Computer network security protection method and system

By building a variety of protection strategies and attack analysis modules, the protection strategies are identified and adjusted in real time, the problem of single computer network security protection strategies is solved, and flexible response to diversified network attacks is achieved, and security and reliability are improved.

CN120281522APending Publication Date: 2025-07-08BEIJING DONGFANG MEASUREMENT & TEST INST
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510392558.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

The existing computer network security protection strategies are relatively single, and it is difficult to deal with diversified and changing cyber attacks, resulting in insufficient security and reliability.

Method used

Build a variety of protection policies, including firewall type settings, firewall rule settings, resource restriction division and encrypted transmission. Combined with the attack analysis module, train the attack type identification model, adjust the protection policies in real time, and track the attackers.

Benefits of technology

By pre-constructing a variety of protection strategies and real-time adjustments, we can flexibly respond to diversified network attacks, significantly improving the reliability and security of computer network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281522A_ABST
    Figure CN120281522A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, in particular to a computer network security protection method and system.The computer network security protection system comprises a protection strategy construction module, an attack analysis module, a protection strategy switching module and an attack tracking module; identifying the latest attack by using an attack type identification model to obtain a specific attack type; the protection strategy switching module is used for correspondingly adjusting the protection strategy based on the attack type; the attack tracking module is used for tracking an attacker and notifying personnel to process; therefore, various protection strategies are preset, then type identification is carried out on the attacks, and after the specific type is identified, the corresponding protection strategy is directly switched to carry out network security protection, so that the diversity of network attacks is flexibly handled, and the reliability and security of computer network security are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular, to a computer network security protection method and system. Background Art

[0002] In computer usage, network security is particularly important, directly related to the confidentiality, integrity, and availability of organizational and personal information. In the digital age, the network has become the core platform for information exchange and business operations, but this has also significantly increased the risk of network attacks. Security protection can effectively resist threats such as hacker intrusion, data theft, and malware infection, protect critical infrastructure from damage, and ensure business continuity and the security of data assets.

[0003] In the aforementioned prior art, the current computer network security protection strategies are relatively single, usually only using a certain type of firewall or firewall rules, while the forms of network attacks are diverse and constantly changing. A single security strategy often fails to comprehensively address various threats and cannot improve the reliability and security of computer network security. Summary of the Invention

[0004] The purpose of the present invention is to provide a computer network security protection method and system to solve the problem that in the prior art, the current computer network security protection strategies are relatively single, usually only using a certain type of firewall or firewall rules, while the forms of network attacks are diverse and constantly changing. A single security strategy often fails to comprehensively address various threats and cannot improve the reliability and security of computer network security.

[0005] To achieve the above purpose, the present invention provides a computer network security protection system, including a protection strategy construction module, an attack analysis module, a protection strategy switching module, and an attack tracking module. The protection strategy construction module, the attack analysis module, the protection strategy switching module, and the attack tracking module are connected in sequence;

[0006] The protection strategy construction module is used to construct multiple protection strategies in advance before the network is attacked;

[0007] The attack analysis module is used to train an attack type recognition model based on past data records, use the attack type recognition model to identify the latest attack received, and obtain the specific attack type;

[0008] The protection strategy switching module is used to make corresponding adjustments to the protection strategy based on the attack type;

[0009] The attack tracking module is used to track the attacker and notify the personnel for handling.

[0010] The protection strategy building module includes a firewall type setting unit, a firewall rule setting unit, a resource restriction division unit and an encryption transmission unit, and the firewall type setting unit, the firewall rule setting unit, the resource restriction division unit and the encryption transmission unit are connected in sequence;

[0011] The firewall type setting unit is used to set different types of firewalls to target different attack methods;

[0012] The firewall rule setting unit is used to set different firewall rules to target different attack methods;

[0013] The resource restriction division unit is used to divide resource information based on attack types;

[0014] The encryption transmission unit is used to encrypt the transmission of resource information when the computer network is attacked.

[0015] The attack analysis module includes a data pre-collection unit, a feature extraction unit, a model training unit and a real-time analysis unit, and the data pre-collection unit, the feature extraction unit, the model training unit and the real-time analysis unit are connected in sequence;

[0016] The data pre-collection unit is used to collect attack data based on previous system logs and firewall intrusion detection logs;

[0017] The feature extraction unit is used to perform data cleaning and standardization on the attack data, and perform feature extraction to obtain attack features;

[0018] The model training unit is used to train an attack type recognition model based on the attack features;

[0019] The real-time analysis unit is used to obtain real-time network attack data, input the data into the attack type identification model, and output a specific attack type.

[0020] Wherein, the model training unit comprises a statistical filtering subunit, an embedded selection subunit, a partitioning subunit and a model training subunit, and the statistical filtering subunit, the embedded selection subunit, the partitioning subunit and the model training subunit are connected in sequence;

[0021] The statistical filtering subunit is used to input the attack features into the decision tree algorithm for statistical filtering;

[0022] The embedded selection subunit is used to automatically select key features in attack features during training using the feature importance evaluation provided by the decision tree;

[0023] The sub - unit for division is used to divide 80% of the key features into a training set and 20% into a test set;

[0024] The model training sub - unit is used to train the model with the training set and test the trained model with the test set. After meeting the preset performance requirements, an attack type recognition model is obtained.

[0025] Among them, the protection policy switching module includes a firewall type switching unit, a firewall rule switching unit, and a resource restriction activation unit, which are connected in sequence;

[0026] The firewall type switching unit is used to find the corresponding firewall type in the system for network protection according to the attack type;

[0027] The firewall rule switching unit is used to find the corresponding firewall rules in the system for network protection according to the attack type;

[0028] The resource restriction activation unit is used to find the corresponding resources in the system for the area divided by the resources and urgently disable them.

[0029] Among them, the attack tracking module includes a data packet capture unit, a device disabling unit, and an alarm unit, which are connected in sequence;

[0030] The data packet capture unit is used to collect network data during an attack using a network packet capture tool to obtain the attacker's IP address and device identification code;

[0031] The device disabling unit is used to permanently disable the obtained IP address and device;

[0032] The alarm unit is used to save and record the obtained IP address and device identification code and notify relevant security personnel for handling.

[0033] The present invention also provides a computer network security protection method, which uses the above - mentioned computer network security protection system and includes the following steps:

[0034] Build multiple protection policies in advance before the network is attacked;

[0035] Collect and analyze previous data records, obtain attack data and pre - process it to obtain attack features;

[0036] Based on the attack features, perform model training to obtain an attack type recognition model;

[0037] Identify the ongoing attack using the attack type recognition model to obtain the specific attack type;

[0038] Make corresponding adjustments to the protection strategy based on the attack type;

[0039] Track the attacker and notify the personnel for handling.

[0040] A computer network security protection method and system of the present invention, the protection strategy construction module is used to construct multiple protection strategies in advance before the network is attacked; the attack analysis module is used to train an attack type recognition model based on past data records, use the attack type recognition model to identify the latest attack received, and obtain the specific attack type; the protection strategy switching module is used to make corresponding adjustments to the protection strategy based on the attack type; the attack tracking module is used to track the attacker and notify the personnel for handling;

[0041] Thus, by presetting multiple protection strategies, then identifying the type of the received attack, and directly switching to the corresponding protection strategy for network security protection after identifying the specific type, various threats can be dealt with relying on the stored multiple protection strategies, thereby flexibly coping with the diversity of network attacks and significantly improving the reliability and security of computer network security. Brief Description of the Drawings

[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art.

[0043] Figure 1 It is the schematic diagram of the computer network security protection system of the present invention.

[0044] Figure 2 It is the schematic diagram of the protection strategy construction module of the present invention.

[0045] Figure 3 It is the schematic diagram of the attack analysis module of the present invention.

[0046] Figure 4 It is the schematic diagram of the model training unit of the present invention.

[0047] Figure 5 It is the schematic diagram of the protection strategy switching module of the present invention.

[0048] Figure 6 It is the schematic diagram of the attack tracking module of the present invention.

[0049] Figure 7 It is the step flow chart of the computer network security protection method of the present invention.

[0050] 1 - Protection strategy construction module, 101 - Firewall type setting unit, 102 - Firewall rule setting unit, 103 - Resource limit division unit, 104 - Encrypted transmission unit, 2 - Attack analysis module, 201 - Data pre - collection unit, 202 - Feature extraction unit, 203 - Model training unit, 2031 - Counting filter subunit, 2032 - Embedded selection subunit, 2033 - Division subunit, 2034 - Model training subunit, 204 - Real - time analysis unit, 3 - Protection strategy switching module, 301 - Firewall type switching unit, 302 - Firewall rule switching unit, 303 - Resource limit activation unit, 4 - Attack tracking module, 401 - Data packet capture unit, 402 - Device disabling unit, 403 - Alarm unit. Detailed implementation manners

[0051] The embodiments of the present invention will be described in detail below. The examples of the embodiments are shown in the accompanying drawings. The embodiments described below by referring to the accompanying drawings are exemplary and are intended to explain the present invention and should not be construed as a limitation to the present invention.

[0052] Please refer to Figures 1 to 6 , the present invention provides a computer network security protection system, specifically including:

[0053] The protection strategy construction module 1 is used to construct a variety of protection strategies in advance before the network is attacked;

[0054] Specifically including:

[0055] The firewall type setting unit 101 is used to set different types of firewalls to target different attack methods;

[0056] Firewall types: Packet - filtering firewall, which is used to filter by checking the source IP, destination IP, port number, and protocol type (such as TCP / UDP) of the data packet, and defend against attacks such as port scanning, unauthorized access, and IP spoofing; specifically, it limits the concurrent connection number of a single IP (such as blocking if it exceeds 100 connections / second), detects abnormal traffic patterns (such as a large number of SYN packets in a short time but the three - way handshake is not completed), and blocks non - session traffic (such as directly sending an RST packet to close others' connections);

[0057] Including application - layer gateway / reverse - proxy firewall, which is used to deeply analyze the content of HTTP / HTTPS requests, identify malicious payloads, and defend against attacks such as SQL injection, XSS, and CC; specifically, it intercepts <script>标签的异常HTTP请求,限制同一IP对登录页面的访问频率(如5次失败则封锁1小时),检查Cookie中是否包含异常字符(如注入攻击特征);

[0058] 包括基于威胁情报的防火墙,用于通过实时同步全球威胁数据库,动态更新黑名单,防御零日漏洞攻击、僵尸网络C&C通信的攻击,具体为自动阻断新发现的恶意域名(如通过DNS请求特征匹配),标记使用加密货币挖矿池IP的出站流量,检测利用刚披露漏洞的攻击载荷(如Log4j漏洞特征)

[0059] 包括行为分析防火墙,用于通过机器学习分析流量基线,识别异常行为,防御APT攻击、内部横向移动的攻击,具体为标记夜间异常大文件传输(如2GB文件从服务器流向外部IP),检测使用非常用工具的流量(如管理员突然通过PowerShell下载文件),识别加密流量中的异常熵值(可能隐藏恶意软件)。

[0060] 所述防火墙规则设置单元102,用于设置防火墙不同的规则,从而针对不同的攻击方式;

[0061] 防火墙规则:

[0062] 最小权限原则,仅开放业务必要端口(如Web服务仅开放80 / 443),使用deny all默认策略,显式放行可信流量;

[0063] 分层防御策略,外层:包过滤防火墙拦截粗粒度攻击,中层:状态检测防火墙验证连接合法性,内层:应用层网关检查内容细节;

[0064] 动态规则更新,订阅CVE漏洞库,自动更新攻击特征规则,结合EDR / XDR系统联动封锁已失陷主机;

[0065] 日志与响应机制,记录所有阻断事件(时间、源IP、攻击类型),配置自动响应规则(如触发高危告警后自动隔离IP)。

[0066] 所述资源限制划分单元103,用于基于攻击类型对资源信息进行划分;

[0067] 将资源信息划分为与攻击类型对应的分类,因此当攻击者使用与某个资源信息对应的攻击类型时,即可启动后续的所述资源限制启动单元303,将该资源分类直接禁止,使得攻击失效。

[0068] 所述加密传输单元104,用于计算机网络受到攻击时,对资源信息的传输进行加密。

[0069] 所述攻击分析模块2,用于基于以往数据记录训练出攻击类型识别模型,使用攻击类型识别模型识别最新受到的攻击,得到具体的攻击类型;

[0070] 具体包括:

[0071] 所述数据预收集单元201,用于依靠以往的系统日志和防火墙的入侵检测日志收集攻击数据;

[0072] 通过查阅系统日志,从服务器的操作系统、应用程序等收集日志。这些日志记录了系统运行时的各种事件;通过查阅网络日志,收集防火墙日志、入侵检测系统(IDS)日志等。这些日志记录了网络流量的详细信息,如攻击数据包的源IP地址、目标IP地址、协议类型、端口号等,通过分析日志中的源IP、目标端口、攻击模式等,追溯攻击的来源,分析攻击流量的特征,如数据包大小、发送时间、数据包类型等,以确定攻击者的真实身份,使用流量分析工具对流量进行聚合和分类,以便更容易地识别攻击流量;由此收集攻击数据以便后续进行处理。

[0073] 所述特征提取单元202,用于将所述攻击数据进行数据清洗和标准化,并进行特征提取,得到攻击特征;

[0074] 数据清洗具体为:检查并修正时间、日期、数值、半全角等显示格式不一致的问题,去除内容中不该存在的字符(空格或特殊符号),确保数据格式和内容的一致性;去除或替换不合理的值,如负数的网络流量、超出正常范围的端口号等。同时,去除或重构不可靠的字段值,如修改矛盾的内容;删除与攻击分析无关的字段,如用户个人信息、非攻击相关的系统日志等,以减少数据冗余,提高分析效率;

[0075] 然后进行数据标准化,将数据变换为均值为0,标准差为1的分布。常用公式为:x'=(x-mean) / σ。标准化更适合处理大数据集,且对异常点相对鲁棒,以便后续提高模型的稳定性和准确性。

[0076] 所述模型训练单元203,用于基于所述攻击特征训练出攻击类型识别模型;

[0077] 具体包括:

[0078] 所述统计过滤子单元2031,用于将攻击特征输入到决策树算法中进行统计过滤;

[0079] 将处理后的攻击特征数据输入到决策树算法中,确保数据的格式和结构与算法要求相匹配,决策树算法会根据输入的攻击特征数据,递归地构建树的节点和分支,在构建过程中,算法会根据特征的重要性进行特征选择,并根据特征的取值将数据集分割成子集;在决策树构建完成后,可以利用其分支结构和叶节点来进行统计过滤,通过遍历决策树,可以根据叶节点的类别标签对输入数据进行分类和过滤,同时,可以利用决策树的路径信息来提取重要的攻击特征和攻击模式;这有助于快速识别和定位网络攻击,提高网络安全防护的效率和准确性。

[0080] 所述嵌入式选择子单元2032,用于使用决策树自带的特征重要性评估,在训练过程中自动选择攻击特征中的关键特征;

[0081] 在决策树构建过程中,自动选择关键特征可以减少模型对噪声数据的敏感性,避免模型学习到过多的噪声信息而导致过拟合,通过剔除不相关或冗余的特征,模型能够更专注于真实有用的信息,从而提高其泛化能力,在未知数据上表现更好。

[0082] 所述划分子单元2033,用于将所述关键特征的百分之80划分为训练集,百分之20划分为测试集;

[0083] 所述模型训练子单元2034,用于将所述训练集对模型进行训练,所述测试集对训练好的模型进行测试,符合预设的性能要求后,得到攻击类型识别模型。

[0084] 所述实时分析单元204,用于将获取实时受到的网络攻击数据,将其输入到所述攻击类型识别模型中,输出得到具体的攻击类型。

[0085] 获得具体的攻击类型后,后续针对此攻击类型进行相应的防护策略切换,达到最优的防护效果和防护效率。

[0086] 所述防护策略切换模块3,用于基于所述攻击类型对防护策略作出相应调整;

[0087] 具体包括:

[0088] 所述防火墙类型切换单元301,用于在系统中查找与攻击类型对应的防火墙类型进行网络防护;

[0089] 前述对防火墙类型进行预设置和储存,而每个防火墙类型均有其最适合防护的攻击类型,因此基于攻击类型直接做出改变即可,同时在切换后,若检测到防护效果不佳,可再次切换其他的类型,直到将攻击拦截为止。

[0090] 所述防火墙规则切换单元302,用于在系统中查找与攻击类型对应的防火墙规则进行网络防护;

[0091] 前述对防火墙规则进行预设置和储存,而每个防火墙规则均有其最适合防护的攻击类型,因此基于攻击类型直接做出改变即可,同时在切换后,若检测到防护效果不佳,可再次切换其他的规则,直到将攻击拦截为止。

[0092] 所述资源限制启动单元303,用于在系统中查找与攻击类型对应的资源,对该资源划分的区域进行紧急禁用。

[0093] 在识别到具体的攻击类型后,即可了解到此攻击类型具体针对攻击的是哪一类资源信息,进而将这类资源信息列为危险系数最高的资源信息,同时将其禁用保护,将对应的服务器关闭,使得攻击手段强制失效。

[0094] 所述攻击追踪模块4,用于对攻击者进行追踪并通知人员处理。

[0095] 具体包括:

[0096] 所述数据抓包单元401,用于采用网络抓包工具,对攻击时的网络数据进行收集,获取攻击者的IP地址和设备识别码;

[0097] 所述设备禁用单元402,用于对获取的IP地址和设备进行永久禁用;

[0098] 所述报警单元403,用于将获取的IP地址和设备识别码保存记录,并通知相关安全人员进行处理。

[0099] 获取IP地址和设备识别码后,即可便于后续对其进行封禁,避免再次对本系统进行访问和攻击,同时也可便于对其进行溯源查找,找出具体位置以便后续进行报警处理。

[0100] 请参阅图7,本发明还提供一种计算机网络安全防护方法,包括如下步骤:

[0101] S1:在网络受到攻击前提前构建多种防护策略;

[0102] S2:收集以往数据记录进行分析,得到攻击数据并预处理,得到攻击特征;

[0103] S3:基于攻击特征进行模型训练,得到攻击类型识别模型;

[0104] S4:使用攻击类型识别模型识别正在受到的攻击,得到具体的攻击类型;

[0105] S5:基于所述攻击类型对防护策略作出相应调整;

[0106] S6:对攻击者进行追踪并通知人员处理。

[0107] 其中,在网络受到攻击前提前构建多种防护策略;收集以往数据记录进行分析,得到攻击数据并预处理,得到攻击特征;基于攻击特征进行模型训练,得到攻击类型识别模型;使用攻击类型识别模型识别正在受到的攻击,得到具体的攻击类型;基于所述攻击类型对防护策略作出相应调整;对攻击者进行追踪并通知人员处理。

[0108] 以上所揭露的仅为本申请一种或多种较佳实施例而已,不能以此来限定本申请之权利范围,本领域普通技术人员可以理解实现上述实施例的全部或部分流程,并依本申请权利要求所作的等同变化,仍属于本申请所涵盖的范围。< / script>

Claims

1. A computer network security protection system, characterized in that it includes a protection policy construction module, an attack analysis module, a protection policy switching module, and an attack tracking module, and the protection policy construction module, the attack analysis module, the protection policy switching module, and the attack tracking module are connected in sequence; the protection policy construction module is used to construct multiple protection policies in advance before the network is attacked; the attack analysis module is used to train an attack type recognition model based on past data records, and use the attack type recognition model to identify the latest attack received to obtain the specific attack type; the protection policy switching module is used to make corresponding adjustments to the protection policy based on the attack type; the attack tracking module is used to track the attacker and notify the personnel for handling.

2. The computer network security protection system according to claim 1, characterized in that the protection policy construction module includes a firewall type setting unit, a firewall rule setting unit, a resource limit division unit, and an encrypted transmission unit, and the firewall type setting unit, the firewall rule setting unit, the resource limit division unit, and the encrypted transmission unit are connected in sequence; the firewall type setting unit is used to set different types of firewalls to target different attack methods; the firewall rule setting unit is used to set different rules of the firewall to target different attack methods; the resource limit division unit is used to divide the resource information based on the attack type; the encrypted transmission unit is used to encrypt the transmission of resource information when the computer network is attacked.

3. The computer network security protection system according to claim 2, characterized in that the attack analysis module includes a data pre-collection unit, a feature extraction unit, a model training unit, and a real-time analysis unit, and the data pre-collection unit, the feature extraction unit, the model training unit, and the real-time analysis unit are connected in sequence; the data pre-collection unit is used to collect attack data relying on past system logs and intrusion detection logs of the firewall; the feature extraction unit is used to clean and standardize the attack data and perform feature extraction to obtain attack features; the model training unit is used to train an attack type recognition model based on the attack features; the real-time analysis unit is used to obtain real-time network attack data, input it into the attack type recognition model, and output the specific attack type.

4. The computer network security protection system according to claim 3, characterized in that the model training unit includes a statistical filtering subunit, an embedded selection subunit, a division subunit, and a model training subunit, and the statistical filtering subunit, the embedded selection subunit, the division subunit, and the model training subunit are connected in sequence; the statistical filtering subunit is used to input the attack features into the decision tree algorithm for statistical filtering; the embedded selection subunit is used to use the feature importance evaluation provided by the decision tree to automatically select the key features in the attack features during the training process; The sub - division unit is used to divide 80% of the key features into a training set and 20% into a test set; The model training sub - unit is used to train the model with the training set and test the trained model with the test set. After meeting the preset performance requirements, an attack type recognition model is obtained.

5. The computer network security protection system according to claim 4, wherein The protection policy switching module includes a firewall type switching unit, a firewall rule switching unit, and a resource restriction activation unit, which are connected in sequence; The firewall type switching unit is used to search for the corresponding firewall type in the system for network protection according to the attack type; The firewall rule switching unit is used to search for the corresponding firewall rules in the system for network protection according to the attack type; The resource restriction activation unit is used to search for the corresponding resources in the system and urgently disable the areas divided by the resources.

6. The computer network security protection system according to claim 5, wherein The attack tracking module includes a data packet capture unit, a device disablement unit, and an alarm unit, which are connected in sequence; The data packet capture unit is used to collect network data during an attack using a network packet capture tool to obtain the attacker's IP address and device identification code; The device disablement unit is used to permanently disable the obtained IP address and device; The alarm unit is used to save and record the obtained IP address and device identification code and notify relevant security personnel for processing.

7. A computer network security protection method, which uses the computer network security protection system as described in claim 6, characterized in that, It includes the following steps: Construct multiple protection policies in advance before the network is attacked; Collect and analyze past data records, obtain attack data and pre - process it to obtain attack features; Perform model training based on the attack features to obtain an attack type recognition model; Use the attack type recognition model to identify the ongoing attack to obtain the specific attack type; Make corresponding adjustments to the protection policy based on the attack type; Track the attacker and notify the personnel for processing.