Computer network security monitoring device and monitoring method
Through methods such as multi-source data acquisition, edge computing, multi-model fusion analysis and automated response, the problems of low detection efficiency, high false alarm rate and slow response in existing network security monitoring technologies are solved, and efficient and accurate network security monitoring is achieved.
Patent Information
- Application Number
- CN202510579566.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-07
- Publication Date
- 2025-07-08
AI Technical Summary
Existing network security monitoring technologies rely on a single data source or model, and centralized processing is difficult to cope with massive data, resulting in low detection efficiency, high false alarm rate and slow response.
Using technical means of multi-source data acquisition, edge computing, multi-model fusion analysis, automated response and distributed storage, data is collected in the network core switch, border router and server cluster through the data acquisition module, the edge computing module performs cleaning and abnormal detection, the data analysis module performs multi-model fusion analysis, the alarm module implements multi-modal alarm, the response module performs automated operations, and the storage module adopts distributed and hierarchical storage.
It improves the accuracy and efficiency of detection, reduces the false alarm rate, shortens the response time, and meets the real-time requirements of modern network security.
Smart Images

Figure CN120281559A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer network security, and particularly to a computer network security monitoring device and a monitoring method. Background Art
[0002] With the rapid development of information technology, computer networks have become an important infrastructure in modern society and are widely used in key fields such as finance, healthcare, education, and transportation. However, the expansion of network scale and the increase in complexity have also brought increasingly severe security challenges. Network attack methods are constantly evolving, from traditional viruses and Trojans to advanced persistent threats (APTs), distributed denial of service (DDoS) attacks, etc. The goals of attackers have also shifted from simple data theft to the destruction of critical infrastructure. These threats not only pose a serious threat to the data security of enterprises and individuals but may also have a significant impact on social stability and national security.
[0003] Currently, traditional network security monitoring methods mainly rely on a single data source or detection model, such as rule-based intrusion detection systems (IDSs) or signature-based antivirus software. When facing complex network attacks, these methods often exhibit problems such as low detection efficiency, high false alarm rates, and slow response speeds. In addition, with the explosive growth of network traffic, the traditional centralized processing mode is difficult to meet the real-time analysis and processing requirements of large-scale data, resulting in a lag in the discovery and response of security incidents and unable to meet the real-time and accuracy requirements of modern network security protection.
[0004] In recent years, the rapid development of edge computing and machine learning technologies has provided new solutions for network security monitoring. Edge computing can perform local processing and screening of data by deploying computing resources at network edge nodes, reducing data transmission latency and bandwidth pressure; while machine learning technology can automatically identify abnormal behaviors and predict potential threats through learning from a large amount of historical data. Therefore, there is an urgent need for a device and method that can efficiently and accurately monitor network security conditions and respond quickly to cope with increasingly complex network security threats. Summary of the Invention
[0005] Based on this, in view of the above problems, the present invention proposes a computer network security monitoring device and a monitoring method, which solve the problems of low detection efficiency, high false alarm rate, and slow response caused by the current network security monitoring technology relying on a single data source or model and the difficulty of centralized processing in coping with massive data.
[0006] The technical solution of the present invention is as follows:
[0007] A computer network security monitoring device, comprising:
[0008] A data acquisition module, used to collect network traffic data, system log data, and user behavior data at the network core switch, border router, and server cluster;
[0009] An edge computing module, used to clean, compress, and perform anomaly detection on the collected data, screen out abnormal data, and encrypt and transmit it;
[0010] A data analysis module, used to perform multi-model fusion analysis on abnormal data, combine a rule engine to judge the type of anomaly, and generate a prediction result of the network security status;
[0011] An alarm module, used to evaluate the threat level based on the prediction result and trigger multi-modal alarms;
[0012] A response module, used to execute automated response operations;
[0013] A storage module, used to store the prediction result and store it in layers according to the data heat;
[0014] Among them, the data acquisition module includes a network probe, a system log collector, and user behavior monitoring software; the edge computing module includes a data cleaning unit, a data compression unit, an anomaly detection unit, and an encryption transmission unit; the data analysis module includes a GBDT model unit, a One-Class SVM model unit, a rule engine unit, and a model fusion unit.
[0015] Preferably, the network probe is used to capture network traffic data in real time; the system log collector is used to collect the operating system and application program logs of servers and devices; the user behavior monitoring software is used to record user login, file operation, and network browsing behavior data; the data cleaning unit is used to remove special characters, invalid information, and duplicate data, and convert unstructured data into structured data; the data compression unit uses a lossless compression algorithm to reduce the data storage space and transmission bandwidth requirements; the anomaly detection unit uses any one of the Z-score analysis, interquartile range method, isolation forest algorithm, or one-class support vector machine algorithm to screen out abnormal data; the encryption transmission unit uses the AES-256 symmetric encryption algorithm to encrypt the abnormal data and transmits it through the SSL / TLS protocol.
[0016] Preferably, the GBDT model unit sets the number of iterations to 50 times, the learning rate to 0.1, and screens key features through the Gini impurity; the One-Class SVM model unit selects the radial basis function as the kernel function and optimizes the parameters through 5-fold cross-validation; the rule engine unit makes a matching judgment on the abnormal data according to the preset security rules; the model fusion unit uses the Stacking method to fuse the prediction results of the GBDT and One-Class SVM models.
[0017] Preferably, the alarm module includes:
[0018] A threat assessment unit, which is used to calculate a threat value according to the weights of the attack frequency of 40%, the attack type of 30%, and the number of affected devices of 30%, and divide it into three levels: high / medium / low;
[0019] A multi-modal alarm unit, which is used to trigger SMS, email, system pop-up windows, and enterprise WeChat alarms according to the threat level.
[0020] Preferably, the response module includes:
[0021] An Ansible automation unit, which is used to execute operations such as blocking the attack source IP, isolating devices, data backup, and encryption;
[0022] A log recording unit, which uses Elasticsearch and Kibana to record response operation logs;
[0023] An emergency plan optimization unit, which is used to simulate attack scenarios quarterly and optimize response measures.
[0024] Preferably, the storage module includes:
[0025] A distributed storage unit, which adopts the Ceph architecture, sets the number of replicas to 3, and has a storage capacity of 100TB;
[0026] A hierarchical storage unit, which is used to store frequently accessed data in solid-state drives, medium-frequency data in mechanical hard drives, and low-frequency data in tape libraries.
[0027] A computer network security monitoring method, which uses the above-mentioned computer network security monitoring device to perform computer network security monitoring, specifically including the following steps:
[0028] Step 1: Collect network traffic data, system log data, and user behavior data at the network core switch, border router, and server cluster through network probes, system log collectors, and user behavior monitoring software;
[0029] Step 2: Clean, compress, and perform anomaly detection on the collected data at the edge computing node, screen out the abnormal data, and encrypt and transmit it;
[0030] Step 3: Perform multi-model fusion analysis on the abnormal data, combine the rule engine to judge the abnormal type, and generate a prediction result of the network security status;
[0031] Step 4: Evaluate the threat level according to the prediction result and trigger multi-modal alarms;
[0032] Step 5: Perform automated response operations, including blocking the attacking source IP, isolating the device, backing up data, and encrypting operations;
[0033] Step 6: Store the prediction results in a distributed storage unit and store them in layers according to data popularity. Frequently accessed data is stored in a solid-state drive, medium-frequency data is stored in a mechanical hard drive, and low-frequency data is stored in a tape library.
[0034] Preferably, in Step 2, the anomaly detection uses any one of the Z-score analysis, interquartile range method, isolation forest algorithm, or one-class support vector machine algorithm; the encrypted transmission uses the AES-256 symmetric encryption algorithm and is transmitted through the SSL / TLS protocol;
[0035] In Step 3, the multi-model fusion analysis includes the fusion of the GBDT model and the One-Class SVM model. Among them, the GBDT model is set with 50 iterations and a learning rate of 0.1, and key features are screened through the Gini impurity. The One-Class SVM model selects the radial basis function as the kernel function and optimizes the parameters through 5-fold cross-validation.
[0036] Preferably, in Step 4, the threat level calculates the threat value according to the weights of the attack frequency of 40%, the attack type of 30%, and the number of affected devices of 30%, and is divided into three levels: high / medium / low, and text messages, emails, system pop-ups, and enterprise WeChat alarms are triggered according to the threat level;
[0037] In Step 5, the automated response operation is executed through the Ansible automation unit. The response operation logs are recorded using Elasticsearch and Kibana, and the response measures are optimized by simulating attack scenarios every quarter.
[0038] Preferably, in Step 3, the rule engine matches and judges the abnormal data according to the preset security rules. The preset security rules include:
[0039] Traffic anomaly rule: If the number of data packets sent by a certain IP address within 5 minutes exceeds 10,000, it is determined as abnormal traffic;
[0040] Port scanning rule: If an IP address attempts to connect to more than 50 different ports within 1 minute, it is determined as a port scanning behavior;
[0041] Abnormal login rule: If the same user account attempts to log in continuously and fails more than 5 times within 10 minutes, it is determined as an abnormal login.
[0042] Compared with the prior art, the beneficial effects of the present invention are:
[0043] When the present invention is in use, the data acquisition module collects multi-source data from the network core switch, the border router, and the server cluster. The edge computing module performs cleaning, compression, and anomaly detection at the data source to reduce the data transmission volume and the pressure on the central server. The data analysis module uses the GBDT model, the One-Class SVM model, and the rule engine for multi-model fusion analysis to improve the detection accuracy and reliability. The alarm module and the response module implement multi-modal alarms and automated responses to shorten the response time. The storage module adopts a distributed and hierarchical storage strategy to support the efficient storage and access of massive data. By combining these technical means of multi-source data acquisition, edge computing, multi-model fusion analysis, automated response, and distributed storage, the problems of the current network security monitoring technology relying on a single data source or model, and the difficulty of centralized processing in dealing with massive data, resulting in low detection efficiency, high false alarm rate, and slow response, are solved. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 FIG. is a schematic diagram of the framework structure of a computer network security monitoring device described in an embodiment of the present invention;
[0045] Figure 2 FIG. is a schematic diagram of the flow of a computer network security monitoring method described in an embodiment of the present invention;
[0046] DESCRIPTION OF THE REFERENCE NUMERALS:
[0047] 10 - data acquisition module, 20 - edge computing module, 30 - data analysis module, 40 - alarm module, 50 - response module, 60 - storage module. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0048] The embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0049] Embodiment:
[0050] As Figure 1 shown, this embodiment discloses a computer network security monitoring device, including:
[0051] A data acquisition module 10, configured to collect network traffic data, system log data, and user behavior data at a network core switch, a border router, and a server cluster;
[0052] An edge computing module 20, configured to clean, compress, and perform anomaly detection on the collected data, screen out abnormal data, and encrypt and transmit it;
[0053] A data analysis module 30, configured to perform multi-model fusion analysis on the abnormal data, combine a rule engine to determine the type of anomaly, and generate a prediction result of the network security status;
[0054] The alarm module 40 is used to evaluate the threat level according to the prediction result and trigger multimodal alarms.
[0055] The response module 50 is used to perform automated response operations.
[0056] The storage module 60 is used to store the prediction results and store them in layers according to data heat.
[0057] Among them, the data acquisition module 10 includes a network probe, a system log collector, and user behavior monitoring software; the edge computing module 20 includes a data cleaning unit, a data compression unit, an anomaly detection unit, and an encrypted transmission unit; the data analysis module 30 includes a GBDT model unit, a One-Class SVM model unit, a rule engine unit, and a model fusion unit.
[0058] When the present invention is in use, the data acquisition module 10 acquires multi-source data from the network core switch, the border router, and the server cluster. The edge computing module 20 performs cleaning, compression, and anomaly detection at the data source to reduce the data transmission volume and the pressure on the central server. The data analysis module 30 uses the GBDT model, the One-Class SVM model, and the rule engine for multi-model fusion analysis to improve the detection accuracy and reliability. The alarm module 40 and the response module 50 implement multimodal alarms and automated responses to shorten the response time. The storage module 60 adopts a distributed and hierarchical storage strategy to support the efficient storage and access of massive data. By combining these technical means of multi-source data acquisition, edge computing, multi-model fusion analysis, automated response, and distributed storage, the problems of low detection efficiency, high false alarm rate, and slow response caused by the current network security monitoring technology relying on a single data source or model and the difficulty of centralized processing in dealing with massive data are solved.
[0059] Among them, the network probe is used to capture network traffic data in real time; the system log collector is used to collect the operating system and application program logs of servers and devices; the user behavior monitoring software is used to record user login, file operation, and network browsing behavior data.
[0060] The present invention provides comprehensive network security information by multi-source data acquisition covering network traffic, system status, and user behavior. It can effectively avoid the limitations of a single data source, improve the comprehensiveness and accuracy of detection. At the same time, it captures data in real time to provide high-quality input for subsequent analysis.
[0061] Specifically, network probes are deployed on the network core switch and the border router to capture network traffic data in real time (such as data packets, protocol types). System log collectors are installed on servers and devices to collect operating system and application program logs (such as login records, error logs). User behavior monitoring software is deployed on user terminal devices to record user login, file operation, and network browsing behavior data.
[0062] Among them, the data cleaning unit is used to remove special characters, invalid information, and duplicate data, and convert unstructured data into structured data; the data compression unit uses a lossless compression algorithm to reduce the data storage space and transmission bandwidth requirements; the anomaly detection unit uses any one of the Z-score analysis, interquartile range method, isolation forest algorithm, or one-class support vector machine algorithm to screen out abnormal data; the encrypted transmission unit uses the AES-256 symmetric encryption algorithm to encrypt the abnormal data and transmits it through the SSL / TLS protocol.
[0063] Specifically, the data cleaning unit can use regular expressions to filter out invalid characters; it can detect and delete duplicate data based on hash values; it can parse log data into JSON format and extract key fields (such as timestamps, event types, user IDs). The data compression unit uses the LZ77 algorithm or the Zstandard algorithm.
[0064] The present invention preprocesses data at the edge node, reduces the transmission of invalid data, screens out abnormal data and encrypts and transmits it. It can effectively reduce the data transmission volume and the load of the central server, and improve the real-time performance. At the same time, encrypted transmission ensures data security and prevents theft or tampering.
[0065] Specifically, the edge computing module 20 is a group of edge computing devices in the prior art that can implement the functions of the present invention. Each of the above units can be mounted on the group of edge computing devices and executed on the group of edge computing devices.
[0066] Among them, the GBDT model unit sets the number of iterations to 50 times and the learning rate to 0.1, and screens key features through the Gini impurity; the One-Class SVM model unit selects the radial basis function as the kernel function and optimizes the parameters through 5-fold cross-validation; the rule engine unit makes a matching judgment on the abnormal data according to the preset security rules; the model fusion unit uses the Stacking method to fuse the prediction results of the GBDT and One-Class SVM models.
[0067] Through the fusion analysis of the GBDT model and the One-Class SVM model, and combined with the rule engine, the present invention comprehensively utilizes statistical learning and expert knowledge to improve the accuracy of anomaly detection. It can effectively reduce the false alarm rate and improve the detection accuracy. At the same time, combined with the rule engine, it can quickly match known attack patterns.
[0068] Specifically, the data analysis module 30 is a high-performance server cluster in the prior art that can implement the functions of the present invention. The above units can be installed on the high-performance server cluster and executed on the high-performance server cluster.
[0069] Among them, the alarm module 40 includes:
[0070] A threat assessment unit, which is used to calculate the threat value according to the weights of the attack frequency 40%, the attack type 30%, and the number of affected devices 30%, and divide it into three levels: high / medium / low;
[0071] A multimodal alarm unit, which is used to trigger text messages, emails, system pop-ups, and enterprise WeChat alarms according to the threat level.
[0072] The present invention quantifies the threat severity and notifies security personnel through multiple channels. It can effectively provide a clear threat level, facilitating quick decision-making by security personnel. At the same time, through multimodal alarms, it ensures the timely transmission of information and improves the response efficiency.
[0073] Among them, the response module 50 includes:
[0074] An Ansible automation unit, which is used to execute operations such as blocking the attack source IP, isolating devices, data backup, and encryption;
[0075] A log recording unit, which uses Elasticsearch and Kibana to record the response operation logs;
[0076] An emergency plan optimization unit, which is used to simulate attack scenarios every quarter and optimize the response measures.
[0077] The present invention shortens the processing time through automated response, the log recording supports auditing and analysis, and the emergency plan optimization improves the response ability. It can effectively improve the response speed and reduce the delay of human intervention. At the same time, through simulation drills, the emergency plan is continuously optimized to enhance the system robustness.
[0078] Among them, the storage module 60 includes:
[0079] A distributed storage unit, which adopts the Ceph architecture, sets the replication factor to 3, and has a storage capacity of 100TB;
[0080] A hierarchical storage unit, which is used to store frequently accessed data in solid-state drives, medium-frequency data in mechanical hard drives, and low-frequency data in tape libraries.
[0081] The present invention provides high availability and scalability through distributed storage, and hierarchical storage optimizes data access performance. It can effectively support massive data storage and meet future expansion requirements. At the same time, it reduces storage costs and improves data access efficiency.
[0082] As Figure 2 shown, a computer network security monitoring method uses the above-mentioned computer network security monitoring device to conduct computer network security monitoring, which specifically includes the following steps:
[0083] Step 1: Collect network traffic data, system log data, and user behavior data at the network core switch, border router, and server cluster through network probes, system log collectors, and user behavior monitoring software;
[0084] Step 2: Clean, compress, and perform anomaly detection on the collected data at the edge computing node, filter out the abnormal data, and encrypt and transmit it;
[0085] Step 3: Conduct multi-model fusion analysis on the abnormal data, combine the rule engine to judge the type of anomaly, and generate a prediction result of the network security status;
[0086] Step 4: Evaluate the threat level according to the prediction result and trigger multimodal alarms;
[0087] Step 5: Perform automated response operations, including blocking the attacking source IP, isolating the device, data backup, and encryption operations;
[0088] Step 6: Store the prediction result in the distributed storage unit and store it hierarchically according to the data heat. Frequently accessed data is stored in solid-state drives, medium-frequency data is stored in mechanical hard drives, and low-frequency data is stored in tape libraries.
[0089] The present invention realizes efficient and accurate network security monitoring through edge computing, multi-model fusion, and automated response. It effectively improves the detection efficiency and accuracy, reduces the false alarm rate, shortens the response time, and meets the real-time requirements of modern network security.
[0090] Among them, in step 2, the anomaly detection adopts any one of the Z-score analysis, interquartile range method, isolation forest algorithm, or one-class support vector machine algorithm; the encrypted transmission adopts the AES-256 symmetric encryption algorithm and is transmitted through the SSL / TLS protocol;
[0091] In step 3, the multi-model fusion analysis includes the fusion of the GBDT model and the One-Class SVM model. The GBDT model is set with 50 iterations and a learning rate of 0.1, and key features are screened by Gini impurity. The One-Class SVM model selects the radial basis function as the kernel function and optimizes the parameters through 5-fold cross-validation.
[0092] Specifically, in step 2, the anomaly detection unit uses Z-score analysis to calculate the Z-score value of the data point, and sets a threshold (such as |Z|>3) to determine anomalies. The specific calculation formula is as follows:
[0093]
[0094] Where:
[0095] X is the value of the current data point;
[0096] μ is the mean of the data set;
[0097] σ is the standard deviation of the data set.
[0098] By calculating the Z-score value of each data point and comparing it with a preset threshold (such as |Z|>3 or |Z|>2), it is determined whether the data point is an anomaly.
[0099] Specifically, in step 3, the model fusion unit uses the Stacking method to fuse the prediction results of the GBDT and One-Class SVM models. The specific logistic regression model formula is as follows:
[0100]
[0101] Where:
[0102] β0, β1, β2 are the parameters of the logistic regression model. β0 is the intercept term, β1 is the weight coefficient of F GBDT (x), and β2 is the weight coefficient of F SVM (x);
[0103] These parameters are usually learned through training data using optimization algorithms such as gradient descent, with the aim of minimizing the error between the prediction result and the true label;
[0104] P(y = 1∣x) is the probability that the sample x is determined to be an anomaly;
[0105] F GBDT (x) is the prediction result of the GBDT model, and F GBDT (x) is used to measure the anomaly degree of the sample x;
[0106] F SVM(x) is the prediction result of the One-Class SVM model, and F SVM (x) is used to measure the degree of abnormality of the sample x.
[0107] First, calculate the value of β0 + β1F GBDT (x) + β2F SVM (x). This value combines the prediction results of the two models and is adjusted by the weight coefficients. Then, take the negative of this value and use it as the input of the exponential function exp, and add 1 as the denominator and 1 as the numerator. Finally, the probability that the sample x is determined to be abnormal is obtained. In this way, by fusing the prediction results of two different models, their respective advantages can be comprehensively utilized to improve the accuracy of anomaly detection.
[0108] Among them, in step 4, the threat level calculates the threat value according to the weights of the attack frequency 40%, the attack type 30%, and the number of affected devices 30%, and is divided into three levels: high / medium / low, and triggers SMS, email, system pop-up window, and enterprise WeChat alarms according to the threat level;
[0109] The specific implementation steps for threat level classification are as follows:
[0110] Data input:
[0111] Obtain the attack frequency: Count the number of attack events occurring within a unit time (such as 5 minutes);
[0112] Obtain the attack type: Determine the attack type (such as DDoS, port scanning, brute force cracking, etc.) according to the rule engine or model analysis results;
[0113] Obtain the number of affected devices: Count the number of devices affected by the attack (such as servers, terminal devices);
[0114] Weight assignment:
[0115] Attack frequency weight: 40%;
[0116] Attack type weight: 30%;
[0117] Weight of the number of affected devices: 30%;
[0118] Threat value calculation:
[0119] Normalize each index (such as mapping the attack frequency to 0 - 100 points);
[0120] Calculate the threat value:
[0121] Threat value = (attack frequency × 0.4) + (attack type × 0.3) + (number of affected devices × 0.3);
[0122] Threat level classification:
[0123] High level: threat value ≥ 80;
[0124] Medium level: 40 ≤ threat value < 80;
[0125] Low level: threat value < 40.
[0126] For different metrics, the normalization method will be different. Here, different normalization strategies are adopted for the attack frequency, attack type, and the number of affected devices respectively:
[0127] Attack frequency: A maximum attack frequency value can be set according to historical data or experience, and map the current attack frequency to 0 - 100 points.
[0128] Attack type: A score can be pre - assigned to each attack type, and directly use this score as the normalization result.
[0129] Number of affected devices: Similarly, a maximum number of affected devices can be set according to historical data or experience, and map the current number of affected devices to 0 - 100 points.
[0130] For example: Set the attack frequency value to 100 times / 5 minutes, at this time it is normalized to 100 points, set the normalization score for "DDoS" to 90 points, the normalization score for "port scanning" to 70 points, the normalization score for "brute - force cracking" to 80 points, set the number of affected devices to 50, and at this time the normalization score is 50 points.
[0131] Specific examples are as follows:
[0132] Attack frequency: 100 times / 5 minutes (normalized to 100 points);
[0133] Attack type: DDoS attack (normalized to 90 points);
[0134] Number of affected devices: 50 (normalized to 50 points);
[0135] Threat value calculation:
[0136] Threat value = (100 × 0.4)+(90 × 0.3)+(50 × 0.3)=40 + 27+15 = 82;
[0137] Threat level: High level.
[0138] Specific steps for alarm implementation are as follows:
[0139] Alarm method configuration:
[0140] SMS alarm: Integrate SMS gateways (such as Alibaba Cloud SMS Service, Tencent Cloud SMS Service), configure SMS templates and recipient mobile phone numbers;
[0141] Email alarm: Integrate an SMTP email server (such as Gmail, Outlook), and configure the sender's email address, recipient's email address, and email template;
[0142] System pop-up alarm: Implement a pop-up notification function on the front-end page of the security management platform;
[0143] Enterprise WeChat alarm: Integrate the Enterprise WeChat API and configure robot or application message push;
[0144] Alarm trigger logic:
[0145] High-level threat: Trigger all alarm methods (SMS, email, system pop-up, Enterprise WeChat);
[0146] Medium-level threat: Trigger email, system pop-up, and Enterprise WeChat alarms;
[0147] Low-level threat: Trigger system pop-up and Enterprise WeChat alarms;
[0148] Alarm content generation;
[0149] Alarm sending:
[0150] SMS alarm: Call the SMS gateway API and send the alarm content to the specified mobile phone number;
[0151] Email alarm: Call the SMTP server API and send the alarm email to the specified email address;
[0152] System pop-up alarm: Display a pop-up notification on the front-end page with the alarm information as the content;
[0153] Enterprise WeChat alarm: Call the Enterprise WeChat API and send the alarm message to the specified group or user.
[0154] Among them, an example of the alarm content template is as follows:
[0155] Threat level: High;
[0156] Attack type: DDoS attack;
[0157] Attack frequency: 100 times / 5 minutes;
[0158] Number of affected devices: 50;
[0159] Suggested measures: Immediately block the attack source IP and isolate the affected devices.
[0160] In step 5, the automated response operation is executed by the Ansible automation unit, the response operation log is recorded by Elasticsearch and Kibana, and the response measures are optimized by simulating the attack scenario every quarter.
[0161] Among them, in step 3, the rule engine matches and judges the abnormal data according to the preset security rules, and the preset security rules include:
[0162] Traffic anomaly rule: If the number of data packets sent by a certain IP address within 5 minutes exceeds 10,000, it is determined as abnormal traffic;
[0163] Port scanning rule: If an IP address attempts to connect to more than 50 different ports within 1 minute, it is determined as a port scanning behavior;
[0164] Abnormal login rule: If the same user account attempts to log in and fails continuously more than 5 times within 10 minutes, it is determined as an abnormal login.
[0165] As a further preference, the preset security rules further include:
[0166] Abnormal file operation rule: If an ordinary user performs a write operation on a sensitive file directory during non-working hours, it is determined as an abnormal file operation;
[0167] System process anomaly rule: If the system log records that a certain process crashes and restarts multiple times within 3 minutes, it is determined as a process anomaly;
[0168] Permission change anomaly rule: If the permission of an ordinary user is promoted to an administrator permission without the operation of an administrator, it is determined as a permission change anomaly.
[0169] Among them, in step 2, the data cleaning includes removing special characters, invalid information and duplicate data, and converting unstructured data into structured data; the data compression uses a lossless compression algorithm to reduce the data storage space and transmission bandwidth requirements.
[0170] Among them, in step 6, the distributed storage unit adopts the Ceph architecture, sets the number of replicas to 3, and the storage capacity is 100TB; the hierarchical storage unit dynamically migrates data according to the data access frequency, stores high-frequency access data in solid-state drives, medium-frequency data in mechanical hard drives, and low-frequency data in tape libraries.
[0171] Among them, in step 5, the automated response operation further includes log recording and emergency plan optimization, where:
[0172] Log recording uses Elasticsearch and Kibana to record the response operation logs, supporting fast query and visual analysis;
[0173] Emergency plan optimization simulates attack scenarios every quarter, optimizes response measures and updates the rule library and model parameters.
[0174] Among them, in step 3, the multi-model fusion analysis adopts the Stacking method, and the prediction results of the GBDT model and the One-Class SVM model are used as new features to input into the logistic regression model to generate the final anomaly detection result.
[0175] Among them, in step 4, the multi-modal alarm includes SMS, email, system pop-up window and enterprise WeChat alarm, and dynamically adjusts the alarm priority and notification scope according to the threat level.
[0176] Among them, in step 2, the edge computing node is deployed near the network core switch, border router and server cluster to reduce data transmission latency and the load of the central server.
[0177] The method of the present invention collects network traffic data, system log data and user behavior data at the network core switch, border router and server cluster through network probes, system log collectors and user behavior monitoring software, and can comprehensively and multi-dimensionally obtain network operation information. Network traffic data can reflect the usage of the network and potential attack signs; system log data records important events and operations of the system; user behavior data can discover abnormal user operations, providing a rich and accurate data basis for subsequent security monitoring. Collecting data at key network nodes can timely capture changes and anomalies in the network, ensuring the timeliness and effectiveness of subsequent analysis and meeting the requirements of modern network security real-time monitoring.
[0178] Any one of the Z-score analysis, interquartile range method, isolation forest algorithm or one-class support vector machine algorithm is used for anomaly detection. These algorithms have their own advantages, and appropriate algorithms can be selected according to different data characteristics and application scenarios to improve the accuracy and flexibility of anomaly detection. At the same time, data cleaning is used to remove special characters, invalid information and duplicate data, and convert unstructured data into structured data, improving the quality and usability of the data and facilitating subsequent analysis and processing. The lossless compression algorithm reduces the data storage space and transmission bandwidth requirements, reduces the data storage and transmission costs, and also improves the data processing efficiency. The AES-256 symmetric encryption algorithm is adopted and the anomaly data is transmitted through the SSL / TLS protocol to ensure the security and integrity of the data during transmission and prevent the data from being stolen or tampered with.
[0179] Deploying the edge computing node near the network core switch, border router and server cluster reduces data transmission latency and the load of the central server, improving the response speed and overall performance of the system.
[0180] The prediction results of the GBDT model and the One-Class SVM model are used as new features and input into the logistic regression model by adopting the Stacking method to generate the final anomaly detection results. This multi-model fusion method can give full play to the advantages of different models, improve the accuracy and reliability of anomaly detection, and reduce the false alarm rate. At the same time, according to the preset security rules, matching judgments are made on the abnormal data, such as traffic anomaly rules, port scanning rules, etc. These rules can quickly identify common network attack behaviors, provide a clear basis for the judgment of anomaly types, and enhance the security and pertinence of the system.
[0181] The threat value is calculated according to the weights of the attack frequency, attack type, and the number of affected devices, and is divided into three levels: high, medium, and low. This scientific evaluation method can accurately reflect the severity of network security threats and provide strong support for subsequent response decisions. At the same time, multi-modal alarms are adopted, including SMS, email, system pop-up windows, and enterprise WeChat alarms, and the alarm priority and notification scope are dynamically adjusted according to the threat level. The multi-modal alarm method can ensure that security information is timely notified to relevant personnel and improve the efficiency of emergency response. Different threat levels correspond to different alarm methods, which can reasonably allocate resources and avoid unnecessary interference.
[0182] Automated response operations are executed through the Ansible automation unit, such as blocking the attack source IP, isolating devices, data backup, and encryption operations, etc. It can quickly and accurately respond to network security threats, shorten the response time, and reduce losses. At the same time, Elasticsearch and Kibana are used to record the response operation logs, supporting fast query and visualization analysis, which is convenient for security personnel to trace and analyze events, summarize experience and lessons, and provide a basis for subsequent security policy adjustments. Simulate attack scenarios every quarter, optimize the response measures, and update the rule library and model parameters to enable the system to continuously adapt to new security threats and improve the security and reliability of the system.
[0183] The distributed storage unit adopts the Ceph architecture, with the replication factor set to 3 and the storage capacity of 100TB, ensuring the high availability and reliability of the data. The setting of multiple replicas can prevent data loss, and at the same time, the distributed architecture can improve the read and write performance of the data. At the same time, the data is dynamically migrated according to the data access frequency. Frequently accessed data is stored on solid-state drives, medium-frequency data is stored on mechanical hard drives, and low-frequency data is stored in tape libraries. This hierarchical storage method can reasonably utilize storage resources, reduce storage costs, and meet the access requirements of different data at the same time.
[0184] In summary, the method of the present invention realizes efficient and accurate network security monitoring through technical means such as edge computing, multi-model fusion, and automated response, improves the detection efficiency and accuracy, reduces the false alarm rate, shortens the response time, and meets the real-time requirements of modern network security.
[0185] The above-described embodiments merely represent the specific implementation manners of the present invention, and their descriptions are relatively specific and detailed. However, they should not be construed as limiting the scope of the patent of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention.
Claims
1. A computer network security monitoring device, characterized in that, Including: A data collection module (10) for collecting network traffic data, system log data, and user behavior data at a network core switch, a border router, and a server cluster; An edge computing module (20) for cleaning, compressing, and detecting anomalies in the collected data, screening out abnormal data, and encrypting and transmitting it; A data analysis module (30) for performing multi-model fusion analysis on the abnormal data, combining a rule engine to determine the type of anomaly, and generating a prediction result of the network security status; An alarm module (40) for evaluating the threat level according to the prediction result and triggering multi-modal alarms; A response module (50) for performing automated response operations; A storage module (60) for storing the prediction results and storing them in layers according to data popularity; Among them, the data collection module (10) includes a network probe, a system log collector, and user behavior monitoring software; the edge computing module (20) includes a data cleaning unit, a data compression unit, an anomaly detection unit, and an encryption transmission unit; the data analysis module (30) includes a GBDT model unit, a One-Class SVM model unit, a rule engine unit, and a model fusion unit.
2. The computer network security monitoring device according to claim 1, characterized in that The network probe is used to capture network traffic data in real time; the system log collector is used to collect the operating system and application program logs of servers and devices; the user behavior monitoring software is used to record user login, file operation, and network browsing behavior data; the data cleaning unit is used to remove special characters, invalid information, and duplicate data, and convert unstructured data into structured data; the data compression unit uses a lossless compression algorithm to reduce the data storage space and transmission bandwidth requirements; the anomaly detection unit uses any one of the Z-score analysis, interquartile range method, isolation forest algorithm, or one-class support vector machine algorithm to screen out abnormal data; the encryption transmission unit uses the AES-256 symmetric encryption algorithm to encrypt the abnormal data and transmits it through the SSL / TLS protocol.
3. The computer network security monitoring device according to claim 2, wherein, The GBDT model unit is set with 50 iterations and a learning rate of 0.1, and key features are screened by Gini impurity; The One-Class SVM model unit selects the radial basis function as the kernel function and optimizes the parameters through 5-fold cross-validation; the rule engine unit makes a matching judgment on the abnormal data according to the preset security rules; the model fusion unit uses the Stacking method to fuse the prediction results of the GBDT and One-Class SVM models.
4. A computer network security monitoring device according to claim 3, characterized in that, The alarm module (40) includes: A threat assessment unit for calculating the threat value according to the weights of the attack frequency of 40%, the attack type of 30%, and the number of affected devices of 30%, and dividing it into three levels: high / medium / low; A multi-modal alarm unit for triggering SMS, email, system pop-up windows, and enterprise WeChat alarms according to the threat level.
5. A computer network security monitoring device according to claim 4, characterized in that, The response module (50) includes: An Ansible automation unit for performing operations such as blocking the attack source IP, isolating devices, backing up data, and encrypting. Logging unit, which uses Elasticsearch and Kibana to record response operation logs; Emergency plan optimization unit, which is used to simulate attack scenarios every quarter and optimize response measures.
6. The computer network security monitoring device according to claim 5, characterized in that, The storage module (60) includes: Distributed storage unit, which adopts the Ceph architecture, sets the replication factor to 3, and has a storage capacity of 100TB; Hierarchical storage unit, which is used to store frequently accessed data in solid-state drives, medium-frequency data in mechanical hard drives, and low-frequency data in tape libraries.
7. A computer network security monitoring method, characterized in that, Using the computer network security monitoring device described in any one of the above claims 1-6 for network security monitoring, specifically including the following steps: Step 1: Collect network traffic data, system log data, and user behavior data at the network core switch, border router, and server cluster through network probes, system log collectors, and user behavior monitoring software; Step 2: Clean, compress, and perform anomaly detection on the collected data at the edge computing node, filter out abnormal data, and encrypt and transmit it; Step 3: Perform multi-model fusion analysis on the abnormal data, combine the rule engine to judge the type of anomaly, and generate a prediction result of the network security status; Step 4: Evaluate the threat level according to the prediction result and trigger multi-modal alarms; Step 5: Execute automated response operations, including blocking the attacking source IP, isolating devices, data backup, and encryption operations; Step 6: Store the prediction result in the distributed storage unit, and perform hierarchical storage according to the data heat. Frequently accessed data is stored in solid-state drives, medium-frequency data is stored in mechanical hard drives, and low-frequency data is stored in tape libraries.
8. A computer network security monitoring method according to claim 7, characterized in that, In Step 2, the anomaly detection adopts any one of the Z-score analysis, interquartile range method, isolation forest algorithm, or one-class support vector machine algorithm; the encrypted transmission adopts the AES-256 symmetric encryption algorithm and is transmitted through the SSL / TLS protocol; In Step 3, the multi-model fusion analysis includes the fusion of the GBDT model and the One-Class SVM model. Among them, the GBDT model sets the number of iterations to 50 times and the learning rate to 0.1, and filters key features through the Gini impurity. The One-Class SVM model selects the radial basis function as the kernel function and optimizes the parameters through 5-fold cross-validation.
9. A computer network security monitoring method according to claim 8, characterized in that, In Step 4, the threat level calculates the threat value according to the weights of the attack frequency of 40%, the attack type of 30%, and the number of affected devices of 30%, and is divided into three levels: high / medium / low. And trigger SMS, email, system pop-up window, and enterprise WeChat alarms according to the threat level; In Step 5, the automated response operation is executed through the Ansible automation unit. The response operation logs are recorded by Elasticsearch and Kibana, and the response measures are optimized by simulating attack scenarios every quarter.
10. A computer network security monitoring method according to claim 9, characterized in that, In Step 3, the rule engine performs matching and judgment on the abnormal data according to the preset security rules. The preset security rules include: Traffic anomaly rule: If the number of data packets sent by a certain IP address exceeds 10,000 within 5 minutes, it is determined as abnormal traffic; Port scanning rule: If an IP address attempts to connect to more than 50 different ports within 1 minute, it is determined as a port scanning behavior; Abnormal login rule: If the same user account attempts to log in and fails continuously more than 5 times within 10 minutes, it is determined as an abnormal login.
Citation Information
Cited By
Behavior identification monitoring system based on security instruction
CN121959557A