Abnormal traffic detection method and device, electronic equipment and storage medium

By acquiring and analyzing the abnormal detection results of various traffic data characteristics, the problem of difficulty in detecting complex abnormal traffic in the prior art is solved, and higher detection accuracy and traffic data security are achieved.

CN120090859APending Publication Date: 2025-06-03BEIJING BAIDU NETCOM SCI & TECH CO LTD +1
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510323749.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-18
Publication Date
2025-06-03

AI Technical Summary

Technical Problem

The prior art is difficult to effectively detect and identify abnormal traffic hidden in complex normal traffic, and the attack methods have become more complex and concealed, increasing the detection difficulty.

Method used

By obtaining multiple different types of data characteristics of the target traffic data (such as time series traffic characteristics, connection characteristics and Flow characteristics), and applying different anomaly detection methods respectively, multiple anomaly detection results are generated, and finally combining these results to determine whether the target traffic data is abnormal traffic data.

Benefits of technology

It improves the accuracy of abnormal traffic detection, can detect different types of attacks in a timely and effective manner, and improves the security of traffic data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090859A_ABST
    Figure CN120090859A_ABST
Patent Text Reader

Abstract

The invention provides an abnormal traffic detection method and device, electronic equipment and a storage medium, and relates to the field of artificial intelligence such as network security, deep learning and large models. The method comprises the following steps: obtaining target traffic data to be detected, and respectively obtaining M different types of data features of the target traffic data, M being a positive integer greater than 1; generating exception detection results corresponding to the various data features according to exception detection modes corresponding to the various data features; and determining whether the target traffic data is abnormal traffic data or not according to each abnormal detection result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of artificial intelligence technology, particularly to fields such as network security, deep learning, and large models, and more particularly to methods, devices, electronic devices, and storage media for detecting abnormal traffic. Background Art

[0002] Detecting abnormal traffic is a highly challenging task. With the diversification of network application scenarios, the patterns of normal traffic are becoming increasingly complex, and it is becoming more and more difficult to detect abnormal traffic hidden in normal traffic. At the same time, traffic attack techniques are also gradually improving, and the means used by attackers are becoming more complex and concealed. These all increase the difficulty of detection. Summary of the Invention

[0003] The present disclosure provides a method, device, electronic device, and storage medium for detecting abnormal traffic.

[0004] An abnormal traffic detection method includes:

[0005] Obtaining target traffic data to be detected, and respectively obtaining M different types of data features of the target traffic data, where M is a positive integer greater than 1;

[0006] Respectively generating abnormal detection results corresponding to various data features according to the abnormal detection methods corresponding to various data features;

[0007] Determining whether the target traffic data is abnormal traffic data according to each abnormal detection result.

[0008] An abnormal traffic detection device includes: an acquisition module, a detection module, and a determination module;

[0009] The acquisition module is configured to obtain target traffic data to be detected, and respectively obtain M different types of data features of the target traffic data, where M is a positive integer greater than 1;

[0010] The detection module is configured to respectively generate abnormal detection results corresponding to various data features according to the abnormal detection methods corresponding to various data features;

[0011] The determination module is configured to determine whether the target traffic data is abnormal traffic data according to each abnormal detection result.

[0012] An electronic device includes:

[0013] At least one processor; and

[0014] A memory communicatively connected to the at least one processor; wherein,

[0015] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method as described above.

[0016] A non-transitory computer-readable storage medium storing computer instructions for causing a computer to execute the method as described above.

[0017] A computer program product including a computer program / instructions, which when executed by a processor implement the method as described above.

[0018] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understood through the following description. Description of the Drawings

[0019] The drawings are used to better understand the solution and do not constitute a limitation to the present disclosure. Among them:

[0020] Figure 1 It is a flowchart of the first embodiment of the abnormal traffic detection method described in the present disclosure;

[0021] Figure 2 It is a flowchart of the method embodiment for determining whether the target traffic data is abnormal traffic data according to each abnormal detection result described in the present disclosure;

[0022] Figure 3 It is a flowchart of the second embodiment of the abnormal traffic detection method described in the present disclosure;

[0023] Figure 4 It is a schematic structural diagram of the composition of the abnormal traffic detection device embodiment 400 described in the present disclosure;

[0024] Figure 5 It shows a schematic block diagram of an electronic device 500 that can be used to implement the embodiments of the present disclosure. Detailed Embodiments

[0025] The following describes exemplary embodiments of the present disclosure with reference to the drawings. Various details of the embodiments of the present disclosure are included to assist understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.

[0026] In addition, it should be understood that the term "and / or" in this text is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this text generally represents an "or" relationship between the preceding and following associated objects.

[0027] Figure 1 This is a flowchart of the first embodiment of the abnormal traffic detection method described in the present disclosure. As Figure 1 shown, it includes the following specific implementation manners.

[0028] In step 101, obtain the target traffic data to be detected, and respectively obtain M different types of data features of the target traffic data, where M is a positive integer greater than 1.

[0029] In step 102, respectively generate abnormal detection results corresponding to various data features according to the abnormal detection methods corresponding to various data features.

[0030] In step 103, determine whether the target traffic data is abnormal traffic data according to each abnormal detection result.

[0031] Traditional abnormal traffic detection methods usually only focus on the change of a single feature of traffic data, such as the fluctuation of traffic volume, and it is difficult to guarantee the accuracy.

[0032] However, by adopting the solution described in the above method embodiment, for the target detection traffic to be detected, multiple different types of data features can be respectively obtained, and then abnormal detection results corresponding to various data features can be generated according to the abnormal detection methods corresponding to various data features. Furthermore, it can be determined whether the target traffic data is abnormal traffic data by combining each abnormal detection result. Compared with the traditional abnormal traffic detection method based on a single feature, in the solution described in the above method embodiment, multiple data features (i.e., multiple different dimensional features) can be combined simultaneously to determine whether the target traffic data is abnormal traffic data, thereby improving the accuracy of the abnormal traffic detection result, and different types of attacks can be detected in a timely and effective manner, so as to take corresponding defense measures subsequently and improve the security of traffic data, etc.

[0033] The target traffic data may refer to the traffic data obtained in real time for the port to be detected. For example, the traffic data generated within the most recent 5 seconds can be used as the target traffic data.

[0034] For the target traffic data, M different types of data features can be respectively obtained, and abnormal detection results corresponding to various data features can be respectively generated according to the abnormal detection methods corresponding to various data features.

[0035] In some embodiments of the present disclosure, the M different types of data features may include: time-series traffic features and connection features. The anomaly detection results corresponding to various data features may include: a first detection result corresponding to the time-series traffic features and a second detection result corresponding to the connection features. The first detection result is used to illustrate whether there is a traffic anomaly in the target traffic data, and the second detection result is used to illustrate whether there is a connection anomaly in the target traffic data.

[0036] The time-series traffic features and connection features are the main data features in the target traffic data. Accordingly, these two types of data features can be obtained to determine whether the target traffic data is abnormal traffic data by combining the anomaly detection results corresponding to these two types of data features. Compared with the traditional anomaly traffic detection method based on a single feature, the accuracy of the anomaly traffic detection result can be improved, etc.

[0037] In addition, in some embodiments of the present disclosure, the M different types of data features may further include: Flow features. Accordingly, the anomaly detection results corresponding to various data features may further include: a third detection result corresponding to the Flow features. The third detection result is used to illustrate whether there is an access anomaly in the target traffic data.

[0038] That is to say, the value of M can be 2 or 3. When the value of M is 2, the 2 data features may be the time-series traffic features and the connection features respectively. When the value of M is 3, the 3 data features may be the time-series traffic features, the connection features and the Flow features respectively. Which M value-taking method to specifically adopt can be determined according to actual needs, which is very flexible and convenient.

[0039] By introducing the Flow features, the content of the data features can be further enriched, so that the anomaly situation of the target traffic data can be evaluated from more dimensions, and further improve the accuracy of the anomaly traffic detection result, etc.

[0040] The time-series traffic features usually include multiple specific features, such as: inbound traffic, outbound traffic, inbound payload, outbound payload, inbound packet count, and outbound packet count, etc.

[0041] The connection features usually also include multiple specific features, such as: the number of newly established SYN (Synchronize Sequence Numbers), the number of newly established ACK (Acknowledge Character), the number of half-open connections, the number of concurrent connections, the number of active connections, the inbound packet flag, the outbound packet flag, the number of closed connections, and the number of failed connections, etc. Among them, the closed connections may include client close, service close, client reset, service reset, service flash break, and timeout close, etc. The failed connections may include client ignore, client reject, and service reject, etc.

[0042] The Flow feature may include specific access request information, such as the request source address (IP address) corresponding to each access request included in the target traffic data, etc.

[0043] There is no limitation on how to obtain the time-series traffic feature, connection feature, and Flow feature. For example, it can be obtained by analyzing and statistically processing the target traffic data.

[0044] According to the time-series traffic feature, a corresponding first detection result can be generated, and the first detection result is used to illustrate whether there is a traffic anomaly in the target traffic data. According to the connection feature, a corresponding second detection result can be generated, and the second detection result is used to illustrate whether there is a connection anomaly in the target traffic data. According to the Flow feature, a corresponding third detection result can be generated, and the third detection result is used to illustrate whether there is an access anomaly in the target traffic data.

[0045] The above-mentioned multiple data features respectively describe the target traffic data from different dimensions. Correspondingly, by combining the detection results corresponding to these multiple data features to determine whether the target traffic data is abnormal traffic data, the accuracy of the determination result can be improved, etc.

[0046] The acquisition methods of the first detection result, the second detection result, and the third detection result are described below respectively.

[0047] 1) First detection result

[0048] In some embodiments of the present disclosure, in response to determining that the data feature is a time-series traffic feature, the time-series traffic feature may be input into a first detection model to obtain the output first detection result.

[0049] The first detection model can be pre-trained. Correspondingly, with the help of the powerful reasoning ability of the first detection model, the accuracy of the obtained first detection result can be improved. For example, training samples can be constructed according to the traffic data obtained from actual operations, and then the first detection model can be trained according to the training samples. The first detection model can predict the change of the time-series traffic feature at different times of each day. Correspondingly, it can be determined whether there is an anomaly in the input time-series traffic feature, and the first detection result can be output accordingly.

[0050] In addition, in some embodiments of the present disclosure, the first detection model may include: a neural network model adopting an inverse transformer (iTransformer) architecture.

[0051] iTransformer is an innovative neural network architecture designed specifically for time series prediction. Compared with traditional Transformer architectures, it adopts an inversion module that can more effectively capture temporal dependencies in sequences, etc. Correspondingly, by using the first detection model with the iTransformer architecture to process time series traffic features, the accuracy of the obtained first detection result can be further improved.

[0052] In practical applications, outputting the first detection result may refer to outputting a first value or a second value. For example, the first value can be 1, indicating that there is a traffic anomaly in the target traffic data, and the second value can be 0, indicating that there is no traffic anomaly in the target traffic data.

[0053] 2) Second detection result

[0054] In some embodiments of the present disclosure, in response to determining that the data feature is a connection feature, the connection feature can be input into the second detection model to obtain the output second detection result.

[0055] In addition, in some embodiments of the present disclosure, the second detection model may include: a neural network model adopting the Extreme Gradient Boosting (XGBoost) architecture.

[0056] The second detection model can be pre-trained. For example, training samples can be constructed based on the traffic data obtained from actual operations, and then the second detection model can be trained based on the training samples. The second detection model can adopt the XGBoost architecture, which is a classic classifier model architecture with many advantages such as fast calculation speed, easy training, and strong fault tolerance. Correspondingly, based on the second detection model adopting the XGBoost architecture, it can efficiently and accurately determine whether there is an anomaly in the input connection feature and output the second detection result accordingly.

[0057] In practical applications, outputting the second detection result may refer to outputting a first value or a second value. For example, the first value can be 1, indicating that there is a connection anomaly in the target traffic data, and the second value can be 0, indicating that there is no connection anomaly in the target traffic data.

[0058] In addition to the above introduction, the first detection model and the second detection model can also be other models, such as common large models. A large model is a super-large-scale language model built based on deep learning technology, which can generate natural language text or understand the meaning of natural language text, etc.

[0059] 3) Third detection result

[0060] In some embodiments of the present disclosure, the Flow feature may include: the request source address corresponding to each access request included in the target traffic data. In this way, in response to determining that the data feature is a Flow feature, each request source address in the Flow feature can be compared with a pre-generated blacklist respectively. In response to determining that any request source address is included in the blacklist, it can be determined that there is an abnormal access situation in the target traffic data, and / or, in response to determining that the occurrence times of any request source address in the Flow feature is greater than a first threshold, it can be determined that there is an abnormal access situation in the target traffic data.

[0061] The specific value of the first threshold can be determined according to actual needs. In addition, the blacklist can be pre-generated and can be updated at any time according to actual needs.

[0062] If it is determined that any request source address is included in the blacklist, then it can be determined that there is an abnormal access situation in the target traffic data. In addition, if it is determined that the occurrence times of any request source address in the Flow feature is greater than the first threshold, that is, it is determined that the access times of the same request source address are too many, it can also be determined that there is an abnormal access situation in the target traffic data.

[0063] If it is determined that there is an abnormal access situation in the target traffic data, a first value can be output. If it is determined that there is no abnormal access situation in the target traffic data, a second value can be output. Among them, the first value can be 1, and the second value can be 0. That is, outputting the third detection result can refer to outputting the first value or the second value.

[0064] In the detection method based on the Flow feature, a neural network model is not required, but the Flow feature is directly analyzed according to a pre-set policy, so that the required third detection result can be determined simply and efficiently.

[0065] Since the detection method based on the Flow feature requires a lot of processing time, such as splitting each access request to obtain the corresponding request source address, and counting the access times of the same request source address and comparing with the threshold, etc., it is mainly applicable to scenarios with low timeliness requirements. In scenarios with high timeliness requirements, the Flow feature may not be obtained, and correspondingly, the third detection result may not be generated.

[0066] After obtaining the anomaly detection results (the first detection result and the second detection result, or the first detection result, the second detection result and the third detection result) corresponding to each data feature respectively, it can be determined whether the target traffic data is abnormal traffic data according to each anomaly detection result.

[0067] In some embodiments of the present disclosure, the number of anomaly detection results meeting the following requirements can be obtained: indicating that there are anomalies in the target traffic data. In response to determining that the number is greater than or equal to a second threshold, the target traffic data is determined to be abnormal traffic data.

[0068] Assume that the anomaly detection results include a first detection result, a second detection result, and a third detection result. Figure 2 It is a flowchart of an embodiment of the method for determining whether the target traffic data is abnormal traffic data according to each anomaly detection result described in the present disclosure. As Figure 2 shown, it includes the following specific implementation manners.

[0069] In step 201, count the number of first values in the first detection result, the second detection result, and the third detection result.

[0070] That is, count the number of anomaly detection results indicating that there are anomalies in the target traffic data.

[0071] In step 202, determine whether the number of first values is greater than or equal to the second threshold. If so, execute step 203; otherwise, execute step 204.

[0072] In step 203, determine that the target traffic data is abnormal traffic data, and then end the process.

[0073] After determining that the target traffic data is abnormal traffic data, it can also be alarmed according to a predetermined alarm method so that relevant personnel can take corresponding defense measures in time.

[0074] In step 204, determine that the target traffic data is normal traffic data, and then end the process.

[0075] The specific value of the second threshold can be determined according to actual needs, which is very flexible and convenient. Among them, if it is necessary to increase the recall quantity of abnormal traffic data and avoid omission, the value of the second threshold can be set smaller. If it is necessary to improve the recall accuracy of abnormal traffic data, the value of the second threshold can be set larger. That is to say, by controlling the value of the second threshold, different usage scenario requirements can be met.

[0076] For example, if it is necessary to recall all abnormal traffic data as much as possible, the value of the second threshold can be set smaller, such as 1. In this way, as long as the value of one anomaly detection result is the first value, the target traffic data can be determined to be abnormal traffic data. If it is necessary to improve the recall accuracy of abnormal traffic data and reduce false recalls, the value of the second threshold can be set larger, such as set to 3. In this way, only when the values of all three anomaly detection results are the first value, will the target traffic data be determined to be abnormal traffic data.

[0077] Combined with the above introduction, Figure 3 This is the flowchart of the second embodiment of the abnormal traffic detection method described in this disclosure. As Figure 3 shown, it includes the following specific implementation manners.

[0078] In step 301, obtain the target traffic data to be detected, and respectively obtain the temporal traffic characteristics, connection characteristics, and Flow characteristics of the target traffic data.

[0079] In practical applications, the target traffic data corresponding to the port to be detected can be generated in real time. For example, the traffic data generated within every 5 seconds can be used as the target traffic data respectively.

[0080] In step 302, input the temporal traffic characteristics into the first detection model to obtain the output first detection result, and the first detection result is used to illustrate whether there is a traffic anomaly in the target traffic data.

[0081] In step 303, input the connection characteristics into the second detection model to obtain the output second detection result, and the second detection result is used to illustrate whether there is a connection anomaly in the target traffic data.

[0082] In step 304, through analyzing the Flow characteristics, determine the third detection result, and the third detection result is used to illustrate whether there is an access anomaly in the target traffic data.

[0083] For example, each request source address in the Flow characteristics can be compared with a pre-generated blacklist respectively. In response to determining that any request source address is included in the blacklist, it is determined that there is an access anomaly in the target traffic data, and / or, in response to determining that the occurrence times of any request source address in the Flow characteristics is greater than the first threshold, it is determined that there is an access anomaly in the target traffic data.

[0084] In step 305, combine the first detection result, the second detection result, and the third detection result to determine whether the target traffic data is abnormal traffic data. If so, execute step 306; otherwise, end the process.

[0085] For example, the number of the first values in the first detection result, the second detection result, and the third detection result can be counted. The first value can represent the existence of an anomaly. Then, the counted number can be compared with the second threshold. If the number is greater than or equal to the second threshold, it can be determined that the target traffic data is abnormal traffic data.

[0086] In step 306, perform an alarm in a predetermined manner, and then end the process.

[0087] There is no limitation on how to perform the alarm. For example, a predetermined alarm sound can be emitted, or the alarm information can be notified to relevant personnel by means of email or text message, etc.

[0088] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should be aware that the present disclosure is not limited by the described action sequence, because according to the present disclosure, certain steps can be performed in other sequences or simultaneously. For example, steps 302, 303, and 304 can be performed in parallel. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present disclosure. In addition, for the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions in other embodiments.

[0089] The above is the introduction of the method embodiments. The following further illustrates the solution of the present disclosure through device embodiments.

[0090] Figure 4 It is a schematic structural diagram of the composition of the abnormal traffic detection device embodiment 400 according to the present disclosure. As Figure 4 shown, it includes: an acquisition module 401, a detection module 402, and a determination module 403.

[0091] The acquisition module 401 is used to acquire the target traffic data to be detected, and respectively acquire M different types of data features of the target traffic data, where M is a positive integer greater than 1.

[0092] The detection module 402 is used to generate abnormal detection results corresponding to various data features respectively according to the abnormal detection methods corresponding to various data features.

[0093] The determination module 403 is used to determine whether the target traffic data is abnormal traffic data according to each abnormal detection result.

[0094] Adopting the solution described in the above device embodiment, for the target detection traffic to be detected, multiple different types of data features can be respectively acquired. Then, abnormal detection results corresponding to various data features can be generated according to the abnormal detection methods corresponding to various data features respectively. Furthermore, it can be determined whether the target traffic data is abnormal traffic data by combining each abnormal detection result. Compared with the traditional abnormal traffic detection method based on a single feature, in the solution described in the above device embodiment, multiple data features can be combined simultaneously to determine whether the target traffic data is abnormal traffic data, thereby improving the accuracy of the abnormal traffic detection result, and can detect different types of attacks in a timely and effective manner, so as to take corresponding defense measures subsequently and improve the security of traffic data, etc.

[0095] In some embodiments of the present disclosure, the M different types of data features may include: temporal traffic features and connection features. The anomaly detection results corresponding to various data features may include: a first detection result corresponding to the temporal traffic features and a second detection result corresponding to the connection features. The first detection result is used to indicate whether there is a traffic anomaly in the target traffic data, and the second detection result is used to indicate whether there is a connection anomaly in the target traffic data.

[0096] In addition, in some embodiments of the present disclosure, the M different types of data features may further include: Flow features. Correspondingly, the anomaly detection results corresponding to various data features may further include: a third detection result corresponding to the Flow features. The third detection result is used to indicate whether there is an access anomaly in the target traffic data.

[0097] In some embodiments of the present disclosure, when the detection module 402 determines that the data feature is a temporal traffic feature, it may input the temporal traffic feature into the first detection model to obtain the output first detection result.

[0098] In some embodiments of the present disclosure, the first detection model may include: a neural network model using the iTransformer architecture.

[0099] In some embodiments of the present disclosure, when the detection module 402 determines that the data feature is a connection feature, it may input the connection feature into the second detection model to obtain the output second detection result.

[0100] In some embodiments of the present disclosure, the second detection model may include: a neural network model using the XGBoost architecture.

[0101] In some embodiments of the present disclosure, the Flow features may include: the request source addresses corresponding to each access request included in the target traffic data. In this way, when the detection module 402 determines that the data feature is a Flow feature, it may compare each request source address in the Flow features with a pre-generated blacklist. When it is determined that any request source address is included in the blacklist, it may be determined that there is an access anomaly in the target traffic data, and / or when it is determined that the occurrence times of any request source address in the Flow features are greater than the first threshold, it may be determined that there is an access anomaly in the target traffic data.

[0102] After obtaining the anomaly detection results (the first detection result and the second detection result, or the first detection result, the second detection result, and the third detection result) corresponding to each data feature respectively, the determination module 403 may determine whether the target traffic data is abnormal traffic data according to each anomaly detection result.

[0103] In some embodiments of the present disclosure, the determination module 403 may obtain the number of anomaly detection results that meet the following requirements: indicating that there are anomalies in the target traffic data. In response to determining that the number is greater than or equal to the second threshold, it is determined that the target traffic data is abnormal traffic data.

[0104] Figure 4 The specific working process of the device embodiments shown can refer to the relevant descriptions in the foregoing method embodiments.

[0105] In summary, by adopting the solution described in the present disclosure, multi-dimensional abnormal traffic detection based on an artificial intelligence model can be achieved, a comprehensive abnormal traffic detection mechanism is constructed, almost all data features of the traffic data are utilized, and driven by the data features, timely and accurate judgments can be made on different types of traffic attacks, so as to quickly take corresponding defense measures subsequently, thereby improving the security of the traffic data. Moreover, it can be applied to different business scenarios and has wide applicability, etc.

[0106] The solution described in the present disclosure can be applied to the field of artificial intelligence, especially in the fields of network security, deep learning, and large models. Artificial intelligence is a discipline that studies how to make a computer simulate certain thinking processes and intelligent behaviors of humans (such as learning, reasoning, thinking, planning, etc.). It has both hardware-level technologies and software-level technologies. Artificial intelligence hardware technologies generally include technologies such as sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, and big data processing. Artificial intelligence software technologies mainly include several major directions such as computer vision technology, speech recognition technology, natural language processing technology, and machine learning / deep learning, big data processing technology, and knowledge graph technology.

[0107] In addition, the traffic data and the like in the embodiments described in the present disclosure are not targeted at a specific user and do not reflect the personal information of a specific user. In the technical solution of the present disclosure, the collection, storage, use, processing, transmission, provision, and disclosure of the user's personal information and other processes all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.

[0108] According to the embodiments of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.

[0109] Figure 5FIG. 0 shows a schematic block diagram of an electronic device 500 that can be used to implement embodiments of the present disclosure. The electronic device is intended to represent various forms of digital computers, such as, for example, laptop computers, desktop computers, workstations, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, for example, personal digital assistants, cellular telephones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementations of the present disclosure described and / or claimed herein.

[0110] As Figure 5 shown, the electronic device 500 includes a computing unit 501 that can perform various appropriate actions and processes in accordance with a computer program stored in a read-only memory (ROM) 502 or a computer program loaded from a storage unit 508 into a random access memory (RAM) 503. In the RAM 503, various programs and data required for the operation of the electronic device 500 can also be stored. The computing unit 501, the ROM 502, and the RAM 503 are connected to each other via a bus 504. An input / output (I / O) interface 505 is also connected to the bus 504.

[0111] A plurality of components in the electronic device 500 are connected to the I / O interface 505, including: an input unit 506, such as, for example, a keyboard, a mouse, etc.; an output unit 507, such as, for example, various types of displays, speakers, etc.; a storage unit 508, such as, for example, a magnetic disk, an optical disk, etc.; and a communication unit 509, such as, for example, a network card, a modem, a wireless communication transceiver, etc. The communication unit 509 allows the electronic device 500 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0112] The computing unit 501 may be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 501 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 501 executes the various methods and processes described above, such as the methods described in this disclosure. For example, in some embodiments, the methods described in this disclosure may be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 508. In some embodiments, part or all of the computer program may be loaded and / or installed onto the electronic device 500 via the ROM 502 and / or the communication unit 509. When the computer program is loaded into the RAM 503 and executed by the computing unit 501, one or more steps of the methods described in this disclosure may be executed. Alternatively, in other embodiments, the computing unit 501 may be configured to execute the methods described in this disclosure by any other suitable means (e.g., by means of firmware).

[0113] The various embodiments of the systems and techniques described above in this document may be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard parts (ASSPs), system on chip systems (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include: implemented in one or more computer programs that may be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a special-purpose or general-purpose programmable processor that receives data and instructions from a storage system, at least one input device, and at least one output device, and transmits the data and instructions to the storage system, the at least one input device, and the at least one output device.

[0114] The program code for implementing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing devices, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowchart and / or block diagram are implemented. The program codes can be executed entirely on the machine, partially on the machine, executed partially on the machine as an independent software package and partially on a remote machine, or executed entirely on a remote machine or server.

[0115] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory, a read-only memory, an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0116] In order to provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a cathode ray tube (CRT) or a liquid crystal display (LCD) monitor); and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the computer. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and the input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0117] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.

[0118] A computer system can include a client and a server. The client and the server are generally far from each other and typically interact through a communication network. The client-server relationship is generated by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, can also be a server of a distributed system, or a server incorporating a blockchain.

[0119] It should be understood that various forms of the processes shown above can be used, steps can be reordered, added, or deleted. For example, the steps recited in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and this is not limited herein.

[0120] The above specific embodiments do not constitute a limitation on the protection scope of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the protection scope of this disclosure.

Claims

1. A method for detecting abnormal traffic, comprising: Obtain target flow data to be detected, and respectively obtain M different types of data features of the target flow data, where M is a positive integer greater than 1; Generate anomaly detection results corresponding to various data features according to anomaly detection methods corresponding to various data features; Whether the target flow data is abnormal flow data is determined according to each abnormality detection result.

2. The method according to claim 1, wherein: The M different types of data features include: time series flow features and connection features; The abnormality detection result includes: a first detection result corresponding to the timing traffic feature and a second detection result corresponding to the connection feature. The first detection result is used to indicate whether there is a traffic abnormality in the target traffic data, and the second detection result is used to indicate whether there is a connection abnormality in the target traffic data.

3. The method according to claim 2, wherein: The M different types of data features also include: flow features; The abnormal detection result also includes: a third detection result corresponding to the flow feature, and the third detection result is used to indicate whether there is an access abnormality in the target traffic data.

4. The method according to claim 2, wherein: The generating of the anomaly detection results corresponding to various data features according to the anomaly detection methods corresponding to various data features respectively includes: In response to determining that the data feature is the time series traffic feature, the time series traffic feature is input into a first detection model to obtain the first detection result as an output.

5. The method according to claim 4, wherein: The first detection model includes: a neural network model using an inverter converter architecture.

6. The method according to claim 2, wherein: The generating of the anomaly detection results corresponding to various data features according to the anomaly detection methods corresponding to various data features respectively includes: In response to determining that the data feature is the connection feature, the connection feature is input into a second detection model to obtain the second detection result as output.

7. The method according to claim 6, wherein: The second detection model includes: a neural network model using an extreme gradient boosting architecture.

8. The method according to claim 3, wherein: The flow characteristics include: a request source address corresponding to each access request included in the target traffic data; The generating of the anomaly detection results corresponding to various data features according to the anomaly detection methods corresponding to various data features respectively includes: In response to determining that the data feature is the flow feature, each request source address in the flow feature is compared with a pre-generated blacklist, and in response to determining that any request source address is included in the blacklist, it is determined that the access anomaly exists in the target traffic data, and / or in response to determining that the number of occurrences of any request source address in the flow feature is greater than a first threshold, it is determined that the access anomaly exists in the target traffic data.

9. The method according to claim 3, wherein: Determining whether the target flow data is abnormal flow data according to each abnormality detection result includes: Obtain the number of anomaly detection results that meet the following requirements: indicating that anomalies exist in the target traffic data; In response to determining that the number is greater than or equal to a second threshold, determining that the target traffic data is the abnormal traffic data.

10. An abnormal flow detection device, comprising: Acquisition module, detection module and determination module; The acquisition module is used to acquire the target flow data to be detected, and respectively acquire M different types of data features of the target flow data, where M is a positive integer greater than 1; The detection module is used to generate anomaly detection results corresponding to various data features according to the anomaly detection methods corresponding to various data features; The determination module is used to determine whether the target flow data is abnormal flow data according to each abnormality detection result.

11. An electronic device, comprising: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 9.

12. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to make a computer execute the method according to any one of claims 1 to 9.

13. A computer program product, comprising a computer program / instruction, wherein when the computer program / instruction is executed by a processor, the method according to any one of claims 1 to 9 is implemented.

Citation Information

Cited By

  • Method, device and equipment for identifying abnormal water quantity source of drainage pipe network and storage medium

    CN120910776A

  • Traffic monitoring method and device, electronic equipment and storage medium

    CN121098532A