Intranet link abnormal behavior detection system and method based on cloud edge collaboration

By collecting and normalizing data processing at edge nodes, combined with cloud collaborative analysis methods, the problems of low data processing efficiency and single feature extraction in intranet link abnormality detection are solved, and efficient, accurate and dynamically adaptable abnormal behavior detection is achieved, improving intranet security and real-time monitoring capabilities.

CN120567474APending Publication Date: 2025-08-29BEIJING XINRAN ELECTRIC POWER TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510689117.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-08-29

AI Technical Summary

Technical Problem

The traditional intranet link abnormality detection methods have problems such as low data processing efficiency, single feature extraction, insufficient cloud-edge collaboration and poor dynamic adaptability, which are difficult to meet the needs of real-time and accuracy.

Method used

The intranet link abnormal behavior detection system based on cloud-edge collaboration is adopted. By collecting basic data at edge nodes, normalizing processing and feature extraction, combining cloud-end collaborative analysis, and using multi-dimensional feature indicators and dynamic threshold comparison, it can achieve rapid identification and in-depth analysis of abnormal behavior.

Benefits of technology

It realizes efficient resource utilization, multi-dimensional accurate detection and dynamic adaptability, reduces false alarm rates, meets the real-time monitoring needs in large-scale intranet environments, and improves network security and scalability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120567474A_ABST
    Figure CN120567474A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of link anomaly detection, and discloses an intranet link abnormal behavior detection system and method based on cloud edge collaboration.The system comprises a data acquisition module, a data transmission module, a preprocessing module, a feature extraction module, an anomaly judgment module and a collaborative analysis module; the edge node is responsible for local data acquisition and compression transmission, greatly reducing bandwidth occupation and improving real-time performance; the cloud comprehensively captures an abnormal mode through normalization processing and dynamic feature extraction of multi-dimensional data, and the false alarm rate is remarkably reduced in combination with double criteria; the cloud edge coordination mechanism not only exerts the advantage of low delay of the edge side, but also effectively identifies distributed attack and resource abuse behaviors by utilizing the global computing power of the cloud; the modular design supports flexible expansion, is suitable for a large-scale intranet environment, gives consideration to the resource efficiency and deployment adaptability while guaranteeing the detection precision, and provides a high-reliability security protection solution for industrial Internet, enterprise intranet and other scenes.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of link anomaly detection, and in particular to a system and method for detecting abnormal behavior of intranet links based on cloud-edge collaboration. Background Art

[0002] With the rapid development of enterprise informatization and network technology, the security and stability of intranets, as critical infrastructure for core business operations and data transmission, are paramount. However, abnormal behavior within intranet links not only impacts network performance but also poses security risks such as malicious attacks, data leaks, and internal misuse. Traditional abnormal behavior detection methods typically rely on centralized detection or single-point monitoring, which suffers from issues such as insufficient real-time performance, high computing resource usage, and difficulty adapting to complex and changing network environments.

[0003] Currently, common anomaly detection technologies mainly include statistical methods, machine learning models, and rule matching. However, these methods face the following challenges in practical applications:

[0004] Low data processing efficiency: The scale of intranet link data is huge, and traditional centralized processing methods may lead to data transmission delays and excessive cloud computing pressure, making it difficult to meet real-time detection needs.

[0005] Single feature extraction: Existing methods mostly focus on single-dimensional analysis of traffic or connection status, lacking collaborative analysis of multi-dimensional features, resulting in insufficient detection accuracy.

[0006] Insufficient cloud-edge collaboration: Edge nodes are usually only responsible for data collection and simple filtering, while the cloud takes on all computing tasks, failing to fully utilize the capabilities of edge computing, resulting in uneven resource utilization and limited response speed.

[0007] Poor dynamic adaptability: Traditional threshold setting methods are fixed and difficult to adapt to dynamic changes in intranet links, which can easily lead to false positives or missed positives.

[0008] To address the above issues, there is an urgent need for an abnormal behavior detection method that is efficient, accurate and adaptable to dynamic network environments. Summary of the Invention

[0009] The purpose of the present invention is to provide a system and method for detecting abnormal behavior of intranet links based on cloud-edge collaboration, which solves the technical problems raised in the background technology.

[0010] The purpose of the present invention can be achieved through the following technical solutions:

[0011] The method for detecting abnormal behavior of intranet links based on cloud-edge collaboration includes the following steps:

[0012] Step 1: Data Collection:

[0013] Set up a data collection module at the edge node of each intranet and collect basic data of the intranet link corresponding to the edge node;

[0014] Step 2: Data transmission:

[0015] Transmit basic data to the cloud server via the intranet link;

[0016] Step 3: Normalization:

[0017] Normalize the basic data to a value between 0 and 1;

[0018] Step 4: Data feature extraction:

[0019] The feature extraction module performs feature extraction on the normalized basic data on each edge node and obtains multiple data features;

[0020] Step 5: Abnormal behavior judgment:

[0021] The abnormality judgment module compares the data features of each edge node with the corresponding preset feature threshold to preliminarily judge abnormal behavior;

[0022] Step 6: Cloud-edge collaborative analysis:

[0023] The collaborative analysis module conducts in-depth analysis of the intranet links corresponding to each edge node with abnormal behavior to determine whether the relevant links have abnormal behavior within the specified analysis period.

[0024] As a further solution of the present invention: basic data includes: data packet flow F, data packet size S, source IP address IP a , destination IP address b , link bandwidth occupancy rate B, data transmission rate R, and link connection time L.

[0025] As a further solution of the present invention: when transmitting basic data, the basic data is also compressed;

[0026] The compression processing methods for packet flow, packet size, link bandwidth utilization, data transmission rate, and link connection duration are similar; for selected packet flow:

[0027] For the data packet flow F(t) of the t-th standard collection period, obtain the data packet flow F(t-1) of the previous standard collection period;

[0028] By using WF=F(t)-F(t-1), the difference between the packet flow F(t) of the tth standard collection period and the packet flow F(t-1) of the t-1th standard collection period is calculated, and then WF(t) is transmitted to the cloud server;

[0029] The WF(t) value for the packet flow rate during the first standard collection period in the current specified analysis cycle is the packet flow rate during the first standard collection period in the current specified analysis cycle minus the packet flow rate during the last standard collection period in the previous specified analysis cycle.

[0030] When the cloud server receives WF(t), the data packet flow F(t-1) already received by the cloud server is added to WF(t) to obtain the data packet flow F(t) of the tth standard collection period;

[0031] The data packet traffic during the first standard collection period within the initially specified analysis cycle is directly transmitted to the cloud server.

[0032] As a further solution of the present invention: the cloud server includes a preprocessing module, a feature extraction module, an abnormality judgment module, and a collaborative analysis module.

[0033] As a further solution of the present invention, the normalization processing method is as follows: the preprocessing module divides the specified analysis period into multiple standard collection time periods, and then obtains the data packet flow F(t), data packet size S(t), link bandwidth occupancy B(t), data transmission rate R(t), and link connection duration L(t) for each standard collection time period;

[0034] Where t = 1, 2, ..., e, where e represents the number of standard acquisition periods within a specified analysis period;

[0035] Among them, the normalization processing method of data packet flow, data packet size, data transmission rate, and link connection time is the same; data packet flow is selected for normalization processing;

[0036] In the data packet flow F(t) of each standard collection period, extract the data packet flow F with the maximum and minimum values max and F min ;

[0037] pass: Calculate the normalized data packet flow value F1(t).

[0038] As a further solution of the present invention: wherein the link bandwidth occupancy rate B(t) itself has a value range of 0% to 100%, then the percentage is converted into a decimal and normalized to between 0 and 1.

[0039] As a further solution of the present invention: the feature extraction processing method is as follows:

[0040] Step K1, Packet Traffic Characteristics:

[0041] pass: Calculate the average flow rate change rate BF within the specified analysis period; where t is the standard collection period after t-1;

[0042] Step K2, Data packet size characteristics:

[0043] pass: Calculate the fluctuation of the packet size within the specified analysis period and use the standard deviation BS to measure it; where PS is the average value of the packet size within the specified analysis period;

[0044] Step K3, link bandwidth utilization characteristics:

[0045] pass: Calculate the change rate BB of the link bandwidth utilization rate within the specified analysis period;

[0046] Step K4, Data transmission rate characteristics:

[0047] pass: Calculate the coefficient of variation (CVR) of the data transmission rate within the specified analysis period; where PR is the average data transmission rate within the specified analysis period, and BR is the standard deviation of the data transmission rate within the specified analysis period;

[0048] Step K5: Link connection duration characteristics:

[0049] During the standard collection period e, count the number of times the link connection duration changes eL;

[0050] Among them, when L(t)≠L(t-1), it means that the link connection duration of two adjacent standard collection periods has changed;

[0051] pass: Calculate the change frequency FL of the link connection duration within the specified analysis period.

[0052] As a further solution of the present invention: the abnormal behavior judgment method is as follows:

[0053] Step U1, determine if the data packet traffic characteristics are abnormal:

[0054] Compare the average flow rate change rate BF with the pre-set flow rate change rate threshold BFy:

[0055] If BF>BFy, it is determined that there is a suspected abnormality in the data packet flow;

[0056] Step U2, determine if the data packet size characteristics are abnormal:

[0057] Compare the data packet size fluctuation degree BS with the pre-set data packet standard deviation threshold BSy:

[0058] If BS>BSy, it is determined that the fluctuation of the number of data packets is suspected to be abnormal;

[0059] Step U3: Determine if the link bandwidth usage is abnormal:

[0060] Compare the link bandwidth usage change rate BB with the preset bandwidth usage threshold BBy:

[0061] If BB>BBy, it is determined that the link bandwidth usage is suspected to be abnormal;

[0062] Step U4: Determine if the data transmission rate is abnormal:

[0063] Compare the coefficient of variation CVR of the data transmission rate with the preset transmission rate variation threshold CVRy:

[0064] When CVR>CVRy, it is determined that the transmission rate is suspected to be abnormal;

[0065] Step U5: Determine if the link connection duration is abnormal:

[0066] The link connection duration change frequency FL is compared with the preset link duration change frequency threshold FLy:

[0067] If FL>FLy, it is determined that the link duration is suspected to be abnormal;

[0068] When at least one of the above five feature anomaly judgments meets the abnormal condition, it is determined that the intranet link of the corresponding edge node has suspected abnormal behavior within the specified analysis period.

[0069] As a further solution of the present invention: the in-depth analysis method is as follows:

[0070] Step Y1. Classify by source IP address and destination IP address, and group the basic data and data features from the links corresponding to the same source IP address and destination IP address.

[0071] Step Y2: For the same set of data, calculate the average value of each basic data of the same set of edge nodes in the same standard collection period within the same specified analysis cycle;

[0072] Step Y3: According to the method in the data feature extraction step: the feature extraction module performs feature extraction processing on the average values ​​of various basic data of the same group of edge nodes within the specified analysis period, and obtains multiple collaborative data features;

[0073] Step Y4: Follow the abnormal behavior judgment step: Use the abnormal judgment module to compare the collaborative data features on each edge node with the corresponding preset feature thresholds to determine whether the data packet flow, data packet number fluctuation, link bandwidth occupancy, data transmission rate, and link connection duration are indeed abnormal;

[0074] When at least one of the above five abnormal features meets the abnormal condition, the source IP address is determined to be a To the destination IP address b The link does have abnormal behavior during the specified analysis period.

[0075] An intranet link abnormal behavior detection system based on cloud-edge collaboration is used to execute an intranet link abnormal behavior detection method based on cloud-edge collaboration. The system includes:

[0076] Data collection module, used to collect basic data of the intranet link corresponding to the edge node;

[0077] Data transmission module, used to transmit basic data to the cloud server through the intranet link;

[0078] Through the preprocessing module, it is used to normalize the basic data to a value between 0 and 1;

[0079] The feature extraction module is used to extract features from the normalized basic data on each edge node and obtain multiple data features;

[0080] The anomaly judgment module is used to compare the data features on each edge node with the corresponding preset feature thresholds to preliminarily judge abnormal behavior;

[0081] The collaborative analysis module is used to conduct in-depth analysis of the intranet links corresponding to each edge node with abnormal behavior, and whether the relevant links have abnormal behavior within the specified analysis period.

[0082] Beneficial effects of the present invention:

[0083] Efficient resource utilization: Through the architectural design of local data collection at the edge node and collaborative analysis in the cloud, cloud computing pressure is reduced, network transmission load is lowered, and resource optimization is achieved.

[0084] Multi-dimensional precision detection: Comprehensive basic data such as packet flow, size, bandwidth utilization, transmission rate, connection duration, etc., combined with multiple dynamic feature indicators, achieves refined identification of abnormal behavior through multi-threshold comparison, and improves the comprehensiveness of detection.

[0085] Intelligent layered judgment mechanism: Adopts a two-layer analysis mode of "initial judgment at the edge + deep collaboration at the cloud": the edge side quickly screens suspected anomalies; the cloud eliminates false positives through IP group statistics and cross-node feature mean analysis, ultimately confirming abnormal links and improving accuracy.

[0086] Dynamic adaptability: Normalization processing and time-varying feature extraction enable the system to adapt to network environments of different scales, supporting long-term trend analysis and short-term sudden anomaly capture.

[0087] Security and scalability: IP address-based link group analysis can trace the source of anomalies and facilitate the location of attack paths; the modular design facilitates the addition of new detection dimensions and the adjustment of threshold policies.

[0088] Real-time and low latency: Standard collection period division and incremental data transmission mechanism ensure real-time monitoring capabilities and meet the needs of rapid response to highly sensitive scenarios.

[0089] The present invention uses cloud-edge collaborative architecture and multi-indicator fusion analysis to significantly improve efficiency while ensuring detection accuracy. It is suitable for security monitoring in large-scale intranet environments and provides a resource-saving, low-false-alarm and scalable solution for identifying abnormal network behavior. BRIEF DESCRIPTION OF THE DRAWINGS

[0090] The present invention will be further described below with reference to the accompanying drawings.

[0091] Figure 1 This is a system block diagram of the intranet link abnormal behavior detection system based on cloud-edge collaboration of the present invention.

[0092] Figure 2 It is a flow chart of the method for detecting abnormal behavior of intranet links based on cloud-edge collaboration of the present invention. DETAILED DESCRIPTION

[0093] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.

[0094] As embodiment 1 of the present invention:

[0095] See also Figure 1 and Figure 2 As shown, the present invention is a method for detecting abnormal behavior of intranet links based on cloud-edge collaboration, which includes the following steps:

[0096] Step 1: Data Collection:

[0097] Set up a data collection module at the edge node of each intranet;

[0098] Edge nodes refer to network devices corresponding to routers and switches;

[0099] The data collection module is responsible for collecting basic data of the intranet link corresponding to the edge node. The basic data includes:

[0100] Packet flow F: the number of packets passing through the link per unit time, in packets per second;

[0101] Data packet size S: the amount of data contained in each data packet, in bytes;

[0102] Source IP address a and destination IP address b : Identify the sender and receiver of the data packet;

[0103] Link bandwidth utilization rate B: The ratio of the actual link bandwidth to the total bandwidth within a specified time, expressed as a percentage, i.e.

[0104] Data transmission rate R: The unit is bits per second;

[0105] Link connection duration L: in seconds;

[0106] The data acquisition module collects and records the above basic data at a fixed time interval Δt;

[0107] Step 2: Data transmission:

[0108] Transmit basic data to the cloud server via the intranet link;

[0109] The cloud server includes a pre-processing module, a feature extraction module, an anomaly judgment module, and a collaborative analysis module;

[0110] Step 3: Normalization:

[0111] The preprocessing module divides the specified analysis period into multiple standard collection periods, and then obtains the data packet flow F(t), data packet size S(t), link bandwidth utilization B(t), data transmission rate R(t), and link connection duration L(t) for each standard collection period;

[0112] Where t = 1, 2, ..., e, where e represents the number of standard acquisition periods within a specified analysis period;

[0113] Select the packet traffic for normalization;

[0114] In the data packet flow F(t) of each standard collection period, extract the data packet flow F with the maximum and minimum values max and F min ;

[0115] pass: Calculate the normalized data packet flow value F1(t).

[0116] The normalization processing method of the packet size S(t), data transmission rate R(t), and link connection time L(t) is the same as the normalization processing method of the packet flow;

[0117] The link bandwidth occupancy rate B(t) itself ranges from 0% to 100%, so its percentage is converted into a decimal and normalized to between 0 and 1;

[0118] Step 4: Data feature extraction:

[0119] The feature extraction module performs feature extraction on the normalized basic data on each edge node and obtains multiple data features;

[0120] The specific method is as follows:

[0121] Step K1, Packet Traffic Characteristics:

[0122] pass: Calculate the average flow rate change rate BF within the specified analysis period;

[0123] Wherein, t is the standard collection period after t-1;

[0124] In this embodiment, the average traffic change rate is used to reflect the change trend of the data packet traffic;

[0125] Step K2, Data packet size characteristics:

[0126] pass: Calculate the fluctuation of the packet size within the specified analysis period and use the standard deviation BS to measure it;

[0127] Where PS is the average value of the packet size within the specified analysis period;

[0128] Step K3, link bandwidth utilization characteristics:

[0129] pass: Calculate the change rate BB of the link bandwidth utilization rate within the specified analysis period;

[0130] In this embodiment, the change rate of the link bandwidth occupancy rate is used to reflect the change trend of the link bandwidth occupancy rate;

[0131] Step K4, Data transmission rate characteristics:

[0132] pass: Calculate the coefficient of variation CVR of the data transmission rate within the specified analysis period;

[0133] Where PR is the average value of the data transmission rate within the specified analysis period, and BR is the standard deviation of the data transmission rate within the specified analysis period;

[0134] In this embodiment, the average flow rate change rate is used to reflect the relative dispersion of the transmission rate;

[0135] Step K5: Link connection duration characteristics:

[0136] During the standard collection period e, count the number of times the link connection duration changes eL;

[0137] Among them, when L(t)≠L(t-1), it means that the link connection duration of two adjacent standard collection periods has changed;

[0138] pass: Calculate the change frequency FL of the link connection duration within the specified analysis period;

[0139] Step 5: Abnormal behavior judgment:

[0140] The abnormality judgment module compares the data features of each edge node with the corresponding preset feature threshold to determine abnormal behavior;

[0141] Step U1, determine if the data packet traffic characteristics are abnormal:

[0142] Compare the average flow rate change rate BF with the pre-set flow rate change rate threshold BFy:

[0143] If BF>BFy, it is determined that there is a suspected abnormality in the data packet flow. In this embodiment, it may be a data leak or a malicious attack that causes a sudden increase in flow.

[0144] Step U2, determine if the data packet size characteristics are abnormal:

[0145] Compare the data packet size fluctuation degree BS with the pre-set data packet standard deviation threshold BSy:

[0146] If BS>BSy, it is determined that the fluctuation of the number of data packets is suspected to be abnormal. In this embodiment, it may be that there are a large number of invalid data packets or malicious packet sending behavior;

[0147] Step U3: Determine if the link bandwidth usage is abnormal:

[0148] Compare the link bandwidth usage change rate BB with the preset bandwidth usage threshold BBy:

[0149] If BB>BBy, it is determined that the link bandwidth usage is suspected to be abnormal;

[0150] Step U4: Determine if the data transmission rate is abnormal:

[0151] Compare the coefficient of variation CVR of the data transmission rate with the preset transmission rate variation threshold CVRy:

[0152] When CVR>CVRy, it is determined that the transmission rate is suspected to be abnormal; in this embodiment, it means that the data transmission rate is unstable, and there may be a network failure or abnormal interference;

[0153] Step U5: Determine if the link connection duration is abnormal:

[0154] The link connection duration change frequency FL is compared with the preset link duration change frequency threshold FLy:

[0155] If FL>FLy, it is determined that the link duration is suspected to be abnormal. In this embodiment, it indicates that the link connection state is unstable and there may be abnormal disconnection and reconnection behavior;

[0156] If at least one of the five characteristic abnormality judgments mentioned above meets the abnormal condition, it is determined that the intranet link of the corresponding edge node has suspected abnormal behavior within the specified analysis period;

[0157] This embodiment implements automated detection of abnormal intranet link behavior by deploying a data collection module at intranet edge nodes to collect basic link data in real time. This data is then normalized and extracted using cloud servers. By comparing multiple characteristic indicators against preset thresholds, potential threats can be quickly identified, significantly improving intranet security. This method utilizes standardized analysis cycles and normalization to ensure data comparability while reducing false alarm rates, making it suitable for real-time monitoring in large-scale network environments.

[0158] As the second embodiment of the present invention:

[0159] See also Figure 1 and Figure 2 As shown, in the specific implementation of this application, compared with the first embodiment, the technical solution of this embodiment is different from that of the first embodiment only in that, in this embodiment, the basic data is also compressed during the basic data transmission;

[0160] The purpose of compression is to reduce the amount of data transmitted and solve the problem of bandwidth limitation in intranet links.

[0161] Using the differential encoding compression method, take data packet traffic as an example:

[0162] For the data packet flow F(t) of the t-th standard collection period, obtain the data packet flow F(t-1) of the previous standard collection period;

[0163] By using WF=F(t)-F(t-1), the difference between the packet flow F(t) of the tth standard collection period and the packet flow F(t-1) of the t-1th standard collection period is calculated, and then WF(t) is transmitted to the cloud server;

[0164] The WF(t) value for the packet flow rate during the first standard collection period in the current specified analysis cycle is the packet flow rate during the first standard collection period in the current specified analysis cycle minus the packet flow rate during the last standard collection period in the previous specified analysis cycle.

[0165] When the cloud server receives WF(t), the data packet flow F(t-1) already received by the cloud server is added to WF(t) to obtain the data packet flow F(t) of the tth standard collection period;

[0166] The data packet traffic during the first standard collection period within the initially specified analysis cycle is directly transmitted to the cloud server;

[0167] The compression method for packet size, link bandwidth usage, data transmission rate, and link connection duration is similar to the compression method for packet traffic:

[0168] In this embodiment, the basic data transmitted to the cloud server is the difference between the basic data corresponding to the current standard collection period and the basic data corresponding to the previous standard collection period;

[0169] This embodiment introduces differential coding compression technology based on the first embodiment. By transmitting the difference between data in adjacent time periods rather than the original values, this significantly reduces data transmission and effectively alleviates pressure on intranet link bandwidth. This method is particularly suitable for high-frequency data collection scenarios, preserving data integrity while improving transmission efficiency, resolving the bottleneck issue of cloud-based analysis in bandwidth-constrained environments. It is also compatible with the anomaly detection logic of the first embodiment, achieving a balanced performance and functionality.

[0170] As the third embodiment of the present invention:

[0171] See also Figure 1 and Figure 2As shown, in the specific implementation of this application, compared with Example 1 and Example 2, the technical solution of this embodiment is to combine the solutions of Example 1 and Example 2. The difference between the technical solution of this embodiment and Example 1 and Example 2 is only that this embodiment further includes steps and cloud-edge collaborative analysis:

[0172] The collaborative analysis module conducts in-depth analysis of the intranet links corresponding to each edge node with abnormal behavior:

[0173] The in-depth analysis method is as follows:

[0174] Step Y1. Classify by source IP address and destination IP address, and group the basic data and data features from the links corresponding to the same source IP address and destination IP address.

[0175] In this embodiment, for example, if edge nodes M1 and M2 respectively collect link data from a source IP address to a destination IP address, the cloud server integrates these two sets of data together;

[0176] Step Y2: For the same set of data, calculate the average value of each basic data of the same set of edge nodes in the same standard collection period within the same specified analysis cycle;

[0177] Take the normalized packet traffic as an example;

[0178] pass: Calculate the average value F0(t) of the data packet flow of different edge nodes in the same standard collection period within the same specified analysis period;

[0179] Where v = 1, 2, ... g, g is the number of edge nodes in the same set of data;

[0180] Step Y3: According to the method in the data feature extraction step: the feature extraction module performs feature extraction processing on the average values ​​of various basic data of the same group of edge nodes within the specified analysis period, and obtains multiple collaborative data features;

[0181] Take the packet traffic characteristics as an example;

[0182] pass: Calculate the collaborative average flow rate change rate BF0 within the specified analysis period;

[0183] Step Y4: According to the abnormal behavior judgment step: the abnormal judgment module compares the collaborative data features on each edge node with the corresponding preset feature threshold to judge abnormal behavior;

[0184] Take the abnormal judgment of data packet traffic characteristics as an example;

[0185] Compare the collaborative average flow change rate BF0 with the pre-set flow change rate threshold BFy:

[0186] If BF0>BFy, the data packet flow is judged to be abnormal;

[0187] Similarly, determine whether the fluctuation in the number of data packets, link bandwidth utilization, data transmission rate, and link connection duration are indeed abnormal;

[0188] When at least one of the above five feature anomaly judgments meets the abnormal condition, it is determined that the intranet link of the corresponding edge node does have abnormal behavior within the specified analysis period.

[0189] This embodiment combines the advantages of the previous two examples and adds a cloud-edge collaborative analysis mechanism. By grouping multiple edge nodes by source / destination IP, the data is integrated, the average value within the group is calculated, and collaborative features are extracted to further eliminate single-node misjudgments. For example, if multiple nodes detect link anomalies for the same IP pair, the global threat is confirmed through collaborative verification. This solution improves detection accuracy and reduces isolated noise interference. It is particularly suitable for identifying distributed attacks, while retaining compressed transmission and basic detection capabilities to form a multi-level defense system.

[0190] As the fourth embodiment of the present invention:

[0191] See also Figure 1 and Figure 2 As shown, when the present application is implemented, compared with Example 1, Example 2 and Example 3, the technical solution of this embodiment is to combine the solutions of the above-mentioned Example 1, Example 2 and Example 3 for implementation.

[0192] This embodiment integrates all the technologies of the previous three examples to form a complete cloud-edge collaborative detection system: through a closed-loop process of edge collection, compressed transmission, and multi-node collaborative analysis in the cloud, it is efficient, accurate, and comprehensive.

[0193] Compression technology ensures real-time performance under high-load networks; collaborative analysis enhances the ability to identify complex attacks; modular design supports flexible deployment and is suitable for various intranet sizes, ultimately achieving the optimal balance between security protection and resource consumption.

[0194] An intranet link abnormal behavior detection system based on cloud-edge collaboration is used to execute an intranet link abnormal behavior detection method based on cloud-edge collaboration. The system includes:

[0195] Data collection module, used to collect basic data of the intranet link corresponding to the edge node;

[0196] Data transmission module, used to transmit basic data to the cloud server through the intranet link;

[0197] Through the preprocessing module, it is used to normalize the basic data to a value between 0 and 1;

[0198] The feature extraction module is used to extract features from the normalized basic data on each edge node and obtain multiple data features;

[0199] The anomaly judgment module is used to compare the data features on each edge node with the corresponding preset feature thresholds to preliminarily judge abnormal behavior;

[0200] The collaborative analysis module is used to conduct in-depth analysis of the intranet links corresponding to each edge node with abnormal behavior, and whether the relevant links have abnormal behavior within the specified analysis period.

[0201] It should be stated that all data collected in this application is collected with the user's consent and authorization, and the use of the data is legal and compliant, and the use and processing of the data complies with the relevant laws, regulations and standards of the relevant regions.

[0202] The above formulas are all dimensionless and numerical calculations. The formulas are obtained by collecting a large amount of data and performing software simulation to obtain the most recent real situation. The preset parameters and thresholds in the formulas are set by technicians in this field according to actual conditions.

[0203] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. The method for detecting abnormal behavior of intranet links based on cloud-edge collaboration is characterized by: The following steps are involved: Data collection: Collect basic data of the intranet link corresponding to the edge node; Data transmission: basic data is transmitted to the cloud server through the intranet link; Normalization: normalize the basic data to a value between 0 and 1; Data feature extraction: Perform feature extraction on the normalized basic data on each edge node and obtain multiple data features; Abnormal behavior judgment: Compare the data features on each edge node with the corresponding preset feature thresholds to preliminarily judge abnormal behavior; Cloud-edge collaborative analysis: Perform in-depth analysis of the intranet links corresponding to each edge node with abnormal behavior to determine whether the relevant links have abnormal behavior within the specified analysis period.

2. The method for detecting abnormal behavior of intranet links based on cloud-edge collaboration according to claim 1 is characterized in that: Basic data includes: data packet flow F, data packet size S, source IP address IP a , destination IP address b , link bandwidth occupancy rate B, data transmission rate R, and link connection time L.

3. The method for detecting abnormal behavior of intranet links based on cloud-edge collaboration according to claim 2 is characterized in that: During basic data transmission, the basic data is also compressed; The compression processing methods for packet flow, packet size, link bandwidth utilization, data transmission rate, and link connection duration are similar; Selected Packet Flow: For the data packet flow F(t) of the t-th standard collection period, obtain the data packet flow F(t-1) of the previous standard collection period; Calculate the difference WF(t) between the packet flow F(t) of the t-th standard collection period and the packet flow F(t-1) of the t-1-th standard collection period, and transmit WF(t) to the cloud server; The WF(t) value for the packet flow rate during the first standard collection period in the current specified analysis cycle is the packet flow rate during the first standard collection period in the current specified analysis cycle minus the packet flow rate during the last standard collection period in the previous specified analysis cycle. When the cloud server receives WF(t), the data packet flow F(t-1) already received by the cloud server is added to WF(t) to obtain the data packet flow F(t) of the tth standard collection period; The data packet traffic during the first standard collection period within the initially specified analysis cycle is directly transmitted to the cloud server.

4. The method for detecting abnormal behavior of intranet links based on cloud-edge collaboration according to claim 2 is characterized in that: The normalization process is as follows: the specified analysis period is divided into multiple standard collection periods, and then the packet flow F(t), packet size S(t), link bandwidth utilization B(t), data transmission rate R(t), and link connection duration L(t) are obtained for each standard collection period. Where t = 1, 2, ..., e, where e represents the number of standard acquisition periods within a specified analysis period; Among them, the normalization processing method of data packet flow, data packet size, data transmission rate, and link connection time is the same; data packet flow is selected for normalization processing; In the data packet flow F(t) of each standard collection period, extract the data packet flow F with the maximum and minimum values max and F min ; pass: Calculate the normalized data packet flow value F1(t).

5. The method for detecting abnormal behavior of intranet links based on cloud-edge collaboration according to claim 4 is characterized in that: in, The link bandwidth occupancy rate B(t) itself ranges from 0% to 100%, so the percentage is converted into a decimal and normalized to between 0 and 1.

6. The method for detecting abnormal behavior of intranet links based on cloud-edge collaboration according to claim 5 is characterized in that: The feature extraction process is as follows: Step K1, by: Calculate the average flow rate change rate BF within the specified analysis period; where t is the standard collection period after t-1; Step K2, by calculating the standard deviation of the sizes of multiple data packets S(t) within the specified analysis period, the fluctuation degree BS of the data packet size within the specified analysis period is obtained; Step K3, through: Calculate the change rate BB of the link bandwidth utilization rate within the specified analysis period; Step K4, through: Calculate the coefficient of variation (CVR) of the data transmission rate within the specified analysis period; where PR is the average data transmission rate within the specified analysis period, and BR is the standard deviation of the data transmission rate within the specified analysis period; Step K5. Count the number of times eL that the link connection duration changes within e standard collection periods. When L(t)≠L(t-1), it indicates that the link connection duration between two adjacent standard collection periods has changed. Then, by calculating the proportion of eL in e, the change frequency FL of the link connection duration within the specified analysis period is obtained.

7. The method for detecting abnormal behavior of intranet links based on cloud-edge collaboration according to claim 6 is characterized in that: Abnormal behavior is determined as follows: If the average traffic change rate BF is greater than the pre-set traffic change rate threshold BFy, it is determined that there is a suspected abnormality in the data packet traffic; If the fluctuation degree BS of the packet size is greater than the preset packet standard deviation threshold BSy, it is determined that there is a suspected abnormality in the fluctuation of the number of packet quantities; If the change rate BB of the link bandwidth occupancy is greater than the preset bandwidth occupancy threshold BBy, it is determined that there is a suspected abnormality in the link bandwidth occupancy; If the coefficient of variation CVR of the data transmission rate is greater than the preset transmission rate variation threshold CVRy, it is determined that there is a suspected abnormality in the transmission rate; If the link connection duration change frequency FL is greater than the preset link duration change frequency threshold FLy, it is determined that there is a suspected abnormality in the link duration; When at least one of the above five feature anomaly judgments meets the abnormal condition, it is determined that the intranet link of the corresponding edge node has suspected abnormal behavior within the specified analysis period.

8. The method for detecting abnormal behavior of intranet links based on cloud-edge collaboration according to claim 7 is characterized in that: The in-depth analysis method is as follows: Classify by source IP address and destination IP address, and group the basic data and data features from the links corresponding to the same source IP address and destination IP address together; For the same set of data, calculate the average value of each basic data of the same group of edge nodes in the same standard collection period within the same specified analysis cycle; Then, according to the data feature extraction step: the feature extraction module performs feature extraction processing on the average values ​​of various basic data of the same group of edge nodes within the specified analysis period, and obtains multiple collaborative data features; At the same time, according to the abnormal behavior judgment step: the abnormal judgment module compares the collaborative data features on each edge node with the corresponding preset feature thresholds to determine whether the data packet flow, data packet number fluctuation, link bandwidth occupancy, data transmission rate, and link connection duration are indeed abnormal; When at least one of the above five abnormal features meets the abnormal condition, the source IP address is determined to be a To the destination IP address b The link does have abnormal behavior during the specified analysis period.

9. A system for detecting abnormal behavior of an intranet link based on cloud-edge collaboration, the system being used to execute the method for detecting abnormal behavior of an intranet link based on cloud-edge collaboration according to any one of claims 1 to 8, characterized in that: The system includes: Data collection module, used to collect basic data of the intranet link corresponding to the edge node; Data transmission module, used to transmit basic data to the cloud server through the intranet link; Through the preprocessing module, it is used to normalize the basic data to a value between 0 and 1; The feature extraction module is used to extract features from the normalized basic data on each edge node and obtain multiple data features; The anomaly judgment module is used to compare the data features on each edge node with the corresponding preset feature thresholds to preliminarily judge abnormal behavior; The collaborative analysis module is used to conduct in-depth analysis of the intranet links corresponding to each edge node with abnormal behavior, and whether the relevant links have abnormal behavior within the specified analysis period.

10. The intranet link abnormal behavior detection system based on cloud-edge collaboration according to claim 9 is characterized in that: The preprocessing module, feature extraction module, anomaly judgment module, and collaborative analysis module are set in the cloud server.