Network security monitoring method and system based on dynamic vulnerability verification

By generating the administrator dynamic key Kt encrypting the data to be verified and combining with the vulnerability library verification, the problem of vulnerability false alarms and high misreport rates during the system is solved, real-time defense and dynamic adaptability are achieved, and the security and accuracy of network security monitoring are improved.

CN120358085AActive Publication Date: 2025-07-22TONGFANG KNOWLEDGE DIGITAL PUBLISHING TECH CO LTD

Patent Information

Application Number
CN202510829451.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-20
Publication Date
2025-07-22
Estimated Expiration
2045-06-20

AI Technical Summary

Technical Problem

The existing vulnerability verification technology has the problem of high false alarm and false alarm rates when the system is running, and lacks real-time defense mechanisms, so it cannot effectively deal with supply chain pollution and quantum computing attacks.

Method used

The network security monitoring method based on vulnerability dynamic verification is adopted, and the data to be verified is encrypted by generating the administrator dynamic key Kt, combining real-time system indicators, defense status parameters and supply chain trust scores, the data is verified by the vulnerability library, and defense is carried out according to the defense level, and the vulnerability library and verification parameters are updated to achieve closed-loop defense.

Benefits of technology

It improves the security of vulnerability verification during system operation, reduces the vulnerability false alarm rate and missed alarm rate, realizes real-time defense and dynamic adaptability, and resists supply chain pollution and quantum attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358085A_ABST
    Figure CN120358085A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of network security, particularly relates to a network security monitoring method and system based on dynamic vulnerability verification, and aims to solve the problems of high false alarm rate of vulnerability verification and lack of defense during system operation. The method comprises the following steps: when a client request is an administrator vulnerability verification request, generating an administrator dynamic key to encrypt to-be-verified data based on a real-time system index, a defense state parameter and a supply chain trust score corresponding to the client request; verifying the encrypted data to be verified; if the to-be-verified data is suspicious or abnormal, calculating the defense level of the to-be-verified data and performing defense; and updating the vulnerability library, the verification parameter and / or the defense parameter according to the defense effect. The generated key can resist supply chain pollution and quantum attacks, and the security of vulnerability verification during system operation is improved; the misjudgment rate is reduced through verification based on the vulnerability library; and a loophole verification result is combined with real-time defense, so that a closed-loop loophole verification and defense evolution system is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Background Art

[0002] Existing vulnerability verification technologies are usually carried out in a non-running state of the system and cannot detect vulnerabilities in real time when the system is working properly, resulting in potential network security hazards. In response to this problem, the Chinese patent document "A Network Security Monitoring Method and System Based on Dynamic Vulnerability Verification" with the publication number CN117240609B discloses a solution. When the system is working properly, different encryption methods are used for the communication interactions of different users, so as to prevent data leakage when sending vulnerability verification messages and ensure the security of vulnerability verification during system operation, enabling vulnerability detection to be carried out even when the system is running. In addition, this patent also discloses a method of improving security by using a consistent key.

[0003] Although the above technical solution can perform differential encryption for ordinary users and administrators, it uses a traditional hash algorithm to generate keys, which is a static encryption algorithm and is easily cracked by quantum computing; and it only completes encrypted communication and does not combine the vulnerability verification results with real-time defense. In addition, in a network system, there is a situation of open-source library supply chain pollution attacks. Attackers tamper with the automatic update mechanism of a popular open-source library and implant hidden memory destruction vulnerabilities in legitimate software update packages. The attack payload has no explicit malicious features, resulting in the failure of traditional feature matching in existing systems. Therefore, the above technical solution has problems of insufficient encryption security and a high false positive rate of vulnerability verification.

[0004] In summary, how to perform vulnerability verification during system operation, reduce missed reports and false positives of vulnerabilities and conduct defense is an urgent problem to be solved. Summary of the Invention

[0005] In order to solve the above problems in the prior art, that is, the high missed report and false positive rates of vulnerability verification during system operation and the lack of defense, the present application provides a network security monitoring method and system based on dynamic vulnerability verification.

[0006] In the first aspect of the present application, a network security monitoring method based on dynamic vulnerability verification is provided, including: receiving a client request. If the client request is an administrator vulnerability verification request, based on real-time system metrics, defense status parameters, and the supply chain trust score T corresponding to the client request SC , generate an administrator dynamic key K t , and encrypt the data to be verified based on the administrator dynamic key K t ; verify the encrypted data to be verified based on a vulnerability database; if the data to be verified is suspicious or abnormal after verification, calculate the defense level of the data to be verified, and conduct defense according to the defense level; update the vulnerability database, update verification parameters, and / or update defense parameters according to defense effect data.

[0007] Optionally, in the network security monitoring method described above: , where ω1, ω2, and ω3 are weight coefficients, ω1 = 0.5, ω1 = 0.3, ω1 = 0.2, SignScore is the signature validity, SignScore = 1 if the signature is valid, SignScore = 0 if the signature is invalid, RepoScore is the maintainer's reputation, RepoScore ∈ [0, 1], Channelcore is the security of the transmission protocol, Channelcore = 1 if the transmission protocol is HTTPS, Channelcore = 0.5 if the transmission protocol is HTTP, and Channelcore = 0 for other transmission protocols; , where V1 is the number of registered users, V2 is the traffic volume, F a is the attack frequency; N b is the number of blocked IPs, QC_Hash is a quantum-resistant hash function based on quantum random walk that outputs a 256-bit hash value, (Fa·Nb) is the current defense status encoding, and Chaos(V2,t) is a chaos sequence generation function with the traffic volume V2 as the initial value. The expression of Chaos(V2,t) is: , where r represents the Logistic map, r = 3.99, x n = V2 / 10 6 , and t is the current timestamp, which iterates once per second.

[0008] Optionally, in the network security monitoring method described above, verifying the encrypted data to be verified based on the vulnerability database includes: Decrypt the data to be verified and extract the features of the data to be verified to construct a vector V; match the feature construction vector V with the vulnerability database and calculate the feature similarity S; Perform taint propagation tracking on the data to be verified; If S < S1, calculate the behavior deviation degree D of the data to be verified; If S < S1 and D < D1, and the data to be verified does not trigger a dangerous function, then determine that the data to be verified is normal; If S1 ≤ S < S2, or D1 ≤ D < D2, or the taint propagation path of the data to be verified has no result, then determine that the data to be verified is suspicious; If S ≥ S2, or D ≥ D2, or the data to be verified triggers a dangerous function, then determine that the data to be verified is abnormal, where S1, S2 are preset feature similarity thresholds, and D1, D2 are preset behavior deviation degree thresholds.

[0009] Optionally, in the network security monitoring method described above, calculating the feature similarity S includes: , where V i is the i-th dimensional value of the traffic feature of the data to be verified, n is the dimensional value of the traffic feature, and the traffic feature is the feature corresponding to the real-time traffic index in the feature construction vector of the data to be verified. C i is the i-th dimensional standard value of the feature in the vulnerability library corresponding to the traffic feature; Calculating the behavior deviation degree D of the data to be verified includes: , where T is the time window length, and the default value is 60 seconds. x t is the traffic feature of the data to be verified, λ is the entropy value weight coefficient, λ = 0.2, and H IB is the implicit behavior entropy of the traffic feature, , where , and x is the implicit behavior event.

[0010] Optionally, in the network security monitoring method, based on the vulnerability library, verifying the encrypted data to be verified further includes: If T sc is less than a preset first threshold, reduce the thresholds D1 and D2 corresponding to the behavior deviation degree D, and the taint propagation tracking increases dynamic memory boundary checking; If T sc is less than a preset first threshold and if H IB is greater than a preset third threshold, the taint propagation tracking increases dynamic memory boundary checking; If T sc is less than a preset second threshold, continue to reduce the thresholds D1 and D2 corresponding to the behavior deviation degree D, and the taint propagation tracking increases dynamic memory boundary checking; If T sc is less than a preset second threshold or if H IB is greater than a preset third threshold, put the data to be verified into a sandbox for verification; If the result of the sandbox verification is abnormal, determine that the data to be verified is abnormal. If the result of the sandbox verification is not abnormal, determine that the data to be verified is suspicious.

[0011] Optionally, for the network security monitoring method, if the data to be verified is suspicious or abnormal after verification, calculating the defense level of the data to be verified includes: calculating the banning weight W: , where α, β, and γ are preset dynamic weight coefficients, δ is the defense tolerance, and the entropy value of the key strength is K t . If the data to be verified is suspicious, the threat level is a preset first level value. If the data to be verified is abnormal, the threat level is a preset second level value.

[0012] Optionally, in the network security monitoring method, if the data to be verified is suspicious or abnormal after verification, before calculating the defense level of the data to be verified, it further includes performing a secondary detection on the data to be verified, and the secondary detection includes: If the data to be verified is suspicious data after verification, replay the suspicious encrypted data in the sandbox and execute the data to be verified. If there is no dangerous behavior in the sandbox, it is determined that the data to be verified is normal; if an unconventional operation is detected and no attack is detected, it is determined that the data to be verified is suspicious; if a vulnerability exploitation is triggered, it is determined that the data to be verified is abnormal; If the data to be verified is abnormal data after verification, perform probe interaction analysis on the data to be verified. If the attacker does not trigger the probe, it is determined that the data to be verified is normal; if the attacker submits a probe and the payload is invalid, it is determined that the data to be verified is suspicious; if the attacker submits a valid attack payload, it is determined that the data to be verified is abnormal; Calculating the defense level of the data to be verified includes calculating the defense level of the data to be verified that is suspicious or abnormal after the secondary detection.

[0013] Optionally, in the network security monitoring method, the defense according to the defense level includes: if the blocking weight W < W1, do nothing; If W1 ≤ W < W2, throttle the request corresponding to the data to be verified and perform short-term monitoring for a preset duration; If W2 ≤ W < W3, block the IP of the request corresponding to the data to be verified and the blocking duration reaches a preset first duration, and generate a basic trap page; If W ≥ W3, block the IP of the request corresponding to the data to be verified and the blocking duration reaches a preset second duration, and generate an advanced trap, where W1, W2, and W3 are preset level thresholds, and the second duration is greater than the first duration.

[0014] Optionally, in the network security monitoring method, before the defense according to the defense level, it further includes: if T sc is less than a preset second threshold, block the IP of the request corresponding to the data to be verified.

[0015] Optionally, in the network security monitoring method, the defense effect data includes false alarm rate, missed alarm rate, traffic baseline smoothness, and key update frequency. Updating the defense parameters according to the defense effect data includes: if the false alarm rate is greater than a preset fourth threshold, reducing the value of α in the calculation of the blocking weight W; if the missed alarm rate is greater than a preset fifth threshold, increasing the value of α; if the traffic baseline smoothness is within a preset range, increasing the value of β in the calculation of the blocking weight W; if the traffic baseline smoothness is outside the preset range, reducing the value of β; if the key update frequency is less than or equal to a preset sixth threshold, keeping the value of γ in the calculation of the blocking weight W; if the key update frequency is greater than the preset sixth threshold, increasing the value of γ, where α, β, and γ are values greater than 0.

[0016] Optionally, in the network security monitoring method, the defense effect data includes false alarm rate and missed alarm rate, and the verification parameters include feature similarity threshold and behavior deviation threshold. Updating the verification parameters according to the defense effect data includes: if the false alarm rate R FP is greater than a preset false alarm threshold, calculating a new behavior deviation threshold D th new , , where η D is a preset behavior deviation learning rate, is a preset behavior deviation loss value, D th new includes new behavior deviation thresholds D1 and D2, D th old is the current behavior deviation threshold, D th old includes the behavior deviation thresholds D1 and D2 before calculating the new behavior deviation threshold; if the missed alarm rate R FN is greater than a preset missed alarm threshold, calculating a new feature similarity threshold S th new , , where η S is a preset feature similarity learning rate, is a preset feature similarity loss value, S th new includes new feature similarity thresholds S1 and S2, S th old is the current feature similarity threshold, S th old includes the feature similarity thresholds S1 and S2 before calculating the new feature similarity threshold.

[0017] Optionally, for the network security monitoring method, updating the vulnerability database according to the defense effect data includes: capturing the attack payload to obtain the standardized feature vector V corresponding to the attack payload new ; calculating V new and the maximum similarity S with the existing features in the vulnerability database max , , where C j is the feature vector of the j-th vulnerability already in the vulnerability database, m is the number of vulnerabilities in the vulnerability database. If S max is less than the preset matching threshold, add V new to the vulnerability database.

[0018] Optionally, for the network security monitoring method, updating the verification parameters according to the defense effect data further includes: obtaining the verification parameters and implicit behavior entropy statistics of all nodes in the network; aggregating and calculating to obtain the global verification parameter θ global : , where DT i is the data volume of node i, DT total is the data volume of all nodes, N is the number of nodes, θ i is the verification parameter of node i, θ i includes the feature similarity threshold and the behavior deviation threshold, μ is the preset correction coefficient, η is the preset learning rate, is the loss function gradient, is calculated based on V new , H IBN,i is the implicit behavior entropy statistic of node i, , where T is the statistical period, H IBN (t) is the real-time implicit behavior entropy of node i at time t, where, , y is the implicit behavior event of node i; Distribute the global verification parameter θ global to each node, and each node uses the global verification parameter θ global as the new verification parameter.

[0019] Optionally, for the network security monitoring method, before distributing the global verification parameter θ global to each node, it further includes: obtaining the number of false alarms and the total number of detections of all nodes, and calculating the global false alarm rate R FP,global , , if R FP,global is greater than the preset global false alarm threshold, adjust the global verification parameter θ global so that , where θ globalold The global verification parameters before adjustment; the adjusted global verification parameters θ global are distributed to each node.

[0020] Optionally, in the network security monitoring method, the method further includes: updating the supply chain trust score T SC : , where ν is a preset learning rate, and R attack is the supply chain attack historical frequency, and R normal = number of normal client requests / total number of client requests, and T SC,old is the supply chain trust score before update; updating the key parameter V2: , where V2' is the updated value of V2.

[0021] In a second aspect of the present application, there is provided a network security monitoring system based on vulnerability dynamic verification, and the system includes: A traffic classification processing module, configured to receive client requests and distinguish whether the client requests are administrator vulnerability verification requests; An encryption module, configured to, if the client request is an administrator vulnerability verification request, generate an administrator dynamic key K SC based on real-time system metrics, defense status parameters, and the supply chain trust score T corresponding to the client request t , and encrypt the data to be verified based on the administrator dynamic key K t ; A verification engine module, configured to verify the encrypted data to be verified based on a vulnerability library; A defense linkage module, configured to, if the data to be verified is suspicious or abnormal after verification, calculate the defense level of the data to be verified and perform defense according to the defense level; A feedback optimization module, configured to update the vulnerability library, update verification parameters, and / or update defense parameters according to defense effect data.

[0022] Optionally, in the network security monitoring system, the verification engine module includes: A decryption module, configured to decrypt the data to be verified and extract the features of the data to be verified to construct a vector V; A matching module, configured to match the feature construction vector V with the vulnerability library and calculate the feature similarity S; A behavior deviation detection module, configured to calculate the behavior deviation degree D of the data to be verified if S < S1; A taint propagation tracking module, configured to perform taint propagation tracking on the data to be verified; A verification module, which is used to determine that the data to be verified is normal if S < S1 and D < D1 and the data to be verified does not trigger a dangerous function; and is used to determine that the data to be verified is suspicious if S1 ≤ S < S2, or D1 ≤ D < D2, or the taint propagation path of the data to be verified has no result; and is used to determine that the data to be verified is abnormal if S ≥ S2, or D ≥ D2, or the data to be verified triggers a dangerous function; where S1, S2 are preset feature similarity thresholds, and D1, D2 are preset behavior deviation thresholds.

[0023] Optionally, in the network security monitoring system, the defense linkage module includes: A defense level calculation module, which is used to calculate the ban weight W: , where α, β, γ are preset dynamic weight coefficients, δ is the defense tolerance, and the entropy value of the key strength is K t If the data to be verified is suspicious, the threat level is a preset first level value, and if the data to be verified is abnormal, the threat level is a preset second level value.

[0024] Optionally, in the network security monitoring system, the defense linkage module further includes a secondary detection module, which is used to perform secondary detection on the data to be verified before the defense level calculation module calculates the defense level of the data to be verified if the verification engine module verifies that the data to be verified is suspicious or abnormal. The secondary detection module includes: A suspicious data secondary detection module, which is used to replay the data to be verified in a sandbox and execute the data to be verified if the verification engine module verifies that the data to be verified is suspicious data. If there is no dangerous behavior in the sandbox, it is determined that the data to be verified is normal; if an unconventional operation is detected and no attack is detected, it is determined that the data to be verified is suspicious; if a vulnerability exploitation is triggered, it is determined that the data to be verified is abnormal; An abnormal data secondary detection module, which is used to perform probe interaction analysis on the data to be verified if the verification engine module verifies that the data to be verified is abnormal data. If the attacker does not trigger a probe, it is determined that the data to be verified is normal; if the attacker submits a probe and the payload is invalid, it is determined that the data to be verified is suspicious; if the attacker submits a valid attack payload, it is determined that the data to be verified is abnormal; The defense level calculation module is used to calculate the ban weight W of the data to be verified that is suspicious or abnormal after being detected by the secondary detection module.

[0025] Optionally, in the network security monitoring system, the defense linkage module further includes: A defense module, which is used to perform defense according to the defense level, including: The first execution module is used to limit the flow of requests corresponding to the data to be verified and perform short-term monitoring for a preset duration if W1 ≤ W < W2; The second execution module is used to block the IP of the request corresponding to the data to be verified for a preset first duration and generate a basic trap page if W2 ≤ W < W3; The third execution module is used to block the IP of the request corresponding to the data to be verified for a preset second duration and generate an advanced trap, where W1, W2, and W3 are preset level thresholds, and the second duration is greater than the first duration.

[0026] Optionally, in the network security monitoring system, the defense effect data includes false alarm rate, missed alarm rate, traffic baseline smoothness, and key update frequency. The feedback optimization module includes a defense parameter adjustment module, and the defense parameter adjustment module includes: The first weight adjustment module is used to decrease the α value in the calculation of the blocking weight W if the false alarm rate is greater than a preset fourth threshold; increase the α value if the missed alarm rate is greater than a preset fifth threshold.

[0027] The second weight adjustment module is used to increase the β value in the calculation of the blocking weight W if the traffic baseline smoothness is within a preset range; decrease the β value if the traffic baseline smoothness is outside the preset range; The third weight adjustment module is used to maintain the γ value in the calculation of the blocking weight W if the key update frequency is less than or equal to a preset sixth threshold; increase the γ value if the key update frequency is greater than the preset sixth threshold.

[0028] Optionally, in the network security monitoring system, the defense effect data includes false alarm rate and missed alarm rate, the verified parameters include feature similarity threshold and behavior deviation threshold, the feedback optimization module includes a verified parameter adjustment module, and the verified parameter adjustment module includes: The behavior deviation threshold adjustment module is used to calculate a new behavior deviation threshold D if the false alarm rate R FP is greater than a preset false alarm threshold, th new , , where η D is a preset behavior deviation learning rate, is a preset behavior deviation loss value, and D th new includes behavior deviation thresholds D1 and D2; The feature similarity threshold adjustment module is used to calculate a new feature similarity threshold S if the missed alarm rate R FN is greater than a preset missed alarm threshold, th new , , where η S is a preset feature similarity learning rate, is a preset feature similarity loss value, S th new includes feature similarity thresholds S1 and S2.

[0029] Optionally, in the network security monitoring system, the feedback optimization module includes a vulnerability database update module, and the vulnerability database update module includes: An attack payload vector generation module for capturing attack payloads and obtaining a standardized feature vector V corresponding to the attack payload new ; An attack payload vector evaluation module for calculating V new and the maximum similarity S max with the existing features in the vulnerability database, , where C j is the feature vector of the jth vulnerability existing in the vulnerability database, and m is the number of vulnerabilities in the vulnerability database; An update module for adding V max to the vulnerability database if S new is less than a preset matching threshold.

[0030] Optionally, in the network security monitoring system, the feedback optimization module further includes a global optimization module, and the global optimization module includes: A first node data acquisition module for acquiring the verification parameters and implicit behavior entropy statistics of all nodes in the network; A global aggregation module for aggregating and calculating to obtain a global verification parameter θ global : , where DT i is the data volume of node i, DT total is the data volume of all nodes, N is the number of nodes, θ i is the verification parameter of node i, θ i includes a feature similarity threshold and a behavior deviation threshold, μ is a preset correction coefficient, η is a preset learning rate, is the loss function gradient, calculated based on V new , H IBN,i is the implicit behavior entropy statistic of node i, , where T is the statistical period, H IBN (t) is the real-time implicit behavior entropy of node i at time t, , where, , y is the implicit behavior event of node i; A distribution module for distributing the global verification parameter θglobal Distribute to each node, and each of the nodes will use the global verification parameter θ global as the new verification parameter.

[0031] Optionally, in the network security monitoring system, the feedback optimization module further includes a global adjustment module, and the global adjustment module includes: A second node data acquisition module, which is used to obtain the number of false alarms and the total number of detections of all nodes before distributing the global verification parameter θ global to each node; A global false alarm rate calculation module, which is used to calculate the global false alarm rate R FP,global , , an adjustment module, which is used to adjust the global verification parameter θ if R FP,global is greater than the preset global false alarm threshold, so that: global where, θ is the global verification parameter before adjustment; global old ; The distribution module is used to distribute the adjusted global verification parameter θ global to each node.

[0032] Optionally, the network security monitoring system further includes: A vulnerability database, which is used to store known vulnerability features and attack features captured by traps; A supply chain trust evaluation module, which is used to obtain the supply chain trust score T corresponding to the client request SC .

[0033] In the third aspect of the present application, a computing device cluster is provided. The computing device cluster includes at least one computing device, and each computing device includes a processor and a memory; the processor of the at least one computing device is used to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the above-mentioned network security monitoring method based on dynamic vulnerability verification.

[0034] In the fourth aspect of the present application, a computer-readable storage medium is provided. The computer-readable storage medium stores computer instructions, and the computer instructions are used to be executed by the computer to execute the above-mentioned network security monitoring method based on dynamic vulnerability verification.

[0035] The network security monitoring method and system based on dynamic vulnerability verification provided by this application distinguish client requests. For administrator vulnerability verification requests, keys are generated based on real-time system metrics, defense status parameters, and supply chain trust scores to encrypt the requested data, enabling the generated keys to resist supply chain contamination, quantum attacks, reverse engineering, and future computing power threats, effectively preventing data leakage and greatly enhancing the security of vulnerability verification during system operation. For the encrypted data, feature similarity verification is performed based on a vulnerability database, and behavior deviation and taint tracking verification can also be combined to reduce the misjudgment rate of vulnerability verification. Moreover, the method and system provided by this application also integrate vulnerability verification results with real-time defense, and update the vulnerability database, optimize verification parameters, and / or optimize defense parameters according to the defense effect, realizing a closed-loop vulnerability verification and defense evolution system, further enhancing the security, real-time performance, and dynamic adaptability of vulnerability verification during system operation, reducing the false alarm rate and missed alarm rate of vulnerabilities, and realizing a defense ecosystem that becomes stronger with use. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] Other features, objectives, and advantages of this application will become more apparent by reading the detailed description of the non-limiting embodiments with reference to the following drawings: Figure 1 It is a flowchart of a network security monitoring method based on dynamic vulnerability verification of this application; Figure 2 It is a flowchart of step S102 in an implementation manner of the network security monitoring method of this application; Figure 3 It is a flowchart of step S103 in an implementation manner of the network security monitoring method of this application; Figure 4 It is a structural diagram of an implementation manner of a network security monitoring system based on dynamic vulnerability verification of this application; Figure 5 It is a structural diagram of another implementation manner of a network security monitoring system based on dynamic vulnerability verification of this application; Figure 6 It is a schematic structural diagram of a computer system of a server for implementing the method, system, and device embodiments of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0037] The following further elaborates on this application in conjunction with the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related invention and are not intended to limit the invention. Additionally, it should be noted that for the sake of description, only parts related to the relevant invention are shown in the drawings.

[0038] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments may be combined with each other. The following will describe the present application in detail with reference to the drawings and in combination with the embodiments.

[0039] The present application provides a network security monitoring method based on dynamic vulnerability verification, which is applied to a network node or a central server, such as Figure 1 shown, the method includes: Step S101: Receive a client request. If the client request is an administrator vulnerability verification request, generate an administrator dynamic key Kt based on real-time system metrics, defense status parameters, and the supply chain trust score TSC corresponding to the client request, and encrypt the data to be verified based on the administrator dynamic key Kt; Step S102: Verify the encrypted data to be verified based on the vulnerability database; Step S103: If the data to be verified is suspicious or abnormal after verification, calculate the defense level of the data to be verified, and perform defense according to the defense level; Step S104: Update the vulnerability database according to the defense effect data, and update the verification parameters and / or defense parameters.

[0040] Specifically, step S101 receives a client request and differentiates the client request. Specifically, the request type can be parsed according to the client original message request protocol to achieve the differentiation of the client request. If the client request is an ordinary user request, a common user key can be generated for the data of the ordinary user request for encryption. The common user key can be a fixed AES (Advanced Encryption Standard)-128 key, and the encrypted data can be responded to the client. If the client request is an administrator vulnerability verification request, then step S101 is based on real-time system metrics (such as the number of registered users V1, the number of visits V2), defense status parameters (such as the attack frequency F a , the number of blocked IPs N b ), and the supply chain trust score T SC corresponding to the client request, generate an administrator dynamic key K t , and encrypt the data to be verified of the administrator vulnerability verification request based on the administrator dynamic key K t .

[0041] Specifically, the credibility of the supply chain corresponding to the client request can be evaluated according to the validity of the code signature certificate (such as whether it is issued by a trusted CA), the reputation score of the open source library maintainer (such as the number of GitHub stars, the activity of contributors), and the security of the update channel (such as whether it is distributed through HTTPS), and calculated through the following formula:

[0042] Among them, ω1, ω2, and ω3 are weight coefficients, and ω1 = 0.5, ω1 = 0.3, ω1 = 0.2 can be set; SignScore is the signature validity. If the signature is valid, SignScore = 1; if the signature is invalid, SignScore = 0; RepoScore is the maintainer's reputation, which can be normalized to a value in the range [0, 1]; Channelcore is the security of the transmission protocol. If the transmission protocol is HTTPS, Channelcore = 1 can be set; if the transmission protocol is HTTP, Channelcore = 0.5 can be set; if the transmission protocol is other, Channelcore = 0 can be set.

[0043] Specifically, the administrator's dynamic key K t is calculated through the following formula: , where V1 is the number of registered users, V2 is the traffic volume, F a is the attack frequency; N b is the number of blocked IPs, QC_Hash is a quantum-resistant hash function based on quantum random walk, which outputs a 256-bit hash value, (Fa·Nb) is the current defense state encoding, and Chaos(V2, t) is a chaotic sequence generation function with the traffic volume V2 as the initial value. The expression of Chaos(V2, t) is: , where r represents the Logistic map, r = 3.99, and x n = V2 / 10 6 , and t is the current timestamp, which is iterated once per second.

[0044] This application generates a key based on real-time system metrics, defense state parameters, and supply chain trust scores, enabling the generated key to resist supply chain pollution, quantum attacks, reverse engineering, and future computing power threats, effectively preventing data leakage, thus making it possible to perform vulnerability verification during system operation and greatly improving the security of vulnerability verification during system operation.

[0045] After encrypting the data to be verified in the administrator's vulnerability verification request using the administrator's dynamic key K t , step S102 verifies the encrypted data to be verified based on the vulnerability database and is executed in the verification engine module. Specifically, as Figure 2 shown, step S102 includes: Step S1021, decrypt the data to be verified and extract the features of the data to be verified to construct a vector V.

[0046] Specifically, use the administrator's dynamic key K tDecrypt the data to be verified, and then the features of the data to be verified can be extracted according to the characteristics of the data to be verified, such as the length of the request parameter, the proportion of special characters, the keyword density (such as the occurrence frequency of UNION and SELECT in SQL), the request time interval, the geographical entropy value of the source IP, etc., to construct a vector V.

[0047] Step S1022: Match the feature construction vector V with the vulnerability database and calculate the feature similarity S.

[0048] Specifically, in one implementation , where V i is the i-th dimensional value of the traffic feature of the data to be verified. The traffic feature is the feature corresponding to the real-time traffic index in the feature construction vector of the data to be verified. The traffic feature can specifically include the length of the request parameter, the proportion of special characters, the keyword density, the request frequency, the encrypted traffic entropy value, the API call chain depth, and the geographical location dispersion degree, etc. C i is the i-th dimensional standard value of the feature in the vulnerability database corresponding to the traffic feature, that is, the i-th dimensional feature value of the feature corresponding to C i in the vulnerability database.

[0049] Step S1023: If S < S1, calculate the behavior deviation degree D of the data to be verified.

[0050] Specifically, S1 is a preset similarity threshold. For example, let S1 be 0.8. If S < S1, it means that there is no feature in the vulnerability database that matches the feature construction vector. Therefore, the behavior deviation degree is further calculated for verification. In one implementation, the calculation of the behavior deviation degree D can also be not restricted by the condition S < S1, that is, the calculation of the behavior deviation degree D and the calculation of the feature similarity can be executed synchronously.

[0051] Specifically, , where T is the time window length, and the default value is 60 seconds. x t is the traffic feature of the data to be verified, LSTM is a pre-trained LSTM (Long Short-Term Memory) prediction model, λ is the entropy value weight coefficient, and λ can be set to 0.2. H IB is the implicit behavior entropy of the traffic feature. , where , x is an implicit behavior event. The implicit behavior event can be an unconventional memory access mode (such as an abnormal jump of the stack pointer), a reflective API call (such as dynamically loading a malicious module through dlopen), and / or a resource state-dependent operation (such as modifying a sensitive memory area under high load), etc.

[0052] Step S1024, perform taint propagation tracking on the data to be verified.

[0053] In the above steps, step S1024 and step S1022, and step S1024 and step S1023 can be executed synchronously, and the writing order does not limit the execution order.

[0054] Step S1025, if S < S1 and D < D1, and the data to be verified does not trigger a dangerous function, then determine that the data to be verified is normal.

[0055] Step S1026, if S1 ≤ S < S2, or D1 ≤ D < D2, or the taint propagation path of the data to be verified has no result, then determine that the data to be verified is suspicious; Step S1027, if S ≥ S2, or D ≥ D2, or the data to be verified triggers a dangerous function, then determine that the data to be verified is abnormal, where S1 and S2 are preset feature similarity thresholds, S1 < S2, and D1 and D2 are preset behavior deviation thresholds, D1 < D2.

[0056] Specifically, if the feature similarity is less than the preset threshold S1, that is, there is no feature in the vulnerability library that matches the feature construction vector, and the behavior deviation is less than the preset threshold D1, that is, the behavior deviation is within the allowable range, and the result of the taint propagation tracking is that the data to be verified does not trigger a dangerous function, then determine that the data to be verified is normal; If the feature similarity is between the lower threshold S1 and the upper threshold S2 (including equal to S1), that is, there are features in the vulnerability library that are relatively similar to the feature construction vector, or the behavior deviation is between the lower threshold D1 and the upper threshold D2 (including equal to D1), that is, the behavior deviation exceeds the allowable range but does not exceed the upper limit, or the result of the taint propagation tracking is unclear, then determine that the data to be verified is suspicious; If the feature similarity is greater than or equal to the upper threshold S2, that is, there are features in the vulnerability library that are highly similar to the feature construction vector, or the behavior deviation is greater than or equal to the upper threshold D2, that is, the behavior deviation is serious, or the result of the taint propagation tracking is that the data to be verified triggers a dangerous function, then determine that the data to be verified is abnormal.

[0057] In one implementation, before performing taint propagation tracking and behavior deviation judgment, step S102 further includes: If T sc is less than the preset first threshold, reduce the thresholds D1 and D2 corresponding to the behavior deviation D, and the taint propagation tracking adds dynamic memory boundary checking; If T sc is less than the preset first threshold and H IBGreater than a preset third threshold of 2.0, the taint propagation tracking increases dynamic memory boundary checking; If T sc Is less than a preset second threshold, continue to reduce the thresholds D1 and D2 corresponding to the behavior deviation degree D, and the taint propagation tracking increases dynamic memory boundary checking; If T sc Is less than a preset second threshold or if H IB Is greater than a preset third threshold, put the data to be verified into a sandbox for verification, and the second threshold is less than the first threshold; If the result of the sandbox verification is abnormal, determine that the data to be verified is abnormal. If the result of the sandbox verification is not abnormal, determine that the data to be verified is suspicious.

[0058] Specifically, step S102 can also first perform a judgment on the supply chain trust score T sc And H IB If T sc Is less than a preset first threshold (for example, set to 0.6), that is, the supply chain trust score is low, then strengthen the verification, improve the detection sensitivity, for example, reduce the thresholds D1 and D2 corresponding to the behavior deviation degree D, and the taint propagation tracking increases dynamic memory boundary checking; If T sc Is less than a preset first threshold and H IB Is greater than a preset third threshold (for example, set to 2.0), that is, the supply chain trust score is low and the implicit behavior entropy is too high (the behavior pattern deviates from the normal baseline), then strengthen the verification, for example, the taint propagation tracking increases dynamic memory boundary checking.

[0059] If T sc Is less than a preset second threshold, that is, the supply chain trust score is too low, further strengthen the verification and improve the detection sensitivity, continue to reduce the thresholds D1 and D2 corresponding to the behavior deviation degree D, and the taint propagation tracking increases dynamic memory boundary checking. The second threshold (for example, set to 0.4) is less than the first threshold. Among them, the taint propagation tracking can refer to the prior art and will not be elaborated.

[0060] Furthermore, if T sc Is less than a preset second threshold, or if H IBIf it is greater than a preset third threshold, the data to be verified is placed in a sandbox for verification, that is, the supply chain trust score is too low or the implicit behavior entropy is too high, and the data to be verified is forced to be replayed and verified in the sandbox: If the result of the sandbox verification is abnormal, it is determined that the data to be verified is abnormal; if the result of the sandbox verification is not abnormal, it is determined that the data to be verified is suspicious. In one implementation, the result priority of the sandbox replay verification is higher than the results of the feature similarity, behavior deviation, and taint propagation tracking verification, that is, after the sandbox replay verification, there is no need to perform the feature similarity, behavior deviation, and taint propagation tracking verification; in another implementation, the result of the sandbox replay verification corroborates the results of the feature similarity, behavior deviation, and taint propagation tracking verification. If there is a conflict, the more serious result is taken. For example, if the result of the sandbox replay verification is suspicious and the verification results of the feature similarity, behavior deviation, and taint propagation tracking are abnormal, the verification result of abnormal is taken.

[0061] If the data to be verified is normal, no processing or defense is performed. Otherwise, step S103 is executed: If the data to be verified is suspicious or abnormal after verification, calculate the defense level of the data to be verified and perform defense according to the defense level. Specifically, as Figure 3 shown, step S103 includes: Step S1031, use the blocking weight W to represent the defense level and calculate the blocking weight W: , where α, β, and γ are preset dynamic weight coefficients, D is the behavior deviation, δ is the preset defense tolerance, δ is a fixed value and does not change with T sc changes, δ can take the value of 0.1, δ is greater than 0, and the lower T sc is, the higher the blocking weight W; the entropy value of the key strength is K t If the data to be verified is suspicious, the threat level is a preset first-level value; if the data to be verified is abnormal, the threat level is a preset second-level value. In one implementation, α is greater than 0, and the first-level value is less than the second-level value. For example, the first-level value can take 1-2, and the second-level value takes 3-4. If the verification result is normal, the threat level is 0.

[0062] Step S1032, if the blocking weight W < W1, that is, the defense level is extremely low and belongs to the range that does not require defense, no defense action is taken; Step S1033, if W1 ≤ W < W2, that is, the defense level belongs to the first-level defense range, throttle the request corresponding to the data to be verified and perform short-term monitoring for a preset duration (such as half an hour); Step S1034, if W2 ≤ W < W3, that is, the defense level belongs to the second-level defense range of the higher level, the defense means is upgraded, the IP of the request corresponding to the data to be verified is blocked and the blocking duration reaches the preset first duration, and a basic trap page is generated; Step S1035, if W ≥ W3, that is, the defense level belongs to the third-level defense range of the even higher level, the defense means is further upgraded, the IP of the request corresponding to the data to be verified is blocked and the blocking duration reaches the preset second duration, and the second duration (such as 24 hours) is greater than the first duration (such as 6 hours), and an advanced trap is generated, and threat intelligence can also be synchronized; Wherein, W1, W2, and W3 are preset level thresholds, and W1 < W2 < W3. For example, let W1 = 1.5, W2 = 2.0, and W3 = 3.0.

[0063] In one implementation, before performing defense according to the blocking weight, the network security monitoring method provided by the present application further includes: according to the attack frequency F a Dividing the preliminary defense level and allocating defense resources according to the preliminary defense level.

[0064] Specifically, if F a < F1, the preliminary defense level is low; if F1 ≤ F a < F2, the preliminary defense level is medium; if F a ≥ F2, the preliminary defense level is high. F1 < F2. For example, F1 is 10 times / minute and F2 is 50 times / minute. Defense resources can be allocated according to the preliminary defense level. For example, more defense resources are allocated when the defense level is high, and then specific defense actions are performed according to the blocking weight, which can not only prevent unnecessary resource waste but also ensure sufficient defense resources to complete the defense actions.

[0065] In one implementation, before performing defense according to the defense level, it further includes: if T sc is less than the preset second threshold, that is, if the trust score of the supply chain corresponding to the request is too low, perform a stricter defense and block the IP of the request corresponding to the data to be verified.

[0066] In one implementation, if the data to be verified is suspicious or abnormal after the foregoing verification, before calculating the defense level of the data to be verified, the network security monitoring method provided by the present application further includes performing secondary detection on the data to be verified, and the secondary detection includes: If the data to be verified is determined to be suspicious after verification, replay the suspicious encrypted data in a sandbox (replay in an isolated environment and monitor its behaviors such as memory modification, system calls, network connections, etc.) and execute the data to be verified (execute in a virtual environment). If there are no dangerous behaviors in the sandbox, it is determined that the data to be verified is normal, and the data can be recorded as a false positive. If unconventional operations are detected and no attacks are detected (such as temporary file creation), it is determined that the data to be verified is suspicious. If a vulnerability exploitation is triggered (such as buffer overflow), it is determined that the data to be verified is abnormal. If the data to be verified is determined to be abnormal after verification, perform probe interaction analysis on the data to be verified (such as returning a false vulnerability page containing dynamic probes to monitor the subsequent behaviors of the attacker). If the attacker does not trigger the probe (such as only scanning without submission), it is determined that the data to be verified is normal. If the attacker submits the probe and the payload is invalid (such as test input), it is determined that the data to be verified is suspicious. If the attacker submits a valid attack payload (such as exploiting the forged vulnerability in the probe), it is determined that the data to be verified is abnormal. Then, calculate the defense level for the data to be verified that is determined to be suspicious or abnormal after secondary detection, that is, calculate the banning weight W.

[0067] Among them, probe interaction analysis can use existing technologies. In one implementation, a trap probe can be generated according to the following formula: , where "||" is the byte concatenation operation, and QC_Hash is a quantum-resistant hash function.

[0068] In one implementation, when verifying the encrypted data to be verified based on the vulnerability database, only feature similarity verification can be performed. In another implementation, feature similarity verification and behavior deviation verification can be combined. In yet another implementation, feature similarity verification, behavior deviation verification, and taint tracking verification can be combined.

[0069] The network security monitoring method provided by this application, for encrypted data, based on the vulnerability database through feature similarity verification, can also combine behavior deviation and taint tracking verification, effectively reducing the false positive rate and false negative rate of vulnerability verification. Moreover, the method provided by this application also combines the vulnerability verification result with real-time defense to ensure the real-time security of system operation. At the same time, the multi-dimensional attack features (threat level, behavior deviation, key security) are quantified into a single index through the banning weight, and different defense actions are selected according to the weight value to achieve defense classification, thereby guiding precise defense and improving the "one-size-fits-all" defense problem in traditional solutions, achieving the balance between system security and availability.

[0070] After performing defense according to the defense level, in step S104, update the vulnerability database, update the verification parameters, and / or update the defense parameters according to the defense effect data.

[0071] Specifically, in one implementation, the defense effect data includes false positive rate, false negative rate, traffic baseline smoothness, and key update frequency. Updating the defense parameters according to the defense effect data includes: If the false positive rate is greater than a preset fourth threshold, then decrease the value of α in the calculation of the blocking weight; if the false negative rate is greater than a preset fifth threshold, then increase the value of α; If the traffic baseline smoothness is within a preset range, then increase the value of β in the calculation of the blocking weight; if the traffic baseline smoothness is outside the preset range, then decrease the value of β; If the key update frequency is less than or equal to a preset sixth threshold, maintain the value of γ in the calculation of the blocking weight; if the key update frequency is greater than the preset sixth threshold, increase the value of γ, where α, β, and γ are all values greater than 0.

[0072] That is, if the false positive rate is too high, then decrease the value of α to decrease the blocking weight, that is, decrease the defense level, thereby decreasing the false positive rate; if the false negative rate is too high, then increase the value of α to increase the blocking weight, that is, increase the defense level, thereby decreasing the false negative rate. The above α is greater than 0. If α is negative, then if the false positive rate is too high, increase the value of α; if the false negative rate is too high, decrease the value of α.

[0073] If the traffic baseline smoothness is within a preset range, then appropriately increase the value of β to appropriately increase the blocking weight and improve the detection sensitivity; if the traffic baseline smoothness is outside the preset range, that is, the traffic baseline fluctuates greatly, then appropriately decrease the value of β to decrease the blocking weight and reduce misjudgment. The above β is greater than 0. If β is negative, then if the traffic baseline smoothness is within a preset range, decrease the value of β; if the traffic baseline fluctuates greatly, increase the value of β.

[0074] If the key update frequency is less than or equal to a preset sixth threshold, that is, the key update is not frequent, then the value of γ can be maintained, that is, the blocking weight is maintained; if the key update frequency is greater than the preset sixth threshold, that is, the key update is frequent and the leakage risk is high, then increase the value of γ, that is, increase the blocking weight to improve the detection sensitivity. The above γ is greater than 0. If γ is negative, then if the key update is frequent, decrease the value of γ; if the false negative rate is too high, increase the value of γ The defense effect data can be calculated and obtained according to the prior art.

[0075] Specifically, in one implementation, the defense effect data includes false positive rate and false negative rate, and the verification parameters include feature similarity threshold and behavior deviation threshold. Updating the verification parameters according to the defense effect data includes: If the false positive rate R FP is greater than a preset false positive threshold, calculate a new behavior deviation threshold D th new: , where η D is a preset learning rate of behavior deviation, which can be set to 0.1, is a preset loss value of behavior deviation, which can be set to 0.05, D th new is the updated behavior deviation threshold, including the new behavior deviation thresholds D1 and D2, D th old is the current behavior deviation threshold, that is, the behavior deviation threshold before update (calculating the new behavior deviation threshold), D th old also includes the behavior deviation thresholds D1 and D2, that is, the upper and lower behavior deviation thresholds are updated by the above formula (that is, D in the formula th is D1 or D2), when the false alarm rate R FP is too high, it indicates that the system is too sensitive, and the judgment condition needs to be relaxed, and the behavior deviation threshold needs to be increased to reduce false alarms.

[0076] If the missed alarm rate R FN is greater than the preset missed alarm threshold, calculate the new feature similarity threshold S th new : , where η S is a preset learning rate of feature similarity, which can be set to 0.1, is a preset loss value of feature similarity, which can be set to 0.05, S th new is the updated behavior deviation threshold, including the new feature similarity thresholds S1 and S2, S th old is the current feature similarity threshold, that is, the feature similarity threshold before update (calculating the new feature similarity threshold), S th old also includes the feature similarity thresholds S1 and S2, that is, the upper and lower feature similarity thresholds are updated by the above formula (that is, S in the formula th is S1 or S2), when the missed alarm rate R FN is too high, it indicates that the system sensitivity is insufficient, and the feature similarity threshold is reduced to improve the detection sensitivity.

[0077] Specifically, in one implementation, the updating the vulnerability database according to the defense effect data includes: Capturing the attack payload to obtain the standardized feature vector V corresponding to the attack payload new , and the capturing of the attack payload and obtaining the standardized feature vector corresponding to the attack payload can refer to the existing technology, which will not be elaborated here.

[0078] Calculate V new The maximum similarity S with the existing features in the vulnerability database max , , where C j is the feature vector of the j-th vulnerability existing in the vulnerability database, and m is the number of vulnerabilities in the vulnerability database; If S max is less than the preset matching threshold, add V new to the vulnerability database. The network security monitoring method provided by this application writes the attack features captured by the trap into the vulnerability database, and the attack features are real-time from capture to storage, which not only improves the detection coverage rate, realizes the self-update of the vulnerability database, but also improves the system's dynamic adaptability and security.

[0079] For the above-mentioned update of the vulnerability database, update of verification parameters, and update of defense parameters, according to security requirements and resource conditions, one of them can be selected, or any two of them can be selected, or all of them can be executed. The update of the vulnerability database, update of verification parameters, and update of defense parameters can be executed sequentially or synchronously.

[0080] The network security monitoring method provided by this application updates the vulnerability database, optimizes verification parameters and / or optimizes defense parameters according to the defense effect, realizes a closed-loop vulnerability verification and defense evolution system, further improves the security, real-time performance and dynamic adaptability of vulnerability verification during system operation, reduces the false alarm rate and missed alarm rate of vulnerabilities, and realizes a defense ecosystem that becomes stronger with use.

[0081] In one implementation, the network security monitoring method provided by this application is not limited to updating the feature similarity threshold and behavior deviation threshold according to the defense effect, but can also update other verification parameters according to the defense effect, such as LSTM model parameters and implicit behavior entropy calculation model parameters. The update algorithm can refer to the calculation of the aforementioned update of the feature similarity threshold and behavior deviation threshold.

[0082] In one implementation, the network security monitoring method provided by this application may further include: updating the supply chain trust score T according to the historical frequency of supply chain attacks SC : , where ν is the preset learning rate, and R attack is the historical frequency of supply chain attacks, R normal = number of normal client requests / total number of client requests, T SC,new is the updated supply chain trust score, and T SC,old is the supply chain trust score before update; T SC can be updated when the historical frequency of supply chain attacks is greater than the preset threshold, or T SC can be updated periodically. By dynamically optimizing T SC, which can improve the real-time performance and security of the administrator's dynamic key and ban weight calculation, and ensure the security and accuracy of vulnerability verification and defense during system operation.

[0083] Further, in one implementation, the network security monitoring method provided by the present application may further include: updating the administrator's dynamic key generation parameter V2 (traffic volume) according to the number of attacks: , where V2' is the updated value of V2. Thus, the higher the attack frequency, the greater the perturbation amplitude of V2, the randomness of the key is enhanced, and by updating V2, the anti-attack ability of the key can be more effectively improved, and the security of the key can be enhanced.

[0084] The network security monitoring method provided by the present application may also update the key parameters (such as the supply chain trust score T SC , traffic volume V2) according to the defense effect data (such as the number of attacks, the historical frequency of supply chain attacks), realizing the dynamic binding of the key-vulnerability, making the key generation parameters strongly correlated with the vulnerability verification and defense results, realizing the self-adaptability of attack defense, and solving the lag problem of traditional systems relying on fixed rules.

[0085] The network security monitoring method provided by the present application can be applied to each node of the distributed system. When the network security monitoring method is applied to the central server or aggregation node of the distributed system, updating the verification parameters according to the defense effect data may further include: Obtaining the verification parameters and implicit behavior entropy statistics of all nodes in the network. Specifically, the verification parameters of the nodes are the same as those of the central server, such as the feature similarity threshold and the behavior deviation threshold, etc.; Aggregating and calculating to obtain the global verification parameter θ global : , where DT i is the data volume of node i, DT total is the data volume of all nodes, N is the number of nodes, θ i is the verification parameter of node i, θ i can be the feature similarity threshold and / or the behavior deviation threshold (that is, θ global and θ i are S1, S2, D1 or D2), θ i can also be other verification parameters, μ is a preset correction coefficient, η is a preset learning rate, is the loss function gradient, Based on V new calculation, H IBN,i is the implicit behavior entropy statistic of node i, H IBN,i only participates in the calculation of the global verification parameter, , where T is the statistical period, and H IBN (t) is the real-time implicit behavior entropy of node i at time t, , where , and y is the implicit behavior event of node i; The global verification parameter θ is aggregated and calculated based on the verification parameters and implicit behavior entropy statistics of each node global After that, the global verification parameter θ global is distributed to each node (including the central server itself), and each node uses the global verification parameter θ global as the new verification parameter.

[0086] Specifically, the aggregation of the global verification parameter and the distribution can be executed periodically or triggered when a new feature V new is formed. The network security monitoring method provided by this application can dynamically optimize the global parameters through the method of global aggregation federated learning, and multi-node collaborative optimization of the verification parameters, so as to cover a wider range of attack patterns and resist distributed attacks.

[0087] Furthermore, for the network security monitoring method provided by this application, before distributing the global verification parameter θ global to each node, it may further include: Obtain the false alarm times and total detection times of all nodes, and calculate the global false alarm rate R FP,global , , if R FP,global is greater than the preset global false alarm threshold (for example, 5%), adjust the global verification parameter θ global such that:

[0088] where θ global old is the global verification parameter before adjustment; Distribute the adjusted global verification parameter θ global to each node, and each node uses the global verification parameter θ global as the new verification parameter.

[0089] This implementation mode comprehensively considers the global false alarm rate. When the global false alarm rate is too high, the global verification parameter is adjusted, so that the global verification parameter is further optimized, effectively reducing the global false alarm rate and improving the global verification and defense effect.

[0090] Correspondingly, when the network security monitoring method provided by this application is applied to a node, it may further include: responding to an instruction from the central server, reporting verification parameters and implicit behavior entropy statistics to the central server, and in one implementation manner, may also respond to an instruction from the central server and report the number of false alarms and the total number of detections to the central server; and receiving the global verification parameter θ issued by the central server global , and updating the local verification parameters according to the global verification parameter θ global

[0091] Although the above steps are described in the above order in the above embodiments, those skilled in the art can understand that in order to achieve the effects of this embodiment, different steps do not have to be executed in such an order, and they can be executed simultaneously (in parallel) or in a reversed order, and these simple changes are all within the protection scope of this application.

[0092] In a second aspect, this application provides a network security monitoring system based on dynamic vulnerability verification, as Figure 4 shown, the system includes: A traffic classification and processing module, configured to receive a client request and distinguish whether the client request is an administrator vulnerability verification request; An encryption module, configured to, if the client request is an administrator vulnerability verification request, generate an administrator dynamic key K based on real-time system metrics, defense status parameters, and the supply chain trust score T corresponding to the client request SC , and encrypt the data to be verified based on the administrator dynamic key K t , and based on the administrator dynamic key K t A verification engine module, configured to verify the encrypted data to be verified based on a vulnerability database; A defense linkage module, configured to, if the data to be verified is suspicious or abnormal after verification, calculate the defense level of the data to be verified and perform defense according to the defense level; A feedback and optimization module, configured to update the vulnerability database, update verification parameters, and / or update defense parameters according to defense effect data.

[0093] Specifically, the traffic classification and processing module receives a client request and distinguishes the client request. If the client request is an ordinary user request, a common user key can be generated for encrypting the data of the ordinary user request, and the encrypted data can be returned to the client. If the client request is an administrator vulnerability verification request, the encryption module is based on real-time system metrics (such as the number of registered users V1, the traffic volume V2), defense status parameters (such as the attack frequency F a , the number of blocked IPs N b ), and the supply chain trust score T corresponding to the client request SC ​​, generate the administrator dynamic key K t , and based on the administrator dynamic key K t , encrypt the data to be verified in the administrator vulnerability verification request. Specifically,

[0094] Among them, ω1, ω2, and ω3 are weight coefficients, and ω1 = 0.5, ω1 = 0.3, ω1 = 0.2 can be set; SignScore is the signature validity, SignScore = 1 if the signature is valid, and SignScore = 0 if the signature is invalid; RepoScore is the maintainer's reputation, which can be normalized to a value within the range [0,1]; Channelcore is the security of the transmission protocol. If the transmission protocol is HTTPS, Channelcore = 1 can be set. If the transmission protocol is HTTP, Channelcore = 0.5 can be set. If the transmission protocol is other, Channelcore = 0 can be set.

[0095] Specifically, , Among them, V1 is the number of registered users, V2 is the traffic volume, F a is the attack frequency; N b is the number of blocked IPs, QC_Hash is a quantum-resistant hash function based on quantum random walk, which outputs a 256-bit hash value, (Fa·Nb) is the current defense state encoding, and Chaos(V2,t) is a chaotic sequence generation function with the traffic volume V2 as the initial value. The expression of Chaos(V2,t) is: , where r represents the Logistic map, r = 3.99, x n = V2 / 10 6 , and t is the current timestamp, which is iterated once per second.

[0096] The system provided by this application generates a key based on real-time system metrics, defense state parameters, and supply chain trust scores, enabling the generated key to resist threats such as supply chain pollution and quantum attacks, effectively preventing data leakage, thereby realizing vulnerability verification during system operation, and greatly improving the security of vulnerability verification during system operation.

[0097] After being encrypted by the encryption module, the verification engine module verifies the encrypted data to be verified based on the vulnerability library. In one implementation, the verification engine module includes: A decryption module, which is used to decrypt the data to be verified and extract the features of the data to be verified to construct a vector V. Specifically, the administrator dynamic key K t decrypts the data to be verified; A matching module for matching the feature construction vector V with the vulnerability database and calculating the feature similarity S. Specifically, in one implementation, , where V i is the i-th dimensional value of the traffic feature of the data to be verified, and the traffic feature is the feature corresponding to the real-time traffic index in the feature construction vector of the data to be verified. C i is the i-th dimensional standard value of the feature in the vulnerability database corresponding to the traffic feature; A behavior deviation detection module for calculating the behavior deviation degree D of the data to be verified if S < S1. Specifically, S1 is a preset similarity threshold. If S < S1, it means that there is no feature in the vulnerability database that matches the feature construction vector. Therefore, the behavior deviation degree is further calculated for verification. In one implementation, the calculation of the behavior deviation degree D can also be not restricted by the condition S < S1, that is, the calculation of the behavior deviation degree D and the calculation of the feature similarity can be executed synchronously. , where T is the time window length, and the default value is 60 seconds. x t is the traffic feature of the data to be verified, λ is the entropy value weight coefficient, and λ can be set to 0.2. H IB is the implicit behavior entropy of the traffic feature. , where , x is the implicit behavior event; A taint propagation tracking module for performing taint propagation tracking on the data to be verified; A verification module for determining that the data to be verified is normal if S < S1 and D < D1, and the data to be verified does not trigger a dangerous function; and for determining that the data to be verified is suspicious if S1 ≤ S < S2, or D1 ≤ D < D2, or the taint propagation path of the data to be verified has no result; and for determining that the data to be verified is abnormal if S ≥ S2, or D ≥ D2, or the data to be verified triggers a dangerous function; where S1, S2 are preset feature similarity thresholds, and D1, D2 are preset behavior deviation thresholds.

[0098] In one implementation, the taint propagation tracking module is further used for: if T sc is less than a preset first threshold, performing a dynamic memory boundary check; if T sc is less than a preset first threshold and if H IB is greater than a preset third threshold, performing a dynamic memory boundary check; if T sc is less than a preset second threshold, performing a dynamic memory boundary check.

[0099] In one embodiment, before determining the behavior deviation degree, the verification module is further configured to: if T sc is less than a preset first threshold, reduce the thresholds D1 and D2 corresponding to the behavior deviation degree D; if T sc is less than a preset second threshold, reduce the thresholds D1 and D2 corresponding to the behavior deviation degree D; if T sc is less than a preset second threshold or if H IB is greater than a preset third threshold, put the data to be verified into a sandbox for verification; if the result of the sandbox verification is abnormal, determine that the data to be verified is abnormal, and if the result of the sandbox verification is not abnormal, determine that the data to be verified is suspicious.

[0100] If the data to be verified is normal, the system does not perform any processing or defense. Otherwise, the defense linkage module performs defense. In one embodiment, the defense linkage module includes: A defense level calculation module, configured to calculate a banning weight W: , where α, β, and γ are preset dynamic weight coefficients, the key strength is the entropy value of K t , if the data to be verified is suspicious, the threat level is a preset first level value, and if the data to be verified is abnormal, the threat level is a preset second level value.

[0101] In one embodiment, the defense linkage module further includes a secondary detection module. The secondary detection module is configured to, if the verification engine module verifies that the data to be verified is suspicious or abnormal, perform secondary detection on the data to be verified before the defense level calculation module calculates the defense level of the data to be verified. The secondary detection module includes: A suspicious data secondary detection module, configured to, if the verification engine module verifies that the data to be verified is suspicious data, replay the data to be verified in the sandbox and execute the data to be verified. If there is no dangerous behavior in the sandbox, determine that the data to be verified is normal; if an unconventional operation is detected and no attack is detected, determine that the data to be verified is suspicious; if a vulnerability exploitation is triggered, determine that the data to be verified is abnormal; An abnormal data secondary detection module, configured to, if the verification engine module verifies that the data to be verified is abnormal data, perform probe interaction analysis on the data to be verified. If the attacker does not trigger a probe, determine that the data to be verified is normal; if the attacker submits a probe and the payload is invalid, determine that the data to be verified is suspicious; if the attacker submits a valid attack payload, determine that the data to be verified is abnormal; The defense level calculation module is configured to calculate the banning weight W of the data to be verified that is suspicious or abnormal after being detected by the secondary detection module.

[0102] The defense linkage module further includes: A defense module for performing defense according to the defense level, including: A first execution module for rate-limiting and short-term monitoring of the request corresponding to the data to be verified if W1 ≤ W < W2; A second execution module for blocking the IP of the request corresponding to the data to be verified and the blocking duration reaching a preset first duration if W2 ≤ W < W3, and generating a basic trap page; A third execution module for blocking the IP of the request corresponding to the data to be verified and the blocking duration reaching a preset second duration if W ≥ W3, and generating an advanced trap; wherein, W1, W2, and W3 are preset level thresholds, and the second duration is greater than the first duration.

[0103] In one implementation, the defense module is further configured to: divide a preliminary defense level according to the attack frequency F a and allocate defense resources according to the preliminary defense level.

[0104] Specifically, if F a < F1, determine that the preliminary defense level is low; if F1 ≤ F a < F2, determine that the preliminary defense level is medium; if F a ≥ F2, determine that the preliminary defense level is high, where F1 < F2. Defense resources can be allocated according to the preliminary defense level, and then specific defense actions are performed according to the blocking weight, which can prevent unnecessary resource waste and ensure sufficient defense resources to complete the defense actions.

[0105] In one implementation, the defense module is further configured to: block the IP of the request corresponding to the data to be verified if T sc is less than a preset second threshold, that is, if the trust score of the supply chain corresponding to the request is too low, perform a stricter defense.

[0106] In one implementation, in the network security monitoring system described in this application, the defense effect data includes false alarm rate, missed alarm rate, traffic baseline smoothness, and key update frequency. The feedback optimization module includes a defense parameter adjustment module, and the defense parameter adjustment module includes: A first weight adjustment module for reducing the α value in the calculation of the blocking weight if the false alarm rate is greater than a preset fourth threshold; and increasing the α value if the missed alarm rate is greater than a preset fifth threshold.

[0107] A second weight adjustment module for increasing the β value in the calculation of the blocking weight if the traffic baseline smoothness is within a preset range; and reducing the β value if the traffic baseline smoothness is outside the preset range; The third weight adjustment module is used to keep the γ value in the calculation of the ban weight if the key update frequency is less than or equal to a preset sixth threshold; if the key update frequency is greater than the preset sixth threshold, increase the γ value.

[0108] That is, if the false alarm rate is too high, the α value is decreased to reduce the ban weight, that is, to reduce the defense level, thereby reducing the false alarm rate; if the missed alarm rate is too high, the α value is increased to increase the ban weight, that is, to increase the defense level, thereby reducing the missed alarm rate. The above α is greater than 0. If α is negative, then if the false alarm rate is too high, the α value is increased; if the missed alarm rate is too high, the α value is decreased, and so on. If the traffic baseline smoothness is within the preset range, the β value can be appropriately increased to appropriately increase the ban weight and improve the detection sensitivity; if the traffic baseline smoothness is outside the preset range, that is, the traffic baseline fluctuates greatly, the β value can be appropriately decreased to reduce the ban weight and reduce misjudgment. If the key update frequency is less than or equal to the preset sixth threshold, that is, the key is not updated frequently, the γ value can be kept, that is, the ban weight is kept; if the key update frequency is greater than the preset sixth threshold, that is, the key is updated frequently and the leakage risk is high, the γ value is increased, that is, the ban weight is increased, to improve the detection sensitivity.

[0109] In one implementation, in the network security monitoring system described in this application, the defense effect data includes the false alarm rate and the missed alarm rate, the verified parameters include the feature similarity threshold and the behavior deviation threshold, and the feedback optimization module includes a verified parameter adjustment module. The verified parameter adjustment module includes: The behavior deviation threshold adjustment module is used to calculate a new behavior deviation threshold D if the false alarm rate R FP is greater than the preset false alarm threshold th new where η is the preset behavior deviation learning rate, D is the preset behavior deviation loss value, and D includes the behavior deviation thresholds D1 and D2; th new The feature similarity threshold adjustment module is used to calculate a new feature similarity threshold S if the missed alarm rate R FN is greater than the preset missed alarm threshold th new where η is the preset feature similarity learning rate, S is the preset feature similarity loss value, and S includes the feature similarity thresholds S1 and S2. th new

[0110] ​​In one embodiment, in the network security monitoring system described in the present application, the feedback optimization module includes a vulnerability database update module, and the vulnerability database update module includes: An attack payload vector generation module, configured to capture an attack payload and obtain a standardized feature vector V corresponding to the attack payload new ; An attack payload vector evaluation module, configured to calculate the maximum similarity S between V new and the existing features in the vulnerability database max , , where C j is the feature vector of the j-th vulnerability existing in the vulnerability database, and m is the number of vulnerabilities in the vulnerability database; An update module, configured to add V max to the vulnerability database if S new is less than a preset threshold.

[0111] The above defense parameter adjustment module, verification parameter adjustment module, and vulnerability database update module can be selected to run only one of them according to security requirements and resource conditions, or any two of them can be selected to run, or all of them can be selected to run. The defense parameter adjustment module, verification parameter adjustment module, and vulnerability database update module can run sequentially or synchronously.

[0112] The network security monitoring system provided by the present application updates the vulnerability database, optimizes the verification parameters and / or optimizes the defense parameters according to the defense effect, realizes a closed-loop vulnerability verification and defense evolution system, greatly improves the security, real-time and dynamic adaptability of vulnerability verification during system operation, and reduces the false alarm rate and missed alarm rate of vulnerabilities.

[0113] In one embodiment, the network security monitoring system provided by the present application is not limited to updating the feature similarity threshold and / or behavior deviation threshold according to the defense effect. The verification parameter adjustment module in the feedback optimization module can also be used to update other verification parameters according to the defense effect, and the update algorithm can refer to the calculation of the aforementioned update feature similarity threshold and behavior deviation threshold.

[0114] In one embodiment, the network security monitoring system provided by the present application, the feedback optimization module may further include: a supply chain trust score update module, configured to update the supply chain trust score T according to the historical frequency of supply chain attacks SC : , where ν is a preset learning rate: R attack is the historical frequency of supply chain attacks; R normal = number of normal client requests / total number of client requests. The supply chain trust score update module can perform T when the historical frequency of supply chain attacks is greater than a preset thresholdSC Update, or update T periodically SC 。By dynamically optimizing T SC The real-time performance and security of the administrator's dynamic key and ban weight can be improved, and the security and accuracy of vulnerability verification and defense during system operation can be ensured.

[0115] Furthermore, in one implementation, in the network security monitoring provided by the present application, the feedback optimization module may further include a dynamic key generation parameter update module, which is used to update the administrator's dynamic key generation parameter V2 (traffic volume) according to the number of attacks: where V2' is the updated value of V2. By updating V2, the anti-attack ability of the key can be more effectively improved, and the security of the key can be enhanced.

[0116] Combining the supply chain trust score update module and the dynamic key generation parameter update module can realize the dynamic binding of keys and vulnerabilities, make the key generation strongly correlated with the vulnerability verification and defense results, and realize the self-adaptability of attack defense.

[0117] The network security monitoring system provided by the present application can be applied to each node of the distributed system. When the network security monitoring system is applied to the central server or aggregation node of the distributed system, the feedback optimization module may further include a global optimization module, and the global optimization module includes: The first node data acquisition module is used to acquire the verification parameters and implicit behavior entropy statistics of all nodes in the network; The global aggregation module is used to aggregate and calculate the global verification parameter θ global : where DT i is the data volume of node i, DT total is the data volume of all nodes, N is the number of nodes, θ i is the verification parameter of node i, θ i includes the feature similarity threshold and the behavior deviation threshold, μ is a preset correction coefficient, η is a preset learning rate, is the loss function gradient, is calculated based on V new H IBN,i is the implicit behavior entropy statistic of node i, where T is the statistical period, H IBN (t) is the real-time implicit behavior entropy of node i at time t, , where, , y is the implicit behavior event of node i; A distribution module for distributing the global verification parameter θ global to each node, and each node uses the global verification parameter θ global as a new verification parameter.

[0118] Specifically, the global aggregation module and the distribution module can run periodically or be triggered to run when a new feature V new is formed. The network security monitoring system provided by this application can dynamically optimize global parameters and cooperatively optimize verification parameters among multiple nodes, thereby being able to cover a wider range of attack patterns and resist distributed attacks.

[0119] In one implementation, the feedback optimization module further includes a global adjustment module, and the global adjustment module includes: A second node data acquisition module for acquiring the false alarm times and total detection times of all nodes before distributing the global verification parameter θ global to each node; A global false alarm rate calculation module for calculating the global false alarm rate R FP,global , , An adjustment module for adjusting the global verification parameter θ FP,global if R global is greater than a preset global false alarm threshold, such that: , where θ global old is the global verification parameter before adjustment; The distribution module for distributing the adjusted global verification parameter θ global to each node.

[0120] This implementation mode comprehensively considers the global false alarm rate. When the global false alarm rate is too high, it adjusts the global verification parameter, so that the global verification parameter is further optimized, effectively reducing the global false alarm rate and improving the global verification and defense effect.

[0121] Correspondingly, when the network security monitoring system provided by this application is applied to nodes, it may further include: a data feedback module for reporting the verification parameter and the implicit behavior entropy statistic to the central server in response to the instruction of the central server, and in one implementation mode, it may also report the false alarm times and the total detection times to the central server in response to the instruction of the central server; and a global response update module for receiving the global verification parameter θ global issued by the central server and updating the local verification parameter according to the global verification parameter θ global .

[0122] In one embodiment, the network security monitoring system provided by the present application further includes: A vulnerability database for storing known vulnerability features and attack features captured by traps.

[0123] In one embodiment, the network security monitoring system provided by the present application further includes: A supply chain trust evaluation module for obtaining the supply chain trust score T corresponding to the client request SC .

[0124] In one embodiment, as Figure 5 shown, the network security monitoring system provided by the present application further includes the vulnerability database and the supply chain trust evaluation module as described above. The vulnerability database and the supply chain trust evaluation module can be integrated into the network security monitoring system or can be arranged outside the network security monitoring system and communicate with the network security monitoring system. The feedback optimization module as described above also updates the vulnerability database and the supply chain trust evaluation value, thereby acting on the vulnerability database and the supply chain trust evaluation module and indirectly acting on the encryption module.

[0125] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working process and related descriptions of the above-described system can refer to the corresponding process in the foregoing method embodiments and will not be repeated here.

[0126] It should be noted that the network security monitoring system based on dynamic vulnerability verification provided in the above embodiments is only illustrated by the division of the above functional modules. In actual applications, the above functions can be allocated to different functional modules as needed, that is, the modules or steps in the embodiments of the present invention can be further decomposed or combined. For example, the modules in the above embodiments can be combined into one module or further split into multiple sub-modules to complete all or part of the functions described above. For the names of the modules and steps involved in the embodiments of the present invention, they are only used to distinguish each module or step and are not regarded as an improper limitation of the present invention.

[0127] In a third aspect, the present application further provides a computing device cluster, which includes at least one computing device, and each computing device includes a processor and a memory; the processor of the at least one computing device is used to execute instructions stored in the memory of the at least one computing device so that the computing device cluster executes the foregoing network security monitoring method based on dynamic vulnerability verification. The computing device cluster can form a distributed network system, and the network security monitoring method provided by the present application can be deployed in nodes and / or central servers of the distributed network system.

[0128] Fourthly, the present application also provides a computer-readable storage medium storing computer instructions for being executed by a computer to implement the foregoing network security monitoring method based on vulnerability dynamic verification.

[0129] Those skilled in the art can clearly understand that for the sake of convenience and brevity of description, the specific working processes and related descriptions of the above-described storage device and processing device can refer to the corresponding processes in the foregoing method embodiments and will not be repeated here.

[0130] Those skilled in the art should be able to realize that the modules and method steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. The programs corresponding to the software modules and method steps can be placed in a random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, register, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field. For the sake of clearly illustrating the interchangeability of electronic hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in the form of electronic hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0131] Next, refer to Figure 6 , which shows a schematic structural diagram of a computer system of a server for implementing the method, system, and device embodiments of the present application. Figure 6 The server shown is only an example and should not impose any limitation on the functions and usage scope of the embodiments of the present application.

[0132] As Figure 6 shown, the computer system includes a central processing unit (CPU, Central Processing Unit) 601, which can execute various appropriate actions and processes according to the program stored in the read-only memory (ROM, Read Only Memory) 602 or the program loaded from the storage section 608 into the random access memory (RAM, Random Access Memory) 603. In the RAM 603, various programs and data required for system operation are also stored. The CPU 601, ROM 602, and RAM 603 are connected to each other through a bus 604. The input / output (I / O, Input / Output) interface 605 is also connected to the bus 604.

[0133] The following components are connected to the I / O interface 605: an input section 606 including a keyboard, a mouse, etc.; an output section 607 including a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage section 608 including a hard disk, etc.; and a communication section 609 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. The communication section 609 performs communication processing via a network such as the Internet. A drive 610 is also connected to the I / O interface 605 as needed. A removable medium 611 such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc. is mounted on the drive 610 as needed so that a computer program read out therefrom is installed into the storage section 608 as needed.

[0134] In particular, according to embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present disclosure include a computer program product that includes a computer program carried on a computer-readable medium, and the computer program includes program code for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through the communication section 609 and / or installed from the removable medium 611. When the computer program is executed by the central processing unit (CPU) 601, the above-described functions defined in the methods of the present application are performed. It should be noted that the computer-readable medium in the present application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present application, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries the computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0135] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The above-mentioned programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any kind of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).

[0136] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0137] The terms "first", "second", etc. are used to distinguish similar objects and not to describe or represent a specific order or sequence.

[0138] The term "comprising" or any other similar term is intended to cover non-exclusive inclusion, so that a process, method, article, or device / apparatus comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent in these processes, methods, articles, or devices / apparatus.

[0139] So far, the technical solution of the present invention has been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easy for those skilled in the art to understand that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.

Claims

1. A network security monitoring method based on dynamic vulnerability verification, characterized in that, Including: Receive a client request. If the client request is an administrator vulnerability verification request, generate an administrator dynamic key K based on real-time system metrics, defense status parameters, and the supply chain trust score T corresponding to the client request SC , and generate an administrator dynamic key K t , and encrypt the data to be verified based on the administrator dynamic key K t ; Based on the vulnerability database, verify the encrypted data to be verified; If the data to be verified is suspicious or abnormal after verification, calculate the defense level of the data to be verified, and perform defense according to the defense level; Update the vulnerability database, update the verification parameters, and / or update the defense parameters according to the defense effect data.

2. The network security monitoring method according to claim 1, wherein: , Among them, ω1, ω2, ω3 are weight coefficients, ω1 = 0.5, ω1 = 0.3, ω1 = 0.2, SignScore is the signature validity, if the signature is valid, SignScore = 1, if the signature is invalid, SignScore = 0, RepoScore is the maintainer reputation, RepoScore ∈ [0,1], Channelcore is the transmission protocol security, if the transmission protocol is HTTPS, then Channelcore = 1, if the transmission protocol is HTTP, then Channelcore = 0.5, if the transmission protocol is other, then Channelcore = 0; , Among them, V1 is the number of registered users, V2 is the traffic volume, and F a is the attack frequency; N b is the number of blocked IPs, QC_Hash is a quantum-resistant hash function based on quantum random walk, which outputs a 256-bit hash value, (Fa·Nb) is the current defense state encoding, and Chaos(V2,t) is a chaotic sequence generation function with the traffic volume V2 as the initial value. The expression of Chaos(V2,t) is: , where r represents the Logistic map, r = 3.99, and x n = V2 / 10 6 , t is the current timestamp, and it iterates once per second.

3. The network security monitoring method according to claim 1, characterized in that, The step of verifying the encrypted data to be verified based on the vulnerability database includes: Decrypt the data to be verified, extract the characteristics of the data to be verified and construct a vector V; Match the feature construction vector V with the vulnerability database and calculate the feature similarity S; Perform taint propagation tracking on the data to be verified; If S < S1, calculate the behavior deviation degree D of the data to be verified; If S < S1 and D < D1, and the data to be verified does not trigger a dangerous function, then determine that the data to be verified is normal; If S1 ≤ S < S2, or D1 ≤ D < D2, or the taint propagation path of the data to be verified has no result, then determine that the data to be verified is suspicious; If S ≥ S2, or D ≥ D2, or the data to be verified triggers a dangerous function, then determine that the data to be verified is abnormal, where S1, S2 are preset feature similarity thresholds, and D1, D2 are preset behavior deviation thresholds: The calculation of the feature similarity S includes: , where V i is the i-th dimensional value of the traffic feature of the data to be verified, n is the dimensional value of the traffic feature, and the traffic feature is the feature corresponding to the real-time traffic index in the feature construction vector of the data to be verified. C i is the i-th dimensional standard value of the feature in the vulnerability database corresponding to the traffic feature; The calculation of the behavior deviation degree D of the data to be verified includes: , where T is the time window length, with a default value of 60 seconds, and x t is the traffic feature of the data to be verified, λ is the entropy value weight coefficient, λ = 0.2, and H IB is the implicit behavior entropy of the traffic feature, , where , and x is an implicit behavior event.

4. The network security monitoring method according to claim 1 or 3, characterized in that When the data to be verified is suspicious or abnormal after verification, calculating the defense level of the data to be verified includes: calculating the banning weight W: , where α, β, and γ are preset dynamic weight coefficients, D is the behavior deviation degree, δ is the preset defense tolerance, and the key strength is K t entropy value of If the data to be verified is suspicious, the threat level is a preset first level value; If the data to be verified is abnormal, the threat level is a preset second level value; The defense according to the defense level includes: If the banning weight W < W1, do nothing; If W1 ≤ W < W2, limit the traffic of the request corresponding to the data to be verified and perform short-term monitoring for a preset duration; If W2 ≤ W < W3, ban the IP of the request corresponding to the data to be verified and the banning duration reaches a preset first duration, and generate a basic trap page; If W ≥ W3, ban the IP of the request corresponding to the data to be verified and the banning duration reaches a preset second duration, and generate an advanced trap; Among them, W1, W2, W3 are preset level thresholds, and the second duration is greater than the first duration.

5. The network security monitoring method according to claim 4, wherein The defense effect data includes false positive rate, false negative rate, traffic baseline smoothness, and key update frequency. Updating the defense parameters according to the defense effect data includes: If the false positive rate is greater than a preset fourth threshold, decrease the value of α; if the false negative rate is greater than a preset fifth threshold, increase the value of α; If the traffic baseline smoothness is within the preset range, increase the value of β; if the traffic baseline smoothness is outside the preset range, decrease the value of β; If the key update frequency is less than or equal to a preset sixth threshold, keep the value of γ; if the key update frequency is greater than the preset sixth threshold, increase the value of γ; where α, β, and γ are values greater than 0. The verification parameters include a feature similarity threshold and a behavior deviation threshold. Updating the verification parameters according to the defense effect data includes: If the false alarm rate R FP is greater than the preset false alarm threshold, calculate the new behavior deviation threshold D th new , , where η D is the preset behavior deviation learning rate, is the preset behavior deviation loss value, and D th new includes the new behavior deviation thresholds D1 and D2, and D th old includes the behavior deviation thresholds D1 and D2 before calculating the new behavior deviation threshold; If the false negative rate R FN is greater than the preset false negative threshold, calculate the new feature similarity threshold S th new , , where η S is the preset feature similarity learning rate, is the preset feature similarity loss value, and S th new includes the new feature similarity thresholds S1 and S2, and S th old includes the feature similarity thresholds S1 and S2 before calculating the new feature similarity threshold; Updating the vulnerability database according to the defense effect data includes: Capture the attack payload and obtain the standardized feature vector V corresponding to the attack payload new ; Calculate V new The maximum similarity S with the existing features in the vulnerability library max , , where C j is the feature vector of the j-th vulnerability already existing in the vulnerability database, m is the number of vulnerabilities in the vulnerability database. If S max is less than the preset matching threshold, add V new to the vulnerability database.

6. The network security monitoring method according to claim 5, wherein Updating the verification parameters according to the defense effect data further includes: Obtain the verification parameters and implicit behavior entropy statistics of all nodes in the network; Aggregate the calculations to obtain the global verification parameter θ global : , where DT i is the data volume of node i, DT total is the data volume of all nodes, N is the number of nodes, θ i is the verification parameter of node i, θ i includes the feature similarity threshold and the behavior deviation threshold, μ is a preset correction coefficient, η is a preset learning rate, is the loss function gradient, is calculated based on V new H IBN,i is the implicit behavior entropy statistic of node i, , where T is the statistical period, H IBN (t) is the real-time implicit behavior entropy of node i at time t, , where, , y is the implicit behavior event of node i; Distribute the global verification parameter θ global to each node, and each of the nodes will use the global verification parameter θ global as the new verification parameter.

7. The network security monitoring method according to claim 2, wherein, The method further includes: Update the supply chain trust score T SC : , where ν is the preset learning rate, and R attack is the historical frequency of supply chain attacks, and R normal = number of normal client requests / total number of client requests, and T SC,old is the supply chain trust score before update; Update key parameter V2: , where V2' is the updated value of V2.

8. A network security monitoring system based on dynamic vulnerability verification, characterized in that, including: A traffic classification processing module, configured to receive a client request and distinguish whether the client request is an administrator vulnerability verification request; An encryption module, which is used to generate an administrator dynamic key K based on real-time system metrics, defense status parameters, and the supply chain trust score T corresponding to the client request if the client request is an administrator vulnerability verification request SC and encrypt the data to be verified based on the administrator dynamic key K t t ​​ A verification engine module, configured to verify the encrypted data to be verified based on the vulnerability database; A defense linkage module, configured to calculate the defense level of the data to be verified if the data to be verified is suspicious or abnormal after verification, and perform defense according to the defense level; A feedback optimization module, configured to update the vulnerability database, update the verification parameters, and / or update the defense parameters according to the defense effect data; further includes: A vulnerability database, configured to store known vulnerability features and attack features captured by traps; A supply chain trust assessment module for obtaining a supply chain trust score T corresponding to the client request SC .

9. A cluster of computing devices, characterized in that, including at least one computing device, each computing device includes a processor and a memory; the processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1-7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, and the computer instructions are used to be executed by the computer to implement the method according to any one of claims 1-7.

Citation Information

Patent Citations

  • Injection type attack detection model based on dynamic stain analysis

    CN108712448A

  • Network dynamic threat tracking quantification method and system

    CN109995793A

  • Network security monitoring method and system based on dynamic vulnerability verification

    CN117240609A

  • Automatic vulnerability management method and device, equipment and medium

    CN119830304A

  • Comprehensive modeling and mitigation of security risk vulnerabilities in an enterprise network

    US10320829B1

Cited By

  • API document semantic perception type parameter behavior risk prediction method and device

    CN121561903A

  • Method and apparatus for predicting parameter behavior risk of api document semantic awareness type

    CN121561903B