Computer network data management system

Through the computer network data management system, the neural network model is used to compare feature profiles, sequences and pattern data, and the problems of difficulty in selecting locations in the switched network are solved, and the accurate detection and timely alarm of intrusion data are realized.

CN120358069APending Publication Date: 2025-07-22GUANGXI UNIVERSITY OF TECHNOLOGY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510659063.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-21
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

Traditional IDS systems have difficulty selecting locations in switched networks, their warnings are inaccurate, and they cannot be updated in time to monitor some cutting-edge intrusions, resulting in missing alarms.

Method used

The computer network data management system is adopted, including computer operation detection module, feature profile splitting module, sequence data splitting module, pattern data splitting module, data decomposition expansion module, feature profile recognition comparison module, sequence recognition comparison module, pattern recognition comparison module, model recognition module, etc. The feature profile, sequence and pattern data are compared through the neural network model, and the intrusion behavior is monitored in real time.

Benefits of technology

It realizes accurate detection of intruded data, improves the recognition rate, ensures that intrusion requests are not missed, and promptly notifies the administrator for processing to prevent information loss.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358069A_ABST
    Figure CN120358069A_ABST
Patent Text Reader

Abstract

The invention provides a computer network data management system, and belongs to the technical field of information. Comprising a computer operation detection module, a computer operation identification data storage module, a computer request acquisition module, a network data real-time capture module, a feature contour splitting module, a sequence data splitting module, a mode data splitting module, a data decomposition extension module, a feature contour data storage module and a sequence data storage module. The system comprises a mode data storage module, a model training module, a feature contour recognition and comparison module, a sequence recognition and comparison module, a mode recognition and comparison module, a model recognition module and the like. Through the first comparison of the neural network model, and then through the comparison of the feature contour, the sequence and the mode data, the detection of the intrusion data is more accurate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information technology, and in particular, to a computer network data management system. Background Art

[0002] With the development of Internet technology and the wide application of networks, network security has become an issue that people pay more and more attention to. Currently, there are various types of intrusion behaviors on computer networks, and the randomness of intrusion time is relatively strong. In the prior art, the method relying on computer maintenance personnel for manual detection has poor real-time performance and low efficiency.

[0003] The traditional IDS is a monitoring system for computers. It monitors the system in real time and issues a warning once an abnormal situation is found. It can be classified into several categories according to the different information sources and detection methods: it can be divided into host-based IDS and network-based IDS according to the information source, and can be further divided into anomaly intrusion detection and misuse intrusion detection according to the detection method. Different from a firewall, the IDS intrusion detection system is a listening device that is not cross-connected to any link and can work without network traffic flowing through it. Therefore, for the deployment of the IDS, the only requirement is that the IDS should be hooked up to the link through which all the traffic of concern must flow. Here, the "traffic of concern" refers to the access traffic from high-risk network areas and the network packets that need to be counted and monitored. In today's network topologies, it is already difficult to find the previous HUB-style shared medium collision domain networks, and most network areas have been fully upgraded to switched network structures. Therefore, the position of the IDS in a switched network is generally selected to be as close as possible to the attack source or as close as possible to the protected resource. However, the warnings of traditional IDS are inaccurate, and some relatively advanced intrusions cannot be updated and monitored in a timely manner, resulting in missed alarms. Therefore, it is necessary to design a computer network data management system. Summary of the Invention

[0004] The purpose of the present invention is to provide a computer network data management system to solve the technical problems that the warnings of traditional IDS are inaccurate and some relatively advanced intrusions cannot be updated and monitored in a timely manner.

[0005] To achieve the above purpose, the technical solution adopted by the present invention is as follows:

[0006] A computer network data management system, comprising a computer operation detection module, a computer operation identification data storage module, a computer request acquisition module, a network data real-time capture module, a feature profile splitting module, a sequence data splitting module, a pattern data splitting module, a data decomposition and extension module, a feature profile data storage module, a sequence data storage module, a pattern data storage module, a model training module, a feature profile recognition and comparison module, a sequence recognition and comparison module, a pattern recognition and comparison module, a model recognition module, a controller module, an alarm module, and a wireless communication module. The computer operation identification data storage module is connected to the computer via the computer operation detection module. The network data real-time capture module is respectively connected to the feature profile splitting module, the sequence data splitting module, the pattern data splitting module, and the data decomposition and extension module. The computer request acquisition module and the controller module are both connected to the feature profile recognition and comparison module, the sequence recognition and comparison module, the pattern recognition and comparison module, and the model recognition module. The feature profile splitting module is connected to the feature profile recognition and comparison module via the feature profile data storage module. The sequence data splitting module is connected to the sequence recognition and comparison module via the sequence data storage module. The pattern data splitting module is connected to the pattern recognition and comparison module via the pattern data storage module. The data decomposition and extension module is connected to the model recognition module via the model training module. The alarm module and the wireless communication module are both connected to the controller module;

[0007] The computer operation identification data storage module is used for the super management to set that when specific operations of the service are required, it is a legal operation only when it carries the super administrator identifier. If there is no computer operation identification data storage module, it is recognized as an intrusion operation. The computer operation detection module is used to detect the running operation data of the service in real time. When an intrusion operation is detected, the intrusion information is sent to the controller module. The feature profile splitting module is used to split the previously obtained intrusion data to establish a feature profile table for each user according to the activities of the user objects. By comparing the current features with the previously established features, the abnormality of the current behavior is judged. The user feature profile table should be continuously updated according to the audit record situation to protect the measurement indicators. The feature profile data storage module is used to store the feature profile data. The sequence data splitting module is used to split according to the service request type, service request length, and service request packet size distribution. The sequence data storage module is used to store the split sequence data. The pattern data splitting module is used to summarize the request data according to the pattern and then perform the same category splitting and summarization. The pattern data storage module is used to store the split pattern data. The data decomposition and expansion module is used to decompose the request data, and then perform network expansion according to the decomposed minimum unit to obtain the training data source, and then provide it to the model training module for training. The feature profile recognition and comparison module, sequence recognition and comparison module, pattern recognition and comparison module, and model recognition module all send the recognition results to the controller module. When the controller module receives one or more intrusion information, it notifies the alarm module to alarm and sends the information to the computer administrator through the wireless communication module.

[0008] Further, the specific working process of the system is as follows:

[0009] Step 1: Use the network data real-time acquisition module to capture and store all computer or network attack data on the Internet;

[0010] Step 2: Decompose, split the data pattern, split the data sequence, and split the data feature profile of the captured data;

[0011] Step 3: Store the decomposed and split data, list the decomposed data as data features for training to obtain a real-time warning training model;

[0012] Step 4: When there is a request to access the computer, the request acquisition module acquires the request data of the computer;

[0013] Step 5: Put the acquired request data into the latest real-time warning training model for recognition, and compare the pattern, sequence, and feature profile with the decomposed data. When an intrusion request occurs, go to Step 7, otherwise go to Step 6;

[0014] Step 6: Detect operations of deleting users without the super administrator identifier, deleting files, creating new user files, consecutive request count operations, and deleting logs on the computer;

[0015] Step 7: Issue an alarm and send a message to notify the computer administrator.

[0016] Furthermore, the specific process of Step 1 is as follows: Regularly crawl relevant data on computer intrusion or network attacks from public systems or forums, then extract intrusion request data or attack request data from the crawled data, and store the request dataset aggregated from the intrusion request data and attack request data. The request dataset is updated regularly according to the crawled data.

[0017] Furthermore, the specific process of Step 2 is as follows: Decompose each request data in the request dataset to obtain several request sources, expand each request source again to obtain a model training dataset, split each request data into a request pattern dataset by request pattern data, split each request data into a request sequence dataset by data sequence, and split each request data into a request feature profile dataset by data feature profile.

[0018] Furthermore, the specific process of further expanding each request source is as follows: After decomposing the request data into the smallest unit once, perform semantic recognition or address location recognition on each smallest unit, then crawl data on the network that is semantically the same or similar to the smallest unit as the secondary smallest unit, and at the same time obtain the address location that is close to the address location and summarize it into this smallest unit. Then, summarize the primary smallest unit and the secondary smallest unit to obtain a model training dataset.

[0019] Furthermore, the specific process of Step 3 is as follows: Use the model training dataset as the recognition feature and put it into the LSTM+CNN convolutional neural network model for training to obtain a trained model. When a new model training dataset appears, put the new model training dataset into the model for training to update the trained model.

[0020] Furthermore, the specific process of Step 5 is as follows: Put the request data into the trained model for intrusion information recognition, and at the same time compare the request data with the request pattern dataset, request sequence dataset, and request feature profile dataset one by one. When the recognition or comparison similarity reaches the set data value, it is determined as an intrusion request.

[0021] Further, the specific process of step 6 is as follows: When setting up the computer, it is specified that operations such as deleting user operations, deleting files, creating new user files, consecutive request count operations, and deleting diaries all require a specific identifier of the super administrator. During the operation of the computer, when it is detected that the operations of deleting user operations, deleting files, creating new user files, consecutive request count operations, and deleting diaries do not have the super administrator identifier, it is recognized as an intrusion operation.

[0022] A system of a computer network data management system, including a computer operation detection module, a computer operation identifier data storage module, a computer request acquisition module, a network data real-time capture module, a feature profile splitting module, a sequence data splitting module, a pattern data splitting module, a data decomposition and expansion module, a feature profile data storage module, a sequence data storage module, a pattern data storage module, a model training module, a feature profile recognition and comparison module, a sequence recognition and comparison module, a pattern recognition and comparison module, a model recognition module, a controller module, an alarm module, and a wireless communication module. The computer operation identifier data storage module is connected to the computer through the computer operation detection module. The network data real-time capture module is respectively connected to the feature profile splitting module, the sequence data splitting module, the pattern data splitting module, and the data decomposition and expansion module. The computer request acquisition module and the controller module are both connected to the feature profile recognition and comparison module, the sequence recognition and comparison module, the pattern recognition and comparison module, and the model recognition module. The feature profile splitting module is connected to the feature profile recognition and comparison module through the feature profile data storage module. The sequence data splitting module is connected to the sequence recognition and comparison module through the sequence data storage module. The pattern data splitting module is connected to the pattern recognition and comparison module through the pattern data storage module. The data decomposition and expansion module is connected to the model recognition module through the model training module. The alarm module and the wireless communication module are both connected to the controller module;

[0023] The computer operation identification data storage module is used for the super management to set that when specific operations of the service are required, only those with a super administrator identifier are legal operations. If there is no computer operation identification data storage module, it is considered an intrusion operation. The computer operation detection module is used to detect the running operation data of the service in real time. When an intrusion operation is detected, the intrusion information is transmitted to the controller module. The feature profile splitting module is used to split the previously obtained intrusion data and establish a feature profile table for each user based on the activities of the user objects. By comparing the current features with the previously established features, the abnormality of the current behavior is judged. The user feature profile table should be continuously updated according to the audit record situation to protect the measurement indicators. The feature profile data storage module is used to store the feature profile data. The sequence data splitting module is used to split according to the service request type, service request length, and service request packet size distribution. The sequence data storage module is used to store the split sequence data. The pattern data splitting module is used to summarize the request data according to the pattern and then perform the same category splitting and summarization. The pattern data storage module is used to store the split pattern data. The data decomposition and expansion module is used to decompose the request data and then perform network expansion based on the decomposed minimum unit to obtain the training data source, which is then provided to the model training module for training. The feature profile recognition and comparison module, sequence recognition and comparison module, pattern recognition and comparison module, and model recognition module all transmit the recognition results to the controller module. When the controller module receives one or more intrusion messages, it notifies the alarm module to alarm and transmits the information to the computer administrator through the wireless communication module.

[0024] Due to the adoption of the above technical solutions, the present invention has the following beneficial effects:

[0025] Through the comparison of the neural network model first and then the comparison of the feature profile, sequence, and pattern data, the present invention makes the detection of intrusion data more accurate, can basically realize the early warning of all requests for intrusion, has a high recognition rate, and can also update the overall data in real time. The data source is updated according to different intrusion situations in society, so that intrusions will not be missed. At the same time, computer operation recognition is added, so that missed requests can also be found in time and the administrator can be notified for timely repair and management. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 It is the system block diagram of the present invention;

[0027] Figure 2 It is the system working flow chart of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0028] To make the objectives, technical solutions and advantages of the present invention more clearly understood, the following provides preferred embodiments with reference to the accompanying drawings and further elaborates on the present invention in detail. However, it should be noted that many details listed in the specification are only for enabling the reader to have a thorough understanding of one or more aspects of the present invention, and these aspects of the present invention can be implemented even without these specific details.

[0029] As Figure 1 shown, a computer network data management system, the method includes the following steps:

[0030] Step 1: Use the network data real-time acquisition module to capture and store all computers or network attack data on the Internet. Regularly capture relevant data on computer intrusion or network attacks from public systems or forums, then extract intrusion request data or attack request data from the captured data, and aggregate the intrusion request data and attack request data into a request data set for storage. The request data set is updated regularly according to the captured data.

[0031] Step 2: Decompose, split the data pattern, split the data sequence, and split the data feature profile of the captured data. Decompose each request data in the request data set to obtain several request sources, expand each request source to obtain a model training data set, split each request data into a request pattern data set, split each request data into a request sequence data set, and split each request data into a request feature profile data set.

[0032] The specific process of further expanding each request source is as follows: after decomposing the request data into the smallest unit once, perform semantic recognition or address location recognition on each smallest unit, then capture data with the same or similar semantics as the smallest unit from the network as the secondary smallest unit, and at the same time obtain address locations close to the address location and summarize them into the smallest unit. Then aggregate the primary smallest unit and the secondary smallest unit to obtain a model training data set.

[0033] Step 3: Store the decomposed and split data, list the decomposed data as data features for training to obtain a real-time warning training model. Use the model training data set as the recognition feature and put it into the LSTM+CNN convolutional neural network model for training to obtain a training model. When a new model training data set appears, put the new model training data set into the model for training to update the trained model.

[0034] Step 4: When there is a request to access the computer, the request acquisition module acquires the request data of the computer. When receiving an access request for the computer, intercept the access request and acquire the characteristic attributes corresponding to the access request.

[0035] Step 5: Put the acquired request data into the latest real-time early warning training model for identification, and compare the pattern, sequence, and feature profile with the decomposed data. When an intrusion request occurs, go to Step 7; otherwise, go to Step 6. At the same time, compare the request data with the request pattern data set, the request sequence data set, and the request feature profile data set one by one. When the recognition or comparison similarity reaches the set data value, it is determined as an intrusion request.

[0036] Step 6: Detect operations on the computer such as deleting users without the super administrator flag, deleting files, creating new user files, consecutive request operations, and deleting logs. When setting up the computer, it is set that operations such as deleting users, deleting files, creating new user files, consecutive request operations, and deleting logs all need to carry a specific flag of the super administrator. During the operation of the computer, when it is detected that there is no super administrator flag during the process of deleting users, deleting files, creating new user files, consecutive request operations, and deleting logs, it is identified as an intrusion operation.

[0037] Step 7: Send an alarm and send a message to notify the computer administrator so that the administrator can discover the intrusion data in time and handle it in time to avoid the loss of computer information or causing irreparable consequences.

[0038] Such as Figure 2As shown, a system of a computer network data management system includes a computer operation detection module, a computer operation identification data storage module, a computer request acquisition module, a network data real-time capture module, a feature profile splitting module, a sequence data splitting module, a pattern data splitting module, a data decomposition and extension module, a feature profile data storage module, a sequence data storage module, a pattern data storage module, a model training module, a feature profile recognition and comparison module, a sequence recognition and comparison module, a pattern recognition and comparison module, a model recognition module, a controller module, an alarm module, and a wireless communication module. The computer operation identification data storage module is connected to the computer via the computer operation detection module. The network data real-time capture module is respectively connected to the feature profile splitting module, the sequence data splitting module, the pattern data splitting module, and the data decomposition and extension module. The computer request acquisition module and the controller module are both connected to the feature profile recognition and comparison module, the sequence recognition and comparison module, the pattern recognition and comparison module, and the model recognition module. The feature profile splitting module is connected to the feature profile recognition and comparison module via the feature profile data storage module. The sequence data splitting module is connected to the sequence recognition and comparison module via the sequence data storage module. The pattern data splitting module is connected to the pattern recognition and comparison module via the pattern data storage module. The data decomposition and extension module is connected to the model recognition module via the model training module. The alarm module and the wireless communication module are both connected to the controller module.

[0039] The computer operation identification data storage module is used for the super management to set that when specific operations of the service are required, only operations with a super administrator identifier are legal operations. If there is no computer operation identification data storage module, it is recognized as an intrusion operation. The computer operation detection module is used to detect the operation data of the service in real time. When an intrusion operation is detected, the intrusion information is transmitted to the controller module. The feature profile splitting module is used to establish a feature profile table for each user based on the activities of the user object by splitting the previously obtained intrusion data. By comparing the current feature with the previously established feature, the abnormality of the current behavior is judged. The user feature profile table should be continuously updated according to the audit record situation to protect the measurement index. The feature profile data storage module is used to store the feature profile data. The sequence data splitting module is used to split according to the service request type, service request length, and service request packet size distribution. The sequence data storage module is used to store the split sequence data. The pattern data splitting module is used to summarize the request data according to the pattern and then perform the same category splitting and summarization. The pattern data storage module is used to store the split pattern data. The data decomposition and expansion module is used to decompose the request data and then perform network expansion based on the decomposed minimum unit to obtain the training data source, and then provide it to the model training module for training. The feature profile recognition and comparison module, sequence recognition and comparison module, pattern recognition and comparison module, and model recognition module all transmit the recognition results to the controller module. When the controller module receives one or more intrusion messages, it notifies the alarm module to alarm and transmits the information to the computer administrator through the wireless communication module.

[0040] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A computer network data management system, characterized in that: It includes a computer operation detection module, a computer operation identification data storage module, a computer request acquisition module, a network data real-time capture module, a feature profile splitting module, a sequence data splitting module, a pattern data splitting module, a data decomposition and expansion module, a feature profile data storage module, a sequence data storage module, a pattern data storage module, a model training module, a feature profile recognition and comparison module, a sequence recognition and comparison module, a pattern recognition and comparison module, a model recognition module, a controller module, an alarm module and a wireless communication module. The computer operation identification data storage module is connected to the computer through the computer operation detection module. The network data real-time capture module is respectively connected to the feature profile splitting module, the sequence data splitting module, the pattern data splitting module and the data decomposition and expansion module. The computer request acquisition module and the controller module are both connected to the feature profile recognition and comparison module, the sequence recognition and comparison module, the pattern recognition and comparison module and the model recognition module. The feature profile splitting module is connected to the feature profile recognition and comparison module through the feature profile data storage module. The sequence data splitting module is connected to the sequence recognition and comparison module through the sequence data storage module. The pattern data splitting module is connected to the pattern recognition and comparison module through the pattern data storage module. The data decomposition and expansion module is connected to the model recognition module through the model training module. The alarm module and the wireless communication module are both connected to the controller module; The computer operation identification data storage module is used for the super management to set that when a service-specific operation is required, it is a legal operation only when it carries a super administrator identifier. If there is no computer operation identification data storage module, it is considered an intrusion operation. The computer operation detection module is used to detect the running operation data of the service in real time. When an intrusion operation is detected, the intrusion information is sent to the controller module. The feature profile splitting module is used to establish a feature profile table for each user based on the activities of the user object for the acquired previous intrusion data. By comparing the current feature with the previously established feature, the abnormality of the current behavior is judged. The user feature profile table should be continuously updated according to the audit record situation to protect the measurement index. The feature profile data storage module is used to store the feature profile data. The sequence data splitting module is used to split according to the service request type, service request length, and service request packet size distribution. The sequence data storage module is used to store the split sequence data. The pattern data splitting module is used to summarize the request data according to the pattern and then perform the same category splitting and summarization. The pattern data storage module is used to store the split pattern data. The data decomposition and expansion module is used to decompose the request data, and then perform network expansion according to the decomposed minimum unit to obtain the training data source, and then provide it to the model training module for training. The feature profile recognition and comparison module, the sequence recognition and comparison module, the pattern recognition and comparison module and the model recognition module all send the recognition results to the controller module. When the controller module receives one or more intrusion information, it notifies the alarm module to alarm and sends the information to the computer administrator through the wireless communication module.

2. The computer network data management system according to claim 1, wherein: The specific working process of the system is as follows: Step 1: Use the network data real-time acquisition module to capture and store all computer or network attack data on the Internet; Step 2: Decompose the captured data, split the data patterns, split the data sequences, and split the data feature profiles; Step 3: Store the decomposed and split data, list the decomposed data as data features for training to obtain a real-time warning training model; Step 4: When there is a request to access a computer, the request acquisition module obtains the request data of the computer; Step 5: Put the obtained request data into the latest real-time warning training model for identification, and compare it with the decomposed data in terms of patterns, sequences, and feature profiles. When an intrusion request occurs, go to Step 7; otherwise, go to Step 6; Step 6: Detect operations on the computer such as deleting users without the super administrator flag, deleting files, creating new user files, consecutive request count operations, and deleting logs; Step 7: Issue an alarm and send a message to notify the computer administrator.

3. A computer network data management system according to claim 2, characterized in that: The specific process of Step 1 is as follows: Regularly capture relevant data on computer intrusion or network attacks from public systems or forums, then extract intrusion request data or attack request data from the captured data, and aggregate the intrusion request data and attack request data into a request data set for storage. The request data set is updated regularly according to the captured data.

4. A computer network data management system according to claim 2, characterized in that: The specific process of Step 2 is as follows: Decompose each request data in the request data set to obtain several request sources, expand each request source again to obtain a model training data set, split each request data into request pattern data to obtain a request pattern data set, split each request data into data sequences to obtain a request sequence data set, and split each request data into data feature profiles to obtain a request feature profile data set.

5. A computer network data management system according to claim 2, characterized in that: The specific process of further expanding each request source is as follows: After decomposing the request data into the smallest unit once, perform semantic recognition or address location recognition on each smallest unit, then capture data on the network that is semantically the same or similar to the smallest unit as the secondary smallest unit, and at the same time obtain address locations that are close in address location and summarize them into the secondary smallest unit. Then aggregate the primary smallest unit and the secondary smallest unit to obtain a model training data set.

6. A computer network data management system according to claim 2, characterized in that: The specific process of Step 3 is as follows: Use the model training data set as recognition features and put them into the LSTM+CNN convolutional neural network model for training to obtain a training model. When a new model training data set appears, put the new model training data set into the model for training to update the trained model.

7. A computer network data management system according to claim 2, characterized in that: The specific process of Step 5 is as follows: Put the request data into the trained model for intrusion information recognition, and at the same time compare the request data with the request pattern data set, the request sequence data set, and the request feature profile data set one by one. When the recognition or comparison similarity reaches the set data value, it is determined as an intrusion request.

8. A computer network data management system according to claim 2, characterized in that: The specific process of step 6 is as follows: When setting up the computer, it is specified that operations such as deleting user operations, deleting files, creating new user files, continuous request count operations, and deleting diary operations all require a specific identifier of the super administrator. During the operation of the computer, when it is detected that there is no super administrator identifier in the process of deleting user operations, deleting files, creating new user files, continuous request count operations, and deleting diary operations, it is recognized as an intrusion operation.