Section probe tool realized based on AOP and risk monitoring method

By using AOP-based sectional probe tools and AI intelligent engine risk monitoring methods in network applications, the problem of difficulty in perceiving security risks in network traffic in the prior art is solved, high-strength and low-loss network risk monitoring is achieved, and network security protection is improved.

CN120110967APending Publication Date: 2025-06-06NANTONG SUPER LIMIT KAIHONG TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510259952.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

The prior art is difficult to timely perceive potential security risks and monitoring blind spots when network traffic enters the application, making it difficult to ensure network security.

Method used

Using AOP (sectional-oriented programming)-based sectional probe tools and risk monitoring methods, through AI intelligent engine and dynamic monitoring deployment, network requests are monitored and analyzed in real time, and flexible risk thresholds and intelligent alarm mechanisms are set to realize full-link tracking and traceability.

Benefits of technology

It realizes high-intensity risk monitoring in low-loss state, improves the accurate perception of network security threats, reduces false alarms and missed reports, and ensures system stability and data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120110967A_ABST
    Figure CN120110967A_ABST
Patent Text Reader

Abstract

The invention discloses a section probe tool realized based on an AOP (automatic optical path) and a risk monitoring method, and relates to the technical field of network index monitoring, in particular to the section probe tool realized based on the AOP and the risk monitoring method. The section probe tool comprises a section service module, a section base, a section base API, a section service module management platform, an operation and maintenance management platform and a monitoring platform, the AOP-based section probe tool and the risk monitoring method quote an AI intelligent engine, an AI model realizes a self-optimization monitoring strategy through attack mode learning and behavior baseline verification, and the AI model realizes the risk monitoring of the section probe tool. High-strength risk monitoring is achieved in a low-loss state, meanwhile, the effectiveness of model training can be improved through data quality access control, it is ensured that the model is not degraded through model updating fusing, misjudgment is reduced through behavior baseline verification, and the accuracy and stability of dynamic monitoring are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of network indicator monitoring, and in particular to an aspect probe tool and a risk monitoring method based on AOP. Background Art

[0002] A network monitoring device refers to a hardware or software tool used to monitor, analyze and manage computer network traffic, security, performance and device status. Network monitoring can help detect potential network failures, security vulnerabilities, performance bottlenecks and other problems, thereby ensuring the normal operation of the network system.

[0003] The patent with the patent announcement number CN102111307B relates to a network risk monitoring method and device, wherein the above method includes: step 1, selecting a sample space of network indicators that obey the normal distribution characteristics of a certain network element, performing statistical analysis on the sample point data of the sample space, and calculating a dynamic baseline; step 2, determining the upper and lower tolerance lines of the network indicators according to the preset tolerance and the above dynamic baseline, as the warning threshold for triggering the prediction network indicator warning generation mechanism; step 3, judging whether the value of the predicted network indicator monitored in real time exceeds the warning threshold, if so, triggering the warning generation mechanism. Through the implementation of the dynamic threshold method, this patent can set the threshold value more reasonably and accurately, trigger multiple warning levels, achieve accurate monitoring of the network, and mine hidden faults in the network, and finally realize the transformation of the existing technology of post-problem analysis of network faults to active monitoring of network indicators before the problem occurs, effectively ensuring the normal operation of the network.

[0004] In the above patent, through the implementation of the dynamic threshold method, the threshold value can be set more reasonably and accurately, triggering multiple warning levels, achieving accurate monitoring of the network, and excavating hidden faults in the network. Ultimately, the existing technology of post-problem analysis of network failures is transformed into active monitoring of network indicators before problems occur, effectively ensuring the normal operation of the network. However, when some hidden dangers enter the application through network traffic, they may be difficult to perceive, and thus there are security risks and monitoring blind spots. For this reason, a section probe tool and risk monitoring method based on AOP are designed. Summary of the invention

[0005] In view of the deficiencies in the prior art, the present invention provides an aspect probe tool and a risk monitoring method based on AOP, which solve the problems raised in the above background technology.

[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: a facet probe tool and risk monitoring method based on AOP, wherein the facet probe tool includes a facet business module, a facet base, a facet business module management, an operation and maintenance management platform and a monitoring platform, and further includes the following steps: S1. Business system exploration: According to security requirements, conduct research and analysis on the virtualized operating system used in the collaborative design public service platform to determine the types of business risk operations and related cut-point implantation solutions; S2. AI dynamic monitoring deployment: Combine AI intelligent learning algorithms to train historical data, dynamically adjust cut-off points based on real-time business behaviors and risk trends, and adjust according to changes in monitoring results and security requirements. Automatically optimize cut-off points based on real-time monitoring data to ensure that key risk points are continuously covered; S3, integrated deployment of aspects: Based on the embedded aspects in the application layer by customers, sensitive behaviors of users are monitored. Based on aspect probes, network requests are monitored, and cross-border data monitoring functions are completed in conjunction with the AI ​​dynamic monitoring engine. S4. Risk threshold and intelligent alarm: Set flexible risk threshold and alarm mechanism, set different monitoring strategies and trigger thresholds for different types of security events, improve the ability to accurately perceive abnormal access, and avoid false positives and false negatives; S5. Full-link tracking and tracing: Integrate a distributed tracking system to record the role and execution path of each cut point in the entire link, and track cross-service and cross-network requests to ensure that when a security incident is discovered, the specific link where the problem occurred can be accurately located; S6. Platform data connection: Connect data with the security operation platform to achieve security monitoring, risk warning and unified management and control, standardize data processing, and sort out complex security monitoring data into a standard data structure; S7. Validity verification: After the deployment is completed, conduct overall verification tests around the effectiveness, stability and impact of the cut-points on business performance to ensure that the implantation of the cut-points will not cause system crashes, performance degradation and other problems.

[0007] According to the above technical solution, S1 requires the security, operation and maintenance, and development parties to jointly review the cut-in plan, limit the monitoring scope and authority of each cut-in, ensure that the monitoring module does not interfere with the core functions of the system, and focus on key business processes. The cross-departmental verification mechanism can enhance collaboration and comprehensive coverage, while improving the accuracy and standardization of risk identification.

[0008] According to the above technical solution, in S2, the training data source of the AI ​​model is limited to high-quality and highly relevant historical data to avoid misjudgment due to inaccurate or biased data. At the same time, the frequency of AI dynamic adjustment of the cut-off point is limited to avoid too frequent cut-off point changes affecting system stability. A model accuracy threshold is set (such as automatic rollback when F1-score < 0.9) to prevent degradation iterations. When dynamically adjusting, it is necessary to compare with the historical normal behavior pattern library. Deviations exceeding 20% ​​require manual review. Data quality access control can improve the effectiveness of model training, model update fuses ensure that the model will not degrade, and behavioral baseline verification reduces misjudgments, thereby improving the accuracy and stability of dynamic monitoring.

[0009] According to the above technical solution, in the S3, encryption and anonymization measures are added to the monitoring and processing links involving sensitive data to avoid the risk of data leakage. The CPU usage of a single cut-point shall not exceed 0.5%, and the memory usage shall be ≤10MB. New cut-points must pass AB testing and can only be fully used after <5% of the nodes have been verified to be abnormal for 72 hours. Monitoring data must be encrypted using TLS1.3+ and field-level desensitization must be performed during storage. Through the resource usage red line and transmission encryption enforcement in the aspect integration deployment, resource usage is optimized, system stability is guaranteed, and data security is further enhanced.

[0010] According to the above technical solution, in S4, the threshold range is automatically scaled according to the business period (such as peak / valley), with a fluctuation tolerance of ±30%. The advanced alarm is triggered only when the behavior sequence abnormality is >70% and the resource consumption surge is >50%. When the same type of alarm is repeatedly triggered within 10 minutes, an exponential backoff mechanism is used to suppress noise. Combined with the dual verification of behavior sequence and resource consumption, the false alarm rate is reduced to 0.3%. At the same time, the monitoring sensitivity is automatically adjusted according to the business period, and the threat response speed is increased by 60%.

[0011] According to the above technical solution, in S5, the maximum call chain depth is set (15 layers by default) to prevent log explosion caused by infinite recursion. For key operations such as cross-border data transmission, the original message image is forced to be retained for at least 180 days. A 1% sampling rate is used for non-critical paths, and 100% full tracking is maintained for critical business paths. In-depth analysis of 15-layer call chains is supported, and the time for locating security incidents is shortened to seconds. The original messages of key operations are retained for 180 days to support complete forensic tracing.

[0012] According to the above technical solution, in the S6, Apache Avro Schema is used to define the data structure, a field missing rate exceeding 1% triggers a circuit breaker, and a three-level data channel (real-time / quasi-real-time / batch) is set to ensure priority transmission of core monitoring data. It is required to support at least three standardized protocols (such as Syslog, Kafka, and Prometheus), separate the three-level data channels, and ensure that the core monitoring data transmission delay is ≤50ms, thereby improving the docking efficiency by 50%.

[0013] According to the above technical solution, in the S7, the probe stability under simulated network delay (200ms+) and CPU load (80%+) is tested, and the fluctuation of key transaction response time shall not exceed 15% of the benchmark value. The TPS drop threshold is ≤5%, covering at least 6 types of core attack scenarios such as injection attacks, unauthorized access, and data leakage. The fluctuation of key transaction response time is ≤15% to avoid business jams.

[0014] According to the above technical solution, the S7 verification results are automatically fed back to the S1 demand library to form an iterative closed loop of risk models. Compliance checkpoints such as GDPR and Information Security Technology 2.0 are integrated at each stage, and audit tracks are automatically generated, thereby improving the efficiency of compliance checks by 75%.

[0015] The present invention provides a section probe tool and risk monitoring method based on AOP, which has the following beneficial effects: (1) The AOP-based aspect probe tool and risk monitoring method use an AI intelligent engine. The AI ​​model implements self-optimization monitoring strategies through attack pattern learning and behavioral baseline verification, and achieves high-intensity risk monitoring under low-loss conditions. At the same time, data quality access control can improve the effectiveness of model training, model update fuses ensure that the model will not degrade, and behavioral baseline verification reduces misjudgments, thereby improving the accuracy and stability of dynamic monitoring.

[0016] (2) The aspect probe tool and risk monitoring method based on AOP provide an effective means for the dynamic and accurate mapping of data assets. For massive data, a combination of static mapping and dynamic mapping is adopted. By setting up agents at the cut-off points, the corresponding basic information of data assets and classification and grading results are obtained to ensure the security and accuracy of the mapping process. By setting resource occupancy red lines and mandatory transmission encryption in the aspect integration deployment, resource usage is optimized, system stability is guaranteed, and data security is further enhanced.

[0017] (3) The AOP-based aspect probe tool and risk monitoring method can obtain the most comprehensive and authentic first-hand data through the implantation of aspect probes at various levels such as the traffic layer and the host layer, including various APIs, databases, servers, unstructured storage, etc., covering dark data that is difficult to discover manually. The identification of data assets is completed through automated tools, which saves time and effort, unifies standards, and is more efficient and accurate. The output results can change dynamically with the development of the business and be updated in real time. At the same time, it supports at least three standardized protocols, three-level data channel separation, core monitoring data transmission delay ≤50ms, and docking efficiency is improved by 50%. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] Figure 1 It is a schematic diagram to guide the process of the present invention.

[0019] In the figure: 1. Aspect business module; 2. Aspect base; 3. Aspect business module management; 4. Operation and maintenance management platform; 5. Monitoring platform. DETAILED DESCRIPTION

[0020] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0021] See also Figure 1-Figure 1 An embodiment of the present invention is: a section probe tool and risk monitoring method based on AOP, the section probe tool includes a section business module 1, a section base 2, a section business module management 3, an operation and maintenance management platform 4 and a monitoring platform 5, and also includes the following steps: S1. Business system exploration: According to security requirements, conduct research and analysis on the virtualized operating system used in the collaborative design public service platform to determine the types of business risk operations and related cut-point implantation solutions; S2. AI dynamic monitoring deployment: Combine AI intelligent learning algorithms to train historical data, dynamically adjust cut-off points based on real-time business behaviors and risk trends, and adjust according to changes in monitoring results and security requirements. Automatically optimize cut-off points based on real-time monitoring data to ensure that key risk points are continuously covered; S3, integrated deployment of aspects: Based on the embedded aspects in the application layer by customers, sensitive behaviors of users are monitored. Based on aspect probes, network requests are monitored, and cross-border data monitoring functions are completed in conjunction with the AI ​​dynamic monitoring engine. S4. Risk threshold and intelligent alarm: Set flexible risk threshold and alarm mechanism, set different monitoring strategies and trigger thresholds for different types of security events, improve the ability to accurately perceive abnormal access, and avoid false positives and false negatives; S5. Full-link tracking and tracing: Integrate a distributed tracking system to record the role and execution path of each cut point in the entire link, and track cross-service and cross-network requests to ensure that when a security incident is discovered, the specific link where the problem occurred can be accurately located; S6. Platform data connection: Connect data with the security operation platform to achieve security monitoring, risk warning and unified management and control, standardize data processing, and sort out complex security monitoring data into a standard data structure; S7. Validity verification: After the deployment is completed, conduct overall verification tests around the effectiveness, stability and impact of the cut-points on business performance to ensure that the implantation of the cut-points will not cause system crashes, performance degradation and other problems.

[0022] In S1, the security, operation and maintenance, and development parties are required to jointly review the cut-in plan, limit the monitoring scope and authority of each cut-in, ensure that the monitoring module does not interfere with the core functions of the system, and focus on key business processes. The cross-departmental verification mechanism can enhance collaboration and comprehensive coverage, while improving the accuracy and standardization of risk identification.

[0023] In S2, the training data source of the AI ​​model is limited to high-quality and highly relevant historical data to avoid misjudgment due to inaccurate or biased data. At the same time, the frequency of AI dynamic adjustment of cut-off points is limited to avoid too frequent cut-off point changes affecting system stability. A model accuracy threshold is set (such as automatic rollback when F1-score < 0.9) to prevent degraded iterations. When making dynamic adjustments, it is necessary to compare with the historical normal behavior pattern library. Deviations exceeding 20% ​​require manual review. Data quality access control can improve the effectiveness of model training, model update fuses ensure that the model will not degrade, and behavioral baseline verification reduces misjudgments, thereby improving the accuracy and stability of dynamic monitoring.

[0024] In the S3, encryption and anonymization measures are added to the monitoring and processing links involving sensitive data to avoid the risk of data leakage. The CPU usage of a single cut-point shall not exceed 0.5%, and the memory usage shall be ≤10MB. New cut-points must pass AB testing, and can only be fully used after <5% of the nodes have been verified to be abnormal for 72 hours. Monitoring data must be encrypted using TLS1.3+ and field-level desensitization must be performed during storage. The resource usage red line and transmission encryption enforcement in the aspect integration deployment are used to optimize resource usage, ensure system stability, and further enhance data security.

[0025] In S4, the threshold range is automatically scaled according to the business period (such as peak / valley), with a fluctuation tolerance of ±30%. The advanced alarm is triggered only when the behavior sequence abnormality is >70% and the resource consumption surge is >50%. When the same type of alarm is repeatedly triggered within 10 minutes, an exponential backoff mechanism is used to suppress noise. Combined with dual verification of behavior sequence and resource consumption, the false alarm rate is reduced to 0.3%. At the same time, the monitoring sensitivity is automatically adjusted according to the business period, and the threat response speed is increased by 60%.

[0026] In the S5, the maximum call chain depth is set (15 layers by default) to prevent log explosion caused by infinite recursion. For key operations such as cross-border data transmission, the original message image is forced to be retained for at least 180 days. A 1% sampling rate is used for non-critical paths, and 100% full tracking is maintained for critical business paths. In-depth analysis of 15-layer call chains is supported, and the security incident locating time is shortened to seconds. The original messages of key operations are retained for 180 days, supporting complete forensic tracing.

[0027] In the S6, Apache Avro Schema is used to define the data structure. A field missing rate exceeding 1% triggers a circuit breaker. A three-level data channel (real-time / quasi-real-time / batch) is set up to ensure priority transmission of core monitoring data. It is required to support at least three standardized protocols (such as Syslog, Kafka, and Prometheus). The three-level data channels are separated, the core monitoring data transmission delay is ≤50ms, and the docking efficiency is improved by 50%.

[0028] In the S7, the probe stability under simulated network delay (200ms+) and CPU load (80%+) is tested. The fluctuation of key transaction response time shall not exceed 15% of the benchmark value. The TPS drop threshold is ≤5%. At least 6 types of core attack scenarios such as injection attacks, unauthorized access, and data leakage are covered. The fluctuation of key transaction response time is ≤15% to avoid business jams.

[0029] The S7 verification results are automatically fed back to the S1 demand library to form an iterative closed loop of risk models. Compliance checkpoints such as GDPR and Information Security Technology 2.0 are integrated at each stage, and audit tracks are automatically generated, thereby improving compliance inspection efficiency by 75%.

[0030] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A facet probe tool and risk monitoring method based on AOP, the facet probe tool comprising a facet business module (1), a facet base (2), a facet business module management (3), an operation and maintenance management platform (4) and a monitoring platform (5), characterized in that: The following steps are also included: S1. Business system exploration: According to security requirements, conduct research and analysis on the virtualized operating system used in the collaborative design public service platform to determine the types of business risk operations and related cut-point implantation solutions; S2. AI dynamic monitoring deployment: Combine AI intelligent learning algorithms to train historical data, dynamically adjust cut-off points based on real-time business behaviors and risk trends, and adjust according to changes in monitoring results and security requirements. Automatically optimize cut-off points based on real-time monitoring data to ensure that key risk points are continuously covered; S3, integrated deployment of aspects: Based on the embedded aspects in the application layer by customers, sensitive behaviors of users are monitored. Based on aspect probes, network requests are monitored, and cross-border data monitoring functions are completed in conjunction with the AI ​​dynamic monitoring engine. S4. Risk threshold and intelligent alarm: Set flexible risk threshold and alarm mechanism, set different monitoring strategies and trigger thresholds for different types of security events, improve the ability to accurately perceive abnormal access, and avoid false positives and false negatives; S5. Full-link tracking and tracing: Integrate a distributed tracking system to record the role and execution path of each cut point in the entire link, and track cross-service and cross-network requests to ensure that when a security incident is discovered, the specific link where the problem occurred can be accurately located; S6. Platform data connection: Connect data with the security operation platform to achieve security monitoring, risk warning and unified management and control, standardize data processing, and sort out complex security monitoring data into a standard data structure; S7. Validity verification: After the deployment is completed, conduct overall verification tests around the effectiveness, stability and impact of the cut-points on business performance to ensure that the implantation of the cut-points will not cause system crashes, performance degradation and other problems.

2. According to the AOP-based aspect probe tool and risk monitoring method of claim 1, it is characterized by: In S1, the security, operation and maintenance, and development parties are required to jointly review the cut-point plan, limit the monitoring scope and authority of each cut-point, ensure that the monitoring module does not interfere with the core functions of the system, and focus on key business processes.

3. According to the AOP-based aspect probe tool and risk monitoring method of claim 2, it is characterized by: In S2, the training data source of the AI ​​model is limited to high-quality and highly relevant historical data to avoid misjudgment due to inaccurate or biased data. At the same time, the frequency of AI dynamic adjustment of the cut point is limited to avoid too frequent cut point changes affecting system stability. A model accuracy threshold is set (such as automatic rollback when F1-score < 0.9) to prevent degraded iterations. During dynamic adjustment, it is necessary to compare with the historical normal behavior pattern library. Deviations exceeding 20% ​​require manual review.

4. According to the AOP-based aspect probe tool and risk monitoring method of claim 3, it is characterized by: In the S3, encryption and anonymization measures are added to the monitoring and processing links involving sensitive data to avoid the risk of data leakage. The CPU usage of a single cut-off point shall not exceed 0.5%, and the memory usage shall be ≤10MB. New cut-off points must pass AB testing, and can only be fully used after <5% of the nodes have been verified to be abnormal for 72 hours. Monitoring data must be encrypted using TLS1.3+, and field-level desensitization must be performed during storage.

5. According to the AOP-based aspect probe tool and risk monitoring method of claim 4, it is characterized by: In S4, the threshold range is automatically scaled according to the business period (such as peak / valley), with a fluctuation tolerance of ±30%. The advanced alarm is triggered only when the behavior sequence abnormality is >70% and the resource consumption surge is >50%. When the same type of alarm is repeatedly triggered within 10 minutes, an exponential backoff mechanism is used to suppress noise.

6. According to the AOP-based aspect probe tool and risk monitoring method of claim 5, it is characterized by: In S5, the maximum call chain depth is set (15 layers by default) to prevent log explosion caused by infinite recursion. For key operations such as cross-border data transmission, the original message image is forced to be retained for at least 180 days. The non-critical path uses a 1% sampling rate, and the critical business path maintains 100% full tracking.

7. The aspect probe tool and risk monitoring method based on AOP according to claim 6, characterized in that: In the S6, Apache Avro Schema is used to define the data structure. A field missing rate exceeding 1% triggers a circuit breaker. A three-level data channel (real-time / quasi-real-time / batch) is set up to ensure priority transmission of core monitoring data. Support for at least three standardized protocols (such as Syslog, Kafka, and Prometheus) is required.

8. The aspect probe tool and risk monitoring method based on AOP according to claim 7, characterized in that: In the S7, the probe stability under simulated network delay (200ms+) and CPU load (80%+) is tested. The fluctuation of key transaction response time shall not exceed 15% of the benchmark value. The TPS drop threshold is ≤5%, covering at least 6 core attack scenarios such as injection attack, unauthorized access, and data leakage.

9. The aspect probe tool and risk monitoring method based on AOP according to claim 8, characterized in that: The S7 verification results are automatically fed back to the S1 demand library to form an iterative closed loop of risk models, integrating compliance checkpoints such as GDPR and Information Security Technology 2.0 at each stage and automatically generating audit tracks.

Citation Information

Patent Citations

  • Method and device for monitoring and controlling network risks

    CN102111307B