Security event monitoring method and device based on traffic

Through online adaptive learning and automatic adjustment of model parameters, traffic-based security incident monitoring methods, the problem of traditional methods being difficult to cope with complex network attacks and handling large-scale network traffic is solved, and efficient detection and defense of unknown threats is achieved.

CN120165900APending Publication Date: 2025-06-17SINOPEC SHARED SERVICES CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510153652.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-12
Publication Date
2025-06-17

AI Technical Summary

Technical Problem

Traditional security incident monitoring methods are difficult to deal with increasingly complex cyber attacks, and data processing capabilities and response speeds are insufficient in the face of large-scale network traffic.

Method used

The traffic-based security incident monitoring method is adopted to analyze network traffic in real time through online adaptive learning, automatically adjust model parameters, and promptly identify and respond to new attack modes without relying on pre-configured defense rules.

Benefits of technology

It greatly improves the detection and defense capabilities of unknown threats, can accurately identify potential abnormal data and attack behaviors, and adapt to complex network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120165900A_ABST
    Figure CN120165900A_ABST
Patent Text Reader

Abstract

The invention provides a traffic-based security event monitoring method and device, and relates to the field of network security monitoring, and the method comprises the steps: carrying out the analysis of obtained traffic data based on a network protocol analysis library, and obtaining corresponding traffic feature data; detecting and analyzing the traffic characteristic data, and determining whether the traffic data is abnormal or not; and if the traffic data is abnormal, marking the traffic data as abnormal traffic data, and performing security processing on a security event corresponding to the abnormal traffic data. Through online adaptive learning, real-time analysis of network traffic, automatic adjustment of model parameters, and timely identification and response of a novel attack mode, the method does not need to depend on a pre-configured defense rule, thereby greatly improving the detection and defense capability of unknown threats.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security monitoring, and specifically to a method and device for monitoring security events based on traffic. Background Art

[0002] With the development of Internet technology, network attacks have become an important factor seriously affecting network security. Traditional security event monitoring methods mainly rely on static defense means such as firewalls and intrusion detection systems (IDS). These methods often have difficulty coping with increasingly complex network attacks. Firewalls usually need to be pre-configured with rules to block specific network traffic. These rules are often based on known attack patterns and threat intelligence. However, network attack means are constantly changing, and new attack patterns may appear before the rules are updated, resulting in the firewall being unable to respond to new threats in a timely manner. Network attack patterns are constantly changing, and static defense systems often cannot detect and respond in a timely manner when facing new attack methods. In addition, in the face of large-scale network traffic, traditional monitoring systems also have significant deficiencies in data processing capabilities and response speeds.

[0003] This section aims to provide background or context for the embodiments of the present invention described in the claims. The description herein is not admitted to be prior art merely because it is included in this section. Summary of the Invention

[0004] In view of the problems in the prior art, the present application provides a method for monitoring security events based on traffic, which can analyze network traffic in real time through online adaptive learning, automatically adjust model parameters, and timely identify and respond to new attack patterns without relying on pre-configured defense rules, thereby greatly improving the detection and defense capabilities against unknown threats.

[0005] To solve the above technical problems, the present application provides the following technical solutions:

[0006] In a first aspect, the present application provides a method for monitoring security events based on traffic, including:

[0007] Parsing the obtained traffic data based on a network protocol parsing library to obtain corresponding traffic feature data;

[0008] Performing detection and analysis on the traffic feature data to determine whether there is an abnormality in the traffic data;

[0009] If there is an abnormality, marking the traffic data as abnormal traffic data and performing security processing on the security event corresponding to the abnormal traffic data.

[0010] Further, the network protocol parsing library includes a TCP parsing library, a UDP parsing library, an HTTP parsing library, and an HTTPS parsing library; parsing the acquired traffic data based on the network protocol parsing library to obtain corresponding traffic feature data, including:

[0011] Parsing the traffic data by using the TCP parsing library, the UDP parsing library, the HTTP parsing library, or the HTTPS parsing library, and extracting parameters of each field of the traffic data; wherein, the parameters include a source IP address, a destination IP address, a source port, a destination port, a packet size, and a transmission timestamp;

[0012] Analyzing statistical features, behavior features, content features, and context extraction features of the traffic data according to the parameters.

[0013] Further, detecting and analyzing the traffic feature data to determine whether there is an abnormality in the traffic data, including:

[0014] Screening the abnormal traffic data according to the standard deviation in the statistical features; or

[0015] Inputting the traffic feature data into a pre-trained random forest model to obtain the abnormal traffic data; wherein, the random forest model is trained by using historical traffic feature data corresponding to historical traffic data.

[0016] Further, detecting and analyzing the traffic feature data to determine whether there is an abnormality in the traffic data, including:

[0017] Screening the abnormal traffic data according to the time series in the statistical features; or

[0018] Constructing a traffic analysis graph according to the context extraction features to screen the abnormal traffic data according to the traffic path in the traffic analysis graph.

[0019] Further, performing security processing on the security event corresponding to the abnormal traffic data, including:

[0020] Performing response processing on the security event corresponding to the abnormal traffic data according to a security event response policy; wherein, the response processing includes blocking the abnormal traffic data;

[0021] Classifying the security event corresponding to the abnormal traffic data to improve the statistical features;

[0022] Performing tracking processing on the security event corresponding to the abnormal traffic data to obtain an abnormal traffic path.

[0023] In a second aspect, the present application provides a security event monitoring device based on traffic, including:

[0024] A traffic feature extraction unit, configured to parse the acquired traffic data based on a network protocol parsing library to obtain corresponding traffic feature data;

[0025] An anomaly judgment unit, configured to detect and analyze the traffic feature data to determine whether there is an anomaly in the traffic data;

[0026] A traffic optimization unit, configured to, if there is an anomaly, mark the traffic data as abnormal traffic data and perform security processing on the security events corresponding to the abnormal traffic data.

[0027] Further, the network protocol parsing library includes a TCP parsing library, a UDP parsing library, an HTTP parsing library, and an HTTPS parsing library; the traffic feature extraction unit includes:

[0028] A parameter extraction module, configured to parse the traffic data by using the TCP parsing library, the UDP parsing library, the HTTP parsing library, or the HTTPS parsing library, and extract the parameters of each field of the traffic data; wherein, the parameters include a source IP address, a destination IP address, a source port, a destination port, a packet size, and a transmission timestamp;

[0029] A parameter analysis module, configured to analyze the statistical features, behavior features, content features, and context extraction features of the traffic data according to the parameters.

[0030] Further, the anomaly judgment unit includes:

[0031] A standard screening module, configured to screen the abnormal traffic data according to the standard deviation in the statistical features; or

[0032] A model screening module, configured to input the traffic feature data into a pre-trained random forest model to obtain the abnormal traffic data; wherein, the random forest model is trained by using the historical traffic feature data corresponding to the historical traffic data.

[0033] Further, the anomaly judgment unit includes:

[0034] A time screening module, configured to screen the abnormal traffic data according to the time series in the statistical features; or

[0035] A graph screening module, configured to construct a traffic analysis graph according to the context extraction features, and screen the abnormal traffic data according to the traffic path in the traffic analysis graph.

[0036] Further, the traffic optimization unit includes:

[0037] A response processing module, configured to perform response processing on the security event corresponding to the abnormal traffic data according to a security event response policy; wherein, the response processing includes blocking the abnormal traffic data;

[0038] A classification processing module, configured to perform classification processing on the security event corresponding to the abnormal traffic data to improve statistical features;

[0039] A tracking processing module, configured to perform tracking processing on the security event corresponding to the abnormal traffic data to obtain an abnormal traffic path.

[0040] In a third aspect, the present application provides an electronic device including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps of the traffic-based security event monitoring method are implemented.

[0041] In a fourth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the traffic-based security event monitoring method are implemented.

[0042] In a fifth aspect, the present application provides a computer program product, including a computer program / instructions. When the computer program / instructions are executed by a processor, the steps of the traffic-based security event monitoring method are implemented.

[0043] Aiming at the problems in the prior art, the traffic-based security event monitoring method and device provided by the present application, compared with traditional static defense means such as firewalls and intrusion detection systems, can incorporate adaptive online learning technology, analyze and learn network traffic data in real time, automatically adjust model parameters, and timely identify and respond to new attack patterns without relying on pre-configured rules, thereby greatly improving the detection and defense capabilities against unknown threats; it also accurately identifies potential abnormal data and attack behaviors while processing large-scale network traffic data by integrating high-precision data acquisition, parsing, feature extraction technologies, as well as time series analysis and graph neural network algorithms. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0045] Figure 1 It is a flowchart of the traffic-based security event monitoring method in the embodiments of the present application;

[0046] Figure 2 It is a flowchart for obtaining corresponding traffic feature data in an embodiment of the present application;

[0047] Figure 3 It is one of the flowcharts for determining whether there is an abnormality in traffic data in an embodiment of the present application;

[0048] Figure 4 It is another flowchart for determining whether there is an abnormality in traffic data in an embodiment of the present application;

[0049] Figure 5 It is a flowchart for response, classification, and tracking processing in an embodiment of the present application;

[0050] Figure 6 It is a structural diagram of a traffic-based security event monitoring device in an embodiment of the present application;

[0051] Figure 7 It is a structural diagram of a traffic feature extraction unit in an embodiment of the present application;

[0052] Figure 8 It is one of the structural diagrams of an abnormality judgment unit in an embodiment of the present application;

[0053] Figure 9 It is another structural diagram of an abnormality judgment unit in an embodiment of the present application;

[0054] Figure 10 It is a structural diagram of a traffic optimization unit in an embodiment of the present application;

[0055] Figure 11 It is a schematic structural diagram of an electronic device in an embodiment of the present application. Detailed implementation manners

[0056] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer and more understandable, the following further describes the embodiments of the present invention in detail with reference to the accompanying drawings. Herein, the illustrative embodiments of the present invention and their descriptions are used to explain the present invention, but not to limit the present invention.

[0057] The information collected in the technical solution of the present application is information and data authorized by the user or fully authorized by all parties, and the collection, storage, use, processing, transmission, provision, disclosure, and application of the relevant data, etc., all comply with the relevant laws, regulations, and standards of the relevant countries and regions, take necessary confidentiality measures, do not violate public order and good customs, and provide corresponding operation entrances for the user to choose to authorize or refuse.

[0058] Provide the user with corresponding operation entrances for the user to choose to agree or refuse the automated decision result; if the user chooses to refuse, then enter the expert decision-making process.

[0059] In one embodiment, refer toFigure 1 , in order to be able to analyze network traffic in real time through online adaptive learning, automatically adjust model parameters, timely identify and respond to new attack patterns without relying on pre-configured defense rules, thereby greatly improving the detection and defense capabilities against unknown threats, this application provides a traffic-based security event monitoring method, including:

[0060] S101: Parse the acquired traffic data based on a network protocol parsing library to obtain corresponding traffic feature data;

[0061] S102: Detect and analyze the traffic feature data to determine whether there is an abnormality in the traffic data;

[0062] S103: If there is an abnormality, mark the traffic data as abnormal traffic data and perform security processing on the security event corresponding to the abnormal traffic data.

[0063] It can be understood that the method provided by this application can be implemented by a traffic-based security event monitoring system. The system includes: 1. Data acquisition module; 2. Parsing module; 3. Traffic detection and analysis module; 4. Behavior comparison module; 5. Security warning module; 6. Optimization module; 7. Interaction module. Each module can be connected through network communication.

[0064] Among them, the data acquisition module includes a data capture unit and a data recording unit; the parsing module includes a data parsing unit, a feature extraction unit, and a data storage unit; the traffic detection and analysis module includes a statistics unit and an adaptive unit; the behavior comparison module includes a time series analysis unit and a graph analysis unit; the security warning module includes a response unit, a classification unit, and a tracking unit; the optimization module includes an online learning unit and an incremental learning unit; the interaction module includes a real-time monitoring unit, an event reporting unit, and an event analysis unit.

[0065] The traffic-based security event monitoring method provided by this application specifically includes the following steps:

[0066] First, the data acquisition module performs packet capture operations on each network node through the data capture unit, captures the data information entering and leaving the network, and records detailed traffic information (also known as traffic data) through the data recording unit.

[0067] Next, the parsing module parses the collected traffic data into different feature data. For example, the data parsing unit uses TCP, UDP, HTTP, and HTTPS parsing libraries to parse the original traffic data packets, and extracts the values (also known as parameters) of each field such as the source IP address, destination IP address, source port, destination port, data packet size, and transmission timestamp; the feature extraction unit further extracts the statistical values, behavior features, content features, and context extraction features of the data, and stores the extracted features into the database through the data storage unit for subsequent analysis and query.

[0068] Subsequently, the traffic detection and analysis module calculates the standard deviation of the data packet size through the statistics unit to identify data packets whose sizes exceed the normal range. It can also use the adaptive unit to continuously update the random forest model parameters (for machine learning) using the online learning method, and use the trained random forest model to identify abnormal data traffic.

[0069] Then, the behavior comparison module analyzes the time characteristics of the traffic data through the time series analysis unit to identify continuous abnormal behaviors. It can also construct a traffic map through the map analysis unit, use the graph neural network to analyze the interaction relationships between nodes, and identify complex attack paths. If abnormal data traffic is detected, the security warning module dynamically adjusts the response strategy through the response unit, sends warning messages according to the type and severity of the security event, and automatically blocks the relevant traffic once a high-risk security event is detected to prevent the attack from spreading further. The classification unit classifies different security events to facilitate faster subsequent responses. The tracking unit reconstructs the attack path by analyzing the time and space characteristics of the traffic data, identifies the attacker's nodes, and provides a basis for subsequent tracking and evidence collection. The optimization module updates the model parameters in real time through the online learning unit to adapt to different traffic patterns, and gradually increases the training data through the incremental learning unit to improve the generalization ability of the model.

[0070] Finally, the interaction module provides a real-time monitoring interface through the real-time monitoring unit to display the current network traffic status and detected security events. The event reporting unit generates a detailed event report, including the event type, time, path, and involved nodes. The event analysis unit conducts in-depth analysis of the events to help administrators conduct comprehensive security management.

[0071] As can be seen from the above description, the traffic-based security event monitoring method and device provided by this application can identify and respond to new attack patterns in a timely manner compared with traditional static defense means such as firewalls and intrusion detection systems, without relying on pre-configured rules, thus greatly improving the detection and defense capabilities against unknown threats; it also integrates high-precision data collection, parsing, feature extraction technologies, as well as time series analysis and graph neural network algorithms, etc., to accurately identify potential abnormal data and attack behaviors while processing large-scale network traffic data.

[0072] In one embodiment, refer to Figure 2 , the network protocol parsing library includes a TCP parsing library, a UDP parsing library, an HTTP parsing library, and an HTTPS parsing library; parsing the obtained traffic data based on the network protocol parsing library to obtain corresponding traffic feature data, including:

[0073] S201: Use the TCP parsing library, UDP parsing library, HTTP parsing library, or HTTPS parsing library to parse the traffic data and extract the parameters of each field of the traffic data; where the parameters include source IP address, destination IP address, source port, destination port, packet size, and transmission timestamp;

[0074] S202: Analyze the statistical features, behavioral features, content features, and context extraction features of the traffic data according to the parameters.

[0075] It can be understood that the data collection module is used to collect network traffic data. Specifically, the data collection module includes a data capture unit and a data recording unit. The data capture unit is mainly used to capture the data information in and out of the network. The data recording unit mainly records detailed traffic information. The data capture unit can install a packet capture tool on the network node with the user's permission.

[0076] The parsing module is mainly used to parse the collected traffic data into different feature data. Specifically, the parsing module includes a data parsing unit, a feature extraction unit, and a data storage unit. The data parsing unit is mainly used to parse the original traffic data packet and extract the numerical values of each field. The parsing method uses parsing libraries including but not limited to TCP, UDP, HTTP, and HTTPS. The extracted numerical values include but not limited to source IP address, destination IP address, source port, destination port, packet size, and transmission timestamp, etc. The feature extraction unit mainly extracts the statistical features, behavioral features, content features, and context extraction features of the data.

[0077] Specifically, the specific representation form of the statistical feature can be calculated by the following formula:

[0078] Packet length statistics:

[0079]

[0080] max(x) = max(x i )

[0081] min(x) = min(x i )

[0082] where, represents the average value of the data packet length, σ represents the standard deviation of the data packet length, max(x) and min(x) respectively represent the maximum and minimum values of the data packet length x, n represents the number of data packet samples, and x i represents the length of the i-th data packet.

[0083] Time interval statistics:

[0084]

[0085] where, represents the average value of the time interval, σ t represents the standard deviation of the time interval, t i+1 -t i represents the time interval between the i-th data packet and the (i + 1)-th data packet, n represents the number of data packet samples, and t i represents the transmission timestamp of the i-th data packet.

[0086] Behavior characteristics: Can be extracted by analyzing the sessions of network traffic, such as session duration, session data volume, session frequency, and session pattern. The specific formulas are as follows:

[0087] Session duration = t last -t first

[0088] Session data volume = ∑ i = 1 n x i

[0089]

[0090] where, t last is the session end time, and t first is the session start time. The meanings of other symbols are the same as above.

[0091] Content characteristics: Can be extracted by parsing the content of data packets, such as using the method of HTTP requests, obtaining the URL of HTTP requests, and keywords in data packets. The specific steps are as follows: First, use regular expressions to parse HTTP requests to extract the request method and URL, and then perform keyword matching on data packets to identify sensitive information or known attack patterns.

[0092] Context features: Can be extracted by analyzing the data packet sequence, such as extracting the time interval between the previous and subsequent data packets, the size change of the previous and subsequent data packets, and the historical session pattern. The specific steps are as follows: First, use the sliding window technique to extract the time interval and size change in the data packet sequence, and then combine the historical session pattern to identify abnormal behaviors.

[0093] The data storage unit mainly stores the extracted features in the database for subsequent analysis and query. Among them, the feature extraction can refer to the following formula:

[0094]

[0095] x max = max(x1, x2, …, x N )

[0096] x min = min(x1, x2, …, x N )

[0097] Among them, μ represents the average value of the data packet size, σ represents the standard deviation of the data packet size, x max represents the maximum value of the data packet size, x min represents the minimum value of the data packet size, N represents the number of data packet samples, and x i represents the length of the i-th data packet.

[0098] Δt i = t i+1 - t i

[0099]

[0100] Among them, Δt i represents the time interval between the i-th data packet and the (i + 1)-th data packet, μ Δt represents the average value of the time interval, σ Δt represents the standard deviation of the time interval, N represents the number of data packet samples, t i represents the transmission timestamp of the i-th data packet, and t i+1 represents the transmission timestamp of the (i + 1)-th data packet.

[0101]

[0102] Among them, f represents the data packet frequency, and N represents the number of data packets captured within time T.

[0103] As can be seen from the above description, the traffic-based security event monitoring method provided by this application can parse the obtained traffic data based on a network protocol parsing library to obtain corresponding traffic feature data.

[0104] In one embodiment, referring to Figure 3 , detecting and analyzing the traffic feature data to determine whether there is an abnormality in the traffic data includes:

[0105] S301: Screening the abnormal traffic data according to the standard deviation in the statistical features; (or)

[0106] S302: Inputting the traffic feature data into a pre-trained random forest model to obtain the abnormal traffic data; wherein, the random forest model is trained using historical traffic feature data corresponding to historical traffic data.

[0107] It can be understood that the traffic detection and analysis module is mainly used to analyze the obtained data and identify the abnormal data therein. Specifically, the traffic detection and analysis module includes a statistical unit and an adaptive unit. The statistical unit is mainly used to calculate the standard deviation of the packet size and identify packets that exceed the normal range. The adaptive unit is mainly updated continuously through an online learning method and adopts a random forest model. The reference formula is as follows:

[0108] Entropy formula:

[0109]

[0110] where p i is the probability of class i.

[0111] Information gain formula:

[0112]

[0113] where S is the data set, S v is the subset of the data set where the feature X has the value v, H(Y|X = v) is the conditional entropy given that the feature X has the value v, and values(X) are the values of X.

[0114] Furthermore, for the standard deviation screening in step S301, the specific implementation steps include:

[0115] 1. Calculate the standard deviation σ of the packet size;

[0116] 2. Set a threshold σ threshold , for example, 3 times the standard deviation; 3. Identify the packets whose standard deviation exceeds the threshold:

[0117]

[0118] Represents the average value of the data packet length, x i Represents the length of the i-th data packet.

[0119] For the screening of the random forest model in step S302, the specific implementation steps include:

[0120] 1. Pre-train a random forest model using the historical traffic feature data corresponding to the historical traffic data for training; 2. Input the current traffic feature data into the random forest model, and the model outputs the anomaly probability; 3. Set a threshold Prob threshold , for example, 0.7; 4. Identify the traffic data with an anomaly probability exceeding the threshold:

[0121] Anomaly traffic data = {traffic feature data | model output probability > Prob threshold}

[0122] As can be seen from the above description, the traffic-based security event monitoring method provided by this application can detect and analyze the traffic feature data to determine whether there is an anomaly in the traffic data.

[0123] In one embodiment, referring to Figure 4 , detecting and analyzing the traffic feature data to determine whether there is an anomaly in the traffic data includes:

[0124] S401: Screen the anomaly traffic data according to the time series in the statistical features; (or)

[0125] S402: Construct a traffic analysis map based on the features extracted from the context to screen the anomaly traffic data according to the traffic path in the traffic analysis map.

[0126] It can be understood that the behavior comparison module compares the normal network behavior pattern with the detected abnormal data. Specifically, the behavior comparison module includes a time series analysis unit and a map analysis unit. The time series analysis unit mainly analyzes the time features of the traffic data.

[0127] The time features mainly include the following parameters, which is a "sequence";

[0128] Transmission timestamp: The transmission time of each data packet, expressed as {t1, t2,..., t n};

[0129] Time interval between data packets: The transmission time difference between adjacent data packets, expressed as {Δt1, Δt2,..., Δt n-1};

[0130] where, Δt i = t i+1 - ti 。

[0131] Then, identify continuous abnormal behaviors. The graph analysis unit mainly identifies complex attack paths by constructing a traffic graph and using a graph neural network to analyze the interaction relationships between nodes. The time series analysis unit can refer to the following formula:

[0132]

[0133] where ρ k represents the autocorrelation coefficient of the time series x t at lag k, μ represents the average value of the time series, and N represents the length of the time series;

[0134] time series;

[0135]

[0136] where x t represents the value of the time series at time t, x t-i represents the value of the time series at time t - i, c is a constant term, φ i is the autoregressive coefficient, p is the order of autoregression, and ∈ t is white noise at time t;

[0137]

[0138] where μ represents the average value of the time series, θ i is the moving average coefficient, q is the order of moving average, and ∈ t is white noise at time t, and ∈ t-i is white noise at time t - i.

[0139] For step S402, it can use a graph neural network (GNN) to construct a traffic graph. Each node represents a device or IP address in the network, and the edge represents the communication relationship between devices. Timestamps and packet sizes are used as the weights of the edges.

[0140] The specific steps include: 1. Convert the extracted traffic feature data into a graph structure. 2. Use the GNN model to analyze the graph structure and identify high-risk nodes and paths. 3. Screen abnormal traffic data according to the output of the GNN model.

[0141] As can be seen from the above description, the traffic-based security event monitoring method provided by this application can detect and analyze the traffic feature data to determine whether there are abnormalities in the traffic data.

[0142] In one embodiment, referring to Figure 5 , the security processing of the security event corresponding to the abnormal traffic data includes:

[0143] S501: Respond to the security event corresponding to the abnormal traffic data according to the security event response policy; wherein, the response processing includes blocking the abnormal traffic data.

[0144] S502: Classify the security event corresponding to the abnormal traffic data to improve the statistical features.

[0145] S503: Track the security event corresponding to the abnormal traffic data to obtain the abnormal traffic path.

[0146] It can be understood that the security warning module is mainly used to give warnings when detecting abnormal data. Specifically, the security warning module includes a response unit, a classification unit, and a tracking unit. The response unit is mainly used to dynamically adjust the response policy according to the security event type and severity, including but not limited to sending warning messages. Once a high-risk security event is detected, it automatically blocks the relevant traffic to prevent the attack from spreading further.

[0147] Among them, the presetting of the security event type and severity: Through expert knowledge and historical data, different types of network attacks and their severities are preset. For example, SQL injection attacks are high-risk events, while a large number of HTTP requests may be medium-risk events.

[0148] For the security event response policy: Dynamically adjust the response policy according to the preset security event type and severity. The specific policies can include: (1) Sending a warning email: including the event type, time, path, and involved nodes. (2) Blocking the relevant traffic: For high-risk events, immediately block the traffic of the relevant IP address or port.

[0149] For the classification processing: Machine learning algorithms (such as decision trees, K-means, etc.) can be used to classify the abnormal traffic data. The specific steps can include: 1. Extract the features of the abnormal traffic data. 2. Use the classification algorithm to classify the extracted features. 3. Generate the classification results and improve the statistical features.

[0150] For the extraction of time and space features:

[0151] Among them, the time feature includes the transmission timestamp sequence of the data packet; the space feature includes the source IP address, destination IP address, etc. of the data packet.

[0152] By analyzing these features, reconstruct the attack path.

[0153] The classification unit mainly classifies different security events to facilitate faster subsequent responses. The tracking unit mainly reconstructs the attack path by analyzing the time and space features of the traffic data, identifies the attacker's nodes, and provides a basis for subsequent tracking and evidence collection.

[0154] Specifically, the time features and space features are included in the features extracted in the foregoing feature extraction step.

[0155] The time features correspond to the "transmission timestamp", which is the time feature extracted from the feature extraction unit 202; and also correspond to the "time interval between data packets", which is the time interval feature extracted from the feature extraction unit 202.

[0156] The space features correspond to the "source IP address" and "destination IP address", which are the IP address features extracted from the feature extraction unit 202; and also correspond to the "source port" and "destination port", which are the port features extracted from the feature extraction unit 202.

[0157] The specific implementation process of this step includes:

[0158] 1. Time feature analysis: According to the timestamp sequence, identify continuous abnormal behaviors, for example, a large number of data packet transmissions in a short period of time.

[0159] 2. Space feature analysis: According to the source IP address and destination IP address, identify the paths of abnormal communications.

[0160] 3. Graph construction: Use time features and space features to construct a traffic graph.

[0161] 4. GNN analysis: Use a graph neural network to analyze the graph and identify high-risk nodes and paths.

[0162] 5. Path reconstruction: According to the output of the GNN, reconstruct the attack path and identify the attacker's nodes.

[0163] The optimization module performs relevant processing and optimization on the detected data. Specifically, the optimization module includes an online learning unit and an incremental learning unit. The online learning unit mainly updates the model parameters in real time through an online learning method, so as to be able to adapt to different traffic patterns. The incremental learning unit mainly improves the generalization ability of the model by gradually increasing the training data. This model includes the aforementioned random forest model.

[0164] The interaction module is mainly used for the administrator to control the system. Specifically, the interaction module includes a real-time monitoring unit, an event reporting unit, and an event analysis unit. The real-time monitoring unit mainly provides a real-time monitoring interface to display the current state of network traffic and the detected security events. The event reporting unit mainly generates a detailed event report, including but not limited to the event type, time, path, and involved nodes.

[0165] As can be seen from the above description, the traffic-based security event monitoring method provided by this application can perform security processing on the security events corresponding to the abnormal traffic data.

[0166] In summary, the overall process of the method provided by this application is as follows:

[0167] First, the data collection module installs packet capture tools on each network node through the data scraping unit, captures the data information flowing in and out of the network, and records detailed traffic information through the data recording unit;

[0168] Next, the parsing module parses the collected traffic data into different feature data. The data parsing unit uses TCP, UDP, HTTP, and HTTPS parsing libraries to parse the original traffic data packets, extracts the values of each field such as source IP address, destination IP address, source port, destination port, packet size, and transmission timestamp. The feature extraction unit further extracts the statistical values, behavior features, content features, and context extraction features of the data, and stores the extracted features in the database through the data storage unit for subsequent analysis and query;

[0169] Subsequently, the traffic detection and analysis module calculates the standard deviation of the packet size through the statistics unit, identifies the packets that exceed the normal range, and uses the online learning method through the adaptive unit to continuously update the model parameters, and uses the random forest model to identify abnormal data;

[0170] Then, the behavior comparison module analyzes the time characteristics of the traffic data through the time series analysis unit to identify continuous abnormal behaviors, constructs a traffic map through the map analysis unit, uses a graph neural network to analyze the interaction relationship between nodes, and identifies complex attack paths. If abnormal data is detected, the security warning module dynamically adjusts the response strategy through the response unit, sends an alarm email according to the type and severity of the security event. Once a high-risk security event is detected, the relevant traffic is automatically blocked to prevent the attack from spreading further. The classification unit classifies different security events for more rapid subsequent response. The tracking unit reconstructs the attack path by analyzing the time and space characteristics of the traffic data, identifies the attacker's node, and provides a basis for subsequent tracking and evidence collection. The optimization module updates the model parameters in real time through the online learning unit to adapt to different traffic patterns, and gradually increases the training data through the incremental learning unit to improve the generalization ability of the model;

[0171] Finally, the interaction module provides a real-time monitoring interface through the real-time monitoring unit to display the current network traffic status and detected security events. The event reporting unit generates a detailed event report, including the event type, time, path, and involved nodes. The event analysis unit conducts in-depth analysis of the event to help the administrator conduct comprehensive security management.

[0172] Based on the same inventive concept, an embodiment of the present application further provides a traffic-based security event monitoring device, which can be used to implement the method described in the above embodiment, as described in the following embodiment. Since the principle of the traffic-based security event monitoring device for solving problems is similar to that of the traffic-based security event monitoring method, the implementation of the traffic-based security event monitoring device can refer to the implementation of the method for determining software performance benchmarks, and the repeated parts will not be described again. As used hereinafter, the term "unit" or "module" can be a combination of software and / or hardware that can achieve a predetermined function. Although the system described in the following embodiments is preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.

[0173] In one embodiment, referring to Figure 6 , in order to be able to analyze network traffic in real time through online adaptive learning, automatically adjust model parameters, and timely identify and respond to new attack patterns without relying on pre-configured defense rules, thereby greatly improving the detection and defense capabilities against unknown threats, the present application provides a traffic-based security event monitoring device, including: a traffic feature extraction unit 601, an anomaly judgment unit 602, and a traffic optimization unit 603.

[0174] The traffic feature extraction unit 601 is configured to parse the acquired traffic data based on a network protocol parsing library to obtain corresponding traffic feature data;

[0175] The anomaly judgment unit 602 is configured to detect and analyze the traffic feature data to determine whether there is an anomaly in the traffic data;

[0176] The traffic optimization unit 603 is configured to, if there is an anomaly, mark the traffic data as abnormal traffic data and perform security processing on the security event corresponding to the abnormal traffic data.

[0177] In one embodiment, referring to Figure 7 , the network protocol parsing library includes a TCP parsing library, a UDP parsing library, an HTTP parsing library, and an HTTPS parsing library; the traffic feature extraction unit 601 includes: a parameter extraction module 701 and a parameter analysis module 702.

[0178] The parameter extraction module 701 is configured to parse the traffic data by using the TCP parsing library, the UDP parsing library, the HTTP parsing library, or the HTTPS parsing library to extract the parameters of each field of the traffic data; wherein, the parameters include a source IP address, a destination IP address, a source port, a destination port, a packet size, and a transmission timestamp;

[0179] The parameter analysis module 702 analyzes the statistical features, behavioral features, content features, and context extraction features of the traffic data according to the parameters.

[0180] In one embodiment, referring to Figure 8 , the anomaly judgment unit 602 includes: a standard screening module 801 and a model screening module 802.

[0181] The standard screening module 801 is configured to screen the abnormal traffic data according to the standard deviation in the statistical features; (or)

[0182] The model screening module 802 is configured to input the traffic feature data into a pre-trained random forest model to obtain the abnormal traffic data; wherein, the random forest model is trained using the historical traffic feature data corresponding to the historical traffic data.

[0183] In one embodiment, referring to Figure 9 , the anomaly judgment unit 602 includes:

[0184] The time screening module 901 is configured to screen the abnormal traffic data according to the time series in the statistical features; (or)

[0185] The atlas screening module 902 is configured to extract features from the context to construct a traffic analysis atlas, and screen the abnormal traffic data according to the traffic path in the traffic analysis atlas.

[0186] In one embodiment, referring to Figure 10 , the traffic optimization unit 603 includes:

[0187] The response processing module 1001 is configured to perform response processing on the security event corresponding to the abnormal traffic data according to the security event response policy; wherein, the response processing includes blocking the abnormal traffic data;

[0188] The classification processing module 1002 is configured to perform classification processing on the security event corresponding to the abnormal traffic data to improve the statistical features;

[0189] The tracking processing module 1003 is configured to perform tracking processing on the security event corresponding to the abnormal traffic data to obtain an abnormal traffic path.

[0190] From a hardware perspective, in order to be able to perform real-time analysis of network traffic through online adaptive learning, automatically adjust model parameters, and timely identify and respond to new attack patterns without relying on pre-configured defense rules, thereby greatly improving the detection and defense capabilities against unknown threats, the present application provides an embodiment of an electronic device for implementing all or part of the content in the above-mentioned traffic-based security event monitoring method. The electronic device specifically includes the following:

[0191] A processor, a memory, a communications interface, and a bus; wherein, the processor, the memory, and the communications interface complete communication with each other through the bus; the communications interface is used to implement information transmission between the traffic-based security event monitoring device and related devices such as a core business system, a user terminal, and a related database, etc.; the logic controller can be a desktop computer, a tablet computer, a mobile terminal, etc., and this embodiment is not limited thereto. In this embodiment, the logic controller can be implemented with reference to the embodiments of the traffic-based security event monitoring method and the embodiments of the traffic-based security event monitoring device in the embodiments, the content of which is incorporated herein, and the repeated parts will not be elaborated again.

[0192] It can be understood that the user terminal can include a smart phone, a tablet electronic device, a network set-top box, a portable computer, a desktop computer, a personal digital assistant (PDA), a vehicle-mounted device, a smart wearable device, etc. Among them, the smart wearable device can include smart glasses, a smart watch, a smart bracelet, etc.

[0193] In practical applications, part of the traffic-based security event monitoring method can be executed on the electronic device side as described above, or all operations can be completed in the client device. Specifically, it can be selected according to the processing capacity of the client device and the limitations of the user usage scenario, etc. This application does not make any limitations in this regard. If all operations are completed in the client device, the client device may further include a processor.

[0194] The above-mentioned client device can have a communication module (i.e., a communication unit), and can be communicatively connected to a remote server to realize data transmission with the server. The server can include a server on the task scheduling center side, and in other implementation scenarios, it can also include a server of an intermediate platform, such as a server of a third-party server platform having a communication link with the task scheduling center server. The server can include a single computer device, or can include a server cluster composed of multiple servers, or a server structure of a distributed device.

[0195] Figure 11 This is a schematic block diagram of the system composition of the electronic device 9600 according to an embodiment of the present application. As Figure 11 shown, the electronic device 9600 can include a central processing unit 9100 and a memory 9140; the memory 9140 is coupled to the central processing unit 9100. It should be noted that this Figure 11 is exemplary; other types of structures can also be used to supplement or replace this structure to implement telecommunication functions or other functions.

[0196] In one embodiment, the function of the traffic-based security event monitoring method can be integrated into the central processing unit 9100. Among them, the central processing unit 9100 can be configured to perform the following controls:

[0197] S101: Parse the acquired traffic data based on the network protocol parsing library to obtain the corresponding traffic feature data;

[0198] S102: Detect and analyze the traffic feature data to determine whether there is an abnormality in the traffic data;

[0199] S103: If there is an abnormality, mark the traffic data as abnormal traffic data and perform security processing on the security event corresponding to the abnormal traffic data.

[0200] As can be seen from the above description, the traffic-based security event monitoring method and device provided by the present application can integrate adaptive online learning technology compared with traditional static defense means such as firewalls and intrusion detection systems, analyze and learn network traffic data in real time, automatically adjust model parameters, and timely identify and respond to new attack patterns without relying on pre-configured rules, thus greatly improving the detection and defense capabilities against unknown threats; it also accurately identifies potential abnormal data and attack behaviors while processing large-scale network traffic data by integrating high-precision data acquisition, parsing, feature extraction technologies, as well as time series analysis and graph neural network algorithms.

[0201] In another embodiment, the traffic-based security event monitoring device can be separately configured from the central processing unit 9100. For example, the traffic-based security event monitoring device of the data composite transmission device can be configured as a chip connected to the central processing unit 9100, and the function of the traffic-based security event monitoring method can be realized through the control of the central processing unit.

[0202] As Figure 11 shown, the electronic device 9600 may further include: a communication module 9110, an input unit 9120, an audio processor 9130, a display 9160, and a power supply 9170. It should be noted that the electronic device 9600 does not necessarily have to include all the components shown in Figure 11 ; in addition, the electronic device 9600 may further include components not shown in Figure 11 , and reference can be made to the prior art.

[0203] As Figure 11 shown, the central processing unit 9100 is sometimes also referred to as a controller or an operation control, and may include a microprocessor or other processor devices and / or logic devices. The central processing unit 9100 receives inputs and controls the operations of the various components of the electronic device 9600.

[0204] Among them, the memory 9140 can be, for example, one or more of a buffer, a flash memory, a hard drive, a removable medium, a volatile memory, a non-volatile memory, or other suitable devices. It can store the above information related to failures, and can also store programs for executing relevant information. And the central processing unit 9100 can execute the program stored in the memory 9140 to implement information storage or processing, etc.

[0205] The input unit 9120 provides input to the central processing unit 9100. The input unit 9120 is, for example, a key or a touch input device. The power supply 9170 is used to supply power to the electronic device 9600. The display 9160 is used to display display objects such as images and texts. The display can be, for example, an LCD display, but is not limited thereto.

[0206] The memory 9140 can be a solid-state memory. For example, a read-only memory (ROM), a random access memory (RAM), a SIM card, etc. It can also be a memory that stores information even when power is off, can be selectively erased, and has more data. An example of this memory is sometimes called an EPROM, etc. The memory 9140 can also be some other type of device. The memory 9140 includes a buffer memory 9141 (sometimes called a buffer). The memory 9140 can include an application / function storage unit 9142, which is used to store application programs and function programs or the processes for operating the electronic device 9600 through the central processing unit 9100.

[0207] The memory 9140 can also include a data storage unit 9143, which is used to store data, such as contacts, digital data, pictures, sounds, and / or any other data used by the electronic device. The driver storage unit 9144 of the memory 9140 can include various drivers of the electronic device for communication functions and / or for executing other functions of the electronic device (such as a messaging application, an address book application, etc.).

[0208] The communication module 9110 is a transmitter / receiver that transmits and receives signals via the antenna 9111. The communication module (transmitter / receiver) 9110 is coupled to the central processing unit 9100 to provide input signals and receive output signals, which can be the same as in the case of a conventional mobile communication terminal.

[0209] Based on different communication technologies, in the same electronic device, multiple communication modules 9110 can be provided, such as a cellular network module, a Bluetooth module, and / or a wireless local area network module, etc. The communication module (transmitter / receiver) 9110 is also coupled to a speaker 9131 and a microphone 9132 via an audio processor 9130 to provide an audio output via the speaker 9131 and receive an audio input from the microphone 9132, so as to implement normal telecommunication functions. The audio processor 9130 can include any suitable buffers, decoders, amplifiers, etc. In addition, the audio processor 9130 is also coupled to a central processor 9100, so that recording can be performed on the local device through the microphone 9132, and the sound stored on the local device can be played through the speaker 9131.

[0210] Embodiments of the present application also provide a computer-readable storage medium capable of implementing all steps of the traffic-based security event monitoring method with the execution subject being a server or a client in the above embodiments. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, all steps of the traffic-based security event monitoring method with the execution subject being a server or a client in the above embodiments are implemented. For example, when the processor executes the computer program, the following steps are implemented:

[0211] S101: Parse the obtained traffic data based on a network protocol parsing library to obtain corresponding traffic feature data;

[0212] S102: Detect and analyze the traffic feature data to determine whether there is an abnormality in the traffic data;

[0213] S103: If there is an abnormality, mark the traffic data as abnormal traffic data, and perform security processing on the security event corresponding to the abnormal traffic data.

[0214] As can be seen from the above description, compared with traditional static defense means such as firewalls and intrusion detection systems, the traffic-based security event monitoring method and device provided by the present application can incorporate adaptive online learning technology, analyze and learn network traffic data in real time, automatically adjust model parameters, and timely identify and respond to new attack patterns without relying on pre-configured rules, thereby greatly improving the detection and defense capabilities against unknown threats; it also accurately identifies potential abnormal data and attack behaviors while processing large-scale network traffic data by integrating high-precision data collection, parsing, feature extraction technologies, as well as time series analysis and graph neural network algorithms.

[0215] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, apparatus, or computer program product. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) that contain computer-usable program code.

[0216] The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (apparatuses), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0217] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device realizes the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0218] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide steps for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0219] Specific embodiments are applied in the present invention to elaborate on the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A traffic-based security event monitoring method, characterized in that: include: Analyze the acquired traffic data based on the network protocol analysis library to obtain the corresponding traffic characteristic data; Detecting and analyzing the flow characteristic data to determine whether the flow data is abnormal; If there is an abnormality, the traffic data is marked as abnormal traffic data, and the security event corresponding to the abnormal traffic data is securely processed.

2. The method for monitoring security events based on traffic according to claim 1, characterized in that: The network protocol parsing library includes a TCP parsing library, a UDP parsing library, an HTTP parsing library and an HTTPS parsing library; The network protocol parsing library is used to parse the acquired traffic data to obtain corresponding traffic characteristic data, including: Parsing the traffic data using the TCP parsing library, UDP parsing library, HTTP parsing library or HTTPS parsing library to extract parameters of each field of the traffic data; wherein the parameters include source IP address, destination IP address, source port, destination port, data packet size and transmission timestamp; The statistical characteristics, behavioral characteristics, content characteristics and context extraction characteristics of the traffic data are analyzed according to the parameters.

3. The method for monitoring security events based on traffic according to claim 2, characterized in that: The detecting and analyzing the flow characteristic data to determine whether the flow data is abnormal includes: Screening the abnormal traffic data according to the standard deviation in the statistical feature; or The flow characteristic data is input into a pre-trained random forest model to obtain the abnormal flow data; wherein the random forest model is trained using historical flow characteristic data corresponding to historical flow data.

4. The method for monitoring security events based on traffic according to claim 2, characterized in that: The detecting and analyzing the flow characteristic data to determine whether the flow data is abnormal includes: Screening the abnormal traffic data according to the time series in the statistical features; or A traffic analysis map is constructed based on the context extraction features to screen the abnormal traffic data based on the traffic paths in the traffic analysis map.

5. The method for monitoring security events based on traffic according to claim 1, characterized in that: The security processing includes response processing, classification processing and tracking processing; The performing security processing on the security event corresponding to the abnormal traffic data includes: Responding to the security incident corresponding to the abnormal traffic data according to the security incident response strategy; wherein the response processing includes blocking the abnormal traffic data; Classify and process the security events corresponding to the abnormal traffic data to improve the statistical features; or The security events corresponding to the abnormal traffic data are tracked and processed to obtain the abnormal traffic path.

6. A flow-based security event monitoring device, characterized in that: include: A flow feature extraction unit, used to parse the acquired flow data based on the network protocol parsing library to obtain corresponding flow feature data; An abnormality judgment unit, used to detect and analyze the flow characteristic data to determine whether the flow data is abnormal; The traffic optimization unit is used to mark the traffic data as abnormal traffic data if an abnormality exists, and to perform security processing on the security event corresponding to the abnormal traffic data.

7. The flow-based security event monitoring device according to claim 6, characterized in that: The network protocol parsing library includes a TCP parsing library, a UDP parsing library, an HTTP parsing library and an HTTPS parsing library; The flow feature extraction unit comprises: A parameter extraction module, used to parse the traffic data using the TCP parsing library, UDP parsing library, HTTP parsing library or HTTPS parsing library, and extract parameters of each field of the traffic data; wherein the parameters include source IP address, destination IP address, source port, destination port, data packet size and transmission timestamp; The parameter analysis module analyzes the statistical characteristics, behavioral characteristics, content characteristics and context extraction characteristics of the traffic data according to the parameters.

8. The flow-based security event monitoring device according to claim 7, characterized in that: The abnormality judgment unit comprises: A standard screening module, used for screening the abnormal flow data according to the standard deviation in the statistical feature; or The model screening module is used to input the traffic characteristic data into a pre-trained random forest model to obtain the abnormal traffic data; wherein the random forest model is trained using historical traffic characteristic data corresponding to historical traffic data.

9. The flow-based security event monitoring device according to claim 7, characterized in that: The abnormality judgment unit comprises: A time screening module, used for screening the abnormal traffic data according to the time series in the statistical features; or The graph screening module is used to construct a traffic analysis graph based on the context extraction features, so as to screen the abnormal traffic data according to the traffic path in the traffic analysis graph.

10. The flow-based security event monitoring device according to claim 6, characterized in that: The security processing includes response processing, classification processing and tracking processing; The traffic optimization unit comprises: A response processing module, used for performing response processing on the security event corresponding to the abnormal traffic data according to the security event response strategy; wherein the response processing includes blocking the abnormal traffic data; A classification processing module is used to classify the security events corresponding to the abnormal traffic data and improve the statistical characteristics; or The tracking and processing module is used to track and process the security events corresponding to the abnormal traffic data to obtain the abnormal traffic path.

11. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the steps of the flow-based security event monitoring method described in any one of claims 1 to 5 are implemented.

12. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the flow-based security event monitoring method described in any one of claims 1 to 5 are implemented.

13. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instruction is executed by a processor, the steps of the flow-based security event monitoring method described in any one of claims 1 to 5 are implemented.

Citation Information

Cited By

  • Encryption protocol structure restoration method and system based on graph neural network

    CN120750678A