Tracing method, device, equipment, medium and product

By introducing a variety of analysis models and multi-path fusion technologies in network traceability, the problem of low traceability accuracy in the existing technology is solved, the accurate identification and positioning of abnormal data transmission paths is achieved, and network protection capabilities are improved.

CN119996023AActive Publication Date: 2025-05-13CHINA UNITED NETWORK COMM GRP CO LTD +2
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510229840.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-05-13
Estimated Expiration
2045-02-27

AI Technical Summary

Technical Problem

In the prior art, the traceability accuracy is low, making it difficult to accurately identify and locate the starting location and path of abnormal data transmission in complex and changeable network environments, especially affected by noise data and encrypted traffic.

Method used

By obtaining traceability tasks and multiple traceability data, calculate the correlation between the receiving end address and each traceability data, build multiple paths and integrate them, and use multiple analysis models and path optimization algorithms to generate target paths to improve the accuracy of traceability.

Benefits of technology

Effectively respond to interference from noise data and encrypted traffic, improve the traceability accuracy and accurately identify the path between the signal sending end and the receiving end.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119996023A_ABST
    Figure CN119996023A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a tracing method, device and equipment, a medium and a product, and relates to the technical field of network security. The method comprises the steps of obtaining a traceability task and a plurality of traceability data; calculating the relevancy between the receiving end address and each traceability data, and taking the traceability data of which the relevancy is greater than a preset first threshold value as security data; constructing a first path according to the plurality of security data; according to the task type, determining target data from the plurality of traceability data, and determining a target model from a plurality of preset analysis models; inputting the target data into the target model to obtain a plurality of target addresses; constructing a second path according to the plurality of target addresses; and generating a target path according to the first path and the second path. According to the traceability method, multiple analysis models and multi-path fusion are introduced, interference of noise data and encrypted traffic is effectively dealt with, the path between the signal sending end and the signal receiving end can be accurately identified, and the traceability accuracy is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a tracing method, device, equipment, medium and product. Background Art

[0002] With the rapid development of the Internet, the network environment has become increasingly complex. In order to effectively maintain the stability and security of the network, a tracing technology that can determine the source of abnormal data transmission events is needed, so as to timely identify and locate the source and path of abnormal data transmission events and improve the network's protection capabilities.

[0003] In the prior art, logs and traffic data from network devices, servers, and security systems are collected, and rule matching and correlation analysis techniques are used to identify and track the source and path of abnormal data transmission. These methods are usually combined with machine learning technology to detect and identify abnormal addresses in data transmission, and determine the starting location and propagation path of abnormal data transmission events based on the detected abnormal addresses.

[0004] However, the existing technology has the problem of low traceability accuracy. When tracing the source of abnormal data transmission events, the existing technology mainly relies on rule matching and association analysis. These methods are easily affected by factors such as noise data and encrypted traffic when facing complex and changeable network environments, resulting in low traceability accuracy and difficulty in accurately identifying and locating the starting position and path of abnormal data transmission. Summary of the invention

[0005] The embodiments of the present application provide a traceability method, device, equipment, medium and product to solve the problem of low traceability accuracy in the prior art.

[0006] In a first aspect, an embodiment of the present application provides a traceability method, including:

[0007] Obtaining a tracing task and multiple tracing data; wherein the tracing task includes a receiving end address and a task type, and the multiple tracing data includes log data and alarm data;

[0008] Calculate the correlation between the receiving end address and each of the traceability data, and take the traceability data with the correlation greater than a preset first threshold as the safety data; wherein the safety information refers to the abnormal data in the multiple traceability data;

[0009] Constructing a first path according to the plurality of security data; wherein the first path refers to any one of a plurality of paths from a sending end address to the receiving end address;

[0010] According to the task type, determine the target data from the multiple traceability data, and determine the target model from the preset multiple analysis models; wherein the target data refers to any one of the multiple traceability data, and the target model refers to any one of the multiple analysis models;

[0011] Inputting the target data into the target model to obtain a plurality of target addresses; wherein the plurality of target addresses refer to addresses on a plurality of paths from the sending end address to the receiving end address;

[0012] Constructing a second path according to the multiple target addresses; wherein the second path refers to any one of the multiple paths from the sender address to the receiver address except the first path;

[0013] A target path is generated according to the first path and the second path; wherein the target path refers to any one of the multiple paths from the sender address to the receiver address except the first path and the second path.

[0014] In one possible design, constructing a first path according to the plurality of security data includes:

[0015] Calculate and obtain portrait data according to the plurality of security data; wherein the portrait data is used to describe the data transmission process between the sending end address and the receiving end address;

[0016] The first path is constructed according to the multiple traceability data and the portrait data.

[0017] In a possible design, constructing a second path according to the multiple target addresses includes:

[0018] Obtaining communication records of the multiple target addresses;

[0019] The second path is constructed according to the multiple target addresses and the communication record.

[0020] In a possible design, after generating a target path according to the first path and the second path, the method further includes:

[0021] Calculate the integrity of the target path according to a preset integrity calculation rule;

[0022] When the completeness is less than a preset second threshold, creating an adjustment task according to the plurality of traceability data, the traceability task and the completeness;

[0023] The adjustment task is performed to improve the target path.

[0024] In a possible design, the obtaining of the traceability task and the plurality of traceability data includes:

[0025] Acquire data source data, shared data and the traceability task; wherein the data source data includes flow data and update data, and the shared data includes communication data and configuration data;

[0026] The data source data and the shared data are preprocessed to obtain the traceability data.

[0027] In a possible design, calculating the correlation between the receiving end address and each of the traceability data, and taking the traceability data with a correlation greater than a preset first threshold as the safety data, includes:

[0028] Acquire address information of each of the traceability data; wherein the address information is used to describe the source of the traceability data;

[0029] The correlation between the address information of each traceability data and the address of the receiving end is calculated respectively, and the traceability data with the correlation greater than the first threshold is taken as the security data.

[0030] In a second aspect, the present application provides a traceability device, the device comprising:

[0031] An acquisition module, used to acquire a traceability task and multiple traceability data; wherein the traceability task includes a receiving end address and a task type, and the multiple traceability data includes log data and alarm data;

[0032] A correlation calculation module, used to calculate the correlation between the receiving end address and each of the traceability data, and take the traceability data with the correlation greater than a preset first threshold as the safety data; wherein the safety information refers to the abnormal data in the multiple traceability data;

[0033] A first path building module, configured to build a first path according to the plurality of security data; wherein the first path refers to any one of a plurality of paths from a sending end address to the receiving end address;

[0034] A determination module, used to determine target data from the plurality of traceability data and determine a target model from a plurality of preset analysis models according to the task type; wherein the target data refers to any one of the plurality of traceability data, and the target model refers to any one of the plurality of analysis models;

[0035] A target address calculation module, used for inputting the target data into the target model to obtain a plurality of target addresses; wherein the plurality of target addresses refer to addresses on a plurality of paths from the sending end address to the receiving end address;

[0036] A second path building module, configured to build a second path according to the multiple target addresses; wherein the second path refers to any one of the multiple paths from the sender address to the receiver address except the first path;

[0037] A target path generation module is used to generate a target path according to the first path and the second path; wherein the target path refers to any one of the multiple paths from the sender address to the receiver address except the first path and the second path.

[0038] In a possible design, the first path construction module includes:

[0039] A portrait data calculation unit, used to calculate the portrait data according to the plurality of security data; wherein the portrait data is used to describe the data transmission process between the sending end address and the receiving end address;

[0040] The first path construction unit is used to construct the first path according to the multiple traceability data and the portrait data.

[0041] In a possible design, the second path construction module includes:

[0042] A communication record acquisition unit, configured to acquire the communication records of the plurality of target addresses;

[0043] The second path construction unit is used to construct the second path according to the multiple target addresses and the communication record.

[0044] In a possible design, the traceability device further includes:

[0045] An integrity calculation module, used to calculate the integrity of the target path according to a preset integrity calculation rule;

[0046] A task creation module, configured to create an adjustment task according to the plurality of traceability data, the traceability task and the completeness when the completeness is less than a preset second threshold;

[0047] The task execution module is used to execute the adjustment task to improve the target path.

[0048] In a possible design, the acquisition module includes:

[0049] A data acquisition unit, used to acquire data source data, shared data and the traceability task; wherein the data source data includes flow data and update data, and the shared data includes communication data and configuration data;

[0050] A data preprocessing unit is used to preprocess the data source data and the shared data to obtain the traceability data.

[0051] In a possible design, the correlation calculation module includes:

[0052] An address information acquisition unit, used to acquire address information of each of the traceability data; wherein the address information is used to describe the source of the traceability data;

[0053] The correlation calculation unit is used to calculate the correlation between the address information of each traceability data and the receiving end address, and take the traceability data with the correlation greater than the first threshold as the security data.

[0054] In a third aspect, the present application provides an electronic device, comprising: a processor, and a memory communicatively connected to the processor;

[0055] The memory stores computer-executable instructions;

[0056] When the processor executes the computer-executable instructions stored in the memory, it is used to implement the tracing method as described in any one of the first aspects.

[0057] In a fourth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer execution instructions, and when the computer execution instructions are executed by a processor, they are used to implement the traceability method as described in any one of the first aspects.

[0058] In a fifth aspect, the present application provides a computer program product, including a computer program, which, when executed by a processor, is used to implement the traceability method as described in any one of the first aspects.

[0059] The present application provides a traceability method, device, equipment, medium and product, the method comprising: obtaining a traceability task and multiple traceability data; calculating the correlation between the receiving end address and each of the traceability data, and taking the traceability data with a correlation greater than a preset first threshold as security data; constructing a first path according to the multiple security data; determining the target data from the multiple traceability data according to the task type, and determining the target model from the preset multiple analysis models; inputting the target data into the target model to obtain multiple target addresses; constructing a second path according to the multiple target addresses; generating a target path according to the first path and the second path. The traceability method of the present application solves the problem of low traceability accuracy in the prior art by introducing multiple analysis models and multi-path fusion. The method determines data and models according to the task type, processes different data using different analysis models, and generates multiple possible paths. By fusing and optimizing these paths, the interference of noise data and encrypted traffic is effectively dealt with, the path between the signal sending end and the receiving end can be accurately identified, and the traceability accuracy is improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, a brief introduction will be given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0061] Figure 1 A schematic diagram of the system architecture of the traceability method provided in an embodiment of the present application;

[0062] Figure 2 A schematic diagram of an application scenario of the traceability method provided in an embodiment of the present application;

[0063] Figure 3 Schematic diagram of the process of the traceability method provided in the embodiment of the present application Figure 1 ;

[0064] Figure 4 Schematic diagram of the process of the traceability method provided in the embodiment of the present application Figure 2 ;

[0065] Figure 5 A schematic diagram of the structure of a traceability device provided in an embodiment of the present application;

[0066] Figure 6 A schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0067] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present application. Instead, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.

[0068] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant laws, regulations and standards, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0069] In the embodiments of the present application, words such as "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects. Those skilled in the art will understand that words such as "first" and "second" do not limit the quantity and execution order, and words such as "first" and "second" do not necessarily limit the difference. It should be noted that in the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "exemplary" or "for example" in this application should not be interpreted as being more preferred or more advantageous than other embodiments or design. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way. In the embodiments of the present application, "at least one" refers to one or more, and "more" refers to two or more.

[0070] It should be noted that the "at..." in the embodiments of the present application can be the instant when a certain situation occurs, or can be a period of time after a certain situation occurs, and the embodiments of the present application do not specifically limit this. In addition, the traceability method provided in the embodiments of the present application is only an example, and the traceability method can also include more or less content.

[0071] In order to clearly describe the technical solutions of the embodiments of the present application, some terms and technologies involved in the embodiments of the present application are briefly introduced below:

[0072] Domain Name System (DNS) logs: are data files that record activities related to domain name resolution requests and responses. These logs can help identify unusual activities, analyze traffic patterns, diagnose network problems, and track potential security threats. By analyzing DNS logs, you can determine how your network is being used.

[0073] Data flow log: It is a log file that records the flow of data in the network, and describes in detail the transmission path, timestamp, destination address, port number, protocol type, and amount of data transmitted of the data packet in the network. These logs can be used to monitor and analyze network traffic, helping network administrators understand network performance, detect abnormal activities, optimize resource allocation, and ensure security.

[0074] Network topology: refers to the physical or logical connection structure between various nodes in the network, such as computers, switches, routers, etc. It describes how network devices connect and interact with each other through communication links. Common network topology types include bus, star, ring, mesh and hybrid. Network topology not only affects the performance, reliability and scalability of the network, but also determines the path and efficiency of data transmission. It is a key factor in network design and management.

[0075] Exemplary embodiments will be described in detail herein, examples of which are shown in the accompanying drawings. When the following description refers to the drawings, the same numbers in different drawings represent the same or similar elements unless otherwise indicated. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present invention. Instead, they are merely examples of devices and methods consistent with some aspects of the present invention as detailed in the appended claims.

[0076] The technical solution of the present invention is described in detail with specific embodiments below. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present invention will be described below in conjunction with the accompanying drawings.

[0077] In order to clearly understand the technical solution of the present application, the solution of the prior art is first introduced in detail. In the prior art, the network security system collects logs and traffic data from network devices, servers, and security systems, and uses rule matching and association analysis techniques to identify and track the source and path of abnormal data transmission. These systems usually predefine a series of rules and patterns to quickly identify abnormal behavior in the data or abnormal addresses in the data transmission. After identifying these abnormal addresses, the system will further analyze to determine the starting location and propagation path of the abnormal data transmission event.

[0078] However, the existing traceability methods have the problem of low traceability accuracy. When tracing abnormal data transmission events, the existing technologies mainly rely on rule matching and association analysis. These methods are easily affected by factors such as noise data and encrypted traffic in the face of complex and changeable network environments, resulting in low traceability accuracy and difficulty in accurately identifying and locating the starting position and path of abnormal data transmission.

[0079] Therefore, in order to solve the problem of low accuracy of the traceability method in the existing technology, it is found in the study that different models can be used according to different task types, as well as multi-path fusion methods can be introduced: ① When tracing abnormal data transmission, different analysis models are selected and applied according to the nature and requirements of the specific task. Different tasks may involve different network environments, data characteristics or security threats. Therefore, by matching suitable models to handle specific tasks, the system can effectively capture the complex patterns of abnormal behavior and optimize the identification process of the traceability path. ② When tracing abnormal data transmission, the information of multiple potential paths is considered at the same time to reduce the errors and uncertainties that may be caused by single path analysis. By fusing data and features from different paths, the system can fully understand the starting position and propagation path of abnormal data transmission, thereby enhancing the overall accuracy of the traceability process. ③ Integrate information from multiple data sources. Different data sources can provide multi-dimensional information, such as network traffic logs, user behavior records, and system event logs. This information complements each other and can more comprehensively reflect the overall picture of network activities. By comprehensively analyzing these diverse data, the system can more effectively identify abnormal patterns and potential threats, overcome the limitations and deviations that may exist in a single data source, and thus enhance the ability to identify and locate abnormal data transmission paths.

[0080] Specific:

[0081] A system architecture can be built that can fully integrate multi-dimensional information, dynamically adapt to different situational needs, and provide multi-level analysis perspectives. In this way, the system can accurately capture and understand abnormal addresses in complex network environments, thereby improving the ability to identify and locate abnormal data transmission activities and improve the accuracy and reliability of traceability.

[0082] The traceability method of the embodiment of the present application solves the problem of low traceability accuracy in the prior art by introducing multiple analysis models and multi-path fusion methods. The method determines the data and model according to the task type, uses different analysis models to process different data, and generates multiple possible paths. By fusing and optimizing these paths, the influence of noise data and encrypted traffic is effectively filtered out, and the path between the signal transmitter and the receiver can be accurately identified. This strategy effectively copes with the interference of factors such as noise data and encrypted traffic, and improves the traceability accuracy.

[0083] Based on the above creative findings, the technical solution of the present application is proposed.

[0084] Figure 1 A schematic diagram of the system architecture of the traceability method provided in the embodiment of the present application. It should be noted that: Figure 1What is shown is merely an example of a system architecture to which the embodiments of the present application can be applied, in order to help those skilled in the art understand the technical content of the present application, but it does not mean that the embodiments of the present application cannot be used in other devices, systems, environments or scenarios.

[0085] like Figure 1 As shown, the system architecture of the method includes a task generation module 101, a data acquisition module 102, a portrait data module 103, a correlation analysis module 104, a model analysis module 105, an anomaly identification module 106 and a path fusion module 107. The task generation module 101 can generate a traceability task and send the traceability task to the data acquisition module 102 and the portrait data module 103. After receiving the traceability task, the data acquisition module 102 can collect traceability data and send the traceability data to the association analysis module 104 and the model analysis module 105. After receiving the traceability task, the portrait data module 103 can perform portrait analysis according to the address in the traceability task, generate portrait data and send the portrait data to the association analysis module 104. After receiving the portrait data and traceability data, the association analysis module 104 can detect abnormal addresses and send them to the abnormal identification module 106. The model analysis module 105 can also detect abnormal addresses after receiving the traceability data and send them to the abnormal identification module 106. After receiving the above two abnormal addresses, the abnormal identification module 106 can generate two paths and send the two paths to the path fusion module 107. The path fusion module 107 can fuse the two paths to obtain the target path.

[0086] In an embodiment of the present application, the task generation module 101 can be a computer hardware controller, which can automatically generate traceability tasks through preset algorithms and logics, and distribute these tasks to the data acquisition module 102 and the portrait data module 103. The data acquisition module 102 can be an embedded device that integrates a sensor interface and data processing capabilities. The module can obtain traceability data in real time or regularly through connections with various data sources. The portrait data module 103 can be a computer software module that is responsible for receiving the traceability tasks sent by the task generation module 101 and performing portrait analysis based on the address information in the task. It uses data analysis algorithms and machine learning techniques to extract and integrate relevant information from multiple data sources to generate detailed portrait data. The association analysis module 104 can be a software system based on data analysis and machine learning algorithms. The module can receive portrait data and traceability data, identify potential relationships and patterns between data through association analysis algorithms, and detect abnormal addresses and behavior patterns. The model analysis module 105 can be a software system that integrates data modeling and predictive analysis capabilities. This module focuses on receiving and processing traceability data from the data acquisition module 102, and conducts in-depth analysis of the data by building and applying mathematical models to identify abnormal addresses and behavior patterns. The abnormal identification module 106 can be a software system that can receive abnormal address data from the association analysis module 104 and the model analysis module 105, and conduct comprehensive analysis and verification of these data. By using an abnormality detection algorithm, the abnormality identification module 106 can effectively identify and confirm abnormal addresses in the data. The path fusion module 107 can be a software system that integrates data integration and path optimization algorithms. The main function of this module is to receive two abnormal paths from the abnormality identification module 106, and integrate these paths through a fusion algorithm to generate an optimized target path.

[0087] The following introduces the application scenarios of the traceability method provided by the embodiments of the present invention. Figure 2 Schematic diagram of application scenarios of the traceability method provided in the embodiment of the present application. Figure 2 As shown, the application scenario includes a mobile terminal 201 and a server 202. The mobile terminal 201 sends a tracing instruction to the server 202, and the server 202 performs tracing according to the tracing instruction and sends the target path obtained by tracing to the mobile terminal 201.

[0088] The embodiments of the present invention are described below in conjunction with the accompanying drawings.

[0089] Figure 3 Schematic diagram of the process of the traceability method provided in the embodiment of the present application Figure 1 .like Figure 3As shown, in this embodiment, the execution subject of the embodiment of the present invention is a server. Then the tracing method provided by this embodiment includes the following steps:

[0090] S301. Obtain a traceability task and multiple traceability data.

[0091] Specifically, the traceability task and multiple traceability data can be obtained through a network monitoring and data acquisition system, which can collect and store log data and alarm data in the network in real time, and classify and organize them according to the preset task type and receiving end address. This design can provide the necessary data foundation for the subsequent traceability analysis process, so as to calculate the relevance, identify security data, build paths, and select appropriate analysis models, so as to achieve the tracking and analysis of the data flow path. Among them, the traceability task includes the receiving end address and task type, and the multiple traceability data include log data and alarm data.

[0092] S302: Calculate the correlation between the receiving end address and each traceability data, and take the traceability data with a correlation greater than a preset first threshold as safe data.

[0093] Specifically, a machine learning-based algorithm can be used to calculate the correlation between the receiving end address and each traceability data. The algorithm can analyze the features in the traceability data, such as timestamp, packet size, communication frequency, etc., compare them with the historical communication pattern of the receiving end address, and calculate the correlation score. The traceability data whose correlation exceeds the preset first threshold is marked as safe data. This process can filter out abnormal data that is highly correlated with the receiving end address so that these data can be focused on in subsequent path construction and analysis, thereby improving the accuracy and efficiency of traceability analysis. Among them, security information refers to abnormal data in multiple traceability data.

[0094] S303: Construct a first path according to multiple security data.

[0095] Specifically, the first path can be constructed by analyzing and organizing the network addresses and communication links involved in the security data. Path optimization technology can be used to connect the source address, destination address and the intermediate nodes in the security data to form a path from the sender to the receiver. Through this design, the transmission path of abnormal data can be effectively identified and tracked, thereby improving the accuracy and reliability of tracing.

[0096] For example, in a network intrusion incident, the security system collects a large amount of log data and alarm data, which includes abnormal access requests and unauthorized login attempts. By analyzing this security data, the system can identify multiple abnormal addresses and calculate the correlation between these addresses, thereby constructing a path from the attacker's initial address to the target address of the attack. This path can help the security team quickly locate the source of the attack, understand the attacker's route of action, and take effective measures to block the attack path, thereby improving overall network security.

[0097] S304: According to the task type, determine the target data from the multiple traceability data, and determine the target model from the multiple preset analysis models.

[0098] Specifically, the target data and target model can be determined through an intelligent decision-making system. The system first filters out the target data related to the task from the traceability data according to the definition of the task type. Then, the system matches the most suitable analysis model according to the task type, for example, using a machine learning model for anomaly detection or a rule engine for pattern matching. Through this design, the system can flexibly adapt to different types of traceability tasks, ensuring that the selected target data and analysis model can effectively identify and track abnormal data transmission activities, thereby improving the accuracy and efficiency of traceability. Among them, the target data refers to any one of multiple traceability data, and the target model refers to any one of multiple analysis models.

[0099] For example, when processing a network intrusion tracing task, the system first selects relevant abnormal login attempts and suspicious traffic data from the collected log data and alarm data as target data according to the task type. Then, the system selects a machine learning model suitable for detecting abnormal behavior from multiple preset analysis models as the target model. By inputting the target data into the target model, the system can identify the attacker's initial address and build a path from that address to the attacked target. This method of accurately screening the target data and analysis models related to the task not only speeds up the response to security incidents, but also reduces false positives and false negatives, enabling the security team to take targeted defense measures in a timely manner, optimize resource utilization, and enhance network security.

[0100] S305: Input the target data into the target model to obtain multiple target addresses.

[0101] Specifically, the target data can be input into a model for pattern recognition, anomaly detection or path prediction. After the model processes the input data, it outputs multiple network addresses related to the target data, which may represent potential communication nodes or path nodes. This design is used for network security and traffic analysis, and aims to identify key addresses related to specific security events or communication patterns through model analysis, so as to accurately track the path and impact range of abnormal data transmission activities. Among them, multiple target addresses refer to addresses on multiple paths from the sender address to the receiver address.

[0102] For example, the target data can be a log field feature, and the target model can be an unsupervised machine learning model. The target model can use an outlier detection algorithm based on empirical cumulative distribution to detect the target data and obtain multiple target addresses with abnormal behavior. The outlier detection algorithm based on empirical cumulative distribution identifies outliers by evaluating the relative position of data points in the distribution of each feature. This method assumes that each feature is independent of each other and uses the empirical cumulative distribution function of each feature to quantify its rarity. Finally, by multiplying the tail probabilities on different dimensions, a comprehensive anomaly score is obtained. The higher the score, the greater the possibility of being an outlier, which is used to measure the degree of abnormality of the data point.

[0103] Assume there are n samples and the feature dimension is d. If Represents the jth feature of the i-th sample. The formula for calculating the left and right tail outliers of the empirical cumulative distribution function is as follows:

[0104]

[0105]

[0106] in, is the indicator function, When the parameter in is true Set to 1, otherwise Set to 0, Z is the preset value.

[0107] The left and right tail probabilities and automatic anomaly scores are calculated for each log field feature, and then the maximum value aggregation is performed to obtain the outlier score of the sample. The calculation formula is as follows:

[0108]

[0109]

[0110]

[0111]

[0112] in, is the sample skewness coefficient of the j-th feature distribution, For a comprehensive anomaly score, the anomaly score of each log field feature can be calculated. When the anomaly score is greater than a preset value, the address corresponding to the target field feature is taken as the target address.

[0113] S306: Construct a second path according to the multiple target addresses.

[0114] Specifically, the second path can be constructed through a path construction algorithm, which uses the connection relationship between the target addresses to form a path from the sender to the receiver. Specific steps may include: analyzing the network topology between the target addresses, identifying possible communication links, and constructing the second path according to preset path selection strategies, such as the shortest path or the lowest delay. This design is used for network tracing and security analysis, and aims to help identify and verify potential abnormal data transmission paths by providing a path different from the first path. Among them, the second path refers to any one of the multiple paths from the sender address to the receiver address except the first path.

[0115] For example, by analyzing the network topology between multiple target addresses, a second path from the attacker to the attacked target can be identified. If the first path is constructed based on the shortest path strategy, the second path can be constructed based on a different strategy. By providing a second path that is different from the first path, it helps to more comprehensively identify and verify the attacker's possible attack path, thereby improving the defense and response capabilities against potential security threats.

[0116] S307: Generate a target path according to the first path and the second path.

[0117] Specifically, the first path and the second path can be merged through path optimization and data integration algorithms. The addresses and connection relationships of the two paths can be compared and merged. The algorithm can automatically identify the key addresses in the two paths and remove duplicate addresses to ensure that the final target path is both concise and complete. The target path can fully understand the trajectory of data from the sender to the receiver, so as to detect, respond and prevent threats in a timely manner. Among them, the target path refers to any one of the multiple paths from the sender address to the receiver address except the first path and the second path.

[0118] For example, in the process of tracing the source of a network attack, the system first constructs the first path and the second path that the attacker may use based on security data. These paths reveal known abnormal paths from the attacker's initial address to the attacked target. Subsequently, the system generates a target path by analyzing these two paths to identify other paths that may be used by the attacker but have not yet been discovered. This process helps the security team identify hidden paths in complex attack chains, providing a more comprehensive view of attacks, so that more effective defense measures can be taken to improve overall network security.

[0119] The present embodiment provides a traceability method, which includes: obtaining a traceability task and multiple traceability data; calculating the correlation between the receiving end address and each traceability data, and taking the traceability data with a correlation greater than a preset first threshold as security data; constructing a first path according to multiple security data; determining the target data from multiple traceability data according to the task type, and determining the target model from multiple preset analysis models; inputting the target data into the target model to obtain multiple target addresses; constructing a second path according to the multiple target addresses; generating a target path according to the first path and the second path. A traceability method achieves the following technical effects: by introducing multiple analysis models and multi-path fusion, the problem of low traceability accuracy in the prior art is solved. The method determines data and models according to the task type, processes different data using different analysis models, and generates multiple possible paths. By fusing and optimizing these paths, the influence of noise data and encrypted traffic is effectively filtered out, and the path between the signal sending end and the receiving end can be accurately identified. This method effectively copes with the interference of complex factors such as noise data and encrypted traffic, and improves the traceability accuracy.

[0120] In a possible design, S303 constructs a first path according to multiple security data, including:

[0121] S3031. Calculate and obtain portrait data based on multiple security data.

[0122] Specifically, data mining or machine learning can be used to analyze and process the characteristic information in the security data, and key features describing the characteristics of data transmission between the sender address and the receiver address can be extracted from the security data. These features can include the size of the data packet, transmission time, transmission frequency, and abnormal behavior patterns. By comprehensively analyzing these features, a portrait data is generated, which can comprehensively describe and characterize the characteristics of the data transmission process. This design is used to identify and understand normal and abnormal behavior patterns in the data transmission process for source tracing analysis. Portrait data can help identify potential security threats and optimize network path selection to improve the security and efficiency of data transmission. By constructing accurate portrait data, the system can effectively monitor and manage network traffic to ensure the reliability and security of data transmission. Among them, the portrait data is used to describe the data transmission process between the sender address and the receiver address.

[0123] S3032. Construct a first path based on multiple traceability data and portrait data.

[0124] Specifically, the first path can be constructed by analyzing the abnormal features in the traceability data and the transmission mode described by the portrait data. The portrait data provides an overview of the transmission process from the sender to the receiver, revealing potential abnormal addresses and path characteristics. By matching this information with the abnormal patterns in the traceability data, the system is able to identify abnormal transmission paths. This design is used to accurately locate the transmission path of abnormal data in the network, thereby improving the accuracy and efficiency of traceability and helping to identify and respond to potential security threats.

[0125] The technical effect of the scheme in this embodiment is: by calculating multiple security data to obtain the portrait data, and combining multiple traceability data and the portrait data to construct the first path, the path of abnormal data transmission can be accurately identified and determined. The path is composed of multiple abnormal addresses. Through this method, the accuracy of traceability can be effectively improved, helping to identify and track the anomalies in the data transmission process, and ultimately achieving a more accurate traceability goal.

[0126] In a possible design, S306 constructs a second path according to the multiple target addresses, including:

[0127] S3061. Obtain communication records of multiple target addresses.

[0128] Specifically, communication records of multiple destination addresses can be obtained through network monitoring and log analysis tools. These tools can capture and record communication data between various addresses in the network in real time, including information such as source address, destination address, transmission time, and packet size. By analyzing these communication records, abnormal communication behaviors and paths can be identified, thereby helping to build a second path. This design is used to identify and track the paths of abnormal data transmission in the network to improve the accuracy of tracing.

[0129] S3062. Construct a second path according to multiple target addresses and communication records.

[0130] Specifically, network traffic logs and system logs related to multiple target addresses can be analyzed. These log records usually contain detailed communication information, such as timestamps, target addresses, port numbers, and protocol types. By analyzing these communication records, the specific path of abnormal data transmission can be identified, thereby building a second path from the sender to the receiver. This design is used to identify and track the path of abnormal data transmission, ensuring that the communication links involving multiple abnormal addresses on the path from the sender to the receiver can be accurately determined. By building and analyzing these paths, the behavior patterns and transmission paths of the data sender can be better understood, thereby improving the accuracy of tracing.

[0131] The technical effect of the scheme in this embodiment is: by obtaining the communication records of multiple target addresses and constructing a second path based on these records, the specific path of abnormal data transmission can be effectively identified and tracked. This process ensures that all abnormal addresses involved in the path from the sender to the receiver are accurately identified and recorded. In this way, the behavior path of the data sender sending data can be fully understood and reconstructed, and the accuracy and completeness of traceability can be improved, thereby providing a more reliable basis for network security protection.

[0132] In a possible design, S301 obtains a traceability task and multiple traceability data, including:

[0133] S3011. Obtain data source data, shared data and traceability tasks.

[0134] Specifically, by integrating multiple data collection mechanisms, traffic data and update data can be extracted from network devices, servers, and security systems, as well as shared communication data and configuration data from cloud service providers or other partners. The traceability task is defined and obtained through the security management system or user interface. This design is used to ensure that the traceability system can comprehensively collect and integrate data from multiple sources to support the accurate identification and analysis of abnormal data transmission paths, thereby improving the accuracy and effectiveness of traceability. In this way, the system can better understand and track abnormal paths from the sender to the receiver and identify potential security threats. Among them, the data source data includes traffic data and update data, and the shared data includes communication data and configuration data.

[0135] For example, the following shared data can be obtained from the server through the cloud sharing mechanism: data flow log, domain name system log, Internet access log, user information, alarm log, full flow data, host log and specific files. Among them, the data flow log may include the source address, destination address, port number, network protocol type, flow start time, flow end time, number of bytes in the incoming direction and number of packets in the incoming direction, etc., the domain name system log may include the requested domain name, request time, requested domain name system record type, record resolution address, domain name, record resolution address and resolution server address, etc., and the Internet access log may include the port number, uniform resource locator, connection type and area code, etc.

[0136] S3012. Preprocess the data source data and shared data to obtain traceability data.

[0137] Specifically, preprocessing can be achieved through steps such as data cleaning, format conversion, and standardization. First, the collected data source data and shared data are cleaned to remove noise and redundant information. Then, format conversion is performed to unify data from different sources into a compatible format. Finally, standardization is performed to ensure data consistency and comparability. This design is used to improve the quality and availability of data, so that traceability analysis can be carried out on a reliable and unified data basis, thereby accurately identifying and tracking abnormal paths from the sender to the receiver, and improving the accuracy and efficiency of traceability.

[0138] The technical effect of the scheme in this embodiment is: by acquiring and preprocessing data source data, shared data, and traceability tasks, high-quality and consistent basic data can be provided for traceability analysis. This process ensures that data collected from multiple sources can be effectively used to identify and track abnormal data transmission paths after being cleaned and standardized. In this way, the system can accurately determine the abnormal path from the sender to the receiver, improving the accuracy and efficiency of traceability.

[0139] In a possible design, S302 calculates the correlation between the receiving end address and each traceability data, and takes the traceability data with a correlation greater than a preset first threshold as the safety data, including:

[0140] S3021. Obtain the address information of each traceability data.

[0141] Specifically, the address information of each traceability data can be obtained by parsing and extracting information such as system logs, alarm data, and target addresses. This information is usually embedded in the packet header or log record and can be effectively extracted through automated scripts or log analysis tools. This design is used to identify and record network entities related to the traceability data, thereby calculating the correlation between these entities and the receiving end address. By accurately obtaining and analyzing this address information, the system can more effectively identify abnormal data transmission paths and improve the accuracy and efficiency of traceability. Among them, the address information is used to describe the source of the traceability data.

[0142] S3022. Calculate the correlation between the address information of each traceability data and the address of the receiving end respectively, and take the traceability data with a correlation greater than a first threshold as safe data.

[0143] Specifically, the degree of correlation between the address information of each traceability data and the address of the receiving end can be calculated by using a similarity algorithm or a machine learning model. Specific methods may include calculating indicators such as the geographical proximity of the address, the similarity of the network topology, or the historical communication frequency. By setting a preset correlation threshold, the system can filter out traceability data that is highly correlated with the address of the receiving end and mark it as safe data. This design is used to identify and filter out data that is highly correlated with abnormal activities, thereby helping to build an accurate abnormal data transmission path and improve the accuracy and effectiveness of traceability.

[0144] The technical effect of the scheme in this embodiment is: by calculating the correlation between the address information of each traceability data and the address of the receiving end, and screening out the traceability data with a correlation greater than a preset threshold as security data, it is possible to effectively identify data closely related to abnormal activities. This process ensures that the basic data for traceability analysis has a high degree of relevance and accuracy, thereby improving the accuracy of identifying abnormal data transmission paths. In this way, the system can accurately track the abnormal path from the sender to the receiver, improving the accuracy and efficiency of traceability.

[0145] Figure 4 Schematic diagram of the process of the traceability method provided in the embodiment of the present application Figure 2 In this embodiment, Figure 3 Based on the provided embodiments, the traceability method is further explained. The traceability method includes:

[0146] S401. Obtain a traceability task and multiple traceability data; wherein the traceability task includes a receiving end address and a task type, and the multiple traceability data includes log data and alarm data.

[0147] S402, calculating the correlation between the receiving end address and each traceability data, and taking the traceability data with a correlation greater than a preset first threshold as safety data; wherein the safety information refers to abnormal data in multiple traceability data.

[0148] S403: construct a first path according to the plurality of security data; wherein the first path refers to any one of the plurality of paths from the sender address to the receiver address.

[0149] S404. According to the task type, determine the target data from the multiple traceability data, and determine the target model from the preset multiple analysis models; wherein the target data refers to any one of the multiple traceability data, and the target model refers to any one of the multiple analysis models.

[0150] S405. Input the target data into the target model to obtain multiple target addresses; wherein the multiple target addresses refer to addresses on multiple paths from the sender address to the receiver address.

[0151] S406. Construct a second path according to the multiple target addresses; wherein the second path refers to any one of the multiple paths from the sender address to the receiver address except the first path.

[0152] S407. Generate a target path according to the first path and the second path; wherein the target path refers to any one of the multiple paths from the sender address to the receiver address except the first path and the second path.

[0153] S401-S407 are similar to S301-S307 and will not be described in detail in this embodiment.

[0154] S408: Calculate the integrity of the target path according to a preset integrity calculation rule.

[0155] Specifically, a set of completeness calculation rules can be defined, which can include indicators such as the number of path addresses, the network range covered by the path, the recognition rate of abnormal addresses in the path, and the degree of deviation of the path from the known normal path. The target path is evaluated and its score on these indicators is calculated to determine the completeness of the path. When the completeness is lower than the preset threshold, the system can trigger an adjustment task to improve and optimize the path identification process, thereby improving the accuracy and reliability of traceability.

[0156] S409: When the completeness is less than a preset second threshold, an adjustment task is created according to the plurality of traceability data, the traceability tasks and the completeness.

[0157] Specifically, a completeness threshold can be set. When the calculated completeness result of the target path is lower than the threshold, the system automatically generates an adjustment task. The creation of adjustment tasks is based on the re-analysis of multiple traceability data and traceability tasks, which may involve re-evaluating data relevance, introducing more data sources, or adjusting the parameters of the analysis model. The adjustment task aims to optimize the path identification and analysis process to fill information gaps in the path or correct identification errors. This design is used to ensure the accuracy and completeness of the traceability path, and to improve the accuracy and reliability of the traceability system in identifying abnormal data transmission paths by dynamically adjusting and optimizing the analysis process.

[0158] S410: Execute an adjustment task to improve the target path.

[0159] Specifically, when performing adjustment tasks, the system can introduce new data sources or update existing data to fill information gaps in the path or correct identification errors. This design is used to dynamically optimize and improve the traceability path to ensure that the identified abnormal data transmission path is as complete and accurate as possible. By performing adjustment tasks, the system can improve the accuracy and reliability of traceability analysis.

[0160] The technical effect of the scheme in this embodiment is: by calculating the completeness of the target path after generating it, and creating and executing an adjustment task when the completeness is lower than a preset threshold, the identification process of abnormal data transmission paths can be dynamically optimized and improved. This mechanism ensures the comprehensiveness and accuracy of the traceability path, and even if the initial path identification is incomplete, it can be supplemented and corrected through adjustment tasks. In this way, the system can more effectively identify and track abnormal activities and improve the accuracy and reliability of traceability analysis.

[0161] Figure 5 This is a schematic diagram of the structure of the traceability device provided in the embodiment of the present application. Figure 5 As shown, the traceability device includes:

[0162] The acquisition module 501 is used to acquire a traceability task and multiple traceability data; wherein the traceability task includes a receiving end address and a task type, and the multiple traceability data includes log data and alarm data.

[0163] The correlation calculation module 502 is used to calculate the correlation between the receiving end address and each traceability data, and take the traceability data with a correlation greater than a preset first threshold as safe data; wherein, the safety information refers to abnormal data in multiple traceability data.

[0164] The first path building module 503 is used to build a first path according to multiple security data; wherein the first path refers to any one of multiple paths from the sender address to the receiver address.

[0165] The determination module 504 is used to determine the target data from multiple traceability data and determine the target model from multiple preset analysis models according to the task type; wherein the target data refers to any one of the multiple traceability data, and the target model refers to any one of the multiple analysis models.

[0166] The target address calculation module 505 is used to input the target data into the target model to obtain multiple target addresses; wherein the multiple target addresses refer to addresses on multiple paths from the sending end address to the receiving end address.

[0167] The second path building module 506 is used to build a second path according to multiple target addresses; wherein the second path refers to any one of the multiple paths from the sender address to the receiver address except the first path.

[0168] The target path generation module 507 is used to generate a target path according to the first path and the second path; wherein the target path refers to any one of the multiple paths from the sender address to the receiver address except the first path and the second path.

[0169] In a possible design, the first path construction module 503 includes:

[0170] The portrait data calculation unit is used to calculate the portrait data based on multiple security data; wherein the portrait data is used to describe the data transmission process between the sending end address and the receiving end address.

[0171] The first path construction unit is used to construct a first path according to multiple traceability data and portrait data.

[0172] In a possible design, the second path construction module 506 includes:

[0173] The communication record acquisition unit is used to acquire the communication records of multiple target addresses.

[0174] The second path construction unit is used to construct a second path according to multiple target addresses and communication records.

[0175] In a possible design, the traceability device further includes:

[0176] The integrity calculation module is used to calculate the integrity of the target path according to a preset integrity calculation rule.

[0177] The task creation module is used to create an adjustment task based on multiple traceability data, traceability tasks and completeness when the completeness is less than a preset second threshold.

[0178] The task execution module is used to execute adjustment tasks to improve the target path.

[0179] In a possible design, the acquisition module 501 includes:

[0180] The data acquisition unit is used to acquire data source data, shared data and traceability tasks; wherein the data source data includes flow data and update data, and the shared data includes communication data and configuration data.

[0181] The data preprocessing unit is used to preprocess the data source data and shared data to obtain traceability data.

[0182] In a possible design, the correlation calculation module 502 includes:

[0183] The address information acquisition unit is used to acquire the address information of each traceability data; wherein the address information is used to express the source of the traceability data.

[0184] The correlation calculation unit is used to calculate the correlation between the address information of each traceability data and the address of the receiving end, and take the traceability data with a correlation greater than a first threshold as safe data.

[0185] The traceability device provided in this embodiment can execute Figure 3 and Figure 4 The technical solution of the method embodiment shown in the figure has the same implementation principle and technical effect as Figure 3 and Figure 4 The method embodiments shown are similar and will not be described in detail here.

[0186] Figure 6 The hardware structure diagram of the electronic device provided in the embodiment of the present application is shown in FIG. Figure 6 As shown, the electronic device includes: at least one processor 610 and a memory 620. The electronic device also includes a communication component 630. The processor 610, the memory 620 and the communication component 630 are connected via a bus 640.

[0187] In the specific implementation process, at least one processor 610 executes the computer execution instructions stored in the memory 620, so that the at least one processor 610 is used to implement the tracing method of the above embodiment.

[0188] The specific implementation process of the processor 610 can be found in the above method embodiment, and its implementation principle and technical effect are similar, so this embodiment will not be repeated here.

[0189] In the above embodiment, it should be understood that the processor 610 can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in the invention can be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.

[0190] The memory 620 may include a high-speed RAM memory, and may also include a non-volatile storage NVM, such as at least one disk storage.

[0191] The bus 640 may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, or an Extended Industry Standard Architecture (EISA) bus, etc. The bus 640 may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the bus 640 in the drawings of the present application is not limited to only one bus or one type of bus.

[0192] The above-mentioned functions implemented by the electronic device and the main control device introduce the scheme provided by the embodiment of the present invention. It can be understood that in order to implement the above-mentioned functions, the electronic device or the main control device includes a hardware structure and / or software module corresponding to the execution of each function. In combination with the units and algorithm steps of each example described in the embodiment disclosed in the embodiment of the present invention, the embodiment of the present invention can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the technical solution of the embodiment of the present invention.

[0193] The embodiment of the present application also provides a computer-readable storage medium, in which computer-executable instructions are stored, and when the computer-executable instructions are executed by a processor, they are used to implement the traceability method of the above embodiment. In the specific implementation of the above-mentioned traceability method, each module can be implemented as a processor.

[0194] The above-mentioned readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The readable storage medium can be any available medium that can be accessed by a general or special-purpose computer.

[0195] An exemplary readable storage medium is coupled to a processor so that the processor can read information from the readable storage medium and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can be located in an application specific integrated circuit (ASIC). Of course, the processor and the readable storage medium can also exist as discrete components in an electronic device or a main control device.

[0196] An embodiment of the present application also provides a computer program product, including a computer program, which, when executed by a processor, is used to implement the traceability method of the above embodiment.

[0197] The computer program is stored in a readable storage medium. At least one processor can read the computer program from the readable storage medium. At least one processor executes the computer program to execute the solution provided in any of the above embodiments.

[0198] Those skilled in the art can understand that all or part of the steps of the above method embodiments can be completed by hardware related to program instructions. The above program can be stored in a computer-readable storage medium. When the program is executed, the steps of the above method embodiments are executed; and the above storage medium includes: ROM, RAM, disk or optical disk and other media that can store program codes.

[0199] So far, the technical solution of the present application has been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present application is obviously not limited to these specific embodiments, and the above embodiments are only used to illustrate the technical solution of the present application rather than to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or replace some or all of the technical features therein by equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A traceability method, characterized in that: The method comprises: Obtaining a tracing task and multiple tracing data; wherein the tracing task includes a receiving end address and a task type, and the multiple tracing data includes log data and alarm data; Calculate the correlation between the receiving end address and each of the traceability data, and take the traceability data with the correlation greater than a preset first threshold as the safety data; wherein the safety information refers to the abnormal data in the multiple traceability data; Constructing a first path according to the plurality of security data; wherein the first path refers to any one of a plurality of paths from a sending end address to the receiving end address; According to the task type, determine the target data from the multiple traceability data, and determine the target model from the preset multiple analysis models; wherein the target data refers to any one of the multiple traceability data, and the target model refers to any one of the multiple analysis models; Inputting the target data into the target model to obtain a plurality of target addresses; wherein the plurality of target addresses refer to addresses on a plurality of paths from the sending end address to the receiving end address; Constructing a second path according to the multiple target addresses; wherein the second path refers to any one of the multiple paths from the sender address to the receiver address except the first path; A target path is generated according to the first path and the second path; wherein the target path refers to any one of the multiple paths from the sender address to the receiver address except the first path and the second path.

2. The traceability method according to claim 1, characterized in that: The step of constructing a first path according to the plurality of security data comprises: Calculate and obtain portrait data according to the plurality of security data; wherein the portrait data is used to describe the data transmission process between the sending end address and the receiving end address; The first path is constructed according to the multiple traceability data and the portrait data.

3. The traceability method according to claim 1, characterized in that: The step of constructing a second path according to the multiple target addresses includes: Obtaining communication records of the multiple target addresses; The second path is constructed according to the multiple target addresses and the communication record.

4. The traceability method according to claim 1, characterized in that: After generating the target path according to the first path and the second path, the method further includes: Calculate the integrity of the target path according to a preset integrity calculation rule; When the completeness is less than a preset second threshold, creating an adjustment task according to the plurality of traceability data, the traceability task and the completeness; The adjustment task is performed to improve the target path.

5. The traceability method according to claim 1, characterized in that: The obtaining of the traceability task and multiple traceability data includes: Acquire data source data, shared data and the traceability task; wherein the data source data includes flow data and update data, and the shared data includes communication data and configuration data; The data source data and the shared data are preprocessed to obtain the traceability data.

6. The traceability method according to claim 1, characterized in that: The calculating the correlation between the receiving end address and each of the traceability data, and taking the traceability data with the correlation greater than a preset first threshold as the safety data, includes: Acquire address information of each of the traceability data; wherein the address information is used to describe the source of the traceability data; The correlation between the address information of each traceability data and the address of the receiving end is calculated respectively, and the traceability data with the correlation greater than the first threshold is taken as the security data.

7. A traceability device, characterized in that: include: An acquisition module, used to acquire a traceability task and multiple traceability data; wherein the traceability task includes a receiving end address and a task type, and the multiple traceability data includes log data and alarm data; A first calculation module is used to calculate the correlation between the receiving end address and each of the traceability data, and take the traceability data with the correlation greater than a preset first threshold as the safety data; wherein the safety information refers to the abnormal data in the multiple traceability data; A first path building module, configured to build a first path according to the plurality of security data; wherein the first path refers to any one of a plurality of paths from a sending end address to the receiving end address; A determination module, used to determine target data from the plurality of traceability data and determine a target model from a plurality of preset analysis models according to the task type; wherein the target data refers to any one of the plurality of traceability data, and the target model refers to any one of the plurality of analysis models; A second calculation module is used to input the target data into the target model to obtain multiple target addresses; wherein the multiple target addresses refer to addresses on multiple paths from the sending end address to the receiving end address; A second path building module, configured to build a second path according to the multiple target addresses; wherein the second path refers to any one of the multiple paths from the sender address to the receiver address except the first path; A path generation module is used to generate a target path according to the first path and the second path; wherein the target path refers to any one of the multiple paths from the sender address to the receiver address except the first path and the second path.

8. An electronic device, characterized in that: include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; When the processor executes the computer-executable instructions stored in the memory, it is used to implement the traceability method as described in any one of claims 1 to 6.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the traceability method according to any one of claims 1 to 6.

10. A computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program is used to implement the traceability method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Data tracing device, method and system

    CN106909660A

  • Threat automatic association traceability method and system, computer equipment and storage medium

    CN114697106A

  • Sensitive data tracing method, device and equipment

    CN116545709A

  • Data stream tracing method, device and equipment and storage medium

    CN116915519A

  • Interactive traceability analysis method and system based on natural language processing technology

    CN117792671A