Network security monitoring system
By extracting and analyzing the field dependencies and mutation trends of network traffic packets in the network security monitoring system, the shortcomings of existing systems in detecting and analyzing network traffic are solved, and higher abnormal traffic recognition capabilities and network protection capabilities are achieved.
Patent Information
- Application Number
- CN202510543650.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-28
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-04-28
AI Technical Summary
When detecting and analyzing network traffic, existing network security monitoring systems are difficult to adapt to complex network environments, and lack fine-grained analysis of the internal structure of data packets, resulting in some abnormal data not being accurately captured, and it is difficult to identify structural abnormal traffic, affecting the reliability of data packet integrity judgment.
A network security monitoring system is designed, through the traffic analysis module, the field name, field value and field order in the network traffic data packet are extracted, the dependence relationship between fields is judged, the field arrangement rules are calculated, and the field dependence mapping results are obtained. Then, the abnormality detection module analyzes the integrity of the data packet structure based on the field dependency mapping results, the traceability module analyzes the packet variation trend, the filter module judges the sustainability characteristics of the source traffic, and the risk assessment module evaluates the impact range and degree of harm of the abnormal traffic.
By analyzing the data packet structure and variation trends in fine-grainedness, the ability to identify abnormal traffic is improved, the ability to protect the network environment is enhanced, the limitations of static rule matching is reduced, and the accuracy and timeliness of security monitoring are improved.
Smart Images

Figure CN120074962A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security monitoring, and particularly to a network security monitoring system. Background Art
[0002] The technical field of network security monitoring includes technical methods for detecting, analyzing, and responding to security threats in computer networks. The core contents include network traffic analysis, intrusion detection, abnormal behavior recognition, and security event log management, etc. Network security monitoring technology identifies potential malicious activities by monitoring the data flow in real time and combines threat intelligence information for risk assessment. Overall, it covers static and dynamic detection methods, including rule-based matching analysis methods and detection strategies combining feature learning. At the same time, it involves the security assessment of network devices, communication protocols, access behaviors, etc. to ensure the stability and reliability of information systems.
[0003] Among them, a network security monitoring system refers to a technical solution for detecting, analyzing, and warning security risks in a computer network environment, covering technical matters such as network packet parsing, protocol layer review, abnormal behavior modeling and comparison, log information classification storage, and risk assessment. Its methods mainly include decoding and analyzing the collected network communication data, extracting data content from dimensions such as protocol characteristics and session behaviors, and performing comparison analysis based on preset strategies to identify potential security threats. In addition, the system classifies and archives the detected security events, constructs a threat situation awareness model by combining time series analysis methods, and generates security warning information using strategy matching methods to achieve continuous security monitoring of the network environment.
[0004] In the existing network security monitoring process, it mainly relies on static rule matching methods for traffic detection, resulting in difficulty in adapting to complex network environments when dealing with traffic anomalies, lacking fine-grained analysis of the internal structure of data packets, and easily ignoring the correlation between data fields, leading to some abnormal data not being accurately captured. Since the detection mechanism fails to combine field arrangement characteristics and dependency relationships for anomaly screening, it is difficult to effectively identify structurally abnormal traffic, affecting the reliability of packet integrity judgment. During the process of tracing abnormal traffic, there is a lack of in-depth analysis of the mutation trend of data packets, resulting in the tracing of traffic sources being limited to the IP and port levels, and it is difficult to accurately locate the attack path. The source traffic analysis is usually based on a single abnormal event and fails to combine historical records to judge the trend of traffic patterns, affecting the ability to identify persistent anomalies and making it difficult to distinguish some short-term anomalies from long-term attacks. In the risk assessment link, the determination method of the impact range of abnormal traffic is relatively static and difficult to dynamically adapt to the changing trend of threats, resulting in a lag in security policy responses and affecting the overall protection ability of the network environment. Summary of the Invention
[0005] The object of the present invention is to solve the disadvantages existing in the prior art, and to propose a network security monitoring system.
[0006] To achieve the above object, the present invention adopts the following technical solutions: A network security monitoring system includes: The traffic analysis module acquires network traffic data packets, extracts the field names, field values and field orders in the network traffic data packets, judges the inter-field dependency relationship, calculates the field arrangement rule, and obtains the field dependency mapping result; The anomaly detection module analyzes the arrangement stability of normal traffic fields based on the field dependency mapping result, compares the field arrangement method of the current network traffic data packet, calculates the field matching degree, and combines the field value relationship to judge the structural integrity of the network traffic data packet, and obtains the field sequence offset analysis result; The traffic tracing module extracts the timestamp, packet sequence number and flag field of the abnormal network traffic data packet based on the field sequence offset analysis result, analyzes the field change trend, traces the IP address, port and path of the abnormal network traffic data packet, and obtains the mutation path association analysis record; The anomaly screening module calculates the distribution frequency of the source IP in the abnormal data packets according to the mutation path association analysis record, calculates the continuity of the abnormal network traffic data packets and the source IP overlap degree, analyzes the matching situation between the packet field mutation amplitude and the time window, and judges whether the source traffic belongs to continuous abnormal traffic, and obtains the proportion data of continuous abnormal traffic.
[0007] As a further solution of the present invention, the field dependency mapping result includes the field name dependency relationship, the field order dependency relationship, and the field value dependency relationship. The field sequence offset analysis result includes the field matching degree, the field arrangement deviation value, and the field value integrity record. The mutation path association analysis record includes the abnormal data packet timestamp, packet sequence number, field mutation range, mutation trend similarity, abnormal data packet IP address and port. The proportion data of continuous abnormal traffic includes the abnormal data packet distribution frequency, the abnormal data packet time distribution pattern, the abnormal traffic continuity analysis result, the source IP overlap degree, and the field mutation amplitude matching situation.
[0008] As a further solution of the present invention, the traffic analysis module includes: The data packet acquisition sub-module acquires network traffic data packets, extracts basic field information such as the protocol type, source IP address, destination IP address, source port, destination port, and data length therein, identifies the validity of the data packets, and screens out abnormal and damaged data packets to obtain valid network traffic data packets; The field parsing sub-module parses the data packet structure based on the valid network traffic data packets, extracts the field names, field values, and field order, analyzes the distribution characteristics of the fields, calculates the field occurrence frequency and proportion, establishes the correspondence between the fields and the protocol types, and uses the formula: ; Calculate the field distribution coefficient , filter the field frequency characteristics, and generate the field distribution mapping result, where represents the th field value, represents the field mean, represents the field standard deviation, represents the protocol weight to which the field belongs, represents the field occurrence frequency, represents the total number of values of the fields in the data packet, represents the total number of all field categories; The dependency analysis sub-module determines the dependency relationship between the fields based on the field distribution mapping result, analyzes the sequence order between the fields, calculates the relative position distance between the fields, constructs a field dependency matrix, and obtains a field dependency mapping result.
[0009] As a further solution of the present invention, the anomaly detection module includes: The field matching sub-module analyzes the arrangement stability of the normal traffic fields based on the field dependency mapping result, extracts the field order characteristics in the normal traffic mode, compares the field arrangement method of the current network traffic data packet, and uses the formula: ; Calculate the field matching error , determine whether the field arrangement conforms to the normal traffic mode, and obtain the field matching error value, where represents the th field position in the current data packet field sequence, represents the expected position of the th field in the normal traffic mode, represents the relative distance between the fields involved in the field matching process, represents the actual number of fields participating in the matching in the data packet, represents the number of times of relative position comparison of the fields involved in the data packet; The deviation screening sub-module filters the data packets with field order deviations exceeding the deviation threshold based on the field matching error value, calculates the proportion of fields exceeding the deviation threshold, determines whether there are field arrangement anomalies in the data packet, and obtains the field arrangement anomaly ratio data; The integrity judgment sub-module determines the integrity of the network traffic data packet structure based on the field arrangement abnormal ratio data, combines the field value relationship, filters the data packets with abnormal structures, and obtains the field sequence offset analysis result.
[0010] As a further solution of the present invention, the traffic traceability module includes: The field mutation calculation sub-module extracts the timestamp, packet sequence number, and flag field of the abnormal network traffic data packet based on the field sequence offset analysis result, calculates the field mutation range and time interval, summarizes the time distribution characteristics of the abnormal data packets, and obtains the field mutation time characteristics; The mutation trend analysis sub-module analyzes the field change trend based on the field mutation time characteristics, compares the field value changes between abnormal data packets, analyzes the field similarity of the data packets, and uses the formula: ; Calculate the field mutation trend characteristics , filter the data packets with consistent field mutation trends, and obtain the field mutation trend matching result, where data packet , represents the field value deviation between data packets, represents the time interval between data packets, represents the number of data packets, represents the number of times of calculating the field deviation of data packets, represents the number of times of calculating the time interval of data packets; The traceability path analysis sub-module filters the IP address, port, and path of the abnormal network traffic data packet based on the field mutation trend matching result, constructs the traceability path relationship of the data packet, and establishes the mutation path correlation analysis record.
[0011] As a further solution of the present invention, the abnormal screening module includes: The source IP analysis sub-module extracts the historical records of the source traffic based on the mutation path correlation analysis record, calculates the distribution frequency of the source IP in the abnormal data packets, summarizes the abnormal occurrence ratio of the source IP, and obtains the abnormal source IP occupancy ratio data; The traffic continuity calculation sub-module analyzes the time distribution pattern of the abnormal data packets based on the abnormal source IP occupancy ratio data, calculates the continuity and source IP overlap degree of the abnormal network traffic data packets, and uses the formula: ; Calculate the traffic time distribution continuity coefficient , filter the data packets with abnormal source IP overlap degree within the time window, and obtain the abnormal traffic continuity coefficient, where represents the The timestamp of an abnormal data packet, represents the timestamp of the previous data packet, represents the number of abnormal data packets within the time window, represents the distribution frequency of the source IP in the abnormal data packets, represents the proportion of normal traffic of the source IP, represents the total number of abnormal data packets, represents the total number of source IPs; The abnormal trend matching sub-module analyzes the matching situation between the field variation amplitude of the data packet and the time window based on the abnormal traffic continuity coefficient, determines whether the source traffic belongs to continuous abnormal traffic, calculates the proportion of abnormal data packets, and obtains the proportion data of continuous abnormal traffic.
[0012] As a further solution of the present invention, the system further includes a risk assessment module; The risk assessment module calculates the distribution of abnormal data packets in different network nodes according to the proportion data of continuous abnormal traffic, determines the influence range of the abnormal data packets, evaluates the harm degree of the abnormal traffic, and issues an abnormal traffic threat message; The abnormal traffic threat message includes the network node distribution record of abnormal data packets, the influence range of abnormal traffic, and the harm degree of abnormal traffic.
[0013] As a further solution of the present invention, the risk assessment module includes: The abnormal traffic distribution sub-module calculates the distribution of abnormal data packets in different network nodes based on the proportion data of continuous abnormal traffic, counts the number and proportion of abnormal data packets in each node, and summarizes the concentrated area of abnormal data to obtain the abnormal traffic node distribution record; The abnormal influence range assessment sub-module determines the influence range of the abnormal data packets based on the abnormal traffic node distribution record, analyzes the distribution trend of the abnormal data packets on each network path, and evaluates the diffusion degree of the abnormal traffic to obtain the abnormal traffic influence index; The threat level determination sub-module evaluates the harm degree of the abnormal traffic based on the abnormal traffic influence index, calculates the threat level distribution situation, screens the risk traffic nodes, and generates an abnormal traffic threat message.
[0014] Compared with the prior art, the advantages and positive effects of the present invention are as follows: In the present invention, by analyzing the network traffic data packet structure, extracting the field names, field values and field order, and calculating the field dependence relationship, an association model of field arrangement and value can be constructed to evaluate the stability of traffic data from a global perspective, avoid misjudgment caused by relying on a single data packet. Based on the deviation analysis of field matching degree and arrangement method, abnormal traffic and normal traffic patterns can be effectively distinguished, the sensitivity to subtle anomalies can be improved, and the limitations brought by static rule matching can be reduced. The calculation of field mutation range, time interval and trend similarity ensures that the data packet traceability can be comprehensively judged in combination with multiple dimensions, improves the accuracy of tracking, and enhances the recognition ability of mutation patterns. The analysis of the distribution frequency and overlap degree of the source IP, combined with the mutation amplitude and time series information of the data packet, can clarify the persistence characteristics of traffic anomalies, expand the security monitoring from single data point analysis to behavior trend analysis. The comprehensive evaluation of the influence range of abnormal traffic, network node distribution and harm degree can provide a quantitative basis for risk warning, enhance the pertinence of security policies, make the response measures more in line with the actual situation of threats, and improve the accuracy and timeliness of overall security monitoring. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 is the system flow chart of the present invention; Figure 2 is the flow chart of the traffic analysis module of the present invention; Figure 3 is the flow chart of the abnormal detection module of the present invention; Figure 4 is the flow chart of the traffic traceability module of the present invention; Figure 5 is the flow chart of the abnormal screening module of the present invention; Figure 6 is the flow chart of the risk assessment module of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0016] In order to make the objectives, technical solutions and advantages of the present invention more clear and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0017] In the description of the present invention, it should be understood that the orientation or positional relationship indicated by the terms "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation to the present invention. In addition, in the description of the present invention, the meaning of "a plurality of" is two or more, unless otherwise specifically defined.
[0018] Please refer to Figure 1 , a network security monitoring system includes: The traffic analysis module acquires network traffic data packets, analyzes the structure of the network traffic data packets, extracts the field names, field values and field orders in the network traffic data packets, judges the dependency relationship between fields, calculates the arrangement rules of fields, establishes a field dependency matrix, and obtains a field dependency mapping result; The anomaly detection module, based on the field dependency mapping result, analyzes the arrangement stability of normal traffic fields, compares the field arrangement method of the current network traffic data packet, calculates the field matching degree, judges whether the field arrangement conforms to the normal traffic pattern, filters out the data packets whose field order deviation exceeds the deviation threshold, and combines the field value relationship to judge the integrity of the network traffic data packet structure, and obtains a field sequence offset analysis result; The traffic tracing module, based on the field sequence offset analysis result, extracts the timestamp, packet sequence number and flag field of the abnormal network traffic data packet, calculates the field variation range and time interval, analyzes the field change trend and calculates the similarity, filters out the data packets with the same field variation trend, traces the IP address, port and path of the abnormal network traffic data packet, and obtains a mutation path correlation analysis record; The anomaly screening module, according to the mutation path correlation analysis record, calculates the distribution frequency of the source IP in the abnormal data packets for the historical records of the source traffic, analyzes the time distribution pattern of the abnormal data packets, calculates the continuity of the abnormal network traffic data packets and the source IP overlap degree, analyzes the matching situation between the field mutation amplitude of the data packets and the time window, and judges whether the source traffic belongs to continuous abnormal traffic, and obtains the proportion data of continuous abnormal traffic; The risk assessment module, according to the proportion data of continuous abnormal traffic, calculates the distribution of abnormal data packets in different network nodes, determines the influence range of the abnormal data packets, evaluates the harm degree of the abnormal traffic, and issues an abnormal traffic threat message.
[0019] The field dependency mapping results include field name dependency relationships, field order dependency relationships, and field value dependency relationships. The field sequence offset analysis results include field matching degrees, field arrangement deviation values, and field value integrity records. The mutation path association analysis records include abnormal data packet timestamps, packet sequence numbers, field mutation ranges, mutation trend similarities, abnormal data packet IP addresses and ports. The continuous abnormal traffic proportion data includes abnormal data packet distribution frequencies, abnormal data packet time distribution patterns, abnormal traffic continuity analysis results, source IP overlap degrees, and field mutation amplitude matching conditions. The abnormal traffic threat information includes abnormal data packet network node distribution records, abnormal traffic influence ranges, and abnormal traffic hazard levels.
[0020] Please refer to Figure 2 , the traffic analysis module includes: The data packet acquisition sub-module acquires network traffic data packets, extracts basic field information such as protocol type, source IP address, destination IP address, source port, destination port, and data length therein, identifies the validity of the data packets, filters out abnormal and damaged data packets, and obtains valid network traffic data packets; The network traffic data packets are acquired from the traffic mirroring port of a switch or a router. The transmission data is monitored through a data packet capture tool to identify the basic fields of the TCP / IP protocol, including source IP address, destination IP address, source port, destination port, protocol type, data length, etc. The extracted data is stored in the original data stream buffer and sorted according to the timestamp to ensure the correct data order. The extracted data packets need to be subjected to validity checks to detect whether there is data loss, data packet truncation, or CRC check errors. For lost or damaged data packets, data repair is performed through a traffic recombination algorithm. The repair rule is to splice the data packets based on the TCP sequence number. After the header information verification of the data packet is completed, the length checksum of the data packet is calculated and compared with the length field in the header field. If the verification does not match, the data packet is marked as a damaged packet and excluded. Suppose the total number of data packets captured within 1 minute is 100,000, the number of valid data packets is 95,800, and the number of invalid or lost data packets is 4,200, among which 2,000 data packets can be repaired through sequence number recombination, and finally valid network traffic data packets are obtained.
[0021] The field parsing sub-module, based on the valid network traffic data packets, parses the data packet structure, extracts the field name, field value, and field order, analyzes the distribution characteristics of the fields, calculates the field occurrence frequency and proportion, establishes the corresponding relationship between the fields and the protocol type, and uses the formula: ; Calculate the field distribution coefficient , filter the field frequency characteristics, and generate the field distribution mapping result, where represents the a field value, representing the field mean, representing the field standard deviation, representing the protocol weight of the field, representing the field occurrence frequency, indicating the total number of values of the field in the data packet, indicating the total number of all field categories; Based on valid network traffic data packets, first parse the header fields of the data packets, including basic fields such as protocol type, IP address, port number, data length, etc., extract application layer fields from the data packet payload part, such as User-Agent field, Cookie field, and Referer field in HTTP requests, count the extracted fields, calculate the occurrence times and their proportions of each field in all data packets. Assume that in the sample data packets, the proportion of HTTP protocol is 55%, the proportion of TCP protocol is 35%, and the proportion of UDP protocol is 10%. When calculating the field occurrence frequency and its proportion, use formulas for calculation.
[0022] Among them, represents the th field value, such as the specific value of User-Agent, is the mean of all possible values of this field, is the standard deviation of the field, represents the protocol weight of the field. For example, the weight of the HTTP field is set to 0.55, represents the occurrence frequency of this field. For example, the occurrence frequency of the User-Agent field in HTTP traffic is 80%. Assume that the standard deviation of the User-Agent field is 5 and the mean is 50, then the distribution coefficient of this field is calculated as follows: ; The calculation results show that the distribution coefficient of the User-Agent field is 2.44. The larger this value is, the greater the volatility of the values of this field. The product of the protocol weight and the field frequency represents the importance of this field in a specific protocol. If this value is high, this field is more representative in the protocol traffic. For example, in HTTP traffic, the occurrence frequency of the Referer field is relatively low, perhaps only 20%, and its corresponding distribution coefficient may only be 1.2. However, the distribution coefficient of the User-Agent field is relatively high, indicating that the values of this field in different data packets vary significantly, and its presence degree in HTTP traffic is relatively high. Therefore, during the field parsing process, it is necessary to further classify and summarize the fields with high distribution coefficients to improve the accuracy of field matching in the subsequent dependency analysis process. After calculating the distribution coefficients of all fields, sort them according to their values, screen out the keyword fields that appear frequently, and establish the field-protocol correspondence relationship, and finally generate the field distribution mapping result.
[0023] Based on the field distribution mapping, the dependency analysis sub-module determines the dependency relationship between fields, analyzes the sequence of fields, calculates the relative position distance between fields, constructs a field dependency matrix, and obtains the field dependency mapping result. Based on the field distribution mapping result, determine the dependency relationship between each field, and count the degree of association between fields. For example, the Referer field in an HTTP request depends on the User-Agent field, and there is a corresponding relationship between the source port and the destination port of a TCP data packet. Quantify the dependency by calculating the correlation coefficient between fields. Set the threshold to 0.7. The basis for setting this value is the correlation measure of common protocol fields in actual network data traffic. Statistically analyze the Pearson correlation coefficient between field pairs in a large number of network traffic samples and find that low-dependency relationships (0.3 - 0.5) between most fields are relatively common, while for highly dependent field pairs, such as the correlation coefficient between the TCP source port and the destination port is usually close to 0.9, and the correlation coefficient between the Referer and User-Agent fields is usually between 0.65 and 0.75. To ensure that the selected field pairs have strong correlations and avoid information redundancy caused by misjudgment, select 0.7 as the determination threshold for high dependencies. If the field correlation coefficient is greater than 0.7, it is determined as a highly dependent field pair. Calculate the relative position distance between fields, and establish a field dependency matrix based on the field appearance order. The rows and columns of the matrix represent each field respectively, and the matrix element value represents the correlation coefficient between two fields. Suppose there are 4 fields a, b, c, d, and its field dependency matrix is as follows: Table 1.1 Field Dependency Matrix Field a b c d a 1.0 0.8 0.3 0.5 b 0.8 1.0 0.2 0.7 c 0.3 0.2 1.0 0.4 d 0.5 0.7 0.4 1.0 As shown in Table 1.1, the dependence between field a and field b is the highest (0.8), and the dependence between field b and field d is also relatively high (0.7). This indicates that there is a strong linear relationship between the values of field a and field b, while the dependence between field b and field d just reaches the set threshold of 0.7. If a lower threshold (such as 0.6) is used, it may lead to too many irrelevant field pairs being marked as highly dependent fields. If the set threshold is too high (such as 0.8), some important field pairs may not be recognized. Therefore, the selection of 0.7 can ensure the reasonable screening of dependent field pairs. High-dependent field pairs are screened based on the matrix to form a field association network, and finally a field dependence mapping result is obtained.
[0024] Please refer to Figure 3 , the anomaly detection module includes: Based on the field dependence mapping result, the field matching sub-module analyzes the arrangement stability of normal traffic fields, extracts the field order characteristics in the normal traffic pattern, compares the field arrangement of the current network traffic packet, and uses the formula: ; Calculate the field matching error , determine whether the field arrangement conforms to the normal traffic pattern, and obtain the field matching error value. Among them, represents the th field position in the current data packet field sequence, represents the expected position of the th field in the normal traffic pattern, represents the relative distance between fields involved in the field matching process, represents the actual number of fields participating in the matching in the data packet, represents the number of times of comparing the relative positions of fields involved in the data packet; Based on the field dependence mapping result, extract the field order characteristics in the normal traffic pattern, construct a field arrangement reference table, classify and quantify the field arrangement structures of data packets under different traffic types, obtain the typical field order in the normal traffic pattern, and convert the field arrangement into a numerical sequence. For example, assume that the typical field sequence in the normal traffic pattern is {a, b, c, d, e}, where a represents the source IP address, b represents the destination IP address, c represents the source port, d represents the destination port, and e represents the protocol type, then it can be mapped to {1, 2, 3, 4, 5}. Then obtain the field arrangement of the current network traffic packet. For example, the actual field sequence of a certain data packet is {a, c, b, e, d}, which can be mapped to {1, 3, 2, 5, 4}. Then use the formula for calculation. Taking the current data packet {1, 3, 2, 5, 4} and the normal mode {1, 2, 3, 4, 5} as an example, calculate: ; ; The threshold is set as follows: Packets in normal network traffic usually have a stable field arrangement pattern. Therefore, in different network environments, traffic packet samples are collected over multiple time periods, and the field matching errors of all samples are calculated , and their mean value is statistically calculated and standard deviation . The abnormal determination threshold is set as: ; Suppose the statistical results are , , then: ; Therefore, the field matching error threshold is set to 1.5. If the field matching error exceeds 1.5, the field arrangement of the packet is abnormal. If , the packet conforms to the normal traffic pattern, and finally the field matching error value is obtained.
[0025] Based on the field matching error value, the deviation screening sub-module screens the packets whose field order deviation exceeds the deviation threshold, calculates the proportion of fields exceeding the deviation threshold, and determines whether there is an abnormal field arrangement in the packet to obtain the field arrangement abnormal ratio data; Based on the field matching error value, the packets whose field order deviation exceeds the deviation threshold are screened, and the proportion of fields exceeding the deviation threshold is calculated. For example, during a traffic detection process, among 1000 packets, 150 packets have a field matching error exceeding 1.5, then the proportion of abnormal packets is calculated as: ; The threshold is set as follows: To determine the reasonable range of abnormal packets in normal network traffic, the data traffic in multiple time periods is statistically calculated, and the proportion of abnormal packets in all traffic detection cycles is calculated , and their mean value is statistically calculated and standard deviation . The abnormal determination threshold is set as: ; Suppose the statistical results are , , then: ; Therefore, the abnormal packet proportion threshold is set to 10%. When the deviation rate exceeds 10%, it is determined that the proportion of abnormal packets in the current traffic is relatively high, otherwise it is determined as normal traffic, and finally the field arrangement abnormal ratio data is obtained.
[0026] Based on the field arrangement anomaly ratio data and combined with the field value relationship, the integrity judgment sub-module determines the integrity of the network traffic packet structure, filters out the packets with abnormal structures, and obtains the field sequence offset analysis result; Based on the field arrangement anomaly ratio and combined with the field value relationship, determine the integrity of the network traffic packet structure, analyze the logical relationship between field values. For example, if the source IP address of a packet is the same as the destination IP address, it may be an abnormal packet, or the protocol type does not match the port number. For example, the HTTP protocol usually corresponds to port 80, and the protocol type identifier of the current packet is HTTP, but the port number is 23 (Telnet port), then there may be a problem with the packet structure. Filter out the packets with abnormal structures, and finally obtain the field sequence offset analysis result.
[0027] Please refer to Figure 4 , the traffic tracing module includes: Based on the field sequence offset analysis result, the field mutation calculation sub-module extracts the timestamp, packet sequence number, and flag field of abnormal network traffic packets, calculates the field mutation range and time interval, and summarizes the time distribution characteristics of abnormal packets to obtain the field mutation time characteristics; Based on the field sequence offset analysis result, extract the timestamp, packet sequence number, and flag field of abnormal network traffic packets. During the extraction process, first identify the timestamp of the packet. The timestamp represents the time point when the packet is captured in the network. For example, the timestamp of a certain packet is 2024-03-11 10:15:30.125. Then parse the packet sequence number. The packet sequence number is used to identify the order of packets. Assume the packet sequence numbers are 1001, 1002, and 1003 respectively. Then extract the flag field. The flag field is used to indicate the control information of the packet, such as SYN, ACK, FIN, etc. A certain packet may have a flag field of SYN=1 and ACK=0. Subsequently, calculate the field mutation range and time interval. The field mutation range is the difference degree between the field values of each packet. For example, the mutation range of the packet sequence number can be obtained by calculating the difference between the maximum value and the minimum value. For the above packet sequence number data, the mutation range is 1003 - 1001 = 2. The time interval calculation method is the difference between the timestamps of adjacent packets. For example, the timestamps of adjacent packets are 2024-03-11 10:15:30.125 and 2024-03-11 10:15:30.250 respectively, and the time interval is calculated as 0.250 - 0.125 = 0.125 seconds. Summarize the time distribution characteristics of abnormal packets. By statistically calculating the mean and variance of the time intervals of multiple abnormal packets, judge the time pattern of packet appearance, as shown in Table 3.1.
[0028] Table 3.1 Statistical table of time characteristics of abnormal packets
[0029] As shown in Table 3.1, there are differences in the data packet time intervals. By calculating the mean and variance, it can be obtained that the mean of the time intervals is (0.125 + 0.250) / 2 = 0.1875 seconds, and the variance is calculated as ((0.125 - 0.1875)^2 + (0.250 - 0.1875)^2) / 2 = 0.0078, obtaining the field mutation time characteristics.
[0030] Based on the field mutation time characteristics, the mutation trend analysis sub-module analyzes the field change trend, compares the field value changes between abnormal data packets, analyzes the similarity of the data packet fields, and uses the formula: ; Calculate the field mutation trend characteristics , filter the data packets with consistent field mutation trends to obtain the field mutation trend matching results, where, data packet , represents the field value deviation between data packets, represents the time interval between data packets, represents the number of data packets, represents the number of times of calculating the data packet field deviation, represents the number of times of calculating the data packet time interval; Based on the field mutation time characteristics, analyze the field change trend. First, compare the field value changes between abnormal data packets. For example, for data packet sequence numbers 1001, 1002, and 1003, the change trend of their flag fields can be expressed as {(SYN, ACK, FIN): (1, 0, 0) → (0, 1, 0) → (1, 1, 0)}, and then calculate using the formula. Assume that the data packet field values V are {1, 0, 0}, {0, 1, 0}, {1, 1, 0}, and the mean value calculation is: ; Field deviation calculation: ; The time intervals are 0.125 and 0.250, and calculate the sum of the time factors: ; Substitute into the formula: ; ; This result shows that the field mutation trend matching value is . The closer this value is to 1, the more similar the field change trends of the data packets are. On the contrary, it indicates that there are obvious differences in the mutation patterns. In this example, It indicates that the field mutation trends of these data packets are highly consistent, suggesting that they may belong to the same attack behavior or abnormal traffic pattern. Therefore, during subsequent traceback processes, these data packets may be attributed to the same attack path or the same source.
[0031] Based on the field mutation trend matching results, the traceback path parsing sub-module filters the IP addresses, ports, and paths of abnormal network traffic data packets, constructs the traceback path relationship of the data packets, and establishes the mutation path correlation analysis record; Based on the field mutation trend matching results, filter the IP addresses, ports, and paths of abnormal network traffic data packets. Assume that the source IP address of an abnormal data packet is 192.168.1.10, the destination IP address is 10.0.0.5, the source port is 443, the destination port is 8080, and the data packet path is a → b → c → d. Construct the traceback path relationship of the data packet as shown in Table 3.2.
[0032] Table 3.2 Abnormal Data Packet Traceback Path Table
[0033] As shown in Table 3.2, the data packets are transmitted through different paths. The traceback path is analyzed by comparing the IP addresses, ports, and relay node information. Assume that during the traceback process, it is found that data packets 1001 and 1002 have two common relay nodes c and d. Then it can be inferred that this path may belong to the same attack source, and thus the mutation path correlation analysis record is established.
[0034] Please refer to Figure 5 , the abnormal screening module includes: Based on the mutation path correlation analysis record, the source IP analysis sub-module extracts the historical records of the source traffic, calculates the distribution frequency of the source IP in the abnormal data packets, summarizes the abnormal occurrence ratio of the source IP, and obtains the data of the abnormal source IP ratio; Based on the mutation path correlation analysis record, extract the historical records of the source traffic, obtain the source IP addresses involved in abnormal data packets in the past period of time, count the number of abnormal data packets corresponding to each source IP, calculate its distribution frequency in the overall abnormal data packets. Assume that the total number of abnormal data packets captured in a certain period is 5000, and the total number of source IPs involved is 2000. The number of abnormal data packets corresponding to each source IP is different. Some source IPs have a relatively large number of abnormal data packets. For example, the number of abnormal data packets associated with a certain source IPa reaches 500, accounting for 10%, and another source IPb is only associated with 10 abnormal data packets, accounting for 0.2%. For these data, construct the source IP abnormal frequency distribution table, and filter out the high-frequency source IPs with an abnormal ratio exceeding 5% as shown in Table 4.1.
[0035] Table 4.1 Source IP Abnormal Distribution Table Source IP Number of Associated Abnormal Data Packets Percentage (%) IPa 500 10 IPb 10 0.2 IPc 250 5 IPd 100 2 ... ... ... As shown in Table 4.1, by counting the distribution of abnormal data packets from different source IPs, it can be found that the proportion of abnormal data packets of some IP addresses far exceeds that of other IPs. Subsequently, a threshold for the abnormal proportion of the source IP is set. Assuming the set threshold is 5%, the high-frequency abnormal source IPs a and IPc are screened out, and finally the proportion of abnormal source IPs is obtained.
[0036] The basis for setting this threshold is as follows: The threshold for the abnormal proportion of the source IP is used to distinguish high-frequency abnormal source IPs from randomly occurring abnormal source IPs. Generally, there are two modes of abnormal behavior of the source IP, discrete distribution and concentrated distribution. To set a reasonable threshold, first, count the abnormal distribution frequency of the source IP in the normal traffic environment. Assume that 50,000 data packets are extracted from the normal network traffic, among which 2,000 are abnormal data packets, accounting for 4%. Calculate its mean and standard deviation: ; ; Assuming that the abnormal proportion of the normal source IP follows a normal distribution, the threshold for the abnormal proportion of the source IP in the 95% confidence interval can be calculated as follows: ; To ensure a sufficient range for screening abnormal IPs, this value is set to 5%, that is: ; This threshold fluctuates with the abnormal occurrence frequency of the source IP, the total traffic base, and the proportion of abnormal data packets. If the overall traffic increases, this value will approach 6%. If the proportion of abnormal data packets decreases, this value will drop to around 4%. In the current calculation, the source IP a has a significant abnormal proportion of 10% higher than 5%, so it is determined as a high-frequency abnormal source IP. The source IP c has a proportion of 5% at the screening boundary and is still included in the high-frequency abnormal source IP. Finally, the proportion of abnormal source IPs is obtained.
[0037] Based on the data of the proportion of abnormal source IPs, the traffic continuity calculation sub-module analyzes the time distribution pattern of abnormal data packets, calculates the continuity of abnormal network traffic data packets and the overlap degree of source IPs, and uses the formula: ; Calculate the traffic time distribution continuity coefficient , screen the data packets with abnormal source IP overlap degree within the time window, and obtain the abnormal traffic continuity coefficient. Among them, represents the timestamp of the th abnormal data packet, represents the timestamp of the previous data packet, Represents the number of abnormal data packets within the time window, Represents the distribution frequency of the source IP in the abnormal data packets, Represents the proportion of normal traffic of the source IP, Represents the total number of abnormal data packets, Represents the total number of source IPs; Based on the proportion data of abnormal source IPs, analyze the time distribution pattern of abnormal data packets, extract the data packets of high-frequency abnormal source IPs, calculate the continuity of abnormal data packets, and count the overlap degree of source IPs. Assume that within the past 24 hours, the number of abnormal data packets per hour is as follows: ; ; Use the formula to calculate the time continuity of abnormal data packets.
[0038] Assume the total amount of abnormal data packets within the time window , the abnormal distribution of the source IP , the proportion of source IPs with normal traffic , substitute into the calculation: ; ; After calculation, it is obtained that , this value represents the time continuity coefficient of abnormal data packets, which is higher than the set threshold of 2.5. Therefore, it can be determined that there is a strong time continuity of abnormal data packets, and the abnormal traffic continuity coefficient is obtained.
[0039] Abnormal traffic continuity coefficient Reflects whether the time distribution of abnormal data packets shows continuous fluctuations. If this value is low (close to 1), it means that the distribution of abnormal data packets is relatively discrete. If this value is high (exceeding 3), it means that abnormal data packets are highly aggregated in the time dimension. To reasonably set the threshold, first calculate the fluctuation range of the time distribution of normal traffic. Assume that 1000 groups of data are extracted from the normal data packet distribution and calculate its The mean value is 1.8 and the standard deviation is 0.4. Therefore, the normal traffic threshold within the 95% confidence interval can be set as: ; To ensure that abnormal data packets can be effectively distinguished, the abnormal threshold is set at 2.5, that is: ; This threshold fluctuates with the distribution frequency of abnormal data packets and the length of the time window. If the number of abnormal data packets is large within a short time, this value will be higher. If the abnormal distribution of data packets is relatively uniform, this value will be close to 2.5. In the current calculation, the abnormal traffic continuity coefficient Significantly exceeding 2.5 indicates that the abnormal traffic shows a high-density distribution, further verifying the continuous abnormal characteristics of the traffic.
[0040] The abnormal trend matching sub-module analyzes the variation range of the packet fields and the matching situation within the time window based on the abnormal traffic continuity coefficient, determines whether the source traffic belongs to continuous abnormal traffic, calculates the proportion of abnormal packets, and obtains the proportion data of continuous abnormal traffic; Based on the abnormal traffic continuity coefficient, analyze the variation range of the packet fields and the matching situation within the time window, filter out the packets whose abnormal traffic continuity coefficient exceeds the set threshold, and calculate the change trend of the source IP in these packets. Assume the number of abnormal packets of source IPa within 24 hours is as follows: ; ; Calculate the variation trend of source IPa in different time windows ( ), compare it with the time distribution trend of global abnormal packets, and calculate the similarity using the Pearson correlation coefficient: ; Assume , , after calculation, it is obtained that , indicating that the packet variation trend of source IPA is highly similar to the time distribution trend of global abnormal packets, determining that the source traffic belongs to continuous abnormal traffic, and finally calculating the proportion data of continuous abnormal traffic.
[0041] Please refer to Figure 6 , the risk assessment module includes: The abnormal traffic distribution sub-module calculates the distribution of abnormal packets in different network nodes based on the proportion data of continuous abnormal traffic, counts the number and proportion of abnormal packets in each node, and summarizes the concentrated areas of abnormal data to obtain the abnormal traffic node distribution record; Based on the proportion data of continuous abnormal traffic, it is necessary to calculate the abnormal packets of different network nodes to understand the distribution of abnormal traffic in the network structure. First, obtain the traffic log data of each network node, and extract the identification information of abnormal packets from it, such as source IP address, destination IP address, port number, and timestamp. Classify these data according to the network topology structure. Subsequently, count the number of abnormal packets in each node and calculate the proportion of abnormal packets in the node traffic. For example, if the total traffic of a certain node within the sampling time is 50,000 packets and the number of abnormal packets is 500, then the calculation of the abnormal traffic proportion of this node is as follows: ; Next, compare the abnormal traffic ratios of different nodes to determine the concentrated areas of abnormal traffic. If the abnormal traffic ratio of a certain node is much higher than the network average level (for example, the average value is 2%, and a certain node is as high as 10%), then mark this node as a high-incidence area of abnormal traffic. In this way, potential hotspots of abnormal traffic can be screened out, and the distribution of abnormal traffic nodes can be obtained.
[0042] The abnormal impact range assessment sub-module determines the impact range of abnormal packets based on the abnormal traffic node distribution record, analyzes the distribution trend of abnormal packets on each network path, evaluates the diffusion degree of abnormal traffic, and obtains the abnormal traffic impact index; Based on the abnormal traffic node distribution record, it is necessary to further analyze the propagation range of abnormal packets to evaluate the impact degree of abnormal traffic. First, sort the abnormal traffic nodes according to the network topology relationship to determine the flow path of the packets. For example, in a certain enterprise network, the abnormal traffic may first pass through the router, then through the switch, and finally reach the terminal device. Monitor the data flow on each path and calculate the ratio of abnormal packets on the path. For example, if the number of normal packets on a certain path is 80,000 and the number of abnormal packets is 2,000, then the abnormal ratio of this path is calculated as follows: ; After obtaining the abnormal ratios of all paths, screen out the paths where the abnormal data flow is relatively concentrated, and determine whether these paths are connected to key network nodes such as servers and gateways. If the ratios of abnormal traffic on multiple key paths all exceed 5% (this 5% threshold is set based on the statistical analysis of the network basic traffic load and the normal traffic fluctuation range. Generally, in an enterprise-level network, the normal traffic fluctuation range on key paths is within ±3%. When the abnormal traffic ratio reaches 5%, it means that the abnormal traffic has exceeded the upper limit of the normal fluctuation and is very likely to affect the normal service ability of the network. Specifically, this value will fluctuate with the change of the network basic load. For example, for a path with a daily average data traffic of 5 million packets, this value may be appropriately relaxed to 6%-7%, and for a data path with a daily average data traffic of less than 500,000, this value can be set to 4% to ensure the adaptability of the judgment criteria in different network environments. In addition, it is found in the attack simulation experiment that when the ratio of abnormal traffic in the key path exceeds 5%, the network packet loss rate begins to increase significantly, and the average server response time increases by more than 30%. Therefore, 5% is used as the basic risk threshold in this type of network environment, and this value can be adjusted according to the network service requirements and security policies to adapt to different scales and security levels of network environments). Finally, combine the abnormal traffic ratio data of these paths to calculate the diffusion index of the overall abnormal traffic to reflect the propagation trend of abnormal packets in the network and obtain the abnormal traffic impact index.
[0043] The threat level determination sub-module evaluates the harm degree of abnormal traffic based on the abnormal traffic impact index, calculates the threat level distribution, filters the risk traffic nodes, and generates abnormal traffic threat information; Based on the abnormal traffic impact index, it is necessary to further analyze the harm degree of abnormal traffic and determine the threat level of abnormal traffic. First, compare the diffusion index of abnormal traffic with a preset security threshold. For example, in a certain network security policy, when the diffusion index of abnormal traffic exceeds 3%, the security monitoring level needs to be improved. If the calculated diffusion index is 4.2%, then the network status is marked as a medium risk level. Next, analyze the source and type of abnormal traffic. If the abnormal traffic mainly comes from a specific IP segment and the data packet structure conforms to known attack behavior patterns (such as SYN Flood attack or DDoS attack), then the risk level needs to be increased. In addition, it is also necessary to calculate the distribution of abnormal traffic in different time periods. If the abnormal traffic continuously exceeds 10% of the normal traffic within a certain time window, then the threat level is further increased. Finally, comprehensively score all the analysis results to determine the final threat level of abnormal traffic, such as low risk (0%-2%), medium risk (2%-5%), high risk (>5%), and send out abnormal traffic threat information.
[0044] The above is only a preferred embodiment of the present invention, and it does not limit the present invention in other forms. Any person skilled in the art may use the technical content disclosed above to make changes or modifications into equivalent embodiments with equivalent changes and apply them to other fields. However, as long as it does not depart from the technical solution content of the present invention, any simple modification, equivalent change, and modification made to the above embodiments based on the technical essence of the present invention still fall within the protection scope of the technical solution of the present invention.
Claims
1. A network security monitoring system, characterized in that: The system comprises: The traffic analysis module obtains network traffic data packets, extracts field names, field values and field orders in network traffic data packets, determines the dependency relationship between fields, calculates the field arrangement rules, and obtains the field dependency mapping results; The anomaly detection module analyzes the arrangement stability of normal traffic fields based on the field dependency mapping results, compares the field arrangement of the current network traffic data packet, calculates the field matching degree, and determines the structural integrity of the network traffic data packet in combination with the field value relationship to obtain the field sequence offset analysis results; The traffic tracing module extracts the timestamp, packet sequence number and flag field of the abnormal network traffic data packet based on the field sequence offset analysis result, analyzes the field change trend, traces the IP address, port and path of the abnormal network traffic data packet, and obtains the variation path association analysis record; The anomaly screening module calculates the distribution frequency of the source IP in the abnormal data packet based on the variation path association analysis record, calculates the continuity of the abnormal network traffic data packet and the source IP overlap, analyzes the matching of the data packet field variation amplitude and the time window, determines whether the source traffic belongs to continuous abnormal traffic, and obtains the continuous abnormal traffic proportion data.
2. The network security monitoring system according to claim 1, characterized in that: The field dependency mapping results include field name dependency, field order dependency, and field value dependency; the field sequence offset analysis results include field matching, field arrangement deviation value, and field value integrity record; the variation path association analysis record includes abnormal data packet timestamp, packet sequence number, field variation range, variation trend similarity, abnormal data packet IP address and port; the continuous abnormal traffic proportion data includes abnormal data packet distribution frequency, abnormal data packet time distribution pattern, abnormal traffic continuity analysis results, source IP overlap, and field variation amplitude matching.
3. The network security monitoring system according to claim 1, characterized in that: The traffic analysis module includes: The data packet acquisition submodule acquires network traffic data packets, extracts the protocol type, source IP address, destination IP address, source port, destination port, data length basic field information, identifies the validity of the data packets, filters out abnormal and damaged data packets, and obtains valid network traffic data packets; The field parsing submodule parses the data packet structure based on the valid network traffic data packet, extracts the field name, field value and field order, analyzes the distribution characteristics of the field, calculates the frequency and proportion of the field, and establishes the corresponding relationship between the field and the protocol type, using the formula: ; Calculate the field distribution coefficient , filter the field frequency characteristics and generate the field distribution mapping results, where: Representative field values, Represents the field mean, Represents the field standard deviation, Represents the protocol weight to which the field belongs. Represents the frequency of occurrence of the field, Indicates the total number of values of the field in the data packet. Indicates the total number of all field categories; The dependency analysis submodule determines the dependency relationship between fields, analyzes the sequence between fields, calculates the relative position distance between fields, constructs a field dependency matrix, and obtains a field dependency mapping result based on the field distribution mapping result.
4. The network security monitoring system according to claim 1, characterized in that: The anomaly detection module comprises: The field matching submodule analyzes the arrangement stability of normal traffic fields based on the field dependency mapping results, extracts the field order characteristics under normal traffic mode, and compares the field arrangement of the current network traffic data packet using the formula: ; Calculate field matching error , determine whether the field arrangement conforms to the normal traffic pattern, and obtain the field matching error value, where, Represents the first field in the current packet sequence. field positions, In normal flow mode The expected position of the field, Represents the relative distance between fields involved in the field matching process. Represents the number of fields actually involved in the match in the data packet. Represents the number of times the relative positions of the fields involved in the data packet are compared; The deviation screening submodule screens data packets whose field sequence deviation exceeds the deviation threshold based on the field matching error value, calculates the field ratio exceeding the deviation threshold, determines whether there is field arrangement abnormality in the data packet, and obtains field arrangement abnormality ratio data; The integrity judgment submodule judges the integrity of the network traffic data packet structure based on the field arrangement abnormality ratio data and the field value relationship, screens data packets with abnormal structures, and obtains field sequence offset analysis results.
5. The network security monitoring system according to claim 1, characterized in that: The traffic tracing module includes: The field variation calculation submodule extracts the timestamp, packet sequence number and flag field of the abnormal network traffic data packet based on the field sequence offset analysis result, calculates the field variation range and time interval, summarizes the time distribution characteristics of the abnormal data packet, and obtains the field variation time characteristics; The variation trend analysis submodule analyzes the field variation trend based on the field variation time characteristics, compares the field value changes between abnormal data packets, and analyzes the data packet field similarity using the formula: ; Calculate field variation trend characteristics , filter the data packets with the same field variation trend, and obtain the field variation trend matching results, where, Represents the i-th Field value, Represents the field mean, Represents the field value deviation between data packets. Represents the time interval between data packets, Represents the number of packets, Represents the number of packet field deviation calculations, Represents the number of packet time interval calculations; The traceability path parsing submodule screens the IP addresses, ports and paths of abnormal network traffic data packets based on the field variation trend matching results, builds the traceability path relationship of the data packets, and establishes variation path association analysis records.
6. The network security monitoring system according to claim 1, characterized in that: The abnormal screening module includes: The source IP analysis submodule extracts the historical records of source traffic based on the variation path association analysis records, calculates the distribution frequency of source IP in abnormal data packets, summarizes the abnormal occurrence ratio of source IP, and obtains the abnormal source IP ratio data; The traffic continuity calculation submodule analyzes the time distribution pattern of abnormal data packets based on the abnormal source IP proportion data, calculates the continuity of abnormal network traffic data packets and the source IP overlap, using the formula: ; Calculate the continuity coefficient of flow time distribution , filter the packets with abnormal source IP overlap within the time window and obtain the abnormal traffic continuity coefficient, where, Representative The timestamp of the abnormal data packet, Represents the timestamp of the previous data packet, Represents the number of abnormal packets in the time window. Represents the distribution frequency of the source IP in the abnormal data packets. Represents the normal traffic ratio of the source IP. Represents the total number of abnormal packets. Represents the total number of source IPs; The abnormal trend matching submodule analyzes the field variation range of the data packet and the matching situation within the time window based on the abnormal traffic continuity coefficient, determines whether the source traffic belongs to continuous abnormal traffic, calculates the proportion of abnormal data packets, and obtains the continuous abnormal traffic proportion data.
7. The network security monitoring system according to claim 1, characterized in that: The system also includes a risk assessment module; The risk assessment module calculates the distribution of abnormal data packets in different network nodes according to the continuous abnormal traffic proportion data, determines the impact range of the abnormal data packets, assesses the degree of harm of the abnormal traffic, and issues abnormal traffic threat information; The abnormal traffic threat information includes abnormal data packet network node distribution records, abnormal traffic impact range, and abnormal traffic hazard degree.
8. The network security monitoring system according to claim 7, characterized in that: The risk assessment module includes: The abnormal traffic distribution submodule calculates the distribution of abnormal data packets in different network nodes based on the continuous abnormal traffic proportion data, counts the number and proportion of abnormal data packets in each node, summarizes the concentrated area of abnormal data, and obtains abnormal traffic node distribution records; The abnormal impact range assessment submodule determines the impact range of the abnormal data packet based on the abnormal traffic node distribution record, analyzes the distribution trend of the abnormal data packet on each network path, assesses the diffusion degree of the abnormal traffic, and obtains the abnormal traffic impact index; The threat level determination submodule evaluates the degree of harm of abnormal traffic based on the abnormal traffic impact index, calculates the threat level distribution, screens risky traffic nodes, and generates abnormal traffic threat information.
Citation Information
Patent Citations
Internet monitoring anti-spamming method and device
CN104050178A
Network information monitoring method and system based on machine learning
CN118523972A
Electronic information dynamic scheduling and management system and method
CN119676166A
Cited By
IP network transmission method for audio data
CN120675982A
Fault root cause positioning method and system based on automatic analysis
CN121037200A
A method and system for fault root cause localization based on automated analysis
CN121037200B
Data management system based on data quality evaluation
CN121233568A
Computer network data flow monitoring system and method
CN121509557A