Smart park communication network security control method and system

By calculating the independent defense degree of each current network traffic data in each feature dimension and reconstructing the dimension coefficient, the problem of insufficient sensitivity of the defense mechanism in the existing technology is solved, and the accurate detection and processing of abnormal traffic in the smart park communication network is achieved.

CN120074948AActive Publication Date: 2025-05-30HUAXIN CONSULTATING CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510510477.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-23
Publication Date
2025-05-30
Estimated Expiration
2045-04-23

AI Technical Summary

Technical Problem

When detecting abnormal traffic in the prior art, the unified dimensional coefficient cannot accurately reflect the abnormality of different traffic data in the characteristic dimensions, resulting in insufficient sensitivity of the defense mechanism.

Method used

By collecting historical and current network traffic data, extracting feature information, calculate the independent defense of each current network traffic data in each feature dimension, and reconstructing the dimension coefficient based on this to detect abnormal traffic data.

Benefits of technology

It improves the sensitivity of the smart park communication network defense mechanism, can accurately detect abnormal traffic data, and ensures the stability and security of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074948A_ABST
    Figure CN120074948A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of digital information processing, in particular to a smart park communication network security control method and system, and the method comprises the steps: collecting a plurality of historical network flow data and a plurality of current network flow data in a smart park communication network, extracting first feature information under a plurality of feature dimensions corresponding to each piece of historical network flow data and second feature information under a plurality of feature dimensions corresponding to each piece of current network flow data; according to the first feature information and the second feature information, calculating an independent defense degree of each piece of current network flow data under each feature dimension; reconstructing a dimension coefficient of each piece of current network flow data when the LOF value is calculated based on the independent defense degree; and detecting abnormal traffic data in the plurality of current network traffic data based on the dimension coefficient, and performing security defense processing on the abnormal traffic data. The abnormal traffic data in the current network can be effectively detected, and the sensitivity of a smart park communication network defense mechanism is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of digital information processing, and particularly to a communication network security control method and system for an intelligent park. Background Art

[0002] An intelligent park refers to an intelligent park system created by applying modern information technologies such as the Internet of Things, big data, artificial intelligence, cloud computing, etc. In this park, users (including enterprise employees, residents, tourists, etc.) usually rely on high-quality network connections for their daily work and life. Therefore, effective abnormal traffic detection and automated control are particularly important, which can not only reduce problems such as network interruptions, delays, and congestion, but also ensure that users can smoothly access various intelligent services in the park, thereby improving the overall satisfaction and experience of users.

[0003] In the prior art, the Local Outlier Factor (LOF) algorithm is generally used for abnormal traffic detection. When calculating the LOF values of different traffic data in the current communication network, the dimensionality coefficients of all feature dimensions are fixed and do not change with the change of traffic data. However, based on the differential performance of traffic data, the defense requirements of different traffic data in different feature dimensions are different. If a unified dimensionality coefficient is used, it cannot accurately reflect the abnormality of different traffic data in the feature dimensions that need to be key-defended, resulting in insufficient sensitivity of the defense mechanism and inability to effectively detect abnormal traffic. Summary of the Invention

[0004] In order to solve the above technical problems, the purpose of the present invention is to provide a communication network security control method and system for an intelligent park, and the specific technical solutions adopted are as follows: In the first aspect, the present invention provides a communication network security control method for an intelligent park, and the method includes: Collect a plurality of historical network traffic data and a plurality of current network traffic data in the communication network of the intelligent park, and extract first feature information corresponding to each of the historical network traffic data under a plurality of feature dimensions, and second feature information corresponding to each of the current network traffic data under the plurality of feature dimensions; According to the single defense degree corresponding to each feature dimension of the first feature information and the overlap of defense functions between any two feature dimensions, correct the single defense degree of the current network traffic data and the second feature information to obtain an independent defense degree of each current network traffic data under each feature dimension; the single defense degree is determined according to the purity of the control result of the historical network traffic data under each feature dimension; Reconstruct the dimensionality coefficient when calculating the LOF value of each current network traffic data based on the independent defense degree; Detect abnormal traffic data among the multiple current network traffic data based on the dimension coefficient, and perform security defense processing on the abnormal traffic data.

[0005] Optionally, obtaining the independent defense degree of each current network traffic data under each feature dimension is as follows: Calculate the target single defense degree under each feature dimension and the coincidence of defense functions between any two feature dimensions based on the first feature information; Calculate the current single defense degree of each current network traffic data under each feature dimension according to the target single defense degree and the second feature information; Modify the current single defense degree based on the coincidence of defense functions between any two feature dimensions to obtain the independent defense degree of each current network traffic data under each feature dimension relative to other feature dimensions.

[0006] Optionally, the first feature information includes the control result label values of each historical network traffic data at different occurrence times, and the first feature values under each feature dimension; The calculating the target single defense degree under each feature dimension and the coincidence of defense functions between any two feature dimensions based on the first feature information includes: Calculate the control result single purity of each historical network traffic data under each feature dimension based on the occurrence time of each historical network traffic data, the control result label value of each historical network traffic data, and the first feature value under each feature dimension; Determine the control result relative purity corresponding to the control result single purity; Calculate the target single defense degree of each feature dimension based on the control result relative purity and the first feature value; Calculate the coincidence of defense functions between any two feature dimensions based on the multiple historical network traffic data and the target single defense degree of each feature dimension.

[0007] Optionally, the determining the control result relative purity corresponding to the control result single purity includes: Among the multiple historical network traffic data, determine multiple normal historical network traffic data or multiple abnormal historical network traffic data corresponding to the same control result label value of each historical network traffic data; Determine the single purity LOF value of each historical network traffic data on the multiple normal historical network traffic data or the multiple abnormal historical network traffic data; Based on the single purity of the control result of each piece of the historical network traffic data under each feature dimension and the LOF value of the single purity, calculate the relative purity of the control result of each piece of the historical network traffic data under each feature dimension.

[0008] Optionally, the calculating the target single defense degree of each feature dimension based on the relative purity of the control result and the first eigenvalue includes: According to the relative purity of the control result of each piece of the historical network traffic data under each feature dimension and the first eigenvalue, determine the first overall eigenvalue of the multiple normal historical network traffic data under each feature dimension, and the second overall eigenvalue of the multiple abnormal historical network traffic data under each feature dimension; Determine the absolute value of the difference between the first overall eigenvalue and the second overall eigenvalue under each feature dimension as the target single defense degree.

[0009] Optionally, the calculating the coincidence of the defense functions between any two feature dimensions based on the multiple historical network traffic data and the target single defense degree of each feature dimension includes: Based on the target single defense degree, the first eigenvalue of each piece of the abnormal historical network traffic data under each feature dimension, and the first overall eigenvalue of the multiple normal historical network traffic data under each feature dimension, calculate the historical single defense degree of each piece of the abnormal historical network traffic data under each feature dimension; Use the historical single defense degree to calculate the coincidence of the defense functions between any two feature dimensions.

[0010] Optionally, the second feature information includes the second eigenvalue of the current network traffic data under each feature dimension; The calculating the current single defense degree of each piece of the current network traffic data under each feature dimension according to the target single defense degree and the second feature information includes: Based on the target single defense degree, the second eigenvalue of each piece of the current network traffic data under each feature dimension, and the first overall eigenvalue of the multiple normal historical network traffic data under each feature dimension, calculate the current single defense degree of each piece of the current network traffic data under each feature dimension.

[0011] Optionally, the correcting the current single defense degree based on the coincidence of the defense functions between any two feature dimensions to obtain the independent defense degree of each piece of the current network traffic data under each feature dimension relative to other feature dimensions includes: Determine the non - overlapping defense function of each feature dimension relative to other feature dimensions according to the overlapping nature of the defense functions between any two feature dimensions. Based on the non - overlapping defense function and the current single defense degree of each current network traffic data under each feature dimension, calculate the independent defense degree of each current network traffic data under each feature dimension relative to other feature dimensions.

[0012] Optionally, the detecting abnormal traffic data among the multiple current network traffic data based on the dimension coefficient includes: Calculate the outlier value of each current network traffic data based on the dimension coefficient. Determine the current network traffic data corresponding to the outlier value greater than a preset threshold among the multiple current network traffic data as abnormal traffic data.

[0013] In a second aspect, an embodiment of the present invention further provides an intelligent park communication network security control system, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, the steps of the method described in any one of the above are implemented.

[0014] The present invention has the following beneficial effects: Through the technical solution provided by the present invention, after collecting multiple historical network traffic data and multiple current network traffic data in the intelligent park communication network, the first feature information of each historical network traffic data corresponding to multiple feature dimensions and the second feature information of each current network traffic data corresponding to multiple feature dimensions can be extracted. Then, according to the first feature information and the second feature information, calculate the independent defense degree of each current network traffic data under each feature dimension. Further, reconstruct the dimension coefficient of each current network traffic data when calculating the LOF value based on the independent defense degree. Finally, detect abnormal traffic data among the multiple current network traffic data based on the dimension coefficient and perform security defense processing on the abnormal traffic data. Starting from the perspective of historical network traffic data, the present invention calculates the independent defense degree of each current network traffic data under each feature dimension, reconstructs the dimension coefficient of each traffic data in the current communication network when calculating the outlier value based on the independent defense degree, and thus can accurately calculate the outlier value of each current network traffic data under the defense focus, effectively detect abnormal traffic data in the current network, and improve the sensitivity of the intelligent park communication network defense mechanism.

[0015] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present invention. Other features and advantages of the present invention will be described in detail in the subsequent specific implementation section. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] To more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0017] Figure 1 A flowchart showing the process of a method for controlling the security of a communication network in an intelligent park provided by an embodiment of the present invention; Figure 2 A flowchart showing the process of a method for controlling the security of a communication network in an intelligent park provided by another embodiment of the present invention. Detailed implementation manners

[0018] To further elaborate on the technical means and effects adopted by the present invention to achieve the intended invention purpose, the following, in conjunction with the drawings and preferred embodiments, details the specific implementation manners, structures, features, and effects of a method and system for controlling the security of a communication network in an intelligent park proposed according to the present invention. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. In addition, the specific features, structures, or characteristics in one or more embodiments can be combined in any suitable form.

[0019] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.

[0020] The following specifically describes the specific solutions of a method and system for controlling the security of a communication network in an intelligent park provided by the present invention in conjunction with the drawings.

[0021] Please refer to Figure 1 , which shows a flowchart of the steps of a method for controlling the security of a communication network in an intelligent park provided by an embodiment of the present invention. The method includes the following steps: Step 110: Collect multiple historical network traffic data and multiple current network traffic data in the communication network of the intelligent park, and extract first feature information corresponding to multiple feature dimensions for each historical network traffic data, and second feature information corresponding to multiple feature dimensions for each current network traffic data.

[0022] Among them, historical network traffic data refers to the traffic data generated by the communication network of the smart park during a certain past period, and these data reflect the past operating conditions of the park network; current network traffic data represents the traffic data of the communication network of the smart park at the current moment or within a short period recently; the first feature information comes from the historical network traffic data in the communication network of the smart park, reflecting the characteristics of past network traffic under multiple feature dimensions. It may include the control result label values of each historical network traffic data at different occurrence times, as well as the first feature values under each feature dimension. The second feature information corresponds to the current network traffic data, showing the current real-time conditions of the network under the same multiple feature dimensions, and it may include the second feature values of the current network traffic data under each feature dimension.

[0023] In a specific application scenario, a network packet capture tool (such as Wireshark) can be used to capture and analyze the current network traffic data in the communication network of the smart park, extract M features related to network behavior to describe the basic characteristics of the traffic, and further help identify potential abnormal behaviors. These features usually include M items such as the size of the data packet, the frequency of communication packets, the time interval between data packet transmissions, the target IP address, etc. After quantification, they are shown in Table 1 below: Table 1. Second feature information corresponding to the current network traffic data

[0024] On this basis, further collect N historical network traffic data samples that have been analyzed for security and annotated with the control results of each traffic data (specifically, when the traffic is determined to be abnormal, the corresponding control result label E is 1, indicating that the system has taken defensive measures; when the traffic is normal traffic, E is 0, indicating that no defensive measures have been taken) and the occurrence time. As shown in Table 2 below: Table 2. First feature information corresponding to the historical network traffic data

[0025] Step 120: According to the single defense degree under each feature dimension corresponding to the first feature information and the overlapping nature of the defense functions between any two feature dimensions, correct the single defense degree of the current network traffic data to obtain the independent defense degree of each current network traffic data under each feature dimension; the single defense degree is determined according to the purity of the control results of the historical network traffic data under each feature dimension.

[0026] Among them, the independent defense degree is a quantitative index used to measure the security, stability or the ability to cope with potential risks of the current network traffic data under a specific feature dimension. When calculating this index, the relationship between the first feature information (historical network traffic data features) and the second feature information (current data features) is comprehensively considered. For example, if the traffic characteristics of the current network in a certain application dimension are quite different from the historical normal traffic characteristics, the independent defense degree may be relatively low, indicating that the network traffic of this application may face risks and requires further attention and defense; conversely, if it conforms to the historical characteristics, the independent defense degree may be relatively high, indicating that the network traffic status of this application is relatively stable and the risk is relatively low. By calculating the independent defense degree, the real-time status of the smart park network in different dimensions can be comprehensively understood, potential problems can be discovered in a timely manner, and a strong basis can be provided for network security protection and optimization.

[0027] Step 130: Reconstruct the dimension coefficient of each current network traffic data when calculating the LOF value based on the independent defense degree.

[0028] When calculating the Local Outlier Factor (LOF) value, different feature dimensions have different importance in determining whether a data point is an outlier, and the dimension coefficient is a parameter that measures this importance. For example, in the smart park network traffic data, for determining network anomalies, the bandwidth dimension of the traffic and the packet type dimension may have different importance, and they will each have corresponding dimension coefficients. If the independent defense degree of the current network traffic data under a certain feature dimension is relatively low, it indicates that the network traffic under this dimension faces risks or is in an unstable state. Then, when calculating the LOF value, the coefficient of this dimension may be increased accordingly, so that this dimension has a greater influence in determining outliers, in order to more sensitively capture potential anomalies under this dimension. Conversely, if the independent defense degree is relatively high, indicating that this dimension is relatively stable, the dimension coefficient may be reduced to reduce the weight of this dimension in determining outliers. By reconstructing the dimension coefficient when calculating the LOF value based on the independent defense degree, potential outliers can be identified more flexibly and accurately according to the real-time status of the network traffic, and the detection ability of abnormal traffic in the smart park communication network can be improved.

[0029] Step 140: Detect abnormal traffic data among multiple current network traffic data based on the dimension coefficient, and perform security defense processing on the abnormal traffic data.

[0030] For the embodiments of the present disclosure, based on the reconstructed dimensionality coefficients, the LOF algorithm can be used to analyze multiple currently collected network traffic data. The LOF algorithm determines whether a data point is an outlier, i.e., abnormal data, by comparing the density of each data point with that of its neighborhood points. Since the adjusted dimensionality coefficients are considered, the detection process can more accurately reflect the influence of different feature dimensions on traffic anomaly judgment. For example, when calculating the LOF value of a certain currently collected network traffic data point, the data transmission rate dimension will have a greater impact on the final LOF value according to its higher coefficient. If the data in this dimension is significantly different from that of the neighborhood points, it will significantly increase the likelihood of this data point being an abnormal point. For the detected abnormal traffic data, corresponding security defense measures are taken. This may include various methods, such as immediately blocking the transmission of abnormal traffic to prevent further impact on the network; tracing the source of abnormal traffic to try to find the attack origin or faulty device; recording detailed information of abnormal traffic, such as traffic characteristics, occurrence time, etc., for subsequent in-depth analysis to improve network security policies. For example, if abnormal traffic generated by a certain IP address is detected, the IP address may be temporarily blocked, and the relevant traffic data is recorded in the log for subsequent analysis by the network security team. Through these security defense processes, the stable and secure operation of the communication network in the smart park can be ensured.

[0031] In summary, according to a smart park communication network security control method provided by the present invention, after collecting multiple historical network traffic data and multiple currently collected network traffic data in the smart park communication network, the first feature information corresponding to each historical network traffic data under multiple feature dimensions and the second feature information corresponding to each currently collected network traffic data under multiple feature dimensions can be extracted; then, according to the first feature information and the second feature information, the independent defense degree of each currently collected network traffic data under each feature dimension is calculated; further, based on the independent defense degree, the dimensionality coefficient of each currently collected network traffic data when calculating the LOF value is reconstructed; finally, based on the dimensionality coefficient, abnormal traffic data is detected among multiple currently collected network traffic data, and security defense processing is performed on the abnormal traffic data. Starting from the perspective of historical network traffic data, the present invention calculates the independent defense degree of each currently collected network traffic data under each feature dimension, reconstructs the dimensionality coefficient of each traffic data in the current communication network when calculating the abnormal value based on the independent defense degree, and thus can accurately calculate the abnormal value of each currently collected network traffic data under the defense focus, effectively detect the abnormal traffic data in the current network, and improve the sensitivity of the communication network defense mechanism in the smart park.

[0032] Based on Figure 1 the embodiments shown, as a refinement and extension of the above embodiments, in order to fully illustrate the specific implementation process of the method in this embodiment, this embodiment provides a specific method as shown in Figure 2 the following.Figure 2 Based on Figure 1 the embodiments shown. As Figure 2 shown, the method includes the following steps: Step 210, collect a plurality of historical network traffic data and a plurality of current network traffic data in the intelligent park communication network, and extract first feature information corresponding to each historical network traffic data under a plurality of feature dimensions, and second feature information corresponding to each current network traffic data under a plurality of feature dimensions.

[0033] For the embodiments of the present disclosure, the specific implementation process can refer to the relevant description in step 110 of the embodiments, and will not be elaborated here.

[0034] Step 220, calculate the target single defense degree under each feature dimension and the overlap of defense functions between any two feature dimensions based on the first feature information.

[0035] Among them, the target single defense degree is an index calculated for each individual feature dimension, which is used to measure the ability of the network to resist potential risks or abnormal conditions under this specific feature dimension. For example, in the feature dimension of "time" (such as the difference in network traffic between weekdays and weekends), by analyzing the first feature information in the historical network traffic data, the target single defense degree of the network in this time dimension can be calculated to understand the network's ability to resist traffic anomalies at different time stages. The overlap of defense functions refers to the degree of overlap of the functions of the network to resist risks or abnormal conditions under different feature dimensions. For example, in the time dimension, the network may have a set of defense mechanisms for traffic anomalies during peak hours on weekdays; in the application type dimension, there are corresponding defense mechanisms for traffic anomalies of video conferencing applications. The defense mechanisms in these two dimensions may have some identical measures or logics, and the overlap is a quantitative evaluation of this identical degree. By calculating this overlap, the association between defense mechanisms in different feature dimensions can be understood, which helps to optimize the overall defense strategy of the network, avoid duplicate construction of defense functions, and at the same time discover possible defense vulnerabilities.

[0036] Correspondingly, for the embodiments of the present disclosure, calculating the target single defense degree under each feature dimension and the overlap of defense functions between any two feature dimensions in step 220 may include the following steps: Step 220-1, calculate the control result single purity of each historical network traffic data under each feature dimension based on the occurrence time of each historical network traffic data, the control result label value of each historical network traffic data, and the first feature value under each feature dimension.

[0037] Since the network environment in the smart park is highly dynamic, network traffic is affected by multiple factors, such as the connection status of devices, mobile devices within the park, network bandwidth allocation, fluctuations in user demands, etc. As time changes, traffic characteristics may change drastically. At this time, some traffic characteristics (such as latency, packet loss rate, etc.) may not be accurately captured, resulting in deviations, making the traffic characteristics of each historical network traffic data not pure for the control result. Therefore, in this step, it is necessary to judge the purity of the control result of each collected historical network traffic data under the influence of each feature dimension. Here, take the control result of the i-th historical network traffic data under the w-th feature dimension as an example: Generally speaking, if the feature values of other historical network traffic data and the i-th traffic data are similar under the feature dimension w, it means that the traffic patterns of the data are very close in this dimension. If the control results are consistent on this basis, it means that their behavior patterns under the feature dimension w have been confirmed, and the control result of the i-th historical network traffic data is considered to be more reliable and pure. However, there are a total of N other historical network traffic data, and not every one of them can contribute to the purity. In the communication network of the smart park, the behavior of traffic data is usually affected by multiple factors, such as device load, network topology, application traffic, etc. If other historical network traffic data is closer in time to traffic data i, it means that there may be the same or similar network states or behavior patterns behind these traffic data, and their contribution degrees should be higher.

[0038] In the embodiment of the present disclosure, the first calculation formula can be constructed through the above description to calculate the single purity of the control result of the i-th historical network traffic data under the w-th feature dimension. Specifically, the occurrence time of each historical network traffic data, the control result label value of each historical network traffic data, and the first feature value under each feature dimension can be substituted into the first calculation formula to calculate the single purity of the control result of each historical network traffic data under each feature dimension. Among them, the formula feature description of the first calculation formula is as follows:

[0039] In the formula, P i represents the single purity of the control result of the i-th historical network traffic data under the w-th feature dimension, N represents that there are a total of N collected historical network traffic data, exp represents the exponential function with e as the base, t i represents the occurrence time of the i-th historical network traffic data, t j represents the occurrence time of the j-th historical network traffic data, exp(-|t i -t j |) represents the proximity of the occurrence times of the i-th historical network traffic data and the j-th historical network traffic data, E iRepresents the control result of the i-th historical network traffic data, E j Represents the control result of the j-th historical network traffic data, ||E i -E j |-1| represents the consistency of the control results of the i-th historical network traffic data and the j-th historical network traffic data, F wi Represents the eigenvalue of the i-th historical network traffic data under the w-th feature dimension, E wj Represents the eigenvalue of the j-th historical network traffic data under the w-th feature dimension, ε 1 Represents a hyperparameter, 1 / (|F wi -E wj |+ε 1 ) represents the eigenvalue similarity of the i-th historical network traffic data and the j-th historical network traffic data under the w-th feature dimension.

[0040] Similarly, the control result single purity of each historical network traffic data under each feature dimension can be determined.

[0041] Step 220-2: Determine the control result relative purity corresponding to the control result single purity.

[0042] Since the network traffic in the smart park is not static but highly dynamic. The usage requirements of devices and applications change over time, and there may be instantaneous fluctuations in network load and traffic patterns. For example, the data collection frequency and transmission rate of some devices may be adjusted according to factors such as personnel activities and environmental changes in the park. The traffic characteristics in a local time period can better reflect the short-term changes of the network and help determine the control result relative purity of each historical network traffic data under all feature dimensions (relative means local). Here, take the control result of the i-th historical network traffic data under the w-th feature dimension as an example: For all the collected historical network traffic data, their control results can be divided into two categories (1 and 0). Accordingly, multiple historical network traffic data can be divided into multiple normal historical network traffic data with the corresponding control result label value of 0 and multiple abnormal historical network traffic data with the corresponding control result label value of 1. Then, plot the abnormal historical network traffic data classified as 1, with the horizontal axis representing time and the vertical axis representing the control result single purity of the abnormal historical network traffic data under the w-th feature dimension; Next, plot the normal historical network traffic data classified as 0, with the horizontal axis also being time and the vertical axis representing the control result single purity of the normal historical network traffic data under the w-th feature dimension.

[0043] For the single purity of the control result of the i-th historical network traffic data in the w-th feature dimension, the more obvious the purity of the traffic data aggregates in the time-single purity two-dimensional space, the more stable the network behavior of the system in this time period, the healthier the operating state (better purity), and the more stable the factors such as network load and application state. In this case, the network management system can more accurately determine the traffic behavior, reduce the risk of misjudgment, and provide more effective traffic control. Therefore, based on the single purity, the more obvious the purity aggregation effect, the smaller the LOF value, and the higher the relatively healthy and useful purity.

[0044] For the embodiments of the present disclosure, the steps of the embodiments may include: among multiple historical network traffic data, determining multiple normal historical network traffic data or multiple abnormal historical network traffic data corresponding to the same control result label value for each historical network traffic data; determining the single purity LOF value of each historical network traffic data on the multiple normal historical network traffic data or multiple abnormal historical network traffic data; based on the single purity of the control result of each historical network traffic data in each feature dimension and the single purity LOF value, calculating the relative purity of the control result of each historical network traffic data in each feature dimension. Specifically, when the control result label value corresponding to the historical network traffic data for which the relative purity of the control result needs to be determined is 0, multiple normal historical network traffic data corresponding to the same control result label value as this historical network traffic data can be obtained in the above-drawn time-single purity two-dimensional space; or, when the control result label value corresponding to the historical network traffic data for which the relative purity of the control result needs to be determined is 1, multiple abnormal historical network traffic data corresponding to the same control result label value as this historical network traffic data can be obtained in the above-drawn time-single purity two-dimensional space. Then, the single purity LOF value of the multiple normal historical network traffic data or multiple abnormal historical network traffic data can be determined. Specifically, the principle of density-based outlier detection using the LOF algorithm can be utilized. If, among the historical network traffic data, the density of a certain traffic data point in its local neighborhood is significantly lower than the density of other surrounding data points, it indicates that its difference from the surrounding data in this single dimension is relatively large, and it may be an outlier, and its single purity LOF value will be relatively high, meaning that the purity of this data point is relatively low, and there may be data anomalies or impurities.

[0045] Correspondingly, for the embodiments of the present disclosure, when calculating the relative purity of the control result of each historical network traffic data in each feature dimension based on the single purity of the control result of each historical network traffic data in each feature dimension and the LOF value of the single purity, the single purity of the control result of each historical network traffic data in each feature dimension and the LOF value of the single purity can be substituted into the second calculation formula to calculate the relative purity of the control result of each historical network traffic data in each feature dimension. Among them, the formula feature description of the second calculation formula is as follows:

[0046] Formula explanation: Among them, represents the relative purity of the control result of the i-th historical network traffic data in the w-th feature dimension, and LOF k (P i ) represents the LOF value of the single purity on multiple normal historical network traffic data or multiple abnormal historical network traffic data corresponding to the same control result label value as the i-th historical network traffic data, and P i represents the single purity of the control result of the i-th historical network traffic data in the w-th feature dimension.

[0047] Similarly, the relative purity of the control result of each historical network traffic data in each feature dimension can be determined.

[0048] Step 220-3: Calculate the target single defense degree of each feature dimension based on the relative purity of the control result and the first eigenvalue.

[0049] For the N historical network traffic data of the intelligent park communication network (with M features), assuming that the defense degree of a certain feature needs to be calculated, it is necessary to subtract the second overall eigenvalue (feature average value) of multiple abnormal historical network traffic data in each feature dimension from the first overall eigenvalue (feature average value) of multiple normal historical network traffic data in each feature dimension under this feature. The greater the absolute value difference, the higher the defense degree of this feature (this process is essentially measuring the difference between this feature and the defense result, reflecting the influence of this feature on distinguishing the defense effect (defense result is 1 or 0)).

[0050] However, the relative purities of the control result labels of all historical network traffic data are not the same. Now it is necessary to make the historical network traffic data with high relative purity contribute more to the feature average value, and make the historical network traffic data with low purity contribute less to the feature average value. Therefore, the following third calculation formula can be constructed to represent the target single defense degree of the w-th feature dimension. Among them, the formula feature description of the third calculation formula is as follows:

[0051] In the formula, X w represents the target single defense degree of the w-th feature dimension, and n 0 represents that there are n normal historical network traffic data with a control result of 0 collected, 0 pieces, represents the control result relative purity of the u-th normal historical network traffic data under the w-th feature dimension, and F0 wu represents the first eigenvalue of the u-th normal historical network traffic data under the w-th feature dimension, represents the first overall eigenvalue of multiple normal historical network traffic data under the w-th feature dimension, and n 1 represents that there are n abnormal historical network traffic data with a control result of 1 collected, 1 pieces, represents the control result relative purity of the v-th abnormal historical network traffic data under the w-th feature dimension, and F1 wv represents the eigenvalue of the v-th abnormal historical network traffic data under the w-th feature dimension, represents the overall eigenvalue of multiple abnormal historical network traffic data (with a control result of 1) under the w-th feature dimension.

[0052] Similarly, the target single defense degree of each feature dimension can be determined.

[0053] Denoted as F0 w Denoted as F1 w Correspondingly, for the embodiments of the present disclosure, the embodiment steps may include: determining the first overall eigenvalue of multiple normal historical network traffic data under each feature dimension and the second overall eigenvalue of multiple abnormal historical network traffic data under each feature dimension according to the control result relative purity and the first eigenvalue of each historical network traffic data under each feature dimension; determining the absolute value of the difference between the first overall eigenvalue and the second overall eigenvalue under each feature dimension as the target single defense degree.

[0054] Step 220-4: Calculate the coincidence of the defense functions between any two feature dimensions based on multiple historical network traffic data and the target single defense degree of each feature dimension.

[0055] For the embodiments of the present disclosure, the steps of the embodiments may include: calculating the historical single defense degree of each abnormal historical network traffic data in each feature dimension based on the target single defense degree, the first eigenvalue of each abnormal historical network traffic data in each feature dimension, and the first overall eigenvalue of multiple normal historical network traffic data in each feature dimension; calculating the coincidence of the defense functions between any two feature dimensions by using the historical single defense degree.

[0056] This step needs to determine the coincidence of the defense functions between any two feature dimensions through abnormal historical network traffic data (traffic data that has been defended). For each abnormal historical network traffic data i with a control result of 1, the coincidence of the defense functions between the k-th feature dimension and the w-th feature dimension is analyzed here: If there is a coincidence of the defense functions between the k-th feature dimension and the w-th feature dimension, then it can be considered that as long as the single defense degree of one of the features is relatively high, it can effectively offset the defense effect of the other feature (i.e., showing an "inverse relationship"), that is, if the difference between |X k (i)-X w (i)| is larger, the defense coincidence is relatively high. However, if the single defense degrees of the abnormal historical network traffic data i in both the k and w dimensions are relatively large, then it can also show a good defense effect. At this time, whether there is a function coincidence is unknown. Therefore, to obtain the coincidence of the defense functions between the k-th feature dimension and the w-th feature dimension using the historical n 1 judged abnormal historical network traffic data, it is necessary to make the contribution degree of the data relatively small when the single defense degrees of k and w are both relatively large, that is, the smaller min(X k (i),X w (i)) is, the better.

[0057] In a specific application scenario, the target single defense degree, the first eigenvalue of each abnormal historical network traffic data in each feature dimension, and the first overall eigenvalue of multiple normal historical network traffic data in each feature dimension can be substituted into the fourth calculation formula to calculate the historical single defense degree of each abnormal historical network traffic data in each feature dimension.

[0058] Among them, the formula features of the fourth calculation formula are described as: X W (R)=X W *|F wR -F0 w | In the formula, X W (R) represents the historical single defense degree of the abnormal historical network traffic data R in the w-th feature dimension, X W represents the target single defense degree of the w-th feature dimension, FwR Denote the first eigenvalue of the abnormal historical network traffic data R in the w-th dimension, F0 w Denote the first overall eigenvalue of the normal historical traffic data (control result is 0) in the w-th feature dimension.

[0059] Similarly, the historical single defense degree of each abnormal historical network traffic data in each feature dimension in the current network can be determined.

[0060] Furthermore, the historical single defense degrees of each abnormal historical network traffic data in any two feature dimensions can be substituted into the fifth calculation formula to calculate the coincidence of the defense functions between any two feature dimensions. Among them, the formula feature description of the fifth calculation formula is:

[0061] In the formula, C k-w Denote the coincidence of the defense functions between the k-th feature dimension and the w-th feature dimension, f denotes the maximum-minimum normalization function (compared with any other two feature dimensions), n 1 Denote that there are n abnormal historical network traffic data with the collected control result of 1 1 pieces, X k (i) Denote the historical single defense degree of the i-th abnormal historical network traffic data Q in the k-th feature dimension, X w (i) Denote the historical single defense degree of the i-th abnormal historical network traffic data Q in the w-th feature dimension, min() denotes selecting the minimum value.

[0062] Similarly, the coincidence of the defense functions between any two feature dimensions can be determined.

[0063] Step 230: Calculate the current single defense degree of each current network traffic data in each feature dimension according to the target single defense degree and the second feature information.

[0064] For the current network traffic data Q in the current communication network of the smart park, if it has a high defense degree in the w feature dimension (X w ), and has a large gap with the feature average value (F0 w ) of the normal historical network traffic data, then the traffic data Q needs to be key-defended in the w dimension.

[0065] Correspondingly, for the embodiments of the present disclosure, the embodiment steps may include: calculating the current single defense degree of each current network traffic data in each feature dimension based on the target single defense degree, the second eigenvalue of each current network traffic data in each feature dimension, and the first overall eigenvalue of multiple normal historical network traffic data in each feature dimension.

[0066] For the embodiments of the present disclosure, the target single defense degree, the second eigenvalue of each current network traffic data under each feature dimension, and the first overall eigenvalue of multiple normal historical network traffic data under each feature dimension can be substituted into the sixth calculation formula to calculate the current single defense degree of each current network traffic data under each feature dimension. Among them, the formula feature description of the sixth calculation formula is as follows: X w (Q)= X w *|F wQ -F0 w | In the formula, X w (Q) represents the current single defense degree of the current network traffic data Q in the w-th feature dimension, X w represents the single defense degree of the w-th feature dimension, F wQ represents the eigenvalue of the current network traffic data Q in the w-th dimension, F0 w represents the overall eigenvalue of the normal historical traffic data (control result is 0) in the w-th feature dimension.

[0067] Similarly, the current single defense degree of each current network traffic data in each feature dimension of the current network can be determined.

[0068] Step 240: Based on the overlap of the defense functions between any two feature dimensions, correct the current single defense degree to obtain the independent defense degree of each current network traffic data in each feature dimension relative to other feature dimensions.

[0069] When the LOF algorithm calculates the current network traffic data, each feature dimension exists independently and is calculated. Therefore, for the defense degree of the current network traffic data Q calculated in the w-th feature dimension, it should also be independent. The above steps have calculated the overlap of the defense functions between each feature dimension and the w-th feature dimension. Therefore, in order to accurately evaluate the independent defense degree of the current network traffic data Q in the w-th feature dimension, it is necessary to eliminate the interference of this overlap on the defense degree evaluation, that is, to use the obtained non-overlap degree to perform weighted construction of the seventh calculation formula. Specifically, the non-overlap of the defense functions of each feature dimension relative to other feature dimensions and the current single defense degree of each current network traffic data in each feature dimension can be substituted into the seventh calculation formula to calculate the independent defense degree of the current network traffic data Q in each feature dimension relative to other feature dimensions.

[0070] Among them, the formula feature description of the seventh calculation formula is as follows:

[0071] In the formula, Y w(Q) represents the independent defense degree of the current network traffic data Q in the w-th feature dimension relative to other dimensions. M represents that there are M feature dimensions in total, and C k-w represents the defense function overlap between the k-th feature dimension and the w-th feature dimension, represents the non-overlap of the defense of the w-th feature dimension relative to other dimensions, X w (Q) represents the current single defense degree of the current network traffic data Q in the w-th feature dimension.

[0072] Similarly, the independent defense degree of each current network traffic data in each feature dimension relative to other dimensions can be determined.

[0073] Correspondingly, for the embodiments of the present disclosure, correcting the current single defense degree based on the overlap of the defense functions between any two feature dimensions in step 240 to obtain the independent defense of each current network traffic data in each feature dimension relative to other feature dimensions may include the following steps: Step 240-1: Determine the non-overlap of the defense function of each feature dimension relative to other feature dimensions according to the overlap of the defense functions between any two feature dimensions.

[0074] Step 240-2: Calculate the independent defense degree of each current network traffic data in each feature dimension relative to other feature dimensions based on the non-overlap of the defense function and the current single defense degree of each current network traffic data in each feature dimension.

[0075] Step 250: Reconstruct the dimension coefficient of each current network traffic data when calculating the LOF value based on the independent defense degree.

[0076] For the embodiments of the present disclosure, the specific implementation process can refer to the relevant description in step 130 of the embodiment, which will not be elaborated here.

[0077] Step 260: Detect abnormal traffic data among multiple current network traffic data based on the dimension coefficient, and perform security defense processing on the abnormal traffic data.

[0078] Correspondingly, for the embodiments of the present disclosure, when detecting abnormal traffic data among multiple current network traffic data based on the dimension coefficient, the embodiment steps may include: calculating the abnormal value of each current network traffic data based on the dimension coefficient; determining the current network traffic data with the abnormal value greater than the preset threshold among the multiple current network traffic data as the abnormal traffic data.

[0079] In a specific application scenario, when the outlier of the current network traffic data is much higher than 1, it indicates that this traffic data point may be an abnormal traffic data. In order to accurately identify abnormal traffic, a threshold is set for these outliers as the judgment criterion. Here, the preset threshold can be set to 2. This value means that when the outlier of a certain traffic data point exceeds 2, it can be considered an abnormal traffic data. For the identified abnormal traffic data, the triggering of security defense measures can be automatically controlled. For example, traffic isolation can be implemented through a network firewall or traffic filtering device to block communication requests from abnormal sources or destinations, cut off the network connection with them, and prevent the further spread of abnormal traffic, which may affect the stability and security of the entire network. As an emergency response measure, traffic isolation can effectively reduce the risks brought by abnormal traffic to network security. However, to ensure the long-term security of the network, other technical means, such as vulnerability repair, can also be combined for comprehensive defense and governance to ensure the security and stability of the network environment.

[0080] In summary, in the technical solution of this application, after collecting multiple historical network traffic data and multiple current network traffic data in the intelligent park communication network, the first feature information corresponding to each historical network traffic data under multiple feature dimensions, and the second feature information corresponding to each current network traffic data under multiple feature dimensions can be extracted; then, according to the first feature information and the second feature information, the independent defense degree of each current network traffic data under each feature dimension is calculated; further, based on the independent defense degree, the dimension coefficient when calculating the LOF value of each current network traffic data is reconstructed; finally, based on the dimension coefficient, abnormal traffic data is detected among multiple current network traffic data, and security defense processing is performed on the abnormal traffic data. Starting from the perspective of historical network traffic data, this invention calculates the independent defense degree of each current network traffic data under each feature dimension, reconstructs the dimension coefficient when calculating the outlier of each traffic data in the current communication network based on the independent defense degree, and thus can accurately calculate the outlier of each current network traffic data under the defense focus, effectively detect abnormal traffic data in the current network, and improve the sensitivity of the defense mechanism of the intelligent park communication network.

[0081] Based on the same inventive concept as the above method, an embodiment of this invention also provides an intelligent park communication network security control system, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, the steps of any one of the above methods for an intelligent park communication network security control method are implemented.

[0082] In summary, the embodiments of the present invention provide a method and system for security control of a communication network in a smart park. From the perspective of historical network traffic data, the independent defense degree of each current network traffic data in each feature dimension is calculated, and the dimension coefficient of each traffic data in the current communication network when calculating the outlier is reconstructed based on the independent defense degree. Furthermore, the outlier of each current network traffic data can be accurately calculated under the defense focus, the abnormal traffic data in the current network can be effectively detected, and the sensitivity of the defense mechanism of the communication network in the smart park can be improved.

[0083] It should be noted that the above sequence of the embodiments of the present invention is only for description and does not represent the superiority or inferiority of the embodiments. In addition, the above specific embodiments of this specification have been described. Moreover, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0084] The embodiments in this specification are all described in a progressive manner. The same or similar parts among the embodiments can be referred to each other, and the differences between each embodiment and other embodiments are emphasized.

[0085] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for controlling the security of a smart park communication network, characterized in that: The method comprises: Collect multiple historical network traffic data and multiple current network traffic data in the smart park communication network, and extract first feature information corresponding to multiple feature dimensions for each of the historical network traffic data, and second feature information corresponding to the multiple feature dimensions for each of the current network traffic data; According to the single defense degree under each characteristic dimension corresponding to the first characteristic information and the overlap of the defense functions between any two characteristic dimensions, the single defense degree of the current network traffic data is corrected to obtain the independent defense degree of each current network traffic data under each characteristic dimension; the single defense degree is determined according to the purity of the control result of the historical network traffic data under each characteristic dimension; Reconstructing the dimension coefficient of each current network traffic data when calculating the LOF value based on the independent defense degree; Abnormal traffic data is detected in the multiple current network traffic data based on the dimension coefficient, and security defense processing is performed on the abnormal traffic data.

2. The smart park communication network security control method according to claim 1 is characterized in that: The independent defense degree of each current network traffic data in each characteristic dimension is obtained as follows: Calculate the single defense degree of the target in each feature dimension and the overlap of the defense functions between any two feature dimensions based on the first feature information; Calculate the current single defense degree of each current network traffic data in each feature dimension according to the target single defense degree and the second feature information; The current single defense degree is corrected based on the overlap of the defense functions between the arbitrary two characteristic dimensions, so as to obtain an independent defense degree of each current network traffic data in each characteristic dimension relative to other characteristic dimensions.

3. The smart park communication network security control method according to claim 2 is characterized in that: The first feature information includes a control result label value of each of the historical network traffic data at different occurrence times, and a first feature value in each feature dimension; The calculating, based on the first feature information, the single defense degree of the target in each feature dimension and the overlap of the defense functions between any two feature dimensions includes: Based on the occurrence time of each of the historical network traffic data, the control result label value of each of the historical network traffic data, and the first characteristic value in each characteristic dimension, calculate the single purity of the control result of each of the historical network traffic data in each characteristic dimension; Determining a relative purity of the control result corresponding to a single purity of the control result; Calculating a target single defense degree of each characteristic dimension based on the relative purity of the control result and the first characteristic value; Based on the multiple historical network traffic data and the target single defense degree of each characteristic dimension, the overlap of defense functions between any two characteristic dimensions is calculated.

4. The smart park communication network security control method according to claim 3 is characterized in that: The determining of the relative purity of the control result corresponding to the single purity of the control result includes: Determine, among the plurality of historical network flow data, a plurality of normal historical network flow data or a plurality of abnormal historical network flow data corresponding to the same control result label value as each of the historical network flow data; Determine a single purity LOF value of each of the historical network traffic data on the plurality of normal historical network traffic data or the plurality of abnormal historical network traffic data; Based on the single purity of the control result of each of the historical network traffic data in each characteristic dimension and the single purity LOF value, the relative purity of the control result of each of the historical network traffic data in each characteristic dimension is calculated.

5. The smart park communication network security control method according to claim 4 is characterized in that: The calculating the target single defense degree of each characteristic dimension based on the relative purity of the control result and the first characteristic value includes: Determine, according to the relative purity of the control result and the first characteristic value of each of the historical network traffic data in each characteristic dimension, a first overall characteristic value of the plurality of normal historical network traffic data in each characteristic dimension, and a second overall characteristic value of the plurality of abnormal historical network traffic data in each characteristic dimension; The absolute value of the difference between the first overall eigenvalue and the second overall eigenvalue in each characteristic dimension is determined as the target single defense degree.

6. The smart park communication network security control method according to claim 4 is characterized in that: The calculating the overlap of defense functions between any two feature dimensions based on the multiple historical network traffic data and the target single defense degree of each feature dimension includes: Calculate the historical single defense degree of each abnormal historical network traffic data in each characteristic dimension based on the target single defense degree, the first characteristic value of each abnormal historical network traffic data in each characteristic dimension, and the first overall characteristic value of each normal historical network traffic data in each characteristic dimension; The historical single defense degree is used to calculate the overlap of defense functions between any two feature dimensions.

7. The smart park communication network security control method according to claim 5 is characterized in that: The second characteristic information includes a second characteristic value of the current network traffic data in each characteristic dimension; The step of calculating the current single defense degree of each current network traffic data in each feature dimension according to the target single defense degree and the second feature information includes: Based on the target single defense level, the second characteristic value of each current network traffic data in each characteristic dimension, and the first overall characteristic value of the multiple normal historical network traffic data in each characteristic dimension, the current single defense level of each current network traffic data in each characteristic dimension is calculated.

8. The smart park communication network security control method according to claim 2 is characterized in that: The method of correcting the current single defense degree based on the overlap of the defense functions between the arbitrary two characteristic dimensions to obtain the independent defense degree of each current network traffic data in each characteristic dimension relative to other characteristic dimensions includes: According to the overlap of the defense functions between any two characteristic dimensions, determining the non-overlap of the defense functions of each characteristic dimension relative to other characteristic dimensions; Based on the non-overlapping of the defense functions and the current single defense degree of each of the current network traffic data in each characteristic dimension, the independent defense degree of each of the current network traffic data in each characteristic dimension relative to other characteristic dimensions is calculated.

9. The smart park communication network security control method according to claim 1 is characterized in that: The detecting abnormal traffic data in the plurality of current network traffic data based on the dimension coefficient comprises: Calculate the abnormal value of each current network traffic data based on the dimension coefficient; The current network traffic data corresponding to the abnormal value greater than a preset threshold among the multiple current network traffic data are determined as abnormal traffic data.

10. A smart campus communication network security control system, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the computer program is executed by the processor, the steps of a smart campus communication network security control method as described in any one of claims 1 to 9 are implemented.

Citation Information

Patent Citations

  • Attack defense strategy visualization method and system

    CN111935143A

  • Abnormity recognition method, device and equipment based on security monitoring, medium and program

    CN118869311A

  • Model version updating-based hidden attack detection method for power grid data

    CN118921199A

  • Electric power operation and maintenance power distribution station intelligent monitoring platform based on artificial intelligence

    CN119154515A

  • Computer network information security monitoring method

    CN119603069A