Abnormal proxy access data determination method and device, equipment and medium
By performing multi-dimensional feature extraction on access data and weighted voting on the abnormal proxy identification model, the problem of inaccurate abnormal proxy access identification in the existing technology is solved, accurate and reliable abnormal proxy access behavior identification is achieved, and the effectiveness of network security defense is improved.
Patent Information
- Application Number
- CN202411937459.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-26
- Publication Date
- 2025-09-19
AI Technical Summary
Existing technologies have difficulty in accurately identifying and distinguishing normal and abnormal proxy access behaviors, especially when faced with diverse proxy types and characteristics, which increases the difficulty of network security defense.
By extracting multi-dimensional features from access data, including network packet message information, network behavior patterns, port opening information, and network protocol address dimension information, we identify abnormal data, generate multiple abnormal data, and input them into a pre-trained abnormal agent identification model. We perform weighted voting to generate a target abnormality score value and determine the abnormal agent access data.
It achieves accurate and reliable identification of abnormal proxy access behavior, improves data security and user experience, and enhances the accuracy of network security defense.
Smart Images

Figure CN120675730A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of artificial intelligence technology, specifically to the field of big data technology and information security technology, and in particular to a method, apparatus, device, medium and program product for determining abnormal proxy access data. Background Art
[0002] With the advancement of computer network technology, the demand for network security defense is increasing in enterprises, including banks. Attackers using proxies to conduct unusual access or logins is a common network security threat. In today's network environment, attackers may exploit proxy servers to hide their true IP addresses, evading detection and blocking, thereby carrying out various network attacks, data theft, or illegal access. This makes network intrusions more difficult to detect and increases the difficulty for security professionals to track and respond to. Therefore, timely and accurate identification of unusual proxy access behavior has become a critical task in network security defense. As network attack methods continue to evolve, attackers are increasingly using proxies for unusual access, creating a multi-layered and multi-faceted proxy threat. The diverse nature of proxies, including anonymous and highly anonymous proxies, creates a more complex and dynamic threat landscape for network security.
[0003] Existing technology solutions face the challenge of attackers using proxies for abnormal access. Traditional single-source detection methods may only identify proxies based on IP addresses or communication patterns. Using single-learning machine methods such as support vector machines for simple identification, these methods struggle to accurately grasp the different types and characteristics of proxies, and to accurately distinguish between normal and abnormal proxy access behaviors. Therefore, a method integrating multi-dimensional features and collaborative detection, combined with a strong learning machine learning algorithm, is needed to improve the accuracy of identifying abnormal proxy access behaviors. Summary of the Invention
[0004] In view of the above problems, the present disclosure provides a method, apparatus, device, medium and program product for determining abnormal agent access data.
[0005] According to a first aspect of the present disclosure, a method for determining abnormal proxy access data is provided, the method comprising: acquiring multiple access data, classifying each access data, and generating network data packet message information data, network behavior pattern data, port opening information data, and network protocol address dimension information data in each access data; performing abnormal data identification on the network data packet message information data in each access data to generate multiple first abnormal data in each access data; performing abnormal data identification on the network behavior pattern data in each access data to generate multiple second abnormal data in each access data; performing abnormal data identification on the port opening information data in each access data to generate multiple third abnormal data in each access data; performing abnormal data identification on the network protocol address dimension information data in each access data to generate multiple fourth abnormal data in each access data; inputting the multiple first abnormal data, multiple second abnormal data, multiple third abnormal data, and multiple fourth abnormal data in each access data into a pre-trained abnormal proxy identification model to generate a target abnormality score value for each access data; and acquiring access data having a target abnormality score value greater than a first preset threshold value from the multiple access data, and determining the access data as abnormal proxy access data.
[0006] According to an embodiment of the present disclosure, abnormal data identification is performed on the network data packet message information data in each access data to generate multiple first abnormal data in each access data, including: obtaining port information in the network data packet message information data in each access data, detecting whether abnormal port data exists in the port information, and if abnormal port data exists, obtaining the abnormal port data; obtaining a network protocol address in the network data packet message information data in each access data, detecting whether an abnormal network protocol address exists in the network protocol address, and if an abnormal network protocol address exists, obtaining the abnormal network protocol address; obtaining a protocol type in the network data packet message information data in each access data, detecting whether an abnormal protocol type exists in the protocol type, and if an abnormal protocol type exists, obtaining the abnormal protocol type; obtaining header information in the network data packet message information data in each access data, detecting whether an abnormal field exists in the header information, and if an abnormal field exists, obtaining the abnormal field; and integrating the abnormal port data, the abnormal network protocol address, the protocol type, and the abnormal field in the network data packet message information data in each access data to generate multiple first abnormal data in each access data.
[0007] According to an embodiment of the present disclosure, abnormal data identification is performed on the network behavior pattern data in each access data to generate multiple second abnormal data in each access data, including: obtaining the access frequency in the network behavior pattern data in each access data, obtaining an access frequency greater than a second preset threshold, and determining it as an abnormal access frequency; obtaining the port change frequency in the network behavior pattern data in each access data, obtaining a port change frequency greater than a third preset threshold, and determining it as an abnormal port change frequency; detecting whether there is early warning information in the network behavior pattern data in each access data, and if the early warning information exists, obtaining the early warning information; and integrating the abnormal access frequency, abnormal port change frequency and early warning information in the network behavior pattern data in each access data to generate multiple second abnormal data in each access data.
[0008] According to an embodiment of the present disclosure, abnormal data identification is performed on the port opening information data in each access data to generate multiple third abnormal data in each access data, including: obtaining the number of open ports in the port opening information data in each access data, obtaining a number of open ports greater than a fourth preset threshold, and determining it as an abnormal number of open ports; detecting whether there is non-standard port data in the port opening information data in each access data, and if the non-standard port data exists, obtaining the non-standard port data; and integrating the abnormal number of open ports and the non-standard port data in the port opening information data in each access data to generate multiple third abnormal data in each access data.
[0009] According to an embodiment of the present disclosure, abnormal data identification is performed on the network protocol address dimension information data in each access data to generate multiple fourth abnormal data in each access data, including: obtaining the network protocol geographic location data in the network protocol address dimension information data in each access data, detecting whether there is abnormal network protocol geographic location data in the network protocol geographic location data, and if there is abnormal network protocol geographic location data, obtaining the abnormal network protocol geographic location data; obtaining the network protocol reputation value in the network protocol address dimension information data in each access data, obtaining a network protocol reputation value less than a fifth preset threshold, and determining it as an abnormal network protocol reputation value; and integrating the abnormal network protocol geographic location data and the abnormal network protocol reputation value in the network protocol address dimension information data in each access data to generate multiple fourth abnormal data in each access data.
[0010] According to an embodiment of the present disclosure, the abnormal agent identification model includes: a first abnormal agent identification sub-model, a second abnormal agent identification sub-model, a third abnormal agent identification sub-model and a fourth abnormal agent identification sub-model, and inputs the multiple first abnormal data, multiple second abnormal data, multiple third abnormal data and multiple fourth abnormal data in each access data into the pre-trained abnormal agent identification model to generate a target abnormality score value for each access data, including: inputting the multiple first abnormal data in each access data into the pre-trained first abnormal agent identification sub-model, and outputting the first abnormality score value for each access data, wherein the first abnormal agent identification sub-model is generated based on the multiple first abnormal data in each historical access data in a plurality of historical access data; inputting the multiple second abnormal data in each access data into the pre-trained second abnormal agent identification sub-model, and outputting the second abnormality score value for each access data, wherein the second abnormal agent identification sub-model is generated based on the multiple first abnormal data in each historical access data in a plurality of historical access data; The method comprises the following steps: training and generating a plurality of second abnormal data in each historical access data in the access data; inputting a plurality of third abnormal data in each access data into a pre-trained third abnormal agent identification sub-model, and outputting a third abnormality score value for each access data, wherein the third abnormal agent identification sub-model is generated based on the training of the plurality of third abnormal data in each historical access data in the plurality of historical access data; inputting a plurality of fourth abnormal data in each access data into a pre-trained fourth abnormal agent identification sub-model, and outputting a fourth abnormality score value for each access data, wherein the fourth abnormal agent identification sub-model is generated based on the training of the plurality of fourth abnormal data in each historical access data in the plurality of historical access data; and generating a target abnormality score value for each access data by performing weighted voting on the first abnormality score value of each access data, the second abnormality score value of each access data, the third abnormality score value of each access data, and the fourth abnormality score value of each access data.
[0011] According to an embodiment of the present disclosure, before inputting the multiple first abnormal data, multiple second abnormal data, multiple third abnormal data and multiple fourth abnormal data in each access data into a pre-trained abnormal agent recognition model, it also includes: performing data cleaning, data deduplication, data labeling and data formatting processing on the multiple first abnormal data, multiple second abnormal data, multiple third abnormal data and multiple fourth abnormal data in each access data.
[0012] According to a second aspect of the present disclosure, a device for determining abnormal proxy access data is provided, which includes: a first generation module for acquiring multiple access data, classifying each access data, and generating network data packet message information data, network behavior pattern data, port opening information data, and network protocol address dimension information data in each access data; a second generation module for performing abnormal data identification on the network data packet message information data in each access data, and generating multiple first abnormal data in each access data; a third generation module for performing abnormal data identification on the network behavior pattern data in each access data, and generating multiple second abnormal data in each access data; a fourth generation module for performing abnormal data identification on the network behavior pattern data in each access data, and generating multiple second abnormal data in each access data; a fifth generation module for performing abnormal data identification on the port opening information data in each access data to generate a plurality of third abnormal data in each access data; a fifth generation module for performing abnormal data identification on the network protocol address dimension information data in each access data to generate a plurality of fourth abnormal data in each access data; a sixth generation module for inputting the plurality of first abnormal data, the plurality of second abnormal data, the plurality of third abnormal data and the plurality of fourth abnormal data in each access data into a pre-trained abnormal proxy identification model to generate a target abnormality score value for each access data; and a determination module for obtaining access data whose target abnormality score value in the plurality of access data is greater than a first preset threshold value, and determining it as abnormal proxy access data.
[0013] According to an embodiment of the present disclosure, the second generation module includes: a first acquisition module, configured to acquire port information from the network data packet message information data in each access data, detect whether there is abnormal port data in the port information, and if so, acquire the abnormal port data; a second acquisition module, configured to acquire a network protocol address from the network data packet message information data in each access data, detect whether there is an abnormal network protocol address in the network protocol address, and if so, acquire the abnormal network protocol address; a third acquisition module, configured to acquire a protocol type from the network data packet message information data in each access data, detect whether there is an abnormal protocol type in the protocol type, and if so, acquire the abnormal protocol type; a fourth acquisition module, configured to acquire header information from the network data packet message information data in each access data, detect whether there is an abnormal field in the header information, and if so, acquire the abnormal field; and a seventh generation module, configured to integrate the abnormal port data, the abnormal network protocol address, the protocol type, and the abnormal field in the network data packet message information data in each access data to generate multiple first abnormal data in each access data.
[0014] According to an embodiment of the present disclosure, the third generation module includes: a fifth acquisition module, used to obtain the access frequency in the network behavior pattern data in each access data, obtain the access frequency greater than the second preset threshold, and determine it as an abnormal access frequency; a sixth acquisition module, used to obtain the port change frequency in the network behavior pattern data in each access data, obtain the port change frequency greater than the third preset threshold, and determine it as an abnormal port change frequency; a seventh acquisition module, used to detect whether there is warning information in the network behavior pattern data in each access data, and if the warning information exists, obtain the warning information; and an eighth generation module, used to integrate the abnormal access frequency, abnormal port change frequency and warning information in the network behavior pattern data in each access data to generate multiple second abnormal data in each access data.
[0015] According to an embodiment of the present disclosure, the fourth generation module includes: an eighth acquisition module, which is used to obtain the number of open ports in the port open information data in each access data, obtain the number of open ports greater than the fourth preset threshold, and determine it as the abnormal number of open ports; a ninth acquisition module, which is used to detect whether there is non-standard port data in the port open information data in each access data, and if the non-standard port data exists, obtain the non-standard port data; and a ninth generation module, which is used to integrate the abnormal number of open ports and the non-standard port data in the port open information data in each access data to generate multiple third abnormal data in each access data.
[0016] According to an embodiment of the present disclosure, the fifth generation module includes: a tenth acquisition module, which is used to obtain the network protocol geographic location data in the network protocol address dimension information data in each access data, detect whether there is abnormal network protocol geographic location data in the network protocol geographic location data, and if there is abnormal network protocol geographic location data, obtain the abnormal network protocol geographic location data; an eleventh acquisition module, which is used to obtain the network protocol reputation value in the network protocol address dimension information data in each access data, obtain a network protocol reputation value less than the fifth preset threshold, and determine it as an abnormal network protocol reputation value; and a tenth generation module, which is used to integrate the abnormal network protocol geographic location data and the abnormal network protocol reputation value in the network protocol address dimension information data in each access data to generate multiple fourth abnormal data in each access data.
[0017] According to an embodiment of the present disclosure, the abnormal agent identification model includes: a first abnormal agent identification sub-model, a second abnormal agent identification sub-model, a third abnormal agent identification sub-model and a fourth abnormal agent identification sub-model, and the sixth generation module includes: an eleventh generation module for inputting the multiple first abnormal data in each access data into the pre-trained first abnormal agent identification sub-model, and outputting a first abnormality score value for each access data, wherein the first abnormal agent identification sub-model is generated based on the training of the multiple first abnormal data in each of the multiple historical access data; a twelfth generation module for inputting the multiple second abnormal data in each of the access data into the pre-trained second abnormal agent identification sub-model, and outputting a second abnormality score value for each access data, wherein the second abnormal agent identification sub-model is generated based on the training of the multiple second abnormal data in each of the multiple historical access data; a thirteenth generation module for inputting the multiple second abnormal data in each of the access data into the pre-trained second abnormal agent identification sub-model, and outputting a second abnormality score value for each access data The multiple third abnormal data in each access data are input into a pre-trained third abnormal agent identification sub-model, and a third abnormality score value for each access data is output, wherein the third abnormal agent identification sub-model is generated by training based on the multiple third abnormal data in each historical access data; a fourteenth generation module is used to input the multiple fourth abnormal data in each access data into a pre-trained fourth abnormal agent identification sub-model, and output a fourth abnormality score value for each access data, wherein the fourth abnormal agent identification sub-model is generated by training based on the multiple fourth abnormal data in each historical access data; and a fifteenth generation module is used to generate a target abnormality score value for each access data by performing weighted voting on the first abnormality score value of each access data, the second abnormality score value of each access data, the third abnormality score value of each access data, and the fourth abnormality score value of each access data.
[0018] According to a third aspect of the present disclosure, an electronic device is provided, comprising: one or more processors; a storage device for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors execute the above-mentioned abnormal proxy access data determination method.
[0019] According to a fourth aspect of the present disclosure, a computer-readable storage medium is provided, on which executable instructions or computer programs are stored. When the instructions or computer programs are executed by a processor, the processor executes the above-mentioned abnormal proxy access data determination method.
[0020] According to a fifth aspect of the present disclosure, a computer program product is also provided, including a computer program, which implements the above-mentioned abnormal proxy access data determination method when executed by a processor.
[0021] This solution classifies access data and extracts features to generate network packet message data, port opening information data, network behavior data features and location dimension data, and then uses these classified data through the abnormal proxy identification model to determine and identify abnormal proxy access data, solving the technical problem of inaccurate identification of abnormal proxy access, and achieving accurate and reliable determination of abnormal proxy access behavior, which is convenient for effectively improving data security and enhancing user experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The above contents and other objects, features and advantages of the present disclosure will become more apparent through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, in which:
[0023] Figure 1 The following schematically illustrates an application scenario diagram of the method and device for determining abnormal proxy access data according to an embodiment of the present disclosure;
[0024] Figure 2 Schematically shows a flow chart of a method for determining abnormal proxy access data according to an embodiment of the present disclosure;
[0025] Figure 3 Schematically shows a flow chart of generating a plurality of first abnormal data in each access data in the abnormal proxy access data determination method according to an embodiment of the present disclosure;
[0026] Figure 4 Schematically shows a flow chart of generating a plurality of second abnormal data in each access data in the abnormal proxy access data determination method according to an embodiment of the present disclosure;
[0027] Figure 5 A flowchart of generating a plurality of third abnormal data in each access data in the abnormal proxy access data determination method according to an embodiment of the present disclosure is schematically shown;
[0028] Figure 6 Schematically shows a flow chart of generating a plurality of fourth abnormal data in each access data in the abnormal proxy access data determination method according to an embodiment of the present disclosure;
[0029] Figure 7 Schematically shows a flow chart of generating a target abnormality score value for each access data in the abnormal proxy access data determination method according to an embodiment of the present disclosure;
[0030] Figure 8 Schematically shows a schematic diagram of a system for determining abnormal proxy access data according to an embodiment of the present disclosure;
[0031] Figure 9Schematically shows a structural block diagram of an apparatus for determining abnormal proxy access data according to an embodiment of the present disclosure; and
[0032] Figure 10 A block diagram of an electronic device suitable for implementing a method for determining abnormal proxy access data according to an embodiment of the present disclosure is schematically shown. DETAILED DESCRIPTION
[0033] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the detailed description below, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of the embodiments of the present disclosure. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessary confusion of the concepts of the present disclosure.
[0034] The terms used herein are only for describing specific embodiments and are not intended to limit the present disclosure. The terms "comprise," "include," etc. used herein indicate the presence of the features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0035] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0036] When expressions such as "at least one of A, B, and C, etc." are used, they should generally be interpreted in accordance with the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).
[0037] The accompanying drawings illustrate some block diagrams and / or flow charts. It should be understood that some blocks in the block diagrams and / or flow charts, or combinations thereof, may be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable control device, so that when executed by the processor, these instructions may create a device for implementing the functions / operations described in the block diagrams and / or flow charts.
[0038] First, let’s explain the technical terms that appear in this article as follows:
[0039] Metadata: It is data that describes data and is a type of structured data about information resources.
[0040] Abnormal proxy: usually used to hide the real IP address to conduct illegal activities such as network fraud, DDos attacks, abnormal crawlers, etc.
[0041] Switch mirroring port: is a network monitoring technology that allows network traffic from one or more switch ports to be copied and redirected to another port for traffic monitoring, analysis, and logging.
[0042] AdaBoost algorithm: It is an iterative algorithm that trains different classifiers (weak classifiers) on the same training set, combines these weak classifiers, and generates the final classifier (strong classifier).
[0043] Weighted voting: The prediction results of each sub-model are weighted and summed according to the determined weights to obtain the final prediction result.
[0044] Embodiments of the present disclosure provide a method for determining abnormal proxy access data. The method includes: obtaining multiple access data, classifying each access data, and generating network data packet information data, network behavior pattern data, port open information data, and network protocol address dimension information data for each access data. Performing abnormal data identification on the network data packet information data in each access data to generate multiple first abnormal data for each access data. Performing abnormal data identification on the network behavior pattern data in each access data to generate multiple second abnormal data for each access data. Performing abnormal data identification on the port open information data in each access data to generate multiple third abnormal data for each access data. Performing abnormal data identification on the network protocol address dimension information data in each access data to generate multiple fourth abnormal data for each access data. Inputting the multiple first abnormal data, multiple second abnormal data, multiple third abnormal data, and multiple fourth abnormal data in each access data into a pre-trained abnormal proxy identification model to generate a target abnormality score for each access data. Finally, obtaining access data from the multiple access data whose target abnormality score is greater than a first preset threshold value and determining it as abnormal proxy access data.
[0045] According to the embodiment of the present disclosure, by classifying access data and extracting features, network data packet message data, port opening information data, network behavior data features and location dimension data are generated, and then these classified data are used to determine and identify abnormal proxy access data through an abnormal proxy identification model, thereby solving the technical problem of inaccurate identification of abnormal proxy access, achieving accurate and reliable determination of abnormal proxy access behavior, and facilitating the technical effect of effectively improving data security and enhancing user experience.
[0046] Figure 1 The following schematically illustrates an application scenario diagram of the method and device for determining abnormal proxy access data according to an embodiment of the present disclosure. Figure 1 The examples shown are merely examples of scenarios in which the embodiments of the present disclosure can be applied, to help those skilled in the art understand the technical content of the present disclosure, but do not mean that the embodiments of the present disclosure cannot be used in other devices, systems, environments or scenarios.
[0047] like Figure 1 As shown, the application scenario 100 according to this embodiment may include an application scenario for determining abnormal proxy access data. A network 104 is used as a medium for providing a communication link between a first terminal device 101, a second terminal device 102, a third terminal device 103, and a server 105. The network 104 may include various connection types, such as wired or wireless communication links or fiber optic cables.
[0048] A user may use a first terminal device 101, a second terminal device 102, or a third terminal device 103 to interact with a server 105 via a network 104 to receive or send messages, etc. Various communication client applications may be installed on the first terminal device 101, the second terminal device 102, or the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (for example only).
[0049] The first terminal device 101 , the second terminal device 102 , and the third terminal device 103 may be various electronic devices having display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, and the like.
[0050] The server 105 may be a server that provides various services, such as a background management server (for example only) that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103. The background management server may analyze and process received data such as user requests, and feed back processing results (e.g., web pages, information, or data obtained or generated based on user requests) to the terminal devices.
[0051] It should be noted that the abnormal proxy access data determination method provided by the embodiment of the present disclosure can generally be executed by the server 105. Accordingly, the abnormal proxy access data determination device provided by the embodiment of the present disclosure can generally be set in the server 105. The abnormal proxy access data determination method provided by the embodiment of the present disclosure can also be executed by a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105. Accordingly, the abnormal proxy access data determination device provided by the embodiment of the present disclosure can also be set in a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105.
[0052] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.
[0053] The following will be based on Figure 1 The scene described by Figures 2 to 8 The method for determining abnormal proxy access data in the disclosed embodiment is described in detail. It should be noted that the above application scenarios are merely provided to facilitate understanding of the spirit and principles of the present disclosure, and the embodiments of the present disclosure are not limited in this respect. On the contrary, the embodiments of the present disclosure can be applied to any applicable scenario.
[0054] Figure 2 The flowchart of the method for determining abnormal proxy access data according to an embodiment of the present disclosure is schematically shown.
[0055] like Figure 2 As shown, the method 200 includes steps S201 to S207.
[0056] Step S201 , obtaining multiple access data, classifying each access data, and generating network data packet message information data, network behavior pattern data, port opening information data, and network protocol address dimension information data in each access data.
[0057] For example, multiple access data can be collected through a switch mirror port, and semantic analysis can be performed on the multiple access data to classify the multiple access data. Network packet information data, network behavior pattern data, port open information data, and network protocol address dimension information data for each access data can be generated. Alternatively, associated metadata for the multiple access data can be obtained, and the associated metadata can be analyzed to classify the multiple access data. Network packet information data, network behavior pattern data, port open information data, and network protocol address dimension information data for each access data can be generated.
[0058] Step S202 : performing abnormal data identification on the network data packet message information data in each access data, and generating a plurality of first abnormal data in each access data.
[0059] For example, network data packets contain rich request source and behavior information, which is crucial for determining whether access is normal or abnormal. By deeply analyzing this information, we can assist in identifying abnormal proxy access behavior, select feature data, and generate the first abnormal data.
[0060] Figure 3 The flowchart of generating a plurality of first abnormal data in each access data in the abnormal proxy access data determination method according to an embodiment of the present disclosure is schematically shown.
[0061] like Figure 3 As shown, the method 300 includes steps S301 to S305.
[0062] Step S301: obtaining port information in the network data packet message information data in each access data, detecting whether there is abnormal port data in the port information, and if there is abnormal port data, obtaining the abnormal port data.
[0063] For example, the port information in the network data packet message information data may include source port information and destination port information. The source port information and the destination port information may be checked to see whether there is abnormal source port information and abnormal destination port information in the source port information and the destination port information. If so, the abnormal source port information and abnormal destination port information are obtained.
[0064] Step S302: obtaining the network protocol address in the network data packet message information data in each access data, detecting whether there is an abnormal network protocol address in the network protocol address, and if there is an abnormal network protocol address, obtaining the abnormal network protocol address.
[0065] For example, the network protocol addresses in the network data packet message information data may include: a source network protocol address and a destination network protocol address. The source network protocol address and the destination network protocol address may be detected to detect whether there are abnormal source network protocol addresses and abnormal destination network protocol addresses in the source network protocol addresses and the destination network protocol addresses. If there are abnormal source network protocol addresses and abnormal destination network protocol addresses, these abnormal source network protocol addresses and abnormal destination network protocol addresses are obtained.
[0066] Step S303: Acquire the protocol type in the network data packet message information data in each access data, detect whether there is an abnormal protocol type in the protocol type, and if there is an abnormal protocol type, acquire the abnormal protocol type.
[0067] Step S304: obtaining header information in the network data packet message information data in each access data, detecting whether there is an abnormal field in the header information, and if there is an abnormal field, obtaining the abnormal field.
[0068] For example, the header information in the network data packet message data may contain proxy chain characteristics. Check whether there are abnormal fields such as HTTP_VIA field, x-forwarded-for field, remote_addr field in the header information. If so, obtain these abnormal fields.
[0069] Step S305 : Integrate the abnormal port data, the abnormal network protocol address, the protocol type, and the abnormal field in the network data packet message information data in each access data to generate a plurality of first abnormal data in each access data.
[0070] By detecting port information, network protocol address, abnormal protocol type and abnormal field, the first abnormal data is determined, which can improve the accuracy and reliability of the first abnormal data and facilitate improving the accuracy of predicted data by improving the quality of model input data.
[0071] In addition, network data packet message information data can also include: timestamp, request method and request path and other data, which can detect whether there are abnormal timestamps, abnormal request methods and abnormal request paths, and combine the above-mentioned abnormal port data, abnormal network protocol address, protocol type and abnormal field to generate abnormal data, further improve the quality of model input data and improve the reliability of prediction data.
[0072] Return to reference Figure 2 In step S203, abnormal data identification is performed on the network behavior pattern data in each access data to generate multiple second abnormal data in each access data.
[0073] For example, abnormal agents usually have network behavior patterns that are different from normal users or normal agents. If an operation is requested with an abnormal behavior frequency or pattern, it is possible to detect whether the same IP sends a large number of requests in a short period of time, select these feature data, and generate second abnormal data.
[0074] Figure 4 The flowchart of generating a plurality of second abnormal data in each access data in the abnormal proxy access data determination method according to an embodiment of the present disclosure is schematically shown.
[0075] like Figure 4 As shown, the method 400 includes steps S401 to S404.
[0076] Step S401: obtaining access frequencies in the network behavior pattern data in each access data, obtaining access frequencies greater than a second preset threshold, and determining them as abnormal access frequencies.
[0077] For example, the access frequency may be the number of times the same IP sends requests within a period.
[0078] Step S402: obtaining a port change frequency in the network behavior pattern data in each access data, obtaining a port change frequency greater than a third preset threshold, and determining it as an abnormal port change frequency.
[0079] For example, the port change frequency may be the number of times the used port is changed and each port is accessed within the same IP cycle.
[0080] Step S403: Detect whether there is warning information in the network behavior pattern data in each access data, and if the warning information exists, obtain the warning information.
[0081] For example, the early warning information may include protective equipment alarm-related information.
[0082] Step S404 : Integrate the abnormal access frequency, abnormal port change frequency, and warning information in the network behavior pattern data in each access data to generate a plurality of second abnormal data in each access data.
[0083] By obtaining abnormal access frequency, abnormal port change frequency and warning information, the second abnormal data is determined, which can improve the accuracy and reliability of the second abnormal data, and facilitate improving the accuracy of the predicted data by improving the quality of model input data.
[0084] Return to reference Figure 2 In step S204, abnormal data identification is performed on the port opening information data in each access data to generate multiple third abnormal data in each access data.
[0085] For example, by analyzing port opening information, we can determine whether there are signs of abnormal proxy, such as whether non-standard ports or high-risk ports are used or whether a large number of ports are open.
[0086] Figure 5 The flowchart of generating a plurality of third abnormal data in each access data in the abnormal proxy access data determination method according to an embodiment of the present disclosure is schematically shown.
[0087] like Figure 5 As shown, the method 500 includes steps S501 to S503.
[0088] Step S501: Obtain the number of open ports in the open port information data in each access data, obtain the number of open ports that is greater than a fourth preset threshold, and determine it as an abnormal number of open ports.
[0089] Step S502: Detect whether non-standard port data exists in the port opening information data in each access data; if so, obtain the non-standard port data.
[0090] Step S503 : Integrate the abnormal port opening quantity and non-standard port data in the port opening information data in each access data to generate a plurality of third abnormal data in each access data.
[0091] By obtaining the number of abnormal port openings and non-standard port data and determining the third abnormal data, the accuracy and reliability of the third abnormal data can be improved, which makes it easier to improve the accuracy of the predicted data by improving the quality of the model input data.
[0092] Return to reference Figure 2 In step S205, abnormal data identification is performed on the network protocol address dimension information data in each access data to generate multiple fourth abnormal data in each access data.
[0093] Figure 6 The flowchart of generating a plurality of fourth abnormal data in each access data in the abnormal proxy access data determination method according to an embodiment of the present disclosure is schematically shown.
[0094] like Figure 6 As shown, the method 600 includes steps S601 to S603.
[0095] Step S601, obtain the network protocol geographic location data in the network protocol address dimension information data in each access data, detect whether there is abnormal network protocol geographic location data in the network protocol geographic location data, and if abnormal network protocol geographic location data exists, obtain the abnormal network protocol geographic location data.
[0096] Step S602: Obtain the network protocol reputation value in the network protocol address dimension information data in each access data, obtain the network protocol reputation value that is less than the fifth preset threshold, and determine it as an abnormal network protocol reputation value.
[0097] Step S603: Integrate the abnormal network protocol geographic location data and the abnormal network protocol reputation value in the network protocol address dimension information data in each access data to generate a plurality of fourth abnormal data in each access data.
[0098] By obtaining the abnormal network protocol geographic location data and the abnormal network protocol reputation value and determining the fourth abnormal data, the accuracy and reliability of the fourth abnormal data can be improved, which facilitates improving the accuracy of the predicted data by improving the quality of the model input data.
[0099] Return to reference Figure 2 In step S206, the multiple first abnormal data, multiple second abnormal data, multiple third abnormal data and multiple fourth abnormal data in each access data are input into the pre-trained abnormal agent recognition model to generate a target abnormality score value for each access data.
[0100] The abnormal agent identification model includes: a first abnormal agent identification sub-model, a second abnormal agent identification sub-model, a third abnormal agent identification sub-model and a fourth abnormal agent identification sub-model.
[0101] Figure 7 The flowchart of generating a target abnormality score value for each access data in the abnormal agent access data determination method according to an embodiment of the present disclosure is schematically shown.
[0102] like Figure 7 As shown, the method 700 includes steps S701 to S705.
[0103] Step S701: Input the multiple first abnormal data in each access data into a pre-trained first abnormal agent identification sub-model, and output a first abnormality score value for each access data, wherein the first abnormal agent identification sub-model is trained and generated based on the multiple first abnormal data in each historical access data in multiple historical access data.
[0104] Step S702: Input the multiple second abnormal data in each access data into a pre-trained second abnormal agent identification sub-model, and output a second abnormality score value for each access data, wherein the second abnormal agent identification sub-model is trained and generated based on the multiple second abnormal data in each historical access data in a plurality of historical access data.
[0105] Step S703: Input the multiple third abnormal data in each access data into a pre-trained third abnormal agent identification sub-model, and output a third abnormality score value for each access data, wherein the third abnormal agent identification sub-model is trained and generated based on the multiple third abnormal data in each historical access data in the multiple historical access data.
[0106] Step S704: Input the multiple fourth abnormal data in each access data into a pre-trained fourth abnormal agent identification sub-model, and output a fourth abnormality score value for each access data, wherein the fourth abnormal agent identification sub-model is trained and generated based on the multiple fourth abnormal data in each of the multiple historical access data.
[0107] Step S705 , generating a target abnormality score value for each access data by performing weighted voting on the first abnormality score value for each access data, the second abnormality score value for each access data, the third abnormality score value for each access data, and the fourth abnormality score value for each access data.
[0108] By predicting the classified data through multiple sub-models and then performing weighted voting based on the actual application scenario requirements to generate prediction results, the accuracy of the model prediction results can be further improved.
[0109] In addition, before the multiple first abnormal data, multiple second abnormal data, multiple third abnormal data and multiple fourth abnormal data in each access data are input into the pre-trained abnormal agent recognition model, the multiple first abnormal data, multiple second abnormal data, multiple third abnormal data and multiple fourth abnormal data in each access data can be cleaned, deduplicated, labeled and formatted.
[0110] For example, the exception data that can be obtained is {time, src_port, dst_port, src_ip, dst_ip, protocol_type, is_via, is_xff, is_remoteaddr, ip_consistent, http_method, url, freq_access, freq_port, alarm_proc, Port_num, port_standard, ip_position, ip_credit, tag}. Then, some abnormal data is formatted as follows: Time{0:00-6:00:0, 6:00-19:00:1, 19:00-24:00:2}; protocol_type{http:0, socks:1,..., tcp:n}; is_via{does not exist:0, exists:1}; is_xff{does not exist:0, exists:1}; is_remoteaddr{does not exist:0, exists:1}; ip_consistent{inconsistent:0, consistent:1}; http_method{get:0, post:1, connect:2,..., search:n}; url{does not contain abnormal information:0, contains abnormal information:1}; ip_credit{untrusted:0, trusted:1}; Tags are represented as {positive samples:1, negative samples:-1}, where positive samples refer to samples marked as abnormal agents.
[0111] By using data cleaning, deduplication, labeling, and formatting, data processing efficiency can be improved, which can save computer resources and improve computing efficiency.
[0112] Return to reference Figure 2 In step S207, access data with a target abnormality score greater than a first preset threshold value among the multiple access data are obtained and determined to be abnormal proxy access data.
[0113] The disclosed embodiment constructs a sample set by extracting multi-dimensional data such as network data packet message features, port opening features, network behavior features, and location dimension features, adopts an iterative algorithm to iteratively train an integrated learning model, and in actual detection, uses weighted voting of all model prediction results to identify whether there is abnormal proxy access behavior, thereby improving the accuracy of identification.
[0114] Figure 8 The following schematically shows a schematic diagram of a system for determining abnormal agent access data according to an embodiment of the present disclosure.
[0115] like Figure 8As shown, in this system 800, the data receiving module is used to receive network data packets to be inspected and provide raw data for analysis. This module can capture raw network traffic packets from the switch mirror port or receive network traffic packets uploaded by users. The network data packet deep analysis module is used to perform deep analysis on packets, extracting the source IP and destination IP at the network layer and the source and destination ports at the transport layer. It further identifies the protocol type and extracts key feature data within each protocol, such as determining whether it is HTTP. If so, it further extracts proxy chain feature data from the request packet header and determines whether the URL path contains abnormal feature data. The port reverse lookup module is used to call the port reverse scanning interface to analyze the source IP extracted by the network data packet deep analysis module, scan for open ports, and count the number of open ports and port numbers occupied by unconventional services, such as 1080 and 7890. The network behavior analysis module is used to call the protection device association interface to analyze the source IP extracted by the network data packet deep analysis module, determine whether there are multiple abnormal alarms, and count the network traffic volume, port numbers used by the same IP within a fixed period of time, and access port numbers within a fixed period of time. The IP address dimension analysis module calls the IP address query interface to analyze the source IP address extracted by the network packet deep analysis module to locate the IP address. It then checks the IP reputation database to see if the proxy matches the blacklisted abnormal proxy pool and whether it has been reported as an abnormal or suspicious proxy. By standardizing the feature data extracted from this analysis into a unified data format and using it as input for the abnormal proxy identification model, the detection model ensures consistent processing across various protocols and data types. The abnormal proxy identification model learns from the extracted feature data and determines whether abnormal proxy access exists based on a weighted vote of the predictions from each model.
[0116] The anomalous proxy identification model can be trained using the AdaBoost ensemble learning algorithm. Specifically, the algorithm adjusts the sample weights during each training session (increasing the weights of misclassified samples), giving greater weight to misclassified samples. Iterative training is performed K times to obtain K weak classification models. These models are then combined into a strong classification ensemble learning model through weighted voting. This strong classification ensemble learning model is then used to identify anomalous proxy access behavior. During the first training session, the number of weak classifiers to be trained, K, is set, and sample weights are initialized, assigning each sample an equal weight (i.e., weight = 1 / number of samples). The dataset input is set to {sample, tag}, and a base classifier is trained using the current sample weights. The error rate and weights of the current weak classification model are trained based on each sample training result. The weights of misclassified samples are updated, and the next weak classification model is iteratively trained based on the current weak classification model. This step is repeated K times to obtain weak classification models with different weights. These weak models are then combined into a strong model to generate the anomalous proxy identification model.
[0117] Based on multiple, iteratively trained models, the system outputs weighted predictions for network packets to be tested, rather than simple binary classification. This makes the system more flexible and capable of handling diverse scenarios in practical applications. By extracting multi-dimensional features from the network packets to be tested, it comprehensively considers multiple aspects of information, including request messages, port reverse scanning, network behavior correlation, and IP location. Using ensemble learning methods, this data can be effectively utilized to improve the model's generalization performance and enhance the accuracy of identifying anomalous proxy access behavior.
[0118] Figure 9 The structural block diagram of the apparatus for determining abnormal proxy access data according to an embodiment of the present disclosure is schematically shown.
[0119] like Figure 9 As shown, the apparatus 900 includes: a first generating module 901 , a second generating module 902 , a third generating module 903 , a fourth generating module 904 , a fifth generating module 905 , a sixth generating module 906 and a determining module 907 .
[0120] The first generation module 901 is configured to obtain multiple access data, classify each access data, and generate network data packet information data, network behavior pattern data, port open information data, and network protocol address dimension information data for each access data. In one embodiment, the first generation module 901 can be configured to execute step S201 described above, which will not be further described here.
[0121] The second generating module 902 is configured to identify abnormal data in the network data packet message information data in each access data, and generate a plurality of first abnormal data in each access data. In one embodiment, the second generating module 902 can be configured to execute the above-described step S202.
[0122] The second generating module 902 includes: a first acquiring module, a second acquiring module, a third acquiring module, a fourth acquiring module and a seventh generating module.
[0123] The first acquisition module is configured to acquire port information from the network data packet message information data in each access data, detect whether there is abnormal port data in the port information, and acquire the abnormal port data if there is abnormal port data. In one embodiment, the first acquisition module can be configured to execute step S301 described above, which will not be further described here.
[0124] The second acquisition module is configured to acquire a network protocol address from the network data packet message information data in each access data, detect whether there is an abnormal network protocol address among the network protocol addresses, and acquire the abnormal network protocol address if there is an abnormal network protocol address. In one embodiment, the second acquisition module can be configured to execute step S302 described above, which will not be further described here.
[0125] The third acquisition module is configured to obtain a protocol type from the network data packet message information data in each access data, detect whether there is an abnormal protocol type in the protocol type, and if so, obtain the abnormal protocol type. In one embodiment, the third acquisition module can be configured to execute step S303 described above, which will not be further described here.
[0126] The fourth acquisition module is configured to obtain header information from the network data packet message information data in each access data, detect whether there is an abnormal field in the header information, and if so, obtain the abnormal field. In one embodiment, the fourth acquisition module can be configured to execute step S304 described above, which will not be further described here.
[0127] The seventh generation module is configured to integrate the abnormal port data, the abnormal network protocol address, the protocol type, and the abnormal field in the network data packet message information data in each access data to generate a plurality of first abnormal data in each access data. In one embodiment, the seventh generation module can be configured to execute step S305 described above and will not be further described here.
[0128] The third generating module 903 is configured to identify abnormal data on the network behavior pattern data in each access data and generate a plurality of second abnormal data in each access data. In one embodiment, the third generating module 903 may be configured to execute step S203 described above.
[0129] The third generating module 903 includes: a fifth acquiring module, a sixth acquiring module, a seventh acquiring module and an eighth generating module.
[0130] The fifth acquisition module is configured to obtain access frequencies from the network behavior pattern data in each access data, obtain access frequencies greater than a second preset threshold, and determine them as abnormal access frequencies. In one embodiment, the fifth acquisition module can be configured to execute step S401 described above, which will not be further described here.
[0131] The sixth acquisition module is configured to obtain a port change frequency from the network behavior pattern data in each access data, obtain a port change frequency greater than a third preset threshold, and determine it as an abnormal port change frequency. In one embodiment, the sixth acquisition module can be configured to execute step S402 described above, and will not be further described here.
[0132] The seventh acquisition module is used to detect whether there is warning information in the network behavior pattern data in each access data, and if the warning information exists, obtain the warning information. In one embodiment, the seventh acquisition module can be used to execute step S403 described above, which will not be repeated here.
[0133] The eighth generation module is configured to integrate the abnormal access frequency, abnormal port change frequency, and warning information in the network behavior pattern data for each access data item to generate a plurality of second abnormal data items for each access data item. In one embodiment, the eighth generation module can be configured to execute step S404 described above and will not be further described here.
[0134] The fourth generating module 904 is configured to identify abnormal data on the port opening information data in each access data, and generate a plurality of third abnormal data in each access data. In one embodiment, the fourth generating module 904 can be configured to execute step S204 described above.
[0135] The fourth generating module 904 includes: an eighth acquiring module, a ninth acquiring module and a ninth generating module.
[0136] The eighth acquisition module is configured to obtain the number of open ports from the open port information data in each access data, obtain a number of open ports greater than a fourth preset threshold, and determine it as an abnormal number of open ports. In one embodiment, the eighth acquisition module can be configured to execute step S501 described above, which will not be further described here.
[0137] The ninth acquisition module is configured to detect whether non-standard port data exists in the port opening information data in each access data, and if so, to acquire the non-standard port data. In one embodiment, the ninth acquisition module may be configured to execute step S502 described above, which will not be described in detail herein.
[0138] A ninth generating module is configured to integrate the number of abnormal open ports and the non-standard port data in the port open information data in each access data to generate a plurality of third abnormal data in each access data. In one embodiment, the ninth generating module can be configured to execute step S503 described above, which is not further described here.
[0139] The fifth generating module 905 is configured to identify abnormal data on the network protocol address dimension information data in each access data, and generate a plurality of fourth abnormal data in each access data. In one embodiment, the fifth generating module 905 can be configured to execute step S205 described above.
[0140] The fifth generating module 905 includes: a tenth obtaining module, an eleventh obtaining module and a tenth generating module.
[0141] A tenth acquisition module is configured to acquire network protocol geographic location data from the network protocol address dimension information data within each access data, detect whether the network protocol geographic location data contains abnormal network protocol geographic location data, and acquire the abnormal network protocol geographic location data if abnormal network protocol geographic location data exists. In one embodiment, the tenth acquisition module may be configured to execute step S601 described above and will not be further described herein.
[0142] The eleventh acquisition module is configured to obtain a network protocol reputation value from the network protocol address dimension information data in each access data, obtain a network protocol reputation value less than a fifth preset threshold, and determine it as an abnormal network protocol reputation value. In one embodiment, the eleventh acquisition module can be configured to execute step S602 described above, which is not further described here.
[0143] A tenth generation module is configured to integrate the abnormal network protocol geographic location data and the abnormal network protocol reputation value in the network protocol address dimension information data in each access data to generate a plurality of fourth abnormal data for each access data. In one embodiment, the tenth generation module can be configured to execute step S603 described above and will not be further described here.
[0144] A sixth generation module 906 is configured to input the plurality of first anomaly data, the plurality of second anomaly data, the plurality of third anomaly data, and the plurality of fourth anomaly data in each access data into a pre-trained anomaly agent identification model to generate a target anomaly score for each access data. In one embodiment, the sixth generation module 906 may be configured to execute step S206 described above.
[0145] The sixth generation module 906 includes: an eleventh generation module, a twelfth generation module, a thirteenth generation module, a fourteenth generation module and a fifteenth generation module.
[0146] An eleventh generation module is configured to input the plurality of first anomaly data items in each access data item into a pre-trained first anomaly agent identification sub-model, and output a first anomaly score for each access data item, wherein the first anomaly agent identification sub-model is trained and generated based on the plurality of first anomaly data items in each of the plurality of historical access data items. In one embodiment, the eleventh generation module may be configured to execute step S701 described above and will not be further described here.
[0147] A twelfth generation module is configured to input the plurality of second anomaly data in each access data into a pre-trained second anomaly agent identification sub-model, and output a second anomaly score for each access data, wherein the second anomaly agent identification sub-model is trained and generated based on the plurality of second anomaly data in each of the plurality of historical access data. In one embodiment, the twelfth generation module can be configured to execute step S702 described above and will not be further described here.
[0148] A thirteenth generation module is configured to input the plurality of third anomaly data items in each access data item into a pre-trained third anomaly agent identification sub-model, and output a third anomaly score for each access data item, wherein the third anomaly agent identification sub-model is trained and generated based on the plurality of third anomaly data items in each of the plurality of historical access data items. In one embodiment, the thirteenth generation module may be configured to execute step S703 described above and will not be further described here.
[0149] A fourteenth generation module is configured to input the plurality of fourth anomaly data items in each access data item into a pre-trained fourth anomaly agent identification sub-model, and output a fourth anomaly score for each access data item, wherein the fourth anomaly agent identification sub-model is trained and generated based on the plurality of fourth anomaly data items in each of the plurality of historical access data items. In one embodiment, the fourteenth generation module may be configured to execute step S704 described above and will not be further described here.
[0150] A fifteenth generation module is configured to generate a target abnormality score for each access data item by performing a weighted vote on the first abnormality score for each access data item, the second abnormality score for each access data item, the third abnormality score for each access data item, and the fourth abnormality score for each access data item. In one embodiment, the fifteenth generation module may be configured to execute step S705 described above, and will not be further described here.
[0151] The determination module 907 is configured to obtain access data having a target abnormality score greater than a first preset threshold value from the plurality of access data and determine the access data as abnormal proxy access data. In one embodiment, the determination module 907 may be configured to execute step S207 described above, which will not be described in detail here.
[0152] According to embodiments of the present disclosure, any multiple of the first generation module 901, the second generation module 902, the third generation module 903, the fourth generation module 904, the fifth generation module 905, the sixth generation module 906, and the determination module 907 may be combined into a single module, or any one of these modules may be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules may be combined with at least part of the functionality of other modules and implemented in a single module. According to embodiments of the present disclosure, at least one of the first generation module 901, the second generation module 902, the third generation module 903, the fourth generation module 904, the fifth generation module 905, the sixth generation module 906, and the determination module 907 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application-specific integrated circuit (ASIC), or may be implemented in hardware or firmware through any other reasonable means of circuit integration or packaging, or may be implemented in any one of software, hardware, and firmware, or any appropriate combination of these. Alternatively, at least one of the first generation module 901, the second generation module 902, the third generation module 903, the fourth generation module 904, the fifth generation module 905, the sixth generation module 906 and the determination module 907 can be at least partially implemented as a computer program module, which can perform the corresponding function when it is executed.
[0153] Figure 10 A block diagram of an electronic device suitable for implementing a method for determining abnormal proxy access data according to an embodiment of the present disclosure is schematically shown.
[0154] like Figure 10As shown, the electronic device 1000 according to an embodiment of the present disclosure includes a processor 1001, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage portion 1008 into a random access memory (RAM) 1003. The processor 1001 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or a related chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 1001 may also include onboard memory for caching purposes. The processor 1001 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0155] Various programs and data required for the operation of the electronic device 1000 are stored in the RAM 1003. The processor 1001, the ROM 1002, and the RAM 1003 are connected to each other via a bus 1004. The processor 1001 performs various operations of the method flow according to the embodiment of the present disclosure by executing the programs in the ROM 1002 and / or the RAM 1003. It should be noted that the programs may also be stored in one or more memories other than the ROM 1002 and the RAM 1003. The processor 1001 may also perform various operations of the method flow according to the embodiment of the present disclosure by executing the programs stored in the one or more memories.
[0156] According to an embodiment of the present disclosure, electronic device 1000 may further include an input / output (I / O) interface 1005, which is also connected to bus 1004. Electronic device 1000 may also include one or more of the following components connected to I / O interface 1005: an input section 1006 including a keyboard, mouse, etc.; an output section 1007 including devices such as a cathode ray tube (CRT), liquid crystal display (LCD), and speakers; a storage section 1008 including a hard disk; and a communication section 1009 including a network interface card such as a LAN card or modem. Communication section 1009 performs communication processing via a network such as the Internet. A drive 1010 is also connected to I / O interface 1005 as needed. Removable media 1011, such as a magnetic disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed in drive 1010 as needed, so that computer programs read from the removable media can be installed into storage section 1008 as needed.
[0157] The present disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments, or may exist independently and not be incorporated into the device / apparatus / system. The computer-readable storage medium carries one or more programs, and when executed, implements the method according to the embodiments of the present disclosure.
[0158] According to an embodiment of the present disclosure, a computer-readable storage medium may be a non-volatile computer-readable storage medium, and may include, for example, but not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present disclosure, a computer-readable storage medium may include ROM 1002 and / or RAM 1003 described above and / or one or more memories other than ROM 1002 and RAM 1003.
[0159] The embodiments of the present disclosure also include a computer program product, which includes a computer program containing program code for executing the method shown in the flowchart. When the computer program product is executed in a computer system, the program code is used to enable the computer system to implement the abnormal proxy access data determination method provided by the embodiments of the present disclosure.
[0160] The computer program executes the above functions defined in the system / device of the embodiment of the present disclosure when the processor 1001 executes the computer program. According to the embodiment of the present disclosure, the system, device, module, unit, etc. described above can be implemented by a computer program module.
[0161] In one embodiment, the computer program may be stored on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may be transmitted and distributed in the form of a signal on a network medium, downloaded and installed via the communication portion 1009, and / or installed from the removable medium 1011. The program code contained in the computer program may be transmitted using any appropriate network medium, including but not limited to wireless, wired, or any suitable combination thereof.
[0162] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 1009, and / or installed from the removable medium 1011. When the computer program is executed by the processor 1001, the above-described functions defined in the system of the embodiment of the present disclosure are performed. According to the embodiment of the present disclosure, the systems, devices, means, modules, units, etc. described above can be implemented by computer program modules.
[0163] According to an embodiment of the present disclosure, the program code for executing the computer program provided by the embodiment of the present disclosure can be written in any combination of one or more programming languages. Specifically, these computer programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, languages such as Java, C++, Python, "C" or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect via the Internet).
[0164] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the above-mentioned module, program segment, or a part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0165] Those skilled in the art will appreciate that the features described in the various embodiments and / or claims of this disclosure may be combined and / or coupled in various ways, even if such combinations and / or couplings are not explicitly described in this disclosure. In particular, the features described in the various embodiments and / or claims of this disclosure may be combined and / or coupled in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or couplings are intended to fall within the scope of this disclosure.
[0166] The embodiments of the present disclosure are described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present disclosure. Although each embodiment has been described separately above, this does not mean that the measures in each embodiment cannot be used in combination to advantage. The scope of the present disclosure is defined by the appended claims and their equivalents. Without departing from the scope of the present disclosure, those skilled in the art may make various substitutions and modifications, which should all fall within the scope of the present disclosure.
Claims
1. A method for determining abnormal proxy access data, characterized in that: The method includes: Acquire multiple access data, classify each access data, and generate network data packet message information data, network behavior pattern data, port open information data, and network protocol address dimension information data in each access data; Performing abnormal data identification on the network data packet message information data in each access data to generate a plurality of first abnormal data in each access data; Performing abnormal data identification on the network behavior pattern data in each access data to generate a plurality of second abnormal data in each access data; performing abnormal data identification on the port opening information data in each access data to generate a plurality of third abnormal data in each access data; Performing abnormal data identification on the network protocol address dimension information data in each access data to generate a plurality of fourth abnormal data in each access data; Inputting the plurality of first abnormal data, the plurality of second abnormal data, the plurality of third abnormal data and the plurality of fourth abnormal data in each access data into a pre-trained abnormal agent identification model to generate a target abnormality score value for each access data; and Access data with a target abnormality score greater than a first preset threshold value among the multiple access data are obtained and determined to be abnormal proxy access data.
2. The method according to claim 1, characterized in that Identifying abnormal data on the network data packet message information data in each access data to generate a plurality of first abnormal data in each access data, including: Obtaining port information in the network data packet message information data in each access data, detecting whether there is abnormal port data in the port information, and if abnormal port data exists, obtaining the abnormal port data; Obtaining a network protocol address in the network data packet message information data in each access data, detecting whether there is an abnormal network protocol address in the network protocol address, and if an abnormal network protocol address exists, obtaining the abnormal network protocol address; Obtaining a protocol type in the network data packet message information data in each access data, detecting whether there is an abnormal protocol type in the protocol type, and if there is an abnormal protocol type, obtaining the abnormal protocol type; Obtaining header information in the network data packet message information data in each access data, detecting whether there is an abnormal field in the header information, and if there is an abnormal field, obtaining the abnormal field; and The abnormal port data, the abnormal network protocol address, the protocol type and the abnormal field in the network data packet message information data in each access data are integrated to generate a plurality of first abnormal data in each access data.
3. The method according to claim 1, characterized in that Identifying abnormal data on the network behavior pattern data in each access data to generate a plurality of second abnormal data in each access data includes: Obtaining access frequencies from the network behavior pattern data in each access data, obtaining access frequencies greater than a second preset threshold, and determining them as abnormal access frequencies; Obtaining a port change frequency in the network behavior pattern data in each access data, obtaining a port change frequency greater than a third preset threshold, and determining it as an abnormal port change frequency; detecting whether there is warning information in the network behavior pattern data in each access data, and if the warning information exists, obtaining the warning information; and The abnormal access frequency, abnormal port change frequency and warning information in the network behavior pattern data in each access data are integrated to generate a plurality of second abnormal data in each access data.
4. The method according to claim 1, wherein Performing abnormal data identification on the port opening information data in each access data to generate a plurality of third abnormal data in each access data, including: Obtaining the number of open ports in the open port information data in each access data, obtaining a number of open ports greater than a fourth preset threshold, and determining it as an abnormal number of open ports; detecting whether non-standard port data exists in the port opening information data in each access data, and if the non-standard port data exists, acquiring the non-standard port data; and The abnormal port opening quantity and the non-standard port data in the port opening information data in each access data are integrated to generate a plurality of third abnormal data in each access data.
5. The method according to claim 1, wherein Performing abnormal data identification on the network protocol address dimension information data in each access data to generate a plurality of fourth abnormal data in each access data, including: Obtaining network protocol geographic location data in the network protocol address dimension information data in each access data, detecting whether there is abnormal network protocol geographic location data in the network protocol geographic location data, and if abnormal network protocol geographic location data exists, obtaining the abnormal network protocol geographic location data; Obtaining a network protocol reputation value in the network protocol address dimension information data in each access data, obtaining a network protocol reputation value that is less than a fifth preset threshold, and determining it as an abnormal network protocol reputation value; and The abnormal network protocol geographic location data and the abnormal network protocol reputation value in the network protocol address dimension information data in each access data are integrated to generate a plurality of fourth abnormal data in each access data.
6. The method according to claim 1, characterized in that The abnormal agent identification model includes: a first abnormal agent identification sub-model, a second abnormal agent identification sub-model, a third abnormal agent identification sub-model, and a fourth abnormal agent identification sub-model. The plurality of first abnormal data, the plurality of second abnormal data, the plurality of third abnormal data, and the plurality of fourth abnormal data in each access data are input into the pre-trained abnormal agent identification model to generate a target abnormality score value for each access data, including: Inputting the plurality of first abnormal data in each access data into a pre-trained first abnormal agent identification sub-model, and outputting a first abnormality score value for each access data, wherein the first abnormal agent identification sub-model is trained and generated based on the plurality of first abnormal data in each of the plurality of historical access data; Inputting the plurality of second abnormal data in each access data into a pre-trained second abnormal agent identification sub-model, and outputting a second abnormality score value for each access data, wherein the second abnormal agent identification sub-model is trained and generated based on the plurality of second abnormal data in each of the plurality of historical access data; inputting the plurality of third abnormal data in each access data into a pre-trained third abnormal agent identification sub-model, and outputting a third abnormality score value for each access data, wherein the third abnormal agent identification sub-model is trained and generated based on the plurality of third abnormal data in each of the plurality of historical access data; Inputting the plurality of fourth abnormal data in each access data into a pre-trained fourth abnormal agent identification sub-model, and outputting a fourth abnormality score value for each access data, wherein the fourth abnormal agent identification sub-model is generated based on the plurality of fourth abnormal data in each of the plurality of historical access data; and A target abnormality score value for each access data is generated by performing weighted voting on the first abnormality score value for each access data, the second abnormality score value for each access data, the third abnormality score value for each access data, and the fourth abnormality score value for each access data.
7. The method according to any one of claims 1 to 6, characterized in that Before inputting the plurality of first abnormal data, the plurality of second abnormal data, the plurality of third abnormal data and the plurality of fourth abnormal data in each access data into the pre-trained abnormal agent identification model, the method further includes: Data cleaning, data deduplication, data marking and data formatting are performed on the plurality of first abnormal data, the plurality of second abnormal data, the plurality of third abnormal data and the plurality of fourth abnormal data in each access data.
8. A device for determining abnormal proxy access data, characterized in that: The device includes: The first generation module is used to obtain multiple access data, classify each access data, and generate network data packet message information data, network behavior pattern data, port open information data, and network protocol address dimension information data in each access data; A second generating module is used to identify abnormal data of the network data packet message information data in each access data, and generate a plurality of first abnormal data in each access data; a third generating module, configured to identify abnormal data on the network behavior pattern data in each access data, and generate a plurality of second abnormal data in each access data; a fourth generating module, configured to identify abnormal data on the port opening information data in each access data, and generate a plurality of third abnormal data in each access data; a fifth generating module, configured to identify abnormal data on the network protocol address dimension information data in each access data, and generate a plurality of fourth abnormal data in each access data; a sixth generating module, configured to input the plurality of first abnormal data, the plurality of second abnormal data, the plurality of third abnormal data, and the plurality of fourth abnormal data in each access data into a pre-trained abnormal agent identification model to generate a target abnormality score value for each access data; and The determination module is configured to obtain access data having a target abnormality score greater than a first preset threshold value from the plurality of access data, and determine the access data as abnormal proxy access data.
9. An electronic device comprising: one or more processors; a memory for storing one or more computer programs, It is characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
11. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.