Communication data transmission security monitoring system
By distributing processing and abnormal judgment of multi-source communication data, the shortcomings of communication data transmission systems in the prior art in terms of security and real-time performance are solved, and higher data transmission accuracy and reliability are achieved.
Patent Information
- Application Number
- CN202510586000.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-08
- Publication Date
- 2025-06-06
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing communication data transmission system has shortcomings in terms of security and real-time performance, and cannot effectively monitor abnormal data transmission conditions, resulting in risks in data use.
By distributing the multi-source communication data, the abnormality judgment result of the associated outlier value M and the traffic information A and the abnormality judgment result of the IP address B are jointly judged by the abnormality status of the data packet, and targeted processing is made based on the abnormality degree.
It improves the accuracy and reliability of communication data transmission, can quickly detect abnormalities and perform targeted processing in high concurrent data transmission scenarios, reducing network bandwidth pressure.
Smart Images

Figure CN120110801A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of security monitoring, and in particular to a communication data transmission security monitoring system. Background Art
[0002] With the rapid development of information technology, communication data transmission is increasingly used in industrial control, Internet of Things, cloud computing and other fields. These fields have extremely high requirements for the real-time, integrity and confidentiality of data, because any abnormality in the data will affect the reliable operation of the automation control system, and even lead to the failure of key infrastructure or the leakage of user privacy.
[0003] However, the existing communication and data transmission systems have many deficiencies in terms of security. First, traditional monitoring solutions mostly adopt a centralized data processing architecture, which requires massive communication data to be transmitted back to the central server for offline analysis. This method not only increases the pressure on network bandwidth, but also causes detection delays in high-concurrency data transmission scenarios, and cannot meet real-time requirements. Secondly, existing communication and data transmission systems often lack accurate monitoring mechanisms and cannot monitor the degree of data transmission anomalies. Once a problem occurs during data transmission, it is impossible to make targeted processing based on the degree of data transmission anomalies, which brings great risks to the use of data. Summary of the invention
[0004] In view of the above situation, the present invention distributes and processes multi-source communication data, and jointly determines the abnormality degree of the data packet by associating the abnormal value M and the abnormal judgment result of the traffic information A and the abnormal judgment result of the IP address B, and makes targeted processing according to the abnormality degree of the data packet, thereby improving the accuracy and reliability of communication data transmission.
[0005] The technical solution includes a data acquisition module, a distributed processing module, an intelligent detection module and a collaborative management module. The data acquisition module captures multi-source communication data packets in real time, marks the data source device identifier and timestamp, and removes noise and redundant information in the data. The distribution processing module extracts the source IP, destination IP, source port, destination port, and protocol type of the communication data packet as hash keywords, and maps the keywords and nodes to a consistent hash ring; Each physical node is allocated N virtual nodes on the ring, N = 200 × node storage capacity / TB, calculates the keyword hash value and locates the nearest virtual node on the ring, stores the data packet in the corresponding physical node, and generates 3 copies to store in the clockwise adjacent nodes; The intelligent detection module extracts the flow information A and IP address B of the communication data packet, where the flow information A includes the number of bytes A1, the transmission frequency A2 and the flow mode A3, and the IP address B includes the source address B1, the destination address B2 and the access mode B3, and calculates the abnormal value A4 of the flow information A and the abnormal value B4 of the IP address B; The collaborative management module calculates the associated abnormal value M, M = A4×0.4+ B4×0.6+ε, where ε is the error correction value of the associated abnormal value M, and jointly determines the abnormal degree of the data packet by combining the associated abnormal value M with the abnormal judgment result of the traffic information A and the abnormal judgment result of the IP address B.
[0006] Furthermore, in the intelligent detection module, M is greater than 0.6, indicating that the data packet is abnormal, and the degree of abnormality is divided into three cases. At this time, the flow information A is abnormal and the IP address B is abnormal, which is marked as a high-risk abnormality; When traffic information A is normal but IP address B is abnormal, it is marked as the first medium-risk abnormality; When traffic information A is abnormal and IP address B is normal, it is marked as the second medium-risk abnormality; M is less than or equal to 0.6, indicating that the data packet is normal. At this time, when the traffic information A is normal and the IP address B is abnormal, it is marked as the first low-risk abnormality; When traffic information A is abnormal and IP address B is normal, it is marked as the second lowest risk abnormality; When traffic information A is normal and IP address B is normal, it is marked as normal.
[0007] Furthermore, a self-healing control module is included. When the self-healing control module receives a high-risk exception, it immediately blocks the transmission of the data packet, discards all data from the source IP address B, and triggers a security alarm to notify the network security team to conduct an emergency response and investigation, and marks the IP address B on the blacklist; When the first medium-risk exception occurs, the speed of IP address B is limited, and dynamic token bucket speed limiting is implemented. The initial rate is set to 2Mbps. Each time an exception is triggered, the rate is reduced by 50% to 128Kbps. If the first medium-risk exception is triggered three times in a row, IP address B will be added to the temporary blacklist, which is valid for 24 hours. When the second medium-risk anomaly occurs, traffic information A is discarded, an alarm message is sent to the user, the data packet is resent, and the number of IP address B anomalies is recorded. If the second medium-risk anomaly is triggered three times in a row, IP address B is added to the temporary blacklist, which is valid for 24 hours. When the first low-risk anomaly occurs, IP address B is marked, and an anomaly message of IP address B is sent to the user. The number of anomalies of IP address B is recorded. If the first low-risk anomaly is triggered three times in a row, it is upgraded to the first medium-risk anomaly. When the second low-risk abnormality occurs, the transmission channel is changed and the number of abnormalities of flow information A is recorded. If the second low-risk abnormality is triggered three times in a row, it is upgraded to the second medium-risk abnormality. Under normal circumstances, multi-source communication data packets are transmitted normally and the system operates normally.
[0008] Furthermore, the distribution processing module uses the SHA-256 algorithm to generate virtual node identifiers, which are evenly distributed in the ring space [0,2^128); Then the hash value of the data packet keyword is calculated and located to the nearest virtual node on the ring, generating a data-node mapping table; Finally, the storage load of each node is monitored, and when the node load difference exceeds 20%, the virtual node redistribution is triggered.
[0009] Furthermore, the distribution processing module extracts a characteristic keyword set K={k1, k2, ..., kn} from the data packet, and each keyword is mapped to a coordinate on the ring through a hash function; Select the median of all keyword coordinates as the data packet storage location; A replication mechanism is used to store data copies in three clockwise adjacent virtual nodes.
[0010] Further, the intelligent detection module extracts the corresponding byte number threshold A11 and transmission frequency threshold A21 from the database according to the IP address B, and calculates the byte number quantization value A12, A12=(A1-A11)÷A11, and the transmission frequency quantization value A22, A22=(A2-A21)÷A21; When the traffic mutation detection exceeds the abnormal traffic threshold of 50% for 10 seconds, the traffic pattern A3 is marked as abnormal traffic, and the traffic pattern quantization value A31 is 1. Otherwise, if the traffic pattern is normal, A31 is 0. Calculate the abnormal value A4 of the traffic information A, A4=A12×0.3+A22×0.3+A31×0.4, where when A1 is less than A11, the number of bytes is normal and A12 is 0; when A2 is less than A21, the transmission frequency is normal and A22 is 0; and when A4 is greater than 0.7, it indicates that the traffic information A is abnormal; otherwise, it indicates that the traffic information A is normal.
[0011] Furthermore, the intelligent detection module retrieves the blacklist of IP address B in the database, and compares the source address B1. If it is in the blacklist, the quantized value B11 of the source address is 1, otherwise, B11 is 0. If the target address B2 is in the blacklist, the quantized value B21 of the target address is 1, otherwise, B21 is 0. At the same time, an access relationship graph of IP address B is constructed. When the same IP address B is frequently connected to different target ports, it is identified as an abnormal access mode. The quantized value B31 of access mode B3 is 1, otherwise, the quantized value B31 of access mode B3 is 0. Finally, the abnormal value B4 of IP address B is calculated, B4=B11×0.3+B21×0.3+B31×0.4. If B4 is greater than 0.6, it means that IP address B is abnormal. Otherwise, it means that IP address B is normal.
[0012] Furthermore, the data acquisition module uses a wavelet transform filtering algorithm to remove electromagnetic interference noise, detects repeated data packets based on a time sliding window, and eliminates redundant information.
[0013] Furthermore, it also includes a feedback optimization module, which compares the abnormal judgment result of the collaborative management module with the actual communication data transmission result. If the comparison results are the same, the abnormal judgment result this time is marked as a correct sample, otherwise, it is marked as an incorrect sample. The correct samples and / or incorrect samples are stored in a database, and machine learning is performed on the sample data to update and optimize the abnormal value A4 of the traffic information A, the abnormal value B4 of the IP address B and the weight value of the associated abnormal value M in the system.
[0014] Due to the adoption of the above technical solution, the present invention has the following advantages compared with the prior art: 1. Through the distribution processing of multi-source communication data, multi-source communication data packets are distributed in different physical nodes, and each physical node is allocated N virtual nodes on the ring for separate storage and calculation, which reduces the pressure on network bandwidth and improves detection efficiency in high-concurrency data transmission scenarios; 2. The abnormal value M is associated with the abnormal judgment result of the traffic information A and the abnormal judgment result of the IP address B to jointly judge the abnormality degree of the data packet, and targeted processing is performed according to the abnormality degree of the data packet, thereby improving the accuracy and reliability of communication data transmission. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 The present invention is a flow chart of a communication data transmission security monitoring system. DETAILED DESCRIPTION
[0016] The above and other technical contents, features and effects of the present invention are described in detail below with reference to the attached Figure 1 The detailed description of the embodiments will clearly show that the structural contents mentioned in the following embodiments are all based on the drawings in the specification.
[0017] Embodiment 1, based on the existing technology, in order to prevent the centralized data processing architecture, and at the same time accurately distinguish the abnormal state degree of the communication data packet, includes a data acquisition module, a distributed processing module, an intelligent detection module and a collaborative management module, the data acquisition module captures multi-source communication data packets in real time, and marks the data source device identifier and timestamp, and removes noise and redundant information in the data; The distribution processing module extracts the source IP, destination IP, source port, destination port, and protocol type of the communication data packet as hash keywords, and maps the keywords and nodes to a consistent hash ring; Each physical node is allocated N virtual nodes on the ring, N = 200 × node storage capacity / TB, calculates the keyword hash value and locates the nearest virtual node on the ring, stores the data packet in the corresponding physical node, and generates 3 copies to store in the clockwise adjacent nodes; The intelligent detection module extracts the flow information A and IP address B of the communication data packet, where the flow information A includes the number of bytes A1, the transmission frequency A2 and the flow mode A3, and the IP address B includes the source address B1, the destination address B2 and the access mode B3, and calculates the abnormal value A4 of the flow information A and the abnormal value B4 of the IP address B; The collaborative management module calculates the associated abnormal value M, M = A4×0.4+ B4×0.6+ε, where ε is the error correction value of the associated abnormal value M, and jointly determines the abnormal degree of the data packet by combining the associated abnormal value M with the abnormal judgment result of the traffic information A and the abnormal judgment result of the IP address B.
[0018] Furthermore, in the intelligent detection module, M is greater than 0.6, indicating that the data packet is abnormal, and the degree of abnormality is divided into three cases. At this time, the flow information A is abnormal and the IP address B is abnormal, which is marked as a high-risk abnormality; When traffic information A is normal but IP address B is abnormal, it is marked as the first medium-risk abnormality; When traffic information A is abnormal and IP address B is normal, it is marked as the second medium-risk abnormality; M is less than or equal to 0.6, indicating that the data packet is normal. At this time, when the traffic information A is normal and the IP address B is abnormal, it is marked as the first low-risk abnormality; When traffic information A is abnormal and IP address B is normal, it is marked as the second lowest risk abnormality; When traffic information A is normal and IP address B is normal, it is marked as normal.
[0019] Furthermore, a self-healing control module is included. When the self-healing control module receives a high-risk exception, it immediately blocks the transmission of the data packet, discards all data from the source IP address B, and triggers a security alarm to notify the network security team to conduct an emergency response and investigation, and marks the IP address B on the blacklist; When the first medium-risk exception occurs, the speed of IP address B is limited, and dynamic token bucket speed limiting is implemented. The initial rate is set to 2Mbps. Each time an exception is triggered, the rate is reduced by 50% to 128Kbps. If the first medium-risk exception is triggered three times in a row, IP address B will be added to the temporary blacklist, which is valid for 24 hours. When the second medium-risk anomaly occurs, traffic information A is discarded, an alarm message is sent to the user, the data packet is resent, and the number of IP address B anomalies is recorded. If the second medium-risk anomaly is triggered three times in a row, IP address B is added to the temporary blacklist, which is valid for 24 hours. When the first low-risk anomaly occurs, IP address B is marked, and an anomaly message of IP address B is sent to the user. The number of anomalies of IP address B is recorded. If the first low-risk anomaly is triggered three times in a row, it is upgraded to the first medium-risk anomaly. When the second low-risk abnormality occurs, the transmission channel is changed and the number of abnormalities of flow information A is recorded. If the second low-risk abnormality is triggered three times in a row, it is upgraded to the second medium-risk abnormality. Under normal circumstances, multi-source communication data packets are transmitted normally and the system operates normally.
[0020] The distribution processing module uses the SHA-256 algorithm to generate virtual node identifiers, which are evenly distributed in the ring space [0, 2^128); Then the hash value of the data packet keyword is calculated and located to the nearest virtual node on the ring, generating a data-node mapping table; Finally, the storage load of each node is monitored, and when the node load difference exceeds 20%, the virtual node redistribution is triggered.
[0021] The distribution processing module extracts a characteristic keyword set K={k1, k2, ..., kn} from the data packet, and each keyword is mapped to a coordinate on the ring through a hash function; Select the median of all keyword coordinates as the data packet storage location; A replication mechanism is used to store data copies in three clockwise adjacent virtual nodes.
[0022] The intelligent detection module extracts the corresponding byte number threshold A11 and transmission frequency threshold A21 from the database according to the IP address B, and calculates the byte number quantization value A12, A12=(A1-A11)÷A11, and the transmission frequency quantization value A22, A22=(A2-A21)÷A21; When the traffic mutation detection exceeds the abnormal traffic threshold of 50% for 10 seconds, the traffic pattern A3 is marked as abnormal traffic, and the traffic pattern quantization value A31 is 1. Otherwise, if the traffic pattern is normal, A31 is 0. Calculate the abnormal value A4 of the traffic information A, A4=A12×0.3+A22×0.3+A31×0.4, where when A1 is less than A11, the number of bytes is normal and A12 is 0; when A2 is less than A21, the transmission frequency is normal and A22 is 0; and when A4 is greater than 0.7, it indicates that the traffic information A is abnormal; otherwise, it indicates that the traffic information A is normal.
[0023] The intelligent detection module retrieves the blacklist of IP address B in the database, and compares the source address B1. If it is in the blacklist, the quantized value B11 of the source address is 1, otherwise, B11 is 0. If the target address B2 is in the blacklist, the quantized value B21 of the target address is 1, otherwise, B21 is 0. At the same time, an access relationship graph of IP address B is constructed. When the same IP address B is frequently connected to different target ports, it is identified as an abnormal access mode. The quantized value B31 of access mode B3 is 1, otherwise, the quantized value B31 of access mode B3 is 0. Finally, the abnormal value B4 of IP address B is calculated, B4=B11×0.3+B21×0.3+B31×0.4. If B4 is greater than 0.6, it means that IP address B is abnormal. Otherwise, it means that IP address B is normal.
[0024] The data acquisition module uses a wavelet transform filtering algorithm to remove electromagnetic interference noise, detects repeated data packets based on a time sliding window, and eliminates redundant information.
[0025] The feedback optimization module compares the abnormal judgment result of the collaborative management module with the actual communication data transmission result. If the comparison result is the same, the abnormal judgment result is marked as a correct sample. Otherwise, it is marked as an incorrect sample. The correct sample and / or incorrect sample are stored in the database, and machine learning is performed on the sample data to update and optimize the abnormal value A4 of the traffic information A, the abnormal value B4 of the IP address B and the weight value of the associated abnormal value M in the system.
[0026] When the present invention is used specifically, based on the prior art, the data acquisition module captures multi-source communication data packets in real time, marks the data source device identifier and timestamp, and removes noise and redundant information in the data; The distribution processing module extracts the source IP, destination IP, source port, destination port, and protocol type of the communication data packet as hash keywords, and maps the keywords and nodes to a consistent hash ring; Each physical node is allocated N virtual nodes on the ring, N = 200 × node storage capacity / TB, calculates the keyword hash value and locates the nearest virtual node on the ring, stores the data packet in the corresponding physical node, and generates 3 copies to store in the clockwise adjacent nodes; The intelligent detection module extracts the flow information A and IP address B of the communication data packet, where the flow information A includes the number of bytes A1, the transmission frequency A2 and the flow mode A3, and the IP address B includes the source address B1, the destination address B2 and the access mode B3, and calculates the abnormal value A4 of the flow information A and the abnormal value B4 of the IP address B; The collaborative management module calculates the associated abnormal value M, M = A4×0.4+ B4×0.6+ε, where ε is the error correction value of the associated abnormal value M, and jointly determines the abnormal degree of the data packet by combining the associated abnormal value M with the abnormal judgment result of the traffic information A and the abnormal judgment result of the IP address B.
[0027] In the intelligent detection module, M is greater than 0.6, indicating that the data packet is abnormal. The degree of abnormality is divided into three cases. At this time, the flow information A is abnormal and the IP address B is abnormal, which is marked as a high-risk abnormality; When traffic information A is normal but IP address B is abnormal, it is marked as the first medium-risk abnormality; When traffic information A is abnormal and IP address B is normal, it is marked as the second medium-risk abnormality; M is less than or equal to 0.6, indicating that the data packet is normal. At this time, when the traffic information A is normal and the IP address B is abnormal, it is marked as the first low-risk abnormality; When traffic information A is abnormal and IP address B is normal, it is marked as the second lowest risk abnormality; When traffic information A is normal and IP address B is normal, it is marked as normal.
[0028] When the self-healing control module receives a high-risk exception, it immediately blocks the transmission of the data packet, discards all data from the source IP address B, and triggers a security alarm, notifying the network security team to conduct an emergency response and investigation, and marking IP address B on the blacklist; When the first medium-risk exception occurs, the speed of IP address B is limited, and dynamic token bucket speed limiting is implemented. The initial rate is set to 2Mbps. Each time an exception is triggered, the rate is reduced by 50% to 128Kbps. If the first medium-risk exception is triggered three times in a row, IP address B will be added to the temporary blacklist, which is valid for 24 hours. When the second medium-risk anomaly occurs, traffic information A is discarded, an alarm message is sent to the user, the data packet is resent, and the number of IP address B anomalies is recorded. If the second medium-risk anomaly is triggered three times in a row, IP address B is added to the temporary blacklist, which is valid for 24 hours. When the first low-risk anomaly occurs, IP address B is marked, and an anomaly message of IP address B is sent to the user. The number of anomalies of IP address B is recorded. If the first low-risk anomaly is triggered three times in a row, it is upgraded to the first medium-risk anomaly. When the second low-risk abnormality occurs, the transmission channel is changed and the number of abnormalities of flow information A is recorded. If the second low-risk abnormality is triggered three times in a row, it is upgraded to the second medium-risk abnormality. In normal times, multi-source communication data packets are transmitted normally and the system works normally. By adopting the above method, multi-source communication data is distributed and processed, and the abnormality degree of the data packet is jointly judged by the associated abnormal value M and the abnormal judgment result of the flow information A and the abnormal judgment result of the IP address B, and targeted processing is made according to the abnormality degree of the data packet, thereby improving the accuracy and reliability of communication data transmission.
[0029] The above is a further detailed description of the present invention in combination with a specific implementation method, and it cannot be determined that the specific implementation of the present invention is limited to this; for technical personnel in the technical field to which the present invention belongs and related technical fields, based on the technical solution of the present invention, the expansion and replacement of operating methods and data should all fall within the protection scope of the present invention.
Claims
1. A communication data transmission security monitoring system, characterized in that: It includes a data acquisition module, a distributed processing module, an intelligent detection module and a collaborative management module. The data acquisition module captures multi-source communication data packets in real time, marks the data source device identifier and timestamp, and removes noise and redundant information in the data; The distribution processing module extracts the source IP, destination IP, source port, destination port, and protocol type of the communication data packet as hash keywords, and maps the keywords and nodes to a consistent hash ring; Each physical node is allocated N virtual nodes on the ring, N = 200 × node storage capacity / TB, calculates the keyword hash value and locates the nearest virtual node on the ring, stores the data packet in the corresponding physical node, and generates 3 copies to store in the clockwise adjacent nodes; The intelligent detection module extracts the flow information A and IP address B of the communication data packet, where the flow information A includes the number of bytes A1, the transmission frequency A2 and the flow mode A3, and the IP address B includes the source address B1, the destination address B2 and the access mode B3, and calculates the abnormal value A4 of the flow information A and the abnormal value B4 of the IP address B; The collaborative management module calculates the associated abnormal value M, M = A4×0.4+ B4×0.6+ε, where ε is the error correction value of the associated abnormal value M, and jointly determines the abnormal degree of the data packet by combining the associated abnormal value M with the abnormal judgment result of the traffic information A and the abnormal judgment result of the IP address B.
2. A communication data transmission security monitoring system according to claim 1, characterized in that: In the intelligent detection module, M is greater than 0.6, indicating that the data packet is abnormal. The degree of abnormality is divided into three cases. At this time, the flow information A is abnormal and the IP address B is abnormal, which is marked as a high-risk abnormality; When traffic information A is normal but IP address B is abnormal, it is marked as the first medium-risk abnormality; When traffic information A is abnormal and IP address B is normal, it is marked as the second medium-risk abnormality; M is less than or equal to 0.6, indicating that the data packet is normal. At this time, when the traffic information A is normal and the IP address B is abnormal, it is marked as the first low-risk abnormality; When traffic information A is abnormal and IP address B is normal, it is marked as the second lowest risk abnormality; When traffic information A is normal and IP address B is normal, it is marked as normal.
3. A communication data transmission security monitoring system according to claim 2, characterized in that: It also includes a self-healing control module. When the self-healing control module receives a high-risk exception, it immediately blocks the transmission of the data packet, discards all data from the source IP address B, and triggers a security alarm to notify the network security team to conduct an emergency response and investigation, and marks the IP address B on the blacklist; When the first medium-risk exception occurs, the speed of IP address B is limited, and dynamic token bucket speed limiting is implemented. The initial rate is set to 2Mbps. Each time an exception is triggered, the rate is reduced by 50% to 128Kbps. If the first medium-risk exception is triggered three times in a row, IP address B will be added to the temporary blacklist, which is valid for 24 hours. When the second medium-risk anomaly occurs, traffic information A is discarded, an alarm message is sent to the user, the data packet is resent, and the number of IP address B anomalies is recorded. If the second medium-risk anomaly is triggered three times in a row, IP address B is added to the temporary blacklist, which is valid for 24 hours. When the first low-risk anomaly occurs, IP address B is marked, and an anomaly message of IP address B is sent to the user. The number of anomalies of IP address B is recorded. If the first low-risk anomaly is triggered three times in a row, it is upgraded to the first medium-risk anomaly. When the second low-risk abnormality occurs, the transmission channel is changed and the number of abnormalities of flow information A is recorded. If the second low-risk abnormality is triggered three times in a row, it is upgraded to the second medium-risk abnormality. Under normal circumstances, multi-source communication data packets are transmitted normally and the system operates normally.
4. A communication data transmission security monitoring system according to claim 1, characterized in that: The distribution processing module uses the SHA-256 algorithm to generate virtual node identifiers, which are evenly distributed in the ring space [0, 2^128); Then the hash value of the data packet keyword is calculated and located to the nearest virtual node on the ring, generating a data-node mapping table; Finally, the storage load of each node is monitored, and when the node load difference exceeds 20%, the virtual node redistribution is triggered.
5. A communication data transmission security monitoring system according to claim 4, characterized in that: The distribution processing module extracts a characteristic keyword set K={k1, k2, ..., kn} from the data packet, and each keyword is mapped to a coordinate on the ring through a hash function; Select the median of all keyword coordinates as the data packet storage location; A replication mechanism is used to store data copies in three clockwise adjacent virtual nodes.
6. A communication data transmission security monitoring system according to claim 1, characterized in that: The intelligent detection module extracts the corresponding byte number threshold A11 and transmission frequency threshold A21 from the database according to the IP address B, and calculates the byte number quantization value A12, A12=(A1-A11)÷A11, and the transmission frequency quantization value A22, A22=(A2-A21)÷A21; When the traffic mutation detection exceeds the abnormal traffic threshold of 50% for 10 seconds, the traffic pattern A3 is marked as abnormal traffic, and the traffic pattern quantization value A31 is 1. Otherwise, if the traffic pattern is normal, A31 is 0. Calculate the abnormal value A4 of the traffic information A, A4=A12×0.3+A22×0.3+A31×0.4, where when A1 is less than A11, the number of bytes is normal and A12 is 0; when A2 is less than A21, the transmission frequency is normal and A22 is 0; and when A4 is greater than 0.7, it indicates that the traffic information A is abnormal; otherwise, it indicates that the traffic information A is normal.
7. A communication data transmission security monitoring system according to claim 6, characterized in that: The intelligent detection module retrieves the blacklist of IP address B in the database, and compares the source address B1. If it is in the blacklist, the quantized value B11 of the source address is 1, otherwise, B11 is 0. If the target address B2 is in the blacklist, the quantized value B21 of the target address is 1, otherwise, B21 is 0. At the same time, an access relationship graph of IP address B is constructed. When the same IP address B is frequently connected to different target ports, it is identified as an abnormal access mode. The quantized value B31 of access mode B3 is 1, otherwise, the quantized value B31 of access mode B3 is 0. Finally, the abnormal value B4 of IP address B is calculated, B4=B11×0.3+B21×0.3+B31×0.
4. If B4 is greater than 0.6, it means that IP address B is abnormal. Otherwise, it means that IP address B is normal.
8. A communication data transmission security monitoring system according to claim 1, characterized in that: The data acquisition module uses a wavelet transform filtering algorithm to remove electromagnetic interference noise, detects repeated data packets based on a time sliding window, and eliminates redundant information.
9. A communication data transmission security monitoring system according to any one of claims 1 to 8, characterized in that: It also includes a feedback optimization module, which compares the abnormal judgment result of the collaborative management module with the actual communication data transmission result. If the comparison result is the same, the abnormal judgment result this time is marked as a correct sample, otherwise, it is marked as an incorrect sample. The correct sample and / or incorrect sample are stored in a database, and machine learning is performed on the sample data to update and optimize the abnormal value A4 of the traffic information A, the abnormal value B4 of the IP address B and the weight value of the associated abnormal value M in the system.
Citation Information
Patent Citations
Abnormal traffic detection method and system, electronic equipment and storage medium
CN115550056A
Data processing method and system for network security operation based on big data
CN117640257A
Remote office network security protection method and system based on big data
CN119728311A