Server intrusion detection method and device, medium and equipment

By integrating log, traffic, and performance data analysis, the method enhances server intrusion detection, addressing new and complex threats with improved accuracy and reduced false alarms.

CN120321049AActive Publication Date: 2025-07-15RONGKE LIANCHUANG (TIANJIN) INFORMATION TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510809253.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-17
Publication Date
2025-07-15
Estimated Expiration
2045-06-17

AI Technical Summary

Technical Problem

The existing server intrusion detection technology has shortcomings in the face of new attacks, complex attack scenarios, and multi-source data fusion analysis. It is difficult to accurately identify complex slow penetration attacks and has a high false alarm rate. It has failed to fully utilize the association relationships of multiple data during server operation.

Method used

By comprehensively collecting system logs, network traffic and system performance information, key rule mining and time series feature extraction, combining historical feature data matrix and server status labels, correlation coefficient vectors are calculated, target operation feature vectors are generated, and finally using the server status classification model to judge the intrusion situation.

Benefits of technology

It improves the accuracy of intrusion detection, reduces the false alarm rate, can accurately judge new and complex attacks, comprehensively characterize the operating status of the server, and mines the key characteristics of the data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321049A_ABST
    Figure CN120321049A_ABST
Patent Text Reader

Abstract

The invention provides a server intrusion detection method and device, a medium and equipment, and relates to the technical field of server intrusion detection, and the method comprises the steps: collecting the operation information of a to-be-detected server at each preset collection time point; performing feature extraction to obtain an initial feature data list; obtaining a correlation coefficient vector according to a historical feature data matrix corresponding to the historical feature data of the to-be-detected server and the server state tag; obtaining a target operation feature vector according to the correlation coefficient vector and the initial operation feature data list; and according to the target operation feature vector and a server state classification model, determining whether the to-be-detected server is invaded currently. According to the method, the detection accuracy is effectively improved, the false report and missing report rate is reduced, meanwhile, intrusion is accurately judged, novel and complex attacks can be found from the feature level, and the defects of a traditional method in the aspect of coping with the novel and complex attacks are overcome.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] With the rapid development of information technology, servers play a crucial role in the business operations of enterprises and various organizations. Servers store and process a large amount of critical data. Once invaded, it may lead to serious consequences such as data leakage, system paralysis, and business interruption, causing huge economic losses and reputational damage to enterprises. Therefore, server intrusion detection technology has become a research hotspot in the field of network security.

[0003] Currently, traditional server intrusion detection methods mainly rely on signature matching and anomaly detection. Signature - based methods rely on known attack signature libraries and identify intrusion behaviors by comparing the collected server data with the patterns in the signature library. However, this method is often ineffective against new and unknown attack means because hackers keep innovating attack methods, and it is difficult to timely include new attack signatures in the signature library.

[0004] Anomaly - based methods establish a model of normal server behavior and compare the real - time monitored data with this model. When the deviation exceeds a certain threshold, it is determined as an intrusion behavior. But this method has a high false - alarm rate because the running state of the server is affected by various factors, such as resource usage changes during peak business hours, system upgrades, etc. These normal fluctuations may be misjudged as intrusion behaviors. At the same time, this method is difficult to effectively identify complex and slowly penetrating attacks because such attacks may long - term be within the normal behavior fluctuation range and are not easily detected.

[0005] In addition, most of the existing intrusion detection methods only focus on a single type of data, such as only analyzing system log information or network traffic information, and fail to fully utilize the correlation between various data generated during the server operation. However, the operation of the server is a complex systematic project. Different types of data (such as system log information, network traffic information, and system performance information) reflect the running state of the server from different perspectives. Comprehensive analysis of these data can more comprehensively and accurately determine whether the server has been invaded.

[0006] In summary, the existing server intrusion detection technologies have deficiencies in the face of new attacks, complex attack scenarios, and multi - source data fusion analysis. There is an urgent need for a more efficient, accurate, and intrusion detection method that can comprehensively utilize various data to improve the security and stability of the server. Summary of the Invention

[0007] In view of the above - mentioned technical problems, this application provides a server intrusion detection method, device, medium, and equipment, which at least partially solve the problems existing in the prior art.

[0008] In a first aspect of the present application, a server intrusion detection method is provided. The method includes: At each preset collection time point, collect the running information of the server to be detected; wherein, the running information includes: system log information, network traffic information, and system performance information; Extract features by performing key rule mining on the system log information and network traffic information, and extract features of time series for the system performance information to obtain an initial feature data list; wherein, the initial feature data list includes a number of initial running feature data; each initial running feature data has a corresponding running feature; According to the historical feature data matrix corresponding to the historical feature data of the server to be detected and the server status label, obtain a correlation coefficient vector; wherein, the historical feature data matrix includes a number of historical data samples; each historical data sample has a corresponding number of historical feature data; each historical feature data has a corresponding running feature; the correlation coefficient vector is used to describe the correlation coefficient between each running feature and the server status label; According to the correlation coefficient vector and the initial running feature data list, obtain a target running feature vector; According to the target running feature vector and the server status classification model, determine whether the server to be detected is currently being invaded.

[0009] Optionally, the feature extraction by performing key rule mining on the system log information includes: Convert the system log information into a log transaction set; wherein, the log transaction set contains a number of log transactions; each log transaction has a corresponding event list and a first preset time window; each event list contains a number of events; the time corresponding to each event is within the range of the first preset time window of the corresponding log transaction; According to the preset minimum support and minimum confidence thresholds, obtain combinations of log events with the number of co-occurrences greater than the preset co-occurrence quantity, and generate a number of association rules; According to the support, confidence, and lift of each association rule, determine a target association rule for feature extraction among the number of association rules; wherein, each association rule has an association degree score; the target association rule is the association rule with the highest association degree score; the association degree score is positively correlated with the support, confidence, and lift.

[0010] Optionally, the feature extraction by performing key rule mining on the network traffic information includes: Obtain a number of intermediate traffic pairs; each intermediate traffic pair consists of two servers; each intermediate traffic pair contains the server to be detected; each intermediate traffic pair has a corresponding pair of IP address information and a pair of port information; the source IP address or the destination IP address of each intermediate traffic pair is the IP address of the server to be detected; the source port number or the destination port number of each intermediate traffic pair is the port number of any one of the several ports of the server to be detected; Obtain at least one target traffic pair according to the traffic correlation of the number of intermediate traffic pairs within the second preset time window; wherein, the traffic correlation of the target traffic pair is greater than the preset traffic correlation threshold; the traffic correlation includes IP traffic correlation and port traffic correlation; Obtain a network traffic association graph according to the IP address and port number corresponding to each target traffic; wherein, each IP address and each port number are nodes; Extract features from the network traffic association graph.

[0011] Optionally, perform feature extraction on the time series of the system performance information, including: Obtain a number of time series curves according to the system performance information; Fit the number of time series curves according to the polynomial function to obtain the coefficients corresponding to the polynomial function; Extract features from the time series curve and the coefficients corresponding to the polynomial function.

[0012] Optionally, obtain a target operation feature vector according to the correlation coefficient vector and the initial operation feature data list, including: Sort each corresponding initial operation feature in the initial operation feature data list according to the corresponding average correlation coefficient according to the correlation coefficient vector; Determine the initial operation features ranked in the top preset number as the target operation features to obtain the target operation feature vector.

[0013] Optionally, when it reaches the preset acquisition time point, after collecting the operation information of the server to be detected, the method further includes: Preprocess the operation information.

[0014] Optionally, after determining whether the server to be detected is currently invaded according to the target operation feature vector and the server state classification model, the method further includes: When an intrusion event is detected, generate an alarm message and send the alarm message to the target display device.

[0015] In the second aspect of the present application, a server intrusion detection device is provided, including: A collection unit, which is used to collect the running information of the server to be detected every time a preset collection time point is reached; wherein, the running information includes: system log information, network traffic information, and system performance information; An extraction unit, which is used to perform feature extraction for key rule mining on the system log information and network traffic information, and perform feature extraction of time series on the system performance information to obtain an initial feature data list; wherein, the initial feature data list includes a number of initial running feature data; each initial running feature data has a corresponding running feature; A vector acquisition unit, which is used to obtain a correlation coefficient vector according to the historical feature data matrix corresponding to the historical feature data of the server to be detected and the server status label; wherein, the historical feature data matrix includes a number of historical data samples; each historical data sample has a corresponding number of historical feature data; each historical feature data has a corresponding running feature; the correlation coefficient vector is used to describe the correlation coefficient between each running feature and the server status label; A target vector determination unit, which is used to obtain a target running feature vector according to the correlation coefficient vector and the initial running feature data list; An intrusion determination unit, which is used to determine whether the server to be detected is currently being invaded according to the target running feature vector and the server status classification model.

[0016] In the third aspect of the present application, a non-transitory computer-readable storage medium is provided. At least one instruction or at least one program segment is stored in the storage medium, and at least one instruction or at least one program segment is loaded and executed by a processor to implement the foregoing server intrusion detection method.

[0017] In the fourth aspect of the present application, an electronic device is provided, including a processor and the foregoing non-transitory computer-readable storage medium.

[0018] The present application has at least the following beneficial effects: The server intrusion detection method, device, medium, and equipment provided by the present application comprehensively collect system logs, network traffic, and system performance information, respectively perform key rule mining and time series feature extraction on them, combine the historical feature data matrix and the server status label to obtain a correlation coefficient vector, and then obtain a target running feature vector. Finally, the intrusion situation is judged by means of the server status classification model. This method can comprehensively describe the running state of the server from multiple dimensions, mine the key features of the data, effectively improve the detection accuracy rate, reduce the false alarm and missed detection rates, accurately judge the intrusion at the same time, and can also discover new and complex attacks from the feature level, making up for the deficiencies of traditional methods in dealing with new and complex attacks. Description of the Drawings

[0019] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0020] Figure 1 It is a flowchart of the server intrusion detection method provided by the embodiments of the present application; Figure 2 It is a structural block diagram of the server intrusion detection device provided by the embodiments of the present application. Detailed implementation manners

[0021] The following will clearly and completely describe the technical solutions in the embodiments of the present application in combination with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the protection scope of the present application.

[0022] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above accompanying drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances, so that the embodiments of the present application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or server including a series of steps or units does not necessarily have to be limited to those clearly listed steps or units, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0023] It should be noted that the following describes various aspects of the embodiments within the scope of the appended claims. It should be obvious that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is merely illustrative. Based on the present application, those skilled in the art should understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement a device and / or practice a method. Additionally, this device and / or practice of this method can be implemented using other structures and / or functionality in addition to one or more of the aspects described herein.

[0024] Please refer to Figure 1As shown in the figure, an embodiment of the present application provides a server intrusion detection method, which includes: S100, at each preset collection time point, collect the running information of the server to be detected; where the running information includes: system log information, network traffic information, and system performance information.

[0025] Specifically, deploy multiple data collection modules on the server to be detected, and collect information such as system log information, network traffic data, system performance information, and user operation records of the server to be detected in real time. Among them, the collection of system log information is as follows: collect the kernel logs of the operating system of the server to be detected (such as / var / log / kern.log of Linux), application logs (such as access logs and error logs of web servers), and security logs (recording information such as user logins and permission changes). Use a log management system (such as the ELK Stack, that is, Elasticsearch, Logstash, and Kibana) to centrally store and manage the logs for subsequent analysis. The collection of network traffic information is as follows: use a network packet capture tool (such as Wireshark, Tcpdump) to capture the data packets of the server network interface. Record the detailed information of the network traffic, including source IP, destination IP, port number, protocol type (TCP, UDP, ICMP, etc.), packet size, timestamp, etc. The collection of system performance information is as follows: with the help of system monitoring tools (such as Prometheus, Grafana), collect the performance metrics of the server in real time, such as CPU usage, memory usage, disk I / O rate, network bandwidth utilization, etc. Record these metrics at fixed time intervals (such as every second, every minute) to form time series data. The collection of user operation records is as follows: record various operation behaviors of users on the server, such as file reading and writing, database operations, etc.

[0026] S200, perform feature extraction for key rule mining on the system log information and network traffic information, and perform feature extraction of time series on the system performance information to obtain an initial feature data list; where the initial feature data list includes several initial running feature data; each initial running feature data has a corresponding running feature.

[0027] Specifically, the feature extraction for key rule mining on the system log information and network traffic information includes: Step a1, convert the system log information into a log transaction set; where the log transaction set contains several log transactions; each log transaction has a corresponding event list and a first preset time window; each event list contains several events; the time corresponding to each event is within the range of the first preset time window of the corresponding log transaction.

[0028] Step a2: According to the preset minimum support and minimum confidence thresholds, obtain combinations of log events whose co-occurrence times are greater than the preset co-occurrence quantity, and generate a number of association rules.

[0029] Step a3: According to the support, confidence, and lift of each association rule, determine the target association rule for feature extraction among a number of association rules; wherein, each association rule has an association degree score; the target association rule is the association rule with the highest association degree score; the association degree score is positively correlated with the support, confidence, and lift.

[0030] Here, the Apriori algorithm is used to mine association rules in system logs to find combinations of events that frequently co-occur. For example, it is found that the "user login" event and the "file download" event frequently occur simultaneously within a certain time interval, and this association rule is used as a feature. Calculate the support, confidence, and lift of each association rule, and select the association rules with higher credibility and practicality as the target association rules.

[0031] In addition, the feature extraction for key rule mining of network traffic information includes: Step b1: Obtain a number of intermediate traffic pairs; each intermediate traffic pair consists of two servers; each intermediate traffic pair contains the server to be detected; each intermediate traffic pair has a corresponding IP address information pair and port information pair; the source IP address or destination IP address of each intermediate traffic pair is the IP address of the server to be detected; the source port number or destination port number of each intermediate traffic pair is the port number of any one of the several ports of the server to be detected.

[0032] Step b2: According to the traffic correlation of a number of intermediate traffic pairs within the second preset time window, obtain at least one target traffic pair, wherein the traffic correlation of the target traffic pair is greater than the preset traffic correlation threshold; the traffic correlation includes IP traffic correlation and port traffic correlation.

[0033] Step b3: According to the IP address and port number corresponding to each target traffic, obtain a network traffic association graph; wherein, each IP address and each port number are nodes.

[0034] Step b4: Perform feature extraction on the network traffic association graph.

[0035] Here, use network packet capture tools such as Tcpdump (for Linux systems) or Wireshark (cross-platform) to capture packets on the server network interface. Capture rules can be set according to requirements, such as capturing only traffic with specific IP addresses, port numbers, or protocol types. Analyze the network traffic associations between different IP addresses and port numbers. By calculating the correlation coefficients of the traffic data, find pairs of target traffic with strong correlations. For example, calculate the traffic correlation between the source IP and the destination IP, and the co-variation characteristics of the traffic between different port pairs. Construct a network traffic association graph, using IP addresses and port numbers as nodes and traffic correlation as the weight of the edges. Extract topological features of the graph, such as node degree, clustering coefficient, and shortest path length, as part of the feature vector.

[0036] In addition, perform feature extraction on the time series of system performance information, including: Step c1: Obtain several time series curves based on the system performance information.

[0037] Step c2: Fit the several time series curves with polynomial functions to obtain the coefficients corresponding to the polynomial functions.

[0038] Step c3: Perform feature extraction on the time series curves and the coefficients corresponding to the polynomial functions.

[0039] Here, install system monitoring tools on the server, such as Prometheus and Node Exporter (for Linux servers). Node Exporter is responsible for collecting various performance metrics of the server, including CPU usage, memory usage, disk I / O rate, and network bandwidth utilization, etc., and exposing these metrics in the form of an HTTP interface. Prometheus, as a time series database, regularly pulls performance metric data from Node Exporter for storage. At the same time, integrate Grafana with Prometheus to create a visual dashboard to display the changing trends of the server's performance metrics in real time, facilitating administrators to monitor the running status of the server. For the time series data of system performance metrics, use the moving average method to calculate the average values of different time windows. By sliding a window of a fixed size, calculate the average value of the data within the window to reflect the short-term and long-term trends of the data. For example, calculate the moving average values for 5 minutes, 10 minutes, and 30 minutes to capture the performance change trends at different time scales. Use polynomial functions to fit the time series data and solve for the coefficients of the polynomial by the least squares method. Extract the slope and curvature of the polynomial curve as features to describe the change speed and change acceleration of the data. For example, quadratic polynomial fitting can reflect the quadratic change trend of the data.

[0040] S300. Obtain a correlation coefficient vector based on the historical feature data matrix corresponding to the historical feature data of the server to be detected and the server status label. The historical feature data matrix includes a number of historical data samples. Each historical data sample has a corresponding number of historical feature data. Each historical feature data has a corresponding operation feature. The correlation coefficient vector is used to describe the correlation coefficient between each operation feature and the server status label.

[0041] S400. Obtain a target operation feature vector based on the correlation coefficient vector and the initial operation feature data list.

[0042] Among them, obtaining the target operation feature vector based on the correlation coefficient vector and the initial operation feature data list includes: Step d1. Sort each initial operation feature in the initial operation feature data list according to the corresponding average correlation coefficient based on the correlation coefficient vector. Step d2. Determine the initial operation features ranked in the top preset number as the target operation features to obtain the target operation feature vector.

[0043] Use the historical feature data to obtain the relationship between each initial operation feature in the initial operation feature data list and the server status label, so as to screen out the operation features with higher weights (larger average correlation coefficients), that is, the operation features that are more important for judging the server status, and finally obtain the target operation feature vector. Among them, the correlation coefficient can be calculated according to the Pearson correlation coefficient.

[0044] The server status label includes: a normal status label and an intrusion status label, that is, the historical data includes normal and abnormal situations respectively. The normal status label represents the situation where the server is free from intrusion threats and operates in an expected and conventional manner. Usually, it can be represented by the value "0". When in the normal state, all operations and data interactions of the server conform to common usage patterns and business rules. For example, in terms of system logs: the login and operation behaviors of users follow the established permissions and processes, without abnormal login failure attempts, privilege escalation operations, etc. For example, legitimate users log in to the server normally during working hours and perform conventional file reading, data query and other operations. In terms of network traffic: the size, source and destination addresses, protocol usage, etc. of network traffic are within the normal range. For example, the server communicates stably with known legitimate clients and conforms to business requirements, without a large number of abnormal port scans, traffic surges in the form of DDoS attacks, etc. In terms of system performance indicators: performance indicators such as CPU usage, memory usage, and disk I / O are within a reasonable range and do not show sudden drastic fluctuations. For example, during the business peak period, the CPU usage of the server will increase, but it will not exceed the server's tolerance, and the fluctuation trend is predictable.

[0045] The intrusion status tag indicates that the server is suffering from or has suffered malicious attacks or illegal intrusion behaviors. Generally, the value "1" is used to represent it. The intrusion status may manifest in the following situations: In terms of system logs: There are a large number of failed login records, which may be that attackers are trying to brute-force passwords; there are abnormal file creation, modification, or deletion operations, especially sensitive files; there are abnormal process startups or permission changes, etc. In terms of network traffic: There are abnormal port scanning behaviors, a large number of data packets are sent from unknown IP addresses to multiple ports of the server; DDoS attacks cause a sharp increase in network traffic, and the server bandwidth is heavily occupied, affecting normal services; there are abnormal remote connection requests, which may be that attackers are trying to remotely control the server. In terms of system performance metrics: The CPU or memory usage suddenly rises significantly and remains high, which may be that malicious programs are consuming system resources; disk I / O is abnormally frequent, which may be that attackers are stealing data or implanting malware.

[0046] S500, according to the target running feature vector and the server status classification model, determine whether the server to be detected is currently being invaded.

[0047] Specifically, collect a large amount of historical data, including data during normal operation and data under various known intrusion scenarios. Divide the data into a training set, a validation set, and a test set according to a certain ratio. Use the training set to train the selected neural network model. During the training process, adopt the cross-validation method to continuously adjust the hyperparameters of the model, such as the learning rate, the number of layers, the number of nodes, etc., to improve the accuracy and generalization ability of the model. Use the validation set to evaluate the model during the training process, and further optimize the model according to the evaluation results. Finally, use the test set to conduct the final performance test on the optimized model to ensure that the model can accurately identify various intrusion behaviors.

[0048] In an exemplary embodiment of the present application, every time a preset collection time point is reached, after collecting the running information of the server to be detected, the method further includes: Preprocess the running information.

[0049] Specifically, use the data cleaning algorithm to remove duplicate, incorrect, and incomplete records in the collected data.

[0050] In an exemplary embodiment of the present application, after determining whether the server to be detected is currently being invaded according to the target running feature vector and the server status classification model, the method further includes: When an intrusion event is detected, generate an alarm message and send the alarm message to the target display device.

[0051] Specifically, when the model detects an intrusion event, the alarm information generation module generates detailed alarm content according to a preset template and the collected relevant information. By calling the SMS gateway interface, email sending server, and API interfaces of instant messaging software, the alarm information is sent to relevant personnel. At the same time, alarm prompts are displayed on the server management interface through pop-up windows, flashing icons, etc.

[0052] Verification of the alarm response process: Simulate various server intrusion scenarios in a laboratory environment, such as simulating a hacker's SQL injection attack, DDoS traffic attack, etc. Observe whether the system can detect the intrusion in a timely manner and send alarm information. The personnel receiving the alarm information operate according to the predetermined alarm response process to verify the effectiveness and feasibility of the emergency handling measures. Through multiple simulation tests, continuously optimize the alarm response process and related handling measures to ensure that server intrusion events can be quickly and effectively responded to in actual applications.

[0053] As Figure 2 shown, an embodiment of the present application provides a server intrusion detection device 100, and the device includes: A collection unit 110, which is used to collect the operation information of the server to be detected every time a preset collection time point is reached; wherein, the operation information includes: system log information, network traffic information, and system performance information.

[0054] An extraction unit 120, which is used to perform feature extraction for key rule mining on the system log information and network traffic information, and perform feature extraction of time series on the system performance information to obtain an initial feature data list; wherein, the initial feature data list includes several initial operation feature data; each initial operation feature data has a corresponding operation feature.

[0055] A vector acquisition unit 130, which is used to obtain a correlation coefficient vector according to the historical feature data matrix corresponding to the historical feature data of the server to be detected and the server status label; wherein, the historical feature data matrix includes several historical data samples; each historical data sample has a corresponding several historical feature data; each historical feature data has a corresponding operation feature; the correlation coefficient vector is used to describe the correlation coefficient between each operation feature and the server status label.

[0056] A target vector determination unit 140, which is used to obtain a target operation feature vector according to the correlation coefficient vector and the initial operation feature data list.

[0057] An intrusion determination unit 150, which is used to determine whether the server to be detected is currently being invaded according to the target operation feature vector and the server status classification model.

[0058] In an exemplary embodiment of the present application, an electronic device capable of implementing the above method is also provided.

[0059] Those skilled in the art can understand that various aspects of the present application can be implemented as a system, a method, or a program product. Therefore, various aspects of the present application can be specifically implemented in the following forms, namely: a complete hardware implementation, a complete software implementation (including firmware, microcode, etc.), or an implementation combining hardware and software aspects, which can be collectively referred to herein as "circuitry", "module", or "system".

[0060] An electronic device according to this embodiment of the present application. The electronic device is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present application.

[0061] The electronic device is presented in the form of a general-purpose computing device. The components of the electronic device may include, but are not limited to: at least one of the above-mentioned processors, at least one of the above-mentioned memories, and a bus connecting different system components (including the memory and the processor).

[0062] Among them, the memory stores program code, and the program code can be executed by the processor, so that the processor executes the steps according to various exemplary embodiments of the present application described in the "Exemplary Method" section of this specification.

[0063] The memory may include a readable medium in the form of a volatile memory, such as a random access memory (RAM) and / or a cache memory, and may further include a read-only memory (ROM).

[0064] The memory may further include a program / utility having a set (at least one) of program modules, and such program modules include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. The implementation of a network environment may be included in each or some combination of these examples.

[0065] The bus may represent one or more of several types of bus structures, including a memory bus or a memory controller, a peripheral bus, a graphics acceleration port, a processor, or a local bus using any bus structure in a variety of bus structures.

[0066] The electronic device can also communicate with one or more external devices (such as a keyboard, a pointing device, a Bluetooth device, etc.), and can also communicate with one or more devices that enable a user to interact with the electronic device, and / or communicate with any device that enables the electronic device to communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication can be carried out through an input / output (I / O) interface. Moreover, the electronic device can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through a network adapter. As shown in the figure, the network adapter communicates with other modules of the electronic device through a bus. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.

[0067] Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software, or can be implemented by the way of software combined with necessary hardware. Therefore, the technical solutions according to the embodiments of the present application can be embodied in the form of a software product, and the software product can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, a terminal device, or a network device, etc.) to execute the method according to the embodiments of the present application.

[0068] In an exemplary embodiment of the present application, there is also provided a computer-readable storage medium, on which a program product capable of implementing the above method of this specification is stored. In some possible implementation manners, various aspects of the present application can also be implemented in the form of a program product, which includes program code. When the program product runs on a terminal device, the program code is used to enable the terminal device to execute the steps according to various exemplary embodiments of the present application described in the above "Exemplary Method" section of this specification.

[0069] The program product can adopt any combination of one or more readable media. The readable media can be a readable signal medium or a readable storage medium. The readable storage medium can, for example, but not be limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0070] A computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, carrying readable program code. Such a propagated data signal may take many forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. The readable signal medium may also be any readable medium other than a readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device.

[0071] The program code contained on the readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0072] The program code for performing the operations of this application may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computing device, partly on the user's device, as a stand-alone software package, partly on the user's computing device and partly on a remote computing device, or entirely on the remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user's computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or, alternatively, may be connected to an external computing device (e.g., through the Internet using an Internet service provider).

[0073] In addition, the above-mentioned drawings are only schematic illustrations of the processes included in the method according to the exemplary embodiments of the present application, and are not for limiting purposes. It is easy to understand that the processes shown in the above-mentioned drawings do not indicate or limit the chronological order of these processes. Additionally, it is also easy to understand that these processes may be executed synchronously or asynchronously, for example, in multiple modules.

[0074] It should be noted that although several modules or units of devices for action execution are mentioned in the above detailed description, such a division is not mandatory. In fact, according to the embodiments of the present application, the features and functions of two or more of the above-mentioned modules or units may be embodied in one module or unit. Conversely, the features and functions of one module or unit described above may be further divided and embodied by multiple modules or units.

[0075] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present application should be covered by the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.

Claims

1. A server intrusion detection method, characterized in that, The method includes: At each preset collection time point, collect the operation information of the server to be detected; wherein, the operation information includes: system log information, network traffic information, and system performance information; Perform feature extraction for key rule mining on the system log information and the network traffic information, and perform feature extraction of time series on the system performance information to obtain an initial feature data list; wherein, the initial feature data list includes a number of initial operation feature data; each initial operation feature data has a corresponding operation feature; According to the historical feature data matrix corresponding to the historical feature data of the server to be detected and the server status label, obtain a correlation coefficient vector; wherein, the historical feature data matrix includes a number of historical data samples; each historical data sample has a corresponding number of historical feature data; each historical feature data has a corresponding operation feature; the correlation coefficient vector is used to describe the correlation coefficient between each operation feature and the server status label; According to the correlation coefficient vector and the initial operation feature data list, obtain a target operation feature vector; According to the target operation feature vector and the server status classification model, determine whether the server to be detected is currently invaded.

2. The server intrusion detection method according to claim 1, wherein The feature extraction for key rule mining on the system log information includes: Convert the system log information into a log transaction set; wherein, the log transaction set contains a number of log transactions; each log transaction has a corresponding event list and a first preset time window; each event list contains a number of events; the time corresponding to each event is within the range of the first preset time window of the corresponding log transaction; According to the preset minimum support and minimum confidence thresholds, obtain a number of combinations of log events with the number of co-occurrences greater than the preset co-occurrence quantity, and generate a number of association rules; According to the support, confidence, and lift of each association rule, determine a target association rule for feature extraction among the number of association rules; wherein, each association rule has an association degree score; the target association rule is the association rule with the highest association degree score; the association degree score is positively correlated with the support, confidence, and lift.

3. The server intrusion detection method according to claim 1, characterized in that The feature extraction for key rule mining on the network traffic information includes: Obtain a number of intermediate traffic pairs; each intermediate traffic pair consists of two servers; each intermediate traffic pair includes the server to be detected; each intermediate traffic pair has a corresponding IP address information pair and port information pair; the source IP address or destination IP address of each intermediate traffic pair is the IP address of the server to be detected; the source port number or target port number of each intermediate traffic pair is the port number of any one of the several ports of the server to be detected; According to the traffic correlation of a number of intermediate traffic pairs within a second preset time window, obtain at least one target traffic pair; wherein, the traffic correlation of the target traffic pair is greater than the preset traffic correlation threshold; the traffic correlation includes IP traffic correlation and port traffic correlation; According to the IP address and port number corresponding to each target traffic, obtain a network traffic association graph; wherein, each IP address and each port number are nodes; Perform feature extraction on the network traffic association graph.

4. The server intrusion detection method according to claim 1, wherein Perform feature extraction on the time series of the system performance information, including: Obtain a number of time series curves based on the system performance information; Fit a number of time series curves according to a polynomial function to obtain the coefficients corresponding to the polynomial function; Perform feature extraction on the time series curves and the coefficients corresponding to the polynomial function.

5. The server intrusion detection method according to claim 1, wherein, The obtaining of the target operation feature vector according to the correlation coefficient vector and the initial operation feature data list includes: Sort each initial operation feature in the initial operation feature data list according to the corresponding average correlation coefficient according to the correlation coefficient vector; Determine the initial operation features ranked in the top preset number as the target operation features to obtain the target operation feature vector.

6. The server intrusion detection method according to claim 1, wherein After collecting the operation information of the server to be detected every time a preset collection time point is reached, the method further includes: Preprocess the operation information.

7. The server intrusion detection method according to claim 1, characterized in that After determining whether the server to be detected is currently invaded according to the target operation feature vector and the server status classification model, the method further includes: When an intrusion event is detected, generate an alarm message and send the alarm message to the target display device.

8. An intrusion detection device for a server, characterized in that, The device includes: A collection unit for collecting the operation information of the server to be detected every time a preset collection time point is reached; wherein, the operation information includes: system log information, network traffic information, and system performance information; An extraction unit for performing feature extraction of key rule mining on the system log information and the network traffic information, and performing feature extraction of time series on the system performance information to obtain an initial feature data list; wherein, the initial feature data list includes a number of initial operation feature data; each initial operation feature data has a corresponding operation feature; A vector acquisition unit for obtaining a correlation coefficient vector according to the historical feature data matrix corresponding to the historical feature data of the server to be detected and the server status label; wherein, the historical feature data matrix includes a number of historical data samples; each historical data sample has a corresponding number of historical feature data; each historical feature data has a corresponding operation feature; the correlation coefficient vector is used to describe the correlation coefficient between each operation feature and the server status label; A target vector determination unit for obtaining a target operation feature vector according to the correlation coefficient vector and the initial operation feature data list; An intrusion determination unit for determining whether the server to be detected is currently invaded according to the target operation feature vector and the server status classification model.

9. A non-transitory computer-readable storage medium, characterized in that, At least one instruction or at least one program is stored in the storage medium, and the at least one instruction or the at least one program is loaded and executed by a processor to implement the method according to any one of claims 1-7.

10. An electronic device, characterized in that, It includes a processor and the non-transitory computer-readable storage medium described in claim 9.

Citation Information

Patent Citations

  • Server network behavior description method

    CN105071985A

  • Multi-stage network attack detection method based on word embedding

    CN112019497A

  • Business risk prediction method and device, computer equipment and storage medium

    CN114662570A

  • Distributed network data processing system and method based on cloud computing

    CN119316182A

  • Artificial intelligence-based government and enterprise gateway log analysis method, device and equipment

    CN119862567A