A network security monitoring system
By extracting and analyzing the field dependencies and structural characteristics of network traffic data packets in the network security monitoring system, the problem of difficult to identify structural abnormal traffic in the prior art is solved, and fine-grained analysis of network traffic and accurate identification of abnormal traffic is realized, which improves the accuracy and timeliness of security monitoring.
Patent Information
- Application Number
- CN202510543650.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-28
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-04-28
AI Technical Summary
When detecting and analyzing network traffic, existing network security monitoring systems are difficult to adapt to complex network environments, and lack fine-grained analysis of the internal structure of data packets, resulting in some abnormal data not being accurately captured, and it is difficult to identify structural abnormal traffic, affecting the reliability of data packet integrity judgment.
The traffic analysis module extracts the field name, field value and field order in the network traffic data packet, judges the dependence relationship between fields, calculates the field arrangement rules, and obtains the field dependency mapping results. Then, the abnormality detection module analyzes the deviations in field matching and arrangement methods based on the field dependency mapping results, and judges the integrity of the network traffic packet structure. The traffic traceability module analyzes the field change trend and traces the IP address, port and path of abnormal network traffic packets. The exception filtering module calculates the distribution frequency and overlap of the source IP to determine whether the source traffic is a continuous abnormal traffic.
By analyzing the data packet structure in a fine-grained manner, we can improve the ability to identify abnormal traffic, reduce the limitations brought by static rule matching, enhance the ability to identify variant patterns, improve the accuracy of traffic traceability, clarify the persistence characteristics of traffic abnormalities, enhance the pertinence of security strategies, and improve the accuracy and timeliness of overall security monitoring.
Smart Images

Figure CN120074962B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security monitoring, and particularly to a network security monitoring system. Background Art
[0002] The technical field of network security monitoring includes technical methods for detecting, analyzing, and responding to security threats in computer networks. The core contents include network traffic analysis, intrusion detection, abnormal behavior recognition, and security event log management, etc. Network security monitoring technology identifies potential malicious activities by monitoring the data flow in real time and combines threat intelligence information for risk assessment. Overall, it covers static and dynamic detection methods, including rule-based matching analysis methods and detection strategies combined with feature learning. At the same time, it involves security assessment of network devices, communication protocols, access behaviors, etc. to ensure the stability and reliability of information systems.
[0003] Among them, a network security monitoring system refers to a technical solution for detecting, analyzing, and warning security risks in a computer network environment, covering technical matters such as network packet parsing, protocol layer review, abnormal behavior modeling and comparison, log information classification storage, and risk assessment. Its methods mainly include decoding and analyzing the collected network communication data, extracting data content from dimensions such as protocol characteristics and session behaviors, and performing comparison analysis based on preset strategies to identify potential security threats. In addition, the system classifies and archives the detected security events, constructs a threat situation awareness model by combining time series analysis methods, and generates security warning information using strategy matching methods to achieve continuous security monitoring of the network environment.
[0004] In the existing network security monitoring process, it mainly relies on static rule matching methods for traffic detection, resulting in difficulty in adapting to complex network environments when dealing with traffic anomalies, lacking fine-grained analysis of the internal structure of data packets, and easily ignoring the correlation between data fields, resulting in some abnormal data not being accurately captured. Since the abnormal screening fails to combine field arrangement characteristics and dependency relationships, the detection mechanism is difficult to effectively identify structurally abnormal traffic, affecting the reliability of packet integrity judgment. During the process of tracing the source of abnormal traffic, there is a lack of in-depth analysis of the mutation trend of data packets, resulting in the tracing of the traffic source being limited to the IP and port levels, and it is difficult to accurately locate the attack path. The source traffic analysis is usually based on a single abnormal event and fails to combine historical records to judge the trend of traffic patterns, affecting the ability to identify persistent anomalies and making it difficult to distinguish between some short-term anomalies and long-term attacks. In the risk assessment link, the determination method of the impact range of abnormal traffic is relatively static and difficult to dynamically adapt to the changing trend of threats, resulting in a lag in security policy responses and affecting the overall protection ability of the network environment. Summary of the Invention
[0005] The object of the present invention is to solve the disadvantages existing in the prior art, and a network security monitoring system is proposed.
[0006] To achieve the above object, the present invention adopts the following technical solution: A network security monitoring system includes:
[0007] The traffic analysis module obtains network traffic data packets, extracts the field names, field values and field orders in the network traffic data packets, judges the dependency relationship between fields, calculates the field arrangement rules, and obtains the field dependency mapping result;
[0008] The anomaly detection module analyzes the arrangement stability of normal traffic fields based on the field dependency mapping result, compares the field arrangement mode of the current network traffic data packet, calculates the field matching degree, and combines the field value relationship to judge the structural integrity of the network traffic data packet, and obtains the field sequence offset analysis result;
[0009] The traffic tracing module extracts the timestamp, packet sequence number and flag field of the abnormal network traffic data packet based on the field sequence offset analysis result, analyzes the field change trend, traces the IP address, port and path of the abnormal network traffic data packet, and obtains the mutant path correlation analysis record;
[0010] The anomaly screening module calculates the distribution frequency of the source IP in the abnormal data packets according to the mutant path correlation analysis record, calculates the continuity of the abnormal network traffic data packets and the source IP overlap degree, analyzes the matching situation between the field mutation amplitude and the time window, and judges whether the source traffic belongs to continuous abnormal traffic, and obtains the proportion data of continuous abnormal traffic.
[0011] As a further solution of the present invention, the field dependency mapping result includes field name dependency relationship, field order dependency relationship, field value dependency relationship, the field sequence offset analysis result includes field matching degree, field arrangement deviation value, field value integrity record, the mutant path correlation analysis record includes abnormal data packet timestamp, packet sequence number, field mutation range, mutation trend similarity, abnormal data packet IP address and port, and the proportion data of continuous abnormal traffic includes abnormal data packet distribution frequency, abnormal data packet time distribution mode, abnormal traffic continuity analysis result, source IP overlap degree, field mutation amplitude matching situation.
[0012] As a further solution of the present invention, the traffic analysis module includes:
[0013] The data packet acquisition sub-module obtains network traffic data packets, extracts basic field information such as protocol type, source IP address, destination IP address, source port, destination port, data length, etc. in them, identifies the validity of the data packets, and filters out abnormal and damaged data packets to obtain valid network traffic data packets;
[0014] The field parsing sub-module parses the data packet structure based on the valid network traffic data packet, extracts the field name, field value, and field order, analyzes the distribution characteristics of the fields, calculates the field occurrence frequency and proportion, establishes the correspondence between the fields and the protocol types, and uses the formula:
[0015] ;
[0016] Calculate the field distribution coefficient , filter the field frequency characteristics, and generate the field distribution mapping result, where represents the th field value, represents the field mean value, represents the field standard deviation, represents the protocol weight to which the field belongs, represents the field occurrence frequency, represents the total number of values of the fields in the data packet, represents the total number of all field categories;
[0017] The dependency analysis sub-module determines the dependency relationship between the fields based on the field distribution mapping result, analyzes the sequence order between the fields, calculates the relative position distance between the fields, constructs a field dependency matrix, and obtains a field dependency mapping result.
[0018] As a further solution of the present invention, the anomaly detection module includes:
[0019] The field matching sub-module analyzes the arrangement stability of the normal traffic fields based on the field dependency mapping result, extracts the field order characteristics in the normal traffic mode, compares the field arrangement method of the current network traffic data packet, and uses the formula:
[0020] ;
[0021] Calculate the field matching error , determine whether the field arrangement conforms to the normal traffic mode, and obtain the field matching error value, where represents the th field position in the current data packet field sequence, represents the expected position of the th field in the normal traffic mode, represents the relative distance between the fields involved in the field matching process, represents the actual number of fields participating in the matching in the data packet, represents the number of times of relative position comparison of the fields involved in the data packet;
[0022] The deviation screening sub-module filters the data packets with field order deviations exceeding the deviation threshold based on the field matching error value, calculates the proportion of fields exceeding the deviation threshold, determines whether there are abnormal field arrangements in the data packets, and obtains the field arrangement abnormal ratio data;
[0023] The integrity judgment sub-module determines the integrity of the network traffic data packet structure based on the field arrangement abnormal ratio data and combines the field value relationships, filters the data packets with abnormal structures, and obtains the field sequence offset analysis results.
[0024] As a further solution of the present invention, the traffic traceability module includes:
[0025] The field mutation calculation sub-module extracts the timestamps, packet sequence numbers, and flag fields of abnormal network traffic data packets based on the field sequence offset analysis results, calculates the field mutation range and time interval, summarizes the time distribution characteristics of abnormal data packets, and obtains the field mutation time characteristics;
[0026] The mutation trend analysis sub-module analyzes the field change trend based on the field mutation time characteristics, compares the field value changes between abnormal data packets, analyzes the field similarity of data packets, and uses the formula:
[0027] ;
[0028] Calculate the field mutation trend characteristics , filter the data packets with consistent field mutation trends, and obtain the field mutation trend matching results, where data packet , represents the field value deviation between data packets, represents the time interval between data packets, represents the number of data packets, represents the number of times of calculating the field deviation of data packets, represents the number of times of calculating the time interval of data packets;
[0029] The traceability path analysis sub-module filters the IP addresses, ports, and paths of abnormal network traffic data packets based on the field mutation trend matching results, constructs the traceability path relationship of data packets, and establishes the mutation path association analysis record.
[0030] As a further solution of the present invention, the abnormal screening module includes:
[0031] The source IP analysis sub-module extracts the historical records of the source traffic based on the mutation path association analysis record, calculates the distribution frequency of the source IP in abnormal data packets, summarizes the abnormal occurrence proportion of the source IP, and obtains the abnormal source IP proportion data;
[0032] Based on the abnormal source IP proportion data, the traffic continuity calculation sub-module analyzes the time distribution pattern of abnormal data packets, calculates the continuity of abnormal network traffic data packets and the overlap degree of source IPs, and uses the formula:
[0033] ;
[0034] Calculate the traffic time distribution continuity coefficient , screen the data packets with abnormal source IP overlap degree within the time window to obtain the abnormal traffic continuity coefficient, where represents the timestamp of the th abnormal data packet, represents the timestamp of the previous data packet, represents the number of abnormal data packets within the time window, represents the distribution frequency of the source IP in the abnormal data packets, represents the normal traffic proportion of the source IP, represents the total number of abnormal data packets, represents the total number of source IPs;
[0035] Based on the abnormal traffic continuity coefficient, the abnormal trend matching sub-module analyzes the matching situation between the field variation amplitude of the data packets and the time window, determines whether the source traffic belongs to continuous abnormal traffic, calculates the proportion of abnormal data packets, and obtains the continuous abnormal traffic proportion data.
[0036] As a further solution of the present invention, the system further includes a risk assessment module;
[0037] The risk assessment module calculates the distribution of abnormal data packets in different network nodes according to the continuous abnormal traffic proportion data, determines the influence range of the abnormal data packets, evaluates the harm degree of the abnormal traffic, and issues an abnormal traffic threat message;
[0038] The abnormal traffic threat message includes the network node distribution record of abnormal data packets, the influence range of abnormal traffic, and the harm degree of abnormal traffic.
[0039] As a further solution of the present invention, the risk assessment module includes:
[0040] The abnormal traffic distribution sub-module calculates the distribution of abnormal data packets in different network nodes according to the continuous abnormal traffic proportion data, counts the number and proportion of abnormal data packets in each node, and summarizes the concentrated area of abnormal data to obtain the abnormal traffic node distribution record;
[0041] The abnormal influence range evaluation sub-module determines the influence range of abnormal data packets based on the abnormal traffic node distribution record, analyzes the distribution trend of abnormal data packets on each network path, evaluates the diffusion degree of abnormal traffic, and obtains the abnormal traffic influence index;
[0042] The threat level determination sub-module evaluates the harm degree of abnormal traffic based on the abnormal traffic influence index, calculates the threat level distribution, screens risk traffic nodes, and generates abnormal traffic threat information.
[0043] Compared with the prior art, the advantages and positive effects of the present invention are as follows:
[0044] In the present invention, by parsing the network traffic data packet structure, extracting the field name, field value and field order, and calculating the field dependency relationship, an association model of field arrangement and value can be constructed to evaluate the stability of traffic data from a global perspective, avoiding misjudgment caused by relying on a single data packet. Based on the deviation analysis of field matching degree and arrangement method, abnormal traffic and normal traffic patterns can be effectively distinguished, the sensitivity to subtle abnormalities can be improved, and the limitations brought by static rule matching can be reduced. The calculation of field mutation range, time interval and trend similarity ensures that the data packet traceability can be comprehensively judged in combination with multiple dimensions, improving the accuracy of tracking and enhancing the recognition ability of mutation patterns. The analysis of the distribution frequency and overlap degree of the source IP, combined with the mutation amplitude and time series information of the data packet, can clarify the persistence characteristics of traffic anomalies, enabling the security monitoring to expand from single data point analysis to behavior trend analysis. The comprehensive evaluation of the influence range of abnormal traffic, network node distribution and harm degree can provide a quantitative basis for risk warning, enhance the pertinence of security policies, make the response measures more in line with the actual situation of threats, and improve the accuracy and timeliness of overall security monitoring. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] Figure 1 is the system flow chart of the present invention;
[0046] Figure 2 is the flow chart of the traffic analysis module of the present invention;
[0047] Figure 3 is the flow chart of the abnormal detection module of the present invention;
[0048] Figure 4 is the flow chart of the traffic traceability module of the present invention;
[0049] Figure 5 is the flow chart of the abnormal screening module of the present invention;
[0050] Figure 6 is the flow chart of the risk assessment module of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0051] In order to make the objectives, technical solutions and advantages of the present invention more clear and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0052] In the description of the present invention, it should be understood that the orientation or positional relationship indicated by the terms "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. is based on the orientation or positional relationship shown in the accompanying drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation to the present invention. In addition, in the description of the present invention, the meaning of "a plurality of" is two or more unless otherwise specifically defined.
[0053] Please refer to Figure 1 , a network security monitoring system includes:
[0054] A traffic analysis module obtains network traffic data packets, analyzes the network traffic data packet structure, extracts the field names, field values and field orders in the network traffic data packets, determines the dependency relationships between the fields, calculates the arrangement rules of the fields, establishes a field dependency matrix, and obtains a field dependency mapping result;
[0055] An anomaly detection module, based on the field dependency mapping result, analyzes the arrangement stability of normal traffic fields, compares the field arrangement methods of the current network traffic data packets, calculates the field matching degree, determines whether the field arrangement conforms to the normal traffic pattern, filters out the data packets whose field order deviation exceeds the deviation threshold, and combines the field value relationships to judge the integrity of the network traffic data packet structure, and obtains a field sequence offset analysis result;
[0056] A traffic tracing module, based on the field sequence offset analysis result, extracts the timestamps, packet sequence numbers and flag fields of abnormal network traffic data packets, calculates the field variation range and time interval, analyzes the field change trend and calculates the similarity, filters out the data packets with consistent field variation trends, and traces the IP addresses, ports and paths of the abnormal network traffic data packets to obtain a variant path association analysis record;
[0057] An anomaly screening module, according to the variant path association analysis record, calculates the distribution frequency of the source IP in the abnormal data packets for the historical records of the source traffic, analyzes the time distribution pattern of the abnormal data packets, calculates the continuity of the abnormal network traffic data packets and the source IP overlap degree, analyzes the matching situation between the field variation amplitude of the data packets and the time window, and determines whether the source traffic belongs to continuous abnormal traffic to obtain the proportion data of continuous abnormal traffic;
[0058] Based on the data of the proportion of continuous abnormal traffic, the risk assessment module calculates the distribution of abnormal data packets in different network nodes, determines the scope of influence of the abnormal data packets, evaluates the harm degree of the abnormal traffic, and issues threat information about the abnormal traffic.
[0059] The field dependency mapping results include field name dependency relationships, field order dependency relationships, and field value dependency relationships. The field sequence offset analysis results include field matching degrees, field arrangement deviation values, and records of field value integrity. The mutant path association analysis records include abnormal data packet timestamps, packet sequence numbers, field mutation ranges, mutation trend similarities, IP addresses and ports of abnormal data packets. The data of the proportion of continuous abnormal traffic includes the distribution frequency of abnormal data packets, the time distribution pattern of abnormal data packets, the analysis results of abnormal traffic continuity, source IP overlap, and the matching situation of field mutation amplitudes. The threat information about abnormal traffic includes records of the network node distribution of abnormal data packets, the scope of influence of abnormal traffic, and the harm degree of abnormal traffic.
[0060] Please refer to Figure 2 , the traffic parsing module includes:
[0061] The data packet acquisition sub-module acquires network traffic data packets, extracts basic field information such as protocol type, source IP address, destination IP address, source port, destination port, and data length therein, identifies the validity of the data packets, filters out abnormal and damaged data packets, and obtains valid network traffic data packets;
[0062] The network traffic data packets are acquired from the traffic mirroring ports of switches or routers. The transmission data is monitored through a data packet capture tool to identify the basic fields of the TCP / IP protocol, including source IP address, destination IP address, source port, destination port, protocol type, data length, etc. The extracted data is stored in the original data stream buffer and sorted according to timestamps to ensure the correct data order. The extracted data packets need to be checked for validity to detect whether there are data losses, data packet truncations, or CRC check errors. For lost or damaged data packets, data repair is performed through a traffic recombination algorithm. The repair rule is to splice data packets based on TCP sequence numbers. After the header information verification of the data packets is completed, the length checksum of the data packets is calculated and compared with the length field in the header field. If the verification does not match, the data packet is marked as a damaged packet and excluded. Suppose the total number of data packets captured within 1 minute is 100,000, the number of valid data packets is 95,800, and the number of invalid or lost data packets is 4,200, among which 2,000 data packets can be repaired through sequence number recombination, and finally valid network traffic data packets are obtained.
[0063] Based on valid network traffic data packets, the field parsing sub-module parses the data packet structure, extracts the field names, field values, and field order, analyzes the distribution characteristics of the fields, calculates the field occurrence frequency and proportion, establishes the correspondence between the fields and the protocol types, and uses the formula:
[0064] ;
[0065] Calculate the field distribution coefficient , filter the field frequency characteristics, and generate the field distribution mapping result. Among them, represents the th field value, represents the field mean value, represents the field standard deviation, represents the protocol weight of the field, represents the field occurrence frequency, represents the total number of values of the field in the data packet, represents the total number of all field categories;
[0066] Based on valid network traffic data packets, first parse the header fields of the data packets, including basic fields such as protocol type, IP address, port number, data length, etc., extract the application layer fields from the data packet payload part, such as the User-Agent field, Cookie field, and Referer field in the HTTP request, count the extracted fields, calculate the occurrence times and proportions of each field in all data packets. Assume that in the sample data packets, the proportion of the HTTP protocol is 55%, the proportion of the TCP protocol is 35%, and the proportion of the UDP protocol is 10%. When calculating the field occurrence frequency and its proportion, use the formula for calculation.
[0067] Among them, represents the th field value, such as the specific value of User-Agent, is the mean value of all possible values of this field, is the standard deviation of the field, represents the protocol weight of the field. For example, the weight of the HTTP field is set to 0.55, represents the occurrence frequency of this field. For example, the occurrence frequency of the User-Agent field in the HTTP traffic is 80%. Assume that the standard deviation of the User-Agent field is 5 and the mean value is 50, then the distribution coefficient of this field is calculated as follows:
[0068] ;
[0069] The calculation results show that the distribution coefficient of the User-Agent field is 2.44. The larger this value, the greater the volatility of the field values. The product of the protocol weight and the field frequency represents the importance of the field in a specific protocol. If this value is high, the field is more representative in the protocol traffic. For example, in HTTP traffic, the appearance frequency of the Referer field is relatively low, perhaps only 20%, and its corresponding distribution coefficient may be only 1.2. However, the distribution coefficient of the User-Agent field is relatively high, indicating that its values vary significantly in different data packets and its presence degree in HTTP traffic is high. Therefore, during the field parsing process, fields with high distribution coefficients need to be further classified and summarized to improve the accuracy of field matching in the subsequent dependency analysis process. After calculating the distribution coefficients of all fields, they are sorted according to their values, the frequently occurring keyword fields are screened out, and the field-protocol correspondence is established, finally generating the field distribution mapping result.
[0070] Based on the field distribution mapping, the dependency analysis sub-module determines the dependency relationships between fields, analyzes the sequence of fields, calculates the relative position distances between fields, constructs a field dependency matrix, and obtains the field dependency mapping result.
[0071] Based on the field distribution mapping result, determine the dependency relationships between fields, and count the degree of association between fields. For example, the Referer field in an HTTP request depends on the User-Agent field, and there is a corresponding relationship between the source port and the destination port of a TCP data packet. The dependency is quantified by calculating the correlation coefficient between fields. The threshold is set to 0.7. The basis for setting this value is the correlation measure of common protocol fields in actual network data traffic. By statistically calculating the Pearson correlation coefficient between field pairs in a large number of network traffic samples, it is found that low-dependency relationships (0.3 - 0.5) between most fields are relatively common, while for high-dependency field pairs, such as the correlation coefficient between the TCP source port and the destination port is usually close to 0.9, and the correlation coefficient between the Referer and User-Agent fields is usually between 0.65 and 0.75. To ensure that the selected field pairs have strong correlations and avoid information redundancy caused by misjudgment, 0.7 is selected as the determination threshold for high dependencies. If the field correlation coefficient is greater than 0.7, it is determined as a high-dependency field pair. Calculate the relative position distances between fields, and establish a field dependency matrix based on the field appearance order. The rows and columns of the matrix represent each field respectively, and the matrix element values represent the correlation coefficients of the two fields. Suppose there are 4 fields a, b, c, d, and its field dependency matrix is as follows:
[0072] Table 1.1 Field Dependency Matrix
[0073] Field a b c d a 1.0 0.8 0.3 0.5 b 0.8 1.0 0.2 0.7 c 0.3 0.2 1.0 0.4 d 0.5 0.7 0.4 1.0
[0074] As shown in Table 1.1, the dependence between field a and field b is the highest (0.8), and the dependence between field b and field d is also relatively high (0.7). This indicates that there is a strong linear relationship between the values of field a and field b, while the dependence between field b and field d just reaches the set threshold of 0.7. If a lower threshold (such as 0.6) is used, it may lead to too many irrelevant field pairs being marked as highly dependent fields. If the set threshold is too high (such as 0.8), it may cause some important field pairs to be unrecognized. Therefore, the selection of 0.7 can ensure the reasonable screening of dependent field pairs. High-dependent field pairs are screened based on the matrix to form a field association network, and finally a field dependence mapping result is obtained.
[0075] Please refer to Figure 3 , the anomaly detection module includes:
[0076] Based on the field dependence mapping result, the field matching sub-module analyzes the arrangement stability of normal traffic fields, extracts the field order characteristics in the normal traffic mode, compares the field arrangement method of the current network traffic data packet, and uses the formula:
[0077] ;
[0078] Calculate the field matching error , determine whether the field arrangement conforms to the normal traffic mode, and obtain the field matching error value. Among them, represents the th field position in the current data packet field sequence, represents the expected position of the th field in the normal traffic mode, represents the relative distance between fields involved in the field matching process, represents the actual number of fields participating in the matching in the data packet, represents the number of times of comparing the relative positions of fields involved in the data packet;
[0079] Based on the field dependency mapping results, extract the field order features in the normal traffic pattern, construct a field arrangement reference table, classify and quantify the packet field arrangement structures under different traffic types, obtain the typical field order in the normal traffic pattern, and convert the field arrangement into a numerical sequence. For example, assume that the typical field sequence in the normal traffic pattern is {a, b, c, d, e}, where a represents the source IP address, b represents the target IP address, c represents the source port, d represents the target port, and e represents the protocol type, then it can be mapped to {1, 2, 3, 4, 5}. Then, obtain the field arrangement method of the current network traffic packet. For example, the actual field sequence of a certain packet is {a, c, b, e, d}, which can be mapped to {1, 3, 2, 5, 4}. Then, use a formula to calculate. Taking the current packet {1, 3, 2, 5, 4} and the normal mode {1, 2, 3, 4, 5} as an example, calculate:
[0080] ;
[0081] ;
[0082] The threshold setting is based on the following: Packets in normal network traffic usually have a stable field arrangement pattern. Therefore, in different network environments, collect traffic packet samples at multiple time periods and calculate the field matching errors of all samples , and statistically calculate their mean value and standard deviation . Set the anomaly determination threshold as:
[0083] ;
[0084] Assume that the statistical result is , , then:
[0085] ;
[0086] Therefore, set the field matching error threshold to 1.5. If the field matching error exceeds 1.5, then the field arrangement of this packet is abnormal. If , then this packet conforms to the normal traffic pattern, and finally obtain the field matching error value.
[0087] The deviation screening sub-module filters out the packets whose field order deviation exceeds the deviation threshold based on the field matching error value, calculates the proportion of fields that exceed the deviation threshold, determines whether there is an abnormal field arrangement in the packet, and obtains the data of the abnormal field arrangement ratio;
[0088] Based on the field matching error value, filter the data packets with field order deviation exceeding the deviation threshold, and calculate the proportion of fields exceeding the deviation threshold. For example, during a traffic detection process, among 1000 data packets, 150 data packets have a field matching error exceeding 1.5, then calculate the proportion of abnormal data packets as:
[0089] ;
[0090] The threshold setting basis is as follows: To determine the reasonable range of abnormal data packets in normal network traffic, count the data traffic in multiple time periods, and calculate the proportion of abnormal data packets in all traffic detection cycles , and count its mean value and standard deviation , and set the abnormal determination threshold as:
[0091] ;
[0092] Suppose the statistics obtain , , then:
[0093] ;
[0094] Therefore, set the abnormal data packet proportion threshold to 10%. When the deviation rate exceeds 10%, it is determined that the proportion of abnormal data packets in the current traffic is relatively high, otherwise it is determined as normal traffic, and finally obtain the field arrangement abnormal ratio data.
[0095] The integrity judgment sub-module, based on the field arrangement abnormal ratio data, combines the field value relationship to judge the integrity of the network traffic data packet structure, filters the data packets with abnormal structures, and obtains the field sequence offset analysis result;
[0096] Based on the field arrangement abnormal ratio, combine the field value relationship to judge the integrity of the network traffic data packet structure, analyze the logical relationship between field values. For example, if the source IP address of the data packet is the same as the destination IP address, it may be an abnormal data packet, or the protocol type does not match the port number. For example, the HTTP protocol usually corresponds to port 80, while the protocol type identifier of the current data packet is HTTP, but the port number is 23 (Telnet port), then there may be a problem with the data packet structure. Filter the data packets with abnormal structures, and finally obtain the field sequence offset analysis result.
[0097] Please refer to Figure 4 , the traffic traceability module includes:
[0098] Based on the field sequence offset analysis results, the field mutation calculation sub-module extracts the timestamps, packet sequence numbers, and flag fields of abnormal network traffic packets, calculates the field mutation range and time interval, summarizes the time distribution characteristics of abnormal packets, and obtains the field mutation time characteristics.
[0099] Based on the field sequence offset analysis results, the timestamps, packet sequence numbers, and flag fields of abnormal network traffic packets are extracted. During the extraction process, the timestamp of the packet is first identified. The timestamp represents the time point when the packet is captured in the network. For example, the timestamp of a certain packet is 2024-03-11 10:15:30.125. Then, the packet sequence number is parsed. The packet sequence number is used to identify the order of the packets. Suppose the packet sequence numbers are 1001, 1002, and 1003 respectively. Next, the flag field is extracted. The flag field is used to indicate the control information of the packet, such as SYN, ACK, FIN, etc. A certain packet may have a flag field of SYN=1 and ACK=0. Subsequently, the field mutation range and time interval are calculated. The field mutation range is the degree of difference between the field values of each packet. For example, the mutation range of the packet sequence number can be obtained by calculating the difference between the maximum value and the minimum value. For the above packet sequence number data, the mutation range is 1003 - 1001 = 2. The time interval calculation method is the difference between the timestamps of adjacent packets. For example, if the timestamps of adjacent packets are 2024-03-11 10:15:30.125 and 2024-03-11 10:15:30.250 respectively, the time interval is calculated as 0.250 - 0.125 = 0.125 seconds. Summarize the time distribution characteristics of abnormal packets. By statistically calculating the mean and variance of the time intervals of multiple abnormal packets, the time pattern of the packet appearance is judged, as shown in Table 3.1.
[0100] Table 3.1 Statistical Table of Abnormal Packet Time Characteristics
[0101]
[0102] As shown in Table 3.1, there are differences in the packet time intervals. By calculating the mean and variance, it can be obtained that the mean of the time intervals is (0.125 + 0.250) / 2 = 0.1875 seconds, and the variance is calculated as ((0.125 - 0.1875)^2 + (0.250 - 0.1875)^2) / 2 = 0.0078, thus obtaining the field mutation time characteristics.
[0103] Based on the field mutation time characteristics, the mutation trend analysis sub-module analyzes the field change trend, compares the field value changes between abnormal packets, analyzes the field similarity of packets, and uses the formula:
[0104] ;
[0105] Calculate the field mutation trend characteristics , filter data packets with consistent field mutation trends to obtain the field mutation trend matching result, where data packet , represents the deviation of field values between data packets, represents the time interval between data packets, represents the number of data packets, represents the number of times of calculating the field deviation of data packets, represents the number of times of calculating the time interval of data packets;
[0106] Based on the time characteristics of field mutation, analyze the field change trend. First, compare the changes in field values between abnormal data packets. For example, for data packet sequence numbers 1001, 1002, and 1003, the change trend of their flag fields can be expressed as {(SYN, ACK, FIN): (1, 0, 0) → (0, 1, 0) → (1, 1, 0)}, and then calculate using the formula. Assume that the field values V of the data packets are {1, 0, 0}, {0, 1, 0}, {1, 1, 0}, and the mean value calculation is:
[0107] ;
[0108] Field deviation calculation:
[0109] ;
[0110] Take the time intervals as 0.125 and 0.250, and calculate the sum of time factors:
[0111] ;
[0112] Substitute into the formula:
[0113] ;
[0114] ;
[0115] This result shows that the field mutation trend matching value is . The closer this value is to 1, the more similar the field change trends of the data packets are. Conversely, it indicates that there are obvious differences in the mutation patterns. In this example, indicates that the field mutation trends of these data packets are highly consistent, indicating that they may belong to the same attack behavior or abnormal traffic pattern. Therefore, in the subsequent tracing process, these data packets may be attributed to the same attack path or the same source.
[0116] Based on the matching results of field mutation trends, the traceability path analysis sub-module filters the IP addresses, ports, and paths of abnormal network traffic data packets, constructs the traceability path relationship of the data packets, and establishes mutation path correlation analysis records;
[0117] Based on the matching results of field mutation trends, filter the IP addresses, ports, and paths of abnormal network traffic data packets. Suppose the source IP address of an abnormal data packet is 192.168.1.10, the destination IP address is 10.0.0.5, the source port is 443, the destination port is 8080, and the data packet path is a→b→c→d. Construct the traceability path relationship of the data packet as shown in Table 3.2.
[0118] Table 3.2 Traceability Path Table for Abnormal Data Packets
[0119]
[0120] As shown in Table 3.2, the data packet is transmitted through different paths. The traceability path is analyzed by comparing the IP addresses, ports, and relay node information. Suppose that during the traceability process, it is found that data packets 1001 and 1002 have two common relay nodes c and d. Then it can be inferred that this path may belong to the same attack source, and thus mutation path correlation analysis records are established.
[0121] Please refer to Figure 5 , the abnormal screening module includes:
[0122] Based on the mutation path correlation analysis records, the source IP analysis sub-module extracts the historical records of the source traffic, calculates the distribution frequency of the source IP in abnormal data packets, summarizes the abnormal occurrence ratio of the source IP, and obtains the data of the abnormal source IP ratio;
[0123] Based on the mutation path correlation analysis records, extract the historical records of the source traffic, obtain the source IP addresses involved in abnormal data packets in the past period of time, count the number of abnormal data packets corresponding to each source IP, calculate its distribution frequency in the overall abnormal data packets. Suppose the total number of abnormal data packets captured in a certain period is 5000, and the total number of source IPs involved is 2000. The number of abnormal data packets corresponding to each source IP is different. Some source IPs have a relatively large number of abnormal data packets. For example, the number of abnormal data packets associated with a certain source IPa reaches 500, accounting for 10%, and another source IPb is only associated with 10 abnormal data packets, accounting for 0.2%. For these data, construct a source IP abnormal frequency distribution table and screen out the high-frequency source IPs with an abnormal ratio exceeding 5%, as shown in Table 4.1.
[0124] Table 4.1 Abnormal Distribution Table of Source IPs
[0125] Source IP Number of Associated Abnormal Data Packets Percentage (%) IPa 500 10 IPb 10 0.2 IPc 250 5 IPd 100 2 ... ... ...
[0126] As shown in Table 4.1, by counting the distribution of abnormal data packets from different source IPs, it can be found that the proportion of abnormal data packets of some IP addresses far exceeds that of other IPs. Subsequently, a threshold for the abnormal proportion of the source IP is set. Assuming the set threshold is 5%, the high-frequency abnormal source IPs a and IPc are screened out, and finally the proportion of abnormal source IPs is obtained.
[0127] The basis for setting this threshold is as follows: The threshold for the abnormal proportion of the source IP is used to distinguish high-frequency abnormal source IPs from randomly occurring abnormal source IPs. Generally, there are two modes of abnormal behavior of the source IP: discrete distribution and concentrated distribution. To set a reasonable threshold, first, count the abnormal distribution frequency of the source IP in a normal traffic environment. Assume that 50,000 data packets are extracted from normal network traffic, among which 2,000 are abnormal data packets, accounting for 4%. Calculate its mean and standard deviation:
[0128] ;
[0129] ;
[0130] Assume that the abnormal proportion of normal source IPs follows a normal distribution, then the threshold for the abnormal proportion of the source IP in the 95% confidence interval can be calculated as follows:
[0131] ;
[0132] To ensure a sufficient range for screening abnormal IPs, this value is set to 5%, that is:
[0133] ;
[0134] This threshold fluctuates with the abnormal occurrence frequency of the source IP, the total traffic base, and the proportion of abnormal data packets. If the overall traffic increases, this value will approach 6%. If the proportion of abnormal data packets decreases, this value will drop to around 4%. In the current calculation, the source IP a has an abnormal proportion of 10%, which is significantly higher than 5%, so it is determined as a high-frequency abnormal source IP. The source IP c has a proportion of 5% and is at the screening boundary, so it is still included in the high-frequency abnormal source IPs. Finally, the proportion of abnormal source IPs is obtained.
[0135] Based on the proportion data of abnormal source IPs, the traffic continuity calculation sub-module analyzes the time distribution pattern of abnormal data packets, calculates the continuity of abnormal network traffic data packets and the overlap degree of source IPs, and uses the formula:
[0136] ;
[0137] Calculate the traffic time distribution continuity coefficient , filter the data packets with abnormal source IP overlap within the time window to obtain the abnormal traffic continuity coefficient, where represents the timestamp of the th abnormal data packet, represents the timestamp of the previous data packet, represents the number of abnormal data packets within the time window, represents the distribution frequency of the source IP in the abnormal data packets, represents the proportion of normal traffic of the source IP, represents the total number of abnormal data packets, represents the total number of source IPs;
[0138] Based on the proportion data of abnormal source IPs, analyze the time distribution pattern of abnormal data packets, extract the data packets of high-frequency abnormal source IPs, calculate the continuity of abnormal data packets, and count the overlap degree of source IPs. Assume that the number of abnormal data packets per hour in the past 24 hours is as follows:
[0139] ;
[0140] ;
[0141] Use the formula to calculate the time continuity of abnormal data packets.
[0142] Assume that the total amount of abnormal data packets within the time window is , the abnormal distribution of source IP is , the proportion of normal traffic source IP is , substitute into the calculation:
[0143] ;
[0144] ;
[0145] After calculation, it is obtained that , this value represents the time continuity coefficient of abnormal data packets, which is higher than the set threshold of 2.5. Therefore, it can be determined that there is a strong time continuity of abnormal data packets, and the abnormal traffic continuity coefficient is obtained.
[0146] The abnormal traffic continuity coefficient reflects whether the time distribution of abnormal data packets shows continuous fluctuations. If this value is low (close to 1), it means that the distribution of abnormal data packets is relatively discrete. If this value is high (exceeding 3), it means that abnormal data packets are highly aggregated in the time dimension. To reasonably set the threshold, first calculate the time distribution fluctuation range of normal traffic. Assume that 1000 groups of data are extracted from the normal data packet distribution and calculate its The mean value is 1.8 and the standard deviation is 0.4. Therefore, the normal traffic threshold within the 95% confidence interval can be set:
[0147] ;
[0148] To ensure that abnormal data packets can be effectively distinguished, the abnormal threshold is set at 2.5, that is:
[0149] ;
[0150] This threshold fluctuates with the distribution frequency of abnormal data packets and the length of the time window. If there are a large number of abnormal data packets in a short period of time, this value will be higher. If the abnormal distribution of data packets is relatively uniform, this value will be close to 2.5. In the current calculation, the abnormal traffic continuity coefficient significantly exceeds 2.5, indicating that the abnormal traffic shows a high-density distribution, further verifying the continuous abnormal characteristics of the traffic.
[0151] The abnormal trend matching sub-module analyzes the matching situation between the field variation amplitude of data packets and the time window based on the abnormal traffic continuity coefficient, determines whether the source traffic belongs to continuous abnormal traffic, calculates the proportion of abnormal data packets, and obtains the proportion data of continuous abnormal traffic;
[0152] Based on the abnormal traffic continuity coefficient, analyze the matching situation between the field variation amplitude of data packets and the time window, filter out the data packets whose abnormal traffic continuity coefficient exceeds the set threshold, and calculate the change trend of the source IP in these data packets. Assume the number of abnormal data packets of source IPa within 24 hours is as follows:
[0153] ;
[0154] ;
[0155] Calculate the variation trend of source IPa in different time windows ( ), compare it with the time distribution trend of global abnormal data packets, and calculate the similarity using the Pearson correlation coefficient:
[0156] ;
[0157] Assume , , after calculation, it is obtained that , indicating that the packet variation trend of source IPA is highly similar to the time distribution trend of global abnormal data packets, determining that the source traffic belongs to continuous abnormal traffic, and finally calculating the proportion data of continuous abnormal traffic.
[0158] Please refer to Figure 6 , the risk assessment module includes:
[0159] Based on the continuous abnormal traffic proportion data, the abnormal traffic distribution sub-module calculates the distribution of abnormal data packets in different network nodes, counts the number and proportion of abnormal data packets in each node, summarizes the concentrated areas of abnormal data, and obtains the abnormal traffic node distribution record;
[0160] Based on the continuous abnormal traffic proportion data, it is necessary to calculate the abnormal data packets of different network nodes to understand the distribution of abnormal traffic in the network structure. First, obtain the traffic log data of each network node, and extract the identification information of abnormal data packets from it, such as source IP address, destination IP address, port number, and timestamp. Classify these data according to the network topology structure. Subsequently, count the number of abnormal data packets in each node and calculate the proportion of abnormal data packets in the node traffic. For example, if the total traffic of a certain node within the sampling time is 50,000 data packets and the number of abnormal data packets is 500, the calculation of the abnormal traffic proportion of this node is as follows:
[0161] ;
[0162] Next, compare the abnormal traffic proportions of different nodes to determine the concentrated areas of abnormal traffic. If the abnormal traffic proportion of a certain node is much higher than the network average level (for example, the average value is 2% and a certain node is as high as 10%), then mark this node as a high-incidence area of abnormal traffic. In this way, potential abnormal traffic hotspots can be screened out to obtain the abnormal traffic node distribution.
[0163] Based on the abnormal traffic node distribution record, the abnormal impact range assessment sub-module determines the impact range of abnormal data packets, analyzes the distribution trend of abnormal data packets on each network path, and evaluates the diffusion degree of abnormal traffic to obtain the abnormal traffic impact index;
[0164] Based on the abnormal traffic node distribution record, it is necessary to further analyze the propagation range of abnormal data packets to evaluate the impact degree of abnormal traffic. First, sort the abnormal traffic nodes according to the network topology relationship to determine the flow path of the data packets. For example, in a certain enterprise network, the abnormal traffic may first pass through the router, then through the switch, and finally reach the terminal device. Monitor the data flow on each path and calculate the proportion of abnormal data packets on the path. For example, if the number of normal data packets on a certain path is 80,000 and the number of abnormal data packets is 2,000, the calculation of the abnormal proportion of this path is as follows:
[0165] ;
[0166] After obtaining the abnormal proportion of all paths, filter out the paths where abnormal data flow is relatively concentrated, and determine whether these paths are connected to key network nodes such as servers and gateways. If the proportion of abnormal traffic exceeds 5% on multiple key paths, it can be determined that the abnormal traffic has a large diffusion trend (the 5% threshold is set based on the statistical analysis of the network basic traffic load and the normal traffic fluctuation range. Generally, the normal traffic fluctuation range on key paths in enterprise-level networks is within ±3%. When the proportion of abnormal traffic reaches 5%, it means that the abnormal traffic has exceeded the upper limit of normal fluctuations and is very likely to affect the normal service ability of the network. Specifically, this value will fluctuate with the change of the network basic load. For example, for a path with a daily average data traffic of 5 million data packets, this value may be appropriately relaxed to 6%-7%, and for a data path with a daily average data traffic of less than 500,000, this value can be set to 4% to ensure the adaptability of the judgment criteria in different network environments. In addition, in the attack simulation experiment, it is found that when the proportion of abnormal traffic in the key path exceeds 5%, the network packet loss rate begins to increase significantly, and the average server response time increases by more than 30%. Therefore, 5% is used as the basic risk threshold in this type of network environment, and this value can be adjusted according to network service requirements and security policies to adapt to different scales and security levels of network environments). Finally, combined with the abnormal traffic proportion data of these paths, calculate the diffusion index of the overall abnormal traffic to reflect the propagation trend of abnormal data packets in the network, and obtain the abnormal traffic impact index.
[0167] The threat level determination sub-module evaluates the harm degree of the abnormal traffic based on the abnormal traffic impact index, calculates the threat level distribution, filters out the risk traffic nodes, and generates the abnormal traffic threat information.
[0168] Based on the abnormal traffic impact index, it is necessary to further analyze the harm degree of the abnormal traffic and determine the threat level of the abnormal traffic. First, compare the diffusion index of the abnormal traffic with the preset security threshold. For example, in a certain network security policy, it is stipulated that when the diffusion index of the abnormal traffic exceeds 3%, the security monitoring level needs to be improved. If the calculated diffusion index is 4.2%, then the network status is marked as a medium risk level. Next, analyze the source and type of the abnormal traffic. If the abnormal traffic mainly comes from a specific IP segment and the data packet structure conforms to the known attack behavior pattern (such as SYN Flood attack or DDoS attack), the risk level needs to be increased. In addition, it is also necessary to calculate the distribution of the abnormal traffic in different time periods. If the abnormal traffic continuously exceeds 10% of the normal traffic within a certain time window, the threat level is further increased. Finally, comprehensively score all the analysis results to determine the final threat level of the abnormal traffic, such as low risk (0%-2%), medium risk (2%-5%), high risk (>5%), and send out the abnormal traffic threat information.
[0169] The above are only the preferred embodiments of the present invention, and do not limit the present invention in other forms. Any person skilled in the art may use the technical content disclosed above to make changes or modifications into equivalent embodiments with equivalent changes and apply them to other fields. However, as long as it does not depart from the technical solution content of the present invention, any simple modification, equivalent change and modification made to the above embodiments based on the technical essence of the present invention still fall within the protection scope of the technical solution of the present invention.
Claims
1. A network security monitoring system, characterized in that: The system comprises: The traffic analysis module obtains network traffic data packets, extracts field names, field values and field orders in network traffic data packets, determines the dependency relationship between fields, calculates the field arrangement rules, and obtains the field dependency mapping results; The anomaly detection module analyzes the arrangement stability of normal traffic fields based on the field dependency mapping results, compares the field arrangement of the current network traffic data packet, calculates the field matching degree, and determines the structural integrity of the network traffic data packet in combination with the field value relationship to obtain the field sequence offset analysis results; The traffic tracing module extracts the timestamp, packet sequence number and flag field of the abnormal network traffic data packet based on the field sequence offset analysis result, analyzes the field change trend, traces the IP address, port and path of the abnormal network traffic data packet, and obtains the variation path association analysis record; The anomaly screening module calculates the distribution frequency of the source IP in the abnormal data packet based on the variation path association analysis record, calculates the continuity of the abnormal network traffic data packet and the source IP overlap, analyzes the matching of the data packet field variation amplitude and the time window, determines whether the source traffic belongs to continuous abnormal traffic, and obtains the continuous abnormal traffic proportion data.
2. The network security monitoring system according to claim 1, characterized in that: The field dependency mapping results include field name dependency, field order dependency, and field value dependency; the field sequence offset analysis results include field matching, field arrangement deviation value, and field value integrity record; the variation path association analysis record includes abnormal data packet timestamp, packet sequence number, field variation range, variation trend similarity, abnormal data packet IP address and port; the continuous abnormal traffic proportion data includes abnormal data packet distribution frequency, abnormal data packet time distribution pattern, abnormal traffic continuity analysis results, source IP overlap, and field variation amplitude matching.
3. The network security monitoring system according to claim 1, characterized in that: The traffic analysis module includes: The data packet acquisition submodule acquires network traffic data packets, extracts the protocol type, source IP address, destination IP address, source port, destination port, data length basic field information, identifies the validity of the data packets, filters out abnormal and damaged data packets, and obtains valid network traffic data packets; The field parsing submodule parses the data packet structure based on the valid network traffic data packet, extracts the field name, field value and field order, analyzes the distribution characteristics of the field, calculates the frequency and proportion of the field, and establishes the corresponding relationship between the field and the protocol type, using the formula: ; Calculate the field distribution coefficient , filter the field frequency characteristics and generate field distribution mapping results, where: Representative field values, Represents the field mean, Represents the field standard deviation, Represents the protocol weight to which the field belongs. Represents the frequency of occurrence of the field, Indicates the total number of values of the field in the data packet. Indicates the total number of all field categories; The dependency analysis submodule determines the dependency relationship between fields, analyzes the sequence between fields, calculates the relative position distance between fields, constructs a field dependency matrix, and obtains a field dependency mapping result based on the field distribution mapping result.
4. The network security monitoring system according to claim 1, characterized in that: The anomaly detection module comprises: The field matching submodule analyzes the arrangement stability of normal traffic fields based on the field dependency mapping results, extracts the field order characteristics under normal traffic mode, and compares the field arrangement of the current network traffic data packet using the formula: ; Calculate field matching error , determine whether the field arrangement conforms to the normal traffic pattern, and obtain the field matching error value, where, Represents the first field in the current packet sequence. field positions, In normal flow mode The expected position of the field, Represents the relative distance between fields involved in the field matching process. Represents the number of fields actually involved in the match in the data packet. Represents the number of times the relative positions of the fields involved in the data packet are compared; The deviation screening submodule screens data packets whose field sequence deviation exceeds the deviation threshold based on the field matching error value, calculates the field ratio exceeding the deviation threshold, determines whether there is field arrangement abnormality in the data packet, and obtains field arrangement abnormality ratio data; The integrity judgment submodule judges the integrity of the network traffic data packet structure based on the field arrangement abnormality ratio data and the field value relationship, screens data packets with abnormal structures, and obtains field sequence offset analysis results.
5. The network security monitoring system according to claim 1, characterized in that: The traffic tracing module includes: The field variation calculation submodule extracts the timestamp, packet sequence number and flag field of the abnormal network traffic data packet based on the field sequence offset analysis result, calculates the field variation range and time interval, summarizes the time distribution characteristics of the abnormal data packet, and obtains the field variation time characteristics; The variation trend analysis submodule analyzes the field variation trend based on the field variation time characteristics, compares the field value changes between abnormal data packets, and analyzes the data packet field similarity using the formula: ; Calculate field variation trend characteristics , filter the data packets with the same field variation trend, and obtain the field variation trend matching results, where, Represents the i-th Field value, Represents the field mean, Represents the field value deviation between data packets. Represents the time interval between data packets, Represents the number of packets, Represents the number of packet field deviation calculations, Represents the number of packet time interval calculations; The traceability path parsing submodule screens the IP addresses, ports and paths of abnormal network traffic data packets based on the field variation trend matching results, builds the traceability path relationship of the data packets, and establishes variation path association analysis records.
6. The network security monitoring system according to claim 1, characterized in that: The abnormal screening module includes: The source IP analysis submodule extracts the historical records of source traffic based on the variation path association analysis records, calculates the distribution frequency of source IP in abnormal data packets, summarizes the abnormal occurrence ratio of source IP, and obtains the abnormal source IP ratio data; The traffic continuity calculation submodule analyzes the time distribution pattern of abnormal data packets based on the abnormal source IP proportion data, calculates the continuity of abnormal network traffic data packets and the source IP overlap, using the formula: ; Calculate the continuity coefficient of flow time distribution , filter the packets with abnormal source IP overlap within the time window and obtain the abnormal traffic continuity coefficient, where, Representative The timestamp of the abnormal data packet, Represents the timestamp of the previous data packet, Represents the number of abnormal packets in the time window. Represents the distribution frequency of the source IP in the abnormal data packets. Represents the normal traffic ratio of the source IP. Represents the total number of abnormal packets. Represents the total number of source IPs; The abnormal trend matching submodule analyzes the field variation range of the data packet and the matching situation within the time window based on the abnormal traffic continuity coefficient, determines whether the source traffic belongs to continuous abnormal traffic, calculates the proportion of abnormal data packets, and obtains the continuous abnormal traffic proportion data.
7. The network security monitoring system according to claim 1, characterized in that: The system also includes a risk assessment module; The risk assessment module calculates the distribution of abnormal data packets in different network nodes according to the continuous abnormal traffic proportion data, determines the impact range of the abnormal data packets, assesses the degree of harm of the abnormal traffic, and issues abnormal traffic threat information; The abnormal traffic threat information includes abnormal data packet network node distribution records, abnormal traffic impact range, and abnormal traffic hazard degree.
8. The network security monitoring system according to claim 7, characterized in that: The risk assessment module includes: The abnormal traffic distribution submodule calculates the distribution of abnormal data packets in different network nodes based on the continuous abnormal traffic proportion data, counts the number and proportion of abnormal data packets in each node, summarizes the concentrated area of abnormal data, and obtains abnormal traffic node distribution records; The abnormal impact range assessment submodule determines the impact range of the abnormal data packet based on the abnormal traffic node distribution record, analyzes the distribution trend of the abnormal data packet on each network path, assesses the diffusion degree of the abnormal traffic, and obtains the abnormal traffic impact index; The threat level determination submodule evaluates the degree of harm of abnormal traffic based on the abnormal traffic impact index, calculates the threat level distribution, screens risky traffic nodes, and generates abnormal traffic threat information.
Citation Information
Patent Citations
Internet monitoring anti-spamming method and device
CN104050178A
Network information monitoring method and system based on machine learning
CN118523972A