Internet security service system based on flow analysis

Through the Internet security service system based on traffic analysis, the problem of lack of in-depth detection of data security in the existing technology is solved, real-time assessment of network risks and efficient screening of abnormal access is achieved, and data security and reliability are improved.

CN119945694AActive Publication Date: 2025-05-06INFORMATION & COMM CO OF STATE GRID XINJIANG ELECTRIC POWER CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202311457748.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-03
Publication Date
2025-05-06
Estimated Expiration
2043-11-03

AI Technical Summary

Technical Problem

The existing Internet security assessment technology mainly focuses on threat analysis of individual events, lacks in-depth detection of data security, resulting in low system access security and inability to understand the overall security status of the network in a timely manner.

Method used

The Internet security service system based on traffic analysis is adopted, and security parameters are extracted through the traffic acquisition and analysis module to establish a network risk model. The terminal management module confirms the data attack index based on access rights, and the decision protection module performs abnormal detection and timeliness judgment, updates the risk model and intercepts non-secure traffic data.

Benefits of technology

Real-time evaluation of network risk performance and efficient screening of abnormal access is realized, data security and reliability are improved, alarms are promptly reported and abnormal traffic information is recorded, which is convenient for subsequent evidence collection and reference.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945694A_ABST
    Figure CN119945694A_ABST
Patent Text Reader

Abstract

The invention provides an internet security service system based on traffic analysis, which comprises a traffic acquisition and analysis module, a network risk model module, a terminal management module, a risk attack test module and a decision protection module, and is characterized in that the decision protection module is used for receiving output of the network risk model module; the traffic data with the network risk performance judged to be safe is used as the input of a risk model, an aging cycle judgment condition is added for updating the risk model, and the time difference between the latest access time and the current time and the information amount change before and after access are verified according to the access record of the same user; according to the method, under the conditions of frequent access and abnormal information change in the application, an alarm can be generated, a network manager can be notified, abnormal traffic information operation can be tracked, a tracking result can be recorded, later evidence obtaining and future reference are facilitated, and the safety of the application is improved through a hierarchical evidence obtaining mode. And the evidence obtaining efficiency of the abnormal traffic information is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of Internet security technology, and in particular to an Internet security service system based on traffic analysis. Background Art

[0002] With the development of Internet technology, network data technology has been widely used. Correspondingly, how to deal with network attacks and better protect network security has become an important topic that needs to be studied and is of great significance.

[0003] Internet security assessment provides important indicators for Internet security defense strategies and is the foundation of Internet security defense. Only by accurately evaluating the security status of the Internet can an effective Internet security defense strategy be formulated. Internet security assessment evaluates the security status and security change trends of the overall Internet information system through comprehensive factors such as the operating status of Internet devices, Internet behavior detection, and user behavior monitoring.

[0004] Existing IoT security detection and assessment generally only assesses the security risks of external networks. The security assessment of network information systems focuses on the threat posed to the system by a single event, such as file damage or file loss. The perspective is too single, especially for data security. It only allows access and reading after a surface analysis of the data security, and does not make targeted in-depth detection of security files. Once illegal access users break through access rights, they use multiple access methods to gradually steal information, resulting in low system access security. It is impossible to timely understand the overall security status of the network and realize it later.

[0005] Therefore, it is necessary to provide a new Internet security service system based on traffic analysis to solve the above technical problems. Summary of the invention

[0006] In order to solve the existing technical problems, especially those related to data security, in which access and reading are allowed only after surface analysis of data security, and no targeted in-depth detection is made for security files, and once an illegal access user breaks through the access rights, multiple accesses are used to gradually steal information, resulting in low system access security, and inability to timely understand and evaluate the security status of the network as a whole, and belated awareness, the present invention provides an Internet security service system based on traffic analysis.

[0007] The Internet security service system based on traffic analysis provided by the present invention includes a traffic collection and analysis module, which is used to collect Internet traffic data and extract security parameters from the Internet traffic data;

[0008] The network risk model module is used to build and train risk models based on security parameters extracted from Internet traffic data;

[0009] The terminal management module is used to establish different permissions for different access users and store the traffic data information uploaded by the access users;

[0010] The risk attack test module is used to conduct attack tests on risk models. Different data attack indexes are determined according to different access rights of terminals. The attack indexes are used to evaluate network risk performance, divide network risk performance into security and non-security, and intercept non-security traffic data.

[0011] The decision protection module is used to receive the output of the network risk model module, use the traffic data whose network risk performance is judged as safe as the input of the risk model, and add the time-limit cycle judgment condition to update the risk model. It verifies the time difference between the most recent access time and the current time and the change in the amount of information before and after the access based on the access records of the same user, and performs anomaly detection on the security traffic data;

[0012] Anomaly detection is as follows:

[0013] If the time difference is less than the preset access interval and the amount of information changes abnormally, it is judged as level 1 non-security;

[0014] If the time difference is less than the scheduled access interval or the amount of information changes abnormally, it is judged as level 2 non-security;

[0015] If the time difference is greater than or equal to the predetermined access interval and the amount of information changes abnormally, it is judged to be level one security;

[0016] If the time difference is less than the predetermined access interval and the amount of information changes normally, it is judged to be level 2 security;

[0017] If the time difference is greater than or equal to the predetermined access interval and the amount of information changes normally, it is judged to be level three security;

[0018] The first-level non-safety and second-level non-safety traffic data are intercepted and alarmed, and the first-level safety and second-level safety traffic data are recorded and tracked to facilitate subsequent evidence collection and reference.

[0019] Further, the attack index is defined as Where D 0 Indicates the amount of non-security traffic data in the initial terminal network attack, D 1 Represents the amount of non-security traffic data under N rounds of attack, N 0 Expressed as the number of devices at the initial terminal, N 1It is expressed as the number of devices in a safe state under N rounds of attacks.

[0020] Furthermore, the information volume change judgment standard is that when the information volume after access is reduced compared with the information volume before access, it is judged that the information volume change is abnormal; when the information volume after access is the same as or increased compared with the information volume before access, it is judged that the information volume change is normal.

[0021] Furthermore, before updating the risk model, the preliminary safety traffic data is cleansed to filter out blank information content to obtain cleaned data.

[0022] Furthermore, the terminal management module also includes a monitoring unit for monitoring the operation content, operation time and operation object of the accessing user, and recording and issuing an alarm when abnormal traffic data or abnormal network operation occurs at the terminal accessed by the accessing user.

[0023] Furthermore, when the abnormal traffic data is confirmed to exist during the abnormal detection process of the security traffic data, the time difference between the most recent access time and the current time and the change in the amount of information before and after the access are verified based on the access records of the same user, and recorded and checked.

[0024] Compared with the related art, the Internet security service system based on traffic analysis provided by the present invention has the following beneficial effects:

[0025] 1. The present invention uses the traffic data judged as security by network risk performance as the input of the risk model, and adds a time cycle judgment condition to update the risk model. It verifies the time difference between the most recent access time and the current time and the change in the amount of information before and after the access based on the access record of the same user, and performs anomaly detection on the security traffic data. In the case of frequent access and abnormal change in the amount of information in the application, it can generate an alarm to notify the network management personnel, and can track abnormal traffic information operations and record the tracking results to facilitate future evidence collection and reference.

[0026] 2. The present invention determines different data attack indexes according to different access rights of the terminal. The attack index is used to evaluate network risk performance, and the network risk performance is divided into security and non-security. The traffic data of the network risk performance judged to be secure is used as the input of the risk model, and a time cycle judgment condition is added to update the risk model, and further screen the security data, thereby realizing the screening of suspected abnormal access to user data, improving the efficiency of judging abnormal access, and further reducing the risk of user data leakage, thereby improving the security and reliability of data.

[0027] 3. The present invention improves the efficiency of collecting evidence of abnormal traffic information through a hierarchical evidence collection method, distinguishes the operation records of different users under different permissions, and further improves the efficiency of judging the storage method of user data, thereby ensuring the efficiency of data extraction and processing. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] Figure 1 A block diagram of the operating principle of the Internet security service system based on traffic analysis provided by the present invention;

[0029] Figure 2 A system structure diagram of the Internet security service system based on traffic analysis provided by the present invention;

[0030] Figure 3 A relationship connection block diagram of the network risk model module provided by the present invention;

[0031] Figure 4 This is a classification structure diagram of the anomaly detection results provided by the present invention. DETAILED DESCRIPTION

[0032] The present invention will be further described below in conjunction with the accompanying drawings and implementation modes.

[0033] Please refer to Figure 1 , Figure 2 , Figure 3 as well as Figure 4 ,in, Figure 1 A block diagram of the operating principle of the Internet security service system based on traffic analysis provided by the present invention; Figure 2 A system structure diagram of the Internet security service system based on traffic analysis provided by the present invention; Figure 3 A relationship connection block diagram of the network risk model module provided by the present invention; Figure 4 This is a classification structure diagram of the anomaly detection results provided by the present invention.

[0034] Those skilled in the art will appreciate that, unless otherwise stated, the singular forms "a", "an", "said" and "the" used herein may also include plural forms. It should be further understood that the term "comprising" used in the specification of the present application refers to the presence of the features, procedures, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, procedures, steps, operations, elements, components and / or groups thereof.

[0035] Embodiment 1

[0036] In the specific implementation process, Figure 1-Figure 4 As shown, the Internet security service system based on traffic analysis includes a traffic collection and analysis module, which is used to collect Internet traffic data and extract security parameters from the Internet traffic data;

[0037] The network risk model module is used to build and train risk models based on security parameters extracted from Internet traffic data;

[0038] The terminal management module is used to establish different permissions for different access users and store the traffic data information uploaded by the access users. The terminal management module also includes a monitoring unit, which is used to monitor the operation content, operation time and operation object of the access users, and to record and alarm when abnormal traffic data or abnormal network operation occurs at the terminal accessed by the access users. When the abnormal detection process of the security traffic data confirms the existence of abnormal traffic data, the time difference between the most recent access time and the current time and the change in the amount of information before and after the access are verified based on the access records of the same user, and then recorded and checked;

[0039] The risk attack test module is used to conduct attack tests on risk models. Different data attack indexes are determined according to different access rights of terminals. The attack indexes are used to evaluate network risk performance, divide network risk performance into security and non-security, and intercept non-security traffic data.

[0040] The aggression index is defined as Where D 0 Indicates the amount of non-security traffic data in the initial terminal network attack, D 1 Represents the amount of non-security traffic data under N rounds of attack, N 0 Expressed as the number of devices at the initial terminal, N 1 It is expressed as the number of devices in a safe state under N rounds of attacks. The larger the attack index, the worse the security. That is, the greater the authority allocation, the lower the security. Targeted behavior monitoring and recording should be carried out for internal users to improve the efficiency of evidence collection of abnormal traffic information, distinguish the operation records of different users under different authorities, and further improve the efficiency of judging the storage method of user data, ensuring the efficiency of data extraction and processing;

[0041] The decision protection module is used to receive the output of the network risk model module, judge the network risk performance as the flow data of security as the input of the risk model, and add the time cycle judgment condition to update the risk model. Before updating the risk model, the preliminary security flow data is cleaned, and the blank information content is screened out to obtain the cleaned data. According to the access record of the same user, the time difference between the most recent access time and the current time and the change in the amount of information before and after the access are verified, and the security flow data is detected for anomalies. The security data is further screened, thereby realizing the screening of suspected abnormal access to user data, improving the efficiency of judging abnormal access, and further reducing the risk of user data leakage, improving the security and reliability of data;

[0042] Basic conditions for abnormal detection of security traffic data: According to the number of initial terminals, select the number of traffic data to be input, where the number of traffic data is twice the number of terminals, and the interval time for a single terminal to access is 1 minute. Divide user permissions into three levels, that is, the first-level permission is only for system access and browsing, the second-level permission can add information content based on the first-level permission, and the third-level permission can modify the existing information content based on the second-level permission. Select the number of attacks required according to the permissions of different access users. The number of attacks for users with first-level permission is 1; the number of attacks for users with second-level permission is 2; the number of attacks for users with third-level permission is 3;

[0043] Anomaly detection is as follows:

[0044] If the time difference is less than the preset access interval and the amount of information changes abnormally, it is judged as level 1 non-safety. For example, if the time difference between the last access time and the current time of a level 3 user is less than 1 minute, that is, less than the allowed access interval, it is considered frequent access, and the amount of information on the access terminal changes, then the access user's behavior is considered non-safety, and the operation record is saved and recorded as level 1 non-safety;

[0045] If the time difference is less than the preset access interval or the amount of information changes abnormally, it is judged as Level 2 non-safety. For example, if the time difference between the last access time and the current time of a Level 3 user is less than 1 minute, that is, less than the allowed access interval, it is a frequent access, or the amount of information on the access terminal changes. If either frequent access or information volume changes, the access user's behavior is considered non-safety, and the operation record is saved and recorded as Level 2 non-safety. Further testing is performed. If both frequent access and information volume changes exist, the access user's behavior is recorded as Level 1 non-safety.

[0046] If the time difference is greater than or equal to the preset access interval and the amount of information changes abnormally, it is judged as level one security. For example, if the time difference between the last access time and the current time of a level three user is greater than or equal to 1 minute, that is, within the allowed access interval, it is a normal access, and the amount of information on the access terminal changes, then the access user's behavior is considered to be security, and the operation record is saved and recorded as level one security;

[0047] If the time difference is less than the preset access interval and the amount of information changes normally, it is judged as level 2 security. For example, if the time difference between the last access time and the current time of a level 3 user is less than 1 minute, that is, less than the allowed access interval, it is considered frequent access, and the amount of information on the access terminal has not changed, then the access user's behavior is considered safe, and the operation record is saved and recorded as level 2 security.

[0048] If the time difference is greater than or equal to the preset access interval and the amount of information changes normally, it is judged as level 3 security. For example, if the time difference between the last access time and the current time of a level 3 user is greater than or equal to 1 minute, that is, within the allowed access interval, it is a normal access, and the amount of information on the access terminal has not changed, then the access user's behavior is considered safe, and the operation record is saved and recorded as level 3 security;

[0049] Level one is the marginal level, which means it is in a suspected state in the judgment of safety and non-safety and is the key monitoring object.

[0050] The first-level non-safety and second-level non-safety traffic data are intercepted and alarmed, and the first-level safety and second-level safety traffic data are recorded and tracked to facilitate subsequent evidence collection and reference.

[0051] Verify the time difference between the most recent access time and the current time based on the access records of the same user to determine whether the traffic data in this time period is frequently accessed;

[0052] The criterion for judging the change in the amount of information is that when the amount of information after access is reduced compared to the amount of information before access, it is judged that the change in the amount of information is abnormal; when the amount of information after access is the same as or increased compared to the amount of information before access, it is judged that the change in the amount of information is normal, that is, no content modification or addition of new content after access is judged as a safe judgment, and content modification after access or frequent access modifications are judged as unsafe judgment.

[0053] Experimental test of this system:

[0054] In order to further verify the performance of the Internet security service system based on traffic analysis proposed by the present invention in practical applications, a network is constructed to simulate normal behavior and attack behavior, and a comparative experiment between the network and the traditional system is carried out. A virtual server is selected as the terminal management module, including 8 virtual servers. The present system and the traditional system are used to perform security detection on the mobile baseline of the virtual server. The experimental test results are as follows:

[0055]

[0056] From the data in the above table, it can be seen that when this system is attacked, the amount of data loss is significantly less than that of the traditional system. At the same time, during the first, fourth and fifth attacks, the amount of data loss of this system is zero, which is of great significance.

[0057] In order to verify the security of the present invention and the traditional method, 30 traffic data are selected as security tests, including 20 traffic data with original address watermarks and 10 traffic data without watermarks. The traffic data without watermarks are taken as abnormal traffic data. The 30 traffic data are uploaded to the present system and the traditional system respectively. The traffic data with large original address watermarks are replaced with watermarks every 1 minute (eliminating the original address watermarks) until 26 watermark-free traffic data are finally reached. Experimental demonstration is carried out to determine the data security. The specific experimental data are compared as follows:

[0058]

[0059]

[0060] From the data in the above table, we can see that this system timely blocks changes in information volume and frequent access, and conducts in-depth inspections on files that were originally judged to be safe. Although the accuracy rate has not reached 100%, it has greatly improved the recognition accuracy of non-safe files compared with traditional systems, improved the efficiency of judging abnormal access, and further reduced the risk of user data leakage, thereby improving data security and reliability.

[0061] The circuits and controls involved in the present invention are all prior art and will not be described in detail here.

[0062] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a general hardware platform, and of course, by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the relevant technology can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0063] The above shows and describes the basic principles and main features of the present invention and the advantages of the present invention. For those skilled in the art, it is obvious that the present invention is not limited to the details of the above exemplary embodiments, and the present invention can be implemented in other specific forms without departing from the spirit or basic features of the present invention. Therefore, no matter from which point of view, the embodiments should be regarded as exemplary and non-restrictive. The scope of the present invention is defined by the attached claims rather than the above description, and it is intended that all changes falling within the meaning and scope of the equivalent elements of the claims are included in the present invention, and any figure mark in the claims should not be regarded as limiting the claims involved.

[0064] In addition, it should be understood that although the present specification is described according to implementation modes, not every implementation mode contains only one independent technical solution. This description of the specification is only for the sake of clarity. Those skilled in the art should regard the specification as a whole. The technical solutions in each embodiment may also be appropriately combined to form other implementation modes that can be understood by those skilled in the art.

Claims

1. An Internet security service system based on traffic analysis, characterized in that: It includes a traffic collection and analysis module for collecting Internet traffic data and extracting security parameters from the Internet traffic data; The network risk model module is used to build and train risk models based on security parameters extracted from Internet traffic data; The terminal management module is used to establish different permissions for different access users and store the traffic data information uploaded by the access users; The risk attack test module is used to conduct attack tests on risk models. Different data attack indexes are determined according to different access rights of terminals. The attack indexes are used to evaluate network risk performance, divide network risk performance into security and non-security, and intercept non-security traffic data. The decision protection module is used to receive the output of the network risk model module, use the traffic data whose network risk performance is judged as safe as the input of the risk model, and add the time-limit cycle judgment condition to update the risk model. It verifies the time difference between the most recent access time and the current time and the change in the amount of information before and after the access based on the access records of the same user, and performs anomaly detection on the security traffic data; Anomaly detection is as follows: If the time difference is less than the preset access interval and the amount of information changes abnormally, it is judged as level 1 non-security; If the time difference is less than the scheduled access interval or the amount of information changes abnormally, it is judged as level 2 non-security; If the time difference is greater than or equal to the predetermined access interval and the amount of information changes abnormally, it is judged to be level one security; If the time difference is less than the predetermined access interval and the amount of information changes normally, it is judged to be level 2 security; If the time difference is greater than or equal to the predetermined access interval and the amount of information changes normally, it is judged to be level three security; The first-level non-safety and second-level non-safety traffic data are intercepted and alarmed, and the first-level safety and second-level safety traffic data are recorded and tracked to facilitate subsequent evidence collection and reference.

2. The Internet security service system based on traffic analysis according to claim 1 is characterized in that: The aggression index is defined as Where D0 represents the amount of non-security traffic data in the initial terminal network attack, D1 represents the amount of non-security traffic data under N rounds of attacks, N0 represents the number of devices in the initial terminal, and N1 represents the number of devices in a safe state under N rounds of attacks.

3. The Internet security service system based on traffic analysis according to claim 2 is characterized in that: The information volume change judgment standard is that when the amount of information after access is reduced compared to the amount of information before access, it is judged that the information volume change is abnormal; when the amount of information after access is the same as or increased compared to the amount of information before access, it is judged that the information volume change is normal.

4. The Internet security service system based on traffic analysis according to claim 3 is characterized in that: Before updating the risk model, the preliminary safety traffic data is cleaned to filter out blank information content to obtain cleaned data.

5. The Internet security service system based on traffic analysis according to claim 4 is characterized in that: The terminal management module also includes a monitoring unit for monitoring the operation content, operation time and operation object of the accessing user, and recording and issuing an alarm when abnormal traffic data or abnormal network operation occurs at the terminal accessed by the accessing user.

6. The Internet security service system based on traffic analysis according to claim 5 is characterized in that: When the abnormal traffic data is confirmed to exist during the abnormal detection process of the security traffic data, the time difference between the most recent access time and the current time and the change in the amount of information before and after the access are verified based on the access records of the same user, and then recorded and checked.

Citation Information

Patent Citations

  • Network threat detection method, device and equipment and storage medium

    CN112134877A

  • Abnormal information determination method and device, equipment, storage medium and program product

    CN116366281A

  • Forensic analysis of computing activity and malware detection using an event graph

    WO2017180666A1