Network security collaborative integrated analysis system and method based on multi-modal processing
Through the multimodal processing of network security collaborative integrated analysis system, combined with session access data and log data, abnormal behavior is identified and blacklists are updated, which solves the lag problem of traditional detection methods and realizes real-time monitoring and protection of network security.
Patent Information
- Application Number
- CN202511171804.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-21
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2045-08-21
AI Technical Summary
Traditional network security detection methods can easily bypass encrypted traffic and imitate legitimate protocols, making it difficult to distinguish between malicious scans and normal high-concurrency access, resulting in delayed blacklist updates.
A network security collaborative integrated analysis system based on multimodal processing is adopted to identify abnormal behaviors and update blacklists through data collection, feature extraction, packet analysis and log analysis modules, combined with session access data and log data.
It realizes real-time security monitoring of network nodes and timely updating of blacklists, improves network security protection capabilities and efficiency, and accurately identifies attack behaviors.
Smart Images

Figure CN120729626A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of network security technology, and specifically relates to a network security collaborative integrated analysis system and method based on multimodal processing. Background Art
[0002] Multimodal processing refers to the ability of a system or model to simultaneously process and understand multiple data types, and to ensure the accuracy of analysis results through information from different modalities. Collaborative integration of network security is a comprehensive concept that emphasizes the integration of different security components, technologies, and processes in the field of network security to achieve collaborative work and improve overall security protection capabilities and efficiency.
[0003] However, traditional solutions often analyze network traffic or application behavior in isolation. Attackers can bypass single detection methods by encrypting traffic, mimicking legitimate protocols, and so on. Traditional detection methods are not only easy to bypass, but also difficult to distinguish between malicious scans and normal high-concurrency access, which leads to delayed blacklist updates. To this end, the present invention proposes a network security collaborative integrated analysis system and method based on multimodal processing. Summary of the Invention
[0004] The purpose of the present invention is to propose a network security collaborative integrated analysis system and method based on multimodal processing to solve the problems raised in the above background technology.
[0005] In the first aspect, in order to achieve the above-mentioned purpose, the present invention adopts the following technical solutions: A network security collaborative integrated analysis system based on multimodal processing, including a data acquisition module, a feature extraction module, a packet analysis module, a log analysis module, and a storage terminal; The data collection module is used to collect session access data and session log data of the corresponding session of the access user, and the data collection module sends the session access data to the feature extraction module and sends the session log data to the log analysis module; The feature extraction module is used to extract and classify the session access data and different types of data in the session access data, and obtain the data packet quintuple and time features and send them to the data packet analysis module; The data packet analysis module is used to determine the security of the prepared detection network node through the network analysis unit and the session analysis unit, obtain a newly added blacklist and send it to the storage terminal; The log analysis module is used to judge the security of the prepared detection network node in combination with the session log data, obtain the newly added blacklist and send it to the storage terminal; The storage terminal is used to receive and update the newly added blacklist, and then store the updated blacklist.
[0006] Furthermore, the session access data includes: the session data packet sent by the accessing user and the corresponding data packet volume of the session data packet received by the preliminary detection network node; the session log data includes the log left by the accessing user after a series of operations during a session.
[0007] Furthermore, the working process of the feature extraction module is as follows: Acquire session access data of the preliminary detection network node, and obtain multiple session data packets sent by the access user received by the corresponding preliminary detection network node; Extract the data packet source IP, data packet source port, data packet destination IP, data packet destination port and data packet sending protocol corresponding to each session data packet, and summarize them into a data packet five-tuple; Identify timestamps of multiple session data packets, read the sending times of the multiple session data packets, and arrange the session data packets in descending order of timestamps; Obtain the transmission start time and transmission completion time of the corresponding data packet according to the timestamp of the session data packet; obtain the transmission duration of the corresponding session data packet by subtracting the transmission start time of the same session data packet from the transmission completion time; Identify the packet volume of the session data packet, and obtain the transmission rate by dividing the packet volume by the transmission duration of the corresponding session data packet. Subtract the transmission completion time of the previous data packet from the transmission start time of the current data packet to obtain the inter-packet waiting time of the current data packet; use the inter-packet waiting time and the transmission rate as the time characteristics of the corresponding session.
[0008] Furthermore, the working process of the network analysis unit is as follows: Acquire multiple data packet quintuples and obtain the data packet sending source IP, data packet sending source port, data packet destination IP, data packet destination port and data packet sending protocol of the corresponding session data packet; If the source IP of the data packet is on the IP blacklist or the source port of the data packet is on the port blacklist, the corresponding session data packet will be marked as a dangerous file and deleted; if the source IP of the data packet is not on the IP blacklist and the source port of the data packet is not on the port blacklist, proceed to the subsequent steps; Identify the node IP and node port corresponding to the prepared detection network node; Compare the node IP with the destination IP of the data packet. If the node IP is the same as the destination IP of the data packet, proceed to the next step. If the node IP is different from the destination IP of the data packet, increase the abnormal IP operand of the source IP of the data packet by one.
[0009] Furthermore, the working process of the network analysis unit also includes: Match the node port with the destination port of the data packet. If the node port contains the destination port of the data packet, proceed to the next step. If the node port does not contain the destination port of the data packet, increase the abnormal port operand of the source port of the data packet by one. Similarly, perform the above operations on the packet quintuples of all session packets; Count the total number of abnormal IP operations of all sending source IPs and the total number of abnormal port operations of all sending source ports; The total number of abnormal IP operations and the total number of abnormal port operations are compared with the corresponding thresholds respectively. If either the total number of abnormal IP operations or the total number of abnormal port operations is greater than or equal to the corresponding threshold, the corresponding IP address or port number is added to the blacklist and the session data packets received in this session are cleared; if the total number of abnormal IP operations or the total number of abnormal port operations are both less than the corresponding threshold, no action is taken.
[0010] Furthermore, the working process of the conversation analysis unit specifically includes: Obtain the time characteristics of the session data packets to obtain the inter-packet waiting time and transmission rate; add the inter-packet waiting time of all session data packets and take the average value to obtain the mean inter-packet waiting time; Based on the mean and inter-packet waiting times, the standard deviation of the inter-packet waiting time of the session data packets is calculated; The first cutoff value is obtained by subtracting the standard deviation of the inter-packet waiting time from the mean inter-packet waiting time, and the second cutoff value is obtained by adding the standard deviation of the inter-packet waiting time to the mean inter-packet waiting time. The first cutoff value is used as the left endpoint and the second cutoff value is used as the right endpoint to obtain the filtering range of the inter-packet waiting time corresponding to the session data packets, and the inter-packet waiting time outside the filtering range is discarded. The remaining packet waiting times are added and averaged to obtain the mean waiting time between denoised packets. The average waiting time between denoised packets is compared with the average waiting time threshold between packets. If the average waiting time between denoised packets is less than the average waiting time threshold between packets, a frequency anomaly signal is generated. If the average waiting time between packets is greater than or equal to the average waiting time threshold between packets, the subsequent steps are carried out. The transmission rates of the remaining session data packets are summed and averaged to obtain the average transmission rate. The average transmission rate is compared with the average transmission rate threshold. If the average transmission rate is greater than or equal to the average transmission rate threshold, a rate anomaly signal is generated. If the average transmission rate is less than the average transmission rate threshold, the subsequent steps are performed. If both frequency anomaly signals and rate anomaly signals exist, the source IP address corresponding to the session data packet is added to the blacklist; otherwise, no action is taken.
[0011] Furthermore, the analysis process of the log analysis module is as follows: Obtain session log data and extract session login logs from the session log data; obtain the start and end time of access by the accessing user based on the session login logs; Extracting multiple system logs with timestamps between the start access time and the end access time; Read the target file accessed by the access user based on the system log, and then obtain the file access path, file access count and file access duration of the target file; Read the historical system logs of the target file within seven days as a training set, and obtain the historical access path, historical access count, and historical access duration corresponding to the target file based on the historical system logs; Count the types of historical access paths. If only one exists, use the corresponding historical access path as the access path baseline. If multiple exist, retain the historical access path with the most occurrences and discard the remaining historical access paths and corresponding historical system logs. Add up all the historical access times and take the average to get the mean historical access time of the target file, and then calculate the standard deviation of the historical access time corresponding to the mean historical access time; Match the file access path of the target file with the access path baseline; If the file access path is different from the access path baseline, the file access path of the target file is considered abnormal; if the file access path is the same as the access path baseline, the file access path of the target file is considered normal and proceed to the next step.
[0012] Furthermore, the analysis process of the log analysis module also includes: Calculate the access time deviation of the target file; Construct the normal interval standard, offset interval standard and abnormal interval standard corresponding to the access time deviation; Count the normal times that the target file appears in the normal interval, the offset times that it appears in the offset interval, and the abnormal times that it appears in the abnormal interval; If the number of exceptions is greater than or equal to one, the access duration is considered abnormal; if the number of exceptions is less than one, the abnormal value of the access duration of the target file is calculated; The access time abnormal value is compared with the access time abnormal threshold. If the access time abnormal value is greater than or equal to the access time abnormal threshold, the access time is considered abnormal; if the access time abnormal value is less than the access time abnormal threshold, the access time is considered normal. If both the file access path and the file access duration are normal, no operation will be performed; if either the file access path or the file access duration is abnormal, the target file access operation will be judged as corresponding to the existence of attack intent; Similarly, all target files are judged for the existence of attack intentions. If any target file is accessed with attack intentions, the IP address corresponding to the accessing user will be added to the blacklist. Otherwise, no action will be taken.
[0013] Furthermore, the process of determining whether an access has an attack intent is as follows: Get the target file and obtain the original sequence of the target file; After adding a bit "1" to the original sequence, fill it with K zeros to get the processed sequence; Convert the original sequence into 64-bit binary form, and then concatenate it with the processed sequence to obtain the calculated sequence; Split the calculation sequence into n 64-byte calculation subsequences; select the first 32 digits of the decimal part of the square root of the first eight prime numbers in natural numbers, convert them into hexadecimal representation to obtain eight initial check values, and use the eight initial check values as the initial values of the first check value to the eighth check value in sequence; Sequentially appending the first to eighth check values to the first to eighth intermediate variables; wherein the initial values of the first to eighth intermediate variables are all 0; an update function for updating the first intermediate variable to the eighth update variable; Add the updated first intermediate variable to the initial first check value to obtain an updated value of the first check value; similarly, obtain updated values of the second to eighth check values; Iterate the operation for n or more times to obtain the final first to eighth check values, and concatenate the first to eighth check values to obtain the file integrity check value of the target file corresponding to the initial state; Similarly, calculate the file integrity check value of the target file after it is accessed; If the file integrity check value in the initial state is inconsistent with the file integrity check value after being accessed, it is determined that the access operation of the target file has an attack intention; otherwise, it is determined that the access operation of the target file has no attack intention and the operation is not performed.
[0014] In a second aspect, the present invention further proposes a network security collaborative integrated analysis method based on multimodal processing, the method comprising: Step S101, collecting session access data and session log data of the corresponding session of the access user; Step S102: extracting session access data and different types of data in the session access data, extracting and classifying them to obtain a data packet quintuple and time features; Step S103: judging the security of the corresponding preliminary detection network node based on the data packet quintuple and time characteristics, and then adding the access user corresponding to the session data packet to the blacklist; Step S104: judging the security of the prepared detection network node in combination with the session log data, and obtaining a newly added blacklist.
[0015] In summary, due to the adoption of the above technical solution, the beneficial effects of the present invention are: 1. The present invention first collects the session access data and session log data of the corresponding session of the access user through the data acquisition module, and then extracts and classifies the session access data and different types of data in the session access data to obtain a five-tuple of data packets and send it with time features; then the data packet analysis module is used to judge the security of the pre-detection network node through the network analysis unit and the session analysis unit, obtain the newly added blacklist and send it to the storage terminal. The present invention realizes the monitoring of the network security of the pre-detection network node at the data transmission level.
[0016] 2. The present invention combines session log data to determine the security of the pre-detection network node, obtains a newly added blacklist, and sends it to a storage terminal; finally, the newly added blacklist is received and updated by the storage terminal, and then the updated blacklist is stored. The present invention realizes timely updating of the blacklist by analyzing the multimodal data of the visiting users. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] To facilitate understanding by those skilled in the art, the present invention is further described below with reference to the accompanying drawings.
[0018] Figure 1 is a block diagram of the overall system of the present invention; Figure 2 This is a system architecture diagram of the present invention; Figure 3 The present invention is a flow chart of the method. DETAILED DESCRIPTION
[0019] The technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0020] Example 1, please refer to Figure 1 and Figure 2 As shown, the technical solution provided by the present invention is: a network security collaborative integrated analysis system based on multimodal processing. The system monitors the data interaction between access users and pre-detection network nodes, performs synchronous analysis at the network and application levels, and then accurately identifies the attack behavior of access users and adds them to the blacklist in a timely manner, ensuring the reliable operation of pre-detection network nodes; The system includes: a data acquisition module, a feature extraction module, a data packet analysis module, a log analysis module and a storage terminal; In the present invention, the data collection module is used to detect the session operation of data interaction between any accessing user and the pre-detection network node, and then collect the session access data and session log data of the accessing user's corresponding session. The data collection module sends the session access data to the feature extraction module and sends the session log data to the log analysis module; The process from establishing a network connection with a pre-detection network node to disconnecting it is considered a session. Session access data includes: session data packets sent by the access user and received by the pre-detection network node, as well as the corresponding data packet volume of the session data packets. Session log data includes logs left by the access user during a series of operations during a session, such as session login logs, system logs, user file logs, file access logs, and network connection logs. In the present invention, the feature extraction module is used to extract and classify session access data and different types of data in the session access data. The working process is as follows: Acquire session access data of the preliminary detection network node, and obtain multiple session data packets sent by the access user received by the corresponding preliminary detection network node; Extract the data packet source IP, data packet source port, data packet destination IP, data packet destination port and data packet sending protocol corresponding to each session data packet, and summarize them into a data packet five-tuple; It should be explained that the packet destination IP refers to the IP address to which the session packet is expected to be sent; the packet destination port refers to the port number to which the session packet is expected to be sent; Identify timestamps of multiple session data packets, read the sending times of the multiple session data packets, and arrange the session data packets in descending order of timestamps; It should be noted that the present invention considers that the communication between the access user and the preliminary detection network node is single-channel, that is, the access user and the preliminary detection network node can only send one session data packet at the same time; The transmission start time and transmission completion time of the corresponding data packet are obtained based on the timestamp of the session data packet; the transmission duration of the corresponding session data packet is obtained by subtracting the transmission start time of the same session data packet from the transmission completion time; the packet volume of the session data packet is identified, and the transmission rate is obtained by dividing the packet volume by the transmission duration of the corresponding session data packet; the inter-packet waiting time of the current data packet is obtained by subtracting the transmission completion time of the previous data packet from the transmission start time of the current data packet; the inter-packet waiting time and the transmission rate are used as the time characteristics of the corresponding session; It should be noted that there is no inter-packet waiting time for the first session data packet; The feature extraction module sends the data packet quintuple and the time feature to the data packet analysis module; In the present invention, the data packet analysis module includes a network analysis unit and a session analysis unit. The network analysis unit is used to determine the security of the preliminary detection network node based on the data packet quintuple. The determination process is as follows: Acquire multiple data packet quintuples and obtain the data packet sending source IP, data packet sending source port, data packet destination IP, data packet destination port and data packet sending protocol of the corresponding session data packet; If the source IP of the data packet is on the IP blacklist or the source port of the data packet is on the port blacklist, the corresponding session data packet will be marked as a dangerous file and deleted; if the source IP of the data packet is not on the IP blacklist and the source port of the data packet is not on the port blacklist, proceed to the subsequent steps; Identify the node IP and node port corresponding to the preliminary detection network node; wherein the number of node ports is greater than or equal to one; Compare the node IP with the destination IP of the data packet. If the node IP is the same as the destination IP of the data packet, proceed to the next step. If the node IP is different from the destination IP of the data packet, increase the abnormal IP operand of the source IP of the data packet by one. Match the node port with the destination port of the data packet. If the node port contains the destination port of the data packet, proceed to the next step. If the node port does not contain the destination port of the data packet, increase the abnormal port operand of the source port of the data packet by one. Similarly, perform the above operations on the packet quintuples of all session packets; Count the total number of abnormal IP operations of all sending source IPs and the total number of abnormal port operations of all sending source ports; The total number of abnormal IP operations and the total number of abnormal port operations are compared with the corresponding thresholds respectively. If either the total number of abnormal IP operations or the total number of abnormal port operations is greater than or equal to the corresponding threshold, the corresponding IP address or port number is added to the blacklist and the session data packets received in this session are cleared; if the total number of abnormal IP operations or the total number of abnormal port operations are both less than the corresponding threshold, no action is taken.
[0021] In the present invention, the session analysis unit is used to determine the security of the preliminary detection network node based on the time feature. The determination process is as follows: Obtain the time characteristics of the session data packets to obtain the inter-packet waiting time and transmission rate; add the inter-packet waiting time of all session data packets and take the average value to obtain the mean inter-packet waiting time; Based on the mean and inter-packet waiting times, the standard deviation of the inter-packet waiting time of the session data packets is calculated; The first cutoff value is obtained by subtracting the standard deviation of the inter-packet waiting time from the mean inter-packet waiting time, and the second cutoff value is obtained by adding the standard deviation of the inter-packet waiting time to the mean inter-packet waiting time. The first cutoff value is used as the left endpoint and the second cutoff value is used as the right endpoint to obtain the filtering range of the inter-packet waiting time corresponding to the session data packets, and the inter-packet waiting time outside the filtering range is discarded. The remaining packet waiting times are added and averaged to obtain the mean waiting time between denoised packets. The average waiting time between denoised packets is compared with the average waiting time threshold between packets. If the average waiting time between denoised packets is less than the average waiting time threshold between packets, a frequency anomaly signal is generated. If the average waiting time between packets is greater than or equal to the average waiting time threshold between packets, the subsequent steps are carried out. The transmission rates of the remaining session data packets are summed and averaged to obtain the average transmission rate. The average transmission rate is compared with the average transmission rate threshold. If the average transmission rate is greater than or equal to the average transmission rate threshold, a rate anomaly signal is generated. If the average transmission rate is less than the average transmission rate threshold, the subsequent steps are performed. If both frequency anomaly signals and rate anomaly signals are present, the source IP address corresponding to the session data packet will be added to the blacklist; otherwise, no action will be taken. The blacklist newly added by the data packet analysis module is sent to the storage terminal.
[0022] The log analysis module is used to determine the security of the pre-detection network node based on the session log data. The analysis process is as follows: Obtain session log data and extract session login logs from the session log data; obtain the start and end time of access by the accessing user based on the session login logs; Extract multiple system logs with timestamps between the start and end of access. The system logs record the operations performed by the accessing user, such as accessing a file, subsequent operations, the number of operations performed, and the duration of the access. Read the target file accessed by the access user based on the system log, and then obtain the file access path, file access count and file access duration of the target file; Read the historical system logs of the target file within seven days as a training set, and obtain the historical access path, historical access count, and historical access duration corresponding to the target file based on the historical system logs; Count the types of historical access paths. If only one exists, use the corresponding historical access path as the access path baseline. If multiple exist, retain the historical access path with the most occurrences and discard the remaining historical access paths and corresponding historical system logs. Add up all the historical access times and take the average to get the mean historical access time of the target file, and then calculate the standard deviation of the historical access time corresponding to the mean historical access time; Match the file access path of the target file with the access path baseline; If the file access path is different from the access path baseline, the file access path of the target file is considered abnormal; if the file access path is the same as the access path baseline, the file access path of the target file is considered normal and the process proceeds to the next step. The access time deviation of the target file is calculated using the formula: Access duration deviation = |file access duration - historical access duration mean| / historical access duration standard deviation; Construct the normal interval standard corresponding to the access time deviation: (0, 1], the offset interval standard: (1, 3], the abnormal interval standard: (3, +∞]; Count the normal times that the target file appears in the normal interval, the offset times that it appears in the offset interval, and the abnormal times that it appears in the abnormal interval; If the number of exceptions is greater than or equal to one, the access duration is considered abnormal; if the number of exceptions is less than one, the abnormal value of the access duration of the target file is calculated using the formula. The specific formula is as follows: Abnormal access duration = (normal times × A1 + abnormal times × A2) / (normal times + abnormal times); where A1 and A2 are weight coefficients, A1 < A2; The access time abnormal value is compared with the access time abnormal threshold. If the access time abnormal value is greater than or equal to the access time abnormal threshold, the access time is considered abnormal; if the access time abnormal value is less than the access time abnormal threshold, the access time is considered normal. If both the file access path and the file access duration are normal, no operation will be performed; if either the file access path or the file access duration is abnormal, the target file access operation will be judged as corresponding to the existence of attack intent; The process of determining whether an access has attack intent is as follows: Get the target file and obtain the original sequence YX of the target file; After adding a bit "1" to the original sequence, fill it with K zeros to get the processed sequence; It should be noted that the processing sequence needs to satisfy: the processing sequence mod the preset divisor = the preset remainder; wherein the preset remainder is preferably 488, and the preset divisor is preferably 512; Convert the original sequence into 64-bit binary form, and then concatenate it with the processed sequence to obtain the calculated sequence; Divide the calculation sequence into n 64-byte calculation subsequences; select the first 32 digits of the decimal part of the square root of the first eight prime numbers in natural numbers, and then convert them into hexadecimal representation to obtain eight initial check values, and use the eight initial check values as the initial values of the first check value to the eighth check value, respectively, and record the first check value to the eighth check value as JY1 to JY8; Sequentially append the first to eighth check values to the first to eighth intermediate variables, and denote the first to eighth intermediate variables as BL1 to BL8, respectively; wherein the initial values of the first to eighth intermediate variables are all 0; The update function of the first intermediate variable to the eighth update variable is updated by the formula. The function is as follows: T1=BL8+HS1(BL5)+HS2(BL5, BL6, BL7)+CS1+CS2; T2=HS3(BL1)+HS4(BL1,BL2,BL3); HS1(BL5)=(BL5>>6)⊕(BL5>>11)⊕(BL5>>25); HS2(BL5,BL6,BL7)=(BL5∧BL6)⊕(¬BL5∧BL7); HS3(BL1)=(BL1>>2)⊕(BL1>>13)⊕(BL1>>22); HS4(BL1,BL2,BL3)=(BL1∧BL2)⊕(BL1∧BL3)⊕(BL2∧BL3); CS1 is a constant, which is a predefined set of 64 32-bit constants. CS2 is a message word, which is extracted from the original sequence of the target file. >>> represents a circular right shift operation, represents a logical right shift operation, ¬ represents a negation operation, ⊕ represents an exclusive-or operation, and ∧ represents an intersection operation; Update the first intermediate variable to the eighth intermediate variable: BL8=BL7; BL7=BL6; BL6=BL5; BL5=BL4+T1; BL4=BL3; BL3=BL2; BL2=BL1; BL1=T1+T2; It should be noted that in the above operation of updating the first intermediate variable to the eighth intermediate variable, "=" represents assignment, that is, the value on the right side of the equal sign is assigned to the left side of the equal sign; Add the updated first intermediate variable to the initial first check value to obtain an updated value of the first check value; similarly, obtain updated values of the second to eighth check values; Iterate the above operation n times to obtain the final first to eighth check values, and concatenate the first to eighth check values to obtain the file integrity check value of the target file corresponding to the initial state; Similarly, calculate the file integrity check value of the target file after it is accessed; If the integrity check value of the file in the initial state is inconsistent with the integrity check value of the file after being accessed, it is determined that the access operation of the target file has an attack intention, indicating that the target file has been tampered with; otherwise, it is determined that the access operation of the target file has no attack intention and the operation is not performed; Similarly, all target files are judged for attack intent. If any target file is accessed with attack intent, the IP address of the accessing user is added to the blacklist and the blacklist is sent to the storage terminal. Otherwise, no action is taken. The storage terminal is used to receive and update the newly added blacklist, and then store the updated blacklist.
[0023] In this application, if a corresponding calculation formula appears, the above calculation formula is dimensionless and its numerical calculation is performed. The weight coefficient, proportional coefficient and other coefficients in the formula are set to a result value obtained by quantifying each parameter. Regarding the size of the weight coefficient and the proportional coefficient, as long as it does not affect the proportional relationship between the parameter and the result value, it is acceptable.
[0024] Example 2, as Figure 3 As shown, based on another concept of the same invention, a network security collaborative integrated analysis method based on multimodal processing is proposed, including the following steps: Step S101, collecting session access data and session log data of the corresponding session of the access user; Step S102: extracting session access data and different types of data in the session access data, extracting and classifying them to obtain a data packet quintuple and time features; Step S103: judging the security of the corresponding preliminary detection network node based on the data packet quintuple and time characteristics, and then adding the access user corresponding to the session data packet to the blacklist; Step S104: judging the security of the prepared detection network node in combination with the session log data, and obtaining a newly added blacklist.
[0025] The preferred embodiments of the present invention disclosed above are intended only to help illustrate the present invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the present invention to specific embodiments. Obviously, many modifications and variations are possible based on the contents of this specification. These embodiments are selected and described in detail in this specification to better explain the principles and practical applications of the present invention, thereby enabling those skilled in the art to better understand and utilize the present invention. The present invention is limited only by the claims and their full scope and equivalents.
Claims
1. A network security collaborative integrated analysis system based on multimodal processing, characterized by: It includes data acquisition module, feature extraction module, data packet analysis module, log analysis module and storage terminal; The data collection module is used to collect session access data and session log data of the corresponding session of the access user, and the data collection module sends the session access data to the feature extraction module and sends the session log data to the log analysis module; The feature extraction module is used to extract and classify the session access data and different types of data in the session access data, and obtain the data packet quintuple and time features and send them to the data packet analysis module; The data packet analysis module is used to determine the security of the prepared detection network node through the network analysis unit and the session analysis unit, obtain a newly added blacklist and send it to the storage terminal; The log analysis module is used to judge the security of the prepared detection network node in combination with the session log data, obtain the newly added blacklist and send it to the storage terminal; The storage terminal is used to receive and update the newly added blacklist, and then store the updated blacklist.
2. The network security collaborative integrated analysis system based on multimodal processing according to claim 1 is characterized in that: The session access data includes: a session data packet sent by a visiting user and received by a preliminary detection network node and the corresponding data packet volume of the session data packet; the session log data includes a log left by a series of operations of the visiting user during a session.
3. The network security collaborative integrated analysis system based on multimodal processing according to claim 1 is characterized in that: The working process of the feature extraction module is as follows: Acquire session access data of the preliminary detection network node, and obtain multiple session data packets sent by the access user received by the corresponding preliminary detection network node; Extract the data packet source IP, data packet source port, data packet destination IP, data packet destination port and data packet sending protocol corresponding to each session data packet, and summarize them into a data packet five-tuple; Identify timestamps of multiple session data packets, read the sending times of the multiple session data packets, and arrange the session data packets in descending order of timestamps; Obtain the transmission start time and transmission completion time of the corresponding data packet according to the timestamp of the session data packet; obtain the transmission duration of the corresponding session data packet by subtracting the transmission start time of the same session data packet from the transmission completion time; Identify the packet volume of the session data packet, and obtain the transmission rate by dividing the packet volume by the transmission duration of the corresponding session data packet. Subtract the transmission completion time of the previous data packet from the transmission start time of the current data packet to obtain the inter-packet waiting time of the current data packet; use the inter-packet waiting time and the transmission rate as the time characteristics of the corresponding session.
4. The network security collaborative integrated analysis system based on multimodal processing according to claim 1 is characterized in that: The working process of the network analysis unit is as follows: Acquire multiple data packet quintuples and obtain the data packet sending source IP, data packet sending source port, data packet destination IP, data packet destination port and data packet sending protocol of the corresponding session data packet; If the source IP of the data packet is on the IP blacklist or the source port of the data packet is on the port blacklist, the corresponding session data packet will be marked as a dangerous file and deleted; if the source IP of the data packet is not on the IP blacklist and the source port of the data packet is not on the port blacklist, proceed to the subsequent steps; Identify the node IP and node port corresponding to the prepared detection network node; Compare the node IP with the destination IP of the data packet. If the node IP is the same as the destination IP of the data packet, proceed to the next step. If the node IP is different from the destination IP of the data packet, increase the abnormal IP operand of the source IP of the data packet by one.
5. The network security collaborative integrated analysis system based on multimodal processing according to claim 4 is characterized in that: The working process of the network analysis unit also includes: Match the node port with the destination port of the data packet. If the node port contains the destination port of the data packet, proceed to the next step. If the node port does not contain the destination port of the data packet, increase the abnormal port operand of the source port of the data packet by one. Similarly, perform the above operations on the packet quintuples of all session packets; Count the total number of abnormal IP operations of all sending source IPs and the total number of abnormal port operations of all sending source ports; The total number of abnormal IP operations and the total number of abnormal port operations are compared with the corresponding thresholds respectively. If either the total number of abnormal IP operations or the total number of abnormal port operations is greater than or equal to the corresponding threshold, the corresponding IP address or port number is added to the blacklist and the session data packets received in this session are cleared; if the total number of abnormal IP operations or the total number of abnormal port operations are both less than the corresponding threshold, no action is taken.
6. The network security collaborative integrated analysis system based on multimodal processing according to claim 1 is characterized in that: The working process of the conversation analysis unit specifically includes: Obtain the time characteristics of the session data packets to obtain the inter-packet waiting time and transmission rate; add the inter-packet waiting time of all session data packets and take the average value to obtain the mean inter-packet waiting time; Based on the mean and inter-packet waiting times, the standard deviation of the inter-packet waiting time of the session data packets is calculated; The first cutoff value is obtained by subtracting the standard deviation of the inter-packet waiting time from the mean inter-packet waiting time, and the second cutoff value is obtained by adding the standard deviation of the inter-packet waiting time to the mean inter-packet waiting time. The first cutoff value is used as the left endpoint and the second cutoff value is used as the right endpoint to obtain the filtering range of the inter-packet waiting time corresponding to the session data packets, and the inter-packet waiting time outside the filtering range is discarded. The remaining packet waiting times are added and averaged to obtain the mean waiting time between denoised packets. The average waiting time between denoised packets is compared with the average waiting time threshold between packets. If the average waiting time between denoised packets is less than the average waiting time threshold between packets, a frequency anomaly signal is generated. If the average waiting time between packets is greater than or equal to the average waiting time threshold between packets, the subsequent steps are carried out. The transmission rates of the remaining session data packets are summed and averaged to obtain the average transmission rate. The average transmission rate is compared with the average transmission rate threshold. If the average transmission rate is greater than or equal to the average transmission rate threshold, a rate anomaly signal is generated. If the average transmission rate is less than the average transmission rate threshold, the subsequent steps are performed. If both frequency anomaly signals and rate anomaly signals exist, the source IP address corresponding to the session data packet is added to the blacklist; otherwise, no action is taken.
7. The network security collaborative integrated analysis system based on multimodal processing according to claim 1 is characterized in that: The analysis process of the log analysis module is as follows: Obtain session log data and extract session login logs from the session log data; obtain the start and end time of access by the accessing user based on the session login logs; Extracting multiple system logs with timestamps between the start access time and the end access time; Read the target file accessed by the access user based on the system log, and then obtain the file access path, file access count and file access duration of the target file; Read the historical system logs of the target file within seven days as a training set, and obtain the historical access path, historical access count, and historical access duration corresponding to the target file based on the historical system logs; Count the types of historical access paths. If only one exists, use the corresponding historical access path as the access path baseline. If multiple exist, retain the historical access path with the most occurrences and discard the remaining historical access paths and corresponding historical system logs. Add up all the historical access times and take the average to get the mean historical access time of the target file, and then calculate the standard deviation of the historical access time corresponding to the mean historical access time; Match the file access path of the target file with the access path baseline; If the file access path is different from the access path baseline, the file access path of the target file is deemed abnormal; If the file access path is the same as the access path baseline, the file access path of the target file is deemed normal and the process proceeds to the next step.
8. The network security collaborative integrated analysis system based on multimodal processing according to claim 1 is characterized in that: The analysis process of the log analysis module also includes: Calculate the access time deviation of the target file; Construct the normal interval standard, offset interval standard and abnormal interval standard corresponding to the access time deviation; Count the normal times that the target file appears in the normal interval, the offset times that it appears in the offset interval, and the abnormal times that it appears in the abnormal interval; If the number of exceptions is greater than or equal to one, the access duration is considered abnormal; if the number of exceptions is less than one, the abnormal value of the access duration of the target file is calculated; The access time abnormal value is compared with the access time abnormal threshold. If the access time abnormal value is greater than or equal to the access time abnormal threshold, the access time is considered abnormal; if the access time abnormal value is less than the access time abnormal threshold, the access time is considered normal. If both the file access path and the file access duration are normal, no operation will be performed; if either the file access path or the file access duration is abnormal, the target file access operation will be judged as corresponding to the existence of attack intent; Similarly, all target files are judged for the existence of attack intentions. If any target file is accessed with attack intentions, the IP address corresponding to the accessing user will be added to the blacklist. Otherwise, no action will be taken.
9. The network security collaborative integrated analysis system based on multimodal processing according to claim 8 is characterized in that: The process of determining whether an access has an attack intent is as follows: Get the target file and obtain the original sequence of the target file; The original sequence is appended with a bit "1" and then filled with K zeros to obtain the processed sequence; Convert the original sequence into 64-bit binary form, and then concatenate it with the processed sequence to obtain the calculated sequence; Split the calculation sequence into n 64-byte calculation subsequences; select the first 32 digits of the decimal part of the square root of the first eight prime numbers in natural numbers, convert them into hexadecimal representation to obtain eight initial check values, and use the eight initial check values as the initial values of the first check value to the eighth check value in sequence; Sequentially appending the first to eighth check values to the first to eighth intermediate variables; wherein the initial values of the first to eighth intermediate variables are all 0; an update function for updating the first intermediate variable to the eighth update variable; Add the updated first intermediate variable to the initial first check value to obtain an updated value of the first check value; similarly, obtain updated values of the second to eighth check values; Iterate the operation for n or more times to obtain the final first to eighth check values, and concatenate the first to eighth check values to obtain the file integrity check value of the target file corresponding to the initial state; Similarly, calculate the file integrity check value of the target file after it is accessed; If the file integrity check value in the initial state is inconsistent with the file integrity check value after being accessed, it is determined that the access operation of the target file has an attack intention; otherwise, it is determined that the access operation of the target file has no attack intention and the operation is not performed.
10. A network security collaborative integrated analysis method based on multimodal processing, characterized by: In combination with the network security collaborative integrated analysis system based on multimodal processing according to any one of claims 1 to 9, the method includes: Step S101, collecting session access data and session log data of the corresponding session of the access user; Step S102: extracting session access data and different types of data in the session access data, extracting and classifying them to obtain a data packet quintuple and time features; Step S103: judging the security of the corresponding preliminary detection network node based on the data packet quintuple and time characteristics, and then adding the access user corresponding to the session data packet to the blacklist; Step S104: judging the security of the prepared detection network node in combination with the session log data, and obtaining a newly added blacklist.
Citation Information
Patent Citations
Flow-based abnormal communication behavior detection method and system
CN110149343A
Login information obtaining and blocking method based on eBPF XDP
CN116055163A
Multi-source log data association analysis method for security service
CN119835040A
Blacklisting of unlicensed mobile access (UMA) users via AAA policy database
US20080220740A1