Communication security management method and system based on big data

By obtaining the real-time and historical characteristics of communication nodes in Internet of Things routing, performing cluster analysis, identifying and managing abnormal behaviors, the problem of difficult to identify encrypted traffic abnormalities in the prior art is solved, and the security management of encrypted communication is realized.

CN120455117AActive Publication Date: 2025-08-08DADAO CLOUD TECHNOLOGY DEVELOPMENT (DONGGUAN CITY) CO LTD
View PDF 10 Cites 0 Cited by

Patent Information

Application Number
CN202510699802.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-28
Publication Date
2025-08-08
Estimated Expiration
2045-05-28

AI Technical Summary

Technical Problem

The prior art is difficult to effectively identify abnormal behaviors hidden in encrypted traffic in Internet of Things routing, making it difficult to perform security management in a timely manner.

Method used

By acquiring real-time and historical communication characteristics between communication nodes, performing cluster analysis, determining abnormal communication data, and executing preset communication security policies based on abnormal behavior characteristic values.

Benefits of technology

It realizes automatic detection and protection of abnormal behaviors in encrypted communications, and improves network security defense capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455117A_ABST
    Figure CN120455117A_ABST
Patent Text Reader

Abstract

The invention provides a communication security management method and system based on big data, and relates to the field of communication security. According to the embodiment of the invention, when the encryption communication is executed between the communication nodes, the abnormal behavior characteristic value between the communication nodes is accurately identified by adopting a mode of analyzing the real-time communication characteristic, and the security management of the Internet of Things routing is executed in time, so that the automatic detection and protection of the abnormal communication behavior in the encryption communication are realized, and the security of the Internet of Things routing is improved. And the network security defense capability is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication security, and in particular to a communication security management method and system based on big data. Background Art

[0002] In today's information age, communication security is a crucial element in IoT routing management. With the explosive growth of data volumes in IoT routing and the rapid advancement of communication technologies, ensuring the security of communication content and behavior has become crucial for safeguarding personal privacy, organizational interests, and even national security.

[0003] Traditional communication security management methods often rely on simple rule matching or static protection strategies, which are difficult to cope with the increasingly complex network environment and highly hidden security threats. Especially when facing encrypted communications, existing methods cannot effectively identify abnormal behavior hidden in encrypted traffic in IoT routing, and it is difficult to perform security management of IoT routing based on abnormal behavior in a timely manner. Summary of the Invention

[0004] In view of this, the present application provides a communication security management method and system based on big data, the main purpose of which is to effectively identify abnormal behaviors hidden in encrypted traffic and promptly perform security management of IoT routing based on abnormal behaviors.

[0005] To achieve the above objectives, the present application discloses, in a first aspect, a communication security management method based on big data, the method comprising: When performing encrypted communication between a plurality of communication nodes, obtaining real-time communication characteristics and historical communication characteristics between the communication nodes; clustering the real-time communication features based on the real-time communication data, the historical communication features, and the connection relationships between the plurality of communication nodes to determine real-time correlation features between the communication nodes; determining at least one piece of abnormal communication data between the communication nodes based on the real-time correlation feature and the historical communication feature between the communication nodes; combining the abnormal communication data to determine abnormal behavior characteristic values between the communication nodes; Based on the abnormal behavior characteristic value, a preset communication security execution strategy is executed.

[0006] In a second aspect of the present application, an embodiment provides a communication security management device based on big data, the device comprising: an acquisition module, configured to acquire real-time communication characteristics and historical communication characteristics between a plurality of communication nodes when performing encrypted communication between the communication nodes; a clustering module, configured to cluster the real-time communication features based on the real-time communication data, the historical communication features, and the connection relationships between the plurality of communication nodes, and determine the real-time correlation features between the communication nodes; A first determining module, configured to determine at least one piece of abnormal communication data between the communication nodes based on the real-time correlation feature and the historical communication feature between the communication nodes; a second determining module, configured to combine the abnormal communication data and determine a characteristic value of abnormal behavior between the communication nodes; The management module is used to execute a preset communication security execution strategy based on the abnormal behavior characteristic value.

[0007] In a third aspect of the present application, an embodiment provides an electronic device, including: At least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute any one of the methods disclosed in the first aspect.

[0008] In a fourth aspect of the present application, an embodiment provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the method described in the first aspect is implemented.

[0009] In summary, according to the technical solution disclosed in this application, when performing encrypted communication between multiple communication nodes, the real-time communication characteristics and historical communication characteristics between the communication nodes are obtained; based on the real-time communication data, historical communication characteristics and the connection relationship between the multiple communication nodes, the real-time communication characteristics are clustered to determine the real-time correlation characteristics between the communication nodes; based on the real-time correlation characteristics and historical communication characteristics between the communication nodes, at least one abnormal communication data between the communication nodes is determined; the abnormal communication data is combined to determine the abnormal behavior characteristic value between the communication nodes; based on the abnormal behavior characteristic value, a preset communication security execution strategy is executed. When performing encrypted communication between communication nodes, this embodiment adopts the method of analyzing the real-time communication characteristics to accurately identify the abnormal behavior characteristic value between the communication nodes, and promptly performs security management of the Internet of Things routing, thereby realizing automatic detection and protection of abnormal communication behavior in encrypted communication and improving network security defense capabilities. The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0011] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0012] Figure 1 A flow chart of a communication security management method based on big data provided by an embodiment of the present application is shown; Figure 2 A system structure diagram of a communication security management method based on big data provided in an embodiment of the present application is shown. DETAILED DESCRIPTION

[0013] In order to more clearly understand the above-mentioned objectives, features and advantages of the present application, the scheme of the present application will be further described below. It should be noted that, in the absence of conflict, the embodiments of the present application and the features therein can be combined with each other.

[0014] In order to solve the problem of being unable to effectively identify abnormal behaviors hidden in encrypted traffic in IoT routing and difficult to timely perform security management of IoT routing based on abnormal behaviors, this application provides the following embodiments to solve the above problems: This embodiment provides a communication security management method based on big data, such as Figure 1 FIG. 1 is a flow chart of the method of this embodiment, and the method of this embodiment may specifically include the following steps: Step 101: When performing encrypted communication between multiple communication nodes, obtain real-time communication characteristics and historical communication characteristics between the communication nodes.

[0015] Traffic data from a communication environment is captured in real time. Network packet capture tools are used to obtain timestamps, packet lengths, and communication frequency information from the traffic data. Preliminary data organization is performed to generate a structured traffic data set. Metadata features are extracted from the structured traffic data set. Data parsing tools are used to isolate the specific timestamps, packet lengths, and communication frequencies. These features are then standardized to determine the format and range of the initial features. A feature dataset is constructed by classifying and organizing the initial features. Database storage tools are used to organize the standardized metadata features in chronological order. If the communication frequency exceeds a preset threshold within a certain time period, it is marked as a potential anomaly, resulting in a marked feature dataset. Pattern analysis is performed on the marked feature dataset, and statistical tools are used to analyze the distribution patterns within the feature dataset. If the distribution patterns deviate from the preset threshold, the feature is marked as a key anomaly target, resulting in preliminary feature extraction results. For example, in a traffic data analysis scenario within a communication environment, real-time traffic data capture is fundamental to the entire process. Consider monitoring an internal enterprise network. Network packet capture tools are used to capture data packets and obtain timestamps, packet lengths, and communication frequency information. During initial compilation, this data is arranged in chronological order to form a structured traffic data set. For example, suppose 1,000 data packets are recorded over a certain period of time, with timestamps accurate to the millisecond, packet lengths ranging from 100 to 1,500 bytes, and communication frequency expressed as requests per minute. Specifically, when extracting metadata features, a data parsing tool is used to separate the timestamp, packet length, and communication frequency, and then normalize them. Assume that timestamps are standardized in UTC format, packet lengths are in bytes, and communication frequency is based on requests per minute to ensure consistency in the initial feature format. After normalization, the data range is clear, facilitating subsequent analysis and effectively reducing errors caused by data inconsistencies. In one embodiment, when constructing the feature dataset, the standardized metadata features are stored in a database in chronological order. If the communication frequency exceeds a preset threshold, such as 100 requests per minute, within a certain period of time, it is marked as a potential outlier. For example, if the communication frequency of a device suddenly increases to 150 requests per minute within a certain hour, far exceeding the normal value of 50, the system automatically marks it as an outlier. This marking method helps quickly locate potential problems and improves the efficiency of anomaly detection. For example, when performing pattern analysis on a labeled feature dataset, statistical tools are used to analyze distribution patterns. Assuming that packet lengths are normally concentrated between 500 and 800 bytes, if packets exceeding 1200 bytes frequently appear within a certain period of time and their distribution deviates from the preset range, they are marked as key targets. This analysis can help identify hidden abnormal patterns, such as potential malicious traffic or device failures, and ensure network security. Specifically, the formation of preliminary feature extraction results relies on the coordinated work of the above steps.From real-time capture to standardized processing, and then to anomaly flagging and pattern analysis, each step contributes to the final result. For example, an analysis revealed unusually high communication frequency during a certain time period. Combined with deviations from the normal packet length distribution, this was suspected to be a precursor to a DDoS attack, prompting timely protective measures. This multi-dimensional analysis improves detection accuracy and reduces false positives.

[0016] Based on a pre-established library of communication behavior patterns, information on communication frequency changes and packet length distribution is obtained from the traffic feature dataset. This dataset is then compared item by item with the standard patterns in the library to determine preliminary regularity description information for the communication behavior. Periodic characteristics of communication frequency changes and statistical characteristics of packet length distribution are extracted from this preliminary regularity description information. These characteristics are then screened using a preset threshold. If the characteristic value exceeds the threshold, the characteristic is determined to be a key indicator of an abnormal behavior pattern, resulting in a marked object to be analyzed. For this marked object to be analyzed, communication behavior data for different time periods is obtained. By comparing the frequency changes and packet length distribution in this data, it is determined whether a fixed pattern or abnormal fluctuations exists, thereby obtaining a dynamic regularity description of the communication behavior. Based on this dynamic regularity description and in combination with pre-established classification rules, the dynamic regularity description is classified and processed to determine whether it conforms to a known pattern, thereby obtaining a final regularity description of the communication behavior.

[0017] For example, when analyzing communication behavior patterns, one can start by examining changes in communication frequency to understand the significance of its periodic characteristics. Changes in communication frequency generally reflect the level of data transmission activity. A sudden increase or decrease in frequency over a period of time may indicate potential abnormal behavior. For example, suppose that within an enterprise network, the communication frequency during normal working hours is 10 times per minute, but during non-working hours, it suddenly rises to 50 times per minute. This change needs to be recorded and compared to the standard pattern in the pattern library. If the comparison reveals that the non-working frequency limit in the standard pattern is 15 times per minute, the data will be flagged as an abnormal indicator. This approach helps quickly identify potential risk points.

[0018] For example, the statistical characteristics of packet length distribution can be used to determine the regularity of communication behavior by observing the concentration trend of packet sizes. If the packet length distribution shows a significant skewness, such as most packets are around 100 bytes, but a large number of packets exceeding 1000 bytes suddenly appear, this may indicate abnormal transmission behavior.

[0019] In one possible implementation, assuming the system sets the normal range of packet length to 50 to 500 bytes, packets exceeding this range that exceed 5% will be marked for analysis. This filtering mechanism can effectively distinguish between normal and abnormal traffic.

[0020] For example, when acquiring communication behavior data over different time periods, one can focus on frequency changes and dynamic fluctuations in packet length. For example, suppose that for three consecutive days, there is a surge in communication frequency at a fixed time each night, and the packet length distribution also tends to be larger. This consistent pattern may indicate a scheduled task or potential threat. By comparing historical data, if the pattern is found to be inconsistent with known patterns, further analysis is needed to identify its dynamic regularity. This dynamic analysis can help uncover hidden periodic behaviors.

[0021] For example, when classifying descriptions of dynamic regularity, preset rules can be used to determine whether they conform to known patterns. For example, if a pattern library defines a pattern of frequent small data packet transmission during business hours, and the current description shows frequent large data packet transmission during non-business hours, it can be classified as an abnormal pattern. This classification method provides a clear basis for subsequent decision-making and improves analysis efficiency.

[0022] For example, the entire process, from screening periodic and statistical features to forming a final regularity description, embodies an analytical logic that moves from static to dynamic, from local to global. Multi-dimensional comparison and classification enable a more comprehensive characterization of communication behavior. This approach is invaluable in ensuring network stability and promptly detecting anomalies.

[0023] Step 102: clustering the real-time communication features based on the real-time communication data, the historical communication features and the connection relationships between the plurality of communication nodes to determine the real-time correlation features between the communication nodes.

[0024] Using real-time communication data and historical communication characteristics, determine the communication regularity parameters between communication nodes; According to the connection relationship between communication nodes, the communication regularity parameters are clustered to determine the real-time correlation characteristics between communication nodes.

[0025] Step 103: Determine at least one piece of abnormal communication data between the communication nodes based on the real-time correlation characteristics and historical communication characteristics between the communication nodes.

[0026] By organizing the regularity descriptions of communication behavior and using clustering tools to group them, node correlation data between different nodes is obtained, generating a preliminary set of behavioral features. Based on this preliminary set of behavioral features and combined with stored historical traffic data, traffic is compared against the behavioral pattern for each set of node correlation data to determine whether there are signs of deviation from the normal pattern. If signs of deviation from the normal pattern are detected, the degree of deviation is quantified using a preset threshold to determine whether it exceeds the threshold and flag potential anomalies. For example, when organizing regularity descriptions of communication behavior, one can begin by structuring the data to understand its underlying connections. Regularity descriptions typically include key indicators such as communication frequency and packet size distribution. Organizing this information can lay the foundation for subsequent grouping. For example, in an enterprise network, the organized data shows that the communication frequency of certain nodes fluctuates periodically within a specific time period. This fluctuation can be used as a basis for grouping to further explore the correlations between nodes. For example, grouping information using clustering tools can be achieved by analyzing the similarities in communication behavior between nodes. Clustering tools group nodes with similar communication patterns based on regularity descriptions, thereby obtaining node-related data. In one possible implementation, suppose certain nodes in an enterprise network all communicate between 10 and 15 times per minute, with packet lengths ranging from 100 to 200 bytes. These nodes are clustered together to form a preliminary set of behavioral signatures. This grouping approach helps uncover hidden communication patterns and provides data support for subsequent analysis. For example, when comparing traffic based on this preliminary set of behavioral signatures with historical traffic data, one can focus on any deviations from the normal pattern. Specifically, suppose historical traffic data shows a stable communication frequency of around 12 times per minute for a group of nodes, but current data shows 30 times per minute. This significant deviation would be noted. Through comparative analysis, it can be preliminarily determined that this group of nodes may exhibit abnormal communication behavior. This approach can quickly identify potential problem nodes. For example, if a deviation from the normal pattern is detected, it is crucial to quantify the degree of deviation using a pre-set threshold. In one possible implementation, assuming the system sets a frequency threshold of 20 times per minute, if a node's frequency reaches 30 times per minute, the deviation is quantified and flagged as exceeding the threshold, generating a potential anomaly flag. This quantitative comparison transforms subjective judgments into objective indicators, improving the accuracy of analysis. For example, the processing of potential anomaly flags can be verified and analyzed from multiple perspectives. If a node is flagged as an anomaly, further investigation can be conducted based on factors such as time period and communication partner.If a node is found to be frequently communicating with unknown external addresses during off-hours, and the packet length exceeds the typical range of 500 bytes, reaching over 2000 bytes, the time and data volume can be used to mutually support and confirm the abnormal nature of the problem. This multi-dimensional verification approach effectively reduces the risk of misjudgment and provides a reliable basis for subsequent processing. For example, throughout the analysis process, the mining of node-related data and the formation of behavioral feature sets demonstrate a logical progression from the local to the global. Through clustering, traffic comparison, and threshold quantification, a complete profile of communication behavior can be gradually constructed. This approach not only helps to discover hidden abnormal patterns but also provides data support for network management and ensures the stability of the communication environment.

[0027] Step 104: Combine the abnormal communication data to determine abnormal behavior feature values between communication nodes.

[0028] In some embodiments, distribution characteristic values of abnormal communication data in communication nodes are determined; the distribution characteristic values are combined using a graph network analysis method to generate a dynamic propagation relationship graph between communication nodes; and abnormal behavior characteristic values between communication nodes are obtained based on the distribution characteristic values and the propagation relationship graph.

[0029] In some embodiments, based on real-time communication characteristics and abnormal behavior characteristic values, the propagation trend characteristic values of the abnormal behavior characteristic values in the dynamic propagation relationship diagram are determined; based on the propagation trend characteristic values, the diffusion risk values of the abnormal behavior characteristic values in the dynamic propagation relationship diagram are determined; and based on the diffusion risk values and real-time communication characteristics, the abnormal behavior category is determined by a support vector machine algorithm.

[0030] In some embodiments, based on the distribution characteristic value and the propagation relationship graph, the starting node corresponding to the abnormal behavior characteristic value is determined; based on the real-time communication characteristics, the high-risk propagation node is determined in the propagation relationship graph; the node set of the combined starting node and the high-risk propagation node is determined; and the propagation trend characteristic value of the abnormal behavior characteristic value in the node set is determined.

[0031] In some embodiments, determining a high-risk time period corresponding to the abnormal behavior characteristic value; Established in a high-risk time period, based on an abnormal behavior distribution set of abnormal behavior feature values, the diffusion risk value of the abnormal behavior feature values in the dynamic propagation relationship diagram is determined.

[0032] By extracting potentially anomalous behavior records from network communication logs, obtaining communication node information and time series data from the records, and performing preliminary analysis of the communication frequencies and timestamps of the communication nodes, the temporal distribution of the anomalous behavior is determined. Based on the temporal distribution of the anomalous behavior, graph database tools are used to construct the connectivity between communication nodes, generating a network propagation path diagram of the anomalous behavior and identifying the locations of key nodes in the propagation path. If the number of connections to a node in the network propagation path diagram exceeds a preset threshold, a depth-first search algorithm is used to traverse the relevant paths of the key nodes to obtain information about the starting point of the anomalous behavior spread and identify the source of the propagation. By extracting the propagation distance from the starting point to each node and the number of affected nodes from the network propagation path diagram, a data visualization tool is used to generate a distribution map of the anomalous behavior's impact range, revealing the specific distribution of the impact range and the set of affected nodes. For example, in the analysis of network communication logs, to extract potentially anomalous behavior records, log parsing tools can be used to filter out communication records marked with anomalies, obtaining communication node information and time series data. Suppose an enterprise network contains 1,000 log records during a certain time period, 50 of which are marked as anomalous. These records involve 10 communication nodes, spanning a 24-hour period. Initial analysis can break down communication frequency by hour. It may be found that a node has an unusually high communication frequency of 200 times per hour during the early morning hours, compared to only 20 times per hour during other periods. This temporal distribution suggests a possible anomaly. Specifically, to analyze the temporal distribution of anomalous behavior, a time series charting tool can be used to plot each node's communication frequency and timestamp into a line graph, visually highlighting the peak periods of anomalous activity. Suppose the analysis reveals a spike in communication frequency between 2:00 AM and 4:00 AM, potentially inconsistent with normal business hours, suggesting further attention needs to be paid to this behavior pattern. For example, when constructing communication node connections, graph database tools can effectively store and query complex relationships between nodes. Suppose there are 10 nodes, of which node A frequently communicates with five other nodes, forming a dense subgraph. By generating a network propagation path diagram, it can be found that node A is a key node in the propagation path, with a number of connections of 5, exceeding the preset threshold of 3. In this case, the depth-first search algorithm can help traverse the relevant paths of node A and find the starting point of the spread of the abnormal behavior. Assume that the abnormal communication is eventually traced back to node A at 2 a.m., which may be the source of the abnormality. Specifically, based on the analysis of the propagation distance and the number of affected nodes, a data visualization tool can be used to generate an impact range distribution map. Assume that starting from the starting point node A, the abnormal behavior spreads to the third layer of nodes, affecting 8 nodes, and the longest propagation distance reaches 3 hops. The distribution map can intuitively display the set of affected nodes, and it is found that the nodes within 2 hops of node A are the most severely affected, accounting for 75%. This analysis helps to quickly locate the core impact area.For example, in a real-world scenario, suppose node A is a server in an enterprise's internal network. Unusually high communication frequency in the early morning hours may be due to unauthorized external access. Using the aforementioned method, the source of the anomaly can be quickly identified. Combined with the impact distribution map, the affected node set can be determined, allowing for timely isolation measures. This approach effectively improves response to abnormal behavior and reduces potential risks. Based on the connection data between communicating nodes, an initial dynamic propagation relationship graph is constructed. The network location and connection strength data for each node are obtained. Based on the starting point of the abnormal behavior, the specific location of the starting node in the relationship graph and its directly connected neighboring nodes are determined, thereby determining the possible initial propagation path of the abnormal behavior. By traversing the node data within the initial propagation path layer by layer, the communication frequency and data exchange volume between nodes at each layer are obtained. Preset thresholds are used to filter the communication frequency and exchange volume. If the communication frequency or exchange volume of a node exceeds the preset threshold, the node is identified as a high-risk propagation node, and a distribution set of high-risk propagation nodes is obtained. Based on the distribution of high-risk propagation nodes, the connection paths and influence ranges of these nodes in the dynamic propagation relationship graph are obtained. For nodes along the connection paths, graph traversal tools are used to quantify the propagation speed and impact strength along the paths, thereby determining the characteristic values of the anomalous behavior's propagation trend within the network. For example, in the scenario of analyzing abnormal network communication behavior, an initial dynamic propagation relationship graph can be constructed based on the connection data between communication nodes by collecting node interaction records from network logs. Suppose an enterprise's internal network has 100 communication nodes, and the logs show an average of 50 interactions per day for each node. The connection strength is quantified based on the interaction frequency and data volume. Based on this data, the dynamic propagation relationship graph can be constructed by drawing connecting lines between nodes. The line thickness represents the connection strength, and the node position reflects its hierarchical relationship within the network. This approach intuitively displays the network structure and facilitates subsequent analysis of the origin of the anomalous behavior. For example, the starting point of an anomalous behavior can be used to determine its position in the relationship graph and its neighboring nodes by tracing back to the node that first experienced the anomalous behavior. Suppose node A experiences abnormal traffic for the first time at 1:00 AM on a certain day. Its three directly connected neighbors are B, C, and D. A relationship diagram reveals that A has the strongest connection with B, interacting 80 times daily, while interactions with C and D occur only 20 and 15 times daily, respectively. Therefore, the initial diffusion path may prioritize the path from A to B. This analysis helps quickly identify the likely direction of spread and provides a focus for subsequent investigation. For example, when traversing node data layer by layer within the initial diffusion path, one can focus on the communication frequency and data interaction volume of nodes at each layer.Suppose, starting with node A, the first layer consists of B, C, and D, and the second layer consists of E and F, to which B connects. It is discovered that the communication frequency between B and E is as high as 100 times per day, and the data exchange volume is 500MB, far exceeding the preset thresholds of 50 times and 200MB per day. Therefore, E is marked as a high-risk propagation node. Through layer-by-layer analysis, a distribution set of high-risk propagation nodes is ultimately obtained. This screening method effectively identifies potential threat points in the network. For example, path tracing tools can be used to analyze the connection paths and impact range of the distribution set of high-risk propagation nodes in a dynamic propagation relationship graph. Suppose, for example, high-risk node E connects to five downstream nodes, affecting 10% of the nodes in the network, and the propagation rate is two newly affected nodes per hour. By quantifying the propagation speed and impact intensity, characteristic values of the propagation trend of the abnormal behavior can be derived. This analysis provides data support for network security protection and helps formulate response strategies in advance. For example, in real-world operations, the threshold screening for communication frequency and data exchange volume may need to be adjusted based on the network scale. For small networks, the threshold can be lower, such as 30 times per day, while for large networks, it may need to be increased to 100 times per day. This flexibility ensures adaptability of the analysis while improving the accuracy of identifying high-risk nodes, bringing greater practical value to network security management. By performing time series analysis on the propagation trend characteristic values, data on the speed and direction of the spread of abnormal behavior is obtained. Combined with the preset diffusion risk threshold, it is determined whether the diffusion trend reaches a high-risk level. If so, the dynamic detection mechanism's response process is triggered. Based on the propagation trend characteristic value data, diffusion speed and direction information are extracted from the time series. Based on data fluctuations within the time series, a time window partitioning tool is used to segment the diffusion speed and direction information, resulting in a set of diffusion changes within each time period. Within this diffusion change set, the diffusion speed and direction information are compared segment by segment using a preset threshold comparison tool. If the diffusion speed within a time period exceeds the preset threshold, the time period is determined to be potentially high-risk, and a distribution set of potentially high-risk time periods is obtained. By gathering data on the distribution of potentially high-risk time periods, we can obtain data on the spread of abnormal behavior. Path tracing tools are then used to continuously monitor directional information for key nodes within the spread range, identifying the set of diffusion paths along which the abnormal behavior spreads within the network. Based on this set of diffusion paths, the dynamic detection mechanism's response process is triggered. For high-risk paths, real-time data collection tools are used to update the spread trend, determine whether to adjust the priority of the response process, and ultimately determine the response scheduling plan. For example, in the context of analyzing abnormal network communication behavior, time series analysis of propagation trend characteristic value data can gradually reveal the dynamic changes in abnormal behavior, starting with diffusion speed and directional information. Time series data typically records the spread of abnormal behavior within the network, such as the number of newly affected nodes per hour and the primary direction of propagation.Suppose, for example, that within an enterprise network, a time series shows that the number of newly affected nodes for a particular anomalous behavior increases from 5 to 30 within 24 hours. Directional information indicates that the primary diffusion path is concentrated in the core server area. Using a time window partitioning tool, the 24-hour period can be divided into six 4-hour time periods. The diffusion rate and directional changes within each time period are analyzed to generate a diffusion change set. For example, a preset threshold comparison tool can be used to perform segment-by-segment comparisons. Suppose the preset diffusion rate threshold is 10 newly affected nodes per hour. Analysis reveals that the diffusion rate in the third time period reaches 12 nodes per hour, exceeding the threshold. Therefore, this time period is marked as potentially high-risk. This segment-by-segment comparison ultimately yields a distribution set of potentially high-risk time periods, such as the third and fifth time periods, which are marked as high-risk. This segmented analysis helps quickly locate key time points during the spread of the anomalous behavior. For example, after obtaining the distribution set for the potentially high-risk time period, further analysis can be performed on the anomalous behavior's spread range. Suppose the spread range for the third time period covers 20% of the nodes in the network, including several key nodes, such as core data storage nodes. By continuously monitoring directional information through path tracing tools, we can identify a set of diffusion paths for abnormal behavior, such as fan-shaped paths from core nodes to edge nodes. This monitoring method clearly demonstrates the propagation trajectory of abnormal behavior. For example, a set of diffusion paths can trigger a dynamic detection mechanism's response process. Suppose, for example, a real-time data collection tool on a high-risk path shows a sudden acceleration in the spread of a particular path, with the number of newly affected nodes increasing from 10 to 15 per hour, exceeding expectations. In this case, we can determine the need to adjust the response process priority, prioritizing resources to protect this path and ultimately formulating a response scheduling plan. This dynamic adjustment mechanism allows for timely response to sudden changes in abnormal behavior. For example, continuous monitoring and path tracing of key nodes can provide granular analysis from multiple perspectives. For example, we can monitor whether the communication frequency of key nodes increases abnormally; for example, we can analyze whether data anomalies are occurring in their downstream nodes. For example, if the communication frequency of a key node increases from 50 to 100 times per day, and downstream nodes experience abnormal traffic, resource scheduling for that path will be prioritized. This multi-dimensional analysis ensures a comprehensive and targeted response process. For example, real-time data collection tools can be combined with historical data to analyze trends. For example, if historical data indicates a stable diffusion rate along a path over the past 24 hours, but current data indicates a sudden increase, the response priority must be adjusted immediately. This combined analysis of historical and real-time data allows for more accurate assessment of the evolving trends of abnormal behavior, providing strong support for network security management.

[0033] Step 105: Execute a preset communication security execution strategy based on the abnormal behavior feature value.

[0034] In some embodiments, the abnormal behavior category and priority of the abnormal behavior feature value are determined; and based on the category and / or priority, a preset communication security execution policy is executed.

[0035] Real-time traffic data is obtained from communication nodes. Pre-established filtering rules are used to perform preliminary screening of this data for high-risk contagion patterns, generating a pre-classified traffic set. The system then determines whether any fluctuations deviate from preset thresholds. If so, the set is marked as potentially anomalous. Based on this potentially anomalous data, classification tools are used to conduct in-depth data analysis, determine the category of the anomalous behavior, and generate a preliminary prioritized list. Using this preliminary prioritized list, historical data from communication nodes associated with high-risk contagion patterns is obtained. Comparison tools are used to match the anomalous behavior with the historical data to determine if any recurring patterns exist. If so, the anomalous behavior is prioritized, resulting in an updated ranking. Based on this updated ranking, monitoring data from communication nodes is obtained for high-priority anomalous behaviors. A logging tool is used to generate a report on the response process for the anomalous behavior and determine the final response sequence. For example, in the field of traffic monitoring in communication networks, obtaining real-time traffic data from communication nodes is a fundamental step. Pre-set filtering rules can be used to perform this preliminary screening for high-risk contagion patterns. Suppose the normal traffic threshold for a communication node is set at 1,000 packets per second. If real-time traffic suddenly spikes to 2,000 packets per second, the system will flag this as an abnormal fluctuation. This preliminary screening aims to quickly identify potentially risky traffic clusters and provide a data foundation for subsequent analysis. For example, for in-depth analysis of potentially anomalous data, classification tools can be used to identify the type of abnormal behavior. Suppose, within the aforementioned traffic cluster, the system discovers an unusually concentrated source address for some packets that matches the characteristics of known malicious attacks. It can then classify these packets as potential distributed denial-of-service attacks. This classification helps clarify the nature of the anomalous behavior and provides a basis for subsequent prioritization. For example, when generating the preliminary priority list, the system ranks the anomalous behavior based on severity and impact. For example, if a certain type of anomalous behavior involves a core communication node and affects more than 5,000 users, it will be assigned the highest priority. This prioritization ensures that resources are prioritized for the most threatening anomalies. For example, historical data comparisons related to high-risk spread can be implemented using comparison tools. If the packet characteristics of current abnormal behavior closely match those of a known attack in the past, such as the same packet size and transmission frequency, the system will increase the priority of the abnormal behavior. This historical matching method helps quickly identify repeated threats and improve response efficiency. For example, when acquiring monitoring data from communication nodes, real-time logging tools can record the details of abnormal behavior. Suppose a node frequently experiences abnormal traffic spikes within a specific time period. The logging tool will record the start time and duration of each spike in detail, forming a complete response process report. This recording method provides a reliable basis for determining the subsequent processing sequence. For example, when determining the final processing order, the system will combine the results of priority sorting and monitoring data.If a particular abnormal behavior is prioritized and monitoring data indicates its spread is expanding, the system prioritizes it and allocates resources for intervention. This approach effectively curbs the further escalation of high-risk spread. For example, the entire process, from initial screening to final determination of the processing order, forms a closed-loop mechanism. The analysis and judgment at each stage are closely linked, ensuring rapid identification and effective response to abnormal behavior. This mechanism is of great significance in the field of communications network security, significantly improving the system's response capabilities to potential threats.

[0036] Detailed data on anomaly categories is obtained from the prioritization results. For communication nodes with higher risk levels, behavior matching is performed using a pre-established protection rule library. At least one appropriate interception or isolation strategy is determined, resulting in a preliminary protection solution configuration. Based on this preliminary protection solution configuration, traffic monitoring tools are used to implement traffic restrictions on the communication node's traffic data. During this process, changes in the node's status are recorded in real time to obtain real-time feedback data. Using this real-time feedback data, combined with a rule update mechanism, protection rules are dynamically adjusted if feedback data deviates from a preset threshold. The updated rules are then determined, resulting in an adjusted protection solution. For example, in the field of traffic monitoring in communication networks, obtaining detailed data on anomaly categories from the prioritization results is a critical step. For communication nodes with higher risk levels, characteristic data on abnormal behavior can be extracted by analyzing their traffic patterns, source distribution, and other information. For example, if a node's traffic surges from 500 packets per second to 1,800 packets per second over a short period of time, with a high concentration of source addresses, these data characteristics may indicate a potential threat. By comparing this data with a pre-established protection rule library, appropriate policies can be quickly identified, such as restricting traffic from specific sources or temporarily isolating a node. For example, when configuring a preliminary protection plan, the traffic monitoring tool can set a dynamic threshold to control traffic flow when implementing traffic limiting operations. For example, the node's traffic limit could be temporarily adjusted to 800 packets per second, with any excess traffic discarded. The node's response status, such as latency changes or packet loss rate, can also be recorded in real time. If latency increases from the normal 0.5 seconds to 2 seconds after limiting, this indicates that the limiting policy may be too restrictive, impacting normal communication. Adjustments based on feedback data are necessary. For example, the rule update mechanism plays a crucial role in dynamically adjusting protection rules. If feedback data indicates that abnormal behavior is not effectively curbed after traffic limiting, and traffic continues to frequently exceed the threshold, the system can, based on pre-set update logic, lower the limit to 600 packets per second or add filtering criteria for specific packet types. This dynamic adjustment better aligns with actual risk scenarios and enhances targeted protection. Furthermore, the updated rule content will be incorporated into subsequent traffic management as part of the new protection plan. Specifically, real-time recording of communication node status changes can be achieved through a logging system. Assume that after implementing traffic restrictions, the system generates a status report every minute, recording the node's traffic value, the effectiveness of the restriction, and the duration of abnormal behavior. For example, a report may show that the proportion of abnormal traffic has dropped from 80% to 30% after the restriction, indicating that the policy is initially effective, but residual risks still require attention. This recording method provides data support for subsequent rule adjustments. It should be noted that the establishment and matching process of the protection rule base requires a combination of historical data and current scenarios.For example, the rule base may contain multiple policies for specific abnormal behaviors, such as traffic throttling for surges and isolation policies for malicious addresses. If the risk profile of a node is highly similar to a historical attack, the system will prioritize the isolation policy that was in effect at that time. This approach reduces trial-and-error costs and improves response speed. In one possible implementation, analysis of real-time feedback data can also incorporate a temporal dimension. For example, if a node experiences some initial reduction in abnormal behavior within 10 minutes after traffic throttling, but then recurs, the system can adjust its policies based on this trend, extending the restriction period or strengthening the restriction. This temporal trend analysis provides a more comprehensive understanding of risk dynamics. Through these multifaceted implementations, a complete protection process is formed, from acquiring abnormality category data to dynamically adjusting protection plans. The seamless integration of each link ensures timely protection of communication nodes facing high risks. Furthermore, through real-time feedback and rule updates, protection effectiveness is continuously optimized, providing a strong guarantee for network security.

[0037] This embodiment also discloses a communication security management system based on big data, such as Figure 2 Shown, including: An acquisition module 21 is configured to acquire real-time communication characteristics and historical communication characteristics between multiple communication nodes when performing encrypted communication between the multiple communication nodes; A clustering module 22 is configured to cluster the real-time communication features based on the real-time communication data, the historical communication features, and the connection relationships between the plurality of communication nodes, and determine the real-time correlation features between the communication nodes; A first determining module 23 is configured to determine at least one abnormal communication data between the communication nodes based on the real-time correlation characteristics and historical communication characteristics between the communication nodes; A second determination module 24 is configured to combine abnormal communication data and determine a characteristic value of abnormal behavior between communication nodes; The management module 25 is configured to execute a preset communication security execution strategy based on the abnormal behavior feature value.

[0038] Based on this understanding, the technical solution of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, USB flash drive, mobile hard disk, etc.), and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute the methods of various implementation scenarios of the present application.

[0039] Based on the above Figure 1 The method shown, and Figure 2In order to achieve the above-mentioned purpose, the embodiment of the virtual device shown in the embodiment of the present application further provides an electronic device that can be configured on the vehicle (such as a new energy vehicle) side, the device includes at least one processor and a memory connected to the at least one processor in communication; the memory is used to store instructions that can be executed by the at least one processor, the instructions are executed by the at least one processor, and the processor is used to execute a computer program to achieve the above-mentioned Figure 1 The method shown.

[0040] Optionally, the physical device may also include a user interface, a network interface, a camera, a radio frequency (RF) circuit, a sensor, an audio circuit, a Wi-Fi module, and the like. The user interface may include a display screen and an input unit such as a keyboard. Optional user interfaces may also include a USB interface and a card reader interface. Optionally, the network interface may include a standard wired interface or a wireless interface (such as a Wi-Fi interface).

[0041] Those skilled in the art will understand that the above-mentioned physical device structure provided in this embodiment does not constitute a limitation on the physical device, and may include more or fewer components, or a combination of certain components, or different component arrangements.

[0042] Based on the above Figure 1 The method shown, the embodiment of the present application also provides a computer-readable storage medium on which a computer program is stored, and when the computer program is executed by a processor, the method corresponding to any embodiment is implemented. The storage medium may also include an operating system and a network communication module. The operating system is a program that manages the hardware and software resources of the above-mentioned physical device and supports the operation of information processing programs and other software and / or programs. The network communication module is used to realize communication between the components inside the storage medium, and communication with other hardware and software in the information processing physical device.

[0043] Based on the above electronic device, the embodiment of the present application further provides a vehicle, which may specifically include: Figure 2 The device shown or the electronic device as described above. The vehicle can be a new energy vehicle or a traditional vehicle.

[0044] Through the description of the above implementation methods, those skilled in the art can clearly understand that the present application can be implemented by means of software plus the necessary general hardware platform, or by hardware. By applying the solution of this embodiment, compared with the current existing technology, this embodiment obtains the real-time communication characteristics and historical communication characteristics between the communication nodes when performing encrypted communication between multiple communication nodes; clusters the real-time communication characteristics based on the real-time communication data, historical communication characteristics and the connection relationship between multiple communication nodes to determine the real-time correlation characteristics between the communication nodes; determines at least one abnormal communication data between the communication nodes based on the real-time correlation characteristics and historical communication characteristics between the communication nodes; combines the abnormal communication data to determine the abnormal behavior characteristic value between the communication nodes; and executes the preset communication security execution strategy based on the abnormal behavior characteristic value. When performing encrypted communication between communication nodes, this embodiment adopts the method of analyzing the real-time communication characteristics to accurately identify the abnormal behavior characteristic value between the communication nodes, and promptly performs security management of the Internet of Things routing, thereby realizing automatic detection and protection of abnormal communication behavior in encrypted communication and improving network security defense capabilities.

[0045] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprises" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a..." do not exclude the presence of other identical elements in the process, method, article or device that includes the elements.

[0046] The foregoing is merely a list of specific embodiments of the present application, intended to enable those skilled in the art to understand and implement the present application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application is not limited to the embodiments described herein, but is intended to conform to the broadest scope consistent with the principles and novel features of the present application.

Claims

1. A communication security management method based on big data, characterized in that: include: When performing encrypted communication between a plurality of communication nodes, obtaining real-time communication characteristics and historical communication characteristics between the communication nodes; clustering the real-time communication features based on the real-time communication data, the historical communication features, and the connection relationships between the plurality of communication nodes to determine real-time correlation features between the communication nodes; determining at least one piece of abnormal communication data between the communication nodes based on the real-time correlation feature and the historical communication feature between the communication nodes; combining the abnormal communication data to determine abnormal behavior characteristic values between the communication nodes; Based on the abnormal behavior characteristic value, a preset communication security execution strategy is executed.

2. The method according to claim 1, characterized in that The clustering of the real-time communication features based on the real-time communication data, the historical communication features, and the connection relationships between the plurality of communication nodes to determine the real-time correlation features between the communication nodes includes: Determining communication regularity parameters between the communication nodes using the real-time communication data and the historical communication characteristics; The communication regularity parameters are clustered according to the connection relationship between the communication nodes to determine the real-time correlation characteristics between the communication nodes.

3. The method according to claim 1, characterized in that The combining of the abnormal communication data to determine abnormal behavior characteristic values between the communication nodes includes: Determining a distribution characteristic value of the abnormal communication data in the communication node; Using a graph network analysis method, the distribution characteristic values are combined to generate a dynamic propagation relationship graph between the communication nodes; According to the distribution characteristic value and the propagation relationship graph, the abnormal behavior characteristic value between the communication nodes is obtained.

4. The method according to claim 3, characterized in that Before executing a preset communication security execution strategy based on the abnormal behavior feature value, the method further includes: Determining a propagation trend characteristic value of the abnormal behavior characteristic value in the dynamic propagation relationship graph according to the real-time communication characteristic and the abnormal behavior characteristic value; Determining a diffusion risk value of the abnormal behavior characteristic value in the dynamic propagation relationship graph based on the propagation trend characteristic value; Determining the abnormal behavior category using a support vector machine algorithm based on the diffusion risk value and the real-time communication characteristics; The executing a preset communication security execution strategy based on the abnormal behavior characteristic value includes: Based on the abnormal behavior category, a preset communication security execution strategy is executed.

5. The method according to claim 4, characterized in that The determining, based on the real-time communication feature and the abnormal behavior feature value, a propagation trend feature value of the abnormal behavior feature value in the dynamic propagation relationship graph includes: Determining a starting node corresponding to the abnormal behavior characteristic value according to the distribution characteristic value and the propagation relationship graph; Based on the real-time communication characteristics, determining high-risk propagation nodes in the propagation relationship graph; Determining a node set that combines the starting node and the high-risk propagation node; Determine a propagation trend characteristic value of the abnormal behavior characteristic value in the node set.

6. The method according to claim 5, characterized in that The determining, based on the propagation trend characteristic value, a diffusion risk value of the abnormal behavior characteristic value in the dynamic propagation relationship graph includes: Determining a high-risk time period corresponding to the abnormal behavior characteristic value; Establishing an abnormal behavior distribution set based on abnormal behavior feature values in the high-risk time period, determining a diffusion risk value of the abnormal behavior feature values in the dynamic propagation relationship graph.

7. The method according to claim 1, characterized in that The executing a preset communication security execution strategy based on the abnormal behavior characteristic value includes: Determine the abnormal behavior category and priority of the abnormal behavior feature value; Based on the category and / or the priority, a preset communication security execution policy is executed.

8. A communication security management system based on big data, characterized in that: include: an acquisition module, configured to acquire real-time communication characteristics and historical communication characteristics between a plurality of communication nodes when performing encrypted communication between the communication nodes; a clustering module, configured to cluster the real-time communication features based on the real-time communication data, the historical communication features, and the connection relationships between the plurality of communication nodes, and determine the real-time correlation features between the communication nodes; A first determining module, configured to determine at least one piece of abnormal communication data between the communication nodes based on the real-time correlation feature and the historical communication feature between the communication nodes; a second determining module, configured to combine the abnormal communication data and determine a characteristic value of abnormal behavior between the communication nodes; The management module is used to execute a preset communication security execution strategy based on the abnormal behavior characteristic value.

9. An electronic device, characterized in that: include: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Abnormal equipment detection method based on equipment communication data characteristics

    CN113542060A

  • Network security threat tracing method and system based on correlation analysis

    CN119324817A

  • Network security situation dynamic defense decision-making method and system based on AI

    CN119382969A

  • Data exception traceability tracking and positioning method, system and device and storage medium

    CN119416131A

  • Agricultural product quality abnormity propagation path prediction system and method based on graph neural network

    CN119476669A