Real-time isolation method and device based on AI traffic anomaly identification
Through a real-time isolation method based on AI traffic anomaly identification, a traffic behavior model is generated and isolation tasks are performed, which solves the problem of low processing efficiency in existing technologies and realizes intelligent and dynamic network security protection.
Patent Information
- Application Number
- CN202511014992.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-23
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2045-07-23
AI Technical Summary
Existing security protection technologies are insufficient in intelligent analysis, real-time response capabilities, and dynamic adaptability, resulting in low recognition rates for new or variant attacks and inefficient processing.
The real-time isolation method based on AI traffic anomaly identification collects network traffic data, generates traffic behavior models, analyzes anomaly characteristics and distribution patterns, and executes isolation tasks when the preset isolation conditions are met.
It improves the efficiency of identifying and isolating abnormal traffic, realizes dynamic and intelligent protection capabilities, and improves the recognition rate of new attacks.
Smart Images

Figure CN120528703B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the fields of network security and artificial intelligence technology, and in particular to a real-time isolation method and device based on AI traffic anomaly identification. Background Art
[0002] As network security threats become increasingly complex, existing security protection methods, which rely heavily on rule matching, static policies, or manual intervention, struggle to meet the demands of dynamic, intelligent protection. However, existing security protection technologies based on traffic anomaly identification still have shortcomings in intelligent analysis, real-time response capabilities, and dynamic adaptability. Traditional traffic feature analysis and pre-set threshold judgments lack the ability to deeply learn and dynamically adapt traffic behavior patterns, potentially resulting in low recognition rates for new or variant attacks.
[0003] The above content is only used to assist in understanding the technical solution of the present invention and does not constitute an admission that the above content is prior art. Summary of the Invention
[0004] The main purpose of this application is to provide a real-time isolation method and device based on AI traffic anomaly identification, aiming to solve the technical problem of low processing efficiency of abnormal traffic identification and isolation in the existing technology.
[0005] To achieve the above objectives, this application provides a real-time isolation method based on AI traffic anomaly identification, which includes:
[0006] Collecting network traffic data based on a preset traffic path, wherein the network traffic data includes communication protocol data, timestamp data, source address data, and destination address data;
[0007] fusing the communication protocol data, the timestamp data, the source address data, and the destination address data to generate a traffic behavior model;
[0008] Analyzing the traffic behavior model to determine abnormal characteristics and distribution patterns of the abnormal characteristics in the traffic behavior;
[0009] When the distribution pattern of the abnormal characteristics meets the preset isolation conditions, the current traffic processing task is switched to the isolation task, and an isolation area and an isolation signal are generated according to the distribution pattern of the abnormal characteristics, and the isolation task is performed based on the isolation area and the isolation signal.
[0010] In one embodiment, the step of fusing the communication protocol data, the timestamp data, the source address data, and the destination address data to generate a traffic behavior model includes:
[0011] Extracting characteristic protocol data and characteristic timestamp data from the communication protocol data and the timestamp data respectively, wherein the characteristic protocol data and the characteristic timestamp data are characteristic information of the same communication behavior and the same time period;
[0012] Calculating a time deviation between the characteristic protocol data and the characteristic timestamp data, and performing time synchronization correction on the communication protocol data and the timestamp data using the time deviation as a correction parameter to obtain time synchronization data;
[0013] Determining a communication relationship of network traffic based on the source address data and the target address data to obtain communication relationship data;
[0014] An initial traffic model is generated based on the network traffic, and the time synchronization data and the communication relationship data are added to the initial traffic model to generate a traffic behavior model.
[0015] In one embodiment, the step of calculating the time deviation between the characteristic protocol data and the characteristic timestamp data, and performing time synchronization correction on the communication protocol data and the timestamp data using the time deviation as a correction parameter to obtain the time synchronization data includes:
[0016] Mapping the characteristic protocol data and the characteristic timestamp data to a reference time axis respectively to obtain a first mapping position and a second mapping position;
[0017] Obtaining time coordinates of the first mapping position and the second mapping position respectively to obtain a first time coordinate and a second time coordinate;
[0018] Taking the first time coordinate as a reference point, calculating a time deviation between the second time coordinate and the first time coordinate, wherein the time deviation includes a time difference and a time direction;
[0019] Obtaining a correction parameter according to the time difference and the time direction;
[0020] The second time coordinate is time-corrected based on the correction parameter so that the first time coordinate and the second time coordinate coincide with each other, thereby obtaining time synchronization data.
[0021] In one embodiment, the step of analyzing the traffic behavior model to determine abnormal features and distribution patterns of the abnormal features in the traffic behavior includes:
[0022] Filtering high-frequency time windows in the timestamp data, determining an associated position between the high-frequency time windows and the communication protocol data, performing behavioral pattern matching on the associated positions, and determining abnormal characteristics in traffic behavior;
[0023] Determining abnormal communication relationship data between the location of abnormal features in the traffic behavior model and current network traffic;
[0024] Recording a first change pattern of the abnormal communication relationship data and a second change pattern of the timestamp data, and determining a behavior path and a behavior frequency of abnormal characteristics according to the first change pattern and the second change pattern;
[0025] A distribution pattern of abnormal features is obtained according to the behavior path and the behavior frequency.
[0026] In one embodiment, the step of determining the behavior path and behavior frequency of the abnormal feature according to the first change rule and the second change rule includes:
[0027] Extracting a correlation change sequence between a source address and a destination address in the communication relationship data, and constructing a propagation path node set with abnormal characteristics based on the correlation change sequence and the first change rule;
[0028] Counting the frequency of occurrence of abnormal features in the second change law in a continuous time window, and combining the jump sequence of the propagation path node set to generate a topological structure of the behavior path;
[0029] Calculating a weighted value of the behavior frequency according to the temporal correlation between the number of jumps between adjacent nodes in the topological structure and the occurrence frequency;
[0030] The topological structure and the weighted value are mapped into a behavior path and a behavior frequency of abnormal characteristics.
[0031] In one embodiment, when the distribution pattern of the abnormal characteristics meets the preset isolation condition, switching the current traffic processing task to an isolation task, generating an isolation area and an isolation signal according to the distribution pattern of the abnormal characteristics, and executing the isolation task based on the isolation area and the isolation signal includes:
[0032] When the distribution pattern of the abnormal characteristics meets the preset isolation conditions, switch the current traffic processing task to the isolation task, determine the remaining bandwidth of the current network traffic, and predict the minimum isolation bandwidth value based on the remaining bandwidth;
[0033] When the remaining bandwidth is less than the minimum isolation bandwidth value, predicting the corresponding behavior trajectory according to the distribution pattern of the abnormal characteristics;
[0034] An isolation area is generated according to the behavior trajectory, an isolation signal is generated according to the isolation area and the behavior trajectory, and an isolation task is performed based on the isolation area and the isolation signal.
[0035] In one embodiment, before the step of collecting network traffic data based on the preset traffic path, the method further includes:
[0036] Dividing the network traffic into a communication domain and a time domain, and generating a traffic boundary according to the constraints of the time domain and the communication domain;
[0037] Determine key nodes in the communication domain, and generate initial traffic paths based on security monitoring points and the key nodes based on a bandwidth priority principle;
[0038] The initial flow path is constrained according to the flow boundary to obtain a preset flow path.
[0039] In one embodiment, the real-time isolation method based on AI traffic anomaly identification further includes:
[0040] Determine the communication identification of the target network device, and generate an identification code based on the communication identification;
[0041] generating a traffic return signal based on the identification code and the traffic return instruction;
[0042] Sending a traffic return signal to a network traffic monitoring device, and receiving traffic perspective data fed back by the network traffic monitoring device based on the traffic return signal;
[0043] The traffic perspective data is delivered to the security central control platform.
[0044] In one embodiment, the real-time isolation method based on AI traffic anomaly identification further includes:
[0045] Determine the communication identification of the target network device and generate an identification code based on the communication identification;
[0046] Sending a manual intervention signal to the target network device based on the identification code, and receiving a response message of receipt after the target network device successfully verifies the manual intervention signal;
[0047] After receiving the response information, establishing a control channel based on the identification code;
[0048] Data is exchanged with the target network device based on the control channel to generate an operation interface for manual operation.
[0049] In addition, to achieve the above objectives, the present application also proposes a real-time isolation device based on AI traffic anomaly recognition, which includes:
[0050] A data collection module is used to collect network traffic data based on a preset traffic path, wherein the network traffic data includes communication protocol data, timestamp data, source address data, and destination address data;
[0051] a behavior modeling module, configured to fuse the communication protocol data, the timestamp data, the source address data, and the destination address data to generate a traffic behavior model;
[0052] An anomaly analysis module, configured to analyze the traffic behavior model and determine abnormal features and distribution patterns of the abnormal features in the traffic behavior;
[0053] The isolation processing module is used to switch the current traffic processing task to the isolation task when the distribution pattern of the abnormal characteristics meets the preset isolation conditions, and generate an isolation area and an isolation signal according to the distribution pattern of the abnormal characteristics, and execute the isolation task based on the isolation area and the isolation signal.
[0054] In addition, to achieve the above-mentioned purpose, the present application also proposes a real-time isolation device based on AI traffic anomaly identification, and the real-time isolation device based on AI traffic anomaly identification includes: a memory, a processor, and a computer program stored on the memory and runnable on the processor. The computer program is configured to implement the steps of the real-time isolation method based on AI traffic anomaly identification as described above.
[0055] In addition, to achieve the above-mentioned purpose, the present invention also proposes a storage medium, which is a computer-readable storage medium. A computer program is stored on the storage medium. When the computer program is executed by the processor, the steps of the real-time isolation method based on AI traffic anomaly identification as described above are implemented.
[0056] In addition, to achieve the above-mentioned purpose, the present application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the steps of the real-time isolation method based on AI traffic anomaly identification as described above.
[0057] The present application provides a real-time isolation method based on AI traffic anomaly identification, which collects network traffic data based on a preset traffic path, fuses the communication protocol data, the timestamp data, the source address data and the destination address data, generates a traffic behavior model, analyzes the traffic behavior model, determines the abnormal features in the traffic behavior and the distribution pattern of the abnormal features, and when the distribution pattern of the abnormal features meets the preset isolation conditions, switches the current traffic processing task to an isolation task, and generates an isolation area and an isolation signal based on the distribution pattern of the abnormal features, and executes the isolation task based on the isolation area and the isolation signal. In this way, the technical problem of low processing efficiency of abnormal traffic identification and isolation in the prior art is solved. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0059] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0060] Figure 1 This is a flow chart of the first embodiment of the real-time isolation method based on AI traffic anomaly identification of this application;
[0061] Figure 2 This is a schematic diagram of determining the time deviation of an embodiment of a real-time isolation method based on AI traffic anomaly identification in this application;
[0062] Figure 3 This is a flow chart of an abnormal feature distribution pattern according to an embodiment of a real-time isolation method based on AI traffic anomaly identification in this application;
[0063] Figure 4 This is a schematic diagram of the module structure of a real-time isolation device based on AI traffic anomaly recognition in an embodiment of the present application;
[0064] Figure 5 This is a schematic diagram of the device structure of the hardware operating environment involved in the real-time isolation method based on AI traffic anomaly identification in the embodiment of the present application.
[0065] The realization of the objectives, functional features and advantages of this application will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION
[0066] It should be understood that the specific embodiments described herein are merely used to explain the technical solutions of the present application and are not intended to limit the present application.
[0067] In order to better understand the technical solution of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.
[0068] The main solution of the embodiment of the present application is: collecting network traffic data based on a preset traffic path, the network traffic data including communication protocol data, timestamp data, source address data and destination address data; fusing the communication protocol data, the timestamp data, the source address data and the destination address data to generate a traffic behavior model; analyzing the traffic behavior model to determine the abnormal features and the distribution pattern of the abnormal features in the traffic behavior; when the distribution pattern of the abnormal features meets the preset isolation conditions, switching the current traffic processing task to an isolation task, and generating an isolation area and an isolation signal according to the distribution pattern of the abnormal features, and executing the isolation task based on the isolation area and the isolation signal.
[0069] With the increasing complexity of network security threats, existing security protection methods, which rely heavily on rule matching, static policies, or manual intervention, struggle to meet the demands of dynamic, intelligent protection. However, existing security protection technologies based on traffic anomaly identification still have shortcomings in intelligent analysis, real-time response capabilities, and dynamic adaptability. Traditional traffic feature analysis and pre-set threshold judgments lack the ability to deeply learn and dynamically adapt to traffic behavior patterns, potentially resulting in low recognition rates for new or variant attacks.
[0070] The present application provides a solution, which collects network traffic data based on a preset traffic path, fuses the communication protocol data, the timestamp data, the source address data, and the destination address data, generates a traffic behavior model, analyzes the traffic behavior model, determines the abnormal characteristics and the distribution pattern of the abnormal characteristics in the traffic behavior, switches the current traffic processing task to an isolation task when the distribution pattern of the abnormal characteristics meets the preset isolation conditions, generates an isolation area and an isolation signal based on the distribution pattern of the abnormal characteristics, and executes the isolation task based on the isolation area and the isolation signal. In this way, the technical problem of low processing efficiency of abnormal traffic identification and isolation in the prior art is solved.
[0071] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication, and program execution functions, such as a tablet computer, personal computer, mobile phone, etc., or an electronic device capable of performing the above functions, such as a real-time isolation device based on AI traffic anomaly identification, etc. This embodiment does not specifically limit this. The following uses a real-time isolation device based on AI traffic anomaly identification as an example to illustrate this embodiment and the following embodiments.
[0072] The present application embodiment provides a real-time isolation method based on AI traffic anomaly identification. Figure 1 , Figure 1 This is a flow chart of the first embodiment of the real-time isolation method based on AI traffic anomaly identification in this application.
[0073] In this embodiment, the real-time isolation method based on AI traffic anomaly identification includes steps S10 to S40:
[0074] Step S10, collecting network traffic data based on a preset traffic path, wherein the network traffic data includes communication protocol data, timestamp data, source address data, and destination address data;
[0075] It should be noted that the preset traffic path refers to the pre-planned network traffic monitoring path, which is a key data transmission channel selected through algorithm optimization.
[0076] It should be understood that communication protocol data includes the protocol type of network traffic (such as TCP / UDP / ICMP) and protocol header information (such as TCP flags and HTTP methods). Communication protocol data is used to identify legitimate and illegitimate services and support protocol compliance analysis in behavioral modeling, such as the frequency of abnormal POST requests in the HTTP protocol. Timestamp data refers to the precise time when a data packet arrives at or leaves a device. It is used to detect high-frequency time windows and perform time synchronization corrections, eliminating the impact of clock skew between devices on analysis. Source address data refers to the network identifier of the traffic initiator, such as the IP address or MAC address. It can be used to establish the source of the attack and build a communication relationship topology, such as identifying the communication cluster of the C&C server in a botnet. Destination address data refers to the network identifier of the traffic receiver, such as the IP address and port number. It is used to identify the attack surface of critical assets and generate behavioral paths based on the source address.
[0077] It's understandable that when identifying traffic anomalies, for example, if an enterprise needs to monitor VPN gateway traffic, it can plan a pre-defined path from firewall to VPN gateway to core switch to cover cross-border traffic and collect data based on this pre-defined path. This targeted collection mechanism can accurately capture data leaks or lateral movement, providing the input foundation for real-time isolation.
[0078] In a feasible implementation manner, before the step of collecting network traffic data based on the preset traffic path, the method further includes:
[0079] Dividing the network traffic into a communication domain and a time domain, and generating a traffic boundary according to the constraints of the time domain and the communication domain;
[0080] Determine key nodes in the communication domain, and generate initial traffic paths based on security monitoring points and the key nodes based on a bandwidth priority principle;
[0081] The initial flow path is constrained according to the flow boundary to obtain a preset flow path.
[0082] It should be noted that the process of generating a preset traffic path can be divided into two steps, one is domain division, and the other is path generation. Based on these two steps, the preset traffic path can be obtained.
[0083] It should be understood that the communication domain is a logical area divided by IP address segments and protocol types (such as HTTP traffic in the 192.168.1.0 / 24 network segment), and the time domain refers to the time period divided by business cycles (such as 9:00-11:00 during peak business hours). Path generation, on the other hand, involves identifying key nodes in the communication domain (such as database servers and VPN gateways).
[0084] In the specific implementation, network traffic is divided into communication domains and time domains. The traffic boundaries are generated by combining the restrictions of the two (such as "only monitoring cross-border HTTP traffic") to clarify the time and space scope of monitoring. Key nodes (such as core servers and gateways) are identified in the communication domain. Based on the bandwidth priority principle (high-bandwidth links are preferred), the security monitoring points (the locations where probes are deployed) are connected to the key nodes to form an initial traffic path covering the core links. The initial path is trimmed using the traffic boundaries (such as eliminating non-cross-border links) to finally obtain the preset traffic path. The monitoring scope is narrowed by limiting the time and space domains. The key nodes and bandwidth optimization are combined to ensure that no core traffic is missed. The final path is constrained by the boundaries to achieve low-overhead, high-coverage security monitoring.
[0085] Step S20, fusing the communication protocol data, the timestamp data, the source address data, and the destination address data to generate a traffic behavior model;
[0086] It should be noted that the traffic behavior model is a dynamic, structured network behavior graph generated by integrating communication protocol data, timestamp data, source address data, and destination address data. Its core is to transform discrete traffic data into quantifiable and analyzable behavior patterns.
[0087] It can be understood that the step of fusing the communication protocol data, the timestamp data, the source address data and the target address data to generate a traffic behavior model includes: extracting the characteristic protocol data and the characteristic timestamp data from the communication protocol data and the timestamp data respectively, the characteristic protocol data and the characteristic timestamp data being the characteristic information of the same communication behavior and the same time period; calculating the time deviation of the characteristic protocol data and the characteristic timestamp data, and performing time synchronization correction on the communication protocol data and the timestamp data using the time deviation as a correction parameter to obtain time synchronization data; determining the communication relationship of the network traffic based on the source address data and the target address data to obtain communication relationship data; generating an initial traffic model based on the network traffic, adding the time synchronization data and the communication relationship data to the initial traffic model to generate a traffic behavior model.
[0088] In the specific implementation, characteristic protocol data is extracted from communication protocol data and timestamp data and feature timestamp data , filter the associated features of the same communication behavior from the original data, and set a single communication behavior In the time period Characteristic protocol data within and feature timestamp data . Among them, the characteristic protocol data and feature timestamp data It can be expressed as:
[0089]
[0090]
[0091] The constraints are: Belong to the same behavior and time period .
[0092] Getting characteristic protocol data and feature timestamp data After that, calculate the characteristic protocol data and feature timestamp data The time deviation is used to eliminate the clock deviation between devices, align the protocol and timestamp data, and obtain time synchronization data. The source address is constructed based on the source address data and the target address data. and the target address Topological relationship, define the communication relationship diagram , where the node set , edge set , communication relationship data ,in is the communication frequency weight. Generate the initial traffic model based on network traffic , the basic structure of the initial traffic model can be expressed as a space-time matrix Represents, where rows represent time windows , listed as source-target pairs , the element is the protocol type distribution. On this basis, the time synchronization data and communication relationship data are injected into the initial traffic model to generate the traffic behavior model ,in, is the protocol-time joint feature, is the tensor concatenation operation, is the feature encoding function.
[0093] In a feasible implementation manner, the step of calculating the time deviation between the characteristic protocol data and the characteristic timestamp data, performing time synchronization correction on the communication protocol data and the timestamp data using the time deviation as a correction parameter, and obtaining the time synchronization data includes:
[0094] Mapping the characteristic protocol data and the characteristic timestamp data to a reference time axis respectively to obtain a first mapping position and a second mapping position;
[0095] Obtaining time coordinates of the first mapping position and the second mapping position respectively to obtain a first time coordinate and a second time coordinate;
[0096] Taking the first time coordinate as a reference point, calculating a time deviation between the second time coordinate and the first time coordinate, wherein the time deviation includes a time difference and a time direction;
[0097] Obtaining a correction parameter according to the time difference and the time direction;
[0098] The second time coordinate is time-corrected based on the correction parameter so that the first time coordinate and the second time coordinate coincide with each other, thereby obtaining time synchronization data.
[0099] It should be noted that the reference time axis is a standard time axis used to unify protocol features and timestamp features. The first mapping position is the mapping position of the characteristic protocol data on the reference time axis, and the second mapping position is the mapping position of the timestamp data on the reference time axis. The coordinate corresponding to the first mapping position on the reference time axis is the first time coordinate. Similarly, the coordinate corresponding to the second mapping position on the reference time axis is the second time coordinate.
[0100] It is understandable that, referring to Figure 2 , Figure 2 Determine the schematic diagram for time deviation. Define the base time axis function , after being mapped onto the reference time axis, the mapping position of the characteristic protocol data is obtained as Mapping location of feature timestamp data .
[0101]
[0102]
[0103] For example, if the protocol feature center is at 10.5s and the timestamp mean is 10.2s, then , .
[0104] The positions of the first mapping position and the second mapping position on the reference time axis correspond to the first time coordinate and the second time coordinate. Therefore, the time deviation between the second time coordinate and the first time coordinate can be calculated with the first time coordinate as the reference point to quantify the clock offset and direction. When determining the time deviation, it is first necessary to determine the time difference. and time direction .
[0105]
[0106]
[0107] , indicating the timestamp expiration protocol, , indicating the timestamp hysteresis protocol.
[0108] The complete deviation can then be determined , .
[0109] Then determine the correction parameters and convert the deviation into an executable correction amount. By aligning the protocol and timestamp data on the time axis through the correction parameters, the corrected timestamp can be expressed as: After calibration, synchronization verification can be performed according to the calibration target to achieve time synchronization. The calibration targets are:
[0110]
[0111] Step S30, analyzing the traffic behavior model to determine abnormal features and distribution patterns of the abnormal features in the traffic behavior;
[0112] It's important to note that anomaly signatures are behavioral indicators detected within traffic behavior models that significantly deviate from the normal baseline. They are the direct product of multi-dimensional data fusion analysis. The distribution pattern of anomaly signatures refers to their diffusion and aggregation patterns across time, space, and network topology, reflecting the evolutionary logic of attack behavior.
[0113] It should be understood that the steps of analyzing the traffic behavior model and determining the abnormal features and distribution patterns of the abnormal features in the traffic behavior include: screening the high-frequency time windows in the timestamp data, determining the associated positions of the high-frequency time windows and the communication protocol data, matching the associated positions with behavioral patterns, and determining the abnormal features in the traffic behavior; determining the abnormal communication relationship data between the positions of the abnormal features in the traffic behavior model and the current network traffic; recording the first change law of the abnormal communication relationship data and the second change law of the timestamp data, and determining the behavior path and behavior frequency of the abnormal features based on the first change law and the second change law; and obtaining the distribution pattern of the abnormal features based on the behavior path and the behavior frequency.
[0114] In the specific implementation, refer to Figure 3 , Figure 3 This is a flow chart of the abnormal feature distribution pattern. Filtering high-frequency time windows in timestamp data, time window function and window traffic density Expressed as:
[0115]
[0116]
[0117] High-frequency window set: ,in, is the dynamic threshold.
[0118] Extract protocol data within the high-frequency window to locate abnormal protocol features .
[0119] Associated location mapping: , It is the protocol feature encoder.
[0120] Behavioral pattern matching for associated locations can be expressed as:
[0121]
[0122] After matching the behavior pattern, the abnormal characteristics in the traffic behavior are determined. When the abnormal characteristics are confirmed, the abnormal characteristics confirmation results are:
[0123]
[0124] Determine the abnormal communication relationship data between the location of the abnormal feature in the traffic behavior model and the current network traffic. Determine the abnormal feature location set , construct an abnormal communication relationship graph based on the abnormal feature location set , where the node ,side .
[0125] The first change rule is the communication relationship change rule, and the second change rule is the timestamp change rule. In the communication relationship change rule, the edge set dynamics can be determined. , the change function is: , is the weight, is the diameter of the graph. In the timestamp transformation law, the abnormal pulse function is: . Determine the behavior path and behavior frequency of the abnormal feature based on the first change rule and the second change rule. Extract the associated change sequence of the source address and the target address in the communication relationship data, and construct a propagation path node set of the abnormal feature based on the associated change sequence and the first change rule; count the frequency of occurrence of the abnormal feature in the continuous time window in the second change rule, and combine the jump sequence of the propagation path node set to generate the topological structure of the behavior path; calculate the weighted value of the behavior frequency based on the time series correlation between the number of jumps between adjacent nodes in the topological structure and the occurrence frequency; map the topological structure and the weighted value to the behavior path and behavior frequency of the abnormal feature. Based on the first rule To construct the propagation path node set .
[0126]
[0127] Generate a topology structure based on the propagation path node set When calculating the frequency of an action, it is possible to determine the time window frequency and edge jump weight , output behavior frequency Then determine the distribution pattern of abnormal features based on the behavior path and behavior frequency ,in is the GraphSAGE space-time compression function, Represents graph tensor concatenation.
[0128] Step S40: When the distribution pattern of the abnormal feature meets the preset isolation condition, the current traffic processing task is switched to the isolation task, and an isolation area and an isolation signal are generated according to the distribution pattern of the abnormal feature, and the isolation task is executed based on the isolation area and the isolation signal.
[0129] It should be noted that the preset isolation condition is a threshold condition used to trigger the execution of the isolation task, and the threshold condition can exist in a static or dynamic form. The isolation task refers to the process of separating traffic with abnormal characteristics from normal traffic.
[0130] It can be understood that when the distribution pattern of the abnormal feature meets the preset isolation conditions, the current traffic processing task is switched to the isolation task, and an isolation area and an isolation signal are generated according to the distribution pattern of the abnormal feature. The process of executing the isolation task based on the isolation area and the isolation signal can be specifically described as: when the distribution pattern of the abnormal feature meets the preset isolation conditions, the current traffic processing task is switched to the isolation task, and the remaining bandwidth of the current network traffic is determined, and the minimum isolation bandwidth value is predicted based on the remaining bandwidth; when the remaining bandwidth is less than the minimum isolation bandwidth value, the corresponding behavior trajectory is predicted according to the distribution pattern of the abnormal feature; an isolation area is generated according to the behavior trajectory, an isolation signal is generated according to the isolation area and the behavior trajectory, and the isolation task is executed based on the isolation area and the isolation signal.
[0131] In a specific implementation, the preset isolation condition can be expressed as:
[0132]
[0133] in, is the threat scoring function, It is a dynamic threshold defined by security policy.
[0134] When performing task switching, the isolation task can be separated from the normal traffic task, and the isolation task resources can be reallocated to the security engine.
[0135] When the isolation task is determined, the remaining bandwidth can be evaluated. Suppose the current total network bandwidth is , the business traffic occupancy is , then the remaining bandwidth . Use the minimum isolation bandwidth as a criterion to predict and determine the basic isolation overhead , the basic isolation overhead is the fixed consumption of traffic analysis, and the dynamic isolation overhead , dynamic isolation overhead Unit traffic processing cost and behavioral path node degree Confirm, specifically:
[0136]
[0137] Then the minimum isolation bandwidth .
[0138] When bandwidth is insufficient, it can be based on distributed mode Deducing the attack path and realizing the prediction of behavior trajectory. When making predictions, based on the Markov prediction model
[0139]
[0140] Enter the current topology and frequency , output predicted path .
[0141] Generate isolation areas based on predicted paths to accurately locate attack flows , yes Based on the attack flow, an isolation signal is generated, and the signal structure is ,in, To perform actions such as DROP, REROUTE, etc., The isolation validity period. Isolation tasks are executed based on the isolation validity period.
[0142] This embodiment provides a real-time isolation method based on AI traffic anomaly identification, which collects network traffic data based on a preset traffic path, fuses the communication protocol data, the timestamp data, the source address data, and the destination address data to generate a traffic behavior model, analyzes the traffic behavior model, determines the abnormal characteristics and the distribution pattern of the abnormal characteristics in the traffic behavior, and when the distribution pattern of the abnormal characteristics meets the preset isolation conditions, switches the current traffic processing task to an isolation task, and generates an isolation area and an isolation signal based on the distribution pattern of the abnormal characteristics, and executes the isolation task based on the isolation area and the isolation signal. Through the above method, the technical problem of low processing efficiency of abnormal traffic identification and isolation in the prior art is solved.
[0143] In a feasible implementation, the real-time isolation method based on AI traffic anomaly identification further includes:
[0144] Determine the communication identification of the target network device, and generate an identification code based on the communication identification;
[0145] generating a traffic return signal based on the identification code and the traffic return instruction;
[0146] Sending a traffic return signal to a network traffic monitoring device, and receiving traffic perspective data fed back by the network traffic monitoring device based on the traffic return signal;
[0147] The traffic perspective data is delivered to the security central control platform.
[0148] In the specific implementation, a unique communication identification code is first generated for the target network device, and then the identification code and preset instructions are encapsulated into a traffic return signal; this signal triggers the designated monitoring device to capture the original traffic and metadata of the target device in real time, generating multi-dimensional traffic perspective data; finally, the data is delivered to the security central control platform through a secure channel to achieve closed-loop management of attack tracing and policy tuning.
[0149] In another feasible implementation, the real-time isolation method based on AI traffic anomaly identification further includes:
[0150] Determine the communication identification of the target network device and generate an identification code based on the communication identification;
[0151] Sending a manual intervention signal to the target network device based on the identification code, and receiving a response message of receipt after the target network device successfully verifies the manual intervention signal;
[0152] After receiving the response information, establishing a control channel based on the identification code;
[0153] Data is exchanged with the target network device based on the control channel to generate an operation interface for manual operation.
[0154] In the specific implementation, first, the communication identifier of the target network device is determined, and an identification code is generated based on the communication identifier. The identification code is a specific identification signal. Next, a manual intervention signal is sent to the target network device based on the identification code. After receiving the manual intervention signal, the device will verify it. If the verification is successful, a response message will be sent back. After receiving the response message, a control channel is established based on the previously generated identification code. Finally, data is exchanged with the target network device through the control channel to generate an operation interface for manual operation. This operation interface is equivalent to providing a "control panel" that allows humans to perform various operations on the device, allowing humans to easily control and manage the device.
[0155] It should be noted that the above examples are only used to understand this application and do not constitute a limitation on the real-time isolation method based on AI traffic anomaly identification of this application. More simple transformations based on this technical concept are all within the scope of protection of this application.
[0156] This application also provides a real-time isolation device based on AI traffic anomaly recognition, please refer to Figure 4 , the real-time isolation device based on AI traffic anomaly recognition includes:
[0157] The data collection module 10 is used to collect network traffic data based on a preset traffic path, wherein the network traffic data includes communication protocol data, timestamp data, source address data, and destination address data;
[0158] a behavior modeling module 20 for fusing the communication protocol data, the timestamp data, the source address data, and the destination address data to generate a traffic behavior model;
[0159] Anomaly analysis module 30, used to analyze the traffic behavior model to determine abnormal features and distribution patterns of abnormal features in the traffic behavior;
[0160] The isolation processing module 40 is used to switch the current traffic processing task to the isolation task when the distribution pattern of the abnormal characteristics meets the preset isolation conditions, and generate an isolation area and an isolation signal according to the distribution pattern of the abnormal characteristics, and perform the isolation task based on the isolation area and the isolation signal.
[0161] In a feasible embodiment, the behavior modeling module 20 is further used to extract characteristic protocol data and characteristic timestamp data from the communication protocol data and the timestamp data, respectively, where the characteristic protocol data and the characteristic timestamp data are characteristic information of the same communication behavior in the same time period;
[0162] Calculating a time deviation between the characteristic protocol data and the characteristic timestamp data, and performing time synchronization correction on the communication protocol data and the timestamp data using the time deviation as a correction parameter to obtain time synchronization data;
[0163] Determining a communication relationship of network traffic based on the source address data and the target address data to obtain communication relationship data;
[0164] An initial traffic model is generated based on the network traffic, and the time synchronization data and the communication relationship data are added to the initial traffic model to generate a traffic behavior model.
[0165] In a feasible implementation manner, the behavior modeling module 20 is further configured to map the characteristic protocol data and the characteristic timestamp data to a reference time axis to obtain a first mapping position and a second mapping position;
[0166] Obtaining time coordinates of the first mapping position and the second mapping position respectively to obtain a first time coordinate and a second time coordinate;
[0167] Taking the first time coordinate as a reference point, calculating a time deviation between the second time coordinate and the first time coordinate, wherein the time deviation includes a time difference and a time direction;
[0168] Obtaining a correction parameter according to the time difference and the time direction;
[0169] The second time coordinate is time-corrected based on the correction parameter so that the first time coordinate and the second time coordinate coincide with each other, thereby obtaining time synchronization data.
[0170] In a feasible embodiment, the anomaly analysis module 30 is further configured to screen high-frequency time windows in the timestamp data, determine the associated position of the high-frequency time windows and the communication protocol data, perform behavioral pattern matching on the associated positions, and determine abnormal characteristics in the traffic behavior;
[0171] Determining abnormal communication relationship data between the location of abnormal features in the traffic behavior model and current network traffic;
[0172] Recording a first change pattern of the abnormal communication relationship data and a second change pattern of the timestamp data, and determining a behavior path and a behavior frequency of abnormal characteristics according to the first change pattern and the second change pattern;
[0173] A distribution pattern of abnormal features is obtained according to the behavior path and the behavior frequency.
[0174] In a feasible embodiment, the anomaly analysis module 30 is further configured to extract a correlation change sequence between the source address and the destination address in the communication relationship data, and construct a propagation path node set of anomaly characteristics based on the correlation change sequence and the first change rule;
[0175] Counting the frequency of occurrence of abnormal features in the second change law in a continuous time window, and combining the jump sequence of the propagation path node set to generate a topological structure of the behavior path;
[0176] Calculating a weighted value of the behavior frequency according to the temporal correlation between the number of jumps between adjacent nodes in the topological structure and the occurrence frequency;
[0177] The topological structure and the weighted value are mapped into a behavior path and a behavior frequency of abnormal characteristics.
[0178] In a feasible embodiment, the isolation processing module 40 is further configured to switch the current traffic processing task to an isolation task when the distribution pattern of the abnormal characteristics meets the preset isolation condition, determine the remaining bandwidth of the current network traffic, and predict the minimum isolation bandwidth value based on the remaining bandwidth;
[0179] When the remaining bandwidth is less than the minimum isolation bandwidth value, predicting the corresponding behavior trajectory according to the distribution pattern of the abnormal characteristics;
[0180] An isolation area is generated according to the behavior trajectory, an isolation signal is generated according to the isolation area and the behavior trajectory, and an isolation task is performed based on the isolation area and the isolation signal.
[0181] In a feasible implementation manner, the data acquisition module 10 is further configured to divide the network traffic into a communication domain and a time domain, and generate a traffic boundary according to the restriction conditions of the time domain and the communication domain;
[0182] Determine key nodes in the communication domain, and generate initial traffic paths based on security monitoring points and the key nodes based on a bandwidth priority principle;
[0183] The initial flow path is constrained according to the flow boundary to obtain a preset flow path.
[0184] In a feasible implementation manner, the traffic monitoring module 50 is further configured to determine a communication identifier of a target network device and generate an identification code according to the communication identifier;
[0185] generating a traffic return signal based on the identification code and the traffic return instruction;
[0186] Sending a traffic return signal to a network traffic monitoring device, and receiving traffic perspective data fed back by the network traffic monitoring device based on the traffic return signal;
[0187] The traffic perspective data is delivered to the security central control platform.
[0188] In a feasible implementation manner, the manual intervention module 60 is further configured to determine a communication identifier of the target network device and generate an identification code based on the communication identifier;
[0189] Sending a manual intervention signal to the target network device based on the identification code, and receiving a response message of receipt after the target network device successfully verifies the manual intervention signal;
[0190] After receiving the response information, establishing a control channel based on the identification code;
[0191] Data is exchanged with the target network device based on the control channel to generate an operation interface for manual operation.
[0192] The real-time isolation device based on AI traffic anomaly identification provided by this application adopts the real-time isolation method based on AI traffic anomaly identification in the above-mentioned embodiment, which can solve the technical problem of low processing efficiency of abnormal traffic identification and isolation. Compared with the prior art, the beneficial effects of the real-time isolation device based on AI traffic anomaly identification provided by this application are the same as the beneficial effects of the real-time isolation method based on AI traffic anomaly identification provided by the above-mentioned embodiment, and the other technical features of the real-time isolation device based on AI traffic anomaly identification are the same as the features disclosed in the above-mentioned embodiment method, which will not be repeated here.
[0193] The present application provides a real-time isolation device based on AI traffic anomaly identification. The real-time isolation device based on AI traffic anomaly identification includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the real-time isolation method based on AI traffic anomaly identification in the above-mentioned embodiment one.
[0194] Reference below Figure 5, which shows a schematic diagram of the structure of a real-time isolation device based on AI traffic anomaly identification suitable for implementing the embodiment of the present application. The real-time isolation device based on AI traffic anomaly identification in the embodiment of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., as well as fixed terminals such as digital TVs, desktop computers, etc. Figure 5 The real-time isolation device based on AI traffic anomaly identification shown is merely an example and should not impose any limitations on the functions and scope of use of the embodiments of the present application.
[0195] like Figure 5 As shown, the real-time isolation device based on AI traffic anomaly identification may include a processing device 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes based on programs stored in ROM (Read Only Memory) 1002 or programs loaded from storage device 1003 into RAM (Random Access Memory) 1004. RAM 1004 also stores various programs and data required for the operation of the real-time isolation device based on AI traffic anomaly identification. Processing device 1001, ROM 1002, and RAM 1004 are interconnected via bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; an output device 1008 including, for example, an LCD (Liquid Crystal Display), speaker, vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the real-time isolation device based on AI traffic anomaly identification to communicate wirelessly or wired with other devices to exchange data. Although the figure shows a real-time isolation device based on AI traffic anomaly identification with various systems, it should be understood that it is not required to implement or have all of the systems shown. More or fewer systems may be implemented or have alternatively.
[0196] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program comprising program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiment disclosed in the present application are executed.
[0197] The real-time isolation device based on AI traffic anomaly identification provided by this application adopts the real-time isolation method based on AI traffic anomaly identification in the above-mentioned embodiment, which can solve the technical problem of real-time isolation based on AI traffic anomaly identification. Compared with the prior art, the beneficial effects of the real-time isolation device based on AI traffic anomaly identification provided by this application are the same as the beneficial effects of the real-time isolation method based on AI traffic anomaly identification provided by the above-mentioned embodiment, and the other technical features of the real-time isolation device based on AI traffic anomaly identification are the same as the features disclosed in the method of the previous embodiment, which will not be repeated here.
[0198] It should be understood that the various parts disclosed in this application can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in any one or more embodiments or examples in a suitable manner.
[0199] The above are only specific embodiments of the present application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.
[0200] The present application provides a computer-readable storage medium having computer-readable program instructions (i.e., a computer program) stored thereon, and the computer-readable program instructions are used to execute the real-time isolation method based on AI traffic anomaly identification in the above-mentioned embodiment.
[0201] The computer-readable storage medium provided herein may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems, or devices, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to, an electrical connection having one or more wires, a portable computer disk, a hard disk, RAM (Random Access Memory), ROM (Read Only Memory), EPROM (Erasable Programmable Read Only Memory or Flash memory), optical fiber, CD-ROM (CD-Read Only Memory), optical storage device, magnetic storage device, or any suitable combination thereof. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium may be transmitted using any suitable medium, including, but not limited to, wires, optical cables, RF (Radio Frequency), etc., or any suitable combination thereof.
[0202] The above-mentioned computer-readable storage medium can be included in the real-time isolation device based on AI traffic anomaly identification; or it can exist independently without being assembled into the real-time isolation device based on AI traffic anomaly identification.
[0203] The above-mentioned computer-readable storage medium carries one or more programs. When the above-mentioned one or more programs are executed by the real-time isolation device based on AI traffic anomaly identification, the real-time isolation device based on AI traffic anomaly identification: collects network traffic data based on a preset traffic path, and the network traffic data includes communication protocol data, timestamp data, source address data and destination address data; fuses the communication protocol data, the timestamp data, the source address data and the destination address data to generate a traffic behavior model; analyzes the traffic behavior model to determine the abnormal features and the distribution pattern of the abnormal features in the traffic behavior; when the distribution pattern of the abnormal features meets the preset isolation conditions, switches the current traffic processing task to an isolation task, and generates an isolation area and an isolation signal according to the distribution pattern of the abnormal features, and executes the isolation task based on the isolation area and the isolation signal.
[0204] The computer program code for performing the operations of the present application may be written in one or more programming languages, or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a LAN (Local Area Network) or a WAN (Wide Area Network), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0205] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order than that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs the specified function or operation, or can be implemented by a combination of dedicated hardware and computer instructions.
[0206] The modules described in the embodiments of the present application may be implemented in software or hardware, wherein the name of a module does not necessarily limit the unit itself.
[0207] The computer-readable storage medium provided in this application stores computer-readable program instructions (i.e., a computer program) for executing the aforementioned real-time isolation method based on AI-powered traffic anomaly identification. This computer-readable storage medium can address the technical issues surrounding real-time isolation based on AI-powered traffic anomaly identification. Compared to the prior art, the beneficial effects of the computer-readable storage medium provided in this application are similar to those of the real-time isolation method based on AI-powered traffic anomaly identification provided in the aforementioned embodiments, and are not further elaborated here.
[0208] The present application also provides a computer program product, including a computer program, which, when executed by a processor, implements the steps of the above-mentioned real-time isolation method based on AI traffic anomaly identification.
[0209] The computer program product provided in this application can solve the technical problem of real-time isolation based on AI-based traffic anomaly identification. Compared with the prior art, the beneficial effects of the computer program product provided in this application are the same as those of the real-time isolation method based on AI-based traffic anomaly identification provided in the above embodiments, and will not be elaborated here.
[0210] The above are only some embodiments of the present application and are not intended to limit the patent scope of the present application. All equivalent structural transformations made using the contents of the present application specification and drawings under the technical concept of the present application, or direct / indirect application in other related technical fields are included in the patent protection scope of the present application.
Claims
1. A real-time isolation method based on AI traffic anomaly identification, characterized in that: The real-time isolation method based on AI traffic anomaly identification includes: Collecting network traffic data based on a preset traffic path, wherein the network traffic data includes communication protocol data, timestamp data, source address data, and destination address data; fusing the communication protocol data, the timestamp data, the source address data, and the destination address data to generate a traffic behavior model; Analyzing the traffic behavior model to determine abnormal characteristics and distribution patterns of the abnormal characteristics in the traffic behavior; When the distribution pattern of the abnormal characteristics meets the preset isolation condition, switching the current traffic processing task to the isolation task, generating an isolation area and an isolation signal according to the distribution pattern of the abnormal characteristics, and executing the isolation task based on the isolation area and the isolation signal; The step of analyzing the traffic behavior model to determine abnormal features and distribution patterns of the abnormal features in the traffic behavior includes: Filtering high-frequency time windows in the timestamp data, determining an associated position between the high-frequency time windows and the communication protocol data, performing behavioral pattern matching on the associated positions, and determining abnormal characteristics in traffic behavior; Determining abnormal communication relationship data between the location of abnormal features in the traffic behavior model and current network traffic; Recording a first change pattern of the abnormal communication relationship data and a second change pattern of the timestamp data, and determining a behavior path and a behavior frequency of abnormal characteristics according to the first change pattern and the second change pattern; Obtaining a distribution pattern of abnormal characteristics according to the behavior path and the behavior frequency; The step of determining the behavior path and behavior frequency of abnormal characteristics according to the first change rule and the second change rule includes: Extracting a correlation change sequence between a source address and a destination address in the communication relationship data, and constructing a propagation path node set with abnormal characteristics based on the correlation change sequence and the first change rule; Counting the frequency of occurrence of abnormal features in the second change law in a continuous time window, and combining the jump sequence of the propagation path node set to generate a topological structure of the behavior path; Calculating a weighted value of the behavior frequency according to the temporal correlation between the number of jumps between adjacent nodes in the topological structure and the occurrence frequency; The topological structure and the weighted value are mapped into a behavior path and a behavior frequency of abnormal characteristics.
2. The method according to claim 1, wherein The step of fusing the communication protocol data, the timestamp data, the source address data, and the destination address data to generate a traffic behavior model includes: Extracting characteristic protocol data and characteristic timestamp data from the communication protocol data and the timestamp data respectively, wherein the characteristic protocol data and the characteristic timestamp data are characteristic information of the same communication behavior and the same time period; Calculating a time deviation between the characteristic protocol data and the characteristic timestamp data, and performing time synchronization correction on the communication protocol data and the timestamp data using the time deviation as a correction parameter to obtain time synchronization data; Determining a communication relationship of network traffic based on the source address data and the target address data to obtain communication relationship data; An initial traffic model is generated based on the network traffic, and the time synchronization data and the communication relationship data are added to the initial traffic model to generate a traffic behavior model.
3. The method according to claim 2, wherein The step of calculating the time deviation between the characteristic protocol data and the characteristic timestamp data, and performing time synchronization correction on the communication protocol data and the timestamp data using the time deviation as a correction parameter to obtain the time synchronization data comprises: Mapping the characteristic protocol data and the characteristic timestamp data to a reference time axis respectively to obtain a first mapping position and a second mapping position; Obtaining time coordinates of the first mapping position and the second mapping position respectively to obtain a first time coordinate and a second time coordinate; Taking the first time coordinate as a reference point, calculating a time deviation between the second time coordinate and the first time coordinate, wherein the time deviation includes a time difference and a time direction; Obtaining a correction parameter according to the time difference and the time direction; The second time coordinate is time-corrected based on the correction parameter so that the first time coordinate and the second time coordinate coincide with each other, thereby obtaining time synchronization data.
4. The method according to claim 1, wherein When the distribution pattern of the abnormal characteristics meets the preset isolation condition, switching the current traffic processing task to the isolation task, generating an isolation area and an isolation signal according to the distribution pattern of the abnormal characteristics, and executing the isolation task based on the isolation area and the isolation signal includes: When the distribution pattern of the abnormal characteristics meets the preset isolation conditions, switch the current traffic processing task to the isolation task, determine the remaining bandwidth of the current network traffic, and predict the minimum isolation bandwidth value based on the remaining bandwidth; When the remaining bandwidth is less than the minimum isolation bandwidth value, predicting the corresponding behavior trajectory according to the distribution pattern of the abnormal characteristics; An isolation area is generated according to the behavior trajectory, an isolation signal is generated according to the isolation area and the behavior trajectory, and an isolation task is performed based on the isolation area and the isolation signal.
5. The method according to claim 1, wherein Before the step of collecting network traffic data based on the preset traffic path, the method further includes: Dividing the network traffic into a communication domain and a time domain, and generating a traffic boundary according to the constraints of the time domain and the communication domain; Determine key nodes in the communication domain, and generate initial traffic paths based on security monitoring points and the key nodes based on a bandwidth priority principle; The initial flow path is constrained according to the flow boundary to obtain a preset flow path.
6. The method according to claim 1, wherein The real-time isolation method based on AI traffic anomaly identification also includes: Determine the communication identification of the target network device, and generate an identification code based on the communication identification; generating a traffic return signal based on the identification code and the traffic return instruction; Sending a traffic return signal to a network traffic monitoring device, and receiving traffic perspective data fed back by the network traffic monitoring device based on the traffic return signal; The traffic perspective data is delivered to the security central control platform.
7. The method according to claim 1, wherein The real-time isolation method based on AI traffic anomaly identification also includes: Determine the communication identification of the target network device and generate an identification code based on the communication identification; Sending a manual intervention signal to the target network device based on the identification code, and receiving a response message of receipt after the target network device successfully verifies the manual intervention signal; After receiving the response information, establishing a control channel based on the identification code; Data is exchanged with the target network device based on the control channel to generate an operation interface for manual operation.
8. A real-time isolation device based on AI traffic anomaly recognition, characterized in that: The real-time isolation device based on AI traffic anomaly recognition includes: A data collection module is used to collect network traffic data based on a preset traffic path, wherein the network traffic data includes communication protocol data, timestamp data, source address data, and destination address data; a behavior modeling module, configured to fuse the communication protocol data, the timestamp data, the source address data, and the destination address data to generate a traffic behavior model; An anomaly analysis module, configured to analyze the traffic behavior model and determine abnormal features and distribution patterns of the abnormal features in the traffic behavior; an isolation processing module, configured to switch the current traffic processing task to an isolation task when the distribution pattern of the abnormal characteristics meets the preset isolation conditions, generate an isolation area and an isolation signal according to the distribution pattern of the abnormal characteristics, and execute the isolation task based on the isolation area and the isolation signal; The step of analyzing the traffic behavior model to determine abnormal features and distribution patterns of the abnormal features in the traffic behavior includes: Filtering high-frequency time windows in the timestamp data, determining an associated position between the high-frequency time windows and the communication protocol data, performing behavioral pattern matching on the associated positions, and determining abnormal characteristics in traffic behavior; Determining abnormal communication relationship data between the location of abnormal features in the traffic behavior model and current network traffic; Recording a first change pattern of the abnormal communication relationship data and a second change pattern of the timestamp data, and determining a behavior path and a behavior frequency of abnormal characteristics according to the first change pattern and the second change pattern; Obtaining a distribution pattern of abnormal characteristics according to the behavior path and the behavior frequency; The step of determining the behavior path and behavior frequency of abnormal characteristics according to the first change rule and the second change rule includes: Extracting a correlation change sequence between a source address and a destination address in the communication relationship data, and constructing a propagation path node set with abnormal characteristics based on the correlation change sequence and the first change rule; Counting the frequency of occurrence of abnormal features in the second change law in a continuous time window, and combining the jump sequence of the propagation path node set to generate a topological structure of the behavior path; Calculating a weighted value of the behavior frequency according to the temporal correlation between the number of jumps between adjacent nodes in the topological structure and the occurrence frequency; The topological structure and the weighted value are mapped into a behavior path and a behavior frequency of abnormal characteristics.
Citation Information
Patent Citations
Abnormal network flow detection system and method based on multi-modal fusion features
CN118353690A
Method and device for processing abnormal traffic in power internet of things, and storage medium
CN118984290A