Computer network security analysis method and system based on big data
By constructing a timing behavior model and using the deviation scoring mechanism to detect abnormal traffic, and combining the clustering algorithm to identify attack types, the problem that existing network traffic analysis methods are difficult to capture timing changes in real time and lack of adaptability is solved, and efficient and accurate network security analysis and real-time response are achieved.
Patent Information
- Application Number
- CN202510211491.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-05-27
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing network traffic analysis methods are difficult to capture the timing changes of network traffic in real time, with high missed and false alarm rates, low computing efficiency, lack of adaptability, and difficult to respond quickly and take effective protective measures.
The computer network security analysis method based on big data is adopted, and the timing characteristics of network traffic are extracted through data collection and preprocessing, and the timing behavior model is constructed. The deviation scoring mechanism is used to detect abnormal traffic, and the attack type is identified through clustering algorithms to achieve real-time response and defense strategy adjustment.
It improves the real-time and accuracy of network traffic analysis, reduces the false alarm rate and missed alarm rate, enhances the adaptability of the network security system, and can quickly respond to and deal with complex network security threats.
Smart Images

Figure CN120050102A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to a computer network security analysis method and system based on big data. Background Art
[0002] With the wide application of the Internet, computer networks have become an important part of people's daily lives and business activities. However, network security issues have become increasingly prominent and have become important issues that need to be solved urgently worldwide. With the continuous evolution of attack technologies, the forms of network attacks have become increasingly complex, including various threats such as malicious scanning, DDoS attacks, and intrusion behaviors, posing a huge challenge to network security.
[0003] Although certain progress has been made in the prior art through the analysis of network traffic, many problems still exist in practical applications. First, existing traffic analysis methods mostly rely on static rule libraries and feature matching technologies, mainly for detecting known attacks. This method often has a high false negative rate and false positive rate when detecting new or unknown attacks. Second, traditional traffic analysis methods are difficult to capture the temporal changes of network traffic in real time. Especially when facing large-scale distributed attacks (such as DDoS attacks), the reaction speed and accuracy of the system are often limited. In addition, the existing technologies generally have the problem of low computational efficiency. Especially when dealing with massive network traffic, it is difficult to effectively control the balance between real-time performance and computational load. Finally, existing network defense strategies are generally based on static rules and preset thresholds, lacking adaptability, and it is difficult to automatically adjust defense strategies according to different attack types and threat levels, resulting in difficulty in quickly responding and taking effective protection measures when actual attack events occur. Summary of the Invention
[0004] The present invention provides a computer network security analysis method and system based on big data.
[0005] A computer network security analysis method based on big data includes the following steps:
[0006] S1, data collection and preprocessing: Deploy multiple data collection devices in the computer network to collect network traffic data in real time and preprocess the collected data;
[0007] S2, temporal feature extraction and modeling: Based on the preprocessed network traffic data, extract the temporal features of the traffic;
[0008] By means of an adaptive sliding window-based method, divide the network traffic data into continuous time segments, and use a long short-term memory network to construct a temporal behavior model of the network traffic for identifying the behavior patterns of normal traffic;
[0009] S3. Anomaly behavior detection and deviation scoring: Using the constructed time-series behavior model, compare the time-series characteristics of real-time network traffic data with the behavior patterns of normal traffic in the time-series behavior model;
[0010] Set a deviation scoring threshold. If the deviation of the time-series characteristics extracted from the real-time network traffic data exceeds the threshold within a certain time window, the real-time network traffic data is considered abnormal traffic;
[0011] S4. Anomaly traffic clustering and classification: Cluster the detected abnormal traffic through a clustering algorithm to find groups of abnormal traffic with similar behavior patterns. Through further classification analysis, identify potential attack types, including malicious scanning, DDoS attacks, and intrusion behavior;
[0012] S5. Real-time response based on deviation scoring: According to the deviation scoring results in S3, combined with the real-time network security status, formulate a real-time defense response strategy;
[0013] If the deviation score exceeds the set threshold, automatically trigger an alarm and send an anomaly report to the administrator. At the same time, according to the category and severity of the abnormal traffic, automatically adjust the firewall, intrusion detection system, and intrusion prevention system to perform corresponding network isolation and access restrictions.
[0014] Optionally, the S1 includes:
[0015] S11. Deployment of data collection nodes: Deploy multiple data collection devices at key positions in the computer network. The devices include network routers, switches, and servers to collect network traffic data in real time.
[0016] S12. Data collection: Through the deployed multiple data collection devices, collect network traffic data in real time. The network traffic data includes network header information, traffic time-series data, and TCP connection status;
[0017] S13. Data cleaning: Clean the collected network traffic data to remove invalid or incorrect data to ensure the quality of the data for subsequent processing.
[0018] S14. Data denoising: Perform denoising processing on the cleaned network traffic data to remove random noise from the network environment;
[0019] S15. Data normalization processing: Perform normalization processing on the denoised network traffic data.
[0020] Optionally, the S2 includes:
[0021] S21, Temporal Feature Extraction: Based on the preprocessed network traffic data, extract the temporal features of the traffic. The temporal features include the traffic change rate, the packet arrival interval time, and the change in packet size.
[0022] S22, Statistical Analysis of Temporal Features: Conduct statistical analysis on the extracted temporal features to obtain the overall behavior pattern of the network traffic.
[0023] Optionally, S2 further includes:
[0024] S23, Network Traffic Data Segmentation: By means of an adaptive sliding window-based method, segment the preprocessed network traffic data into continuous time segments.
[0025] S24, Temporal Behavior Model Construction: Use a long short-term memory network to model the segmented time segments and construct a temporal behavior model of the network traffic.
[0026] S25, Behavior Pattern Recognition: Use the trained temporal behavior model to predict the real-time network traffic data and identify the behavior pattern of normal traffic.
[0027] Optionally, S3 includes:
[0028] S31, Input of Real-Time Network Traffic Data: Input the temporal features of the real-time collected network traffic data into the constructed temporal behavior model.
[0029] S32, Comparison of Temporal Features with Normal Behavior Patterns: Use the trained temporal behavior model to process the temporal features of the real-time network traffic data and compare them with the behavior patterns of normal traffic. The comparison process includes feature matching and error calculation.
[0030] S33, Deviation Score Calculation: Calculate the deviation score based on the error between the real-time network traffic and the normal traffic behavior pattern. The deviation score reflects the degree of deviation between the real-time traffic and the normal behavior pattern. The larger the score value, the higher the degree of abnormality of the real-time network traffic.
[0031] S34, Comparison of Deviation Score with Threshold: Set a threshold for the deviation score. If the calculated deviation score exceeds this threshold, determine that the real-time network traffic data for this period is abnormal traffic.
[0032] Optionally, S4 includes:
[0033] S41, Input for Abnormal Traffic Clustering: Input the abnormal traffic data detected in S3 into the clustering algorithm.
[0034] S42, Application of K-means Clustering Algorithm: Apply the K-means clustering algorithm to conduct clustering analysis on the abnormal traffic data.
[0035] S43, Cluster result analysis: Analyze the K-means clustering results to find abnormal traffic groups with similar behavior patterns.
[0036] S44, Cluster result classification and attack type identification: Conduct classification analysis based on the clustering results and identify potential attack types.
[0037] S45, Attack type report generation: Generate a detailed attack report based on the identified attack types.
[0038] Optionally, the S5 includes:
[0039] S51, Real-time network security status input: Monitor the security status of the computer network in real time according to the deviation score results generated in S3.
[0040] S52, Alarm mechanism: Automatically trigger the alarm mechanism if the deviation score exceeds the set threshold.
[0041] S53, Defense response strategy formulation: Formulate real-time defense response strategies according to the real-time network security status and the identified abnormal traffic types.
[0042] Optionally, the S5 includes:
[0043] S54, Automatically adjust the firewall and intrusion detection / defense system: Automatically adjust network security devices according to the real-time defense response strategy.
[0044] S55, Network isolation and access restriction: Conduct network isolation and access restriction according to the defense response strategy.
[0045] A computer network security analysis system based on big data, used to implement the above-mentioned computer network security analysis method based on big data, includes the following modules:
[0046] Data acquisition module: Deploy multiple data acquisition devices in the computer network to collect network traffic data in real time and preprocess the collected data;
[0047] Model construction module: Extract the time series features of the traffic based on the preprocessed network traffic data, and use a long short-term memory network to construct a time series behavior model of the network traffic for identifying the behavior patterns of normal traffic;
[0048] Abnormal traffic identification module: Use the constructed time series behavior model to compare the time series features of the real-time network traffic data with the behavior patterns of normal traffic in the time series behavior model. If the deviation of the time series features extracted from the real-time network traffic data exceeds the preset threshold within a certain time window, the real-time network traffic data is considered abnormal traffic;
[0049] Abnormal traffic classification module: Cluster the detected abnormal traffic through a clustering algorithm to identify potential attack types;
[0050] Real-time response module: Based on the deviation scoring results and combined with the real-time network security status, formulate real-time defense response strategies.
[0051] Advantages of the present invention:
[0052] In the present invention, by combining the time-series behavior model and the deviation scoring mechanism, the time-series features in network traffic data can be efficiently extracted, and the behavior patterns of normal traffic can be accurately modeled. By comparing with real-time traffic data, traffic anomalies can be identified in a timely manner, and dynamic thresholds can be set based on the deviation scoring to effectively distinguish normal traffic from potential attack behaviors. Compared with traditional signature-based detection methods, the present invention has stronger real-time performance and higher accuracy, and can effectively reduce the false alarm rate and the missed alarm rate.
[0053] In the present invention, a clustering algorithm is used to group abnormal traffic, and different attack types such as malicious scanning, DDoS attacks, and intrusion behaviors can be accurately identified. Through this clustering-based classification analysis, the behavior patterns of each attack type can be deeply understood, providing a more accurate basis for formulating subsequent defense strategies. Further, through the real-time response mechanism, the configurations of firewalls, intrusion detection systems, and intrusion prevention systems are automatically adjusted according to the type and severity of abnormal traffic, ensuring flexible response to complex network security threats. Brief description of the drawings
[0054] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only for the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0055] Figure 1 It is a schematic flowchart of the method according to an embodiment of the present invention;
[0056] Figure 2 It is a schematic flowchart of the system according to an embodiment of the present invention. Detailed implementation manners
[0057] The following will describe the present invention in detail with reference to the drawings and specific embodiments. At the same time, it should be noted here that in order to make the embodiments more detailed, the following embodiments are the best and preferred embodiments. For some well-known technologies, those skilled in the art can also adopt other alternative methods for implementation; and the drawings are only for more specific description of the embodiments, and are not intended to specifically limit the present invention.
[0058] It should be noted that in the specification, when it is mentioned "an embodiment", "embodiment", "exemplary embodiment", "some embodiments", etc., it indicates that the described embodiment may include specific features, structures or characteristics, but not necessarily every embodiment includes such specific features, structures or characteristics. Additionally, when combining an embodiment to describe a specific feature, structure or characteristic, implementing such feature, structure or characteristic in combination with other embodiments (whether explicitly described or not) should be within the knowledge scope of those skilled in the relevant art.
[0059] Generally, terms can be understood at least in part from their use in context. For example, at least in part depending on the context, the term "one or more" used herein can be used to describe any feature, structure or characteristic in a singular sense, or can be used to describe a combination of features, structures or characteristics in a plural sense. Additionally, the term "based on" can be understood as not necessarily intended to convey a set of exclusive factors, but instead, at least in part depending on the context, allowing for the existence of other factors that may not be explicitly described.
[0060] As Figure 1 shown, a computer network security analysis method based on big data includes the following steps:
[0061] S1, Data collection and preprocessing: Deploy multiple data collection devices in the computer network to collect network traffic data in real time and preprocess the collected data;
[0062] S2, Temporal feature extraction and modeling: Based on the preprocessed network traffic data, extract the temporal features of the traffic;
[0063] By means of a method based on an adaptive sliding window, divide the network traffic data into continuous time segments, and use a long short-term memory network to construct a temporal behavior model of the network traffic for identifying the behavior patterns of normal traffic;
[0064] S3, Abnormal behavior detection and deviation scoring: Use the constructed temporal behavior model to compare the temporal features of the real-time network traffic data with the behavior patterns of normal traffic in the temporal behavior model;
[0065] Set a deviation scoring threshold. If the deviation of the temporal features extracted from the real-time network traffic data exceeds the threshold within a certain time window, consider the real-time network traffic data as abnormal traffic;
[0066] S4, Abnormal traffic clustering and classification: Cluster the detected abnormal traffic through a clustering algorithm to find groups of abnormal traffic with similar behavior patterns, and through further classification analysis, identify potential attack types, and the attack types include malicious scanning, DDoS attacks and intrusion behaviors;
[0067] S5, Real-time Response Based on Deviation Scoring: Based on the deviation scoring results in S3, combined with the real-time network security status, formulate a real-time defense response strategy;
[0068] When the deviation score exceeds the set threshold, an alarm is automatically triggered, and an exception report is sent to the administrator. At the same time, according to the category and severity of the abnormal traffic, the firewall, intrusion detection system, and intrusion prevention system are automatically adjusted for corresponding network isolation and access restrictions.
[0069] S1 includes:
[0070] S11, Deployment of Data Collection Nodes: Deploy multiple data collection devices at key positions in the computer network. The devices include network routers, switches, and servers to collect network traffic data in real-time.
[0071] S12, Data Collection: Through the deployed multiple data collection devices, collect network traffic data in real-time. Network traffic data includes network packet header information, traffic time series data, and TCP connection status, where;
[0072] Network Packet Header Information: Contains basic information such as the source IP address, destination IP address, source port number, destination port number, and protocol type of the data packet;
[0073] Traffic Time Series Data: Includes time series data such as the arrival timestamp, packet size, and transmission rate of each data packet;
[0074] TCP Connection Status: Contains information on the establishment, maintenance, and closure status of TCP connections, helping to monitor the connection status and traffic changes in the network;
[0075] S13, Data Cleaning: Clean the collected network traffic data, remove invalid or incorrect data, and ensure the data quality for subsequent processing. The cleaning steps include:
[0076] Removing Duplicate Data: Detect and delete duplicate network traffic data packets to avoid interference caused by duplicate calculations;
[0077] Format Error Repair: Repair or mark data packets with format errors, such as packets missing header information or incomplete TCP connection data;
[0078] Deleting Invalid Data: Delete invalid network traffic data, such as empty packets, abnormal packets without a source or a destination.
[0079] S14, Data Denoising: Perform denoising processing on the cleaned network traffic data to remove random noise from the network environment to improve the effectiveness of the data. The denoising methods include:
[0080] Kalman Filter: Filter the time-series data to reduce the impact of instantaneous fluctuations or outliers on data analysis;
[0081] Mean Filter: Use the mean filter method to smooth the data within a continuous time period, removing extreme values and abnormal fluctuations;
[0082] Low-pass Filter: Remove high-frequency noise through a low-pass filter and retain the main trend in network traffic;
[0083] S15, Data Standardization: Standardize the denoised network traffic data for subsequent modeling and analysis. The standardization process includes:
[0084] Numerical Standardization: Convert attributes such as packet sizes and timestamps from different sources into a unified standardized range, converting the values into values between 0 and 1 or a standard normal distribution.
[0085] S2 includes:
[0086] S21, Temporal Feature Extraction: Based on the preprocessed network traffic data, extract the temporal features of the traffic. The temporal features include traffic change rate, packet arrival interval time, and packet size change, as follows:
[0087] Traffic Change Rate: Calculate the change rate of network traffic to reflect the volatility of network load. The traffic change rate can be calculated using the following formula:
[0088]
[0089] Among them, the traffic in the current time period represents the total number of bytes transmitted within the current time period, and the traffic in the previous time period represents the total number of bytes transmitted in the previous time period;
[0090] Packet Arrival Interval Time: Calculate the time interval between consecutive packet arrivals to measure the temporality and traffic density of the network. The interval time is calculated using the following formula:
[0091] Packet Arrival Interval Time = T i+1 −T i
[0092] Among them, T i+1 is the arrival timestamp of the (i + 1)-th packet, and T i is the arrival timestamp of the i-th packet;
[0093] Packet Size Change: Calculate the change in the size of consecutive packets in the network to detect irregularities or anomalies in packet sizes. The packet size change is calculated using the following formula:
[0094]
[0095] Among them, the current data packet size is the number of bytes of the current data packet, and the previous data packet size is the number of bytes of the previous data packet;
[0096] S22, Statistical analysis of temporal features: Perform statistical analysis on the extracted temporal features to obtain the overall behavior pattern of network traffic. The statistical analysis includes:
[0097] Mean and standard deviation of features: Calculate the mean and standard deviation of each temporal feature to measure the dispersion and volatility of traffic features;
[0098] Autocorrelation of features: Calculate the autocorrelation coefficient of temporal features to analyze the periodicity and temporal dependence of network traffic;
[0099] Spectrum analysis of features: Perform frequency-domain transformation on temporal features to analyze the periodic changes of traffic features and identify periodic fluctuations through spectrograms.
[0100] S2 also includes:
[0101] S23, Network traffic data segmentation: Through a method based on an adaptive sliding window, segment the preprocessed network traffic data into continuous time segments. The size of the time segments is dynamically determined by the change of traffic, and it is achieved through the following methods:
[0102] Dynamic adjustment of the sliding window size: Automatically adjust the size of the sliding window according to temporal features such as traffic change rate or packet arrival interval time. For example, if the traffic change rate is large, increase the length of the sliding window to capture more network fluctuation information; if the traffic is relatively stable, reduce the window size to reduce the computational complexity.
[0103] Sliding step of the window: Set a fixed or dynamic sliding step, usually the time interval of one data packet or the time period of several data packets, to control the overlap or non-overlap division of time segments.
[0104] S24, Temporal behavior model construction: Use a long short-term memory network to model the segmented time segments and construct a temporal behavior model of network traffic. This model is established through the following steps:
[0105] Input data preparation: Use the temporal features extracted within each time segment as the input of the temporal behavior model, usually a multi-dimensional feature vector, including features such as traffic change rate, packet arrival interval time, and packet size change;
[0106] Model Training: Use the labeled normal traffic data to train the time-series behavior model. The long short-term memory network adjusts its parameters by backpropagating the error, thus learning the time-series behavior patterns of normal traffic. The training process of the long short-term memory network is optimized through the backpropagation algorithm, with the goal of minimizing the error between the prediction and the actual data. The model calculation formula is expressed as:
[0107] h t =σ(W h x t +U h h t-1 +b h );
[0108] Among them, h t represents the hidden state at the current moment, x t is the input feature at the current moment, h t-1 is the hidden state at the previous moment, W h , U h , b h are the weight and bias parameters of the long short-term memory network, and σ is the activation function (usually the sigmoid function);
[0109] Model Validation: Evaluate the performance of the model on different datasets through methods such as cross-validation to ensure that the model can accurately identify normal traffic patterns.
[0110] S25, Behavioral Pattern Recognition: Use the trained time-series behavior model to predict the real-time network traffic data and identify the behavioral patterns of normal traffic. Through the following steps:
[0111] Traffic Input: Input the time-series features of the real-time network traffic data into the trained time-series behavior model;
[0112] Pattern Output: The model outputs the predicted normal traffic behavior pattern, which is compared with the behavioral pattern of the actual traffic. If the comparison result is consistent, the traffic is considered normal traffic.
[0113] S3 includes:
[0114] S31, Real-time Network Traffic Data Input: Input the time-series features of the real-time collected network traffic data into the constructed time-series behavior model;
[0115] S32, Comparison of Time-series Features with Normal Behavioral Patterns: Use the trained time-series behavior model to process the time-series features of the real-time network traffic data and compare them with the behavioral patterns of normal traffic. The comparison process includes feature matching and error calculation, specifically as follows:
[0116] Feature matching: Match the temporal features of real-time network traffic data with the normal traffic patterns predicted by the model. By calculating the error between the real-time data and the predicted data, evaluate the similarity between the real-time traffic and the normal behavior pattern;
[0117] Error calculation: Calculate the deviation error between the real-time traffic and the normal behavior pattern. The error formula is:
[0118]
[0119] where x t ,i is the temporal feature of the real-time network traffic data, is the normal traffic feature predicted by the temporal behavior model, and n is the dimension of the feature vector.
[0120] S33, Deviation score calculation: Calculate the deviation score based on the error between the real-time network traffic and the normal traffic behavior pattern. The deviation score reflects the degree of deviation between the real-time traffic and the normal behavior pattern. The larger the score value, the higher the degree of abnormality of the real-time network traffic. The deviation score calculation method is:
[0121] Scoring formula: Calculate the deviation score through the following formula based on the calculated error value:
[0122]
[0123] where the error is the difference between the real-time traffic data and the normal traffic pattern, and the error threshold is the preset normal fluctuation range value;
[0124] S34, Comparison of deviation score with threshold: Set a threshold for the deviation score. If the calculated deviation score exceeds this threshold, determine that the real-time network traffic data for this period is abnormal traffic. The threshold is set using a fixed threshold setting method, and the threshold for the deviation score is set according to historical experience or standard test data.
[0125] S4 includes:
[0126] S41, Input for abnormal traffic clustering: Input the abnormal traffic data detected in S3 into the clustering algorithm. The abnormal traffic data includes network traffic data with a deviation score exceeding the set threshold, and includes its temporal features, deviation score, and other information related to abnormal behavior. The input data for the clustering process includes:
[0127] Temporal features: Include temporal features such as traffic change rate, packet arrival interval time, and packet size change;
[0128] Deviation score: Include the deviation score calculated through step S3, which is used to evaluate the severity of abnormal traffic;
[0129] Traffic metadata: It includes metadata such as the source IP of the traffic, the destination IP, and the port number, which are used to analyze the origin and destination of the traffic.
[0130] S42, Application of K-means clustering algorithm: The K-means clustering algorithm is used to perform clustering analysis on the abnormal traffic data. The steps are as follows:
[0131] The K-means clustering algorithm divides the abnormal traffic data into K groups;
[0132] Select the value of K: According to the data characteristics and actual requirements, select the number of clusters K. The value of K can be determined by methods such as the elbow method and the silhouette coefficient to ensure the best clustering effect;
[0133] Initialize the center points: Randomly select K initial clustering centers (centroids), or select appropriate initial center points through data analysis;
[0134] Data assignment: Assign all abnormal traffic data to the group to which the nearest clustering center belongs. The distance metric of the clustering center usually uses the Euclidean distance;
[0135] Update the clustering center: Update the clustering center according to the mean value of all data in each group until the clustering center is stable or the maximum number of iterations is reached;
[0136] Convergence condition: When the clustering center no longer changes or reaches the preset stop condition, the algorithm ends and the clustering result is determined.
[0137] S43, Analysis of clustering results: Analyze the K-means clustering results to find abnormal traffic groups with similar behavior patterns. The clustering analysis includes the following steps:
[0138] Group behavior recognition: Through the statistical analysis of each clustering group, extract the typical behavior patterns of the group, including traffic characteristics, time distribution characteristics, IP distribution characteristics, etc.;
[0139] Behavior pattern annotation: Compare the behavior patterns of the group with the known network attack characteristics, and label the potential attack types of each clustering group, for example:
[0140] Malicious scanning: The traffic pattern of scanning the destination IP from multiple source IPs;
[0141] DDoS attack: High-frequency and high-concurrency traffic aggregation, usually involving a large number of source IPs attacking the target;
[0142] Intrusion behavior: Malicious traffic penetrates the target network through specific ports or protocols.
[0143] S44, Classification of Clustering Results and Identification of Attack Types: Conduct classification analysis based on the clustering results and identify potential attack types. The classification process includes the following steps:
[0144] Classification of Behavioral Patterns: Based on the results of clustering analysis, classify each group into known attack types, such as malicious scanning, DDoS attacks, and intrusion behaviors;
[0145] Establishment of Attack Type Model: Construct an attack type identification model, and use the clustering results and known attack characteristics to train a classification model, such as a support vector machine or a decision tree model, for automatic classification and identification;
[0146] Attack Identification: Automatically identify the attack type for each clustering group and label it with the corresponding attack type. The attack types include:
[0147] Malicious Scanning: The typical abnormal traffic pattern is frequent port scanning, usually distributed among multiple source IPs;
[0148] DDoS Attack: A large number of data packets arrive at the target within a short period of time, forming a sudden increase in traffic, and the source IPs may be highly dispersed;
[0149] Intrusion Behavior: Malicious traffic usually shows fluctuations in traffic targeting specific ports or protocols, with obvious attack characteristics.
[0150] S45, Generation of Attack Type Report: Generate a detailed attack report based on the identified attack types. The report content includes:
[0151] Attack Type: Indicate the detected attack type, such as malicious scanning, DDoS attack, or intrusion behavior;
[0152] Traffic Characteristics: Provide detailed information such as the temporal characteristics of attack traffic, source IP, and target IP;
[0153] Potential Risk Assessment: Evaluate the potential network security risks brought by the detected attacks and provide a basis for subsequent responses.
[0154] S5 includes:
[0155] S51, Input of Real-time Network Security Status: According to the deviation score results generated in S3, monitor the security status of the computer network in real time. The real-time network security status includes the following:
[0156] Deviation Score: The deviation score from step S3, used to quantify the difference between real-time network traffic and normal behavior patterns;
[0157] Network Traffic Status: Real-time traffic characteristics, including traffic change rate, packet arrival interval time, packet size, etc.
[0158] S52, Alarm Mechanism: When the deviation score exceeds the set threshold, the alarm mechanism is automatically triggered. The alarm content includes:
[0159] Deviation Score: Provide the deviation score of the abnormal traffic and its changing trend;
[0160] Abnormal Traffic Characteristics: Include the time series characteristics of the abnormal traffic, packet size, source / destination IP, etc.;
[0161] Attack Type Prediction: According to the clustering analysis results in S6, report the possible attack types corresponding to the abnormal traffic, such as malicious scanning, DDoS attacks, etc.
[0162] Alarm Method: The alarm information is sent to the administrator or network security personnel through multiple channels. The alarm methods include email, SMS, desktop notifications, etc.
[0163] S53, Formulation of Defense Response Strategy: According to the real-time network security status and the identified abnormal traffic types, formulate real-time defense response strategies. The formulation of the defense response strategy includes the following steps:
[0164] Classification of Abnormal Traffic: According to the clustering analysis results and deviation scores in S6, determine the attack types of the abnormal traffic, such as malicious scanning, DDoS attacks or intrusion behaviors.
[0165] Assessment of Attack Severity: By evaluating the severity of the attack, combining factors such as the duration of the abnormal traffic, traffic peak, and impact scope, assess the harm level of the attack, and formulate response strategies based on this level.
[0166] Low-Risk Attacks: For low-risk attack types, such as malicious scanning, take mild response measures, such as IP blacklisting or traffic restriction;
[0167] High-Risk Attacks: For high-risk attack types, such as DDoS attacks, take more severe defense measures, such as traffic cleaning, network isolation, etc.
[0168] S5 includes:
[0169] S54, Automatic Adjustment of Firewall and Intrusion Detection / Prevention System: According to the real-time defense response strategy, automatically adjust the configurations of network security devices (such as firewalls, intrusion detection systems (IDS) and intrusion prevention systems (IPS)). The steps of automatic adjustment include:
[0170] Firewall Adjustment: According to the source IP, destination IP and attack type of the abnormal traffic, automatically modify the firewall rules. The adjustment measures include:
[0171] IP Blocking: Block the IP of the abnormal traffic source or restrict access;
[0172] Port Blocking: Block the ports of the attack target to prevent malicious traffic from entering the network.
[0173] Intrusion Detection System Adjustment: Adjust the monitoring strategy of the IDS and increase the monitoring intensity for abnormal traffic patterns. The adjustment measures include:
[0174] Increase Packet Inspection Frequency: Increase the monitoring frequency for in-depth inspection and content analysis of packets;
[0175] Detect Sensitive Traffic Features: Pay close attention to traffic similar to abnormal traffic features and give early warnings of possible attacks.
[0176] Intrusion Prevention System Adjustment: Automatically activate the defense function of the IPS, take measures against abnormal traffic, and ensure that the network is protected from attacks. The adjustment measures include:
[0177] Traffic Filtering: Filter or clean large-scale traffic such as DDoS attacks to reduce the impact of attacks on the network;
[0178] Attack Interception: Intercept intrusion behaviors in real time to prevent malicious traffic from entering the internal network.
[0179] S55, Network Isolation and Access Restriction: According to the defense response strategy, perform network isolation and access restriction. The specific implementation of this step includes:
[0180] Network Isolation: During high-risk attacks (such as DDoS attacks or intrusion behaviors), the system can automatically isolate the affected network segments, limit the spread of abnormal traffic, and prevent attacks from spreading.
[0181] Access Restriction: Restrict access or limit the rate of abnormal traffic source IPs to prevent attackers from consuming system resources through a large number of requests. This step can be achieved through the joint work of firewalls, IPSs, and IDSs.
[0182] Such as Figure 2 As shown, a computer network security analysis system based on big data is used to implement the above-mentioned computer network security analysis method based on big data, and includes the following modules:
[0183] Data Acquisition Module: Deploy multiple data acquisition devices in the computer network, collect network traffic data in real time, and preprocess the collected data;
[0184] Model Construction Module: Based on the preprocessed network traffic data, extract the temporal features of the traffic, and use a long short-term memory network to construct a temporal behavior model of network traffic for identifying the behavior patterns of normal traffic;
[0185] Abnormal traffic recognition module: Using the constructed time-series behavior model, compare the time-series characteristics of real-time network traffic data with the behavior patterns of normal traffic in the time-series behavior model. If the deviation of the time-series characteristics extracted from the real-time network traffic data exceeds the preset threshold within a certain time window, the real-time network traffic data is considered abnormal traffic;
[0186] Abnormal traffic classification module: Cluster the detected abnormal traffic through a clustering algorithm to identify potential attack types;
[0187] Real-time response module: According to the deviation scoring result, combined with the real-time network security status, formulate a real-time defense response strategy.
[0188] This invention covers any substitutions, modifications, equivalent methods, and solutions made to the essence and scope of this invention. To enable the public to have a thorough understanding of this invention, specific details are described in detail in the following preferred embodiments of this invention. However, those skilled in the art can fully understand this invention without these detailed descriptions. Additionally, well-known methods, processes, procedures, components, and circuits are not described in detail to avoid unnecessary confusion to the essence of this invention.
[0189] The above are only the preferred embodiments of this invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of this invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of this invention.
Claims
1. A computer network security analysis method based on big data, characterized in that: The following steps are involved: S1, data collection and preprocessing: deploy multiple data collection devices in the computer network to collect network traffic data in real time and preprocess the collected data; S2, time series feature extraction and modeling: based on the preprocessed network traffic data, extract the time series features of the traffic; The network traffic data is segmented into continuous time segments based on an adaptive sliding window method, and a time series behavior model of network traffic is constructed using a long short-term memory network to identify the behavior pattern of normal traffic. S3, abnormal behavior detection and deviation scoring: using the constructed time series behavior model, the time series characteristics of real-time network traffic data are compared with the behavior pattern of normal traffic in the time series behavior model; A deviation scoring threshold is set. If the deviation of the time series features extracted from the real-time network traffic data exceeds the threshold within a certain time window, the real-time network traffic data is considered to be abnormal traffic. S4, abnormal traffic clustering and classification: The detected abnormal traffic is clustered through a clustering algorithm to find abnormal traffic groups with similar behavior patterns. Through further classification analysis, potential attack types are identified, including malicious scanning, DDoS attacks and intrusion behaviors; S5, real-time response based on deviation scoring: formulate a real-time defense response strategy based on the deviation scoring results in S3 and the real-time network security status; If the deviation score exceeds the set threshold, an alarm is automatically triggered and an abnormality report is sent to the administrator. At the same time, according to the category and severity of the abnormal traffic, the firewall, intrusion detection system and intrusion prevention system are automatically adjusted to perform corresponding network isolation and access restrictions.
2. According to a computer network security analysis method based on big data according to claim 1, it is characterized in that: The S1 includes: S11, data collection node deployment: deploying multiple data collection devices in a computer network, the devices including network routers, switches and servers, to collect network traffic data in real time; S12, data collection: collect network traffic data in real time through multiple deployed data collection devices, the network traffic data including network packet header information, traffic timing data and TCP connection status; S13, data cleaning: cleaning the collected network traffic data to remove invalid or erroneous data; S14, data denoising: performing denoising processing on the cleaned network traffic data to remove random noise from the network environment; S15, data standardization processing: standardizing the denoised network traffic data.
3. A computer network security analysis method based on big data according to claim 2, characterized in that: The S2 includes: S21, extracting time series features: extracting time series features of traffic based on the preprocessed network traffic data, wherein the time series features include traffic change rate, packet arrival interval time and packet size change; S22, statistical analysis of timing features: performing statistical analysis on the extracted timing features to obtain the overall behavior pattern of the network traffic.
4. A computer network security analysis method based on big data according to claim 3, characterized in that: The S2 further includes: S23, network traffic data segmentation: segmenting the preprocessed network traffic data into continuous time segments by a method based on an adaptive sliding window; S24, temporal behavior model construction: Use long short-term memory network to model the segmented time segments and build a temporal behavior model of network traffic; S25, behavior pattern recognition: Use the trained time series behavior model to predict real-time network traffic data and identify the behavior pattern of normal traffic.
5. A computer network security analysis method based on big data according to claim 4, characterized in that: The S3 includes: S31, real-time network traffic data input: inputting the time series characteristics of the real-time collected network traffic data into the constructed time series behavior model; S32, comparing the timing characteristics with the normal behavior pattern: using the trained timing behavior model, processing the timing characteristics of the real-time network traffic data, and comparing them with the behavior pattern of the normal traffic, the comparison process includes feature matching and error calculation; S33, deviation score calculation: according to the error between the real-time network traffic and the normal traffic behavior pattern, the deviation score is calculated, and the larger the score value, the higher the abnormality of the real-time network traffic; S34, comparing the deviation score with a threshold: setting a deviation score threshold, if the calculated deviation score exceeds the threshold, the real-time network traffic data of the time period is determined to be abnormal traffic.
6. A computer network security analysis method based on big data according to claim 5, characterized in that: The S4 includes: S41, abnormal traffic clustering input: input the abnormal traffic data detected in S3 into the clustering algorithm; S42, K-means clustering algorithm application: K-means clustering algorithm is used to perform cluster analysis on abnormal traffic data; S43, clustering result analysis: Analyze the K-means clustering results to find abnormal traffic groups with similar behavior patterns; S44, clustering result classification and attack type identification: perform classification analysis based on the clustering results and identify potential attack types; S45, attack type report generation: Generate a detailed attack report according to the identified attack type.
7. A computer network security analysis method based on big data according to claim 6, characterized in that: The S5 includes: S51, real-time network security status input: according to the deviation scoring result generated in S3, the security status of the computer network is monitored in real time; S52, alarm mechanism: if the deviation score exceeds the set threshold, the alarm mechanism is automatically triggered; S53, Defense response strategy formulation: formulate a real-time defense response strategy based on the real-time network security status and the identified abnormal traffic types.
8. A computer network security analysis method based on big data according to claim 7, characterized in that: The S5 includes: S54, Automatically adjust firewall and intrusion detection / prevention systems: Automatically adjust network security devices based on real-time defense response strategies; S55, Network isolation and access restriction: Perform network isolation and access restriction based on defense response strategies.
9. A computer network security analysis system based on big data, used to implement a computer network security analysis method based on big data as described in any one of claims 1 to 8, characterized in that: Includes the following modules: Data collection module: deploy multiple data collection devices in the computer network to collect network traffic data in real time and pre-process the collected data; Model building module: Based on the preprocessed network traffic data, the time series characteristics of the traffic are extracted, and the time series behavior model of the network traffic is constructed using the long short-term memory network to identify the behavior pattern of normal traffic; Abnormal traffic identification module: using the established time series behavior model, the time series features of real-time network traffic data are compared with the behavior patterns of normal traffic in the time series behavior model. If the deviation of the time series features extracted from the real-time network traffic data within a certain time window exceeds the preset threshold, the real-time network traffic data is considered to be abnormal traffic; Abnormal traffic classification module: clusters the detected abnormal traffic through a clustering algorithm to identify potential attack types; Real-time response module: formulates real-time defense response strategies based on deviation scoring results and real-time network security status.
Citation Information
Cited By
Traffic processing method and device, electronic equipment and storage medium
CN120750664A
DDoS attack defense method and system based on multi-source flow perception
CN120915548A