Network attack AI detection analysis method and system based on smart Internet
Through distributed edge nodes collaboratively building an attack feature library and a multimodal interaction map, combining virtualized network environment and AI interaction verification, the problems of update delay and misjudgment in traditional network security solutions are solved, and efficient network attack detection and defense are achieved.
Patent Information
- Application Number
- CN202510563187.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-07-08
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Traditional network security solutions are difficult to deal with complex network attacks, centralized feature library update delays, cross-protocol attack detection accuracy is insufficient, static defense strategies are misjudgment rates, lack dynamic defense mechanisms, and cannot effectively identify new attack modes.
The attack feature library is constructed through distributed edge nodes, the multi-modal interaction map is used to identify potential attack links, and the virtualized network environment is deployed to dynamically adjust defense strategies. Combined with the AI interaction verification process and distributed node consensus mechanism, dynamic feature library updates and policy optimization are achieved.
It improves the accuracy of network attack detection and adaptability of defense strategies, reduces the misjudgment rate and policy error blocking rate, shortens the response time, and improves the level of network security protection.
Smart Images

Figure CN120281555A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security protection, and particularly relates to a method and system for AI detection and analysis of network attacks based on the intelligent Internet. Background Art
[0002] In today's digital age, network security has received increasing attention. Especially with the rapid development of the intelligent Internet, the threats of network attacks have become increasingly complex and diverse. With the popularization of Internet of Things, cloud computing, and big data technologies, network attack methods have also become more intelligent, such as using AI technology for attacks and amplifying attack effects through automated means. In response, traditional network security solutions such as signature-based intrusion detection systems (IDS) and firewalls have become difficult to effectively cope with emerging complex attack patterns. These traditional technologies often rely on existing attack feature libraries, lack the ability to real-time identify unknown attacks, and due to their high false alarm rate and missed alarm rate, the effectiveness of network security protection has been severely affected.
[0003] Although existing machine learning-based network attack detection methods have improved the detection ability to some extent, they often face problems of data privacy and security during the process of data processing, feature selection, and model training. In addition, due to the timeliness and limitations of obtaining training data, the model may not be able to flexibly adapt to new variant attacks in actual applications. Therefore, how to use the method of edge computing and distributed nodes to achieve dynamic fusion of data and real-time update of the detection model while ensuring data privacy has become a technical problem that needs to be solved urgently. In addition, the existing methods lack effective integration of dynamic identification of attack links and generation of defense strategies, making it difficult for the protection system to form a complete closed loop in the face of complex attacks. Therefore, there is an urgent need for a new technical solution that combines edge computing, artificial intelligence, and dynamic feature analysis to achieve effective detection and analysis of network attacks, thereby improving the overall level of network security protection.
[0004] The existing technologies have the following core defects:
[0005] First of all, the centralized feature library update mechanism is difficult to adapt to the dynamic attack scenarios of edge nodes. The traditional periodic rule distribution mode leads to spatio-temporal mismatch problems between feature library sharding and local network load, and cannot effectively capture regional new attack traces.
[0006] Secondly, the identification of cross-protocol attack links depends on static weight maps, lacking dynamic quantitative evaluation of temporal stability and protocol interaction deviation, resulting in insufficient detection accuracy for multi-stage composite attacks such as DNS tunnel covert communication and HTTP request header injection. For example, existing graph models do not incorporate protocol benchmark frequencies and real-time interaction deviations into weight calculations, making it difficult to identify payload concealment behaviors achieved through protocol compliance fields.
[0007] In addition, there are configuration deviations between the mirror environment and the real topology in the existing sandbox policy verification mechanism, resulting in business misjudgment easily caused by the defense policy when blocking the attack link, and there is a lack of closed-loop feedback optimization for the bypass behavior of attackers.
[0008] Research shows that the misjudgment rate of traditional solutions is as high as 12% when blocking SYN flood attacks, and the recognition delay for lateral movement attacks exceeds 300 milliseconds. At the level of behavior verification, the existing AI interaction mechanism adopts a fixed threshold trigger strategy, and no dynamic mapping relationship between abnormal mode types and verification elements is established, making it impossible to effectively distinguish the differential threat levels of timing anomalies, privilege escalation, and protocol structure deviation, resulting in a 27% increase in the mis-trigger rate of the verification process. More seriously, the existing distributed node consensus mechanism does not introduce a topology isolation virtual execution sandbox, and it is impossible to accurately quantify the cumulative risk values of process-level high-risk behaviors (such as privileged instruction execution and illegal memory writing), making the dynamic adjustment of the defense policy lag behind the attack evolution speed. Summary of the Invention
[0009] In view of the above existing problems, the technical problems solved by the present invention are as follows: Solving the problem that the traditional centralized detection architecture is difficult to cope with large-scale distributed network attacks, and there is a lack of a secure and efficient collaboration mechanism between edge nodes, resulting in a delay in updating the attack feature library and being unable to dynamically fuse new attack patterns across regions; Solving the problem that the detection of a single protocol layer cannot effectively associate multi-protocol attack behaviors (such as the collaborative exploitation of HTTP and DNS), and there is a lack of dynamic modeling and analysis capabilities for the cross-protocol operation intentions of attackers; Solving the problem that static defense rules are difficult to adapt to the rapid changes in the attack path, and the existing technology lacks a verification mechanism for simulating the blocking effect of the attack link in an isolated environment, resulting in possible mis-blocking of normal services or triggering new attack paths after the policy is deployed; Solving the problem that traditional honeypot technologies rely on fixed induction features, cannot adjust the decoy strategy in real time according to the interaction behavior of attackers, and have poor synchronization with the vulnerability status of real systems, resulting in low trapping efficiency.
[0010] To solve the above technical problems, a network attack AI detection and analysis method based on the intelligent Internet is proposed, including,
[0011] Collaboratively constructing an attack feature library through distributed edge nodes, each node generates feature parameters based on local attack events, and transmits them to the central server for dynamic fusion through encrypted transmission; constructing multi-modal interaction graphs for cross-protocol network behavior data, and identifying potential attack links based on the association strength between the graph nodes; deriving attack intentions according to the attack links, generating defense policies and verifying the feasibility of the policies; deploying a virtualized network environment and dynamically injecting induction features, and adjusting the induction strategy in real time according to the interaction behavior of attackers; monitoring the abnormal patterns of user behavior sequences, triggering an AI interaction verification process that can be dynamically adjusted, and storing the defense policies through a distributed node consensus mechanism.
[0012] As a preferred solution of a network attack AI detection and analysis method based on the intelligent Internet according to the present invention, wherein: the distributed edge node collaboration includes deploying lightweight clients on the Internet of Things gateway and the edge server, configuring the TPM security chip to encrypt local model parameters, and periodically collecting attack feature data;
[0013] The local model parameters are encrypted and processed by the differential privacy encryption algorithm between nodes to generate a feature vector containing only the parameter change trend; the central server de-identifies and clusters the feature vectors to generate a shard of the feature library with regional characteristics;
[0014] The shard of the feature library is compared with the global feature library for differences, the feature traces of the new attack pattern are extracted, the optimal shard distribution path is selected, and the nodes perform correlation analysis on the feature traces and the local historical data to generate a threat level assessment report.
[0015] As a preferred solution of a network attack AI detection and analysis method based on the intelligent Internet according to the present invention, wherein: the multi-modal interaction graph includes using all shards of the feature library as data sources to input and establish a request-process association matrix, and using the dynamic mapping relationship between network requests and terminal operations as the initial nodes of the graph;
[0016] The edge weights of the graph are dynamically calculated by the standard deviation of the session data packet arrival time and the deviation degree of the protocol interaction frequency to construct a multi-modal interaction graph; calculate the association strength between the graph nodes, and identify potential attack links based on the association strength between the graph nodes;
[0017] When a new protocol is detected, the graph nodes are automatically expanded and initial connection edges are established, and pruning operations are performed on the low-weight edges every preset period to remove invalid connections with historical interaction frequencies lower than the threshold.
[0018] As a preferred solution of a network attack AI detection and analysis method based on the intelligent Internet according to the present invention, wherein: the defense strategy includes generating a virtual test environment according to the identified potential attack links, extracting the key node information in the current multi-modal interaction graph, mirroring and replicating the key node configuration in an isolated sandbox environment, and constructing a virtual network topology copy;
[0019] Monitor the attack link blocking effect in the virtual environment, replay the behavior data of each stage of the attack link in the virtual environment, inject the defense strategy at the preset blocking point, monitor the attacker's behavior response after blocking, and record the new attack path that the attacker tries to bypass the defense;
[0020] Judge the feasibility of the strategy according to the blocking effect. When the defense strategy causes errors in normal service requests or the blocking rate is lower than the preset threshold, trigger a strategy optimization alarm and generate a strategy optimization instruction; for the strategy that successfully blocks the attack but triggers a new attack path, automatically generate an auxiliary defense rule supplement package.
[0021] As a preferred solution of a network attack AI detection and analysis method based on the intelligent Internet according to the present invention, wherein: the induction strategy includes receiving an instruction for strategy optimization, monitoring protocol interaction characteristics, embedding a tracking identifier in the virtual service response message, and the tracking identifier changes dynamically with each request of the attacker, and analyzing the retry behavior pattern of the attacker for the abnormal response for vulnerability feature matching;
[0022] The vulnerability feature matching includes establishing a multi-dimensional vulnerability feature vector space, using an approximate nearest neighbor search algorithm to quickly locate similar historical vulnerabilities in the vector space for matching, selecting a basic response framework from the template library according to the matched vulnerability features, generating mutated fields through protocol fuzz testing, implanting controllable vulnerability exploitation points in the response data, and the vulnerability exploitation points are synchronized with the security patch status of the real system to generate bait response data, and circularly updating the defense strategy according to the interaction feedback of the attacker to the bait response data.
[0023] As a preferred solution of a network attack AI detection and analysis method based on the intelligent Internet according to the present invention, wherein: the AI interaction verification process includes identifying an abnormal pattern through AI according to the interaction feedback of the attacker to the bait response data;
[0024] Statistically calculate the standard deviation of the request interval time of the attacker for the bait response and calculate the burst coefficient to judge the timing abnormality; record the permission level of the virtual resources that the attacker attempts to access, record the number of permission escalations and the number of lateral movement attempts within a single client session to judge the permission abnormality; calculate the tampering rate of the preset trap field in the bait response and the structural deviation degree of the request message from the RFC standard to judge the protocol abnormality; at the same time, establish a mapping relationship table between the abnormal pattern type and the verification elements.
[0025] As a preferred solution of a network attack AI detection and analysis method based on the intelligent Internet according to the present invention, wherein: the distributed node consensus mechanism includes, according to the abnormal results of the AI interaction verification, each node receives the abnormal pattern type, and each node combines the local defense log to generate a defense strategy evaluation matrix;
[0026] Calculate the priority weight of the defense strategy based on the evaluation matrix, establish a topological isolation virtual execution sandbox in the constructed virtual environment, input the calculated defense strategy priority weights into the sandbox in turn, import the suspicious requests into the sandbox, monitor the system call sequence triggered by it, and decide whether to release the original request according to the danger level of the behavior in the sandbox;
[0027] When a new attack pattern is detected in the topology-isolated virtual execution sandbox, temporary filtering rules are automatically generated and broadcast to all nodes, and it is determined whether to store the temporary filtering rules in combination with the threat level assessment report.
[0028] Another object of the present invention is to provide a network attack AI detection and analysis system based on the intelligent Internet. This system constructs a dynamically updated attack feature library through the encryption cooperation mechanism between edge nodes and the central server, solving the problem of delayed update of the traditional centralized feature library; based on the calculation of the association strength of the multimodal interaction graph, breaking through the detection blind spot of a single protocol and identifying advanced persistent threats across protocol layers; through the pre-verification of the defense strategy of the virtualized sandbox and the dynamic injection of induced features, realizing the adaptive evolution of defense rules and reducing the policy mis-blocking rate; combining AI behavior analysis with the distributed consensus mechanism to implement a dynamic verification process for abnormal requests to ensure the seamless passage of legitimate business traffic.
[0029] As a preferred solution of a network attack AI detection and analysis system based on the intelligent Internet according to the present invention, it is characterized by including a data collection and fusion module, a multimodal interaction graph construction module, a defense module, an induction module, and an anomaly monitoring module;
[0030] The data collection and fusion module collaboratively constructs an attack feature library through distributed edge nodes. Each node generates feature parameters based on local attack events and transmits them to the central server for dynamic fusion through encryption;
[0031] The multimodal interaction graph construction module constructs cross-protocol network behavior data into a multimodal interaction graph and identifies potential attack links based on the association strength between graph nodes;
[0032] The defense module derives the attack intention based on the attack link, generates a defense strategy, and verifies the feasibility of the strategy;
[0033] The induction module deploys a virtualized network environment and dynamically injects induced features, and adjusts the induction strategy in real time according to the interaction behavior of the attacker;
[0034] The anomaly monitoring module monitors the abnormal patterns of the user behavior sequence, triggers an AI interaction verification process that can be dynamically adjusted, and stores the defense strategy through the distributed node consensus mechanism.
[0035] A computer device includes a memory and a processor. The memory stores a computer program, and it is characterized in that when the processor executes the computer program, the steps of a network attack AI detection and analysis method based on the intelligent Internet as described above are implemented.
[0036] A computer-readable storage medium stores a computer program thereon. The computer program, when executed by a processor, implements the steps of the method for detecting and analyzing network attacks AI based on the intelligent Internet as described above.
[0037] Advantages of the present invention: The present invention realizes dynamic and precise defense of network attack detection through a multi-step collaborative technical solution. By deploying lightweight clients on distributed edge nodes and configuring TPM security chips, and combining differential privacy encryption algorithms to encrypt and obfuscate local model parameters, a feature vector containing only parameter trends is generated, significantly reducing the feature transmission bandwidth consumption while protecting node privacy during the attack feature collection process; the central server generates shards of the regional feature library through de-identified clustering and compares them with the global library to improve the timeliness of identifying new attack patterns. The dynamic shard distribution mechanism combined with hash verification controls the feature library update delay within milliseconds. By constructing a cross-protocol multi-modal interaction graph, dynamically calculating using the time difference of the request-process association matrix, and generating dynamic weights by combining the temporal stability index and the protocol frequency deviation degree, the accuracy of identifying hidden attack links is improved, and the graph maintenance overhead of the automatic pruning mechanism is reduced. Using the virtual network topology replica mirroring technology, by replaying attack behaviors in a sandbox environment and injecting defense strategies, the strategy verification cycle is shortened to 1 / 5 of the traditional method, and the strategy mis-blocking rate is reduced. Innovatively deploying dynamic tracking identifiers and decoy response data, achieving millisecond-level matching of vulnerability features through the approximate nearest neighbor search algorithm, and inducing strategies to increase the capture volume of attacker interaction behaviors. By establishing an intelligent mapping between abnormal patterns and verification elements and combining the distributed node consensus mechanism, the blocking response time for high-risk attacks is shortened to within 300 ms, and the false alarm rate is controlled below 5% by the risk accumulation assessment model based on a sliding window. The adaptive conversion mechanism of the temporary filtering rule improves the generation efficiency of new attack defense rules. Each step organically collaborates with edge computing and central intelligence to build a full-chain closed-loop system covering attack feature collection, behavior analysis, strategy verification, and active defense. Description of the Drawings
[0038] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts, where:
[0039] Figure 1 It is the overall flowchart of a method for detecting and analyzing network attacks AI based on the intelligent Internet provided by an embodiment of the present invention.
[0040] Figure 2System solution module diagram of a network attack AI detection and analysis system based on the intelligent Internet provided by an embodiment of the present invention. Detailed implementation manners
[0041] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following will describe the detailed implementation manners of the present invention with reference to the accompanying drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention.
[0042] In the following description, many specific details are set forth to facilitate a full understanding of the present invention. However, the present invention may be implemented in other ways different from those described herein. Those skilled in the art can make similar generalizations without departing from the spirit of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0043] Secondly, the so-called "one embodiment" or "embodiment" herein refers to specific features, structures, or characteristics that may be included in at least one implementation manner of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it an embodiment that is separately or selectively mutually exclusive with other embodiments.
[0044] The present invention is described in detail in conjunction with schematic diagrams. When detailing the embodiments of the present invention, for the convenience of explanation, the cross-sectional views showing the device structure will be enlarged locally in a non-general proportion, and the schematic diagrams are only examples and should not limit the scope of protection of the present invention here. In addition, in actual production, three-dimensional spatial dimensions including length, width, and depth should be included.
[0045] At the same time, in the description of the present invention, it should be noted that the orientation or positional relationships indicated by terms such as "upper, lower, inner, and outer" are based on the orientation or positional relationships shown in the drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation to the present invention. In addition, the terms "first, second, or third" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance.
[0046] Unless otherwise clearly defined and limited in the present invention, the terms "installation, connection, and coupling" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can also be a mechanical connection, an electrical connection, or a direct connection, or can be indirectly connected through an intermediate medium, or can be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.
[0047] Example 1, referring to Figure 1 , which is the first embodiment of the present invention. This embodiment provides a method for AI detection and analysis of network attacks based on the intelligent Internet, including:
[0048] S1: Collaboratively construct an attack feature library through distributed edge nodes. Each node generates feature parameters based on local attack events and transmits them to the central server for dynamic fusion after encryption.
[0049] It should be noted that lightweight clients are deployed on the IoT gateway and edge servers, and each client is configured with a dedicated TPM security chip for encrypting local model parameters;
[0050] Each node periodically collects local attack feature data, including the connection frequency of abnormal TCP / UDP ports at the network layer, the characteristics of SYN flood attack packets, the HTTP request header injection mode at the application layer, and the DNS tunnel payload characteristics;
[0051] Furthermore, the local model parameters are encrypted and processed by the differential privacy encryption algorithm between nodes. Each edge node trains a lightweight attack detection model based on the local attack feature data, encrypts and confuses the local model parameters, and generates a feature vector that only contains the parameter change trend;
[0052] The central server receives the encrypted feature vectors uploaded by the edge nodes and performs de-identification processing;
[0053] Remove the metadata related to the node device characteristics, perform clustering analysis based on the cosine similarity between the feature vectors, and generate a shard of the feature library with regional characteristics;
[0054] Compare the shard of the feature library with the global feature library to extract the feature traces of new attack patterns;
[0055] According to the geographical location and network load of the edge nodes, dynamically select the optimal shard distribution path. After the node receives the shard of the feature library, verify the data integrity through hash verification. The node performs correlation analysis on the feature traces and local historical data to generate a threat level assessment report.
[0056] S2: Construct multi-modal interaction graphs from cross-protocol network behavior data and identify potential attack links based on the association strength between the graph nodes.
[0057] Furthermore, use all shards of the feature library as data sources to establish a dynamic mapping relationship between network requests and terminal operations. Capture the user agent information in the HTTP / HTTPS / DNS protocol request headers at the protocol parsing layer and align the timestamps with the startup logs of the terminal processes;
[0058] Establish a request - process association matrix, where the matrix element values are dynamically calculated from the time difference between the request initiation time and the process startup time. Among them, the mapping relationship serves as the initial node of the graph;
[0059] Furthermore, based on the edges of the graph, assign dynamic weights, and statistically calculate the standard deviation of the arrival time intervals of consecutive data packets in the same session as the time - series stability index;
[0060] Set a benchmark interaction frequency according to the protocol type, calculate the deviation of the actual interaction frequency from the benchmark value, generate a dynamic weight coefficient by integrating the time - series stability index and the frequency deviation, and construct a multi - modal interaction graph;
[0061] Calculate the association strength between the nodes of the graph, and identify potential attack links based on the association strength between the nodes of the graph;
[0062] When a new protocol is detected, automatically expand the graph nodes and establish initial connection edges, and perform pruning operations on the low - weight edges every preset period to remove invalid connections with historical interaction frequencies lower than the threshold.
[0063] S3: Deduce the attack intention based on the attack link, generate a defense strategy and verify the feasibility of the strategy.
[0064] Furthermore, according to the identified potential attack links, generate a virtual test environment, and extract the key node information in the current multi - modal interaction graph, including router configuration, firewall rules, and service port status;
[0065] Mirror and copy the key node configurations in an isolated sandbox environment to construct a virtual network topology replica;
[0066] It should be noted that monitor the blocking effect of the attack link in the virtual environment, and replay the behavior data of each stage of the attack link in the virtual environment;
[0067] Inject defense strategies at preset blocking points, including traffic redirection, protocol field filtering, and session termination instructions;
[0068] Monitor the attacker's behavioral response after blocking, and record the new attack paths that the attacker attempts to bypass the defense;
[0069] Judge the feasibility of the strategy according to the blocking effect. When the defense strategy causes errors in normal service requests or the blocking rate is lower than the preset threshold, trigger a strategy optimization alarm and generate a strategy optimization instruction;
[0070] For the strategy that successfully blocks the attack but triggers new attack paths, automatically generate an auxiliary defense rule supplement package.
[0071] S4: Deploy a virtualized network environment and dynamically inject induced features, and adjust the induction strategy in real - time according to the attacker's interaction behavior.
[0072] Furthermore, it receives instructions for policy optimization, monitors protocol interaction characteristics, and embeds tracking identifiers in virtual service response messages;
[0073] The tracking identifier changes dynamically with each attacker's request, and analyzes the attacker's retry behavior pattern for abnormal responses to perform vulnerability feature matching, including the distribution of retry intervals and parameter variation rules;
[0074] The vulnerability feature matching includes establishing a multi-dimensional vulnerability feature vector space, where the vector dimensions include protocol type, payload structure features, and abnormal field offsets;
[0075] Use the approximate nearest neighbor search algorithm to quickly locate similar historical vulnerabilities in the vector space for matching;
[0076] It should be noted that the basic response framework is selected from the template library according to the matched vulnerability features;
[0077] Generate mutated fields through protocol fuzz testing, including randomizing string length and inserting unconventional character sequences;
[0078] A controllable vulnerability exploit point is implanted in the response data. The vulnerability exploit point is synchronized with the security patch status of the real system to generate bait response data. The defense strategy is cyclically updated based on the attacker's interactive feedback on the bait response data.
[0079] S5: Monitor abnormal patterns in user behavior sequences, trigger dynamically adjustable AI interactive verification processes, and store defense strategies through a distributed node consensus mechanism.
[0080] Furthermore, AI can be used to identify abnormal patterns based on the attacker’s interactive feedback on the decoy response data;
[0081] The standard deviation σ of the attacker's request interval response to the bait is calculated. When σ exceeds 3 times the protocol benchmark value, the timing anomaly mark is triggered. The burst coefficient of continuous requests (i.e., the ratio of the maximum request frequency to the average frequency) is calculated. When the burst coefficient is greater than 5, it is determined to be a timing anomaly.
[0082] Record the permission level of the virtual resources that the attacker attempts to access. When the number of permission jumps in a single client session exceeds the topology depth value, an exception is triggered. Detect the number of lateral movement attempts and set a dynamic threshold T = log (number of authorized resources) + 1. When the number of lateral movement attempts is greater than T, a permission exception is triggered.
[0083] Calculate the tampering rate of the preset trap field in the bait response. When the tampering rate is greater than 30%, a protocol anomaly is triggered. Calculate the structural deviation between the request message and the RFC standard. That is, the structural deviation is the ratio of the number of abnormal fields to the total number of key fields. When the structural deviation exceeds 0.25, it is determined to be a protocol anomaly.
[0084] Establish a mapping relationship table between abnormal mode types and verification elements. For the time-series anomaly class, map it to graphical logic verification: generate a topological connection verification graph with time constraints;
[0085] For the permission anomaly class, map it to multi-factor verification, triggering the dual binding of device fingerprint + biometric features;
[0086] For the protocol anomaly class, map it to semantic verification, requiring the user to describe the operation intention in natural language.
[0087] It should be noted that according to the abnormal results of AI interaction verification, each node receives the abnormal mode type, and each node combines the local defense log to generate a defense strategy evaluation matrix;
[0088] Among them, the dimensions of the defense strategy evaluation matrix include the distribution density of time-series anomaly marks, the geographical location correlation of permission elevation events, and the propagation path of protocol structure deviation;
[0089] Calculate the priority weight of the defense strategy based on the evaluation matrix, establish a topological isolation virtual execution sandbox in the constructed virtual environment, input the calculated defense strategy priority weights into the sandbox in sequence, import the suspicious requests into the sandbox, monitor the system call sequence triggered by them, and decide whether to release the original request according to the danger level of the behavior in the sandbox;
[0090] Specifically, record the system call sequence triggered by the processes in the sandbox and mark the high-risk behaviors:
[0091] Among them, high-risk behaviors at least include sensitive file access (such as attempting to modify / etc / passwd), execution of privileged instructions (such as sudo privilege elevation operation), and illegal writing to memory space (such as stack overflow characteristics). Each type of behavior is cumulatively scored according to a preset risk coefficient (0.1 - 1.0);
[0092] Capture the network connection requests initiated in the sandbox and evaluate their threat level:
[0093] ① Whether the target IP is an entry in the known malicious address library;
[0094] ② Port scanning behavior (a single process accessing multiple non-common ports in a short time);
[0095] ③ The verification result of the certificate legitimacy of the encrypted communication protocol (such as TLS);
[0096] Statistical process resource occupancy patterns, sudden changes in CPU / memory occupancy rate (such as increasing by more than 200% within 10 seconds), frequency of child process derivation (such as creating more than 5 child processes within 1 second), and cross-directory traversal behavior (such as jumping from the download directory to the system configuration directory);
[0097] Train a feature importance model based on historical attack data to assign feature weights, and adopt a sliding window mechanism to calculate the cumulative risk value within the current window period every 30 seconds:
[0098] When the cumulative risk value belongs to [0, 0.3), it belongs to the low-risk level. Automatically release and record the features, generate a temporary access token for low-risk requests. The token is bound to the hash value of the original request and the fingerprint of the target service, and the validity period does not exceed 5 minutes. Verify the validity of the token at the load balancer layer;
[0099] When the cumulative risk value belongs to [0.3, 0.7), it belongs to the medium-risk level, and it is input into the AI interaction verification process for secondary verification;
[0100] When the cumulative risk value exceeds 0.7, it belongs to the high-risk level, block the request and trigger a network-wide warning;
[0101] It should also be noted that when a new attack pattern is found in the topology isolation virtual execution sandbox, a temporary filtering rule is automatically generated and broadcast to all nodes. Among them, the temporary filtering rule becomes a permanent rule when the adoption rate is higher than 50% after 5 rounds of verification cycles and there is a threat level assessment report. If the temporary filtering rule does not exceed 50% after 5 rounds of verification cycles and there is no threat level assessment report, it will automatically expire.
[0102] Embodiment 2, the second embodiment of the present invention, which is different from the previous embodiment:
[0103] If the described function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. And the aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0104] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a definable sequence list of executable instructions for implementing a logical function, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or in conjunction with these instruction execution systems, apparatuses, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0105] More specific examples (a non-exhaustive list) of computer-readable media include the following: an electrical connection portion with one or more wirings (electronic device), a portable computer diskette (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, the computer-readable medium can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpretation, or otherwise processing as appropriate, and then stored in a computer memory.
[0106] It should be understood that various parts of the present invention can be implemented using hardware, software, firmware, or combinations thereof. In the above-described embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one or a combination of the following techniques well-known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application-specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0107] Example 3, referring to Figure 2 , is the third embodiment of the present invention. This embodiment provides a network attack AI detection and analysis system based on the intelligent Internet, including a data collection and fusion module, a multi-modal interaction graph construction module, a defense module, an induction module, and an anomaly monitoring module;
[0108] Data collection and fusion module, adopting a lightweight client (deployed on the Internet of Things gateway and edge server) and a hardware-level encryption architecture of the TPM security chip to achieve trusted collection of attack feature data. Nodes periodically collect multi-dimensional attack traces at the network layer (TCP / UDP abnormal port connection frequency, SYN flood attack packet characteristics) and application layer (HTTP request header injection mode, DNS tunnel payload characteristics), encrypt and obfuscate local model parameters through the differential privacy encryption algorithm to generate feature vectors containing only the parameter change trends;
[0109] Collaboratively construct an attack feature library through distributed edge nodes. Each node generates feature parameters based on local attack events and transmits them to the central server for dynamic fusion after encryption;
[0110] Multi-modal interaction graph construction module, establishing a request-process association matrix across protocols (HTTP / HTTPS / DNS), constructing a multi-modal interaction graph through timestamp alignment and dynamic weight calculation (time series stability index + frequency deviation), and identifying potential attack links based on the association strength between graph nodes;
[0111] Defense module, deducing attack intentions based on attack links, generating defense strategies and verifying the feasibility of the strategies;
[0112] Embed a dynamically changing tracking identifier in the virtual service response to analyze the attacker's retry behavior (interval distribution, parameter mutation). Establish a multi-dimensional vulnerability feature vector space (protocol type, payload structure, abnormal field offset), and match historical vulnerabilities through approximate nearest neighbor search. Select a response template and perform fuzz testing to generate mutated fields (random strings, unconventional characters), and implant vulnerability exploitation points synchronized with real patches. Update decoy data according to the attacker's feedback and iteratively optimize the defense strategy.
[0113] Induction module, deploying a virtualized network environment and dynamically injecting induction features, and adjusting induction strategies in real time according to the attacker's interaction behavior;
[0114] Statistically calculate the standard deviation of the attacker's request interval and the burst coefficient to mark time series anomalies. Detect that the number of privilege escalations exceeds the topological depth or the number of lateral movement attempts exceeds the dynamic threshold to trigger privilege anomalies. Calculate the decoy field tampering rate and the message structure deviation to determine protocol anomalies. Abnormal type mapping verification methods: Time series anomalies trigger time-constrained topology graph verification; Privilege anomalies require device fingerprint + biometric characteristics; Protocol anomalies require natural language description of operation intentions.
[0115] Abnormal monitoring module, monitoring the abnormal patterns of user behavior sequences, triggering an AI interaction verification process that can be dynamically adjusted, and storing defense strategies through a distributed node consensus mechanism;
[0116] Each node generates an evaluation matrix (temporal anomaly density, privilege escalation geographical location, protocol deviation propagation path) based on the defense log and calculates the policy priority weight. Monitor system calls (sensitive file access, privilege escalation operations, illegal memory writes), network connections (malicious IP, port scanning, illegal certificates), and sudden changes in resource occupancy (CPU / memory sudden increase of 200%, high-frequency subprocesses) in the topological isolation sandbox. Classify and process the cumulative risk value: release low-risk and generate a 5-minute temporary token; conduct secondary verification for medium-risk; block and give an early warning for high-risk. If the adoption rate of the temporary filtering rule is >50% after 5 rounds of verification, it will be converted into a permanent rule, otherwise it will become invalid.
[0117] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.
Claims
1. A network attack AI detection and analysis method based on the intelligent Internet, characterized in that: including collaboratively building an attack feature library through distributed edge nodes, where each node generates feature parameters based on local attack events and transmits them to the central server for dynamic fusion after encryption; constructing cross - protocol network behavior data into a multi - modal interaction graph, and identifying potential attack links based on the association strength between graph nodes; deriving attack intentions according to the attack links, generating defense strategies and verifying the feasibility of the strategies; deploying a virtualized network environment and dynamically injecting induced features, and adjusting the induction strategy in real - time according to the interaction behavior of the attacker; monitoring the abnormal patterns of user behavior sequences, triggering an AI interaction verification process that can be dynamically adjusted, and storing defense strategies through a distributed node consensus mechanism.
2. The network attack AI detection and analysis method based on the intelligent Internet according to claim 1, characterized in that: The collaboration of the distributed edge nodes includes deploying lightweight clients on the IoT gateway and edge servers, configuring TPM security chips to encrypt local model parameters, and periodically collecting attack feature data; Nodes encrypt and process local model parameters through the differential privacy encryption algorithm to generate feature vectors that only contain the trend of parameter changes; the central server performs de - identification clustering on the feature vectors to generate shards of the feature library with regional characteristics; Compare the shards of the feature library with the global feature library, extract the feature traces of new attack patterns, select the optimal shard distribution path, and nodes perform correlation analysis on the feature traces and local historical data to generate a threat level assessment report.
3. The network attack AI detection and analysis method based on the intelligent Internet according to claim 2, wherein: The multi - modal interaction graph includes using all shards of the feature library as data sources to input and establish a request - process association matrix, and using the dynamic mapping relationship between network requests and terminal operations as the initial nodes of the graph; The edge weights of the graph are dynamically calculated through the standard deviation of the session packet arrival time and the deviation degree of protocol interaction frequency to construct a multi - modal interaction graph; calculate the association strength between graph nodes, and identify potential attack links based on the association strength between graph nodes; When a new protocol is detected, automatically expand the graph nodes and establish initial connection edges, and perform pruning operations on low - weight edges every preset period to remove invalid connections with historical interaction frequencies lower than the threshold.
4. The network attack AI detection and analysis method based on the intelligent Internet according to claim 3, wherein: The defense strategy includes generating a virtual test environment according to the identified potential attack links, extracting key node information in the current multi - modal interaction graph, mirror - replicating the key node configuration in an isolated sandbox environment, and constructing a virtual network topology copy; Monitor the blocking effect of the attack link in the virtual environment, replay the behavior data of each stage of the attack link in the virtual environment, inject the defense strategy at the preset blocking point, monitor the attacker's behavior response after blocking, and record the new attack paths that the attacker tries to bypass the defense; Judge the feasibility of the strategy according to the blocking effect. When the defense strategy causes errors in normal service requests or the blocking rate is lower than the preset threshold, trigger a strategy optimization alarm and generate a strategy optimization instruction; for the strategy that successfully blocks the attack but triggers new attack paths, automatically generate an auxiliary defense rule supplement package.
5. The network attack AI detection and analysis method based on the intelligent Internet according to claim 4, characterized in that: The induction strategy includes receiving the instruction of strategy optimization, monitoring protocol interaction characteristics, embedding a tracking identifier in the virtual service response message, where the tracking identifier changes dynamically with each request of the attacker, and analyzing the retry behavior pattern of the attacker for abnormal responses to perform vulnerability feature matching; The vulnerability feature matching includes establishing a multi-dimensional vulnerability feature vector space, using the approximate nearest neighbor search algorithm to quickly locate similar historical vulnerabilities in the vector space for matching, selecting a basic response framework from the template library according to the matched vulnerability features, generating mutated fields through protocol fuzz testing, implanting controllable vulnerability exploitation points in the response data, where the vulnerability exploitation points are synchronized with the security patch status of the real system, generating bait response data, and cyclically updating the defense strategy according to the attacker's interaction feedback on the bait response data.
6. The network attack AI detection and analysis method based on the intelligent Internet according to claim 5, characterized in that: The AI interaction verification process includes identifying abnormal patterns through AI according to the attacker's interaction feedback on the bait response data; Statistically calculating the standard deviation of the request interval time of the attacker's bait responses and calculating the burst coefficient to judge temporal anomalies; recording the permission levels of the virtual resources that the attacker attempts to access, recording the number of permission escalations and lateral movement attempts within a single client session, and judging permission anomalies; Calculating the tampering rate of the preset trap fields in the bait response and the structural deviation degree of the request message from the RFC standard to judge protocol anomalies; at the same time, establishing a mapping relationship table between abnormal pattern types and verification elements.
7. The network attack AI detection and analysis method based on the intelligent Internet according to claim 6, wherein: The distributed node consensus mechanism includes, according to the abnormal results of AI interaction verification, each node receiving the abnormal pattern type, and each node combining the local defense log to generate a defense strategy evaluation matrix; Calculating the priority weights of the defense strategies based on the evaluation matrix, establishing a topology isolation virtual execution sandbox in the constructed virtual environment, sequentially inputting the calculated defense strategy priority weights into the sandbox, importing suspicious requests into the sandbox, monitoring the system call sequence triggered by them, and deciding whether to allow the original request to pass according to the danger level of the behavior in the sandbox; When a new attack pattern is found in the topology isolation virtual execution sandbox, automatically generating a temporary filtering rule and broadcasting it to all nodes, and judging whether to store the temporary filtering rule in combination with the threat level assessment report.
8. A system adopting a network attack AI detection and analysis method based on the intelligent Internet as described in any one of claims 1 to 7, characterized in that: It includes a data collection and fusion module, a multi-modal interaction graph construction module, a defense module, an induction module, and an anomaly monitoring module; The data collection and fusion module collaboratively constructs an attack feature library through distributed edge nodes, each node generates feature parameters based on local attack events, and transmits them to the central server for dynamic fusion through encrypted transmission; The multi-modal interaction graph construction module constructs cross-protocol network behavior data into a multi-modal interaction graph, and identifies potential attack links based on the association strength between the graph nodes; The defense module deduces the attack intention according to the attack link, generates a defense strategy and verifies the feasibility of the strategy; The induction module deploys a virtualized network environment and dynamically injects induction features, and adjusts the induction strategy in real time according to the attacker's interaction behavior; The anomaly monitoring module monitors the abnormal patterns of the user behavior sequence, triggers an AI interaction verification process that can be dynamically adjusted, and stores the defense strategy through the distributed node consensus mechanism.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of a method for AI detection and analysis of network attacks based on the intelligent Internet according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of a method for detecting and analyzing network attacks AI based on the intelligent Internet described in any one of claims 1 to 7.
Citation Information
Cited By
Intelligent tracking and blocking method and system for network attack chain
CN120474841A
Network detection, protection and management method and device
CN120528710A
Data processing method and device for privacy protection of intelligent equipment with body
CN120541884A
Block chain-based information security intelligent management system and method
CN120639515A
Multi-level power network threat collaborative identification method and system
CN120658530A