Method and system for alarm study and judgment and enabling optimization based on enhanced self-adaption

An intelligent threat detection model using SVM classification and adversarial training enhances network attack detection by adapting to new threats, reducing false positives, and improving response speed and accuracy.

CN119995933AActive Publication Date: 2025-05-13XIAMEN ANSCEN NETWORK TECH CO LTD

Patent Information

Application Number
CN202411953499.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-27
Publication Date
2025-05-13
Estimated Expiration
2044-12-27

AI Technical Summary

Technical Problem

Traditional network attack detection methods rely heavily on outdated threat intelligence and predefined rules, leading to inefficiencies in detecting new threats, high false positive rates, and difficulty in distinguishing between legitimate and malicious activities, which hampers response speed and accuracy.

Method used

A method involving an intelligent threat detection model that uses SVM classification, Q-learning, and adversarial training to enhance the model's adaptability and accuracy by simulating network attacks and learning from historical data, enabling it to identify and mitigate sophisticated threats.

Benefits of technology

The method improves threat detection accuracy and response speed by continuously adapting to new threats and reducing false positives, ensuring timely and effective defense against evolving network attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995933A_ABST
    Figure CN119995933A_ABST
Patent Text Reader

Abstract

The method comprises the following steps: constructing an intelligent research and judgment model, carrying out environment modeling on the intelligent research and judgment model, constructing a network attack path according to the intelligent research and judgment model, and identifying a network attack by using a known signature of the network attack or a rule-based detection technology; classifying and marking the data of the network security equipment by using an SVM classification algorithm, training an intelligent study and judgment model, establishing a threat identification strategy of the network attack, and identifying the features of the network attack; performing context learning and state prediction by using the intelligent study and judgment model, and optimizing a threat identification strategy of network attacks; a data field of a normal HTTP request is slightly disturbed, an adversarial sample is generated by using a threat of a known network attack, adversarial training is performed in combination with a forged HTTP request, and a deceptive network attack is identified. According to the method, cross validation and correlation analysis of high-quality and multi-source threat intelligence are realized, and the attack defense capability is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the fields of computer technology and network security technology, and in particular to a method and system for enhanced adaptive alarm analysis and enabling optimization. Background Art

[0002] Traditional network attack analysis and judgment technology mainly relies on anomaly detection models and predefined rule feature recognition to identify potential network security threats. This method has limited detection capabilities for emerging or variant threats because it relies on timely updated threat intelligence and attack event information to design corresponding analysis and judgment thresholds. This dependence makes it impossible for the system to be updated in real time to detect emerging threats or predict attack variants, thus affecting the response speed and accuracy to new network attack threats.

[0003] In addition, traditional analysis and judgment technologies usually have a high false alarm rate, often mistakenly identifying normal behavior as abnormal behavior, or failing to accurately distinguish between real threats and non-threatening activities. False alarms not only consume the valuable time and resources of the security team, but may also lead to the neglect of real threats. Professionals are required to conduct regular management and analysis to reduce false alarms and missed alarms and improve the accuracy of the analysis and judgment. However, this management and analysis work is not only time-consuming but also requires a high level of expertise, which greatly limits the efficiency and scalability of the analysis and judgment process.

[0004] In response to the above problems, this application proposes a method and system based on enhanced adaptive alarm analysis and enabling optimization. Summary of the invention

[0005] This application proposes the following technical solutions to address one or more technical deficiencies in the above-mentioned prior art.

[0006] Based on the first aspect of the present application, a method for enhanced adaptive alarm analysis and enabling optimization is proposed, including:

[0007] S1: Establishing the architecture of the intelligent judgment model according to the IT infrastructure and application system within the enterprise, obtaining the data flow of the architecture components, the user's access path and the data of the network security device, and performing environmental modeling on the intelligent judgment model according to the data flow, the access path and the data of the network security device to obtain the intelligent judgment model;

[0008] S2: constructing a network attack path according to the intelligent analysis model, and matching the data of the network security device using known signatures of network attacks or rule-based detection technology;

[0009] S3: using the SVM classification algorithm to classify and label the data of the network security device, and using the data of the network security device to train the intelligent analysis model, combining the network attack path to establish the threat identification strategy of the network attack, and identify the network attack;

[0010] S4: Perform context learning and state prediction on the intelligent analysis model through Q-learning method, SGD incremental learning method and Softmax method, analyze attack patterns and attack events in network historical data, fine-tune parameters of the intelligent analysis model based on the analysis results and the characteristics of the network attack, optimize the threat identification strategy of the network attack, and enhance the generalization ability and autonomous association reasoning ability of the intelligent analysis model;

[0011] S5: By making slight perturbations to the data fields of normal HTTP requests, adversarial samples are generated using known threats of the network attack to obtain forged HTTP requests. The intelligent analysis model is adversarially trained by combining normal HTTP requests, forged HTTP requests, features of the network attack and the adversarial samples to obtain the final intelligent analysis model to identify deceptive network attacks.

[0012] Furthermore, the architecture of the intelligent analysis model includes user-end equipment, internal network, database server, application server, Web server, firewall, IDS / IPS and log server.

[0013] Furthermore, the data of the network security device includes network traffic data, system logs, endpoint data, security event data and user behavior data;

[0014] Wherein, the network traffic data includes data in captured data packets;

[0015] The system logs include operating system logs, application logs, Web server logs, firewall logs, IDS / IPS logs and database logs;

[0016] The endpoint data includes behavioral data of the terminal device including process information, file operations, and registry changes;

[0017] The user behavior data includes the user's login data, access path data and operation behavior data;

[0018] The security event data includes IDS / IPS alarm data and anti-virus software scanning result data.

[0019] Furthermore, the network attack path includes:

[0020] The attacker invades the Web server through the network, enters the internal application server through the vulnerability of the Web server, and obtains the access rights of the internal application database;

[0021] The attacker infected internal devices with malware, spread the infection through the internal network and attacked the internal database server;

[0022] Attackers gain system management privileges by stealing administrator accounts, modifying databases and stealing sensitive information.

[0023] Constructing a network attack path based on the intelligent analysis model can uncover existing network attack behaviors, improve emergency response speed, reduce attackers' continued damage to the system, shorten network attack recovery time, and improve the overall security level.

[0024] Furthermore, the attack patterns and attack events analyzed in the network history data include:

[0025] Extracting attack type, attack intensity, and attack duration from the network traffic data, and then using cosine similarity to calculate the similarity between different attack patterns, and analyzing the correlation between different attack patterns;

[0026] Use the ARIMA time series analysis algorithm to model the time series of attack events to predict future network attack trends;

[0027] Classify the attack sources, use IP address resolution and DNS query methods to determine the geographic location of the attack sources, and analyze the relationship between the attack events and the attack sources.

[0028] Furthermore, the forged HTTP request includes:

[0029] Forge the User-Agent header in HTTP requests to simulate normal browser identification and the legitimate user source of HTTP requests;

[0030] Forge the Redirector header in the HTTP request to simulate the redirect page of the HTTP request;

[0031] Forge the Authorization header in the HTTP request to impersonate the user's legitimate identity to bypass authentication.

[0032] Furthermore, the known signatures of the network attack include hash values ​​of malware, specific patterns of SQL injection, and abnormal packet formats of specific protocols.

[0033] Conducting adversarial training on the intelligent analysis model using normal HTTP requests and forged HTTP requests is beneficial for the intelligent analysis model to learn how to distinguish normal HTTP requests from forged HTTP requests, accurately identify fraudulent network attacks, and thus conduct effective attack defense.

[0034] Based on the second aspect of the present application, a system based on enhanced adaptive alarm analysis and enabling optimization is proposed, including:

[0035] Model building module: Establish the architecture of the intelligent judgment model according to the IT infrastructure and application system within the enterprise, obtain the data flow of the architecture components, the user's access path and the data of the network security device, and perform environmental modeling on the intelligent judgment model according to the data flow, the access path and the data of the network security device to obtain the intelligent judgment model;

[0036] Network attack path module: constructs a network attack path according to the intelligent analysis model, and uses known signatures of network attacks or rule-based detection technology to match the data of the network security device;

[0037] Identification module: Use the SVM classification algorithm to classify and label the data of the network security device, and use the data of the network security device to train the intelligent analysis model, combine the network attack path to establish the threat identification strategy of the network attack, and identify the network attack;

[0038] Optimization module: Use Q-learning method, SGD incremental learning method and Softmax method to perform context learning and state prediction on the intelligent analysis model, analyze attack patterns and attack events in network historical data, and fine-tune the parameters of the intelligent analysis model based on the analysis results and the characteristics of the network attack, optimize the threat identification strategy of the network attack, and enhance the generalization ability and autonomous association reasoning ability of the intelligent analysis model;

[0039] Re-optimization module: by making slight perturbations to the data fields of normal HTTP requests, using known threats of the network attack to generate adversarial samples, forged HTTP requests are obtained, and adversarial training is performed on the intelligent analysis model by combining normal HTTP requests, forged HTTP requests, the characteristics of the network attack and the adversarial samples to obtain the final intelligent analysis model to identify deceptive network attacks.

[0040] Based on the third aspect of the present application, a computer program product is proposed, which has one or more computer programs thereon, and when the computer program is executed by a computer processor, implements any of the methods described above.

[0041] The technical effect of the present invention is that: this application introduces alarm analysis based on a large security model, conducts intelligent analysis on the alarms reported by security equipment, constructs an intelligent analysis model, combines reinforcement learning and interaction with the environment for training and optimization, and continuously improves the analysis capability of the analysis model. In the face of ever-changing environments or conditions, it continuously empowers and optimizes intelligent analysis work, adapts to new attacks and attack strategy variants, and improves alarm analysis efficiency and accuracy based on cross-validation and correlation analysis of high-quality, multi-source threat intelligence, ensuring that important security incidents are not overwhelmed by massive alarms, and improving the active defense capabilities of network attacks and threats. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] Other features, objects and advantages of the present application will become more apparent from the detailed description of non-limiting embodiments made with reference to the following drawings.

[0043] Figure 1 It is a flow chart of a method for enhanced adaptive alarm analysis and enabling optimization provided according to an embodiment of the present invention.

[0044] Figure 2 It is a system framework diagram of alarm analysis and enabling optimization based on enhanced adaptation provided according to an embodiment of the present invention.

[0045] Figure 3 It is a structural diagram of an electronic device suitable for implementing the computer system of the embodiment of the present application. DETAILED DESCRIPTION

[0046] The present application will be further described in detail below in conjunction with the accompanying drawings and embodiments. It is to be understood that the specific embodiments described herein are only used to explain the relevant invention, rather than to limit the invention. It should also be noted that, for ease of description, only the parts related to the relevant invention are shown in the accompanying drawings.

[0047] It should be noted that, in the absence of conflict, the embodiments and features in the embodiments of the present application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0048] Figure 1 A method for enhanced adaptive alarm analysis and enabling optimization is shown, including:

[0049] S1: Establishing the architecture of the intelligent judgment model according to the IT infrastructure and application system within the enterprise, obtaining the data flow of the architecture components, the user's access path and the data of the network security device, and performing environmental modeling on the intelligent judgment model according to the data flow, the access path and the data of the network security device to obtain the intelligent judgment model;

[0050] S2: constructing a network attack path according to the intelligent analysis model, and matching the data of the network security device using known signatures of network attacks or rule-based detection technology;

[0051] S3: using the SVM classification algorithm to classify and label the data of the network security device, and using the data of the network security device to train the intelligent analysis model, combining the network attack path to establish the threat identification strategy of the network attack, and identify the network attack;

[0052] S4: Perform context learning and state prediction on the intelligent analysis model through Q-learning method, SGD incremental learning method and Softmax method, analyze attack patterns and attack events in network historical data, fine-tune parameters of the intelligent analysis model based on the analysis results and the characteristics of the network attack, optimize the threat identification strategy of the network attack, and enhance the generalization ability and autonomous association reasoning ability of the intelligent analysis model;

[0053] S5: By making slight perturbations to the data fields of normal HTTP requests, adversarial samples are generated using known threats of the network attack to obtain forged HTTP requests. The intelligent analysis model is adversarially trained by combining normal HTTP requests, forged HTTP requests, features of the network attack and the adversarial samples to obtain the final intelligent analysis model to identify deceptive network attacks.

[0054] It should be noted that the architecture of the intelligent analysis model includes user-end equipment, internal network, database server, application server, Web server, firewall, IDS / IPS and log server.

[0055] It should be noted that the data of the network security device includes network traffic data, system logs, endpoint data, security event data and user behavior data;

[0056] Wherein, the network traffic data includes data in captured data packets;

[0057] The system logs include operating system logs, application logs, Web server logs, firewall logs, IDS / IPS logs and database logs;

[0058] The endpoint data includes behavioral data of the terminal device including process information, file operations, and registry changes;

[0059] The user behavior data includes the user's login data, access path data and operation behavior data;

[0060] The security event data includes IDS / IPS alarm data and anti-virus software scanning result data.

[0061] It should be noted that the network attack paths include:

[0062] The attacker invades the Web server through the network, enters the internal application server through the vulnerability of the Web server, and obtains the access rights of the internal application database;

[0063] The attacker infected internal devices with malware, spread the infection through the internal network and attacked the internal database server;

[0064] Attackers gain system management privileges by stealing administrator accounts, modifying databases and stealing sensitive information.

[0065] It should be noted that the analysis of attack patterns and attack events in network historical data specifically includes:

[0066] Extracting attack type, attack intensity, and attack duration from the network traffic data, and then using cosine similarity to calculate the similarity between different attack patterns, and analyzing the correlation between different attack patterns;

[0067] Use the ARIMA time series analysis algorithm to model the time series of attack events to predict future network attack trends;

[0068] Classify the attack sources, use IP address resolution and DNS query methods to determine the geographic location of the attack sources, and analyze the relationship between the attack events and the attack sources.

[0069] It should be noted that the forged HTTP request includes:

[0070] Forge the User-Agent header in HTTP requests to simulate normal browser identification and the legitimate user source of HTTP requests;

[0071] Forge the Redirector header in the HTTP request to simulate the redirect page of the HTTP request;

[0072] Forge the Authorization header in the HTTP request to impersonate the user's legitimate identity to bypass authentication.

[0073] It should be noted that the known signatures of the network attack include hash values ​​of malware, specific patterns of SQL injection, and abnormal packet formats of specific protocols.

[0074] It should be noted that this application establishes an intelligent analysis and judgment model environment based on the characteristics of existing business systems, carries out identification and extraction of network attack threat characteristics, studies identification strategies for known network attack threats, clusters and predicts known attack methods, and continuously optimizes and corrects the identification strategies for network security threats, thereby realizing intelligent analysis and judgment of network attack threats.

[0075] It should be noted that adversarial samples of known network attack threats are introduced during the training process, so that the intelligent analysis model can make correct judgments under abnormal disturbances. At the same time, formal methods are used to analyze the security vulnerabilities of the model, perform adversarial sample detection and model reinforcement, and ensure that the verification and testing of the model can cover a variety of security threats and edge cases. It can comprehensively evaluate the performance of the model and enhance the robustness and security of the intelligent analysis model in decision-making and judgment.

[0076] It should be noted that by integrating and strengthening adaptive technology and autonomous correlation reasoning technology, the generalization ability of the intelligent analysis model can be enhanced, and the potential relationship between unknown threats and network attacks, as well as the correlation between attack threats and network environments, can be better understood. The transparency of the learning decision-making process of the intelligent analysis model can be improved, and the learning of the intelligent analysis model can be accelerated. At the same time, the associated knowledge in historical information can be identified and transferred, so as to better improve and strengthen the ability to identify unknown potential network attack threats.

[0077] It should be noted that by learning the environmental model and predicting state changes, it is possible to learn the environmental state and the identification strategy of network attack threats from the interaction, adjust the identification strategy of network attack threats to adapt to the new model environment, and in the scenario of uncertain network attack threats, dynamically correct the judgment criteria of the intelligent judgment model to improve the anti-interference ability of the intelligent judgment model.

[0078] It should be noted that the environmental modeling is one of the core technologies of virtual reality technology, which uses computer technology to generate a three-dimensional, interactive virtual world. The environmental model used in this application includes models of system architecture, network topology, key components, data flow and user behavior.

[0079] It should be noted that before identifying the characteristics of the network attack, the original data needs to be cleaned, formatted and standardized, irrelevant data and useless log entries need to be deleted, and data from different sources need to be converted into a unified standard format.

[0080] In a specific embodiment, the specific code for classifying and labeling the data of the network security device using the SVM classification algorithm is as follows:

[0081] "from sk-learn import svm

[0082] from sklearn.model_selection import train_test_split

[0083] from sklearn.preprocessing import StandardScaler

[0084] from sklearn.metrics import accuracy_score

[0085] # Assume X is the feature matrix and y is the label (0 for normal, 1 for attack)

[0086] X = # Feature matrix

[0087] y = # Label

[0088] # Split the data into training and test sets

[0089] X_train, X_test, y_train, y_test = train_test_split(X, y, test_size = 0.2, random_state = 42)

[0090] # Feature standardization

[0091] scaler = StandardScaler()

[0092] X_train = scaler.fit_transform(X_train)

[0093] X_test = scaler.transform(X_test)

[0094] # SVM model with RBF kernel

[0095] clf = svm.SVC(kernel = 'rbf', gamma ='scale', C = 1)

[0096] # Train the SVM model

[0097] clf.fit(X_train, y_train)

[0098] # Make predictions on the test set

[0099] y_pred = clf.predict(X_test)

[0100] # Output classification accuracy

[0101] accuracy=accuracy_score(y_test,y_pred)

[0102] pr int(f'Accuracy:{accuracy*100:.2f}%')".

[0103] In a specific embodiment, cross-validation is used to adjust hyperparameters to improve classification accuracy, and the code for optimizing the threat identification strategy of the network attack is as follows:

[0104] "from sk learn.mode l_se lect ion import Gr idSearchCV

[0105] #Define parameter range

[0106] param_gr id={'C':[0.1,1,10],'gamma':['sca le','auto',0.1,1]}

[0107] #Use grid search and cross validation to select the best parameters

[0108] gr id_search=Gr idSearchCV(svm.SVC(kerne l='rbf'),param_gr id,cv=5)

[0109] gr id_search.fit(X_train,y_train)

[0110] #Output the best parameters and best score

[0111] pr int(f'Best Parameters:{gr id_search.best_params_}')

[0112] pr int(f'Best Score:{gr id_search.best_score_}')".

[0113] It should be noted that by using the Q-learning method to continuously adjust the Q value to optimize the decision-making strategy of the intelligent analysis model, when new data continues to arrive, the intelligent analysis model can continuously update parameters through incremental learning Stochastic Gradient Descent (SGD), and smoothly explore and utilize through the Softmax method to make decisions based on the value of the current state.

[0114] It should be noted that the intelligent analysis model is trained by mixing normal HTTP requests with counterfeit HTTP requests. During the training process, it learns how to distinguish normal HTTP requests from forged HTTP requests. The trained intelligent analysis model can detect forged HTTP requests with slight modifications and accurately identify potential deceptive attacks, thereby effectively preventing attacks and enhancing the ability to resist network attacks.

[0115] It should be noted that the architecture of the intelligent analysis model includes user-end equipment, internal network, database server, application server, Web server, firewall, IDS / IPS and log server;

[0116] Client devices include desktop computers, laptops, and mobile devices used by employees;

[0117] The internal network includes the enterprise local area network (LAN), as well as network devices such as switches and routers;

[0118] The database server is a database that stores enterprise data, including customer information, financial data, and other data information;

[0119] Application servers are servers that process enterprise business logic and are responsible for hosting the enterprise's business applications (such as ERP systems);

[0120] Web servers provide corporate websites and online services to the outside world;

[0121] Firewalls are used to monitor and control traffic in and out of a network;

[0122] IDS / IPS (Intrusion Detection / Prevention System) is used to detect and block potential attacks in real time;

[0123] The log server is used to centrally record the log data of all systems, networks, and applications for analysis and auditing.

[0124] In a specific embodiment, in environmental modeling, after completing the architecture modeling, the data flow and user access path are further constructed, including how users access the system, applications and data, and how data flows between components of different systems. Modeling the network security device is conducive to clarifying the role and configuration of the network security device, as well as how the network security devices interact with other parts of the system.

[0125] In a specific embodiment, the user's access path specifically includes:

[0126] Access path from user devices to application servers: Users access internal business systems through browsers or client applications and send requests to application servers.

[0127] Access path from application server to database server: The application server communicates with the database server through the intranet to extract or update data from the database.

[0128] External access path to the Web server: External users access the company website through the Internet, and the Web server provides public Web services.

[0129] Access path for database backup: Regular database backups are transmitted to the backup server via the intranet.

[0130] In a specific embodiment, a forged HTTP request sample is generated to simulate the process of an attacker forging a request, and the intelligent analysis model can identify and prevent forged HTTP requests;

[0131] The code to forge the User-Agent header in the HTTP request is:

[0132]

[0133] The code to forge the Request header in the HTTP request is:

[0134]

[0135] The code to forge the Authorization header in the HTTP request is:

[0136]

[0137] In a specific embodiment, the code for training the intelligent judgment model is:

[0138]

[0139]

[0140] The trained intelligent analysis model can detect forged HTTP requests with minor changes and accurately identify potential deceptive network attacks. The code for verifying the intelligent analysis model is:

[0141]

[0142] Figure 2 A system based on enhanced adaptive alarm analysis and empowerment optimization is shown, including a model building module a, a network attack path module b, an identification module c, an optimization module d and a re-optimization module e.

[0143] In a specific embodiment, the model building module a is configured to: establish the architecture of the intelligent analysis model based on the IT infrastructure and application systems within the enterprise, obtain the data flow of the architecture components, the user's access path and the data of the network security device, and perform environmental modeling on the intelligent analysis model based on the data flow, the access path and the data of the network security device to obtain the intelligent analysis model.

[0144] In a specific embodiment, the network attack path module b is configured to: construct a network attack path according to the intelligent analysis model, and use known signatures of network attacks or rule-based detection technology to match the data of the network security device.

[0145] In a specific embodiment, the identification module c is configured to: use the SVM classification algorithm to classify and label the data of the network security device, and use the data of the network security device to train the intelligent analysis model, combine the network attack path to establish the threat identification strategy of the network attack, and identify the network attack.

[0146] In a specific embodiment, the optimization module d is configured to: perform context learning and state prediction on the intelligent analysis model through Q-learning method, SGD incremental learning method and Softmax method, analyze attack patterns and attack events in network historical data, and fine-tune parameters of the intelligent analysis model based on the analysis results and the characteristics of the network attack, optimize the threat identification strategy of the network attack, and enhance the generalization ability and autonomous association reasoning ability of the intelligent analysis model.

[0147] In a specific embodiment, the re-optimization module e is configured to: generate adversarial samples using known threats of the network attack by slightly perturbing the data fields of normal HTTP requests to obtain forged HTTP requests, and perform adversarial training on the intelligent analysis model by combining normal HTTP requests, forged HTTP requests, features of the network attack and the adversarial samples to obtain the final intelligent analysis model to identify deceptive network attacks.

[0148] It should be noted that this application introduces alarm analysis based on security big models, conducts intelligent analysis of alarms on network security equipment, and combines big data analysis technology to collaborate with staff to complete the processing of complex alarms, ensuring that network security information is not overwhelmed by massive alarms. It also provides fast and accurate security alarms and early warning functions, establishes cross-verification and correlation analysis of high-quality, multi-source threat intelligence, and improves the defense capabilities of network attacks.

[0149] Reference below Figure 3, which shows a schematic diagram of the structure of a computer system suitable for implementing an electronic device of an embodiment of the present application. Figure 3 The electronic device shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.

[0150] like Figure 3 As shown, the computer system includes a central processing unit (CPU) 301, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 302 or a program loaded from a storage part 308 into a random access memory (RAM) 303. Various programs and data required for system operation are also stored in the RAM 303. The CPU 301, the ROM 302, and the RAM 303 are connected to each other via a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.

[0151] The following components are connected to the I / O interface 305: an input section 306 including a keyboard, a mouse, etc.; an output section 307 including a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 308 including a hard disk, etc.; and a communication section 309 including a network interface card such as a LAN card, a modem, etc. The communication section 309 performs communication processing via a network such as the Internet. A drive 310 is also connected to the I / O interface 305 as needed. A removable medium 311, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 310 as needed, so that a computer program read therefrom is installed into the storage section 308 as needed.

[0152] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a computer-readable storage medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 309, and / or installed from the removable medium 311. When the computer program is executed by the central processing unit (CPU) 301, the above functions defined in the method of the present application are executed. It should be noted that the computer-readable storage medium of the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium can be, for example, - but not limited to - an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection with one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device, or device. In the present application, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which a computer-readable program code is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable storage medium other than a computer-readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, device, or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wireless, wireline, optical cable, RF, etc., or any suitable combination of the foregoing.

[0153] Computer program code for performing the operations of the present application may be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages, such as Java, Smalltalk, C++, and conventional procedural programming languages, such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0154] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present application. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0155] The modules involved in the embodiments of the present application may be implemented by software or hardware.

[0156] As another aspect, the present application also provides a computer-readable storage medium, which may be included in the electronic device described in the above embodiment; or it may exist independently and not be assembled into the electronic device. The above computer-readable storage medium carries one or more programs. When the above one or more programs are executed by the electronic device, the electronic device: establishes the architecture of the intelligent analysis model according to the internal IT infrastructure and application system of the enterprise, obtains the data flow of the architecture components, the user's access path and the data of the network security device, and performs environmental modeling on the intelligent analysis model according to the data flow, the access path and the data of the network security device to obtain the intelligent analysis model; constructs a network attack path according to the intelligent analysis model, and uses known signatures of network attacks or rule-based detection technology to match the data of the network security device; uses the SVM classification algorithm to classify and label the data of the network security device, and uses the data of the network security device to train the intelligent analysis model, and establishes the threat identification strategy of the network attack in combination with the network attack path to identify the network attack; through Q-learn ing method, SGD incremental learning method and Softmax method are used to perform context learning and state prediction on the intelligent analysis model, analyze attack patterns and attack events in historical network data, and fine-tune the parameters of the intelligent analysis model based on the analysis results and the characteristics of the network attack, optimize the threat identification strategy of the network attack, and enhance the generalization ability and autonomous associative reasoning ability of the intelligent analysis model; by making slight perturbations to the data fields of normal HTTP requests, adversarial samples are generated using the known threats of the network attack to obtain forged HTTP requests, and adversarial training is performed on the intelligent analysis model based on normal HTTP requests, forged HTTP requests, the characteristics of the network attack and the adversarial samples to obtain the final intelligent analysis model to identify deceptive network attacks.

[0157] Finally, it should be noted that the above description is only a preferred embodiment of the present application and an explanation of the technical principles used. Those skilled in the art should understand that the scope of the invention involved in the present application is not limited to the technical solution formed by a specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above invention concept. For example, the above features are replaced with the technical features with similar functions disclosed in this application (but not limited to) by each other to form a technical solution.

Claims

1. A method for enhanced adaptive alarm analysis and empowerment optimization, characterized in that: include: S1: Establishing the architecture of the intelligent judgment model according to the IT infrastructure and application system within the enterprise, obtaining the data flow of the architecture components, the user's access path and the data of the network security device, and performing environmental modeling on the intelligent judgment model according to the data flow, the access path and the data of the network security device to obtain the intelligent judgment model; S2: constructing a network attack path according to the intelligent analysis model, and matching the data of the network security device using known signatures of network attacks or rule-based detection technology; S3: using the SVM classification algorithm to classify and label the data of the network security device, and using the data of the network security device to train the intelligent analysis model, combining the network attack path to establish the threat identification strategy of the network attack, and identify the network attack; S4: Perform context learning and state prediction on the intelligent analysis model through Q-learning method, SGD incremental learning method and Softmax method, analyze attack patterns and attack events in network historical data, fine-tune parameters of the intelligent analysis model based on the analysis results and the characteristics of the network attack, optimize the threat identification strategy of the network attack, and enhance the generalization ability and autonomous association reasoning ability of the intelligent analysis model; S5: By making slight perturbations to the data fields of normal HTTP requests, adversarial samples are generated using known threats of the network attack to obtain forged HTTP requests. The intelligent analysis model is adversarially trained by combining normal HTTP requests, forged HTTP requests, features of the network attack and the adversarial samples to obtain the final intelligent analysis model to identify deceptive network attacks.

2. The method according to claim 1, characterized in that The architecture of the intelligent analysis model includes user-end equipment, internal network, database server, application server, Web server, firewall, IDS / IPS and log server.

3. The method according to claim 1, characterized in that The data of the network security device includes network traffic data, system logs, endpoint data, security event data and user behavior data; Wherein, the network traffic data includes data in captured data packets; The system logs include operating system logs, application logs, Web server logs, firewall logs, IDS / IPS logs and database logs; The endpoint data includes behavioral data of the terminal device including process information, file operations, and registry changes; The user behavior data includes the user's login data, access path data and operation behavior data; The security event data includes IDS / IPS alarm data and anti-virus software scanning result data.

4. The method according to claim 1, characterized in that: The network attack paths include: The attacker invades the Web server through the network, enters the internal application server through the vulnerability of the Web server, and obtains the access rights of the internal application database; The attacker infected internal devices with malware, spread the infection through the internal network and attacked the internal database server; Attackers gain system management privileges by stealing administrator accounts, modifying databases and stealing sensitive information.

5. The method according to claim 3, characterized in that: Analyzing attack patterns and attack events in historical network data specifically includes: Extracting attack type, attack intensity, and attack duration from the network traffic data, and then using cosine similarity to calculate the similarity between different attack patterns, and analyzing the correlation between different attack patterns; Use the ARIMA time series analysis algorithm to model the time series of attack events to predict future network attack trends; Classify the attack sources, use IP address resolution and DNS query methods to determine the geographic location of the attack sources, and analyze the relationship between the attack events and the attack sources.

6. The method according to claim 1, characterized in that The forged HTTP request includes: Forge the User-Agent header in HTTP requests to simulate normal browser identification and the legitimate user source of HTTP requests; Forge the Redirector header in the HTTP request to simulate the redirect page of the HTTP request; Forge the Authorization header in the HTTP request to impersonate the user's legitimate identity to bypass authentication.

7. The method according to claim 1, characterized in that The known signatures of the network attack include hash values ​​of malware, specific patterns of SQL injection, and abnormal packet formats of specific protocols.

8. A system based on enhanced adaptive alarm analysis and empowerment optimization, characterized in that: include: Model building module: Establish the architecture of the intelligent judgment model according to the IT infrastructure and application system within the enterprise, obtain the data flow of the architecture components, the user's access path and the data of the network security device, and perform environmental modeling on the intelligent judgment model according to the data flow, the access path and the data of the network security device to obtain the intelligent judgment model; Network attack path module: constructs a network attack path according to the intelligent analysis model, and uses known signatures of network attacks or rule-based detection technology to match the data of the network security device; Identification module: Use the SVM classification algorithm to classify and label the data of the network security device, and use the data of the network security device to train the intelligent analysis model, combine the network attack path to establish the threat identification strategy of the network attack, and identify the network attack; Optimization module: Use Q-learning method, SGD incremental learning method and Softmax method to perform context learning and state prediction on the intelligent analysis model, analyze attack patterns and attack events in network historical data, and fine-tune the parameters of the intelligent analysis model based on the analysis results and the characteristics of the network attack, optimize the threat identification strategy of the network attack, and enhance the generalization ability and autonomous association reasoning ability of the intelligent analysis model; Re-optimization module: by making slight perturbations to the data fields of normal HTTP requests, using known threats of the network attack to generate adversarial samples, forged HTTP requests are obtained, and adversarial training is performed on the intelligent analysis model by combining normal HTTP requests, forged HTTP requests, the characteristics of the network attack and the adversarial samples to obtain the final intelligent analysis model to identify deceptive network attacks.

9. A computer program product having one or more computer programs thereon, characterized in that: When the computer program is executed by a computer processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Network security training platform construction method and system based on user operation behaviors

    CN117176478A

  • Intelligent network equipment service host security management system based on deep learning

    CN117424740A

  • Network security early warning method and system based on deep learning

    CN118353667A

  • Information security monitoring method and system based on industrial internet

    CN118509214A

  • Light emitting device and polycyclic compound for the same

    KR1020240003784A

Cited By

  • Network security alarm research and judgment model training method and device

    CN121418127A

  • Network security system based on cloud computing and artificial intelligence

    WO2026103157A1