A network threat detection method and system under dynamic protocol reorganization
By capturing the network traffic feature set and introducing a dynamic reorganization fitness optimization protocol, the lag problem of traditional threat detection technology in the dynamic reorganization scenario of protocols is solved, real-time accurate threat identification and adaptive defense are achieved, and network security is improved.
Patent Information
- Application Number
- CN202510799824.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-16
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2045-06-16
AI Technical Summary
Traditional threat detection technology based on fixed protocol rules is difficult to deal with dynamic protocol restructuring scenarios, resulting in high threat detection lag and missed response rates. Especially in scenarios where heterogeneous protocols such as the Internet of Things and the Industrial Internet frequently interact, it is impossible to effectively identify zero-day attacks and advanced persistent threats in encrypted channels.
By capturing the network traffic feature set, dynamic reorganization fitness is introduced as an evaluation indicator for dynamic reorganization optimization of protocols, dynamic protocols are generated, and protocol feature set is analyzed through threat detectors, real-time threat types are identified and defense strategies are called.
Real-time accurate threat identification and adaptive defense in complex network environments are realized, and the detection efficiency and protection response speed of unknown threats are improved.
Smart Images

Figure CN120321043B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a network threat detection method and system under dynamic protocol reorganization. Background Art
[0002] The dual pressures of dynamic protocol evolution and variability in attack methods in network traffic environments pose a serious risk of failure for traditional threat detection systems based on fixed protocol rules. Current mainstream detection technologies rely on predefined protocol templates for traffic parsing, making them incapable of addressing emerging attack methods such as dynamic obfuscation of protocol fields and disguised encryption handshake behavior. This is particularly true in scenarios where heterogeneous protocols frequently interact, such as those in the Internet of Things and Industrial Internet. Attackers can exploit protocol reassembly vulnerabilities to bypass detection engines. Existing methods lack a quantitative evaluation mechanism for the dynamic protocol reassembly process and are unable to adjust protocol parsing strategies based on real-time traffic characteristics. This makes it difficult to effectively identify zero-day attacks and advanced persistent threats (APTs) within encrypted channels. Furthermore, traditional feature extraction techniques are often limited to single-dimensional traffic parameter analysis and fail to establish a correlation model between protocol structure topology and threat behavior, resulting in a blind spot in detecting distributed coordinated attacks and protocol-level covert channels. Therefore, network threat detection methods based on dynamic protocol reassembly have emerged to address the rapid evolution of dynamic and hidden security threats in complex network environments. Summary of the Invention
[0003] This application provides a network threat detection method and system under dynamic protocol reorganization, aiming to solve the technical problem that traditional static protocol analysis technology is difficult to adapt to the dynamic protocol reorganization scenario, resulting in delayed threat detection and high missed reporting rate.
[0004] The first aspect disclosed in the present application provides a network threat detection method under dynamic protocol reorganization, the method comprising: capturing network traffic and obtaining a traffic feature set of the network traffic, wherein the traffic feature set includes multiple traffic parameters; introducing dynamic reorganization fitness as an effect evaluation index of the dynamic protocol reorganization, and performing optimization analysis of the dynamic protocol reorganization with the effect evaluation index and the multiple traffic parameters as constraints to obtain a dynamic protocol; capturing the protocol data stream of the dynamic protocol, and analyzing the protocol data stream to obtain a protocol feature set; activating a threat detector to analyze the protocol feature set to obtain a real-time threat type, and calling a threat defense strategy corresponding to the real-time threat type for network processing.
[0005] Another aspect disclosed in the present application provides a network threat detection system under dynamic protocol reorganization, the system comprising: a traffic feature acquisition module for capturing network traffic and acquiring a traffic feature set of the network traffic, wherein the traffic feature set comprises a plurality of traffic parameters; an optimization analysis module for introducing dynamic reorganization fitness as an evaluation index for the effect of dynamic protocol reorganization, and performing optimization analysis of the dynamic protocol reorganization with the effect evaluation index and the plurality of traffic parameters as constraints to obtain a dynamic protocol; a protocol feature acquisition module for capturing the protocol data stream of the dynamic protocol, and analyzing the protocol data stream to obtain a protocol feature set; a network processing module for activating a threat detector to analyze the protocol feature set to obtain a real-time threat type, and calling a threat defense strategy corresponding to the real-time threat type for network processing.
[0006] One or more technical solutions provided in this application have at least the following technical effects or advantages:
[0007] The aforementioned network threat detection method for dynamic protocol reconfiguration first captures network traffic and extracts multiple traffic parameters to form a traffic signature set. Subsequently, by introducing dynamic reconfiguration fitness as an indicator to evaluate the effectiveness of the protocol reconfiguration, the protocol is optimized and analyzed in combination with traffic signatures to generate a dynamic protocol. The protocol data stream of this dynamic protocol is then captured and analyzed to obtain a protocol signature set. Finally, a threat detector is activated to perform real-time analysis of the protocol signature set, identify threat types, and, based on the identified results, invoke appropriate defense strategies to address the network, thereby improving network security.
[0008] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0010] Figure 1 The figure is a flow chart of a network threat detection method under dynamic protocol reorganization in one embodiment.
[0011] Figure 2 The following is an architecture diagram of a network threat detection system under dynamic protocol reorganization in one embodiment.
[0012] Explanation of the reference numerals: traffic feature acquisition module 11, optimization analysis module 12, protocol feature acquisition module 13, network processing module 14. DETAILED DESCRIPTION
[0013] The embodiments of the present application provide a network threat detection method and system under dynamic protocol reorganization to solve the technical problem that traditional static protocol analysis technology is difficult to adapt to the dynamic protocol reorganization scenario, resulting in delayed threat detection and high missed reporting rate.
[0014] The following will be combined with the accompanying drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only some of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0015] It should be noted that the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or server that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or modules that are not clearly listed or are inherent to these processes, methods, products or devices.
[0016] Example 1, as Figure 1 As shown, the present application provides a network threat detection method under dynamic protocol reorganization, the method comprising:
[0017] Capturing network traffic and obtaining a traffic feature set of the network traffic, wherein the traffic feature set includes a plurality of traffic parameters.
[0018] In an embodiment of the present application, by monitoring data transmission activities on the network, network traffic information in transmission is captured in real time, and relevant traffic parameters such as data packet size, transmission rate, protocol type, source and destination IP addresses, etc. are extracted. These characteristic parameters are combined into a traffic feature set to help identify the nature and pattern of network traffic and provide data support for subsequent protocol optimization and threat detection.
[0019] The dynamic reorganization fitness is introduced as an effect evaluation index of the protocol dynamic reorganization, and the optimization analysis of the protocol dynamic reorganization is performed with the effect evaluation index and the multiple flow parameters as constraints to obtain a dynamic protocol.
[0020] In one embodiment, dynamic reconfiguration fitness is introduced as a criterion for evaluating the effectiveness of protocol dynamic reconfiguration. This fitness is weighted based on predetermined dimensions (such as dynamic characteristics, security, and energy consumption) to reflect the protocol's adaptability in different network environments. By using this effectiveness evaluation metric and multiple traffic parameters as constraints, a historical protocol detection database is screened and fitness calculated to identify dynamic protocols that are compatible with the current network environment. This allows them to more effectively respond to various network demands and potential threats within the current network environment, thereby improving the overall operational efficiency and security of the network.
[0021] Furthermore, the present application provides that the dynamic reorganization fitness refers to the value obtained by weighted calculation of predetermined dimensional information of the dynamically reorganized protocol, wherein the predetermined dimensional information includes information on dynamic characteristic dimension, security characteristic dimension, energy consumption characteristic dimension and compatibility characteristic dimension.
[0022] Preferably, the dynamic reconfiguration fitness is a value obtained by weighted calculation of multiple predetermined dimensions of information about the protocol, including the protocol's dynamic characteristics, security characteristics, energy consumption characteristics, and compatibility characteristics. The protocol's dynamic characteristics are used to assess its adaptability, flexibility, and scalability. Adaptability measures the protocol's ability to automatically adjust its parameters when network conditions change, such as automatically adjusting the data transmission rate when network latency increases. Flexibility assesses whether the protocol supports multiple configurations and options to adapt to different network requirements. Scalability assesses the protocol's performance in large-scale network environments, ensuring that the protocol remains efficient even when network load increases. The protocol's security features are assessed in terms of encryption strength, authentication strength, and integrity checking. Encryption strength measures the strength of the encryption algorithm and key length used in the protocol to ensure confidentiality is not compromised during data transmission. Authentication strength assesses the security and complexity of the protocol's authentication mechanism, ensuring that only authorized users can access the system and preventing unauthorized access. Integrity checking ensures that data has not been tampered with during transmission, ensuring data accuracy and consistency and preventing malicious modification during transmission. A protocol's resource consumption includes bandwidth consumption, computing resources, and storage requirements. Bandwidth consumption assesses the network bandwidth required for the protocol's execution, preventing it from causing excessive network traffic and congestion. Computing resources refer to the CPU and memory resources required by the protocol during operation. Excessive computing resource consumption can impact the efficiency of other system processes. Storage requirements consider the storage space required for the protocol's operation. Efficiently managing storage resources is crucial to avoid wasted storage space, especially when the protocol requires large amounts of data. Protocol compatibility includes backward compatibility and cross-platform compatibility. Backward compatibility assesses the protocol's compatibility with older versions of systems, ensuring that the new protocol can support older devices and systems. Cross-platform compatibility assesses the protocol's ability to run properly across different operating systems and devices, ensuring seamless integration across multiple platforms and a consistent service experience. These dimensions are weighted together to produce a comprehensive fitness value, the dynamic reconfiguration fitness, which evaluates the protocol's dynamic reconfiguration effectiveness in the current network environment, thereby ensuring optimal performance and security in real-world applications.
[0023] Furthermore, the present application provides the introduction of dynamic reorganization fitness as an effect evaluation index of the dynamic reorganization of the protocol, and performs optimization analysis of the dynamic reorganization of the protocol with the effect evaluation index and the multiple traffic parameters as constraints to obtain a dynamic protocol, including:
[0024] A historical protocol detection database is obtained using the multiple traffic parameters as data screening constraints; a first historical data group is obtained from the historical protocol detection database, wherein the first historical data group includes first network threat detection data under a first historical dynamic protocol; the first network threat detection data is reorganized and evaluated using the effect evaluation index as a reorganization evaluation constraint to obtain a first historical fitness; if the first historical fitness reaches a predetermined fitness limit, the first historical dynamic protocol is used as the dynamic protocol.
[0025] Preferably, multiple traffic parameters are first used as data screening constraints to filter data from a historical protocol detection database to identify data with mean errors within a tolerance range. Random sampling is then performed from this filtered data to obtain a first historical data set, which contains first network threat detection data for a first historical dynamic protocol. Subsequently, the introduced effectiveness evaluation indicators are used as constraints for reorganization and evaluation to extract any relevant features from this first network threat detection data. The feedback coefficient corresponding to each feature is calculated, and these feedback coefficients are weighted and fused to obtain a first historical fitness value. After obtaining the first historical fitness value, a determination is made as to whether it meets a predetermined fitness limit (which can be determined by domain experts based on network security requirements and historical experience). If the fitness value meets a predetermined standard, the historical dynamic protocol is deemed to perform well in the current network environment and can be used as the final dynamic protocol for practical application. This process, by combining historical data with predetermined standards, ensures that the selected dynamic protocol has sufficient adaptability and effectiveness, thereby better addressing future network security threats.
[0026] Furthermore, the present application provides a method of performing a reorganization evaluation on the first network threat detection data using the effect evaluation index as a reorganization evaluation constraint to obtain a first historical fitness, including:
[0027] Based on the dynamic reorganization fitness, any characteristic indicator of any dimension is obtained; any traffic feature group corresponding to the arbitrary characteristic indicator is matched in the traffic feature database; the first reorganized traffic feature set in the first network threat detection data is obtained, and the first reorganized traffic feature set is traversed and analyzed with the arbitrary traffic feature group to obtain any feedback coefficient of the arbitrary characteristic indicator; the first historical fitness of the first historical dynamic protocol is calculated based on the arbitrary feedback coefficient.
[0028] Optionally, based on the dynamic reassembly fitness, any one dimension from multiple dimensions is selected as an arbitrary feature indicator to provide a more detailed assessment of protocol performance. Subsequently, the selected arbitrary feature indicator is matched against a traffic feature database (which stores each feature dimension and its corresponding specific features) to find a corresponding traffic feature group. This traffic feature group contains data related to the dimension represented by the arbitrary feature indicator. For example, when the arbitrary feature indicator is a security feature dimension, the corresponding traffic feature group includes feature data such as encryption strength, authentication strength, and integrity verification. Next, a first reassembled traffic feature set is extracted from the first network threat detection data. These feature sets, after dynamic reassembly, reflect the protocol's adjustments under different network conditions. The first reassembled traffic feature set is traversed and matched using the matched arbitrary traffic feature group to extract the specific feature data corresponding to the arbitrary traffic feature group. The matched data is then fused using a preset weighted fusion strategy to obtain a feedback coefficient for the arbitrary feature indicator. This feedback coefficient reflects the impact of the protocol adjustments on the network characteristics. The weighted fusion strategy includes normalization and weighting. The normalization strategy uses the maximum-minimum normalization method, while the weighting strategy includes weights for each feature, determined based on prior experience. Finally, all calculated feedback coefficients are fused using preset weights for each dimension to calculate the first historical fitness of the first historical dynamic protocol. This fitness value comprehensively considers the protocol's performance in a specific network environment and provides a quantitative basis for subsequent protocol optimization.
[0029] For example, in the dynamic characteristics dimension, the index value of adaptability is 0.7 and the weight is 0.4, the index value of flexibility is 0.6 and the weight is 0.3, and the index value of scalability is 0.8 and the weight is 0.3. Therefore, the feedback coefficient is (0.4×0.7)+(0.3×0.6)+(0.3×0.8)=0.28+0.18+0.24=0.7. In the security characteristics dimension, the index value of encryption strength is 0.9 and the weight is 0.4, the index value of authentication strength is 0.8 and the weight is 0.3, and the index value of integrity check is 0.7 and the weight is 0.3. Therefore, the feedback coefficient is (0.4×0.9)+(0.3×0.8)+(0.3×0.7)=0.36+0.24+0.21=0.81. In the energy consumption dimension, the bandwidth consumption index is 0.5 and the weight is 0.4; the computing resource index is 0.6 and the weight is 0.3; the storage requirement index is 0.7 and the weight is 0.3. Therefore, the feedback coefficient is (0.4 × 0.5) + (0.3 × 0.6) + (0.3 × 0.7) = 0.2 + 0.18 + 0.21 = 0.59. In the compatibility dimension, the backward compatibility index is 0.8 and the weight is 0.5; the cross-platform compatibility index is 0.7 and the weight is 0.5. Therefore, the feedback coefficient is (0.5 × 0.8) + (0.5 × 0.7) = 0.4 + 0.35 = 0.75. The weights of the four dimensions are 0.3, 0.3, 0.2, and 0.2 respectively. Then, the first historical fitness is (0.3×0.7)+(0.3×0.81)+(0.2×0.59)+(0.2×0.75)=0.21+0.243+0.118+0.15=0.721.
[0030] The protocol data stream of the dynamic protocol is captured, and the protocol data stream is analyzed to obtain a protocol feature set.
[0031] In one embodiment, after obtaining a dynamic protocol, the protocol data stream generated by the dynamically reorganized protocol is first captured. The protocol data stream refers to the data packets and information streams transmitted in the network, which are organized and transmitted according to the protocol rules. By capturing these data streams, the behavior of the protocol in actual operation can be obtained. Subsequently, the captured protocol data stream is analyzed to extract the protocol feature set. The protocol feature set includes various key information extracted from the data stream, such as the size of the data packet, the transmission rate, the IP addresses of the communicating parties, the port number, the protocol type, etc. By analyzing these features, the performance, stability, and adaptability of the protocol in different network environments can be understood. These features provide important data support for subsequent threat detection and protocol optimization.
[0032] Furthermore, this application also includes:
[0033] The protocol feature set is screened to obtain a target feature; a protocol graph of the dynamic protocol is constructed based on the target feature; a graph parsing plan is called to parse the protocol graph to obtain a protocol feature value; a first historical protocol feature value of the first historical dynamic protocol is obtained; the protocol feature value is compared with the first historical protocol feature value to obtain a first feature difference; if the first feature difference reaches a predetermined difference limit, the first historical dynamic protocol is used as the dynamic protocol.
[0034] Optionally, the protocol feature set is first filtered to extract target features relevant to network security and performance optimization. Target features are key data selected from multiple protocol features. They represent key behaviors and properties of the protocol in a specific network environment, such as packet size, encryption protocol handshake characteristics, and graph node characteristics. This helps focus on the most meaningful aspects for protocol optimization and threat detection. Subsequently, based on the filtered target features, a protocol graph for the dynamic protocol is constructed. The protocol graph is an abstract representation model that links target features with different layers and elements of the network protocol to form a visual network relationship diagram. This graph facilitates analysis of the protocol structure, operating mode, and potential optimization directions. Next, a graph parsing plan is invoked to parse the protocol graph and obtain protocol feature values. The graph parsing plan includes a series of processing rules, such as graph transformation, matrix calculation, and matrix decomposition, to extract useful information from the protocol graph. The resulting protocol feature values reflect the actual performance of the protocol in different network environments. Next, a first historical protocol feature value is obtained from the first historical dynamic protocol. This first historical protocol feature value represents the protocol's past performance under similar network conditions. By comparing the characteristic values of the current protocol with the characteristic values of the historical protocol, a first characteristic difference is obtained. This first characteristic difference is the difference between the current protocol and the historical protocol in terms of specific characteristics, which is used to measure the effectiveness of protocol optimization. If the first characteristic difference meets the requirements of the predetermined difference limit, that is, the first characteristic difference is within the required range of the predetermined difference limit, it means that the current dynamic protocol meets the requirements in terms of performance and adaptability. Therefore, the first historical dynamic protocol currently in use will be used as the final dynamic protocol for subsequent threat analysis and processing. Otherwise, the aforementioned comparison of historical dynamic protocols will be continued to find the next historical dynamic protocol that meets the predetermined fitness limit, so as to improve the detection efficiency and protection response speed of unknown threats in complex network environments.
[0035] Furthermore, this application also includes:
[0036] An initial protocol graph of the dynamic protocol is constructed based on the protocol feature set; and a dimension reduction process is performed on the initial protocol graph to obtain the protocol graph.
[0037] Optionally, based on target features extracted from the protocol feature set, such as source IP, destination IP, packet size, arrival time, Client Hello, Server Hello, etc., each target feature is then mapped as a node in a graph. For example, source IP, destination IP, and port number can be considered distinct nodes, with each node representing a key element in the protocol. Edges are then defined based on the relationships between these nodes, such as the connection between communicating parties, the data transmission sequence, and the encryption handshake process. This constructs an initial protocol graph. Each node and edge in this initial protocol graph contains detailed information about the protocol features, reflecting the protocol's transmission patterns and behavior within the network. The initial protocol graph is then subjected to dimensionality reduction. Common dimensionality reduction methods include principal component analysis (PCA), t-distributed stochastic neighbor embedding (t-SNE), or autoencoders. During dimensionality reduction, the correlation between features in the graph needs to be assessed. By calculating the similarity between nodes or the strength of edges, we can understand which features are closely related and which are redundant. Strongly correlated features can be merged, while redundant features can be removed. Then, based on the selected dimensionality reduction method, the high-dimensional feature data in the graph is mapped to a low-dimensional space. For example, PCA is used to project the feature matrix into a new coordinate system, retaining the most information while discarding a small amount of information with low variance. In this process, the nodes and edges in the graph will be converted into a simpler representation, reducing computational complexity. The resulting protocol graph after dimensionality reduction will contain fewer dimensions but retain the core features of the protocol. Each node and edge in the reduced graph represents streamlined protocol information, which can more efficiently represent the structure and behavior of the protocol. Dimensionality reduction may also change the structure of the graph. The edges between some nodes may be reorganized or optimized to better reflect the key behaviors of the protocol, thereby providing strong support for subsequent analysis and optimization.
[0038] Furthermore, the present application provides that the protocol feature set at least includes connection features, metadata features, encryption protocol handshake features and graph node features.
[0039] Optionally, the protocol feature set extracts key information from the reassembled protocol data stream to describe the protocol's behavior and performance within the network. This includes, but is not limited to, connection features, metadata features, cryptographic protocol handshake features, and graph node features. Connection features describe the basic connection information between the two communicating parties, primarily including the source and destination IP addresses (identifying the source and destination), port numbers (indicating the communication port), and protocol types (indicating the network protocol used, such as TCP or UDP). These features help analyze the basic structure of network traffic. Metadata features describe the transmission details of protocol packets, including packet size, arrival time, and payload byte count. These features reflect the scale, temporal distribution, and network load of data transmission, helping to analyze traffic patterns and bandwidth consumption. The TLS encryption protocol handshake features focus on the TLS encryption protocol handshake process, including the Client Hello and Server Hello messages (which are the initial steps in establishing an encrypted connection) and certificate verification (a security mechanism used to verify the identities of the communicating parties). These features are critical to protocol security and communication integrity. Graph node features describe the relationships between features, including node type (indicating the role of each node in the graph, such as data source and data receiver), edge type (describing the connection relationship between nodes, such as data flow direction and communication protocol), and call sequence (describing the order of interactions between nodes). These features enable a structured representation of protocol data flows. This collection of features comprehensively describes all aspects of the protocol, including network connectivity, data transmission, encryption security, and protocol structure, providing a critical basis for protocol analysis, optimization, and threat detection.
[0040] Furthermore, the present application provides a method for retrieving a graph analysis plan to parse the protocol graph to obtain protocol feature values, including:
[0041] The protocol graph is converted into a protocol feature undirected graph according to the graph analysis plan; the degree matrix and the adjacency matrix of the protocol feature undirected graph are obtained respectively; the difference between the degree matrix and the adjacency matrix is taken as the protocol Laplace matrix; the protocol Laplace matrix is decomposed to obtain the protocol eigenvalue.
[0042] Optionally, before processing the protocol graph, invoke the graph parsing plan and use it to convert the graph into an undirected graph. Specifically, the protocol graph's nodes and edges are first analyzed to identify the representative features of each node (such as connection features, metadata features, and cryptographic protocol handshake features), as well as the relationships between nodes (such as data flow, communication sequence, and interdependencies between protocol features). Directed edges in the protocol graph are then converted to undirected edges. Edges between some nodes in the protocol graph may have a direction, indicating the direction of data flow or communication (such as a connection from client to server). To convert the graph into an undirected graph, directionality is ignored; edges only represent the relationship between nodes, regardless of which node is the starting or ending node. For example, a connection from "client" to "server" should be converted into an undirected connection between "client" and "server." After all edges are processed, an undirected protocol feature graph is obtained. The degree matrix and adjacency matrix are then obtained from the undirected protocol feature graph. The degree matrix is a diagonal matrix, where each diagonal element represents the degree of the corresponding node in the graph, that is, the number of edges connected to that node. In a protocol-featured undirected graph, the degree matrix reflects the connectivity of each protocol-featured node. The adjacency matrix is a square matrix, whose elements represent the connectivity between nodes in the graph. If two nodes are connected by an edge, the corresponding element in the matrix is 1; if there is no connection, it is 0. The adjacency matrix can be used to describe direct relationships or communication between nodes. Then, subtracting the degree matrix from the adjacency matrix yields the protocol Laplacian matrix, which represents the strength of connections between nodes in the graph and the overall structure of the network. The protocol Laplacian matrix is then subjected to eigenvalue decomposition. The purpose of eigenvalue decomposition is to decompose the Laplacian matrix into a set of eigenvectors and eigenvalues. The resulting eigenvalues provide information about the graph's structure. The magnitude of the eigenvalues is generally related to properties such as the connectivity and stability of the nodes in the graph. Through these steps, the mathematical representation of the protocol graph (via degree matrix, adjacency matrix, Laplacian matrix, and eigenvalues) is further analyzed and processed, which can provide a deep understanding of the protocol structure, performance, and potential problems, thereby accurately identifying threats and improving the detection efficiency and protection response speed of unknown threats in complex network environments.
[0043] The threat detector is activated to analyze the protocol feature set to obtain a real-time threat type, and a threat defense strategy corresponding to the real-time threat type is called to perform network processing.
[0044] In one embodiment, a threat detector is first activated to perform real-time analysis of the extracted protocol feature set. Using its internal event sequence correlation detection component and graph neural network detection component, the threat detector analyzes key protocol features (such as connection characteristics, encryption characteristics, and traffic patterns) to identify potential security threats. For example, the detector may detect APT attacks, malicious traffic, encrypted malicious traffic, and smart contract vulnerabilities. Once a potential threat is detected, the threat detector instantly classifies it and identifies the specific real-time threat type. Based on the identified threat type, pre-defined threat defense strategies are then invoked to address it. These strategies may include blocking abnormal connections in real time, enabling stronger encryption protocols, restricting access, or reconfiguring network security settings. These measures help to immediately respond to and mitigate threats, ensuring network security and stability. This entire process ensures that the network can automatically identify and respond to various potential security threats during protocol operation, providing a dynamic, real-time security protection mechanism.
[0045] Furthermore, the present application provides activating a threat detector to analyze the protocol feature set to obtain a real-time threat type, including:
[0046] Activate the event sequence association detection component in the threat detector; obtain a first threat type set through dynamic detection by the event sequence association detection component in combination with the protocol feature set; activate the graph neural network detection component in the threat detector; obtain a second threat type set through dynamic detection by the graph neural network detection component in combination with the protocol feature set; the first threat type set and the second threat type set constitute the real-time threat type.
[0047] Preferably, after obtaining the protocol feature set, the event sequence association detection component within the threat detector is activated. This component performs dynamic detection based on the data in the protocol feature set, aiming to identify possible multi-step attack behaviors (such as advanced persistent threat attacks (APTs)). By analyzing the temporal order and interrelationships between events, the event sequence association model can identify multi-stage, highly hidden attack patterns, thereby generating a first threat type set. This first threat type set includes possible attack types, such as staged attacks exploiting protocol vulnerabilities. Furthermore, the graph neural network detection component within the threat detector is activated. This component is capable of processing complex network structures and node relationships, making it suitable for detecting complex network threats such as smart contract vulnerabilities and encrypted malicious traffic. By passing the protocol feature set to the graph neural network detection component, the graph neural network detection component analyzes anomalous relationships within the network based on this feature data and identifies potentially risky attack behaviors. This process can reveal hidden threats that are difficult to detect using conventional detection methods, thereby generating a second threat type set, which includes complex threats such as encrypted malicious traffic or smart contract vulnerabilities. Finally, the first threat type set and the second threat type set are combined to form a real-time threat type, which is used for subsequent targeted network processing to ensure network security.
[0048] The event sequence association detection component within the threat detector can be constructed using deep learning models, Markov models, and association rule learning. For example, the long short-term memory (LSTM) within deep learning models can be used to build the component's infrastructure. Training is then performed using historical threat processing data (including historical protocol features and historical threat types), with steps such as forward propagation, loss calculation, backpropagation, and parameter optimization iteratively performed until the maximum number of iterations is reached or convergence occurs. The graph neural network detection component within the threat detector is constructed using a graph neural network, and training is similar to the previous implementation, using steps such as forward propagation, loss calculation, backpropagation, and parameter optimization.
[0049] In summary, the embodiments of the present application have at least the following technical effects:
[0050] The embodiment of the present application first captures network traffic and obtains a traffic feature set of the network traffic, wherein the traffic feature set includes multiple traffic parameters; then, dynamic reorganization fitness is introduced as an effect evaluation index of protocol dynamic reorganization, and the optimization analysis of protocol dynamic reorganization is performed with the effect evaluation index and the multiple traffic parameters as constraints to obtain a dynamic protocol; then, the protocol data stream of the dynamic protocol is captured, and the protocol data stream is analyzed to obtain a protocol feature set; finally, the threat detector is activated to analyze the protocol feature set to obtain a real-time threat type, and the threat defense strategy corresponding to the real-time threat type is called to perform network processing. These technical effects jointly solve the technical problem that traditional static protocol analysis technology is difficult to adapt to the protocol dynamic reorganization scenario, resulting in delayed threat detection and a high missed reporting rate, and realize real-time accurate threat identification and adaptive defense based on dynamic reorganization optimization, and improve the detection efficiency and protection response speed of unknown threats in complex network environments.
[0051] Example 2, based on the same inventive concept as the network threat detection method under a protocol dynamic reorganization in the above embodiment, such as Figure 2 As shown, the present application provides a network threat detection system under dynamic protocol reorganization, and the system includes: a traffic feature acquisition module 11: capturing network traffic and obtaining a traffic feature set of the network traffic, wherein the traffic feature set includes multiple traffic parameters; an optimization analysis module 12: introducing dynamic reorganization fitness as an effect evaluation index of protocol dynamic reorganization, and performing optimization analysis of protocol dynamic reorganization with the effect evaluation index and the multiple traffic parameters as constraints to obtain a dynamic protocol; a protocol feature acquisition module 13: capturing the protocol data stream of the dynamic protocol, and analyzing the protocol data stream to obtain a protocol feature set; a network processing module 14: activating a threat detector to analyze the protocol feature set to obtain a real-time threat type, and calling a threat defense strategy corresponding to the real-time threat type for network processing.
[0052] Furthermore, the optimization analysis module 12 is further configured to perform the following method:
[0053] The dynamic reorganization fitness refers to the value obtained by weighted calculation of predetermined dimension information of the dynamically reorganized protocol, wherein the predetermined dimension information includes information on dynamic characteristic dimension, security characteristic dimension, energy consumption characteristic dimension and compatibility characteristic dimension.
[0054] Furthermore, the optimization analysis module 12 is further configured to perform the following method:
[0055] A historical protocol detection database is obtained using the multiple traffic parameters as data screening constraints; a first historical data group is obtained from the historical protocol detection database, wherein the first historical data group includes first network threat detection data under a first historical dynamic protocol; the first network threat detection data is reorganized and evaluated using the effect evaluation index as a reorganization evaluation constraint to obtain a first historical fitness; if the first historical fitness reaches a predetermined fitness limit, the first historical dynamic protocol is used as the dynamic protocol.
[0056] Furthermore, the optimization analysis module 12 is further configured to perform the following method:
[0057] Based on the dynamic reorganization fitness, any characteristic indicator of any dimension is obtained; any traffic feature group corresponding to the arbitrary characteristic indicator is matched in the traffic feature database; the first reorganized traffic feature set in the first network threat detection data is obtained, and the first reorganized traffic feature set is traversed and analyzed with the arbitrary traffic feature group to obtain any feedback coefficient of the arbitrary characteristic indicator; the first historical fitness of the first historical dynamic protocol is calculated based on the arbitrary feedback coefficient.
[0058] Furthermore, the optimization analysis module 12 is further configured to perform the following method:
[0059] The protocol feature set is screened to obtain a target feature; a protocol graph of the dynamic protocol is constructed based on the target feature; a graph parsing plan is called to parse the protocol graph to obtain a protocol feature value; a first historical protocol feature value of the first historical dynamic protocol is obtained; the protocol feature value is compared with the first historical protocol feature value to obtain a first feature difference; if the first feature difference reaches a predetermined difference limit, the first historical dynamic protocol is used as the dynamic protocol.
[0060] Furthermore, the optimization analysis module 12 is further configured to perform the following method:
[0061] An initial protocol graph of the dynamic protocol is constructed based on the protocol feature set; and a dimension reduction process is performed on the initial protocol graph to obtain the protocol graph.
[0062] Furthermore, the optimization analysis module 12 is further configured to perform the following method:
[0063] The protocol feature set includes at least connection features, metadata features, encryption protocol handshake features and graph node features.
[0064] Furthermore, the optimization analysis module 12 is further configured to perform the following method:
[0065] According to the graph analysis plan, the protocol graph is converted into a protocol feature undirected graph; the degree matrix and the adjacency matrix of the protocol feature undirected graph are respectively obtained; the difference between the degree matrix and the adjacency matrix is taken as the protocol Laplace matrix; the protocol Laplace matrix is decomposed to obtain the protocol eigenvalue.
[0066] Furthermore, the network processing module 14 is further configured to execute the following method:
[0067] Activate the event sequence association detection component in the threat detector; obtain a first threat type set through dynamic detection by the event sequence association detection component in combination with the protocol feature set; activate the graph neural network detection component in the threat detector; obtain a second threat type set through dynamic detection by the graph neural network detection component in combination with the protocol feature set; the first threat type set and the second threat type set constitute the real-time threat type.
[0068] It should be noted that the order in which the embodiments of the present application are presented is for illustrative purposes only and does not necessarily represent the superiority or inferiority of the embodiments. Furthermore, the foregoing descriptions of specific embodiments of this specification are provided. The processes depicted in the accompanying drawings do not necessarily require the specific order or sequential sequence shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0069] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.
[0070] This specification and drawings are merely illustrative of the present application and are intended to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Obviously, those skilled in the art may make various modifications and variations to this application without departing from the scope of this application. Thus, this application is intended to include such modifications and variations as fall within the scope of this application and its equivalents.
Claims
1. A network threat detection method under dynamic protocol reorganization, characterized in that: include: Capturing network traffic and obtaining a traffic feature set of the network traffic, wherein the traffic feature set includes a plurality of traffic parameters; Introducing dynamic reorganization fitness as an effect evaluation index of the protocol dynamic reorganization, and performing optimization analysis of the protocol dynamic reorganization with the effect evaluation index and the multiple traffic parameters as constraints to obtain a dynamic protocol; Capturing a protocol data stream of the dynamic protocol and analyzing the protocol data stream to obtain a protocol feature set; activating a threat detector to analyze the protocol feature set to obtain a real-time threat type, and invoking a threat defense strategy corresponding to the real-time threat type to perform network processing; The dynamic reorganization fitness is introduced as an effect evaluation index of the dynamic reorganization of the protocol, and the optimization analysis of the dynamic reorganization of the protocol is performed with the effect evaluation index and the multiple traffic parameters as constraints to obtain a dynamic protocol, including: Acquiring a historical protocol detection database using the multiple traffic parameters as data screening constraints; Obtaining a first historical data group in the historical protocol detection database, wherein the first historical data group includes first network threat detection data under a first historical dynamic protocol; Reorganize and evaluate the first network threat detection data using the effect evaluation index as a reorganization evaluation constraint to obtain a first historical fitness; If the first historical fitness reaches a predetermined fitness limit, using the first historical dynamic protocol as the dynamic protocol; The first network threat detection data is reorganized and evaluated using the effect evaluation index as a reorganization evaluation constraint to obtain a first historical fitness, including: Obtaining any characteristic index of any dimension based on the dynamic reorganization fitness; Match any traffic feature group corresponding to any feature indicator in a traffic feature database; Obtaining a first reorganized traffic feature set in the first network threat detection data, and performing a traversal analysis on the first reorganized traffic feature set using the arbitrary traffic feature group to obtain an arbitrary feedback coefficient of the arbitrary feature indicator; Calculating the first historical fitness of the first historical dynamic protocol based on the arbitrary feedback coefficient; Among them, also include: Screening the protocol feature set to obtain target features; Constructing a protocol graph of the dynamic protocol based on the target feature; Retrieving a graph analysis plan to analyze the protocol graph and obtain a protocol characteristic value; Obtaining a first historical protocol characteristic value of the first historical dynamic protocol; Comparing the protocol characteristic value with the first historical protocol characteristic value to obtain a first characteristic difference; If the first characteristic difference reaches a predetermined difference limit, using the first historical dynamic protocol as the dynamic protocol; The activating threat detector to analyze the protocol feature set to obtain a real-time threat type includes: activating an event sequence correlation detection component in the threat detector; Dynamically detecting a first threat type set by combining the event sequence association detection component with the protocol feature set; activating a graph neural network detection component in the threat detector; Dynamically detecting a second threat type set by combining the graph neural network detection component with the protocol feature set; The first threat type set and the second threat type set constitute the real-time threat type.
2. The network threat detection method under dynamic protocol reconfiguration according to claim 1, characterized in that: The dynamic reorganization fitness refers to the value obtained by weighted calculation of predetermined dimensional information of the dynamically reorganized protocol, wherein the predetermined dimensional information includes information on dynamic characteristic dimension, security characteristic dimension, energy consumption characteristic dimension and compatibility characteristic dimension.
3. The network threat detection method under dynamic protocol reorganization according to claim 1, characterized in that: Also includes: Constructing an initial protocol graph of the dynamic protocol based on the protocol feature set; Performing dimensionality reduction processing on the initial protocol graph to obtain the protocol graph.
4. The network threat detection method under dynamic protocol reconfiguration according to claim 1, characterized in that: The protocol feature set includes at least connection features, metadata features, encryption protocol handshake features and graph node features.
5. The network threat detection method under dynamic protocol reconfiguration according to claim 1, characterized in that: Retrieve the graph analysis plan to analyze the protocol graph to obtain protocol feature values, including: Converting the protocol graph into a protocol feature undirected graph according to the graph parsing plan; Obtaining the degree matrix and adjacency matrix of the protocol feature undirected graph respectively; Taking the difference between the degree matrix and the adjacency matrix as the agreement Laplace matrix; Decomposing the protocol Laplace matrix to obtain the protocol eigenvalues.
6. A network threat detection system under dynamic protocol reconfiguration, characterized in that: The system is used to execute a network threat detection method under dynamic protocol reconfiguration according to any one of claims 1 to 5, comprising: Traffic feature acquisition module: captures network traffic and acquires a traffic feature set of the network traffic, wherein the traffic feature set includes multiple traffic parameters; Optimization analysis module: introduces dynamic reorganization fitness as an effect evaluation index of protocol dynamic reorganization, and performs optimization analysis of protocol dynamic reorganization based on the effect evaluation index and the multiple traffic parameters as constraints to obtain a dynamic protocol; Protocol feature acquisition module: captures the protocol data stream of the dynamic protocol and analyzes the protocol data stream to obtain a protocol feature set; Network processing module: activates the threat detector to analyze the protocol feature set to obtain a real-time threat type, and calls the threat defense strategy corresponding to the real-time threat type to perform network processing.
Citation Information
Patent Citations
Real-time flow analysis method and system for network routing
CN119697094A
Network security penetration detection method and system based on artificial intelligence
CN120050079A