Network intrusion detection method and device, computer equipment and medium

By building an intrusion detection architecture and using the coordinated work of policy execution points and policy decision points, the problem of inability to effectively identify and respond to new attack threats in 6G networks is solved, more efficient network threat detection and processing capabilities are achieved, and the security and robustness of the network are enhanced.

CN120018140APending Publication Date: 2025-05-16Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510037399.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-09
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The existing technology cannot effectively identify and respond to new attack threats in 6G networks, and has not yet effectively integrated the zero-trust architecture and intrusion detection mechanism.

Method used

Build an intrusion detection architecture that includes policy execution points and policy decision points. The network data flow to be detected is converted into multiple groups through the stream generator, and determine whether inflow is allowed through the policy manager and the detection module. If the judgment result cannot be obtained, send the multi-group to the policy decision point for judgment and feedback the results for trust evaluation.

Benefits of technology

It improves attack processing and threat detection capabilities for network scenarios, effectively responds to new attack threats in 6G networks, and enhances the robustness and security of the network through the principle of zero trust and federated learning.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120018140A_ABST
    Figure CN120018140A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a network intrusion detection method and device, computer equipment and a medium, and the method comprises the following steps: constructing an intrusion detection architecture comprising a strategy execution point and a strategy decision point between each terminal and an external network; when a to-be-detected network data stream from the outside is monitored, the to-be-detected network data stream is converted into a multi-tuple through a stream generator of a strategy execution point, and whether the to-be-detected network data stream is allowed to flow in or not is judged according to the multi-tuple through a strategy manager and a detection module. Executing a strategy for the to-be-detected network data flow according to a judgment result; and if the judgment result cannot be obtained in the strategy execution point, sending the multi-tuple to the strategy decision point, judging whether the inflow of the network data flow to be detected is allowed through a strategy generator of the strategy decision point, and feeding back the judgment result to the strategy execution point. According to the scheme, through an intrusion detection architecture, processing of attacks of a network scene and detection of threats are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a network intrusion detection method, device, computer equipment and medium. Background Art

[0002] The revolutionary breakthrough of 6G brings convenience but also poses a serious threat to network security. Compared with 5G, the number of IoT devices in 6G networks will explode, and the leap in communication quality will greatly promote the trend of remote work and BYOD. However, the high heterogeneity, openness and complexity of 6G networks have led to increasingly blurred network boundaries. The generally weak protection capabilities of IoT devices, coupled with the potential attack surfaces introduced by network slicing and emerging applications, together pose a severe challenge to network security. However, existing research has not effectively integrated zero-trust architecture and intrusion detection mechanisms to meet the security needs of 6G networks, resulting in the inability to effectively identify and respond to new attack threats. Summary of the invention

[0003] In view of this, an embodiment of the present invention provides a method for detecting network intrusion to solve the technical problem that the prior art cannot effectively identify and respond to new attack threats. The method includes:

[0004] An intrusion detection architecture including a policy execution point and a policy decision point is constructed between each terminal and an external network, wherein the policy execution point includes a flow generator, a policy manager and a detection module, and the policy decision point includes a policy generator;

[0005] When a network data flow to be detected is detected from outside the intrusion detection architecture, the network data flow to be detected is converted into a tuple by the flow generator of the policy execution point, and the policy manager and the detection module determine whether to allow the inflow of the network data flow to be detected according to the tuple. In the policy manager, the policy for the network data flow to be detected is executed according to the judgment result, wherein the tuple is used to define the data characteristics of the network data flow to be detected, and the policy includes permission or rejection;

[0006] If the judgment result cannot be obtained in the policy execution point, the tuple is sent to the policy decision point, and the policy generator of the policy decision point determines whether to allow the inflow of the network data flow to be detected, and feeds back the judgment result to the policy execution point, where the policy decision point is used to evaluate the trust of the policy execution point.

[0007] An embodiment of the present invention also provides a network intrusion detection device to solve the technical problem that the prior art has not yet effectively integrated the zero-trust architecture and intrusion detection mechanism to meet the security requirements of 6G networks.

[0008] The device includes:

[0009] A detection architecture building module, used to build an intrusion detection architecture including a policy execution point and a policy decision point between each terminal and an external network, wherein the policy execution point includes a flow generator, a policy manager and a detection module, and the policy decision point includes a policy generator;

[0010] The execution point detection module is used for, when a network data flow to be detected from outside the intrusion detection architecture is detected, converting the network data flow to be detected into a tuple through the flow generator of the policy execution point, judging whether to allow the inflow of the network data flow to be detected according to the tuple through the policy manager and the detection module, and executing the policy for the network data flow to be detected according to the judgment result in the policy manager, wherein the tuple is used to define the data characteristics of the network data flow to be detected, and the policy includes permission or rejection;

[0011] The decision point detection module is used to send the tuple to the policy decision point if the judgment result cannot be obtained in the policy execution point, and judge whether to allow the inflow of the network data flow to be detected through the policy generator of the policy decision point, and feed back the judgment result to the policy execution point, wherein the policy decision point is used for trust evaluation of the policy execution point.

[0012] An embodiment of the present invention also provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements any of the above-mentioned network intrusion detection methods when executing the computer program, so as to solve the technical problem that the prior art has not yet effectively integrated the zero-trust architecture and intrusion detection mechanism to meet the security requirements of 6G networks.

[0013] An embodiment of the present invention also provides a computer-readable storage medium, which stores a computer program for executing any of the above-mentioned network intrusion detection methods, so as to solve the technical problem that the prior art has not yet effectively integrated the zero-trust architecture and intrusion detection mechanism to meet the security requirements of 6G networks.

[0014] Compared with the prior art, the at least one technical solution adopted in the embodiments of this specification can achieve the following beneficial effects:

[0015] The network intrusion detection method of the embodiment of the present invention improves the processing of attacks on network scenarios and the detection of threats by constructing an intrusion detection architecture. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0017] Figure 1 is a flow chart of a network intrusion detection method provided by an embodiment of the present invention;

[0018] Figure 2 It is an architecture diagram of an intrusion detection for implementing the above-mentioned network intrusion detection method provided by an embodiment of the present invention;

[0019] Figure 3 It is an architecture diagram of intrusion detection of the Internet of Things based on the "cloud-edge-end" mode provided by an embodiment of the present invention;

[0020] Figure 4 It is an architectural diagram of intrusion detection of an internal network provided by an embodiment of the present invention;

[0021] Figure 5 is a diagram of a remote office network detection architecture provided by an embodiment of the present invention;

[0022] Figure 6 is a structural block diagram of a computer device provided by an embodiment of the present invention;

[0023] Figure 7 It is a structural block diagram of a network intrusion detection device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0024] The embodiments of the present application are described in detail below with reference to the accompanying drawings.

[0025] The following describes the implementation methods of the present application through specific examples, and those skilled in the art can easily understand other advantages and effects of the present application from the contents disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The present application can also be implemented or applied through other different specific implementation methods, and the details in this specification can also be modified or changed in various ways based on different viewpoints and applications without departing from the spirit of the present application. It should be noted that, in the absence of conflict, the following embodiments and the features in the embodiments can be combined with each other. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in the field without making creative work belong to the scope of protection of the present application.

[0026] In an embodiment of the present invention, a method for detecting network intrusion is provided, such as Figure 1 and Figure 2 As shown, the method includes:

[0027] Step S101: constructing an intrusion detection architecture including a policy execution point and a policy decision point between each terminal and an external network, wherein the policy execution point includes a flow generator, a policy manager and a detection module, and the policy decision point includes a policy generator;

[0028] Step S102: when a network data flow to be detected from outside the intrusion detection architecture is monitored, the network data flow to be detected is converted into a tuple by the flow generator of the policy execution point, and the policy manager and the detection module determine whether to allow the inflow of the network data flow to be detected according to the tuple. In the policy manager, the policy for the network data flow to be detected is executed according to the determination result, wherein the tuple is used to define the data characteristics of the network data flow to be detected, and the policy includes permission or rejection;

[0029] Step S103: If the judgment result cannot be obtained in the policy execution point, the tuple is sent to the policy decision point, and the policy generator of the policy decision point determines whether to allow the inflow of the network data flow to be detected, and feeds back the judgment result to the policy execution point, where the policy decision point is used to evaluate the trust of the policy execution point.

[0030] Specifically, Figure 2 As shown, the policy enforcement point (PEP) includes a flow generator, a policy manager, and a detection module.

[0031] In specific implementation, in order to determine whether to allow inflow through the policy manager, the following steps are implemented to determine whether to allow inflow of the network data flow to be detected according to the multi-tuple through the policy manager and the detection module, and in the policy manager, the policy for the network data flow to be detected is executed according to the judgment result:

[0032] Initialize the flow table on the policy manager, match the tuple with the tuple in the flow table, if they match, obtain the tuple policy corresponding to the tuple from the flow table, if they do not match, send the tuple to the detection module, where the flow table is used to store the correspondence between the tuple and the tuple policy; in the detection module, detect the network data flow to be detected through a detection method based on data features or data anomalies and generate a judgment result, and send the judgment result to the policy manager.

[0033] In specific implementation, the following steps are performed to convert the network data flow to be detected into a tuple through the flow generator of the policy execution point:

[0034] In the flow generator, the access subject, access object, access action, timestamp and subject security situation are abstracted from the network data flow to be detected, wherein the access subject is the initiator of the network data flow to be detected, the access object is the receiver of the network data flow to be detected, the access action is the interaction between the access subject and the access object, the timestamp is the access time of the network data flow to be detected, and the subject security situation is the situation assessment made on the access subject; the access subject, access object, access action, timestamp and subject security situation are combined to generate a tuple.

[0035] Specifically, the flow generator converts network data flow (traffic) into a specific flow (flow), which we define as the subject's access to resources. From the data packets of the network data flow, we abstract the subject, object, access action, timestamp, subject security situation level and other tuples, which can be expressed as a flow {subject, object, access action, timestamp, subject security situation} and sent to the policy manager, and then matched the relevant policies from the policy manager. The access subject of the flow is the initiator of the network data flow, such as an external user or device; the access object of the flow is the receiver of the flow, such as a resource or service; the access action is the interaction between the subject and the object, including downloading files, logging into the database, etc.; the timestamp is the time of the current access of the flow; the subject security situation refers to the situation assessment made on the access subject, which can give an assessment of the security status of the access subject based on whether the device software is updated to the latest version, whether the device has high-risk vulnerabilities, etc. The flow generator converts the network data flow into a tuple, which makes it easy for PEP to quickly match relevant policies from the policy manager and make a quick response.

[0036] Specifically, the policy manager is an important component of PEP for quickly determining whether a network data flow is abnormal. The flow table stored therein is a plurality of multi-group policies {subject, object, access action, timestamp, subject security situation, action (policy)}. It makes corresponding policy judgments for each flow. Actions (policies) include permission and rejection. The policy manager will be updated according to the information of the PEP detection module. If a new multi-group is added to the policy manager, the policy manager will send the flow to the PDP. After making a judgment, the PDP will broadcast it to other PEPs to enhance the overall intrusion detection capability. If the multi-group of the flow generator does not get a corresponding match in the policy manager (for example, the direct match of the malicious subject is successful and the flow is rejected. It is also possible that there is no correlation between the subject and the object. Subject A should not access subject B. If subject A accesses subject B, it can also be directly matched successfully and the flow is rejected), the detection module is started for detection.

[0037] In specific implementation, the following steps are implemented in the detection module to detect the network data flow to be detected and generate a judgment result based on data features or data anomalies, and send the judgment result to the policy manager:

[0038] If the detection method based on data features or data anomalies can obtain a judgment result, the judgment result will be sent to the policy manager. The policy manager will update the policy in the flow table according to the judgment result and execute the multi-group policy for the network data flow to be detected. If the judgment result cannot be obtained, the multi-group will be sent to the policy decision point, which will determine whether to allow the inflow of the network data flow to be detected.

[0039] Specifically, the detection module is the core component of PEP, and its performance directly determines the intrusion detection capability. In the detection module, we adopt different methods according to the different resources and computing power of PEP itself. We can perform detection based on lightweight methods of anomalies or features, and inform the policy manager of the detection results. The policy manager will update the policy accordingly and execute policy actions to allow or deny the network data flow. If the detection module cannot accurately determine whether the network data flow behavior is abnormal, PEP will query PDP and request PDP to make a decision.

[0040] Specifically, Figure 2 As shown, the policy decision point (PDP) includes a policy generator, a federated learning center, a trust manager, and a risk assessment center.

[0041] In specific implementation, the following steps are performed to send the tuple to the policy decision point, and the policy generator of the policy decision point determines whether to allow the inflow of the network data flow to be detected:

[0042] The policy decision point also includes a trust manager; in the policy generator, the trust values ​​of all policy execution points in the intrusion detection architecture are obtained through the trust manager, and multiple policy execution points with high trust values ​​are selected as collaborative policy execution points; the network data flow to be detected is sent to the collaborative policy execution point, the judgment result is obtained in the collaborative policy execution point, and multiple judgment results are sent to the policy decision point; all judgment results are aggregated in the policy generator, and the aggregated judgment results are sent to the policy execution point.

[0043] Specifically, the policy generator is the core component of the PDP. The access control decisions of the entire network are determined and generated by it. It is used to collect information from the entire network and external threat intelligence sources, vulnerability management, etc., update the optimal policy in real time, and broadcast it to the entire network for a period of time to ensure that the entire network maintains a high level of detection capabilities. The policy generator also stores policy tuples. When a PEP's detection module cannot make a judgment, the PDP will query the policy of the relevant flow from the policy generator to help the PEP make a decision. If the PDP's policy decision center does not have a relevant policy, it will start the collaborative detection mode and send the traffic data packet to multiple PEPs with higher trust values. These PEPs will judge the traffic based on their own experience and knowledge, and resend the results to the PDP after obtaining them. The PDP can aggregate the feedback information based on the trust value of each node to obtain the final judgment result, and then generate a new policy tuple to store and send to the inquiring PEP.

[0044] Specifically, the trust manager is an important component for achieving the reliability of the collaborative intrusion detection architecture, and is used to assist the PDP in determining the correctness of the query PEP results. Trust assessment is not only a trust assessment of the PEP, but also a trust assessment of the access entity. The trust assessment module embodies the core concept of zero-trust "continuous authentication". In a network, direct and indirect trust assessments can be performed based on multiple dimensions such as node communication success rate and node resources. At the same time, trust value predictions can be made based on Bayesian theory or Markov models. Different methods can be used for evaluation according to the actual network conditions.

[0045] In specific implementation, the following steps are used to improve the detection accuracy of the intrusion detection architecture through the policy decision point:

[0046] The policy decision point also includes a federated learning center; the federated learning center is used to obtain the detection accuracy of the intrusion detection architecture in real time; the federated learning center is also used to perform the following operations when the detection accuracy is lower than the set threshold until the detection accuracy is greater than or equal to the set threshold: the global model and the parameters of the global model saved in the federated learning center are sent to each policy execution point; in each policy execution point, the global model is trained using the data set in the policy execution point, and the parameters and gradients of the global model generated by the training are transmitted to the federated learning center; the trust values ​​of all policy execution points in the intrusion detection architecture are obtained through the trust manager, and the federated learning center aggregates the trust values ​​of each policy execution point to generate a new global model, which is then sent to each policy execution point.

[0047] Specifically, the federated learning center is a key component for enhancing network robustness. When the PDP finds that the detection accuracy of the overall network has decreased, it will organize PEPs to conduct federated learning. First, the global model and parameters are sent to each PEP. The PEP trains the model based on its own unique data, and then only uploads the model parameters and gradients to the PDP. After that, the PDP aggregates a new global model based on the trust value of each PEP and sends it to the PEP again. Federated learning can update the model while protecting the privacy of PEP node data, enhance the ability of anomaly detection, and effectively ensure the robustness and robustness of network detection.

[0048] In specific implementation, active defense is achieved through the risk assessment center through the following steps:

[0049] The risk assessment center is used to proactively defend against cyber attacks and threats received by policy decision points.

[0050] Specifically, the risk assessment center is an important component for protecting PDP. PDP is the core of the entire network and will be subject to more network attacks and threats. In order to protect PDP and achieve the effect of active defense, honeypot technology can be used to lure network attacks and analyze them. In the face of advanced persistent attacks, the Markov model and network kill chain can be combined to conduct risk assessment on the current PDP.

[0051] In one embodiment, Figure 3 As shown in the figure, in the IoT model based on the "cloud-edge-end" model, IoT devices, as access entities to network resources, have weak protection mechanisms that attract attackers, and most IoT devices are not bound to user identities. Therefore, it is required to perform a security posture check on each IoT device before accessing the network, and set a corresponding trust value based on the security protocol level it uses.

[0052] The edge server is used as the policy enforcement point (PEP) and the cloud server is used as the policy generator (PDP).

[0053] Since most devices have limited network resources, the detection module chooses to use a signature-based lightweight detection method (the lightweight detection method has low requirements for computing power and storage resources, but can only identify known attacks and has certain limitations). A feature database is built into the IoT device. Each signature represents a rule for identifying the corresponding attack. When a network data flow is detected to match a certain signature, an early warning is given. Then, the multi-tuple information in the flow data of the network data flow is extracted and sent to the edge server (PEP). The edge server will add the flow to the flow table for subsequent detection. The signature-based lightweight detection method can only detect known attacks, so the cloud server (PDP) generates corresponding rules based on threat intelligence sources and the latest vulnerability sources, and the edge server forwards them to the IoT device (terminal) for updating, which can resist zero-day attacks to a certain extent.

[0054] When an attacker controls an IoT device and bypasses signature-based intrusion detection, they still need to face detection by the edge server (PEP). The edge server (PEP) has powerful computing resources and can perform anomaly detection based on deep learning to enhance the detection of unknown attacks. In addition, most IoT devices will request read and write operations on fixed resources within a fixed time period, so the device baseline behavior can be set. Even if an attacker controls the device and attempts to access resources beyond the permission or read a large number of resources, the edge server will detect and deny access, and at the same time reduce its trust value. Trust evaluation can be based on device energy and malicious behavior. The higher the energy value and the fewer malicious behaviors, the higher the trust.

[0055] If the edge server cannot detect whether the flow data is normal, it will initiate collaborative detection to other edge servers through the cloud server. In addition, the cloud server will organize the edge server to conduct federated learning training in a timely manner according to the overall network's missed alarm rate and false alarm rate to improve the network's detection accuracy. Malicious edge servers will not only deliberately release malicious traffic, but also block the legitimate access of normal traffic, disrupting the normal operation of the network. Therefore, the trust value judgment of edge servers must be more stringent. The cloud server can send challenge queries to the edge server from time to time and update its trust value based on the edge server's response. Once the trust value is lower than the threshold, the identity of the edge server will be re-verified and its service will be temporarily taken over by the adjacent edge server.

[0056] In one embodiment, Figure 4 As shown, in the remote office detection mode, the remote user and his / her device are the access entities. Before the remote access device enters the network, it is necessary not only to perform a security posture check and assign a corresponding trust value, but also to bind the user and the device.

[0057] The client in the device is regarded as a lightweight client PEP, the campus PEP is regarded as a PEP, and the campus center network is regarded as a policy generator (PDP).

[0058] The client in the device can be a lightweight client PEP (referring to a component with a lightweight detection method embedded in the terminal) with a lightweight client PEP component installed, which is responsible for verifying the identity of the user and the device, dynamically analyzing the security situation and adaptively adjusting the trust value of the device. When a remote user accesses, the device ID, user ID, access time, access location and other information must be added to the data packet. The campus center network (PDP) will update the user's location and notify the lightweight client PEP. The lightweight client PEP determines whether the access is reasonable based on the user's data packet, and determines whether there is a remote login or login at an abnormal time. The lightweight client PEP will perform behavioral baseline modeling and learning based on the user's long-term usage habits, and can judge the user's abnormal behavior. Even if the attacker obtains the login key, it is difficult to imitate the user's behavior habits, so it will be judged as abnormal behavior and issue an early warning, which greatly curbs counterfeit attacks.

[0059] The lightweight client PEP and campus PEP will encrypt all inbound and outbound traffic, and can protect data security to the greatest extent even if the data is attacked by a man-in-the-middle attack. If the lightweight client PEP is attacked by an attacker, detections such as behavioral baselines will not work, and the information about the user status in the package sent to the campus PEP will be tampered with according to the legitimate information stored in the lightweight client PEP. In order to evaluate the trust value of the lightweight client PEP, the PDP will rely on the trusted campus PEP to intentionally send incorrect user status information to the lightweight client PEP. The user will choose to accept or reject according to his actual status, and the attacker cannot judge the correctness of the message and accepts the wrong status information, which causes the trust value to drop. Then the campus PEP can deny remote access based on the trust value.

[0060] The campus PEP has powerful computing power and can perform anomaly detection based on deep learning. When it encounters a situation where it cannot judge the flow data, it will start collaborative detection. When the overall network leakage rate and false alarm rate increase, the campus center network (PDP) will conduct federated learning on the campus PEP and update the overall strategy. The campus center network (PDP) will conduct a trust assessment on the campus PEP. Therefore, even if the campus PEP is compromised by an attacker, the use of the malicious campus PEP can be suspended based on the trust value. After checking the security situation of the users and devices managed by the campus PEP, they will be temporarily assigned to the management of the neighboring campus PEP to ensure the normal operation of the network.

[0061] In one embodiment, Figure 5 As shown in the figure, in the internal network detection mode, the users and their devices of the internal network are the access entities, and the area where they are located is the most core and sensitive area of ​​the entire park. Therefore, all devices must go through a strict network access process, conduct security posture checks and record the current patches to facilitate subsequent real-time inspections. In addition, all intranet resources are segmented using micro-isolation technology, and PEP is deployed at the entrance of each resource or service. Lightweight client PEP can be installed in the intranet device according to needs, or community PEP can be deployed at the network exit of a department, based on which a multi-level collaborative detection architecture is formed.

[0062] The entry point of each resource or service is used as a policy enforcement point (PEP), the intranet devices (devices and clients) are used as lightweight client PEPs, the campus PEP is used as a policy enforcement point (PEP), and the campus center network is used as a policy generator (PDP).

[0063] The lightweight client PEP will perform security situation detection on the device according to the update of PDP policy, patch vulnerabilities in time, and reduce the occurrence of zero-day vulnerabilities. If the user refuses to update, the user's trust value will be reduced and access rights will be restricted. A baseline behavior detection module can also be established based on the device to determine whether the device is used by others and warn the PDP. The PDP will notify the community PEP to perform abnormal detection on the inbound and outbound traffic of the device. If the community PEP cannot effectively determine whether the device behavior is normal, it will request the PDP to start assisted detection, and the neighboring community PEP will assist in the detection.

[0064] An attacker may have compromised an intranet device through a zero-day vulnerability and gained control of the client PEP. Even if the attacker's behavior does not meet the baseline, the lightweight client PEP will not issue an alert. The community PEP will continue to conduct trust assessments on the lightweight client PEPs in its community from time to time. The assessment content includes security posture checks on the devices, and will adjust the trust value of the PEP after issuing a challenge to the lightweight client PEP. If a community PEP is compromised by an attacker, the devices in the entire community may be in a malicious state. Even if the community PEP indicates a normal access request, when the PEP at the resource entrance detects that the trust value of the community PEP has recently decreased or is below the threshold, it will re-check and review the device's access request. If an abnormality is detected, access will be denied and the trust value of the community PEP will be further reduced. When the number of suspicious events in the intranet increases, the campus center network PDP will conduct federated learning on the community PEPs with high trust values ​​in the entire network, update the parameter information, and use manual or automated methods to handle those PEPs with low trust values ​​to eliminate risks and improve the security of the overall network.

[0065] In this embodiment, a computer device is provided, such as Figure 6 As shown, it includes a memory 601, a processor 602, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, any of the above-mentioned network intrusion detection methods is implemented.

[0066] Specifically, the computer device may be a computer terminal, a server or a similar computing device.

[0067] In this embodiment, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program for executing any of the above-mentioned network intrusion detection methods.

[0068] Specifically, computer-readable storage media include permanent and non-permanent, removable and non-removable media, and information storage can be achieved by any method or technology. Information can be computer-readable instructions, data structures, modules of programs or other data. Examples of computer-readable storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, read-only compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable storage media does not include temporary computer-readable media (transitory media), such as modulated data signals and carrier waves.

[0069] Based on the same inventive concept, a network intrusion detection device is also provided in an embodiment of the present invention, as described in the following embodiments. Since the principle of solving the problem by the network intrusion detection device is similar to that of the network intrusion detection method, the implementation of the network intrusion detection device can refer to the implementation of the network intrusion detection method, and the repeated parts will not be repeated. As used below, the term "unit" or "module" can be a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceived.

[0070] Figure 7 is a structural block diagram of a network intrusion detection device according to an embodiment of the present invention, such as Figure 7 As shown, it includes: a detection architecture building module 701, an execution point detection module 702 and a decision point detection module 703. The structure is described below.

[0071] A detection architecture building module 701 is used to build an intrusion detection architecture including a policy execution point and a policy decision point between each terminal and an external network, wherein the policy execution point includes a flow generator, a policy manager and a detection module, and the policy decision point includes a policy generator;

[0072] The execution point detection module 702 is used for, when a network data flow to be detected from outside the intrusion detection architecture is monitored, converting the network data flow to be detected into a tuple through the flow generator of the policy execution point, judging whether to allow the inflow of the network data flow to be detected according to the tuple through the policy manager and the detection module, and executing the policy for the network data flow to be detected according to the judgment result in the policy manager, wherein the tuple is used to define the data characteristics of the network data flow to be detected, and the policy includes allowing or denying;

[0073] The decision point detection module 703 is used to send the tuple to the policy decision point if the judgment result cannot be obtained in the policy execution point, and judge whether to allow the inflow of the network data flow to be detected through the policy generator of the policy decision point, and feed back the judgment result to the policy execution point, wherein the policy decision point is used for trust evaluation of the policy execution point.

[0074] In one embodiment, the execution point detection module includes:

[0075] The data stream abstraction unit is used to abstract the access subject, access object, access action, timestamp and subject security situation from the network data stream to be detected in the stream generator, wherein the access subject is the initiator of the network data stream to be detected, the access object is the receiver of the network data stream to be detected, the access action is the interaction between the access subject and the access object, the timestamp is the access time of the network data stream to be detected, and the subject security situation is the situation assessment made on the access subject;

[0076] The tuple generation unit is used to generate a tuple after combining the access subject, the access object, the access action, the timestamp and the subject security situation.

[0077] In one embodiment, the execution point detection module further includes:

[0078] a tuple matching unit, configured to initialize a flow table on a policy manager, match a tuple with a tuple in the flow table, and if a match is found, obtain a tuple policy corresponding to the tuple from the flow table; if a match is found, send the tuple to a detection module, wherein the flow table is configured to store a correspondence between the tuple and the tuple policy;

[0079] The detection unit is used to detect the network data flow to be detected in the detection module through a detection method based on data characteristics or data anomalies, generate a judgment result, and send the judgment result to the policy manager.

[0080] In one embodiment, the multi-tuple matching unit is used to send the judgment result to the policy manager if the detection method based on data features or data anomalies can obtain the judgment result. The policy manager updates the policy in the flow table according to the judgment result and executes the multi-tuple policy for the network data flow to be detected. If the judgment result cannot be obtained, the multi-tuple is sent to the policy decision point, and the policy decision point determines whether to allow the inflow of the network data flow to be detected.

[0081] In one embodiment, the trust manager module includes:

[0082] The trust manager unit, for the policy decision point also includes a trust manager;

[0083] A collaborative policy execution point determination unit is used to obtain the trust values ​​of all policy execution points in the intrusion detection architecture through the trust manager in the policy generator, and select multiple policy execution points with high trust values ​​as collaborative policy execution points;

[0084] A judgment result obtaining unit, used for sending the network data flow to be detected to the collaborative policy execution point, obtaining the judgment result in the collaborative policy execution point, and sending multiple judgment results to the policy decision point;

[0085] The result aggregation unit is used to aggregate all judgment results in the policy generator and send the judgment results generated by the aggregation to the policy execution point.

[0086] In one embodiment, the above apparatus further includes a federated learning center module.

[0087] In one embodiment, the federated learning center module includes:

[0088] A federated learning center unit, used for the federated learning center to obtain the detection accuracy of the intrusion detection architecture in real time;

[0089] The accuracy judgment unit is used in the federated learning center. It is also used to perform the following operations when the detection accuracy is lower than the set threshold until the detection accuracy is greater than or equal to the set threshold:

[0090] The first model delivery unit is used to deliver the global model and the parameters of the global model stored in the federated learning center to each policy execution point;

[0091] A model training unit, used to train the global model in each policy execution point using the data set in the policy execution point, and transmit the parameters and gradients of the global model generated by the training to the federated learning center;

[0092] The second model distribution unit is used to obtain the trust values ​​of all policy execution points in the intrusion detection architecture through the trust manager. The federated learning center aggregates the trust values ​​of each policy execution point to generate a new global model, and then distributes it to each policy execution point.

[0093] In one embodiment, the above device further includes a risk assessment center module.

[0094] In one embodiment, the risk assessment center module includes:

[0095] The risk assessment center unit is used by the risk assessment center to actively defend against network attacks and threats received by the policy decision point.

[0096] The embodiments of the present invention achieve the following technical effects:

[0097] For the collaborative intrusion detection architecture based on zero trust of 6G network, the network intrusion detection method of the embodiment of the present invention not only takes into account the access subject and access environment on the basis of anomaly and feature detection, uses federated learning to ensure the robustness of the network, and uses challenge queries to continuously perform trust assessment on network nodes according to the zero trust principle to enhance the overall security; under the 6G network conditions, the network intrusion detection method of the embodiment of the present invention can effectively face the three typical scenarios of campus network: Internet of Things, remote office, and internal network, and can effectively prevent threats and attacks against common attack models. In addition, the robustness of the network is guaranteed by the federated learning center, and the core concept of zero trust is used to continuously authenticate network nodes, which effectively links the internal threats of the collaborative architecture, effectively combines the collaborative architecture and the zero trust architecture, and achieves the effect of "1+1>2".

[0098] Obviously, those skilled in the art should understand that the modules or steps of the above-mentioned embodiments of the present invention can be implemented by a general computing device, they can be concentrated on a single computing device, or distributed on a network composed of multiple computing devices, and optionally, they can be implemented by a program code executable by a computing device, so that they can be stored in a storage device and executed by the computing device, and in some cases, the steps shown or described can be executed in a different order from that here, or they can be made into individual integrated circuit modules, or multiple modules or steps therein can be made into a single integrated circuit module for implementation. In this way, the embodiments of the present invention are not limited to any specific combination of hardware and software.

[0099] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. For those skilled in the art, the embodiments of the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for detecting network intrusion, characterized in that: include: An intrusion detection architecture including a policy execution point and a policy decision point is constructed between each terminal and an external network, wherein the policy execution point includes a flow generator, a policy manager and a detection module, and the policy decision point includes a policy generator; When a network data flow to be detected from outside the intrusion detection architecture is monitored, the flow generator of the policy execution point converts the network data flow to be detected into a tuple, and the policy manager and the detection module determine whether to allow the inflow of the network data flow to be detected according to the tuple, and in the policy manager, the policy for the network data flow to be detected is executed according to the determination result, wherein the tuple is used to define the data characteristics of the network data flow to be detected, and the policy includes permission or rejection; If the judgment result cannot be obtained in the policy execution point, the tuple is sent to the policy decision point, and the policy generator of the policy decision point determines whether to allow the inflow of the network data flow to be detected, and feeds back the judgment result to the policy execution point, wherein the policy decision point is used to evaluate the trust of the policy execution point.

2. The method for detecting network intrusion according to claim 1, characterized in that: By means of the policy manager and the detection module, judging whether to allow the inflow of the network data flow to be detected according to the multi-tuple, and in the policy manager, executing the policy for the network data flow to be detected according to the judgment result, including: Initializing a flow table on the policy manager, matching the tuple with the tuple in the flow table, and if a match is found, obtaining a tuple policy corresponding to the tuple from the flow table, and if a match is found, sending the tuple to the detection module, wherein the flow table is used to store a correspondence between the tuple and the tuple policy; In the detection module, the network data flow to be detected is detected by a detection method based on data features or data anomalies to generate a judgment result, and the judgment result is sent to the policy manager.

3. The method for detecting network intrusion according to claim 2, characterized in that: In the detection module, the multi-tuple is detected by a detection method based on data features or data anomalies to generate a judgment result, and the judgment result is sent to the policy manager, including: If the detection method based on data features or data anomalies can obtain a judgment result, the judgment result is sent to the policy manager, and the policy manager updates the policy in the flow table according to the judgment result, and executes the multi-group policy for the network data flow to be detected; If the judgment result cannot be obtained, the tuple is sent to a policy decision point, and the policy decision point determines whether to allow the inflow of the network data flow to be detected.

4. The method for detecting network intrusion according to claim 1, characterized in that: The flow generator of the policy execution point converts the network data flow to be detected into a tuple, including: In the flow generator, the access subject, access object, access action, timestamp and subject security situation are abstracted from the network data flow to be detected, wherein the access subject is the initiator of the network data flow to be detected, the access object is the recipient of the network data flow to be detected, the access action is the interaction between the access subject and the access object, the timestamp is the access time of the network data flow to be detected, and the subject security situation is the situation assessment made on the access subject; The access subject, the access object, the access action, the timestamp and the subject security situation are combined to generate a tuple.

5. The network intrusion detection method according to any one of claims 1 to 4, characterized in that: Sending the tuple to the policy decision point, and determining whether to allow the inflow of the network data flow to be detected by the policy generator of the policy decision point, comprises: The policy decision point also includes a trust manager; In the policy generator, the trust values ​​of all the policy execution points in the intrusion detection architecture are obtained through the trust manager, and a plurality of the policy execution points with high trust values ​​are selected as collaborative policy execution points; Sending the network data flow to be detected to the collaborative policy execution point, obtaining a judgment result in the collaborative policy execution point, and sending a plurality of the judgment results to the policy decision point; All the judgment results are aggregated in the policy generator, and the aggregated judgment results are sent to the policy execution point.

6. The method for detecting network intrusion according to any one of claims 1 to 4, characterized in that: The strategy decision point also includes a federated learning center; The federated learning center is used to obtain the detection accuracy of the intrusion detection architecture in real time; The federated learning center is further configured to, when the detection accuracy is lower than a set threshold, perform the following operations until the detection accuracy is greater than or equal to the set threshold: Sending the global model and the parameters of the global model stored in the federated learning center to each of the policy execution points; In each of the policy execution points, the global model is trained using the data set in the policy execution point, and the parameters and gradients of the global model generated by the training are transmitted to the federated learning center; The trust values ​​of all the policy execution points in the intrusion detection architecture are obtained through a trust manager. The federated learning center aggregates and generates a new global model based on the trust values ​​of each policy execution point, and then sends it to each policy execution point.

7. The network intrusion detection method according to any one of claims 1 to 4, characterized in that: The strategic decision point also includes a risk assessment center; The risk assessment center is used to actively defend against network attacks and threats received by the policy decision point.

8. A network intrusion detection device, characterized in that: include: A detection architecture building module, used to build an intrusion detection architecture including a policy execution point and a policy decision point between each terminal and an external network, wherein the policy execution point includes a flow generator, a policy manager and a detection module, and the policy decision point includes a policy generator; An execution point detection module, which is used for, when a network data flow to be detected from outside the intrusion detection architecture is monitored, converting the network data flow to be detected into a tuple through the flow generator of the policy execution point, judging whether to allow the inflow of the network data flow to be detected according to the tuple through the policy manager and the detection module, and executing the policy for the network data flow to be detected according to the judgment result in the policy manager, wherein the tuple is used to define the data characteristics of the network data flow to be detected, and the policy includes permission or rejection; A decision point detection module is used to send the tuple to the policy decision point if the judgment result cannot be obtained in the policy execution point, and judge whether to allow the inflow of the network data flow to be detected through the policy generator of the policy decision point, and feed back the judgment result to the policy execution point, wherein the policy decision point is used for trust evaluation of the policy execution point.

9. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the network intrusion detection method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program for executing the network intrusion detection method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Communication method, and security policy negotiation method and system for supporting trusted network connect

    CN102215211A

  • Classification detection method facing network abnormal data flow

    CN106060039A

  • Network attack tracing and countering system based on host defense

    CN113992444A

  • Trusted connector and industrial flow management and control system and method based on zero trust

    CN116015804A

  • Network access traffic control method and server

    WO2015103984A1