Real-time network security monitoring protection method and system based on deep learning
Through a deep learning-based method, CNN and LSTM are used to identify network attack types and adjust protection levels in real time according to attack strength and risk scores, the problem that traditional network security technologies are difficult to cope with complex network attacks is solved, and the overall efficiency and accuracy of network security management is improved.
Patent Information
- Application Number
- CN202510038844.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-10
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-01-10
AI Technical Summary
Traditional network security defense technologies are difficult to deal with complex and changeable cyber attacks, they cannot analyze and take protective measures in real time, and they cannot adjust protective measures according to real-time situations.
The real-time network security monitoring and protection method based on deep learning is adopted to extract local features of network traffic through convolutional neural network (CNN), and time-sequential feature analysis is used to identify network attack types, and the protection level is adjusted in real time according to the attack intensity and risk score.
Real-time analysis of network traffic and accurate identification of attack types are achieved, the accuracy of network attack detection and classification is improved, network security risks are reduced, and customized and optimized according to different network environments and security needs.
Smart Images

Figure CN120017320A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security protection technology, and in particular to a real-time network security monitoring and protection method and system based on deep learning. Background Art
[0002] With the rapid development of the Internet and the widespread application of information technology, network security issues have become increasingly prominent. Traditional security defense technologies are often unable to cope with complex and changeable network attacks, such as advanced persistent threat (APT) attacks and phishing attacks, which pose a great threat to the network security environment. In addition, traditional network attack defense technologies cannot perform real-time analysis of network attacks and automatically take corresponding protective measures, nor can they adjust protective measures according to the real-time network attack situation. Therefore, the development of an intelligent network security system that can monitor network traffic in real time, automatically identify attack types and take protective measures is of great significance to ensuring network security.
[0003] In response to the above problems, this application proposes a real-time network security monitoring and protection method and system based on deep learning. Summary of the invention
[0004] The present invention proposes the following technical solutions to address one or more technical deficiencies in the above-mentioned prior art.
[0005] Based on the first aspect of the present application, a real-time network security monitoring and protection method based on deep learning is proposed, comprising:
[0006] S1: extract local features of network traffic through convolutional neural network CNN, determine whether the network traffic is abnormal, use long short-term memory network LSTM to perform time series feature analysis on abnormal network traffic, and identify the type of network attack;
[0007] S2: Calculate the intensity of the network attack based on the traffic rate, duration and number of source IP addresses of the network attack, and classify the intensity of the network attack into low intensity, medium intensity and high intensity;
[0008] The calculation formula of the intensity of the network attack is:
[0009] Ascore=W R ×R+W T ×T+W I ×I;
[0010] Among them, Ascore is the intensity of network attack, W R is the weight of the traffic rate, W T is the weight of the network attack duration, W Iis the weight of the number of source IP addresses of network attacks; R is the traffic rate, T is the duration of network attacks, and I is the number of source IP addresses of network attacks;
[0011] S3: Calculating a risk score based on the local characteristics of the network traffic, and classifying the attack risk of the network traffic into low risk, medium risk and high risk;
[0012] The risk score is calculated as follows:
[0013] Rscore=Wx1×x1+Wx2×x2+……+Wx n × n ;
[0014] Among them, Rscore is the risk score, Wx1, Wx2, Wx n are the weights of the local features of the network traffic, x1, x2, x n is a local feature of the network traffic;
[0015] S4: performing weighted calculation on the risk score and the intensity of the network attack to obtain a comprehensive score;
[0016] The calculation formula of the comprehensive score is:
[0017] Tscore=(W1×Ascore)+(W2×Rscore)
[0018] Among them, W1 is the weight of the intensity of the network attack, and W2 is the weight of the risk score;
[0019] S5: In response to different types of network attacks and in combination with the comprehensive scores of different types of network attacks, different network attack protection measures are executed. Specifically,
[0020] For network attacks caused by malicious behaviors of suspicious IP or IP segments, use iptables or firewall to restrict network access of suspicious IP or IP segments, and use GeoIP to block traffic from the area where the suspicious IP or IP segment belongs.
[0021] For network attacks caused by malicious requests of XSS and SQL injection, define rules through Web application firewall to block malicious requests, and use Ngnix to limit the frequency of malicious requests from the same IP address.
[0022] For large-scale DDos attacks, redirect network attack traffic to third-party cleaning services to filter malicious traffic;
[0023] For network attacks caused by abnormal traffic, configure request limits for abnormal traffic in the Web server and limit the number of requests for abnormal traffic through the mod_evasive module of Apache;
[0024] S6: Adjust the protection level in real time according to the intensity of the network attack and the risk score, record the network attack information and protection measures in real time and generate a security log.
[0025] This application can analyze the flow of network data in real time, identify attack types and take corresponding protective measures, thereby improving the accuracy of network attack detection and classification and reducing network security risks.
[0026] Furthermore, the protection level is adjusted in real time according to the intensity and risk score of the network attack. Specifically,
[0027] When the intensity of the network attack is low (Ascore<20), log recording is performed and an alarm is triggered;
[0028] When the intensity of the network attack is medium (20≤Ascore<50), limit the frequency of malicious requests from the IP or increase the network bandwidth;
[0029] When the intensity of the network attack is high (Ascore≥50), firewall definition rule measures, traffic cleaning services or temporary isolation of some network nodes are enabled.
[0030] Real-time protection measures at different levels according to the intensity of different network attacks can help concentrate network resources to combat network attacks and arrange network resources reasonably.
[0031] Furthermore, the real-time adjustment of the protection level according to the intensity and risk score of the network attack also includes:
[0032] When the risk score is low risk (Rscore<3), no action is taken;
[0033] When the risk score is medium risk (3≤Rscore<6), the request for abnormal traffic is restricted;
[0034] When the risk score is high risk (Rscore≥6), traffic cleaning or DDos protection measures are performed.
[0035] Taking different levels of protection for different risks is conducive to the rational adjustment of network resources, concentrating resources to attack when the network risk is too high, and further waiting for network attacks and responding when the network risk is low.
[0036] Furthermore, local features of network traffic are extracted through a convolutional neural network (CNN) to determine whether the network traffic is abnormal. Specifically, user behavior features and network topology features are converted into numerical feature vectors through one-hot encoding or embedding methods, and the numerical feature vectors are merged with local features of the network traffic to obtain a feature matrix, which is input into a convolutional neural network (CNN) to determine and extract abnormal behavior of the network traffic.
[0037] Using convolutional neural networks to identify abnormal behavior of network traffic can adaptively adjust network training parameters when facing different attack types, set different reward functions, achieve the best abnormal behavior detection effect, and identify the static characteristics of network traffic.
[0038] Furthermore, the long short-term memory network LSTM is used to perform time series feature analysis on abnormal network traffic. Specifically, the abnormal network traffic data is divided into time windows of fixed length, and the characteristics of the number of data packets, number of bytes, average traffic size, frequency of use of network protocols and number of connections of the network traffic are extracted and standardized within the time window. The network traffic trend and network attacks in a certain period of time in the future are analyzed through the sliding window of the LSTM network, and the behavioral characteristics and time series characteristics of the network attacks are captured.
[0039] The long short-term memory network (LSTM) can capture the attack behavior characteristics of network traffic at different time sequences and identify the time dependency and complex and continuous attack patterns in network traffic data.
[0040] Furthermore, the content of the security log includes the log ID, network attack event timestamp, network attack event type, network attack information, protection measures taken against network attacks, response time of network attack events, and impact scope of network attack events.
[0041] Furthermore, the network attack information includes the network attack source IP and target IP, network attack time and network attack method.
[0042] Based on the second aspect of the present application, a real-time network security monitoring and protection system based on deep learning is also proposed, including an identification module a, a strength module b, a risk module c, a comprehensive module d, a response module e and a log module f.
[0043] In a specific embodiment, the identification module a is configured to: extract local features of network traffic through a convolutional neural network CNN, determine whether the network traffic is abnormal, use a long short-term memory network LSTM to perform time series feature analysis on abnormal network traffic, and identify the type of network attack.
[0044] In a specific embodiment, the intensity module b is configured to: calculate the intensity of the network attack based on the traffic rate, duration and number of source IPs of the network attack, and divide the intensity of the network attack into low intensity, medium intensity and high intensity;
[0045] The calculation formula of the intensity of the network attack is:
[0046] Ascore=W R ×R+W T ×T+W I ×I;
[0047] Among them, Ascore is the intensity of network attack, W R is the weight of the traffic rate, W T is the weight of the network attack duration, W I is the weight of the number of source IP addresses of network attacks; R is the traffic rate, T is the duration of network attacks, and I is the number of source IP addresses of network attacks.
[0048] In a specific embodiment, the risk module c is configured to: calculate a risk score based on the local characteristics of the network traffic, and classify the attack risk of the network traffic into low risk, medium risk and high risk;
[0049] The risk score is calculated as follows:
[0050] Rscore=Wx1×x1+Wx2×x2+……+Wx n × n ;
[0051] Among them, Rscore is the risk score, Wx1, Wx2, Wx n are the weights of the local features of the network traffic, x1, x2, x n is a local feature of the network traffic.
[0052] In a specific embodiment, the comprehensive module d is configured to: perform weighted calculation on the risk score and the intensity of the network attack to obtain a comprehensive score;
[0053] The calculation formula of the comprehensive score is:
[0054] Tscore=(W1×Ascore)+(W2×Rscore)
[0055] Among them, W1 is the weight of the intensity of the network attack, and W2 is the weight of the risk score;.
[0056] In a specific embodiment, the response module e is configured to: respond to different types of network attacks and execute different network attack protection measures in combination with the comprehensive scores of different types of network attacks. Specifically,
[0057] For network attacks caused by malicious behaviors of suspicious IP or IP segments, use iptables or firewall to restrict network access of suspicious IP or IP segments, and use GeoIP to block traffic from the area where the suspicious IP or IP segment belongs.
[0058] For network attacks caused by malicious requests of XSS and SQL injection, define rules through Web application firewall to block malicious requests, and use Ngnix to limit the frequency of malicious requests from the same IP address.
[0059] For large-scale DDos attacks, redirect network attack traffic to third-party cleaning services to filter malicious traffic;
[0060] For network attacks caused by abnormal traffic, configure request limits for abnormal traffic in the Web server and limit the number of requests for abnormal traffic through Apache's mod_evasive module.
[0061] In a specific embodiment, the log module f is configured to: adjust the protection level in real time according to the intensity of the network attack and the risk score, record the network attack information and protection measures in real time and generate a security log.
[0062] Based on the third aspect of the present application, a computer program product is also proposed, which has one or more computer programs thereon, and when the computer program is executed by a computer processor, implements any of the methods described above.
[0063] The technical effect of the present invention is that: the present application improves the overall efficiency and accuracy of network security management by performing real-time analysis of network traffic, can effectively detect, analyze and respond to network attacks in real time, and can also optimize network attack protection measures according to the intensity and risk level of network attacks through data mining and predictive analysis, improve the accuracy of attack detection and classification, reduce network security risks, and can be customized and optimized according to different network environments and security requirements, making network attack protection flexible. BRIEF DESCRIPTION OF THE DRAWINGS
[0064] Other features, objects and advantages of the present application will become more apparent from the detailed description of non-limiting embodiments made with reference to the following drawings.
[0065] Figure 1It is a flowchart of a real-time network security monitoring and protection method based on deep learning provided according to an embodiment of the present invention.
[0066] Figure 2 It is a framework diagram of a real-time network security monitoring and protection system based on deep learning provided according to an embodiment of the present invention.
[0067] Figure 3 A schematic diagram of the structure of a computer system suitable for implementing an electronic device of an embodiment of the present application is shown. DETAILED DESCRIPTION
[0068] The present application will be further described in detail below in conjunction with the accompanying drawings and embodiments. It is to be understood that the specific embodiments described herein are only used to explain the relevant invention, rather than to limit the invention. It should also be noted that, for ease of description, only the parts related to the relevant invention are shown in the accompanying drawings.
[0069] It should be noted that, in the absence of conflict, the embodiments and features in the embodiments of the present application can be combined with each other. The present application will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0070] Figure 1 It is shown that the present application proposes a real-time network security monitoring and protection method based on deep learning, including:
[0071] S1: extract local features of network traffic through convolutional neural network CNN, determine whether the network traffic is abnormal, use long short-term memory network LSTM to perform time series feature analysis on abnormal network traffic, and identify the type of network attack;
[0072] S2: Calculate the intensity of the network attack based on the traffic rate, duration and number of source IP addresses of the network attack, and classify the intensity of the network attack into low intensity, medium intensity and high intensity;
[0073] The calculation formula of the intensity of the network attack is:
[0074] Ascore=W R ×R+W T ×T+W I ×I;
[0075] Among them, Ascore is the intensity of network attack, W R is the weight of the traffic rate, W T is the weight of the network attack duration, W I is the weight of the number of source IP addresses of network attacks; R is the traffic rate, T is the duration of network attacks, and I is the number of source IP addresses of network attacks;
[0076] S3: Calculating a risk score based on the local characteristics of the network traffic, and classifying the attack risk of the network traffic into low risk, medium risk and high risk;
[0077] The risk score is calculated as follows:
[0078] Rscore=Wx1×x1+Wx2×x2+……+Wx n × n ;
[0079] Among them, Rscore is the risk score, Wx1, Wx2, Wx n are the weights of the local features of the network traffic, x1, x2, x n is a local feature of the network traffic;
[0080] S4: performing weighted calculation on the risk score and the intensity of the network attack to obtain a comprehensive score;
[0081] The calculation formula of the comprehensive score is:
[0082] Tscore=(W1×Ascore)+(W2×Rscore)
[0083] Among them, W1 is the weight of the intensity of the network attack, and W2 is the weight of the risk score;
[0084] S5: In response to different types of network attacks and in combination with the comprehensive scores of different types of network attacks, different network attack protection measures are executed. Specifically,
[0085] For network attacks caused by malicious behaviors of suspicious IP or IP segments, use iptables or firewall to restrict network access of suspicious IP or IP segments, and use GeoIP to block traffic from the area where the suspicious IP or IP segment belongs.
[0086] For network attacks caused by malicious requests such as XSS and SQL injection, define rules through the Web application firewall to block malicious requests, and use Nginx to limit the frequency of malicious requests from the same IP address.
[0087] For large-scale DDos attacks, redirect network attack traffic to third-party cleaning services to filter malicious traffic;
[0088] For network attacks caused by abnormal traffic, configure request limits for abnormal traffic in the Web server and limit the number of requests for abnormal traffic through the mod_evasive module of Apache;
[0089] S6: Adjust the protection level in real time according to the intensity of the network attack and the risk score, record the network attack information and protection measures in real time and generate a security log.
[0090] It should be noted that the protection level is adjusted in real time according to the intensity and risk score of the network attack. Specifically,
[0091] When the intensity of the network attack is low (Ascore<20), log recording is performed and an alarm is triggered;
[0092] When the intensity of the network attack is medium (20≤Ascore<50), limit the frequency of malicious requests from the IP or increase the network bandwidth;
[0093] When the intensity of the network attack is high (Ascore≥50), firewall definition rule measures, traffic cleaning services or temporary isolation of some network nodes are enabled.
[0094] It should be noted that the real-time adjustment of the protection level according to the intensity and risk score of the network attack also includes:
[0095] When the risk score is low risk (Rscore<3), no action is taken;
[0096] When the risk score is medium risk (3≤Rscore<6), the request for abnormal traffic is restricted;
[0097] When the risk score is high risk (Rscore≥6), traffic cleaning or DDos protection measures are performed.
[0098] It should be noted that the local features of network traffic are extracted by convolutional neural network (CNN) to determine whether the network traffic is abnormal. Specifically, user behavior features and network topology features are converted into numerical feature vectors through one-hot encoding or embedding methods, and the numerical feature vectors are merged with the local features of the network traffic to obtain a feature matrix, which is input into the convolutional neural network (CNN) to determine and extract abnormal behavior of the network traffic.
[0099] It should be noted that the use of the long short-term memory network LSTM to perform time series feature analysis on abnormal network traffic is specifically to divide the abnormal network traffic data into time windows of fixed length, extract the number of data packets, number of bytes, average traffic size, frequency of use of network protocols and number of connections in the time window and standardize them, analyze the network traffic trend and network attacks in a certain period of time in the future through the sliding window of the LSTM network, and capture the behavioral characteristics and time series characteristics of network attacks.
[0100] It should be noted that the content of the security log includes the log ID, network attack event timestamp, network attack event type, network attack information, protection measures taken against network attacks, response time of network attack events, and impact scope of network attack events.
[0101] It should be noted that the network attack information includes the network attack source IP and target IP, network attack time and network attack method.
[0102] Figure 2 A real-time network security monitoring and protection system based on deep learning is shown, including an identification module a, a strength module b, a risk module c, a comprehensive module d, a response module e, and a log module f.
[0103] In a specific embodiment, the identification module a is configured to: extract local features of network traffic through a convolutional neural network CNN, determine whether the network traffic is abnormal, use a long short-term memory network LSTM to perform time series feature analysis on abnormal network traffic, and identify the type of network attack.
[0104] In a specific embodiment, the intensity module b is configured to: calculate the intensity of the network attack based on the traffic rate, duration and number of source IPs of the network attack, and divide the intensity of the network attack into low intensity, medium intensity and high intensity;
[0105] The calculation formula of the intensity of the network attack is:
[0106] Ascore=W R ×R+W T ×T+W I ×I;
[0107] Among them, Ascore is the intensity of network attack, W R is the weight of the traffic rate, W T is the weight of the network attack duration, W I is the weight of the number of source IP addresses of network attacks; R is the traffic rate, T is the duration of network attacks, and I is the number of source IP addresses of network attacks.
[0108] In a specific embodiment, the risk module c is configured to: calculate a risk score based on the local characteristics of the network traffic, and classify the attack risk of the network traffic into low risk, medium risk and high risk;
[0109] The risk score is calculated as follows:
[0110] Rscore=Wx1×x1+Wx2×x2+……+Wx n × n ;
[0111] Among them, Rscore is the risk score, Wx1, Wx2, Wx n are the weights of the local features of the network traffic, x1, x2, x n is a local feature of the network traffic.
[0112] In a specific embodiment, the comprehensive module d is configured to: perform weighted calculation on the risk score and the intensity of the network attack to obtain a comprehensive score;
[0113] The calculation formula of the comprehensive score is:
[0114] Tscore=(W1×Ascore)+(W2×Rscore)
[0115] Among them, W1 is the weight of the intensity of the network attack, and W2 is the weight of the risk score.
[0116] In a specific embodiment, the response module e is configured to: respond to different types of network attacks and execute different network attack protection measures in combination with the comprehensive scores of different types of network attacks. Specifically,
[0117] For network attacks caused by malicious behaviors of suspicious IP or IP segments, use iptables or firewall to restrict network access of suspicious IP or IP segments, and use GeoIP to block traffic from the area where the suspicious IP or IP segment belongs.
[0118] For network attacks caused by malicious requests of XSS and SQL injection, define rules through Web application firewall to block malicious requests, and use Ngnix to limit the frequency of malicious requests from the same IP address.
[0119] For large-scale DDos attacks, redirect network attack traffic to third-party cleaning services to filter malicious traffic;
[0120] For network attacks caused by abnormal traffic, configure request limits for abnormal traffic in the Web server and limit the number of requests for abnormal traffic through Apache's mod_evasive module.
[0121] In a specific embodiment, the log module f is configured to: adjust the protection level in real time according to the intensity of the network attack and the risk score, record the network attack information and protection measures in real time and generate a security log.
[0122] It should be noted that the network data packets are captured by using tools such as Wi reshark, tcpdump and Zeek, and hardware devices (such as Packet Shapers) are used to capture high-throughput network traffic in real time.
[0123] It should be noted that the captured network traffic data is denoised, irrelevant data and erroneous network traffic data are removed, invalid and repeated network traffic records are removed, missing values are filled, and the network traffic data is standardized and normalized using the Min-Max Sca l ing or Z-score standardization method to ensure that the magnitudes of different network traffic data features are similar.
[0124] It should be noted that the user behavior characteristics include user login frequency and user access mode;
[0125] The network topology features include source IP address, destination IP address and port number;
[0126] The local characteristics of the network traffic include, but are not limited to, the size of network traffic packets, the duration of network traffic, the frequency of network traffic, the traffic rate and the standard deviation of the network traffic size.
[0127] It should be noted that different features of the network traffic data are mapped to different channels of a matrix to obtain a feature matrix, each feature represents a dimension of the matrix, and the convolutional layer of the convolutional neural network CNN learns the feature correlation of the network traffic data and identifies the local pattern or abnormal behavior of the network traffic data features;
[0128] The long short-term memory network LSTM identifies the temporal pattern of attack behavior by processing the time series data of the network traffic, divides the network traffic data into time windows of fixed length, calculates the statistical features within the time window as the input of each time window, and extracts the total number of bytes, the number of data packets, the frequency of use of the network protocol and the change in the number of connections within each time window.
[0129] When training convolutional neural networks (CNN) and long short-term memory networks (LSTM), network traffic data is used as the training set. The gap between the model output and the true label is evaluated by defining a loss function (such as the cross-entropy loss function). The model parameters are updated through the back-propagation algorithm. Reinforcement learning is introduced to optimize the hyperparameters of convolutional neural networks (CNN) and long short-term memory networks (LSTM). During the training process, the model parameters are continuously adjusted to maximize the reward, thereby achieving adaptive optimization and improving the accuracy of attack detection and classification.
[0130] It should be noted that the convolutional neural network CNN extracts the features of network traffic data and classifies them, and can quickly extract meaningful patterns from the static features of network traffic data, preliminarily distinguish normal network traffic from abnormal network traffic, identify malicious patterns hidden in network traffic, and enhance the accuracy of risk assessment; the long short-term memory network LSTM remembers historical network traffic data information through cell states and hidden states, identifies the time dependency of network traffic data and continuous and complex attacks, and distinguishes different types of network attacks.
[0131] It should be noted that the convolutional neural network CNN is responsible for coarse classification of network traffic. After determining that the network traffic is abnormal traffic, the long short-term memory network LSTM performs further time series analysis to accurately identify the type of attack.
[0132] It should be noted that in the process of combining convolutional neural network CNN and long short-term memory network LSTM, intrusion detection system and intrusion prevention system can be identified to identify known types of attacks. With the help of professional systems, multi-level protection can be achieved, attacks can be identified with higher accuracy and faster response measures can be taken.
[0133] It should be noted that the comprehensive score can be adjusted according to the priority of different evaluation modes. The intensity of the network attack directly affects the actual load of the network attack, so it generally has a greater weight. The result of the risk score is generally used as a background reference;
[0134] Low-intensity network attacks have low traffic volume, short duration, and small impact;
[0135] Medium-intensity network attacks have medium traffic and last for a long time, which may affect some services.
[0136] High-intensity network attacks have huge traffic and last for a long time, which may cause a complete paralysis of network services.
[0137] In a specific embodiment, for a network attack caused by malicious behavior of a suspicious IP or IP segment, iptables or firewalld is used to restrict network access of the suspicious IP or IP segment, and GeoIP is used to block traffic from the area to which the suspicious IP or IP segment belongs. The code is:
[0138] "sudo iptab les -A INPUT -s<attacker_ip> -j DROP";
[0139] For network attacks caused by malicious requests of XSS and SQL injection, the code for defining rules through the Web application firewall to block malicious requests is:
[0140] "SecRu le ARGS|ARGS_NAMES|REQUEST_HEADERS|XML: / *"@rx un ion.*select.*from"\
[0141] "id:1000001,phase:2,deny,status:403,msg:'SQL Injection AttackDetected'"";
[0142] The code to use Ngnix to limit the frequency of malicious requests from the same IP is:
[0143]
[0144] In a specific embodiment, the protection strength is automatically adjusted according to the duration and traffic size of the network attack. For example, a loose traffic limit can be set in the early stage of a DDoS attack, and a strict traffic limit can be set when the attack intensifies. In addition, firewall rules, Nginx configurations, etc. are adjusted through automated tools (Ansible, SaltStack, etc.) to quickly respond to new attacks.
[0145] It should be noted that for logs related to network attack events, relational databases are used to store structured log data, NoSQL databases are used to store large-scale, unstructured log data, distributed file systems are used to store large-scale log files, and cloud storage services are used to store large-scale logs for a long time.
[0146] It should be noted that log data is written to persistent storage to avoid data loss, and data security is ensured through regular backup and redundant storage. Strategies such as batch writing and asynchronous writing are used to improve storage efficiency. When the amount of log data is large, a distributed log collection system (such as Kafka) can be used to alleviate high-concurrency writing pressure. For historical logs that are not frequently accessed, they can be compressed and archived regularly to reduce storage costs.
[0147] It should be noted that the present application can set up a visual monitoring interface to understand the current network traffic, attack events and abnormal traffic information in real time, and generate dynamic icons for real-time monitoring so that administrators can respond quickly; for example, use a traffic monitoring chart to display real-time network traffic conditions, and use a line chart or stacked chart to represent traffic change trends (upstream, downstream, total traffic, etc.); graphically display the number and severity of different attack types (such as DDoS, malicious scanning, SQL injection, etc.) of the current attack events; display the geographical location of the attack source through an attack source map, and identify the attack source location through a heat map or IP geographic distribution map; and network device status monitoring displays the status of network devices (such as switches, routers, firewalls, etc.) in real time, including traffic, CPU, memory, load and other information.
[0148] Reference below Figure 3 , which shows a schematic diagram of the structure of a computer system suitable for implementing an electronic device of an embodiment of the present application. Figure 3 The electronic device shown is merely an example and should not bring any limitation to the functions and scope of use of the embodiments of the present application.
[0149] like Figure 3 As shown, the computer system includes a central processing unit (CPU) 301, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 302 or a program loaded from a storage part 308 into a random access memory (RAM) 303. Various programs and data required for system operation are also stored in the RAM 303. The CPU 301, the ROM 302, and the RAM 303 are connected to each other via a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.
[0150] The following components are connected to the I / O interface 305: an input section 306 including a keyboard, a mouse, etc.; an output section 307 including a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 308 including a hard disk, etc.; and a communication section 309 including a network interface card such as a LAN card, a modem, etc. The communication section 309 performs communication processing via a network such as the Internet. A drive 310 is also connected to the I / O interface 305 as needed. A removable medium 311, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 310 as needed, so that a computer program read therefrom is installed into the storage section 308 as needed.
[0151] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a computer-readable storage medium, and the computer program includes a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 309, and / or installed from the removable medium 311. When the computer program is executed by the central processing unit (CPU) 301, the above functions defined in the method of the present application are executed. It should be noted that the computer-readable storage medium of the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium can be, for example, - but not limited to - an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection with one or more conductors, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device, or device. In the present application, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which a computer-readable program code is carried. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable storage medium other than a computer-readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, device, or device. The program code contained on the computer-readable storage medium may be transmitted using any appropriate medium, including but not limited to: wireless, wireline, optical cable, RF, etc., or any suitable combination of the foregoing.
[0152] Computer program code for performing the operations of the present application may be written in one or more programming languages or a combination thereof, including object-oriented programming languages, such as Java, Smalltalk, C++, and conventional procedural programming languages, such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0153] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present application. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0154] The modules involved in the embodiments of the present application may be implemented by software or by hardware.
[0155] As another aspect, the present application also provides a computer-readable storage medium, which may be included in the electronic device described in the above embodiment; or it may exist alone and not be assembled into the electronic device. The above computer-readable storage medium carries one or more programs. When the above one or more programs are executed by the electronic device, the electronic device: extracts local features of network traffic through a convolutional neural network, analyzes the timing features of abnormal network traffic using a long short-term memory network, and identifies the type of network attack; calculates the intensity of the network attack based on the traffic rate, duration, and number of source IPs of the network attack, calculates the risk score based on the local features of the network traffic, and weights the risk score and the intensity of the network attack to obtain a comprehensive score; responds to different types of network attacks and combines the comprehensive scores of different types of network attacks, executes different network attack protection measures, adjusts the protection level in real time according to the intensity and risk score of the network attack, records network attack information and protection measures, and generates security logs.
[0156] Finally, it should be noted that the above description is only a preferred embodiment of the present application and an explanation of the technical principles used. Those skilled in the art should understand that the scope of the invention involved in the present application is not limited to the technical solution formed by a specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above invention concept. For example, the above features are replaced with the technical features with similar functions disclosed in this application (but not limited to) by each other to form a technical solution.
Claims
1. A real-time network security monitoring and protection method based on deep learning, characterized in that: include: S1: extract local features of network traffic through convolutional neural network CNN, determine whether the network traffic is abnormal, use long short-term memory network LSTM to perform time series feature analysis on abnormal network traffic, and identify the type of network attack; S2: Calculate the intensity of the network attack based on the traffic rate, duration and number of source IP addresses of the network attack, and classify the intensity of the network attack into low intensity, medium intensity and high intensity; The calculation formula of the intensity of the network attack is: Ascore=W R ×R+W T ×T+W I ×I; Among them, Ascore is the intensity of network attack, W R is the weight of the traffic rate, W T is the weight of the network attack duration, W I is the weight of the number of source IP addresses of network attacks; R is the traffic rate, T is the duration of network attacks, and I is the number of source IP addresses of network attacks; S3: Calculating a risk score based on the local characteristics of the network traffic, and classifying the attack risk of the network traffic into low risk, medium risk and high risk; The risk score is calculated as follows: Rscore=Wx1×x1+Wx2×x2+……+Wx n ×x n ; Among them, Rscore is the risk score, Wx1, Wx2, Wx n are the weights of the local features of the network traffic, x1, x2, x n is a local feature of the network traffic; S4: performing weighted calculation on the risk score and the intensity of the network attack to obtain a comprehensive score; The calculation formula of the comprehensive score is: Tscore=(W1×Ascore)+(W2×Rscore) Among them, W1 is the weight of the intensity of the network attack, and W2 is the weight of the risk score; S5: In response to different types of network attacks and in combination with the comprehensive scores of different types of network attacks, different network attack protection measures are executed. Specifically, For network attacks caused by malicious behaviors of suspicious IP or IP segments, use iptables or firewalld to restrict network access of suspicious IP or IP segments, and use GeoIP to block traffic from the area where the suspicious IP or IP segment belongs. For network attacks caused by malicious requests of XSS and SQL injection, define rules through Web application firewall to block malicious requests, and use Ngnix to limit the frequency of malicious requests from the same IP. For large-scale DDos attacks, redirect network attack traffic to third-party cleaning services to filter malicious traffic; For network attacks caused by abnormal traffic, configure request limits for abnormal traffic in the Web server and limit the number of requests for abnormal traffic through the mod_evasive module of Apache; S6: Adjust the protection level in real time according to the intensity of the network attack and the risk score, record the network attack information and protection measures in real time and generate a security log.
2. The method according to claim 1, characterized in that The protection level is adjusted in real time according to the intensity and risk score of the network attack. Specifically, When the intensity of the network attack is low (Ascore<20), log recording is performed and an alarm is triggered; When the intensity of the network attack is medium (20≤Ascore<50), limit the frequency of malicious requests from the IP or increase the network bandwidth; When the intensity of the network attack is high (Ascore≥50), firewall definition rule measures, traffic cleaning services or temporary isolation of some network nodes are enabled.
3. The method according to claim 1, characterized in that: Adjusts protection levels in real time based on the intensity and risk score of the cyberattack in question, and also includes: When the risk score is low risk (Rscore<3), no action is taken; When the risk score is medium risk (3≤Rscore<6), the request for abnormal traffic is restricted; When the risk score is high risk (Rscore≥6), traffic cleaning or DDos protection measures are performed.
4. The method according to claim 1, characterized in that: The local features of network traffic are extracted by convolutional neural network (CNN) to determine whether the network traffic is abnormal. Specifically, user behavior features and network topology features are converted into numerical feature vectors by one-hot encoding or embedding methods, and the numerical feature vectors are merged with the local features of the network traffic to obtain a feature matrix. The feature matrix is input into the convolutional neural network (CNN) to determine and extract abnormal behavior of the network traffic.
5. The method according to claim 1, characterized in that The method uses a long short-term memory network LSTM to perform time series feature analysis on abnormal network traffic. Specifically, the abnormal network traffic data is divided into time windows of fixed length, and the characteristics of the number of data packets, number of bytes, average traffic size, frequency of use of network protocols and number of connections of the network traffic are extracted and standardized within the time window. The network traffic trend and network attacks in a certain period of time in the future are analyzed through the sliding window of the LSTM network, and the behavioral characteristics and time series characteristics of the network attacks are captured.
6. The method according to claim 1, characterized in that The content of the security log includes the log ID, network attack event timestamp, network attack event type, network attack information, protection measures taken against network attacks, response time of network attack events, and impact scope of network attack events.
7. The method according to claim 6, characterized in that The network attack information includes the network attack source IP and target IP, network attack time and network attack method.
8. A real-time network security monitoring and protection system based on deep learning, characterized in that: include: Identification module: extract local features of network traffic through convolutional neural network CNN, determine whether the network traffic is abnormal, use long short-term memory network LSTM to analyze the time series features of abnormal network traffic, and identify the type of network attack; Intensity module: calculates the intensity of the network attack based on the traffic rate, duration and number of source IP addresses of the network attack, and divides the intensity of the network attack into low intensity, medium intensity and high intensity; The calculation formula of the intensity of the network attack is: Ascore=W R ×R+W T ×T+W I ×I; Among them, Ascore is the intensity of network attack, W R is the weight of the traffic rate, W T is the weight of the network attack duration, W I is the weight of the number of source IP addresses of network attacks; R is the traffic rate, T is the duration of network attacks, and I is the number of source IP addresses of network attacks; Risk module: Calculate risk scores based on local features of the network traffic, and classify the attack risks of the network traffic into low risk, medium risk, and high risk; The risk score is calculated as follows: Rscore=Wx1×x1+Wx2×x2+……+Wx n ×x n ; Among them, Rscore is the risk score, Wx1, Wx2, Wx n are the weights of the local features of the network traffic, x1, x2, x n is a local feature of the network traffic; Comprehensive module: weighted calculation of the risk score and the intensity of the network attack to obtain a comprehensive score; The calculation formula of the comprehensive score is: Tscore=(W1×Ascore)+(W2×Rscore) Among them, W1 is the weight of the intensity of the network attack, and W2 is the weight of the risk score; Response module: responds to different types of network attacks and executes different network attack protection measures in combination with the comprehensive scores of different types of network attacks. Specifically, For network attacks caused by malicious behaviors of suspicious IP or IP segments, use iptables or firewalld to restrict network access of suspicious IP or IP segments, and use GeoIP to block traffic from the area where the suspicious IP or IP segment belongs. For network attacks caused by malicious requests of XSS and SQL injection, define rules through Web application firewall to block malicious requests, and use Ngnix to limit the frequency of malicious requests from the same IP. For large-scale DDos attacks, redirect network attack traffic to third-party cleaning services to filter malicious traffic; For network attacks caused by abnormal traffic, configure request limits for abnormal traffic in the Web server and limit the number of requests for abnormal traffic through the mod_evasive module of Apache; Log module: adjust the protection level in real time according to the intensity of the network attack and the risk score, record the network attack information and protection measures in real time and generate a security log.
9. A computer program product having one or more computer programs thereon, characterized in that: When the computer program is executed by a computer processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
BiLSTM-ELM-based DDoS attack classification detection method, device and equipment
CN115473748A
Network attack classification method and system for power distribution network
CN115879030A
Network intrusion attack identification system and method based on Internet of Things
CN118337540A
Automatic processing method, system and equipment for network security attack traffic
CN119051982A
Detecting and predicting cyber-attack phases in data processing environment regions
US20170230408A1
Cited By
Big data network security adaptive defense system based on deep learning
CN120528706A
Risk defense method and device based on network cloud security detection and medium
CN120639440A
Network threat detection and response system based on deep learning
CN121690840A
Deep learning based network threat detection and response system
CN121690840B