Intelligent video conference network security and state monitoring method based on traffic characteristics
Through intelligent monitoring methods based on traffic characteristics, the traffic data of the video conferencing network is analyzed in real time, the traffic fingerprint is generated and compared, and abnormal traffic is identified and cut off, the problem of insufficient real-time and responsiveness of video conferencing security monitoring in the existing technology is solved, and efficient network security monitoring and response capabilities are achieved.
Patent Information
- Application Number
- CN202411865384.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-18
- Publication Date
- 2025-05-09
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The prior art lacks real-time monitoring and immediate response capabilities in security monitoring of video conferencing applications, making it difficult to effectively identify and respond to network intrusions, especially in the face of zero-day attacks and advanced persistent threats (APTs).
The intelligent video conferencing network security and status monitoring method based on traffic characteristics is adopted. All connection ports of the video conferencing application are monitored in real time, and the traffic data is collected and analyzed using deep packet detection technology, the traffic fingerprint of each thread is generated, and the normal traffic fingerprint database is compared to the normal traffic fingerprint database to identify abnormal traffic and automatically cut off the network connection of the intruding thread.
Real-time security monitoring and instant response to the video conferencing network are realized, which significantly reduces the occurrence of false alarms and underreports, improves the identification and response capabilities of zero-day attacks and APTs, and ensures the security of the video conferencing system.
Smart Images

Figure CN119966655A_ABST
Abstract
Description
Technical Field
[0001] The invention belongs to the technical field of network monitoring, and relates to a method for monitoring the security and status of an intelligent video conference network based on traffic characteristics. Background Art
[0002] Security monitoring of video conferencing applications is critical because such applications are often used to transmit sensitive and confidential information, such as business strategies, financial data, personal privacy information, etc. In the current digital age, the consequences of information leakage can be extremely serious, not only resulting in financial losses, but also damaging the company's brand reputation and customer trust. In addition, the popularity of video conferencing platforms has made them a popular target for hacker attacks. Attackers may try to steal information or disrupt the normal progress of meetings through various means, such as malware, phishing attacks or other advanced persistent threats (APT) methods.
[0003] Current network security technologies have some significant shortcomings in handling security monitoring of video conferencing applications. First, many existing solutions lack the ability to monitor and respond in real time, which leads to delays in detecting and responding to network intrusions, increasing the risk of information leakage or system damage. Second, traditional security monitoring tools often rely on known threat signatures or constantly updated databases, which are not up to the task when fighting against the ever-changing attack methods, especially in dealing with zero-day attacks and advanced persistent threats (APTs). In addition, many tools are not sophisticated enough in data analysis and processing, and cannot effectively distinguish between normal business traffic and potential malicious traffic, which is prone to false positives or false negatives, affecting normal business operations. Summary of the invention
[0004] In view of the problems existing in the above prior art, the present invention provides an intelligent video conferencing network security and status monitoring method based on traffic characteristics. By real-time monitoring of all connection ports of the video conferencing application and using deep packet inspection technology, it can collect and analyze traffic data in real time, thereby identifying abnormal patterns more quickly. Secondly, by generating a traffic fingerprint for each thread and comparing it with a normal traffic fingerprint database, the solution can more accurately identify abnormal traffic, greatly reducing the occurrence of false positives and false negatives, and is particularly suitable for protecting critical video conferencing systems from network attacks, thereby solving the above technical problems.
[0005] In order to achieve the above purpose and other purposes, the technical solution adopted by the present invention is as follows: A first aspect of the present invention provides a method for monitoring the security and status of an intelligent video conference network based on traffic characteristics, the method comprising the following steps: Step 1: Port monitoring and data collection: All connection ports of the video conferencing application are monitored in real time through the intelligent monitoring system, and the traffic data transmitted by each thread during the video conference is collected in real time using deep packet inspection technology; Step 2: Traffic fingerprint generation: Analyze the collected traffic data transmitted by each thread during the video conference and generate the traffic fingerprint of each thread in real time; Step 3: Anomaly detection and intrusion identification: compare the traffic fingerprint of each thread generated in real time with the pre-established normal traffic fingerprint database, match the traffic fingerprint of each thread with the similarity of the normal traffic fingerprint in the traffic fingerprint database, and then determine whether there is traffic anomaly in each thread; Step 4: Intrusion thread analysis: abnormal threads are recorded as suspicious threads, and each suspicious thread is deeply analyzed to evaluate the potential threat coefficient of each suspicious thread; Step 5: Cut off the intrusion thread: The actual intrusion threads are finally determined based on the potential threat coefficient of each suspicious thread, and the network connection of each actual intrusion thread is quickly cut off through the automated security response module in the intelligent monitoring system.
[0006] In a possible design, the traffic data transmitted by each thread during the video conference specifically includes the capacity, transmission time interval and protocol type of each data packet.
[0007] In a possible design, the traffic fingerprint of each thread is generated in real time. The specific generation steps are as follows: The capacity of each data packet transmitted by each thread during the video conference is aggregated to form the capacity sequence of each thread. , where j is the number of each thread, i is the number of each data packet, j=1,2,...N, are the capacities of the first, second, i-th, and last data packet transmitted by the j-th thread during the video conference, respectively; Similarly, the transmission time intervals and protocol types of each data packet transmitted by each thread during the video conference are integrated and summarized to form the interval sequence of each thread. and protocol type sequence ; This generates the traffic fingerprint of each thread ; In the above formula is the average data packet capacity of the data packet corresponding to the jth thread, is the standard deviation of the data packet capacity corresponding to the jth thread, is the average transmission time interval of the data packet corresponding to the jth thread, is the standard deviation of the data packet transmission time interval corresponding to the jth thread; is the average value of the protocol type of the data packet corresponding to the jth thread, , The protocol type used by the jth thread to transmit the i-th packet during the video conference; A mapping function for the protocol type, used to convert the protocol type into a numerical representation; is the weighted average of the capacity of the data packet corresponding to the jth thread and the transmission time interval, ; is the logarithmic mean of the packet capacity corresponding to the jth thread, ; is the entropy of the packet protocol type corresponding to the jth thread, ; is the entropy of the protocol type sequence, and the calculation formula is , c is the number of each protocol type, is the probability of protocol type c appearing.
[0008] In a possible design, the traffic fingerprint of each thread is matched to the similarity of the normal traffic fingerprint in the traffic fingerprint database. The specific matching process is as follows: Based on the mapping function of the protocol type, the protocol type of each data packet transmitted by each thread during the video conference is converted into the protocol type value of each data packet transmitted by each thread during the video conference; The data matrix of each thread is formed by combining the capacity, transmission time interval and protocol type values of each data packet transmitted by each thread during the video conference, wherein the data matrix is in the form of 3×N; Calculate the mean of each column in the data matrix of each thread, subtract each element in the data matrix of each thread from the mean of the corresponding column, obtain each centralized element in the data matrix of each thread, combine each centralized element in the data matrix of each thread, and form a new data matrix of each thread; The covariance matrix of the new data matrix corresponding to each thread is calculated , is the new data matrix of the jth thread, and T is the transposed symbol of the matrix; Get normal traffic fingerprints from the traffic fingerprint database , calculate the difference between the traffic fingerprint of each thread and the normal traffic fingerprint in the traffic fingerprint database , is the inverse matrix of the covariance matrix of the new data matrix corresponding to the jth thread; Finally, the similarity between the traffic fingerprint of each thread and the normal traffic fingerprint in the traffic fingerprint database is calculated. .
[0009] In a possible design, the judgment logic for determining whether each thread has traffic anomalies is as follows: The similarity between the traffic fingerprint of each thread and the normal traffic fingerprint in the traffic fingerprint database is compared with the set standard similarity threshold. If the similarity between the traffic fingerprint of a certain thread and the normal traffic fingerprint in the traffic fingerprint database is less than the set standard similarity threshold, the thread is judged to have traffic anomaly. Otherwise, the thread is judged to have no traffic anomaly. According to the above determination method, it is determined whether there is traffic anomaly in each thread.
[0010] In a possible design, the process of evaluating the potential threat factor of each suspicious thread includes: Extract the values of each behavioral feature of each suspicious thread during the video conference, and normalize the values of each behavioral feature of each suspicious thread during the video conference to obtain the normalized values of each behavioral feature of each suspicious thread during the video conference, thereby obtaining the suspicious score of the behavioral feature of each suspicious thread during the video conference ; Construct the traffic path matrix of each suspicious thread during the video conference, and obtain the traffic path suspicion score of each suspicious thread during the video conference. ; Finally, calculate the potential threat coefficient of each suspicious thread , are the weight ratio indexes of the suspicious score of behavior characteristics and the suspicious score of traffic path in the potential threat coefficient calculation formula, and , p is the number of each suspicious thread.
[0011] In a possible design, the suspicious score of the behavior characteristics of each suspicious thread during the video conference is obtained, and the specific acquisition process is as follows: Normalized value based on the behavioral characteristics of each suspicious thread during the video conference , p is the number of each suspicious thread, b is the number of each behavior feature, b=1,2,...B, B is the total number of behavior features; The normalized values of the behavioral features of each suspicious thread during the video conference are used to form a vector to obtain the feature vector of each suspicious thread. , Respectively represent the normalized values of the first, second, and last behavior characteristics of each suspicious thread during the video conference; The K value is determined by the elbow rule, and the feature vectors of each suspicious thread are assigned to K clusters. For each cluster k, the center of the kth cluster is , is the number of threads in cluster k; Then calculate the distance between each suspicious thread and the center of the corresponding cluster , is the value of the bth behavior feature corresponding to the center of the kth cluster; Finally, the suspicious score of the behavioral characteristics of each suspicious thread during the video conference is calculated , e is a natural constant.
[0012] In a possible design, the suspicious score of the traffic path of each suspicious thread during the video conference is obtained, and the specific acquisition process is as follows: Construct a traffic path matrix for each suspicious thread during the video conference , where each element in the traffic path matrix of each suspicious thread during the video conference is the traffic from the pth suspicious thread to each other suspicious thread, which is recorded as , g is the number of other suspicious threads, g=1,2,...U-1; U is the total number of suspicious threads, p is the number of each suspicious thread, p=1,2,...U; Based on the historical normal behavior model, an expected traffic matrix is constructed, where each element in the expected traffic matrix is the expected traffic from the pth suspicious thread to each other suspicious thread under normal operating conditions, which is recorded as ; Thus, the relative entropy between the element in the pth column and the gth row of the traffic path matrix of each suspicious thread during the video conference and the element in the corresponding position in the expected traffic matrix is calculated. , It is a set calculation constant used to prevent division by zero errors; Finally, the suspicious score of the traffic path of each suspicious thread during the video conference is calculated. .
[0013] A second aspect of the present invention provides an intelligent video conference network security and status monitoring device based on traffic characteristics, including a processor, a memory and a communication bus; The memory stores a computer-readable program executable by the processor; The communication bus realizes the connection and communication between the processor and the memory; When the processor executes the computer-readable program, it is executed to implement the intelligent video conferencing network security and status monitoring method based on traffic characteristics as described in the present invention.
[0014] As described above, the intelligent video conference network security and status monitoring method based on traffic characteristics provided by the present invention has at least the following beneficial effects: The intelligent video conferencing network security and status monitoring method based on traffic characteristics provided by the present invention can provide instant insight into network activities by collecting and analyzing traffic data in real time. This real-time performance allows the security team to detect anomalies in the early stages of a threat, thereby shortening response time and reducing potential losses. By generating a traffic fingerprint for each thread, the network behavior pattern of the thread can be accurately described, and any behavior that deviates from the normal pattern can be identified; traffic fingerprint matching provides an effective anomaly detection mechanism. By comparing the traffic fingerprint generated in real time with a normal traffic fingerprint database, the similarity of thread behavior can be quantified to help identify potential anomalies and threats. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for describing the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.
[0016] Figure 1 It is a schematic diagram of the connection of each step of the method of the present invention. DETAILED DESCRIPTION
[0017] The above contents in combination with the implementation of the present invention are merely examples and explanations of the concept of the present invention. The technical personnel in the relevant technical field may make various modifications or supplements to the specific embodiments described or replace them in a similar manner. As long as they do not deviate from the concept of the invention or exceed the scope defined by the claims, they shall all fall within the protection scope of the present invention.
[0018] Example 1 See also Figure 1 As shown, a method for monitoring the network security and status of an intelligent video conference based on traffic characteristics comprises the following steps: Step 1: Port monitoring and data collection: All connection ports of the video conferencing application are monitored in real time through the intelligent monitoring system, and the traffic data transmitted by each thread during the video conference is collected in real time using deep packet inspection technology; As a preferred solution, the traffic data transmitted by each thread during the video conference specifically includes the capacity, transmission time interval and protocol type of each data packet.
[0019] Step 2: Traffic fingerprint generation: Analyze the collected traffic data transmitted by each thread during the video conference and generate the traffic fingerprint of each thread in real time; As a preferred solution, the traffic fingerprint of each thread is generated in real time. The specific generation steps are as follows: The capacity of each data packet transmitted by each thread during the video conference is aggregated to form the capacity sequence of each thread. , where j is the number of each thread, i is the number of each data packet, j=1,2,...N, are the capacities of the first, second, i-th, and last data packet transmitted by the j-th thread during the video conference, respectively; Similarly, the transmission time intervals and protocol types of each data packet transmitted by each thread during the video conference are integrated and summarized to form the interval sequence of each thread. and protocol type sequence ; This generates the traffic fingerprint of each thread ; In the above formula is the average data packet capacity of the data packet corresponding to the jth thread, ; is the standard deviation of the data packet capacity corresponding to the jth thread, ; is the average transmission time interval of the data packet corresponding to the jth thread, , is the transmission time interval for the jth thread to transmit the i-th data packet during the video conference; is the standard deviation of the packet transmission time interval corresponding to the jth thread, ; is the average value of the protocol type of the data packet corresponding to the jth thread, , The protocol type used by the jth thread to transmit the i-th packet during the video conference; A mapping function for the protocol type, used to convert the protocol type into a numerical representation; is the weighted average of the capacity of the data packet corresponding to the jth thread and the transmission time interval, ; is the logarithmic mean of the packet capacity corresponding to the jth thread, ; is the entropy of the packet protocol type corresponding to the jth thread, ; is the entropy of the protocol type sequence, and the calculation formula is , c is the number of each protocol type, is the probability of protocol type c appearing.
[0020] Step 3: Anomaly detection and intrusion identification: compare the traffic fingerprint of each thread generated in real time with the pre-established normal traffic fingerprint database, match the traffic fingerprint of each thread with the similarity of the normal traffic fingerprint in the traffic fingerprint database, and then determine whether there is traffic anomaly in each thread; As a preferred solution, the traffic fingerprint of each thread is matched with the similarity of the normal traffic fingerprint in the traffic fingerprint database. The specific matching process is as follows: Based on the mapping function of the protocol type, the protocol type of each data packet transmitted by each thread during the video conference is converted into the protocol type value of each data packet transmitted by each thread during the video conference; The data matrix of each thread is formed by combining the capacity, transmission time interval and protocol type values of each data packet transmitted by each thread during the video conference, wherein the data matrix is in the form of 3×N; Calculate the mean of each column in the data matrix of each thread, subtract each element in the data matrix of each thread from the mean of the corresponding column, and obtain each centralized element in the data matrix of each thread. The purpose of this is to adjust the mean of each element in the data matrix of each thread to 0, thereby eliminating the offset between elements; combine each centralized element in the data matrix of each thread to form a new data matrix of each thread; The covariance matrix of the new data matrix corresponding to each thread is calculated , is the new data matrix of the jth thread, T is the transposed symbol of the matrix; where 3×N represents the total number of elements in the new data matrix; Get normal traffic fingerprints from the traffic fingerprint database , calculate the difference between the traffic fingerprint of each thread and the normal traffic fingerprint in the traffic fingerprint database , is the inverse matrix of the covariance matrix of the new data matrix corresponding to the jth thread; The difference degree is used to measure the distance between a point and the distribution, taking into account the correlation and covariance structure between the elements. It can effectively identify traffic that is significantly different from the normal traffic pattern. By calculating the difference degree between the traffic data and the normal traffic distribution, the difference degree between the traffic fingerprint of each thread and the normal traffic fingerprint in the traffic fingerprint database can be obtained.
[0021] Finally, the similarity between the traffic fingerprint of each thread and the normal traffic fingerprint in the traffic fingerprint database is calculated. .
[0022] As a preferred solution, the judgment logic for determining whether each thread has traffic anomalies is as follows: The similarity between the traffic fingerprint of each thread and the normal traffic fingerprint in the traffic fingerprint database is compared with the set standard similarity threshold. If the similarity between the traffic fingerprint of a certain thread and the normal traffic fingerprint in the traffic fingerprint database is less than the set standard similarity threshold, the thread is judged to have traffic anomaly. Otherwise, the thread is judged to have no traffic anomaly. According to the above determination method, it is determined whether there is traffic anomaly in each thread.
[0023] Step 4: Intrusion thread analysis: abnormal threads are recorded as suspicious threads, and each suspicious thread is deeply analyzed to evaluate the potential threat coefficient of each suspicious thread; As a preferred solution, the evaluation process of evaluating the potential threat coefficient of each suspicious thread includes: Map each suspicious thread to a network host, use a network monitoring tool to extract the value of each behavioral feature of each suspicious thread during the video conference, and normalize the value of each behavioral feature of each suspicious thread during the video conference to obtain the normalized value of each behavioral feature of each suspicious thread during the video conference, thereby obtaining the suspicious score of the behavioral feature of each suspicious thread during the video conference ; Construct the traffic path matrix of each suspicious thread during the video conference, and obtain the traffic path suspicion score of each suspicious thread during the video conference. ; Finally, calculate the potential threat coefficient of each suspicious thread , are the weight ratio indexes of the suspicious score of behavior characteristics and the suspicious score of traffic path in the potential threat coefficient calculation formula, and , p is the number of each suspicious thread.
[0024] As a preferred solution, the suspicious score of the behavior characteristics of each suspicious thread during the video conference is obtained. The specific acquisition process is: Normalized value based on the behavioral characteristics of each suspicious thread during the video conference , p is the number of each suspicious thread, b is the number of each behavior feature, b=1,2,...B, B is the total number of behavior features; The behavior characteristics include but are not limited to CPU usage, memory usage, number of network port connections, number of file accesses, number of abnormal terminations, number of thread context switches, or log generation frequency; The CPU and memory usage rates are used directly as percentage values; the number of network port connections, file access times, and abnormal termination times are used directly as count values; the number of thread context switches is used directly as count values; and the log generation frequency can be calculated by calculating the number of log entries generated per unit time.
[0025] The normalized values of the behavioral features of each suspicious thread during the video conference are used to form a vector to obtain the feature vector of each suspicious thread. , Respectively represent the normalized values of the first, second, and last behavior characteristics of each suspicious thread during the video conference; The K value is determined by the elbow rule, and the feature vectors of each suspicious thread are assigned to K clusters. For each cluster k, the center of the kth cluster is , is the number of threads in cluster k; In the above formula, b=1 means starting from the first behavior feature and continuing to the Bth behavior feature, so the cluster center is a vector in which each element corresponds to the average value of the behavior feature. The b in the formula represents the index of the behavior feature, ranging from 1 to B; Then calculate the distance between each suspicious thread and the center of the corresponding cluster , is the value of the bth behavior feature corresponding to the center of the kth cluster; In cluster analysis, cluster centers are calculated The purpose is to determine the center point of each cluster, which is composed of the feature mean of all threads in the cluster. Specifically, Each element in represents the central value of cluster k on the bth behavior feature. Then, in the distance calculation, It represents the difference between the bth behavior feature of thread p and the center of its cluster in terms of this feature. By calculating the sum of squares of this difference and taking the square root, we can get the Euclidean distance between the thread and the center of the cluster. , which reflects the degree to which a thread deviates from its cluster center. Therefore, the cluster center The calculation directly affects the distance , because the distance is based on the difference between the thread characteristics and the cluster center characteristics; Finally, the suspicious score of the behavioral characteristics of each suspicious thread during the video conference is calculated , e is a natural constant.
[0026] As a preferred solution, the suspicious score of the traffic path of each suspicious thread during the video conference is obtained. The specific acquisition process is as follows: Construct a traffic path matrix for each suspicious thread during the video conference , where each element in the traffic path matrix of each suspicious thread during the video conference is the traffic from the pth suspicious thread to each other suspicious thread, which is recorded as , g is the number of other suspicious threads, g=1,2,...U-1; U is the total number of suspicious threads, p is the number of each suspicious thread, p=1,2,...U; The traffic path matrix of the above suspicious threads during the video conference They represent the traffic from the first suspicious thread, the pth suspicious thread, and the Uth suspicious thread to the first other suspicious thread respectively; They are the traffic from the first suspicious thread, the pth suspicious thread, and the Uth suspicious thread to the gth other suspicious thread; The traffic from the first suspicious thread, the pth suspicious thread, and the Uth suspicious thread to the last other suspicious thread respectively; Based on the historical normal behavior model, an expected traffic matrix is constructed, where each element in the expected traffic matrix is the expected traffic from the pth suspicious thread to each other suspicious thread under normal operating conditions, which is recorded as ; Thus, the relative entropy between the element in the pth column and the gth row of the traffic path matrix of each suspicious thread during the video conference and the element in the corresponding position in the expected traffic matrix is calculated. , It is a set calculation constant used to prevent division by zero errors; Finally, the suspicious score of the traffic path of each suspicious thread during the video conference is calculated. .
[0027] Normal network traffic usually follows a certain pattern, and an expected traffic matrix can be constructed based on historical data or normal behavior models. When abnormal behaviors (such as malware propagation or data leakage) occur in the network, these abnormal behaviors often lead to deviations in traffic patterns. Therefore, by constructing a traffic path matrix and detecting deviations, anomalies can be effectively identified.
[0028] The above calculation process can provide a comprehensive view of network behavior and help identify abnormal activities that are not easy to detect. Secondly, by quantifying the degree of deviation, it can provide clear anomaly scores for security analysis, which helps to quickly respond to and deal with potential threats.
[0029] By comparing the traffic behaviors of suspicious threads in the traffic path matrix with the expected traffic matrix, relative entropy can be used to effectively quantify the degree of abnormality of these behaviors. By summing and calculating the mean of all relevant p and g, a comprehensive traffic path suspicion score is obtained. This score reflects the degree of abnormality of the suspicious thread during the entire video conference and helps to identify potential intrusion behaviors, as intrusions are often accompanied by abnormal changes in traffic patterns. Relative entropy provides a sensitive measurement tool that can capture small but significant traffic deviations, thereby more accurately locating and responding to threats.
[0030] Step 5: Cut off the intrusion thread: Based on the potential threat coefficient of each suspicious thread, the actual intrusion thread is finally determined, and the network connection of each actual intrusion thread is quickly cut off through the automated security response module in the intelligent monitoring system to prevent it from further affecting the normal progress of the video conference.
[0031] The potential threat coefficient of each suspicious thread is compared with the set potential threat coefficient threshold. If there is a suspicious thread whose potential threat coefficient is less than the set potential threat coefficient threshold, the suspicious thread is recorded as an actual intrusion thread.
[0032] It should be noted that the two steps of step 4 "intrusion thread analysis" and step 5 "intrusion thread cutting" are not parallel, but sequential. The purpose of intrusion thread analysis is to deeply understand the nature, source and possible impact of the intrusion thread after detecting potential threats. Through detailed analysis, misjudgment and miscutting can be avoided to ensure that only real threats are handled; after analysis, the cutting operation is a quick response to confirmed threats, aiming to prevent the intrusion thread from further affecting the system. Although timely cutting is important, cutting without analysis may lead to misoperation, affect normal business processes, and even ignore deeper threats. Therefore, the sequential relationship between analysis and cutting ensures the accuracy and effectiveness of security measures, while providing important data support and decision-making basis for future security policy optimization. In this way, the system can not only respond to current threats in a timely manner, but also better prevent potential attacks in the future.
[0033] Example 2 An intelligent video conference network security and status monitoring device based on traffic characteristics, including a processor, a memory and a communication bus; The memory stores a computer-readable program executable by the processor; The communication bus realizes the connection and communication between the processor and the memory; When the processor executes the computer-readable program, it is executed to implement the intelligent video conferencing network security and status monitoring method based on traffic characteristics as described in the present invention.
[0034] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0035] It should be understood that determining B based on A does not mean determining B only based on A. B can also be determined based on A and / or other information.
[0036] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
[0037] Finally: The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the protection scope of the present invention.
Claims
1. A method for monitoring the security and status of an intelligent video conference network based on traffic characteristics, characterized in that: The steps include: Port monitoring and data collection: All connection ports of the video conferencing application are monitored in real time through the intelligent monitoring system, and the traffic data transmitted by each thread during the video conference is collected in real time using deep packet inspection technology; Traffic fingerprint generation: Analyze the collected traffic data transmitted by each thread during the video conference and generate the traffic fingerprint of each thread in real time; Anomaly detection and intrusion identification: The traffic fingerprint of each thread generated in real time is compared with the pre-established normal traffic fingerprint database, and the traffic fingerprint of each thread is matched with the similarity of the normal traffic fingerprint in the traffic fingerprint database, so as to determine whether there is traffic anomaly in each thread; Intrusion thread analysis: abnormal threads are recorded as suspicious threads, and each suspicious thread is deeply analyzed to evaluate the potential threat coefficient of each suspicious thread; Cutting off intrusion threads: Based on the potential threat coefficient of each suspicious thread, the actual intrusion threads are finally determined, and the network connection of each actual intrusion thread is quickly cut off through the automated security response module in the intelligent monitoring system.
2. The method for monitoring the network security and status of an intelligent video conference based on traffic characteristics according to claim 1 is characterized in that: The traffic data transmitted by each thread during the video conference specifically includes the capacity, transmission time interval and protocol type of each data packet.
3. The method for monitoring the network security and status of an intelligent video conference based on traffic characteristics according to claim 2 is characterized in that: Generate the traffic fingerprint of each thread in real time. The specific generation steps are as follows: The capacity of each data packet transmitted by each thread during the video conference is aggregated to form the capacity sequence of each thread. , where j is the number of each thread, i is the number of each data packet, j=1,2,...N, are the capacities of the first, second, i-th, and last data packet transmitted by the j-th thread during the video conference, respectively; Similarly, the transmission time intervals and protocol types of each data packet transmitted by each thread during the video conference are integrated and summarized to form the interval sequence of each thread. and protocol type sequence ; This generates the traffic fingerprint of each thread ; In the above formula is the average data packet capacity of the data packet corresponding to the jth thread, is the standard deviation of the data packet capacity corresponding to the jth thread, is the average transmission time interval of the data packet corresponding to the jth thread, is the standard deviation of the data packet transmission time interval corresponding to the jth thread; is the average value of the protocol type of the data packet corresponding to the jth thread, , The protocol type used by the jth thread to transmit the i-th packet during the video conference; A mapping function for the protocol type, used to convert the protocol type into a numerical representation; is the weighted average of the capacity of the data packet corresponding to the jth thread and the transmission time interval, ; is the logarithmic mean of the packet capacity corresponding to the jth thread, ; is the entropy of the packet protocol type corresponding to the jth thread, ; is the entropy of the protocol type sequence, and the calculation formula is , c is the number of each protocol type, is the probability of protocol type c appearing.
4. According to the intelligent video conference network security and status monitoring method based on traffic characteristics of claim 1, the traffic fingerprint of each thread is matched with the similarity of the normal traffic fingerprint in the traffic fingerprint database. The specific matching process is as follows: Based on the mapping function of the protocol type, the protocol type of each data packet transmitted by each thread during the video conference is converted into the protocol type value of each data packet transmitted by each thread during the video conference; The data matrix of each thread is formed by combining the capacity, transmission time interval and protocol type values of each data packet transmitted by each thread during the video conference, wherein the data matrix is in the form of 3×N; Calculate the mean of each column in the data matrix of each thread, subtract each element in the data matrix of each thread from the mean of the corresponding column, obtain each centralized element in the data matrix of each thread, combine each centralized element in the data matrix of each thread, and form a new data matrix of each thread; The covariance matrix of the new data matrix corresponding to each thread is calculated , is the new data matrix of the jth thread, and T is the transposed symbol of the matrix; Get normal traffic fingerprints from the traffic fingerprint database , calculate the difference between the traffic fingerprint of each thread and the normal traffic fingerprint in the traffic fingerprint database , is the inverse matrix of the covariance matrix of the new data matrix corresponding to the jth thread; Finally, the similarity between the traffic fingerprint of each thread and the normal traffic fingerprint in the traffic fingerprint database is calculated. .
5. The method for monitoring the network security and status of an intelligent video conference based on traffic characteristics according to claim 1 is characterized in that: The judgment logic for determining whether each thread has traffic anomalies is as follows: The similarity between the traffic fingerprint of each thread and the normal traffic fingerprint in the traffic fingerprint database is compared with the set standard similarity threshold. If the similarity between the traffic fingerprint of a certain thread and the normal traffic fingerprint in the traffic fingerprint database is less than the set standard similarity threshold, the thread is judged to have traffic anomaly. Otherwise, the thread is judged to have no traffic anomaly. According to the above determination method, it is determined whether there is traffic anomaly in each thread.
6. The method for monitoring the network security and status of an intelligent video conference based on traffic characteristics according to claim 1 is characterized in that: The evaluation process for assessing the potential threat factor of each suspicious thread includes: Extract the values of each behavioral feature of each suspicious thread during the video conference, and normalize the values of each behavioral feature of each suspicious thread during the video conference to obtain the normalized values of each behavioral feature of each suspicious thread during the video conference, thereby obtaining the suspicious score of the behavioral feature of each suspicious thread during the video conference ; Construct the traffic path matrix of each suspicious thread during the video conference, and obtain the traffic path suspicion score of each suspicious thread during the video conference. ; Finally, calculate the potential threat coefficient of each suspicious thread , are the weight ratio indexes of the suspicious score of behavior characteristics and the suspicious score of traffic path in the potential threat coefficient calculation formula, and , p is the number of each suspicious thread.
7. The method for monitoring the network security and status of an intelligent video conference based on traffic characteristics according to claim 6 is characterized in that: The suspicious score of the behavior characteristics of each suspicious thread during the video conference is obtained. The specific acquisition process is as follows: Normalized value based on the behavioral characteristics of each suspicious thread during the video conference , p is the number of each suspicious thread, b is the number of each behavior feature, b=1,2,...B, B is the total number of behavior features; The normalized values of the behavioral features of each suspicious thread during the video conference are used to form a vector to obtain the feature vector of each suspicious thread. , Respectively represent the normalized values of the first, second, and last behavior characteristics of each suspicious thread during the video conference; The K value is determined by the elbow rule, and the feature vectors of each suspicious thread are assigned to K clusters. For each cluster k, the center of the kth cluster is , is the number of threads in cluster k; Then calculate the distance between each suspicious thread and the center of the corresponding cluster , is the value of the bth behavior feature corresponding to the center of the kth cluster; Finally, the suspicious score of the behavioral characteristics of each suspicious thread during the video conference is calculated , e is a natural constant.
8. According to the intelligent video conference network security and status monitoring method based on traffic characteristics of claim 6, the traffic path suspicious score of each suspicious thread during the video conference is obtained, and the specific acquisition process is: Construct a traffic path matrix for each suspicious thread during the video conference , where each element in the traffic path matrix of each suspicious thread during the video conference is the traffic from the pth suspicious thread to each other suspicious thread, which is recorded as , g is the number of other suspicious threads, g=1,2,...U-1; U is the total number of suspicious threads, p is the number of each suspicious thread, p=1,2,...U; Based on the historical normal behavior model, an expected traffic matrix is constructed, where each element in the expected traffic matrix is the expected traffic from the pth suspicious thread to each other suspicious thread under normal operating conditions, which is recorded as ; Thus, the relative entropy between the element in the pth column and the gth row of the traffic path matrix of each suspicious thread during the video conference and the element in the corresponding position in the expected traffic matrix is calculated. , It is a set calculation constant used to prevent division by zero errors; Finally, the suspicious score of the traffic path of each suspicious thread during the video conference is calculated. .
9. Intelligent video conference network security and status monitoring device based on traffic characteristics, characterized by: It is implemented based on the intelligent video conference network security and status monitoring method based on traffic characteristics as described in any one of claims 1 to 8, and includes a processor, a memory and a communication bus; The memory stores a computer-readable program executable by the processor; The communication bus realizes the connection and communication between the processor and the memory; When the processor executes the computer-readable program, it is executed to implement the intelligent video conferencing network security and status monitoring method based on traffic characteristics as described in any one of claims 1-8.
Citation Information
Cited By
Traffic fingerprint detection method and device, storage medium and electronic equipment
CN120238379A
Internet-based remote video transmission potential safety hazard processing method and system
CN120512306A