Network security protection method and system based on flow analysis
The method and system dynamically analyze and adjust protocols to identify and block attacks by categorizing multiple protocol interactions, enhancing detection and response to protocol-masking attacks, thereby improving network security.
Patent Information
- Application Number
- CN202510803571.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-17
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-06-17
AI Technical Summary
Existing network security protection technologies based on traffic analysis cannot effectively identify camouflage attacks under multi-protocol interaction, especially when malicious traffic is transmitted through hybrid protocols, and the cross-protocol traffic identification mechanism cannot be dynamically regulated, resulting in the attack not being discovered and blocked in time.
Through packet-by-packet access processing, the protocol identification fields and port information of the data packet are extracted, the multi-protocol interaction traffic is judged, the interaction behavior characteristic information is obtained, the degree of interaction behavior change between protocols is evaluated, and the cross-protocol traffic identification mechanism is dynamically regulated based on the evaluation results, including generating interaction change coefficients and structural complex indexes, to realize dynamic identification and protection of multi-protocol interactions.
It significantly improves the ability to identify multi-protocol interactive camouflage attacks, realizes fine-grained dynamic monitoring and intelligent protection of network transmission traffic, enhances network security response and adaptability, and reduces false alarm rates.
Smart Images

Figure CN120321044A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security protection, and particularly to a network security protection method and system based on traffic analysis. Background Art
[0002] Network security protection refers to the means of using technical measures, management measures, and strategies to ensure that computer networks and their data are protected from unauthorized access, destruction, leakage, or tampering, and to ensure the reliability, integrity, and security of the network. Traditional network security protection methods mainly rely on firewalls, intrusion detection systems (IDS), and intrusion prevention systems (IPS), etc. They usually detect known attack behaviors based on rules, signatures, or blacklists. However, with the continuous evolution and transformation of network attack means, traditional methods are often difficult to cope with new and unknown attacks. Therefore, network security protection based on traffic analysis has emerged. This is a technology that discovers abnormal behaviors and identifies potential threats by analyzing the characteristics and patterns of network traffic in real time. Different from traditional signature-based protection methods, the protection method based on traffic analysis can capture traffic that does not conform to normal network behaviors in a timely manner by observing the flow of data packets and the changing rules of traffic, and then identify potential attack or intrusion behaviors. This method does not rely on known attack patterns, but effectively discovers new types of attacks and unknown threats through deep learning and behavior analysis of network traffic. Network security protection based on traffic analysis not only enhances the response speed and adaptability of network security, but also reduces the false alarm rate and significantly improves the protection effect, which is of great significance for combating the increasingly complex network security challenges currently.
[0003] Existing network security protection technologies based on traffic analysis mainly identify abnormal traffic and potential network threats by monitoring and analyzing the traffic in the network. The core of this technology lies in analyzing the behavior patterns of the network by capturing data packets, extracting traffic characteristics, and identifying traffic patterns. Specifically, this technology usually includes multiple steps: First, network traffic data is captured in real time by a collection device, and this data includes information such as the size of the data packet, transmission time, flow direction, and protocol type. Next, through traffic feature extraction and data preprocessing, the captured data is converted into a format suitable for analysis. Then, statistical analysis, machine learning algorithms, or deep learning models are used to analyze the traffic characteristics to identify the differences between normal traffic and abnormal traffic. Abnormal traffic usually shows as sharp fluctuations in traffic, frequent connection requests, or behaviors that do not conform to normal communication patterns, all of which may be manifestations of potential attacks. Finally, through traffic analysis-based strategies, the system can detect and block these abnormal behaviors in real time, such as by enabling firewall rules, blocking malicious traffic, or triggering alarm mechanisms. Through the collaborative work of these steps, network security protection based on traffic analysis can provide effective defense against unknown attacks and complex threats.
[0004] The prior art has the following deficiencies: When an attacker launches an attack by disguising protocol packets as normal traffic, especially by transmitting malicious traffic through multiple protocols simultaneously (such as the combination of HTTP and DNS protocols), existing network security protection technologies based on traffic analysis usually can only perform traffic analysis at a single protocol level and cannot comprehensively analyze the interaction behavior between protocols. In this case, the attacker uses the protocol mixing method to hide malicious traffic. Since the protection system fails to fully identify the interaction patterns between different protocols, the traffic between protocols cannot be effectively captured. The prior art cannot dynamically adjust the cross-protocol traffic recognition mechanism according to the degree of change in the interaction behavior between protocols in the case of multi-protocol interaction traffic. The prior art relies on the analysis of the behavior patterns of a single protocol and lacks comprehensive analysis of the interaction patterns of different protocols, thus unable to identify the disguised attacks carried out by multiple protocols in cooperation. Eventually, malicious traffic may be transmitted between different protocols and not be captured by the protection mechanism at a single protocol layer, resulting in the system failing to detect and prevent these disguised attacks in a timely manner, and further possibly leading to more complex attack methods, such as reflection attacks, data leakage, remote code execution, etc., seriously affecting network security.
[0005] The above information disclosed in the background art section is only used to enhance the understanding of the background of the present disclosure, and thus it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention
[0006] The object of the present invention is to provide a network security protection method and system based on traffic analysis to solve the problems in the above background art.
[0007] To achieve the above object, the present invention provides the following technical solution: A network security protection method based on traffic analysis, specifically including the following steps: Perform per-packet access processing on all traffic transmitted through the network, extract the protocol identification field, port information, and transmission direction information of each data packet, and complete the classification of the protocol types of each data packet; Based on the protocol type classification result, determine whether there is a situation of multi-protocol interaction traffic. If there is such a situation, determine all the protocols participating in the interaction and classify them into a protocol interaction identification set; Obtain the interaction behavior characteristic information of each protocol in the protocol interaction identification set, and perform analysis after obtaining it to evaluate the degree of change in the interaction behavior between each protocol in the protocol interaction identification set; According to the evaluation result, perform dynamic adjustment on the cross-protocol traffic recognition mechanism; Execute corresponding protection actions based on the recognition results after dynamic regulation, while recording the recognition results and the corresponding interactive behavior feature information, and updating the evaluation conditions and regulation strategies based on the recorded content.
[0008] Preferably, based on the protocol type classification results, determine whether there is a situation of multi-protocol interactive traffic. If such a situation exists, determine all the protocols participating in the interaction and classify them into a protocol interaction identification set. Specifically: Based on the protocol type classification results of each data packet, within a preset continuous time window, count the network traffic after protocol type classification. By analyzing the arrangement of data packets corresponding to all protocols within the preset continuous time window in chronological order, determine whether there is a situation of multi-protocol interactive traffic; the situation of multi-protocol interactive traffic refers to the situation where data packets of several protocols appear alternately within the preset continuous time window. If it is determined that there is a situation of multi-protocol interactive traffic, determine the protocol types corresponding to all alternately appearing data packets within the preset continuous time window as the protocols participating in the interaction, and construct the determined protocol combination into a protocol interaction identification set.
[0009] Preferably, obtain the interactive behavior feature information of each protocol in the protocol interaction identification set, and analyze it after obtaining, to evaluate the degree of change in the interactive behavior between each protocol in the protocol interaction identification set. Specifically, it includes the following steps: Obtain the interactive behavior feature information of each protocol in the protocol interaction identification set, and perform preprocessing after obtaining. Extract the protocol payload fluctuation feature information and protocol structure complexity feature information from the preprocessed interactive behavior feature information, and analyze them after extraction to generate an interactive payload difference coefficient and a structure complexity index respectively. Based on the generated interactive payload difference coefficient and structure complexity index, generate an interactive change coefficient through weighted summation. Determine a preset threshold interval for the interactive change coefficient, and compare it with the generated interactive change coefficient after determination. According to the comparison result, evaluate the degree of change in the interactive behavior between each protocol in the protocol interaction identification set.
[0010] Preferably, the acquisition logic of the interactive payload difference coefficient is as follows: Extract the protocol payload fluctuation feature information from the preprocessed interactive behavior feature information, specifically including the sum of the sizes of all data packets within each protocol in the protocol interaction identification set, the number of data packets, and the difference between the maximum data packet size and the minimum data packet size, and respectively label them as 、 and , represents the The sum of the sizes of all data packets within a protocol, represents the number of data packets within the th protocol in the protocol interaction identification set, represents the difference between the maximum and minimum data packet sizes within the th protocol in the protocol interaction identification set, , where [ID] is a positive integer; Calculate the weighted load fluctuation factor for each protocol in the protocol interaction identification set. The specific calculation formula is as follows: ; In the formula, is the weighted load fluctuation factor for the th protocol in the protocol interaction identification set; Take the logarithm of the weighted load fluctuation factor for each protocol in the protocol interaction identification set to form a logarithmic load index, according to the formula: ; In the formula, is the logarithmic load index for the th protocol in the protocol interaction identification set; Calculate the interaction load difference coefficient. The specific calculation formula is as follows: ; In the formula, is the interaction load difference coefficient.
[0011] Preferably, the acquisition logic of the structure complexity index is as follows: Extract protocol structure complexity feature information from the preprocessed interaction behavior feature information, specifically including the number of types of all data packet header fields, the control field ratio, and the header field information entropy value within each protocol in the protocol interaction identification set, and label them respectively as , and , represents the number of types of all data packet header fields within the th protocol in the protocol interaction identification set, represents the control field ratio within the th protocol in the protocol interaction identification set, represents the header field information entropy value within the th protocol in the protocol interaction identification set, , where [ID] is a positive integer; Calculate the structure complexity factor for each protocol in the protocol interaction identification set. The specific calculation formula is as follows: ; In the formula, is the structural complexity factor of the th protocol in the protocol interaction identification set; Calculate the structural complexity index, and the specific calculation formula is as follows: ; In the formula, is the structural complexity index.
[0012] Preferably, based on the generated interaction load difference coefficient and the structural complexity index , generate an interaction change coefficient through weighted summation, and the specific calculation formula is as follows: ; In the formula, is the interaction change coefficient, and are respectively non-zero weight coefficients of the interaction load difference coefficient and the structural complexity index , and .
[0013] Preferably, determine a preset interaction change coefficient threshold interval , and after determination, compare it with the generated interaction change coefficient , and evaluate the change degree of the interaction behavior between each protocol in the protocol interaction identification set according to the comparison result. The specific comparison and analysis are as follows: If , the change degree of the interaction behavior between each protocol in the protocol interaction identification set is a normal change degree; If , the change degree of the interaction behavior between each protocol in the protocol interaction identification set is a significant change degree; If , the change degree of the interaction behavior between each protocol in the protocol interaction identification set is a drastic change degree.
[0014] Preferably, according to the evaluation result, perform dynamic regulation on the cross-protocol traffic identification mechanism, specifically: If the evaluation result is a normal change degree, maintain the current operating parameters of the cross-protocol traffic identification mechanism, and continue to use the existing protocol identification rules and protection strategies; If the evaluation result is a significant change degree, increase the sensitivity of traffic analysis, adjust the monitoring window of the data traffic between protocols, and enhance the extraction frequency of the interaction behavior characteristics of the protocols to identify potential protocol collaborative attacks and disguises; If the evaluation result is a drastic change level, adjust the core parameters of the cross - protocol traffic recognition mechanism, enable the advanced protocol analysis algorithm, strengthen the traffic filtering mechanism, block potential malicious protocol traffic, and trigger the real - time threat recognition function to isolate suspicious traffic.
[0015] Preferably, a network security protection system based on traffic analysis includes a protocol identification and classification module, an interactive protocol calibration module, an interactive behavior evaluation module, an identification strategy regulation module, and a protection closed - loop optimization module; The protocol identification and classification module performs per - packet access processing on all traffic transmitted through the network, extracts the protocol identification field, port information, and transmission direction information of each data packet, and completes the classification of the protocol type of each data packet. The interactive protocol calibration module, based on the protocol type classification result, determines whether there is a situation of multi - protocol interactive traffic. If this situation exists, it determines all the protocols participating in the interaction and classifies them into a protocol interaction identification set. The interactive behavior evaluation module obtains the interactive behavior characteristic information of each protocol in the protocol interaction identification set, and analyzes it after obtaining it to evaluate the change degree of the interactive behavior between each protocol in the protocol interaction identification set. The identification strategy regulation module dynamically regulates the cross - protocol traffic recognition mechanism according to the evaluation result. The protection closed - loop optimization module performs corresponding protection actions based on the identification result after dynamic regulation, records the identification result and the corresponding interactive behavior characteristic information at the same time, and updates the evaluation conditions and regulation strategies based on the recorded content.
[0016] In the above technical solution, the technical effects and advantages provided by the present invention are: 1. The present invention can achieve dynamic recognition and judgment of the interactive behavior between multiple protocols in network transmission traffic for the complex scenario of multi - protocol interactive traffic. By introducing a continuous time window to capture the pattern of staggered protocols, it avoids the recognition blind area caused by only analyzing the single - protocol behavior pattern in the traditional method, and significantly improves the recognition ability of protocol hybrid camouflage attacks. Especially when facing the fusion attack behavior of protocols such as HTTP and DNS, it can actively perceive and construct a protocol interaction identification set, thus providing a basic guarantee for subsequent behavior characteristic analysis and identification strategy adjustment.
[0017] 2. The present invention introduces two quantitative indicators, namely the interaction load difference coefficient and the structural complexity index, and constructs an interaction change coefficient through mathematical modeling to accurately evaluate the degree of change in the interaction behavior between protocols. This mechanism breaks through the traditional identification method based on static rule judgment and realizes fine-grained dynamic monitoring of protocol interaction patterns through a data-driven approach. The application of mathematical means such as weighted modeling, exponential transformation, and logarithmic analysis not only improves the accuracy and controllability of the identification results but also constructs a set of quantifiable and adjustable dynamic evaluation mechanisms, providing a reliable basis for the decision-making of subsequent intelligent protection strategies.
[0018] 3. The present invention constructs a complete closed-loop process from identification, evaluation to dynamic regulation and then to optimization learning. Under different evaluation results, the cross-protocol traffic identification mechanism is hierarchically regulated according to the degree of interaction change, effectively achieving a balance between protection accuracy and system resource consumption. At the same time, after the protection action is executed, the identification results and interaction behavior characteristics are recorded and the strategy is updated, with the ability of continuous evolution and self-adaptation. This closed-loop optimization mechanism not only improves the response ability and adaptability of the system in the face of complex traffic attacks but also provides technical support for the intelligent and modular evolution of network security protection systems, having significant practical value and promotion prospects. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments recorded in the present invention, and those of ordinary skill in the art can also obtain other drawings based on these drawings.
[0020] Figure 1 It is a schematic flowchart of a network security protection method and system based on traffic analysis according to the present invention.
[0021] Figure 2 It is a schematic diagram of the modules of a network security protection method and system based on traffic analysis according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0022] Now, the exemplary embodiments will be described more fully with reference to the accompanying drawings. However, the exemplary embodiments can be implemented in various forms and should not be construed as limited to the examples set forth herein; rather, these exemplary embodiments are provided so that the present disclosure will be more complete and comprehensive, and will fully convey the concept of the exemplary embodiments to those skilled in the art.
[0023] The present invention provides a network security protection method based on traffic analysis as Figure 1 shown, specifically including the following steps: Perform per-packet access processing on all traffic transmitted over the network, extract the protocol identification field, port information, and transmission direction information of each data packet, and complete the classification of the protocol type of each data packet; The per-packet access processing of all traffic transmitted over the network can be achieved through software. Specifically, based on the listening mechanism of the data link layer or network layer, the raw socket or packet capture engine can be used to complete the packet capture. For example, in the Linux environment, the libpcap interface can be called, and in the Windows system, the Npcap driver can be used. These packet capture tools can monitor the specified network interface in real time and capture all packets transmitted thereon. The software can set capture filters to screen the required traffic by network card, protocol, port, or flow direction. During the capture process, all packets will enter the processing flow in the order of their arrival, without being discarded or rearranged, and the complete meta-information, such as timestamp, data length, and source and destination information, will be retained, thus realizing complete, sequential, and continuous per-packet access.
[0024] After the traffic access is completed, the protocol fields of each data packet can be parsed through software, and then the protocol identification field, port information, and transmission direction information can be extracted. The specific implementation methods include parsing the packet structure layer by layer. Starting from the link layer, the EtherType field is read to identify the network layer protocol type, such as IPv4 or IPv6, and then the Protocol field in the IP packet is read at the transport layer to determine whether it is a protocol type such as TCP, UDP, ICMP, etc. At the transport layer, the TCP or UDP header fields are further parsed to extract the source port and destination port, and combined with the predefined port mapping rules, the application layer protocol, such as HTTP, DNS, SMTP, etc., is identified. The transmission direction information can be judged according to the relationship between the source IP and the destination IP relative to the local address. After the above information extraction is completed, the data packets are classified into the corresponding protocol categories according to the protocol mapping table, forming a traffic structure classified by protocol.
[0025] The process of per-packet access to all traffic transmitted over the network and extraction of protocol-related fields is the prerequisite for realizing protocol interaction recognition and dynamic protection regulation. In network communication, the protocol stack is complex and the protocol types are diverse. If the protocol structure and interaction path of each data packet cannot be obtained in real time, a complete traffic behavior feature model cannot be constructed. In the scenario of multi-protocol cross-transmission or malicious traffic disguise, only by completely extracting the protocol information and transmission direction of the data packets can the starting point and path of cross-protocol association behavior be identified. This process ensures the context integrity of data analysis and provides structured and accurate raw data support for subsequent protocol interaction behavior evaluation and protection strategy execution, which is the key starting point for building a complete dynamic protection system based on traffic analysis.
[0026] Based on the protocol type classification result, determine whether there is a situation of multi-protocol interaction traffic. If such a situation exists, determine all the protocols participating in the interaction and classify them into the protocol interaction identification set. In this embodiment, based on the protocol type classification result, determine whether there is a situation of multi-protocol interaction traffic. If such a situation exists, determine all the protocols participating in the interaction and classify them into the protocol interaction identification set, specifically as follows: Based on the protocol type classification result of each data packet, within a preset continuous time window, count the network traffic after protocol type classification. By analyzing the arrangement of data packets corresponding to all protocols within the preset continuous time window in chronological order, determine whether there is a situation of multi-protocol interaction traffic; the situation of multi-protocol interaction traffic refers to the situation where data packets of several protocols appear alternately within the preset continuous time window. It is possible to perform chronological statistical analysis on the data packets after protocol type classification within a preset continuous time window through software. In implementation, the software first continuously marks the time stamps and maps the protocol types of each real-time accessed data packet according to a fixed-length time window, and writes the data packets into the cache structure in chronological order. At the end of each time window, the software traverses the data packet sequence within the window, counts the distribution positions of each protocol on the time axis, and constructs a protocol-time distribution map. Subsequently, by scanning the chronological arrangement of data packets between different protocols, detect whether there is a phenomenon of data packets of multiple protocols interspersed and continuously interleaved. If it is recognized that at least two protocols appear alternately in time sequence within a certain time period, it can be determined that there is multi-protocol interaction traffic in this time window, and the protocol types involved in this interleaved distribution are extracted for subsequent processing.
[0027] The reason for this is that multi-protocol interaction is one of the common camouflage techniques in current complex network attacks. Attackers often split and embed malicious payloads into multiple protocols and send them alternately, taking advantage of the hierarchical isolation characteristics of protocol detection systems to avoid the monitoring capabilities of single-protocol analysis models. Traditional analysis methods based on single-protocol behavior characteristics are difficult to detect such cross-interleaved patterns. By analyzing the arrangement order of protocol types of data packets within a time window, the timing characteristics of "protocol interleaving" can be accurately identified, and this characteristic itself is an important behavior characteristic of multi-protocol collaborative communication. Timely identification of this alternating pattern helps to locate potential cross-protocol communication relationships, thereby providing structural inputs for subsequent feature extraction, threat modeling, and protection strategy selection, and improving the detection ability and response accuracy for covert attacks.
[0028] If it is determined that there is multi - protocol interaction traffic, determine the protocol types corresponding to all the alternately - appearing data packets within the preset continuous time window as the protocols participating in the interaction, and construct the determined protocol combination into a protocol interaction identification set.
[0029] In the case where it is determined that there is multi - protocol interaction traffic, the protocol types corresponding to all the alternately - appearing data packets within the preset continuous time window can be further extracted by software and combined to construct a protocol interaction identification set. In implementation, after the alternating detection and confirmation are completed, the software will perform a retrospective analysis on the data packets within the time window, traverse each data packet in the alternating segment in chronological order, and record its protocol type in a protocol recognition set structure. This set structure usually has a de - duplication mechanism to avoid double - counting the same protocol type. After the traversal is completed, what remains in the set is the protocol types involved in all the alternately - appearing data packets within this time window. The software then logically associates this protocol type set as a protocol interaction identification set and stores it as the protocol interaction instance corresponding to this window for subsequent extraction of interaction behavior characteristics and risk assessment processing.
[0030] The purpose of doing this is to accurately capture the potential relationship patterns formed by the collaborative communication between protocols. In network attacks, attackers often complete the construction of communication links or the distribution of tasks through multiple protocols combined. For example, they use the HTTP protocol to issue commands and then use the DNS channel to send back data. If the participation relationships of these protocols cannot be identified and combined within the time dimension, the analysis system will only process the traffic isolatedly at the protocol level and cannot establish the behavior chain between protocols. By constructing a protocol interaction identification set, a perception basis for the collaborative activities of multiple protocols can be established at the detection layer, enabling subsequent behavior analysis to shift from a single - protocol scenario to an overall perception and tracking of cross - protocol attack behaviors, thereby enhancing the ability to identify complex attack means and effectively supporting the activation of the dynamic protection decision - making mechanism and the matching of refined strategies.
[0031] Obtain the interaction behavior characteristic information of each protocol in the protocol interaction identification set, and analyze it after obtaining, to evaluate the degree of change in the interaction behaviors between the protocols in the protocol interaction identification set; In this embodiment, obtaining the interaction behavior characteristic information of each protocol in the protocol interaction identification set, and analyzing it after obtaining, to evaluate the degree of change in the interaction behaviors between the protocols in the protocol interaction identification set specifically includes the following steps: Obtain the interaction behavior characteristic information of each protocol in the protocol interaction identification set, and perform pre - processing after obtaining; To obtain the interaction behavior feature information of each protocol in the protocol interaction identifier set, it can be achieved by parsing each network packet marked as the protocol interaction identifier set within a continuous time window. Specifically, a traffic capture tool is used to intercept network traffic in real time, and in the traffic analysis module, according to the protocol type of each packet, the content of its protocol header fields, field structure configuration, field value distribution, occurrence of control fields, etc. are extracted respectively, and a corresponding feature vector set is constructed for each protocol. These sets include, but are not limited to, structured data such as the number of field types, field hierarchy, control field ratio, field content distribution density, typical field patterns, etc. Through the protocol classification and indexing mechanism, they are respectively assigned to the feature sets corresponding to each protocol in the protocol interaction identifier set, so as to obtain the interaction behavior feature information of each protocol. This process can be achieved by a traffic analysis tool in cooperation with a feature extraction algorithm, such as regular-based protocol field extraction and statistical coding, to ensure that the obtained results have structural and quantifiable features.
[0032] The main purpose of preprocessing the obtained interaction behavior feature information is to eliminate noise fields, standardize feature dimensions, and improve the computational stability of subsequent analysis and the accuracy of parameter generation. Due to differences in field structures between protocols, the originally obtained feature information may have problems such as inconsistent data formats, inconsistent field encoding methods, missing fields, or outliers. Therefore, preprocessing operations must be performed. Preprocessing includes field normalization (for example, using Z-score standardization or Min-Max scaling to compress the feature of each field to the same scale interval), outlier removal (for example, removing extreme values based on the threshold judgment of the median and interquartile range), missing field filling (interpolation can be performed using the protocol average field value or protocol default structure template), and redundant field filtering (removing fields that appear repeatedly in multiple protocols and have no discriminative ability). Through the above methods, the feature information of each protocol can be converted into a vector format with consistent structure, stable values, and suitable for subsequent modeling, providing an accurate basis for evaluating the degree of change in interaction behavior.
[0033] Extract the protocol payload fluctuation feature information and protocol structure complexity feature information from the preprocessed interaction behavior feature information, and perform analysis after extraction to generate the interaction payload difference coefficient and the structure complexity index respectively; Extract the protocol payload fluctuation feature information and protocol structure complexity feature information from the preprocessed interactive behavior feature information, which can be implemented in software by constructing a feature parsing model and a multi-dimensional statistical analysis process. Specifically, the software first calls the payload class and structure class field extraction module based on the preprocessed feature vectors corresponding to each protocol, focusing on the field dimensions related to data transmission payload and protocol structure complexity respectively. For the protocol payload fluctuation feature information, the software extracts and calculates the total packet size, the number of packets, and the difference between the maximum and minimum packet sizes of each protocol within the interactive time window, and constructs a three-dimensional feature group representing the payload fluctuation. For the protocol structure complexity feature information, the software extracts the number of protocol header field types, the ratio of control fields, and the entropy value based on the field distribution from the preprocessed vectors to measure the complexity of the protocol message structure in terms of functionality and randomness. The entire extraction process is completed based on field label index matching and rule-driven extraction, and all extraction results will be stored in a structured protocol information feature set as the basic data support for subsequent parameter calculation and interactive behavior evaluation.
[0034] Based on the generated interactive payload difference coefficient and structure complexity index, generate an interactive change coefficient through weighted summation; Determine the pre-set threshold interval of the interactive change coefficient, and compare it with the generated interactive change coefficient after determination, and evaluate the change degree of the interactive behavior between each protocol in the protocol interaction identification set according to the comparison result.
[0035] Determining the pre-set threshold interval of the interactive change coefficient can be achieved by the software executing historical modeling analysis and policy rule generation. Specifically, in the offline training stage, the software analyzes a large amount of labeled historical network traffic data, classifies these data according to whether there are multi-protocol interaction abnormal behaviors, and conducts clustering statistical analysis on the interactive change coefficients (generated by weighting the interactive payload difference coefficient and the structure complexity index) calculated in each class of samples. The software uses clustering algorithms such as K-means or Gaussian mixture model to identify the numerical distribution characteristics of the interactive change coefficients in different interactive states, and then sets the numerical intervals reflecting the boundaries of three behaviors: normal interaction, suspicious interaction, and abnormal interaction, and saves these three threshold intervals as policy configuration parameters. During the actual operation process, the software automatically loads these threshold intervals according to the predefined rules and uses them as the judgment benchmark for interactive behavior evaluation, so as to ensure that the evaluation mechanism has dynamic adaptability and discrimination accuracy. This process can update the historical samples in real time according to the operating environment and recalculate the threshold interval periodically to optimize the recognition effect.
[0036] In this embodiment, the acquisition logic of the interactive payload difference coefficient is as follows: Extract the protocol payload fluctuation feature information from the preprocessed interactive behavior feature information, specifically including the sum of the sizes of all data packets, the number of data packets, and the difference between the maximum and minimum data packet sizes within each protocol in the protocol interaction identification set, and label them respectively as 、 and , represents the sum of the sizes of all data packets within the -th protocol in the protocol interaction identification set, represents the number of data packets within the -th protocol in the protocol interaction identification set, represents the difference between the maximum and minimum data packet sizes within the -th protocol in the protocol interaction identification set, , is a positive integer; For the data such as the sum of the sizes of all data packets, the number of data packets, and the difference between the maximum and minimum data packet sizes within each protocol in the protocol interaction identification set, after real-time capturing of network traffic and protocol classification, they can be obtained through statistical analysis by protocol dimension in the data processing stage. The specific implementation method is as follows: After completing the per-packet access processing and protocol type classification, the software system can traverse the data packet set corresponding to each protocol, read and accumulate the effective payload length field of each data packet to obtain the sum of the sizes of all data packets within the protocol; at the same time, count the data packets that appear in the protocol during the traversal to obtain the number of data packets; for the difference between the maximum and minimum data packets, maintain a status record of the current maximum and minimum data packet sizes during the traversal, and calculate their difference at the end of the traversal. The above three types of data can be dynamically updated and cached in memory through software logic without manual intervention, and can reflect the data carrying characteristics of the protocol in the current interaction window in real time. Among them, the sum of the data packet sizes is used to reflect the total data carrying capacity of the protocol, the number of data packets reveals its interaction frequency in communication, and the difference between the maximum and minimum data packet sizes reflects the fluctuation range of the protocol transmission load. These three types of data together constitute the basic input for evaluating the complexity and stability of protocol behavior.
[0037] Calculate the weighted load fluctuation factor for each protocol in the protocol interaction identification set. The specific calculation formula is as follows: ; In the formula, is the weighted load fluctuation factor of the -th protocol in the protocol interaction identification set; In the calculation of this weighted load fluctuation factor, use The combined form aims to comprehensively evaluate the traffic load level and fluctuation characteristics of each protocol in multi - protocol interactions, enhancing the ability to identify potential abnormal interaction behaviors. Among them, represents the average packet size of the th protocol within the interaction window, which is used to measure the basic load intensity of the protocol. If this value is abnormally large or small, it may indicate that the protocol undertakes an atypical data transmission task; Then, the degree of fluctuation of the packet size within the protocol is introduced. is the difference between the maximum and minimum packet sizes. This item controls the influence of outliers through logarithmic transformation, improving the stability and discrimination of the overall index. Adding these two items together can form a composite index that reflects both the data volume scale and the traffic volatility, thus accurately depicting the transmission state of each protocol during the interaction. The physical meaning of the weighted load fluctuation factor is that it can reveal the traffic - carrying capacity and its stability change of the protocol within the interaction window, and is the key basis for evaluating whether a certain protocol in a multi - protocol hybrid interaction scenario has abnormal load and whether it may be exploited by attackers for data hiding or channel camouflage.
[0038] Taking the logarithm of the weighted load fluctuation factors of each protocol in the protocol interaction identifier set forms the logarithmic load index, according to the formula: ; ; In the formula, is the logarithmic load index of the th protocol in the protocol interaction identifier set; The calculation of the logarithmic load index uses this formula. Its core purpose is to perform scale compression and non - linear enhancement on the weighted load fluctuation factors of each protocol, so as to improve the sensitivity to subtle fluctuation differences in multi - protocol traffic and reduce the interference caused by outliers. Logically, first, the comprehensive load and fluctuation of each protocol are normalized into an index with a unified dimension, and then processed through the logarithmic function, making the numerical growth show a decreasing trend. Thus, the numerical gap is widened among protocols with smaller loads, highlighting their slight behavioral differences; for extremely large or abnormal values, their change effects will be compressed by the logarithmic function, avoiding excessive influence on the overall evaluation result. Adding the constant 1 is to prevent the logarithmic operation from being undefined when , and at the same time ensure that all values are in the positive interval for subsequent statistical analysis. The physical meaning of this logarithmic load index is that it is a stable and highly comparable quantitative representation of the complexity of the transmission behavior of the protocol within the interaction window, which can reflect whether the data role undertaken by the protocol in the multi - protocol interaction scenario has abnormal changes, and lay a foundation for further aggregation calculation of load differences.
[0039] Calculate the interactive load difference coefficient. The specific calculation formula is as follows: ; In the formula, is the interactive load difference coefficient.
[0040] The core purpose of this formula is to measure the difference in load fluctuations among various protocols in the protocol interaction identification set. First, calculate the logarithmic load index for each protocol, which reflects the load fluctuation level of each protocol during the data packet transmission process. Next, by calculating the mean value of all protocols (i.e., ), a general reference load level is provided for the entire protocol set. Then, through the method of squared differences, calculate the deviation of the load fluctuation of each protocol from the mean value, that is, the degree of dispersion of the load fluctuation of the protocol. Finally, take the square root of the average of the squares of the deviations of all protocols to obtain the interactive load difference coefficient . The physical meaning of this interactive load difference coefficient is that it provides a quantitative measure of the load changes during the interaction of the entire protocol set. If has a large value, it indicates that there are significant differences in load fluctuations among the protocols, which may indicate abnormal traffic or behavior of some protocols and may be a signal of potential attacks or abnormal behavior; if has a small value, it shows that the load fluctuations among the protocols are relatively consistent, usually representing a high stability in the protocol interaction process. Therefore, the interactive load difference coefficient can be effectively used to detect abnormal fluctuations in protocol interactions and serve as the basis for subsequent adjustment of the protection mechanism.
[0041] The interactive load difference coefficient directly reflects the degree of difference in load fluctuations among various protocols in the protocol interaction identification set. Therefore, it has a high correlation with evaluating the change degree of the interaction behavior among protocols. When the interactive load difference coefficient is large, it indicates that each protocol shows significantly different load fluctuation patterns within the same interaction window, that is, the transmission behavior of some protocols deviates significantly from that of other protocols in terms of intensity or stability. This inconsistency usually means that there are mutations or abnormal changes in the interaction behavior among protocols, which may characterize the existence of attack behaviors such as malicious traffic nesting, hidden channel construction, or camouflaged communication; on the contrary, when the interactive load difference coefficient is small, it means that the load fluctuations among the protocols are relatively consistent and the interaction behavior tends to be stable and coordinated, usually indicating that the current protocol cooperation environment is in a normal state. Therefore, by judging the value of , it is possible to effectively evaluate whether the protocol interaction behavior is within the normal fluctuation range, thereby providing an accurate discrimination basis for subsequent dynamic regulation.
[0042] In this embodiment, the acquisition logic of the structural complexity index is as follows: Extract the protocol structure complexity feature information from the preprocessed interaction behavior feature information, specifically including the number of types of all data packet header fields, the control field ratio, and the header field information entropy value within each protocol in the protocol interaction identification set, and label them respectively as , and , represents the number of types of all data packet header fields within the th protocol in the protocol interaction identification set, represents the control field ratio within the th protocol in the protocol interaction identification set, represents the header field information entropy value within the th protocol in the protocol interaction identification set, , is a positive integer; To obtain the three types of data, namely "the number of types of all data packet header fields, the control field ratio, and the header field information entropy value within each protocol in the protocol interaction identification set", it can be gradually completed by means of software parsing network data packets. First, in the per-packet processing stage, use a protocol analysis library (such as libpcap used by Wireshark or a deep packet inspection engine) to decode each data packet and extract its header fields. The number of types of data packet header fields can be obtained by identifying different field names in each protocol and performing deduplication counting, which reflects the diversity of the protocol header structure; the control field ratio refers to the proportion of the number of fields used for functions such as status management, connection control, and handshake negotiation in the total number of protocol header fields, which can be calculated by predefining the classification of field semantics and counting the proportion of relevant fields; the header field information entropy value is calculated by statistically analyzing the frequency distribution of each field in a protocol dataset and using the information entropy formula (such as Shannon Entropy) to calculate the distribution uncertainty of the field content. The larger the value, the more random the field changes and the more complex the structure. Through the above method, the software can quantify the structural characteristics of each protocol reflected in the network traffic, providing basic support for the subsequent generation of structural complexity factors.
[0043] Calculate the structural complexity factor of each protocol in the protocol interaction identification set. The specific calculation formula is as follows: ; In the formula, is the structural complexity factor of the th protocol in the protocol interaction identification set; This formula design aims to characterize the structural complexity of each protocol in the protocol interaction identification set from multiple dimensions. Its calculation process integrates three aspects: the intensity of control logic, the complexity of information distribution, and the diversity of field types. First, represents the square of the control field ratio. By squaring, the impact of a high ratio of control fields on structural complexity is enhanced, indicating that the higher the degree of control logic dominance in the protocol, the more complex its internal structure. Second, is the exponential operation on the information entropy of the header field. The information entropy describes the unpredictability and uncertainty of the header field distribution. The exponential processing further amplifies the complexity of protocols with high entropy values, increasing the weight of protocols with chaotic or variable structures in the metric. Finally, is the logarithmic function transformation of the number of field types . It not only preserves the trend of quantity change but also avoids directly linearly amplifying the number of fields, reflecting the impact of field richness on the structure. By combining these three terms in a multiplicative way, the structure complexity factor can comprehensively reflect the complex characteristics of the protocol in three aspects: control logic, field diversity, and header field distribution. Its physical meaning is to measure the complexity challenge brought by a certain protocol to the system identification and parsing ability during the interaction process, thus providing an important reference for the subsequent assessment of behavior changes.
[0044] Calculate the structure complexity index. The specific calculation formula is as follows: ; In the formula, is the structure complexity index.
[0045] This calculation method uses the arithmetic mean to comprehensively process the structure complexity factors of multiple protocols, aiming to measure the overall level of the protocol interaction set in the dimension of structural complexity. The operation process first sums up the structure complexity factors of each protocol to obtain the total amount of structural complexity in the interaction protocol set, and then divides it by the number of protocols for standardization, thus avoiding biases caused by different numbers of protocols. This design can effectively reflect the average complexity of all interaction protocols at the overall structure level, with good comparability and stability. The physical meaning of the structure complexity index is that it represents the overall complexity of the protocol interaction structure in the current interaction window. The higher the complexity, the more difficult it is to model and identify the protocol interaction relationship, and the stronger the potential attack concealment, providing a basic basis for the dynamic regulation and identification mechanism of network security protection. In other words, is the key reference quantity for driving the sensitivity adjustment and strategy optimization of the cross-protocol traffic identification mechanism.
[0046] The structure complexity index Its size directly reflects the comprehensive complexity of each protocol in the protocol interaction identification set at the structural level, and this complexity is closely related to the changes in the interaction behavior between protocols. When the structural complexity index is large, it indicates that the types of data packet header fields in the protocol set are numerous, the proportion of control fields is relatively high, and the information entropy value of the field distribution is large, meaning that these protocols may have high dynamic adaptability and hiding ability during the interaction process, the interaction methods between protocols are more flexible and changeable, and the degree of behavioral change is relatively high. Therefore, it is difficult to effectively identify them through static patterns. On the contrary, when the structural complexity index is small, it means that the protocol structure is relatively stable, the use of control fields is concentrated, and the information entropy is low. The interaction behavior tends to be regular and fixed, and its degree of change is relatively low, making it easier to be identified and modeled. Therefore, the higher the structural complexity index, the greater the degree of change in the protocol interaction behavior, reflecting that the current interaction state between protocols faced by the system is more complex and unpredictable, thus posing higher requirements for the dynamic protection mechanism. Its size can be used as an important parameter basis for evaluating and quantifying the degree of such behavioral changes.
[0047] In this embodiment, based on the generated interaction load difference coefficient and the structural complexity index , an interaction change coefficient is generated by weighted summation. The specific calculation formula is as follows: ; In the formula, is the interaction change coefficient, and are the non-zero weight coefficients of the interaction load difference coefficient and the structural complexity index respectively, and .
[0048] The generation of the interaction change coefficient can be implemented by software. Specifically, first, the already calculated interaction load difference coefficient and the structural complexity index are imported into the analysis model as input parameters respectively; subsequently, two non-zero weight coefficients, namely and , are preset in the model to respectively regulate the influence proportions of and in the interaction change coefficient . Among them, represents the degree of emphasis on the influence of load difference when evaluating the degree of change in interaction behavior, represents the degree of emphasis on the influence of the protocol structure complexity, and the two are set according to the requirements of the network protection strategy, with flexibility and adjustability, meeting the constraint condition. Usually, if the target system pays more attention to abnormal traffic distribution, weight; if more attention is paid to the change in the structural diversity of the protocol itself, the weight of can be appropriately increased. Finally, an interaction change coefficient is generated through weighted summation operation to achieve a comprehensive quantitative evaluation of the overall change trend of multi-protocol interaction behavior.
[0049] In this embodiment, a preset threshold interval of the interaction change coefficient is determined and compared with the generated interaction change coefficient after determination. According to the comparison result, the change degree of the interaction behavior between each protocol in the protocol interaction identifier set is evaluated. The specific comparison and analysis are as follows: If , the change degree of the interaction behavior between each protocol in the protocol interaction identifier set is a normal change degree; This situation indicates that the change degree of the protocol interaction behavior is within the normal range. At this time, the interaction between protocols is relatively stable, and the load fluctuation and structural complexity change of the protocol are small. Generally, it indicates that the protocol interaction in the network is in the expected normal state, without signs of abnormal or malicious traffic. In this case, the network security protection system can continue to maintain the current protection strategy without overresponding. The impact in this state is that the protection resources and computing power of the system can focus on monitoring other higher-risk activities, avoiding unnecessary computing overhead.
[0050] If , the change degree of the interaction behavior between each protocol in the protocol interaction identifier set is a significant change degree; This situation means that there are obvious changes in the load fluctuation or structural complexity between protocols, which may be due to the adjustment of the behavior of some protocols in the network or the existence of abnormal data interaction patterns. At this time, the protection system should monitor these protocols more carefully to identify potential network attack or data leakage risks. In this case, the protection mechanism may trigger an alarm or take preventive measures, such as strengthening traffic analysis and enabling more detection algorithms to identify potential malicious activities to prevent the problem from further expanding.
[0051] If , the change degree of the interaction behavior between each protocol in the protocol interaction identifier set is a drastic change degree.
[0052] This situation indicates a sudden change in the interaction mode between protocols, extreme anomalies in load fluctuations or protocol structure complexity, which may indicate the emergence of malicious traffic, such as high-risk events like network attacks, protocol spoofing, and data leakage. This change is usually caused by the malicious exploitation or abnormal behavior of certain protocols in the network. At this time, the protection system needs to immediately take emergency measures, such as blocking suspicious traffic, analyzing the traffic source, and even starting a more advanced intrusion prevention system to prevent possible attacks. The impact in this case is that the system needs to quickly identify anomalies and take actions to reduce potential network risks, while starting protection mechanisms to ensure network security.
[0053] According to the evaluation results, perform dynamic regulation on the cross-protocol traffic recognition mechanism; In this embodiment, according to the evaluation results, performing dynamic regulation on the cross-protocol traffic recognition mechanism specifically includes: If the evaluation result is a normal degree of change, maintain the current operating parameters of the cross-protocol traffic recognition mechanism and continue to use the existing protocol recognition rules and protection strategies; If the evaluation result is a normal degree of change, to maintain the current operating parameters of the cross-protocol traffic recognition mechanism and continue to use the existing protocol recognition rules and protection strategies, it can be achieved through software configuration and dynamic parameter control. Specifically, the software will first trigger a regular status check process based on the evaluation results to confirm that the current traffic recognition algorithm and protection strategy are in a normal working state and there are no signs of abnormal fluctuations or malicious traffic. In this case, the system will keep the existing protocol recognition rules and detection strategies unchanged and continue to monitor the normal interaction behavior of the protocol. To ensure the execution of this operation, the software will maintain fixed settings for parameters such as the monitoring window size of the interaction traffic, the protocol hierarchy analysis method, and the packet filtering threshold through the threshold parameters in the configuration file. The reason for adopting this method is that under the normal degree of change, the behavior changes of protocol interactions are not significant, the network state is relatively stable, and continuing to use the existing protection strategies can save computing resources, avoid unnecessary system scheduling and burdens, and at the same time ensure that network protection will not affect system performance or generate false alarms due to over-response. Therefore, the software will choose not to adjust the protection strategy and continue with regular traffic monitoring and protocol recognition.
[0054] If the evaluation result is a significant degree of change, increase the sensitivity of traffic analysis, adjust the monitoring window of the data traffic between protocols, and enhance the extraction frequency of the protocol interaction behavior characteristics to identify potential protocol collaborative attacks and spoofing; If the evaluation result shows a significant degree of change, the sensitivity of traffic analysis can be adjusted through software, the monitoring window for inter-protocol data traffic can be optimized, and the extraction frequency of protocol interaction behavior characteristics can be enhanced to identify potential protocol collaborative attacks and disguises. The specific implementation methods are as follows: First, after the software identifies a significant change in protocol interaction based on the evaluation result, it automatically increases the sampling frequency of network traffic, that is, shortens the time span of the protocol monitoring window, enabling the system to capture subtle changes in protocol interaction at a higher frequency. Second, the software will improve the extraction accuracy and frequency of protocol behavior characteristics, add a data packet analysis function, and detect abnormal patterns in protocol traffic in real time. Especially in the scenario of multiple protocol collaborative interactions, the parsing of data packets will be further refined, with a focus on potential protocol disguises and attack behaviors. To optimize the sensitivity of traffic analysis, the software can also enable a more refined rule engine to conduct deeper mining on the statistical characteristics, transmission modes, traffic ratios, etc. of inter-protocol traffic, thereby enhancing the ability to identify complex attacks. The reason for adopting this approach is that under the significant degree of change, the behavior of protocol interaction has changed significantly, and simple static monitoring rules may not be able to identify potential attack behaviors or data disguises in a timely manner. Increasing the sensitivity and analysis frequency can ensure higher detection accuracy, thus preventing potential threats in advance and avoiding the attack from expanding to a more serious stage.
[0055] If the evaluation result shows a drastic degree of change, then adjust the core parameters of the cross-protocol traffic recognition mechanism, enable advanced protocol analysis algorithms, strengthen the traffic filtering mechanism, block potential malicious protocol traffic, and trigger the real-time threat recognition function to isolate suspicious traffic.
[0056] If the evaluation result is a drastic change level, the core parameters of the cross - protocol traffic recognition mechanism can be adjusted through software, enabling advanced protocol analysis algorithms, strengthening the traffic filtering mechanism, blocking potential malicious protocol traffic, and triggering the real - time threat recognition function to isolate suspicious traffic. The specific implementation methods include: First, after the software system detects a drastic change, it will immediately modify the key configuration parameters in the cross - protocol traffic recognition module through the dynamic parameter adjustment mechanism, such as increasing the depth of protocol analysis, shortening the packet analysis cycle, and adjusting the packet feature extraction algorithm to promptly detect significant changes in protocol behavior. Second, the software will start advanced protocol analysis algorithms, such as deep packet inspection (DPI) or machine - learning - based behavior analysis algorithms, which can more deeply analyze abnormal patterns, protocol camouflage, and traffic mixing behaviors in protocol interactions, especially in the case of multiple protocol collaborative interactions. To further enhance protection, the software will also activate more stringent traffic filtering rules, automatically filtering based on real - time data traffic patterns, protocol characteristics, and blacklists to block suspicious malicious traffic. Finally, in this situation, the software will also enable the real - time threat recognition function. By analyzing information such as traffic source, target address, and protocol identifier, it will trigger an automated isolation mechanism to isolate possible malicious traffic and prevent it from spreading to other network nodes. The reason for adopting this approach is that when there are drastic changes in protocol interaction behaviors, conventional detection means and protection strategies cannot effectively cope with sudden malicious traffic or complex attack patterns. Therefore, it is necessary to adjust core parameters and enable advanced analysis algorithms to respond in real - time and accurately identify potential threats to ensure the security of the network system is not compromised.
[0057] Execute corresponding protection actions based on the recognition result after dynamic regulation, and at the same time record the recognition result and the corresponding interaction behavior characteristic information, and update the evaluation conditions and regulation strategies based on the recorded content.
[0058] After completing the dynamic regulation of the cross - protocol traffic recognition mechanism, the software can execute protection actions corresponding to the recognition result through the integrated rule matching and behavior response mechanism. Specifically, the software will first call the rules in the corresponding protection strategy library according to the matching degree between the recognized protocol interaction behavior and the attack pattern, including operations such as connection blocking, session interruption, IP blacklist marking, and specific protocol restrictions, and set the response priority according to the risk level classified by the recognition result. At the same time, the system will store the recognition result in a structured manner, including information such as the recognized protocol combination, abnormal behavior pattern, and associated packet characteristics, and record them together with the timestamp, recognition logic, and triggered response measures in the log database. These recording operations are implemented in software by the log management sub - module, supporting automatic archiving, tagged classification, and index retrieval, providing a basis for subsequent analysis and auditing.
[0059] In addition, the software system inputs the recorded interactive behavior feature information and the recognition result as feedback information into the evaluation module to achieve dynamic optimization of the evaluation conditions and regulation strategies. The software executes a periodic policy evaluation program in the background, conducts cluster analysis and rule evolution on the recorded recognition cases, automatically optimizes the feature extraction parameters, adjusts the threshold range of the interactive change coefficient, updates the protocol recognition granularity and triggering conditions based on the previously successfully recognized attack patterns, so as to improve the system's adaptability when facing new or evolving attack behaviors in the future. This mechanism realizes a closed-loop process from recognition, response, recording to self-optimization, not only improving the real-time performance and accuracy of the protection system, but also enhancing the sustainable evolution ability of the system, which is an important part of realizing adaptive security protection based on software control logic.
[0060] Such as Figure 2 The network security protection system based on traffic analysis shown, includes a protocol recognition and classification module, an interactive protocol calibration module, an interactive behavior evaluation module, a recognition strategy regulation module, and a protection closed-loop optimization module; The protocol recognition and classification module performs packet-by-packet access processing on all traffic transmitted through the network, extracts the protocol identification field, port information, and transmission direction information of each data packet, and completes the classification of the protocol type of each data packet; The interactive protocol calibration module, based on the protocol type classification result, determines whether there is a situation of multi-protocol interactive traffic. If this situation exists, it determines all the protocols participating in the interaction and classifies them into a protocol interaction identification set; The interactive behavior evaluation module obtains the interactive behavior feature information of each protocol in the protocol interaction identification set, and analyzes it after obtaining, to evaluate the degree of change in the interactive behavior between each protocol in the protocol interaction identification set; The recognition strategy regulation module dynamically regulates the cross-protocol traffic recognition mechanism according to the evaluation result; The protection closed-loop optimization module performs corresponding protection actions based on the recognition result after dynamic regulation, records the recognition result and the corresponding interactive behavior feature information at the same time, and updates the evaluation conditions and regulation strategies based on the recorded content.
[0061] The above formulas are all dimensionless and take their numerical values for calculation. The formula is obtained by collecting a large amount of data for software simulation to get a formula closest to the real situation. The preset parameters in the formula are set by technicians in the field according to the actual situation.
[0062] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more collections of available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, or magnetic tape), an optical medium (such as a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state drive.
[0063] It should be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0064] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0065] In several embodiments provided in the present application, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the above-described embodiments are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be indirect couplings or communication connections through some interfaces, devices, or units, and can be in an electrical, mechanical, or other form.
[0066] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or may be distributed over multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0067] In addition, each functional unit in various embodiments of the present application may be integrated in a processing unit, may exist separately as individual physical units, or two or more units may be integrated in one unit.
[0068] As mentioned above, the above are only specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A network security protection method based on traffic analysis, characterized in that Specifically, it includes the following steps: Perform per-packet access processing on all traffic transmitted through the network, extract the protocol identification field, port information, and transmission direction information of each data packet, and complete the classification of the protocol type of each data packet; Based on the protocol type classification result, determine whether there is a situation of multi-protocol interaction traffic. If there is such a situation, determine all the protocols participating in the interaction and classify them into a protocol interaction identification set; Obtain the interaction behavior characteristic information of each protocol in the protocol interaction identification set, and analyze it after obtaining, and evaluate the degree of change in the interaction behavior between each protocol in the protocol interaction identification set; According to the evaluation result, perform dynamic regulation on the cross-protocol traffic recognition mechanism; Based on the recognition result after dynamic regulation, perform corresponding protection actions, and at the same time record the recognition result and the corresponding interaction behavior characteristic information, and update the evaluation conditions and regulation strategies based on the recorded content.
2. The network security protection method based on traffic analysis according to claim 1, characterized in that, Based on the protocol type classification result, determine whether there is a situation of multi-protocol interaction traffic. If there is such a situation, determine all the protocols participating in the interaction and classify them into a protocol interaction identification set. Specifically: Based on the protocol type classification result of each data packet, within a pre-set continuous time window, perform statistics on the network traffic after protocol type classification. By analyzing the arrangement of data packets corresponding to all protocols within the pre-set continuous time window in chronological order, determine whether there is a situation of multi-protocol interaction traffic; the situation of multi-protocol interaction traffic refers to the situation where data packets of several protocols appear alternately within the pre-set continuous time window; If it is determined that there is a situation of multi-protocol interaction traffic, determine the protocol types corresponding to all the alternately appearing data packets within the pre-set continuous time window as the protocols participating in the interaction, and construct the determined protocol combination into a protocol interaction identification set.
3. The network security protection method based on traffic analysis according to claim 2, characterized in that, Obtain the interaction behavior characteristic information of each protocol in the protocol interaction identification set, and analyze it after obtaining, and evaluate the degree of change in the interaction behavior between each protocol in the protocol interaction identification set. Specifically, it includes the following steps: Obtain the interaction behavior characteristic information of each protocol in the protocol interaction identification set, and perform preprocessing after obtaining; Extract the protocol payload fluctuation characteristic information and protocol structure complexity characteristic information from the preprocessed interaction behavior characteristic information, and analyze them after extraction to generate an interaction payload difference coefficient and a structure complexity index respectively; Based on the generated interaction payload difference coefficient and structure complexity index, generate an interaction change coefficient through weighted summation; Determine a pre-set interaction change coefficient threshold interval, and compare it with the generated interaction change coefficient after determination, and evaluate the degree of change in the interaction behavior between each protocol in the protocol interaction identification set according to the comparison result.
4. The network security protection method based on traffic analysis according to claim 3, wherein, The acquisition logic of the interaction payload difference coefficient is as follows: Extract protocol payload fluctuation feature information from the preprocessed interactive behavior feature information, specifically including the sum of the sizes of all data packets, the number of data packets, and the difference between the maximum data packet size and the minimum data packet size within each protocol in the protocol interaction identification set, and label them respectively as 、 and , represents the sum of the sizes of all data packets within the -th protocol in the protocol interaction identification set, represents the number of data packets within the -th protocol in the protocol interaction identification set, represents the difference between the maximum data packet size and the minimum data packet size within the -th protocol in the protocol interaction identification set, , is a positive integer; Calculate the weighted payload fluctuation factor of each protocol in the protocol interaction identification set. The specific calculation formula is as follows: In the formula, is the weighted load fluctuation factor of the th protocol in the protocol interaction identification set; The weighted load fluctuation factor of each protocol in the protocol interaction identifier set Take the logarithm to form a logarithmic load index, according to the formula: wherein, is the logarithmic payload metric of the th protocol in the protocol interaction identification set; Calculate the interaction payload difference coefficient. The specific calculation formula is as follows: In the formula, is the interactive load difference coefficient.
5. The network security protection method based on traffic analysis according to claim 4, wherein The acquisition logic of the structure complexity index is as follows: Extract protocol structure complex feature information from the preprocessed interactive behavior feature information, specifically including the number of types of all data packet header fields, the control field ratio, and the header field information entropy value within each protocol in the protocol interaction identification set, and respectively label them as , and , represents the number of types of all data packet header fields within the -th protocol in the protocol interaction identification set, represents the control field ratio within the -th protocol in the protocol interaction identification set, represents the header field information entropy value within the -th protocol in the protocol interaction identification set, , is a positive integer; Calculate the structure complexity factor of each protocol in the protocol interaction identification set. The specific calculation formula is as follows: In the formula, is the structural complexity factor of the th protocol in the protocol interaction identification set; Calculate the structure complexity index. The specific calculation formula is as follows: In the formula, is the structural complexity index.
6. The network security protection method based on traffic analysis according to claim 5, wherein Based on the generated interaction load difference coefficient and structural complexity index , an interaction change coefficient is generated by weighted summation, and the specific calculation formula is as follows: In the formula, is the interaction change coefficient, and are the interaction load difference coefficient and the structural complexity index non-zero weight coefficients, and .
7. The network security protection method based on traffic analysis according to claim 6, wherein Determine the pre-set threshold interval of the interaction change coefficient , and after determination, compare it with the generated interaction change coefficient , and evaluate the change degree of the interaction behavior between each protocol in the protocol interaction identifier set according to the comparison result. The specific comparison and analysis are as follows: If , the degree of change in the interaction behavior between the various protocols in the protocol interaction identifier set is a normal degree of change; If , the degree of change in the interaction behavior between the protocols in the protocol interaction identifier set is a significant degree of change; If , the degree of change in the interaction behavior between the protocols in the protocol interaction identifier set is a drastic degree of change.
8. The network security protection method based on traffic analysis according to claim 7, characterized in that Based on the evaluation results, perform dynamic regulation on the cross - protocol traffic recognition mechanism, specifically as follows: If the evaluation result shows a normal degree of change, maintain the current operating parameters of the cross - protocol traffic recognition mechanism and continue to use the existing protocol recognition rules and protection strategies; If the evaluation result shows a significant degree of change, increase the sensitivity of traffic analysis, adjust the monitoring window for data traffic between protocols, and enhance the extraction frequency of the interaction behavior characteristics of protocols to identify potential protocol collaborative attacks and disguises; If the evaluation result shows a drastic degree of change, adjust the core parameters of the cross - protocol traffic recognition mechanism, enable advanced protocol analysis algorithms, strengthen the traffic filtering mechanism, block potential malicious protocol traffic, and trigger the real - time threat recognition function to isolate suspicious traffic.
9. A network security protection system based on traffic analysis, which is used to implement the network security protection method based on traffic analysis described in any one of the above claims 1-8, and is characterized in that, It includes a protocol recognition and classification module, an interactive protocol calibration module, an interactive behavior evaluation module, a recognition strategy regulation module, and a protection closed - loop optimization module; The protocol recognition and classification module performs per - packet access processing on all traffic transmitted through the network, extracts the protocol identification field, port information, and transmission direction information of each data packet, and completes the classification of the protocol type of each data packet; The interactive protocol calibration module, based on the protocol type classification result, determines whether there is a situation of multi - protocol interactive traffic. If such a situation exists, it determines all the protocols participating in the interaction and classifies them into a protocol interaction identification set; The interactive behavior evaluation module obtains the interactive behavior characteristic information of each protocol in the protocol interaction identification set, and analyzes it after obtaining it to evaluate the degree of change in the interaction behavior between the protocols in the protocol interaction identification set; The recognition strategy regulation module performs dynamic regulation on the cross - protocol traffic recognition mechanism according to the evaluation results; The protection closed - loop optimization module performs corresponding protection actions based on the recognition results after dynamic regulation, records the recognition results and the corresponding interactive behavior characteristic information at the same time, and updates the evaluation conditions and regulation strategies based on the recorded content.
Citation Information
Patent Citations
Security protection method and system based on protocol controller and security gateway
CN117118652A
Industrial control flow analysis system and equipment
CN117375957A
Industrial gateway and protocol conversion method
CN117914961A
Multi-protocol compatibility testing method and system for gateway equipment
CN119766706A
Digital information security transmission system and method based on network protocol analysis
CN119995996A
Cited By
Multifunctional network access detection system supporting unified intelligent terminal operating system protocol
CN121125583A