Network security event monitoring method and system
By deploying multiple nodes in the network and utilizing distributed firewalls, neural network models and other technologies, the causal relationship and temporal relationship between network events are established, and the problem of insufficient identification accuracy in the existing technology is solved, and more efficient network security incident monitoring and response is achieved.
Patent Information
- Application Number
- CN202510052709.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-14
- Publication Date
- 2025-05-23
AI Technical Summary
Existing network security incident monitoring methods are difficult to effectively identify and predict causal and temporal relationships between multiple network events, resulting in insufficient recognition accuracy.
By deploying multiple nodes in the network, using distributed firewall and neural network models, the causal relationship and temporal relationship between network events are established, and the deep packet detection technology and machine learning algorithms can be used to identify and respond to security events in real time.
It improves the accuracy of identification and prediction of network security incidents, enhances the real-time response capabilities to abnormal network events, and ensures multi-level protection of network security defense.
Smart Images

Figure CN120034360A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a method and system for monitoring network security events. Background Art
[0002] Network security incident monitoring is an indispensable part of the modern information security system. It identifies, analyzes and responds to various security threats by monitoring network and system activities in real time. With the rapid development of network technology, enterprises and individual users are facing more and more security challenges. Therefore, an effective monitoring mechanism has become particularly important. Network security threats are diverse, and they are constantly evolving and looking for new ways to violate system security. Viruses, Trojans and phishing attacks are the three most well-known types of network threats. In the field of network security, event monitoring is a vital function that involves continuous observation of network traffic and system activities to identify, analyze and respond to potential security threats. Effective event monitoring can reveal attack behaviors in a timely manner, help organizations reduce losses and quickly return to normal. At present, the commonly used network security event monitoring methods mainly include signature-based detection and abnormal behavior detection.
[0003] To this end, we propose a method that can establish connections between multiple network events, establish connections between different network events in time and causality, and identify network security events through correlation analysis. Summary of the invention
[0004] The present invention establishes the cause-effect relationship of multiple network events, uses a neural network model to make predictions, and further establishes the temporal association of network events to improve the accuracy of prediction and identification.
[0005] The technical solution proposed by the present invention is: a method for monitoring network security events, the method comprising: Deploy multiple nodes in the network to disperse and monitor network attack traffic in real time and obtain information on various security events; Use distributed firewalls to coordinate the work of various nodes to identify and isolate attack traffic in real time, and use neural networks to analyze the traffic characteristics of network security events to ensure that normal traffic enters the system while intercepting or discarding attack traffic; Adjust protection strategies based on traffic characteristics of network security events and regularly update firewall rules to cope with ever-changing attack methods; Combined with deep packet inspection technology, it analyzes different network security events, tracks the attack source and records the attack path, providing a basis for subsequent security response; Import security tools to work together to form a multi-level protection network to provide security defense for the network.
[0006] Preferably, the method of deploying multiple nodes in the network, distributing and real-time monitoring network attack traffic, and obtaining a variety of security event information includes the following steps: Each node receives traffic data independently and detects potential attack behaviors through a machine learning algorithm rule engine; Send the test results to a central server for aggregation and further processing; Use streaming data processing technology to process and analyze traffic data in real time, and set thresholds and anomaly detection algorithms to identify and respond to security incidents in real time; Collect security event information from each node; use log aggregation tools to centrally store and analyze security event information.
[0007] Preferably, the distributed firewall is used to coordinate the work of each node to identify and isolate attack traffic in real time, and a neural network is used to analyze the traffic characteristics of network security events to ensure that normal traffic enters the system, while intercepting or discarding attack traffic, including: Use the preset attack signature library to filter traffic; The detection results are sent to the central node, which aggregates the information of all nodes, analyzes them, and makes decisions; Based on the decision results, the attack traffic is discarded or redirected to ensure that normal traffic enters the system; specifically: The captured traffic data is preprocessed and high-level features are extracted from the traffic data using a convolutional neural network (CNN); Use the trained convolutional neural network to classify the newly captured traffic and determine whether it is attack traffic; Import pre-stored normal traffic characteristics, and any traffic that meets these characteristics is allowed to enter the system.
[0008] Preferably, the protection strategy is adjusted according to the traffic characteristics of network security events, and firewall rules are updated regularly to cope with the ever-changing attack methods, including: Analyze the extracted traffic features through convolutional neural networks to determine whether there is potential attack behavior; Automatically generate or update firewall rules based on the judgment results. The firewall rules are based on the following logic: blocking traffic from known malicious IPs, limiting the access frequency of specific ports or protocols, and implementing access control within a time window; Deploy the newly generated firewall rules to the firewall and continuously monitor their effects. If false positives or false negatives are detected, adjust the convolutional neural network or update the firewall rules.
[0009] Preferably, the deep packet inspection technology is combined to analyze different network security events, track the attack source and record the attack path, and provide a basis for subsequent security response, including: Capture network traffic and obtain multiple packets; Parse each data packet and extract the source IP, destination IP, and protocol from the data packet; Based on the preset attack identification rules, the SYN flag is detected through the convolutional neural network to identify the port; Reconstruct the attack path by recording the timestamp and sequence of each data packet; The analysis results are saved in a JSON file to provide a basis for subsequent security response.
[0010] Preferably, the imported security tools work together to form a multi-level protection network to provide security defense for the network, including: A multi-level protection network is set up, the protection network includes: The first layer is used for firewalls and intrusion detection systems; the second layer is used for anti-virus software and malware detection tools; the third layer is used for data encryption and access control; the fourth layer is used for security auditing and log management; Monitor network traffic and system status in real time through each layer of the protection network, and trigger corresponding alarm responses when abnormal behavior or potential threats are found; Share security events and log information between various layers of the protection network, and use automated tools and scripts to quickly deploy and execute alarm response strategies.
[0011] Preferably, the method further comprises: grouping all network events that are bound to occur in the entire network system to be monitored and have a time sequence, and grouping all network events that are bound to occur in a time sequence between any two terminals in the network system to be monitored and have a time sequence; According to the preset time rules of the network system to be monitored, the time interval range between each network event is set to form a time chain for each group of behavior events; the time rules include: The time sequence and time interval of all network events that are bound to occur and have a time sequence in the entire network system to be monitored, and the time sequence and time interval of all network events that are bound to occur and have a time sequence between any two terminals in the network system to be monitored; Group the network events with normal protocols in the monitored network system, list all the network events with normal protocols as one group, and list the interaction time between any two terminals as one group; The time of occurrence of the first network event in each group is taken as the reference time, and the time interval between other events and the reference time is automatically calculated. The time interval is compared with the time chain of the corresponding group behavior events. Once the interval exceeds the preset time interval, the event is considered to be a network event with abnormal time. Otherwise, the event is considered to be a network event with normal time.
[0012] Preferably, the method further comprises: Obtain physical system information of the network through Simple Network Management Protocol SNMP, NetFlow, and sFlow; Convert the collected information into a behavior event vector, each element of which represents a specific network event, wherein the network event includes data packet sending, receiving, and connection establishment; The elements of the vector represent a certain event of the network system to be monitored, and the order of the elements of the vector represents the time order of the events in the network system to be monitored; By analyzing the timing characteristics of normal network events, an expected event sequence is established, and the actual event sequence is compared with the expected model. If the timing of an event does not conform to the expected model, it is considered to be a logically abnormal network event.
[0013] The present invention also provides a network security event monitoring system, wherein the system is used to execute the network security event monitoring method.
[0014] The present invention also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and the computer program is executed by a processor to implement the method for monitoring network security events.
[0015] Beneficial effects of the present invention: 1. The present invention predicts the occurrence of network security events through neural network model analysis; and further improves the accuracy of identifying abnormal network events by analyzing the time relationship between multiple network events and the time connection between events.
[0016] 2. The present invention maps the behavioral events of the information-physical system into behavioral event vectors in time sequence. The elements of the vector represent a certain event of the network system to be monitored, and the sequence of the vector elements characterizes the time sequence of the events in the network system to be monitored. Once the timing relationship of the occurrence of a certain network event does not conform to the preset timing relationship of the network system to be monitored, the network event is identified as a logically abnormal network event. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 The present invention is a flow chart of a method for monitoring network security events. DETAILED DESCRIPTION
[0018] The following description is used to disclose the present invention so that those skilled in the art can implement the present invention. The preferred embodiments described below are only examples, and those skilled in the art can think of other obvious variations. The basic principles of the present invention defined in the following description can be applied to other embodiments, variations, improvements, equivalents, and other technical solutions that do not deviate from the spirit and scope of the present invention.
[0019] It is to be understood that the term "one" should be understood as "at least one" or "one or more", that is, in one embodiment, the number of an element may be one, while in another embodiment, the number of the element may be multiple, and the term "one" should not be understood as a limitation on the quantity.
[0020] Embodiment 1: refer to Figure 1 The technical solution provided by the present invention is: a method for monitoring network security events, comprising the following steps: Step 1: Deploy multiple nodes in the network to disperse and monitor network attack traffic in real time and obtain various security event information; including the following steps: Each node receives traffic data independently and detects potential attack behaviors through the machine learning algorithm rule engine; Send the test results to a central server for aggregation and further processing; Use streaming data processing technology to process and analyze traffic data in real time, and set thresholds and anomaly detection algorithms to identify and respond to security incidents in real time; Collect security event information from each node; use log aggregation tools to centrally store and analyze security event information.
[0021] Step 2: Use a distributed firewall to coordinate the work of each node, identify and isolate attack traffic in real time, use a neural network to analyze the traffic characteristics of network security events, ensure that normal traffic enters the system, and intercept or discard attack traffic; including the following steps: Use the preset attack signature library to filter traffic; The detection results are sent to the central node, which aggregates the information of all nodes, analyzes them, and makes decisions; Based on the decision results, the attack traffic is discarded or redirected to ensure that normal traffic enters the system. Specifically: the captured traffic data is preprocessed, and high-level features are extracted from the convolutional neural network (CNN) traffic data. The newly captured traffic is classified using the trained convolutional neural network to determine whether it is attack traffic. The pre-stored normal traffic features are imported, and any traffic that meets these features is allowed to enter the system.
[0022] Step 3: Adjust the protection strategy according to the traffic characteristics of network security events and regularly update the firewall rules to cope with the ever-changing attack methods; use convolutional neural network to analyze the extracted traffic characteristics to determine whether there is potential attack behavior; Automatically generate or update firewall rules based on the judgment results. The firewall rules are based on the following logic: blocking traffic from known malicious IPs, limiting the access frequency of specific ports or protocols, and implementing access control within a time window; Deploy the newly generated firewall rules to the firewall and continuously monitor their effects. If false positives or false negatives are detected, adjust the convolutional neural network or update the firewall rules.
[0023] Step 4: Combine deep packet inspection technology to analyze different network security events, track the attack source and record the attack path to provide a basis for subsequent security response; Deep Packet Inspection (DPI) is a network traffic monitoring technology that identifies and classifies network traffic by inspecting the payload content of data packets. DPI can identify application layer protocols, file types, malware, etc., thereby providing more fine-grained network traffic analysis. In order to track the attack source and record the attack path, we need to take the following steps:
[0024] Use DPI tools to capture network traffic. Parse captured packets and extract key information such as IP address, port number, protocol type, etc. Identify potential attack behaviors based on predefined rules or machine learning models.
[0025] Reconstruct the attack path based on timestamps and packet sequences. Log the analysis results for subsequent security responses, such as encrypting stored data or restricting access to files.
[0026] Specifically: Use the Scapy library to capture packets. Parse the packets and extract necessary information. Based on the preset attack identification rules, detect the SYN flag bit through the convolutional neural network to identify the port. Reconstruct the attack path based on the timestamp and sequence of the packets. Write the results to the log file.
[0027] Step 5: Import security tools to work together to form a multi-level protection network to provide security defense for the network. This includes the following steps:
[0028] A multi-level protection network is set up, the protection network includes: The first layer is used for firewalls and intrusion detection systems; the second layer is used for anti-virus software and malware detection tools; the third layer is used for data encryption and access control; the fourth layer is used for security auditing and log management; Monitor network traffic and system status in real time through each layer of the protection network, and trigger corresponding alarm responses when abnormal behavior or potential threats are found; Share security events and log information between various layers of the protection network, and use automated tools and scripts to quickly deploy and execute alarm response strategies.
[0029] Embodiment 2: The difference between this embodiment and the first embodiment is that the following steps are further included: Group all network events that are bound to occur in the entire network system to be monitored and have a time sequence into one group, and group all network events that are bound to occur in a time sequence between any two terminals in the network system to be monitored into one group; According to the preset time rules of the network system to be monitored, the time interval range between each network event is set to form a time chain for each group of behavior events; the time rules include: The time sequence and time interval of all network events that must occur and have a time sequence in the entire network system to be monitored, and the time sequence and time interval of all network events that must occur and have a time sequence between any two terminals in the network system to be monitored; specifically: The global network events and their time sequence are parsed into a directed graph, where nodes represent events and edges represent time sequences.
[0030] Parse local network events and their time sequence into multiple directed graphs, each representing the event sequence between different terminal pairs. Topologically sort the global directed graph to determine the global time sequence of events. Topologically sort each local directed graph to determine the event sequence for a specific terminal pair. Based on the topological sorting results, calculate the time range of each event.
[0031] For a global event, the time range of the current event is determined based on the time ranges of the previous and next events.
[0032] For a local event, the time range of the current event is determined based on the time ranges of the previous and next events and the time range of the global event. Each event and its time range are combined into a time chain.
[0033] Group the network events with normal protocols in the monitored network system, list all the network events with normal protocols as one group, and list the interaction time between any two terminals as one group; The time of occurrence of the first network event in each group is taken as the reference time, and the time interval between other events and the reference time is automatically calculated. The time interval is compared with the time chain of the corresponding group behavior events. Once the interval exceeds the preset time interval, the event is considered to be a network event with abnormal time. Otherwise, the event is considered to be a network event with normal time.
[0034] Specific: All network events are stored in an event list, each of which contains a timestamp and event type.
[0035] The timestamp of the first event in each group. The difference between the events in each group and the reference time is stored. Normal protocol network events: group all normal protocol network events into one group. Group the interaction time between any two terminals into one group.
[0036] Set a threshold to determine whether an event is a time anomaly. For each event in each group, calculate the difference between it and the benchmark time. If the difference exceeds the preset time interval, it is marked as a time anomaly event; otherwise, it is marked as a time normal event.
[0037] Obtain physical system information of the network through Simple Network Management Protocol SNMP, NetFlow, and sFlow; Convert the collected information into a behavior event vector, each element of which represents a specific network event, wherein the network event includes data packet sending, receiving, and connection establishment; The elements of the vector represent a certain event of the network system to be monitored, and the order of the elements of the vector represents the time order of the events in the network system to be monitored; By analyzing the timing characteristics of normal network events, an expected event sequence is established, and the actual event sequence is compared with the expected model. If the timing of an event does not conform to the expected model, it is considered to be a logically abnormal network event.
[0038] The present invention also provides a network security event monitoring system, wherein the system is used to execute the network security event monitoring method.
[0039] The present invention also provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and the computer program is executed by a processor to implement the method for monitoring network security events.
[0040] In the embodiments disclosed in the present invention, the process described above with reference to the flowchart can be implemented as a computer software program. The embodiments disclosed in the present invention include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains a program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication part, and / or installed from a removable medium. When the computer program is executed by the central processing unit (CPU), the above functions defined in the method of the present application are executed. It should be noted that the computer-readable medium mentioned above in the present application can be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection with one or more wire segments, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present application, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, which carries a computer-readable program code. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code embodied on the computer readable medium may be transmitted using any appropriate medium, including but not limited to wireless, electrical wire, optical cable, RF, etc., or any suitable combination of the foregoing.
[0041] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present invention. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of a code, and the module, a program segment or a part of a code contains one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions marked in the boxes can also occur in a different order than the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0042] Those skilled in the art should understand that the embodiments of the present invention described above and shown in the accompanying drawings are only examples and do not limit the present invention. The objectives of the present invention have been fully and effectively achieved. The functions and structural principles of the present invention have been demonstrated and explained in the embodiments. Without departing from the principles, the implementation methods of the present invention may be subject to any changes or modifications.
Claims
1. A method for monitoring network security events, characterized in that: The method comprises: Deploy multiple nodes in the network to disperse and monitor network attack traffic in real time and obtain information on various security events; Use distributed firewalls to coordinate the work of various nodes to identify and isolate attack traffic in real time, and use neural networks to analyze the traffic characteristics of network security events to ensure that normal traffic enters the system while intercepting or discarding attack traffic; Adjust protection strategies based on traffic characteristics of network security events and regularly update firewall rules to cope with ever-changing attack methods; Combined with deep packet inspection technology, it analyzes different network security events, tracks the attack source and records the attack path, providing a basis for subsequent security response; Import security tools to work together to form a multi-level protection network to provide security defense for the network.
2. A method for monitoring network security events according to claim 1, characterized in that: The method of deploying multiple nodes in the network, distributing and real-time monitoring network attack traffic, and obtaining various security event information includes the following steps: Each node receives traffic data independently and detects potential attack behaviors through the machine learning algorithm rule engine; Send the test results to a central server for aggregation and further processing; Use streaming data processing technology to process and analyze traffic data in real time, and set thresholds and anomaly detection algorithms to identify and respond to security incidents in real time; Collect security event information from each node; use log aggregation tools to centrally store and analyze security event information.
3. A method for monitoring network security events according to claim 2, characterized in that: The distributed firewall is used to coordinate the work of each node, identify and isolate attack traffic in real time, and use neural networks to analyze the traffic characteristics of network security events to ensure that normal traffic enters the system, while intercepting or discarding attack traffic, including: Use the preset attack signature library to filter traffic; The detection results are sent to the central node, which aggregates the information of all nodes, analyzes them, and makes decisions; Based on the decision results, the attack traffic is discarded or redirected to ensure that normal traffic enters the system; specifically: The captured traffic data is preprocessed and high-level features are extracted from the traffic data using a convolutional neural network (CNN); Use the trained convolutional neural network to classify the newly captured traffic and determine whether it is attack traffic; Import pre-stored normal traffic characteristics, and any traffic that meets these characteristics is allowed to enter the system.
4. A method for monitoring network security events according to claim 3, characterized in that: Adjust the protection strategy according to the traffic characteristics of network security events and regularly update firewall rules to cope with the ever-changing attack methods, including: Analyze the extracted traffic features through convolutional neural networks to determine whether there is potential attack behavior; Automatically generate or update firewall rules based on the judgment results. The firewall rules are based on the following logic: blocking traffic from known malicious IPs, limiting the access frequency of specific ports or protocols, and implementing access control within a time window; Deploy the newly generated firewall rules to the firewall and continuously monitor their effects. If false positives or false negatives are detected, adjust the convolutional neural network or update the firewall rules.
5. A method for monitoring network security events according to claim 4, characterized in that: The deep packet inspection technology is combined to analyze different network security events, track the attack source and record the attack path, providing a basis for subsequent security response, including: Capture network traffic and obtain multiple packets; Parse each data packet and extract the source IP, destination IP and protocol from the data packet; Based on the preset attack identification rules, the SYN flag is detected through the convolutional neural network to identify the port; Reconstruct the attack path by recording the timestamp and sequence of each data packet; The analysis results are saved in a JSON file to provide a basis for subsequent security response.
6. A method for monitoring network security events according to claim 5, characterized in that: The imported security tools work together to form a multi-layered protection network to provide security defense for the network, including: A multi-level protection network is set up, the protection network includes: The first layer is used for firewalls and intrusion detection systems; the second layer is used for anti-virus software and malware detection tools; the third layer is used for data encryption and access control; the fourth layer is used for security auditing and log management; Monitor network traffic and system status in real time through each layer of the protection network, and trigger corresponding alarm responses when abnormal behavior or potential threats are found; Share security events and log information between various layers of the protection network, and use automated tools and scripts to quickly deploy and execute alarm response strategies.
7. A method for monitoring network security events according to claim 6, characterized in that: Also includes: Group all network events that are bound to occur in the entire network system to be monitored and have a time sequence into one group, and group all network events that are bound to occur in a time sequence between any two terminals in the network system to be monitored into one group; According to the preset time rules of the network system to be monitored, the time interval range between each network event is set to form a time chain for each group of behavior events; the time rules include: The time sequence and time interval of all network events that are bound to occur and have a time sequence in the entire network system to be monitored, and the time sequence and time interval of all network events that are bound to occur and have a time sequence between any two terminals in the network system to be monitored; Group the network events with normal protocols in the monitored network system, list all the network events with normal protocols as one group, and list the interaction time between any two terminals as one group; The time of occurrence of the first network event in each group is taken as the reference time, and the time interval between other events and the reference time is automatically calculated. The time interval is compared with the time chain of the corresponding group behavior events. Once the interval exceeds the preset time interval, the event is considered to be a network event with abnormal time. Otherwise, the event is considered to be a network event with normal time.
8. A method for monitoring network security events according to claim 7, characterized in that: The method further comprises: Obtain physical system information of the network through Simple Network Management Protocol SNMP, NetFlow, and sFlow; Convert the collected information into a behavior event vector, each element of which represents a specific network event, wherein the network event includes data packet sending, receiving, and connection establishment; The elements of the vector represent a certain event of the network system to be monitored, and the order of the elements of the vector represents the time order of the events in the network system to be monitored; By analyzing the timing characteristics of normal network events, an expected event sequence is established, and the actual event sequence is compared with the expected model. If the timing of an event does not conform to the expected model, it is considered to be a logically abnormal network event.
9. A network security incident monitoring system, characterized in that: The system is used to execute a network security event monitoring method as described in any one of claims 1-8 above.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and the computer program is executed by a processor to implement a method for monitoring network security events as described in any one of claims 1 to 8.