Unknown threat alarm method and device, electronic equipment and storage medium
By using a pre-stored session detection model to detect real-time session detection data, the problem of unknown threat detection in the network is solved, timely alarms are achieved and network security is improved.
Patent Information
- Application Number
- CN202510436342.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-09
- Publication Date
- 2025-05-13
AI Technical Summary
The existing technology is difficult to detect and alert unknown threats in the network in a timely manner, such as viruses, Trojans and DDoS attacks, which will threaten the security and interests of individuals and enterprises.
By obtaining real-time session detection data and detecting it based on the pre-stored session detection model, it is determined whether the data is abnormal data. If the detection result is abnormal, an alarm message is displayed. The session detection model is determined based on historical session data, including session time, session number, session traffic, and session quintiles.
It realizes timely detection and alarm of unknown threats in the network, improves network security for individuals and enterprises, and avoids risks that threaten security and interests.
Smart Images

Figure CN119996070A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer network technology, and in particular to an unknown threat warning method, device, electronic device and storage medium. Background Art
[0002] The continuous development of Internet technology has brought convenience to people's lives, but the rapid development of the network has also brought threats. For example, various levels of network threats emerge in an endless stream, and attacks such as viruses, Trojans, and DDoS seriously threaten the safety and interests of individuals and enterprises. Therefore, how to detect abnormal session status in time and display alarms is an urgent problem to be solved. Summary of the invention
[0003] Some embodiments of the present application aim to provide an unknown threat alarm method, device, electronic device and storage medium. Through the technical solution of the embodiments of the present application, real-time session detection data is obtained; according to a pre-stored session detection model, a detection result corresponding to the session detection data is determined, wherein the pre-stored session detection model is determined using historical session data, and the historical session data at least includes session time and the number of sessions corresponding to the session time, session traffic and session quintuple; if the detection result is abnormal data, an alarm message is displayed. In the embodiments of the present application, a session detection model is determined in advance based on historical session data, and then the session detection model is used to detect the real-time collected session detection data to determine whether the real-time collected session detection data is abnormal data. If it is abnormal data, an alarm is displayed, so that abnormal data can be discovered in time to avoid threats to the safety and interests of individuals and enterprises.
[0004] In a first aspect, some embodiments of the present application provide an unknown threat warning method, including: Get real-time session detection data; Determine a detection result corresponding to the session detection data according to a pre-stored session detection model, wherein the pre-stored session detection model is determined by using historical session data, the historical session data at least includes session time and the number of sessions corresponding to the session time, session traffic, and session quintuple, and the pre-stored session detection model is determined by a database or a corresponding relationship determined according to the session time and the number of sessions corresponding to the session time, session traffic, and session quintuple, or is obtained by training a large language model using the session time and the number of sessions corresponding to the session time, session traffic, and session quintuple; If the detection result is abnormal data, an alarm message is displayed.
[0005] In some embodiments of the present application, a session detection model is determined in advance based on historical session data. The pre-stored session detection model is determined based on a database or corresponding relationship determined according to session time and the number of sessions corresponding to the session time, session traffic, and session quintuple, or is obtained by training a large language model using the session time, the number of sessions corresponding to the session time, the session traffic, and the session quintuple. The session detection model is then used to detect session detection data collected in real time to determine whether the session detection data collected in real time is abnormal data. If it is abnormal data, an alarm is displayed, so that abnormal data can be discovered in a timely manner to avoid threats to the safety and interests of individuals and enterprises.
[0006] Optionally, the pre-stored session detection model is determined based on a database or a corresponding relationship determined based on session time and the number of sessions corresponding to the session time, session traffic, and a session quintuple.
[0007] Some embodiments of the present application obtain historical session data of a past period of time, including session time and the number of sessions corresponding to the session time, session traffic, and session quintuples, and perform statistics on the historical session data to obtain corresponding relationships between them, thereby forming a database or table for detecting abnormal data.
[0008] Optionally, the pre-stored session detection model is obtained by training a large language model using session time and the number of sessions corresponding to the session time, session traffic, and session quintuples.
[0009] Some embodiments of the present application train a large language model using historical conversation data to obtain a conversation detection model for detecting abnormal data.
[0010] Optionally, determining, according to a pre-stored session detection model, a detection result corresponding to the session detection data includes: The session detection data is compared with preset detection data in the pre-stored session detection model to obtain a detection result corresponding to the session detection data, wherein the detection result at least includes normal data or abnormal data. In some embodiments of the present application, a session detection model is used to match the session detection data collected in real time, thereby determining whether the session detection data collected in real time is abnormal data, thereby improving the accuracy of abnormal data determination. Optionally, if the detection result is abnormal data, displaying an alarm message includes: If the session detection data does not match the preset detection data, and the session detection data is a multiple of a preset value of the preset detection data, and the duration is greater than a preset time value, the session detection data is determined to be abnormal data, and if the session detection data is determined to be abnormal data, an alarm message is displayed.
[0011] Some embodiments of the present application match the real-time collected session detection data with the preset detection data, and then determine that the session detection data is abnormal data, and display an alarm message, so that the abnormal data can be discovered in time to avoid threatening the safety and interests of individuals and enterprises.
[0012] Optionally, the displaying of warning information includes: The warning information is displayed by email, log or printing.
[0013] Some embodiments of the present application are used to display alarm information by setting multiple alarm modes.
[0014] Optionally, the method further comprises: In the case where it is determined that the detection result is abnormal data, a secondary detection is performed using the pre-stored session detection model, and the detection result is displayed.
[0015] Some embodiments of the present application may also perform secondary detection on the detected abnormal data to improve the accuracy of abnormal data detection.
[0016] In a second aspect, some embodiments of the present application provide an unknown threat warning device, including: An acquisition module is used to obtain real-time session detection data; a determination module, configured to determine a detection result corresponding to the session detection data according to a pre-stored session detection model, wherein the pre-stored session detection model is determined using historical session data, the historical session data at least including session time and the number of sessions corresponding to the session time, session traffic, and session quintuple, and the pre-stored session detection model is determined based on a database or a corresponding relationship determined based on the session time and the number of sessions corresponding to the session time, session traffic, and session quintuple, or is obtained by training a large language model using the session time, the number of sessions corresponding to the session time, the session traffic, and the session quintuple; The alarm module is used to display an alarm message if the detection result is abnormal data.
[0017] In some embodiments of the present application, a session detection model is determined in advance based on historical session data. The pre-stored session detection model is determined based on a database or corresponding relationship determined according to session time and the number of sessions corresponding to the session time, session traffic, and session quintuple, or is obtained by training a large language model using the session time, the number of sessions corresponding to the session time, the session traffic, and the session quintuple. The session detection model is then used to detect session detection data collected in real time to determine whether the session detection data collected in real time is abnormal data. If it is abnormal data, an alarm is displayed, so that abnormal data can be discovered in a timely manner to avoid threats to the safety and interests of individuals and enterprises.
[0018] Optionally, the pre-stored session detection model is determined based on a database or a corresponding relationship determined based on session time and the number of sessions corresponding to the session time, session traffic, and a session quintuple.
[0019] Some embodiments of the present application obtain historical session data of a past period of time, including session time and the number of sessions corresponding to the session time, session traffic, and session quintuples, and perform statistics on the historical session data to obtain corresponding relationships between them, thereby forming a database or table for detecting abnormal data.
[0020] Optionally, the pre-stored session detection model is obtained by training a large language model using session time and the number of sessions corresponding to the session time, session traffic, and session quintuples.
[0021] Some embodiments of the present application train a large language model using historical conversation data to obtain a conversation detection model for detecting abnormal data.
[0022] Optionally, the determining module is used to: The session detection data is compared with preset detection data in the pre-stored session detection model to obtain a detection result corresponding to the session detection data, wherein the detection result at least includes normal data or abnormal data. In some embodiments of the present application, a session detection model is used to match the session detection data collected in real time, thereby determining whether the session detection data collected in real time is abnormal data, thereby improving the accuracy of abnormal data determination. Optionally, the alarm module is used to: If the session detection data does not match the preset detection data, and the session detection data is a multiple of a preset value of the preset detection data, and the duration is greater than a preset time value, the session detection data is determined to be abnormal data, and if the session detection data is determined to be abnormal data, an alarm message is displayed.
[0023] Some embodiments of the present application match the real-time collected session detection data with the preset detection data, and then determine that the session detection data is abnormal data, and display an alarm message, so that the abnormal data can be discovered in time to avoid threatening the safety and interests of individuals and enterprises.
[0024] Optionally, the alarm module is used to: The warning information is displayed by email, log or printing.
[0025] Some embodiments of the present application are used to display alarm information by setting multiple alarm modes.
[0026] Optionally, the alarm module is used to: In the case where it is determined that the detection result is abnormal data, a secondary detection is performed using the pre-stored session detection model, and the detection result is displayed.
[0027] Some embodiments of the present application may also perform secondary detection on the detected abnormal data to improve the accuracy of abnormal data detection.
[0028] In a third aspect, some embodiments of the present application provide an electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the program, the unknown threat warning method as described in any embodiment of the first aspect can be implemented.
[0029] In a fourth aspect, some embodiments of the present application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, can implement the unknown threat warning method as described in any embodiment of the first aspect.
[0030] In a fifth aspect, some embodiments of the present application provide a computer program product, wherein the computer program product includes a computer program, wherein when the computer program is executed by a processor, it can implement the unknown threat warning method as described in any embodiment of the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] In order to more clearly illustrate the technical solutions of some embodiments of the present application, the drawings required for use in some embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0032] Figure 1 A flowchart of an unknown threat warning method provided in an embodiment of the present application; Figure 2 A schematic diagram of the structure of an unknown threat warning device provided in an embodiment of the present application; Figure 3 A schematic diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0033] The technical solutions in some embodiments of the present application will be described below in conjunction with the drawings in some embodiments of the present application.
[0034] It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.
[0035] With the continuous development of Internet technology, it has brought convenience to people's lives, but the rapid development of the network has also brought threats. For example, network threats at various levels emerge in an endless stream, and attacks such as viruses, Trojans, and DDoS seriously threaten the safety and interests of individuals and enterprises. Therefore, how to detect abnormal states in a timely manner and display alarms is a problem that needs to be solved urgently. In view of this, some embodiments of the present application provide an alarm method for unknown threats, which includes: obtaining real-time session detection data; determining a detection result corresponding to the session detection data according to a pre-stored session detection model, wherein the pre-stored session detection model is determined using historical session data, and the historical session data at least includes the session time and the number of sessions corresponding to the session time, the session traffic, and the session five-tuple; if the detection result is abnormal data, then display the alarm information. In the embodiment of the present application, the session detection model is determined in advance according to the historical session data, and then the session detection model is used to detect the real-time collected session detection data, and it is determined whether the real-time collected session detection data is abnormal data. If it is abnormal data, then display the alarm, so that the abnormal data can be discovered in time to avoid threatening the safety and interests of individuals and enterprises.
[0036] like Figure 1 As shown, an embodiment of the present application provides an unknown threat warning method, the method comprising: S101, obtaining real-time session detection data; Specifically, an embodiment of the present application is applied to a server, which is connected to multiple terminal devices. The server can be a gateway, and the gateway obtains session detection data sent by each terminal device in real time, wherein the session detection data includes at least one or more of the number of sessions, session traffic, source IP address, destination IP address, source port, destination port or transport layer protocol. In the specific implementation process, the user can select one or more of the session detection data. For example, if it is desired to detect the number of sessions in the session detection data, the gateway obtains the number of sessions in the session detection data. If it is desired to detect the session traffic in the session detection data, the gateway obtains the session traffic in the session detection data. In this way, it can be set according to user needs or business needs to meet different business needs.
[0037] S102. Determine a detection result corresponding to the session detection data according to a pre-stored session detection model, wherein the pre-stored session detection model is determined by using historical session data, and the historical session data at least includes session time and the number of sessions corresponding to the session time, session traffic, and session quintuple; the pre-stored session detection model is determined by a database or a corresponding relationship determined according to the session time and the number of sessions corresponding to the session time, session traffic, and session quintuple, or is obtained by training a large language model using the session time and the number of sessions corresponding to the session time, session traffic, and session quintuple; Specifically, the gateway pre-acquires historical session data for a period of time, which includes at least the number of sessions, session traffic and session quintuples, and constructs a session detection model based on the correspondence between session time and the number of sessions, session traffic and session quintuples.
[0038] After acquiring the real-time session detection data, the gateway compares the session detection data with the preset detection data in the pre-stored session detection model to obtain the detection result.
[0039] Moreover, in the specific implementation process, the session detection data obtained in real time can be determined according to business needs. For example, if the number of sessions is obtained, the gateway compares the number of sessions with the preset number of sessions in the pre-stored session detection model to obtain the detection result.
[0040] For example, if the number of preset sessions in the pre-stored session detection model is 1000 during working days, and the session detection data acquired by the gateway in real time is 10000, 1000 and 10000 are compared to obtain the detection result.
[0041] S103. If the detection result is abnormal data, an alarm message is displayed.
[0042] Specifically, the gateway compares the session detection data with the preset detection data. If the session detection data matches the preset detection data, the session detection data is determined to be normal data. If the session detection data does not match the preset detection data, the session detection data is determined to be abnormal data and an alarm message is displayed.
[0043] Some embodiments of the present application determine a session detection model in advance based on historical session data, and then use the session detection model to detect session detection data collected in real time to determine whether the session detection data collected in real time is abnormal data. If it is abnormal data, an alarm is displayed, so that abnormal data can be discovered in time to avoid threats to the safety and interests of individuals and enterprises.
[0044] Another embodiment of the present application further supplements the unknown threat warning method provided in the above embodiment.
[0045] Optionally, the pre-stored session detection model is determined based on a database or corresponding relationship determined based on session time and the number of sessions corresponding to the session time, session traffic, and a session quintuple.
[0046] Specifically, the gateway collects statistics on the acquired session time for a period of time and the number of sessions corresponding to the session time, the session traffic, and the session quintuple, which can be saved as a database or a data table.
[0047] Some embodiments of the present application obtain historical session data of a past period of time, including session time and the number of sessions corresponding to the session time, session traffic, and session quintuples, and perform statistics on the historical session data to obtain corresponding relationships between them, thereby forming a database or table for detecting abnormal data.
[0048] Optionally, the pre-stored session detection model is obtained by training a large language model using session time and the number of sessions corresponding to the session time, session traffic, and session quintuples.
[0049] Among them, large language models use large-scale data sets to train models, enabling them to generate natural language text or understand the meaning of language text. These models learn and simulate the complex laws of human language through a stacked neural network structure, achieving text generation capabilities close to human levels.
[0050] Some embodiments of the present application train a large language model using historical conversation data to obtain a conversation detection model for detecting abnormal data.
[0051] Optionally, determining a detection result corresponding to the session detection data according to a pre-stored session detection model includes: The session detection data is compared with preset detection data in a pre-stored session detection model to obtain a detection result corresponding to the session detection data, and the detection result at least includes normal data or abnormal data.
[0052] Among them, the session detection data obtained by the gateway in real time can be set according to different business needs. If the number of sessions needs to be detected, the session detection data is the number of sessions; if the source IP address needs to be detected, the session detection data is the source IP address, etc.
[0053] Depending on the business needs, the pre-stored session detection model used is also different. If the number of sessions is detected, the pre-stored session detection model is the preset number of sessions. If the source IP address is detected, the pre-stored session detection model is the preset source IP address.
[0054] In some embodiments of the present application, a session detection model is used to match the session detection data collected in real time, thereby determining whether the session detection data collected in real time is abnormal data, thereby improving the accuracy of abnormal data determination. Optionally, if the detection result is abnormal data, an alarm message is displayed, including: If the session detection data does not match the preset detection data, and the session detection data is a multiple of the preset value of the preset detection data, and the duration is greater than the preset time value, the session detection data is determined to be abnormal data. If the session detection data is determined to be abnormal data, an alarm message is displayed.
[0055] Some embodiments of the present application match the real-time collected session detection data with the preset detection data, and then determine that the session detection data is abnormal data, and display an alarm message, so that the abnormal data can be discovered in time to avoid threatening the safety and interests of individuals and enterprises.
[0056] Optionally, display warning information, including: The alarm information is displayed by email, log or printing.
[0057] Some embodiments of the present application are used to display alarm information by setting multiple alarm modes.
[0058] Optionally, the method further comprises: When it is determined that the detection result is abnormal data, a pre-stored session detection model is used to perform a secondary detection and the detection result is displayed.
[0059] When the session detection data is detected to be abnormal data, further detection may be performed on the data to prevent detection errors.
[0060] Some embodiments of the present application may also perform secondary detection on the detected abnormal data to improve the accuracy of abnormal data detection.
[0061] Specifically, in the embodiment of the present application, the security gateway is connected to multiple client terminals, and a session traffic model is set at the entrance of the security gateway. The session traffic model, i.e., the session detection model, is obtained by training a large language model using historical session data, and is trained according to user needs. For example, it can be the number of sessions, or the bandwidth, a five-tuple, etc. The five-tuple includes the source IP address, the destination IP address, the source port, the destination port, and the transport layer protocol; The session traffic model obtains historical session data, which is the session data volume and bandwidth data for a period of time in the past. For example, a week's data is obtained, and the number of sessions on Monday is 1k, the number of sessions on Tuesday is 2k, the number of sessions on Wednesday is 1k, the number of sessions on Thursday is 1.5k, and the number of sessions on Friday is 2k. In this way, the large language model is trained based on these session numbers to obtain the session traffic model.
[0062] 2. In actual applications, the number of sessions is obtained in real time, and the number of sessions is judged based on the number of sessions and the pre-established session traffic model. If the number of sessions matches the session traffic model, it means that the number of sessions is a normal session. If the number of sessions does not match the session traffic model, for example, the number of sessions is n times of a preset value or a preset range, illustratively, n is a natural number greater than 10, it means that the number of sessions is an abnormal session. The duration can also be judged.
[0063] 3. Perform secondary detection on the abnormal sessions. For example, determine whether the abnormal meeting place is truly abnormal based on the actual situation. If a meeting is to be held on a certain day and the number of sessions is 100,000, this is not considered abnormal.
[0064] 4. If an abnormal session is detected, an alarm can be issued by email, sislog or printing.
[0065] It should be noted that each implementable method in this embodiment may be implemented separately, or may be implemented in combination in any combination without conflict, and this application is not limited thereto.
[0066] Another embodiment of the present application provides an unknown threat warning device, which is used to execute the unknown threat warning method provided by the above embodiment.
[0067] like Figure 2 2 is a schematic diagram of the structure of the unknown threat alarm device provided in the embodiment of the present application. The unknown threat alarm device includes an acquisition module 201, a determination module 202 and an alarm module 203, wherein: The acquisition module 201 is used to acquire real-time session detection data; The determination module 202 is used to determine the detection result corresponding to the session detection data according to a pre-stored session detection model, wherein the pre-stored session detection model is determined by using historical session data, and the historical session data at least includes session time and the number of sessions corresponding to the session time, session traffic, and session quintuple, and the pre-stored session detection model is determined by a database or a corresponding relationship determined according to the session time and the number of sessions corresponding to the session time, session traffic, and session quintuple, or is obtained by training a large language model using the session time and the number of sessions corresponding to the session time, session traffic, and session quintuple; The alarm module 203 is used to display an alarm message if the detection result is abnormal data.
[0068] Regarding the device in this embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.
[0069] Some embodiments of the present application determine a session detection model in advance based on historical session data, and then use the session detection model to detect session detection data collected in real time to determine whether the session detection data collected in real time is abnormal data. If it is abnormal data, an alarm is displayed, so that abnormal data can be discovered in time to avoid threats to the safety and interests of individuals and enterprises.
[0070] Another embodiment of the present application further supplements the unknown threat warning device provided in the above embodiment.
[0071] Optionally, the pre-stored session detection model is determined based on a database or corresponding relationship determined based on session time and the number of sessions corresponding to the session time, session traffic, and a session quintuple.
[0072] Some embodiments of the present application obtain historical session data of a past period of time, including session time and the number of sessions corresponding to the session time, session traffic, and session quintuples, and perform statistics on the historical session data to obtain corresponding relationships between them, thereby forming a database or table for detecting abnormal data.
[0073] Optionally, the pre-stored session detection model is obtained by training a large language model using session time and the number of sessions corresponding to the session time, session traffic, and session quintuples.
[0074] Some embodiments of the present application train a large language model using historical conversation data to obtain a conversation detection model for detecting abnormal data.
[0075] Optionally, a module is determined to: The session detection data is compared with preset detection data in a pre-stored session detection model to obtain a detection result corresponding to the session detection data, and the detection result at least includes normal data or abnormal data. In some embodiments of the present application, a session detection model is used to match the session detection data collected in real time, thereby determining whether the session detection data collected in real time is abnormal data, thereby improving the accuracy of abnormal data determination. Optionally, the alarm module is used to: If the session detection data does not match the preset detection data, and the session detection data is a multiple of the preset value of the preset detection data, and the duration is greater than the preset time value, the session detection data is determined to be abnormal data. If the session detection data is determined to be abnormal data, an alarm message is displayed.
[0076] Some embodiments of the present application match the real-time collected session detection data with the preset detection data, and then determine that the session detection data is abnormal data, and display an alarm message, so that the abnormal data can be discovered in time to avoid threatening the safety and interests of individuals and enterprises.
[0077] Optionally, the alarm module is used to: The alarm information is displayed by email, log or printing.
[0078] Some embodiments of the present application are used to display alarm information by setting multiple alarm modes.
[0079] Optionally, the alarm module is used to: When it is determined that the detection result is abnormal data, a pre-stored session detection model is used to perform a secondary detection and the detection result is displayed.
[0080] Some embodiments of the present application may also perform secondary detection on the detected abnormal data to improve the accuracy of abnormal data detection.
[0081] Regarding the device in this embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.
[0082] It should be noted that each implementable method in this embodiment may be implemented separately, or may be implemented in combination in any combination without conflict, and this application is not limited thereto.
[0083] An embodiment of the present application further provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the operation of the method corresponding to any embodiment of the unknown threat warning method provided in the above embodiments can be implemented.
[0084] An embodiment of the present application further provides a computer program product, wherein the computer program product includes a computer program, wherein when the computer program is executed by a processor, it can implement the operations corresponding to the method of any embodiment of the unknown threat warning method provided in the above embodiments.
[0085] like Figure 3 As shown, some embodiments of the present application provide an electronic device 300, which includes: a memory 310, a processor 320, and a computer program stored in the memory 310 and executable on the processor 320, wherein the processor 320 can implement any of the embodiments of the unknown threat alarm method as described above when reading the program from the memory 310 through a bus 330 and executing the program.
[0086] Processor 320 can process digital signals and can include various computing structures, such as complex instruction set computer structure, reduced instruction set computer structure, or a structure that implements a combination of multiple instruction sets. In some examples, processor 320 can be a microprocessor.
[0087] The memory 310 may be used to store instructions executed by the processor 320 or data related to the execution of instructions. These instructions and / or data may include codes for implementing some or all functions of one or more modules described in the embodiments of the present application. The processor 320 of the disclosed embodiment may be used to execute instructions in the memory 310 to implement the method shown above. The memory 310 includes a dynamic random access memory, a static random access memory, a flash memory, an optical memory, or other memory known to those skilled in the art.
[0088] The above are only embodiments of the present application and are not intended to limit the scope of protection of the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings.
[0089] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
[0090] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.
Claims
1. A warning method for unknown threats, characterized in that: The method comprises: Acquire real-time session detection data, wherein the session detection data includes at least one or more of the number of sessions, session traffic, source IP address, destination IP address, source port, destination port or transport layer protocol; Determine a detection result corresponding to the session detection data according to a pre-stored session detection model, wherein the pre-stored session detection model is determined by using historical session data, the historical session data at least includes session time and the number of sessions corresponding to the session time, session traffic, and session quintuple, and the pre-stored session detection model is determined by a database or a corresponding relationship determined according to the session time and the number of sessions corresponding to the session time, session traffic, and session quintuple, or is obtained by training a large language model using the session time and the number of sessions corresponding to the session time, session traffic, and session quintuple; If the detection result is abnormal data, an alarm message is displayed.
2. The unknown threat warning method according to claim 1, characterized in that: The determining, according to the pre-stored session detection model, a detection result corresponding to the session detection data includes: The session detection data is compared with preset detection data in the pre-stored session detection model to obtain a detection result corresponding to the session detection data, wherein the detection result at least includes normal data or abnormal data.
3. The unknown threat warning method according to claim 2, characterized in that: If the detection result is abnormal data, an alarm message is displayed, including: If the session detection data does not match the preset detection data, and the session detection data is a multiple of a preset value of the preset detection data, and the duration is greater than a preset time value, the session detection data is determined to be abnormal data, and if the session detection data is determined to be abnormal data, an alarm message is displayed.
4. The unknown threat warning method according to claim 1, characterized in that: The display of warning information includes: The warning information is displayed by email, log or printing.
5. The unknown threat warning method according to claim 1, characterized in that: The method further comprises: In the case where it is determined that the detection result is abnormal data, a secondary detection is performed using the pre-stored session detection model, and the detection result is displayed.
6. An unknown threat warning device, characterized in that: The device comprises: An acquisition module, used to acquire real-time session detection data, wherein the session detection data includes at least one or more of the number of sessions, session traffic, source IP address, destination IP address, source port, destination port or transport layer protocol; a determination module, configured to determine a detection result corresponding to the session detection data according to a pre-stored session detection model, wherein the pre-stored session detection model is determined using historical session data, the historical session data at least including session time and the number of sessions corresponding to the session time, session traffic, and session quintuple, and the pre-stored session detection model is determined based on a database or a corresponding relationship determined based on the session time and the number of sessions corresponding to the session time, session traffic, and session quintuple, or is obtained by training a large language model using the session time, the number of sessions corresponding to the session time, the session traffic, and the session quintuple; The alarm module is used to display an alarm message if the detection result is abnormal data.
7. The unknown threat warning device according to claim 6, characterized in that: The determining module is used to: The session detection data is compared with preset detection data in the pre-stored session detection model to obtain a detection result corresponding to the session detection data, wherein the detection result at least includes normal data or abnormal data.
8. The unknown threat warning device according to claim 7, characterized in that: The alarm module is used to: If the session detection data does not match the preset detection data, and the session detection data is a multiple of a preset value of the preset detection data, and the duration is greater than a preset time value, the session detection data is determined to be abnormal data, and if the session detection data is determined to be abnormal data, an alarm message is displayed.
9. An electronic device, characterized in that: The invention comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor can implement the unknown threat warning method as described in any one of claims 1 to 5 when executing the program.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein when the program is executed by a processor, the unknown threat warning method described in any one of claims 1 to 5 can be implemented.
Citation Information
Patent Citations
Network abnormal data detection method and device, computer equipment and storage medium
CN108259482A
Multimedia information transmission method and apparatus, terminal, and readable storage medium
CN109688258A
Traffic detection method and device, electronic equipment and storage medium
CN111181923A
Method and device for detecting anomaly of intelligent dialogue system, medium and equipment
CN115455166A
Packet capture flow anomaly identification method, device, equipment and medium
CN119232475A
Cited By
Model training method and apparatus, service processing method and apparatus, storage medium, and device
US12718024B2