A smart park communication network security control method and system

By collecting and analyzing traffic data in the smart park communication network, calculating independent defense degrees and reconstructing dimensional coefficients, the problem of insufficient sensitivity of the defense mechanism in the existing technology is solved, and the accurate detection and processing of abnormal traffic is realized, which improves network security.

CN120074948BActive Publication Date: 2025-09-02HUAXIN CONSULTATING CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510510477.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-23
Publication Date
2025-09-02
Estimated Expiration
2045-04-23

AI Technical Summary

Technical Problem

In the prior art, in the detection of abnormal traffic, the smart park communication network cannot reflect the defense requirements of different traffic data in different characteristic dimensions, resulting in insufficient sensitivity of the defense mechanism and ineffective detection of abnormal traffic.

Method used

The historical and current network traffic data of the smart park communication network are collected, feature information is extracted, the independent defense degree is calculated under each feature dimension, and the dimensional coefficient of the LOF value is reconstructed based on the independent defense degree, and abnormal traffic is detected by adjusting the dimensional coefficient.

Benefits of technology

It improves the sensitivity of the defense mechanism of the smart park communication network, can accurately detect and process abnormal traffic data, and ensure network stability and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074948B_ABST
    Figure CN120074948B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of digital information processing technology, and specifically to a smart park communication network security control method and system, the method comprising: collecting multiple historical network traffic data and multiple current network traffic data in the smart park communication network, and extracting first feature information corresponding to multiple feature dimensions for each historical network traffic data, and second feature information corresponding to multiple feature dimensions for each current network traffic data; calculating the independent defense degree of each current network traffic data in each feature dimension based on the first feature information and the second feature information; reconstructing the dimension coefficient of each current network traffic data when calculating the LOF value based on the independent defense degree; detecting abnormal traffic data in multiple current network traffic data based on the dimension coefficient, and performing security defense processing on the abnormal traffic data. The present invention can effectively detect abnormal traffic data in the current network and improve the sensitivity of the defense mechanism of the smart park communication network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of digital information processing technology, and in particular to a method and system for controlling the communication network security of a smart park. Background Art

[0002] A smart campus is an intelligent campus system built by applying modern information technologies such as the Internet of Things, big data, artificial intelligence, and cloud computing. Within this campus, users (including employees, residents, and tourists) often rely on high-quality network connections for their daily work and lives. Therefore, effective abnormal traffic detection and automated control are particularly important. This not only reduces network outages, latency, and congestion, but also ensures smooth access to various intelligent services within the campus, thereby improving overall user satisfaction and experience.

[0003] In existing technologies, anomalous traffic detection is typically performed using a Local Outlier Factor (LOF) algorithm. When calculating the LOF values ​​for different traffic data within a current communication network, the dimensionality coefficients for all feature dimensions are fixed and do not change with changes in traffic data. However, due to the differentiated nature of traffic data, different traffic data requires different defenses in different feature dimensions. Using a unified dimensionality coefficient would fail to accurately reflect the anomalies of different traffic data in the feature dimensions that require focused defense, resulting in insufficient sensitivity in the defense mechanism and an inability to effectively detect anomalous traffic. Summary of the Invention

[0004] In order to solve the above technical problems, the purpose of the present invention is to provide a method and system for controlling the communication network security of a smart park. The technical solutions adopted are as follows:

[0005] In a first aspect, the present invention provides a method for controlling the communication network security of a smart park, the method comprising:

[0006] Collecting multiple historical network traffic data and multiple current network traffic data in the smart campus communication network, and extracting first feature information corresponding to multiple feature dimensions for each of the historical network traffic data, and second feature information corresponding to the multiple feature dimensions for each of the current network traffic data;

[0007] Based on the single defense degree in each characteristic dimension corresponding to the first characteristic information and the overlap of defense functions between any two characteristic dimensions, the single defense degree of the current network traffic data is modified and combined with the second characteristic information to obtain an independent defense degree for each characteristic dimension of the current network traffic data; the single defense degree is determined based on the purity of the control results of the historical network traffic data in each characteristic dimension;

[0008] Reconstructing the dimension coefficient of each current network traffic data when calculating the LOF value based on the independent defense degree;

[0009] Abnormal traffic data is detected in the multiple current network traffic data based on the dimension coefficient, and security defense processing is performed on the abnormal traffic data.

[0010] Optionally, the independent defense degree of each current network traffic data in each characteristic dimension is obtained as follows:

[0011] Calculate the single defense degree of the target in each feature dimension and the overlap of defense functions between any two feature dimensions based on the first feature information;

[0012] Calculating a current single defense degree of each current network traffic data in each feature dimension according to the target single defense degree and the second feature information;

[0013] The current single defense degree is modified based on the overlap of the defense functions between the arbitrary two characteristic dimensions to obtain the independent defense degree of each current network traffic data in each characteristic dimension relative to other characteristic dimensions.

[0014] Optionally, the first feature information includes a control result label value of each of the historical network traffic data at different occurrence times, and a first feature value in each feature dimension;

[0015] The calculating, based on the first feature information, the target single defense degree in each feature dimension and the overlap of defense functions between any two feature dimensions includes:

[0016] Calculate the single purity of the control result of each historical network traffic data in each feature dimension based on the occurrence time of each historical network traffic data, the control result label value of each historical network traffic data, and the first feature value in each feature dimension;

[0017] Determining a relative purity of the control result corresponding to a single purity of the control result;

[0018] Calculating a target single defense degree for each characteristic dimension based on the relative purity of the control result and the first characteristic value;

[0019] Based on the plurality of historical network traffic data and the target single defense degree of each characteristic dimension, the overlap of defense functions between any two characteristic dimensions is calculated.

[0020] Optionally, determining the relative purity of the control result corresponding to the single purity of the control result includes:

[0021] Determining, from the plurality of historical network traffic data, a plurality of normal historical network traffic data or a plurality of abnormal historical network traffic data corresponding to the same control result label value as each of the historical network traffic data;

[0022] Determine a single purity LOF value of each of the historical network traffic data on the plurality of normal historical network traffic data or the plurality of abnormal historical network traffic data;

[0023] Based on the single purity of the control result of each historical network traffic data in each characteristic dimension and the single purity LOF value, the relative purity of the control result of each historical network traffic data in each characteristic dimension is calculated.

[0024] Optionally, calculating the target single defense degree of each characteristic dimension based on the relative purity of the control result and the first characteristic value includes:

[0025] Determine, based on the relative purity of the control result and the first characteristic value of each of the historical network traffic data in each characteristic dimension, a first overall characteristic value of each of the normal historical network traffic data in each characteristic dimension, and a second overall characteristic value of each of the abnormal historical network traffic data in each characteristic dimension;

[0026] The absolute value of the difference between the first overall eigenvalue and the second overall eigenvalue in each characteristic dimension is determined as the target single defense degree.

[0027] Optionally, the calculating the overlap of defense functions between any two feature dimensions based on the plurality of historical network traffic data and the target single defense degree of each feature dimension includes:

[0028] Calculating a historical single defense degree for each abnormal historical network traffic data in each characteristic dimension based on the target single defense degree, the first characteristic value of each abnormal historical network traffic data in each characteristic dimension, and the first overall characteristic value of each normal historical network traffic data in each characteristic dimension;

[0029] The historical single defense degree is used to calculate the overlap of defense functions between any two feature dimensions.

[0030] Optionally, the second feature information includes a second feature value of the current network traffic data in each feature dimension;

[0031] Calculating the current single defense degree of each current network traffic data in each characteristic dimension according to the target single defense degree and the second characteristic information includes:

[0032] Based on the target single defense level, the second characteristic value of each current network traffic data in each characteristic dimension, and the first overall characteristic value of the multiple normal historical network traffic data in each characteristic dimension, the current single defense level of each current network traffic data in each characteristic dimension is calculated.

[0033] Optionally, the modifying the current single defense degree based on the overlap of the defense functions between any two characteristic dimensions to obtain the independent defense degree of each current network traffic data in each characteristic dimension relative to other characteristic dimensions includes:

[0034] Determining the non-overlapping of the defense functions of each characteristic dimension relative to other characteristic dimensions based on the overlap of the defense functions between any two characteristic dimensions;

[0035] Based on the non-overlapping nature of the defense functions and the current single defense degree of each current network traffic data in each characteristic dimension, the independent defense degree of each current network traffic data in each characteristic dimension relative to other characteristic dimensions is calculated.

[0036] Optionally, detecting abnormal traffic data from the plurality of current network traffic data based on the dimensionality coefficient includes:

[0037] Calculate an abnormal value of each of the current network traffic data based on the dimension coefficient;

[0038] The current network traffic data corresponding to the abnormal value greater than a preset threshold among the multiple current network traffic data are determined as abnormal traffic data.

[0039] In a second aspect, an embodiment of the present invention also provides a smart campus communication network security control system, comprising a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the processor implements the steps of any one of the above methods when executing the computer program.

[0040] The present invention has the following beneficial effects: through the technical solution provided by the present invention, after collecting multiple historical network traffic data and multiple current network traffic data in the smart park communication network, the first feature information corresponding to each historical network traffic data under multiple feature dimensions and the second feature information corresponding to each current network traffic data under multiple feature dimensions can be extracted; then, based on the first feature information and the second feature information, the independent defense degree of each current network traffic data under each feature dimension is calculated; further based on the independent defense degree, the dimension coefficient of each current network traffic data when calculating the LOF value is reconstructed; finally, based on the dimension coefficient, abnormal traffic data is detected in multiple current network traffic data, and security defense processing is performed on the abnormal traffic data. Starting from the perspective of historical network traffic data, the present invention calculates the independent defense degree of each current network traffic data under each feature dimension, and reconstructs the dimension coefficient of each traffic data in the current communication network when calculating the abnormal value based on the independent defense degree, thereby being able to accurately calculate the abnormal value of each current network traffic data under the defense focus, effectively detect abnormal traffic data in the current network, and enhance the sensitivity of the defense mechanism of the smart park communication network.

[0041] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory and cannot limit the present invention. Other features and advantages of the present invention will be described in detail in the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the technical solutions and advantages of the embodiments of the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the prior art descriptions. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0043] Figure 1 A schematic flow chart of a method for controlling security of a smart campus communication network provided by one embodiment of the present invention;

[0044] Figure 2 A flowchart of a smart campus communication network security control method provided by another embodiment of the present invention. DETAILED DESCRIPTION

[0045] To further illustrate the technical means and effectiveness of the present invention to achieve its intended purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, describes in detail the specific implementation, structure, features, and effectiveness of a smart campus communication network security control method and system proposed by the present invention. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. In addition, specific features, structures, or characteristics of one or more embodiments may be combined in any suitable form.

[0046] Unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs.

[0047] The specific scheme of the smart park communication network security control method and system provided by the present invention is described in detail below with reference to the accompanying drawings.

[0048] See also Figure 1 , which shows a flowchart of a method for controlling security of a smart campus communication network provided by an embodiment of the present invention, the method comprising the following steps:

[0049] Step 110: Collect multiple historical network traffic data and multiple current network traffic data in the smart campus communication network, and extract the first feature information under multiple feature dimensions corresponding to each historical network traffic data, and the second feature information under multiple feature dimensions corresponding to each current network traffic data.

[0050] Among them, historical network traffic data refers to the traffic data generated by the smart campus communication network within a certain period of time in the past. These data reflect the past operating status of the campus network; current network traffic data represents the traffic data of the smart campus communication network at the current moment or in the recent short period of time; the first feature information comes from the historical network traffic data in the smart campus communication network, reflecting the characteristics of past network traffic in multiple feature dimensions. It may include the control result label value of each historical network traffic data at different occurrence times, as well as the first feature value in each feature dimension. The second feature information corresponds to the current network traffic data, showing the real-time status of the network in the same multiple feature dimensions. It may include the second feature value of the current network traffic data in each feature dimension.

[0051] In specific application scenarios, network packet capture tools (such as Wireshark) can be used to capture and analyze current network traffic data in the smart campus communication network, extracting M features related to network behavior to describe the basic characteristics of the traffic and help identify potential abnormal behavior. These features typically include M factors such as packet size, communication packet frequency, packet transmission interval, and destination IP address. These are quantified as shown in Table 1 below:

[0052] Table 1. Second characteristic information corresponding to current network traffic data

[0053]

[0054] On this basis, we further collected N historical network traffic data samples that had undergone security analysis and were labeled with the control results of each traffic data (specifically, when the traffic was judged to be abnormal, the corresponding control result label E was 1, indicating that the system had taken defensive measures; when the traffic was normal, E was 0, indicating that no defensive measures had been taken) and the time of occurrence. This is shown in Table 2 below:

[0055] Table 2. The first characteristic information corresponding to historical network traffic data

[0056]

[0057] Step 120: Based on the single defense degree in each characteristic dimension corresponding to the first characteristic information and the overlap of defense functions between any two characteristic dimensions, the single defense degree of the current network traffic data is corrected to obtain an independent defense degree for each characteristic dimension of the current network traffic data; the single defense degree is determined based on the purity of the control results of the historical network traffic data in each characteristic dimension.

[0058] The independent defense degree is a quantitative indicator used to measure the security, stability, or ability to address potential risks of current network traffic data within a specific characteristic dimension. This indicator is calculated by comprehensively considering the relationship between the first characteristic information (historical network traffic data characteristics) and the second characteristic information (current data characteristics). For example, if the current network traffic characteristics within a certain application dimension differ significantly from historical normal traffic characteristics, the independent defense degree may be low, indicating that the network traffic of this application may be at risk and require further attention and defense. Conversely, if it aligns with historical characteristics, the independent defense degree may be high, indicating that the network traffic status of this application is relatively stable and the risk is low. By calculating the independent defense degree, we can fully understand the real-time status of the smart campus network in different dimensions, promptly identify potential problems, and provide a strong basis for network security protection and optimization.

[0059] Step 130: Reconstruct the dimension coefficient of each current network traffic data when calculating the LOF value based on the independent defense degree.

[0060] When calculating the Local Outlier Factor (LOF) value, different feature dimensions have varying importance in determining whether a data point is an outlier. The dimension coefficient is a parameter that measures this importance. For example, in smart campus network traffic data, the bandwidth dimension and the packet type dimension may be of varying importance in determining network anomalies, each with a corresponding dimension coefficient. If the independent defense of the current network traffic data for a certain feature dimension is low, indicating that the network traffic in that dimension is at risk or unstable, the coefficient of that dimension may be increased when calculating the LOF value, making it more influential in determining outliers and more sensitive to possible anomalies in that dimension. Conversely, if the independent defense is high, indicating that the dimension is relatively stable, the dimension coefficient may be decreased, reducing its weight in determining outliers. By reconstructing the dimension coefficients used in calculating the LOF value based on the independent defense, potential outliers can be more flexibly and accurately identified based on the real-time status of network traffic, improving the detection capabilities of abnormal traffic in smart campus communication networks.

[0061] Step 140: Detect abnormal traffic data in multiple current network traffic data based on the dimension coefficient, and perform security defense processing on the abnormal traffic data.

[0062] In the disclosed embodiments, the reconstructed dimensionality coefficients can be used as a basis to analyze the collected data points using the LOF algorithm. The LOF algorithm determines whether each data point is an outlier, or abnormal data, by comparing the density of each data point with its neighboring points. By considering the adjusted dimensionality coefficients, the detection process can more accurately reflect the impact of different characteristic dimensions on traffic anomaly determination. For example, when calculating the LOF value for a current network traffic data point, the data transmission rate dimension, due to its higher coefficient, will have a greater impact on the final LOF value. If the data on this dimension differs significantly from its neighboring points, the likelihood of the data point being an outlier is significantly increased. Appropriate security measures are implemented for detected abnormal traffic data. These may include various methods, such as immediately blocking the transmission of abnormal traffic to prevent further impact on the network; tracing the source of the abnormal traffic to attempt to identify the attack source or faulty equipment; and recording detailed information about the abnormal traffic, such as traffic characteristics and occurrence time, for subsequent in-depth analysis and improved network security strategies. For example, if abnormal traffic is detected from a specific IP address, the IP address may be temporarily blocked, and the relevant traffic data will be logged for subsequent analysis by the network security team. These security defenses ensure the stable and secure operation of the smart campus communication network.

[0063] In summary, according to a smart park communication network security control method provided by the present invention, after collecting multiple historical network traffic data and multiple current network traffic data in the smart park communication network, the first feature information corresponding to each historical network traffic data under multiple feature dimensions and the second feature information corresponding to each current network traffic data under multiple feature dimensions can be extracted; then, based on the first feature information and the second feature information, the independent defense degree of each current network traffic data under each feature dimension is calculated; further, based on the independent defense degree, the dimension coefficient of each current network traffic data when calculating the LOF value is reconstructed; finally, based on the dimension coefficient, abnormal traffic data is detected in multiple current network traffic data, and security defense processing is performed on the abnormal traffic data. Starting from the perspective of historical network traffic data, the present invention calculates the independent defense degree of each current network traffic data under each feature dimension, and reconstructs the dimension coefficient of each traffic data in the current communication network when calculating the abnormal value based on the independent defense degree, thereby being able to accurately calculate the abnormal value of each current network traffic data under the defense focus, effectively detect abnormal traffic data in the current network, and enhance the sensitivity of the smart park communication network defense mechanism.

[0064] based on Figure 1 The embodiment shown is a refinement and expansion of the above embodiment. In order to fully illustrate the specific implementation process of the method of this embodiment, this embodiment provides the following Figure 2 The specific method shown. Figure 2 based on Figure 1 The embodiment shown. Figure 2 As shown, the method includes the following steps:

[0065] Step 210: Collect multiple historical network traffic data and multiple current network traffic data in the smart campus communication network, and extract the first feature information under multiple feature dimensions corresponding to each historical network traffic data, and the second feature information under multiple feature dimensions corresponding to each current network traffic data.

[0066] For the embodiment of the present disclosure, the specific implementation process can be found in the relevant description of step 110 of the embodiment, which will not be repeated here.

[0067] Step 220: Calculate the target single defense degree in each feature dimension and the overlap of defense functions between any two feature dimensions based on the first feature information.

[0068] The target single defense degree (TSD) is a metric calculated for each individual feature dimension, measuring the network's ability to defend against potential risks or anomalies within that specific dimension. For example, within the "time" dimension (such as the difference in network traffic between weekdays and weekends), by analyzing the first feature information in historical network traffic data, the network's TSD can be calculated for that time dimension, thereby understanding the network's ability to defend against traffic anomalies at different time periods. The overlap of defense functions refers to the degree of overlap in the network's ability to defend against risks or anomalies across different feature dimensions. For example, within the time dimension, the network may have a defense mechanism for traffic anomalies during peak weekday hours; within the application type dimension, it may also have a corresponding defense mechanism for traffic anomalies in video conferencing applications. The defense mechanisms in these two dimensions may share some common measures or logic, and overlap is a quantitative assessment of this overlap. By calculating this overlap, we can understand the correlation between defense mechanisms across different feature dimensions, helping to optimize the network's overall defense strategy, avoid duplication of defense functions, and identify potential defense gaps.

[0069] Accordingly, in the embodiment of the present disclosure, calculating the target single defense degree in each feature dimension and the overlap of defense functions between any two feature dimensions based on the first feature information in step 220 may include the following steps:

[0070] Step 220-1: Calculate the single purity of the control result of each historical network traffic data in each feature dimension based on the occurrence time of each historical network traffic data, the control result label value of each historical network traffic data, and the first feature value in each feature dimension.

[0071] The network environment in a smart campus is highly dynamic. Network traffic is affected by multiple factors, such as device connection status, mobile devices within the campus, network bandwidth allocation, and fluctuations in user demand. Traffic characteristics can change dramatically over time. Consequently, certain traffic characteristics (such as latency and packet loss rate) may not be accurately captured, resulting in deviations and impurities in the control results for each historical network traffic data set. Therefore, this step determines the purity of the control results for each collected historical network traffic data set under the influence of each feature dimension. Here, we take the control results for the i-th historical network traffic data set under the w-th feature dimension as an example. Generally speaking, if other historical network traffic data sets have similar feature values ​​under feature dimension w, then the traffic patterns of the data are very similar in that dimension. If the control results are consistent based on this, then their behavior patterns under that feature dimension w have been confirmed, and the control results for the i-th historical network traffic data set are considered more reliable and pure. However, there are N other historical network traffic data sets, and not every one of them contributes to the purity of the control results. In the communication network of a smart campus, the behavior of traffic data is usually affected by multiple factors, such as device load, network topology, application traffic, etc. If other historical network traffic data is closer in time to traffic data i, it means that there may be the same or similar network status or behavior pattern behind these traffic data, and their contribution should be higher.

[0072] In the embodiment of the present disclosure, the first calculation formula can be constructed through the above description to calculate the single purity of the control result of the i-th historical network traffic data under the w-th characteristic dimension. Specifically, the occurrence time of each historical network traffic data, the control result label value of each historical network traffic data, and the first characteristic value under each characteristic dimension can be substituted into the first calculation formula to calculate the single purity of the control result of each historical network traffic data under each characteristic dimension. Among them, the formula characteristic description of the first calculation formula is:

[0073]

[0074] Where, P i represents the single purity of the control result of the i-th historical network traffic data under the w-th feature dimension, N represents the total number of collected historical network traffic data, exp represents the exponential function with e as the base, t i Indicates the occurrence time of the i-th historical network traffic data, t j Indicates the occurrence time of the jth historical network traffic data, exp(-|t i -t j |) represents the similarity of the occurrence time of the i-th historical network traffic data and the j-th historical network traffic data, Ei represents the control result of the i-th historical network traffic data, E j represents the control result of the jth historical network traffic data, ||E i -E j |-1| indicates the consistency of the control results of the i-th historical network traffic data and the j-th historical network traffic data, F wi represents the characteristic value of the i-th historical network traffic data in the w-th characteristic dimension, E wj represents the characteristic value of the j-th historical network traffic data in the w-th characteristic dimension, ε1 represents a hyperparameter, 1 / (|F wi -E wj |+ε1) represents the similarity of the feature values ​​of the i-th historical network traffic data and the j-th historical network traffic data in the w-th feature dimension.

[0075] Similarly, the single purity of the control result of each historical network traffic data in each characteristic dimension can be determined.

[0076] Step 220 - 2 : Determine the relative purity of the control result corresponding to the single purity of the control result.

[0077] Because network traffic in smart parks is not static but highly dynamic, the usage requirements of devices and applications change over time, and network load and traffic patterns may experience instantaneous fluctuations. For example, the data collection frequency and transmission rate of certain devices may be adjusted based on factors such as human activities and environmental changes within the park. Traffic characteristics within a local time period can better reflect short-term changes in the network and help determine the relative purity of the control results of each historical network traffic data in all feature dimensions (relative means local). Here, we take the control results of the i-th historical network traffic data in the w-th feature dimension as an example: for all collected historical network traffic data, the control results can be divided into two categories (1 and 0). Based on this, multiple historical network traffic data can be divided into multiple normal historical network traffic data corresponding to the control result label value of 0 and multiple abnormal historical network traffic data corresponding to the control result label value of 1. Then, the abnormal historical network traffic data classified as 1 is plotted, with the horizontal axis representing time and the vertical axis representing the single purity of the control result of the abnormal historical network traffic data under the w-th feature dimension; then, the normal historical network traffic data classified as 0 is plotted, with the horizontal axis also representing time and the vertical axis representing the single purity of the control result of the normal historical network traffic data under the w-th feature dimension.

[0078] For the single purity control result of the i-th historical network traffic data in the w-th characteristic dimension, the more pronounced the concentration of traffic data purity in the two-dimensional space of time and single purity, the more stable the network behavior and healthier the system's operating status (better purity) during that period, and the more stable factors such as network load and application status are. In this case, the network management system can more accurately determine traffic behavior, reduce the risk of misjudgment, and provide more effective traffic control. Therefore, based on the single purity, the more pronounced the purity concentration effect and the smaller the LOF value, the higher the relatively healthy and useful purity.

[0079] For the embodiments of the present disclosure, the steps of the embodiment may include: determining, from multiple historical network traffic data, multiple normal historical network traffic data or multiple abnormal historical network traffic data corresponding to the same control result label value for each historical network traffic data; determining a single purity LOF value for each historical network traffic data on the multiple normal historical network traffic data or multiple abnormal historical network traffic data; and calculating the relative purity of the control result for each historical network traffic data in each feature dimension based on the single purity of the control result and the single purity LOF value for each historical network traffic data. Specifically, when the control result label value corresponding to the historical network traffic data for which the relative purity of the control result needs to be determined is 0, multiple normal historical network traffic data corresponding to the same control result label value as the historical network traffic data can be obtained in the above-drawn time-single purity two-dimensional space; or, when the control result label value corresponding to the historical network traffic data for which the relative purity of the control result needs to be determined is 1, multiple abnormal historical network traffic data corresponding to the same control result label value as the historical network traffic data can be obtained in the above-drawn time-single purity two-dimensional space. Afterwards, the single purity LOF value of multiple normal historical network traffic data or multiple abnormal historical network traffic data can be determined. Specifically, the LOF algorithm can be used to judge anomalies based on density. If in the historical network traffic data, the density of a certain traffic data point in its local neighborhood is significantly lower than the density of other surrounding data points, it means that it is significantly different from the surrounding data in this single dimension, and it may be an anomaly. Its single purity LOF value will be higher, which means that the purity of the data point is relatively low, and there may be data anomalies or impurities.

[0080] Accordingly, in the embodiment of the present disclosure, when calculating the relative purity of the control result of each historical network traffic data in each characteristic dimension based on the single purity of the control result and the single purity LOF value of each historical network traffic data in each characteristic dimension, the single purity of the control result and the single purity LOF value of each historical network traffic data in each characteristic dimension can be substituted into the second calculation formula to calculate the relative purity of the control result of each historical network traffic data in each characteristic dimension. The formula characteristic description of the second calculation formula is:

[0081]

[0082] Formula explanation: Where, Indicates the relative purity of the control result of the i-th historical network traffic data under the w-th feature dimension, LOF k (P i ) represents a single purity LOF value on multiple normal historical network traffic data or multiple abnormal historical network traffic data corresponding to the same control result label value as the i-th historical network traffic data, P i It represents the single purity of the control result of the i-th historical network traffic data under the w-th feature dimension.

[0083] Similarly, the relative purity of the control results of each historical network traffic data in each characteristic dimension can be determined.

[0084] Step 220 - 3 : Calculate the target single defense degree of each characteristic dimension based on the relative purity of the control result and the first characteristic value.

[0085] For N historical network traffic data sets of a smart campus communication network (with M features), if we want to calculate the defense level for a particular feature, we need to subtract the second overall eigenvalue (feature average) of multiple abnormal historical network traffic data sets in each feature dimension from the first overall eigenvalue (feature average) of multiple normal historical network traffic data sets in each feature dimension. The larger the absolute value difference, the higher the defense level for that feature. (This process essentially measures the difference between the feature and the defense result, reflecting the feature's influence on distinguishing the defense effect (defense result of 1 or 0)).

[0086] However, not all historical network traffic data control result labels have the same relative purity. We need to make historical network traffic data with high relative purity contribute more to the feature average, while making historical network traffic data with low relative purity contribute less to the feature average. Therefore, we can construct the following third calculation formula to represent the target single defense level of the wth feature dimension. The formula feature description of the third calculation formula is:

[0087]

[0088] Where, X w represents the single defense degree of the target in the wth feature dimension, n0 represents the number of normal historical network traffic data with a control result of 0, F0 represents the relative purity of the control result of the u-th normal historical network traffic data under the w-th feature dimension, wu represents the first eigenvalue of the u-th normal historical network traffic data under the w-th feature dimension, represents the first overall eigenvalue of multiple normal historical network traffic data under the wth feature dimension, n1 represents the number of abnormal historical network traffic data with a control result of 1. F1 represents the relative purity of the control result of the vth abnormal historical network traffic data under the wth feature dimension, wv represents the characteristic value of the vth abnormal historical network traffic data in the wth characteristic dimension, Represents the overall eigenvalue of multiple abnormal historical network traffic data (the control result is 1) in the wth feature dimension.

[0089] Similarly, the single defense degree of the target in each characteristic dimension can be determined.

[0090] Denoted as F0 w

[0091] F1 w

[0092] Accordingly, for the embodiment of the present disclosure, the embodiment steps may include: determining the first overall eigenvalue of multiple normal historical network traffic data in each characteristic dimension and the second overall eigenvalue of multiple abnormal historical network traffic data in each characteristic dimension based on the relative purity of the control result and the first eigenvalue of each historical network traffic data in each characteristic dimension; and determining the absolute value of the difference between the first overall eigenvalue and the second overall eigenvalue in each characteristic dimension as the target single defense degree.

[0093] Step 220 - 4 : Based on the multiple historical network traffic data and the target single defense degree of each feature dimension, the overlap of the defense functions between any two feature dimensions is calculated.

[0094] For the embodiments disclosed herein, the embodiment steps may include: calculating the historical single defense degree of each abnormal historical network traffic data in each characteristic dimension based on the target single defense degree, the first eigenvalue of each abnormal historical network traffic data in each characteristic dimension, and the first overall eigenvalue of multiple normal historical network traffic data in each characteristic dimension; and using the historical single defense degree to calculate the overlap of defense functions between any two characteristic dimensions.

[0095] This step requires using abnormal historical network traffic data (traffic data that has been defended) to determine the overlap of defense functions between any two feature dimensions. For each abnormal historical network traffic data item i with a control result of 1, the overlap of defense functions between feature dimensions k and w is analyzed: If there is overlap in defense functions between the kth feature dimension and the wth feature dimension, then it can be assumed that as long as the single defense degree of one feature is high, it can effectively offset the defense effect of the other feature (i.e., a "one increases, the other decreases" relationship). In other words, if |X k (i)-X w (i)|, the greater the gap, the higher the defense overlap. However, if the abnormal historical network traffic data i has a large single defense degree in both dimensions k and w, then it can also show a good defense effect. At this time, whether there is functional overlap is unknown. Therefore, we need to use the historical n1 abnormal historical network traffic data that have been judged to obtain the defense function overlap of the kth feature dimension and the wth feature dimension. It is necessary to make sure that when the single defense degree of k and w is large, the contribution of the data is relatively small, that is, min(X k (i),X w (i)) The smaller the better.

[0096] In a specific application scenario, the target single defense degree, the first eigenvalue of each abnormal historical network traffic data in each characteristic dimension, and the first overall eigenvalue of multiple normal historical network traffic data in each characteristic dimension can be substituted into the fourth calculation formula to calculate the historical single defense degree of each abnormal historical network traffic data in each characteristic dimension.

[0097] The characteristic description of the fourth calculation formula is:

[0098] X W (R)=X W *|F wR -F0 w |

[0099] Where, X W (R) represents the historical single defense degree of abnormal historical network traffic data R in the wth feature dimension, X Wrepresents the single defense degree of the target in the wth feature dimension, F wR Indicates the first eigenvalue of the abnormal historical network traffic data R in the wth dimension, F0 w Represents the first overall eigenvalue of normal historical traffic data (control result is 0) in the wth feature dimension.

[0100] Similarly, the historical single defense degree of each abnormal historical network traffic data in each characteristic dimension in the current network can be determined.

[0101] Furthermore, the historical single defense degree of each abnormal historical network traffic data under any two characteristic dimensions can be substituted into the fifth calculation formula to calculate the overlap of the defense function between any two characteristic dimensions. The formula characteristics of the fifth calculation formula are described as follows:

[0102]

[0103] Where C k-w represents the overlap of the defense functions of the kth feature dimension and the wth feature dimension, f represents the maximum and minimum value normalization function (compared with any two other feature dimensions), n1 represents the number of abnormal historical network traffic data with a control result of 1, X k (i) represents the historical single defense degree of the i-th abnormal historical network traffic data Q in the k-th feature dimension, X w (i) represents the historical single defense degree of the i-th abnormal historical network traffic data Q in the w-th feature dimension, and min() represents selecting the minimum value.

[0104] Similarly, the overlap of defense functions between any two feature dimensions can be determined.

[0105] Step 230: Calculate the current single defense degree of each current network traffic data in each characteristic dimension according to the target single defense degree and the second characteristic information.

[0106] For the current network traffic data Q in the current communication network of the smart park, if the defense degree of the w feature dimension is high (X w ), and the characteristic average value of normal historical network traffic data (F0 w ) The gap is large, then it is necessary to focus on defending the traffic data Q in the w dimension.

[0107] Accordingly, for the embodiment of the present disclosure, the embodiment steps may include: calculating the current single defense degree of each current network traffic data in each feature dimension based on the target single defense degree, the second feature value of each current network traffic data in each feature dimension, and the first overall feature value of multiple normal historical network traffic data in each feature dimension.

[0108] In the disclosed embodiment, the target single defense level, the second eigenvalue of each current network traffic data item in each characteristic dimension, and the first overall eigenvalue of multiple normal historical network traffic data items in each characteristic dimension can be substituted into the sixth calculation formula to calculate the current single defense level of each current network traffic data item in each characteristic dimension. The formula characteristics of the sixth calculation formula are described as follows:

[0109] X w (Q) = X w *|F wQ -F0 w |

[0110] Where, X w (Q) represents the current single defense degree of the current network traffic data Q in the wth feature dimension, X w represents the single defense degree of the wth feature dimension, F wQ Indicates the characteristic value of the current network traffic data Q in the wth dimension, F0 w Represents the overall eigenvalue of normal historical traffic data (control result is 0) in the wth feature dimension.

[0111] Similarly, the current single defense level of each current network traffic data in each characteristic dimension can be determined.

[0112] Step 240: Based on the overlap of defense functions between any two feature dimensions, the current single defense level is modified to obtain the independent defense level of each current network traffic data in each feature dimension relative to other feature dimensions.

[0113] When the LOF algorithm calculates the current network traffic data, each feature dimension exists and is calculated independently. Therefore, the calculated defense level of the current network traffic data Q in the w-th feature dimension must also be independent. The above steps have calculated the overlap of defense functions between each feature dimension and the w-th feature dimension. Therefore, in order to accurately evaluate the independent defense level of the current network traffic data Q in the w-th feature dimension, it is necessary to eliminate the interference of this overlap on the defense level evaluation, that is, to use the obtained non-overlapping degree. A weighted calculation formula is constructed. Specifically, the non-overlapping defense function of each feature dimension relative to other feature dimensions and the current single defense degree of each current network traffic data in each feature dimension are substituted into the seventh calculation formula to calculate the independent defense degree of the current network traffic data Q in each feature dimension relative to other feature dimensions.

[0114] The formula characteristic description of the seventh calculation formula is:

[0115]

[0116] Where Y w (Q) represents the independent defense degree of the wth feature dimension of the current network traffic data Q relative to other dimensions, M represents a total of M feature dimensions, C k-w represents the overlap of the defense functions of the kth feature dimension and the wth feature dimension, represents the defensive non-overlap of the wth feature dimension relative to other dimensions, X w (Q) represents the current single defense degree of the current network traffic data Q in the w-th feature dimension.

[0117] Similarly, the independent defense degree of each current network traffic data in each characteristic dimension relative to other dimensions can be determined.

[0118] Accordingly, in the embodiment of the present disclosure, step 240 of correcting the current single defense level based on the overlap of defense functions between any two feature dimensions to obtain the independent defense of each current network traffic data in each feature dimension relative to other feature dimensions may include the following steps:

[0119] Step 240 - 1 : Determine the non-overlapping of the defense functions of each feature dimension relative to other feature dimensions based on the overlap of the defense functions between any two feature dimensions.

[0120] Step 240 - 2 : Based on the non-overlapping nature of defense functions and the current single defense level of each current network traffic data in each characteristic dimension, calculate the independent defense level of each current network traffic data in each characteristic dimension relative to other characteristic dimensions.

[0121] Step 250: Reconstruct the dimension coefficient of each current network traffic data when calculating the LOF value based on the independent defense degree.

[0122] For the specific implementation process of the embodiment of the present disclosure, please refer to the relevant description in step 130 of the embodiment, which will not be repeated here.

[0123] Step 260: Detect abnormal traffic data in multiple current network traffic data based on the dimension coefficient, and perform security defense processing on the abnormal traffic data.

[0124] Accordingly, for the embodiments of the present disclosure, when detecting abnormal traffic data in multiple current network traffic data based on the dimensionality coefficient, the embodiment steps may include: calculating the abnormal value of each current network traffic data based on the dimensionality coefficient; and determining the current network traffic data whose corresponding abnormal value in the multiple current network traffic data is greater than a preset threshold as abnormal traffic data.

[0125] In a specific application scenario, when the outlier value of the current network traffic data is much higher than 1, it indicates that the traffic data point may be an abnormal traffic data. In order to accurately identify abnormal traffic, a threshold is set for these outliers as a judgment criterion. Here, the preset threshold can be set to 2. This value means that when the outlier value of a certain traffic data point exceeds 2, it can be considered as an abnormal traffic data. For the identified abnormal traffic data, security defense measures can be automatically controlled to be triggered. For example, traffic isolation can be implemented through a network firewall or traffic filtering device to block communication requests from abnormal sources or targets, cut off the network connection with them, and prevent the abnormal traffic from spreading further and affecting the stability and security of the entire network. Traffic isolation, as an emergency response measure, can effectively reduce the risks posed by abnormal traffic to network security. However, in order to ensure the long-term security of the network, it can also be combined with other technical means, such as vulnerability repair, to comprehensively carry out defense and governance to ensure the security and stability of the network environment.

[0126] In summary, the technical solution in this application can extract the first feature information corresponding to multiple feature dimensions of each historical network traffic data and multiple current network traffic data in the smart campus communication network, and the second feature information corresponding to multiple feature dimensions of each current network traffic data; then, based on the first feature information and the second feature information, calculate the independent defense degree of each current network traffic data in each feature dimension; further reconstruct the dimension coefficient of each current network traffic data when calculating the LOF value based on the independent defense degree; finally, detect abnormal traffic data in multiple current network traffic data based on the dimension coefficient, and perform security defense processing on the abnormal traffic data. Starting from the perspective of historical network traffic data, the present invention calculates the independent defense degree of each current network traffic data in each feature dimension, and reconstructs the dimension coefficient of each traffic data in the current communication network when calculating the abnormal value based on the independent defense degree, thereby being able to accurately calculate the abnormal value of each current network traffic data under the defense focus, effectively detect abnormal traffic data in the current network, and enhance the sensitivity of the defense mechanism of the smart campus communication network.

[0127] Based on the same inventive concept as the above method, an embodiment of the present invention also provides a smart campus communication network security control system, including a memory, a processor, and a computer program stored in the memory and running on the processor. When the processor executes the computer program, it implements the steps of any one of the above-mentioned smart campus communication network security control methods.

[0128] In summary, the embodiments of the present invention provide a smart campus communication network security control method and system. Starting from the perspective of historical network traffic data, the independent defense degree of each current network traffic data in each characteristic dimension is calculated, and the dimension coefficient of each traffic data in the current communication network when calculating the abnormal value is reconstructed based on the independent defense degree. Then, the abnormal value of each current network traffic data can be accurately calculated under the defense focus, the abnormal traffic data in the current network can be effectively detected, and the sensitivity of the smart campus communication network defense mechanism can be improved.

[0129] It should be noted that the order in which the embodiments of the present invention are described above is for illustrative purposes only and does not necessarily represent the superiority or inferiority of the embodiments. Furthermore, the foregoing descriptions of specific embodiments of this specification are provided. Furthermore, the processes depicted in the accompanying drawings do not necessarily require the specific order or sequential sequence shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0130] The various embodiments in this specification are described in a progressive manner, and the same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments.

[0131] The above are only preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A method for controlling the security of a smart park communication network, characterized in that: The method comprises: Collecting multiple historical network traffic data and multiple current network traffic data in the smart campus communication network, and extracting first feature information corresponding to multiple feature dimensions for each of the historical network traffic data, and second feature information corresponding to the multiple feature dimensions for each of the current network traffic data; Based on the single defense degree in each characteristic dimension corresponding to the first characteristic information and the overlap of defense functions between any two characteristic dimensions, the single defense degree of the current network traffic data is modified to obtain an independent defense degree for each characteristic dimension of the current network traffic data; the single defense degree is determined based on the purity of the control results of the historical network traffic data in each characteristic dimension; The current single defense degree is obtained based on the target single defense degree and the second feature information; the target single defense degree is obtained based on the relative purity of the control result and the first feature value; the relative purity of the control result corresponds to the single purity of the control result, and the single purity of the control result is obtained based on the occurrence time of each historical network traffic data, the control result label value of each historical network traffic data, and the first feature value in each feature dimension; The independent defense degree is obtained based on the non-overlapping of defense functions and the current single defense degree; the non-overlapping of defense functions is obtained based on the overlap; the method for obtaining the relative purity of the control result is: determining multiple normal historical network traffic data or multiple abnormal historical network traffic data corresponding to the same control result label value for each historical network traffic data; determining the single purity LOF value of each historical network traffic data on the multiple normal historical network traffic data or multiple abnormal historical network traffic data; based on the single purity of the control result and the single purity LOF value of each of the historical network traffic data in each characteristic dimension, the relative purity of the control result of each historical network traffic data in each characteristic dimension is calculated; Reconstructing the dimension coefficient of each current network traffic data when calculating the LOF value based on the independent defense degree; Abnormal traffic data is detected in the multiple current network traffic data based on the dimension coefficient, and security defense processing is performed on the abnormal traffic data.

2. The smart park communication network security control method according to claim 1 is characterized in that: The method for obtaining the independent defense degree of each current network traffic data in each characteristic dimension is as follows: Calculate the single defense degree of the target in each feature dimension and the overlap of defense functions between any two feature dimensions based on the first feature information; Calculating a current single defense degree of each current network traffic data in each feature dimension according to the target single defense degree and the second feature information; The current single defense degree is modified based on the overlap of the defense functions between the arbitrary two characteristic dimensions to obtain the independent defense degree of each current network traffic data in each characteristic dimension relative to other characteristic dimensions.

3. The smart park communication network security control method according to claim 2, characterized in that: The first feature information includes a control result label value of each of the historical network traffic data at different occurrence times, and a first feature value in each feature dimension; The calculating, based on the first feature information, the target single defense degree in each feature dimension and the overlap of defense functions between any two feature dimensions includes: Calculate the single purity of the control result of each historical network traffic data in each feature dimension based on the occurrence time of each historical network traffic data, the control result label value of each historical network traffic data, and the first feature value in each feature dimension; Determining a relative purity of the control result corresponding to a single purity of the control result; Calculating a target single defense degree for each characteristic dimension based on the relative purity of the control result and the first characteristic value; Based on the plurality of historical network traffic data and the target single defense degree of each characteristic dimension, the overlap of defense functions between any two characteristic dimensions is calculated.

4. The smart park communication network security control method according to claim 1, characterized in that: Calculating the target single defense degree of each characteristic dimension based on the relative purity of the control result and the first characteristic value includes: Determine, based on the relative purity of the control result and the first characteristic value of each of the historical network traffic data in each characteristic dimension, a first overall characteristic value of each of the normal historical network traffic data in each characteristic dimension, and a second overall characteristic value of each of the abnormal historical network traffic data in each characteristic dimension; The absolute value of the difference between the first overall eigenvalue and the second overall eigenvalue in each characteristic dimension is determined as the target single defense degree.

5. The smart park communication network security control method according to claim 4 is characterized in that: The calculating the overlap of defense functions between any two feature dimensions based on the plurality of historical network traffic data and the target single defense degree of each feature dimension includes: Calculating a historical single defense degree for each abnormal historical network traffic data in each characteristic dimension based on the target single defense degree, the first characteristic value of each abnormal historical network traffic data in each characteristic dimension, and the first overall characteristic value of each normal historical network traffic data in each characteristic dimension; The historical single defense degree is used to calculate the overlap of defense functions between any two feature dimensions.

6. The smart park communication network security control method according to claim 4, characterized in that: The second feature information includes a second feature value of the current network traffic data in each feature dimension; Calculating the current single defense degree of each current network traffic data in each characteristic dimension according to the target single defense degree and the second characteristic information includes: Based on the target single defense level, the second characteristic value of each current network traffic data in each characteristic dimension, and the first overall characteristic value of the multiple normal historical network traffic data in each characteristic dimension, the current single defense level of each current network traffic data in each characteristic dimension is calculated.

7. The smart park communication network security control method according to claim 2, characterized in that: The method of correcting the current single defense degree based on the overlap of the defense functions between any two characteristic dimensions to obtain the independent defense degree of each current network traffic data in each characteristic dimension relative to other characteristic dimensions includes: Determining the non-overlapping of the defense functions of each characteristic dimension relative to other characteristic dimensions based on the overlap of the defense functions between any two characteristic dimensions; Based on the non-overlapping nature of the defense functions and the current single defense degree of each current network traffic data in each characteristic dimension, the independent defense degree of each current network traffic data in each characteristic dimension relative to other characteristic dimensions is calculated.

8. The smart park communication network security control method according to claim 1, characterized in that: The detecting abnormal traffic data from the plurality of current network traffic data based on the dimension coefficient includes: Calculate an abnormal value of each of the current network traffic data based on the dimension coefficient; The current network traffic data corresponding to the abnormal value greater than a preset threshold among the multiple current network traffic data are determined as abnormal traffic data.

9. A smart campus communication network security control system, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the computer program is executed by a processor, the steps of a smart campus communication network security control method as described in any one of claims 1 to 8 are implemented.

Citation Information

Patent Citations

  • Abnormity recognition method, device and equipment based on security monitoring, medium and program

    CN118869311A

  • Computer network information security monitoring method

    CN119603069A