Network attack detection method and system based on event-driven architecture
Through the network attack detection method based on the event-driven architecture, multi-layer packet characteristics are analyzed, detection thresholds are dynamically adjusted, and communication connections are constructed to analyze graph models. The problem of difficulty in detecting multi-stage attacks in traditional methods is solved, and precise attack detection and defense is achieved in complex network environments.
Patent Information
- Application Number
- CN202510427333.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-07
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2045-04-07
AI Technical Summary
Traditional cyberattack detection methods are difficult to effectively deal with complex and changeable network environments, especially when facing multi-stage attacks, it is difficult to analyze the attack link through the correlation of paths and communication frequency characteristics, resulting in limited attack defense capabilities.
The network attack detection method based on the event-driven architecture is adopted, and multi-layer packet feature mapping information is established by analyzing the application layer and transmission layer parameters, extracting non-standard ports and abnormal data packets, dynamically adjusting the detection threshold, building a graph model to analyze communication connections between nodes, generating network abnormal event association information, and finally filtering potential attack behaviors.
It realizes accurate detection of potential attacks in complex network environments, dynamically adjusts detection thresholds to adapt to changes in network environments, quickly locates high-frequency communication entities and attack paths, and improves attack defense capabilities.
Smart Images

Figure CN120165952A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security, and in particular to a network attack detection method and system based on an event-driven architecture. Background Art
[0002] The technical field of network security includes strategies and technologies for protecting computer networks, data, software, and other information technology assets from unauthorized access, attacks, and damage. The network security field covers a variety of defense mechanisms from physical security measures to encryption technologies. The core content of network security includes defending against external attacks, internal leaks, and abuse of network services, ensuring the confidentiality, integrity, and availability of information, involving the application of attack detection systems, firewalls, intrusion prevention systems, and encryption technologies, aiming to create a secure network environment to resist evolving network threats.
[0003] Among them, the network attack detection method refers to monitoring network activities through automated tools and technologies to discover potential malicious behaviors and threats. The technical matters targeted by this method cover using behavior pattern matching and anomaly detection technologies to identify suspicious activities, and achieving attack detection by real-time monitoring of network traffic, analyzing the content of data packets, and comparing known attack patterns, thereby identifying abnormal behaviors. Network attack detection aims to quickly identify and prevent potential attack behaviors by real-time analyzing network traffic and data packets, and adopting specific analysis methods and protocol reviews.
[0004] Traditional detection methods rely on fixed pattern matching and static anomaly detection mechanisms, and it is difficult to effectively cope with complex and changeable network environments. For example, fixed pattern matching can only detect known attack behaviors, but when facing unknown threats and new attack patterns, the detection effect significantly decreases; static anomaly detection methods are usually based on preset rules or thresholds and are difficult to adapt to the dynamic changes of real-time network traffic. When the network environment fluctuates significantly, it will lead to a high false alarm rate or missed alarm rate, reducing the detection accuracy and missing key clues of hidden attack behaviors. For example, in the face of multi-stage attacks, traditional methods are difficult to analyze the attack link through path and communication frequency feature correlation, resulting in a significant limitation of the attack defense ability. Summary of the Invention
[0005] In order to solve the technical problem in the prior art that in the face of multi-stage attacks, traditional methods are difficult to analyze the attack link through path and communication frequency feature correlation, resulting in a significant limitation of the attack defense ability, the embodiments of the present invention provide a network attack detection method and system based on an event-driven architecture. The technical solution is as follows:
[0006] On the one hand, a network attack detection method based on an event-driven architecture is provided. This method is implemented by a network attack detection device based on the event-driven architecture, and the method includes:
[0007] S1. Based on the target network environment, by parsing application layer parameters and combining transport layer parameters, establish a multi-layer mapping table according to field relationships to obtain multi-layer packet feature mapping information;
[0008] S2. Based on the multi-layer packet feature mapping information, extract the usage of non-standard ports and packets that do not conform to the path specification, establish an exception group by combining path values and port information, and generate a multi-layer abnormal behavior recognition result;
[0009] S3. Based on the multi-layer abnormal behavior recognition result, extract the time interval distribution value of abnormal packets and the packet length statistical value, and combine the normal distribution range of historical network behavior records to dynamically adjust the detection threshold range and path determination rules to obtain an adaptive detection threshold rule set;
[0010] S4. Based on the adaptive detection threshold rule set, construct a graph model with communication entities as nodes and paths as edges, analyze the change value of the number of communication connections between nodes and the growth rate of abnormal path values in the edge set, extract the number of new connections between nodes and the abnormal increment distribution value of the edge set, and generate network anomaly event association information;
[0011] S5. Based on the network anomaly event association information, compare the path value distribution feature with the association feature of known attack event records, and screen the node pair combinations and path distributions that conform to the potential attack behavior characteristics to obtain a potential network attack detection result.
[0012] On the other hand, a network attack detection system based on an event-driven architecture is provided. This system is applied to the network attack detection method based on the event-driven architecture, and the system includes:
[0013] A data parsing unit, configured to establish a multi-layer mapping table according to field relationships based on the target network environment by parsing application layer parameters and combining transport layer parameters to obtain multi-layer packet feature mapping information;
[0014] An abnormal behavior analysis unit, configured to extract the usage of non-standard
[0015] ports and packets that do not conform to the path specification based on the multi-layer packet feature mapping information, establish an exception group by combining path values and port information, and generate a multi-layer abnormal behavior recognition result;
[0016] A detection threshold adjustment unit, configured to extract the time interval distribution value of abnormal data packets and the packet length statistical value based on the multi-layer abnormal behavior recognition result, and combine the normal distribution range of the historical network behavior record to dynamically adjust the detection threshold range and the path determination rule, so as to obtain an adaptive detection threshold rule set;
[0017] An abnormal event analysis unit, configured to construct a graph model with communication entities as nodes and paths as edges based on the adaptive detection threshold rule set, analyze the change value of the communication connection times between nodes and the growth rate of abnormal path values in the edge set, extract the number of new connections between nodes and the abnormal increment distribution value of the edge set, and generate network abnormal event association information;
[0018] An attack detection unit, configured to compare the path value distribution feature with the association feature of the known attack event record based on the network abnormal event association information, and screen out the node pair combinations and path distributions that conform to the potential attack behavior characteristics, so as to obtain the potential network attack detection result.
[0019] On the other hand, there is provided a network attack detection device based on an event-driven architecture. The network attack detection device based on the event-driven architecture includes: a processor; a memory, on which computer-readable instructions are stored. When the computer-readable instructions are executed by the processor, any one of the methods in the above-mentioned network attack detection method based on the event-driven architecture is implemented.
[0020] On the other hand, there is provided a computer-readable storage medium, in which at least one instruction is stored. The at least one instruction is loaded and executed by a processor to implement any one of the methods in the above-mentioned network attack detection method based on the event-driven architecture.
[0021] The beneficial effects brought by the technical solutions provided in the embodiments of the present invention at least include:
[0022] In an embodiment of the present invention, first, based on a target network environment, by parsing application layer parameters and combining transport layer parameters, a multi-layer mapping table is established according to field relationships to obtain multi-layer packet feature mapping information; based on the multi-layer packet feature mapping information, the usage of non-standard ports and packets that do not conform to path specifications are extracted, an abnormal group is established by combining path values and port information, and a multi-layer abnormal behavior recognition result is generated; based on the multi-layer abnormal behavior recognition result, the time interval distribution value and packet length statistical value of abnormal packets are extracted, and combined with the normal distribution range of historical network behavior records, the detection threshold range and path determination rules are dynamically adjusted to obtain an adaptive detection threshold rule set; secondly, based on the adaptive detection threshold rule set, a graph model is constructed with communication entities as nodes and paths as edges, the change value of the communication connection times between nodes and the growth rate of abnormal path values in the edge set are analyzed, the number of new connections between nodes and the abnormal increment distribution value of the edge set are extracted, and network abnormal event association information is generated; finally, based on the network abnormal event association information, by comparing the path value distribution characteristics with the association characteristics of known attack event records, the node pair combinations and path distributions that conform to the potential attack behavior characteristics are screened to obtain a potential network attack detection result.
[0023] In an embodiment of the present invention, by capturing packets in the network in real time, parsing them layer by layer and establishing a multi-layer mapping relationship, it is possible to comprehensively capture the source and characteristics of abnormal packets; combined with the analysis of the time interval distribution value and the ratio of the packet lengths, as well as the detection method deviating from historical records, the screening of abnormal packets is made more accurate, the detection threshold interval can be dynamically adjusted to adapt to network environment changes; by constructing a graph structure model of the paths and time distributions between communication entities and combining the analysis of communication frequencies and abnormal increment changes, it is possible to quickly locate high-frequency communication entity pairs and potential attack paths, and generate network abnormal event association information; by comparing each path value with the attack event records one by one, and combining the path distribution characteristics and the association with historical attack records, the node pair combinations and path distributions that conform to the potential attack characteristics are accurately screened, making the detection range of potential attacks wider, the response speed faster and the targeting stronger. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0025] Figure 1 is a flowchart of a network attack detection method based on an event-driven architecture provided by an embodiment of the present invention;
[0026] Figure 2It is a flowchart for obtaining multi-layer data packet feature mapping information provided by an embodiment of the present invention;
[0027] Figure 3 It is a flowchart for generating multi-layer abnormal behavior recognition results provided by an embodiment of the present invention;
[0028] Figure 4 It is a flowchart for obtaining an adaptive detection threshold rule set provided by an embodiment of the present invention;
[0029] Figure 5 It is a flowchart for generating network abnormal event correlation information provided by an embodiment of the present invention;
[0030] Figure 6 It is a flowchart for potential network attack detection results provided by an embodiment of the present invention;
[0031] Figure 7 It is a block diagram of a network attack detection system based on an event-driven architecture provided by an embodiment of the present invention;
[0032] Figure 8 It is a structural schematic diagram of a network attack detection device based on an event-driven architecture provided by an embodiment of the present invention. Detailed implementation manners
[0033] Next, the technical solutions in the present invention will be described with reference to the accompanying drawings.
[0034] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as an "example" in the present invention should not be construed as being more preferred or more advantageous than other embodiments or design solutions. Exactly speaking, the use of the word "example" is intended to present concepts in a specific manner. In addition, in the embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one of the two can be selected.
[0035] In the embodiments of the present invention, "image" and "picture" can sometimes be used interchangeably. It should be noted that when the difference is not emphasized, the meanings they express are the same. "(of)", "corresponding", and "corresponding" can sometimes be used interchangeably. It should be noted that when the difference is not emphasized, the meanings they express are the same.
[0036] In the embodiments of the present invention, sometimes subscripts such as W1 may be written in a non-subscript form such as W1. When the difference is not emphasized, the meanings they express are the same.
[0037] To make the technical problems, technical solutions, and advantages to be solved by the present invention clearer, the following will be described in detail with reference to the accompanying drawings and specific embodiments.
[0038] An embodiment of the present invention provides a network attack detection method based on an event-driven architecture. This method can be implemented by a network attack detection device based on an event-driven architecture, and the network attack detection device based on an event-driven architecture can be a terminal or a server. As Figure 1 shown in the flowchart of the network attack detection method based on an event-driven architecture, the processing flow of this method can include the following steps:
[0039] S1. Based on the target network environment, by parsing application layer parameters and combining transport layer parameters, establish a multi-layer mapping table according to the field relationship to obtain multi-layer packet feature mapping information.
[0040] Among them, as Figure 2 shown is a flowchart of obtaining multi-layer packet feature mapping information provided by an embodiment of the present invention.
[0041] Optionally, the specific implementation process of S1 includes S11 - S13:
[0042] S11. Based on the target network environment, capture network packets in real time; extract the timestamps of the packets, sort them in chronological order to obtain sorted packets; parse the field types and field value combinations of the application layer in the sorted packets to obtain the chronological packet parsing result;
[0043] In a feasible implementation, based on the target network environment, capture network packets in real time, group the packets one by one, and the grouping basis is the source address, target address, and transport protocol; extract the timestamp information of the captured packets, arrange the grouped packets in ascending order of the timestamp, and correct the timestamp accuracy during the arrangement process, using millisecond-level timestamps as the arrangement benchmark to avoid time overlap in packet sorting; extract the application layer field types in each packet through a parsing module, including protocol types, field quantities, and field value ranges; quantify the field types into standard numerical values according to parsing rules. For example, the field type of a TCP packet can be set to 1, and the field value range can be quantified into an integer interval of 0 - 255. After quantification, combine the field values, and form independent structured forms with the field combinations to facilitate parsing the meaning and use of the field values; at the same time, detect abnormal values in the application layer fields. For field values exceeding the quantified interval, mark them as abnormal and store them independently in the abnormal field value table, and form the chronological packet parsing result through multiple rounds of packet parsing.
[0044] S12. Extract the transport protocol identifier and packet length information in the application layer data based on the chronological packet parsing result; parse the port information and packet flag bits in the transport layer data to obtain the application layer and transport layer parsing information.
[0045] In a feasible implementation, based on the chronological packet parsing result, extract the specific fields in the application layer data that identify the transport protocol, analyze each identifier field value one by one to determine the distribution quantity and proportion of different transport protocol identifiers; for example, for the HTTP protocol identifier value, it can be calculated by counting the occurrence frequency, and at the same time, parse the packet length field for each protocol identifier, divide the range of packet lengths into several intervals; such as intervals of 100 - 500 bytes and 500 - 1000 bytes, etc., and count the distribution proportion of each protocol identifier in different length intervals, parse the port information in the transport layer data, extract the port number and the corresponding packet flag bits, divide the range of port numbers into standard ports and non - standard ports, count the proportion of the number of packets of the two types of ports, extract the transport layer connection status through the packet flag bits; for example, the combination of flag bits such as SYN and ACK, perform an association analysis between the flag bits and the port number to form a distribution table for each port status, and obtain the application layer and transport layer parsing information through parsing.
[0046] S13. Based on the application layer and transport layer parsing information, parse the source address, destination address, and path value of the network layer to obtain the parsing result; according to the parsing result, establish a correspondence table between the field value and the path value to obtain the multi - layer packet feature mapping information.
[0047] In a feasible implementation, based on the application layer and transport layer parsing information, parse the packet field values in the network layer, including the source address, destination address, and path value; the source address and destination address are classified through an IP address segment parsing module; for example, divide the network address segment through a subnet mask, and match and classify the address segment of each packet; the parsing of the path value is to perform a secondary extraction on the path field in the data packet header, form a correspondence between the path field and the destination address, store all the packet field values and the corresponding relationships in an independent table, use this table to perform duplicate removal processing on the path value, and filter out the unique path value set; establish an index for the correspondence between the path value and the field value, for example, information such as the protocol identifier and packet length extracted from the field value can be quickly located through the path value index, and form a correspondence table between the field value and the path value through the integration of the index table to obtain the multi - layer packet feature mapping information.
[0048] S2. Based on the multi - layer packet feature mapping information, extract the usage of non - standard ports and the packets that do not conform to the path specification, establish an exception group by combining the path value and the port information, and generate a multi - layer abnormal behavior recognition result.
[0049] Among them, as Figure 3 shown is a flowchart for generating multi-layer abnormal behavior recognition results provided by an embodiment of the present invention.
[0050] Optionally, the specific implementation process of S2 includes S21 - S23:
[0051] S21. Based on the multi-layer data packet feature mapping information, compare the path values and port records in the network interaction item by item, filter out abnormal data packets with path values that do not match the standard ports from the path values, and generate abnormal path value data;
[0052] In a feasible implementation manner, based on the multi-layer data packet feature mapping information, by parsing the path values and port records in the network interaction item by item, extract the path value information of the multi-layer data packets, and classify the path values according to the network layer protocol type; for example, separately mark the path values of the TCP protocol, group and store the path values of the UDP protocol separately, compare the port numbers associated with the path values item by item by calling the standard port table, extract the path values that fail to match the standard ports, and filter out the combinations of path values and their associated port numbers; by statistically analyzing the recorded range of abnormal port numbers, identify the frequently occurring abnormal port numbers, analyze the combined features that frequently occur in these port and path value combinations, and at the same time check the topological distribution structure of the path values to determine the association of abnormal paths; for example, by calculating the frequency of occurrence of abnormal path values in the network topology and their communication correlation with the standard path values, record and mark the abnormal path values that do not match the standard ports and their associated information, and generate abnormal path value data.
[0053] S22. Based on the abnormal path value data, extract the time distribution and data packet length information of the abnormal data packets; group the extracted time distribution according to time intervals to obtain time interval distribution information;
[0054] In a feasible implementation, based on the abnormal path value data, by extracting the time distribution information of the abnormal data packets corresponding to each path value, reordering the data packets according to the timestamps to determine the occurrence frequency of the abnormal data packets in different time periods; for the data packet length information of each path value, extracting its length field value and grouping the data packets according to the specified length intervals; for example, dividing the data packet lengths into four intervals: less than 100 bytes, 100 - 500 bytes, 500 - 1000 bytes, and greater than 1000 bytes, calculating the length distribution characteristics of each path value by counting the number distribution of the data packets in each length interval, and at the same time detecting the abnormal peaks of the time distribution, extracting the peak points of the timestamps and the corresponding data packet quantities; by constructing a joint distribution table of the timestamps and the data packet lengths, conducting an association analysis on the peak of the data packet length and the abnormal time period of the time distribution, refining the abnormal time distribution characteristics of the path value, and storing the statistical results of the time interval and the data packet length according to the path value to obtain the time interval distribution information.
[0055] S23. Based on the time interval distribution information, calculate the difference value of the time intervals in the grouping; combine the difference value with the data packet length to screen out the abnormal data, establish a set of path values and a list of port information for the abnormal combination, and generate a multi - layer abnormal behavior recognition result.
[0056] In a feasible implementation, based on the time interval distribution information, by calculating the difference value of the time interval distribution; first, extract the grouped mean of the time intervals, for example, calculate the mean of the time intervals of the abnormal data packets in each time period, arrange the mean of the time intervals of different groupings in chronological order, and extract the difference value of the time intervals by calculating the change range of the mean of the time intervals; analyze the difference value in combination with the data packet length information, extract the peak points of the time interval difference value and the corresponding length distribution of the data packets, and screen out the abnormal points in the joint distribution of the difference value and the data packet length; mark the abnormal points according to the path value and establish an index relationship table between the path value and the abnormal points, and at the same time count the number of abnormal points and the port information of each path value, extract the high - frequency abnormal path port combinations in the path topology through the combination of the path value and the port number, store them as a set of path values and a list of port information, and generate a multi - layer abnormal behavior recognition result.
[0057] S3. Based on the multi - layer abnormal behavior recognition result, extract the time interval distribution value of the abnormal data packets and the packet length statistical value, combine the normal distribution range of the historical network behavior records, and dynamically adjust the detection threshold range and the path determination rule to obtain an adaptive detection threshold rule set.
[0058] Among them, as Figure 4 shown is a flowchart of obtaining an adaptive detection threshold rule set provided by an embodiment of the present invention.
[0059] Optionally, the specific implementation of S3 includes S31 - S33:
[0060] S31. Based on the recognition results of multi - layer abnormal behaviors, extract the time - interval distribution value and packet - length information of each path; arrange the time - interval distribution values in ascending order of time increment to obtain the time - increment sorting result;
[0061] In a feasible implementation, based on the recognition results of multi - layer abnormal behaviors, extract the time - interval distribution value and packet - length information of each path; call the stored data table of multi - layer abnormal behavior results, and parse the path time information and packet - length information for each path value field in the table; extract the timestamp data associated with each path, obtain the time - interval value by calculating the difference between timestamps, store the time - interval data grouped by the path field, and at the same time read the information of the packet - length field, extract the packet length corresponding to each path, bind the length value to the path field for storage, arrange the time - interval values in ascending order of time increment; use a step - by - step comparison method to detect the ascending change trend of the increment value, ensure the continuity of the time - increment arrangement, determine whether there is a jump - increment anomaly through the increment - sorting verification program, mark the time - interval values with anomaly points as specific anomaly categories, after completing the overall arrangement of the time increment, store the sorted increment information with the path field as the index, and combine the packet length to generate the complete time - increment sorting result.
[0062] S32. Based on the time - increment sorting result, calculate the change range of the time increment; perform a corresponding - ratio calculation between the time - increment change range and the packet - length statistical value to obtain the ratio - relationship calculation result;
[0063] In a feasible implementation, based on the time - increment sorting result, by calculating the change range of the time increment and performing a corresponding - ratio calculation with the packet - length statistical value, extract the increment - value field in the time - increment sorting result; calculate the difference between adjacent two groups of increment values to obtain the time - increment change range; store the change - range field grouped by the path field, perform statistical analysis on the packet - length information, calculate the maximum value, minimum value, and average value of the packet length in each path; match the statistical value with the time - increment change - range field item by item, and perform a ratio calculation between the time - increment change range and the average value of the packet length; for example, use the formula to calculate the time - increment change ratio of each path , where, is the time - increment change range, is the average value of the packet length; store the result of the ratio calculation by the path field, and at the same time record the anomaly mark of the ratio field for the path with a relatively large ratio result value, and group - store the ratio values as the ratio - relationship calculation result.
[0064] S33. Calculate the result based on the proportional relationship, determine whether the proportion deviates from the normal range in the historical record, adjust the detection threshold according to the degree of deviation, update the port range parameter in the path determination rule, and obtain an adaptive detection threshold rule set.
[0065] Optionally, the process of adjusting the detection threshold is represented by the following formula (1):
[0066] (1)
[0067] where, represents the updated detection threshold, represents the detection threshold before adjustment, represents the observed ratio of the path value to the packet length statistic value in the current calculation, represents the average ratio of the path value to the packet length statistic value in the historical record, represents the variance value of the historical ratio distribution, represents the weight coefficient that adjusts the influence of the ratio deviation on the threshold adjustment, represents the adjustment parameter that adjusts the sensitivity of the detection threshold by the path determination rule, represents the stability coefficient that adjusts the noise influence range.
[0068] Among them, the updated detection threshold is used as a new judgment criterion in network monitoring; the detection threshold before adjustment is usually obtained from the initial settings of the system or the previous monitoring period; the average ratio of the path value to the packet length statistic value in the historical record is calculated by statistically analyzing the historical network data; the variance value of the historical ratio distribution is calculated by statistically analyzing the dispersion degree of the ratios in the historical data; the weight coefficient that adjusts the influence of the ratio deviation on the threshold adjustment is preset according to the sensitivity requirements of the system for anomaly detection; the adjustment parameter that adjusts the sensitivity of the detection threshold by the path determination rule is preset according to the system requirements; the stability coefficient that adjusts the noise influence range reduces the influence of accidental anomalies in the variance and is preset according to the system requirements.
[0069] In a feasible implementation manner, the following is an embodiment of calculating the new detection threshold:
[0070] Let , , , , , , .
[0071] Calculate the absolute value of the ratio deviation:
[0072] ;
[0073] Calculate the denominator part:
[0074] ;
[0075] Calculate the adjustment amount:
[0076]
[0077] Calculate the new detection threshold:
[0078]
[0079] Among them, through the above calculations, the new detection threshold is approximately 50.792. The system adjusts the detection threshold according to the currently observed proportional deviation and the statistical characteristics of historical data to better adapt to the current network conditions.
[0080] S4. Based on the adaptive detection threshold rule set, using communication entities as nodes and paths as edges, construct a graph model, analyze the change value of the number of communication connections between nodes and the growth rate of abnormal path values in the edge set, extract the number of new connections between nodes and the abnormal increment distribution value of the edge set, and generate network anomaly event correlation information.
[0081] Among them, as Figure 5 shown is a flowchart of generating network anomaly event correlation information provided by an embodiment of the present invention;
[0082] Optionally, the specific implementation process of S4 includes S41 - S43:
[0083] S41. Based on the adaptive detection threshold rule set, extract the path value and time distribution record of communication entities in network interactions; according to the path correspondence relationship between communication entities, establish a graph structure model with communication entities as nodes and path relationships as edges, and obtain a network interaction graph model;
[0084] In a feasible implementation, based on the adaptive detection threshold rule set, extract the path values and time distribution records of communication entities in network interactions; extract all path value information from the rule set and classify it according to the source address and target address of the communication entity pair; bind and store the path values with their time distribution fields, and parse the time distribution records; group and store the time records according to the communication entity pair, establish an index relationship between the grouped time distribution records and the path values, and establish a preliminary node information table for the path values and their time distribution fields of each communication entity pair; where the node table contains the unique identifier of the communication entity, the path value index, and the time distribution information; by parsing the path value correspondence of each communication entity pair in the node table, establish an edge information table, and record the path quantity, communication direction, and time interval data between each pair of communication entities in the edge table; construct the set data of nodes and edges, associate the path values and time distribution information of all communication entity pairs as the node set and the edge set, and generate a complete graph structure in combination with the graph construction tool, and output the nodes as communication entities and the edges as path relationships as the network interaction graph model.
[0085] S42. Based on the network interaction graph model, by analyzing the abnormal change values of the time intervals in the path values, extract the entity pair combinations whose communication frequencies exceed the threshold, calculate the abnormal communication quantity and the corresponding abnormal path quantity of each entity, and generate the abnormal communication statistical results;
[0086] In a feasible implementation, based on the network interaction graph model, by analyzing the abnormal change values of the time intervals in the path values, extract the entity pair combinations whose communication frequencies exceed the threshold; parse each node and edge in the graph model one by one, extract the time interval field data on the edges, and calculate the mean and variance of the time intervals; compare the current time interval with the historical mean, calculate the deviation degree, and calculate using the following formula (2):
[0087] (2)
[0088] Where, is the current time interval deviation degree, is the current time interval, is the historical time interval mean, is the standard deviation of the historical time interval; record the edges with deviation degrees exceeding the preset threshold as abnormal paths, and at the same time count the communication frequencies of each node, and compare the communication frequencies of the nodes with the set threshold; mark the nodes with frequencies exceeding the threshold as high-frequency communication entities, form abnormal entity pair combinations by extracting all the edges marked as abnormal paths and high-frequency communication nodes, and at the same time count the communication path quantities of each abnormal entity, generate the abnormal communication quantity and abnormal path quantity of each entity, and organize all the statistical results into the abnormal communication statistical results.
[0089] S43. Based on the abnormal communication statistics results, arrange the statistics results in chronological order, extract the abnormal incremental changes of the path values, and combine the incremental change results to screen the high-frequency communication entity pair combinations to obtain the network abnormal event association information.
[0090] In a feasible implementation manner, based on the abnormal communication statistics results, arrange the statistics results in chronological order, perform a trend analysis of the change of the abnormal path quantity field on the time axis, and extract the incremental value of the abnormal path quantity at each time point; sort all the incremental values in chronological order, and extract the peak points within the time period by calculating the change amplitude of the incremental values; perform an associated extraction of the time and path values corresponding to the peak points, and screen the high-frequency communication entity pair combinations; for example, sort the entity pairs with a communication frequency exceeding the threshold in descending order according to the incremental change amplitude of the path values, select the entity pair with the highest communication frequency and the largest incremental change amplitude as the high-frequency communication entities, and store the selected high-frequency communication entities and their path relationships as the network abnormal event association information to obtain a complete associated analysis result of the time distribution of network interactions and the path relationships of entity pairs.
[0091] S5. Based on the network abnormal event association information, compare the association characteristics of the path value distribution features with the known attack event records, and screen the node pair combinations and path distributions that conform to the potential attack behavior characteristics to obtain the potential network attack detection results.
[0092] Among them, as Figure 6 shown is a flowchart of a potential network attack detection result provided by an embodiment of the present invention.
[0093] Optionally, the specific implementation process of S5 includes S51 - S53:
[0094] S51. Based on the network abnormal event association information, extract the high-frequency communication entity pair combinations from the graph; sort the path values in the high-frequency communication entity pairs according to the communication frequency to generate high-frequency communication path information;
[0095] In a feasible implementation manner, based on the network abnormal event association information, extract the high-frequency communication entity pair combinations from the graph, and extract the communication entity pair fields from the network abnormal event association information; parse the communication frequency fields of each communication entity pair, and sort the communication frequency values in descending order; extract the path values of the high-frequency communication entity pairs, and establish an index relationship between the extracted path value fields and the communication frequency fields; group and store the path values according to the communication frequency, and perform a statistics on the frequency distribution of the path values, and count the occurrence frequency of each path value and the corresponding number of communication entity pairs; mark the path values with higher frequencies as high-frequency paths to form an independent high-frequency path information table; generate high-frequency communication path information by comparing the distribution relationship between the high-frequency path table and the communication frequency fields and store it as an independent data table.
[0096] S52. Extract the path value distribution characteristics between communication entity pairs based on the high-frequency communication path information, combine the abnormal increment distribution peaks of the path values, establish a correspondence table between the path values and the increment peaks, and obtain the path-peak correspondence table;
[0097] In a feasible implementation, based on the high-frequency communication path information, extract the path value distribution characteristics between communication entity pairs; extract the path value field and its corresponding communication entity pair field from the high-frequency communication path information, analyze the distribution range of each path value, and classify and store them according to the distribution area of the path value; establish an association between the distribution frequency field of the path value and the communication entity pair field to form a path value distribution feature set; combine the abnormal increment distribution data of the path values, detect the peak value of the increment distribution in the path value field, extract the peak value features by calculating the mean and maximum values of the abnormal increments in the path value field, and establish a correspondence between the distribution range of the path value and the peak value feature value; store the path value field and its peak value field as an independent index table to obtain the path-peak correspondence table.
[0098] S53. Based on the path-peak correspondence table, compare each item by item through the association characteristics between the path value distribution characteristics and the attack event records, evaluate the feature matching degree, screen out the node pair combinations and path distributions that meet the potential attack behavior characteristics, and generate the potential network attack detection results.
[0099] Optionally, the process of evaluating the feature matching degree is represented by the following formula (3):
[0100] (3)
[0101] where, represents the feature matching score, represents the th observed feature value in the path value distribution, represents the average value of the th feature in the historical record, represents the actual distribution value of the th path in the path distribution characteristics, represents the distribution value of the th path in the historical attack events, represents the historical distribution variance of the th feature value, represents the historical distribution variance of the path distribution value, represents the weight of the deviation of the feature value from the matching degree, represents the weight of the deviation of the path distribution from the matching degree, represents the stable value to prevent the denominator from being zero, represents the stable value of the path distribution variance.
[0102] Among them, the th observed eigenvalue in the path value distribution is obtained by extracting the observed values in each time period through the path values and feature distributions in the real-time monitoring network; the average value of the th feature in the historical record is calculated by averaging the sum of all corresponding eigenvalue in the historical record, and is used for comparison with the real-time observed values; the actual distribution value of the th path in the path distribution feature is calculated by counting the path values in the network traffic data in the current time period to calculate the distribution proportion of each path; the distribution value of the th path in the historical attack events is calculated by counting the historical data of known attack events to calculate the distribution proportion of each path; the historical distribution variance of the th eigenvalue is obtained by calculating the degree of dispersion of the eigenvalue data of a certain feature in the historical record; the historical distribution variance of the path distribution value is obtained by statistically calculating the degree of change in the path distribution proportion in all historical attack events; the weight of the eigenvalue deviation to the matching degree is set manually according to the system requirements, mainly used to adjust the proportion of the feature level; the weight of the path distribution deviation to the matching degree is set manually according to the system requirements, mainly used to adjust the proportion of the path level; a stable value to prevent the denominator from being zero, used to prevent the denominator from being zero and ensure the calculation stability, usually set to a very small value, such as ; a stable value of the path distribution variance, used to prevent abnormal calculation of the path distribution variance, usually set to a very small value, such as .
[0103] In a feasible implementation manner, the following is an embodiment of calculating the evaluation feature matching degree:
[0104] Set the following parameter values: , ; , ; ,
[0105] ; , , ; ; , ; , ;
[0106] Calculate the eigenvalue deviation part of the first feature:
[0107]
[0108] Calculate the eigenvalue deviation part of the second feature:
[0109]
[0110] Calculate the first path distribution deviation part:
[0111]
[0112] Calculate the second path distribution deviation part:
[0113]
[0114] Aggregate and calculate the matching score :
[0115]
[0116] Among them, the matching score . It indicates that the current path distribution and the characteristics of historical attack records have a medium degree of relevance and can be screened as candidates for potential network attack behaviors.
[0117] Optionally, multi-layer packet feature mapping information, including: field type value table, port usage record table, path value correspondence table, and time-ordered packet list;
[0118] Multi-layer abnormal behavior recognition results, including: abnormal path value set, abnormal port information list, time interval distribution group list, and packet length statistical table;
[0119] Adaptive detection threshold rule set, including: time increment change range, packet length ratio threshold, and path determination rule parameter set;
[0120] Network anomaly event association information, including: communication entity node set, path edge set, communication anomaly increment distribution table, and high-frequency abnormal communication node pair;
[0121] Potential network attack detection results, including: communication entity pair combination feature table, path value distribution feature set, and abnormal increment peak information table.
[0122] In the embodiment of the present invention, first, based on the target network environment, by parsing the application layer parameters and combining the transport layer parameters, a multi-layer mapping table is established according to the field relationship to obtain multi-layer data packet feature mapping information; based on the multi-layer data packet feature mapping information, the usage of non-standard ports and data packets that do not conform to the path specification are extracted, and the path values and port information are combined to establish an abnormal group to generate a multi-layer abnormal behavior recognition result; based on the multi-layer abnormal behavior recognition result, the time interval distribution value and packet length statistical value of abnormal data packets are extracted, and combined with the normal distribution range of historical network behavior records, the detection threshold range and path determination rules are dynamically adjusted to obtain an adaptive detection threshold rule set; secondly, based on the adaptive detection threshold rule set, a graph model is constructed with communication entities as nodes and paths as edges, the change value of the communication connection times between nodes and the growth rate of abnormal path values in the edge set are analyzed, the number of new connections between nodes and the abnormal increment distribution value of the edge set are extracted to generate network anomaly event association information; finally, based on the network anomaly event association information, by comparing the path value distribution feature with the association feature of known attack event records, the node pair combinations and path distributions that conform to the potential attack behavior characteristics are screened to obtain the potential network attack detection result.
[0123] In the embodiment of the present invention, by capturing data packets in the network in real time, parsing them layer by layer and establishing a multi-layer mapping relationship, it is possible to comprehensively capture the source and characteristics of abnormal data packets; combined with the analysis of the time interval distribution value and the ratio of the data packet length, as well as the detection method deviating from the historical record, the screening of abnormal data packets is made more accurate, the detection threshold interval can be dynamically adjusted to adapt to the changes in the network environment; by constructing a graph structure model of the path and time distribution between communication entities and combining the analysis of communication frequency and abnormal increment changes, it is possible to quickly locate high-frequency communication entity pairs and potential attack paths to generate network anomaly event association information; by comparing each path value with the attack event record one by one, and combining the path distribution feature and the association of historical attack records, the node pair combinations and path distributions that conform to the potential attack characteristics are accurately screened, making the detection range of potential attacks wider, the reaction speed faster and the pertinence stronger.
[0124] Figure 7 FIG. is a block diagram of a network attack detection system based on an event-driven architecture shown according to an exemplary embodiment. This system is used for the network attack detection method based on the event-driven architecture. Refer to Figure 7 , this system includes a data parsing unit 710, an abnormal behavior analysis unit 720, a detection threshold adjustment unit 730, an abnormal event analysis unit 740, and an attack detection unit 750. Among them:
[0125] The data parsing unit 710 is configured to, based on the target network environment, by parsing the application layer parameters and combining the transport layer parameters, establish a multi-layer mapping table according to the field relationship to obtain multi-layer data packet feature mapping information;
[0126] An abnormal behavior analysis unit 720, configured to extract the usage of non-standard ports and packets that do not conform to path specifications based on the multi-layer packet feature mapping information, establish abnormal groups by combining path values and port information, and generate a multi-layer abnormal behavior recognition result;
[0127] A detection threshold adjustment unit 730, configured to extract the time interval distribution value of abnormal packets and the packet length statistical value based on the multi-layer abnormal behavior recognition result, and dynamically adjust the detection threshold range and path determination rules in combination with the normal distribution range of historical network behavior records to obtain an adaptive detection threshold rule set;
[0128] An abnormal event analysis unit 740, configured to construct a graph model with communication entities as nodes and paths as edges based on the adaptive detection threshold rule set, analyze the change value of the number of communication connections between nodes and the growth rate of abnormal path values in the edge set, extract the number of new connections between nodes and the abnormal increment distribution value of the edge set, and generate network abnormal event association information;
[0129] An attack detection unit 750, configured to compare the path value distribution feature with the association feature of known attack event records based on the network abnormal event association information, and screen the node pair combinations and path distributions that conform to the potential attack behavior characteristics to obtain a potential network attack detection result.
[0130] Optionally, the multi-layer packet feature mapping information includes: a field type value table, a port usage record table, a path value correspondence table, and a time-ordered packet list;
[0131] The multi-layer abnormal behavior recognition result includes: an abnormal path value set, an abnormal port information list, a time interval distribution group list, and a packet length statistical table;
[0132] The adaptive detection threshold rule set includes: a time increment change range, a packet length ratio threshold, and a path determination rule parameter set;
[0133] The network abnormal event association information includes: a communication entity node set, a path edge set, a communication abnormal increment distribution table, and high-frequency abnormal communication node pairs;
[0134] The potential network attack detection result includes: a communication entity pair combination feature table, a path value distribution feature set, and an abnormal increment peak information table.
[0135] Optionally, the data parsing unit 710 is configured to:
[0136] Based on the target network environment, capture network data packets in real time; extract the timestamps of the data packets, sort them in chronological order, and obtain the sorted data packets; parse the field types and field value combinations in the application layer of the sorted data packets to obtain the parsing results of the chronological data packets;
[0137] Based on the parsing results of the chronological data packets, extract the transport protocol identifier and data packet length information in the application layer data; parse the port information and data packet flag bits in the transport layer data to obtain the parsing information of the application layer and the transport layer;
[0138] Based on the parsing information of the application layer and the transport layer, parse the source address, destination address, and path value of the network layer to obtain the parsing results; according to the parsing results, establish a correspondence table between the field values and the path values to obtain the multi-layer data packet feature mapping information.
[0139] Optionally, the abnormal behavior analysis unit 720 is used for:
[0140] Based on the multi-layer data packet feature mapping information, compare the path values and port records in the network interaction item by item, screen out the abnormal data packets with un-matched standard ports from the path values, and generate the abnormal path value data;
[0141] Based on the abnormal path value data, extract the time distribution and data packet length information of the abnormal data packets; group the extracted time distribution according to the time interval to obtain the time interval distribution information;
[0142] Based on the time interval distribution information, calculate the difference value of the time intervals in the group; combine the difference value with the data packet length to screen out the abnormal data, establish the path value set of the abnormal combination and the port information list, and generate the multi-layer abnormal behavior recognition result.
[0143] Optionally, the detection threshold adjustment unit 730 is used for:
[0144] Based on the multi-layer abnormal behavior recognition result, extract the time interval distribution value and data packet length information of each path; arrange the time interval distribution values in the order of time increment to obtain the time increment sorting result;
[0145] Based on the time increment sorting result, calculate the change range of the time increment; perform a corresponding ratio calculation on the change range of the time increment and the packet length statistical value to obtain the ratio relationship calculation result;
[0146] Based on the ratio relationship calculation result, judge whether the ratio deviates from the normal range in the historical record, and adjust the detection threshold according to the deviation degree, and update the port range parameter in the path determination rule to obtain the adaptive detection threshold rule set.
[0147] Optionally, the process of adjusting the detection threshold is represented by the following formula (1):
[0148] (1)
[0149] where represents the updated detection threshold, represents the detection threshold before adjustment, represents the observed ratio of the path value to the packet length statistic in the current calculation, represents the average ratio of the path value to the packet length statistic in the historical record, represents the variance value of the historical ratio distribution, represents the weight coefficient of the influence of the adjustment ratio deviation on the threshold adjustment, represents the adjustment parameter of the detection threshold sensitivity by adjusting the path determination rule, represents the stability coefficient for adjusting the noise influence range.
[0150] Optionally, the abnormal event analysis unit 740 is used for:
[0151] Based on the adaptive detection threshold rule set, extract the path value and time distribution record of the communication entity in the network interaction; according to the path correspondence relationship between communication entities, establish a graph structure model with communication entities as nodes and path relationships as edges, and obtain the network interaction graph model;
[0152] Based on the network interaction graph model, by analyzing the abnormal change value of the time interval in the path value, extract the entity pair combinations with communication frequencies exceeding the threshold, calculate the abnormal communication quantity of each entity and the corresponding abnormal path number, and generate the abnormal communication statistical result;
[0153] Based on the abnormal communication statistical result, arrange the statistical results in chronological order, extract the abnormal increment change of the path value, and combine the increment change result to screen the high-frequency communication entity pair combinations to obtain the network abnormal event association information.
[0154] Optionally, the attack detection unit 750 is used for:
[0155] Based on the network abnormal event association information, extract the high-frequency communication entity pair combinations from the graph; sort the path values in the high-frequency communication entity pairs according to the communication frequency to generate the high-frequency communication path information;
[0156] Based on the high-frequency communication path information, extract the path value distribution characteristics between communication entity pairs, and combine the abnormal increment distribution peak value of the path value to establish a correspondence table between the path value and the increment peak value to obtain the path and peak correspondence table;
[0157] Based on the path and peak correspondence table, by comparing each item one by one through the correlation features between the path value distribution characteristics and the attack event records, the feature matching degree is evaluated, and the node pair combinations and path distributions that meet the characteristics of potential attack behaviors are screened to generate potential network attack detection results.
[0158] Optionally, the process of evaluating the feature matching degree is represented by the following formula (2):
[0159] (2)
[0160] Wherein, represents the feature matching score, represents the th observed feature value in the path value distribution, represents the average value of the th feature in the historical records, represents the actual distribution value of the th path in the path distribution characteristics, represents the distribution value of the th path in the historical attack events, represents the historical distribution variance of the th feature value, represents the historical distribution variance of the path distribution value, represents the weight of the deviation of the feature value from the matching degree, represents the weight of the deviation of the path distribution from the matching degree, represents a stable value to prevent the denominator from being zero, represents a stable value of the path distribution variance.
[0161] In the embodiment of the present invention, first, based on the target network environment, by parsing the application layer parameters and combining the transport layer parameters, a multi-layer mapping table is established according to the field relationship to obtain multi-layer data packet feature mapping information; based on the multi-layer data packet feature mapping information, the usage of non-standard ports and data packets that do not conform to the path specification are extracted, and the path values and port information are combined to establish an abnormal group to generate a multi-layer abnormal behavior recognition result; based on the multi-layer abnormal behavior recognition result, the time interval distribution value and packet length statistical value of abnormal data packets are extracted, and combined with the normal distribution range of historical network behavior records, the detection threshold range and path determination rules are dynamically adjusted to obtain an adaptive detection threshold rule set; secondly, based on the adaptive detection threshold rule set, a graph model is constructed with communication entities as nodes and paths as edges, the change value of the communication connection times between nodes and the growth rate of abnormal path values in the edge set are analyzed, the number of new connections between nodes and the abnormal increment distribution value of the edge set are extracted to generate network anomaly event association information; finally, based on the network anomaly event association information, by comparing the path value distribution feature with the association feature of known attack event records, the node pair combinations and path distributions that conform to the potential attack behavior characteristics are screened to obtain the potential network attack detection result.
[0162] In the embodiment of the present invention, by capturing data packets in the network in real time, parsing them layer by layer and establishing a multi-layer mapping relationship, it can comprehensively capture the source and characteristics of abnormal data packets; combined with the analysis of the time interval distribution value and the ratio of the data packet length, as well as the detection method deviating from the historical record, the screening of abnormal data packets is more accurate, the detection threshold interval can be dynamically adjusted to adapt to the changes in the network environment; by constructing a graph structure model of the path and time distribution between communication entities and combining the analysis of communication frequency and abnormal increment changes, it can quickly locate high-frequency communication entity pairs and potential attack paths to generate network anomaly event association information; by comparing each path value with the attack event record one by one, combining the path distribution feature and the historical attack record association, the node pair combinations and path distributions that conform to the potential attack characteristics are accurately screened, making the detection range of potential attacks wider, the response speed faster and the pertinence stronger.
[0163] Figure 8 It is a schematic structural diagram of a network attack detection device based on an event-driven architecture provided by an embodiment of the present invention, as Figure 8 shown, the network attack detection device based on the event-driven architecture may include the above-mentioned Figure 7 shown network attack detection system based on the event-driven architecture. Optionally, the network attack detection device 810 based on the event-driven architecture may include a first processor 2001.
[0164] Optionally, the network attack detection device 810 based on the event-driven architecture may further include a memory 2002 and a transceiver 2003.
[0165] Among them, the first processor 2001, the memory 2002, and the transceiver 2003 can be connected, for example, through a communication bus.
[0166] Next, in combination with Figure 8 each component of the network attack detection device 810 based on an event-driven architecture will be specifically introduced:
[0167] Among them, the first processor 2001 is the control center of the network attack detection device 810 based on an event-driven architecture, which can be a single processor or a collective term for multiple processing elements. For example, the first processor 2001 is one or more central processing units (CPUs), or can be an application-specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present invention, such as: one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs).
[0168] Optionally, the first processor 2001 can execute various functions of the network attack detection device 810 based on an event-driven architecture by running or executing software programs stored in the memory 2002 and calling data stored in the memory 2002.
[0169] In a specific implementation, as an embodiment, the first processor 2001 can include one or more CPUs, such as Figure 8 CPU0 and CPU1 shown in
[0170] In a specific implementation, as an embodiment, the network attack detection device 810 based on an event-driven architecture can also include multiple processors, such as Figure 8 the first processor 2001 and the second processor 2004 shown in
[0171] Among them, the memory 2002 is used to store software programs for implementing the solution of the present invention and is controlled by the first processor 2001 for execution. The specific implementation method can refer to the above method embodiments and will not be elaborated here.
[0172] Optionally, the memory 2002 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or may also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 2002 may be integrated with the first processor 2001 or may exist independently and is coupled to the first processor 2001 through an interface circuit ( Figure 8 not shown) of the network attack detection device 810 based on an event-driven architecture. The embodiments of the present invention do not make specific limitations thereto.
[0173] A transceiver 2003 is configured to communicate with a network device or communicate with a terminal device.
[0174] Optionally, the transceiver 2003 may include a receiver and a transmitter ( Figure 8 not separately shown). Among them, the receiver is used to implement the receiving function, and the transmitter is used to implement the transmitting function.
[0175] Optionally, the transceiver 2003 may be integrated with the first processor 2001 or may exist independently and is coupled to the first processor 2001 through an interface circuit ( Figure 8 not shown) of the network attack detection device 810 based on an event-driven architecture. The embodiments of the present invention do not make specific limitations thereto.
[0176] It should be noted that Figure 8 the structure of the network attack detection device 810 based on an event-driven architecture shown does not constitute a limitation to the router. The actual knowledge structure recognition device may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0177] In addition, the technical effects of the network attack detection device 810 based on an event-driven architecture may refer to the technical effects of the network attack detection method based on an event-driven architecture described in the above method embodiments, and will not be elaborated here.
[0178] It should be understood that the first processor 2001 in the embodiments of the present invention may be a central processing unit (CPU), and the processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0179] It should also be understood that the memory in the embodiments of the present invention may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM) or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM) and direct rambus RAM (DR RAM).
[0180] The above embodiments can be implemented in whole or in part by software, hardware (such as circuits), firmware, or any other combination. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present invention are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable systems. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (such as infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or a data center that contains one or more collections of available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, or magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.
[0181] It should be understood that the term "and / or" in this document is merely a description of the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. Additionally, the character " / " in this document generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship, which can be specifically understood by referring to the context before and after.
[0182] In the present invention, "at least one" means one or more, and "a plurality" means two or more. "At least one of the following" or its similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.
[0183] It should be understood that in various embodiments of the present invention, the magnitudes of the sequence numbers of the above processes do not imply the order of execution. The order of execution of each process should be determined based on its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.
[0184] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present invention.
[0185] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the devices, systems, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0186] In several embodiments provided by the present invention, it should be understood that the disclosed devices, systems, and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of systems or units can be electrical, mechanical, or other forms.
[0187] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0188] In addition, the functional units in each embodiment of the present invention can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.
[0189] When the above-mentioned function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0190] As described above, the above are only specific implementation manners of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A network attack detection method based on event-driven architecture, characterized in that: The method comprises: S1. Based on the target network environment, by parsing the application layer parameters and combining the transport layer parameters, a multi-layer mapping table is established according to the field relationship to obtain multi-layer data packet feature mapping information; S2, based on the multi-layer data packet feature mapping information, extract the usage of non-standard ports and data packets that do not meet the path specification, combine the path value and the port information to establish an abnormal group, and generate a multi-layer abnormal behavior recognition result; S3. Based on the multi-layer abnormal behavior identification results, extract the abnormal data packet time interval distribution value and packet length statistics, combine the normal distribution range of historical network behavior records, dynamically adjust the detection threshold range and path determination rules, and obtain an adaptive detection threshold rule set; S4. Based on the adaptive detection threshold rule set, a graph model is constructed with communication entities as nodes and paths as edges, the change value of the number of communication connections between nodes and the growth rate of abnormal path values in the edge set are analyzed, the number of newly added connections between nodes and the abnormal incremental distribution value of the edge set are extracted, and the association information of network abnormal events is generated; S5. Based on the network abnormal event correlation information, the path value distribution characteristics are compared with the correlation characteristics of the known attack event records, and the node pair combination and path distribution that meet the potential attack behavior characteristics are screened to obtain the potential network attack detection result.
2. The network attack detection method based on event-driven architecture according to claim 1 is characterized in that: The multi-layer data packet feature mapping information includes: a field type value table, a port usage record table, a path value correspondence table, and a time-ordered data packet list; The multi-layer abnormal behavior identification result includes: an abnormal path value set, an abnormal port information list, a time interval distribution group list, and a data packet length statistics table; The adaptive detection threshold rule set includes: a time increment variation range, a packet length ratio threshold, and a path determination rule parameter set; The network abnormal event association information includes: a communication entity node set, a path edge set, a communication abnormality increment distribution table, and a high-frequency abnormal communication node pair; The potential network attack detection result includes: a communication entity pair combination feature table, a path value distribution feature set, and an abnormal increment peak information table.
3. The network attack detection method based on event-driven architecture according to claim 1 is characterized in that: The S1, based on the target network environment, parses the application layer parameters, combines the transport layer parameters, establishes a multi-layer mapping table according to the field relationship, and obtains multi-layer data packet feature mapping information, including: S11. Based on the target network environment, capture the data packets in the network in real time; extract the timestamps of the data packets, sort them in chronological order, and obtain the sorted data packets; parse the field type and field value combination of the application layer in the sorted data packets to obtain the time sequence data packet parsing results; S12, based on the time sequence data packet parsing results, extract the transmission protocol identifier and data packet length information in the application layer data; parse the port information and data packet flag bits in the transport layer data to obtain application layer and transport layer parsing information; S13. Based on the application layer and transport layer parsing information, parse the source address, destination address and path value of the network layer to obtain the parsing result; according to the parsing result, establish a correspondence table between the field value and the path value to obtain the multi-layer data packet feature mapping information.
4. The network attack detection method based on event-driven architecture according to claim 1 is characterized in that: The S2 extracts the usage of non-standard ports and data packets that do not conform to path specifications based on the multi-layer data packet feature mapping information, combines the path value with the port information to establish an abnormal group, and generates a multi-layer abnormal behavior recognition result, including: S21. Based on the multi-layer data packet feature mapping information, the path values and port records in the network interaction are compared one by one, and abnormal data packets that do not match the standard port are filtered out from the path values to generate abnormal path value data; S22, based on the abnormal path value data, extracting the time distribution and data packet length information of the abnormal data packet; grouping the extracted time distribution according to time intervals to obtain time interval distribution information; S23. Based on the time interval distribution information, calculate the difference value of the time interval in the group; combine the difference value with the data packet length, filter the abnormal data, establish a path value set and a port information list of the abnormal combination, and generate a multi-layer abnormal behavior recognition result.
5. The network attack detection method based on event-driven architecture according to claim 1 is characterized in that: The S3 extracts the time interval distribution value and packet length statistics of abnormal data packets based on the multi-layer abnormal behavior identification results, dynamically adjusts the detection threshold range and path determination rules in combination with the normal distribution range of historical network behavior records, and obtains an adaptive detection threshold rule set, including: S31. Based on the multi-layer abnormal behavior recognition results, extract the time interval distribution value and data packet length information of each path; arrange the time interval distribution values in the order of time increments to obtain the time increment sorting result; S32, based on the time increment sorting result, calculating the change range of the time increment; performing corresponding proportional calculation on the change range of the time increment and the packet length statistical value to obtain a proportional relationship calculation result; S33. Based on the calculation result of the proportional relationship, determine whether the proportion deviates from the normal range in the historical record, adjust the detection threshold according to the degree of deviation, update the port range parameter in the path determination rule, and obtain an adaptive detection threshold rule set.
6. The network attack detection method based on event-driven architecture according to claim 5 is characterized in that: The process of adjusting the detection threshold is expressed by the following formula (1): (1) in, represents the updated detection threshold, represents the detection threshold before adjustment, Indicates the observed ratio of the path value and the packet length statistics in the current calculation. Indicates the average ratio of path value to packet length statistics in the historical records. represents the variance value of the historical proportion distribution, Indicates the weight coefficient of the impact of the adjustment ratio deviation on the threshold adjustment, It represents the adjustment parameter for adjusting the sensitivity of the path determination rule to the detection threshold. Indicates the stability factor for adjusting the noise influence range.
7. The network attack detection method based on event-driven architecture according to claim 1 is characterized in that: The S4 is based on the adaptive detection threshold rule set, takes the communication entity as the node and the path as the edge to build a graph model, analyzes the change value of the number of communication connections between nodes and the growth rate of the abnormal path value in the edge set, extracts the number of newly added connections between nodes and the abnormal incremental distribution value of the edge set, and generates network abnormal event correlation information, including: S41, based on the adaptive detection threshold rule set, extracting the path value and time distribution record of the communication entity in the network interaction; according to the path correspondence between the communication entities, establishing a graph structure model in which the nodes are the communication entities and the edges are the path relationships, and obtaining a network interaction graph model; S42, based on the network interaction graph model, by analyzing the abnormal change value of the time interval in the path value, extracting the entity pair combination whose communication frequency exceeds the threshold, calculating the number of abnormal communications and the corresponding number of abnormal paths for each entity, and generating abnormal communication statistics; S43. Based on the abnormal communication statistical results, the statistical results are arranged in chronological order, the abnormal incremental changes of the path values are extracted, and the high-frequency communication entity pair combinations are screened in combination with the incremental change results to obtain the network abnormal event correlation information.
8. The network attack detection method based on event-driven architecture according to claim 1 is characterized in that: The S5, based on the network abnormal event correlation information, compares the path value distribution characteristics with the correlation characteristics of the known attack event records, screens the node pair combination and path distribution that meet the potential attack behavior characteristics, and obtains the potential network attack detection result, including: S51, based on the network abnormal event correlation information, extracting high-frequency communication entity pair combinations from the graph; sorting the path values in the high-frequency communication entity pairs according to the communication frequency to generate high-frequency communication path information; S52, based on the high-frequency communication path information, extract the path value distribution characteristics between the communication entity pairs, combine the abnormal incremental distribution peak of the path value, establish a corresponding relationship table between the path value and the incremental peak value, and obtain a path and peak corresponding relationship table; S53. Based on the path-peak correspondence table, the path value distribution characteristics are compared with the associated characteristics of the attack event records one by one, the feature matching degree is evaluated, the node pair combination and path distribution that meet the potential attack behavior characteristics are screened, and the potential network attack detection results are generated.
9. The network attack detection method based on event-driven architecture according to claim 8 is characterized in that: The process of evaluating the feature matching degree is expressed by the following formula (2): (2) in, represents the feature matching score, Indicates the path value distribution Item observed characteristic value, Indicates the number of The average value of the feature, Indicates the path distribution characteristics The actual distribution value of the item path, Indicates the number of historical attacks The distribution value of the item path, Indicates The historical distribution variance of the eigenvalues of the term, represents the historical distribution variance of the path distribution value, Indicates the weight of the eigenvalue deviation on the matching degree, Indicates the weight of path distribution deviation on matching degree, represents a stable value that prevents the denominator from reaching zero, Represents a stable value of the variance of the path distribution.
10. A network attack detection system based on an event-driven architecture, wherein the network attack detection system based on an event-driven architecture is used to implement the network attack detection method based on an event-driven architecture as claimed in any one of claims 1 to 9, characterized in that: The system comprises: A data parsing unit is used to parse application layer parameters based on the target network environment, combine the transport layer parameters, establish a multi-layer mapping table according to the field relationship, and obtain multi-layer data packet feature mapping information; An abnormal behavior analysis unit, used to extract the usage of non-standard ports and data packets that do not meet the path specification based on the multi-layer data packet feature mapping information, combine the path value and the port information to establish an abnormal group, and generate a multi-layer abnormal behavior identification result; A detection threshold adjustment unit, for extracting the time interval distribution value and packet length statistics of abnormal data packets based on the multi-layer abnormal behavior identification results, dynamically adjusting the detection threshold range and path determination rules in combination with the normal distribution range of historical network behavior records, and obtaining an adaptive detection threshold rule set; An abnormal event analysis unit is used to construct a graph model based on the adaptive detection threshold rule set, with communication entities as nodes and paths as edges, analyze the change value of the number of communication connections between nodes and the growth rate of abnormal path values in the edge set, extract the number of newly added connections between nodes and the abnormal incremental distribution value of the edge set, and generate network abnormal event association information; The attack detection unit is used to compare the path value distribution characteristics with the correlation characteristics of known attack event records based on the network abnormal event correlation information, screen the node pair combination and path distribution that meet the potential attack behavior characteristics, and obtain the potential network attack detection result.
Citation Information
Patent Citations
Abnormal flow detection system and abnormal flow detection method based on service model
CN108289088A
Network attack detection method, device, equipment and computer program
CN115473658A
Network attack detection method and system based on multi-modal feature fusion
CN119696859A
Method and system for collecting network security threat information
CN119743335A
Methods and systems for automated detection and tracking of network attacks
US20100050262A1
Cited By
Network security event analysis method, system and equipment
CN120729618A
Industrial data security protection method and system
CN120915611A
Industrial data security protection method and system
CN120915611B
Industrial edge multi-node anomaly detection method, device and equipment and storage medium
CN122394961A