network nodes being greater than the second threshold value includes multiple cases, for example, network attack behaviors such as hacker attacks, Distributed Denial of Service (DDoS) attacks, etc. can cause the alarm traffic between network nodes to abnormally increase, thereby causing the traffic risk expectation value to abnormally increase; or, improper server configuration, insufficient bandwidth, cache invalidation, and other technical problems can also cause the alarm traffic between network nodes to surge, thereby causing the traffic risk expectation value to abnormally increase.
[0090] For example, the first threshold value is 50%, and the second threshold value is 0.2. In the case of Figure 3As shown in the network topology diagram, the traffic probability between network node 1 and network node 3 is 30%, and the traffic risk expectation between network node 1 and network node 3 is 0.28, so network node 1 and network node 3 are target network nodes with traffic abnormality.
[0091] S103, analyze the traffic data of the target network node.
[0092] In some embodiments, the target network nodes include a first target network node and a second target network node that have a connection relationship; the traffic data of the target network nodes includes traffic between the first target network node and the second target network node based on each type of protocol transmission; and the step S103 can be implemented by performing anomaly detection on the traffic between the first target network node and the second target network node based on each type of protocol transmission to obtain an anomaly detection result.
[0093] For example, for HTTP protocol type, the following information is obtained based on the probed traffic: request header, request body: including uniform resource locator (URL), request method (GET, POST, etc.), status code, response time, response body size, etc.; client IP, server IP, request timestamp; User-Agent information, Cookie, request parameter; request statistics obtained by analyzing the above information: request type (success, failure), request duration, response body size; anomaly analysis: abnormal request (such as 4xx, 5xx error code), frequently accessed URL, potential DDoS attack; trend chart: time sequence change of request number, response time, error rate.
[0094] In some embodiments, the type of traffic protocol between the first target network node and the second target network node includes a target protocol type; and as Figure 4 As shown, after the step S103, the method further includes the following step S104:
[0095] S104, issue an anomaly alarm information based on the anomaly detection result.
[0096] In some embodiments, the anomaly alarm information is issued in a case where the anomaly detection result indicates that there is abnormal traffic and / or attack behavior in the traffic between the first target network node and the second target network node based on the target protocol type.
[0097] The alarm information is used to indicate that there is an anomaly in the traffic between the first target network node and the second target network node based on the target protocol type.
[0098] In some embodiments, as Figure 5As shown, after step S103 is performed, the method further includes the following step S105.
[0099] S105, sending a decision request message to a decision system based on the anomaly detection result.
[0100] The decision request message is used to instruct the decision system to determine a security protection policy based on the anomaly detection result, and send the security protection policy to the security device node, so that the security device node performs security protection based on the security protection policy.
[0101] It can be understood that the decision request message can include the anomaly detection result, therefore, after receiving the decision request message, the decision system can determine the security protection policy based on the anomaly detection result, and send the security protection policy to the security device node; accordingly, after receiving the security protection policy sent by the decision system, the security device node can perform security protection based on the security protection policy.
[0102] In some embodiments, the type of traffic protocol between the first target network node and the second target network node includes a first protocol type and a second protocol type; in the case that the anomaly detection result includes an anomaly detection result of the first protocol type and an anomaly detection result of the second protocol type, the security protection policy includes a security protection policy of the first protocol type and a security protection policy of the second protocol type; wherein the execution priority of the security protection policy of the first protocol type and the security protection policy of the second protocol type is determined based on the alarm weight of the first protocol type and the second protocol type, and the alarm weight of each protocol type is used to reflect the probability of occurrence of alarm traffic based on the traffic transmitted by each protocol type; the anomaly detection result of the first protocol type is the anomaly detection result of the traffic transmitted between the first target network node and the second target network node based on the first protocol type; the anomaly detection result of the second protocol type is the anomaly detection result of the traffic transmitted between the first target network node and the second target network node based on the second protocol type.
[0103] It can be understood that setting the execution priority of the security protection policy of different protocol types can on the one hand ensure that the key or important protocol type between nodes is given priority protection, reducing the security risk of the overall network; on the other hand, the system can reduce excessive protection of low-priority protocol types, thereby releasing network bandwidth and computing resources.
[0104] The security protection strategy includes at least one of the following: performing traffic analysis based on real-time exploration of traffic of each protocol, automatically adjusting the protection priority of each protocol; automatically increasing the monitoring intensity and protection weight of the related protocol based on malicious activities such as SQL injection or DDoS attack; automatically adjusting the weight of each protocol based on an AI-based intelligent decision engine according to the protocol type, attack mode and historical data; based on the situation that the protocol weight is raised, the firewall, Intrusion Detection System (IDS) / Intrusion Prevention System (IPS) and load balancer and other devices respond through an automatic mechanism, for example, blocking abnormal traffic, triggering deep packet inspection, etc.
[0105] After the security device node adjusts the security strategy based on the security protection strategy sent by the decision system, the protection effect of the network is improved, the false positive rate is reduced, and the network performance is improved, and the bandwidth utilization is optimized. For example, as shown in Table 1 below, before adjustment: during the traffic peak period, the security device responds slowly, causing the business traffic to be affected, the network delay is too high, and the user experience is affected. After adjustment: through optimization of load balancing and traffic distribution strategy (such as cache, parallel processing, etc.), the throughput and response speed of the security device are improved, ensuring efficient processing of traffic and reducing delay.
[0106] Table 1 Comparison of corresponding indicators before and after adjustment
[0107]
[0108] Next, the traffic analysis method of the embodiments of the present application will be illustrated by combining the system architecture shown in Figure 1 The specific implementation process of the method includes the following steps.
[0109] Step a1, the security device node obtains the traffic data of the user equipment and sends it to the traffic analysis module.
[0110] Step a2, the traffic analysis module analyzes the input traffic data to obtain an analysis result and output.
[0111] In some embodiments, for different types of protocols, the input traffic data is different, and the output analysis result is also different. Exemplarily, the following will be illustrated by taking HTTP protocol, DNS protocol and MySQL protocol as examples respectively.
[0112] (1) Input traffic data
[0113] HTTP protocol: 1) Request header, request body: including URL, request method (GET, POST, etc.), status code, response time, response body size, etc.; 2) Client IP, server IP, request timestamp; 3) User-Agent information, Cookie, request parameters, etc.
[0114] DNS protocol: 1) DNS query request: query type (A record, CNAME, MX record, etc.), query domain name, request timestamp; 2) DNS response data: response type (A, AAAA, etc.), response time, TTL (time to live), queried IP address; 3) DNS request source IP, query frequency, cache status.
[0115] MySQL protocol: 1) SQL query content: query statement, parameters, execution time, number of rows returned by query, error log; 2) User IP, database user information, query duration, connection state, resource consumption (CPU, memory, etc.).
[0116] (2) Output analysis results
[0117] HTTP protocol: 1) Request statistics: request type (success, failure), request duration, response body size; 2) Exception analysis: abnormal requests (such as 4xx, 5xx error codes), frequently accessed URLs, potential DDoS attacks; 3) Trend chart: number of requests, response time, error rate over time.
[0118] DNS protocol: 1) DNS query distribution: number of queries by query type, response status (success, failure); 2) Suspected attack identification: such as DNS amplification attack, large number of identical query requests; 3) Query delay analysis: trends in query response time, high delay request source IP.
[0119] MySQL protocol: 1) Query performance: SQL execution time distribution, slow query analysis; 2) Abnormal query: detected error query, abnormally long query, frequently accessed table; 3) Resource consumption: database connection number, CPU occupancy, memory usage, etc.
[0120] In some embodiments, the data analysis module analyzes the input traffic data involves the following processes: 1) Data preprocessing: parsing and cleaning the received data, removing noise data (such as invalid requests, duplicate requests, etc.). 2) Traffic feature extraction: extract feature data of each protocol, such as HTTP status code, DNS query type, MySQL SQL query, etc. 3) Anomaly detection: identify abnormal traffic or attack behavior through statistical model, rule engine or machine learning model, send anomaly detection results. 4) Data visualization: generate visual reports to display traffic trends, abnormal points, attack types, etc.
[0121] In some embodiments, the network topology is generated based on analysis of network traffic data within a preset time period; and the target network node with the traffic anomaly is determined based on the network topology.
[0122] In some embodiments, the traffic analysis module is further configured to analyze the traffic data of the target network node.
[0123] For example, the target network node includes a first target network node and a second target network node that have a connection relationship; the traffic data of the target network node includes traffic transmitted between the first target network node and the second target network node based on each type of protocol; and the traffic analysis module performs anomaly detection on the traffic transmitted between the first target network node and the second target network node based on each type of protocol to obtain an anomaly detection result.
[0124] In some embodiments, the traffic analysis module generates a traffic report based on the analysis result of the input traffic data. For example, the traffic report can include the anomaly detection result.
[0125] For example, the traffic report specifically includes at least one of the following:
[0126] 1) Traffic Overview: Total Traffic Statistics: Displays the total amount of network traffic within a certain time range, including inbound and outbound traffic, usually in bytes or bits; Traffic Trend: Shows the trend of traffic changes within a time period, which can help security personnel identify traffic fluctuations, peaks and troughs, etc.
[0127] 2) Traffic Protocol Distribution: Protocol Statistics: Analyzes the types of protocols used in traffic (such as HTTP, DNS, MySQL, etc.), and shows the proportion of each protocol in the total traffic; Protocol Usage Frequency: Displays the usage frequency of each protocol (such as request times, data transmission volume, etc.), which can help identify protocol abuse or abnormal traffic.
[0128] 3) Attack Traffic Analysis: Attack Type: Lists the types of attacks detected, such as DDoS, SQL injection, cross-site scripting (XSS), malicious scanning, port scanning, etc.; Attack Source: Shows the IP address, geographic location, and distribution of attack traffic of the attack source; Attack Strength and Impact: Evaluates the strength of the attack (such as traffic, attack packet size, attack duration, etc.), and gives an impact assessment on the network and business.
[0129] 4) Anomaly traffic detection: abnormal traffic patterns: identify abnormal situations in traffic, such as traffic surges, frequent DNS queries, abnormal port usage, etc., which are usually found by comparing traffic baselines; deviation from standard traffic: analyze and report deviations from normal traffic patterns, identify potential security risks.
[0130] 5) User behavior analysis: user request analysis: show the number of requests initiated by a specific user or IP address, access targets, protocols used, etc.; malicious user / activity identification: identify and label users with abnormal behavior, such as users initiating frequent illegal access, brute force attacks, etc.
[0131] 6) Security device status and alarm: device status: provide current status, load, performance data, etc. of various security devices (such as firewalls, IDS / IPS, load balancers, etc.); alarm information: list traffic-related alarm information, including abnormal behavior or threats detected by security devices.
[0132] Step a3, the traffic analysis module sends the traffic report to the monitoring center.
[0133] Step a4, the monitoring center can perform abnormal alarm based on the abnormal detection results carried in the traffic detection report.
[0134] For example, when the abnormal detection result indicates that there is abnormal traffic and / or attack behavior in the traffic between the first target network node and the second target network node based on the target protocol type, the monitoring center sends an abnormal alarm information to the management platform.
[0135] Step a5, the management platform receives the abnormal alarm information sent by the monitoring center and performs unified management and analysis of the alarm information.
[0136] For example, the unified management and analysis of the alarm information by the management platform includes at least one of the following:
[0137] 1) Traffic monitoring and trend analysis: help network security team to monitor traffic changes in real time, find traffic anomalies, potential bottlenecks and attack behaviors in time; based on traffic trends, network bandwidth, load balancing strategies can be optimized, and resource scheduling can be performed.
[0138] 2) Security threat detection and response: through the analysis of attack traffic, various network attacks such as DDoS, SQL injection, XSS, etc. can be found and responded to in time; provide detailed attack sources and attack methods to help security team to trace the source, understand the behavior of attackers and develop defense strategies.
[0139] 3) Optimize security policies: Based on the traffic report, the security team can optimize the rules of firewall, IPS / IDS, load balancing and other devices to improve protection effect; through the analysis of traffic protocol distribution, the configuration of security devices can be adjusted to better prevent potential risks.
[0140] 4) Compliance and audit support: Traffic report can provide detailed records of network traffic, which is very important for compliance checks, audits and legal compliance; for example, the report may record traffic related to accessing sensitive data, which is crucial for compliance such as General Data Protection Regulation (GDPR) or Payment Card Industry Data Security Standard (PCIDSS).
[0141] 5) Performance optimization: Analyze performance bottlenecks in network traffic, identify factors that may affect system performance (such as excessive bandwidth consumption, excessive irrelevant traffic, etc.); provide real-time traffic analysis to help administrators optimize network resources and improve system response speed.
[0142] Step a6, the traffic analysis module sends a decision request message to the decision system based on the anomaly detection result.
[0143] Among them, the decision request message is used to instruct the decision system to determine the security protection policy based on the anomaly detection result, and send the security protection policy to the security device node, so that the security device node performs security protection based on the security protection policy.
[0144] Step a7, in response to the decision request message, the decision system determines the security protection policy based on the anomaly detection result.
[0145] In some embodiments, the decision support module will obtain the user-defined security policy (such as blocking specific IP, speed limit policy, etc.). After receiving the decision request message sent by the traffic analysis module, the decision system determines the security protection policy based on the user-defined security policy and the anomaly detection result carried in the decision request message (for example, adjust the policy based on the cause of the security protection policy). For example, block attack traffic, adjust server load, increase firewall rules, etc.
[0146] In some embodiments, the decision system will further analyze the impact of policy adjustment on system performance, such as delay, throughput, etc.
[0147] Exemplarily, the way to adjust the policy includes:
[0148] 1) Adjusting policies based on traffic analysis: Large traffic: If HTTP traffic exceeds a certain threshold, automatically enable traffic throttling or adjust load balancing policies; DDoS attack: When a large number of requests from the same source IP are identified, automatically enable firewall rules to limit the request source; Abnormal SQL query: When slow or error queries are identified for MySQL protocol, automatically limit the execution of specific queries to prevent database overload.
[0149] 2) Adjusting policies based on threat intelligence: If known malicious IP or domain name is detected, the system can automatically update firewall rules to block communication with these IPs.
[0150] 3) Automated response and manual intervention: If the severity of the security incident reaches a preset level, the system automatically starts emergency response procedures such as closing vulnerability ports, suspending services, etc.; For complex or ambiguous events, generate a decision support report and submit it to the security team for review for further policy adjustments.
[0151] In some embodiments, the security protection policy includes different aspects of security protection, such as network security protection, host security protection, data security protection, application security protection, user identity and access management, vulnerability management and patch management, security monitoring and log management, etc.
[0152] For example, network security protection includes: 1) Boundary protection: Protect the network boundary through firewalls, IPS, etc. to prevent unauthorized access. 2) VPN: Use Virtual Private Network (VPN) to protect the secure communication of remote office workers and the company's internal network. 3) Intrusion detection and prevention: Deploy IDS and IPS to monitor network traffic and detect and prevent malicious activities in a timely manner. 4) Network isolation: Isolate networks of different security levels through VLAN or subnet segmentation to reduce attack surface. 5) Web application firewall: Protect web applications from SQL injection, XSS attacks, etc.
[0153] For example, host security protection includes: 1) Anti-virus and anti-malware: Install and regularly update anti-virus software and anti-malware software to protect the host from viruses, Trojans, ransomware, etc. 2) Host firewall: Perform access control on host ports through the operating system firewall (such as Windows Firewall). 3) Security patch management: Ensure that all systems and software regularly apply the latest security patches to prevent exploitation of known vulnerabilities. 4) Strong password and authentication mechanism: Enforce complex password policies and improve identity verification security through Multi-Factor Authentication (MFA).
[0154] Exemplarily, data security protection includes: 1) Data encryption: using encryption technology to ensure the confidentiality of data during storage and transmission. Common encryption algorithms include symmetric encryption and asymmetric encryption. 2) Data backup and recovery: Regularly backup critical data and ensure the security, integrity and recoverability of backup data. 3) Data leakage prevention (DLP): Monitor the storage, transmission and access of sensitive data through technical means to prevent data leakage. 4) Access control: Implement role-based access control (RBAC) and the principle of least privilege to ensure that only authorized users can access sensitive data.
[0155] Exemplarily, application security protection includes: 1) Web application security: Implement common web security measures such as SQL injection protection, XSS protection, etc. 2) Vulnerability scanning and management: Regularly perform application vulnerability scanning and promptly fix discovered security vulnerabilities to avoid being exploited by hackers. 3) Code audit and secure development: During application development, conduct security code audits to avoid introducing common security vulnerabilities (such as buffer overflow, privilege escalation, etc.). 4) Application Programming Interface (API) security: Implement access control, authentication, rate limiting, etc. measures for APIs to prevent abuse and attacks.
[0156] Exemplarily, user identity and access management (Identity and Access Management, IAM) includes: 1) Identity verification: Strengthen user identity verification through multi-factor authentication (MFA), single sign-on (SSO) and other mechanisms. 2) Permission management: Ensure that users only have the minimum permissions required to perform their work through the principle of least privilege and role-based access control. 3) Account audit: Regularly review user account activities to ensure there is no abuse or inappropriate access behavior.
[0157] Exemplarily, vulnerability management and patch management includes: 1) Vulnerability scanning: Regularly scan systems, networks, and applications for vulnerabilities to promptly discover and fix known vulnerabilities. 2) Patch management: Ensure that security patches for operating systems, applications and services are applied in a timely manner to avoid vulnerabilities being exploited by hackers.
[0158] Exemplarily, security monitoring and log management includes: 1) SIEM: Centralized management and analysis of security logs to detect security events in real time and ensure rapid response. 2) Log audit and analysis: Regularly audit the logs of important systems and applications to track possible security events and abnormal behaviors.
[0159] Step a8, the decision system sends the security protection strategy to the security device node; correspondingly, the security device node receives the security protection strategy.
[0160] Step a9, the security device node performs security protection based on the security protection strategy.
[0161] Optionally, the security device node includes: a firewall (Firewall), an intrusion detection system, an intrusion prevention system, a load balancer (Load Balancer).
[0162] The functions of the firewall: control the flow in and out of the network, and determine whether to allow or reject the data packet through the rule set. The protection measures of the firewall: the firewall will monitor and intercept different flows according to the configured strategy. For example, when the flow is high, the firewall will perform more flow control measures, such as rate limiting, blocking communication of specific ports or protocols, etc.; when the flow is low, the firewall is in a lighter protection mode, and more attention is paid to normal flow filtering and connection management.
[0163] The function of the intrusion detection system: monitor potential security threats in network traffic, and detect malicious activities by analyzing known attack characteristics. The protection measures of the intrusion detection system: mainly detect abnormal behaviors in the flow, such as DDoS attacks, SQL injection, XSS attacks, etc. For example, during the period of attack activity surge, IDS will detect abnormalities at high frequency through rule base and behavior analysis technology; during the low flow period, IDS is in a lighter working state, mainly focusing on the basic abnormalities of the flow.
[0164] The function of the intrusion prevention system: similar to IDS, but further takes defensive measures, and can actively intercept malicious traffic. The protection measures of IPS: IPS automatically prevents the further spread of malicious traffic according to the configured strategy. The intrusion prevention system plays an important role when large-scale attacks (such as DDoS) occur, and can quickly respond and interrupt the attack.
[0165] The function of the load balancer: distribute the flow entering the network to ensure the effective use of server resources and prevent a single server from being overloaded. The protection measures of the load balancer: through intelligent flow distribution algorithm, balance the load of the server during high flow period. When encountering large-scale DDoS attacks, the load balancer can distribute attack traffic to multiple nodes to reduce the pressure on a single server.
[0166] Optionally, the protection state of the security device node includes the following parameters: time period, flow condition, protection measure, attack condition, and security device load. For example, as shown in Table 2.
[0167] Table 2 Protection state of security device node
[0168]
[0169] Optionally, a distributed traffic analysis and response mechanism is configured on each security device node, and the adjusted protocol weight is timely delivered to each security device node, ensuring that each node can quickly respond and take corresponding protective measures.
[0170] The above mainly describes the scheme of the embodiments of the present disclosure from the perspective of the method. It can be understood that, in order to implement the above functions, the traffic analysis device comprises at least one of the corresponding hardware structure and software module for executing each function. Those skilled in the art should easily realize that, in combination with the units and algorithm steps of each example described in the embodiments disclosed herein, the embodiments of the present disclosure can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is implemented in hardware or computer software driven hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the embodiments of the present disclosure.
[0171] The embodiments of the present disclosure can divide the traffic analysis device into functional modules according to the above method embodiments. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one functional module. The above integrated module can be implemented in the form of hardware or software. It should be noted that the division of modules in the embodiments of the present disclosure is illustrative, and is only a logical functional division. Actual implementation can have another division manner. The following takes the example of dividing each functional module according to each function.
[0172] Figure 6 A composition schematic diagram of a traffic analysis device provided by the embodiments of the present disclosure is shown in the figure. The traffic analysis device is used to execute the traffic analysis method provided by the method embodiments. As shown in the figure, the traffic analysis device comprises an acquisition module 601 and a processing module 602. Figure 4
[0173] The acquisition module 601 is used to acquire the network topology in a preset time period. The network topology is generated based on the network traffic data in the preset time period. The network topology is used to reflect the traffic interaction between each network node in the preset time period.
[0174] The processing module 602 is used to determine the target network node with traffic abnormality based on the network topology, and analyze the traffic data of the target network node.
[0175] In a possible implementation, the traffic interaction condition comprises at least one of the following: a connection between the network nodes, a data flow direction, a traffic probability, a traffic risk expectation value, a protocol type of the traffic, traffic transmitted based on each protocol type, and an alarm weight of each protocol type; the traffic risk expectation value is used to reflect a probability of alarm traffic in the traffic between the network nodes; and the alarm weight of each protocol type is used to reflect a probability of alarm traffic in the traffic transmitted based on each protocol type.
[0176] In another possible implementation, the network topology comprises a first network node and a second network node in a connection relationship, and the traffic flows from the first network node to the second network node; and the traffic risk expectation value between the first network node and the second network node is determined based on the following parameters: a total traffic between other network nodes connected to the first network node and the first network node, a protocol type between the first network node and the second network node, traffic transmitted based on each protocol type between the first network node and the second network node, and an alarm weight of each protocol type between the first network node and the second network node.
[0177] In still another possible implementation, the traffic risk expectation value satisfies the following formula:
[0178]
[0179] wherein E(i, j) represents a traffic risk expectation value from the first network node i to the second network node j; S(i) represents a total traffic between other network nodes k connected to the first network node i and the first network node i; F(k, i) represents a traffic size between other network nodes k connected to the first network node i; F(s, i, j) represents a traffic size transmitted based on an s-type protocol between the first network node i and the second network node j; W(s, i, j) represents an alarm weight of the s-type protocol between the first network node i and the second network node j; m represents a number of protocol types between the first network node i and the second network node j; and n represents a number of all network nodes connected to the first network node i.
[0180] In still another possible implementation, the alarm weight of each protocol type is determined based on at least one of the following: a traffic mode of the traffic transmitted based on each protocol type; the traffic mode comprises normal traffic and attack traffic; and an attack protection parameter configured in the security device node for the traffic of each protocol type.
[0181] In still another possible implementation, the traffic abnormal condition comprises at least one of the following: a traffic probability between the network nodes is greater than a first threshold value; and a traffic risk expectation value between the network nodes is greater than a second threshold value.
[0182] In another possible implementation, the target network nodes include a first target network node and a second target network node that have a connection relationship; the traffic data of the target network nodes includes traffic transmitted between the first target network node and the second target network node based on each type of protocol; and the processing module 602 is specifically configured to analyze the traffic data of the target network nodes, including: performing anomaly detection on the traffic transmitted between the first target network node and the second target network node based on each type of protocol to obtain an anomaly detection result.
[0183] In another possible implementation, the type of the traffic protocol between the first target network node and the second target network node includes a target protocol type; and the processing module 602 is further configured to: in a case where the anomaly detection result indicates that there is abnormal traffic and / or attack behavior in the traffic transmitted between the first target network node and the second target network node based on the target protocol type, send an anomaly alarm message; and the alarm message is used to indicate that there is an anomaly in the traffic transmitted between the first target network node and the second target network node based on the target protocol type.
[0184] In another possible implementation, the processing module 602 is further configured to: send a decision request message to a decision system based on the anomaly detection result, the decision request message being used to instruct the decision system to determine a security protection policy based on the anomaly detection result, and send the security protection policy to a security device node, so that the security device node performs security protection based on the security protection policy.
[0185] In another possible implementation, the type of the traffic protocol between the first target network node and the second target network node includes a first protocol type and a second protocol type; in a case where the anomaly detection result includes an anomaly detection result of the first protocol type and an anomaly detection result of the second protocol type, the security protection policy includes a security protection policy of the first protocol type and a security protection policy of the second protocol type; and the execution priority of the security protection policy of the first protocol type and the security protection policy of the second protocol type is determined based on alarm weights of the first protocol type and the second protocol type, and the alarm weight of each type of protocol is used to reflect a probability of alarm traffic appearing in the traffic transmitted based on each type of protocol; the anomaly detection result of the first protocol type is an anomaly detection result of the traffic transmitted between the first target network node and the second target network node based on the first protocol type; and the anomaly detection result of the second protocol type is an anomaly detection result of the traffic transmitted between the first target network node and the second target network node based on the second protocol type.
[0186] In an example embodiment, the application also provides an electronic device, Figure 7 A composition diagram of an electronic device provided by the application is shown in FIG. 1. Figure 7As shown, the electronic device can include a processor 701 and a memory 702; the memory 702 stores instructions executable by the processor 701; the processor 701 is configured to execute the instructions, so that the electronic device or the network device or the manager implements the method as described in the foregoing method embodiment.
[0187] In actual implementation, the acquisition module 601 and the processing module 602 can be implemented by Figure 7 The processor 701 shown in the figure calls the instructions stored in the memory 702 to implement. The specific execution process can refer to the description of the traffic analysis method part above, which will not be repeated here.
[0188] In an exemplary embodiment, the embodiments of the present application also provide a readable storage medium, which stores program instructions; when the program instructions are executed by a computer, the computer implements the method as described in the foregoing embodiments. The readable storage medium can be a non-transitory readable storage medium, for example, the non-transitory readable storage medium can be a read-only memory (ROM), a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk and an optical data storage device, etc.
[0189] In an exemplary embodiment, the embodiments of the present application also provide a computer program product, when the computer program product runs on a computer, the computer executes the above-mentioned related method steps to implement the traffic analysis method in the above-mentioned embodiments.
[0190] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited to this, any change or replacement within the technical scope disclosed in the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A traffic analysis method, characterized by, The method comprises: obtaining a network topology structure in a preset time period, the network topology structure being generated based on network traffic data in the preset time period; the network topology structure is used to reflect traffic interaction between network nodes in the preset time period; the traffic interaction comprises connection between network nodes, data flow direction, traffic probability, traffic risk expectation value, protocol type of traffic, traffic transmitted based on each protocol type, and alarm weight of each protocol type; wherein the traffic risk expectation value is used to reflect the probability of alarm traffic in the traffic between network nodes; and the alarm weight of each protocol type is used to reflect the probability of alarm traffic in the traffic transmitted based on the each protocol type; the network topology structure comprises a first network node and a second network node in a connection relationship, wherein traffic flows from the first network node to the second network node; and the traffic risk expectation value between the first network node and the second network node is determined based on the following parameters: the sum of traffic between other network nodes connected to the first network node and the first network node, the protocol type between the first network node and the second network node, the traffic transmitted based on each protocol type between the first network node and the second network node, and the alarm weight of each protocol type between the first network node and the second network node; the traffic risk expectation value satisfies the following formula: Wherein, the P ij represents the traffic risk expectation value from the first network node i to the second network node j; the represents the sum of the traffic between the other network node k connected with the first network node i and the first network node i; the w ik represents the traffic size between the other network node k connected with the first network node i; the p s represents the traffic size between the first network node i and the second network node j based on the s type protocol transmission; the A s represents the alarm weight of the s type protocol between the first network node i and the second network node j; the m represents the number of protocol types between the first network node i and the second network node j; the n represents the number of all network nodes connected with the first network node i; based on the network topology structure, determining a target network node with a traffic anomaly; the traffic anomaly comprises that the traffic probability between network nodes is greater than a first threshold value, and the traffic risk expectation value between network nodes is greater than a second threshold value; analyzing traffic data of the target network node.
2. The method of claim 1, wherein, the alarm weight of each protocol type is determined based on at least one of the following: a traffic mode based on the traffic transmitted based on each protocol type; wherein the traffic mode comprises normal traffic and attack traffic; attack protection parameters configured in a security device node for the traffic of each protocol type.
3. The method of claim 1, wherein, the target network node comprises a first target network node and a second target network node in a connection relationship; and the traffic data of the target network node comprises traffic transmitted based on each protocol type between the first target network node and the second target network node. the analyzing of the traffic data of the target network node comprises: performing anomaly detection on the traffic transmitted based on each protocol type between the first target network node and the second target network node to obtain an anomaly detection result.
4. The method of claim 3, wherein, the type of traffic protocol between the first target network node and the second target network node comprises a target protocol type; and the method further comprises: in a case where the anomaly detection result indicates that there is abnormal traffic and / or attack behavior in the traffic based on the target protocol type between the first target network node and the second target network node, issuing an anomaly alarm information; the alarm information is used to indicate that there is an anomaly in the traffic based on the target protocol type between the first target network node and the second target network node.
5. The method of claim 3, wherein, the method further comprises: The decision request message is used to instruct the decision system to determine a security protection policy based on the anomaly detection result and send the security protection policy to a security device node, so that the security device node performs security protection based on the security protection policy.
6. The method of claim 5, wherein, The type of traffic protocol between the first target network node and the second target network node includes a first protocol type and a second protocol type; In a case where the anomaly detection result includes an anomaly detection result of the first protocol type and an anomaly detection result of the second protocol type, the security protection policy includes a security protection policy of the first protocol type and a security protection policy of the second protocol type; wherein the execution priority of the security protection policy of the first protocol type and the security protection policy of the second protocol type is determined based on the alarm weight of the first protocol type and the second protocol type, and the alarm weight of each protocol is used to reflect the probability of alarm traffic in the traffic transmitted based on each protocol; The anomaly detection result of the first protocol type is an anomaly detection result of traffic transmitted between the first target network node and the second target network node based on the first protocol type; and the anomaly detection result of the second protocol type is an anomaly detection result of traffic transmitted between the first target network node and the second target network node based on the second protocol type.
7. An electronic device, comprising: The electronic device includes a processor and a memory; The memory stores instructions executable by the processor; The processor is configured to execute the instructions, so that the electronic device implements the method of any one of claims 1-6.
8. A readable storage medium, characterized by, The readable storage medium includes software instructions; When the electronic device runs the software instructions, the electronic device implements the method of any one of claims 1-6.
9. A computer program product, characterised in that, The computer program product includes a computer program, when the computer program runs on the electronic device, the electronic device executes the method of any one of claims 1-6.
Citation Information
Patent Citations
Method and device for determining network topology and computer storage medium
CN112751714A
Method and device for determining default parameter value, server and storage medium
CN113992507A