Network attack detection method and related product thereof

By combining the unsupervised model and the score card model, using real-time domain name system traffic data for abnormal and risk assessment, the problems of high dependence and high detection cost for labeled black data in the existing technology are solved, and the low-cost rapid identification and accurate detection of DNS tunnels are achieved.

CN120223365APending Publication Date: 2025-06-27NANJING XIYIN ECOMMERCE CO LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510276265.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-07
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The prior art relies on supervised learning models when detecting DNS tunnel attacks, requires a large number of black data samples, and is costly. The model has weak interpretability to the decision-making process, making it difficult to quickly and effectively verify and trace the source.

Method used

Using a combination of unsupervised model and score card model, by obtaining real-time domain name system traffic data, inputting unsupervised model and score card model to obtain abnormal evaluation scores and risk evaluation scores, reducing dependence on labeled black data, and achieving low-cost and rapid identification of DNS tunnels.

Benefits of technology

It realizes low-cost and rapid identification when DNS tunnels appear, reduces false alarm rates and missed alarm rates, enhances detection accuracy and adaptability, and ensures the security of the network environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223365A_ABST
    Figure CN120223365A_ABST
Patent Text Reader

Abstract

The invention discloses a network attack detection method and a related product thereof. The method comprises the following steps: acquiring real-time domain name system flow data; inputting the real-time domain name system flow data into the unsupervised model and the score card model to obtain an abnormal assessment score output by the unsupervised model and a risk assessment score output by the score card model; wherein a score card model is constructed based on normal traffic sample data and abnormal traffic sample data; training based on normal traffic sample data to obtain an unsupervised model; determining a target judgment score based on the exception assessment score and the risk assessment score; and determining whether the domain name system tunnel exists based on the target judgment score and the abnormal judgment threshold. By using the technical scheme of the invention, strong dependence on annotated black data can be reduced, low-cost rapid identification is carried out when a DNS tunnel appears, timely and accurate detection of a network attack is realized, and the security of a network environment is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application generally relates to the field of Internet technologies. More specifically, this application relates to a network attack detection method and related products thereof. Background Art

[0002] Currently, the threat detection and defense of enterprise internal networks often rely on deep learning and supervised learning models. The models are trained by labeling known attack samples (black samples) to identify potential attacks. DNS (Domain Name System) tunneling is a type of attack that takes advantage of the flexibility and concealment of the DNS protocol to hide and transmit data in DNS query and response traffic. These tunneling tools, such as Dnscat2, Dns2tcp, Iodine, Dnstunnel, MSF, CobaltStrike, etc., can encapsulate any data as legitimate DNS requests and responses, thus bypassing traditional protection means. However, there are obvious deficiencies in using supervised learning models to detect rapidly evolving and continuously updated DNS tunneling attacks. First, supervised learning requires a large number of high-quality and accurately labeled black data samples, but the process of obtaining these black samples is complex and expensive, and network attackers continuously modify and distort known DNS tunneling tools. Second, the training and deployment of deep learning models require a large amount of computing power and resources, with too high costs. In addition, such models are relatively "black box", with weak interpretability of their decision-making processes, making it inconvenient for security analysts to quickly and effectively verify and trace the decision results.

[0003] In view of this, there is an urgent need to provide a network attack detection method that can reduce the strong dependence on labeled black data, quickly identify at low cost when DNS tunneling appears, achieve timely and accurate detection of network attacks, and ensure the security of the network environment. Summary of the Invention

[0004] To at least solve one or more of the above-mentioned technical problems, this application proposes a network attack detection method and related products thereof in multiple aspects. The network attack detection method can reduce the strong dependence on labeled black data, quickly identify at low cost when DNS tunneling appears, achieve timely and accurate detection of network attacks, and ensure the security of the network environment.

[0005] In a first aspect, the present application provides a network attack detection method, including: obtaining real-time Domain Name System (DNS) traffic data; respectively inputting the real-time DNS traffic data into an unsupervised model and a scoring card model to obtain an anomaly evaluation score output by the unsupervised model and a risk evaluation score output by the scoring card model; wherein, the scoring card model is constructed based on normal traffic sample data and abnormal traffic sample data; the unsupervised model is trained based on the normal traffic sample data; a target judgment score is determined based on the anomaly evaluation score and the risk evaluation score; and it is determined whether there is a DNS tunnel based on the target judgment score and an anomaly judgment threshold.

[0006] In some embodiments, constructing the scoring card model based on normal traffic sample data and abnormal traffic sample data includes: obtaining normal traffic sample data and abnormal traffic sample data; determining an original detection feature type set and constructing a derivative detection feature type set based on the original detection type feature set; performing data type screening on the normal traffic sample data and the abnormal traffic sample data based on the original detection feature type set and the derivative detection feature type set to obtain normal traffic training data and abnormal traffic training data; inputting the normal traffic training data and the abnormal traffic training data into an initial logistic regression model for training, and obtaining a target logistic regression model after the training is completed; constructing a scoring card format based on the continuous feature values, label values, and regression coefficients output by the target logistic regression model to obtain the scoring card model.

[0007] In some embodiments, constructing the scoring card format based on the continuous feature values, label values, and regression coefficients output by the target logistic regression model includes: performing feature bucketing on the continuous feature values, and determining the black-and-white data ratio corresponding to each feature bucket based on the label values; determining the attack log odds corresponding to each continuous feature based on the black-and-white data ratio corresponding to each feature bucket and the regression coefficients; determining the attack probability change coefficient corresponding to each continuous feature based on the attack log odds corresponding to each continuous feature, and determining the Factor parameter corresponding to each continuous feature based on a preset additional score and the attack probability change coefficient corresponding to each continuous feature; determining the feature score corresponding to the continuous feature value based on the continuous feature value, the Factor parameter corresponding to each continuous feature, and the regression coefficients, and determining the risk evaluation score based on a preset reference score and the feature score corresponding to each continuous feature value.

[0008] In some embodiments, training the unsupervised model based on the normal traffic sample data includes: inputting the normal traffic sample data into an isolation forest model for training to obtain the unsupervised model.

[0009] In some embodiments, determining a target judgment score based on an anomaly evaluation score and a risk evaluation score includes: extracting normal traffic verification data and abnormal traffic verification data from normal traffic sample data and abnormal traffic sample data respectively; determining an anomaly evaluation weight corresponding to the anomaly evaluation score and a risk evaluation weight corresponding to the risk evaluation score based on the normal traffic verification data and the abnormal traffic verification data; and determining the target judgment score based on the anomaly evaluation score, the risk evaluation score, the anomaly evaluation weight corresponding to the anomaly evaluation score, and the risk evaluation weight corresponding to the risk evaluation score.

[0010] In some embodiments, determining a target judgment score based on the anomaly evaluation score, the risk evaluation score, the anomaly evaluation weight corresponding to the anomaly evaluation score, and the risk evaluation weight corresponding to the risk evaluation score includes: determining the risk direction of the risk evaluation score based on the detection feature combination of real-time Domain Name System (DNS) traffic data; converting the risk evaluation score into a risk parameter value based on the risk direction; and determining the target judgment score based on the anomaly evaluation score, the risk parameter value, the anomaly evaluation weight corresponding to the anomaly evaluation score, and the risk evaluation weight corresponding to the risk evaluation score.

[0011] In some embodiments, determining whether there is a DNS tunnel based on the target judgment score and an anomaly judgment threshold includes: determining the anomaly judgment threshold based on the normal traffic verification data, the abnormal traffic verification data, a scoring card model, and an unsupervised model; comparing the target judgment score with the anomaly judgment threshold, and determining whether there is a DNS tunnel according to the comparison result.

[0012] In some embodiments, determining whether there is a DNS tunnel according to the comparison result includes: if the target judgment score is greater than the anomaly judgment threshold, determining that there is a DNS tunnel; if the target judgment score is less than or equal to the anomaly judgment threshold, determining that there is no DNS tunnel.

[0013] In a second aspect, the present application provides a device for network attack detection, including: a memory; and at least one processor configured to: obtain real-time DNS traffic data; input the real-time DNS traffic data into an unsupervised model and a scoring card model respectively to obtain an anomaly evaluation score output by the unsupervised model and a risk evaluation score output by the scoring card model; wherein, the scoring card model is constructed based on normal traffic sample data and abnormal traffic sample data; the unsupervised model is trained based on the normal traffic sample data; the target judgment score is determined based on the anomaly evaluation score and the risk evaluation score; and it is determined whether there is a DNS tunnel based on the target judgment score and the anomaly judgment threshold.

[0014] In a third aspect, the present application provides a non-transitory machine-readable medium having program code for network attack detection stored thereon. When the program code is executed by at least one processor, the code guides the execution operations of the at least one processor. The program code includes: obtaining real-time Domain Name System (DNS) traffic data; respectively inputting the real-time DNS traffic data into an unsupervised model and a scoring card model to obtain an anomaly evaluation score output by the unsupervised model and a risk evaluation score output by the scoring card model; wherein, the scoring card model is constructed based on normal traffic sample data and abnormal traffic sample data; the unsupervised model is trained based on normal traffic sample data; determining a target judgment score based on the anomaly evaluation score and the risk evaluation score; and determining whether there is a DNS tunnel based on the target judgment score and an anomaly judgment threshold.

[0015] The technical solutions provided by the present application may include the following beneficial effects:

[0016] The network attack detection method and related products provided by the present application obtain real-time DNS traffic data, and then respectively input the real-time DNS traffic data into an unsupervised model and a scoring card model to obtain an anomaly evaluation score output by the unsupervised model and a risk evaluation score output by the scoring card model. Among them, the scoring card model is a model constructed based on normal traffic sample data and abnormal traffic sample data, so that the scoring card model has the ability to output the characteristic score values corresponding to each feature affecting the occurrence of the DNS tunnel, and can output a risk evaluation score based on the characteristic score values corresponding to each feature. The unsupervised model is a model trained based on normal traffic sample data, so that the unsupervised model has the ability to identify traffic that does not conform to the normal access pattern and capture unknown DNS tunnels without relying on labeled black data, and output an anomaly evaluation score according to the degree of anomaly.

[0017] Furthermore, the present application can determine a target judgment score based on the anomaly evaluation score and the risk evaluation score, and then make a comprehensive judgment based on the target judgment score and the anomaly judgment threshold to determine whether there is a DNS tunnel, which is beneficial to reducing the false alarm rate and the missed alarm rate, and enhancing the accuracy and adaptability of the overall detection.

[0018] Generally speaking, the present application can reduce the strong dependence on labeled black data, quickly identify at low cost when a DNS tunnel appears, realize timely and accurate detection of network attacks, and ensure the security of the network environment. Brief Description of the Drawings

[0019] By reading the following detailed description with reference to the accompanying drawings, the above and other objects, features, and advantages of the exemplary embodiments of the present application will become readily understandable. In the drawings, several embodiments of the present application are shown in an exemplary rather than restrictive manner, and the same or corresponding reference numerals represent the same or corresponding parts, where:

[0020] Figure 1 An exemplary flowchart of a network attack detection method according to some embodiments of the present application is shown;

[0021] Figure 2 An exemplary flowchart of a network attack detection method according to other embodiments of the present application is shown;

[0022] Figure 3 An exemplary flowchart of a network attack detection method according to still other embodiments of the present application is shown;

[0023] Figure 4 A block diagram of the hardware configuration of a device 400 for network attack detection that can implement the network attack detection method according to the embodiments of the present application is shown. Detailed implementation manners

[0024] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. For the sake of simplicity and clarity of illustration, where appropriate, the same reference numerals may be repeated in the drawings to indicate corresponding or similar elements. Additionally, the present application sets forth many specific details in order to provide a thorough understanding of the embodiments described herein. However, those of ordinary skill in the art will understand that the embodiments described herein may be practiced without these specific details. In other instances, well-known methods, procedures, and components have not been described in detail so as not to obscure the embodiments described herein. Moreover, this description should not be regarded as limiting the scope of the embodiments described herein. All other embodiments obtained by those skilled in the art based on the embodiments of the present application without creative efforts shall fall within the scope of protection of the present application.

[0025] It should be understood that the possible terms "first" or "second", etc. in the claims, the description, and the drawings disclosed in the present application are used to distinguish different objects, rather than to describe a specific order. The terms "including" and "comprising" used in the description and claims of the present application indicate the presence of the described features, wholes, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.

[0026] It should also be understood that the terms used in the specification of this application are merely for the purpose of describing specific embodiments and are not intended to limit this application. As used in the specification and claims of this application, unless the context clearly indicates otherwise, the singular forms "a", "an" and "the" are intended to include the plural forms. It should further be understood that the term "and / or" used in the specification and claims of this application refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0027] As used in this specification and the claims, the term "if" may be interpreted as "when" or "once" or "in response to determining" or "in response to detecting" depending on the context. Similarly, the phrase "if determined" or "if [the described condition or event] is detected" may be interpreted as meaning "once determined" or "in response to determining" or "once [the described condition or event] is detected" or "in response to detecting [the described condition or event]" depending on the context.

[0028] DNS (Domain Name System) tunneling is a type of attack method that utilizes the flexibility and concealment of the DNS protocol to hide and transmit data in DNS query and response traffic. These tunneling tools such as Dnscat2, Dns2tcp, Iodine, Dnstunnel, MSF, CobaltStrike, etc. can encapsulate arbitrary data as legitimate DNS requests and responses, thereby bypassing traditional protection means. However, there are obvious deficiencies in using supervised learning models to detect rapidly evolving and continuously updated DNS tunneling attacks. In view of this, there is an urgent need to provide a network attack detection method that can reduce the strong dependence on labeled black data, quickly identify at low cost when DNS tunneling appears, achieve timely and accurate detection of network attacks, and ensure the security of the network environment.

[0029] The following will describe in detail the specific embodiments of this application with reference to the accompanying drawings.

[0030] Figure 1 An exemplary flowchart of the network attack detection method according to some embodiments of this application is shown. Please refer to Figure 1 The network attack detection method shown in the embodiments of this application may include:

[0031] In step S101, real-time Domain Name System (DNS) traffic data is obtained. The aforementioned real-time DNS traffic data refers to real-time DNS (Domain Name System) traffic data. DNS traffic data refers to data packets related to domain name resolution transmitted in the network, including DNS query requests, DNS responses, and related metadata (such as query timestamps, query types, response status codes, and time to live, etc.). In the embodiments of the present application, preprocessing can be performed on the real-time DNS traffic data. For example, communication records regarding responses and query requests can be filtered out, and query records related to the appearance of DNS tunnels can be filtered out, etc.; also, for example, analysis can be performed on non-conventional top-level domains (TLDs) in the real-time DNS traffic data. Specifically, non-conventional domain names can be filtered out through predefined rules (such as specific suffixes, domain name lengths, TTL value ranges) to avoid triggering a large number of NXDOMAIN (domain name does not exist) responses; special processing (such as Base32, Base64 encoding detection) can also be performed on encrypted and deformed domain names. It can be understood that the methods for real-time DNS traffic data are diverse. In actual applications, the actual operations for preprocessing the real-time DNS traffic data need to be determined according to the actual application scenarios. The present application does not impose any restrictions in this regard.

[0032] In step S102, the real-time DNS traffic data is respectively input into an unsupervised model and a scoring card model, and an anomaly evaluation score output by the unsupervised model and a risk evaluation score output by the scoring card model are obtained. In the embodiments of the present application, a scoring card model can be constructed based on normal traffic sample data and abnormal traffic sample data, and an unsupervised model can be trained based on normal traffic sample data, effectively reducing the dependence on marked black data and reducing the data collection cost. Among them, normal traffic sample data (i.e., white data, normal and legal DNS traffic data) can be collected from the network monitoring systems of normally operating enterprise office networks (such as NetFlow, DNS server logs, or passive DNS monitoring tools) to ensure that the obtained data can cover various business accesses in normal office scenarios. In addition, to improve representativeness, the collection period of normal traffic sample data can be no less than one week to include access patterns at different times during weekdays and weekends, and abnormal daily data that may exist can be excluded.

[0033] In addition, several known DNS tunneling tools, such as Dnscat2, Dns2tcp, Iodine, Dnstunnel, MSF, and CobaltStrike, etc., can be deployed in an isolated test environment. In a controlled environment, simulate DNS tunnel communication to the target server through the aforementioned DNS tunneling tools (such as regularly transmitting encrypted data through DNS requests), and record their request and response characteristics. Furthermore, capture the DNS traffic within the test environment. It can be understood that at this time, all DNS traffic data initiated through the specified tunneling tool is black data. Further, traffic data with different DNS tunneling tools, different encoding methods (Base32, Base64, etc.), different traffic rates, and deformation rules can be collected respectively to obtain as diverse black data samples as possible, which is beneficial to improving the generalization ability of the unsupervised model, so as to obtain abnormal traffic sample data including various attributes such as the requested domain name, resource record type, request and response packet sizes, request timestamp, frequency statistics of requests and responses, domain name length, domain name character distribution (such as information entropy), etc.

[0034] After collecting the normal traffic sample data and abnormal traffic sample data, data cleaning operations can be performed on the aforementioned data, including outlier processing (such as removing extremely abnormal request frequency or length data), duplicate data deduplication, data type unification, and format standardization to ensure the quality and consistency of the data.

[0035] In step S103, determine the target judgment score based on the anomaly evaluation score and the risk evaluation score. In the embodiments of the present application, it is necessary to combine the anomaly evaluation score output by the unsupervised model and the risk evaluation score output by the scoring card model for fusion judgment. Among them, the aforementioned anomaly evaluation score reflects the degree of anomaly of the real-time domain name system traffic data relative to the normal baseline; the risk evaluation score is the cumulative sum of the characteristic score values corresponding to each feature related to the occurrence of the domain name system tunnel (DNS tunnel) in the real-time domain name system traffic data, reflecting the degree of risk of receiving a DNS tunnel attack.

[0036] In step S104, it is determined whether there is a Domain Name System (DNS) tunnel based on the target judgment score and the abnormal judgment threshold. In the embodiments of the present application, the aforementioned abnormal judgment threshold can be dynamically adjusted in empirical studies. For example, data can be extracted from normal traffic sample data and abnormal traffic sample data to form a verification data set, and the True Positive Rate (TPR, which represents the proportion of all actually positive (abnormal) samples that are correctly predicted as positive), False Positive Rate (FPR, which represents the proportion of all actually negative (normal) samples that are wrongly predicted as positive), and Precision-Recall (which can be used to draw a PR curve) of the abnormal evaluation score output by the unsupervised model and the risk evaluation score output by the scoring card model are monitored under different threshold values, so as to realize the dynamic optimization and adjustment of the abnormal judgment threshold.

[0037] In the embodiments of the present application, by obtaining real-time DNS traffic data, the real-time DNS traffic data is respectively input into an unsupervised model and a scoring card model, and an abnormal evaluation score output by the unsupervised model and a risk evaluation score output by the scoring card model are obtained. Among them, the scoring card model is a model constructed based on normal traffic sample data and abnormal traffic sample data, so that the scoring card model has the ability to output the characteristic score values corresponding to each feature affecting the occurrence of DNS tunnels and can output a risk evaluation score based on the characteristic score values corresponding to each feature. The unsupervised model is a model trained based on normal traffic sample data, so that the unsupervised model has the ability to identify traffic that does not conform to the normal access pattern and capture unknown DNS tunnels without relying on labeled black data, and output an abnormal evaluation score according to the degree of abnormality. Further, the present application can determine a target judgment score based on the abnormal evaluation score and the risk evaluation score, and then make a comprehensive judgment based on the target judgment score and the abnormal judgment threshold to determine whether there is a DNS tunnel, which is beneficial to reducing the false alarm rate and the missed alarm rate and enhancing the accuracy and adaptability of the overall detection.

[0038] Generally speaking, the present application can reduce the strong dependence on labeled black data, quickly identify at low cost when a DNS tunnel appears, realize the timely and accurate detection of network attacks, and ensure the security of the network environment.

[0039] In some embodiments, the construction process of the scoring card model and the training process of the unsupervised model can be further designed. The following will be combined with Figure 2 to elaborate in detail on the construction process of the scoring card model and the training process of the unsupervised model. Figure 2 An exemplary flowchart of a network attack detection method according to other embodiments of the present application is shown. Please refer to Figure 2, the network attack detection method shown in the embodiments of the present application may include:

[0040] In step S201, normal traffic sample data and abnormal traffic sample data are obtained. In the embodiments of the present application, the normal traffic sample data (i.e., white data, normal and legal DNS traffic data) can be collected from the network monitoring systems of normal operating enterprise office networks (such as NetFlow, DNS server logs, or passive DNS monitoring tools). The collection period can be no less than one week to include access patterns at different times during weekdays and weekends, and abnormal daily data that may exist is excluded.

[0041] In addition, several known DNS tunneling tools, such as Dnscat2, Dns2tcp, Iodine, Dnstunnel, MSF, and CobaltStrike, etc., can be deployed in an isolated test environment. In a controlled environment, the DNS tunneling tools are used to simulate DNS tunnel communication to the target server (such as regularly transmitting encrypted data through DNS requests), and their request and response characteristics are recorded. Furthermore, the DNS traffic in the test environment can be captured. It can be understood that all DNS traffic data initiated through the specified tunneling tool at this time is black data. Further, traffic data with different DNS tunneling tools, different encoding methods (Base32, Base64, etc.), different traffic rates, and deformation rules can be collected respectively to obtain as diverse black data samples as possible, which is beneficial to improving the generalization ability of the unsupervised model, so as to obtain abnormal traffic sample data including various attributes such as the requested domain name, resource record type, request and response packet sizes, request timestamp, frequency statistics of requests and responses, domain name length, and domain name character distribution (such as information entropy).

[0042] After collecting the normal traffic sample data and abnormal traffic sample data, data cleaning operations can be performed on the foregoing data, including outlier processing (such as removing extremely abnormal request frequency or length data), duplicate data deduplication, data type unification, and format standardization to ensure the quality and consistency of the data.

[0043] In step S202, an original detection feature type set is determined and a derivative detection type feature set is constructed based on the original detection type feature set. In the embodiments of the present application, the key feature types most influential for DNS tunnel detection can be selected according to the characteristics of DNS access behavior and statistical analysis (such as correlation analysis, variance analysis, etc.) to form the original detection feature type set. Among them, the original detection feature type set may include, but is not limited to, domain name length, request frequency (such as the number of requests per unit time), character set complexity and information entropy in the domain name, DNS request type statistical distribution, response code distribution, top-level domain (TLD) type, etc. Further, in the embodiments of the present application, more predictive derivative features may also be constructed on the basis of the original detection feature type set to form a derivative detection type feature set. Among them, the derivative detection type feature set may include, but is not limited to, time window aggregation features (i.e., counting the number of requests, failure rate, average entropy, etc. within a fixed time window), frequency change rate features (i.e., comparing the change rate of statistical quantities between the current time window and the previous time window), and domain name structure features (i.e., analyzing the number of domain name levels, the length distribution of each level, and suspicious character patterns in sub-domains such as mixed coding features). The aforementioned derivative detection type feature set can better characterize the behavior pattern of DNS traffic.

[0044] In the embodiments of the present application, logarithmic transformation, standardization, or normalization can be performed on each feature in the above original detection feature type set and derivative detection type feature set to reduce the bias caused by the dimensional difference between features, which is beneficial to improving the stability and convergence of model training.

[0045] In step S203, data type screening is performed on the normal traffic sample data and abnormal traffic sample data based on the original detection feature type set and derivative detection type feature set to obtain normal traffic training data and abnormal traffic training data. Data matching the feature types in the original detection feature type set and derivative detection type feature set is screened out from the normal traffic sample data and abnormal traffic sample data to form the normal traffic training data and abnormal traffic training data.

[0046] In step S204, the normal traffic training data and the abnormal traffic training data are input into the initial logistic regression model for training, and after the training is completed, the target logistic regression model is obtained. In the embodiments of the present application, the logistic regression model can be trained by using the maximum log-likelihood method, and the initial parameters can be randomly initialized or zero-initialized (i.e., all parameters are initialized to 0). Then, through gradient descent, such as using Adam (Adaptive Moment Estimation) or L-BFGS (Limited-memory Broyden-Fletcher-Goldfarb-Shanno) to iteratively optimize the parameters, so that the deviation between the output of the Logistic function (also known as the Sigmoid function, which is a non-linear function widely used in logistic regression and other machine learning models) and the data label (for example, the normal data label is 0 and the abnormal data label is 1) is minimized. After the training is completed, the target logistic regression model can be obtained.

[0047] In step S205, a scoring card format is constructed based on the continuous eigenvalue, label value, and regression coefficient output by the target logistic regression model to obtain a scoring card model. In the embodiments of the present application, the continuous eigenvalue can be first subjected to feature bucketing, that is, the continuous eigenvalue is divided into multiple intervals. For example, the continuous eigenvalue of the domain name length can be divided into intervals such as [0-10], [11-20], [21-30], etc. In practical applications, the optimal combination of segmentation points that makes the KS value (Kolmogorov-Smirnov) and Gini coefficient (or AUC) of the model optimal can be selected by grid search or iterative attempts of different bucketing numbers and boundary points. The discrete eigenvalue can be grouped according to the feature category, but generally no scoring is performed. Then, based on the label value (for example, the normal data label is 0 and the abnormal data label is 1), the black-and-white data ratio corresponding to each feature bucket is determined. The WOE (Weight of Evidence) index can be used to evaluate each bucket of each feature, and the monotonicity and good WOE distribution should be satisfied after bucketing.

[0048] Then, the attack log-odds corresponding to each continuous feature can be determined based on the black-and-white data ratio and regression coefficient corresponding to each feature bucket, and can be calculated through the following formula 1 and formula 2:

[0049]

[0050] where, w i is the proportion of the normal traffic training data quantity in the i-th bucket to the total normal traffic training data quantity, bi is the proportion of the abnormal traffic training data quantity in the i-th bucket to the total abnormal traffic training data quantity, and WOE iIt is the WOE index value corresponding to the i-th bin. In addition, p is the attack probability corresponding to the continuous feature, is the attack log-odds corresponding to the continuous feature, β0 is the intercept of the logistic regression, and β i is the regression coefficient of the logistic regression, and n is the number of bins.

[0051] Next, the attack probability change coefficient corresponding to each continuous feature can be determined based on the attack log-odds corresponding to each continuous feature, and the Factor parameter corresponding to each continuous feature can be determined based on the preset additional score and the attack probability change coefficient corresponding to each continuous feature. Among them, the change multiple of the attack probability p can be determined based on the attack log-odds corresponding to each continuous feature, and the preset additional score is the score that needs to be added whenever the attack probability p increases or decreases by k times. The calculation of the Factor parameter can be carried out through the following formula three:

[0052]

[0053] where Factor is the Factor parameter, PDO is the preset additional score, and k is the attack probability change coefficient.

[0054] Furthermore, the feature score corresponding to the continuous feature value can be determined based on the continuous feature value, the Factor parameter corresponding to each continuous feature, and the regression coefficient. The feature score corresponding to the continuous feature value can be determined through the following formula four:

[0055] Score = -Factor·β i ·X (Formula Four)

[0056] where Score is the feature score corresponding to the continuous feature value, and X is the continuous feature value.

[0057] Furthermore, the risk assessment score can be determined based on the preset reference score and the feature score corresponding to each continuous feature value. The preset base score can be determined based on the Factor parameter, the intercept β0 of the logistic regression, and the Offset parameter. Specifically, the calculation of the Offset parameter is based on the following assumption: when the default probability is p, the score is B. Then, according to the aforementioned assumption, the Offset parameter can be expressed by Formula Five:

[0058] Offset = B + Factor·ln(p) (Formula Five)

[0059] Then the preset reference score can be determined through the following formula six:

[0060] Basescore = Offset - Factor·β0 (Formula Six)

[0061] Among them, Basescore is a preset reference score.

[0062] Then the risk assessment score can be calculated by the following formula (7):

[0063]

[0064] Among them, T Score is the risk assessment score, m is the number of continuous feature values, and Score j is the feature score corresponding to the j-th continuous feature value. Doing so facilitates security analysts to analyze each feature, can intuitively understand the reasons for model decisions, and accordingly quickly optimize and respond to detection strategies, improving the interpretability of the decision-making process and facilitating security analysts to quickly and effectively verify and trace the decision results.

[0065] In step S206, the normal traffic sample data is input into the isolation forest model for training to obtain an unsupervised model. In the embodiments of the present application, the unsupervised model can adopt the isolation forest model, and then use the normal traffic sample data to train the unsupervised model, thereby establishing a baseline for normal access. Specifically, the basic parameters of the isolation forest can be set, such as the number of trees (n_estimators = 100), the size of the subsample (such as 256), and the anomaly score threshold (by default, determined by the model itself). The isolation forest training mainly isolates samples by constructing multiple random trees. Usually, a stable result can be obtained by default with n_estimators = 100 - 200. For higher accuracy, n_estimators can be appropriately increased or the model can be trained multiple times to compare the results. Thus, after multiple trainings, the model parameter settings that can stably generate the desired false alarm rate are selected, so as to determine samples deviating from the normal distribution as anomalies, thereby achieving the purpose of identifying traffic that does not conform to the normal access pattern and capturing unknown Domain Name System tunnels.

[0066] In some embodiments, the anomaly assessment score and the risk assessment score can be weighted and fused, and a comprehensive judgment can be made based on the target judgment score obtained after weighted fusion to determine whether there is a Domain Name System tunnel. The following will be combined with Figure 3 to elaborate in detail on the judgment process of whether there is a Domain Name System tunnel. Figure 3 shows an exemplary flowchart of the network attack detection method according to still some other embodiments of the present application. Please refer to Figure 3 , the network attack detection method shown in the embodiments of the present application may include:

[0067] In step S301, normal traffic verification data and abnormal traffic verification data are respectively extracted from the normal traffic sample data and the abnormal traffic sample data. In the embodiment of the present application, data can be randomly selected from the normal traffic sample data and the abnormal traffic sample data to constitute the normal traffic verification data and the abnormal traffic verification data.

[0068] In step S302, based on the normal traffic verification data and the abnormal traffic verification data, the abnormal evaluation weight corresponding to the abnormal evaluation score and the risk evaluation weight corresponding to the risk evaluation score are determined. In the embodiment of the present application, through grid search or optimization algorithm, based on the normal traffic verification data and the abnormal traffic verification data, the abnormal evaluation weight corresponding to the abnormal evaluation score and the risk evaluation weight corresponding to the risk evaluation score are searched to ensure that the searched weights are stable in various scenarios.

[0069] In step S303, based on the abnormal evaluation score, the risk evaluation score, the abnormal evaluation weight corresponding to the abnormal evaluation score, and the risk evaluation weight corresponding to the risk evaluation score, a target judgment score is determined. In the embodiment of the present application, first, the risk direction of the risk evaluation score can be determined based on the detection feature combination of the real-time domain name system traffic data, that is, whether the higher the risk evaluation score indicates the higher the risk or the higher the risk evaluation score indicates the lower the risk. Furthermore, the risk evaluation score can be converted into a risk parameter value based on the risk direction.

[0070] When the higher the risk evaluation score indicates the higher the risk, the risk parameter value can be expressed by formula eight:

[0071] E = MaxScore - T Score (Formula eight)

[0072] When the higher the risk evaluation score indicates the lower the risk, the risk parameter value can be expressed by formula nine:

[0073]

[0074] Among them, E is the risk parameter value, and MaxScore is the highest score output by the scoring card model after inputting all the normal traffic verification data and the abnormal traffic verification data into the scoring card model.

[0075] Finally, based on the abnormal evaluation score, the risk parameter value, the abnormal evaluation weight corresponding to the abnormal evaluation score, and the risk evaluation weight corresponding to the risk evaluation score, the target judgment score is determined. Among them, the target judgment score can be calculated by the following formula ten:

[0076] F Score = w1·Y Score + w2·E (Formula ten)

[0077] Among them, FScore is the target judgment score, w1 is the anomaly evaluation weight corresponding to the anomaly evaluation score, and Y Score is the anomaly evaluation score, whose range is [0, 1], 1 indicates the most abnormal, and w2 is the risk evaluation weight corresponding to the risk evaluation score.

[0078] In step S304, an anomaly judgment threshold is determined based on the normal traffic verification data, abnormal traffic verification data, scoring card model, and unsupervised model. In the embodiments of the present application, the normal traffic verification data and abnormal traffic verification data can be input into the unsupervised model and scoring card model to monitor the TPR (True Positive Rate, indicating the proportion of all actually positive (abnormal) samples that are correctly predicted as positive), FPR (False Positive Rate, indicating the proportion of all actually negative (normal) samples that are wrongly predicted as positive), and Precision-Recall (Precision-Recall, which can be used to draw the PR curve) when the anomaly evaluation score output by the unsupervised model and the risk evaluation score output by the scoring card model take different threshold values, and then calculate the F1-score or G-Mean respectively. Among them, the F1-score is the harmonic mean of Precision and Recall, and the G-Mean is the geometric mean of TPR (True Positive Rate) and TNR (True Negative Rate), and TNR = 1 - FPR. Then, the threshold value when the F1-score or G-Mean has the optimal value is used as the anomaly judgment threshold.

[0079] In step S305, the target judgment score is compared with the anomaly judgment threshold, and it is determined whether there is a Domain Name System tunnel according to the comparison result. In the embodiments of the present application, if the target judgment score is greater than the anomaly judgment threshold (for example, 0.5), it is determined that there is a Domain Name System tunnel; if the target judgment score is less than or equal to the anomaly judgment threshold, it is determined that there is no Domain Name System tunnel.

[0080] Corresponding to the foregoing method embodiments for implementing application functions, the present application also provides a device for network attack detection and corresponding embodiments.

[0081] Figure 4 A block diagram showing the hardware configuration of a device 400 for network attack detection that can implement the network attack detection method of the embodiments of the present application. As Figure 4 shown, the device 400 for network attack detection may include a processor 410 and a memory 420. In Figure 4 the device 400 for network attack detection, only the constituent elements related to this embodiment are shown. Therefore, it is obvious to those of ordinary skill in the art that: the device 400 for network attack detection may further includeFigure 4 Common constituent elements with different constituent elements as shown. For example: fixed-point arithmetic unit.

[0082] The device 400 for network attack detection can correspond to a computing device with various processing functions. For example, functions for generating a neural network, training or learning a neural network, quantizing a floating-point neural network into a fixed-point neural network, or retraining a neural network. For example, the device 400 for network attack detection can be implemented as various types of devices, such as a personal computer (PC), a server device, a mobile device, etc.

[0083] The processor 410 controls all functions of the device 400 for network attack detection. For example, the processor 410 controls all functions of the device 400 for network attack detection by executing a program stored in the memory 420 on the device 400 for network attack detection. The processor 410 can be implemented by a central processing unit (CPU), a graphics processing unit (GPU), an application processor (AP), an artificial intelligence processor chip (IPU), etc. provided in the device 400 for network attack detection. However, this application is not limited thereto.

[0084] In some embodiments, the processor 410 may include an input / output (I / O) unit 411 and a computing unit 412. The I / O unit 411 can be used to receive various data, such as real-time Domain Name System traffic data. Exemplarily, the computing unit 412 can be used to input the real-time Domain Name System traffic data obtained by the I / O unit 411 into an unsupervised model and a scoring card model respectively, obtain an anomaly evaluation score output by the unsupervised model and a risk evaluation score output by the scoring card model; determine a target judgment score based on the anomaly evaluation score and the risk evaluation score; determine whether there is a Domain Name System tunnel based on the target judgment score and an anomaly judgment threshold. The result of whether there is a Domain Name System tunnel can be output by the I / O unit 411, for example. The output data can be provided to the memory 420 for other devices (not shown) to read and use, or can be directly provided to other devices for use.

[0085] The memory 420 is hardware for storing various data processed in the device 400 for network attack detection. For example, the memory 420 can store processed data and data to be processed in the device 400 for network attack detection. The memory 420 can store data sets involved in the process of network attack detection methods that have been processed or are to be processed by the processor 410, such as real-time Domain Name System traffic data, etc. In addition, the memory 420 can store applications, drivers, etc. to be driven by the device 400 for network attack detection. For example, the memory 420 can store various programs related to the network attack detection method to be executed by the processor 410. The memory 420 can be DRAM, but the present application is not limited thereto. The memory 420 can include at least one of volatile memory or non-volatile memory. The non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory, phase change RAM (PRAM), magnetic RAM (MRAM), resistive RAM (RRAM), ferroelectric RAM (FRAM), etc. The volatile memory can include dynamic RAM (DRAM), static RAM (SRAM), synchronous DRAM (SDRAM), PRAM, MRAM, RRAM, ferroelectric RAM (FeRAM), etc. In an embodiment, the memory 420 can include at least one of a hard disk drive (HDD), a solid state drive (SSD), a high density flash (CF) card, a secure digital (SD) card, a micro secure digital (Micro-SD) card, a mini secure digital (Mini-SD) card, an extreme digital (xD) card, caches, or a memory stick.

[0086] In summary, the specific functions implemented by the memory 420 and the processor 410 of the device 400 for network attack detection provided in the embodiments of this specification can be explained in contrast to the foregoing embodiments in this specification, and can achieve the technical effects of the foregoing embodiments, which will not be elaborated here.

[0087] In this embodiment, the processor 410 can be implemented in any suitable manner. For example, the processor 410 can take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller, and a form embedded microcontroller, etc.

[0088] It should also be understood that any module, unit, component, server, computer, terminal, or device that executes instructions exemplified herein may include or otherwise access a computer-readable medium, such as a storage medium, a computer storage medium, or a data storage device (removable) and / or non-removable), such as a magnetic disk, an optical disk, or a magnetic tape. The computer storage medium may include volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data.

[0089] The foregoing may be better understood in accordance with the following clauses:

[0090] Clause A1. A method for detecting network attacks, which includes: obtaining real-time Domain Name System (DNS) traffic data; respectively inputting the real-time DNS traffic data into an unsupervised model and a scoring card model to obtain an anomaly evaluation score output by the unsupervised model and a risk evaluation score output by the scoring card model; wherein, the scoring card model is constructed based on normal traffic sample data and abnormal traffic sample data; the unsupervised model is trained based on the normal traffic sample data; a target judgment score is determined based on the anomaly evaluation score and the risk evaluation score; and it is determined whether there is a DNS tunnel based on the target judgment score and an anomaly judgment threshold.

[0091] Clause A2. The method for detecting network attacks according to Clause A1, wherein constructing the scoring card model based on normal traffic sample data and abnormal traffic sample data includes: obtaining the normal traffic sample data and the abnormal traffic sample data; determining an original detection feature type set and constructing a derivative detection feature type set based on the original detection type feature set; performing data type screening on the normal traffic sample data and the abnormal traffic sample data based on the original detection feature type set and the derivative detection feature type set to obtain normal traffic training data and abnormal traffic training data; inputting the normal traffic training data and the abnormal traffic training data into an initial logistic regression model for training, and obtaining a target logistic regression model after the training is completed; and constructing a scoring card format based on the continuous feature values, label values, and regression coefficients output by the target logistic regression model to obtain the scoring card model.

[0092] Clause A3. The network attack detection method according to Clause A2, wherein constructing the scorecard format based on the continuous eigenvalue, label value, and regression coefficient output by the target logistic regression model includes: performing feature bucketing on the continuous eigenvalue, and determining the black-and-white data ratio corresponding to each feature bucket based on the label value; determining the attack log odds corresponding to each continuous feature based on the black-and-white data ratio corresponding to each feature bucket and the regression coefficient; determining the attack probability change coefficient corresponding to each continuous feature based on the attack log odds corresponding to each continuous feature, and determining the Factor parameter corresponding to each continuous feature based on a preset additional score and the attack probability change coefficient corresponding to each continuous feature; determining the feature score corresponding to the continuous eigenvalue based on the continuous eigenvalue, the Factor parameter corresponding to each continuous feature, and the regression coefficient, and determining the risk assessment score based on a preset reference score and the feature score corresponding to each continuous eigenvalue.

[0093] Clause A4. The network attack detection method according to Clause A1, wherein training the unsupervised model based on the normal traffic sample data includes: inputting the normal traffic sample data into an isolation forest model for training to obtain the unsupervised model.

[0094] Clause A5. The network attack detection method according to Clause A1, wherein determining the target judgment score based on the abnormal evaluation score and the risk assessment score includes: extracting normal traffic verification data and abnormal traffic verification data from the normal traffic sample data and the abnormal traffic sample data respectively; determining the abnormal evaluation weight corresponding to the abnormal evaluation score and the risk assessment weight corresponding to the risk assessment score based on the normal traffic verification data and the abnormal traffic verification data; determining the target judgment score based on the abnormal evaluation score, the risk assessment score, the abnormal evaluation weight corresponding to the abnormal evaluation score, and the risk assessment weight corresponding to the risk assessment score.

[0095] Clause A6. The network attack detection method according to Clause A5, wherein determining the target judgment score based on the abnormal evaluation score, the risk assessment score, the abnormal evaluation weight corresponding to the abnormal evaluation score, and the risk assessment weight corresponding to the risk assessment score includes: determining the risk direction of the risk assessment score based on the detection feature combination of the real-time domain name system traffic data; converting the risk assessment score into a risk parameter value based on the risk direction; determining the target judgment score based on the abnormal evaluation score, the risk parameter value, the abnormal evaluation weight corresponding to the abnormal evaluation score, and the risk assessment weight corresponding to the risk assessment score.

[0096] Clause A7. The network attack detection method according to Clause A5, wherein determining whether there is a Domain Name System (DNS) tunnel based on the target judgment score and the anomaly judgment threshold includes: determining the anomaly judgment threshold based on the normal traffic verification data, the abnormal traffic verification data, the scoring card model, and the unsupervised model; comparing the target judgment score with the anomaly judgment threshold, and determining whether there is the DNS tunnel according to the comparison result.

[0097] Clause A8. The network attack detection method according to Clause A7, wherein determining whether there is the DNS tunnel according to the comparison result includes: if the target judgment score is greater than the anomaly judgment threshold, determining that there is the DNS tunnel; if the target judgment score is less than or equal to the anomaly judgment threshold, determining that there is no DNS tunnel.

[0098] Clause A9. A device for network attack detection, including: a memory; and at least one processor configured to: obtain real-time Domain Name System traffic data; input the real-time Domain Name System traffic data into an unsupervised model and a scoring card model respectively, to obtain an anomaly evaluation score output by the unsupervised model and a risk evaluation score output by the scoring card model; wherein, the scoring card model is constructed based on normal traffic sample data and abnormal traffic sample data; the unsupervised model is trained based on the normal traffic sample data; determining a target judgment score based on the anomaly evaluation score and the risk evaluation score; and determining whether there is a DNS tunnel based on the target judgment score and the anomaly judgment threshold.

[0099] Clause A10. A non-transitory machine-readable medium storing program code for network attack detection, when the program code is executed by at least one processor, the code guides the execution operations of at least one processor, and the program code includes: obtaining real-time Domain Name System traffic data; inputting the real-time Domain Name System traffic data into an unsupervised model and a scoring card model respectively, to obtain an anomaly evaluation score output by the unsupervised model and a risk evaluation score output by the scoring card model; wherein, the scoring card model is constructed based on normal traffic sample data and abnormal traffic sample data; the unsupervised model is trained based on the normal traffic sample data; determining a target judgment score based on the anomaly evaluation score and the risk evaluation score; and determining whether there is a DNS tunnel based on the target judgment score and the anomaly judgment threshold.

Claims

1. A network attack detection method, characterized in that: include: Get real-time DNS traffic data; The real-time domain name system traffic data is input into an unsupervised model and a scoring card model respectively, and an abnormality assessment score output by the unsupervised model is obtained and a risk assessment score output by the scoring card model is obtained; wherein the scoring card model is constructed based on normal traffic sample data and abnormal traffic sample data; and the unsupervised model is obtained by training based on the normal traffic sample data; determining a target judgment score based on the abnormality assessment score and the risk assessment score; It is determined whether a domain name system tunnel exists based on the target judgment score and the abnormal judgment threshold.

2. The network attack detection method according to claim 1, characterized in that: The constructing of the scoring card model based on normal traffic sample data and abnormal traffic sample data includes: Acquire the normal traffic sample data and the abnormal traffic sample data; Determining an original detection feature type set and constructing a derived detection type feature set based on the original detection type feature set; Based on the original detection feature type set and the derived detection type feature set, the normal traffic sample data and the abnormal traffic sample data are screened for data types to obtain normal traffic training data and abnormal traffic training data; Inputting the normal flow training data and the abnormal flow training data into an initial logistic regression model for training, and obtaining a target logistic regression model after the training is completed; A scorecard format is constructed based on the continuous feature values, label values ​​and regression coefficients output by the target logistic regression model to obtain the scorecard model.

3. The network attack detection method according to claim 2, characterized in that: The scoring card format constructed based on the continuous feature values, label values ​​and regression coefficients output by the target logistic regression model includes: Performing feature bucketing processing on the continuous feature value, and determining the black and white data ratio corresponding to each feature bucket based on the label value; Determine the attack logarithmic probability corresponding to each continuous feature based on the black and white data ratio corresponding to each feature bucket and the regression coefficient; Determine the attack probability variation coefficient corresponding to each continuous feature based on the attack logarithmic probability corresponding to each continuous feature, and determine the Factor parameter corresponding to each continuous feature based on the preset additional score and the attack probability variation coefficient corresponding to each continuous feature; The feature score corresponding to the continuous feature value is determined based on the continuous feature value, the Factor parameter corresponding to each continuous feature and the regression coefficient, and the risk assessment score is determined based on the preset benchmark score and the feature score corresponding to each continuous feature value.

4. The network attack detection method according to claim 1, characterized in that: The unsupervised model obtained by training based on normal traffic sample data includes: The normal traffic sample data is input into the isolation forest model for training to obtain the unsupervised model.

5. The network attack detection method according to claim 1, characterized in that: Determining the target judgment score based on the abnormality assessment score and the risk assessment score includes: Extracting normal traffic verification data and abnormal traffic verification data from the normal traffic sample data and the abnormal traffic sample data respectively; Determine, based on the normal traffic verification data and the abnormal traffic verification data, an abnormality assessment weight corresponding to the abnormality assessment score and a risk assessment weight corresponding to the risk assessment score; The target judgment score is determined based on the abnormality assessment score, the risk assessment score, the abnormality assessment weight corresponding to the abnormality assessment score, and the risk assessment weight corresponding to the risk assessment score.

6. The network attack detection method according to claim 5, characterized in that: Determining the target judgment score based on the abnormality assessment score, the risk assessment score, the abnormality assessment weight corresponding to the abnormality assessment score, and the risk assessment weight corresponding to the risk assessment score includes: Determining the risk orientation of the risk assessment score based on the detection feature combination of the real-time domain name system traffic data; Converting the risk assessment score into a risk parameter value based on the risk orientation; The target judgment score is determined based on the abnormality assessment score, the risk parameter value, the abnormality assessment weight corresponding to the abnormality assessment score, and the risk assessment weight corresponding to the risk assessment score.

7. The network attack detection method according to claim 5, characterized in that: The determining whether there is a domain name system tunnel based on the target judgment score and the abnormal judgment threshold comprises: Determine the abnormality judgment threshold based on the normal traffic verification data, the abnormal traffic verification data, the scoring card model and the unsupervised model; The target judgment score is compared with the abnormal judgment threshold, and whether the domain name system tunnel exists is determined according to the comparison result.

8. The network attack detection method according to claim 7, characterized in that: Determining whether the domain name system tunnel exists according to the comparison result includes: If the target judgment score is greater than the abnormal judgment threshold, it is determined that the domain name system tunnel exists; If the target judgment score is less than or equal to the abnormal judgment threshold, it is determined that the domain name system tunnel does not exist.

9. A device for network attack detection, characterized in that: include: Memory; as well as at least one processor configured to: Get real-time DNS traffic data; The real-time domain name system traffic data is input into an unsupervised model and a scoring card model respectively, and an abnormality assessment score output by the unsupervised model is obtained and a risk assessment score output by the scoring card model is obtained; wherein the scoring card model is constructed based on normal traffic sample data and abnormal traffic sample data; and the unsupervised model is obtained by training based on the normal traffic sample data; determining a target judgment score based on the abnormality assessment score and the risk assessment score; It is determined whether a domain name system tunnel exists based on the target judgment score and the abnormal judgment threshold.

10. A non-transitory machine-readable medium having stored thereon a program code for network attack detection, wherein when the program code is executed by at least one processor, the code guides the execution operation of the at least one processor, the program code comprising: Get real-time DNS traffic data; The real-time domain name system traffic data is input into an unsupervised model and a scoring card model respectively, and an abnormality assessment score output by the unsupervised model is obtained and a risk assessment score output by the scoring card model is obtained; wherein the scoring card model is constructed based on normal traffic sample data and abnormal traffic sample data; and the unsupervised model is obtained by training based on the normal traffic sample data; determining a target judgment score based on the abnormality assessment score and the risk assessment score; It is determined whether a domain name system tunnel exists based on the target judgment score and the abnormal judgment threshold.