Financial risk intelligent early warning method and system based on big data technology

By evaluating the MITM attack level with the superior sequence diagram method, the problem of lack of in-depth analysis and comprehensive evaluation in the existing technology is solved, and effective prevention and rapid response to man-in-the-middle attacks is achieved.

CN120263477AInactive Publication Date: 2025-07-04JIANGSU VOCATION & TECHNICAL COLLEGE OF FINANCE & ECONOMICS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510414012.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-07-04
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing technology lacks in-depth analysis of the network layer and application layer in traffic monitoring, and cannot comprehensively evaluate the importance of different protection methods, resulting in possible vulnerabilities or redundancy, and cannot effectively prevent man-in-the-middle attacks.

Method used

By monitoring traffic, combining DNS spoof detection, evaluating risk levels, and using the superior sequence diagram method to judge the weight of each means, selecting appropriate protection measures, and comprehensively assessing the MITM attack level.

Benefits of technology

It realizes timely detection of potential security threats, improves protection flexibility and response speed, and avoids excessive or insufficient protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263477A_ABST
    Figure CN120263477A_ABST
Patent Text Reader

Abstract

The invention discloses a financial risk intelligent early warning method and system based on a big data technology, relates to the technical field of intelligent early warning, and is used for solving the problems that deep analysis of details in a specific network layer, an application layer and interaction of the network layer and the application layer is lacked during flow monitoring, and risk assessment only considers flow magnitude or abnormal behaviors, so that the risk assessment efficiency is high. The problems that multi-level features of attacks are not considered, comprehensive analysis on multi-dimensional detection results is lacked, weight distribution cannot be effectively carried out according to detection capabilities and protection efficiencies of different means, and possible loopholes or redundancy is caused are solved. The current security risk is dynamically evaluated by monitoring the flow in real time and combining detection methods such as DNS cheating, potential security threats are found in time, and the protection flexibility and response speed are improved. According to the method, the risk level and the detection means are combined, proper protection measures are selected, the MITM attack level is comprehensively evaluated, the weight of each means is judged by using an optimal sequence diagram method, and the relative importance of each detection means in overall safety protection is quantified.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of intelligent early warning, and more specifically, to an intelligent financial risk early warning method and system based on big data technology. Background Art

[0002] Using certificate verification, traffic tampering detection, DNS hijacking check, latency anomaly, and two-way authentication selection to jointly verify man-in-the-middle attacks is a common preventive measure for intelligent early warning of man-in-the-middle attacks. Combining multiple aspects such as the network layer, application layer, and authentication mechanism effectively increases the difficulty for attackers to conduct man-in-the-middle attacks and ensures the security of communication. Through these multi-level protection measures, the difficulty for attackers to conduct man-in-the-middle attacks can be effectively increased, ensuring the confidentiality, integrity of data, and reliability of authentication, thereby enhancing the overall security.

[0003] The existing technologies have the following deficiencies:

[0004] During traffic monitoring, it may only stay at the analysis of traffic volume or simple protocol anomaly detection, lacking in-depth analysis of the details in the specific network layer, application layer, and their interactions, and unable to comprehensively judge whether it is threatened by a MITM attack. Risk assessment is often one-dimensional, possibly only considering traffic volume or abnormal behavior, and failing to consider the multi-level characteristics of attacks, such as factors like DNS hijacking and latency anomaly. Most existing technologies may only rely on a certain means alone, lacking the coordinated application of multiple protection measures and the comprehensive analysis of multi-dimensional detection results. Existing protection technologies often lack a reasonable assessment of the importance of different protection means and are unable to effectively allocate weights based on the detection capabilities and protection effectiveness of different means, resulting in possible vulnerabilities or redundancies.

[0005] In view of the above problems, the present invention proposes a solution. Summary of the Invention

[0006] To overcome the above-mentioned defects of the existing technologies, embodiments of the present invention provide an intelligent financial risk early warning method and system based on big data technology to solve the problems raised in the above background art.

[0007] To achieve the above object, the present invention provides the following technical solutions:

[0008] An intelligent financial risk early warning method and system based on big data technology, including the following steps:

[0009] Step S1: Monitor the traffic, judge whether the protocol is abnormal, and combine the DNS spoofing detection parsing results to judge the current degree of risk.

[0010] Step S2: Based on the degree level of the risk combined with the size feature risk level, select the corresponding means combination for certificate verification, traffic tampering detection, DNS hijacking check, latency anomaly, and two-way authentication to evaluate the MITM attack level;

[0011] Step S3: Combine the detection capabilities and protection effectiveness of the selected means above to judge the relative importance, and use the preference ranking organization method for enrichment evaluation (PROMETHEE) to judge the weights corresponding to the selected means above;

[0012] Step S4: Based on the weights of the selected means, comprehensively calculate the MITM attack score, judge the final warning level, and perform screening and marking.

[0013] In a preferred embodiment, Step S1 includes the following content:

[0014] Monitor the traffic, obtain and record the protocol features and size features of the traffic, comprehensively judge the protocol feature risk and size feature risk to determine whether there are potential dangerous or abnormal behaviors and the feature risk level;

[0015] Calculate the traffic proportion of each protocol within a specific time period, and compare it with the protocol distribution under normal conditions. If it deviates significantly from the normal distribution, mark the protocol feature risk according to the deviation amplitude;

[0016] Judge whether the traffic is abnormal by calculating the average packet size of the traffic, the change rate of the total traffic, the size of a single data packet, etc. If the fluctuation amplitude or size of the traffic exceeds the preset threshold, mark the size feature risk according to the fluctuation amplitude;

[0017] Combine the feature risk and size feature risk to judge the feature risk level;

[0018] Calculate the Manhattan distance between the actual protocol behavior and the standard protocol behavior. Represent the actual protocol behavior feature vector as: A = (a1, a2, a3,..., a n ), represent the standard protocol behavior feature vector as: B = (b1, b2, b3,..., b n ), and the calculation formula of the Manhattan distance D is expressed as: Among them, a n is the actual protocol behavior feature, b n is the standard protocol behavior feature, and n is the number of features;

[0019] Obtain the expected IP address. After obtaining the DNS response, check whether the IP address in the response is consistent with the expected IP address. If it is consistent, return normal; if it is inconsistent, it is considered that there is a potential DNS spoofing attack;

[0020] After receiving whether the feature risk level, Manhattan distance, and DNS response address are consistent, define the feature risk level, Manhattan distance, and whether the DNS response address is consistent as input variables, and divide them into different fuzzy sets respectively;

[0021] Define the degree level of risk as the output variable and divide it into a fuzzy set;

[0022] Formulate fuzzy rules to describe the influence of the definition of the feature risk level, Manhattan distance, and whether the DNS response address is consistent on the degree level of risk;

[0023] Perform fuzzy reasoning according to the fuzzy rules to determine the degree level of risk.

[0024] In a preferred embodiment, step S2 includes the following content:

[0025] Determine the MITM attack risk based on the degree level of risk in combination with the size feature risk level. The rules are as follows:

[0026] Rule 1: When the degree level of risk and the size feature risk level are of the same level, that is, the MITM attack risk is of this level;

[0027] Rule 2: When the degree level of risk and the size feature risk level are of different levels and are adjacent levels, the MITM attack risk is of the higher level;

[0028] Rule 3: When the degree level of risk and the size feature risk level are of different levels and are not adjacent levels, the MITM attack risk is of the medium level;

[0029] According to different risk levels, select suitable technology combination rules as follows:

[0030] Low risk: Use certificate verification + DNS hijacking check;

[0031] Medium risk: Use certificate verification + traffic tampering detection + latency anomaly;

[0032] High risk: Use two-way authentication analysis + certificate verification + traffic tampering detection

[0033] In a preferred embodiment, step S3 includes the following content:

[0034] For the above five means, evaluate their relative importance according to the detection ability and protection effectiveness, and assign scores to them respectively:

[0035] Certificate verification: Detection ability 3 points, protection effectiveness 4 points;

[0036] Traffic tampering detection: Detection ability 4 points, protection effectiveness 4 points;

[0037] DNS hijacking check: Detection ability: 3 points, protection effectiveness: 3 points;

[0038] Abnormal latency: Detection ability: 2 points, protection effectiveness: 2 points;

[0039] Two-way authentication: Detection ability: 5 points, protection effectiveness: 5 points;

[0040] Add the assigned score of the detection ability and the assigned score of the protection effectiveness of each measure to obtain a comparison score, compare the sizes of the comparison scores of each measure, and determine the weight value of each measure

[0041] In a preferred embodiment, step S4 includes the following content:

[0042] Perform a weighted average calculation on the battery status of each functional part according to the weight value of the battery status distribution coefficient of each functional part to obtain the overall battery status. The formula can be expressed as: R overall = R A × w A + R B × w B + R C × w C , where: R A , R B , R C are the comparison score values obtained by adding the detection ability and protection effectiveness of means A, B, and C respectively, and w A , w B , w C are the weight values corresponding to means A, B, and C respectively;

[0043] Set a threshold for the MITM attack score to judge and screen and mark the final warning level. To judge the final warning level, it is necessary to set a reasonable threshold according to the score of the MITM attack. The warning level is divided into three levels, and two different thresholds T1 and T2 are set to determine the severity of the current MITM attack;

[0044] When R overall ≤ T1, screen and mark it as a low MITM attack risk;

[0045] When T1 < R overall < T2, screen and mark it as a medium MITM attack risk;

[0046] When R overall ≥ T1, screen and mark it as a high MITM attack risk.

[0047] The technical effects and advantages of a financial risk intelligent early warning method and system based on big data technology according to the present invention:

[0048] By monitoring traffic in real time and combining detection methods such as DNS spoofing, dynamically evaluate the current security risks, timely detect potential security threats, and improve the flexibility and response speed of protection. Combine the risk level with detection means, select appropriate protection measures, comprehensively evaluate the MITM attack level, and take different levels of protection measures according to the severity of the attack to avoid over-protection or under-protection. Use the analytic hierarchy process method to determine the weights of each means and quantify the relative importance of each detection means in the overall security protection. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] Figure 1 It is a schematic structural diagram of a financial risk intelligent early warning method based on big data technology of the present invention.

[0050] Figure 2 It is a schematic structural diagram of a financial risk intelligent early warning system based on big data technology of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0051] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0052] Embodiment 1

[0053] The present invention discloses a financial risk intelligent early warning method and system based on big data technology, including the steps of:

[0054] Step S1: Monitor the traffic, judge whether the protocol is abnormal, and combine the DNS spoofing detection and analysis results to judge the degree of risk currently suffered;

[0055] Step S2: According to the degree of risk combined with the size feature risk level, select corresponding means combinations for certificate verification, traffic tampering detection, DNS hijacking check, latency anomaly, and mutual authentication to evaluate the MITM attack level;

[0056] Step S3: Combine the detection capabilities and protection effectiveness of the selected means above to judge the relative importance, and use the analytic hierarchy process method to judge the weights corresponding to the selected means above;

[0057] Step S4: Comprehensively calculate the MITM attack score according to the weights of the selected means, judge the final early warning level, and perform screening and marking.

[0058] In step S1, monitor the traffic, judge whether the protocol is abnormal, and combine the DNS spoofing detection and analysis results to judge the degree of risk currently suffered. The specific content includes:

[0059] Monitor the traffic, obtain and record the protocol characteristics and size characteristics of the traffic, and comprehensively judge the protocol characteristic risk and size characteristic risk to determine whether there are potential dangers or abnormal behaviors and the characteristic risk level.

[0060] The protocol characteristics refer to the protocol types used in the traffic and related communication behaviors. If there are unconventional protocols or abnormal protocol combinations, it may be a sign of malicious behavior. If unknown or uncommon protocols are frequently used in the traffic, it may indicate the existence of some network attacks or malicious behaviors.

[0061] Calculate the traffic proportion of each protocol within a specific time period and compare it with the protocol distribution under normal circumstances. If it deviates significantly from the normal distribution, mark the protocol characteristic risk according to the deviation amplitude.

[0062] The size characteristics refer to the size distribution of the traffic, such as the size of a single data packet, the size of the total traffic, and the size of requests and responses, etc. By analyzing the size characteristics of the traffic, it is possible to identify whether there are abnormal activities. Abnormal large traffic fluctuations may indicate malicious traffic, such as DDoS attacks. Rapid, excessive or concentrated size changes in the traffic at a certain time period usually indicate possible attack activities.

[0063] Judge whether the traffic is abnormal by calculating the average packet size of the traffic, the change rate of the total traffic, the size of a single data packet, etc. If the fluctuation amplitude or size of the traffic exceeds the preset threshold, mark the size characteristic risk according to the fluctuation amplitude.

[0064] It should be noted that the preset threshold needs to be adjusted according to the characteristics of the financial data traffic, which can be set by those skilled in the art according to the actual situation and will not be elaborated here.

[0065] Combine the characteristic risk and the size characteristic risk to judge the characteristic risk level.

[0066] The actual protocol behavior refers to the specific manifestation form of protocol communication in the actual network environment, including parameters such as the number and size of data packets at different time points; the standard protocol behavior refers to the behavior performance that the protocol should have under ideal conditions and is used to check whether the protocol follows the predetermined protocol standard. The difference between the actual behavior of the protocol and the standard protocol behavior can reveal whether there are abnormalities in the protocol.

[0067] Represent the actual protocol behavior feature vector as: A = (a1, a2, a3,..., a n ) and represent the standard protocol behavior feature vector as: B = (b1, b2, b3,..., b n ). The calculation formula of the Manhattan distance D is expressed as: where an is the actual protocol behavior feature, b n is the standard protocol behavior feature, and n is the number of features.

[0068] It should be noted that the protocol standard behavior is to check whether the protocol follows the predetermined protocol standard. The Manhattan distance is a common distance metric method used to measure the difference between two data points. The standard behavior of the protocol is used as a reference standard, and the Manhattan distance between the traffic feature and these standards is calculated. The similarity is measured by calculating the following content. The smaller the calculated value, the more similar the behavior of the traffic is to the behavior of the standard protocol. On the contrary, the greater the difference, it may indicate a protocol anomaly.

[0069] Obtain the expected IP address, which can be an IP address in a whitelist or a correct IP obtained through a trusted method. Parse the DNS query request. When the user's device (such as a browser or an application) requests to resolve a certain domain name, the DNS server will return the IP address corresponding to the domain name.

[0070] After obtaining the DNS response, check whether the IP address in the response is consistent with the expected IP address. If it is consistent, return normal; if it is inconsistent, it is considered that there is a potential DNS spoofing attack.

[0071] After receiving the feature risk level, the Manhattan distance, and whether the DNS response address is consistent, define the feature risk level, the Manhattan distance, and whether the DNS response address is consistent as input variables, and divide them into different fuzzy sets respectively.

[0072] For example, "Low", "Medium", "High" for the feature risk level, "Low", "Medium", "High" for the Manhattan distance, and "Yes", "No" for whether the DNS response address is consistent.

[0073] Define the degree level of risk as the output variable and divide it into a fuzzy set. For example, "Low", "Medium", "High" for the degree level of risk.

[0074] Formulate a set of fuzzy rules to describe the influence of different input variables on the output variable. The definition of the rules can be based on professional knowledge or obtained through data analysis and experiments. For example:

[0075] Mark the feature risk level as G, the Manhattan distance as D, whether the DNS response address is consistent as S, and the degree level of risk as Grade, then it can be defined

[0076] Rule 1: IF (G is High) AND (D is High) AND (S is No) THEN (Grade is High)

[0077] Rule 2: IF (G is Low) AND (D is Low) AND (S is Yes) THEN (Grade is Low) ...

[0079] A solution for determining the degree level of risk through fuzzy inference based on fuzzy rules.

[0080] It should be noted that the division of fuzzy sets can be adjusted according to the actual situation. For example, although four fuzzy sets are used as an example in this embodiment, in fact, the characteristic risk level, Manhattan distance, whether the DNS response addresses are consistent, and the degree level of risk can be divided into more than four sets to facilitate more accurate adjustment according to different temperatures.

[0081] Furthermore, for the judgment of high, medium, and low levels of the characteristic risk level, Manhattan distance, and whether the DNS response addresses are consistent, thresholds can be set for judgment according to the actual situation, which will not be elaborated here.

[0082] In step S2, based on the degree level of risk combined with the size characteristic risk level, corresponding means combinations are selected for evaluating the MITM attack level for certificate verification, traffic tampering detection, DNS hijacking check, latency anomaly, and mutual authentication. The specific content includes:

[0083] Determine the MITM attack risk based on the degree level of risk combined with the size characteristic risk level. The rules are as follows:

[0084] Rule 1: When the degree level of risk and the size characteristic risk level are of the same level, that is, the MITM attack risk is at that level. For example, when the degree level of risk and the size characteristic risk level are both high risk, the MITM attack risk is also high risk;

[0085] Rule 2: When the degree level of risk and the size characteristic risk level are of different levels and are adjacent levels, the MITM attack risk is at the higher level. For example, when the degree level of risk is high and the size characteristic risk level is medium risk, the MITM attack risk is high risk;

[0086] Rule 3: When the degree level of risk and the size characteristic risk level are of different levels and are not adjacent levels, the MITM attack risk is at the medium level. For example, when the degree level of risk is high and the size characteristic risk level is low risk, the MITM attack risk is medium risk.

[0087] The advantages and disadvantages of certificate verification, traffic tampering detection, DNS hijacking detection, latency anomalies, and mutual authentication are analyzed as follows:

[0088] 1. Advantages of certificate verification:

[0089] Effectiveness: By verifying the certificate chain, the problem of forged certificates can be effectively prevented;

[0090] Widespread support: Most TLS / SSL communications have certificate verification, which can ensure the legitimacy of the identities of both communication parties;

[0091] Security: It can effectively prevent MITM attacks, especially those using forged certificates.

[0092] Disadvantages of certificate verification:

[0093] Dependency: It is necessary to ensure the security of certificate management and updates for both the client and the server. Expired or tampered certificates may be exploited by attackers;

[0094] Complexity: In some cases, the configuration and management of certificate verification are relatively complex.

[0095] 2. Advantages of traffic tampering detection:

[0096] Tampering detection: It can detect data modifications by a man-in-the-middle, such as injecting malicious scripts or modifying transmitted data;

[0097] Real-time: By analyzing network traffic, malicious tampering can be quickly detected.

[0098] Disadvantages of traffic tampering detection:

[0099] Performance overhead: Traffic monitoring may increase the burden on the system, especially in high-traffic networks;

[0100] Disguise and concealment: Some advanced MITM attacks may encrypt or disguise the traffic, increasing the difficulty of detection.

[0101] 3. Advantages of DNS hijacking detection:

[0102] Highly targeted: Specifically for attacks such as DNS hijacking, by checking whether the domain name resolution process has been tampered with, some specific MITM attacks can be effectively prevented;

[0103] Easy to implement: Compared with other network-level attacks, DNS hijacking detection usually does not require overly complex hardware or system support.

[0104] Disadvantages of DNS hijacking detection:

[0105] Limitations: It is only applicable to detecting MITM attacks related to DNS and cannot effectively detect attacks in encrypted traffic;

[0106] DNS configuration dependency: If the DNS server itself is attacked or maliciously configured, the inspection becomes ineffective.

[0107] 4. Advantages of latency anomaly detection:

[0108] Low cost: By analyzing latency anomalies to detect potential attack activities on the network, the cost is relatively low and does not require excessive hardware support;

[0109] Easy to integrate: It can be combined with existing network monitoring tools for real-time monitoring.

[0110] Disadvantages of latency anomaly detection:

[0111] False positives: Network latency can be affected by various factors, which may lead to false alarms, especially in complex network environments;

[0112] Insufficient sensitivity: Some MITM attacks may not significantly increase latency, so relying on latency anomaly detection may not be able to fully detect MITM attacks.

[0113] 5. Advantages of mutual authentication analysis:

[0114] High security: Mutual authentication can ensure that both parties authenticate their identities, preventing intrusions by forgers;

[0115] Preventing impersonation: By requiring both the client and the server to provide valid certificates, MITM attacks can be greatly prevented.

[0116] Disadvantages of mutual authentication analysis:

[0117] Complexity: It is necessary to configure mutual certificate verification for the client and the server, which is relatively complex and may increase the management difficulty of the system;

[0118] Compatibility issues: Some clients may not support mutual authentication, resulting in the inability to fully use this method.

[0119] Based on the advantages and disadvantages of the above methods, suggestions for combining when evaluating the level of MITM attacks are formulated. According to different risk levels, the appropriate technology combination rules are as follows:

[0120] Low risk (such as regular Internet browsing, low-sensitivity data transmission): Use certificate verification + DNS hijacking check. For low-risk environments, basic certificate verification is sufficient to ensure the security of communication, and DNS hijacking check can effectively prevent DNS-based MITM attacks. Traffic tampering detection and mutual authentication may not require much investment of resources.

[0121] Medium risk (for sensitive operations such as electronic payment, login, etc.): Use certificate verification + traffic tampering detection + latency anomaly. In a medium-risk environment, certificate verification remains the basis. Traffic tampering detection and latency anomaly detection can further enhance the protection against MITM attacks, especially for attacks that do not pass through DNS. Latency anomaly helps detect some possible MITM attacks.

[0122] High risk (for financial transactions, government or enterprise internal communications): Use two-way authentication analysis + certificate verification + traffic tampering detection. For a high-risk environment, two-way authentication is crucial as it provides the highest level of authentication and prevents any man-in-the-middle from posing as one of the communicating parties. Combining certificate verification and traffic tampering detection can ensure data security during communication and further reduce the risk of MITM attacks.

[0123] In step S3, judge the relative importance by combining the detection capabilities and protection effectiveness of the selected means above, and use the preference ranking method to judge the weights corresponding to the selected means above. The specific content includes:

[0124] For the above five means, evaluate their relative importance according to the detection capabilities and protection effectiveness, and assign scores to them respectively:

[0125] Certificate verification:

[0126] Detection capability: 3 points. It can verify the security of communication, but may fail if the certificate chain is forged or the user ignores certificate errors.

[0127] Protection effectiveness: 4 points. It ensures the security of encrypted communication and is the basis for protecting against MITM attacks.

[0128] Traffic tampering detection:

[0129] Detection capability: 4 points. It can detect tampering behaviors in most network communications.

[0130] Protection effectiveness: 4 points. It can detect attacks that have occurred, but cannot directly prevent attacks.

[0131] DNS hijacking check:

[0132] Detection capability: 3 points. It can identify the attack method of DNS hijacking and prevent attackers from guiding traffic by tampering with DNS resolution.

[0133] Protection effectiveness: 3 points. It is applicable to specific ways of MITM attacks, but cannot cover all types of MITM attacks.

[0134] Latency anomaly:

[0135] Detection capability: 2 points. It can detect network latency changes, but may be interfered by other network problems.

[0136] Protection effectiveness: 2 points. It is only used as an auxiliary detection method and cannot directly prevent MITM attacks.

[0137] Mutual authentication:

[0138] Detection ability: 5 points. By verifying the identities of both parties, it can effectively prevent forged identities and MITM attacks;

[0139] Protection effectiveness: 5 points. Mutual authentication can effectively prevent MITM attacks, especially for high-risk scenarios.

[0140] Add the assigned scores of the detection ability and the assigned scores of the protection effectiveness of each method to obtain a comparison score. Comparing the sizes of the comparison scores of each method, obviously, the method with a larger comparison score deserves more attention and should have a greater weight in the consideration of methods. This will not be elaborated here.

[0141] Specifically, the weight assignment of the comparison scores of each method is carried out according to the priority diagram method as shown in Table 1 below:

[0142]

[0143] Table 1

[0144] It should be noted that in Table 1, means A, B, and C correspond to the three selected means in this embodiment. After sorting each means according to the sizes of the detection ability and the protection effectiveness, they are respectively corresponded to means A, B, and C in descending order. In this table, the TTL index is used as a weighting factor. By determining the relative importance of different means in the MITM attack score, the sum of the scores assigned to the relative importance of each means after comparison is used to reasonably calculate and evaluate the overall battery state, and the detection ability and the protection effectiveness of each means are considered when calculating the weights of each region.

[0145] In step S4, calculate the MITM attack score comprehensively according to the weights of the selected means, and judge the final warning level for screening and marking. The specific content includes:

[0146] Perform a weighted average calculation on the battery states of each functional part according to the weight values of the battery state distribution coefficients of each functional part to obtain the overall battery state. The formula can be expressed as: R overall = R A × w A + R B × w B + R C × w C , where: R A , R B , R CThey are the comparative score values obtained by adding the detection capabilities and protection efficacies of means A, B, and C respectively, where w A , w B , w C are the weight values corresponding to means A, B, and C respectively.

[0147] Set a threshold for the MITM attack score to judge and screen-mark the final warning level. To judge the final warning level, a reasonable threshold needs to be set according to the score of the MITM attack. The warning level is divided into three levels, and two different thresholds T1 and T2 are set to determine the severity of the current MITM attack.

[0148] When R overall ≤ T1, the screening mark is a low MITM attack risk;

[0149] When T1 < R overall < T2, the screening mark is a medium MITM attack risk;

[0150] When R overall ≥ T1, the screening mark is a high MITM attack risk.

[0151] It should be noted that the thresholds T1 and T2 are set by professionals in the field according to the actual situation and data, representing different warning levels, which will not be elaborated here.

[0152] Embodiment 2

[0153] Figure 2 This invention provides an intelligent financial risk early warning system based on big data technology, including: a risk prediction module, a means selection module, a weight calculation module, and a marking and warning module:

[0154] Risk prediction module: Monitor the traffic, judge whether the protocol is abnormal, and combine the DNS spoofing detection and analysis results to judge the degree level of the current risk;

[0155] Means selection module: Based on the degree level of the risk and combined with the size feature risk level, select the corresponding means combination for certificate verification, traffic tampering detection, DNS hijacking check, latency anomaly, and mutual authentication to evaluate the MITM attack level;

[0156] Weight calculation module: Combine the detection capabilities and protection efficacies of the above-selected means to judge the relative importance, and use the preference ranking method to judge the weights corresponding to the above-selected means;

[0157] Marking and warning module: Based on the weights of the selected means, comprehensively calculate the MITM attack score, judge the final warning level, and conduct screening and marking.

[0158] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data for software simulation to get a formula that is closest to the actual situation. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.

[0159] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product.

[0160] Those of ordinary skill in the art can realize that the modules and algorithm steps of each example described in combination with the embodiments disclosed in this article can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application of the technical solution and the inventive constraints. Professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0161] In addition, the functional modules in each embodiment of this application can be integrated into one processing module, or each module can exist physically alone, or two or more modules can be integrated into one module.

[0162] As described above, the above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in this application, and all should be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

[0163] Finally: The above is only the preferred embodiment of the present invention and is not used to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. An intelligent financial risk early warning method based on big data technology, characterized in that, Including the steps: Step S1: Monitor the traffic, determine whether the protocol is abnormal, and combine the DNS spoofing detection parsing results to judge the current risk level. Step S2: Based on the risk level and combined with the size feature risk level, select the corresponding means combination for certificate verification, traffic tampering detection, DNS hijacking check, latency anomaly, and mutual authentication to evaluate the MITM attack level. Step S3: Combine the detection capabilities and protection effectiveness of the selected means above to judge the relative importance, and use the preference ranking organization method for enrichment evaluation (PROMETHEE) to judge the weights corresponding to the selected means above. Step S4: Based on the weights of the selected means, comprehensively calculate the MITM attack score, judge the final warning level, and perform screening and marking.

2. A financial risk intelligent early warning method based on big data technology according to claim 1, characterized in that: Monitor the traffic, obtain and record the protocol features and size features of the traffic, comprehensively judge the protocol feature risk and size feature risk to determine whether there are potential dangers or abnormal behaviors and the feature risk level. Calculate the traffic proportion of each protocol within a specific time period, and compare it with the protocol distribution under normal conditions. If it deviates significantly from the normal distribution, mark the protocol feature risk according to the deviation amplitude. Judge whether the traffic is abnormal by calculating the average packet size of the traffic, the change rate of the total traffic, the size of a single data packet, etc. If the fluctuation amplitude or size of the traffic exceeds the preset threshold, mark the size feature risk according to the fluctuation amplitude. Combine the feature risk and size feature risk to judge the feature risk level. Calculate the Manhattan distance between the actual protocol behavior and the standard protocol behavior. Represent the actual protocol behavior feature vector as: A = (a1, a2, a3,..., a n ), and represent the standard protocol behavior feature vector as: B = (b1, b2, b3,..., b n ). The calculation formula for the Manhattan distance D is expressed as: where a n is the actual protocol behavior feature, b n is the standard protocol behavior feature, and n is the number of features; Obtain the expected IP address. After obtaining the DNS response, check whether the IP address in the response is consistent with the expected IP address. If it is consistent, return normal; if it is inconsistent, it is considered that there is a potential DNS spoofing attack. After receiving the feature risk level, Manhattan distance, and whether the DNS response address is consistent, define the feature risk level, Manhattan distance, and whether the DNS response address is consistent as input variables, and divide them into different fuzzy sets respectively. Define the risk level as the output variable and divide it into a fuzzy set. Formulate fuzzy rules to describe the influence of the feature risk level, Manhattan distance, and whether the DNS response address is consistent on the risk level. Perform fuzzy reasoning according to the fuzzy rules to determine the risk level.

3. A financial risk intelligent early warning method based on big data technology according to claim 2, characterized in that: Determine the MITM attack risk based on the risk level and combined with the size feature risk level. The rules are as follows: Rule 1: When the risk level and the size feature risk level are the same level, the MITM attack risk is this level. Rule 2: When the risk level and the size feature risk level are different levels and are adjacent levels, the MITM attack risk is the higher level. Rule 3: When the risk level and the size feature risk level are different levels and are not adjacent levels, the MITM attack risk is the medium level. According to different risk levels, select the appropriate technology combination. The rules are as follows: Low risk: Use certificate verification + DNS hijacking check; Medium risk: Use certificate verification + traffic tampering detection + latency anomaly; High risk: Use mutual authentication analysis + certificate verification + traffic tampering detection.

4. The intelligent financial risk early warning method based on big data technology according to claim 3, characterized in that ; For the above five measures, evaluate their relative importance according to the detection ability and protection effectiveness, and assign scores to them respectively: Certificate verification: Detection ability: 3 points, protection effectiveness: 4 points; Traffic tampering detection: Detection ability: 4 points, protection effectiveness: 4 points; DNS hijacking check: Detection ability: 3 points, protection effectiveness: 3 points; Latency anomaly: Detection ability: 2 points, protection effectiveness: 2 points; Mutual authentication: Detection ability: 5 points, protection effectiveness: 5 points; Add the detection ability score value and the protection effectiveness score value of each measure to obtain a comparison score, compare the sizes of the comparison scores of each measure, and determine the weight value of each measure.

5. The intelligent financial risk early warning method based on big data technology according to claim 4, characterized in that: The battery status of each functional part is weighted and averaged according to the weight value of the battery status distribution coefficient of each functional part to obtain the overall battery status. The formula can be expressed as: R overall = R A × w A + R B × w B + R C × w C , where: R A , R B , R C are the comparative score values obtained by adding the detection capabilities and protection efficiencies of means A, B, and C respectively, and w A , w B , w C are the weight values corresponding to means A, B, and C respectively; Set a threshold for the MITM attack score to judge the final early warning level for screening and marking. In order to judge the final early warning level, it is necessary to set a reasonable threshold according to the score of the MITM attack. The early warning level is divided into three levels, and two different thresholds T1 and T2 are set to determine the severity of the current MITM attack; When R overall ≤ T1, the screening flag is for low MITM attack risk; When T1 < R overall < T2, the screening marks the medium MITM attack risk; When R overall ≥ T1, the screening flag is for high MITM attack risk.

6. An intelligent financial risk early warning system based on big data technology, which is used to implement an intelligent financial risk early warning method based on big data technology according to any one of claims 1-5, and is characterized in that, Including: Risk prediction module, means selection module, weight calculation module and marking early warning module; Risk prediction module: Monitor the traffic, judge whether the protocol is abnormal, and combine the DNS spoofing detection and analysis results to judge the degree of risk at present; Means selection module: Select the corresponding means combination to evaluate the MITM attack level for certificate verification, traffic tampering detection, DNS hijacking check, latency anomaly and mutual authentication according to the degree of risk and the size characteristic risk level; Weight calculation module: Judge the relative importance by combining the detection ability and protection effectiveness of the selected means above, and use the preference ranking method to judge the weights corresponding to the selected means above; Marking early warning module: Comprehensively calculate the MITM attack score according to the weights of the selected means, judge the final early warning level for screening and marking.