Network security threat perception identification response method based on security knowledge graph
By building a security knowledge graph, obtaining key indicators of enterprise network equipment in real time, dynamically adjusting traffic and quantity thresholds, and identifying network threats, it solves the problems of low recognition accuracy and slow response speed caused by large data volume and model dependence in the existing technology, and achieves efficient and accurate network security threat identification and response.
Patent Information
- Application Number
- CN202510532316.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2045-04-25
AI Technical Summary
The existing network security dynamic warning system based on knowledge graph faces data acquisition performance bottlenecks in high-traffic network environments. The large amount of data has led to a decrease in the system processing speed, the model training time is long and the generalization ability is limited, so it is impossible to efficiently identify network security threats in real time, reducing the accuracy and reliability of early warnings.
By building a security knowledge graph, we can obtain the traffic change rate, inbound and outbound traffic ratio, source IP address, request success rate and session interrupt rate of enterprise network equipment in real time, dynamically adjust the traffic and quantity thresholds, filter out temporary, concerned, tag, risk and suspicious nodes, form graph edges, identify abnormal nodes and issue alarms.
It realizes efficient perception and accurate identification of network security threats, dynamically adjusts judgment standards, improves the long-term effectiveness and adaptability of the system, avoids misjudgment caused by short-term traffic fluctuations, and recognizes complex attack paths and coordinated attack behaviors.
Smart Images

Figure CN120301665A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular, to a network security threat perception recognition and response method based on a security knowledge graph. Background Art
[0002] In the enterprise internal network environment, there are usually a large number of business systems and complex network topologies. Employees access enterprise internal application programs and data resources through various terminal devices, and at the same time, the enterprise also needs to conduct data interaction with external partners. Such a complex network environment provides more intrusion opportunities and hiding spaces for network security threats. Traditional network security protection can resist some common network attacks to a certain extent, but in the face of increasingly complex new threats, its limitations are gradually emerging.
[0003] The patent document with the publication number CN117834282A discloses a network security dynamic early warning system, method and storage medium based on a knowledge graph. The system includes: a network data collection module for collecting data from a network environment; a data processing and analysis module for processing and analyzing the collected data; a knowledge graph construction module for converting the processed data into a structured knowledge graph; a deep learning and pattern recognition module for analyzing the data in the knowledge graph to identify and learn network security-related patterns and behaviors and obtain recognition results; an early warning and response module for generating and issuing network security early warnings according to the recognition results; and a data storage module for storing data, as well as the knowledge graph and recognition results.
[0004] It can be seen that the network security dynamic early warning system based on the knowledge graph has the following problems: the network data volume is huge, especially in a high-traffic network environment, the data collection module faces performance bottlenecks and cannot collect data in real time and efficiently; the large data volume will cause the system processing speed to decrease and cannot respond in real time; machine learning algorithms require a large amount of labeled data for training and the training time is long; the limited model generalization ability will cause the system to be unable to effectively identify new network security threats, reducing the accuracy and reliability of early warnings. Summary of the Invention
[0005] Therefore, the present invention provides a network security threat perception recognition and response method based on a security knowledge graph, which is used to overcome the problems of low accuracy of danger recognition and slow response speed caused by excessive data volume and over-reliance on models in the prior art through a security knowledge graph, multi-level traffic index analysis and a dynamic adjustment mechanism.
[0006] To achieve the above object, the present invention provides a network security threat perception recognition and response method based on a security knowledge graph, including:
[0007] Obtaining in real time the traffic change rate, the incoming and outgoing traffic ratio, the source IP address, the request success rate, and the session interruption rate of each monitoring node in the security knowledge graph constructed by an enterprise with each network device as a monitoring node;
[0008] Determining a number of temporary nodes and attention nodes according to the traffic change rate and a preset traffic threshold;
[0009] Determining a number of marked nodes according to the incoming and outgoing traffic ratio and the source IP address of the attention node and any of the temporary nodes within a preset marking duration;
[0010] Determining a number of risk nodes and a number of suspicious nodes according to the request success rate and the session interruption rate of each of the marked nodes;
[0011] Determining a number of risk nodes according to the incoming and outgoing traffic ratio of the attention node and any of the suspicious nodes within a preset correction duration;
[0012] Connecting two risk nodes according to the source IP addresses of any two of the risk nodes to obtain a number of graph edges;
[0013] Determining a number of abnormal nodes according to the number of times each of the risk nodes is connected by the graph edges and a preset number threshold;
[0014] Adjusting the preset traffic threshold according to the traffic change rate, the incoming and outgoing traffic ratio, and the number of each of the abnormal nodes to obtain an adjusted traffic threshold, or adjusting the preset number threshold to obtain an adjusted number threshold;
[0015] Issuing an alarm for all the abnormal nodes re-determined based on the adjusted traffic threshold or the adjusted number threshold.
[0016] Further, determining a number of temporary nodes and attention nodes according to the traffic change rate and a preset traffic threshold includes:
[0017] When the traffic change rate is greater than the preset traffic threshold, determining the monitoring node as the temporary node to obtain a number of the temporary nodes;
[0018] Comparing the traffic change rates of all the temporary nodes, and determining the temporary node with the largest traffic change rate as the attention node.
[0019] Further, determining a number of marked nodes according to the incoming and outgoing traffic ratio and the source IP address of the attention node and any of the temporary nodes within a preset marking duration includes:
[0020] Calculate the standard deviation of the in-out flow ratio of the concerned node to obtain the concerned flow ratio fluctuation value;
[0021] Count the number of different source IP addresses among all the source IP addresses of the concerned node, calculate the probability of each source IP address appearing, calculate the Shannon entropy based on all the probabilities, and calculate the standard deviation of the Shannon entropy to obtain the concerned dispersion fluctuation value;
[0022] Perform normalization processing on the concerned flow ratio fluctuation value to obtain the concerned flow normalization value, and perform normalization processing on the concerned dispersion fluctuation value to obtain the concerned dispersion normalization value;
[0023] Calculate the correlation coefficient between the concerned flow normalization value and the concerned dispersion normalization value to obtain the concerned correlation degree;
[0024] When the concerned correlation degree is greater than the preset correlation degree threshold, calculate the standard deviation of the in-out flow ratio of each of the temporary nodes to obtain the temporary flow ratio fluctuation value;
[0025] Count the number of different source IP addresses among all the source IP addresses of the temporary node, calculate the probability of each source IP address appearing, calculate the Shannon entropy based on all the probabilities, and calculate the standard deviation of the Shannon entropy to obtain the temporary dispersion fluctuation value;
[0026] Perform normalization processing on the temporary flow ratio fluctuation value to obtain the temporary flow normalization value, and perform normalization processing on the temporary dispersion fluctuation value to obtain the temporary dispersion normalization value;
[0027] Calculate the correlation coefficient between the temporary flow normalization value and the temporary dispersion normalization value to obtain the temporary correlation degree;
[0028] When the temporary correlation degree is greater than the concerned correlation degree, determine the temporary node and the concerned node as the marked nodes to determine a number of marked nodes.
[0029] Further, determine a number of risk nodes and a number of suspicious nodes according to the request success rate and the session interruption rate of each of the marked nodes, including:
[0030] Draw a change curve of the request success rate within a preset determination duration to obtain a request change curve;
[0031] Calculate the slope change rate of the request change curve at a preset time distance to obtain a number of request slope change rates;
[0032] When the number of times the request slope change rate is less than zero is greater than the preset number threshold, draw a change curve of the session interruption rate within a preset determination duration to obtain an interruption change curve;
[0033] Calculate the slope change rate of the interruption change curve of the preset time distance to obtain a number of interruption slope change rates;
[0034] When the number of times the interruption slope change rate is greater than zero is greater than the preset number threshold, calculate the mean value of all the request slope change rates to obtain the average request change rate, and calculate the mean value of all the interruption slope change rates to obtain the average interruption change rate;
[0035] Calculate the relative deviation between the absolute value of the average request change rate and the absolute value of the average interruption change rate to obtain the slope deviation;
[0036] When the slope deviation is less than the preset slope deviation threshold, determine a number of risk nodes and a number of suspicious nodes according to the request success rate, the session interruption rate, and the preset consistency threshold.
[0037] Further, determining a number of risk nodes and a number of suspicious nodes according to the request success rate, the session interruption rate, and the preset consistency threshold includes:
[0038] Calculate the standard deviation of the request success rate within the preset determination duration to obtain the request fluctuation value;
[0039] Calculate the standard deviation of the session interruption rate within the preset determination duration to obtain the interruption fluctuation value;
[0040] Normalize the request fluctuation value within the preset determination duration to obtain the standard request fluctuation value, and normalize the interruption fluctuation value within the preset determination duration to obtain the standard interruption fluctuation value;
[0041] Calculate the correlation coefficient between the standard request fluctuation value and the standard interruption fluctuation value to obtain the change consistency;
[0042] When the change consistency is less than zero and the absolute value of the change consistency is greater than the preset consistency threshold, determine the concerned node as the risk node to determine a number of risk nodes;
[0043] When the change consistency is greater than zero and the absolute value of the change consistency is greater than the preset consistency threshold, determine the concerned node as the suspicious node to determine a number of suspicious nodes.
[0044] Further, determining a number of risk nodes according to the in-out flow ratio of the concerned node and any suspicious node within the preset correction duration includes:
[0045] Calculate the standard deviation of the in-out flow ratio of the concerned node to obtain the concerned in-out ratio fluctuation value;
[0046] Calculate the standard deviation of the in-out flow ratio of the suspicious node to obtain the suspicious in-out ratio fluctuation value;
[0047] Normalize the concerned in-out ratio fluctuation value to obtain the concerned in-out ratio normalized value, and normalize the suspicious in-out ratio fluctuation value to obtain the suspicious in-out ratio normalized value;
[0048] Calculate the relative deviation between the concerned in-out ratio normalized value and the suspicious in-out ratio normalized value to obtain the in-out ratio deviation value;
[0049] When the in-out ratio deviation value is less than the preset in-out ratio deviation threshold, determine the suspicious node as the risk node to identify a number of risk nodes.
[0050] Further, connect any two risk nodes according to their source IP addresses to obtain a number of graph edges, including:
[0051] Count the occurrence times of all the source IP addresses of each risk node to obtain the source IP count;
[0052] When the ratio of the source IP counts of any two risk nodes is less than the preset ratio threshold, calculate the coincidence rate of the source IP addresses of the two risk nodes to obtain the IP coincidence rate;
[0053] When the IP coincidence rate is greater than the preset coincidence rate threshold, connect the two risk nodes to obtain a number of graph edges.
[0054] Further, determine a number of abnormal nodes according to the number of connections of each risk node by the graph edges and the preset number threshold, including:
[0055] When the number is greater than the preset number threshold, determine the risk node as the abnormal node to identify a number of abnormal nodes.
[0056] Further, adjust the preset flow threshold to obtain an adjusted flow threshold, or adjust the preset number threshold to obtain an adjusted number threshold according to the flow change rate, the in-out flow ratio, and the number of each abnormal node, including:
[0057] Calculate the relative deviation between the flow change rate and the preset flow threshold to obtain the change deviation;
[0058] Calculate the relative deviation between the in-out flow ratio and the preset flow ratio threshold to obtain the flow ratio deviation;
[0059] Perform a weighted sum of the change deviation, the preset flow change weight, the flow ratio deviation, and the preset flow ratio weight to obtain the deviation index;
[0060] Adjust the preset flow threshold according to the deviation index, the preset deviation index range, and the quantity to obtain an adjusted flow threshold, or adjust the preset quantity threshold to obtain an adjusted quantity threshold.
[0061] Further, adjusting the preset flow threshold according to the deviation index, the preset deviation index range, and the quantity to obtain an adjusted flow threshold, or adjusting the preset quantity threshold to obtain an adjusted quantity threshold, includes:
[0062] When the deviation index is greater than the maximum value of the preset deviation index range, increase the preset flow threshold according to the relative deviation between the deviation index and the maximum value of the preset deviation index range and a preset first adjustment coefficient to obtain an adjusted flow threshold;
[0063] When the deviation index is less than the minimum value of the preset deviation index range, calculate the relative deviation between the deviation index and the minimum value of the preset deviation index range to obtain an index deviation;
[0064] Calculate the absolute value of the relative deviation between the quantity and the preset quantity threshold to obtain a quantity deviation;
[0065] Perform a weighted sum of the quantity deviation, the preset quantity deviation weight, the index deviation, and the preset index deviation weight to obtain an adjustment factor;
[0066] Increase the preset quantity threshold according to the adjustment factor and a preset second adjustment coefficient to obtain an adjusted quantity threshold.
[0067] Compared with the prior art, the beneficial effects of the present invention are as follows: by obtaining the key indicators of each network device monitoring node of an enterprise in real time, screening out temporary nodes and nodes of concern based on the flow change rate and the preset flow threshold, further determining marked nodes by combining the incoming and outgoing flow ratio and the source IP address, determining risk nodes and suspicious nodes based on the request success rate and the session interruption rate, effectively distinguishing normal network fluctuations from malicious attack behaviors, and re-determining risk nodes through the incoming and outgoing flow ratio can dynamically adjust the determination of risk nodes, avoiding misjudgment caused by short-term traffic fluctuations. Forming graph edges by connecting risk nodes through the source IP address, and determining abnormal nodes according to the connection quantity and the quantity threshold, utilizing the correlation analysis ability of the knowledge graph to identify complex attack paths and collaborative attack behaviors. Finally, by dynamically adjusting the preset flow threshold and the quantity threshold, optimizing the determination criteria in real time according to the changes in the network environment, ensuring the long-term effectiveness and adaptability of the system, and effectively solving the problems of low accuracy of danger identification and slow response speed due to excessive data volume and over-reliance on models.
[0068] Furthermore, through the judgment of the traffic change rate threshold and comparative analysis, potential temporary nodes can be quickly screened out. Abnormal traffic changes are usually associated with network attacks or abnormal behaviors. Among many abnormal nodes, the node with the most significant traffic change is often the potential threat source that deserves the most attention. This can not only quickly narrow the monitoring scope, improve the analysis efficiency of the system, but also ensure the priority handling of the most likely threats, thus achieving the efficient perception and accurate identification of network security threats.
[0069] Furthermore, by combining indicators such as traffic ratio fluctuation, source IP address dispersion degree, and correlation coefficient, temporary nodes that are similar in behavior pattern to the nodes of concern and may be related can be accurately identified, thereby determining the marked nodes; the traffic ratio fluctuation value reflects the stability of the node traffic change, the dispersion degree measures the diversity of traffic sources, and the correlation coefficient further quantifies the correlation between traffic fluctuation and source IP address dispersion degree; through normalization processing and correlation calculation, the system can objectively compare the behavior characteristics of different nodes, avoiding misjudgment caused by the contingency of a single indicator. When the correlation degree of the temporary node is higher than the preset threshold and greater than the correlation degree of the node of concern, it indicates that the behavior pattern of the temporary node is highly similar to that of the node of concern and may have participated in similar network activities, thus marking it as a marked node. This can effectively filter out noise data and accurately locate potential threat nodes.
[0070] Furthermore, by plotting the change curves of the request success rate and session interruption rate and calculating their slope change rates, the change trends of these key indicators can be dynamically monitored. A request slope change rate less than zero indicates a decrease in the request success rate, which may imply service availability problems; an interruption slope change rate greater than zero indicates an increase in the session interruption rate, which may imply connection stability problems. By setting a preset number threshold, nodes with frequent occurrences of these changes are screened out to further focus on potential problem nodes. Calculating the average request change rate and average interruption change rate and evaluating the relative deviation (slope deviation) between them can determine whether the change trends of the request success rate and session interruption rate are consistent. If the slope deviation is less than the preset threshold, it indicates that the change trends of the two are correlated and may be manifestations of the same network problem, thereby enabling more accurate identification of risk nodes and suspicious nodes.
[0071] Furthermore, by quantifying the fluctuations in the request success rate and session interruption rate and calculating their correlation coefficient, risk nodes and suspicious nodes can be accurately distinguished. The fluctuation values of the request success rate and the session interruption rate reflect the stability of the nodes within the preset determination duration. When the change consistency is less than zero and its absolute value is greater than the preset consistency threshold, it indicates that the change trends of the two are negatively correlated and the difference is significant, which usually implies the existence of potential network attacks or faults. Therefore, this node is determined as a risk node. On the contrary, when the change consistency is greater than zero and its absolute value is greater than the preset consistency threshold, it indicates that the change trends of the two are positively correlated and the difference is significant, and there may be anomalies. Therefore, this node is determined as a suspicious node. It can effectively distinguish different types of abnormal nodes, improving the accuracy and reliability of network security threat identification.
[0072] Furthermore, by quantifying and comparing the fluctuations in the in-out traffic ratio of the concerned nodes and the suspicious nodes, it is possible to dynamically identify whether the suspicious nodes with potential threats should be further determined as risk nodes. By calculating the standard deviation of the in-out traffic ratio, the respective fluctuation values are obtained, which can capture the change stability of the traffic ratio; calculating the relative deviation between the normalized values further quantifies the difference degree of the traffic ratio fluctuations between the concerned nodes and the suspicious nodes; when the in-out ratio deviation value is less than the preset threshold, it indicates that the traffic ratio fluctuation of the suspicious node is similar to that of the concerned node, which means that the behavior pattern of the suspicious node is similar to the known risk pattern. Therefore, it is determined as a risk node. It can dynamically adjust the assessment of suspicious nodes, avoid misjudgment caused by short-term traffic fluctuations, and ensure the timely discovery and accurate identification of potential threats.
[0073] Furthermore, by analyzing the coincidence of the source IP addresses among the risk nodes, potential correlation relationships can be effectively identified, thus constructing a knowledge graph reflecting the network threat propagation path and collaborative behavior; counting the number of occurrences of the source IP addresses of each risk node can understand the diversity of the traffic sources of each node; by comparing the ratio of the source IP numbers of any two risk nodes, node pairs with similar traffic source scales can be screened out; similar traffic source scales may imply similar network behavior patterns. Further calculating the coincidence rate of the source IP addresses quantifies the similarity of the traffic sources between the two nodes. When the coincidence rate exceeds the preset threshold, it indicates that these two risk nodes may share a large number of similar traffic sources, and this high coincidence is very likely due to their participation in the same attack path or collaborative attack behavior; at this time, connecting these two nodes to form a graph edge can visually display their correlation relationship; effectively mining the potential threat correlations hidden in the massive data.
[0074] Furthermore, by counting the number of connections of risk nodes by the graph edges and comparing it with a preset quantity threshold, nodes with significant correlation relationships in the network can be effectively identified, thereby accurately locating abnormal nodes. The number of connections of the graph edges reflects the degree of tight correlation between risk nodes. If a risk node is connected by a large number of other risk nodes, it indicates that its behavior pattern in the network is highly correlated with other risk nodes and may be a key node or the source of an attack path in the attack path. By setting a preset quantity threshold, those nodes with a relatively large number of connections and strong correlation can be distinguished and determined as abnormal nodes. This avoids the limitations of relying solely on individual node metrics and improves the ability to identify complex attack paths and coordinated attack behaviors.
[0075] Furthermore, by calculating the relative deviation of the traffic change rate and the in-out traffic ratio, abnormal fluctuations in network traffic can be keenly captured, and the deviation index obtained by weighted summation further quantifies the degree of these abnormalities, providing a scientific basis for the dynamic adjustment of the threshold. Combining the number of abnormal nodes for threshold adjustment enables the system to automatically optimize the monitoring parameters according to the actual traffic conditions in different network environments, thereby improving the recognition accuracy and response efficiency for potential threats.
[0076] Furthermore, by comprehensively considering multi-dimensional data such as the deviation index, the preset deviation index range, and the quantity, the deviation index reflects the degree of deviation of the current network traffic from the preset range. By comparing it with the maximum and minimum values of the preset range, it can be determined whether the network traffic is abnormal. When the deviation index exceeds the preset range, the traffic threshold is moderately increased by a preset first adjustment coefficient to avoid misjudgment caused by excessive threshold adjustment amplitude and ensure that the traffic threshold can adapt to the dynamic changes of network traffic. Secondly, when the deviation index is lower than the preset range, a weighted summation is performed by combining the index deviation and the quantity deviation to obtain an adjustment factor, and then the quantity threshold is adjusted. This can not only flexibly adjust the threshold according to the actual changes in network traffic but also effectively reduce the false alarm rate and improve the accuracy and adaptability of network security monitoring. Description of the Drawings
[0077] Figure 1 is the flowchart of the network security threat awareness recognition and response method based on the security knowledge graph in this embodiment;
[0078] Figure 2 is the decision logic diagram for determining temporary nodes in this embodiment;
[0079] Figure 3 is the decision logic diagram for determining marked nodes in this embodiment;
[0080] Figure 4 is the decision logic diagram for determining risk nodes and suspicious nodes in this embodiment. Detailed Implementation Modes
[0081] To make the objectives and advantages of the present invention more clear and understandable, the present invention will be further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0082] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are only used to explain the technical principles of the present invention and do not limit the protection scope of the present invention.
[0083] Please refer to Figure 1 as shown, which is a flowchart of the network security threat perception and identification response method based on a security knowledge graph in this embodiment;
[0084] This embodiment provides a network security threat perception and identification response method based on a security knowledge graph, including:
[0085] Real-time acquisition of the traffic change rate, in-out traffic ratio, source IP address, request success rate, and session interruption rate of each monitoring node in the security knowledge graph constructed by an enterprise with each network device as a monitoring node;
[0086] Determine a number of temporary nodes and focus nodes according to the traffic change rate and a preset traffic threshold;
[0087] Determine a number of marked nodes according to the in-out traffic ratio and the source IP address of the focus node and any of the temporary nodes within a preset marking duration;
[0088] Determine a number of risk nodes and a number of suspicious nodes according to the request success rate and the session interruption rate of each of the marked nodes;
[0089] Determine a number of risk nodes according to the in-out traffic ratio of the focus node and any of the suspicious nodes within a preset correction duration;
[0090] Connect two risk nodes according to the source IP addresses of any two of the risk nodes to obtain a number of graph edges;
[0091] Determine a number of abnormal nodes according to the number of connections of each of the risk nodes by the graph edges and a preset number threshold;
[0092] Adjust the preset traffic threshold according to the traffic change rate, the in-out traffic ratio, and the number of each of the abnormal nodes to obtain an adjusted traffic threshold, or adjust the preset number threshold to obtain an adjusted number threshold;
[0093] Send an alarm for all abnormal nodes re-determined based on the adjusted traffic threshold or the adjusted number threshold.
[0094] In an enterprise network environment, each network device serves as a monitoring node to construct a security knowledge graph for real-time monitoring of network traffic and behavior. Network devices refer to the hardware or software components that constitute the enterprise network infrastructure, including but not limited to routers, switches, firewalls, load balancers, intrusion detection / defense systems (IDS / IPS), gateways, proxy servers; the traffic change rate refers to the degree of change in network traffic per unit time, used to detect abnormal growth or decline of traffic, and is collected through traffic monitoring tools; the in-out traffic ratio is the ratio of the traffic entering and leaving a network node, used to identify abnormal traffic flow directions, and is analyzed using network traffic analysis software (such as Wireshark or PRTG); the source IP address is the IP address that initiates a network request, used to trace the data source, and is obtained through firewall logs or network intrusion detection system (IDS) logs; the request success rate is the ratio of the number of requests with successful responses to the total number of requests, reflecting the availability of network services, and the request-response situation of application programs is monitored through application performance monitoring tools (such as APM tools); the session interruption rate is the ratio of the number of abnormal session interruptions to the total number of sessions, used to detect potential attack behaviors, and the interruption situation of network sessions is monitored using network session monitoring tools (such as TCPdump or specialized session analysis software).
[0095] The preset traffic threshold is a reference value used to determine whether traffic changes are abnormal, depending on the normal traffic characteristics of the network, business types, historical data statistics, and security policies, and is usually set between 2 to 3 standard deviations of the historical average traffic. In this embodiment, it is set to 2.5 times the standard deviation of the historical average traffic, which can effectively distinguish normal traffic fluctuations from abnormal traffic, avoid false alarms, and timely detect traffic anomalies, improving the sensitivity and accuracy of the system.
[0096] The historical average traffic refers to the average value of network traffic in the past week, which is obtained through statistical analysis of historical traffic data and is used to reflect the traffic level of the network under normal operating conditions.
[0097] The preset correction duration refers to the time window for re-evaluating the traffic data of the concerned nodes and suspicious nodes within a certain period of time, depending on the dynamic change characteristics of network traffic, the real-time requirements of the business, and security policies, and is usually set between 10 minutes and 30 minutes. In this embodiment, it is set to 15 minutes, which can timely correct misjudgments caused by short-term fluctuations, while ensuring the real-time performance and response speed of the system.
[0098] The preset quantity threshold is used to determine whether the number of risk nodes connected by the graph edges exceeds the benchmark value within the normal range. It depends on the network topology, the statistical rules of normal business connections, and the security policy, and is usually set between 3 and 5. In this embodiment, it is set to 4, which can effectively identify abnormal nodes associated with multiple risk nodes and avoid judging the risk of a single node in isolation.
[0099] By obtaining the key indicators of the monitoring nodes of each network device of the enterprise in real time, and based on the traffic change rate and the preset traffic threshold, a number of temporary nodes and attention nodes are screened out. Subsequently, in combination with the in-out traffic ratio and the source IP address of the attention nodes and the temporary nodes, a number of marked nodes are further determined. According to the request success rate and session interruption rate of the marked nodes, a number of risk nodes and suspicious nodes are identified. Again, based on the in-out traffic ratio of the attention nodes and the suspicious nodes, the risk nodes are adjusted and determined. Then, the source IP addresses of any two risk nodes are connected to form a number of graph edges. Finally, according to the number of graph edges connected to the risk nodes and the preset quantity threshold, a number of abnormal nodes are determined. In addition, according to the traffic change rate, the in-out traffic ratio, and the number of graph edges connected to the risk nodes, the preset traffic threshold or the preset quantity threshold is dynamically adjusted, and an alarm is issued for all abnormal nodes re-determined based on the adjusted threshold.
[0100] By obtaining the key indicators of the monitoring nodes of each network device of the enterprise in real time, screening out temporary nodes and attention nodes based on the traffic change rate and the preset traffic threshold, further determining marked nodes in combination with the in-out traffic ratio and the source IP address, determining risk nodes and suspicious nodes based on the request success rate and session interruption rate, effectively distinguishing normal network fluctuations from malicious attack behaviors, re-determining risk nodes through the in-out traffic ratio can dynamically adjust the determination of risk nodes, avoiding misjudgment caused by short-term traffic fluctuations, connecting risk nodes through the source IP address to form graph edges, and determining abnormal nodes according to the connection number and the quantity threshold, making use of the association analysis ability of the knowledge graph to identify complex attack paths and collaborative attack behaviors. Finally, by dynamically adjusting the preset traffic threshold and the quantity threshold, the determination criteria are optimized in real time according to the changes in the network environment, ensuring the long-term effectiveness and adaptability of the system, and effectively solving the problems of low accuracy in danger identification and slow response speed due to excessive data volume and over-reliance on models.
[0101] Please continue to refer to Figure 2 as shown, which is the decision logic diagram for determining temporary nodes in this embodiment;
[0102] Determining a number of temporary nodes and attention nodes according to the traffic change rate and the preset traffic threshold includes:
[0103] When the traffic change rate is greater than the preset traffic threshold, determining the monitoring node as the temporary node to obtain a number of the temporary nodes;
[0104] Compare the flow change rates of all the temporary nodes, and determine the temporary node with the largest flow change rate as the node of interest.
[0105] By determining a node as a temporary node when the flow change rate of a monitoring node exceeds a preset flow threshold, a number of temporary nodes are obtained. Subsequently, compare the flow change rates of these temporary nodes, find the node with the largest flow change rate among them, and determine it as the node of interest.
[0106] Through the judgment of the flow change rate threshold and comparative analysis, potential temporary nodes can be quickly screened out. Usually, abnormal flow changes are associated with network attacks or abnormal behaviors. Among many abnormal nodes, the node with the most significant flow change is often the potential threat source that deserves the most attention. It can not only quickly narrow the monitoring scope, improve the analysis efficiency of the system, but also ensure the priority processing of the most likely threats, thus realizing the efficient perception and accurate identification of network security threats.
[0107] Please continue to refer to Figure 3 as shown, which is the decision logic diagram for determining the marked nodes in this embodiment;
[0108] Determine a number of marked nodes according to the inbound and outbound flow ratios and the source IP addresses of the node of interest and any of the temporary nodes within a preset marking duration, including:
[0109] Calculate the standard deviation of the inbound and outbound flow ratios of the node of interest to obtain the attention flow ratio fluctuation value;
[0110] Count the number of different source IP addresses among all the source IP addresses of the node of interest, calculate the probability of each source IP address appearing, calculate the Shannon entropy according to all the probabilities, and calculate the standard deviation of the Shannon entropy to obtain the attention dispersion fluctuation value;
[0111] Perform normalization processing on the attention flow ratio fluctuation value to obtain the attention flow normalization value, and perform normalization processing on the attention dispersion fluctuation value to obtain the attention dispersion normalization value;
[0112] Calculate the correlation coefficient of the attention flow normalization value and the attention dispersion normalization value to obtain the attention correlation degree;
[0113] When the attention correlation degree is greater than a preset correlation degree threshold, calculate the standard deviation of the inbound and outbound flow ratios of each of the temporary nodes to obtain the temporary flow ratio fluctuation value;
[0114] Count the number of different source IP addresses among all the source IP addresses of the temporary nodes, calculate the probability of each source IP address appearing, calculate the Shannon entropy according to all the probabilities, and calculate the standard deviation of the Shannon entropy to obtain the temporary dispersion fluctuation value;
[0115] Normalize the temporary flow ratio fluctuation value to obtain a temporary flow normalization value, and normalize the temporary dispersion fluctuation value to obtain a temporary dispersion normalization value;
[0116] Calculate the correlation coefficient of the temporary flow normalization value and the temporary dispersion normalization value to obtain a temporary correlation degree;
[0117] When the temporary correlation degree is greater than the concerned correlation degree, determine that the temporary node and the concerned node are the marked nodes to determine a number of marked nodes.
[0118] The preset marking duration is the time window for calculating the flow ratio fluctuation value and the dispersion fluctuation value, which depends on the dynamic characteristics of network traffic, the real-time requirements of services, and security policies, and is usually set between 5 minutes and 20 minutes. In this embodiment, it is set to 10 minutes, which can effectively capture the short-term fluctuations of network traffic and avoid misjudgment caused by too short time.
[0119] The preset correlation degree threshold is the reference value for judging the correlation between the flow ratio and the dispersion degree, which depends on the statistical laws of normal network behaviors, service logics, and security requirements, and is usually set between 0.7 and 0.9. In this embodiment, it is set to 0.8, which can more accurately screen out potential threat nodes and avoid false alarms and missed reports.
[0120] Calculate the standard deviation of the incoming and outgoing flow ratio of the concerned node to obtain the flow ratio fluctuation value. At the same time, count the number of all source IP addresses of this node and calculate the probability of each address appearing, and then obtain the Shannon entropy and its standard deviation, that is, the dispersion fluctuation value. Subsequently, normalize these two fluctuation values respectively to obtain the flow normalization value and the dispersion normalization value, and calculate their correlation coefficient, which is called the concerned correlation degree. If the correlation degree of the concerned node exceeds the preset correlation degree threshold, then perform the same calculation process on the temporary node to obtain the temporary flow ratio fluctuation value, the temporary dispersion fluctuation value, the flow normalization value, the dispersion normalization value, and the temporary correlation degree. Finally, if the temporary correlation degree of the temporary node is higher than the correlation degree of the concerned node, then mark the temporary node and the concerned node as marked nodes together to determine a number of marked nodes.
[0121] By combining indicators such as traffic ratio fluctuation, source IP address dispersion, and correlation coefficient, it is possible to accurately identify temporary nodes that have a similar behavior pattern to the node of interest and may be associated, thereby determining the marked nodes; the traffic ratio fluctuation value reflects the stability of the node traffic change, the dispersion measures the diversity of traffic sources, and the correlation coefficient further quantifies the correlation between the traffic fluctuation and the source IP address dispersion; through normalization processing and correlation calculation, the system can objectively compare the behavior characteristics of different nodes and avoid misjudgment caused by the contingency of a single indicator. When the correlation of the temporary node is higher than the preset threshold and greater than the correlation of the node of interest, it indicates that the behavior pattern of the temporary node is highly similar to that of the node of interest and may have participated in similar network activities, thus marking it as a marked node. It can effectively filter out noise data and accurately locate potential threat nodes.
[0122] Specifically, a number of risk nodes and a number of suspicious nodes are determined according to the request success rate and the session interruption rate of each of the marked nodes, including:
[0123] Draw a change curve of the request success rate within a preset determination duration to obtain a request change curve;
[0124] Calculate the slope change rate of the request change curve at a preset time distance to obtain a number of request slope change rates;
[0125] When the number of times the request slope change rate is less than zero is greater than a preset number threshold, draw a change curve of the session interruption rate within a preset determination duration to obtain an interruption change curve;
[0126] Calculate the slope change rate of the interruption change curve at the preset time distance to obtain a number of interruption slope change rates;
[0127] When the number of times the interruption slope change rate is greater than zero is greater than the preset number threshold, calculate the mean of all the request slope change rates to obtain an average request change rate, and calculate the mean of all the interruption slope change rates to obtain an average interruption change rate;
[0128] Calculate the relative deviation between the absolute value of the average request change rate and the absolute value of the average interruption change rate to obtain a slope deviation;
[0129] When the slope deviation is less than a preset slope deviation threshold, determine a number of risk nodes and a number of suspicious nodes according to the request success rate, the session interruption rate, and a preset consistency threshold.
[0130] The preset determination duration refers to the time window used to analyze the changes in request success rate and session interruption rate, which depends on: the dynamic characteristics of network traffic, the real-time requirements of services, and security policies, and is usually set between 5 minutes and 30 minutes. In this embodiment, it is set to 10 minutes, which can capture short-term changes in a timely manner and avoid misjudgment caused by too short a time.
[0131] The preset time distance refers to the time interval used when calculating the slope change rate, which depends on the dynamic characteristics of network traffic, service requirements, and the response speed of the monitoring system, and is usually set between 1 minute and 10 minutes. In this embodiment, it is set to 3 minutes, which can significantly improve the sensitivity of monitoring, capture the rapid changes in network traffic in a timely manner, and avoid the increase in computational complexity and false alarm rate caused by too short a time interval.
[0132] The preset slope deviation threshold refers to the maximum allowable deviation between the absolute value of the request slope change rate and the absolute value of the interruption slope change rate, which depends on the statistical laws of normal network behavior, business logic, and security policies, and is usually set in the range of 0.1 to 0.3. In this embodiment, it is set to 0.2, which can effectively distinguish normal traffic fluctuations from abnormal behaviors, avoid misjudgment caused by the contingency of a single indicator, and improve the accuracy and reliability of identification.
[0133] The preset consistency threshold is a reference value used to determine whether the change trends of the request success rate and session interruption rate are consistent, which depends on the statistical laws of normal network behavior, business logic, and security requirements, and is usually set between 0.8 and 0.5. In this embodiment, it is set to 0.65, which can effectively distinguish normal network fluctuations from abnormal behaviors and avoid misjudgment caused by the contingency of a single indicator.
[0134] By plotting the change curve of the request success rate, and then calculating the slope change rate of this curve within the preset time interval, multiple request slope change rates are obtained. If the number of times the request slope change rate is less than zero exceeds the preset number threshold, then plot the change curve of the session interruption rate and calculate its slope change rate within the same time interval to obtain multiple interruption slope change rates. When the number of times the interruption slope change rate is greater than zero also exceeds the preset number threshold, calculate the mean values of all request slope change rates and interruption slope change rates to obtain the average request change rate and the average interruption change rate respectively. Subsequently, calculate the relative deviation between the absolute values of these two average values to obtain the slope deviation. If the slope deviation is less than the preset slope deviation threshold, then determine a number of risk nodes and a number of suspicious nodes based on the request success rate, session interruption rate, and the preset consistency threshold.
[0135] By plotting the change curves of the request success rate and the session interruption rate and calculating the rate of change of their slopes, the changing trends of these key metrics can be dynamically monitored. A request slope rate of change less than zero indicates a decrease in the request success rate, which may imply service availability issues; an interruption slope rate of change greater than zero indicates an increase in the session interruption rate, which may imply connection stability issues. By setting a preset number threshold, nodes with frequent occurrences of these changes are screened out to further focus on potential problem nodes. Calculating the average request rate of change and the average interruption rate of change and evaluating the relative deviation (slope deviation) between them can determine whether the changing trends of the request success rate and the session interruption rate are consistent. If the slope deviation is less than the preset threshold, it indicates that the changing trends of the two are correlated and may be manifestations of the same network problem, thus enabling more accurate identification of risk nodes and suspicious nodes.
[0136] Please continue to refer to Figure 4 as shown, which is the decision logic diagram for determining risk nodes and suspicious nodes in this embodiment;
[0137] Determine a number of risk nodes and a number of suspicious nodes according to the request success rate, the session interruption rate, and a preset consistency threshold, including:
[0138] Calculate the standard deviation of the request success rate within the preset decision duration to obtain a request fluctuation value;
[0139] Calculate the standard deviation of the session interruption rate within the preset decision duration to obtain an interruption fluctuation value;
[0140] Normalize the request fluctuation value within the preset decision duration to obtain a standard request fluctuation value, and normalize the interruption fluctuation value within the preset decision duration to obtain a standard interruption fluctuation value;
[0141] Calculate the correlation coefficient between the standard request fluctuation value and the standard interruption fluctuation value to obtain a change consistency;
[0142] When the change consistency is less than zero and the absolute value of the change consistency is greater than the preset consistency threshold, determine that the concerned node is the risk node to determine a number of risk nodes;
[0143] When the change consistency is greater than zero and the absolute value of the change consistency is greater than the preset consistency threshold, determine that the concerned node is the suspicious node to determine a number of suspicious nodes.
[0144] Calculate the standard deviation of the request success rate within a preset determination duration to obtain a request fluctuation value, and at the same time calculate the standard deviation of the session interruption rate to obtain an interruption fluctuation value. Then, perform normalization processing on all the request fluctuation values and interruption fluctuation values respectively to obtain a standard request fluctuation value and a standard interruption fluctuation value. Subsequently, calculate the correlation coefficient between these two standard fluctuation values to obtain a change consistency degree. If the change consistency degree is less than zero and its absolute value is higher than a preset consistency threshold, then determine the marked node as a risk node, thereby identifying a number of risk nodes; conversely, if the change consistency degree is greater than zero and its absolute value is greater than the preset consistency threshold, then determine the marked node as a suspicious node, and then identify a number of suspicious nodes.
[0145] By quantifying the fluctuations of the request success rate and the session interruption rate, and calculating the correlation coefficient between them, risk nodes and suspicious nodes can be accurately distinguished. The fluctuation value of the request success rate and the fluctuation value of the session interruption rate reflect the stability of the node within the preset determination duration. When the change consistency degree is less than zero and its absolute value is greater than the preset consistency threshold, it indicates that the change trends of the two are negatively correlated and the difference is significant, which usually implies the existence of potential network attacks or faults, so the node is determined as a risk node. On the contrary, when the change consistency degree is greater than zero and its absolute value is greater than the preset consistency threshold, it indicates that the change trends of the two are positively correlated and the difference is significant, and there may be anomalies, so the node is determined as a suspicious node. It can effectively distinguish different types of abnormal nodes, improving the accuracy and reliability of network security threat identification.
[0146] Specifically, determine a number of risk nodes according to the in-out traffic ratio of the concerned node and any of the suspicious nodes within a preset correction duration, including:
[0147] Calculate the standard deviation of the in-out traffic ratio of the concerned node to obtain a concerned in-out ratio fluctuation value;
[0148] Calculate the standard deviation of the in-out traffic ratio of the suspicious node to obtain a suspicious in-out ratio fluctuation value;
[0149] Perform normalization processing on the concerned in-out ratio fluctuation value to obtain a concerned in-out ratio normalized value, and perform normalization processing on the suspicious in-out ratio fluctuation value to obtain a suspicious in-out ratio normalized value;
[0150] Calculate the relative deviation between the concerned in-out ratio normalized value and the suspicious in-out ratio normalized value to obtain an in-out ratio deviation value;
[0151] When the in-out ratio deviation value is less than a preset in-out ratio deviation threshold, determine the suspicious node as the risk node to identify a number of risk nodes.
[0152] The preset deviation threshold of the in-out ratio is a reference value used to determine whether the relative deviation of the normalized fluctuation value of the in-out flow ratio is within the normal range. It depends on the normal fluctuation range of network traffic, business logic, and security policies, and is usually set between 0.1 and 0.3. In this embodiment, it is set to 0.2, which can ensure the sensitivity of the system to abnormal traffic while avoiding misjudgment due to minor differences in traffic fluctuations.
[0153] Calculate the standard deviation of the in-out flow ratio of the concerned nodes to obtain the concerned in-out ratio fluctuation value, and at the same time calculate the standard deviation of the in-out flow ratio of the suspicious nodes to obtain the suspicious in-out ratio fluctuation value. Then, perform normalization processing on the concerned in-out ratio fluctuation value to obtain the concerned in-out ratio normalized value, and also perform normalization processing on the suspicious in-out ratio fluctuation value to obtain the suspicious in-out ratio normalized value. Next, calculate the relative deviation between the concerned in-out ratio normalized value and the suspicious in-out ratio normalized value to obtain the in-out ratio deviation value. If this in-out ratio deviation value is less than the preset in-out ratio deviation threshold, then determine the suspicious node as a risk node, thereby identifying a number of risk nodes.
[0154] By quantifying and comparing the in-out flow ratio fluctuations of the concerned nodes and the suspicious nodes, it is possible to dynamically identify whether a suspicious node with potential threats should be further determined as a risk node. By calculating the standard deviation of the in-out flow ratio, the respective fluctuation values can be obtained, which can capture the change stability of the flow ratio; calculating the relative deviation between the normalized values further quantifies the difference degree of the flow ratio fluctuations between the concerned nodes and the suspicious nodes; when the in-out ratio deviation value is less than the preset threshold, it indicates that the flow ratio fluctuation of the suspicious node is similar to that of the concerned node, which means that the behavior pattern of the suspicious node is similar to the known risk pattern, so it is determined as a risk node. It can dynamically adjust the evaluation of suspicious nodes, avoid misjudgment caused by short-term traffic fluctuations, and ensure the timely discovery and accurate identification of potential threats.
[0155] Specifically, connect two risk nodes according to the source IP addresses of any two of the risk nodes to obtain a number of graph edges, including:
[0156] Count the number of occurrences of all the source IP addresses of each risk node to obtain the source IP count;
[0157] When the ratio of the source IP counts of any two of the risk nodes is less than the preset ratio threshold, calculate the coincidence rate of the source IP addresses of the two risk nodes to obtain the IP coincidence rate;
[0158] When the IP coincidence rate is greater than the preset coincidence rate threshold, connect the two risk nodes to obtain a number of graph edges.
[0159] The preset ratio threshold is a reference value for judging whether the number of IPs of two risk nodes is comparable, which depends on the network topology, the IP distribution characteristics of normal business traffic, and the security policy. It is usually set between 1.5 and 3. In this embodiment, it is set to 2, which can effectively filter out node pairs with too large a difference in the number of source IPs and avoid misjudgment caused by too large a difference in the number of IPs.
[0160] The preset coincidence rate threshold is a reference value for judging whether there is an association between two risk nodes, which depends on the IP address distribution law of normal business traffic in the network environment, the characteristics of attack behaviors, and the strictness of the security policy. The usually set range is between 30% and 50%. In this embodiment, it is set to 40%, which can not only effectively identify nodes with obvious associations but also avoid misjudgment caused by accidental coincidence.
[0161] By counting the occurrence times of all source IP addresses of each risk node, the number of source IPs of each node is obtained. Then, for any two risk nodes, if the ratio of their source IP numbers is less than the preset IP number threshold, the coincidence rate of the source IP addresses of these two nodes is further calculated. When the calculated IP coincidence rate is greater than the preset coincidence rate threshold, these two risk nodes are connected to form several graph edges.
[0162] By analyzing the coincidence of source IP addresses between risk nodes, potential association relationships can be effectively identified, thereby constructing a knowledge graph that reflects the network threat propagation path and collaborative behaviors; counting the occurrence times of source IP addresses of each risk node can understand the diversity of traffic sources of each node; by comparing the ratio of the number of source IPs of any two risk nodes, node pairs with similar traffic source scales are screened out; similar traffic source scales may imply similar network behavior patterns. Further calculating the coincidence rate of source IP addresses quantifies the similarity of traffic sources between two nodes. When the coincidence rate exceeds the preset threshold, it indicates that these two risk nodes may share a large number of similar traffic sources, and this high degree of coincidence is likely due to their participation in the same attack path or collaborative attack behavior; at this time, connecting these two nodes to form a graph edge can visually display their association relationship; effectively mine potential threat associations hidden in the massive data.
[0163] Specifically, a number of abnormal nodes are determined according to the number of connections of each of the risk nodes by the graph edges and a preset number threshold, including:
[0164] When the number is greater than the preset number threshold, it is determined that the risk node is the abnormal node to determine a number of abnormal nodes.
[0165] By counting the number of connections of each risk node by the edges of the graph, and then comparing this number with a preset quantity threshold. If the number of connections of a certain risk node is greater than the preset quantity threshold, then it is determined that the risk node is an abnormal node, thereby determining a number of abnormal nodes.
[0166] By counting the number of connections of risk nodes by the edges of the graph and comparing it with a preset quantity threshold, nodes with significant correlation relationships in the network can be effectively identified, thereby accurately locating abnormal nodes. The number of connections of the graph edges reflects the degree of connection tightness between risk nodes. If a risk node is connected by a large number of other risk nodes, it indicates that its behavior pattern in the network is highly correlated with other risk nodes and may be a key node or the source of an attack path in the attack path. By setting a preset quantity threshold, nodes with a relatively large number of connections and strong correlation can be distinguished and determined as abnormal nodes. This avoids the limitations of relying solely on individual node metrics and improves the ability to identify complex attack paths and collaborative attack behaviors.
[0167] Specifically, adjusting the preset traffic threshold according to the traffic change rate, the incoming and outgoing traffic ratio, and the quantity of each of the abnormal nodes to obtain an adjusted traffic threshold, or adjusting the preset quantity threshold to obtain an adjusted quantity threshold, includes:
[0168] Calculating the relative deviation between the traffic change rate and the preset traffic threshold to obtain a change deviation;
[0169] Calculating the relative deviation between the incoming and outgoing traffic ratio and the preset traffic ratio threshold to obtain a traffic ratio deviation;
[0170] Performing a weighted sum of the change deviation, the preset traffic change weight, the traffic ratio deviation, and the preset traffic ratio weight to obtain a deviation index;
[0171] Adjusting the preset traffic threshold according to the deviation index, the preset deviation index range, and the quantity to obtain an adjusted traffic threshold, or adjusting the preset quantity threshold to obtain an adjusted quantity threshold.
[0172] The preset traffic change weight is an importance coefficient used to measure the importance of the deviation of the traffic change rate to the overall deviation, depending on the importance of the traffic change rate in network security threat identification and the requirements of the business scenario, and is usually set between 0.3 and 0.7. In this embodiment, it is set to 0.5, which can balance the contributions of the traffic change rate and other metrics.
[0173] The preset traffic ratio weight is used to measure the importance coefficient of the contribution of the deviation of the in-out traffic ratio to the overall deviation when calculating the deviation index. It depends on the importance of the in-out traffic ratio in network security threat identification and the requirements of the business scenario, and is usually set between 0.3 and 0.7. In this embodiment, the preset traffic ratio weight is set to 0.5, which can balance the contributions of the in-out traffic ratio and other indicators.
[0174] The preset deviation index range is a reference interval for judging whether the deviation index is within the normal range. It depends on the statistical characteristics of normal network traffic changes and traffic ratio changes as well as security policies, and is usually set between [0.1, 0.9]. In this embodiment, it is set to [0.3, 0.7], which can effectively distinguish normal network fluctuations and abnormal traffic changes, ensure that the system does not frequently adjust the threshold under normal circumstances, and can respond in a timely manner under abnormal circumstances, improving the stability and sensitivity of the system.
[0175] By calculating the relative deviation between the traffic change rate and the preset traffic threshold, the change deviation is obtained; then, the relative deviation between the in-out traffic ratio and the preset traffic ratio threshold is calculated to obtain the traffic ratio deviation. Then, the change deviation is weighted and summed with the preset traffic change weight, and the traffic ratio deviation is weighted and summed with the preset traffic ratio weight respectively to obtain the deviation index. According to the deviation index, the preset deviation index range, and the quantity, the preset traffic threshold is adjusted to obtain the adjusted traffic threshold, or the preset quantity threshold is adjusted to obtain the adjusted quantity threshold.
[0176] By calculating the relative deviations of the traffic change rate and the in-out traffic ratio, the abnormal fluctuations of network traffic can be keenly captured, and the deviation index obtained by weighted summation further quantifies the degree of these abnormalities, providing a scientific basis for the dynamic adjustment of the threshold. Combining the adjustment of the threshold with the number of abnormal nodes enables the system to automatically optimize the monitoring parameters according to the actual traffic conditions in different network environments, thereby improving the recognition accuracy and response efficiency of potential threats.
[0177] Specifically, adjusting the preset traffic threshold according to the deviation index, the preset deviation index range, and the quantity to obtain the adjusted traffic threshold, or adjusting the preset quantity threshold to obtain the adjusted quantity threshold includes:
[0178] When the deviation index is greater than the maximum value of the preset deviation index range, the preset traffic threshold is increased according to the relative deviation between the deviation index and the maximum value of the preset deviation index range and the preset first adjustment coefficient to obtain the adjusted traffic threshold;
[0179] When the deviation index is less than the minimum value of the preset deviation index range, the relative deviation between the deviation index and the minimum value of the preset deviation index range is calculated to obtain the index deviation;
[0180] Calculate the absolute value of the relative deviation between the quantity and the preset quantity threshold to obtain a quantity deviation;
[0181] Perform a weighted sum of the quantity deviation, the preset quantity deviation weight, the exponential deviation, and the preset exponential deviation weight to obtain an adjustment factor;
[0182] Increase the preset quantity threshold according to the adjustment factor and the preset second adjustment coefficient to obtain an adjusted quantity threshold.
[0183] The preset first adjustment coefficient is a coefficient used to adjust the preset flow threshold when the deviation index exceeds a preset range. It depends on the dynamic characteristics of network traffic changes and the flexibility of security policies, and is usually set between 1.1 and 1.5. In this embodiment, it is set to 1.2, which can ensure that when the deviation index exceeds the normal range, the flow threshold can be moderately increased to avoid misjudgment caused by an overly large threshold adjustment amplitude.
[0184] The preset quantity deviation weight is a weight coefficient used to adjust the influence degree of the quantity deviation on the final adjustment factor when calculating the adjustment factor. It depends on the importance of the quantity deviation in the overall anomaly detection and the sensitivity of the system to changes in the associated quantity of nodes, and is usually set between 0.3 and 0.7. In this embodiment, it is set to 0.5, which can balance the contributions of the quantity deviation and other factors to the adjustment factor.
[0185] The preset exponential deviation weight is a weight coefficient used to adjust the influence degree of the deviation index on the final adjustment factor when calculating the adjustment factor. It depends on the importance of the deviation index in the overall anomaly detection and the sensitivity of the system to the abnormal degree of traffic changes, and is usually set between 0.3 and 0.7. In this embodiment, it is set to 0.5, which can balance the contributions of the deviation index and other factors to the adjustment factor.
[0186] The preset second adjustment coefficient is a proportional coefficient used to adjust the preset quantity threshold according to the adjustment factor. It depends on the sensitivity and stability requirements of the system for adjusting the quantity threshold and the dynamic change characteristics of the network environment, and is usually set between 0.1 and 0.3. In this embodiment, it is set to 0.2, which can ensure that the adjustment of the quantity threshold can not only reflect the changes in the network environment but also not cause system instability due to an overly large adjustment amplitude.
[0187] By comparing the deviation index with the preset deviation index range, when the deviation index is greater than the maximum value of the preset range, according to the relative deviation between the deviation index and the maximum value of the preset range, combined with the preset first adjustment coefficient, moderately increase the preset flow threshold, so as to obtain the adjusted flow threshold; when the deviation index is less than the minimum value of the preset range, calculate the relative deviation between the deviation index and the minimum value of the preset deviation index range to obtain the index deviation, then calculate the absolute value of the relative deviation between the current connection number and the preset number threshold to obtain the quantity deviation, and then, perform weighted summation on the quantity deviation and the index deviation respectively with their corresponding preset weights to obtain the adjustment factor, and finally, adjust the preset number threshold according to the adjustment factor and the preset second adjustment coefficient to obtain the new adjusted quantity threshold.
[0188] By comprehensively considering multi-dimensional data such as the deviation index, the preset deviation index range, and the quantity, the deviation index reflects the deviation degree of the current network traffic from the preset range. By comparing with the maximum and minimum values of the preset range, it can be judged whether the network traffic is abnormal. When the deviation index exceeds the preset range, moderately increase the flow threshold through the preset first adjustment coefficient to avoid misjudgment caused by excessive threshold adjustment and ensure that the flow threshold can adapt to the dynamic changes of network traffic. Secondly, when the deviation index is lower than the preset range, perform weighted summation on the combined index deviation and quantity deviation to obtain the adjustment factor, and then adjust the quantity threshold, which can not only flexibly adjust the threshold according to the actual changes of network traffic, but also effectively reduce the false alarm rate and improve the accuracy and adaptability of network security monitoring.
[0189] So far, the technical solution of the present invention has been described in combination with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.
Claims
1. A network security threat perception and identification response method based on a security knowledge graph, characterized in that Including: Obtaining in real time the traffic change rate, inbound and outbound traffic ratio, source IP address, request success rate, and session interruption rate of each monitoring node in the security knowledge graph constructed by an enterprise with each network device as a monitoring node; Determining a number of temporary nodes and attention nodes according to the traffic change rate and a preset traffic threshold; Determining a number of marked nodes according to the inbound and outbound traffic ratio and the source IP address of the attention node and any of the temporary nodes within a preset marking duration; Determining a number of risk nodes and a number of suspicious nodes according to the request success rate and the session interruption rate of each of the marked nodes; Determining a number of risk nodes according to the inbound and outbound traffic ratio of the attention node and any of the suspicious nodes within a preset correction duration; Connecting two risk nodes according to the source IP addresses of any two of the risk nodes to obtain a number of graph edges; Determining a number of abnormal nodes according to the number of times each of the risk nodes is connected by the graph edges and a preset number threshold; Adjusting the preset traffic threshold to obtain an adjusted traffic threshold, or adjusting the preset number threshold to obtain an adjusted number threshold according to the traffic change rate, the inbound and outbound traffic ratio, and the number of each of the abnormal nodes; Issuing an alarm for all the abnormal nodes re-determined based on the adjusted traffic threshold or the adjusted number threshold.
2. The network security threat perception recognition and response method based on a security knowledge graph according to claim 1, characterized in that, Determining a number of temporary nodes and attention nodes according to the traffic change rate and a preset traffic threshold, including: When the traffic change rate is greater than the preset traffic threshold, determining the monitoring node as the temporary node to obtain a number of the temporary nodes; Comparing the traffic change rates of all the temporary nodes, and determining the temporary node with the largest traffic change rate as the attention node.
3. The network security threat perception recognition and response method based on a security knowledge graph according to claim 2, wherein Determining a number of marked nodes according to the inbound and outbound traffic ratio and the source IP address of the attention node and any of the temporary nodes within a preset marking duration, including: Calculating the standard deviation of the inbound and outbound traffic ratio of the attention node to obtain an attention traffic ratio fluctuation value; Counting the number of different source IP addresses among all the source IP addresses of the attention node, calculating the probability of occurrence of each source IP address, calculating the Shannon entropy according to all the probabilities, and calculating the standard deviation of the Shannon entropy to obtain an attention dispersion fluctuation value; Performing normalization processing on the attention traffic ratio fluctuation value to obtain an attention traffic normalization value, and performing normalization processing on the attention dispersion fluctuation value to obtain an attention dispersion normalization value; Calculating the correlation coefficient between the attention traffic normalization value and the attention dispersion normalization value to obtain an attention correlation degree; When the attention correlation degree is greater than a preset correlation degree threshold, calculating the standard deviation of the inbound and outbound traffic ratio of each of the temporary nodes to obtain a temporary traffic ratio fluctuation value; Counting the number of different source IP addresses among all the source IP addresses of the temporary node, calculating the probability of occurrence of each source IP address, calculating the Shannon entropy according to all the probabilities, and calculating the standard deviation of the Shannon entropy to obtain a temporary dispersion fluctuation value; Performing normalization processing on the temporary traffic ratio fluctuation value to obtain a temporary traffic normalization value, and performing normalization processing on the temporary dispersion fluctuation value to obtain a temporary dispersion normalization value; Calculate the correlation coefficient of the temporary traffic normalization value and the temporary dispersion normalization value to obtain the temporary correlation degree; When the temporary correlation degree is greater than the concerned correlation degree, determine that the temporary node and the concerned node are the marked nodes to determine a number of marked nodes.
4. The network security threat perception recognition and response method based on a security knowledge graph according to claim 3, wherein Determine a number of risk nodes and a number of suspicious nodes according to the request success rate and the session interruption rate of each of the marked nodes, including: Draw a change curve of the request success rate within a preset determination duration to obtain a request change curve; Calculate the slope change rate of the request change curve at a preset time distance to obtain a number of request slope change rates; When the number of times the request slope change rate is less than zero is greater than a preset number threshold, draw a change curve of the session interruption rate within a preset determination duration to obtain an interruption change curve; Calculate the slope change rate of the interruption change curve at the preset time distance to obtain a number of interruption slope change rates; When the number of times the interruption slope change rate is greater than zero is greater than the preset number threshold, calculate the mean value of all the request slope change rates to obtain an average request change rate, and calculate the mean value of all the interruption slope change rates to obtain an average interruption change rate; Calculate the relative deviation between the absolute value of the average request change rate and the absolute value of the average interruption change rate to obtain a slope deviation; When the slope deviation is less than a preset slope deviation threshold, determine a number of risk nodes and a number of suspicious nodes according to the request success rate, the session interruption rate, and a preset consistency threshold.
5. The method for identifying and responding to cybersecurity threats based on a security knowledge graph according to claim 4, wherein Determine a number of risk nodes and a number of suspicious nodes according to the request success rate, the session interruption rate, and a preset consistency threshold, including: Calculate the standard deviation of the request success rate within the preset determination duration to obtain a request fluctuation value; Calculate the standard deviation of the session interruption rate within the preset determination duration to obtain an interruption fluctuation value; Perform normalization processing on the request fluctuation value within the preset determination duration to obtain a standard request fluctuation value, and perform normalization processing on the interruption fluctuation value within the preset determination duration to obtain a standard interruption fluctuation value; Calculate the correlation coefficient of the standard request fluctuation value and the standard interruption fluctuation value to obtain a change consistency; When the change consistency is less than zero and the absolute value of the change consistency is greater than the preset consistency threshold, determine that the concerned node is the risk node to determine a number of risk nodes; When the change consistency is greater than zero and the absolute value of the change consistency is greater than the preset consistency threshold, determine that the concerned node is the suspicious node to determine a number of suspicious nodes.
6. The network security threat perception recognition and response method based on a security knowledge graph according to claim 5, characterized in that, Determine a number of risk nodes according to the inflow and outflow traffic ratio of the concerned node and any of the suspicious nodes within a preset correction duration, including: Calculate the standard deviation of the inflow and outflow traffic ratio of the concerned node to obtain a concerned inflow and outflow ratio fluctuation value; Calculate the standard deviation of the inflow and outflow traffic ratio of the suspicious node to obtain a suspicious inflow and outflow ratio fluctuation value; Perform normalization processing on the concerned inflow and outflow ratio fluctuation value to obtain a concerned inflow and outflow ratio normalization value, and perform normalization processing on the suspicious inflow and outflow ratio fluctuation value to obtain a suspicious inflow and outflow ratio normalization value; Calculate the relative deviation between the normalized ratio of concerned in-and-out and the normalized ratio of suspicious in-and-out to obtain the in-and-out ratio deviation value; When the in-and-out ratio deviation value is less than the preset in-and-out ratio deviation threshold, determine the suspicious node as the risk node to identify a number of risk nodes.
7. The method for identifying and responding to network security threats based on a security knowledge graph according to claim 6, wherein Connect two risk nodes according to the source IP addresses of any two of the risk nodes to obtain a number of graph edges, including: Count the occurrence times of all the source IP addresses of each risk node to obtain the source IP count; When the ratio of the source IP counts of any two of the risk nodes is less than the preset ratio threshold, calculate the coincidence rate of the source IP addresses of the two risk nodes to obtain the IP coincidence rate; When the IP coincidence rate is greater than the preset coincidence rate threshold, connect the two risk nodes to obtain a number of graph edges.
8. The method for identifying and responding to network security threats based on a security knowledge graph according to claim 7, wherein, Determine a number of abnormal nodes according to the number of connections of each risk node by the graph edges and the preset number threshold, including: When the number is greater than the preset number threshold, determine the risk node as the abnormal node to identify a number of abnormal nodes.
9. The method for identifying and responding to network security threats based on a security knowledge graph according to claim 8, characterized in that, Adjust the preset flow threshold according to the flow change rate, the in-and-out flow ratio and the number of each abnormal node to obtain the adjusted flow threshold, or adjust the preset number threshold to obtain the adjusted number threshold, including: Calculate the relative deviation between the flow change rate and the preset flow threshold to obtain the change deviation; Calculate the relative deviation between the in-and-out flow ratio and the preset flow ratio threshold to obtain the flow ratio deviation; Perform a weighted sum of the change deviation, the preset flow change weight, the flow ratio deviation and the preset flow ratio weight to obtain the deviation index; Adjust the preset flow threshold according to the deviation index, the preset deviation index range and the number to obtain the adjusted flow threshold, or adjust the preset number threshold to obtain the adjusted number threshold.
10. The method for identifying and responding to network security threats based on a security knowledge graph according to claim 9, wherein, Adjust the preset flow threshold according to the deviation index, the preset deviation index range and the number to obtain the adjusted flow threshold, or adjust the preset number threshold to obtain the adjusted number threshold, including: When the deviation index is greater than the maximum value of the preset deviation index range, increase the preset flow threshold according to the relative deviation between the deviation index and the maximum value of the preset deviation index range and the preset first adjustment coefficient to obtain the adjusted flow threshold; When the deviation index is less than the minimum value of the preset deviation index range, calculate the relative deviation between the deviation index and the minimum value of the preset deviation index range to obtain the index deviation; Calculate the absolute value of the relative deviation between the number and the preset number threshold to obtain the number deviation; Perform a weighted sum of the number deviation, the preset number deviation weight, the index deviation and the preset index deviation weight to obtain the adjustment factor; Increase the preset number threshold according to the adjustment factor and the preset second adjustment coefficient to obtain the adjusted number threshold.
Citation Information
Patent Citations
Network security situation assessment method and system based on security knowledge graph
CN113783874A
Perceptual security protection method, system and equipment based on network port protection device
CN118611997A
Network security situation awareness and early warning system and method based on artificial intelligence
CN119276529A
Network security situation early warning method and system based on knowledge graph
CN119603058A
DDoS attack real-time detection and traceability analysis method based on knowledge graph
CN119728286A
Cited By
Transaction link risk intelligent monitoring method and system based on knowledge graph construction
CN120653512A
Transaction link risk intelligent monitoring method and system based on knowledge graph construction
CN120653512B