Network threat detection method and system under dynamic protocol recombination
The method and system dynamically adapt protocol analysis using adaptability metrics to optimize network traffic detection, addressing the limitations of traditional systems in handling dynamic protocol changes and improving threat detection in heterogeneous networks.
Patent Information
- Application Number
- CN202510799824.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-16
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-06-16
AI Technical Summary
Traditional threat detection systems based on fixed protocol rules are difficult to cope with the problems of threat detection lag and high missed response rates caused by dynamic protocol reorganization. Especially in scenarios where heterogeneous protocols such as the Internet of Things and the industrial Internet are frequently interacting, zero-day attacks and persistent advanced threats cannot be effectively identified.
By capturing the network traffic feature set, dynamic reorganization fitness is introduced as evaluation indicators, dynamic reorganization optimization analysis is carried out, dynamic protocols are generated, and protocol data flow is captured for feature analysis, and threat detectors are activated for real-time threat type identification and defense.
Real-time accurate threat identification and adaptive defense in dynamic protocol restructuring scenarios are realized, and the detection efficiency and protection response speed of unknown threats in complex network environments are improved.
Smart Images

Figure CN120321043A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and particularly relates to a network threat detection method and system under protocol dynamic recombination. Background Art
[0002] Under the dual pressures of the dynamic evolution of protocols and the mutation of attack means in the network traffic environment, the traditional threat detection system based on fixed protocol rules faces a serious risk of failure. The current mainstream detection technologies rely on predefined protocol templates for traffic parsing, and it is difficult to cope with new attack methods such as dynamic confusion of protocol fields and encryption handshake behavior disguise. Especially in scenarios where heterogeneous protocols interact frequently, such as the Internet of Things and industrial Internet, attackers can use protocol recombination vulnerabilities to bypass the detection engine. Existing methods lack a quantitative evaluation mechanism for the protocol dynamic recombination process and cannot adjust the protocol parsing strategy according to real-time traffic characteristics, resulting in zero-day attacks and persistent advanced threats (APT) in encrypted channels being difficult to be effectively identified. At the same time, traditional feature extraction technologies are mostly limited to the analysis of single-dimensional traffic parameters, and no correlation model between protocol structure topology and threat behavior is established, resulting in detection blind spots for distributed collaborative attacks and protocol-level covert channels. Therefore, a network threat detection method based on protocol dynamic recombination has emerged to cope with the rapid evolution of dynamic and hidden security threats in complex network environments. Summary of the Invention
[0003] This application provides a network threat detection method and system under protocol dynamic recombination, aiming to solve the technical problems that traditional static protocol analysis technologies are difficult to adapt to the protocol dynamic recombination scenario, resulting in lagging threat detection and high false negative rates.
[0004] In the first aspect disclosed in this application, a network threat detection method under protocol dynamic recombination is provided. The method includes: capturing network traffic and obtaining a traffic feature set of the network traffic, where the traffic feature set includes multiple traffic parameters; introducing dynamic recombination fitness as an effect evaluation index for protocol dynamic recombination, and performing an optimization analysis of protocol dynamic recombination with the effect evaluation index and the multiple traffic parameters as constraints to obtain a dynamic protocol; capturing a protocol data stream of the dynamic protocol and analyzing the protocol data stream to obtain a protocol feature set; activating a threat detector to analyze the protocol feature set to obtain a real-time threat type, and invoking a threat defense strategy corresponding to the real-time threat type for network processing.
[0005] Another aspect disclosed in this application provides a network threat detection system under protocol dynamic recombination. The system includes: a traffic feature acquisition module: capturing network traffic and obtaining a traffic feature set of the network traffic, where the traffic feature set includes multiple traffic parameters; an optimization analysis module: introducing dynamic recombination fitness as an evaluation index for the effect of protocol dynamic recombination, and performing optimization analysis of protocol dynamic recombination with the evaluation index and the multiple traffic parameters as constraints to obtain a dynamic protocol; a protocol feature acquisition module: capturing the protocol data stream of the dynamic protocol and analyzing the protocol data stream to obtain a protocol feature set; a network processing module: activating a threat detector to analyze the protocol feature set to obtain a real-time threat type, and invoking a threat defense strategy corresponding to the real-time threat type for network processing.
[0006] One or more technical solutions provided in this application have at least the following technical effects or advantages: The above-mentioned network threat detection method under protocol dynamic recombination first captures network traffic and extracts multiple traffic parameters from it to form a traffic feature set. Subsequently, by introducing dynamic recombination fitness as an index for evaluating the effect of protocol dynamic recombination, the protocol is optimized and analyzed in combination with the traffic features to generate a dynamic protocol. Then, the protocol data stream of the dynamic protocol is captured and analyzed to obtain a protocol feature set. Finally, a threat detector is activated to perform real-time analysis on the protocol feature set, identify the threat type, and call the corresponding defense strategy according to the identification result for network processing, thereby improving network security.
[0007] The above description is only an overview of the technical solutions of this application. In order to be able to understand the technical means of this application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of this application more obvious and understandable, the following specific embodiments of this application are specifically given. Brief Description of the Drawings
[0008] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0009] Figure 1 It is a schematic flowchart of a network threat detection method under protocol dynamic recombination in an embodiment.
[0010] Figure 2 It is an architecture diagram of a network threat detection system under protocol dynamic recombination in an embodiment.
[0011] Explanation of the reference numerals: traffic feature acquisition module 11, optimization analysis module 12, protocol feature acquisition module 13, network processing module 14. DETAILED DESCRIPTION
[0012] The embodiments of the present application provide a network threat detection method and system under dynamic protocol reorganization to solve the technical problem that traditional static protocol analysis technology is difficult to adapt to the dynamic protocol reorganization scenario, resulting in delayed threat detection and high false negative rate.
[0013] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.
[0014] It should be noted that the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or server that includes a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or modules that are not explicitly listed or inherent to these processes, methods, products or devices.
[0015] Embodiment 1, as Figure 1 As shown, the present application provides a network threat detection method under dynamic protocol reorganization, the method comprising: Capturing network traffic and acquiring a traffic feature set of the network traffic, wherein the traffic feature set includes a plurality of traffic parameters.
[0016] In an embodiment of the present application, by monitoring data transmission activities on the network, network traffic information in transmission is captured in real time, and relevant traffic parameters such as data packet size, transmission rate, protocol type, source and destination IP addresses, etc. are extracted therefrom. These characteristic parameters are combined into a traffic feature set to help identify the nature and pattern of network traffic and provide data support for subsequent protocol optimization and threat detection.
[0017] The dynamic reorganization fitness is introduced as an effect evaluation index of the dynamic reorganization of the protocol, and the optimization analysis of the dynamic reorganization of the protocol is performed with the effect evaluation index and the multiple flow parameters as constraints to obtain a dynamic protocol.
[0018] In one embodiment, a dynamic recombination fitness is introduced as a criterion for evaluating the effect of protocol dynamic recombination. The dynamic recombination fitness is obtained by weighting based on predetermined dimension information (such as dynamic characteristics, security, energy consumption, etc.), and is used to reflect the adaptability of the protocol in different network environments. By using this effect evaluation index and multiple traffic parameters as constraints, the historical protocol detection database is screened and the fitness is calculated to find a dynamic protocol that conforms to the current network environment, enabling it to more effectively handle various network requirements and potential threats in the current network environment, thereby improving the overall operation efficiency and security of the network.
[0019] Further, the present application provides that the dynamic recombination fitness refers to a value obtained by weighted calculation of the predetermined dimension information of the protocol after dynamic recombination, wherein the predetermined dimension information includes information on the dynamic characteristic dimension, the security characteristic dimension, the energy consumption characteristic dimension, and the compatibility characteristic dimension.
[0020] Preferably, the dynamic recombination fitness is a value obtained by weighted calculation of multiple predetermined dimension information of the protocol. These predetermined dimension information include the dynamic characteristics, security characteristics, energy consumption characteristics, and compatibility characteristics of the protocol. Among them, the dynamic characteristics of the protocol are used to evaluate the adaptive ability, flexibility, and scalability of the protocol. The adaptive ability is the ability to measure the protocol's automatic adjustment of its parameters when the network conditions change. For example, when the network latency increases, the data transmission rate is automatically adjusted. Flexibility is to evaluate whether the protocol supports multiple configurations and options to adapt to different network requirements. Scalability is to evaluate the performance of the protocol in a large-scale network environment to ensure that the protocol can still operate efficiently even when the network load increases. The evaluation of the security characteristics of the protocol includes encryption strength, authentication strength, and integrity verification. Encryption strength measures the strength of the encryption algorithm and the key length used in the protocol to ensure that the confidentiality during data transmission is not leaked. Authentication strength evaluates the security and complexity of the authentication mechanism in the protocol to ensure that only authorized users can access the system and prevent unauthorized access. Integrity verification is a mechanism to ensure that the data is not tampered with during transmission, guaranteeing the accuracy and consistency of the data and avoiding malicious modification of the information during transmission. The resource consumption of the protocol includes bandwidth consumption, computing resources, and storage requirements. Bandwidth consumption evaluates the network bandwidth required for the protocol to run, avoiding excessive traffic caused by the protocol in the network and resulting in network congestion. Computing resources refer to the requirements of the protocol for CPU and memory resources during operation. Excessive consumption of computing resources may affect the operation efficiency of other processes in the system. Storage requirements consider the storage space required during the operation of the protocol. Especially when the protocol needs to store a large amount of data, how to efficiently manage the storage resources becomes an important consideration point to avoid waste of storage space. The compatibility of the protocol includes backward compatibility and cross-platform compatibility. Backward compatibility evaluates the compatibility of the protocol with old version systems to ensure that the new protocol can support early version devices and systems. Cross-platform compatibility evaluates whether the protocol can operate normally on different operating systems and devices to ensure that the protocol can achieve seamless docking on multiple platforms and provide a consistent service experience. After the information of these dimensions is weighted and calculated, a comprehensive fitness value, that is, the dynamic recombination fitness, is obtained to evaluate the dynamic recombination effect of the protocol in the current network environment, so as to ensure that the protocol can achieve the best performance and security in practical applications.
[0021] Furthermore, the present application provides an optimization analysis of protocol dynamic recombination by introducing the dynamic recombination fitness as an evaluation index for the effect of protocol dynamic recombination and using the effect evaluation index and the multiple traffic parameters as constraints to obtain a dynamic protocol, including: Obtain a historical protocol detection database by using the multiple traffic parameters as data screening constraints; obtain a first historical data group in the historical protocol detection database, where the first historical data group includes first network threat detection data under a first historical dynamic protocol; perform a recombination evaluation on the first network threat detection data by using the effect evaluation index as a recombination evaluation constraint to obtain a first historical fitness; if the first historical fitness reaches a predetermined fitness limit value, then use the first historical dynamic protocol as the dynamic protocol.
[0022] Preferably, first, use multiple traffic parameters as constraints for data screening, screen out data with an error mean within the tolerance range from the historical protocol detection database, and then randomly extract from the screened data to obtain a first historical data group, which contains first network threat detection data under a first historical dynamic protocol. Subsequently, use the introduced effect evaluation index as a constraint for recombination evaluation, extract any relevant features from these first network threat detection data, calculate the feedback coefficient corresponding to each feature, and then perform weighted fusion on these feedback coefficients to obtain a first historical fitness. After obtaining the first historical fitness value, judge whether it reaches a predetermined fitness limit value (which can be decided and set by domain experts based on network security requirements and historical experience). If the fitness value meets the predetermined standard, it is considered that the historical dynamic protocol performs well in the current network environment and can be used as the final dynamic protocol for actual applications. This process combines historical data with predetermined standards to ensure that the selected dynamic protocol has sufficient adaptability and effectiveness, so as to better cope with future network security threats.
[0023] Furthermore, the present application provides performing a recombination evaluation on the first network threat detection data by using the effect evaluation index as a recombination evaluation constraint to obtain a first historical fitness, including: Obtain any feature index of any dimension based on the dynamic recombination fitness; match any traffic feature group corresponding to the any feature index in the traffic feature database; obtain a first recombined traffic feature set in the first network threat detection data, and perform a traversal analysis on the first recombined traffic feature set by using the any traffic feature group to obtain any feedback coefficient of the any feature index; calculate the first historical fitness of the first historical dynamic protocol based on the any feedback coefficient.
[0024] Optionally, based on the dynamic recombination fitness, any one dimension is selected from multiple dimensions as any feature index to evaluate the performance of the protocol in more detail. Subsequently, the selected any feature index is matched in the traffic feature database (which stores each feature dimension and the corresponding specific features), and the corresponding traffic feature group is found. This traffic feature group is the data related to the dimension represented by any feature index. For example, when any feature index is the security feature dimension, the corresponding traffic feature group is the feature data such as encryption strength, authentication strength, and integrity check. Then, the first recombined traffic feature set is extracted from the first network threat detection data. These feature sets have undergone dynamic recombination processing and reflect the adjustment results of the protocol under different network conditions. By traversing and matching the first recombined traffic feature set with the matched any traffic feature group, the specific feature data corresponding to any traffic feature group is extracted, and then the matched data is fused through a preset weighted fusion strategy to obtain the feedback coefficient of any feature index. This feedback coefficient reflects the impact degree of the protocol adjustment on this network feature. Among them, the weighted fusion strategy includes a normalization strategy and a weighting strategy. The normalization strategy is the maximum-minimum normalization method, and the weighting strategy includes the weight corresponding to each feature, which is determined based on prior experience. Finally, based on all the calculated feedback coefficients, through the preset weights of each dimension, the first historical fitness of the first historical dynamic protocol is calculated. This fitness value comprehensively considers the performance of the protocol in a specific network environment and provides a quantitative basis for the optimization of subsequent protocols.
[0025] Exemplarily, in the dynamic characteristic dimension, the index value of the adaptability is 0.7 and the weight is 0.4, the index value of the flexibility is 0.6 and the weight is 0.3, the index value of the scalability is 0.8 and the weight is 0.3. Then, the feedback coefficient is (0.4×0.7)+(0.3×0.6)+(0.3×0.8)=0.28+0.18+0.24=0.7. In the security characteristic dimension, the index value of the encryption strength is 0.9 and the weight is 0.4, the index value of the authentication strength is 0.8 and the weight is 0.3, the index value of the integrity check is 0.7 and the weight is 0.3. Then, the feedback coefficient is (0.4×0.9)+(0.3×0.8)+(0.3×0.7)=0.36+0.24+0.21=0.81. In the energy consumption characteristic dimension, the index value of the bandwidth consumption is 0.5 and the weight is 0.4, the index value of the computing resource is 0.6 and the weight is 0.3, the index value of the storage requirement is 0.7 and the weight is 0.3. Then, the feedback coefficient is (0.4×0.5)+(0.3×0.6)+(0.3×0.7)=0.2+0.18+0.21=0.59. In the compatibility characteristic dimension, the index value of the backward compatibility is 0.8 and the weight is 0.5, the index value of the cross-platform compatibility is 0.7 and the weight is 0.5. Then, the feedback coefficient is (0.5×0.8)+(0.5×0.7)=0.4+0.35=0.75. The weights of the four dimensions are 0.3, 0.3, 0.2, and 0.2 respectively. Then, the first historical fitness is (0.3×0.7)+(0.3×0.81)+(0.2×0.59)+(0.2×0.75)=0.21+0.243+0.118+0.15=0.721.
[0026] Capture the protocol data stream of the dynamic protocol, and analyze the protocol data stream to obtain a protocol feature set.
[0027] In one embodiment, after obtaining the dynamic protocol, first capture the protocol data stream generated by the protocol after dynamic recombination. The protocol data stream refers to the data packets and information flows transmitted in the network, and these data packets are organized and transmitted according to the protocol rules. By capturing these data streams, the behavioral performance of the protocol during actual operation can be obtained. Subsequently, analyze the captured protocol data stream and extract the protocol feature set. The protocol feature set includes various key information extracted from the data stream, such as the size of the data packet, the transmission rate, the IP addresses of both communication parties, the port numbers, the protocol type, etc. By analyzing these features, the performance, stability, and adaptability of the protocol in different network environments can be understood. These features provide important data support for subsequent threat detection and protocol optimization.
[0028] Furthermore, the present application further includes: Screen the protocol feature set to obtain target features; construct a protocol graph of the dynamic protocol based on the target features; retrieve a graph parsing plan to perform parsing processing on the protocol graph to obtain protocol feature values; obtain first historical protocol feature values of the first historical dynamic protocol; compare the protocol feature values with the first historical protocol feature values to obtain a first feature difference; if the first feature difference reaches a predetermined difference limit value, then use the first historical dynamic protocol as the dynamic protocol.
[0029] Optionally, first screen the protocol feature set to extract target features related to network security and performance optimization. The target features are key data selected from multiple protocol features, which represent the key behaviors and attributes of the protocol in a specific network environment, such as packet size, encryption protocol handshake features, graph node features, etc., and can help focus on the parts that are most meaningful for protocol optimization and threat detection. Subsequently, based on the screened target features, construct a protocol graph of the dynamic protocol. The protocol graph is an abstract representation model that forms a visual network relationship diagram by associating the target features with different levels and elements of the network protocol. This graph helps analyze the structure, operation mode, and potential optimization directions of the protocol. Then, retrieve the graph parsing plan and perform parsing processing on the protocol graph to obtain the feature values of the protocol. Among them, the graph parsing plan includes a series of processing rules, such as graph transformation, matrix calculation, matrix decomposition, etc., for extracting useful information from the protocol graph. Through parsing, the obtained protocol feature values reflect the actual performance of the protocol in different network environments. Then, obtain the first historical protocol feature values from the first historical dynamic protocol. This first historical protocol feature value represents the performance of the past protocol under similar network conditions. By comparing the feature values of the current protocol with those of the historical protocol, a first feature difference is obtained. This first feature difference is the difference between the current protocol and the historical protocol in specific features and is used to measure the effect of protocol optimization. If the first feature difference meets the requirements of the predetermined difference limit value, that is, the first feature difference is within the range of the requirements of the predetermined difference limit value, it means that the current dynamic protocol meets the requirements in terms of performance and adaptability. Therefore, the currently used first historical dynamic protocol will be used as the final dynamic protocol for subsequent threat analysis and processing. Otherwise, the comparison of the previous historical dynamic protocol will continue to find the next historical dynamic protocol that meets the predetermined fitness limit value to improve the detection efficiency and protection response speed against unknown threats in a complex network environment.
[0030] Furthermore, this application also includes: Construct an initial protocol graph of the dynamic protocol based on the protocol feature set; perform dimensionality reduction processing on the initial protocol graph to obtain the protocol graph.
[0031] Optionally, based on the target features extracted from the protocol feature set, such as source IP, destination IP, packet size, arrival time, Client Hello, Server Hello, etc. Subsequently, each target feature is mapped to a node in the graph. For example, source IP, destination IP, port number, etc. can be regarded as different nodes, and each node represents an important element in the protocol. Then, edges are defined according to the relationships between these nodes, such as the connection between the two communicating parties, the order of data transmission, the process of encrypted handshake, etc., so as to construct an initial protocol graph. Each node and edge in this initial protocol graph contains detailed information of the protocol features, reflecting the transmission mode and behavior of the protocol in the network. After that, dimensionality reduction processing is performed on the initial protocol graph. Common dimensionality reduction methods include principal component analysis (PCA), t-SNE (t-distributed stochastic neighbor embedding), or autoencoders, etc. When performing dimensionality reduction, it is necessary to evaluate the correlation between various features in the graph. By calculating the similarity between nodes or the strength of edges, it can be understood which features are closely related and which are redundant. Features with strong correlation can be merged, and redundant features can be removed. Then, according to the selected dimensionality reduction method, the high-dimensional feature data in the graph is mapped to a low-dimensional space. For example, using PCA to project the feature matrix into a new coordinate system, retaining the most information while discarding a small amount of information with small variance. During this process, the nodes and edges in the graph will be transformed into a more simplified representation form, reducing the computational complexity. The protocol graph obtained after dimensionality reduction will contain fewer dimensions but retain the core features of the protocol. Each node and edge in the dimensionality-reduced graph represents the refined protocol information, which can more efficiently represent the structure and behavior of the protocol. Dimensionality reduction may also change the structure of the graph. The edges between some nodes may be reorganized or optimized to better reflect the key behaviors of the protocol, thus providing strong support for subsequent analysis and optimization.
[0032] Furthermore, the present application provides that the protocol feature set at least includes connection features, metadata features, encrypted protocol handshake features, and graph node features.
[0033] Optionally, the protocol feature set is the key information extracted from the reorganized protocol data stream, used to describe the behavior and performance of the protocol in the network, including but not limited to connection features, metadata features, TLS encryption protocol handshake features, and graph node features. Among them, the connection features are used to describe the basic connection information between the two parties of the protocol communication, mainly including the source IP and destination IP (used to identify the data source and destination), port number (indicating the communication port), and protocol type (indicating the network protocol used, such as TCP, UDP, etc.). These features help analyze the basic structure of network traffic. The metadata features involve the transmission details of protocol packets, including the packet size, arrival time, and payload byte count, etc. They reflect the scale, time distribution, and network load of data transmission, and help analyze traffic patterns and bandwidth consumption. The TLS encryption protocol handshake features focus on the handshake process of the TLS encryption protocol, including Client Hello and Server Hello messages (which are the initial steps for establishing an encrypted connection), and certificate verification (a security mechanism used to verify the identities of both communication parties). These features are crucial for the security and communication integrity of the protocol. The graph node features are used to describe the relationships between features, including node type (indicating the role of each node in the graph, such as data source, data recipient, etc.), edge type (describing the connection relationship between nodes, such as data flow direction, communication protocol, etc.), and call order (describing the interaction order between nodes). Through these features, a structured representation of the protocol data stream can be constructed. These feature sets comprehensively describe all aspects of the protocol, including network connection, data transmission, encryption security, and protocol structure, etc., providing an important basis for protocol analysis, optimization, and threat detection.
[0034] Furthermore, the present application provides a method of invoking a graph parsing plan to parse the protocol graph to obtain protocol feature values, including: Converting the protocol graph into a protocol feature undirected graph according to the graph parsing plan; respectively obtaining the degree matrix and adjacency matrix of the protocol feature undirected graph; taking the difference between the degree matrix and the adjacency matrix as the protocol Laplacian matrix; decomposing the protocol Laplacian matrix to obtain the protocol feature values.
[0035] Optionally, before processing the protocol graph, call the graph parsing pre-plan and use this graph parsing pre-plan to convert the graph into an undirected graph. Specifically, first analyze the nodes and edges in the protocol graph, clarify the representative features of each node (such as connection features, metadata features, encryption protocol handshake features, etc.), and the relationships between nodes (such as data flow direction, communication order, mutual dependencies between protocol features, etc.). Subsequently, convert the directed edges in the protocol graph into undirected edges. Some of the edges between nodes in the protocol graph may have directions, indicating the direction of data flow or communication (such as a connection from the client to the server). To convert it into an undirected graph, the directionality needs to be ignored, and the edge only represents the relationship between nodes, without caring which node is the starting node and which node is the ending node. For example, the connection relationship from the "client" to the "server" should be converted into an undirected connection between the "client" and the "server". After all the edges are processed, a protocol feature undirected graph is obtained. Then, obtain the degree matrix and the adjacency matrix from the protocol feature undirected graph. The degree matrix is a diagonal matrix, where each diagonal element represents the degree of the corresponding node in the graph, that is, the number of edges connected to this node. In the protocol feature undirected graph, the degree matrix reflects the connection situation of each protocol feature node. The adjacency matrix is a square matrix, and the elements in it represent the connection relationships between the nodes in the graph. If there is an edge connecting two nodes, the corresponding element in the matrix is 1, and if there is no connection, it is 0. The adjacency matrix can be used to describe the direct relationships or communications between nodes. Then, subtract the degree matrix from the adjacency matrix to obtain the protocol Laplacian matrix, which represents the connection strength between the nodes in the graph and the overall structure of the network. Then, perform eigenvalue decomposition on the protocol Laplacian matrix. The purpose of eigenvalue decomposition is to decompose the Laplacian matrix into a set of eigenvectors and eigenvalues. Through decomposition, the obtained eigenvalues provide the structural information of the graph. The magnitude of the eigenvalues is usually related to properties such as the connectivity and stability of the nodes in the graph. Through these steps, the mathematical representation of the protocol graph (through the degree matrix, adjacency matrix, Laplacian matrix, and eigenvalues) is further analyzed and processed, which can provide in-depth understanding of the structure, performance, and potential problems of the protocol, thereby accurately identifying threats and improving the detection efficiency and protection response speed of unknown threats in a complex network environment.
[0036] Activate the threat detector to analyze the protocol feature set to obtain real-time threat types, and call the threat defense strategies corresponding to the real-time threat types for network processing.
[0037] In one embodiment, the threat detector is first activated to perform real-time analysis on the extracted protocol feature set. The threat detector analyzes the key features of the protocol (such as connection features, encryption characteristics, traffic patterns, etc.) through the internal event sequence correlation detection component and the graph neural network detection component, and identifies possible security threats. For example, the detector may discover APT attacks, malicious traffic, encrypted malicious traffic, smart contract vulnerabilities, etc. Once a potential threat is detected, the threat detector immediately classifies these threats and identifies the specific real-time threat types. Subsequently, based on the identified threat types, predefined threat defense strategies are called to respond. The defense strategies may include real-time blocking of abnormal connections, enabling stronger encryption protocols, restricting access, or reconfiguring network security settings, etc. These measures help to immediately respond to and mitigate threats, ensuring the security and stability of the network. The entire process ensures that the network can automatically identify and respond to various potential security threats during the protocol operation, providing a dynamic and real-time security protection mechanism.
[0038] Furthermore, the present application provides activating the threat detector to analyze the protocol feature set to obtain real-time threat types, including: Activating the event sequence correlation detection component in the threat detector; dynamically detecting a first threat type set through the event sequence correlation detection component in combination with the protocol feature set; activating the graph neural network detection component in the threat detector; dynamically detecting a second threat type set through the graph neural network detection component in combination with the protocol feature set; the first threat type set and the second threat type set constitute the real-time threat types.
[0039] Preferably, after obtaining the protocol feature set, the event sequence association detection component in the threat detector is activated. This component performs dynamic detection based on the data in the protocol feature set with the aim of identifying possible multi-step attack behaviors (such as Advanced Persistent Threats - APT). The event sequence association model can identify those attack patterns with multiple stages and strong concealment by analyzing the chronological order and mutual relationships between events, thereby obtaining the first threat type set, which contains possible attack types, such as staged attacks using protocol vulnerabilities. In addition, the graph neural network detection component in the threat detector is also activated. This component can handle complex network structures and node relationships and is suitable for detecting complex network threats, such as smart contract vulnerabilities and encrypted malicious traffic. By passing the protocol feature set to the graph neural network detection component, the graph neural network detection component will analyze the abnormal relationships that appear in the network based on these feature data and identify attack behaviors with potential risks. This process can reveal hidden threats that are difficult to discover by ordinary detection methods, thereby obtaining the second threat type set, which contains complex threats such as encrypted malicious traffic or smart contract vulnerabilities. Finally, the first threat type set and the second threat type set are combined to form the real-time threat type for subsequent targeted network processing to ensure network security.
[0040] For the event sequence association detection component in the threat detector, deep learning models, Markov models, and association rule learning can be used to construct it. Taking the deep learning model as an example, the long short-term memory (LSTM) in the deep learning model can be used to construct the basic structure of the event sequence association detection component, and then it is trained using historical threat processing data (including historical protocol features and historical threat types), including steps such as forward propagation, loss calculation, backpropagation, and parameter optimization, which are iterated until the maximum number of iterations is reached or convergence occurs. For the graph neural network detection component in the threat detector, it is constructed using a graph neural network, and the training method is similar to the previous one, also through steps such as forward propagation, loss calculation, backpropagation, and parameter optimization.
[0041] In summary, the embodiments of the present application have at least the following technical effects: In the embodiment of the present application, network traffic is first captured, and a traffic feature set of the network traffic is obtained, where the traffic feature set includes multiple traffic parameters; subsequently, dynamic recombination fitness is introduced as an effect evaluation index for protocol dynamic recombination, and optimization analysis of protocol dynamic recombination is performed with the effect evaluation index and the multiple traffic parameters as constraints to obtain a dynamic protocol; then, the protocol data stream of the dynamic protocol is captured, and the protocol data stream is analyzed to obtain a protocol feature set; finally, a threat detector is activated to analyze the protocol feature set to obtain a real-time threat type, and a threat defense strategy corresponding to the real-time threat type is called for network processing. These technical effects together solve the technical problem that traditional static protocol analysis technologies are difficult to adapt to the scenario of protocol dynamic recombination, resulting in lagging threat detection and a high false negative rate, and achieve the technical effects of real-time and accurate threat identification and adaptive defense based on dynamic recombination optimization, improving the detection efficiency of unknown threats and the protection response speed in complex network environments.
[0042] Embodiment 2, based on the same inventive concept as the method for network threat detection under a protocol dynamic recombination in the foregoing embodiment, as Figure 2 shown, the present application provides a network threat detection system under a protocol dynamic recombination, and the system includes: a traffic feature acquisition module 11: capturing network traffic and obtaining a traffic feature set of the network traffic, where the traffic feature set includes multiple traffic parameters; an optimization analysis module 12: introducing dynamic recombination fitness as an effect evaluation index for protocol dynamic recombination, and performing optimization analysis of protocol dynamic recombination with the effect evaluation index and the multiple traffic parameters as constraints to obtain a dynamic protocol; a protocol feature acquisition module 13: capturing the protocol data stream of the dynamic protocol and analyzing the protocol data stream to obtain a protocol feature set; a network processing module 14: activating a threat detector to analyze the protocol feature set to obtain a real-time threat type, and calling a threat defense strategy corresponding to the real-time threat type for network processing.
[0043] Further, the optimization analysis module 12 is further configured to execute the following method: The dynamic recombination fitness refers to a value obtained by weighted calculation of the predetermined dimension information of the protocol after dynamic recombination, where the predetermined dimension information includes information on the dynamic characteristic dimension, the security characteristic dimension, the energy consumption characteristic dimension, and the compatibility characteristic dimension.
[0044] Further, the optimization analysis module 12 is further configured to execute the following method: Obtain a historical protocol detection database using the multiple traffic parameters as data screening constraints; obtain a first historical data group in the historical protocol detection database, where the first historical data group includes first network threat detection data under a first historical dynamic protocol; perform a recombination evaluation on the first network threat detection data using the effect evaluation index as a recombination evaluation constraint to obtain a first historical fitness; if the first historical fitness reaches a predetermined fitness limit value, then use the first historical dynamic protocol as the dynamic protocol.
[0045] Further, the optimization analysis module 12 is further configured to execute the following method: Obtain any feature index of any dimension based on the dynamic recombination fitness; match any traffic feature group corresponding to the any feature index in the traffic feature database; obtain a first recombined traffic feature set in the first network threat detection data, and perform a traversal analysis on the first recombined traffic feature set using the any traffic feature group to obtain any feedback coefficient of the any feature index; calculate the first historical fitness of the first historical dynamic protocol based on the any feedback coefficient.
[0046] Further, the optimization analysis module 12 is further configured to execute the following method: Screen the protocol feature set to obtain target features; construct a protocol graph of the dynamic protocol based on the target features; retrieve a graph parsing plan to perform parsing processing on the protocol graph to obtain protocol feature values; obtain a first historical protocol feature value of the first historical dynamic protocol; compare the protocol feature values with the first historical protocol feature values to obtain a first feature difference; if the first feature difference reaches a predetermined difference limit value, then use the first historical dynamic protocol as the dynamic protocol.
[0047] Further, the optimization analysis module 12 is further configured to execute the following method: Construct an initial protocol graph of the dynamic protocol based on the protocol feature set; perform dimensionality reduction processing on the initial protocol graph to obtain the protocol graph.
[0048] Further, the optimization analysis module 12 is further configured to execute the following method: The protocol feature set at least includes connection features, metadata features, encrypted protocol handshake features, and graph node features.
[0049] Further, the optimization analysis module 12 is further configured to execute the following method: Convert the protocol graph into an undirected graph of protocol features according to the protocol graph parsing plan; respectively obtain the degree matrix and the adjacency matrix of the undirected graph of protocol features; take the difference between the degree matrix and the adjacency matrix as the protocol Laplacian matrix; decompose the protocol Laplacian matrix to obtain the protocol eigenvalues.
[0050] Further, the network processing module 14 is further configured to execute the following method: Activate the event sequence correlation detection component in the threat detector; dynamically detect the first threat type set through the event sequence correlation detection component in combination with the protocol feature set; activate the graph neural network detection component in the threat detector; dynamically detect the second threat type set through the graph neural network detection component in combination with the protocol feature set; the first threat type set and the second threat type set constitute the real-time threat type.
[0051] It should be noted that the above sequence of embodiments of the present application is only for description and does not represent the superiority or inferiority of the embodiments. And the above description of specific embodiments of this specification has been made. The processes depicted in the drawings do not necessarily require the specific order and continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0052] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.
[0053] This specification and the drawings are only exemplary descriptions of the present application and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of the present application. Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the present application and its equivalent technologies, the present application is intended to include these modifications and variations.
Claims
1. A network threat detection method under dynamic protocol recombination, characterized in that, including: capturing network traffic and obtaining a traffic feature set of the network traffic, where the traffic feature set includes a plurality of traffic parameters; introducing dynamic recombination fitness as an effect evaluation index for protocol dynamic recombination, and performing optimization analysis of protocol dynamic recombination with the effect evaluation index and the plurality of traffic parameters as constraints to obtain a dynamic protocol; capturing a protocol data stream of the dynamic protocol and analyzing the protocol data stream to obtain a protocol feature set; activating a threat detector to analyze the protocol feature set to obtain a real-time threat type, and invoking a threat defense strategy corresponding to the real-time threat type for network processing.
2. The network threat detection method under dynamic protocol recombination according to claim 1, wherein, The dynamic recombination fitness refers to a value obtained by weighted calculation of predetermined dimension information of the protocol after dynamic recombination, where the predetermined dimension information includes information on a dynamic characteristic dimension, a security characteristic dimension, an energy consumption characteristic dimension, and a compatibility characteristic dimension.
3. The network threat detection method under dynamic protocol recombination according to claim 1, characterized in that Introducing dynamic recombination fitness as an effect evaluation index for protocol dynamic recombination, and performing optimization analysis of protocol dynamic recombination with the effect evaluation index and the plurality of traffic parameters as constraints to obtain a dynamic protocol, including: obtaining a historical protocol detection database with the plurality of traffic parameters as data screening constraints; obtaining a first historical data group in the historical protocol detection database, where the first historical data group includes first network threat detection data under a first historical dynamic protocol; performing recombination evaluation on the first network threat detection data with the effect evaluation index as a recombination evaluation constraint to obtain a first historical fitness; if the first historical fitness reaches a predetermined fitness limit value, then using the first historical dynamic protocol as the dynamic protocol.
4. The network threat detection method under dynamic protocol recombination according to claim 3, characterized in that Performing recombination evaluation on the first network threat detection data with the effect evaluation index as a recombination evaluation constraint to obtain a first historical fitness, including: obtaining any characteristic index of any dimension based on the dynamic recombination fitness; matching any traffic feature group corresponding to the any characteristic index in a traffic feature database; obtaining a first recombined traffic feature set in the first network threat detection data, and traversing and analyzing the first recombined traffic feature set with the any traffic feature group to obtain any feedback coefficient of the any characteristic index; calculating the first historical fitness of the first historical dynamic protocol based on the any feedback coefficient.
5. The network threat detection method under dynamic protocol reorganization according to claim 3, characterized in that, further including: screening the protocol feature set to obtain target features; constructing a protocol graph of the dynamic protocol based on the target features; invoking a graph parsing preplan to perform parsing processing on the protocol graph to obtain protocol feature values; obtaining first historical protocol feature values of the first historical dynamic protocol; comparing the protocol feature values with the first historical protocol feature values to obtain a first feature difference; if the first feature difference reaches a predetermined difference limit value, then using the first historical dynamic protocol as the dynamic protocol.
6. The network threat detection method under dynamic protocol recombination according to claim 5, characterized in that further including: constructing an initial protocol graph of the dynamic protocol based on the protocol feature set; performing dimensionality reduction processing on the initial protocol graph to obtain the protocol graph.
7. The network threat detection method under dynamic protocol reorganization according to claim 5, wherein The protocol feature set at least includes connection features, metadata features, encrypted protocol handshake features, and graph node features.
8. The network threat detection method under dynamic protocol recombination according to claim 5, wherein Retrieve the protocol map parsing plan to parse the protocol map and obtain protocol feature values, including: Convert the protocol map into a protocol feature undirected graph according to the protocol map parsing plan; Obtain the degree matrix and adjacency matrix of the protocol feature undirected graph respectively; Take the difference between the degree matrix and the adjacency matrix as the protocol Laplacian matrix; Decompose the protocol Laplacian matrix to obtain the protocol feature values.
9. The method for detecting network threats under dynamic protocol reorganization according to claim 1, wherein Activate the threat detector to analyze the protocol feature set to obtain real-time threat types, including: Activate the event sequence correlation detection component in the threat detector; Dynamically detect the first threat type set through the event sequence correlation detection component in combination with the protocol feature set; Activate the graph neural network detection component in the threat detector; Dynamically detect the second threat type set through the graph neural network detection component in combination with the protocol feature set; The first threat type set and the second threat type set constitute the real-time threat type.
10. A network threat detection system under dynamic protocol recombination, characterized in that, The system is used to execute the network threat detection method under a protocol dynamic reorganization as described in any one of claims 1-9, including: Traffic feature acquisition module: Capture network traffic and obtain the traffic feature set of the network traffic, where the traffic feature set includes multiple traffic parameters; Optimization analysis module: Introduce the dynamic reorganization fitness as an evaluation index for the effect of protocol dynamic reorganization, and perform optimization analysis of protocol dynamic reorganization with the evaluation index and the multiple traffic parameters as constraints to obtain a dynamic protocol; Protocol feature acquisition module: Capture the protocol data stream of the dynamic protocol and analyze the protocol data stream to obtain a protocol feature set; Network processing module: Activate the threat detector to analyze the protocol feature set to obtain real-time threat types, and call the threat defense strategies corresponding to the real-time threat types for network processing.
Citation Information
Patent Citations
Systems and methods for generating network threat intelligence
CA2982107A1
Network threat evaluation method based on multi-granularity anomaly detection
CN105407103A
Network security monitoring and response system
CN118118258A
Self-evolution network security defense strategy generation and dynamic deployment method
CN119561793A
Real-time flow analysis method and system for network routing
CN119697094A
Cited By
Business internet platform big data security protection system
CN121000484A
Multifunctional network access detection system supporting unified intelligent terminal operating system protocol
CN121125583A