Security isolation exchange method and system for network data exception
By collecting multi-source data to calculate risk confidence, generating streaming isolation instructions and transmitting them through RDMA channels, and combining multiple technologies for hierarchical isolation, the problem of lengthy isolation operation processing in existing technologies is solved, and accurate quantification and rapid response of network risks are achieved, thereby improving the intelligent level of network security protection.
Patent Information
- Application Number
- CN202511017758.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-23
- Publication Date
- 2025-09-16
AI Technical Summary
Existing network security isolation measures require manual configuration and have lengthy processing procedures, making it difficult to quickly respond to the rapid spread of network attacks.
By collecting network traffic, endpoint behavior, security device alarms and user behavior log data, calculating risk confidence, generating streaming isolation instructions, and transmitting them to the policy execution end via the RDMA channel, automated isolation operations are performed, and hierarchical isolation is performed by combining REST API, 802.1X protocol, SDN and eBPF technology.
It has achieved accurate quantification and rapid response to network risks, improved the intelligence level of network security protection, and reduced the risks of data leakage and system paralysis.
Smart Images

Figure CN120658507A_ABST
Abstract
Claims
1. A secure isolation exchange method for network data anomalies, characterized in that: include: Collect network traffic data, endpoint behavior log data, security device alarm data, and user behavior log data to obtain detection data; Calculate risk confidence based on detection data; Determine the isolation level code according to the risk confidence threshold division rule, and extract the target identifier from the detection data to obtain a streaming isolation instruction; the instruction includes the target identifier, the isolation level code, the risk confidence value and the timestamp; Transmitting the instruction to the policy execution end via a remote direct memory access (RDMA) channel; The policy execution end receives the instruction and performs an isolation operation according to the isolation level code in the instruction.
2. A secure isolation and exchange method for network data anomalies according to claim 1, characterized in that: The calculating of risk confidence based on the detection data includes: Preprocessing the detection data; the preprocessing includes timestamp alignment, missing value filling and normalization; The LSTM model is used to analyze the preprocessed network traffic data and output the standard deviation multiple of the current network traffic data from the normal baseline to obtain the network score NS; the normal baseline represents a statistical value obtained based on historical normal traffic data; The host behavior score HS is calculated based on the process tree in the preprocessed endpoint behavior log data using the formula: HS = ∑(PR × PPTL). PR represents the risk value of the child process, which is calculated based on the preset value of the child process's category. PPTL represents the trust level of the parent process, which is calculated based on the preset value of the parent process's category. The user entity behavior analysis method UEBA is used to process the pre-processed user behavior logs to obtain the user behavior score US; The threat intelligence score TS is calculated based on the pre-processed security device alarm data using the formula: TS = ∑(threat signature matching number) / total signature number. The threat signature matching number represents the number of matches between the security device alarm data and known malicious signatures in the threat intelligence library. The total signature number represents the total number of pre-defined malicious signatures used for risk assessment in the threat intelligence library. The threat intelligence library is used for; The weighted summation formula is used to calculate the sum of the network score NS, host behavior score HS, user behavior score US, and threat intelligence score to obtain the risk confidence level.
3. A secure isolation and exchange method for network data anomalies according to claim 1, characterized in that: The streaming isolation instruction includes: A1. Determine the isolation level code based on the risk confidence threshold classification rule: When T1≤risk confidence<T2, a first-level isolation code is generated; When T2≤risk confidence<T3, a secondary isolation code is generated; When the risk confidence level is greater than T3, a level 3 isolation code is generated; A2, obtains the target identification by extracting the IP address or MAC address from the network traffic data and the process ID or container ID from the endpoint behavior log data; A3, encapsulates the target identification, isolation level code, risk confidence and timestamp into a streaming isolation instruction.
4. A secure isolation and exchange method for network data anomalies according to claim 1, characterized in that: The performing of the isolation operation according to the isolation level code in the instruction includes: When the isolation level code is level 1, configure the boundary firewall rules through the Representational State Transfer Application Programming Interface (REST) API to block the target IP's access to the preset high-risk ports; When the isolation level code is a level 2 isolation code, restricting outbound traffic of a target device based on the 802.1X protocol using a network access control device, the target device being a device determined according to the target identifier; When the isolation level code is a level three isolation code, a micro-isolation mechanism is executed; the micro-isolation mechanism represents an isolation measure implemented on the target device based on software-defined networking SDN and extended Berkeley packet filter eBPF technology.
5. A secure isolation and exchange method for network data anomalies according to claim 4, characterized in that: The micro-isolation mechanism includes: Modify the flow table through the SDN controller and move the target device into the isolated virtual local area network VLAN; Determine the target host by using the IP or MAC address in the target identifier and the mapping relationship in the configuration management database; Injecting kernel-level firewall rules into the eBPF program deployed on the target host; the kernel-level firewall rules represent network traffic control policies implemented at the kernel level based on eBPF technology; Establish an encrypted data transmission path as a secure exchange channel; Utilize secure exchange channels for data transmission to the target host.
6. A secure isolation and exchange method for network data anomalies according to claim 5, characterized in that: The kernel-level firewall rules include: Mount the compiled eBPF bytecode of the eBPF program to the key network hook points of the kernel system; the key network hook points represent the execution locations in the kernel network protocol stack for intercepting and processing network data packets, including the fast data path XDP hook, the traffic control system TCS hook, the Netfilter hook, and the socket layer hook; The data packet of the target host is matched and checked. When the destination port or protocol type of the data packet is in the preset port whitelist and protocol type, the data packet is retained; otherwise, the data packet is discarded to block the illegal network connection.
7. A secure isolation and exchange method for network data anomalies according to claim 5, characterized in that: The secure exchange channel includes data encryption, data detection and data filtering; wherein, The data encryption includes generating a session key using a key encryption algorithm; The key distribution center securely distributes and manages session keys, establishing an encrypted communication link between the target host and the secure exchange channel; Encrypting transmitted application layer data using a data encryption algorithm; the application layer data represents the payload data generated by the application of the target host, including the request body and response body in the HTTP protocol, the file content transmitted by the FTP protocol, the email data transmitted by the SMTP protocol, and the query statement and return result set of the SQL protocol; The data detection includes using a pre-trained BERT model to classify the transmitted plaintext data and extract predefined sensitive fields; The sensitive fields are encrypted using the format-preserving encryption algorithm FPE to obtain encrypted sensitive fields; Calculate the sliding window entropy value of the plaintext data after extracting the predefined sensitive fields; When the sliding window entropy value is greater than a preset threshold, the sandbox dynamic analysis is triggered; The data filtering includes filtering the transmitted application layer protocol traffic according to a predefined whitelist protocol; the application layer protocol traffic represents the data flow generated by the application layer protocol during the data transmission process, and the application layer protocol includes HTTP protocol, DNS protocol and SQL protocol.
8. A secure isolation and exchange method for network data anomalies according to claim 7, characterized in that: The calculation formula of the sliding window threshold is: ; Among them, p i Indicates the probability of a byte value occurring within a preset sliding window.
9. A secure isolation and exchange method for network data anomalies according to claim 1, characterized in that: The network traffic data represents real-time information and statistical characteristics of data transmission in the network; The endpoint behavior log data represents the record information of various operation behaviors on the terminal device; The security device alarm data represents threat information detected by the security protection device; The user behavior log data represents the record information of the user's operating activities in the system.
10. A secure isolation and exchange system for network data anomalies, characterized in that: include: Data acquisition module, risk assessment module and instruction execution module; among them, The data collection module is used to collect network traffic data, endpoint behavior log data, security device alarm data and user behavior log data to obtain detection data; The risk assessment module is used to calculate the risk confidence based on the detection data, determine the isolation level code according to the threshold division rule of the risk confidence, and extract the target identifier from the detection data to generate a streaming isolation instruction including the target identifier, the isolation level code, the risk confidence value and the timestamp; The instruction execution module is used to receive the instruction through a remote direct memory access (RDMA) channel and perform an isolation operation according to the isolation level code in the instruction.
Citation Information
Cited By
Network device security service enhancement method, system, device and program product
CN120915599A
A network device security service enhancement method, system, device and program product
CN120915599B
Real-time data exchange anomaly detection method and device based on deep learning
CN120956531A
Security control method for network security equipment interconnection and context driving
CN121125315A