An intelligent security protection system based on big data

Through an intelligent security protection system based on big data, combined with access path reconstruction, abnormal cross detection, instruction stack monitoring and bandwidth resonance discrimination modules, the problem of difficult to identify hidden risks of deep operation chains in existing systems is solved, and high-precision dynamic response and policy adaptive adjustment of potential threats in complex network environments is achieved.

CN120223432BActive Publication Date: 2025-07-25AVIC INTELLIGENT CONSTR (SHENZHEN) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510646737.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-20
Publication Date
2025-07-25
Estimated Expiration
2045-05-20

AI Technical Summary

Technical Problem

The existing intelligent security protection system lacks a cross-dimensional linkage mechanism between access path jumps and operation resource calls in the behavior recognition process, and cannot effectively identify the dynamic growth trends and abnormal evolution of parameter structures in nested instructions, making it difficult to detect hidden risks in the deep operation chain, and the strategy response level does not form a comprehensive recognition power in the judgment of behavior deviations, and the system's response in complex network environments is insufficient.

Method used

Using an intelligent security protection system based on big data, through access path reconstruction module, exception cross detection module, instruction stacking monitoring module and bandwidth resonance discrimination module, combined with access logs, node behavior sequences and communication link analysis, we identify access abnormal path segments, filter high-risk nodes, and integrate multi-dimensional behavior parameters such as resource call frequency, instruction stacking intensity and path jump amplitude to achieve dynamic response and real-time adjustment.

Benefits of technology

It significantly enhances the deep restoration and early warning accuracy of potential security threats, improves the system's dynamic control ability in complex network environments, and ensures the accuracy of overall system response and the adaptability of policy configuration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223432B_ABST
    Figure CN120223432B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of network security technology, and specifically provides an intelligent security protection system based on big data. The system includes: an access path reconstruction module, an abnormal cross-detection module, an instruction stack monitoring module, a bandwidth resonance discrimination module, and a risk warning output module. In the present invention, by dynamically identifying the jump frequency, parameter fluctuations, and node behavior sequences of access logs, it is possible to quickly locate abnormal access path segments, and combine the call coincidence characteristics of node operation resources and abnormal time density to achieve fine screening of high-risk nodes in the behavior trajectory. Further, through the joint analysis of the instruction nesting level and parameter structure in the communication link, the stacking expansion trend and parameter abnormal variation in the instruction call behavior are captured at the time series level, enhancing the three-dimensional recognition ability of deep abnormal operations. Mapping the change trend of nested instructions to the network bandwidth usage rate sequence can effectively capture the deep manifestation form of resource allocation imbalance.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to an intelligent security protection system based on big data. Background Art

[0002] The field of network security technology includes technical means and methods to ensure the safe operation of computer network systems. Its core content includes monitoring and protecting the information transmission, data exchange and storage process in the network to prevent unauthorized access, data leakage, malicious attacks and system damage. Network security technology mainly involves identity authentication, access control, data encryption, security auditing, intrusion detection and defense, etc., and its application scope covers government affairs, finance, industrial control, personal privacy and other industries.

[0003] Among them, the intelligent security protection system refers to a software and hardware integrated solution for automatically identifying potential security threats and performing protection operations, which specifically covers technical matters such as feature analysis of access behavior, real-time monitoring of abnormal communications, feature identification of malicious code, analysis and determination of external device access behavior, etc. It is usually achieved through a policy-based access behavior determination rule set, a correlation matching method between behavior features and communication content, a multi-dimensional comparison method between code structure and dynamic behavior, and an anomaly identification method based on access features and historical patterns.

[0004] The existing intelligent security protection system relies on static rules and single-dimensional feature judgment in the process of behavior recognition. The processing granularity of abnormal jump frequency and parameter fluctuation of access behavior is insufficient, and it is difficult to identify micro-structure variations at the parameter level. The lack of a cross-dimensional linkage mechanism between access path jumps and operation resource calls makes it easy to miss high-coupling risk points when abnormal node behaviors intersect at multiple points. Instruction-level analysis is limited to the static comparison of a single call trajectory, and it is impossible to effectively mine the dynamic growth trend and abnormal evolution of parameter structure in nested instructions, making it difficult to discover hidden risks in deep operation chains. Under the existing mechanism, only surface statistics are made for bandwidth fluctuations, ignoring the potential coupling relationship with the instruction nesting level, and failing to effectively characterize the imbalance in resource allocation. For example, in the case where the attacker continues to call deep service instructions at a low frequency, causing the bandwidth to be gradually eroded, the system is prone to judge it as normal traffic because it does not associate the nesting level trend with the bandwidth sequence change, and misses the opportunity for intervention. In addition, the judgment of behavioral deviation at the policy response level does not form a joint comparison among behavioral paths, call frequency, and resource access, and lacks comprehensive recognition of complex behavioral patterns, which makes the system's real-time and accuracy in policy adjustment obviously insufficient. Summary of the invention

[0005] The purpose of the present invention is to solve the shortcomings of the prior art and to propose an intelligent security protection system based on big data.

[0006] To achieve the above object, the present invention adopts the following technical solutions: An intelligent security protection system based on big data includes:

[0007] The access path reconstruction module obtains access logs in the network environment, identifies the abnormal frequency of access jumps and parameter fluctuations, filters out path segments with excessive jump times and abnormal parameters, and generates a set of path jump segments;

[0008] The abnormal cross-detection module extracts the node numbers and corresponding operation resource parameters in the jump segments of the set of path jump segments, analyzes the distribution of nodes in the abnormal area and the coincidence degree of call characteristics, and generates cross-abnormal node data;

[0009] The instruction stack monitoring module calls the instruction nesting records in the communication link according to the node numbers in the cross-abnormal node data, analyzes the parameter structure, target address and callback times in the instruction call process, filters out nodes with abnormal growth of instruction stacks, and generates a set of stack abnormal characteristics;

[0010] The bandwidth resonance discrimination module analyzes the correlation between the change of instruction stack level and the fluctuation of bandwidth occupancy rate for the nodes in the set of stack abnormal characteristics, filters out nodes with bandwidth imbalance phenomenon, and obtains a set of bandwidth imbalance nodes;

[0011] The risk warning output module analyzes the deviation of the current behavior characteristics of the nodes from the policy benchmark based on the set of bandwidth imbalance nodes, and executes corresponding adjustment operations to generate a dynamic security protection result.

[0012] As a further solution of the present invention, the set of path jump segments includes abnormal distribution of jump times, parameter feature deviation records, and node sequence positioning information. The cross-abnormal node data includes resource call coincidence identifiers, behavior frequency synchronization markers, and abnormal area mapping results. The set of stack abnormal characteristics is specifically instruction nesting level information, call structure feature values, and node stack offset conditions. The set of bandwidth imbalance nodes specifically refers to bandwidth occupancy fluctuation records, path allocation imbalance identifiers, and node association relationship data. The dynamic security protection result includes permission adjustment records, instruction call limit parameters, and bandwidth allocation optimization configurations.

[0013] As a further solution of the present invention, the access path reconstruction module includes:

[0014] The node extraction sub-module obtains the big data resources of access logs in the network environment, extracts access nodes, jump types and request parameters, counts the occurrence frequency and jump type distribution of each access node, and generates node behavior feature data in combination with the quantity and type of request parameters;

[0015] The jump detection sub-module detects non-adjacent jump behaviors in the access node sequence based on the node behavior feature data, counts the jump times and jump intervals of each node segment, calls the benchmark path record of normal access behaviors, compares whether the jump times and jump intervals exceed the jump frequency benchmark interval, filters out the node segments with abnormal jumps, and obtains jump abnormal node data;

[0016] The parameter comparison sub-module counts the differences in the key names of the request parameters before and after the jump, the changes in the parameter value types, and the fluctuations in the parameter set scale according to the jump abnormal node data, calls the normal request parameter distribution data, compares whether the parameter feature changes exceed the parameter fluctuation benchmark interval, filters out the node segments with excessive jump times and abnormal parameter features, and generates a path jump segment set.

[0017] As a further solution of the present invention, the abnormal cross-detection module includes:

[0018] The resource parameter association sub-module extracts the node numbers of the jump segments and the corresponding operation resource parameters based on the path jump segment set, detects whether the operation resource parameters appear in the abnormal behavior records of network security events, counts the abnormal association times of the node resource identifiers, calls the resource abnormal association benchmark value, filters out the nodes with abnormal association times exceeding the benchmark value, and generates resource association abnormal data;

[0019] The abnormal area matching sub-module extracts the operation time information of the corresponding nodes according to the resource association abnormal data, counts the time distribution density of the nodes in the abnormal behavior records, calls the abnormal time distribution benchmark value, compares whether the time distribution density of the nodes is higher than the density benchmark value, filters out the nodes with time distribution density exceeding the density benchmark value, and obtains abnormal area concentration data;

[0020] The behavior feature comparison sub-module calls the abnormal area concentration data, extracts the resource call parameters of the corresponding nodes, counts the operation type consistency rate, the call time interval coincidence rate, and the resource identifier matching rate of the nodes, calls the behavior feature coincidence threshold, judges whether the three indicators exceed the threshold at the same time, filters out the nodes that coincide in both resource call features and behavior frequencies, and generates cross-abnormal node data.

[0021] As a further solution of the present invention, the instruction stack monitoring module includes:

[0022] The instruction record extraction sub-module extracts the corresponding node numbers based on the cross-abnormal node data, calls the instruction nesting records in the communication link, obtains the instruction call sequence and the nesting level information of each node, counts the instruction call times and the change interval of the nesting level, and generates instruction call sequence data;

[0023] The parameter structure analysis sub-module calls the sequence data according to the instruction, extracts the input parameter structure and target address characteristics of each layer of instructions, counts the number of input parameter fields, the distribution of parameter types and the number of target address changes, calls the benchmark interval of the parameter structure, judges whether the parameter quantity and the target address change are abnormal, filters the nodes with abnormal parameter structures, and obtains the abnormal quantity of the parameter structure;

[0024] The stacking trend calculation sub-module calls the abnormal quantity of the parameter structure, analyzes the growth of the nested levels during the continuous call process, calculates the growth rate of the stacking level of each node, calls the stacking growth threshold, judges whether the growth rate exceeds the threshold, filters the nodes with abnormal growth of the stacking level, and generates a set of abnormal stacking characteristics.

[0025] As a further solution of the present invention, the bandwidth resonance discrimination module includes:

[0026] The bandwidth usage record extraction sub-module aims at the nodes in the set of abnormal stacking characteristics, obtains the upper limit of the bandwidth allocation of the network path where the node is located and the usage traffic within the corresponding time period, calls the timestamp and node ID recorded in the instruction nesting record, aligns the timestamp and maps it to the sampling time point of the bandwidth record, matches the usage traffic and the allocated bandwidth through the corresponding node ID, and calculates the bandwidth occupancy rate of each time period as the bandwidth usage rate sequence of the current node;

[0027] The hierarchical association relationship analysis sub-module, according to the bandwidth usage rate sequence and the nested level change sequence of the nodes in the set of abnormal stacking characteristics, pairs the nested level of each instruction with the bandwidth usage rate at the same time point in a sequence alignment manner, constructs a joint sequence in chronological order, calculates the difference between the growth rate of the nested level and the change amplitude of the bandwidth usage rate within each window, filters the continuous decline section of the bandwidth occupancy rate, and generates the analysis result of the bandwidth decline amplitude;

[0028] The unbalanced node screening sub-module, based on the bandwidth decline amplitude and the nested level growth rate in the analysis result of the bandwidth decline amplitude, compares whether the two conditions of continuous increase of the nested level and continuous decrease of the bandwidth usage rate are satisfied in the same window for each node one by one, records the unbalanced nodes during the comparison process, and generates a set of bandwidth unbalanced nodes.

[0029] As a further solution of the present invention, the risk warning output module includes:

[0030] The feature integration sub-module, based on the set of bandwidth unbalanced nodes, integrates the call frequency, call object type and duration fields recorded by each node in the resource call log, and performs joint pairing with the stacking level in the instruction nesting record and the number of jump times field in the path record, classifies the resource call coincidence, instruction stacking intensity and path jump amplitude of the nodes within the same time period, and generates a multi-dimensional abnormal feature quantity;

[0031] The policy deviation judgment sub-module calls the multi-dimensional abnormal feature quantity, performs field-level matching with the resource access permissions, instruction call frequency limits, and bandwidth allocation references in the security policy database, calculates the deviation degrees of the current node behavior in the dimensions of permissions, frequencies, and bandwidths compared with the policy benchmarks respectively, performs label marking and classification statistics on the policy fields whose deviation degrees exceed the set thresholds, and obtains the policy deviation degree distribution result;

[0032] The security parameter adjustment sub-module, according to the policy deviation degree distribution result, maps operation items to the over-limit fields in sequence for each node, performs the operation of lowering the corresponding access level for permission convergence, controls the instruction frequency to the maximum threshold within the set range, and adjusts the bandwidth configuration value of the current node to align with the policy reference value, records the node numbers of all nodes for which the adjustment operation is successfully executed, and generates the dynamic security protection result.

[0033] Compared with the prior art, the advantages and positive effects of the present invention are as follows:

[0034] In the present invention, through the dynamic recognition of the jump frequency, parameter fluctuations of the access logs, and the node behavior sequences, the abnormal access path segments can be quickly located. Combining the call coincidence characteristics of the node operation resources and the abnormal time density, the fine screening of high-risk nodes in the behavior trajectory is realized. Further, through the joint analysis of the instruction nesting levels and parameter structures in the communication link, the stacking expansion trend and parameter abnormal variation in the instruction call behavior are captured at the time sequence level, enhancing the three-dimensional recognition ability of deep abnormal operations. Mapping the change trend of the nested instructions to the network bandwidth usage sequence, a resonance mode of nested level growth and bandwidth usage decline is constructed to effectively capture the deep manifestation form of resource allocation imbalance. Based on the identification of abnormal nodes, multi-dimensional behavior parameters such as resource call frequency, instruction stacking intensity, and path jump amplitude are integrated. Through the behavior portrait deviating from the policy benchmark, dynamic response and real-time adjustment to high-risk behaviors are realized. This process realizes a multi-dimensional collaborative discrimination mechanism among access, behavior, resources, and policies at different levels, significantly enhancing the depth restoration and early warning accuracy of potential security threats, improving the system's dynamic control ability over the hidden and progressive security risks in a complex network environment, and ensuring the accuracy of the overall system response and the self-adaptability of the policy configuration. Description of the Drawings

[0035] Figure 1 is the system flow chart of the present invention;

[0036] Figure 2 is the flow chart of the access path reconstruction module of the present invention;

[0037] Figure 3 is the flow chart of the abnormal cross-detection module of the present invention;

[0038] Figure 4 This is the flowchart of the instruction stack monitoring module of the present invention;

[0039] Figure 5 This is the flowchart of the bandwidth resonance discrimination module of the present invention;

[0040] Figure 6 This is the flowchart of the risk warning output module of the present invention. Specific embodiments

[0041] In order to make the objectives, technical solutions and advantages of the present invention more clear and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0042] In the description of the present invention, it should be understood that the orientation or positional relationship indicated by the terms "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. is based on the orientation or positional relationship shown in the accompanying drawings, and is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus cannot be construed as a limitation to the present invention. In addition, in the description of the present invention, "a plurality of" means two or more, unless otherwise specifically defined.

[0043] Please refer to Figure 1 , an intelligent security protection system based on big data includes:

[0044] The access path reconstruction module obtains the big data resources of access logs in the network environment, extracts access nodes, jump types and request parameters. For the access node sequence, it detects the node non-adjacent jump behavior occurring in the continuous access process, counts the jump times and jump intervals of each node segment, calls the benchmark path record of normal access behavior, compares whether the jump times exceed the jump frequency interval in the benchmark path, further counts the key name differences, parameter value type changes and parameter set scale fluctuations of the request parameters before and after the jump, calls the normal request parameter distribution data, compares whether the parameter feature changes exceed the parameter fluctuation benchmark interval, screens out the node segments with excessive jump times and abnormal parameter features, and generates a path jump segment set;

[0045] The abnormal cross-detection module extracts the node numbers and corresponding operation resource parameters in the jump segment set of the path jump segment, correlates with the big data abnormal behavior records in the network security event, detects the distribution of the target node in the abnormal behavior concentration area, compares the resource call parameters of the jump node with the operation type, call time interval, and resource identifier of the nodes in the abnormal area, filters the nodes that coincide in both resource call characteristics and behavior frequencies, and generates cross-abnormal node data;

[0046] Based on the node numbers in the cross-abnormal node data, the instruction stack monitoring module calls the instruction nesting records in the communication link, obtains the input parameter structure, target address characteristics, and callback times of the corresponding nodes, analyzes the change trend of the stack level during the instruction call process, identifies the abnormal nodes where the stack level growth exceeds the growth threshold during continuous calls, and generates a stack abnormal feature set;

[0047] For the nodes in the stack abnormal feature set, the bandwidth resonance discrimination module obtains the records of network path bandwidth allocation and actual usage, analyzes the correlation between the change of the instruction stack level and the fluctuation of the bandwidth occupancy rate, judges whether there is an abnormal decrease in the bandwidth occupancy rate during the process of stack level improvement, filters the nodes with bandwidth imbalance phenomenon, and obtains a bandwidth imbalance node set;

[0048] Based on the bandwidth imbalance node set, the risk warning output module integrates the resource call big data, instruction stack characteristics, and path jump behavior of the nodes. For the nodes with path anomalies, resource call coincidence, instruction stack anomalies, and bandwidth imbalance characteristics, it matches the security policy database in the big data, detects the resource access permissions, instruction call restrictions, and bandwidth allocation rules corresponding to the nodes, analyzes the deviation of the current behavior characteristics of the nodes from the policy benchmark, performs permission convergence, instruction call frequency limit, and bandwidth allocation adjustment operations, filters the nodes that have completed security adjustments, and generates a dynamic security protection result;

[0049] The path jump segment set includes abnormal distribution of jump times, parameter feature deviation records, and node sequence positioning information. The cross-abnormal node data includes resource call coincidence identification, behavior frequency synchronization mark, and abnormal area mapping result. The stack abnormal feature set is specifically the instruction nesting level information, call structure feature value, and node stack offset situation. The bandwidth imbalance node set specifically refers to the bandwidth occupancy fluctuation record, path allocation imbalance identification, and node association relationship data. The dynamic security protection result includes permission adjustment records, instruction call limit parameters, and bandwidth allocation optimization configuration.

[0050] Please refer to Figure 2 , the access path reconstruction module includes:

[0051] The node extraction sub-module obtains the big data resources of access logs in the network environment, extracts access nodes, jump types, and request parameters, counts the occurrence frequency of each access node and the distribution of jump types, and combines the quantity and type of request parameters to generate node behavior feature data;

[0052] First, collect the access log files at different times of each day, arrange the access records in the order of timestamps, and extract the access node identifier, jump type code, and request parameter list in each record. The access node identifier is used to distinguish different resource entrances, the jump type code reflects the user operation path, and the request parameter list includes the specific content and parameter values requested by the user. For the extracted access node identifier, count its occurrence frequency within 24 hours. For example, node A appears 150 times in a day, node B appears 85 times, and node C appears 200 times. Through frequency statistics, the access hotspots can be initially identified. Subsequently, classify and count the jump type codes, dividing them into three categories: direct jump, indirect jump, and cross-domain jump. Calculate the distribution ratio of the corresponding jump types for each node. For example, in node A, the direct jump accounts for 60%, the indirect jump accounts for 30%, and the cross-domain jump accounts for 10%. Then, for the request parameter list, count the number of request parameters and the distribution of parameter types for each node. The parameter types include strings, numerical types, boolean types, etc. For example, the average number of request parameters for node A is 5, and the type distribution is 60% strings, 30% numerical types, and 10% boolean types. After completing the basic data statistics, combine the access frequency, jump type distribution, and request parameter characteristics to calculate the behavior feature interval for each node. The behavior feature interval is determined by setting frequency thresholds, jump ratio thresholds, and parameter quantity fluctuation thresholds. Among them, the frequency threshold is set at ±20% based on the standard deviation of the daily average access volume, the jump ratio threshold is set at ±15% of the average proportion of each type, and the parameter quantity fluctuation threshold is set at ±10% of the historical average. For example, the frequency threshold interval for node A is 120 to 180 times, the jump ratio threshold for direct jump is 51% to 69%, and the parameter quantity fluctuation interval is 4.5 to 5.5 parameters. If the actual statistical value of a certain node exceeds the above interval, it is marked as a node with abnormal behavior characteristics. Finally, generate node behavior feature data.

[0053] The jump detection sub-module, based on the node behavior feature data, detects non-adjacent jump behaviors in the access node sequence, counts the number of jumps and jump intervals in each node segment, calls the benchmark path record of normal access behaviors, compares whether the number of jumps and jump intervals exceed the jump frequency benchmark interval, and filters out the node segments with abnormal jumps to obtain jump abnormal node data;

[0054] First, call the generated node behavior feature data, extract the access frequency, jump type distribution, and parameter feature interval of each node, arrange the access node sequence in chronological order, and detect whether the adjacent node numbers in the node sequence are continuous. If the node numbers are discontinuous and the jump is not made according to the standard path jump rule, it is determined as a non-adjacent jump behavior. For example, if the standard path is node A - B - C - D, and it is detected that after node A, it directly jumps to node D, it is recorded as a non-adjacent jump. Count the number of jumps and jump intervals in each node segment. The number of jumps is the cumulative number of consecutive non-adjacent jumps, and the jump interval is the difference in the number of nodes between two jumps. For example, in the node segment A - D - C - F, there are two non-adjacent jumps, and the jump intervals are 3 and 2 respectively. Subsequently, call the benchmark path record of normal access behavior, which is statistically obtained based on historical normal access data. Set the benchmark interval for jump frequency as the daily average number of jumps ± 25% and the jump interval not exceeding 1.5 times the length of the standard path. For example, the benchmark jump count interval is 1 to 3 times, and the benchmark jump interval is not exceeding 3 nodes. Compare the detected number of jumps and jump intervals. If the number of jumps exceeds 3 times or the jump interval exceeds 3, it is determined that this node segment is a jump abnormal node segment. Screen the node segments that meet the conditions for marking, and finally obtain the jump abnormal node data.

[0055] The parameter comparison sub-module, based on the jump abnormal node data, counts the differences in the key names of the request parameters before and after the jump, the changes in the parameter value types, and the fluctuations in the parameter set scale, calls the normal request parameter distribution data, compares whether the parameter feature changes exceed the parameter fluctuation benchmark interval, screens the node segments with excessive jump counts and abnormal parameter features, and generates a set of path jump segments;

[0056] First, compare the key names of the request parameters before and after the jump, calculate the quantity difference between the newly added key names and the missing key names. For example, if the parameter key names before the jump are {id, user, type, status} and after the jump are {id, user, level, mode}, then there are 2 key name differences. Then, compare the parameter value types, and count whether the parameter value types corresponding to the same key names have changed. For example, if "status" was of string type before the jump and becomes numeric type after the jump, it is recorded as 1 type change. At the same time, count the total quantity change of the parameter sets before and after the jump. If the parameter quantity was 4 before the jump and 6 after the jump, the fluctuation amplitude is 50%. Subsequently, call the normal request parameter distribution data, and set the parameter fluctuation benchmark interval based on the key name difference rate, parameter type change rate, and parameter set scale volatility in historical normal access. Among them, the benchmark interval for the key name difference rate is set not to exceed 20%, the parameter type change rate not to exceed 10%, and the parameter set scale volatility not to exceed 15%. For example, in a jump, the detected key name difference rate is 50%, the type change rate is 25%, and the parameter set volatility is 50%, all of which exceed the corresponding benchmark intervals. It is determined that there are abnormal parameter characteristics in this jump segment. At the same time, combined with the jump count information in the jump anomaly node data, judge whether the jump count exceeds the limit. If the jump count exceeds the upper limit of the jump frequency benchmark interval, further confirm that this node segment is a node segment with excessive jump count and abnormal parameter characteristics. Finally, filter out all eligible node segments to generate a set of path jump segments.

[0057] Please refer to Figure 3 , the abnormal cross-detection module includes:

[0058] Based on the set of path jump segments, the resource parameter association sub-module extracts the jump segment node numbers and the corresponding operation resource parameters, detects whether the operation resource parameters appear in the abnormal behavior records of network security events, counts the abnormal association times of the node resource identifiers, calls the resource abnormal association benchmark value, filters out the nodes with abnormal association times exceeding the benchmark value, and generates resource association abnormal data;

[0059] Based on the set of path jump segments, extract the node numbers and corresponding operation resource parameters in each jump segment. The operation resource parameters include a resource identifier, an operation type, and a call time. The resource identifier is used to uniquely identify the object to be operated on in the network. The operation type describes the category of access or modification behavior, and the call time records the specific operation time point. For the extracted resource identifiers, compare them item by item with the abnormal behavior records in the network security events to detect whether the resource identifier appears in the abnormal behavior records. If it appears, it is counted as one abnormal association. For example, if the resource identifier corresponding to the node number N123 is R567 and it appears 3 times in the abnormal behavior records, then the number of abnormal associations of this node is 3 times. Statistically count the resource abnormal association times of all nodes in turn, and then call the resource abnormal association benchmark value. This benchmark value is set according to the abnormal association frequency of resource calls in normal operations. Refer to the distribution of resource association times in normal operations in the most recent 30 days, and take the mean plus twice the standard deviation as the benchmark value. Suppose the mean obtained by statistics is 1.5 times and the standard deviation is 0.8 times, then the benchmark value is set to 1.5 + 2×0.8 = 3.1 times, and it is rounded to 3 times in actual application. If the number of abnormal associations of a certain node is greater than 3 times, it is determined as an abnormal node. Finally, screen out all nodes whose abnormal association times exceed the benchmark value to generate resource association abnormal data.

[0060] The abnormal area matching sub-module extracts the operation time information of the corresponding nodes according to the resource association abnormal data, statistically counts the time distribution density of the nodes in the abnormal behavior records, calls the abnormal time distribution benchmark value, compares whether the time distribution density of the nodes is higher than the density benchmark value, and screens out the nodes whose time distribution density exceeds the density benchmark value to obtain the abnormal area concentration data;

[0061] According to the resource association abnormal data, extract the corresponding operation timestamps of each node in the abnormal behavior records, sort the operations of each node in time sequence in turn, and statistically count the inter-segment distribution formed by all operations on the time line. Define the time interval between each pair of consecutive operations as and the operation frequency is n, and the total time span is That is: where and are the time (in hours) when the node appears for the last time and the first time respectively. Define the time distribution density value of this node as the distribution function after the average density superposition offset correction of all operation time pairs: where : The time distribution density value, which represents the operation density of the node per unit time, and the unit is "times / hour"; : The overall operation frequency of the node, which reflects the average operation density during the entire active period; : Accumulate and sum all continuous operation intervals, ranging from the 1st to the th interval; : The duration of the th operation interval, with the unit of "hour"; : The minimum interval correction constant to avoid the denominator approaching zero when the operation interval is extremely small. The value is 0.01 hour to ensure the stability of formula calculation; : Represents the averaging process of the operation interval part, normalizing the density of all intervals. The first term is the basic access frequency density, and the second term is the operation interval density, is the minimum interval constant to avoid the denominator being zero, with a value of 0.01 hour. All variable units are unified as "times / hour". For example, node N789 appears 5 times in the abnormal behavior records, at the 1st, 3rd, 4th, 6th, and 7th hours respectively. Corresponding to ΔT_total = 6 hours and ΔT_i being 2, 1, 2, 1 hour, the calculation is as follows: The first term: , the second term: , the overall density value: . Then, set the abnormal time distribution reference value, establish a threshold based on the statistical results of the time distribution density of normal nodes. Collect the operation records of 100 normal nodes in the same network system, calculate the average time density mean value to be 0.65 times / hour, and the standard deviation to be 0.28 times / hour. Set the upper threshold according to the 3σ control principle as: , compare with the calculated density value of node N789, which is 1.577 times / hour. Since 1.577 > 1.49, it is determined that this node is a node with abnormal time distribution. After performing the above process on all nodes, filter out the nodes whose time distribution density values exceed the threshold to obtain the concentrated data in the abnormal area.

[0062] The behavior feature comparison sub-module calls the concentrated data in the abnormal area, extracts the resource call parameters of the corresponding nodes, counts the consistency rate of node operation types, the coincidence rate of call time intervals, and the matching rate of resource identifiers, calls the behavior feature coincidence threshold, judges whether the three indicators simultaneously exceed the threshold, filters out the nodes that coincide in both resource call features and behavior frequencies, and generates cross-abnormal node data;

[0063] Call the data in the abnormal area, extract the resource call parameters of the corresponding nodes, and count the consistency rate of node operation types, the coincidence rate of call time intervals, and the matching rate of resource identifiers. The consistency rate of operation types is the ratio of the node operation type to the operation type in the abnormal behavior record. The coincidence rate of call time intervals is the ratio of the node call time interval to the time interval in the abnormal record. The matching rate of resource identifiers is the ratio of the node resource identifier to the resource identifier in the abnormal record. Calculate the three indicators respectively. For example, the consistency rate of operation types of node N123 is 85%, the coincidence rate of call time intervals is 75%, and the matching rate of resource identifiers is 90%. Call the behavior feature coincidence threshold, which is set to the maximum value of each indicator in normal operation plus a safety margin of 10%. Assume that the maximum consistency rate in normal operation is 60%, then the threshold is 66%. Determine whether all three indicators exceed 66%. If all are satisfied at the same time, it is determined that there is an abnormal coincidence in the resource call characteristics and behavior frequencies of this node. Screen the qualified nodes and generate cross-abnormal node data.

[0064] Please refer to Figure 4 , the instruction stack monitoring module includes:

[0065] Based on the cross-abnormal node data, the instruction record extraction sub-module extracts the corresponding node numbers, calls the instruction nesting records in the communication link, obtains the instruction call sequence and nesting level information of each node, counts the instruction call times and the change range of the nesting level, and generates instruction call sequence data;

[0066] First, the unique number of each node needs to be sequentially extracted from the cross-abnormal node set, and the number is retrieved node by node in the communication link data to locate all communication records that match the node number. During this process, the instruction identification code, parent-child call relationship identification, and timestamp information in each record need to be extracted and sorted. By judging the time sequence and parent identification matching relationship between the parent and child instructions, a complete call nesting tree structure is constructed. Then, count the number of occurrences and nesting level positions of each instruction node in the nesting tree, and divide the hierarchical fluctuation range within different time windows through time series analysis of the hierarchical change trend over time. For example, if the hierarchical change range of a certain node jumps from 2 to 7 within a certain window, it is recorded as the interval [2, 7]. Such change intervals will be used as a reflection of call stability in the future. The above processing process is applied to the instruction link backtracking in the automated assembly system. For example, when extracting the controller with node ID R1223 in the robot arm control system, its historical instruction nesting chain is MOVE→CHECK→LOCK→ROTATE→GRAB→CHECK. Then a hierarchical structure with a nesting depth of 6 is constructed. By counting at each time point, the hierarchical sequence can be obtained as [1, 2, 3, 4, 5, 6], and its interval fluctuation is [1, 6]. The final set of call times and fluctuation intervals of all nodes is recorded as instruction call sequence data.

[0067] The parameter structure analysis sub-module extracts the input parameter structure and target address features of each layer of instructions according to the instruction call sequence data, counts the number of input parameter fields, parameter type distribution, and the number of target address changes, calls the parameter structure benchmark interval, determines whether the parameter quantity and target address changes are abnormal, filters the nodes with abnormal parameter structures, and obtains the abnormal quantity of the parameter structure;

[0068] First, extract the input parameter information of each instruction layer by layer. The specific operation is to traverse each layer of instruction records, parse fields such as "param_count", "param_types", and "target_addr" in them. By analyzing these three types of fields, a complete input parameter structure feature array of each layer of instructions can be constructed. Subsequently, count the number of parameter fields of each instruction node and record its type distribution (such as integer type, floating-point type, string, etc.). Compare the number of changes in the "target_addr" field in each instruction record. If the target address switches more than 3 times in 10 consecutive records, it is considered that there are frequent changes. Then call the set parameter structure benchmark interval. For example, for the MOV instruction in an industrial control system, the benchmark parameter number is set to 3±1, and the target address change not exceeding 2 times is normal. Compare the actual collected value with the benchmark value. For example, if the parameter number is 5 and the target address change is 4 times, then this node is determined to be an abnormal node, and its parameter structure is included in the abnormal quantity statistics. The abnormal quantity is defined as the number of abnormal structure entries per thousand instructions. For example, a total of 10000 instructions are detected, and 345 abnormal structures are found, then the abnormal quantity is 345 / 10000 = 0.0345, indicating that there is an obvious parameter structure fluctuation problem in this sampling section.

[0069] The stack trend calculation sub-module calls the abnormal quantity of the parameter structure, analyzes the growth of the nested levels during the continuous call process, calculates the growth rate of the stack level of each node, calls the stack growth threshold, determines whether the growth rate exceeds the threshold, filters the nodes with abnormal stack level growth, and generates a set of stack abnormal features;

[0070] Call the abnormal quantity of the parameter structure and analyze the growth of the nested levels during the continuous call process. First, for the instruction call sequence of a certain node in the communication link, assume that the set of nested levels within a time window is , where each represents the nested level value of the th instruction, which is a positive integer representing its nested depth in the instruction tree structure. Denote the maximum level as , where represents the maximum value of the nested levels in the analysis window; , where represents the minimum value of the nested levels within this window. The change amount of the node stack level is defined as the difference between the two: , where represents the range of hierarchical changes and is used to measure the degree of structural fluctuations. Subsequently, the growth rate of the stacked hierarchy is calculated , and its formula is: , where represents the total number of instructions within the current analysis window and is a positive integer; represents the average growth rate of the nesting level within this window. In the sliding analysis, the window can be continuously moved to obtain multiple growth rate values. Let the total number of windows be , the th window's maximum and minimum hierarchical values are respectively , , the window span is , then the growth rate of this window is: , where represents the stacked growth rate of the th window, and are respectively the maximum and minimum nesting level values within this window, is the number of instructions within this window. Further, the average of the growth rates of all windows is taken, and the average growth rate is: , where is the average growth rate; is the total number of windows; represents summing over all windows from 1 to . To determine whether there is abnormal stacking behavior, the growth rate needs to be compared with the historical threshold. The stacked growth threshold is calculated as follows: , where represents the stacked growth judgment threshold; is the average value of the growth rates of historical normal nodes; is the standard deviation of the growth rate; is the adjustment coefficient. The adjustment coefficient is set as follows: Downsample the non-abnormal nodes in the system under the training data to obtain their growth rate set , calculate its mean and standard deviation , and set the adjustment coefficient to with the strategy of not exceeding 5% of the statistical outliers, that is, the growth rate of nodes outside two standard deviations is determined as abnormal growth. If the actual business tolerance is different, it can be set in the following intervals: Set in the lightweight monitoring system, and set in the strict audit system. The specific value should be calibrated based on the fluctuation range tolerated by the actual scenario and the distribution density of historical data. If it is calculated that , then it is considered that the One window is an abnormal stack window. For example, assume that the nested level sequence of a certain node within a certain window is Then there is , , . Substituting into the formula gives: If the historical statistical result is , , and it is set that , then there is: Since , this window is determined to be a stack abnormal growth window, and the position of this node and the window are recorded in the stack abnormal feature set.

[0071] Please refer to Figure 5 , the bandwidth resonance discrimination module includes:

[0072] The bandwidth usage record extraction sub-module obtains the upper limit of the bandwidth allocation of the network path where the node is located and the actual usage traffic within the corresponding time period for the nodes in the stack abnormal feature set, calls the time stamps and node IDs recorded in the instruction nesting record, aligns the time stamps and maps them to the sampling time points of the bandwidth record, matches its usage traffic and allocated bandwidth through the corresponding node ID, and calculates the bandwidth occupancy rate for each time period as the bandwidth usage rate sequence of the current node;

[0073] For the nodes in the stack abnormal feature set, obtain the bandwidth resource information of the node in the specified network path, correspond the node number to the path information in the network topology structure, obtain the upper limit value of the bandwidth allocation on its path, and call the node usage traffic value and the corresponding time stamp field recorded in the communication monitoring log at the minute granularity, perform sequence alignment processing by comparing with the time stamp field in the instruction nesting record, match the time stamp of each instruction in the nesting record downward to the bandwidth record time point not greater than its time point, accurately match the bandwidth usage value at the current time point with the upper limit value of the bandwidth allocation recorded in its network configuration through the node number field in the instruction record, after completing the double matching of time and node, calculate the bandwidth occupancy rate, and its formula is the current usage traffic divided by the bandwidth upper limit value, and the value range is 0, 1. For example, the bandwidth upper limit of node X320 at the time point of 08:00 is 100 Mbps, and the usage traffic is 60 Mbps, then the occupancy rate is 60 / 100 = 0.6. If it is recorded as 70 Mbps at 08:05, then it is 0.7, and so on. The bandwidth occupancy rate sequence of node X320 at multiple time points is [0.6, 0.7, 0.75, 0.68, 0.65]. Each value is obtained from the ratio of the usage amount to the upper limit bandwidth of the same node at different times, and the bandwidth usage rate sequence is constructed in turn. In a large-scale distributed processing system, after multiple nodes generate the bandwidth usage rate sequence in parallel, it can be used for subsequent judgment of the impact of the stack level, and generate the bandwidth usage rate sequence.

[0074] The hierarchical association analysis sub-module pairs the nested level of each instruction with the bandwidth utilization rate at the same time point in the sequence alignment manner according to the bandwidth utilization rate sequence and the nested level change sequence of the nodes in the stack anomaly feature set, constructs a joint sequence in chronological order, calculates the difference between the nested level growth rate and the bandwidth utilization rate change amplitude within each window, filters out the continuous decline section of the bandwidth occupancy rate, and generates the bandwidth decline amplitude analysis result;

[0075] According to the bandwidth utilization rate sequence and the nested level change sequence of the nodes in the stack anomaly feature set, the two sequences are jointly aligned with the timestamp as the primary key. The nested level value and the bandwidth utilization rate value of the node are extracted for each time point, and a joint sequence pair is constructed. For example, the corresponding value of T1 is the nested level 3 and the bandwidth occupancy rate 0.75, T2 is 4 and 0.7, and so on, forming a structure of [(T1, 3, 0.75), (T2, 4, 0.7), (T3, 5, 0.65)]. For the above structure, the growth rate value of the nested level and the change amplitude of the bandwidth occupancy rate within each window are calculated according to the sliding window with a window length of 3. The calculation method is to take the difference between the end value and the start value and then divide by the window span. For example, if the level ranges from 3 to 5, the growth rate is (5 - 3) / 3 = 0.666, and if the occupancy rate drops from 0.75 to 0.65, the change amplitude is (0.65 - 0.75) / 3 = -0.0333. Repeat the above process to obtain the bandwidth change trend of each window. If the negative change amplitude of the bandwidth occupancy rate appears in three or more consecutive windows and is less than -0.02 each time, then this continuous section is regarded as the bandwidth decline section, and its start and end time points and the amplitude value range are recorded. For example, if the bandwidth value of a node continuously declines within 08:00 - 08:10, it is marked as a valid section, and the bandwidth decline amplitude analysis result is generated.

[0076] Based on the bandwidth decline amplitude and the nested level growth rate in the bandwidth decline amplitude analysis result, the imbalance node screening sub-module compares whether the two conditions of the continuous increase of the nested level and the continuous decrease of the bandwidth utilization rate are simultaneously met for each node in the same window, records the imbalance nodes in the comparison process, and generates the bandwidth imbalance node set;

[0077] Based on the bandwidth decline rate in the analysis result of the bandwidth decline and the growth rate of the nested level recorded in the stack anomaly feature set, call the above two sequences one by one according to the node number, and compare whether the two constraint conditions are simultaneously met according to the time window: one is that the bandwidth utilization rate shows negative growth in three consecutive windows, and the change amplitude is less than the set bandwidth decline threshold each time. Here, it is set to 0.2, that is, a 20% utilization rate decline amplitude. For example, if the bandwidth drops from 0.75 to 0.55, the amplitude of 0.2 can be regarded as meeting the condition. The other is that the growth rate value of the nested level within the corresponding time window exceeds the growth rate reference value of 0.3. If the node meets the above two conditions, record the current node number and mark it as a bandwidth stack imbalance node. For example, within the section from 08:00 to 08:15, the bandwidth value of node X320 drops from 0.75 to 0.52, and the nested level increases from 3 to 7. The corresponding growth rate is (7 - 3) / 3 = 1.33, then it meets the dual determination conditions, and mark this node as a valid imbalance point to generate a bandwidth imbalance node set.

[0078] Please refer to Figure 6 , the risk warning output module includes:

[0079] Based on the bandwidth imbalance node set, the feature integration sub-module integrates the call frequency, call object type, and duration fields recorded for each node in the resource call log, and performs joint pairing with the stack level in the instruction nesting record and the jump times field in the path record, and classifies the resource call coincidence, instruction stack intensity, and path jump amplitude of the node within the same time period to generate multi-dimensional anomaly feature quantities;

[0080] Extract the multiple field information recorded for each node in the resource call log. First, call the resource call log, and sequentially read the node number field and its corresponding call frequency field, call object type field, and call duration field. After completing the extraction of the corresponding relationship between the fields, call the stack level information of this node in the instruction nesting record, and obtain the jump times field from the path record. Through the alignment operation of the node number and the timestamp, map the data in the three data sources to a unified time axis, and compare the multiple field values within the same time period to complete the joint pairing. During the pairing process, take the time window as the unit, and count the number of times the call object type repeats within this window for each node one by one, and calculate the resource call coincidence rate value. The calculation formula for the coincidence rate is: , where represents the resource call coincidence rate, is the number of times of calling the same resource object within the time window, is the total number of resource calls within this time window. If a node calls a resource 10 times within a time window, and 7 of them are calls to the same type of resource, then the resource call coincidence rate of this node is , while counting the changes in the corresponding stack level values and recording the maximum stack level change amplitude as the stack strength index, and then counting the fluctuation range of the path jump times as the jump amplitude reference value. For example, if the stack level of node A rises from 2 to 6 within a certain time window, the stack change amplitude is 4, and the jump times increase from 4 to 9, then the jump amplitude is 5. Generate feature combinations for each node in the above manner, classify and organize them into three index value sequences: resource overlap rate, stack change amplitude, and path jump amplitude, complete the construction of the multi-dimensional behavior state of the node, and obtain multi-dimensional abnormal feature quantities.

[0081] The policy deviation judgment sub-module calls the multi-dimensional abnormal feature quantities, performs field-level matching with the resource access permissions, instruction call frequency limits, and bandwidth allocation references in the security policy database, calculates the deviation degrees of the current node's behavior in the dimensions of permissions, frequencies, and bandwidths compared with the policy benchmarks respectively, performs label marking and classification statistics on the policy fields whose deviation degrees exceed the set thresholds, and obtains the policy deviation degree distribution result;

[0082] Match the corresponding fields in the security policy database by node, and perform field-level comparison on the resource access permission field, instruction call frequency limit field, and bandwidth allocation reference field in turn. Compare the resource call overlap rate in the abnormal feature quantity with the permission field respectively, calculate the difference and define it as the permission deviation degree value. Calculate the frequency deviation degree value after comparing the instruction stack change amplitude with the frequency limit field, and the deviation between the bandwidth usage and the reference value is the bandwidth deviation degree value. The three deviation degrees uniformly adopt the following deviation degree calculation formula: , where represents the deviation degree of the corresponding policy field, is the abnormal feature value of the current node, is the reference standard value of the corresponding field in the security policy. For example, the resource call overlap rate of node B is 0.7, while the permission tolerance overlap rate benchmark value set by the policy is 0.5, then the permission deviation degree is: , if its stack strength is 4 and the corresponding frequency benchmark value is 3, then the frequency deviation degree is , if the bandwidth usage ratio is 0.65 and the reference bandwidth configuration is 0.75, then the bandwidth deviation degree is , where the setting basis of the deviation degree threshold is to count the deviation range of historical data of similar nodes in the policy database, calculate the deviation average value and standard deviation, set the permission deviation threshold to 0.3, the frequency deviation threshold to 0.25, and the bandwidth deviation threshold to 0.2. The selection standard is the average value plus 1.5 times the standard deviation. Do not adopt the fixed value setting method to avoid static failure. Mark the fields whose deviation degrees exceed the threshold and classify and count them according to the field type. Finally, merge the types and quantities of the deviation fields of each node to obtain the policy deviation degree distribution result.

[0083] The security parameter adjustment sub-module, according to the policy deviation degree distribution result, maps the operation items to the over-limit fields in sequence by node, executes the operation of lowering the corresponding access level for permission convergence, controls the instruction frequency to the maximum threshold within the set range, aligns the bandwidth configuration value of the current node with the policy reference value, records the node numbers of all nodes where the adjustment operation is successfully executed, and generates the dynamic security protection result;

[0084] According to the policy deviation degree distribution result, taking the node as the unit, sequentially read the corresponding over-limit field items, set the operation mapping rule to correspond the field type with the specific control item, execute the operation of lowering the access level for the node with over-limit permission field, that is, set the permission level field to one level lower than the original basic level, control the instruction call frequency field of the node with over-limit frequency deviation field to the upper limit of this type in the policy table, directly replace the current configured bandwidth value of the node with over-limit bandwidth deviation field with the reference recorded in the policy table, record the node numbers of all nodes that complete the above three types of operations, aggregate and mark them by node to generate a node set, and obtain the dynamic security protection result.

[0085] The above are only the preferred embodiments of the present invention, and do not limit the present invention in other forms. Any person skilled in the art may use the technical content disclosed above to make changes or modifications into equivalent embodiments with equivalent changes and apply them to other fields. However, as long as it does not depart from the technical solution content of the present invention, any simple modification, equivalent change and modification made to the above embodiments based on the technical essence of the present invention still fall within the protection scope of the technical solution of the present invention.

Claims

1. An intelligent security protection system based on big data, characterized in that, The system includes: The access path reconstruction module obtains access logs in the network environment, identifies the abnormal frequency of access jumps and parameter fluctuations, filters out path segments with excessive jump times and abnormal parameters, and generates a set of path jump segments; The abnormal cross-detection module extracts the node numbers and corresponding operation resource parameters in the jump segments of the path jump segment set, analyzes the distribution of nodes in the abnormal area and the coincidence degree of call characteristics, and generates cross-abnormal node data; The instruction stack monitoring module calls the instruction nesting records in the communication link according to the node numbers in the cross-abnormal node data, analyzes the parameter structure, target address and callback times in the instruction call process, filters out the nodes with abnormal instruction stack growth, and generates a set of stack abnormal characteristics; The bandwidth resonance discrimination module analyzes the correlation between the change of instruction stack level and the fluctuation of bandwidth occupancy rate for the nodes in the stack abnormal characteristic set, filters out the nodes with bandwidth imbalance, and obtains a bandwidth imbalance node set; The risk warning output module analyzes the deviation of the current behavior characteristics of the nodes from the policy benchmark based on the bandwidth imbalance node set, and executes corresponding adjustment operations to generate a dynamic security protection result.

2. The intelligent security protection system based on big data according to claim 1, characterized in that, The path jump segment set includes abnormal distribution of jump times, parameter feature deviation records, and node sequence positioning information. The cross-abnormal node data includes resource call coincidence identifiers, behavior frequency synchronization marks, and abnormal area mapping results. The stack abnormal characteristic set is specifically instruction nesting level information, call structure characteristic values, and node stack offset conditions. The bandwidth imbalance node set specifically refers to bandwidth occupancy fluctuation records, path allocation imbalance identifiers, and node association relationship data. The dynamic security protection result includes permission adjustment records, instruction call limit parameters, and bandwidth allocation optimization configurations.

3. The intelligent security protection system based on big data according to claim 1, characterized in that, The access path reconstruction module includes: The node extraction sub-module obtains the big data resources of access logs in the network environment, extracts access nodes, jump types, and request parameters, counts the occurrence frequency and jump type distribution of each access node, and generates node behavior characteristic data in combination with the quantity and type of request parameters; The jump detection sub-module detects non-adjacent jump behaviors in the access node sequence based on the node behavior characteristic data, counts the jump times and jump intervals of each node segment, calls the benchmark path records of normal access behaviors, compares whether the jump times and jump intervals exceed the jump frequency benchmark interval, filters out the node segments with abnormal jumps, and obtains jump abnormal node data; The parameter comparison sub-module counts the key name differences, parameter value type changes, and parameter set scale fluctuations of the request parameters before and after the jump according to the jump abnormal node data, calls the normal request parameter distribution data, compares whether the parameter feature changes exceed the parameter fluctuation benchmark interval, filters out the node segments with excessive jump times and abnormal parameter characteristics, and generates a set of path jump segments.

4. The intelligent security protection system based on big data according to claim 3, characterized in that, The abnormal cross-detection module includes: The resource parameter association sub-module extracts the jump segment node numbers and corresponding operation resource parameters based on the path jump segment set, detects whether the operation resource parameters appear in the network security event abnormal behavior record, counts the abnormal association times of the node resource identifiers, calls the resource abnormal association benchmark value, filters the nodes with abnormal association times exceeding the benchmark value, and generates resource association abnormal data; The abnormal area matching sub-module extracts the operation time information of the corresponding nodes according to the resource association abnormal data, counts the time distribution density of the nodes in the abnormal behavior record, calls the abnormal time distribution benchmark value, compares whether the time distribution density of the nodes is higher than the density benchmark value, filters the nodes with time distribution density exceeding the density benchmark value, and obtains the abnormal area concentration data; The behavior feature comparison sub-module calls the abnormal area concentration data, extracts the resource call parameters of the corresponding nodes, counts the operation type consistency rate, call time interval coincidence rate and resource identifier matching rate of the nodes, calls the behavior feature coincidence threshold, judges whether the three indicators exceed the threshold at the same time, filters the nodes that coincide in both resource call features and behavior frequencies, and generates cross-abnormal node data.

5. The intelligent security protection system based on big data according to claim 4, characterized in that The instruction stack monitoring module includes: The instruction record extraction sub-module extracts the corresponding node numbers based on the cross-abnormal node data, calls the instruction nesting records in the communication link, obtains the instruction call sequence and nesting level information of each node, counts the instruction call times and the change range of the nesting level, and generates the instruction call sequence data; The parameter structure analysis sub-module extracts the input parameter structure and target address features of each layer of instructions according to the instruction call sequence data, counts the number of input parameter fields, parameter type distribution and the number of target address changes, calls the parameter structure benchmark interval, judges whether the parameter quantity and target address changes are abnormal, filters the nodes with abnormal parameter structures, and obtains the abnormal quantity of the parameter structure; The stack trend calculation sub-module calls the abnormal quantity of the parameter structure, analyzes the growth of the nesting level during the continuous call process, calculates the stack level growth rate of each node, calls the stack growth threshold, judges whether the growth rate exceeds the threshold, filters the nodes with abnormal stack level growth, and generates the stack abnormal feature set.

6. The intelligent security protection system based on big data according to claim 5, characterized in that The bandwidth resonance discrimination module includes: The bandwidth usage record extraction sub-module obtains the bandwidth allocation upper limit of the network path where the node is located and the usage traffic within the corresponding time period for the nodes in the stack abnormal feature set, calls the time stamps and node IDs recorded in the instruction nesting records, aligns the time stamps and maps them to the sampling time points of the bandwidth records, matches the usage traffic and allocated bandwidth through the corresponding node IDs, and calculates the bandwidth occupancy rate of each time period as the bandwidth usage rate sequence of the current node; The hierarchical association analysis sub-module pairs the nested level of each instruction with the bandwidth utilization rate at the same time point in a sequence alignment manner according to the bandwidth utilization rate sequence and the nested level change sequence of nodes in the stack anomaly feature set, constructs a joint sequence in chronological order, calculates the difference between the nested level growth rate and the bandwidth utilization rate change amplitude within each window, screens the continuous decline section of the bandwidth occupancy rate, and generates the bandwidth decline amplitude analysis result; The unbalanced node screening sub-module, based on the bandwidth decline amplitude and the nested level growth rate in the bandwidth decline amplitude analysis result, compares whether the two conditions of continuous increase in the nested level and continuous decrease in the bandwidth utilization rate are simultaneously met within the same window for each node one by one, records the unbalanced nodes during the comparison process, and generates a bandwidth unbalanced node set.

7. The intelligent security protection system based on big data according to claim 6, characterized in that The risk warning output module includes: The feature integration sub-module, based on the bandwidth unbalanced node set, integrates the call frequency, call object type, and duration fields recorded for each node in the resource call log, and performs joint pairing with the stack level in the instruction nesting record and the jump times field in the path record, classifies the resource call coincidence, instruction stack intensity, and path jump amplitude of the node within the same time period, and generates multi-dimensional anomaly feature quantities; The policy deviation judgment sub-module calls the multi-dimensional anomaly feature quantities, performs field-level matching with the resource access permissions, instruction call frequency limits, and bandwidth allocation references in the security policy database, calculates the deviation degrees of the current behavior of the node in the dimensions of permissions, frequency, and bandwidth compared with the policy benchmark respectively, performs label marking and classification statistics on the policy fields with deviation degrees exceeding the set threshold, and obtains the policy deviation degree distribution result; The security parameter adjustment sub-module, according to the policy deviation degree distribution result, maps the operation items to the over-limit fields in sequence for each node, performs the operation of lowering the corresponding access level for permission convergence, controls the instruction frequency to the maximum threshold within the set range, aligns the current node's bandwidth configuration value with the policy reference value, records the node numbers of all successfully executed adjustment operations, and generates the dynamic security protection result.

Citation Information

Patent Citations

  • Remote office network security protection method and system based on big data

    CN119728311A

  • Method and apparatus for identifying abnormal calling of API gateway, device, and product

    WO2023093100A1