Campus Internet of Things-oriented multi-modal traffic anomaly identification and defense method
By refining partitioning in the campus Internet of Things and deploying traffic feature acquisition nodes, calculating partition abnormality index and boundary fragility index, combined with machine learning models, the traffic abnormality identification and defense in the campus Internet of Things environment is achieved, solving the problems of insufficient detection and diffusion hysteresis in the existing technology, and improving identification accuracy and defense capabilities.
Patent Information
- Application Number
- CN202510573327.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-06
- Publication Date
- 2025-07-18
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
It is difficult for the prior art to realize real-time and accurate identification and defense of traffic anomalies in campus Internet of Things environments, especially in the case of large number of devices, diverse communication modes and complex cross-region communications. Traditional methods have problems such as insufficient detection sensitivity, high false alarm rate and delayed response to abnormal diffusion.
The campus IoT partition is refined into multiple microparticle subunit areas, the traffic feature acquisition node is deployed, the multi-modal traffic feature data is collected, and the partition dynamics index and boundary fragility index are calculated, risk levels are generated in combination with machine learning models, and dynamic regulation operations are performed, such as limiting communication rates, increasing authentication mechanisms and isolating high-risk interaction paths.
It improves the accuracy and sensitivity of traffic abnormality recognition, effectively suppresses abnormal spread, and enhances the accuracy and autonomous adaptability of defense systems in the Internet of Things environment on campus.
Smart Images

Figure CN120342728A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of Internet of Things security technology. More specifically, the present invention relates to a multi-modal traffic anomaly recognition and defense method for campus Internet of Things. Background Art
[0002] With the rapid popularization of Internet of Things technology in campus scenarios, various intelligent terminal devices have been widely deployed in different functional areas such as dormitory areas, experimental areas, and office areas, forming a complex, dense, and dynamically changing Internet of Things communication network structure. Due to the large number of devices, diverse communication modes, and significant differences in application scenarios, the traffic anomaly detection and defense work in the campus Internet of Things environment faces new challenges. Traditional anomaly recognition methods based on single communication characteristics or coarse-grained global analysis are difficult to meet the requirements of real-time performance, accuracy, and zonal prevention and control.
[0003] In the prior art, methods for detecting Internet of Things traffic anomalies mainly focus on single-modal feature analysis, relying on single feature indicators such as fixed communication frequency, packet anomaly rate, or interaction duration to judge risks. As a result, in the actual campus environment with high feature concealment and complex and changeable attack methods, there are problems such as insufficient detection sensitivity, high false alarm rate, and delayed response to anomaly diffusion. At the same time, the campus is divided into multiple relatively independent zones with legitimate cross-zone communication. Existing detection means lack the ability to conduct fine-grained monitoring and dynamic risk assessment of changes in cross-subunit traffic interaction behaviors. Once an initial infection occurs in a local area such as a dormitory area, abnormal traffic can easily spread to important areas such as experimental areas and office areas through legitimate communication channels such as normal data exchange among students, causing large-scale abnormal propagation. Therefore, the present invention proposes a multi-modal traffic anomaly recognition and defense method for campus Internet of Things to solve the above problems.
[0004] To achieve the above object, the present invention provides the following technical solutions: A multi-modal traffic anomaly recognition and defense method for campus Internet of Things, comprising the following steps: Step 1: Divide each independent zone of the campus Internet of Things into multiple micro-particle sub-unit areas, deploy traffic feature acquisition nodes for each sub-unit, and collect traffic feature data including communication frequency, packet size, interaction duration, and anomaly trigger marks; Step 2: Continuously monitor the traffic interaction status of each sub-unit and the interaction pairs formed by its corresponding sub-units through the traffic feature acquisition nodes, extract the communication frequency change rate, packet anomaly ratio, and interaction duration anomaly offset as a risk feature data group, and judge whether to enter the risk assessment process according to the set trigger threshold conditions; Step 3: In the risk assessment process, calculate the partition anomaly index and the boundary vulnerability index for each interaction pair respectively as the quantitative basis for evaluating the degree of interaction risk; Step 4: Use the partition change index and the boundary vulnerability index corresponding to each interaction pair as inputs and feed them into a pre-trained machine learning model to generate the risk level corresponding to the interaction pair. The risk levels are subdivided into low risk, medium risk, and high risk. Step 5: Perform dynamic regulation operations based on the generated risk levels. The regulation operations include limiting the communication rate, adding an authentication mechanism, and isolating high-risk interaction paths.
[0005] In a preferred embodiment, in Step 1, the traffic feature collection node performs time-window-based segmentation on traffic feature data such as communication frequency, packet size, interaction duration, and anomaly trigger marks, and extracts a time-segmented feature set according to a preset time-window length to enhance the time sensitivity of traffic interaction state changes and the accuracy of extracting risk feature data groups.
[0006] In a preferred embodiment, in Step 2, the traffic feature collection node continuously monitors the traffic interaction states of each sub-unit and the interaction pairs formed by the corresponding sub-units. During the monitoring process, the following three indicators are obtained: the communication frequency change rate is calculated by the ratio of the change amplitude of the number of packets sent per unit time to the reference communication frequency; the packet anomaly ratio is calculated by the ratio of the number of abnormal packets to the total number of packets per unit time; the interaction duration anomaly offset is calculated by the ratio of the difference between the current interaction duration and the historical average duration. Based on these three indicators, a risk feature data group is extracted in real time. During the extraction process, the scales of the indicators are unified according to a unified normalization standard, and a weighted feature enhancement strategy is adopted to amplify the feature changes deviating from normal communication behavior, thereby improving the representation accuracy of the risk feature data group. Finally, according to the set trigger threshold conditions, the risk change trend of each interaction pair is determined to control whether to enter the subsequent risk assessment process.
[0007] In a preferred embodiment, in Step 2, the set trigger threshold conditions generate corresponding single-item risk scores based on the communication frequency change rate, the packet anomaly ratio, and the interaction duration anomaly offset respectively. Each single-item risk score is weighted and integrated according to a preset sub-item weight to obtain the comprehensive risk score of the interaction pair. When the comprehensive risk score exceeds the preset comprehensive threshold, it is determined as a high-risk interaction pair and triggers the entry into the risk assessment process. During the calculation of the comprehensive risk score, a risk change trajectory curve is established for each interaction pair. The risk change trajectory curve is formed by recording the change trends of single-item risk scores within consecutive time slices. By dynamically comparing the slope of the trajectory curve with the set reference slope, if the slope of the trajectory curve is greater than the set reference slope, it is also determined as a high-risk interaction pair and triggers the entry into the risk assessment process.
[0008] In a preferred embodiment, in step three, the calculation of the partition anomaly index includes the following steps: Step S1, for each interaction pair, within a set time window, record the sequence of the change rate of communication frequency in consecutive time slices, calculate the communication frequency deviation value within each time slice based on the reference communication frequency, and obtain the communication frequency offset curve; Step S2, based on the sequence of the abnormal ratio of data packets collected within the time window, calculate the change amplitude of the abnormal ratio between adjacent time slices to form the abnormal fluctuation curve; Step S3, based on the abnormal offset sequence of the interaction duration collected within the time window, calculate the change slope of the duration deviation between adjacent time slices to obtain the duration drift curve; Step S4, linearly combine the communication frequency offset curve, the abnormal fluctuation curve, and the duration drift curve according to the preset feature fusion rule to generate a joint dynamic change curve, and calculate the total change energy of the curve within the time window. The total change energy is used as the value of the partition anomaly index. The higher the partition anomaly index, the greater the degree of change in the traffic behavior of the interaction pair.
[0009] In a preferred embodiment, in step three, the calculation of the boundary vulnerability index includes the following steps: Step W1, for each interaction pair, based on the change rate of communication frequency recorded by the traffic feature acquisition node, within a set time window, statistically calculate the standard deviation of the number of data packets per unit time, and form a communication density fluctuation curve with the change of the standard deviation over time as the basic communication fluctuation model; Step W2, based on the abnormal ratio of data packets, identify the continuous time period with a sharp rise in the abnormal ratio within a preset short time on the communication density fluctuation curve, define this time period as the local outbreak abnormal segment, and the set time window consists of multiple preset short times; Step W3, in the local outbreak abnormal segment, use the abnormal offset data of the interaction duration to calculate the cumulative increment of the duration offset change, and draw the abnormal expansion trend line with the change of the increment over time; Step W4, calculate the correlation coefficient between the change rate of the abnormal expansion trend line and the change amplitude of the communication density fluctuation curve, and determine the vulnerability degree of the interaction pair boundary during the local abnormal propagation according to the level of the correlation coefficient, and finally generate the boundary vulnerability index. The higher the boundary vulnerability index, the more easily the interaction pair boundary is affected by the abnormal traffic diffusion.
[0010] In a preferred embodiment, during the calculation of the partition anomaly index, the feature fusion rule of the joint dynamic change curve adopts one of the following multiple methods: Method 1: Linear weighted fusion. A combined dynamic change curve is generated by directly adding the preset weights of the communication frequency offset curve, the abnormal fluctuation curve, and the duration drift curve. Method 2: Rate-of-change sensitive fusion. Weighted terms are calculated based on the change slopes of the respective curves, and curves with larger change slopes are given higher weights during fusion to highlight short-term rapid change characteristics. Method 3: Abnormal frequency-dominated fusion. The fusion weights of the respective curves are adjusted based on the density of the number of fluctuations in the abnormal ratio of data packets, and the weight of the abnormal fluctuation curve is enhanced during periods of high abnormal occurrence. The basis for selecting the feature fusion rule is as follows: When the standard deviation of the communication frequency change rate in the risk feature data group within a set time window is less than the preset stability threshold, and the absolute value of the difference in the communication frequency change rate between any two consecutive time slices is lower than the reference difference threshold, linear weighted fusion is selected. When the abnormal offset of the communication frequency change rate or the interaction duration continuously increases in the same direction in three or more consecutive time slices within a set time window, and the growth amplitude exceeds the set growth rate threshold, rate-of-change sensitive fusion is selected. When the number of abnormal fluctuations of the data packet abnormal ratio within a set time window exceeds the set frequency threshold, and the fluctuation amplitude exceeds the abnormal ratio fluctuation amplitude threshold for more than two consecutive times, abnormal frequency-dominated fusion is selected.
[0011] In a preferred embodiment, in step four, a machine learning classification model trained with historical interaction data is used. The partition movement index and the boundary vulnerability index corresponding to each interaction pair are used as input features. After the input features are standardized, they enter the machine learning classification model for inference, and the risk level corresponding to the interaction pair is output. The risk level is subdivided into low risk, medium risk, and high risk. The machine learning classification model is selected from one of the decision tree model, the random forest model, or the lightweight multi-layer perceptron model. During the model training process, based on the labeled historical interaction pair risk data set, the parameter optimization is completed using the supervised learning method, with the goal of minimizing the classification error of the interaction pair risk level as the optimization objective. In the inference stage, the machine learning classification model calculates the confidence scores corresponding to each risk level based on the combined features of the input partition movement index and the boundary vulnerability index, and selects the risk level with the highest confidence as the risk output result of the current interaction pair.
[0012] In a preferred embodiment, in step five, dynamic regulation operations are performed according to the risk level generated in step four. The dynamic regulation operations include: When the risk level of the interaction pair is low risk, an operation to increase the authentication mechanism is performed, and the controllability of the communication behavior is improved by introducing an additional verification process during the communication process of the interaction pair. When the risk level of the interaction pair is medium risk, perform the operation of limiting the communication rate. Based on the partition change index corresponding to the interaction pair, according to the preset rate adjustment rule, limit the traffic rate whose communication frequency change rate exceeds the normal range, and suppress the abnormal expansion trend; When the risk level of the interaction pair is high risk, perform the operation of isolating the high-risk interaction path. First, combine the partition change index and the boundary vulnerability index of the interaction pair, and screen out the interaction pairs whose partition change index is higher than the first threshold and the boundary vulnerability index is higher than the second threshold. Prioritize the interaction pairs that meet the screening conditions for physical isolation or logical disconnection operations to cut off the abnormal diffusion channel and prevent cross-unit abnormal propagation; for the interaction pairs that do not meet the screening conditions but are still determined to be high risk, according to the comprehensive score of the partition change index and the boundary vulnerability index, in the order from high to low according to the risk comprehensive score, perform the superposition control measures of communication rate limit and additional authentication mechanism to suppress the potential abnormal diffusion risk; The comprehensive score refers to the risk assessment value calculated by the weighted linear combination method based on the partition change index and the boundary vulnerability index of the interaction pair. The specific calculation method is: Comprehensive score = partition change index × first weighting coefficient + boundary vulnerability index × second weighting coefficient, and the first weighting coefficient and the second weighting coefficient are set according to the contribution degree of each index to the abnormal propagation risk.
[0013] The technical effects and advantages of the present invention: By refining the independent partitions of each campus Internet of Things into multiple micro-particle sub-unit areas and deploying traffic feature acquisition nodes inside each sub-unit, the present invention can achieve high-precision acquisition of multi-modal traffic features such as communication frequency, packet size, interaction duration, and abnormal trigger marks. Based on the fine-grained data acquisition, it not only improves the time sensitivity and spatial resolution of the traffic interaction change state, but also provides a rich and multi-dimensional feature basis for subsequent abnormal risk identification, significantly enhancing the early perception ability of local abnormal fluctuations and potential diffusion signs.
[0014] By extracting the risk feature data group composed of the communication frequency change rate, the packet abnormality ratio, and the abnormal offset of the interaction duration, and calculating the partition change index and the boundary vulnerability index respectively in the risk assessment process, the present invention can achieve double quantitative modeling of the abnormal dynamic change degree of the interaction pair and the cross-unit propagation vulnerability degree. Combining multiple feature fusion rules and the dynamic trigger mechanism of the risk change trajectory, the abnormal detection process has an adaptive characteristic, can quickly respond and adjust to different types and different stages of abnormal behaviors, and greatly improves the accuracy and sensitivity of traffic abnormal identification in the campus Internet of Things environment.
[0015] By using the partition anomaly index and the boundary vulnerability index as input features, feeding them into a pre-trained machine learning classification model to generate the risk level of interaction pairs, and performing dynamic regulation operations such as limiting the communication rate, adding an authentication mechanism, and isolating high-risk interaction paths according to the risk level, the intelligent hierarchical control and hierarchical response to abnormal risks can be realized. By dynamically adjusting the communication frequency, authentication intensity, and interaction channel status, the abnormal diffusion speed is effectively suppressed, the cross-unit propagation risk is reduced, and the accuracy, real-time performance, and self-adaptive ability of the traffic anomaly defense system in the campus Internet of Things environment are comprehensively improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] For the convenience of those skilled in the art to understand, the present invention will be further described below in conjunction with the accompanying drawings; Figure 1 It is a schematic diagram of the multi-modal traffic anomaly recognition and defense method for the campus Internet of Things in the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0017] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the protection scope of the present invention.
[0018] Referring to Figure 1 The following embodiments are obtained: Embodiment 1: In the present invention, the independent partition of the campus Internet of Things refers to a set of sub-regions formed based on the physical area division or functional area division within the campus, and having relatively independent network communication characteristics and device deployment characteristics. The independent partitions usually include, but are not limited to, dormitory areas, experimental areas, teaching building areas, office building areas, library areas, and public activity areas. The intelligent terminal devices, communication behavior patterns, and data flow characteristics within each partition have high consistency. At the same time, the partitions are interconnected through gateways, switching devices, or local networks to achieve limited cross-region communication.
[0019] Due to its unique application requirements and management mode, the campus Internet of Things environment presents the characteristics of strong device heterogeneity, diverse application scenarios, high communication density, and complex interaction modes. The dormitory area is mainly composed of personal terminal devices, and the communication behavior is highly individualized and dynamic; a large number of scientific research instruments and high-performance computing devices are centrally deployed in the experimental area, and the traffic characteristics are stable and the load is high; the office area and the teaching area focus on resource access and management communication, and have clear business communication modes. This communication behavior difference naturally formed due to functional partitions makes each independent partition have obvious spatial locality in traffic abnormal behavior characteristics.
[0020] Therefore, the present invention proposes a multi-modal traffic anomaly recognition and defense method for campus Internet of Things. First, each independent partition is refined into multiple micro-particle sub-unit regions, and traffic feature collection nodes are deployed in each sub-unit to collect traffic feature data including communication frequency, packet size, interaction duration, and anomaly trigger marks. During the collection process, the data is processed in segments based on a time window to extract a time-segmented feature set to enhance the sensitivity to temporal changes. Subsequently, continuously monitor the traffic interaction status of each sub-unit and the interaction pairs formed by its corresponding sub-units, extract the communication frequency change rate, packet anomaly ratio, and interaction duration anomaly offset, and generate a risk feature data group based on a unified normalization standard and a weighted feature enhancement strategy. By calculating the comprehensive risk score and dynamically comparing the risk change trajectory curve, it is determined whether to enter the subsequent risk assessment process.
[0021] In the risk assessment stage, for each interaction pair, calculate the partition anomaly index and the boundary vulnerability index respectively as the quantitative basis for evaluating the interaction risk level. Among them, the partition anomaly index is generated by constructing a communication frequency offset curve, an abnormal fluctuation curve, and a duration drift curve and linearly combining them with a feature fusion rule to generate a joint dynamic change curve, and then taking a value based on the total change energy; the boundary vulnerability index is generated by extracting local outbreak abnormal segments based on the communication density fluctuation model, combining the change characteristics of the abnormal expansion trend line, and through correlation analysis, reflecting the sensitivity of the interaction pair boundary to abnormal diffusion. The feature fusion rule dynamically selects the optimal fusion method according to the standard deviation, growth trend, and abnormal fluctuation frequency of the risk feature data group to ensure the accuracy and sensitivity of abnormal feature extraction.
[0022] By taking the partition anomaly index and the boundary vulnerability index of each interaction pair as input features and feeding them into a machine learning classification model trained with historical interaction data, the corresponding risk level is generated. The risk level is divided into low risk, medium risk, and high risk. According to different risk levels, dynamic control operations are performed. For low-risk interaction pairs, the security is strengthened by adding an authentication mechanism; for medium-risk interaction pairs, the diffusion risk is controlled by limiting the communication rate; for high-risk interaction pairs, first, the interaction pairs that meet the isolation conditions are screened based on the partition anomaly index and the boundary vulnerability index and are preferentially physically isolated or logically disconnected; for the interaction pairs that do not meet the isolation conditions, they are sorted from high to low according to the comprehensive score, and a superimposed control measure of communication rate limitation and additional authentication mechanism is adopted to ensure that the interaction pairs at different risk levels obtain targeted and hierarchical protection processing, effectively improving the overall traffic anomaly recognition and defense ability of the campus Internet of Things. Specifically, it includes the following steps: Step 1: Divide the independent partitions of each campus Internet of Things into multiple micro-sized sub-unit areas, deploy traffic feature collection nodes for each sub-unit, and collect traffic feature data including communication frequency, packet size, interaction duration, and anomaly trigger marks. Step 2: Continuously monitor the traffic interaction status of each sub-unit and its corresponding interaction pair through the traffic feature collection nodes, extract the communication frequency change rate, packet anomaly ratio, and interaction duration anomaly offset as a risk feature data group, and determine whether to enter the risk assessment process according to the set trigger threshold conditions. Step 3: In the risk assessment process, calculate the partition anomaly index and the boundary vulnerability index for each interaction pair respectively, as a quantitative basis for evaluating the degree of interaction risk. Step 4: Use the partition anomaly index and the boundary vulnerability index corresponding to each interaction pair as inputs, and feed them into the pre-trained machine learning model to generate the risk level of the corresponding interaction pair. The risk level is subdivided into low risk, medium risk, and high risk. Step 5: Perform dynamic regulation operations according to the generated risk level. The regulation operations include limiting the communication rate, increasing the authentication mechanism, and isolating high-risk interaction paths.
[0023] In Step 1, by further refining the independent partitions of each campus Internet of Things into multiple micro-sized sub-unit areas and deploying traffic feature collection nodes within each sub-unit, fine-grained perception of network communication behavior can be achieved. By collecting basic traffic feature data such as communication frequency, packet size, interaction duration, and anomaly trigger marks, a comprehensive, continuous, and quantifiable basic data set of sub-unit interactions is established, providing high spatio-temporal resolution data support for subsequent risk identification and effectively avoiding the problem of hidden anomalies in traditional coarse-grained monitoring.
[0024] In Step 2, through the traffic feature collection nodes, continuously monitor the traffic interaction status of each sub-unit and its corresponding interaction pair, and further extract three core indicators: the communication frequency change rate, the packet anomaly ratio, and the interaction duration anomaly offset, to form a risk feature data group. Based on the set trigger threshold conditions, dynamically judge the risk trend of the interaction pair, which can timely screen out the interaction relationships with potential abnormal diffusion tendencies, ensuring that the risk assessment process is only started when the risk changes significantly, and improving the overall system resource utilization efficiency and response timeliness.
[0025] In Step 3, for the interaction pairs that have triggered the risk assessment process, calculate the partition anomaly index and the boundary vulnerability index respectively, which can accurately reflect the change range of internal traffic behavior of the interaction pair and the abnormal propagation sensitivity of the interaction boundary in a quantitative way. This step can transform complex multi-dimensional risk feature data into numerical indicators with clear physical meanings and directly comparable, providing a reliable input basis for subsequent risk level inference based on machine learning models and dynamic regulation decisions, and realizing the accurate quantitative characterization of potential abnormal diffusion risks.
[0026] In step four, the partition change index and the boundary vulnerability index corresponding to each interaction pair are used as the normalized input features and fed into the machine learning classification model trained with historical interaction data. Using the inference ability optimized by supervised learning, the risk level classification of the corresponding interaction pair is generated. By subdividing into three levels: low risk, medium risk, and high risk, it is possible to achieve fast, intelligent, and hierarchical identification of interaction pairs with different risk levels, laying a foundation for formulating differentiated dynamic defense strategies subsequently and effectively improving the accuracy and pertinence of abnormal defense measures.
[0027] In step five, according to the risk level results generated by the machine learning model, corresponding dynamic regulation operations are executed, including enhancing the communication security of low-risk interaction pairs by adding an authentication mechanism, suppressing the abnormal diffusion trend of medium-risk interaction pairs by limiting the communication rate, and blocking potential cross-unit propagation links by preferentially isolating high-risk interaction paths. By dynamically adjusting the defense strategy by combining the risk level and the real-time feature evaluation results, it is possible to achieve an adaptive response to the complex traffic anomaly situation in the campus Internet of Things environment and comprehensively improve the system's anomaly tolerance ability and overall security.
[0028] In step one, the traffic feature collection node performs segmented processing on traffic feature data such as communication frequency, packet size, interaction duration, and anomaly trigger marker based on a time window, and extracts the sub-period feature set according to the preset time window length to enhance the time sensitivity of the traffic interaction state change and the accuracy of the risk feature data group extraction.
[0029] Among them, the communication frequency refers to the number of data packets sent or received by a subunit per unit time, which is used to reflect the communication activity; the packet size refers to the amount of information data carried by a single data packet, usually in bytes, which is used to characterize the communication load level; the interaction duration refers to the length of time that a subunit maintains a connection state after establishing a communication connection with other subunits, which can reflect the stability and persistence of the interaction behavior; the anomaly trigger marker refers to an abnormal event record automatically generated during the communication process based on preset anomaly detection rules (such as abnormal packet format, abnormal communication behavior), which is used to capture potential abnormal activity signals.
[0030] During the process of collecting traffic feature data, the traffic feature collection node performs segmented processing according to a preset time window length. A time window refers to a fixed time period that is continuously divided during the collection process. For example, it can be set to a window every five minutes or every ten minutes to batch-organize the real-time collected traffic feature data. Segmented processing means separately summarizing and statistically analyzing the communication frequency, packet size, interaction duration, and abnormal trigger marker data collected within each time window to form corresponding sub-period feature sets. Each sub-period feature set represents the general characteristics of the communication behavior of the sub-units within that time window.
[0031] In specific implementation, for example, if the time window is set to five minutes, a certain sub-unit sends five hundred packets within a certain time window, the average packet size is one thousand bytes, establishes communication connections with three other sub-units, the average duration of each connection is two minutes, and one abnormal trigger event is detected during this period. Then the sub-period feature set corresponding to this time window is recorded as: communication frequency five hundred times, packet size one thousand bytes, interaction duration two minutes, and number of abnormal triggers once.
[0032] Through this segmented processing based on time windows, it can effectively enhance the time sensitivity of the change in the traffic interaction state, that is, it can capture the change trend of short-term communication behavior and improve the response ability to sudden anomalies. At the same time, the summarized sub-period feature sets provide standardized and time-aligned data inputs for the extraction of subsequent risk feature data groups, significantly improving the accuracy and timeliness of risk identification and subsequent anomaly detection processes, and avoiding data deviation problems caused by mixed traffic feature collection times or inconsistent statistical periods.
[0033] In step two, the traffic feature collection node continuously monitors the traffic interaction state of each interaction pair composed of a sub-unit and its corresponding sub-unit, aiming to dynamically capture the change characteristics of the communication behavior between sub-units. An interaction pair refers to a two-way communication relationship established between a sub-unit and a corresponding sub-unit, and the traffic interaction state refers to the change situation of the communication characteristics of this interaction pair within a certain time window.
[0034] During the monitoring process, the following three metrics are obtained for subsequent analysis: the communication frequency change rate, the abnormal packet ratio, and the abnormal deviation of the interaction duration. The communication frequency change rate refers to the ratio of the change amplitude of the number of packets sent per unit time to the baseline communication frequency, which is used to reflect the degree of fluctuation of communication activity caused by the interaction; the baseline communication frequency refers to the average communication frequency per unit time in the normal state obtained from historical statistics. The abnormal packet ratio refers to the ratio between the number of abnormal packets and the total number of packets per unit time, which is used to measure the occurrence density of abnormal events during the communication process; abnormal packets refer to packets that do not conform to the normal format, timing, or content standards. The abnormal deviation of the interaction duration refers to the proportion of the difference between the current interaction duration and the historical average duration, which is used to reveal the change in the stability of the interaction relationship; the historical average duration refers to the average holding time of connections established under normal communication conditions.
[0035] Based on the above three metrics, the risk characteristic data group corresponding to each interaction pair is extracted in real time. During the extraction process, in order to ensure that characteristic data with different dimensions and magnitudes have a unified comparison basis, first, the communication frequency change rate, the abnormal packet ratio, and the abnormal deviation of the interaction duration are uniformly scaled according to a unified normalization standard. The normalization standard means linearly stretching or compressing each piece of characteristic data according to the historical statistical range or the set upper and lower limit intervals, so that its numerical distribution is within a unified standard interval, such as between zero and one, to eliminate the influence caused by the difference in the value ranges of different characteristic indicators.
[0036] After the normalization process, in order to further improve the sensitivity of the risk characteristic data group to abnormal behavior changes, a weighted feature enhancement strategy is adopted. The weighted feature enhancement strategy means that based on the different correlations between specific characteristic indicators and communication anomaly risks, different weighting coefficients are assigned to each feature, and the original normalized characteristic data is amplified or reduced. Specifically, when a certain characteristic indicator (such as the communication frequency change rate) is verified to be highly sensitive to communication anomalies in historical data analysis, a higher weighting coefficient is assigned to this feature to highlight its change amplitude in the risk characteristic data group; on the contrary, a lower weighting coefficient is assigned to the characteristic indicator with lower change sensitivity. The specific weighting coefficient values can be determined by the expert assignment method. In this way, when synthesizing the risk characteristic data group, the characteristic changes deviating from normal communication behavior can account for a larger proportion in the overall characteristic vector, thereby enhancing the early perception ability of potential abnormal risks.
[0037] In specific implementation, for example, set the weighting coefficient of the communication frequency change rate to 0.5, the weighting coefficient of the data packet anomaly ratio to 0.3, and the weighting coefficient of the abnormal deviation of the interaction duration to 0.2. If the normalized eigenvalue of the three items within a certain time window is 0.4, 0.6, and 0.3 respectively, the weighted eigenvalues are 0.2, 0.18, and 0.06 respectively, forming a risk feature data group. It can be seen from this that in the risk feature data group, the communication frequency change rate is amplified due to the high weight, and its impact on subsequent risk determination is more significant.
[0038] Finally, based on the set trigger threshold conditions, the risk change trend of each interaction pair is dynamically determined. The trigger threshold conditions refer to the comprehensive risk score or change trend calculated based on the extraction results of the risk feature data group. When the comprehensive risk score exceeds the preset value, or the slope of the risk change trajectory exceeds the reference standard, it is determined that the interaction pair enters the risk assessment process and enters the subsequent calculation stage of the partition anomaly index and the boundary vulnerability index.
[0039] In step two, the set trigger threshold conditions are used to determine whether there is a potential high-risk trend in the interaction pair, and the corresponding single-item risk scores are generated based on the three indicators of the communication frequency change rate, the data packet anomaly ratio, and the abnormal deviation of the interaction duration. The communication frequency change rate refers to the ratio of the change amplitude of the number of data packets sent per unit time to the reference communication frequency, and is used to evaluate the abnormal degree of communication activity; the data packet anomaly ratio refers to the ratio of the number of abnormal data packets to the total number of data packets per unit time, and is used to evaluate the abnormal density during the communication process; the abnormal deviation of the interaction duration refers to the ratio of the difference between the current interaction duration and the historical average duration, and is used to measure the change in the stability of the interaction relationship.
[0040] In the process of generating the single-item risk score, for each indicator, the deviation amount is measured based on its normalized value and the set normal range. Specifically, if the communication frequency change rate exceeds the normal range, a high-risk score is assigned to it proportionally; if the data packet anomaly ratio increases, the corresponding risk score is also given according to the deviation degree; when the abnormal deviation of the interaction duration is large, the score is also increased accordingly. After the three single-item risk scores are generated, they are weighted and synthesized according to the preset sub-item weights, and different weights are set for different indicators according to their importance in risk perception. For example, the weight of the communication frequency change rate can be set to 0.4, the weight of the data packet anomaly ratio is set to 0.35, and the weight of the abnormal deviation of the interaction duration is set to 0.25. After weighted synthesis, the comprehensive risk score of the interaction pair is obtained.
[0041] When the comprehensive risk score of an interaction pair exceeds the preset comprehensive threshold, it is determined that the interaction pair is a high-risk interaction pair, and the subsequent risk assessment process is directly triggered. The preset comprehensive threshold is a numerical boundary set according to the statistical analysis results of historical communication behaviors, which is used to distinguish normal fluctuations from abnormal diffusion trends.
[0042] During the calculation of the comprehensive risk score, a risk change trajectory curve is established for each interaction pair at the same time. The risk change trajectory curve refers to a curve plotted with time as the horizontal axis and the evolution of the single-item risk score over time as the vertical axis, which is used to dynamically reflect the change trend of the risk level of the interaction pair. Each point on the curve represents the corresponding risk score value within a specific time slice. By continuously recording the score changes in multiple time slices, a complete trajectory curve is formed.
[0043] After the risk change trajectory curve is established, it is further compared dynamically with the set reference slope through the slope of the trajectory curve. The slope of the trajectory curve refers to the ratio of the change in the risk score between two consecutive time slices to the change in time, which reflects the change rate of the risk score; the set reference slope is the standard change rate set based on the analysis of historical high-risk event data. If the slope of the trajectory curve exceeds the set reference slope in any continuous time segment, it is determined that the interaction pair has a sharp deterioration trend. Even if the comprehensive risk score does not reach the comprehensive threshold, it is also determined as a high-risk interaction pair, and the risk assessment process is immediately triggered.
[0044] For example, if the set reference slope is 0.1, and for a certain interaction pair, the risk scores in three consecutive time slices are 0.3, 0.45, and 0.65 respectively, and the slopes per unit time are 0.15 and 0.2 respectively, both of which exceed the reference slope standard. Thus, the rapid upward trend of the risk can be dynamically identified, and the risk response can be triggered in a timely manner to ensure early warning before the risk spreads on a large scale.
[0045] In Step 3, the calculation of the partition change index is used to quantify the severity of the change in the traffic behavior of the interaction pair within a certain time window. To achieve this purpose, the calculation of the partition change index includes the following specific steps: In Step S1, for each interaction pair, within the set time window, record the sequence of the change rate of the communication frequency in consecutive time slices. An interaction pair refers to the communication interaction relationship between a subunit and a corresponding subunit. The time window refers to a continuous time period artificially set in traffic monitoring, such as five minutes or ten minutes, which is used to segment and process the monitoring data. The change rate of the communication frequency refers to the ratio of the change amplitude of the number of data packets per unit time to the reference communication frequency, which reflects the fluctuation of the communication activity. The reference communication frequency refers to the historical average communication frequency of this interaction pair in the normal communication state. After recording the sequence of the change rate of the communication frequency, based on the reference communication frequency, calculate the communication frequency deviation value within each time slice, that is, the difference between the current communication frequency and the reference communication frequency, to form a communication frequency offset curve. The communication frequency offset curve describes the change trajectory of the communication activity level of this interaction pair within the time window.
[0046] In Step S2, based on the sequence of the abnormal ratio of the data packets collected within the time window, calculate the change amplitude of the abnormal ratio between adjacent time slices. The abnormal ratio of the data packets refers to the ratio of the number of abnormal data packets per unit time to the total number of data packets, which reflects the communication abnormal density. The change amplitude of the abnormal ratio refers to the absolute value of the difference between the abnormal ratio values of the data packets in two consecutive time slices, which can capture the fluctuations in the occurrence frequency and intensity of abnormal events. By calculating the change of the abnormal ratio in consecutive time slices, form an abnormal fluctuation curve. The abnormal fluctuation curve is used to describe the dynamic change pattern of the communication abnormal degree within the time window.
[0047] In Step S3, based on the sequence of the abnormal offset of the interaction duration collected within the time window, calculate the change slope of the duration deviation between adjacent time slices. The abnormal offset of the interaction duration refers to the proportion of the difference between the current interaction duration and the historical average interaction duration. The change slope of the duration deviation refers to the ratio of the change amount of the abnormal offset of the interaction duration in consecutive time slices to the time change amount, which is used to quantify the rate of change of the interaction stability. Through continuous calculation, obtain a duration drift curve. The duration drift curve reflects the dynamic trend of the change in the stability of the interaction relationship.
[0048] In step S4, the communication frequency offset curve, the abnormal fluctuation curve and the duration drift curve are linearly combined according to the preset feature fusion rules. Feature fusion rules refer to weighted combination methods set according to the importance and change sensitivity of different feature curves, including three strategies: linear weighted fusion, change rate sensitive fusion and abnormal frequency dominant fusion. Linear combination refers to the numerical weighted superposition according to the weight coefficients assigned to each curve to form a unified joint dynamic change curve. The joint dynamic change curve comprehensively reflects the overall dynamic change pattern of the interaction pair in terms of communication activity, abnormality and interaction stability.
[0049] Finally, after the joint dynamic change curve is generated, the total energy of the change of the curve within the time window is calculated. The total energy of change refers to the cumulative value of the sum of the squares of the change amplitudes of each time slice of the joint dynamic change curve, which is used to measure the overall intensity of the change in traffic behavior. The larger the total energy of change, the more drastic the change in traffic behavior of the interaction pair during the monitoring period. The value of the total energy of change is taken as the partition anomaly index. The higher the value of the partition anomaly index, the more significant the communication anomaly or interaction behavior mutation of the interaction pair exists, indicating a higher potential risk level.
[0050] In specific implementation, for example, the time window is set to five minutes, and each minute in the time period is taken as a time slice. The communication frequency change rate sequence of the interaction pair is recorded as 0.1, 0.3, 0.2, 0.4, and 0.5 respectively. The communication frequency offset curve is calculated by the reference communication frequency; at the same time, the abnormal ratio change of the data packet is collected to form an abnormal fluctuation curve; the abnormal offset of the interaction duration is synchronously collected to form a duration drift curve. According to the set feature fusion rules, the three curves are weighted and combined to generate a joint dynamic change curve. The square and cumulative sum of the change amplitude of each time slice are calculated, and the sum is the total change energy, which is used as the partition anomaly index value of the interaction pair in the time window.
[0051] In step three, the calculation of the boundary vulnerability index is used to evaluate the weakness of boundary protection during the local anomaly propagation process of interaction pairs, so as to quantify the sensitivity of interaction pairs to the impact of anomaly diffusion. To achieve this goal, the calculation of the boundary vulnerability index includes the following specific steps: In step W1, for each interaction pair, based on traffic characteristics, the change rate of the communication frequency recorded by the node is collected and statistically processed within a set time window. The change rate of communication frequency refers to the ratio of the change amplitude of the number of data packets sent per unit time to the reference communication frequency, and is used to measure the fluctuation of communication activity. The time window refers to a fixed time period defined for continuous monitoring and analysis, such as five minutes or ten minutes. Within the time window, the standard deviation of the number of data packets per unit time is statistically calculated. The standard deviation is a statistic that measures the dispersion degree of data distribution and can reflect the stability of communication behavior. A curve is plotted with the changing trend of the standard deviation over time. This curve is the communication density fluctuation curve, which is used to describe the fluctuation characteristics of the communication activity of the interaction pair in the time series. This curve also serves as the basic communication fluctuation model for subsequent analysis.
[0052] In step W2, based on the traffic characteristics, the packet anomaly ratio recorded by the node is collected, and local anomaly bursts are identified on the communication density fluctuation curve. The packet anomaly ratio refers to the ratio of the number of abnormal data packets to the total number of data packets per unit time, and is used to measure the anomaly intensity during the communication process. A short detection period is set, such as one to two minutes, and the time window is divided into multiple preset short time periods. If within a certain preset short time period, the packet anomaly ratio shows a sharp increase, that is, exceeds the set growth amplitude threshold, then this time period is marked as a local burst anomaly segment. A local burst anomaly segment refers to a continuous time period during which the communication anomaly rapidly intensifies within a short time, representing the start or acceleration of anomaly propagation.
[0053] In step W3, within the identified local burst anomaly segments, further extended feature analysis is carried out using the abnormal offset data of the interaction duration. The abnormal offset of the interaction duration refers to the proportion of the difference between the current interaction connection duration and the historical average duration, and is used to reflect the abnormal fluctuation of interaction stability. Within the local burst anomaly segment, the change increment of the abnormal offset of the interaction duration for each time slice is continuously calculated, and the cumulative increment sequence evolving over time is obtained by accumulation. An abnormal expansion trend line is plotted with the change of the cumulative increment value over time. The abnormal expansion trend line is used to reflect the cumulative diffusion impact of local burst anomaly events on interaction stability.
[0054] In step W4, calculate the correlation coefficient between the change rate of the abnormal expansion trend line and the change amplitude of the communication density fluctuation curve. The change rate refers to the ratio of the cumulative incremental change amount of the abnormal expansion trend line within consecutive time slices to the time change amount, and the change amplitude refers to the change amount of the standard deviation value of the communication density fluctuation curve within the same time slice. The correlation coefficient is used to quantify the linear correlation degree between two change sequences, with a value range from negative one to positive one. A positive correlation indicates that the two features change synchronously, a negative correlation indicates that the two features change in the opposite direction, and a zero correlation indicates that the two are unrelated. Based on the level of the correlation coefficient, determine the vulnerability degree of the interaction pair boundary during local abnormal propagation. The higher the correlation coefficient, the more sensitive the interaction pair boundary is to abnormal diffusion response and the weaker the protection ability.
[0055] Finally, generate a boundary vulnerability index based on the correlation coefficient value. The higher the value of the boundary vulnerability index, the more easily the interaction pair boundary is affected by local abnormal traffic diffusion, indicating a higher level of protection weakness in the overall communication network.
[0056] During specific implementation, for example, set the time window to ten minutes and divide it into five two-minute short time periods. The standard deviations of the collected communication frequency change rates are ten, twelve, eighteen, twenty, and fifteen in sequence; within the third to fourth short time periods, a sharp rise in the abnormal ratio of data packets is detected and marked as a local outbreak abnormal segment. Within this local outbreak abnormal segment, the cumulative incremental deviation of the interaction duration anomaly continuously increases, forming an obvious upward abnormal expansion trend line. Calculate the correlation coefficient between the change rate of the abnormal expansion trend line and the change amplitude of the communication density fluctuation, and obtain a value of 0.85, indicating a high positive correlation between the two. Therefore, the generated boundary vulnerability index is relatively high, indicating that there is a relatively high risk of local abnormal diffusion for this interaction pair.
[0057] In the calculation process of the partition movement index, the feature fusion rule of the combined dynamic change curve adopts one of the following multiple methods to fuse the communication frequency offset curve, the abnormal fluctuation curve, and the duration drift curve, so as to form a combined dynamic change curve reflecting the comprehensive dynamic change characteristics of the interaction: The first method is linear weighted fusion. Linear weighted fusion means directly performing a weighted summation process on the values of the three curves in the same time slice according to the preset weights of the communication frequency offset curve, the abnormal fluctuation curve, and the duration drift curve, to generate the combined dynamic change curve. Among them, the communication frequency offset curve is a curve formed by the evolution of the difference between the communication frequency change rate and the reference communication frequency over time. The abnormal fluctuation curve is a curve formed by the change of the abnormal ratio of data packets between adjacent time slices over time. The duration drift curve is a curve formed by the change slope of the abnormal offset of the interaction duration over time. In the process of linear weighted fusion, a fixed weight coefficient is set for each curve according to its importance to the overall communication anomaly dynamics. For example, the weight of the communication frequency offset curve is set to 0.4, the weight of the abnormal fluctuation curve is set to 0.35, and the weight of the duration drift curve is set to 0.25. The corresponding value of the combined dynamic change curve is obtained by superimposing according to this weight coefficient for each time slice. Linear weighted fusion is applicable to scenarios where the overall communication state is stable and the change amplitudes of each feature are evenly distributed, in order to maintain the balance of the contribution degrees of each feature.
[0058] The second method is rate-sensitive fusion. Rate-sensitive fusion means dynamically calculating the weighting terms based on the change slopes of the communication frequency offset curve, the abnormal fluctuation curve, and the duration drift curve, and assigning higher weights to the curves with larger change slopes during fusion. The change slope refers to the rate of change of the values of the feature curve between consecutive time slices, reflecting the short-term change trend of the feature index. The specific operation is to calculate the change slopes of the three curves respectively in each time slice, and dynamically allocate the fusion weights according to the magnitudes of their respective slopes. The larger the slope, the higher the weight. Then, the values of the three curves are weighted and superimposed according to the dynamic weights to generate the combined dynamic change curve. Rate-sensitive fusion can highlight the characteristic signals of short-term rapid changes and is applicable to scenarios where communication behaviors change rapidly or the initial signs of sudden anomalies appear.
[0059] Method 3 is anomaly frequency - dominant fusion. Anomaly frequency - dominant fusion means dynamically adjusting the fusion weights of feature curves based on the density of the fluctuation times of the anomaly ratio of data packets. During the period of frequent anomaly fluctuations, the weight of the anomaly - fluctuation curve is enhanced. The number of fluctuation times of the data - packet anomaly ratio refers to the number of times that the data - packet anomaly ratio continuously fluctuates beyond a preset amplitude threshold within a set time window. The specific operation is as follows: count the number of fluctuation times of the anomaly ratio within the time window. When the number of fluctuation times exceeds the preset frequency threshold, increase the weight of the anomaly - fluctuation curve in the fusion process and reduce the weight ratios of other curves. Then, perform weighted superposition according to the adjusted weights to generate a combined dynamic change curve. Anomaly frequency - dominant fusion can amplify the anomaly - feature signals during the period of high - frequency anomaly occurrences and is applicable to scenarios with high incidences of communication anomalies and accelerating potential propagation speeds.
[0060] The basis for selecting the feature - fusion rule is as follows: First, detect whether the standard deviation of the communication - frequency change rate in the risk - feature data group within a set time window is less than a preset stability threshold, and whether the absolute value of the difference in the communication - frequency change rate between any two consecutive time slices is lower than the reference - difference threshold. If both conditions are met, select linear - weighted fusion to maintain the balanced integration of each feature; when it is detected that the abnormal deviation of the communication - frequency change rate or the interaction duration shows a same - direction increase in three or more consecutive time slices within a set time window, and the growth amplitude exceeds the set growth - rate threshold, select rate - sensitive fusion to give priority to highlighting features with significant change rates; when it is detected that the number of abnormal fluctuations of the data - packet anomaly ratio within a set time window exceeds the set frequency threshold, and the fluctuation amplitude exceeds the anomaly - ratio fluctuation - amplitude threshold for more than two consecutive times, select anomaly - frequency - dominant fusion to enhance the feature prominence during the stage of frequent anomaly outbreaks.
[0061] In specific implementation, for example, within a certain time window, the standard deviation of the communication - frequency change rate is lower than 0.05, and the change amplitude of the communication - frequency change rate between consecutive time slices is less than the set reference - difference threshold of 0.02, then the linear - weighted fusion method is adopted; if within other time windows, the abnormal deviation of the interaction duration rises three times continuously, and the growth rate is greater than 20%, select rate - sensitive fusion; and if within another window, the number of fluctuation times of the data - packet anomaly ratio exceeds 5, and the fluctuation amplitude is greater than 10% for two consecutive times, then select anomaly - frequency - dominant fusion. By dynamically and reasonably selecting the fusion method, it is ensured that the combined dynamic change curve can truly and sensitively reflect the traffic - behavior change characteristics of the interaction pair under different risk situations.
[0062] In step four, the machine learning classification model trained with historical interaction data is adopted, and the partition anomaly index and boundary vulnerability index corresponding to each interaction pair are used as input features for inference to generate risk level results. The partition anomaly index is a quantitative index reflecting the severity of the change in the traffic behavior of the interaction pair, and the boundary vulnerability index is a quantitative index reflecting the weakness of the boundary protection of the interaction pair.
[0063] The input features refer to the feature pairs composed of the partition anomaly index and the boundary vulnerability index calculated for each interaction pair during the monitoring period. Before entering the machine learning classification model, the input features need to be standardized, that is, through linear transformation, the value ranges of different indicators are mapped to a unified standard interval, such as between zero and one, to eliminate the influence caused by different dimensions of different features and ensure that the model can fairly learn the importance of each feature.
[0064] The machine learning classification model is selected from one of the decision tree model, random forest model or lightweight multi-layer perceptron model. The decision tree model is a classification model based on recursive partitioning of the space by feature conditions. By constructing a tree-like structure composed of feature threshold branches, according to the value path of the input features, it finally falls to the leaf node and outputs the corresponding risk level. The random forest model is an ensemble learning model composed of multiple decision trees. Each decision tree is independently trained. During inference, the final risk level is comprehensively judged through the voting results of each decision tree, so as to improve the classification accuracy and anti-overfitting ability. The lightweight multi-layer perceptron model is an artificial neural network model composed of an input layer, one or two hidden layers and an output layer. It learns the complex mapping relationship between the input features and the risk level through non-linear transformation, has good feature combination expression ability and small inference calculation amount, and is suitable for the resource-constrained Internet of Things environment.
[0065] During the model training process, it is trained based on the labeled historical interaction pair risk data set. The historical interaction pair risk data set refers to the set of the collected interaction pair behavior data and the corresponding manually labeled true risk level labels. During the training process, the supervised learning method is adopted, that is, the input features are paired with the true labels. By continuously adjusting the internal parameters of the model, the classification error between the risk level predicted by the model and the true label is minimized. The classification error can be evaluated through the cross-entropy loss function or the classification accuracy. The parameter optimization is completed through gradient descent, feature selection optimization of the random forest or pruning operation of the decision tree. The specific optimization strategy depends on the selected machine learning model.
[0066] In the inference stage, the machine learning classification model receives the standardized partition anomaly index and boundary vulnerability index as inputs, and infers the risk level based on the mapping relationship learned in the training stage. During inference, the machine learning classification model calculates the confidence scores corresponding to each risk level (low risk, medium risk, high risk) according to the combined input features. The confidence score refers to the prediction probability or confidence level of the model that the input features belong to a certain risk level. Finally, the risk level with the highest confidence is selected as the output result of the current interaction pair, that is, the risk classification of the interaction pair is determined, which is used to guide subsequent dynamic regulation operations.
[0067] In specific implementation, for example, when the partition anomaly index of an interaction pair is 0.65 and the boundary vulnerability index is 0.75, after standardization, they are 0.7 and 0.8 respectively. Input into the trained random forest model, the confidence of low risk is 0.15, the confidence of medium risk is 0.3, and the confidence of high risk is 0.55. Then the high risk level is finally output as the judgment result of this interaction pair. If a lightweight multi-layer perceptron model is selected for inference, the probabilities corresponding to the three risk levels of the output nodes are calculated through forward propagation, and the risk level corresponding to the maximum probability is also selected as the output.
[0068] In step five, according to the risk level results generated by the machine learning classification model in step four, targeted dynamic regulation operations are performed to address the potential threat of abnormal diffusion of interaction pairs with different risk levels. The risk levels are divided into three categories: low risk, medium risk, and high risk. Each category of risk level corresponds to different dynamic regulation strategies to ensure that communication efficiency and abnormal defense effects are balanced to the greatest extent.
[0069] When the risk level of the interaction pair is low risk, an operation to increase the authentication mechanism is performed. Increasing the authentication mechanism means introducing an additional verification process during the communication of the interaction pair, such as adding two-way authentication, multi-factor authentication, or dynamic update of session keys, to strengthen the credibility of the communication identity and the integrity of the communication content. This measure aims to improve the controllability and anti-interference ability of the communication link of low-risk interaction pairs and prevent the spread of subsequent attack behaviors induced by low-intensity threats.
[0070] When the risk level of an interaction pair is medium risk, perform the operation of limiting the communication rate. Limiting the communication rate means dynamically restricting the traffic rate of the communication frequency change rate exceeding the normal range according to the partition change index corresponding to the interaction pair and the preset rate adjustment rule. The partition change index is a quantitative index used to measure the degree of change in the communication activity of the interaction pair, and the normal range is set by historical statistical analysis. The preset rate adjustment rule is formulated according to the communication frequency adjustment standard corresponding to the value of the partition change index. For example, when the partition change index approaches the abnormal boundary, the data packet sending rate is limited to 80% of the normal peak value. In this way, it is possible to effectively suppress the potential abnormal expansion trend of the medium-risk interaction pair and reduce the propagation speed and influence range of abnormal traffic.
[0071] When the risk level of an interaction pair is high risk, perform the operation of isolating the high-risk interaction path. Isolating the high-risk interaction path means disconnecting or isolating the interaction path with a high-risk abnormal propagation tendency physically or logically during the network communication process. First, screen by combining the partition change index and the boundary vulnerability index of the interaction pair. The partition change index reflects the degree of drastic change in the communication behavior of the interaction pair, and the boundary vulnerability index reflects the sensitivity of the boundary of the interaction pair to the influence of abnormal propagation. The screening condition is an interaction pair with a partition change index higher than the first threshold and a boundary vulnerability index higher than the second threshold. The first threshold and the second threshold are determined based on historical abnormal event statistical data. Give priority to performing physical isolation operations on the interaction pairs that meet the screening conditions, such as disconnecting the communication link, or performing logical isolation operations, such as setting access control policies to prohibit cross-unit communication, to cut off the abnormal diffusion channel and prevent cross-subunit propagation.
[0072] For the interaction pairs that do not meet the screening conditions but are still judged to be high risk, perform the superimposed control measures of communication rate limitation and additional authentication mechanism according to the comprehensive score of the partition change index and the boundary vulnerability index, sorted from high to low. The comprehensive score is a risk assessment value calculated by a weighted linear combination based on the partition change index and the boundary vulnerability index of the interaction pair, and is used to further divide the risk priority within the high risk. The specific calculation method is that the comprehensive score is equal to the partition change index multiplied by the first weighting coefficient plus the boundary vulnerability index multiplied by the second weighting coefficient. The first weighting coefficient and the second weighting coefficient are set based on the analysis of the contribution degree of each index to the abnormal propagation risk. For example, the first weighting coefficient is set to 0.6 and the second weighting coefficient is set to 0.4.
[0073] In specific implementation, for example, set the first threshold to 0.7, the second threshold to 0.65, the partition anomaly index of a certain interaction pair to 0.8, and the boundary vulnerability index to 0.7. Then, the screening condition is met, and the physical isolation operation is directly executed. If the partition anomaly index of another interaction pair is 0.65 and the boundary vulnerability index is 0.6, which does not meet the double-threshold screening condition, then calculate the comprehensive score, sort according to the comprehensive score from high to low, and first limit the communication rate of the interaction pair with a high score to 50% of the normal peak value, and add two-factor authentication. Subsequently, process the interaction pairs with lower scores in turn until the dynamic regulation of all high-risk interaction pairs is completed.
[0074] Through the above dynamic regulation mechanism, hierarchical defense can be achieved according to different risk characteristics of interaction pairs, taking into account both normal communication efficiency and abnormal protection effects, and greatly improving the overall ability and response accuracy of traffic anomaly recognition and defense in the campus Internet of Things environment.
[0075] The above formulas are all dimensionless and take their numerical values for calculation. The formula is obtained by collecting a large amount of data for software simulation to obtain a formula that is closest to the actual situation. The preset parameters in the formula are set by those skilled in the art according to the actual situation.
[0076] It should be understood that in various embodiments of the present application, the magnitudes of the sequence numbers of the above processes do not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0077] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0078] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the above-described devices and units can refer to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0079] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in the present application, and all should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A multi-modal traffic anomaly recognition and defense method for the campus Internet of Things, characterized in that It includes the following steps: Step 1: Divide the independent partitions of each campus Internet of Things into multiple micro-sized sub-unit areas, deploy traffic feature collection nodes for each sub-unit, and collect traffic feature data including communication frequency, packet size, interaction duration, and anomaly trigger markers; Step 2: Continuously monitor the traffic interaction status of each sub-unit and the interaction pairs composed of its corresponding sub-units through the traffic feature collection nodes, extract the communication frequency change rate, packet anomaly ratio, and interaction duration anomaly offset as a risk feature data group, and judge whether to enter the risk assessment process according to the set trigger threshold conditions; Step 3: In the risk assessment process, calculate the partition anomaly index and the boundary vulnerability index for each interaction pair respectively, as the quantitative basis for evaluating the degree of interaction risk; Step 4: Take the partition anomaly index and the boundary vulnerability index corresponding to each interaction pair as inputs, and feed them into the pre-trained machine learning model to generate the risk level of the corresponding interaction pair. The risk level is subdivided into low risk, medium risk, and high risk; Step 5: Execute dynamic regulation operations according to the generated risk level. The regulation operations include limiting the communication rate, adding an authentication mechanism, and isolating high-risk interaction paths.
2. The multi-modal traffic anomaly recognition and defense method for campus Internet of Things according to claim 1, characterized in that In Step 1, the traffic feature collection nodes perform segmented processing of the traffic feature data of communication frequency, packet size, interaction duration, and anomaly trigger markers based on a time window, and extract the sub-period feature sets according to the preset time window length to enhance the time sensitivity of the traffic interaction status change and the accuracy of the risk feature data group extraction.
3. The multi-modal traffic anomaly recognition and defense method for campus Internet of Things according to claim 2, characterized in that, In Step 2, through the traffic feature collection nodes, continuously monitor the traffic interaction status of each sub-unit and the interaction pairs composed of its corresponding sub-units. During the monitoring process, obtain the following three indicators: The communication frequency change rate is calculated by the ratio of the change amplitude of the number of packets sent per unit time to the reference communication frequency. The packet anomaly ratio is calculated by the ratio of the number of abnormal packets per unit time to the total number of packets. The interaction duration anomaly offset is calculated by the ratio of the difference between the current interaction duration and the historical average duration; Based on these three indicators, extract the risk feature data group in real time. During the extraction process, perform scale unification processing on each indicator according to a unified normalization standard, and adopt a weighted feature enhancement strategy to amplify the feature changes deviating from normal communication behavior, so as to improve the representation accuracy of the risk feature data group. Finally, according to the set trigger threshold conditions, judge the risk change trend of each interaction pair and control whether to enter the subsequent risk assessment process.
4. The multi-modal traffic anomaly recognition and defense method for campus Internet of Things according to claim 3, characterized in that In Step 2, the set trigger threshold conditions generate corresponding single-item risk scores based on the communication frequency change rate, packet anomaly ratio, and interaction duration anomaly offset respectively. Each single-item risk score is weighted and integrated according to the preset sub-item weights to obtain the comprehensive risk score of the interaction pair; When the comprehensive risk score exceeds the preset comprehensive threshold, it is determined as a high-risk interaction pair and triggered to enter the risk assessment process; During the calculation of the comprehensive risk score, a risk change trajectory curve is established for each interaction pair. The risk change trajectory curve is formed by recording the changing trend of the single-item risk score within consecutive time slices. Through dynamic comparison of the slope of the trajectory curve with the set reference slope, if the slope of the trajectory curve is greater than the set reference slope, it is also determined as a high-risk interaction pair and triggered to enter the risk assessment process.
5. The multi-modal traffic anomaly recognition and defense method for campus Internet of Things according to claim 4, wherein In step three, the calculation of the partition anomaly index includes the following steps: Step S1, for each interaction pair, within the set time window, record the sequence of the change rate of the communication frequency in consecutive time slices. Based on the baseline communication frequency, calculate the communication frequency deviation value within each time slice to obtain the communication frequency offset curve. Step S2, based on the sequence of the abnormal ratio of the data packets collected within the time window, calculate the change amplitude of the abnormal ratio between adjacent time slices to form the abnormal fluctuation curve. Step S3, based on the sequence of the abnormal offset of the interaction duration collected within the time window, calculate the change slope of the duration deviation between adjacent time slices to obtain the duration drift curve. Step S4, linearly combine the communication frequency offset curve, the abnormal fluctuation curve, and the duration drift curve according to the preset feature fusion rule to generate the joint dynamic change curve, and calculate the total change energy of this curve within the time window. The total change energy is used as the value of the partition anomaly index.
6. The multi-modal traffic anomaly recognition and defense method for campus Internet of Things according to claim 5, characterized in that, In step three, the calculation of the boundary vulnerability index includes the following steps: Step W1, for each interaction pair, based on the change rate of the communication frequency recorded by the node for traffic feature collection, within the set time window, statistically calculate the standard deviation of the number of data packets per unit time, and form the communication density fluctuation curve with the change of the standard deviation over time as the basic communication fluctuation model. Step W2, based on the abnormal ratio of the data packets, identify the consecutive time periods with a sharp rise in the abnormal ratio within the preset short time on the communication density fluctuation curve, and define this time period as the local outbreak abnormal segment. The set time window consists of multiple preset short times. Step W3, within the local outbreak abnormal segment, use the abnormal offset data of the interaction duration to calculate the cumulative increment of the duration offset change, and draw the abnormal expansion trend line with the change of the increment over time. Step W4, calculate the correlation coefficient between the change rate of the abnormal expansion trend line and the change amplitude of the communication density fluctuation curve, and determine the vulnerability degree of the interaction pair boundary during the local abnormal propagation according to the level of the correlation coefficient. Finally, generate the boundary vulnerability index. The higher the boundary vulnerability index, the more easily the interaction pair boundary is affected by the abnormal traffic diffusion.
7. The multi-modal traffic anomaly recognition and defense method for the campus Internet of Things according to claim 6, characterized in that, During the calculation of the partition anomaly index, the feature fusion rule of the joint dynamic change curve adopts one of the following multiple methods: Method 1, linear weighted fusion, directly add the preset weights of the communication frequency offset curve, the abnormal fluctuation curve, and the duration drift curve to generate the joint dynamic change curve. Method 2, change rate sensitive fusion, calculate the weighted term based on the change slope of each curve. The curve with a larger change slope is given a higher weight during fusion to highlight the short-term rapid change feature. Method 3: Abnormality frequency dominates the fusion. Adjust the fusion weights of each curve based on the density of the fluctuation times of the abnormal ratio of data packets. During the period of high abnormal occurrences, enhance the weight of the abnormal fluctuation curve; The basis for selecting the feature fusion rule is as follows: When the standard deviation of the communication frequency change rate in the risk feature data group within the set time window is less than the preset stability threshold, and the absolute value of the difference in the communication frequency change rate between any two consecutive time slices is lower than the reference difference threshold, linear weighted fusion is selected; When the abnormal deviation of the communication frequency change rate or the interaction duration shows a same-direction growth in three or more consecutive time slices within the set time window, and the growth amplitude exceeds the set growth rate threshold, rate-sensitive fusion is selected; When the number of abnormal fluctuations of the data packet abnormal ratio within the set time window exceeds the set frequency threshold, and the fluctuation amplitude exceeds the abnormal ratio fluctuation amplitude threshold for more than two consecutive times, abnormality frequency-dominated fusion is selected.
8. The multi-modal traffic anomaly recognition and defense method for campus Internet of Things according to claim 7, characterized in that In Step 4, use the machine learning classification model trained with historical interaction data. Take the partition movement index and the boundary vulnerability index corresponding to each interaction pair as input features. After the input features are standardized, they enter the machine learning classification model for inference, and the risk level corresponding to the interaction pair is output. The risk level is subdivided into low risk, medium risk, and high risk; The machine learning classification model is selected from one of the decision tree model, the random forest model, or the lightweight multi-layer perceptron model. During the model training process, based on the labeled historical interaction pair risk data set, the parameter optimization is completed using the supervised learning method, with the goal of minimizing the classification error of the interaction pair risk level; In the inference stage, the machine learning classification model calculates the confidence scores corresponding to each risk level based on the combined features of the input partition movement index and the boundary vulnerability index, and selects the risk level with the highest confidence as the risk output result of the current interaction pair.
9. The multi-modal traffic anomaly recognition and defense method for campus Internet of Things according to claim 8, characterized in that, In Step 5, perform dynamic regulation operations according to the risk levels generated in Step 4. The dynamic regulation operations include: When the risk level of the interaction pair is low risk, perform the operation of adding an authentication mechanism to enhance the controllability of the communication behavior by introducing an additional verification process during the communication process of the interaction pair; When the risk level of the interaction pair is medium risk, perform the operation of limiting the communication rate. Based on the partition movement index corresponding to the interaction pair, according to the preset rate adjustment rule, limit the traffic rate of the communication frequency change rate exceeding the normal range to suppress the abnormal expansion trend; When the risk level of the interaction pair is high risk, perform the operation of isolating the high-risk interaction path. First, combine the partition movement index and the boundary vulnerability index of the interaction pair to screen the interaction pairs with the partition movement index higher than the first threshold and the boundary vulnerability index higher than the second threshold. Priority is given to performing physical isolation or logical disconnection operations on the interaction pairs that meet the screening conditions to cut off the abnormal diffusion channel and prevent cross-unit abnormal propagation; for the interaction pairs that do not meet the screening conditions but are still determined to be high risk, according to the comprehensive score of the partition movement index and the boundary vulnerability index, in the order of the risk comprehensive score from high to low, perform the superimposed control measures of communication rate limitation and additional authentication mechanism to suppress the potential abnormal diffusion risk; The comprehensive score refers to the risk assessment value calculated by the weighted linear combination method based on the partition movement index and the boundary vulnerability index of the interaction pair. The specific calculation method is as follows: Comprehensive score = partition movement index × first weighting coefficient + boundary vulnerability index × second weighting coefficient. The first weighting coefficient and the second weighting coefficient are set according to the contribution degree of each index to the abnormal propagation risk.
Citation Information
Cited By
Self-service vending machine wireless intelligent networking system and networking method
CN120512456A
Self-service vending machine wireless intelligent networking system and networking method
CN120512456B
System vulnerability detection method and device based on penetration test
CN120658521A
System vulnerability detection method and device based on penetration test
CN120658521B
Network security situation awareness method based on multi-layer defense architecture
CN120692094A