A network attack detection method and system based on an event-driven architecture
Through the event-driven architecture of network attack detection method, the application layer and transport layer parameters are parsed, the detection threshold is dynamically adjusted, and a graph model is constructed to analyze the communication connection. This solves the problem of insufficient detection ability of traditional methods in multi-stage attacks and realizes efficient potential attack detection.
Patent Information
- Application Number
- CN202510427333.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-07
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-04-07
AI Technical Summary
Traditional network attack detection methods are unable to effectively respond to multi-stage attacks and are unable to analyze the attack link through the correlation of path and communication frequency characteristics, resulting in limited attack defense capabilities.
A network attack detection method based on an event-driven architecture establishes a multi-layer mapping table by parsing application layer and transport layer parameters, extracts abnormal data packet features, dynamically adjusts detection threshold rules, builds a graph model to analyze communication connection and path anomalies, and detects potential attacks in combination with historical behavior records.
It achieves accurate detection of multi-stage attacks, dynamically adapts to changes in the network environment, quickly locates potential attack paths, and improves detection accuracy and response speed.
Smart Images

Figure CN120165952B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network attack detection method and system based on an event-driven architecture. Background Art
[0002] The field of cybersecurity encompasses strategies and techniques used to protect computer networks, data, software, and other information technology assets from unauthorized access, attack, and destruction. Cybersecurity encompasses a wide range of defenses, from physical security measures to encryption. The core of cybersecurity involves defending against external attacks, internal breaches, and the misuse of network services, ensuring the confidentiality, integrity, and availability of information. This involves the use of attack detection systems, firewalls, intrusion prevention systems, and encryption technologies to create a secure network environment that can withstand evolving cyber threats.
[0003] Network attack detection methods involve monitoring network activity through automated tools and techniques to identify potential malicious behavior and threats. These methods address technical matters such as identifying suspicious activity using behavioral pattern matching and anomaly detection techniques. Attack detection is achieved through real-time monitoring of network traffic, analyzing packet content, and comparing known attack patterns to identify anomalous behavior. Network attack detection uses real-time analysis of network traffic and packets, employing specific analytical methods and protocol review, to rapidly identify and prevent potential attacks.
[0004] Traditional detection methods rely on fixed pattern matching and static anomaly detection mechanisms, making them ineffective in complex and volatile network environments. For example, fixed pattern matching can only detect known attack behaviors, but its detection effectiveness significantly decreases when faced with unknown threats and new attack patterns. Static anomaly detection methods are typically based on preset rules or thresholds and struggle to adapt to the dynamic changes in real-time network traffic. Significant fluctuations in the network environment can lead to high false positive or false negative rates, reducing detection accuracy and missing key clues to covert attack behaviors. For example, in the face of multi-stage attacks, traditional methods struggle to identify attack links by correlating and analyzing path and communication frequency characteristics, significantly limiting attack defense capabilities. Summary of the Invention
[0005] To address the technical problem in existing technologies that traditional methods have difficulty analyzing attack links by correlating path and communication frequency characteristics when facing multi-stage attacks, significantly limiting attack defense capabilities, the present invention provides a network attack detection method and system based on an event-driven architecture. The technical solution is as follows:
[0006] In one aspect, a network attack detection method based on an event-driven architecture is provided. The method is implemented by a network attack detection device based on an event-driven architecture, and the method includes:
[0007] S1. Based on the target network environment, by parsing the application layer parameters and combining them with the transport layer parameters, a multi-layer mapping table is established according to the field relationship to obtain multi-layer data packet feature mapping information;
[0008] S2. Based on the multi-layer data packet feature mapping information, extract the usage of non-standard ports and data packets that do not conform to path specifications, combine the path value and port information to establish an abnormal group, and generate a multi-layer abnormal behavior recognition result;
[0009] S3. Based on the multi-layer abnormal behavior identification results, extract the abnormal data packet time interval distribution value and packet length statistics, combine the normal distribution range of historical network behavior records, dynamically adjust the detection threshold range and path determination rules, and obtain an adaptive detection threshold rule set;
[0010] S4. Based on the adaptive detection threshold rule set, a graph model is constructed with communication entities as nodes and paths as edges. The change value of the number of communication connections between nodes and the growth rate of abnormal path values in the edge set are analyzed. The number of new connections between nodes and the abnormal incremental distribution value of the edge set are extracted to generate network abnormal event correlation information.
[0011] S5. Based on the network abnormal event correlation information, the path value distribution characteristics are compared with the correlation characteristics of known attack event records to screen node pair combinations and path distributions that meet the potential attack behavior characteristics to obtain potential network attack detection results.
[0012] On the other hand, a network attack detection system based on an event-driven architecture is provided. The system is applied to a network attack detection method based on an event-driven architecture. The system includes:
[0013] The data parsing unit is used to parse the application layer parameters based on the target network environment, combine the transport layer parameters, establish a multi-layer mapping table according to the field relationship, and obtain the multi-layer data packet feature mapping information;
[0014] Abnormal behavior analysis unit, used for extracting non-standard
[0015] The port usage and data packets that do not conform to the path specification are combined with the path value and port information to establish an abnormal group, generating multi-layer abnormal behavior identification results;
[0016] A detection threshold adjustment unit is configured to extract the time interval distribution value and packet length statistics of abnormal data packets based on the multi-layer abnormal behavior identification results, and dynamically adjust the detection threshold range and path determination rules in combination with the normal distribution range of historical network behavior records to obtain an adaptive detection threshold rule set;
[0017] An abnormal event analysis unit is used to construct a graph model based on the adaptive detection threshold rule set, using communication entities as nodes and paths as edges, analyze the change value of the number of communication connections between nodes and the growth rate of abnormal path values in the edge set, extract the number of new connections between nodes and the abnormal incremental distribution value of the edge set, and generate network abnormal event correlation information;
[0018] The attack detection unit is used to compare the path value distribution characteristics with the correlation characteristics of known attack event records based on the network abnormal event correlation information, screen the node pair combinations and path distributions that meet the potential attack behavior characteristics, and obtain potential network attack detection results.
[0019] On the other hand, a network attack detection device based on an event-driven architecture is provided, and the network attack detection device based on the event-driven architecture includes: a processor; a memory, wherein the memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, any one of the network attack detection methods based on the event-driven architecture is implemented.
[0020] On the other hand, a computer-readable storage medium is provided, wherein the storage medium stores at least one instruction, and the at least one instruction is loaded and executed by a processor to implement any one of the above-mentioned network attack detection methods based on event-driven architecture.
[0021] The beneficial effects brought about by the technical solution provided by the embodiment of the present invention include at least:
[0022] The embodiment of the present invention firstly analyzes application layer parameters based on the target network environment, combines them with transport layer parameters, and establishes a multi-layer mapping table according to field relationships to obtain multi-layer packet feature mapping information. Based on the multi-layer packet feature mapping information, the usage of non-standard ports and packets that do not conform to path specifications are extracted, and path values and port information are combined to establish anomaly groups to generate multi-layer abnormal behavior identification results. Based on the multi-layer abnormal behavior identification results, the time interval distribution value and packet length statistics of abnormal packets are extracted. Combined with the normal distribution range of historical network behavior records, the detection threshold range and path determination rules are dynamically adjusted to obtain an adaptive detection threshold rule set. Secondly, based on the adaptive detection threshold rule set, a graph model is constructed with communication entities as nodes and paths as edges. The change value of the number of communication connections between nodes and the growth rate of abnormal path values in the edge set are analyzed. The number of new connections between nodes and the abnormal incremental distribution value of the edge set are extracted to generate network abnormal event correlation information. Finally, based on the network abnormal event correlation information, the path value distribution characteristics are compared with the correlation characteristics of known attack event records to screen node pair combinations and path distributions that meet the potential attack behavior characteristics to obtain potential network attack detection results.
[0023] The embodiments of the present invention can comprehensively capture the sources and characteristics of abnormal data packets by capturing data packets in the network in real time, performing hierarchical analysis and establishing multi-layer mapping relationships; by combining the proportional analysis of time interval distribution values and data packet lengths, as well as the detection method of deviation from historical records, the screening of abnormal data packets is made more accurate, and the detection threshold interval can be dynamically adjusted to adapt to changes in the network environment; by constructing a graph structure model of the path and time distribution between communication entities, and combining the analysis of communication frequency and abnormal incremental changes, high-frequency communication entity pairs and potential attack paths can be quickly located, and network abnormal event correlation information can be generated; by comparing path values with attack event records one by one, combining path distribution characteristics with historical attack record correlation, node pair combinations and path distributions that meet potential attack characteristics are accurately screened out, making the detection range of potential attacks wider, the response faster, and the targeting more targeted. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0025] Figure 1 This is a flow chart of a network attack detection method based on an event-driven architecture provided by an embodiment of the present invention;
[0026] Figure 2This is a flow chart of obtaining multi-layer data packet feature mapping information provided by an embodiment of the present invention;
[0027] Figure 3 This is a flow chart of generating multi-layer abnormal behavior recognition results provided by an embodiment of the present invention;
[0028] Figure 4 This is a flow chart of obtaining an adaptive detection threshold rule set provided by an embodiment of the present invention;
[0029] Figure 5 This is a flow chart of generating network abnormal event correlation information provided by an embodiment of the present invention;
[0030] Figure 6 This is a flow chart of potential network attack detection results provided by an embodiment of the present invention;
[0031] Figure 7 This is a block diagram of a network attack detection system based on an event-driven architecture provided by an embodiment of the present invention;
[0032] Figure 8 This is a schematic diagram of the structure of a network attack detection device based on an event-driven architecture provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0033] The technical solution of the present invention is described below in conjunction with the accompanying drawings.
[0034] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as an "exemplary" in the present invention should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of the word "exemplary" is intended to present concepts in a concrete manner. Furthermore, in the embodiments of the present invention, "and / or" can mean both or either of the two.
[0035] In the embodiments of the present invention, the terms "image" and "picture" may sometimes be used interchangeably. It should be noted that, when the distinction is not emphasized, the meanings they convey are the same. The terms "of," "corresponding," and "corresponding" may sometimes be used interchangeably. It should be noted that, when the distinction is not emphasized, the meanings they convey are the same.
[0036] In the embodiments of the present invention, sometimes a subscript such as W1 may be written as a non-subscript such as W1. When the difference is not emphasized, the meanings to be expressed are the same.
[0037] In order to make the technical problems, technical solutions and advantages to be solved by the present invention clearer, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.
[0038] The embodiment of the present invention provides a network attack detection method based on an event-driven architecture. The method can be implemented by a network attack detection device based on an event-driven architecture. The network attack detection device based on an event-driven architecture can be a terminal or a server. Figure 1 The flowchart of the network attack detection method based on the event-driven architecture is shown. The processing flow of the method may include the following steps:
[0039] S1. Based on the target network environment, by parsing the application layer parameters and combining them with the transport layer parameters, a multi-layer mapping table is established according to the field relationship to obtain multi-layer data packet feature mapping information.
[0040] Among them, such as Figure 2 Shown is a flow chart of obtaining multi-layer data packet feature mapping information provided by an embodiment of the present invention.
[0041] Optionally, the specific implementation process of S1 includes S11-S13:
[0042] S11. Based on the target network environment, capture data packets in the network in real time; extract timestamps from the data packets and sort them in chronological order to obtain sorted data packets; parse the field types and field value combinations of the application layer in the sorted data packets to obtain time-sequential data packet parsing results;
[0043] In a feasible implementation, based on the target network environment, real-time capture of data packets in the network is implemented, and the data packets are grouped one by one, and the grouping basis is source address, destination address and transmission protocol; the timestamp information of the captured data packets is extracted, and the grouped data packets are arranged in order of timestamp size. The timestamp accuracy needs to be corrected during the arrangement process, and millisecond timestamps are used as the arrangement basis to avoid time overlap in data packet sorting; the application layer field type in each data packet is extracted through a parsing module, including protocol type, number of fields and field value range; the field type is quantized into a standard value according to the parsing rules, for example, the field type of a TCP data packet can be set to 1, and the field value range can be quantized into an integer range of 0-255. After quantization, the field values are combined and the fields are combined into an independent structured form to facilitate the analysis of the meaning and purpose of the field values; at the same time, abnormal values in the application layer fields are detected, and field values exceeding the quantization interval are marked as abnormal and stored independently in an abnormal field value table, and a time-sequential data packet parsing result is formed through multiple rounds of data packet parsing.
[0044] S12. Extracting the transport protocol identifier and packet length information from the application layer data based on the time-sequential data packet parsing results; parsing the port information and packet flag bits from the transport layer data to obtain application layer and transport layer parsing information;
[0045] In a feasible implementation, based on the results of time-sequential data packet parsing, specific fields identifying the transport protocol in the application layer data are extracted, the identification field values are analyzed one by one, and the distribution quantity and proportion of different transport protocol identifiers are determined; for example, the HTTP protocol identifier value can be calculated by counting the frequency of occurrence, and at the same time, the data packet length field of each protocol identifier is parsed, and the range of data packet length is divided into several intervals; for example, intervals such as 100-500 bytes and 500-1000 bytes, and the distribution ratio of each protocol identifier in different length intervals is counted, the port information in the transport layer data is parsed, the port number and the corresponding data packet flag are extracted, the port number range is divided into standard ports and non-standard ports, the proportion of the number of data packets of the two types of ports is counted, and the transport layer connection status is extracted through the data packet flag; for example, the combination of flag bits such as SYN and ACK, the flag bits are correlated with the port number for analysis, and a distribution table of each port status is formed, and the application layer and transport layer parsing information is obtained through parsing.
[0046] S13. Based on the application layer and transport layer parsing information, parse the source address, destination address and path value of the network layer to obtain the parsing result; according to the parsing result, establish a correspondence table between the field value and the path value to obtain multi-layer data packet feature mapping information.
[0047] In a feasible implementation, based on the application layer and transport layer parsing information, the data packet field values in the network layer are parsed, including the source address, destination address and path value; the source address and destination address are classified through the IP address segment parsing module; for example, the network address segment is divided by the subnet mask, and the address segment of each data packet is matched and classified; the path value is parsed by performing a secondary extraction of the path field in the data packet header, forming a correspondence between the path field and the destination address, and storing the field values and correspondence of all data packets in an independent table, which is used to deduplicate the path value and filter a unique set of path values; an index is established for the correspondence between the path value and the field value, for example, information such as the protocol identifier and data packet length extracted from the field value can be quickly located through the path value index, and a correspondence table between the field value and the path value is formed by integrating the index table to obtain multi-layer data packet feature mapping information.
[0048] S2. Based on the multi-layer packet feature mapping information, the usage of non-standard ports and packets that do not conform to the path specification are extracted, the path value and port information are combined to establish anomaly groups, and the multi-layer abnormal behavior recognition results are generated.
[0049] Among them, such as Figure 3 The figure shows a flow chart of generating multi-layer abnormal behavior recognition results provided by an embodiment of the present invention.
[0050] Optionally, the specific implementation process of S2 includes S21-S23:
[0051] S21. Based on the multi-layer packet feature mapping information, compare the path values and port records in the network interaction one by one, filter out abnormal data packets that do not match the standard port from the path values, and generate abnormal path value data;
[0052] In a feasible implementation, based on multi-layer data packet feature mapping information, the path value information of the multi-layer data packet is extracted by parsing the path value and port records in the network interaction one by one, and the path value is classified according to the network layer protocol type; for example, the TCP protocol path value is separately marked, and the UDP protocol path value is stored in groups respectively, and the port number associated with the path value is compared one by one by calling the standard port table, the path value that fails to match the standard port is extracted, and the combination of the path value and its associated port number is screened; by statistically analyzing the record range of the abnormal port number, the abnormal port number that appears frequently is identified, and the combination features that appear frequently in these port and path value combinations are parsed, and the topological distribution structure of the path value is checked at the same time to determine the association of the abnormal path; for example, by calculating the frequency of abnormal path values in the network topology and the communication association between them and the standard path value, the abnormal path values that do not match the standard port and their associated information are recorded and marked to generate abnormal path value data.
[0053] S22. Extracting time distribution and packet length information of abnormal data packets based on the abnormal path value data; grouping the extracted time distribution according to time intervals to obtain time interval distribution information;
[0054] In a feasible implementation, based on abnormal path value data, by extracting the time distribution information of abnormal data packets corresponding to each path value, the data packets are reordered according to the timestamp to determine the frequency of occurrence of abnormal data packets in different time periods; for the data packet length information of each path value, its length field value is extracted, and the data packets are grouped according to the specified length interval; for example, the data packet length is divided into four intervals of less than 100 bytes, 100-500 bytes, 500-1000 bytes and greater than 1000 bytes, and the length distribution characteristics of each path value are calculated by counting the number distribution of data packets in each length interval, and at the same time, the abnormal peak of the time distribution is detected, and the peak point of the timestamp and the corresponding number of data packets are extracted; by constructing a joint distribution table of timestamp and data packet length, the peak value of the data packet length and the abnormal time period of the time distribution are correlated and analyzed, the abnormal time distribution characteristics of the path value are refined, and the statistical results of the time interval and data packet length are stored according to the path value to obtain the time interval distribution information.
[0055] S23. Based on the time interval distribution information, calculate the difference value of the time interval in the group; combine the difference value with the data packet length, filter abnormal data, establish a path value set and port information list of abnormal combinations, and generate a multi-layer abnormal behavior recognition result.
[0056] In a feasible implementation, based on the time interval distribution information, the difference value of the time interval distribution is calculated; first, the group mean of the time interval is extracted, for example, the time interval mean of the abnormal data packets in each time period is calculated, the time interval mean values of different groups are arranged in chronological order, and the time interval difference value is extracted by calculating the change amplitude of the time interval mean; the difference value is analyzed in combination with the data packet length information, the peak point of the time interval difference value and the length distribution of the corresponding data packet are extracted, and the abnormal points of the joint distribution of the difference value and the data packet length are screened; the abnormal points are marked according to the path value, and an index relationship table of the path value and the abnormal points is established, and the number of abnormal points and port information of each path value are counted at the same time. The high-frequency abnormal path port combination in the path topology is extracted by the combination of the path value and the port number, and it is stored as a path value set and a port information list to generate a multi-layer abnormal behavior recognition result.
[0057] S3. Based on the multi-layer abnormal behavior identification results, the time interval distribution value and packet length statistics of abnormal data packets are extracted. Combined with the normal distribution range of historical network behavior records, the detection threshold range and path determination rules are dynamically adjusted to obtain an adaptive detection threshold rule set.
[0058] Among them, such as Figure 4 Shown is a flow chart of obtaining an adaptive detection threshold rule set provided by an embodiment of the present invention.
[0059] Optionally, the specific implementation of S3 includes S31-S33:
[0060] S31. Based on the multi-layer abnormal behavior identification results, extract the time interval distribution value and data packet length information of each path; arrange the time interval distribution values in time increment order to obtain a time increment sorting result;
[0061] In a feasible implementation, based on the multi-layer abnormal behavior identification results, the time interval distribution value and data packet length information of each path are extracted; the stored multi-layer abnormal behavior result data table is called, and the path value fields in the table are analyzed one by one for path time information and data packet length information; the timestamp data associated with each path is extracted, and the time interval value is obtained by calculating the difference between the timestamps. The time interval data is grouped and stored according to the path field, and the data packet length field information is read at the same time to extract the data packet length corresponding to each path. The length value is bound to the path field and stored, and the time interval value is arranged in time increment order; a step-by-step comparison method is used to detect the ascending change trend of the incremental value to ensure the continuity of the time increment arrangement, and an incremental sorting verification program is used to determine whether there is a jumping incremental anomaly, and the time interval value with the abnormal point is marked as a specific anomaly category. After completing the overall arrangement of the time increment, the sorted incremental information is stored with the path field as the index, and a complete time increment sorting result is generated in combination with the data packet length.
[0062] S32. Based on the time increment sorting result, calculate the range of the time increment change; perform a corresponding proportional calculation on the time increment change range and the packet length statistics to obtain a proportional relationship calculation result;
[0063] In a feasible implementation, based on the time increment sorting result, the increment value field in the time increment sorting result is extracted by calculating the time increment variation range and performing a corresponding ratio calculation with the packet length statistics; the difference between two adjacent groups of increment values is calculated to obtain the time increment variation range; the variation range field is grouped and stored according to the path field, and the packet length information is statistically analyzed to calculate the maximum, minimum and average value of the packet length in each path; the statistics are matched with the time increment variation range field one by one, and the time increment variation range is proportionally calculated with the average value of the packet length; for example, the formula is used. Calculate the time increment change ratio for each path ,in, is the time increment range, The average length of the data packets; the results of the proportion calculation are stored by path field, and the abnormal mark of the proportion field is recorded for the path with a large proportion result value, and the proportion values are grouped and stored as the proportion relationship calculation result.
[0064] S33, judging whether the ratio deviates from the normal range in the historical record based on the calculation result, adjusting the detection threshold according to the deviation degree, updating the port range parameter in the path determination rule, and obtaining an adaptive detection threshold rule set.
[0065] Optionally, the process of adjusting the detection threshold is represented by the following formula (1):
[0066] (1)
[0067] wherein, represents the updated detection threshold, represents the detection threshold before adjustment, represents the ratio of the time increment change range to the packet length statistical value in the current calculation, represents the average ratio of the time increment change range to the packet length statistical value in the historical record, represents the variance value of the historical ratio distribution, represents a weight coefficient of the influence of the adjustment ratio deviation on the threshold adjustment, represents an adjustment parameter of the sensitivity of the adjustment path determination rule to the detection threshold, represents a stability coefficient of the adjustment noise influence range.
[0068] wherein, the updated detection threshold is used as a new judgment standard in network monitoring; the detection threshold before adjustment is usually obtained from the initial setting of the system or the previous monitoring period; the average ratio of the time increment change range to the packet length statistical value in the historical record is calculated by statistical analysis of the historical network data; the variance value of the historical ratio distribution is calculated by statistical analysis of the dispersion degree of the ratio in the historical data; the weight coefficient of the influence of the adjustment ratio deviation on the threshold adjustment is preset according to the sensitivity requirement of the system to abnormal detection; the adjustment parameter of the sensitivity of the adjustment path determination rule to the detection threshold is preset according to the system requirement; and the stability coefficient of the adjustment noise influence range is preset according to the system requirement to reduce the influence of accidental abnormalities in the variance.
[0069] In a feasible implementation, the following is an embodiment of calculating the new detection threshold:
[0070] Let , , , , , , .
[0071] Calculate the absolute value of the ratio deviation:
[0072] ;
[0073] The denominator part is calculated:
[0074]
[0075] The adjustment amount is calculated:
[0076]
[0077] The new detection threshold is calculated:
[0078]
[0079] Through the above calculation, the new detection threshold is about 50.792. The system adjusts the detection threshold according to the current observed proportion deviation, combined with the statistical characteristics of historical data, to better adapt to the current network situation.
[0080] S4, based on the adaptive detection threshold rule set, taking the communication entity as the node and the path as the edge to construct a graph model, analyzing the change value of the communication connection between nodes and the abnormal path value growth rate in the edge set, extracting the newly added connection quantity between nodes and the abnormal increment distribution value of the edge set, and generating network abnormal event correlation information.
[0081] Among them, as Figure 5 shown in the flowchart for generating network abnormal event correlation information provided by the embodiment of the application;
[0082] Optionally, the specific implementation process of S4 includes S41-S43:
[0083] S41, based on the adaptive detection threshold rule set, extracting the path value and time distribution record of the communication entity in the network interaction; according to the path corresponding relationship between the communication entities, establishing a graph structure model with nodes as communication entities and edges as path relationships, and obtaining a network interaction graph model;
[0084] In a feasible implementation, based on an adaptive detection threshold rule set, the path values and time distribution records of communication entities in network interactions are extracted; all path value information is extracted from the rule set and classified according to the source address and destination address of the communication entity pair; the path value and its time distribution field are bound and stored, and the time distribution record is parsed; the time records are grouped and stored according to the communication entity pair, an index relationship is established between the grouped time distribution records and the path value, and a preliminary node information table is established for the path value and time distribution field of each communication entity pair; wherein the node table contains the unique identifier of the communication entity, the path value index and the time distribution information; by parsing the path value correspondence of each communication entity pair in the node table, an edge information table is established, and the edge table records the number of paths, communication direction and time interval data between each pair of communication entities; the set data of nodes and edges is constructed, and the path values and time distribution information of all communication entity pairs are associated as node sets and edge sets, and a complete graph structure is generated in combination with a graph construction tool, and the nodes are regarded as communication entities and the edges are regarded as path relationships, which are output as a network interaction graph model.
[0085] S42. Based on the network interaction graph model, by analyzing the abnormal change values of the time interval in the path value, extracting the entity pairs whose communication frequency exceeds the threshold, calculating the number of abnormal communications and the corresponding abnormal path number for each entity, and generating abnormal communication statistics;
[0086] In a feasible implementation, based on the network interaction graph model, by analyzing the abnormal change value of the time interval in the path value, the entity pair combination whose communication frequency exceeds the threshold is extracted; each node and edge in the graph model is parsed one by one, the time interval field data on the edge is extracted, and the mean and variance of the time interval are calculated; the current time interval is compared with the historical mean, and the degree of deviation is calculated using the following formula (2):
[0087] (2)
[0088] in, is the current time interval deviation, is the current time interval, is the mean of the historical time interval, is the standard deviation of the historical time interval; the edges with a deviation exceeding the preset threshold are recorded as abnormal paths, and the communication frequency of each node is counted, and the communication frequency of the node is compared with the set threshold; the nodes whose frequency exceeds the threshold are marked as high-frequency communication entities, and abnormal entity pairs are formed by extracting all edges marked as abnormal paths and high-frequency communication nodes. At the same time, the number of communication paths for each abnormal entity is counted to generate the number of abnormal communications and the number of abnormal paths for each entity, and all statistical results are organized into abnormal communication statistics.
[0089] S43. Based on the abnormal communication statistical results, the statistical results are arranged in chronological order, abnormal incremental changes in path values are extracted, and high-frequency communication entity pairs are screened in combination with the incremental change results to obtain network abnormal event correlation information.
[0090] In a feasible implementation, based on the abnormal communication statistical results, the statistical results are arranged in chronological order, the change trend of the abnormal path number field on the time axis is analyzed, and the incremental value of the abnormal path number at each time point is extracted; all incremental values are sorted in chronological order, and the peak points within the time period are extracted by calculating the change amplitude of the incremental values; the time and path values corresponding to the peak points are correlated and extracted, and high-frequency communication entity pair combinations are screened; for example, entity pairs whose communication frequency exceeds a threshold are sorted in descending order according to the incremental change amplitude of the path value, and the entity pairs with the highest communication frequency and the largest incremental change amplitude are selected as high-frequency communication entities, and the screened high-frequency communication entities and their path relationships are stored as network abnormal event correlation information, so as to obtain a complete correlation analysis result of the time distribution of network interaction and the path relationship of entity pairs.
[0091] S5. Based on the correlation information of network abnormal events, the path value distribution characteristics are compared with the correlation characteristics of known attack event records to screen the node pair combinations and path distributions that meet the characteristics of potential attack behavior to obtain potential network attack detection results.
[0092] Among them, such as Figure 6 Shown is a flow chart of potential network attack detection results provided by an embodiment of the present invention.
[0093] Optionally, the specific implementation process of S5 includes S51-S53:
[0094] S51. Based on the network abnormal event correlation information, extract high-frequency communication entity pair combinations from the graph; sort the path values in the high-frequency communication entity pairs according to the communication frequency to generate high-frequency communication path information;
[0095] In a feasible implementation, based on network abnormal event correlation information, high-frequency communication entity pair combinations are extracted from the graph, and communication entity pair fields are extracted from the network abnormal event correlation information; the communication frequency field of each communication entity pair is parsed, and the communication frequency values are sorted in descending order; the path values of the high-frequency communication entity pairs are extracted, and an index relationship is established between the extracted path value field and the communication frequency field; the path values are grouped and stored according to the communication frequency, and the frequency distribution of the path values is statistically analyzed, and the frequency of occurrence of each path value and the corresponding number of communication entity pairs are statistically analyzed; the path values with higher frequencies are marked as high-frequency paths, forming an independent high-frequency path information table; by comparing the distribution relationship between the high-frequency path table and the communication frequency field, high-frequency communication path information is generated and stored as an independent data table.
[0096] S52. Extracting path value distribution characteristics between pairs of communication entities based on high-frequency communication path information, and establishing a corresponding relationship table between path values and incremental peak values in combination with abnormal incremental distribution peak values of path values, thereby obtaining a corresponding relationship table between paths and peak values.
[0097] In a feasible implementation, based on high-frequency communication path information, path value distribution characteristics between communication entity pairs are extracted; path value fields and their corresponding communication entity pair fields are extracted from the high-frequency communication path information, the distribution range of each path value is analyzed, and the paths are classified and stored according to the distribution area of the path values; the distribution frequency field of the path value is associated with the communication entity pair field to form a set of path value distribution characteristics; combined with the abnormal incremental distribution data of the path value, the peak value of the incremental distribution in the path value field is detected, the peak feature is extracted by calculating the mean and maximum value of the abnormal increments in the path value field, and a correspondence is established between the distribution range of the path value and the peak feature value; the path value field and its peak field are stored as an independent index table to obtain a path and peak correspondence table.
[0098] S53. Based on the path-peak correspondence table, the path value distribution characteristics are compared with the associated characteristics of the attack event records one by one to evaluate the feature matching degree, and the node pair combinations and path distributions that meet the potential attack behavior characteristics are screened to generate potential network attack detection results.
[0099] Optionally, the process of evaluating feature matching is expressed by the following formula (3):
[0100] (3)
[0101] in, represents the feature matching score, Indicates the path value distribution Observed characteristic values, Indicates the number of The average value of the feature, Indicates the path distribution characteristics The actual distribution value of the item path, Indicates the number of historical attacks The distribution value of the item path, Indicates the The historical distribution variance of the item eigenvalue, represents the historical distribution variance of the path distribution value, Indicates the weight of the eigenvalue deviation on the matching degree, Indicates the weight of path distribution deviation on matching degree, represents a stable value that prevents the denominator from being zero, Represents the stable value of the variance of the path distribution.
[0102] Among them, the path value distribution The observation feature value is obtained by real-time monitoring of the path value and feature distribution in the network, and the observation value in each time period is extracted; The average value of each feature is calculated by averaging the sum of all corresponding feature values in the historical records and is used for comparison with the real-time observation value; The actual distribution value of a path is calculated by counting the path values in the network traffic data in the current time period and calculating the distribution ratio of each path; The distribution value of each path is calculated by statistically analyzing the historical data of known attack events and calculating the distribution ratio of each path; The historical distribution variance of the item eigenvalue is calculated by calculating the degree of dispersion of a certain eigenvalue data in the historical records; the historical distribution variance of the path distribution value is calculated by counting the changes in the path distribution ratio in all historical attack events; the weight of the eigenvalue deviation on the matching degree is manually set according to system requirements, mainly used to adjust the proportion of the feature level; the weight of the path distribution deviation on the matching degree is manually set according to system requirements, mainly used to adjust the proportion of the path level; the stable value to prevent the denominator from being zero is used to prevent the denominator from being zero and ensure calculation stability. It is usually set to a very small value, such as ; The stable value of the path distribution variance is used to prevent abnormalities in the calculation of the path distribution variance. It is usually set to a minimum value, such as .
[0103] In a feasible implementation, the following is an example of calculating and evaluating the feature matching degree:
[0104] Assume the following parameter values: , ; , ; ,
[0105] ; , , ; ; , ; , ;
[0106] Calculate the deviation of the eigenvalue of the first feature:
[0107]
[0108] Calculate the deviation of the eigenvalue of the second feature:
[0109]
[0110] Calculate the first path distribution deviation part:
[0111]
[0112] Calculate the second path distribution deviation part:
[0113]
[0114] Summarize the matching score :
[0115]
[0116] Wherein, the matching score . Indicate that the current path distribution and the characteristics of the historical attack record have a moderate degree of relevance, which can be used as a candidate for screening potential network attack behavior.
[0117] Optionally, the multi-layer data packet feature mapping information includes: a field type value table, a port usage record table, a path value correspondence table, and a time-ordered packet list.
[0118] The multi-layer abnormal behavior recognition result includes: an abnormal path value set, an abnormal port information list, a time interval distribution group list, and a data packet length statistics table.
[0119] The adaptive detection threshold rule set includes: a time increment change range, a packet length proportion threshold, and a path determination rule parameter set.
[0120] The network anomaly event association information includes: a communication entity node set, a path edge set, a communication anomaly increment distribution table, and a high-frequency abnormal communication node pair.
[0121] The potential network attack detection result includes: a communication entity pair combination feature table, a path value distribution feature set, and an abnormal increment peak value information table.
[0122] The embodiment of the present invention firstly analyzes application layer parameters based on the target network environment, combines them with transport layer parameters, and establishes a multi-layer mapping table according to field relationships to obtain multi-layer packet feature mapping information. Based on the multi-layer packet feature mapping information, the usage of non-standard ports and packets that do not conform to path specifications are extracted, and path values and port information are combined to establish anomaly groups to generate multi-layer abnormal behavior identification results. Based on the multi-layer abnormal behavior identification results, the time interval distribution value and packet length statistics of abnormal packets are extracted. Combined with the normal distribution range of historical network behavior records, the detection threshold range and path determination rules are dynamically adjusted to obtain an adaptive detection threshold rule set. Secondly, based on the adaptive detection threshold rule set, a graph model is constructed with communication entities as nodes and paths as edges. The change value of the number of communication connections between nodes and the growth rate of abnormal path values in the edge set are analyzed. The number of new connections between nodes and the abnormal incremental distribution value of the edge set are extracted to generate network abnormal event correlation information. Finally, based on the network abnormal event correlation information, the path value distribution characteristics are compared with the correlation characteristics of known attack event records to screen node pair combinations and path distributions that meet the potential attack behavior characteristics to obtain potential network attack detection results.
[0123] The embodiments of the present invention can comprehensively capture the sources and characteristics of abnormal data packets by capturing data packets in the network in real time, performing hierarchical analysis and establishing multi-layer mapping relationships; by combining the proportional analysis of time interval distribution values and data packet lengths, as well as the detection method of deviation from historical records, the screening of abnormal data packets is made more accurate, and the detection threshold interval can be dynamically adjusted to adapt to changes in the network environment; by constructing a graph structure model of the path and time distribution between communication entities, and combining the analysis of communication frequency and abnormal incremental changes, high-frequency communication entity pairs and potential attack paths can be quickly located, and network abnormal event correlation information can be generated; by comparing path values with attack event records one by one, combining path distribution characteristics with historical attack record correlation, node pair combinations and path distributions that meet potential attack characteristics are accurately screened out, making the detection range of potential attacks wider, the response faster, and the targeting more targeted.
[0124] Figure 7 This is a block diagram of a network attack detection system based on an event-driven architecture according to an exemplary embodiment. The system is used for a network attack detection method based on an event-driven architecture. Figure 7 The system includes a data parsing unit 710, an abnormal behavior analysis unit 720, a detection threshold adjustment unit 730, an abnormal event analysis unit 740, and an attack detection unit 750.
[0125] The data parsing unit 710 is used to parse application layer parameters based on the target network environment, combine them with transport layer parameters, establish a multi-layer mapping table according to field relationships, and obtain multi-layer data packet feature mapping information;
[0126] An abnormal behavior analysis unit 720 is configured to extract the usage of non-standard ports and packets that do not conform to path specifications based on the multi-layer packet feature mapping information, combine the path value and the port information to establish an abnormal group, and generate a multi-layer abnormal behavior identification result;
[0127] A detection threshold adjustment unit 730 is configured to extract the time interval distribution value and packet length statistics of abnormal data packets based on the multi-layer abnormal behavior identification results, and dynamically adjust the detection threshold range and path determination rules in combination with the normal distribution range of historical network behavior records to obtain an adaptive detection threshold rule set;
[0128] An abnormal event analysis unit 740 is used to construct a graph model based on the adaptive detection threshold rule set, using communication entities as nodes and paths as edges, analyze the change value of the number of communication connections between nodes and the growth rate of abnormal path values in the edge set, extract the number of new connections between nodes and the abnormal incremental distribution value of the edge set, and generate network abnormal event correlation information;
[0129] The attack detection unit 750 is used to compare the path value distribution characteristics with the correlation characteristics of known attack event records based on the network abnormal event correlation information, screen node pair combinations and path distributions that meet the potential attack behavior characteristics, and obtain potential network attack detection results.
[0130] Optionally, the multi-layer data packet feature mapping information includes: a field type value table, a port usage record table, a path value correspondence table, and a time-sorted data packet list;
[0131] The multi-layer abnormal behavior identification results include: abnormal path value set, abnormal port information list, time interval distribution group list and data packet length statistics table;
[0132] The adaptive detection threshold rule set includes: a time increment variation range, a packet length ratio threshold, and a path determination rule parameter set;
[0133] The network abnormal event association information includes: a communication entity node set, a path edge set, a communication abnormality increment distribution table, and a high-frequency abnormal communication node pair;
[0134] The potential network attack detection result includes: a communication entity pair combination feature table, a path value distribution feature set, and an abnormal increment peak information table.
[0135] Optionally, the data parsing unit 710 is configured to:
[0136] Based on the target network environment, the system captures data packets in the network in real time; extracts the timestamps of the data packets and sorts them in chronological order to obtain sorted data packets; parses the field types and field value combinations of the application layer in the sorted data packets to obtain the time-sequential data packet parsing results;
[0137] Based on the time sequence data packet parsing results, the transmission protocol identifier and data packet length information in the application layer data are extracted; the port information and data packet flag bits in the transport layer data are parsed to obtain the application layer and transport layer parsing information;
[0138] Based on the application layer and transport layer parsing information, the source address, destination address and path value of the network layer are parsed to obtain the parsing results; according to the parsing results, a correspondence table between field values and path values is established to obtain multi-layer data packet feature mapping information.
[0139] Optionally, the abnormal behavior analysis unit 720 is configured to:
[0140] Based on multi-layer packet feature mapping information, the path values and port records in network interactions are compared one by one, and abnormal packets that do not match the standard ports are filtered out from the path values to generate abnormal path value data;
[0141] Based on the abnormal path value data, the time distribution and packet length information of the abnormal data packets are extracted; the extracted time distribution is grouped according to time intervals to obtain time interval distribution information;
[0142] Based on the time interval distribution information, the difference value of the time interval in the group is calculated; the difference value is combined with the packet length, abnormal data is filtered, and a path value set and port information list of the abnormal combination are established to generate multi-layer abnormal behavior recognition results.
[0143] Optionally, the detection threshold adjustment unit 730 is configured to:
[0144] Based on the multi-layer abnormal behavior recognition results, the time interval distribution value and packet length information of each path are extracted; the time interval distribution values are arranged in time increment order to obtain the time increment sorting result;
[0145] Based on the time increment sorting results, the range of time increment changes is calculated; the time increment change range and the packet length statistics are proportionally calculated to obtain the proportional relationship calculation result;
[0146] Based on the calculation result of the proportional relationship, it is determined whether the ratio deviates from the normal range in the historical records. According to the degree of deviation, the detection threshold is adjusted, the port range parameter in the path determination rule is updated, and an adaptive detection threshold rule set is obtained.
[0147] Optionally, the process of adjusting the detection threshold is expressed by the following formula (1):
[0148] (1)
[0149] in, represents the updated detection threshold, represents the detection threshold before adjustment, Indicates the observed ratio of the path value and packet length statistics in the current calculation. Indicates the average ratio of path value to packet length statistics in historical records. represents the variance value of the historical proportion distribution, Indicates the weight coefficient of the impact of the adjustment ratio deviation on the threshold adjustment, It represents the adjustment parameter for adjusting the sensitivity of the path decision rule to the detection threshold. Indicates the stability factor for adjusting the noise influence range.
[0150] Optionally, the abnormal event analysis unit 740 is configured to:
[0151] Based on the adaptive detection threshold rule set, the path value and time distribution records of communication entities in network interaction are extracted; according to the path correspondence between communication entities, a graph structure model is established with nodes as communication entities and edges as path relationships to obtain a network interaction graph model;
[0152] Based on the network interaction graph model, by analyzing the abnormal change values of the time interval in the path value, the entity pairs with communication frequency exceeding the threshold are extracted, the number of abnormal communications and the corresponding abnormal path number of each entity are calculated, and the abnormal communication statistics are generated;
[0153] Based on the abnormal communication statistics, the statistical results are arranged in chronological order, and the abnormal incremental changes of path values are extracted. Combined with the incremental change results, high-frequency communication entity pairs are screened to obtain the correlation information of network abnormal events.
[0154] Optionally, the attack detection unit 750 is configured to:
[0155] Based on the network abnormal event correlation information, high-frequency communication entity pairs are extracted from the graph; the path values in the high-frequency communication entity pairs are sorted according to the communication frequency to generate high-frequency communication path information;
[0156] Based on high-frequency communication path information, the path value distribution characteristics between communication entity pairs are extracted. Combined with the abnormal incremental distribution peak of the path value, a corresponding relationship table between the path value and the incremental peak is established to obtain the path and peak correspondence table;
[0157] Based on the path-peak correspondence table, the path value distribution characteristics are compared with the associated characteristics of the attack event records one by one to evaluate the feature matching degree, screen the node pair combinations and path distributions that meet the potential attack behavior characteristics, and generate potential network attack detection results.
[0158] Optionally, the process of evaluating the feature matching degree is expressed by the following formula (2):
[0159] (2)
[0160] in, represents the feature matching score, Indicates the path value distribution Observed eigenvalues, Indicates the number of The average value of the feature, Indicates the path distribution characteristics The actual distribution value of the item path, Indicates the number of historical attacks The distribution value of the item path, Indicates the The historical distribution variance of the item eigenvalue, represents the historical distribution variance of the path distribution value, Indicates the weight of the eigenvalue deviation on the matching degree, Indicates the weight of path distribution deviation on matching degree, represents a stable value that prevents the denominator from being zero, Represents the stable value of the variance of the path distribution.
[0161] The embodiment of the application first obtains multi-layer data packet characteristic mapping information by establishing a multi-layer mapping table according to field relationships based on a target network environment, by analyzing application layer parameters and combining transmission layer parameters; extracts the use of non-standard ports and data packets that do not conform to path specifications, and establishes an abnormal group by combining path values and port information, to generate a multi-layer abnormal behavior identification result; extracts abnormal data packet time interval distribution values and packet length statistical values, and dynamically adjusts the detection threshold range and path determination rules based on the normal distribution range of historical network behavior records, to obtain an adaptive detection threshold rule set based on the multi-layer abnormal behavior identification result; secondly, a graph model is constructed by taking a communication entity as a node and a path as an edge based on the adaptive detection threshold rule set, and the node-to-node communication connection number change value and abnormal path value growth rate in the edge set are analyzed to extract the node-to-node new connection number and edge set abnormal increment distribution value, to generate network abnormal event correlation information; finally, the network abnormal event correlation information is compared with the correlation characteristics of known attack event records based on the network abnormal event correlation information, and the node pair combination and path distribution that conform to the potential attack behavior characteristics are screened, to obtain a potential network attack detection result.
[0162] The embodiment of the application can comprehensively capture the source and characteristics of abnormal data packets by capturing data packets in the network in real time, layer-by-layer analysis and establishment of multi-layer mapping relationships; the screening of abnormal data packets is more accurate by combining time interval distribution value and packet length ratio analysis and deviation from historical record detection methods, and the threshold interval of detection can be dynamically adjusted to adapt to network environment changes; the high-frequency communication entity pair and potential attack path can be quickly located by constructing a graph structure model of the path and time distribution between communication entities and combining communication frequency and abnormal increment change analysis, to generate network abnormal event correlation information; the node pair combination and path distribution that conform to the potential attack characteristics can be accurately screened by comparing the path value with the attack event record, combining the path distribution characteristics and historical attack record correlation, so that the detection range of potential attacks is wider, the reaction speed is faster, and the targeting is stronger.
[0163] Figure 8 is a structural schematic diagram of a network attack detection device based on an event-driven architecture provided by the embodiment of the application, as Figure 8 shown, the network attack detection device based on the event-driven architecture can include the network attack detection system based on the event-driven architecture shown in Figure 7 above. Optionally, the network attack detection device based on the event-driven architecture 810 can include the first processor 2001.
[0164] Optionally, the network attack detection device based on the event-driven architecture 810 can further include the memory 2002 and the transceiver 2003.
[0165] The first processor 2001, the memory 2002 and the transceiver 2003 may be connected via a communication bus.
[0166] The following combination Figure 8 The components of the network attack detection device 810 based on the event-driven architecture are described in detail:
[0167] The first processor 2001 is the control center of the network attack detection device 810 based on the event-driven architecture, and can be a single processor or a collective term for multiple processing elements. For example, the first processor 2001 can be one or more central processing units (CPUs), or application-specific integrated circuits (ASICs), or one or more integrated circuits configured to implement embodiments of the present invention, such as one or more digital signal processors (DSPs) or one or more field programmable gate arrays (FPGAs).
[0168] Optionally, the first processor 2001 can perform various functions of the network attack detection device 810 based on the event-driven architecture by running or executing a software program stored in the memory 2002 and calling data stored in the memory 2002.
[0169] In a specific implementation, as an embodiment, the first processor 2001 may include one or more CPUs, such as Figure 8 CPU0 and CPU1 are shown in FIG.
[0170] In a specific implementation, as an embodiment, the network attack detection device 810 based on the event-driven architecture may also include multiple processors, such as Figure 8 1 and 2. The first processor 2001 and the second processor 2004 are shown in FIG. Each of these processors can be a single-core processor (single-CPU) or a multi-core processor (multi-CPU). A processor herein can refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).
[0171] The memory 2002 is used to store the software program for executing the solution of the present invention, and is controlled by the first processor 2001 for execution. The specific implementation method can refer to the above method embodiment and will not be repeated here.
[0172] Alternatively, the memory 2002 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, a random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, an optical disc storage (including a compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and capable of being accessed by a computer, but not limited thereto. The memory 2002 may be integrated with the first processor 2001 or may exist independently and accessed through the interface circuit ( Figure 8 (not shown) is coupled to the first processor 2001, which is not specifically limited in this embodiment of the present invention.
[0173] The transceiver 2003 is used to communicate with a network device or a terminal device.
[0174] Optionally, the transceiver 2003 may include a receiver and a transmitter ( Figure 8 The receiver is used to implement a receiving function, and the transmitter is used to implement a sending function.
[0175] Optionally, the transceiver 2003 may be integrated with the first processor 2001 or may exist independently and be connected to the network attack detection device 810 based on the event-driven architecture through an interface circuit ( Figure 8 (not shown) is coupled to the first processor 2001, which is not specifically limited in this embodiment of the present invention.
[0176] It should be noted that Figure 8 The structure of the network attack detection device 810 based on the event-driven architecture shown in the figure does not constitute a limitation on the router. The actual knowledge structure identification device may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0177] In addition, the technical effects of the network attack detection device 810 based on the event-driven architecture can refer to the technical effects of the network attack detection method based on the event-driven architecture described in the above method embodiment, and will not be repeated here.
[0178] It should be understood that the first processor 2001 in the embodiment of the present invention may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor, or the processor may be any conventional processor, etc.
[0179] It should also be understood that the memory in the embodiments of the present invention may be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory may be random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of random access memory (RAM) are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0180] The above embodiments can be implemented in whole or in part via software, hardware (e.g., circuits), firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product comprises one or more computer instructions or computer programs. When loaded or executed on a computer, the processes or functions described in accordance with the embodiments of the present invention are fully or partially performed. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable system. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired means (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium accessible by a computer or a data storage device such as a server or data center that contains a collection of one or more available media. The available medium can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.
[0181] It should be understood that the term "and / or" as used herein simply describes a relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A alone, A and B together, or B alone. A and B can be singular or plural. Furthermore, the character " / " as used herein generally indicates an "or" relationship between the associated objects, but it may also indicate an "and / or" relationship. For specific understanding, please refer to the context.
[0182] In this disclosure, "at least one" means one or more, and "plurality" means two or more. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, "at least one of a, b, or c" can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.
[0183] It should be understood that in various embodiments of the present invention, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0184] Those skilled in the art can clearly understand that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0185] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the devices, systems and units described above can refer to the corresponding processes in the foregoing method embodiments, which will not be repeated here.
[0186] In several embodiments provided by the present application, it should be understood that the disclosed devices, systems and methods can be implemented in other ways. For example, the system embodiments described above are merely schematic, for example, the division of the units is only a logical functional division, and actual implementation can have another division, for example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be through some interfaces, indirect coupling or communication connection between the systems or units, which can be electrical, mechanical or other forms.
[0187] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place or distributed on multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment.
[0188] In addition, each functional unit in each embodiment of the present application can be integrated into a processing unit, or each unit can exist physically independently, or two or more units can be integrated into one unit.
[0189] If the functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or the portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage media include various media that can store program code, such as USB flash drives, mobile hard drives, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical disks.
[0190] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present invention should be included in the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be based on the scope of protection of the claims.
Claims
1. A network attack detection method based on event-driven architecture, characterized in that: The method comprises: S1. Based on the target network environment, by parsing the application layer parameters, combining the transport layer parameters, and establishing a multi-layer mapping table according to the field relationship, the multi-layer data packet feature mapping information is obtained; The S1 is based on the target network environment, by parsing the application layer parameters, combining the transport layer parameters, and establishing a multi-layer mapping table according to the field relationship to obtain multi-layer data packet feature mapping information, including: S11. Based on the target network environment, capture data packets in the network in real time; extract timestamps from the data packets and sort them in chronological order to obtain sorted data packets; parse the field types and field value combinations of the application layer in the sorted data packets to obtain time-sequential data packet parsing results; S12. Extracting the transport protocol identifier and packet length information from the application layer data based on the time-sequential data packet parsing results; parsing the port information and packet flag bits from the transport layer data to obtain application layer and transport layer parsing information; S13. Based on the application layer and transport layer parsing information, parse the source address, destination address, and path value of the network layer to obtain a parsing result; based on the parsing result, establish a correspondence table between field values and path values to obtain multi-layer data packet feature mapping information; S2. Based on the multi-layer data packet feature mapping information, extract the usage of non-standard ports and data packets that do not conform to path specifications, combine the path value and port information to establish an abnormal group, and generate a multi-layer abnormal behavior recognition result; S3. Based on the multi-layer abnormal behavior identification results, extract the abnormal data packet time interval distribution value and packet length statistics, combine the normal distribution range of historical network behavior records, dynamically adjust the detection threshold range and path determination rules, and obtain an adaptive detection threshold rule set; S4. Based on the adaptive detection threshold rule set, a graph model is constructed with communication entities as nodes and paths as edges. The change value of the number of communication connections between nodes and the growth rate of abnormal path values in the edge set are analyzed. The number of new connections between nodes and the abnormal incremental distribution value of the edge set are extracted to generate network abnormal event correlation information. S5. Based on the network abnormal event correlation information, the path value distribution characteristics are compared with the correlation characteristics of known attack event records to screen node pair combinations and path distributions that meet the potential attack behavior characteristics to obtain potential network attack detection results.
2. The network attack detection method based on event-driven architecture according to claim 1 is characterized in that: The multi-layer data packet feature mapping information includes: a field type value table, a port usage record table, a path value correspondence table, and a time-sorted data packet list; The multi-layer abnormal behavior identification results include: abnormal path value set, abnormal port information list, time interval distribution group list and data packet length statistics table; The adaptive detection threshold rule set includes: a time increment variation range, a packet length ratio threshold, and a path determination rule parameter set; The network abnormal event association information includes: a communication entity node set, a path edge set, a communication abnormality increment distribution table, and a high-frequency abnormal communication node pair; The potential network attack detection result includes: a communication entity pair combination feature table, a path value distribution feature set, and an abnormal increment peak information table.
3. The network attack detection method based on event-driven architecture according to claim 1 is characterized in that: The S2 extracts the usage of non-standard ports and packets that do not conform to path specifications based on the multi-layer packet feature mapping information, combines the path value with the port information to establish an abnormal group, and generates a multi-layer abnormal behavior recognition result, including: S21. Based on the multi-layer packet feature mapping information, compare the path values and port records in the network interaction one by one, filter out abnormal data packets that do not match the standard port from the path values, and generate abnormal path value data; S22. Extracting time distribution and packet length information of abnormal data packets based on the abnormal path value data; grouping the extracted time distribution according to time intervals to obtain time interval distribution information; S23. Based on the time interval distribution information, calculate the difference value of the time interval in the group; combine the difference value with the data packet length, filter abnormal data, establish a path value set and port information list of abnormal combinations, and generate a multi-layer abnormal behavior recognition result.
4. The network attack detection method based on event-driven architecture according to claim 1 is characterized in that: The S3 extracts the time interval distribution value and packet length statistics of abnormal data packets based on the multi-layer abnormal behavior identification results, combines the normal distribution range of historical network behavior records, dynamically adjusts the detection threshold range and path determination rules, and obtains an adaptive detection threshold rule set, including: S31. Based on the multi-layer abnormal behavior identification results, extract the time interval distribution value and data packet length information of each path; arrange the time interval distribution values in time increment order to obtain a time increment sorting result; S32. Based on the time increment sorting result, calculate the range of the time increment change; perform a corresponding proportional calculation on the time increment change range and the packet length statistics to obtain a proportional relationship calculation result; S33. Based on the calculation result of the proportional relationship, determine whether the proportion deviates from the normal range in the historical records, adjust the detection threshold according to the degree of deviation, update the port range parameter in the path determination rule, and obtain an adaptive detection threshold rule set.
5. The network attack detection method based on event-driven architecture according to claim 4 is characterized in that: The process of adjusting the detection threshold is expressed by the following formula (1): (1) in, represents the updated detection threshold, represents the detection threshold before adjustment, Represents the ratio of the time increment change range to the packet length statistics in the current calculation. Represents the average ratio of the time increment change range to the packet length statistics in the historical records. represents the variance value of the historical proportion distribution, Indicates the weight coefficient of the impact of the adjustment ratio deviation on the threshold adjustment, It represents the adjustment parameter for adjusting the sensitivity of the path decision rule to the detection threshold. Indicates the stability factor for adjusting the noise influence range.
6. The network attack detection method based on event-driven architecture according to claim 1 is characterized in that: The S4 is based on the adaptive detection threshold rule set, uses communication entities as nodes and paths as edges to build a graph model, analyzes the change value of the number of communication connections between nodes and the growth rate of abnormal path values in the edge set, extracts the number of new connections between nodes and the abnormal incremental distribution value of the edge set, and generates network abnormal event correlation information, including: S41. Extracting path values and time distribution records of communication entities in network interactions based on an adaptive detection threshold rule set; establishing a graph structure model in which nodes are communication entities and edges are path relationships according to the path correspondence between the communication entities, thereby obtaining a network interaction graph model; S42. Based on the network interaction graph model, by analyzing the abnormal change values of the time interval in the path value, extracting the entity pairs whose communication frequency exceeds the threshold, calculating the number of abnormal communications and the corresponding abnormal path number for each entity, and generating abnormal communication statistics; S43. Based on the abnormal communication statistical results, the statistical results are arranged in chronological order, abnormal incremental changes in path values are extracted, and high-frequency communication entity pairs are screened in combination with the incremental change results to obtain network abnormal event correlation information.
7. The network attack detection method based on event-driven architecture according to claim 1 is characterized in that: The step S5 compares the path value distribution characteristics with the correlation characteristics of known attack event records based on the network abnormal event correlation information, screens node pair combinations and path distributions that meet the potential attack behavior characteristics, and obtains potential network attack detection results, including: S51. Based on the network abnormal event correlation information, extract high-frequency communication entity pair combinations from the graph; sort the path values in the high-frequency communication entity pairs according to the communication frequency to generate high-frequency communication path information; S52. Extracting path value distribution characteristics between pairs of communication entities based on high-frequency communication path information, and establishing a corresponding relationship table between path values and incremental peak values in combination with abnormal incremental distribution peak values of path values, thereby obtaining a corresponding relationship table between paths and peak values. S53. Based on the path-peak correspondence table, the path value distribution characteristics are compared with the associated characteristics of the attack event records one by one to evaluate the feature matching degree, and the node pair combinations and path distributions that meet the potential attack behavior characteristics are screened to generate potential network attack detection results.
8. The network attack detection method based on event-driven architecture according to claim 7 is characterized in that: The process of evaluating the feature matching degree is expressed by the following formula (2): (2) in, represents the feature matching score, Indicates the path value distribution Observed eigenvalues, Indicates the number of The average value of the feature, Indicates the path distribution characteristics The actual distribution value of the item path, Indicates the number of historical attacks The distribution value of the item path, Indicates the The historical distribution variance of the item eigenvalue, represents the historical distribution variance of the path distribution value, Indicates the weight of the eigenvalue deviation on the matching degree, Indicates the weight of path distribution deviation on matching degree, represents a stable value that prevents the denominator from being zero, Represents the stable value of the variance of the path distribution.
9. A network attack detection system based on an event-driven architecture, wherein the network attack detection system based on an event-driven architecture is used to implement the network attack detection method based on an event-driven architecture according to any one of claims 1 to 8, characterized in that: The system comprises: The data parsing unit is used to parse the application layer parameters based on the target network environment, combine the transport layer parameters, establish a multi-layer mapping table according to the field relationship, and obtain the multi-layer data packet feature mapping information; Based on the target network environment, by parsing the application layer parameters and combining them with the transport layer parameters, a multi-layer mapping table is established according to the field relationship to obtain multi-layer packet feature mapping information, including: S11. Based on the target network environment, capture data packets in the network in real time; extract timestamps from the data packets and sort them in chronological order to obtain sorted data packets; parse the field types and field value combinations of the application layer in the sorted data packets to obtain time-sequential data packet parsing results; S12. Extracting the transport protocol identifier and packet length information from the application layer data based on the time-sequential data packet parsing results; parsing the port information and packet flag bits from the transport layer data to obtain application layer and transport layer parsing information; S13. Based on the application layer and transport layer parsing information, parse the source address, destination address, and path value of the network layer to obtain a parsing result; based on the parsing result, establish a correspondence table between field values and path values to obtain multi-layer data packet feature mapping information; an abnormal behavior analysis unit, configured to extract, based on the multi-layer data packet feature mapping information, usage of non-standard ports and data packets that do not conform to path specifications, combine path values with port information to establish abnormal groups, and generate multi-layer abnormal behavior identification results; A detection threshold adjustment unit is configured to extract the time interval distribution value and packet length statistics of abnormal data packets based on the multi-layer abnormal behavior identification results, and dynamically adjust the detection threshold range and path determination rules in combination with the normal distribution range of historical network behavior records to obtain an adaptive detection threshold rule set; An abnormal event analysis unit is used to construct a graph model based on the adaptive detection threshold rule set, using communication entities as nodes and paths as edges, analyze the change value of the number of communication connections between nodes and the growth rate of abnormal path values in the edge set, extract the number of new connections between nodes and the abnormal incremental distribution value of the edge set, and generate network abnormal event correlation information; The attack detection unit is used to compare the path value distribution characteristics with the correlation characteristics of known attack event records based on the network abnormal event correlation information, screen the node pair combinations and path distributions that meet the potential attack behavior characteristics, and obtain potential network attack detection results.
Citation Information
Patent Citations
Abnormal flow detection system and abnormal flow detection method based on service model
CN108289088A
Method and system for collecting network security threat information
CN119743335A