Multi-level dynamic network attack detection and response method
Through the combination of intrusion detection systems and machine learning algorithms, network traffic is monitored and user behavior is analyzed, and firewall rules are dynamically adjusted to deal with complex network attacks, solving the shortcomings of existing technologies in dealing with complex attack chains and cross-system interoperability, and achieving efficient network security response and protection.
Patent Information
- Application Number
- CN202411924855.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-25
- Publication Date
- 2025-05-09
AI Technical Summary
The existing technology is difficult to effectively deal with complex and changeable cyber attack chains, especially in terms of unknown threats and zero-day attacks, and the multi-level detection system has insufficient cross-system interoperability and dynamic attack chain response capabilities.
Monitor abnormal patterns in network traffic through an intrusion detection system, analyze user and device behavior in combination with machine learning algorithms, evaluate network risks, and dynamically adjust firewall rules and network security device configuration to block identified threats.
The organic integration of multi-level detection technology has been achieved, the identification ability and response efficiency of complex attack chains have been improved, and the overall reliability and intelligence level of the network security protection system have been enhanced.
Smart Images

Figure CN119966659A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a multi-level dynamic network attack detection and response method. Background Art
[0002] In the field of modern network security defense, multi-level dynamic network attack detection and response methods are widely used technical means to improve the detection capability and response efficiency of complex attacks. Existing network attack detection technologies usually include signature-based intrusion detection systems (IDS) and behavior analysis-based detection systems. The former identifies threats by matching the characteristics of known attack patterns, while the latter discovers potential attacks by analyzing the behavioral deviations of systems or users. However, in the face of complex and changing attack chains, it is difficult to effectively respond to detection methods that rely solely on a single technology.
[0003] Signature-based detection methods have high accuracy in dealing with known attacks, but they are insufficient in dealing with unknown threats or zero-day attacks. Although behavioral analysis detection based on machine learning can adapt to new attacks, it has problems such as high false alarm rate and complex model training and updating. In addition, how to organically integrate different detection technologies so that they can cooperate with each other in multi-level and multi-dimensional security protection to form a synergistic effect is still one of the difficulties of current technology. The existing multi-level detection system also faces other challenges in the implementation process, such as cross-system interoperability issues. The data sharing mechanism between different security systems is not perfect, resulting in the inability to link detection and response measures at multiple levels. At the same time, the existing system lacks the ability to flexibly respond to dynamic attack chains and cannot adjust defense strategies in real time according to changes in attacks, thereby reducing the overall protection effect. Therefore, how to achieve cross-platform data sharing and automated response while improving the integration of technology is an urgent problem that existing technologies need to solve. Summary of the invention
[0004] The purpose of the present invention is to provide a multi-level dynamic network attack detection and response method to solve the problem of how to achieve cross-platform data sharing and automated response while improving technical integration.
[0005] To achieve the above object, the present invention provides the following technical solution: a multi-level dynamic network attack detection and response method, the method comprising:
[0006] S1: Monitor abnormal patterns in network traffic through intrusion detection systems to identify potential attacks;
[0007] The step S1 includes collecting original data packets from the network interface, parsing the data packets and extracting features using deep packet inspection technology, applying anomaly detection algorithms to analyze the features and generate security event records;
[0008] S2: Use machine learning algorithms to analyze user and device behavior to detect activities that deviate from normal baselines;
[0009] The step S2 includes performing feature engineering on the user's operation data to construct a user behavior model, using historical normal behavior as a training data set to train a supervised learning model, comparing the difference between the user's current behavior and the expected behavior predicted by the model, and issuing an alarm for deviation from normal activity when the comparison shows statistical significance;
[0010] S3: Evaluate network risks based on the intrusion detection results and behavior analysis results, and formulate corresponding strategies;
[0011] S4: Dynamically adjust firewall rules and network security device configurations to block confirmed threats.
[0012] Preferably, step S3 comprises:
[0013] The frequency of anomalies in the comprehensive security event log and their potential impact;
[0014] Score overall network health status by combining alerts for deviations from normal activity;
[0015] Automatically define urgency and priority levels through an expert rule system;
[0016] Create a list of policy recommendations for adjusting protection settings.
[0017] Preferably, step S4 comprises:
[0018] The control strategy recommends updating the blacklist library containing known threat feature signatures;
[0019] Automatically apply configuration changes to all applicable devices in the affected scope;
[0020] Use automated test scripts to verify the effectiveness and compatibility of new rules;
[0021] Start real-time log tracking to monitor the adjusted operating status and prepare a rollback mechanism.
[0022] Preferably, the step S3 further comprises:
[0023] Obtaining alarm information from the intrusion detection system;
[0024] Analyze user and device behavior records;
[0025] Comprehensive intrusion detection system alarm information and behavior deviation records to conduct risk quantitative assessment;
[0026] Set risk levels and plan response plans based on risk quantification assessment results.
[0027] Preferably, the risk quantification assessment based on the integrated intrusion detection system alarm information and behavior deviation records includes:
[0028] Convert the warning information level into a numerical score to indicate its severity;
[0029] Count the number of device or user behavior deviations within a specific time period;
[0030] If the number of user behavior deviations multiplied by the weight factor plus the warning information score is greater than the preset score, it is considered a significant threat;
[0031] Correspond this score to different network risk levels and determine the corresponding response plan design principles.
[0032] Preferably, if the number of user behavior deviations multiplied by the weight factor plus the warning information score is greater than a preset score, it is considered that there is a significant threat, including:
[0033] When the alarm information level is set to severe level, the corresponding score is A;
[0034] Set the weight factor to different values W according to the importance of the behavior;
[0035] Calculate the number of deviations C of the user in the time period T and convert it into a score F = C × W;
[0036] When the calculated total of F+A exceeds a predefined threshold (T>F+A), it is determined that the network activity has a threat level.
[0037] Preferably, when the calculated total of F+A exceeds a predefined threshold (T>F+A), determining that the network activity may have a high threat level further includes:
[0038] Check whether F+A always maintains a high risk level within the T time window;
[0039] If the F value plus the A value in T is S, and S is greater than or equal to the safety boundary value, an alarm is triggered;
[0040] Safety margins are regularly adjusted based on historical data analysis;
[0041] Finally, based on this judgment, it was decided to adopt a security policy to protect sensitive resources.
[0042] Preferably, if S is greater than or equal to the safety boundary value, the specific steps of triggering an alarm include:
[0043] Calculate the average S under historical statistics and compare it with the current S to see if it continues to rise to a certain range;
[0044] If the growth rate R of S exceeds the average rate N plus the allowable fluctuation range V, then the trend is considered obvious;
[0045] When the above conditions are met, it indicates that new high-frequency and high-risk events may be occurring or about to occur;
[0046] At this time, emergency measures are automatically enabled to strengthen the protection level until the incident is resolved and a safe and stable state is restored.
[0047] It can be seen from the above technical solution that the present invention has the following beneficial effects:
[0048] This multi-level dynamic network attack detection and response method monitors abnormal patterns in network traffic through an intrusion detection system to identify potential attacks, uses machine learning algorithms to analyze the behavior of users and devices to discover activities that deviate from normal baselines, evaluates network risks based on the intrusion detection results and the results of the behavior analysis, and formulates corresponding strategies to dynamically adjust firewall rules and network security device configurations to block confirmed threats. It realizes the organic integration of various detection technologies, can more efficiently and accurately identify potential threats in complex attack chains, and realizes automatic adjustment of defense strategies, so that the system can respond in real time according to changes in attacks, improves the agility of the overall defense architecture, and makes the linkage response between levels more efficient, thereby enhancing the overall reliability and intelligence level of the network security protection system, and solves the problem of how to achieve cross-platform data sharing and automatic response while improving technical integration. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] Figure 1 The figure is a flow chart of the method of the present invention. DETAILED DESCRIPTION
[0050] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0051] like Figure 1 A multi-level dynamic network attack detection and response method is shown, the method comprising:
[0052] S1: Monitor abnormal patterns in network traffic through intrusion detection systems to identify potential attacks;
[0053] S2: Use machine learning algorithms to analyze user and device behavior to detect activities that deviate from normal baselines;
[0054] S3: Evaluate network risks based on the intrusion detection results and behavior analysis results, and formulate corresponding strategies;
[0055] S4: Dynamically adjust firewall rules and network security device configurations to block confirmed threats.
[0056] This method aims to deal with multi-dimensional and dynamic network security threats by integrating multiple security mechanisms. The first step of the method includes continuously monitoring the data flow inside the network through an intrusion detection system (IDS), monitoring and recording all data packet information entering the network by comparing preset rules or using abnormal behavior pattern analysis methods. For example, the characteristic signature of the intrusion detection system will match the data flow entering the internal system. Once data that matches the known attack pattern is found, an alarm will be generated and the event will be recorded in the IDS log for subsequent analysis and processing. The second step is to perform detailed statistics and records on the behavior patterns of hosts, users and other subjects in the network based on the first step, and use machine learning classification or clustering models and other technologies to find trends consistent with malicious intent from a large number of normal activity pattern databases. Specifically, when an administrator fails to log in successfully during his regular login time, it is regarded as a failed attempt and no warning will be triggered; however, if a brute force attack with a large number of wrong credentials is attempted during a non-working period or a terminal that has never been seen, it will be automatically identified as abnormal and trigger the next action instruction. After collecting and identifying the information at the above two levels, the third step is to conduct a comprehensive and accurate evaluation and processing of the obtained data to determine whether potential risks have occurred and to issue an early warning to the administrator; then a complete set of automated response plans are designed and implemented in advance, which may involve notifying the IT support team to intervene or immediately taking specific measures to cut off the network link. For example, after discovering that a specific IP address is conducting continuous scanning activities in an attempt to find potential weaknesses and carry out targeted attacks, the existing protection rules can be quickly adjusted based on the previously collected analysis results to block the address to prevent it from further endangering the security of the company's resources and facilities; the fourth step is to make immediate adjustments and controls based on the specific conclusions drawn from the previous three steps of analysis: implement blocking measures for the identified hazards and continue to track subsequent developments until the risk is resolved, while also continuously optimizing the defense strategy of the entire system to improve efficiency and maintain flexibility.
[0057] Therefore, this new framework that integrates multiple means and can flexibly adjust to the characteristics of emerging threats can effectively solve the many shortcomings of the traditional single method. Through cross-layer linkage to form a closed-loop mechanism, it can effectively control various types and levels of risks and reduce the possibility of destructive impact on the stable operation of the enterprise network.
[0058] Next, the specific steps of the step of monitoring abnormal patterns in network traffic to identify potential attacks through an intrusion detection system of the present invention are described as follows: first, raw data packets are collected from the network interface. This step usually involves deploying one or more sensors at key nodes of the network, such as routers, switches or servers, etc., to capture all inbound and outbound traffic; during the collection process, the integrity and real-time of the data need to be ensured to ensure that every data unit that may carry attack information is captured;
[0059] A specific example is that a hardware-based network probe is deployed in the data center of an e-commerce company. This device is configured to monitor all packets entering and leaving the edge of the data center network. This setting can capture all inbound or outbound HTTP(S) requests to further analyze whether there is malicious traffic and ensure the normal transaction process.
[0060] Then, deep packet inspection technology is used to parse the data packets and extract features, that is, by deeply parsing the payload part of the collected original data packets, its protocol, header field value and other attributes are obtained; according to specific rules or preset standards, the payload data is decrypted and meaningful metadata features are deeply extracted, such as whether the port number is abnormal, whether the protocol type is compliant, etc., to support subsequent further processing and threat behavior identification;
[0061] Specifically, in the extracted feature list, it may be found that non-standard HTTP connection requests are continuously initiated on a certain port (for example, trying to establish a Web request on port 8889 instead of the default port 80 or 443). This abnormal phenomenon may be part of the precursor of a DOS attack. At this stage, it is also necessary to build a mathematical model to quantify the importance of the feature. At this time, some common formulas can be introduced, such as information entropy H(X) = -Σ[P(x)*log2(P(x))], where the parameter P(x) is the probability of observing data x. By evaluating the probability of occurrence of data packets, we can understand the frequency and importance of the features in all observed data streams, and identify which ones belong to typical attack patterns.
[0062] Then, an anomaly detection algorithm is applied to analyze the features and generate a security event record, which means that the extracted metadata is scored using an anomaly recognition model, and the data is put into a model (such as a machine learning model or a rule engine); the gap between the currently collected data and the normal traffic model is determined based on the pre-trained knowledge base; the alarm mechanism is triggered by setting reasonable threshold conditions and the defense mechanism is activated or a warning message is sent to the management personnel to remind them to take necessary measures to protect the network from damage.
[0063] To continue with the example, during the analysis process, it was found that the number of SYN connection requests sent from a certain IP address to the target machine in a unit time far exceeded the historical average. By setting the threshold for anomaly detection (i.e., the alarm threshold line), when it exceeds the predefined threshold, an alarm signal will be generated and recorded in the database of the intrusion detection system, becoming evidence for the security team's investigation; the algorithm used in this example is a type of supervision algorithm called isolation forest to determine whether the host is likely to suffer a DDoS attack, thereby providing timely intelligence reference for the network security department to formulate targeted measures.
[0064] Next, the specific steps of the present invention for analyzing the behavior of users and devices using machine learning algorithms to discover activities that deviate from the normal baseline are described. First, the process of performing feature engineering on the user's operation data to build a user behavior model. This process involves data collection on various user activities, such as login time points, commonly used software applications, and network services used. This data is processed and converted by selecting and extracting it, and a corresponding feature vector is created. For example, in a banking system, this may be expressed as converting the number of daily logins for each customer, the use of specific services, or the frequency of transactions into a numerical or categorized format as input features for subsequent algorithm modeling.
[0065] In the second step, we will extract the training data set from the collated data set of normal user activities to build our supervised learning model. This step requires us to select appropriate historical behavior patterns as reference data representing the normal state of user behavior, such as all account activities that have not reported security issues in the past month. In our example, the log entries of normal logins and account information browsing on the bank website within a month may be used for training, with the goal of teaching the machine to learn and distinguish the boundary between normal activities and atypical and suspicious operation patterns.
[0066] Next comes the comparison phase, which is the stage where the trained learner evaluates whether the newly observed behavior in actual situations follows the predicted behavior trend for comparison. In actual usage scenarios, the model will score the latest user behavior events in real time and compare them with the learned behavior patterns. For example, when a customer attempts to log in from abroad during a very uncommon time period, the anomaly can be detected and recorded.
[0067] If the results of the above analysis are statistically significant, the last step will be activated: if the degree of behavioral deviation is found to be above the set security threshold in the comparison, the alarm mechanism will be immediately triggered to notify the corresponding security department to pay attention and handle it, and initiate a response plan to prevent potential security violations from spreading or occurring. Here, it is assumed that the warning threshold in the bank case has been set (for example, if there is no overseas login record in the past week and the login activity occurs after 11 pm, it is considered abnormal). At this time, the monitoring platform should push a notification message to the relevant responsible person so that the latter can respond quickly and verify the legitimacy of the login. This can not only prevent unauthorized access in a timely manner, but also help improve the overall security of the system and user experience.
[0068] Next, the specific steps of the present invention for evaluating network risks based on the intrusion detection results and behavior analysis results and formulating corresponding strategies are described. First, it is necessary to comprehensively analyze the abnormal frequency and potential impact of security event records; this step is to collect log information from firewalls, antivirus software, and intrusion detection systems (IDS), and count the number of abnormal behaviors in these data and the impact they may have on enterprises or individuals; for example, when the system records multiple unauthorized access attempts and malware activities within a week, it will determine that the frequency is high, and evaluate the overall risk based on its impact level.
[0069] Then, the overall network health status is scored in combination with the alarm situation of deviation from normal activities; this means that based on the previously collected and statistical data, a weighted algorithm is used (such as the formula X = A × α + I × β, where A is the number of abnormalities, I represents the potential impact, α and β are weighted coefficients for the two and must be greater than zero but less than or equal to 1, and the sum of the two is greater than 0 but less than or equal to 2) to obtain a quantitative evaluation index for the robustness of the entire network system, the overall network score. For example, in an actual environment, one day the internal network encountered a large number of abnormal behavior warnings (A = 10), and each warning has a high level of danger (I = 7, assuming that the weight α is set to 0.6 and β is 0.8 as a common configuration), then through this equation we can calculate X = 10 × 0.6 + 7 × 0.8 = 6 + 5.6 = 11.6, where the score of 11.6 indicates that the current network is in a relatively high risk state and corresponding measures need to be taken as soon as possible to prevent the situation from deteriorating.
[0070] Next, the urgency and priority levels are automatically defined through an expert rule system; this stage involves using a pre-written set of rule bases (usually based on the experience of IT security personnel or security consultants) to specify the priority order for each security threat or vulnerability found based on the risk index calculated in the first two steps and the specific situation. For example, when a score like 11.6 appears in the above case, the alarm level within this numerical range may be extremely high according to the preset rules, and the priority is set to red (the highest level).
[0071] Finally, a list of strategic recommendations is established for adjusting protection settings; in this final stage, the system will form a series of specific defense action proposals (which may include increasing monitoring frequency / enhancing firewall filtering logic / changing user password strength policies, etc.) based on the assessed risk level, alarm type and priority, and provide these recommendations to management personnel for review and implementation to enhance system protection and improve previously discovered risk areas to prevent more serious violations in the future. If the extremely high-level and highest-level processing urgency exceptions mentioned in the case require immediate feedback measures to protect key resources from threats, then the strategies that may be formed will include improving the firewall's recognition and filtering accuracy for external IP addresses or enforcing a strong authentication system for operations on all important servers to ensure the safe operation of core services.
[0072] Next, the specific steps of the present invention for dynamically adjusting firewall rules and network security device configuration to block confirmed threats are described as follows: First, the blacklist database needs to be updated in accordance with the policy recommendations. In this step, the latest threat feature signatures need to be integrated into the existing blacklist database. These feature signatures are extracted from the recently captured attack behaviors through machine learning or other analysis methods; a specific example may be that an IP address that has been confirmed as a DDoS attack source is added to the blacklist in the firewall rules. This is followed by automated configuration changes for applicable network devices, during which network administrators can use centralized security management software to apply predefined updates to all related routers, switches or firewalls with one click, so that these network facilities can instantly identify and block potential dangerous connection requests; for example, when an external server is found to be trying to illegally access the company's internal database, the automatic system will deploy a new firewall rule to the entire company within a few minutes. Next, we use automated test scripts to verify whether the new firewall rules and the updated settings of network equipment can effectively prevent similar attacks from happening while not hindering access to legitimate services. During this process, we pre-set certain security detection scenarios as the script's running content to ensure that the rule changes are executed correctly and verify that malicious activities can be blocked from continuing to affect the system without misjudgment. For example, when the script simulates legitimate users and suspicious attack behaviors to try to connect to the protected data center server, the former is normally not interfered with and the latter should be rejected. Finally, we enable the real-time log function to continuously monitor the effects of configuration changes and prepare emergency measures to restore the previous version at any time. Before the network technicians observe the results of the new rules for a period of time, they will keep the fallback mechanism in an active state at any time to prevent further damage caused by unexpected events. If a user reports that they suddenly cannot connect to certain specific services on the intranet, the network team can quickly roll back the previous changes to restore the required functions or applications as soon as possible. As for the relevant formulas mentioned, they refer to the specific numerical comparison of various network indicators such as bandwidth utilization and delay changes before and after the configuration modification to determine the optimal settings. Generally speaking, these indicators will set a threshold to avoid a significant impact on daily operational efficiency, thereby achieving the goal of protecting network security while ensuring normal services.
[0073] Next, the specific steps of evaluating network risks based on the intrusion detection results and behavior analysis results and formulating corresponding strategies are described in the present invention: First, the alarm information of the intrusion detection system is obtained. This link mainly captures all generated alarms from the IDS (intrusion detection system) installed on the key nodes of the network and pre-processes them to extract relevant parameters. For example, when a computer attempts to access a known malicious server, the IDS will issue an alarm. This alarm information contains data elements such as timestamp, source address, target address, and attack type;
[0074] The purpose of analyzing user and device behavior records is to establish a baseline of normal behavior and compare the currently observed behavior with this baseline to identify potential anomalies. For example, by analyzing the time and operation pattern of an administrator's regular logins and matching their login attempts with these patterns, we can find that attempts to log in during non-working hours may indicate account abuse. The behavioral deviation records involved in this process usually include changes in login time, abnormal increases in resource requests, etc.
[0075] The quantitative risk assessment based on the alarm information and behavior deviation records of the integrated intrusion detection system involves the process of converting the alarm into a digital representation of the probability level of network security events based on the frequency, urgency and past abnormal behavior history of the alarm. At this stage, we can use the formula R = F * V, where R represents the risk index, F is the frequency of this type of threat, and V is the value loss caused by this intrusion. The optimal risk level should be kept at the lowest possible level to reduce the impact on the overall network operation. In this hypothetical example, if the frequency is high (for example, F = 0.8) and the potential value impact is large (assuming V = 200,000 yuan), the calculated comprehensive risk score is high (ie R = 16), which indicates that a prompt response should be made;
[0076] Finally, setting risk levels and planning response plans based on the results of risk quantification assessment means assigning priority labels to various risks based on the specific circumstances obtained from previous analysis, and then selecting the most appropriate response measures based on this classification. For example, low-level incidents can be handled by automated tools, while more serious intrusions require immediate notification to senior analysts and the initiation of detailed defense processes. Taking a real scenario as an example, assuming that an endpoint in a company's intranet is confirmed to have been attacked by ransomware and has spread to a few other workstations, in addition to disconnecting the infected host, measures such as improving the strength of the network security boundary are also needed to prevent the further spread of the attack range, and at the same time, professional technicians are arranged to conduct in-depth investigations to ensure that all traces of the intruder can be found.
[0077] Next, the specific steps of conducting risk quantification assessment based on the alarm information and behavior deviation records of the integrated intrusion detection system of the present invention are described: the first step is to convert all alarm information levels generated by the intrusion detection system into a numerical score form that is easy to calculate. The purpose of this step is to clearly and intuitively reflect the different levels of security impact of each alarm through quantitative scores; for example, the three different levels of low, medium and high alarms that the IDS may issue will be converted into 1, 2 and 3 points as quantitative indicators of severity.
[0078] Following the above steps is a statistical analysis of the frequency of changes in system equipment and user behavior patterns that occurred within a specific time period. This process is intended to measure the frequency of abnormal behavioral activities in the network environment, that is, if a user's login behavior or network activity is found to be far from the established normal pattern and the number of these deviations occurs is recorded, the number of abnormal behavior records is obtained for weighted consideration in subsequent analysis. Assuming that a system has ten unsuccessful attack attempts (uncommon operations) in one day, this record is included as a basis for counting the number of behavioral deviations of the system or account during the evaluation period.
[0079] After calculating the severity of the alarm and the behavioral deviation, the next step is to construct the threat level based on the two data obtained above. This step is achieved through a pre-established risk algorithm formula. The formula may be expressed as the alarm information score plus the frequency of behavioral deviation multiplied by a pre-established weight factor used to emphasize the importance of this abnormal behavior. The total value obtained can be regarded as the risk assessment score of the entire system or a single entity over a period of time; if the daily risk score of a system exceeds the predetermined safety threshold, such as reaching or exceeding 15 (this preset safety score can be adjusted by the security policy maker to reflect different security situations), then the threat situation of the system is considered to be quite urgent and immediate response measures must be taken.
[0080] The last task is to classify the security evaluation values obtained, corresponding to the different risk levels set by the company, and take appropriate security measures to reduce the harmfulness of these discovered hidden dangers. If the results of the risk assessment indicate that there is a high-risk threat situation, the organization should immediately implement the corresponding emergency plan according to the pre-designed principles, such as temporarily interrupting the connection between the infected service node and the outside world until the potential security threat factors are eliminated to protect the integrity of network assets. These pre-planned treatment measures should be adjusted in a timely manner according to changes in actual conditions in order to more effectively adapt to the current network security situation and prevent the spread and escalation of threat events from affecting the operation capabilities of a wider range of information technology facilities.
[0081] Next, the specific steps of the present invention are described, in which if the number of deviations of user behavior multiplied by the weight factor plus the score of the alarm information is greater than the preset score, it is considered that there is a significant threat. First, the score corresponding to the alarm information level is set to A when it is at the severe level. This is to distinguish the different levels of risk that may be caused by alarm information of various levels. For example, the system may identify a situation where a user attempts to access a website marked as malicious. Assume that the alarm corresponding to this behavior is at the severe level, and assign it a value of A as a score, where A can be any positive value set according to the actual risk situation and experience.
[0082] Then, the weight factor can be set to different values W according to the importance of the behavior. The weight factor reflects the risk level of a specific behavior or operation in the environment in which it occurs. It can be adjusted and optimized according to the importance of the behavior and the frequency of occurrence in historical data. For example, if a login mode has many records of causing security problems in history, the corresponding weight can be increased to highlight its importance. The weight usually ranges from zero to the maximum value, depending on the different evaluations of different behaviors.
[0083] Then calculate the number of deviations C of the user in the T time period and convert it into a score F = C × W. The T time period here refers to the unit time of evaluation, which may be hourly, daily or weekly. If a user fails to log in multiple times during this time, these events that deviate from the normal pattern will be represented by C, and further converted into a score F by multiplying it with the predetermined importance weight W. In the case of a week as the statistical unit, the number of failed login attempts of a user is ten times and the behavior weight for this item is determined to be 1.5, then F = 10 × 1.5 = 15.
[0084] When the calculated total of F+A exceeds the predefined threshold (T>F+A), it is judged that this network activity may have a high threat level. Finally, once the result of the comprehensive calculation exceeds the pre-established critical value of danger, the system can determine that there is a potential risk and needs to investigate or initiate a response mechanism to mitigate the control. In this hypothetical example, assuming that the system's security warning threshold is set to 30 points, if the aforementioned severity score (set as A=20) and the above-calculated behavioral risk score of 15 are added, then since F+A=15+20=35, which is greater than the security warning line, it is judged that the network activity has posed a high security threat.
[0085] Next, the specific steps of the present invention are described, in which when the calculated total of F+A exceeds a predefined threshold value (T>F+A), it is determined that this network activity may have a higher threat level. First, within a given time window T, the risk score F of the network behavior and the behavioral activity score A are summed up to form a comprehensive evaluation index S. Here, F can represent the potential security threat assessment score brought about by a certain behavior pattern (such as data access frequency), and its value can be between 0 and 10 (where 0 means completely safe and 10 is the most unsafe situation), and A represents the frequency of occurrence or intensity assessment value of the corresponding network behavior, which is also set to the same interval in practice. T is set to a time interval window determined in advance by analysis, which may range from ten minutes to several hours, depending on the specific monitoring needs.
[0086] Furthermore, during this pre-set T period, the sum of the F and A values, the so-called risk activity score sum (abbreviated as S), will be continuously monitored. The purpose of this monitoring is to see whether this value is high throughout the entire period. If this comprehensive assessment result remains above a high level during the monitoring period, it means that there is a continuous high-risk network operation in progress, and further actions need to be taken immediately for prevention and control.
[0087] After confirming that S exceeds a certain preset threshold, which usually refers to a statistical standard summarized from a large number of previous cyber attack cases or a security benchmark limit set based on empirical rules, the system's built-in security warning mechanism is triggered. The triggering of this alarm not only relies on a static single digital standard value, but also continuously updates and evolves the numerical value range of its security threshold with the daily business activities of the enterprise and the new network security risks it faces, so that the protection system can better adapt to the ever-changing characteristics of external attack methods and ensure that its own network security defense line is more solid.
[0088] As a simple example, consider a company's internal network system, where the number of data extractions for an important database resource and its corresponding abnormal risk index increased significantly within a continuous half-hour. At this time, the cumulative value of F and A far exceeds the upper limit of the empirical value under the pre-determined normal operating conditions. Therefore, an emergency warning notification is automatically generated according to the method of the present invention, and more stringent information control measures are taken based on the above judgment to limit the scope of non-essential access rights to relevant key systems until it is confirmed that the danger has been eliminated before returning to normal. This example fully demonstrates how this solution uses intelligent judgment processes to improve the effective handling level and emergency response efficiency of enterprises facing unknown security challenges.
[0089] Next, the specific steps of the specific implementation steps of the alarm triggered when S is greater than or equal to the safety boundary value of the present invention are described. The first step is to calculate the average S value of the historical statistical data of the network system under normal operating conditions, and compare it with the data S at the current moment to determine whether it continues to show an upward trend and the growth amount reaches a pre-defined safety interval. This step analyzes the normal behavior pattern of the system and uses it as a standard baseline. Any deviation indicates a possible attack or abnormal activity.
[0090] The next step is to evaluate whether the current value growth ratio R exceeds the expected fluctuation compared with the system's long-term statistical average ratio N when the above growth trend appears. The specific judgment rule is to check whether the sum of R(N) and the historical average ratio V exceeds the maximum allowable change range. Here, N refers to the median ratio of the change trend of S in the security environment obtained through long-term observation, and the optimal value varies depending on the specific network environment; R represents the growth rate ratio of the actual change value of the security parameter obtained by monitoring in the recent time period; and V, as a variable, represents the upper limit of the allowable error to take into account the uncertainty caused by the noise in the actual network operation and the influence of other non-intrusion events. Its optimal setting range needs to be determined through a large amount of experimental data analysis in the early stage.
[0091] Once it is determined that the growth of the system S exceeds the allowed range of changes, that is, when the RSV logic is established, it is considered that there may be a new potential security incident with a high threat level. At this time, the system immediately activates the preset emergency protection plan. Such response actions may involve increasing the monitoring frequency, deploying more firewalls, or taking more stringent filtering measures on network traffic until the threat is eliminated and it can run smoothly again. For example, assuming that the historical security index S of a certain enterprise's internal network monitoring platform is 8 points on average, and recently due to the outbreak of malware, this value has surged to more than 10 points, with a growth rate of 14%. If N is 9, and the allowable threshold V is set at about 5% according to the specific environment, then it is obvious that RS (14) is significantly higher than NV (N + 5%), thus triggering the corresponding warning mechanism to start the emergency response procedure. This can ensure that even in the case of unpredictable attack events in the network environment, a quick response can be made to avoid causing greater harm and losses.
[0092] In summary, a multi-level dynamic network attack detection and response method of the present invention includes: first, by real-time monitoring of data traffic changes in the network, using an intrusion detection system deployed at key nodes of the network to identify and extract abnormal patterns in data streams that may indicate that the network is under malicious attack; then, a pre-trained machine learning model is used to compare and learn user activity records within a specific time window and the interaction process between devices. When it is found that the current behavior data deviates from the previous learning results, it is considered that the user's account may be suspected of being hijacked or the current operating environment does not meet security requirements; then, based on the results obtained from the above analysis, the threat level of the entire system is calculated, and then a list of target objects that need to be processed immediately and a list of recommended protection measures are arranged in order of priority; finally, the corresponding rule items in the internal security policy file are modified in a timely manner based on the collected information, so as to achieve the purpose of making a rapid response to external illegal access requests and preventing potential hazards from further spreading to the internal trusted area, thereby forming a cyclic iterative process architecture. In this way, through the coordinated use of multi-level detection methods and flexible adjustment of the network boundary defense structure, suspicious trends can be discovered at an early stage and further intrusion actions can be prevented from occurring, while the frequency of unnecessary interception of non-dangerous incidents can be reduced as much as possible, and it helps to form an effective handling capability for various sudden network security threat scenarios.
[0093] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A multi-level dynamic network attack detection and response method, characterized in that: The method comprises: S1: Monitor abnormal patterns in network traffic through intrusion detection systems to identify potential attacks; The step S1 includes collecting original data packets from the network interface, parsing the data packets and extracting features using deep packet inspection technology, applying anomaly detection algorithms to analyze the features and generate security event records; S2: Use machine learning algorithms to analyze user and device behavior to detect activities that deviate from normal baselines; The step S2 includes performing feature engineering on the user's operation data to construct a user behavior model, using historical normal behavior as a training data set to train a supervised learning model, comparing the difference between the user's current behavior and the expected behavior predicted by the model, and issuing an alarm for deviation from normal activity when the comparison shows statistical significance; S3: Evaluate network risks based on the intrusion detection results and behavior analysis results, and formulate corresponding strategies; S4: Dynamically adjust firewall rules and network security device configurations to block confirmed threats.
2. A multi-level dynamic network attack detection and response method according to claim 1, characterized in that: The step S3 comprises: The frequency of anomalies in the comprehensive security event log and their potential impact; Score overall network health status by combining alerts for deviations from normal activity; Automatically define urgency and priority levels through an expert rule system; Create a list of policy recommendations for adjusting protection settings.
3. A multi-level dynamic network attack detection and response method according to claim 1, characterized in that: The step S4 comprises: The control strategy recommends updating the blacklist library containing known threat feature signatures; Automatically apply configuration changes to all applicable devices in the affected scope; Use automated test scripts to verify the effectiveness and compatibility of new rules; Start real-time log tracking to monitor the adjusted operating status and prepare a rollback mechanism.
4. The multi-level dynamic network attack detection and response method according to claim 1, characterized in that: The step S3 further comprises: Obtaining alarm information from the intrusion detection system; Analyze user and device behavior records; Comprehensive intrusion detection system alarm information and behavior deviation records to conduct risk quantitative assessment; Set risk levels and plan response plans based on risk quantification assessment results.
5. A multi-level dynamic network attack detection and response method according to claim 4, characterized in that: The risk quantification assessment based on the integrated intrusion detection system alarm information and behavior deviation records includes: Convert the warning information level into a numerical score to indicate its severity; Count the number of device or user behavior deviations within a specific time period; If the number of user behavior deviations multiplied by the weight factor plus the warning information score is greater than the preset score, it is considered a significant threat; Correspond this score to different network risk levels and determine the corresponding response plan design principles.
6. A multi-level dynamic network attack detection and response method according to claim 5, characterized in that: If the number of user behavior deviations multiplied by the weight factor plus the warning information score is greater than the preset score, it is considered that there is a significant threat including: When the alarm information level is set to severe level, the corresponding score is A; Set the weight factor to different values W according to the importance of the behavior; Calculate the number of deviations C of the user in the time period T and convert it into a score F = C × W; When the calculated total of F+A exceeds a predefined threshold (T>F+A), it is determined that the network activity has a threat level.
7. A multi-level dynamic network attack detection and response method according to claim 6, characterized in that: When the calculated total of F+A exceeds a predefined threshold (T>F+A), judging that the network activity may have a high threat level also includes: Check whether F+A always maintains a high risk level within the T time window; If the F value plus the A value in T is S, and S is greater than or equal to the safety boundary value, an alarm is triggered; Safety margins are regularly adjusted based on historical data analysis; Finally, based on this judgment, it was decided to adopt a security policy to protect sensitive resources.
8. A multi-level dynamic network attack detection and response method according to claim 7, characterized in that: If S is greater than or equal to the safety boundary value, the specific steps of triggering the alarm include: Calculate the average S under historical statistics and compare it with the current S to see if it continues to rise to a certain range; If the growth rate R of S exceeds the average rate N plus the allowable fluctuation range V, then the trend is considered obvious; When the above conditions are met, it indicates that new high-frequency and high-risk events may be occurring or about to occur; At this time, emergency measures are automatically enabled to strengthen the protection level until the incident is resolved and a safe and stable state is restored.
Citation Information
Cited By
Computer information real-time security detection method and system
CN120263556A
Multi-node multi-factor security authentication method and system
CN120415752A
API security protection method and device, electronic device and storage medium
CN120692051A
Network security monitoring method, device, equipment and medium
CN121037017A
Network risk behavior identification method, electronic equipment, storage medium and program
CN121125169A