Operation and maintenance data query analysis method of Internet data center
By using initial threshold dynamic adaptive adjustment strategy and machine learning model to generate latent permeability coefficients in IDC, the problem of difficulty in detecting and defending low bandwidth and decentralized permeability attacks is solved, and timely discovery and response to highly concealed attacks is achieved, ensuring network security and stability.
Patent Information
- Application Number
- CN202510274816.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-10
- Publication Date
- 2025-05-27
AI Technical Summary
The existing technology is difficult to detect and defend against low-bandwidth, decentralized penetration attacks within IDCs. This type of attack is highly concealed and can often be undetected within months or even years, resulting in serious risk of information leakage.
The initial threshold dynamic adaptive adjustment strategy is adopted, and the microbehavior characteristics are extracted in combination with deep analysis, and latent permeability coefficients are generated through machine learning models to accurately identify abnormal traffic. When abnormal risks are detected, the initial detection threshold is automatically adjusted to enhance the detection system's perception of latent attacks.
It effectively improves IDC's detection and response capabilities for highly concealed and long-term continuous attack activities, minimizes the long-term potential leakage risk of enterprise sensitive information, and ensures the security and stability of IDC's cyberspace.
Smart Images

Figure CN120050113A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of operation and maintenance of Internet data centers, and particularly to a method for querying and analyzing operation and maintenance data of an Internet data center. Background Art
[0002] Querying and analyzing operation and maintenance data based on an Internet data center (IDC) means using information technology to efficiently query, mine, and analyze various types of data generated during the daily operation and maintenance of the IDC to support operation and maintenance management and optimization decisions. The operation and maintenance data of the IDC includes multi-dimensional data such as server running status, network traffic, storage utilization, fault logs, security events, and energy consumption monitoring. By building an efficient data query system, key indicators can be quickly retrieved to achieve real-time monitoring of the health status of devices; combined with technologies such as big data analysis and machine learning, abnormal patterns can be mined, fault trends can be predicted, and resource allocation can be optimized, thereby improving the operation and maintenance efficiency of the IDC, reducing the failure rate, optimizing energy consumption management, and enhancing the overall service quality and user experience.
[0003] Querying and analyzing the horizontal traffic data of the IDC is mainly used for network security monitoring, resource optimization, anomaly detection, and fault troubleshooting. Horizontal traffic refers to the traffic between servers, storage devices, and virtual machines within the data center. Its analysis can help identify potential lateral penetration attacks (such as internal worm propagation and unauthorized access), detect abnormal traffic patterns (such as sudden large-scale data copying or abnormal high-frequency API calls), and prevent internal data leakage or malware spread. At the same time, by analyzing the traffic load, the network architecture can be optimized, computing and storage resources can be balanced, bandwidth bottlenecks can be reduced, and data transmission efficiency can be improved. In addition, combined with historical traffic data, the IDC can predict business growth trends, adjust network resource allocation, and ensure efficient and stable operation and maintenance management.
[0004] The existing technologies have the following deficiencies:
[0005] When an attacker obtains access rights within the IDC, they usually do not directly send a large amount of data outward. Instead, they use a distributed small-flow method to transmit data in batches between multiple servers by disguising as data transmission protocols of legitimate services (such as DNS tunnels, ICMP tunnels, and internal P2P traffic), and finally transmit it externally uniformly by a specific outbound node. Since most existing detection technologies mainly target large-flow abnormal activities, this low-bandwidth and decentralized penetration is extremely concealed and can often continue for months or even years without being discovered, ultimately causing serious losses to enterprises or organizations.
[0006] The above information disclosed in the background art section is only used to enhance the understanding of the background of the present disclosure. Therefore, it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention
[0007] The object of the present invention is to provide an operation and maintenance data query and analysis method for an Internet data center, which adopts an initial threshold dynamic adaptive adjustment strategy, combines in-depth analysis to extract key microscopic behavior characteristics, and then deeply analyzes the traffic with the help of a machine learning model to generate a latent penetration coefficient to accurately identify abnormal traffic; finally, when an abnormal risk is detected, the initial detection threshold is automatically adjusted to continuously enhance the detection system's perception ability of latent attacks, enabling the IDC to timely discover and actively respond to highly concealed and long-term continuous attack activities, minimizing the risk of long-term latent leakage of enterprise sensitive information, ensuring the security and stability of the IDC network space, and providing a strong guarantee for the secure operation of enterprise information, so as to solve the problems in the above-mentioned background technology.
[0008] To achieve the above object, the present invention provides the following technical solution: An operation and maintenance data query and analysis method for an Internet data center, comprising the following steps:
[0009] Combined with existing business requirements, security policies, and historical traffic data, set an initial detection threshold for horizontal traffic detection to distinguish normal traffic from suspicious traffic;
[0010] After completing the initial detection threshold setting, comprehensively capture real-time data of all horizontal traffic within the IDC, and preprocess the obtained traffic data;
[0011] Extract features from the real-time obtained traffic data, and deeply analyze the extracted features to initially quantify the behavior pattern of abnormal transmission of distributed small traffic;
[0012] Input the features obtained through in-depth analysis as feature vectors into a pre-trained machine learning model to identify abnormal behaviors of distributed small traffic transmission;
[0013] When the machine learning model confirms the detection of abnormal transmission of distributed small traffic data, immediately activate the dynamic threshold adjustment mechanism, and according to the prediction result of the machine learning model, lower the original initial detection threshold to make the traffic monitoring system more sensitive to subsequent abnormal behaviors of low bandwidth and small traffic.
[0014] Preferably, to distinguish normal traffic from suspicious traffic, the specific steps are as follows:
[0015] Real-time monitor the internal lateral traffic in the IDC, and compare and analyze the size of the real-time traffic actually collected in each time period with the set initial detection threshold one by one; if the size of the real-time traffic exceeds the set initial detection threshold, mark it as suspicious traffic and initiate an in-depth anomaly analysis process for further anomaly detection and fault troubleshooting; conversely, if the size of the real-time traffic does not exceed the initial detection threshold, mark it as normal traffic, allow it to continue transmission and record it in real time.
[0016] Preferably, comprehensively capture real-time data of all internal lateral traffic in the IDC, and the specific steps are as follows:
[0017] Deploy distributed traffic collection devices at key network nodes;
[0018] Configure the distributed traffic collection devices to capture all protocol data, and ensure data time synchronization and refined marking;
[0019] Use a high-speed data acquisition and storage system to aggregate and transmit the real-time captured data to the central monitoring platform;
[0020] Transmit the captured data to the traffic analysis and anomaly detection system in real time to provide detailed data support for subsequent security monitoring and fault troubleshooting.
[0021] Preferably, extract features from the real-time obtained traffic data. Among them, the extracted features include the proportion of the average packet size remaining at a low level and continuously sending, and the path dispersion degree of small traffic horizontally jumping in the internal network. During the monitoring window period, deeply analyze the extracted features, respectively generate a micro-packet persistence reference value and a horizontal jump reference value, and initially quantify the abnormal transmission behavior pattern of distributed small traffic through the micro-packet persistence reference value and the horizontal jump reference value.
[0022] Preferably, input the micro-packet persistence reference value and the horizontal jump reference value obtained through in-depth analysis as feature vectors into a pre-trained machine learning model, generate a latent penetration coefficient through the machine learning model, and identify the abnormal behavior of distributed small traffic transmission through the latent penetration coefficient.
[0023] Preferably, compare and analyze the latent penetration coefficient generated by the pre-trained machine learning model during the prediction of all internal lateral traffic transmission processes in the IDC with the pre-set latent penetration coefficient reference threshold to identify the abnormal behavior of distributed small traffic transmission. The specific identification process is as follows:
[0024] If the latent penetration coefficient is greater than the latent penetration coefficient reference threshold, classify the internal lateral traffic transmission process in the IDC as an abnormal behavior of distributed small traffic transmission; if the latent penetration coefficient is less than or equal to the latent penetration coefficient reference threshold, classify the internal lateral traffic transmission process in the IDC as a normal process transmission behavior.
[0025] Preferably, within the monitoring window period, the specific steps for deeply analyzing the proportion of the average packet size remaining at a low level and continuously transmitting to generate a micro-packet persistence reference value are as follows:
[0026] Within the monitoring window period, first process all captured lateral traffic data and analyze packets with a size lower than the preset threshold S th For the packets, mark the packets with a size lower than the preset threshold as micro-packet traffic. Calculate the micro-packet persistence factor through the micro-packet traffic data to quantify the persistence and density of micro-packet transmission. The calculation formula for the micro-packet persistence factor is:
[0027]
[0028] , where: L pcf is the micro-packet persistence factor, N is the total number of packets within the monitoring window period, λ is the weight parameter for adjusting time sensitivity, is the indicator function. If s k <S th then output 1, otherwise output 0. s k represents the size of the k-th packet. To describe the continuity of low-traffic packets in time, introduce the time interval d k between every two consecutive micro-packets and attenuate it with an exponential weight;
[0029] After obtaining the micro-packet persistence factor, combine it with the overall proportion R of micro-packet transmission to construct a micro-packet persistence reference value that comprehensively reflects the abnormal transmission behavior of distributed small traffic. The constructed expression is:
[0030]
[0031] , where: M ppi is the micro-packet persistence reference value, α and μ are adjustable parameters for adjusting the weights of the overall proportion R of micro-packet transmission and the micro-packet persistence factor L pcf in the final micro-packet persistence reference value, and η is a small constant to prevent the denominator from being zero.
[0032] Preferably, within the monitoring window period, the specific steps for deeply analyzing the path dispersion degree of small traffic horizontally jumping in the internal network to generate a micro-packet persistence reference value are as follows:
[0033] Within the monitoring window period T, capture all the horizontal jump paths of small traffic and construct a path dispersion matrix to measure the propagation of distributed traffic between different servers. Let the set of servers in the network topology be S = {s 1 , s 2 ,..., s n}, where \(n\) represents the total number of servers. Among them, the hopping relationship of small traffic between servers is represented by the hopping weight matrix \(J(t)\), which represents the horizontal hopping degree of small traffic. The specific expression is:
[0034]
[0035] , where: \(H\) ij (t) represents the frequency of small traffic hopping from server \(s\) i to server \(s\) j ; \(w\) ij is the business correlation weight from server \(s\) i to \(s\) j ; \(d\) ij is the topological shortest path from server \(s\) i to \(s\) j , representing the network distance between two servers;
[0036] After obtaining the hopping weight matrix \(J(t)\), the horizontal hopping reference value is calculated through the hopping weight matrix to quantify the abnormal hopping behavior of small traffic in the internal network. The calculation expression is:
[0037]
[0038] , where: \(L\) hi is the horizontal hopping reference value, \(K\) represents the maximum observed continuous hopping number within the monitoring window period, \(P\) i (t) is the number of micro-packets of server \(s\) i at time \(t\), \(k\) represents the number of horizontal hops of a certain observed small traffic, that is, the number of hopping layers of a single small traffic packet from the source server through different target servers in sequence, and \(\beta\) is the amplification coefficient of the exponential growth factor, which is used to amplify the weight of traffic with high hopping times, so that the abnormal score during multiple consecutive hops can be quickly improved.
[0039] Preferably, when the machine learning model confirms the detection of abnormal transmission of distributed small traffic data, the dynamic threshold regulation mechanism is started to lower the original initial detection threshold. The specific steps are as follows:
[0040] Calculate the dynamic regulation factor, which is used to calculate the adjustment amplitude of the new detection threshold according to the deviation degree between the latent penetration coefficient and the latent penetration coefficient reference threshold. The calculation expression of the dynamic regulation factor is:
[0041]
[0042] , where: \(A\) af is the dynamic regulation factor, \(latent\) infilis the latent penetration coefficient predicted by the current machine learning model, which reflects the degree of abnormality in traffic transmission, latent th is the preset reference threshold of the latent penetration coefficient, which is used to judge whether the traffic behavior is normal, γ x is the adjustment sensitivity coefficient, which controls the change amplitude of the detection threshold. tanh(·) is the hyperbolic tangent function, ensuring that the change of the regulation factor is between (-1, 1), making the adjustment amplitude have the characteristic of non-linear growth. ∈ is the minimum term to prevent the denominator from being zero;
[0043] Calculate the dynamic regulation factor A af After that, apply this dynamic regulation factor to adaptively lower the original initial detection threshold, making the traffic monitoring system more sensitive to small traffic attacks. The calculation formula of the new dynamic detection threshold is as follows:
[0044] T new =T 0 ·(1 - α x ·|A af |)
[0045] , where: T 0 is the initial detection threshold, representing the normal detection standard of the system when there is no abnormality, T new is the actual detection threshold after dynamic adjustment, ensuring that the monitoring system is more sensitive to the abnormal behavior of small traffic transmission. α x is the dynamic regulation weight, 0 < α x ≤1, which is used to adjust the intensity of the detection threshold reduction to adapt to the security requirements in different environments. |A af | takes the absolute value of the dynamic regulation factor A af , ensuring that the detection threshold is always reduced when adjusted.
[0046] In the above technical solution, the technical effects and advantages provided by the present invention are as follows:
[0047] The present invention adopts the initial threshold dynamic adaptive adjustment strategy, combines in-depth analysis to extract key microscopic behavior characteristics, and then uses the machine learning model to deeply analyze the traffic, so as to generate the latent penetration coefficient to accurately identify abnormal traffic; finally, when detecting abnormal risks, automatically regulate the initial detection threshold, continuously strengthen the perception ability of the detection system for latent attacks, enable the IDC to timely discover and actively respond to highly concealed and long-term continuous attack activities, minimize the risk of long-term latent leakage of enterprise sensitive information, ensure the security and stability of the IDC cyberspace, and provide a strong guarantee for the secure operation of enterprise information. Description of the Drawings
[0048] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required in the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments recorded in the present invention. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings.
[0049] Figure 1 This is a method flowchart of an operation and maintenance data query and analysis method for an Internet data center of the present invention. Specific embodiments
[0050] Now, the exemplary embodiments will be described more comprehensively with reference to the accompanying drawings. However, the exemplary embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these exemplary embodiments are provided so that the present disclosure will be more comprehensive and complete, and will fully convey the concept of the exemplary embodiments to those skilled in the art.
[0051] The present invention provides Figure 1 An operation and maintenance data query and analysis method for an Internet data center as shown, including the following steps:
[0052] Combined with existing business requirements, security policies, and historical traffic data, set an initial detection threshold for horizontal traffic detection to distinguish normal traffic from suspicious traffic;
[0053] The purpose of setting this initial detection threshold is to enable the system to have a set of judgment criteria at an early stage, which can quickly alarm most abnormal traffic (especially large - volume anomalies). At the same time, turn on the real - time traffic monitoring function to continuously collect the horizontal traffic inside the IDC to ensure that the latest and complete traffic data is available in the subsequent detection and analysis stages.
[0054] To distinguish normal traffic from suspicious traffic, the specific steps are as follows:
[0055] Real - time monitor the horizontal traffic inside the IDC, and compare and analyze the size of the actually collected traffic in each time period with the set initial detection threshold one by one; if the real - time traffic size exceeds the set initial detection threshold, mark it as suspicious traffic and start an in - depth anomaly analysis process for further anomaly detection and fault troubleshooting; conversely, if the real - time traffic size does not exceed the initial detection threshold, mark it as normal traffic, allow it to continue transmission, and record it in real time.
[0056] After setting the initial detection threshold, perform a comprehensive real - time data capture on all horizontal traffic inside the IDC, and pre - process the obtained traffic data;
[0057] To comprehensively and real-time capture all lateral traffic within the IDC, first, distributed traffic collection devices need to be deployed at key network nodes (such as core switches, routers, and server ports); second, configure these devices to capture all protocol data including TCP, UDP, ICMP, DNS, HTTP, etc., and ensure data time synchronization and refined marking; then, use a high-speed data collection and storage system to aggregate and transmit the real-time captured data to the central monitoring platform; finally, transmit the processed data to the traffic analysis and anomaly detection system in real time to provide detailed data support for subsequent security monitoring and fault troubleshooting.
[0058] The lateral traffic within the IDC mainly refers to the internal data exchange and communication among servers, storage devices, virtual machines, and containers in the data center. These traffic not only cover regular business interactions such as database synchronization, API calls, file sharing, and service calls, but also include internal management and monitoring data, communication between virtualization platforms, and data transmission of various distributed computing tasks. In addition, it may also involve internal P2P communication, distributed cache synchronization, and traffic between security devices. These traffic together constitute the lateral traffic environment within the IDC.
[0059] Preprocessing mainly includes steps such as data cleaning, format conversion, denoising, data normalization, and timestamp alignment. Specifically, the cleaning process filters out duplicate, invalid, or incomplete data packets; format conversion ensures that all traffic data has a unified standard for subsequent analysis; denoising and normalization steps help reduce the impact of data fluctuations, enabling traffic data from different sources and different formats to be compared under the same benchmark; timestamp alignment ensures that when conducting time-series analysis on traffic, each data record can be correctly matched. The main role of preprocessing is to improve data quality, provide accurate, clean, and unified input data for subsequent feature extraction and anomaly detection, thereby enhancing the accuracy and reliability of the detection system.
[0060] Extract features from the real-time obtained traffic data, and conduct in-depth analysis on the extracted features to preliminarily quantify the behavior patterns of abnormal transmission of distributed small traffic.
[0061] Extract features from the real-time obtained traffic data. Among them, the extracted features include the proportion of the average packet size remaining at a low level (such as dozens of bytes) and continuously sending, and the path dispersion degree of small traffic hopping laterally in the internal network. During the monitoring window period, conduct in-depth analysis on the extracted features to generate a micro-packet persistence reference value and a lateral jump reference value respectively, and preliminarily quantify the behavior patterns of abnormal transmission of distributed small traffic through the micro-packet persistence reference value and the lateral jump reference value.
[0062] When all the internal IDC horizontal traffic is comprehensively and real-time captured, if the monitoring data shows that the average packet size continuously remains at an extremely low level (for example, only dozens of bytes), and the sending ratio of such small packets is significantly high, this usually indicates the existence of potential distributed small traffic abnormal transmission behavior. Because normal business data transmission often exhibits characteristics of larger data packets or significant data fluctuations, while attackers, to avoid triggering traditional large traffic anomaly detection, will use low-bandwidth, continuous, and dispersed small traffic methods for data penetration, thus making this abnormal traffic characteristic an important indication signal for covert attacks.
[0063] During the monitoring window period, the specific steps to generate a micro-packet persistence reference value by deeply analyzing the average packet size maintained at a low level (such as dozens of bytes) and the continuous sending ratio are as follows:
[0064] During the monitoring window period, first process all the captured horizontal traffic data, and focus on analyzing the data packets with a size lower than the preset threshold S th (such as dozens of bytes). Denote the data packets lower than the preset threshold as micro-packet traffic. Calculate the micro-packet persistence factor through the micro-packet traffic data to quantify the persistence and density of micro-packet transmission. The calculation formula for the micro-packet persistence factor is:
[0065]
[0066] , where: L pcf is the micro-packet persistence factor, N is the total number of data packets within the monitoring window period, λ is the weight parameter for adjusting time sensitivity, is the indicator function. If s k <S th then output 1, otherwise output 0. s k represents the size of the k-th data packet. To depict the continuity of low-traffic packets in time, introduce the time interval d k between every two consecutive micro-packets, and decay it with exponential weight to emphasize that the shorter the interval, the greater its contribution;
[0067] The function of this step is to quantify the persistence and density of micro-packet transmission. A high micro-packet persistence factor value indicates strong micro-packet continuity within the monitoring window period, laying a foundation for subsequent abnormal pattern recognition.
[0068] After obtaining the micro-packet persistence factor, combined with the overall ratio R of micro-packet sending (that is, the ratio of the number of micro-packets to the total number of data packets within the monitoring window), construct a micro-packet persistence reference value that comprehensively reflects the distributed small traffic abnormal transmission behavior. The constructed expression is:
[0069]
[0070] , where: M ppiis the micro-packet continuous reference value, where α and μ are used to adjust the overall ratio R of micro-packet sending and the micro-packet continuous factor L pcf is an adjustable parameter of the weight in the final micro-packet continuous reference value, and η is a small constant to prevent the denominator from being zero;
[0071] This formula combines the increase in the micro-packet sending ratio (the attacker takes advantage of the characteristic of transmitting data with a large number of small packets) and the enhancement of the continuity between micro-packets (the attacker hides data transmission by sending micro-packets frequently and at short intervals) to generate a micro-packet continuous reference value that comprehensively reflects the abnormal transmission behavior of distributed small traffic. A high micro-packet continuous reference value indicates an obvious abnormal transmission behavior of distributed small traffic. The role of this step is to comprehensively quantify multi-dimensional traffic characteristics and provide a clear indicator for the real-time monitoring system to judge whether there are potential security threats.
[0072] As can be seen from the micro-packet continuous reference value, during the monitoring window period, the larger the performance value of the micro-packet continuous reference value generated by deeply analyzing the ratio of the average packet size remaining at a low level (such as dozens of bytes) and being continuously sent, it indicates that during the monitoring window period, the continuous sending ratio of low-size packets (such as dozens of bytes) is higher, and the transmission mode of these small packets presents the characteristics of high frequency, long time, and stability, which usually means there is a potential abnormal transmission behavior of distributed small traffic. In order to avoid being detected by traditional traffic anomaly detection systems, attackers may adopt a low-bandwidth and long-time small packet penetration strategy, which is manifested as a significant increase in the micro-packet continuous reference value. Therefore, when the micro-packet continuous reference value is high, attention should be paid to whether there are malicious data leakage or internal lateral movement behaviors. If the micro-packet continuous reference value is low, it indicates that the distribution, persistence, and concealment of the current small traffic data transmission are weak, and the possibility of abnormal penetration is small. Therefore, the size of the micro-packet continuous reference value directly reflects the risk level of small traffic abnormal transmission and can be used as an important indicator for detecting distributed covert attacks.
[0073] If the path dispersion degree of small traffic in the IDC internal network is relatively high, it usually indicates the existence of potential distributed small traffic abnormal transmission behavior during the data transmission process. This situation means that the traffic is not concentrated between specific source and destination nodes, but shows a wide jumping distribution among multiple servers, forming a multi-hop or "relay-style" transmission mode. Attackers may utilize this characteristic to forward small-scale data in batches between different servers to reduce the abnormal perception of a single node and bypass traditional traffic detection strategies. Such highly dispersed paths usually do not conform to the characteristics of normal business traffic, such as database synchronization, load balancing, or internal microservice calls, which often have a stable topology. Therefore, if the path distribution of lateral traffic exhibits high randomness, high dispersion, and is accompanied by low bandwidth and low frequency characteristics, it is very likely that attackers are using distributed small traffic for data leakage or stealth penetration, and further in-depth analysis and corresponding defense measures need to be taken.
[0074] During the monitoring window period, the specific steps for generating the micro-packet continuous reference value by deeply analyzing the path dispersion degree of small traffic in the internal network are as follows:
[0075] During the monitoring window period T, capture all the lateral jump paths of small traffic (the small traffic is the above-mentioned micro-packet traffic, that is, the data packets with a size lower than the preset threshold), and construct a path dispersion matrix to measure the propagation of distributed traffic between different servers. Let the set of servers in the network topology be S = {s 1 , s 2 ,..., s n}, where n represents the total number of servers. Among them, the jump relationship of small traffic between servers is represented by the jump weight matrix J(t), which represents the lateral jump degree of small traffic. The specific expression is:
[0076]
[0077] , where: H ij (t) represents the frequency (number of jumps) of small traffic from server s i to server s j at time t, w ij is the business correlation weight between server s i and s j . If the business correlation is low (unconventional interaction path), the weight is small and the abnormality degree is high. d ij is the topological shortest path (number of hops) from server s i to s j , indicating the network distance between two servers;
[0078] The key to this step is to construct the jump weight matrix J(t) for the horizontal traffic, taking into account the frequency of horizontal jumps, business relevance, and topological structure.
[0079] After obtaining the jump weight matrix J(t), calculate the horizontal jump reference value through the jump weight matrix to quantify the abnormal jump behavior of small traffic in the internal network. The calculation formula is:
[0080]
[0081] , where: L hi is the horizontal jump reference value, K represents the maximum observed number of consecutive jumps within the monitoring window period (i.e., the maximum number of horizontal jumps for a single small traffic), P i (t) is the number of micro-packets of server s i at time t, k represents the number of horizontal jumps of a certain small traffic currently observed, that is, the number of jump layers of a single small traffic packet from the source server through different target servers in sequence. β is the amplification coefficient of the exponential growth factor, used to perform more significant weight amplification on traffic with a high number of jumps (a large k value), so that the abnormal score during multiple consecutive jumps can be quickly improved, thereby more accurately identifying distributed penetration or hidden transmission behavior;
[0082] The horizontal jump reference value enables the system to accurately detect potential distributed small traffic covert transmissions by quantitatively evaluating the horizontal jump distribution of small traffic, and is used for subsequent security response and optimization of automated defense strategies.
[0083] From the horizontal jump reference value, it can be seen that within the monitoring window period, the larger the performance value of the micro-packet continuous reference value generated by deeply analyzing the path dispersion degree of small traffic horizontal jumps in the internal network, the higher the path dispersion degree, the more jump times, and the greater the abnormal weight of small traffic in the internal network, which means that the risk of distributed small traffic abnormal transmission behavior during data transmission is higher. This situation usually indicates that the attacker may be using multiple intermediate servers for low-speed and covert data distribution to avoid traditional traffic detection mechanisms and achieve data leakage or horizontal penetration. Conversely, if the value of the horizontal jump reference value is small, it means that the horizontal jump behavior of small traffic is less, the path distribution is more concentrated, or it conforms to the characteristics of normal business traffic, so the abnormal risk is lower. Therefore, the horizontal jump reference value is the core indicator for measuring the concealment and diffusion of distributed small traffic attacks, and can be used to dynamically adjust security policies and improve the detection ability of small traffic covert attacks.
[0084] Input the features obtained through in-depth analysis as feature vectors into the pre-trained machine learning model to identify abnormal behaviors of distributed small traffic transmissions;
[0085] The continuously referenced micro-packet value and the lateral jump reference value obtained through in-depth analysis are used as feature vectors and input into a pre-trained machine learning model. The machine learning model generates a latent penetration coefficient, and the abnormal behavior of distributed small-flow transmission is identified through the latent penetration coefficient.
[0086] The pre-trained machine learning model refers to that before actual application, a large amount of historical data and prior knowledge are used to pre-train and optimize the model parameters, enabling it to accurately capture and identify various complex behavior patterns in distributed small-flow transmission. Specifically, the model has been trained with a large number of sample data before actual deployment, and a recognizer that can extract key patterns from the feature space has been constructed using deep learning, decision trees, random forests, or other advanced algorithms. In this solution, the continuously referenced micro-packet value and the lateral jump reference value obtained through in-depth analysis are used as input feature vectors and input into this pre-trained model. By comparing the distribution characteristics of normal traffic and abnormal traffic in history, the model learns the internal correlation and dynamic change law between various indicators in different scenarios, and thus can automatically generate a "latent penetration coefficient". The latent penetration coefficient not only reflects the abnormal degree of the current network traffic, but also can quantitatively evaluate the hidden risk of data distributed transmission in the internal network, and then assist the security team to judge whether there are abnormal behaviors of continuous latency and hidden penetration. The advantage of the pre-trained machine learning model is that it has a high generalization ability and can quickly identify transmission behaviors that conform to historical abnormal patterns in newly emerging data. Even if these behaviors seem normal in a single indicator, they show an abnormal aggregation effect in the overall feature vector, thus realizing the accurate detection and early warning of distributed small-flow transmission.
[0087] The implementation process of the pre-trained model usually includes multiple links such as data preprocessing, feature extraction, model selection, and parameter optimization. In the data preprocessing stage, a large amount of horizontal traffic data collected inside the IDC will be cleaned, normalized, and feature engineered to ensure that the input data has high quality and representativeness. Next, by performing deep feature extraction on the data, two key parameters, the micro-packet continuous reference value and the horizontal jump reference value, are obtained, which reflect the dynamic characteristics of the traffic in terms of time and space. Then, using these feature data, researchers select appropriate machine learning algorithms (such as deep neural networks, convolutional neural networks, or ensemble learning models) for model training. During the training process, the model will continuously adjust its internal parameters to minimize the error between the predicted output (in this case, the latent penetration coefficient) and the actual abnormal behavior. After the pre-training process is completed, the model can quickly respond in real-time monitoring. By calculating the latent penetration coefficient generated by each input feature vector, it can evaluate whether there is abnormal penetration behavior in the current traffic. The entire process is supported by a large amount of historical data, making the model more robust and accurate when facing actual application scenarios. The pre-trained model can not only continuously receive new data for online fine-tuning after deployment, but also combine a continuous feedback mechanism to continuously optimize its discrimination ability to adapt to the dynamic changes in the network environment and evolving attack techniques. Finally, the latent penetration coefficient generated by this model can be used as an important reference index for the security monitoring system, helping operation and maintenance personnel to timely discover and respond to potential threats in distributed small-flow transmissions, thereby providing strong technical support for the security protection of the IDC.
[0088] The machine learning model is not specifically limited here. Any model that can implement the comprehensive analysis of the micro-packet continuous reference value M ppi and the horizontal jump reference value L hi to generate the latent penetration coefficient latent infil is acceptable. To implement the technical solution of the present invention, the present invention provides a specific implementation method; the calculation formula for generating the latent penetration coefficient latent infil is: latent infil =b p *M ppi +b q *L hi , where b p , b q are respectively the preset proportionality coefficients of the micro-packet continuous reference value M ppi and the horizontal jump reference value L hi , and both b p , b are greater than 0. The preset proportionality coefficient refers to when calculating the latent penetration coefficient (latent infil ), respectively for the micro-packet continuous reference value M ppi and the horizontal jump reference value Lhi The assigned weight factor b p and b q , which is used to control the contribution ratio of these two indicators in the final calculation. The role of these preset ratio coefficients is to adjust and optimize the influence of different features on the latent penetration behavior, ensuring that the calculation results can accurately reflect the degree of abnormality in data transmission. Since the micro-packet continuous reference value M ppi reflects the persistence characteristics of micro-packets, while the lateral jump reference value L hi reflects the jump diffusion of lateral traffic, and their influence degrees on abnormal transmission may be different. Therefore, it is necessary to artificially set appropriate ratio coefficients before calculation to adapt to different security environments and network structures. The preset ratio coefficient b p >0, b q >0 indicates that both of them act on the latent penetration coefficient, and their values can be optimized through experiments or historical data to make the detection model more accurate and stable.
[0089] From the latent penetration coefficient, it can be seen that during the monitoring window period, the larger the performance value of the micro-packet continuous reference value generated by deeply analyzing the proportion of the average packet size maintained at a low level (such as dozens of bytes) and continuously sent, and the larger the performance value of the micro-packet continuous reference value generated by deeply analyzing the path dispersion of small traffic jumping laterally in the internal network, that is, the larger the performance value of the latent penetration coefficient generated by the machine learning model completed through pre-training for predicting all lateral traffic transmission processes inside the IDC, the greater the risk of distributed small traffic abnormal transmission behavior during data transmission. On the contrary, it indicates that the risk of distributed small traffic abnormal transmission behavior during data transmission is smaller.
[0090] Compare and analyze the latent penetration coefficient generated by the machine learning model completed through pre-training for predicting all lateral traffic transmission processes inside the IDC with the preset latent penetration coefficient reference threshold to identify the abnormal behavior of distributed small traffic transmission. The specific identification process is as follows:
[0091] If the latent penetration coefficient is greater than the latent penetration coefficient reference threshold, then classify the lateral traffic transmission process inside the IDC as an abnormal behavior of distributed small traffic transmission; if the latent penetration coefficient is less than or equal to the latent penetration coefficient reference threshold, then classify the lateral traffic transmission process inside the IDC as a normal process transmission behavior.
[0092] When the machine learning model confirms the detection of abnormal transmission of distributed small traffic data, immediately start the dynamic threshold adjustment mechanism. According to the prediction results of the machine learning model, lower the original initial detection threshold to make the traffic monitoring system more sensitive to subsequent abnormal behaviors of low bandwidth and small traffic;
[0093] When the machine learning model confirms the detection of abnormal transmission of distributed small - flow data, start the dynamic threshold regulation mechanism and lower the original initial detection threshold. The specific steps are as follows:
[0094] After the machine learning model detects the abnormal transmission of distributed small - flow data, it is necessary to dynamically adjust the originally set initial detection threshold to improve the sensitivity of the detection system to low - bandwidth and small - flow attacks. First, calculate the dynamic regulation factor, which is used to calculate the adjustment amplitude of the new detection threshold according to the deviation degree between the latent penetration coefficient and the reference threshold of the latent penetration coefficient. The calculation expression of the dynamic regulation factor is:
[0095]
[0096] , where: A af is the dynamic regulation factor, latent infil is the latent penetration coefficient predicted by the current machine learning model, reflecting the abnormal degree of traffic transmission, latent th is the pre - set reference threshold of the latent penetration coefficient, used to judge whether the traffic behavior is normal, γ x is the adjustment sensitivity coefficient, controlling the change amplitude of the detection threshold. Usually, γ > 0, and its size determines the response strength of the system to abnormal situations. tanh(·) is the hyperbolic tangent function, ensuring that the change of the regulation factor is between (-1, 1), making the adjustment amplitude have a non - linear growth characteristic, preventing high false - alarm rates caused by large - amplitude oscillations, ∈ is a minimum term, preventing the denominator from being zero, usually taking ∈≈10 -6 ;
[0097] The dynamic regulation factor calculated in this step is used as the adjustment ratio coefficient, which can adaptively control the change of the detection threshold according to the deviation between the latent penetration coefficient and the reference threshold of the latent penetration coefficient. When the latent penetration coefficient far exceeds the reference threshold of the latent penetration coefficient, the dynamic regulation factor approaches the adjustment sensitivity coefficient, prompting the system to significantly lower the detection threshold; conversely, if the latent penetration coefficient only slightly exceeds the reference threshold of the latent penetration coefficient, the adjustment amplitude is small, avoiding too high a false - alarm rate.
[0098] After calculating the dynamic regulation factor A af , apply this dynamic regulation factor to adaptively lower the original initial detection threshold, making the traffic monitoring system more sensitive to small - flow attacks. The calculation formula of the new dynamic detection threshold is as follows:
[0099] T new = T 0 ·(1 - α x ·|A af |)
[0100] , where: T 0is the initial detection threshold, representing the normal detection standard of the system when there is no abnormality, T new is the actual detection threshold after dynamic adjustment, ensuring that the monitoring system is more sensitive to abnormal behaviors of small - flow transmissions, α x is the dynamic regulation weight, 0 < α x ≤1, which is used to adjust the intensity of the reduction of the detection threshold to adapt to the security requirements in different environments, |A af takes the absolute value of the dynamic regulation factor A af to ensure that the detection threshold is always reduced when adjusted (i.e., to improve the detection sensitivity);
[0101] This step implements an adaptive dynamic detection strategy:
[0102] When the latent penetration coefficient far exceeds the reference threshold of the latent penetration coefficient (indicating a serious abnormal transmission): A af ≈γ x , which causes the actual detection threshold after dynamic adjustment to drop significantly, greatly improving the detection sensitivity.
[0103] When the latent penetration coefficient is only slightly higher than the reference threshold of the latent penetration coefficient (indicating a slight abnormality): A af takes a small value, and the actual detection threshold after dynamic adjustment only drops slightly, preventing false alarms from interfering with normal operations.
[0104] When the latent penetration coefficient is less than or equal to the reference threshold of the latent penetration coefficient (indicating normal traffic): A af ≈0, then T new ≈T 0 , and the system maintains the original initial detection threshold without changing the detection sensitivity.
[0105] Through the above - mentioned scheme, the detection accuracy and sensitivity for abnormal transmissions of distributed small - flow within the IDC can be effectively improved. Especially in the scenario of data - stealing attacks with low bandwidth, long - term latency, and frequent lateral jumps, which are difficult to identify by traditional traffic anomaly detection means, this scheme adopts an initial threshold dynamic adaptive adjustment strategy, combines in - depth analysis to extract key microscopic behavior features (such as the micro - packet continuous reference value and the lateral jump reference value), and then uses a machine - learning model to deeply analyze the traffic, thereby generating a latent penetration coefficient to accurately identify abnormal traffic; finally, when abnormal risks are detected, the initial detection threshold is automatically regulated to continuously enhance the detection system's perception ability of latent attacks, enabling the IDC to timely discover and actively respond to highly concealed and long - term continuous attack activities, minimizing the risk of long - term latent leakage of enterprise sensitive information, ensuring the security and stability of the IDC cyberspace, and providing a strong guarantee for the secure operation of enterprise information.
[0106] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to get a formula closest to the actual situation. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.
[0107] As described above, it is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
[0108] Only some exemplary embodiments of the present invention have been described by way of illustration above. Undoubtedly, for those of ordinary skill in the art, the described embodiments can be modified in various different ways without departing from the spirit and scope of the present invention. Therefore, the above drawings and description are illustrative in nature and should not be construed as limiting the protection scope of the claims of the present invention.
Claims
1. A method for querying and analyzing operation and maintenance data of an Internet data center, characterized in that: The following steps are involved: Combine existing business requirements, security policies, and historical traffic data to set an initial detection threshold for lateral traffic detection to distinguish normal traffic from suspicious traffic. After the initial detection threshold is set, all lateral traffic within the IDC is fully captured in real time, and the acquired traffic data is preprocessed; Extract features from real-time traffic data and conduct in-depth analysis on the extracted features to preliminarily quantify the behavior patterns of abnormal transmission of distributed small traffic; The features obtained through deep analysis are used as feature vectors to input into the pre-trained machine learning model to identify abnormal behaviors of distributed small-volume traffic transmission. When the machine learning model confirms that abnormal transmission of distributed small-flow data has been detected, the dynamic threshold control mechanism is immediately activated. According to the results predicted by the machine learning model, the original initial detection threshold is lowered, making the traffic monitoring system more sensitive to subsequent low-bandwidth and small-flow abnormal behaviors.
2. The method for querying and analyzing operation and maintenance data of an Internet data center according to claim 1, characterized in that: To distinguish normal traffic from suspicious traffic, the specific steps are as follows: Monitor the lateral traffic inside the IDC in real time, and compare and analyze the actual real-time traffic size collected in each time period with the set initial detection threshold one by one; if the real-time traffic size exceeds the set initial detection threshold, it will be marked as suspicious traffic, and an in-depth anomaly analysis process will be initiated to conduct further anomaly detection and troubleshooting; conversely, if the real-time traffic size does not exceed the initial detection threshold, it will be marked as normal traffic, allowing it to continue to be transmitted and recorded in real time.
3. The method for querying and analyzing operation and maintenance data of an Internet data center according to claim 1, characterized in that: Comprehensive real-time data capture of all lateral traffic within the IDC is performed. The specific steps are as follows: Deploy distributed traffic collection equipment at key network nodes; Configure distributed traffic collection devices to capture all protocol data and ensure data time synchronization and refined tagging; Utilize high-speed data acquisition and storage systems to aggregate and transmit real-time captured data to a central monitoring platform; The captured data is transmitted to the traffic analysis and anomaly detection system in real time, providing detailed data support for subsequent security monitoring and troubleshooting.
4. The method for querying and analyzing operation and maintenance data of an Internet data center according to claim 1, characterized in that: Feature extraction is performed on the traffic data acquired in real time, where the extracted features include the proportion of average data packet size maintained at a low level and continuously sent, and the path dispersion of small traffic lateral jumps in the internal network. During the monitoring window period, the extracted features are deeply analyzed to generate micro-packet continuity reference values and lateral jump reference values, respectively. The micro-packet continuity reference values and lateral jump reference values are used to preliminarily quantify the behavioral patterns of abnormal transmission of distributed small traffic.
5. The method for querying and analyzing operation and maintenance data of an Internet data center according to claim 4, characterized in that: The micropacket continuity reference value and lateral jump reference value obtained through deep analysis are input into the pre-trained machine learning model as feature vectors. The latent permeability coefficient is generated by the machine learning model, and the abnormal behavior of distributed small traffic transmission is identified through the latent permeability coefficient.
6. The method for querying and analyzing operation and maintenance data of an Internet data center according to claim 5, characterized in that: The latent permeability coefficient generated by the pre-trained machine learning model when predicting all lateral traffic transmission processes within the IDC is compared and analyzed with the pre-set latent permeability coefficient reference threshold to identify abnormal behaviors of distributed small traffic transmission. The specific identification process is as follows: If the latent permeability coefficient is greater than the latent permeability coefficient reference threshold, the lateral traffic transmission process inside the IDC is classified as distributed small traffic transmission abnormal behavior; if the latent permeability coefficient is less than or equal to the latent permeability coefficient reference threshold, the lateral traffic transmission process inside the IDC is classified as normal process transmission behavior.
7. The method for querying and analyzing operation and maintenance data of an Internet data center according to claim 4, characterized in that: During the monitoring window period, the specific steps for deeply analyzing the proportion of average data packets that remain at a low level and are continuously sent to generate a continuous reference value for micro packets are as follows: During the monitoring window, all captured lateral flow data are first processed to analyze the data packets whose size is below the preset threshold S. th The data packets below the preset threshold are recorded as micro-packet traffic. The micro-packet persistence factor is calculated based on the micro-packet traffic data to quantify the persistence and density of micro-packet transmission. The calculation formula of the micro-packet persistence factor is: , where: L pcf is the micropacket persistence factor, N is the total number of data packets within the monitoring window, and λ is the weight parameter for adjusting time sensitivity. is the indicator function, if s k th If it is, the output is 1, otherwise it is 0. k represents the size of the kth data packet. To characterize the temporal continuity of low-flow packets, the time interval d between every two consecutive micro-packets is introduced. k , and decay it with an exponential weight; After obtaining the micro-packet persistence factor, combined with the overall proportion R of micro-packet transmission, a micro-packet persistence reference value that comprehensively reflects the abnormal transmission behavior of distributed small traffic is constructed. The constructed expression is: , where: M ppi is the micropacket duration reference value, α and μ are used to adjust the overall ratio R of micropacket sending and the micropacket duration factor L pcf is an adjustable parameter for the weight in the final micropacket persistence reference value, and η is a small constant that prevents the denominator from being zero.
8. The method for querying and analyzing operation and maintenance data of an Internet data center according to claim 7, characterized in that: During the monitoring window period, the specific steps for deeply analyzing the path dispersion of small traffic lateral jumps in the internal network to generate micro-packet continuous reference values are as follows: During the monitoring window period T, all lateral jump paths of small traffic are captured and a path dispersion matrix is constructed to measure the propagation of distributed traffic between different servers. Suppose the server set in the network topology is S = {s1, s2, ..., s n }, n represents the total number of servers, where the jump relationship between small flows is represented by the jump weight matrix J(t), which represents the horizontal jump degree of small flows. The specific expression is: , where: H ij (t) represents the small traffic from server s at time t i Jump to server j The frequency, w ij For servers i to j The business relevance weight between ij For servers i to j The topological shortest path represents the network distance between two servers; After obtaining the jump weight matrix J(t), the horizontal jump reference value is calculated by the jump weight matrix to quantify the abnormal jump behavior of small traffic in the internal network. The calculation expression is: , where: L hi is the horizontal jump reference value, K represents the maximum number of consecutive jumps observed during the monitoring window, and P i (t) is the server s i The number of micropackets at time t, k represents the number of lateral jumps of a small flow currently observed, that is, the number of jump layers that a single small flow packet starts from the source server and passes through different target servers in sequence, and β is the amplification coefficient of the exponential growth factor, which is used to weight the traffic with a high number of jumps, so that the anomaly score can be quickly improved during multiple consecutive jumps.
9. The method for querying and analyzing operation and maintenance data of an Internet data center according to claim 6, characterized in that: When the machine learning model confirms that abnormal transmission of distributed small-flow data is detected, the dynamic threshold control mechanism is activated to lower the original initial detection threshold. The specific steps are as follows: The dynamic control factor is calculated to calculate the new detection threshold adjustment range according to the degree of deviation between the latent permeability coefficient and the reference threshold of the latent permeability coefficient. The calculation expression of the dynamic control factor is: , where: A af is a dynamic regulatory factor, latent infil is the latent permeability coefficient predicted by the current machine learning model, reflecting the abnormal degree of traffic transmission. th is the preset reference threshold of latent permeability coefficient, which is used to judge whether the flow behavior is normal or not, γ x To adjust the sensitivity coefficient and control the amplitude of the detection threshold change, tanh(·) is a hyperbolic tangent function, which ensures that the change of the control factor is between (-1, 1) and makes the adjustment amplitude have a nonlinear growth characteristic. ∈ is the minimum value term to prevent the denominator from being zero; Calculate the dynamic control factor A af After that, the dynamic control factor is applied to adaptively lower the original initial detection threshold, making the traffic monitoring system more sensitive to small traffic attacks. The new dynamic detection threshold calculation formula is as follows: T new =T0·(1-α x ·|A af |), where: T0 is the initial detection threshold, representing the normal detection standard of the system when there is no abnormality, T new The actual detection threshold after dynamic adjustment ensures that the monitoring system is more sensitive to abnormal behaviors of small traffic transmission. x To dynamically adjust the weight, 0<α x ≤1, used to adjust the intensity of detection threshold reduction to meet the security requirements in different environments, |A af | Take the dynamic control factor A af The absolute value of , ensures that the detection threshold is always reduced when adjusted.
Citation Information
Cited By
Method and system for identifying potential item in data stream, computer equipment and medium
CN120596997A
A method, system, computer device, and medium for identifying potential items in a data stream.
CN120596997B
Fan fault detection method and device of gas water heater and readable storage medium
CN121205972A
Fan fault detection method and device of gas water heater, readable storage medium
CN121205972B