An internet security service system based on traffic analysis

By using an internet security service system based on traffic analysis, the problem of insufficient internal data security detection in existing technologies has been solved, enabling timely alarms and tracking of abnormal access, thereby improving data security and reliability.

CN119945694BActive Publication Date: 2025-10-17INFORMATION & COMM CO OF STATE GRID XINJIANG ELECTRIC POWER CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311457748.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-11-03
Publication Date
2025-10-17
Estimated Expiration
2043-11-03

AI Technical Summary

Technical Problem

Existing internet security assessment systems only evaluate external network security risks and lack in-depth testing of internal data security. This allows unauthorized users to gradually steal information through multiple accesses, resulting in low system access security and an inability to promptly understand the overall network security status.

Method used

An internet security service system based on traffic analysis is adopted, including a traffic collection and analysis module, a network risk model module, a terminal management module, a risk attack testing module, and a decision protection module. It extracts security parameters to perform risk modeling, classifies and judges access permissions, performs anomaly detection and interception, and uses attack index to evaluate network risk performance and update the risk model.

Benefits of technology

It enables timely alerts and tracking of abnormal access, improves the efficiency of abnormal access judgment, reduces the risk of data leakage, enhances data security and reliability, and ensures the efficiency of data storage and processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945694B_ABST
    Figure CN119945694B_ABST
Patent Text Reader

Abstract

The application provides an internet security service system based on flow analysis, comprising a flow collection and analysis module, a network risk model module, a terminal management module, a risk attack test module and a decision protection module, the decision protection module is used for receiving the output of the network risk model module, taking the network risk performance judgment as the safety flow data as the input of the risk model, and adding a time limit cycle judgment condition for updating the risk model, performing abnormal detection on the safety flow data according to the time difference between the latest access time and the current time and the information amount change before and after the access of the same user, the application can generate an alarm, notify the network management personnel and track the abnormal flow information operation in the case that the application exists frequent access and abnormal information amount change, record the tracking results, facilitate the evidence collection and the backup check in the future, and improve the evidence collection efficiency of the abnormal flow information through the hierarchical evidence collection mode.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of Internet security, and particularly relates to an Internet security service system based on traffic analysis. BACKGROUND

[0002] With the development of Internet technology, network data technology has been widely applied, and accordingly, how to deal with network attacks and better protect network security has become an important topic to be studied, which is of great significance.

[0003] Internet security assessment is an important index basis for Internet security defense strategy and the basis of Internet security defense. Only by accurately assessing the security status of the Internet can an effective Internet security protection strategy be developed. Internet security assessment is to assess the security status and security trend of the overall Internet information system through the running state of Internet equipment, Internet behavior detection and user behavior monitoring.

[0004] The existing Internet of Things security detection and assessment generally only assesses the security risks of external networks. The security assessment of network information systems focuses on the threat of single events to the system, such as file damage and file loss. The angle is too single, especially for data security, which only analyzes the security of data on the surface and allows access and reading after that. There is no targeted deep detection for secure files. Once the illegal access user breaks the access permission, it uses multiple access methods to gradually steal information, resulting in low system access security. It is impossible to assess the security status of the network as a whole in time and realize the problem after the fact.

[0005] Therefore, it is necessary to provide a new Internet security service system based on traffic analysis to solve the above technical problems. SUMMARY

[0006] To solve the technical problem that the existing security of data is only analyzed on the surface and access and reading are allowed after that, and there is no targeted deep detection for secure files. Once the illegal access user breaks the access permission, it uses multiple access methods to gradually steal information, resulting in low system access security. It is impossible to assess the security status of the network as a whole in time and realize the problem after the fact, the present application provides an Internet security service system based on traffic analysis.

[0007] The Internet security service system based on traffic analysis provided by the present application comprises a traffic collection and analysis module for collecting Internet traffic data and extracting security parameters from the Internet traffic data.

[0008] a network risk model module for risk model modeling and training according to security parameters extracted from internet traffic data;

[0009] a terminal management module for establishing different permissions for different access users and storing traffic data information uploaded by the access users;

[0010] a risk attack test module for attack testing of the risk model, confirming different data attack indexes according to different access permissions of the terminal, the attack indexes being used for evaluating network risk performance, dividing the network risk performance into safety and non-safety, and intercepting non-safety traffic data;

[0011] a decision protection module for receiving an output of the network risk model module, taking traffic data with safe network risk performance as an input of the risk model, and adding a time limit cycle judgment condition for updating the risk model, verifying a time difference between a latest access time and a current time and an information amount change before and after access according to access records of the same user, and performing abnormal detection on the safe traffic data;

[0012] the abnormal detection is as follows:

[0013] if the time difference is less than a predetermined access interval time and the information amount change is abnormal, it is determined as first-level non-safety;

[0014] if the time difference is less than the predetermined access interval time or the information amount change is abnormal, it is determined as second-level non-safety;

[0015] if the time difference is greater than or equal to the predetermined access interval time and the information amount change is abnormal, it is determined as first-level safety;

[0016] if the time difference is less than the predetermined access interval time and the information amount change is normal, it is determined as second-level safety;

[0017] if the time difference is greater than or equal to the predetermined access interval time and the information amount change is normal, it is determined as third-level safety;

[0018] the first-level non-safety and second-level non-safety traffic data are intercepted and alarmed, and the first-level safety and second-level safety traffic data are recorded and tracked for facilitating subsequent evidence collection and backup.

[0019] Further, the attack index is defined as wherein D0 represents an initial terminal network attack non-safety traffic data quantity, D1 represents a non-safety traffic data quantity under N rounds of attack, N0 represents an initial terminal device quantity, and N1 represents a device quantity in a safe state under N rounds of attack.

[0020] Further, the information amount change judgment criterion is that when the information amount after access is reduced compared with the information amount before access, it is judged that the information amount change is abnormal, and when the information amount after access is the same or increased compared with the information amount before access, it is judged that the information amount change is normal.

[0021] Further, the preliminary security flow data is cleaned before the risk model is updated, and the blank information content is screened out to obtain cleaned data.

[0022] Further, the terminal management module further comprises a monitoring unit for monitoring operation content, operation time and operation object of the access user, and recording and alarming when the terminal accessed by the access user has abnormal flow data or abnormal network operation.

[0023] Further, when the abnormal detection process of the security flow data confirms that there is abnormal flow data, the time difference between the latest access time and the current time and the information amount change before and after access are verified according to the access record of the same user, and recording and troubleshooting are performed.

[0024] Compared with the related art, the internet security service system based on flow analysis provided by the present application has the following beneficial effects:

[0025] 1. The present application judges the security flow data of network risk performance as the input of the risk model, adds the time limit cycle judgment condition for updating the risk model, verifies the time difference between the latest access time and the current time and the information amount change before and after access according to the access record of the same user, performs abnormal detection on the security flow data, and generates an alarm in the case of frequent access and abnormal information amount change in the application, notifies the network management personnel, traces the abnormal flow information operation, records the tracing result, and facilitates future evidence collection and backup.

[0026] 2. The present application confirms different data attack indexes according to different access permissions of the terminal, the attack indexes are used for evaluating network risk performance, the network risk performance is divided into security and non-security, the security flow data of network risk performance is judged as the input of the risk model, the time limit cycle judgment condition is added for updating the risk model, and the security data is further screened, so that the abnormal access of suspicious access user data is screened, the efficiency of abnormal access judgment is improved, the risk of user data leakage is further reduced, and the security and reliability of data are improved.

[0027] 3. The present application improves the evidence collection efficiency of abnormal flow information by hierarchical evidence collection, distinguishes the operation records of different users under different permissions, further improves the efficiency of judgment on the storage mode of user data, and guarantees the efficiency of data extraction and processing. BRIEF DESCRIPTION OF DRAWINGS

[0028] Figure 1 a running principle block diagram of the internet security service system based on traffic analysis provided by the present application;

[0029] Figure 2 a system structure block diagram of the internet security service system based on traffic analysis provided by the present application;

[0030] Figure 3 a relation connection block diagram of the network risk model module provided by the present application;

[0031] Figure 4 a classification structure block diagram of the abnormal detection result provided by the present application. DETAILED DESCRIPTION

[0032] The present application will be further described below in combination with the drawings and embodiments.

[0033] Please refer to Figure 1 , Figure 2 , Figure 3 and Figure 4 , among which, Figure 1 a running principle block diagram of the internet security service system based on traffic analysis provided by the present application; Figure 2 a system structure block diagram of the internet security service system based on traffic analysis provided by the present application; Figure 3 a relation connection block diagram of the network risk model module provided by the present application; Figure 4 a classification structure block diagram of the abnormal detection result provided by the present application.

[0034] Those skilled in the art can understand that, unless specifically stated, the singular forms "a", "an" and "the" used herein can also include the plural forms. It should be further understood that the phrase "comprising" used in the specification of the present application means that the features, programs, steps, operations, elements and / or components exist, but does not exclude the existence or addition of one or more other features, programs, steps, operations, elements, components and / or groups thereof.

[0035] Embodiment one

[0036] In the specific implementation process, as shown in Figure 1-Figure 4 , the internet security service system based on traffic analysis includes a traffic collection and analysis module, which is used to collect internet traffic data and extract security parameters from the internet traffic data;

[0037] a network risk model module, which is used to model and train the risk model according to the security parameters extracted from the internet traffic data;

[0038] The terminal management module is configured to establish different permissions for different access users and store traffic data information uploaded by the access users, and further comprises a monitoring unit configured to monitor operation content, operation time and operation object of the access users, record and alarm when abnormal traffic data or abnormal network operation occurs in a terminal accessed by the access users, and record and investigate when it is confirmed that there is abnormal traffic data in the process of abnormal detection of security traffic data, and verify a time difference between a latest access time and a current time and an information amount change before and after access according to access records of the same user.

[0039] The risk attack test module is configured to perform attack test on the risk model, confirm different data attack indexes according to different access permissions of the terminal, and evaluate network risk performance by using the attack indexes, divide the network risk performance into security and insecurity, and intercept non-secure traffic data.

[0040] The attack index is defined as wherein D0 represents a quantity of non-secure traffic data in an initial terminal network attack, D1 represents a quantity of non-secure traffic data under N rounds of attack, N0 represents a quantity of initial terminals, and N1 represents a quantity of terminals in a secure state under N rounds of attack. The greater the attack index, the worse the security, that is, the greater the permission allocation and the lower the security. The internal user should be monitored and recorded in a targeted manner to improve evidence collection efficiency of abnormal traffic information, distinguish operation records of different users under different permissions, further improve efficiency of judgment on a storage mode of user data, and ensure efficiency of extraction and processing of data.

[0041] The decision protection module is configured to receive an output of the network risk model module, judge the network risk performance as secure traffic data as an input of the risk model, and add a time limit cycle judgment condition for updating the risk model. The decision protection module is further configured to perform data cleaning on the preliminary secure traffic data before updating the risk model, filter out blank information amount content to obtain cleaned data, verify a time difference between a latest access time and a current time and an information amount change before and after access according to access records of the same user, perform abnormal detection on the secure traffic data, further filter secure data, thereby realizing screening of abnormal access of suspected access user data, improving efficiency of judgment on abnormal access, further reducing a risk of leakage of user data, and improving security and reliability of data.

[0042] The basic condition for abnormality detection of security traffic data: according to the number of initial terminals, the number of traffic data to be input is selected, wherein the number of traffic data is 2 times the number of terminals, the interval time allowed to be accessed by a single terminal is 1 minute, the user authority is divided into three levels, i.e. the first-level authority is only for system access browsing, the second-level authority can add information content on the basis of the first-level authority, and the third-level authority can modify the existing information content on the basis of the second-level authority, the number of attacks is selected according to the authority of different access users, the number of attacks of the first-level authority user is 1, the number of attacks of the second-level authority user is 2, and the number of attacks of the third-level authority is 3;

[0043] Abnormality detection is as follows:

[0044] If the time difference is less than the predetermined access interval time and the information amount changes abnormally, it is judged as first-level non-security, for example: the time difference between the latest access time of the third-level authority user and the current time is less than 1 minute, i.e. less than the allowed access interval time, which belongs to frequent access, and the information amount of the accessed terminal changes, then it is determined that the access user's behavior this time is non-security, the operation record is saved and recorded as first-level non-security;

[0045] If the time difference is less than the predetermined access interval time or the information amount changes abnormally, it is judged as second-level non-security, for example: the time difference between the latest access time of the third-level authority user and the current time is less than 1 minute, i.e. less than the allowed access interval time, which belongs to frequent access, or the information amount of the accessed terminal changes, when one of the two exists, it is determined that the access user's behavior this time is non-security, the operation record is saved and recorded as second-level non-security, and further detection is performed, if both the frequent access and the information amount change exist at the same time, the access user's behavior this time is recorded as first-level non-security;

[0046] If the time difference is greater than or equal to the predetermined access interval time and the information amount changes abnormally, it is judged as first-level security, for example: the time difference between the latest access time of the third-level authority user and the current time is greater than or equal to 1 minute, i.e. within the allowed access interval time, which belongs to normal access, and the information amount of the accessed terminal changes, then it is determined that the access user's behavior this time is security, the operation record is saved and recorded as first-level security;

[0047] If the time difference is less than the predetermined access interval time and the information amount changes normally, it is judged as second-level security, for example: the time difference between the latest access time of the third-level authority user and the current time is less than 1 minute, i.e. less than the allowed access interval time, which belongs to frequent access, and the information amount of the accessed terminal does not change, then it is determined that the access user's behavior this time is security, the operation record is saved and recorded as second-level security;

[0048] If the time difference is greater than or equal to the predetermined access interval time and the information amount change is normal, it is judged as three-level security, for example, if the time difference between the latest access time of a three-level permission user and the current time is greater than or equal to 1 minute, that is, within the interval time allowed for access, it is a normal access, and the information amount of the access terminal has not changed, it is determined that the behavior of the access user this time is safe, the operation record is saved and recorded as three-level security;

[0049] The first level is the marginalization level, that is, in the security and non-security judgment, it is in a suspected state, and is a key monitoring object.

[0050] The flow data of the first-level non-security and the second-level non-security is intercepted and an alarm is given, and the flow data of the first-level security and the second-level security is recorded and tracked, so as to facilitate subsequent evidence collection and backup.

[0051] According to the access record of the same user, whether the time difference between the latest access time and the current time is determined to judge whether the flow data in the time period is frequently accessed;

[0052] The information amount change judgment standard is that when the information amount after access is reduced compared with the information amount before access, it is judged that the information amount change is abnormal, and when the information amount after access is the same or increased compared with the information amount before access, it is judged that the information amount change is normal, that is, no content is modified or new content is added after access as a security judgment, and content modification or frequent access modification after access is a non-security judgment.

[0053] The system experiment test:

[0054] In order to further verify the performance of the internet security service system based on flow analysis proposed in the present application in actual application, a network is constructed, normal behavior and attack behavior are simulated, comparative experiments on the system and the traditional system are carried out, a virtual server is selected as a terminal management module, which includes 8 virtual servers, the mobile baseline of the virtual servers is detected by the system and the traditional system, and the experimental test results are as follows:

[0055]

[0056] From the data in the above table, it can be seen that when the system is attacked, the data loss amount is obviously smaller than that of the traditional system, and at the first, fourth and fifth attacks, the data loss amount of the system is zero, which has very important significance.

[0057] In order to verify the security of the present application and the traditional method, 30 pieces of traffic data are selected as the security test, 20 pieces of traffic data with original address watermark and 10 pieces of traffic data without watermark, the traffic data without watermark is used as abnormal traffic data, and the 30 pieces of traffic data are uploaded to the present system and the traditional system respectively, the traffic data with original address watermark is replaced without watermark (eliminate the original address watermark) every 1 minute, until 26 pieces of traffic data without watermark are finally reached, the experimental demonstration judges the data security, and the specific experimental data comparison is as follows:

[0058]

[0059]

[0060] From the data in the above table, it can be seen that the present system can accurately detect the non-safe files by the timely blocking of the information amount change and the frequent access, although the accuracy rate is not 100%, but compared with the traditional system, the identification accuracy of the non-safe files has great progress, the judgment efficiency of the abnormal access is improved, and the risk of user data leakage is further reduced, and the data security and reliability are improved.

[0061] The circuit and control involved in the present application are prior art, and will not be described in detail here.

[0062] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be realized by means of software plus a general hardware platform, and of course can also be realized by hardware. Based on such understanding, the above technical solutions or the part that contributes to the related art can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes a plurality of instructions to make a computer device (which can be a personal computer, server, or network device, etc.) execute the method described in each embodiment or some part of the embodiment.

[0063] The basic principles and main features of the present application and the advantages of the present application have been shown and described above, and it is obvious for those skilled in the art that the present application is not limited to the details of the above exemplary embodiments, and the present application can be realized in other specific forms without departing from the spirit or basic characteristics of the present application. Therefore, from any point of view, the embodiments should be regarded as exemplary and non-limiting, and the scope of the present application is defined by the appended claims rather than the above description, and therefore all changes falling within the meaning and scope of the equivalent elements of the claims are intended to be included in the present application, and any reference signs in the claims should not be regarded as limiting the claims.

[0064] Furthermore, it should be understood that although the specification is described in terms of embodiments, not every embodiment includes every feature or implementation described herein. The specification can include implicit combinations of explicitly mentioned features and / or implicit combinations of implicitly mentioned features. Such combinations are also expressly included within the scope of the specification and an embodiment.

Claims

1. An Internet security service system based on traffic analysis, characterized in that: It includes a traffic collection and analysis module for collecting Internet traffic data and extracting security parameters from the Internet traffic data; Network risk model module, used to build and train risk models based on security parameters extracted from Internet traffic data; The terminal management module is used to establish different permissions for different access users and store traffic data information uploaded by access users; The risk attack test module is used to conduct attack tests on risk models. It determines different data attack indices based on the different access rights of the terminal. The attack indices are used to evaluate network risk performance, classify network risk performance into security and non-security, and intercept non-security traffic data. The decision-making protection module receives the output of the network risk model module, uses the traffic data judged as safe by network risk performance as the input of the risk model, and adds a time-limited cycle judgment condition to update the risk model. It verifies the time difference between the most recent access time and the current time and the change in information volume before and after the access based on the access records of the same user, and performs anomaly detection on the security traffic data; Anomaly detection is as follows: If the time difference is less than the predetermined access interval and the amount of information changes abnormally, it is judged as level one non-security; If the time difference is less than the scheduled access interval or the amount of information changes abnormally, it is judged as level 2 non-security; If the time difference is greater than or equal to the predetermined access interval and the amount of information changes abnormally, it is judged to be level one security; If the time difference is less than the predetermined access interval and the amount of information changes normally, it is judged to be level 2 security; If the time difference is greater than or equal to the predetermined access interval and the amount of information changes normally, it is judged to be level three security; Intercept and alarm the first-level non-safety and second-level non-safety traffic data, and record and track the first-level safety and second-level safety traffic data to facilitate subsequent evidence collection and reference.

2. The Internet security service system based on traffic analysis according to claim 1, characterized in that: The aggression index is defined as Where D0 represents the amount of non-security traffic data in the initial terminal network attack, D1 represents the amount of non-security traffic data under N rounds of attacks, N0 represents the number of devices at the initial terminal, and N1 represents the number of devices in a safe state under N rounds of attacks.

3. The Internet security service system based on traffic analysis according to claim 2, characterized in that: The information volume change judgment standard is that when the information volume after access is reduced compared with the information volume before access, it is judged that the information volume change is abnormal; when the information volume after access is the same as or increased compared with the information volume before access, it is judged that the information volume change is normal.

4. The Internet security service system based on traffic analysis according to claim 3, characterized in that: Before updating the risk model, the preliminary safety traffic data is cleaned to filter out blank information content to obtain cleaned data.

5. The Internet security service system based on traffic analysis according to claim 4, characterized in that: The terminal management module also includes a monitoring unit for monitoring the operation content, operation time and operation object of the accessing user, and recording and issuing an alarm when abnormal traffic data or abnormal network operation occurs at the terminal accessed by the accessing user.

6. The Internet security service system based on traffic analysis according to claim 5, characterized in that: When the abnormal traffic data is detected during the abnormality detection process, the time difference between the most recent access time and the current time and the change in the amount of information before and after the access are verified based on the access records of the same user, and recorded and checked.

Citation Information

Patent Citations

  • Network threat detection method, device and equipment and storage medium

    CN112134877A

  • Abnormal information determination method and device, equipment, storage medium and program product

    CN116366281A