Software operation environment safety supervision system based on Internet

By performing interval analysis on the software's historical traffic data, the characteristic traffic interval and characteristic trend interval are determined, and combined with real-time traffic monitoring and similarity analysis processing center, the operation security status of the software is evaluated, which solves the problem of the inability to improve the comprehensiveness of operating software security supervision in the existing technology, and achieves high-accuracy abnormal detection and rapid attack recognition.

CN120145389AActive Publication Date: 2025-06-13ZHENGZHOU UNIVERSITY OF LIGHT INDUSTRY

Patent Information

Application Number
CN202510177292.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-06-13
Estimated Expiration
2045-02-18

AI Technical Summary

Technical Problem

The prior art fails to confirm the relevant characteristics of the traffic based on the different historical traffic data generated by the software in the historical process, resulting in the inability to improve the comprehensiveness of the security supervision of running the software.

Method used

The historical traffic data of the specified software is obtained through the historical data acquisition end. The feature interval confirmation end conducts interval analysis on the historical traffic data, determines the feature traffic interval and feature trend interval, and combines the real-time traffic monitoring and similarity analysis processing center to evaluate the operating security status of the software and identify whether the abnormal traffic data is attack data.

Benefits of technology

By comprehensively characterizing the traffic characteristics of the software when it is running normally, the accuracy of abnormal detection is improved, misjudgment may be caused by a single standard, and quickly locate known types of attacks, improving the efficiency and targetedness of attack detection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120145389A_ABST
    Figure CN120145389A_ABST
Patent Text Reader

Abstract

The invention discloses a software operation environment security supervision system based on the Internet, relates to the technical field of software security, and solves the problem that related confirmation of characteristic traffic is not carried out based on different historical traffic data generated by corresponding software in a historical process. According to the method, when interval analysis is conducted on historical flow data, the characteristic density of different processing intervals is calculated, the interval with the most obvious characteristics is obtained through comparison and serves as the characteristic flow interval, and the distribution and change conditions of the flow data are fully considered; meanwhile, the characteristic trend interval is further determined based on the characteristic flow interval, the flow characteristic during normal operation of the software can be comprehensively described, and a foundation is laid for subsequent accurate judgment of an abnormal state.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of software security, and specifically to an Internet-based software running environment security supervision system. Background Art

[0002] In today's digital age, software has become an indispensable part of various business and life scenarios; however, the complexity and openness of the software running environment have brought many security risks; software running environment security supervision aims to ensure that software runs in a safe and stable environment through a series of technical and management means, protecting the integrity, confidentiality, and availability of data and systems.

[0003] The application with the patent publication number CN114968761B discloses an Internet-based software running environment security supervision system, which relates to the technical field of software environment security supervision, and solves the technical problem in the prior art that it is impossible to accurately analyze the defects caused by the current running environment to the software operation and match a suitable repair method. It can perform running environment analysis during the software operation process, and obtain the defects that the software actually has during the running environment analysis process, so as to improve the software operation efficiency. At the same time, when the software has defects, it performs real-time operation analysis, and reasonably selects the current defect repair method through real-time analysis, thereby improving the current software repair efficiency and preventing the software operation efficiency from being reduced due to unreasonable repair methods; it judges the running intensity of the current analysis object, thereby improving the accuracy of the repair method selection, and reducing the impact brought by running defects while not affecting the running efficiency of the analysis object.

[0004] During the security supervision process of its corresponding running software's running environment, it generally confirms the abnormal traffic generated based on a preset traffic range, so as to identify whether there are security problems in the running environment of the corresponding software. However, in the actual operation process, the monitoring method of the corresponding preset range is relatively one-sided. Because the corresponding running software has different running situations and the running environments are also different, the accuracy associated with the original preset range needs to be adjusted. It does not perform relevant confirmation of characteristic traffic based on the different historical traffic data generated by the corresponding software in the historical process, resulting in the inability to improve the comprehensiveness of the security supervision of the running software. Summary of the Invention

[0005] Aiming at the deficiencies of the prior art, the present invention provides an Internet-based software running environment security supervision system, which solves the problem that it is impossible to improve the comprehensiveness of the security supervision of the running software because it does not perform relevant confirmation of characteristic traffic based on the different historical traffic data generated by the corresponding software in the historical process.

[0006] To achieve the above objectives, the present invention is implemented through the following technical solutions: A software operation environment security supervision system based on the Internet, comprising:

[0007] A historical data acquisition end, which acquires the historical traffic data generated during the operation of a specified software and transmits the acquired historical traffic data into the feature interval confirmation end;

[0008] A feature interval confirmation end, which, for the historical traffic data generated by a specified software, identifies the historical traffic data associated with each operation stage, and then, based on the current moment, selects the relevant operation stages close to the current moment from different operation stages, performs interval analysis on the historical traffic data of the selected relevant operation stages, and selects the characteristic traffic interval and the characteristic trend interval belonging to this specified software;

[0009] A real-time data monitoring end, which monitors the real-time traffic during the operation of a specified software and transmits the monitored real-time traffic into the abnormal assessment center;

[0010] An abnormal assessment center, which determines the operation safety state of a specified software based on the monitored real-time traffic of the specified software, the confirmed characteristic traffic interval, and the characteristic trend interval, and assesses whether this specified software has an abnormal state based on the determination result, and transmits the abnormal traffic data associated with the duration of the abnormal state into the similarity analysis and processing center. The specific method is as follows:

[0011] Calibrate the monitored real-time traffic of the specified software as S t , where t represents different moments, and compare the monitored real-time traffic S t with the determined characteristic traffic interval. If S t ∈ the characteristic traffic interval, continue to monitor. If ∉ the characteristic traffic interval, confirm the traffic change data generated at the current moment and the previous moment, and calibrate it as B t . If B t ∈ the characteristic trend interval, continue to monitor. If ∉ the characteristic trend interval, record that this specified software has an abnormal state during operation, calibrate the current moment as the abnormal moment, record the specific time period associated with the continuously confirmed abnormal moments as the duration of this abnormal state, record the traffic data generated by the specified software during the duration as the abnormal traffic data, and transmit the determined abnormal traffic data into the similarity analysis and processing center;

[0012] A cloud database, which stores the traffic characteristic curves belonging to different attack characteristics, and all its traffic characteristic curves are preset curves;

[0013] The similarity analysis processing center, based on the abnormal traffic data regarding the continuous period confirmed by the abnormal assessment center, first confirms the data change curve associated with this abnormal traffic data, then extracts the stored traffic feature curves from the cloud database, and conducts a similarity analysis between the data change curve and the traffic feature curves to evaluate whether the currently generated abnormal traffic data is attack data. The specific method is as follows:

[0014] Based on the abnormal traffic data confirmed for the continuous period, confirm the data change curve associated with the corresponding continuous period;

[0015] Then, based on the confirmed multiple groups of traffic feature curves, sequentially select a single group of traffic feature curves from the multiple groups of traffic feature curves for similarity analysis with the data change curve: Place the data change curve and the single group of traffic feature curves in the same two-dimensional coordinate system, control the data change curve to move horizontally, and confirm from the moving process the group of moving processes with the longest intersection segment between the data change curve and the single group of traffic feature curves. Denote this moving process as the standard process, and confirm the proportion of the intersection segment located on the data change curve in the standard process, denoted as ZB p , where p represents different traffic feature curves, and identify ZB p Whether it satisfies: ZB p ≥90%. If it satisfies, directly calibrate this abnormal traffic data as attack data and display it; if it does not satisfy, then select other traffic feature curves for intersection segment analysis with this data change curve to confirm whether there is a situation where ZB p ≥90%. If it exists, calibrate this abnormal traffic data as attack data. If it does not exist, generate a signal for personnel to intervene.

[0016] Furthermore, the specific method for the feature interval confirmation end to conduct interval analysis on the historical traffic data of the selected relevant operation stages is as follows:

[0017] Based on the current moment, select N groups of operation stages close to the current moment, where N is a preset value. Process the traffic data of each group of operation stages, confirm the different traffic data associated with different moments within the corresponding operation stage, and then generate the traffic data change curve belonging to the corresponding operation stage;

[0018] From all the traffic data associated with each group of operation stages, select the maximum traffic data value and the minimum traffic data value to confirm a group of traffic intervals;

[0019] Based on this traffic interval, confirm the characteristic traffic interval of the specified software. The confirmation method is as follows:

[0020] S11, taking the current flow interval as the processing interval, confirming the flow difference of the processing interval, this flow difference = the maximum value of the flow interval - the minimum value of the flow interval, and then confirming the relevant line segments belonging to this flow interval from each set of flow data change curves, and recording the total length L of the relevant line segments, using: flow difference ÷ L = M to confirm the characteristic density M associated with the current processing interval;

[0021] Prioritize downgrade processing:

[0022] S111, lower the maximum value of the flow interval by a set of unit flow, confirm another set of processing intervals, whose unit flow is the preset flow, and use the same method as step S11 to confirm the characteristic density M associated with the corresponding processing interval k , where k represents different treatment intervals;

[0023] S112, the maximum value of the flow interval is adjusted down by two groups of unit flow, and a group of processing intervals is confirmed again. After confirming the characteristic density of the corresponding processing interval, the unit flow is adjusted down in sequence, and the characteristic density of different processing intervals is confirmed in sequence, until the flow difference between the maximum value and the minimum value of the last group of processing intervals = a group of unit flow, the downward adjustment process is completed;

[0024] Then execute the upward processing process:

[0025] S121, adjust the minimum value of the flow interval by a group of unit flow to confirm another group of processing intervals, and use the same method as step S11 to confirm the characteristic density M associated with the corresponding processing interval k ;

[0026] S122, the minimum value of the flow interval is adjusted upward by two groups of unit flows, and a group of processing intervals is confirmed again. After confirming the characteristic density of the corresponding processing interval, the unit flows are adjusted upward in sequence, and the characteristic densities of different processing intervals are confirmed in sequence, until the flow difference between the maximum and minimum values ​​of the last group of processing intervals = a group of unit flows, and the downward adjustment process is completed;

[0027] According to the different characteristic densities M associated with different processing intervals k , from several sets of characteristic density M k In the k The processing interval associated with min is used as the characteristic flow interval of the currently specified software;

[0028] Based on the characteristic flow interval confirmed by the specified software, the characteristic trend interval associated with the current specified software is confirmed in the following ways:

[0029] From the confirmed flow data change curve, some curve segments belonging to this characteristic flow interval are eliminated, and the remaining curve segments are confirmed and recorded as the segments to be processed;

[0030] Confirm the difference in traffic data associated within a unit time in the segment to be processed, and the traffic data difference ≥ 0. Select the minimum value and the maximum value from the confirmed several groups of traffic data differences as the characteristic trend interval associated with the current specified software.

[0031] The present invention provides an Internet-based software operation environment security supervision system. Compared with the prior art, it has the following beneficial effects:

[0032] When the present invention performs interval analysis on historical traffic data, by calculating the characteristic density of different processing intervals and comparing to obtain the interval with the most obvious characteristics as the characteristic traffic interval, this method fully considers the distribution and change of traffic data. At the same time, based on the characteristic traffic interval, further determine the characteristic trend interval, which can comprehensively describe the traffic characteristics when the software is running normally, laying a foundation for accurately judging the abnormal state subsequently;

[0033] Combine real-time traffic with the characteristic traffic interval and the characteristic trend interval for judgment. When the real-time traffic exceeds the characteristic traffic interval, further determine whether it is an abnormal state based on whether the traffic change data is within the characteristic trend interval. This dual judgment criterion effectively avoids misjudgment that may be caused by a single criterion and improves the accuracy of anomaly detection. For example, some short-term traffic fluctuations may still be within the normal change trend and will not be misjudged as abnormal;

[0034] Based on the traffic characteristic curve preset according to past attack characteristics, the similarity analysis processing center performs similarity analysis on the change curve of abnormal traffic data with it. This attack recognition method based on historical experience can quickly locate known types of attacks and improve the efficiency and pertinence of attack detection. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 It is a schematic diagram of the principle framework of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0036] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0037] Please refer to Figure 1, this application provides an Internet-based software operation environment security supervision system, including a historical data acquisition terminal, a feature interval confirmation terminal, a real-time data monitoring terminal, an anomaly evaluation center, a cloud database, and a similarity analysis and processing center. Among them, the historical data acquisition terminal is electrically connected to the input node of the feature interval confirmation terminal, and both the feature interval confirmation terminal and the real-time data monitoring terminal are electrically connected to the input node of the anomaly evaluation center, and both the anomaly evaluation center and the cloud database are electrically connected to the input node of the similarity analysis and processing center;

[0038] Among them, the historical data acquisition terminal acquires the historical traffic data generated during the operation of the specified software and transmits the acquired historical traffic data to the feature interval confirmation terminal. The historical traffic data is different traffic data generated at different times during the operation of the corresponding software, that is, when the corresponding software is running normally, interactive traffic will be generated, and corresponding traffic data will be generated;

[0039] Among them, the feature interval confirmation terminal identifies the historical traffic data associated with each operation stage from the historical traffic data generated by the specified software, and then based on the current moment, selects the relevant operation stages close to the current moment from different operation stages, and performs interval analysis on the historical traffic data of the selected relevant operation stages to select the characteristic traffic interval and characteristic trend interval belonging to this specified software. Specifically, during the normal operation of each software, except for the large traffic during the startup stage, the traffic data generated during the normal operation stage should be relatively balanced and regular. Then, based on such traffic data, specific analysis of the numerical curve can be carried out to specifically confirm the traffic characteristics, which is convenient for subsequent confirmation of abnormal traffic stages during numerical monitoring;

[0040] Among them, the specific method for performing interval analysis on the historical traffic data of the selected relevant operation stages is as follows:

[0041] Based on the current moment, select N groups of operation stages close to the current moment, where N is a preset value pre-set by the operator, generally taking the value of 5, and it should not be too much. Process the traffic data of each group of operation stages, identify the different traffic data associated with different times within the corresponding operation stage, and then generate a traffic data change curve belonging to the corresponding operation stage (the horizontal axis of this curve is the time line, and the vertical axis is the traffic data);

[0042] Select the maximum traffic data value and the minimum traffic data value from all the traffic data associated with each group of operation stages (the traffic data here is the traffic data associated with all operation stages) to confirm a group of traffic intervals;

[0043] Based on this traffic interval, confirm the characteristic traffic interval of the specified software:

[0044] S11. Take the current flow rate range as the processing range, confirm the flow rate difference in the processing range. This flow rate difference = the maximum value of the flow rate range - the minimum value of the flow rate range. Then, confirm the relevant line segments belonging to this flow rate range from each group of flow rate data change curves, and record the total line length L of the relevant line segments. Use: flow rate difference ÷ L = M to confirm the characteristic density M associated with the current processing range;

[0045] Give priority to executing the downward adjustment processing process:

[0046] S111. Lower the maximum value of the flow rate range by one unit of flow rate to confirm another group of processing ranges. Its unit flow rate is the preset flow rate, which is set in advance by the operator, generally taking a value of 100 kb. Use the same method as in step S11 to confirm the characteristic density M associated with the corresponding processing range k where k represents different processing ranges;

[0047] S112. Lower the maximum value of the flow rate range by two units of flow rate to confirm another group of processing ranges. After confirming the characteristic density of the corresponding processing range, then sequentially lower the unit flow rate, and sequentially confirm the characteristic densities of different processing ranges until the flow rate difference between the maximum value and the minimum value of the last group of processing ranges = one unit of flow rate, and complete the downward adjustment processing process;

[0048] Then execute the upward adjustment processing process:

[0049] S121. Raise the minimum value of the flow rate range by one unit of flow rate to confirm another group of processing ranges. Use the same method as in step S11 to confirm the characteristic density M associated with the corresponding processing range k ;

[0050] S122. Raise the minimum value of the flow rate range by two units of flow rate to confirm another group of processing ranges. After confirming the characteristic density of the corresponding processing range, then sequentially raise the unit flow rate, and sequentially confirm the characteristic densities of different processing ranges until the flow rate difference between the maximum value and the minimum value of the last group of processing ranges = one unit of flow rate, and complete the downward adjustment processing process;

[0051] According to the different characteristic densities M associated with different processing ranges k , from several groups of characteristic densities M k select M k min (the relevant stage with the smallest difference and the longest line length L, then the characteristics associated with the flow rate associated with such a stage are the most obvious) associated processing range as the characteristic flow rate range of the current specified software;

[0052] Based on the characteristic flow rate range confirmed for the specified software, confirm the characteristic trend range associated with the current specified software:

[0053] From the confirmed flow data change curve, some curve segments belonging to this characteristic flow interval are eliminated, and the remaining curve segments are confirmed and recorded as the segments to be processed;

[0054] Confirm the flow data difference associated with the unit time in the processing section (that is, adjacent moments, which can be directly known in the coordinate system of the flow data change curve), and the flow data difference is ≥ 0, and the unit time is the preset time, generally 1 second. From the confirmed groups of flow data differences, select the minimum and maximum values ​​as the characteristic trend interval associated with the current specified software;

[0055] Specifically, when the corresponding software is running, there are generally two stages, either a stable stage or a fluctuating stage. The stable stage is confirmed based on the specific changes in the traffic data, that is, the characteristic traffic interval associated with the corresponding designated software. Once the corresponding characteristic traffic interval is determined, the associated fluctuating stage can be confirmed based on the confirmed stable stage. The fluctuating stage is the relevant stage excluding the stable stage. Based on the corresponding fluctuating stage, the change data per unit time can be identified to confirm the trend interval. In this way, the relevant characteristics of the designated software can be confirmed one by one, which is convenient for the subsequent specific judgment of abnormal situations, and the security status of the operating environment of the designated software can be monitored in real time to ensure the comprehensiveness of network status security supervision.

[0056] The real-time data monitoring terminal monitors the real-time traffic of the specified software during operation and transmits the monitored real-time traffic to the abnormality assessment center, wherein the monitored real-time traffic is monitored by the system's own traffic monitoring module;

[0057] The abnormality assessment center determines the operational safety status of the designated software based on the real-time traffic monitored by the designated software and the confirmed characteristic traffic interval and characteristic trend interval, and assesses whether the designated software is in an abnormal state based on the determination result, and transmits the abnormal traffic data associated with the duration of the abnormal state to the similarity analysis processing center. The specific method for determining the operational safety status of the designated software is as follows:

[0058] The real-time flow monitored by the specified software is calibrated as S t , where t represents different moments, and the monitored real-time traffic S t Check with the determined characteristic flow interval. If S t ∈ characteristic flow interval, then continue to monitor, if Characteristic flow interval, then confirm the flow change data generated at the current moment and the previous moment, and mark it as B t , if B t∈ the characteristic trend interval, continuous monitoring is carried out. If it is not in the characteristic trend interval, record that the specified software has an abnormal state during operation, mark the current moment as the abnormal moment, record the specific time period associated with the continuously confirmed and successive abnormal moments as the duration of this abnormal state, record the traffic data generated by the specified software during the duration as abnormal traffic data, and transmit the determined abnormal traffic data to the similarity analysis and processing center.

[0059] Specifically, when the monitored real-time traffic changes normally, the generated relevant traffic data will change within the confirmed characteristic traffic interval. When it does not change within the corresponding characteristic traffic interval, trend confirmation can be carried out. If the confirmed numerical change trend also does not belong to the confirmed trend interval, it means that the running state of the corresponding software belongs to the abnormal running state. Then, the abnormal traffic data associated with the corresponding abnormal running state can be confirmed, and then the verification analysis of such abnormal traffic data can be carried out.

[0060] Among them, the cloud database stores traffic characteristic curves belonging to different attack characteristics. The traffic characteristic curves are all preset curves, which are preset in advance by relevant operators based on past attack characteristics. When each different attack characteristic occurs, there will be corresponding characteristic traffic changes, so that the corresponding traffic characteristic curves can be locked;

[0061] Among them, the similarity analysis and processing center, based on the abnormal traffic data about the duration confirmed by the abnormal evaluation center, first confirms the data change curve associated with this abnormal traffic data, then extracts the stored traffic characteristic curves from the cloud database, and performs similarity analysis on the data change curve and the traffic characteristic curve to evaluate whether the currently generated abnormal traffic data is attack data. The specific method for evaluation is as follows:

[0062] Based on the abnormal traffic data confirmed during the duration, confirm the data change curve associated with the corresponding duration (the abscissa is the time line and the ordinate is the abnormal traffic);

[0063] Then, based on the confirmed several groups of traffic characteristic curves, successively select a single group of traffic characteristic curves from the several groups of traffic characteristic curves to perform similarity analysis with the data change curve: place the data change curve and the single group of traffic characteristic curves in the same two-dimensional coordinate system, control the data change curve to move horizontally, and confirm the group of moving processes with the longest intersection segment between the data change curve and the single group of traffic characteristic curves during the moving process (the intersection segment is the overlapping segment between the data change curve and the single group of traffic characteristic curves, and the overlapping segment is the intersection segment). Record this moving process as the standard process, and confirm the proportion of the intersection segment in the data change curve during the standard process, denoted as ZB p, where p represents different flow characteristic curves, identifying ZB p Is it satisfied: ZB p ≥90%. If it meets the requirement, the abnormal traffic data is directly marked as attack data and displayed. If it does not meet the requirement, other traffic characteristic curves are selected to analyze the intersection of the data change curve to confirm whether there is ZB. p ≥90% of the cases, if it exists, the abnormal traffic data will be marked as attack data. If it does not exist, a personnel intervention signal will be generated. After the personnel intervene, it will be assessed whether the current running process is normal. If it is normal, the characteristic traffic interval and characteristic trend interval associated with the current specified software will be re-determined. If it is not normal, such traffic data will be deleted to ensure the environmental security of the current software during operation;

[0064] Specifically, by storing preset traffic characteristic curves based on past attack characteristics in the cloud database, the system can quickly match known attack types. When abnormal traffic occurs, it can be directly compared with these preset curves, which greatly improves the detection efficiency and accuracy compared to non-targeted detection methods. For example, if a certain DDoS attack has a unique traffic increase and decrease pattern, after storing it as a traffic characteristic curve, the system can quickly identify it when facing similar attacks. Once abnormal traffic occurs, the system can confirm the data change curve based on the abnormal traffic data and quickly perform similarity analysis with the traffic characteristic curve in the cloud database. This fast matching mechanism helps to lock in the attack type in the early stages of the attack, buying time for timely response measures.

[0065] Some of the data in the above formulas are numerically calculated by removing their dimensions. Meanwhile, the contents not described in detail in this specification belong to the prior art known to those skilled in the art.

[0066] The above embodiments are only used to illustrate the technical method of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical method of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical method of the present invention.

Claims

1. A software operating environment security supervision system based on the Internet, characterized in that: include: The historical data acquisition terminal acquires the historical traffic data generated during the operation of the specified software, and transmits the acquired historical traffic data to the characteristic interval confirmation terminal; The characteristic interval confirmation terminal identifies the historical flow data associated with each operation stage from the historical flow data generated by the specified software, and then based on the current moment, selects the relevant operation stage close to the current moment from the different operation stages, performs interval analysis on the historical flow data of the selected relevant operation stage, and selects the characteristic flow interval and characteristic trend interval belonging to the specified software; The real-time data monitoring terminal monitors the real-time traffic of the specified software during operation and transmits the monitored real-time traffic to the abnormality assessment center; The anomaly assessment center determines the operational safety status of the designated software based on the real-time traffic monitored by the designated software and the confirmed characteristic traffic interval and characteristic trend interval, and assesses whether the designated software is in an abnormal state based on the determination result, and transmits the abnormal traffic data associated with the duration of the abnormal state to the similarity analysis processing center; The cloud database stores traffic characteristic curves belonging to different attack characteristics, and the traffic characteristic curves are all preset curves; The similarity analysis and processing center, based on the abnormal traffic data of the continuous period confirmed by the anomaly assessment center, first confirms the data change curve associated with the abnormal traffic data, then extracts the stored traffic characteristic curve from the cloud database, performs similarity analysis on the data change curve and the traffic characteristic curve, and assesses whether the currently generated abnormal traffic data is attack data.

2. The Internet-based software operating environment security supervision system according to claim 1, characterized in that: The specific method of performing interval analysis on the historical flow data of the selected relevant operation stage at the characteristic interval confirmation end is as follows: Based on the current moment, select N groups of operation stages close to the current moment, where N is a preset value, process the flow data of each group of operation stages, confirm the different flow data associated with different moments in the corresponding operation stage, and then generate the flow data change curve belonging to the corresponding operation stage; From all the flow data associated with each set of operation stages, a maximum flow data value and a minimum flow data value are selected to determine a set of flow intervals; Based on this flow interval, the characteristic flow interval of the specified software is confirmed; Based on the characteristic flow interval confirmed by the designated software, the characteristic trend interval associated with the current designated software is confirmed.

3. The Internet-based software operating environment security supervision system according to claim 2, characterized in that: The characteristic interval confirmation end confirms the characteristic flow interval of the specified software based on the flow interval: S11, taking the current flow interval as the processing interval, confirming the flow difference of the processing interval, this flow difference = the maximum value of the flow interval - the minimum value of the flow interval, and then confirming the relevant line segments belonging to this flow interval from each set of flow data change curves, and recording the total length L of the relevant line segments, using: flow difference ÷ L = M to confirm the characteristic density M associated with the current processing interval; Prioritize downgrade processing: S111, lower the maximum value of the flow interval by a set of unit flow, confirm another set of processing intervals, whose unit flow is the preset flow, and use the same method as step S11 to confirm the characteristic density M associated with the corresponding processing interval k , where k represents different treatment intervals; S112, the maximum value of the flow interval is adjusted down by two groups of unit flow, and a group of processing intervals is confirmed again. After confirming the characteristic density of the corresponding processing interval, the unit flow is adjusted down in sequence, and the characteristic density of different processing intervals is confirmed in sequence, until the flow difference between the maximum value and the minimum value of the last group of processing intervals = a group of unit flow, the downward adjustment process is completed; Then execute the upward processing process: S121, adjust the minimum value of the flow interval by a group of unit flow to confirm another group of processing intervals, and use the same method as step S11 to confirm the characteristic density M associated with the corresponding processing interval k ; S122, the minimum value of the flow interval is adjusted upward by two groups of unit flows, and a group of processing intervals is confirmed again. After confirming the characteristic density of the corresponding processing interval, the unit flows are adjusted upward in sequence, and the characteristic densities of different processing intervals are confirmed in sequence, until the flow difference between the maximum and minimum values ​​of the last group of processing intervals = a group of unit flows, and the downward adjustment process is completed; According to the different characteristic densities M associated with different processing intervals k , from several sets of characteristic density M k In the k The processing interval associated with min is used as the characteristic flow interval of the currently specified software.

4. The Internet-based software operating environment security supervision system according to claim 3, characterized in that: The specific method of the characteristic interval confirmation end for confirming the characteristic trend interval associated with the specified software is: From the confirmed flow data change curve, some curve segments belonging to this characteristic flow interval are eliminated, and the remaining curve segments are confirmed and recorded as the segments to be processed; The flow data difference associated with the unit time in the processing section is confirmed, and the flow data difference is ≥ 0. From the confirmed groups of flow data differences, the minimum and maximum values ​​are selected as the characteristic trend interval associated with the current specified software.

5. The Internet-based software operating environment security supervision system according to claim 1, characterized in that: The specific method for the abnormal assessment center to determine the safety status of the specified software operation is: The real-time flow monitored by the specified software is calibrated as S t , where t represents different moments, and the monitored real-time traffic S t Check with the determined characteristic flow interval. If S t ∈ characteristic flow interval, then continue to monitor, if Then confirm the flow change data generated at the current moment and the previous moment, and mark it as B t , if B t ∈ characteristic trend interval, then continue to monitor, if The abnormal state of the specified software during its operation is recorded, and the current time is marked as the abnormal time. The specific time period associated with the abnormal moments that are confirmed in real time and occur successively is recorded as the duration of the abnormal state. The traffic data generated by the specified software during the duration is recorded as abnormal traffic data, and the determined abnormal traffic data is transmitted to the similarity analysis processing center.

6. The Internet-based software operating environment security monitoring system according to claim 5, characterized in that: The specific method of the similarity analysis processing center to assess whether the currently generated abnormal traffic data is attack data is as follows: Based on the abnormal flow data confirmed during the duration period, confirm the data change curve associated with the corresponding duration period; Based on the confirmed groups of flow characteristic curves, select a single group of flow characteristic curves and the data change curve in turn from the groups of flow characteristic curves for similarity analysis: place the data change curve and the single group of flow characteristic curves in the same two-dimensional coordinate system, and control the data change curve to move horizontally, and confirm the group of movement processes with the longest intersection between the data change curve and the single group of flow characteristic curve from the movement process, record this movement process as the standard process, and confirm the proportion of the intersection in the data change curve in the standard process, which is recorded as ZB p , where p represents different flow characteristic curves, identifying ZB p Is it satisfied: ZB p ≥90%. If it is met, the abnormal traffic data will be directly marked as attack data and displayed.

7. The Internet-based software operating environment security supervision system according to claim 1, characterized in that: The ZB p If ZB is not satisfied p When it is ≥90%, select other flow characteristic curves and this data change curve for intersection analysis to confirm whether there is ZB p ≥90% of the cases, if it exists, the abnormal traffic data will be marked as attack data, if not, a personnel intervention signal will be generated.

Citation Information

Patent Citations

  • A software runtime environment security monitoring system based on the Internet

    CN114968761B

  • Network traffic abnormality detection method based on relative-entropy theory

    CN107231348A

  • Network traffic anomaly detection method based on historical time point taking method

    CN108965055A

  • Traffic monitoring method and device, model training method and device and storage medium

    CN110839040A

  • Real-time anomaly detection system and method for EPG connection number

    CN113887616A

Cited By

  • Software running state monitoring method based on software safe running

    CN120811653A