Method and system for network traffic abnormity supervision and protection
By collecting and analyzing network traffic data in real time and utilizing preset supervision rules and hierarchical protection models, the problems of low accuracy and high missed reporting rate in existing network traffic monitoring technologies are solved, efficient anomaly identification and security enhancement are achieved, and the network's security protection level is improved.
Patent Information
- Application Number
- CN202511180645.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-22
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2045-08-22
AI Technical Summary
Existing network traffic monitoring methods have low accuracy and high false negative rates, and are unable to effectively identify unknown attacks, making network recovery difficult and posing serious security threats.
By collecting network traffic data in real time, identifying response behaviors and execution objects, using preset supervision rules to identify anomalies, building a hierarchical protection model, performing hierarchical optimization and retrospective analysis, eliminating abnormal features, and performing security enhancement processing.
It improves network security, reduces anomalies, enhances the ability to identify unknown attacks, ensures network business continuity, enhances the ability to resist similar anomalies, and achieves continuous improvement in network security protection.
Smart Images

Figure CN120729630A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security supervision, and in particular to a method and system for monitoring and protecting network traffic anomaly. Background Art
[0002] With the rapid development of the internet, cyberattacks are becoming increasingly frequent. Attackers employ various attack methods, disrupting normal network services. This often leads to network downtime, data leaks, and privacy breaches, among other malicious activities. Furthermore, the inability to quickly identify the attacker's attack methods makes network recovery difficult, posing a serious threat to network security. Traditional network traffic monitoring methods often rely on single rule matching or simple threshold judgments. While this approach can limit the amount of information attackers can obtain, it suffers from low measurement accuracy, a high false negative rate, and a weak ability to identify unknown attacks. Furthermore, it is unable to accurately track the attacker's attack methods, placing the network at risk again. Therefore, effectively maintaining network security and remediating network vulnerabilities has become a pressing issue.
[0003] Therefore, the present invention provides a method and system for monitoring and protecting network traffic anomalies. Summary of the Invention
[0004] The present invention provides a method and system for monitoring and protecting network traffic anomalies, which can monitor and protect traffic data in the network in real time, thereby not only protecting network security but also promptly repairing defects in the network and reducing the occurrence of network anomalies.
[0005] The present invention provides a method for monitoring and protecting network traffic anomalies, comprising: Step 1: Collecting raw traffic data in the network in real time, and identifying the network response behavior and the corresponding traffic execution object corresponding to each raw traffic data; Step 2: using preset supervision rules to identify anomalies of the network response behavior and the traffic execution object, and obtaining a traffic anomaly level corresponding to each raw traffic data; Step 3: Based on the traffic anomaly level, the corresponding raw traffic data is input into a level protection model for anomaly optimization to eliminate the abnormal features of each raw traffic data; Step 4: Perform a retrospective analysis on the original traffic data according to the abnormal characteristics to obtain the abnormal cause corresponding to the original traffic data, and perform corresponding security enhancement processing on the network according to the abnormal cause.
[0006] In one practicable manner, The step 1 comprises: Step 11: synchronously collecting mirrored traffic on the network to obtain real-time mirrored data in the network, obtaining a plurality of mirrored data values contained in the real-time mirrored data, constructing a visual histogram of the real-time mirrored data, identifying curve features of the visual histogram, and determining a probability distribution rule for the real-time mirrored data; Step 12: constructing a data distribution graph of the real-time mirror data using the probability distribution rule, and determining a plurality of data distribution areas of the real-time mirror data and data volume information corresponding to each of the data distribution areas in the data distribution graph; Step 13: constructing a mirror flip rule for the real-time mirror data based on the regional position relationship between different data distribution areas, and using the mirror flip rule to flip the corresponding data volume information in each data distribution area to obtain the original traffic data of the network; Step 14: Perform behavioral analysis on each of the original traffic data to obtain the response behavior of the original traffic data of the network, and perform performance analysis on each of the response behaviors to obtain the traffic execution object corresponding to the original traffic data.
[0007] In one practicable manner, The step 14 includes: Step 141: Determine the IP address and protocol type of the traffic source based on the raw traffic data, filter historical traffic data for the same IP address, and when the historical traffic data and the raw traffic data exhibit a continuous pattern, connect the historical traffic data with the raw traffic data based on the protocol type to generate output traffic data for the IP address. Step 142: Identify multiple access locations of the output traffic data in the network, construct an access behavior corresponding to each access location based on data information contained in the output traffic data, and identify the network's response to each access behavior to obtain multiple response behaviors of the network to the original traffic data; Step 143: Perform performance analysis on each of the response behaviors respectively to obtain a behavior result corresponding to each of the access behaviors, and construct a result endpoint included in the behavior result to determine a traffic execution object corresponding to the original traffic data.
[0008] In one practicable manner, The step 2 comprises: Step 21: Obtain updated network security regulations from the big data, use the updated network security regulations to adjust existing supervision rules to generate preset supervision rules, identify multiple independent rules included in the preset supervision rules, and establish the supervision focus of the preset supervision rules based on the rule requirements corresponding to each independent rule; Step 22: Analyzing each of the network response behaviors and the traffic execution objects using the preset supervision rules to obtain a plurality of first supervision results for each of the network response behaviors and a plurality of second supervision results for each of the traffic execution objects; Step 23: Filtering a plurality of first supervision results of targets that do not match the supervision focus, constructing a first abnormal feature of the network response behavior, filtering a plurality of second supervision results of targets that do not match the supervision focus, and constructing a second abnormal feature of the traffic execution object; Step 24: Determine a first abnormality level of the network response behavior based on the first supervision result, determine a second abnormality level of the traffic execution object based on the second supervision result, and perform abnormal superposition on the target first supervision result and the target second supervision result based on the first abnormality level and the second abnormality level to obtain the traffic abnormality level corresponding to the original traffic data.
[0009] In one practicable manner, The step 3 comprises: Step 31: Inputting the corresponding raw traffic data into the corresponding model layer of the hierarchical protection model according to the traffic anomaly level, identifying the abnormal pattern of the raw traffic data at the model layer, and identifying several optimization methods of the abnormal pattern in the big data; Step 32: In the model layer, each optimization method is used to perform optimization simulation on the original traffic data to obtain the optimization defects and optimization advantages corresponding to each optimization method, select the target optimization method with the smallest optimization defect, and match each optimization advantage with the target optimization defect of the target optimization method to obtain the compensation optimization method of the target optimization method; Step 33: Use the compensation optimization method to compensate for the defects of the target optimization method to obtain the protection optimization method of the original traffic data, identify several abnormal features of the original traffic data in the model layer, and use the protection optimization method to optimize the original traffic data in the model layer until the original traffic data does not contain abnormal features.
[0010] In one practicable manner, Also includes: When the traffic anomaly level belongs to a high-risk anomaly level, the original traffic data is divided into a plurality of sub-data segments, and the segment anomaly level corresponding to each sub-data segment is identified; Each of the sub-data segments is input into a corresponding model layer according to the segment abnormality level for abnormality optimization.
[0011] In one practicable manner, The step 4 comprises: Step 41: identifying an abnormal data segment corresponding to each abnormal feature in the original traffic data, performing enhancement processing on each abnormal data segment, and obtaining a data weight of each abnormal data segment in the original traffic data; Step 42: setting a corresponding dimensionality reduction number for each abnormal data segment according to the data weight, performing dimensionality reduction processing on the corresponding abnormal data segment according to the dimensionality reduction number, obtaining key information of each abnormal data segment, and tracking the key information in the network; Step 43: Based on the tracing path corresponding to each key information, construct the abnormal cause corresponding to the abnormal traffic data, expand the abnormal cause in the network, obtain the network-related node of the abnormal cause, and enhance each of the network-related nodes according to the abnormal cause until the abnormal cause is eliminated in the network.
[0012] In one practicable manner, Also includes: Obtaining historical anomaly level reports of the network and extracting anomaly level content from big data; Constructing a model hierarchical framework based on the historical anomaly reports and the anomaly level content; According to the abnormality level, corresponding data processing functions and data optimization functions are added to the corresponding model layer to generate a hierarchical protection model of the network.
[0013] The present invention provides a system for monitoring and protecting network traffic anomalies, comprising: A data processing module is used to collect raw traffic data in the network in real time, and respectively identify the network response behavior and the corresponding traffic execution object corresponding to each piece of raw traffic data; an anomaly identification module, configured to identify anomalies of the network response behavior and the traffic execution object respectively using preset supervision rules, and obtain a traffic anomaly level corresponding to each of the raw traffic data; An abnormality optimization module, configured to input the corresponding raw traffic data into a level protection model based on the traffic abnormality level to perform abnormality optimization and eliminate abnormal features of each raw traffic data; The enhancement elimination module is used to perform a retrospective analysis on the original traffic data according to the abnormal characteristics, obtain the abnormal cause corresponding to the original traffic data, and perform corresponding security enhancement processing on the network according to the abnormal cause.
[0014] In one practicable manner, The data processing module includes: a rule construction unit, configured to synchronously collect mirrored traffic on the network to obtain real-time mirrored data in the network, obtain a plurality of mirrored data values contained in the real-time mirrored data, construct a visual histogram of the real-time mirrored data, identify curve features of the visual histogram, and determine a probability distribution rule for the real-time mirrored data; a data processing unit, configured to construct a data distribution graph of the real-time mirror data using the probability distribution rule, and determine, in the data distribution graph, a plurality of data distribution areas of the real-time mirror data and data volume information corresponding to each of the data distribution areas; a mirror flipping unit, configured to construct a mirror flipping rule for the real-time mirror data according to the regional position relationship between different data distribution areas, and flip the corresponding data volume information in each data distribution area using the mirror flipping rule to obtain the original traffic data of the network; The behavior analysis unit is used to perform behavior analysis on each of the original traffic data to obtain the response behavior of the original traffic data of the network, and to perform performance analysis on each of the response behaviors to obtain the traffic execution object corresponding to the original traffic data.
[0015] The achievable beneficial effects of the above technical solution are: in order to improve the security of the network and reduce the number of network anomalies, the network response behavior and traffic execution objects in the network are first determined by synchronously collecting the original traffic data in the network, providing a more comprehensive basis for subsequent anomaly identification, and then using preset supervision rules to synchronously supervise the network response behavior and traffic execution objects, and determine the traffic anomaly level of the original traffic data. Then, based on the traffic anomaly level, the corresponding level protection model is matched to achieve hierarchical protection, and a more stringent optimization strategy is adopted for high-level anomalies, and a relatively mild processing method is adopted for low-level anomalies. It can not only efficiently eliminate the abnormal characteristics of different levels, but also minimize the interference with normal network traffic and ensure the continuity of network services. Finally, through retrospective analysis, the cause of the anomaly is excavated and security enhancement processing is performed. In this way, not only the current anomaly problem can be solved, but also network security vulnerabilities can be made up from the root, and the network's resistance to similar anomalies can be improved, the level of network security protection can be continuously improved, and the ever-changing network security threats can be effectively responded to.
[0016] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purpose and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the written description and the accompanying drawings.
[0017] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings: Figure 1 A schematic diagram of a workflow of a method for monitoring and protecting network traffic anomalies according to an embodiment of the present invention; Figure 2 The present invention is a schematic diagram of a system for monitoring and protecting network traffic anomalies according to an embodiment of the present invention. DETAILED DESCRIPTION
[0019] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention and are not used to limit the present invention.
[0020] Example 1: This embodiment provides a method for monitoring and protecting network traffic anomalies. Figure 1 Shown, including: Step 1: Collecting raw traffic data in the network in real time, and identifying the network response behavior and the corresponding traffic execution object corresponding to each raw traffic data; Step 2: using preset supervision rules to identify anomalies of the network response behavior and the traffic execution object, and obtaining a traffic anomaly level corresponding to each raw traffic data; Step 3: Based on the traffic anomaly level, the corresponding raw traffic data is input into a level protection model for anomaly optimization to eliminate the abnormal features of each raw traffic data; Step 4: Perform a retrospective analysis on the original traffic data according to the abnormal characteristics to obtain the abnormal cause corresponding to the original traffic data, and perform corresponding security enhancement processing on the network according to the abnormal cause.
[0021] In this instance, the network response behavior represents the behavior corresponding to the original traffic data; In this instance, the traffic execution object represents the object on which the raw traffic data acts; In this example, the purpose of simultaneously monitoring network response behavior and traffic execution objects is to: avoid the one-sidedness that may exist in single-dimensional analysis; In this example, the traffic anomaly level represents the anomaly level of the original traffic data; In this example, the hierarchical protection model represents a model that optimizes protection for raw traffic data of different traffic anomaly levels; In this example, retrospective analysis refers to the analysis process of finding the cause of anomalies in the original traffic data; In this example, the security enhancement process refers to a process of eliminating the cause of abnormality in the network.
[0022] The working principle and beneficial effects of the above technical solution: In order to improve the security of the network and reduce the number of network anomalies, the network response behavior and traffic execution object in the network are first determined by synchronously collecting the original traffic data in the network, providing a more comprehensive basis for subsequent anomaly identification. Then, the preset supervision rules are used to synchronously supervise the network response behavior and traffic execution object, and the traffic anomaly level of the original traffic data is determined. Then, based on the traffic anomaly level, the corresponding level protection model is matched to achieve hierarchical protection. A stricter optimization strategy is adopted for high-level anomalies, and a relatively mild processing method is adopted for low-level anomalies. It can not only efficiently eliminate the abnormal characteristics of different levels, but also minimize the interference with normal network traffic and ensure the continuity of network services. Finally, through retrospective analysis, the cause of the anomaly is excavated and security enhancement processing is performed. In this way, not only the current anomaly problem can be solved, but also network security vulnerabilities can be made up from the root, and the network's resistance to similar anomalies can be improved, the level of network security protection can be continuously improved, and the ever-changing network security threats can be effectively responded to.
[0023] Example 2: Based on Example 1, the method for monitoring and protecting network traffic anomaly, step 1, includes: Step 11: synchronously collecting mirrored traffic on the network to obtain real-time mirrored data in the network, obtaining a plurality of mirrored data values contained in the real-time mirrored data, constructing a visual histogram of the real-time mirrored data, identifying curve features of the visual histogram, and determining a probability distribution rule for the real-time mirrored data; Step 12: constructing a data distribution graph of the real-time mirror data using the probability distribution rule, and determining a plurality of data distribution areas of the real-time mirror data and data volume information corresponding to each of the data distribution areas in the data distribution graph; Step 13: constructing a mirror flip rule for the real-time mirror data based on the regional position relationship between different data distribution areas, and using the mirror flip rule to flip the corresponding data volume information in each data distribution area to obtain the original traffic data of the network; Step 14: Perform behavioral analysis on each of the original traffic data to obtain the response behavior of the original traffic data of the network, and perform performance analysis on each of the response behaviors to obtain the traffic execution object corresponding to the original traffic data.
[0024] In this example, real-time mirror data represents a mirrored representation of existing data on the network. The purpose of collecting mirror data is: first, to ensure the authenticity and integrity of the original data; second, to minimize the impact on the normal operation of the network; In this example, the mirror data value represents the data value contained in the real-time mirror data; In this example, the probability distribution rule represents the distribution rule of the mirror data value in the real-time mirror data, including: discrete probability distribution, continuous probability distribution, normal distribution, Bernoulli distribution, binomial distribution, uniform distribution, Poisson distribution, exponential distribution, etc.; In this example, the data distribution graph represents a result of expressing the distribution of mirror data values in the real-time mirror data in a graphical manner; In this example, the data distribution region represents a region in the data distribution graph that contains mirror data values; In this example, the mirror flip rule is used to restore mirrored data. This rule is not a supervised flip. The flipping process involves flipping each data distribution area separately. The positional relationship between the flipped results is then determined based on the real-time mirrored data. This is then rearranged to obtain the original traffic data. In this example, behavior analysis represents the execution behavior corresponding to the original traffic data, and performance analysis represents the function presented by the response behavior.
[0025] The working principle and beneficial effects of the above technical solution are as follows: real-time mirror data is obtained through mirror traffic collection, and the probability distribution rules are determined by combining the curve feature analysis of the visual histogram to intuitively reflect the inherent distribution law of the data, so as to match the corresponding probability distribution rules for the real-time mirror data. Then, based on the probability distribution rules, a data distribution map is constructed and the data distribution area is divided, so as to present the distribution of data in different intervals and the corresponding data volume. Then, according to the regional position relationship, a mirror flipping rule is constructed and the data volume information is flipped to obtain the original traffic data, so as to restore the real traffic situation in the network to the greatest extent, reduce information loss in the data collection and processing process, and ensure the integrity of the original traffic data. Finally, through behavior analysis and performance analysis, the response behavior and traffic execution object are respectively obtained, which realizes the accurate extraction from the original traffic data to the key features, provides a specific and clear analysis object for subsequent anomaly identification, ensures the pertinence and effectiveness of anomaly supervision and protection, and makes the starting point of the entire protection process more accurate and reliable.
[0026] Example 3: Based on Example 2, the method for monitoring and protecting network traffic anomaly, step 14, includes: Step 141: Determine the IP address and protocol type of the traffic source based on the raw traffic data, filter historical traffic data for the same IP address, and when the historical traffic data and the raw traffic data exhibit a continuous pattern, connect the historical traffic data with the raw traffic data based on the protocol type to generate output traffic data for the IP address. Step 142: Identify multiple access locations of the output traffic data in the network, construct an access behavior corresponding to each access location based on data information contained in the output traffic data, and identify the network's response to each access behavior to obtain multiple response behaviors of the network to the original traffic data; Step 143: Perform performance analysis on each of the response behaviors respectively to obtain a behavior result corresponding to each of the access behaviors, and construct a result endpoint included in the behavior result to determine a traffic execution object corresponding to the original traffic data.
[0027] In this example, when the historical traffic data and the original traffic data present a continuous feature, it indicates that the original traffic data and the historical traffic data have the same source and are continuous data; In this example, the data information represents data presented in the output traffic data when an access location is accessed.
[0028] The working principle and beneficial effects of the above technical solution are as follows: First, by screening the historical traffic data of the same IP address, combining the continuous features and protocol type docking to generate output traffic data, the scattered original traffic and historical data are associated into a complete traffic sequence, and the continuous interaction process of the same IP at different times is fully captured. Then, based on the output traffic data, the access location is identified, and the access behavior corresponding to each location is constructed, and then combined with the network's response to these behaviors, finally, the behavior results are obtained by analyzing the performance of the response behavior, and the traffic execution object is determined from the result endpoint to ensure that anomaly identification can focus on specific behaviors and objects, thereby making subsequent level protection and retrospective analysis more targeted, thereby improving the effectiveness of the entire network traffic anomaly supervision and protection system from the source.
[0029] Example 4: Based on Example 1, the method for monitoring and protecting network traffic anomaly, step 2, includes: Step 21: Obtain updated network security regulations from the big data, use the updated network security regulations to adjust existing supervision rules to generate preset supervision rules, identify multiple independent rules included in the preset supervision rules, and establish the supervision focus of the preset supervision rules based on the rule requirements corresponding to each independent rule; Step 22: Analyzing each of the network response behaviors and the traffic execution objects using the preset supervision rules to obtain a plurality of first supervision results for each of the network response behaviors and a plurality of second supervision results for each of the traffic execution objects; Step 23: Filtering a plurality of first supervision results of targets that do not match the supervision focus, constructing a first abnormal feature of the network response behavior, filtering a plurality of second supervision results of targets that do not match the supervision focus, and constructing a second abnormal feature of the traffic execution object; Step 24: Determine a first abnormality level of the network response behavior based on the first supervision result, determine a second abnormality level of the traffic execution object based on the second supervision result, and perform abnormal superposition on the target first supervision result and the target second supervision result based on the first abnormality level and the second abnormality level to obtain the traffic abnormality level corresponding to the original traffic data.
[0030] In this example, the existing supervision rules represent the currently used supervision rules. Whenever updated cybersecurity regulations appear in big data, the existing supervision rules are automatically updated and preset supervision rules are generated. This ensures that the rules can keep up with new requirements and new standards in the field of cybersecurity, avoiding the omission of new network threats due to lagging rules. In this instance, supervision focuses on the supervision content when independent rules supervise network response behaviors and traffic execution objects; In this example, the first supervision result represents the result obtained when supervising the network response behavior, and the second supervision result represents the result obtained when performing comparative supervision on the traffic; In this example, the first abnormality level indicates the abnormality level of the network response behavior, and the second abnormality level indicates the abnormality level of the traffic execution object. The working principle and beneficial effects of the above technical solution are as follows: In order to achieve efficient supervision, the first task is to determine the traffic anomaly level of the original traffic data. First, the existing rules are adjusted in combination with the updated network security regulations in big data to generate preset supervision rules. Then, the network response behavior and traffic execution object are analyzed separately to obtain the first supervision result and the second supervision result. The target results that do not match the supervision focus are screened out, and the first and second anomaly features are constructed to achieve the purpose of accurately locating anomalies from complex data. This object-based and dimension-based analysis method reduces the interference of irrelevant information, making the identification of anomaly features more accurate and reliable. The final traffic anomaly level is obtained by further determining the first and second anomaly levels and superimposing the anomalies. This avoids the one-sidedness that may exist in single-dimensional judgments and can more comprehensively reflect the degree of anomaly in the original traffic data, laying a solid foundation for subsequent protection work.
[0031] Example 5: Based on Example 1, the method for monitoring and protecting network traffic anomaly, step 3, includes: Step 31: Inputting the corresponding raw traffic data into the corresponding model layer of the hierarchical protection model according to the traffic anomaly level, identifying the abnormal pattern of the raw traffic data at the model layer, and identifying several optimization methods of the abnormal pattern in the big data; Step 32: In the model layer, each optimization method is used to perform optimization simulation on the original traffic data to obtain the optimization defects and optimization advantages corresponding to each optimization method, select the target optimization method with the smallest optimization defect, and match each optimization advantage with the target optimization defect of the target optimization method to obtain the compensation optimization method of the target optimization method; Step 33: Use the compensation optimization method to compensate for the defects of the target optimization method to obtain the protection optimization method of the original traffic data, identify several abnormal features of the original traffic data in the model layer, and use the protection optimization method to optimize the original traffic data in the model layer until the original traffic data does not contain abnormal features.
[0032] In this instance, the abnormal pattern represents the pattern presented when the original traffic data is abnormal; In this example, the optimization method refers to the method used to eliminate anomalies in the original traffic data; In this example, the optimization defect indicates the defective content presented after the original traffic data is optimized using the optimization method, and the optimization advantage indicates the optimal optimization content presented after the original traffic data is optimized using the optimization direction.
[0033] The working principle and beneficial effects of the above technical solution are as follows: first, the original traffic data is input into the corresponding model layer according to the traffic anomaly level, so that anomalies of different levels can be adaptively processed, avoiding blind optimization and improving the accuracy of the optimization direction. Then, by simulating different optimization methods, analyzing their optimization defects and strengths, screening out the target optimization method with the smallest optimization defects, and combining the strengths of other methods to compensate for the defects, forming a more complete protection optimization method, reducing the residual anomalies caused by incomplete optimization, and further using the protection optimization method to continuously optimize the original traffic data until there are no abnormal features, ensuring that the abnormal features are completely eliminated and avoiding the recurrence of anomalies caused by partial optimization. In this way, complete elimination can be achieved, which provides a strong guarantee for the security of network traffic and creates good conditions for subsequent retrospective analysis and security enhancement processing.
[0034] Example 6: Based on Example 5, the method for monitoring and protecting against network traffic anomalies further includes: When the traffic anomaly level belongs to a high-risk anomaly level, the original traffic data is divided into a plurality of sub-data segments, and the segment anomaly level corresponding to each sub-data segment is identified; Each of the sub-data segments is input into a corresponding model layer according to the segment abnormality level for abnormality optimization.
[0035] The working principle and beneficial effects of the above technical solution are as follows: when the original traffic data belongs to a high-risk anomaly level, it is divided into several sub-data segments and anomaly optimization is performed separately, thereby improving the optimization efficiency while ensuring the optimization quality and ensuring the security of the network environment.
[0036] Example 7: Based on Example 1, the method for monitoring and protecting network traffic anomaly, step 4, includes: Step 41: identifying an abnormal data segment corresponding to each abnormal feature in the original traffic data, performing enhancement processing on each abnormal data segment, and obtaining a data weight of each abnormal data segment in the original traffic data; Step 42: setting a corresponding dimensionality reduction number for each abnormal data segment according to the data weight, performing dimensionality reduction processing on the corresponding abnormal data segment according to the dimensionality reduction number, obtaining key information of each abnormal data segment, and tracking the key information in the network; Step 43: Based on the tracing path corresponding to each key information, construct the abnormal cause corresponding to the abnormal traffic data, expand the abnormal cause in the network, obtain the network-related node of the abnormal cause, and enhance each of the network-related nodes according to the abnormal cause until the abnormal cause is eliminated in the network.
[0037] In this example, the data weight indicates the importance of the abnormal data segment in the original traffic data; In this example, the dimensionality reduction is related to the data weight. The larger the data weight, the larger the dimensionality reduction. The dimensionality reduction corresponding to the abnormal data segment with the largest data weight is the same as the dimension of the abnormal data segment, and the remaining abnormal data segments are all smaller than this dimension. In this example, the network-related node represents a network node associated with the abnormal cause.
[0038] The working principle and beneficial effects of the above technical solution: By identifying the abnormal data segments corresponding to the abnormal features and assigning data weights, the importance of key abnormal information can be highlighted to avoid being interfered with by irrelevant information in massive data. Then, the dimensionality reduction dimension is set for the abnormal data segments according to the data weights and dimensionality reduction processing is performed. While retaining the core information, the complexity of the data is simplified and the key information is extracted. Finally, the cause of the abnormality is constructed by tracking the path, and the network-related nodes are found by expanding the cause of the abnormality. These nodes are enhanced until the cause of the abnormality is eliminated. In this way, the current abnormality can be handled, and the related potential risk points can be checked and strengthened to avoid the abnormal cause from recurring in other nodes of the network, thereby improving the network's security protection capabilities as a whole.
[0039] Example 8: Based on Example 1, the method for monitoring and protecting against network traffic anomalies further includes: Obtaining historical anomaly level reports of the network and extracting anomaly level content from big data; Constructing a model hierarchical framework based on the historical anomaly reports and the anomaly level content; According to the abnormality level, corresponding data processing functions and data optimization functions are added to the corresponding model layer to generate a hierarchical protection model of the network.
[0040] The working principle and beneficial effects of the above technical solution are as follows: abnormal supervision is achieved by building a model, and the model is constantly updated with the progress of the times, ensuring the effectiveness of supervision and improving the quality of supervision.
[0041] Example 9: This embodiment provides a system for monitoring and protecting network traffic anomalies. Figure 2 Shown, including: A data processing module is used to collect raw traffic data in the network in real time, and respectively identify the network response behavior and the corresponding traffic execution object corresponding to each piece of raw traffic data; an anomaly identification module, configured to identify anomalies of the network response behavior and the traffic execution object respectively using preset supervision rules, and obtain a traffic anomaly level corresponding to each of the raw traffic data; An abnormality optimization module, configured to input the corresponding raw traffic data into a level protection model based on the traffic abnormality level to perform abnormality optimization and eliminate abnormal features of each raw traffic data; The enhancement elimination module is used to perform a retrospective analysis on the original traffic data according to the abnormal characteristics, obtain the abnormal cause corresponding to the original traffic data, and perform corresponding security enhancement processing on the network according to the abnormal cause.
[0042] In this instance, the network response behavior represents the behavior corresponding to the original traffic data; In this instance, the traffic execution object represents the object on which the raw traffic data acts; In this example, the purpose of simultaneously monitoring network response behavior and traffic execution objects is to: avoid the one-sidedness that may exist in single-dimensional analysis; In this example, the traffic anomaly level represents the anomaly level of the original traffic data; In this example, the hierarchical protection model represents a model that optimizes protection for raw traffic data of different traffic anomaly levels; In this example, retrospective analysis refers to the analysis process of finding the cause of anomalies in the original traffic data; In this example, the security enhancement process refers to a process of eliminating the cause of abnormality in the network.
[0043] The working principle and beneficial effects of the above technical solution: In order to improve the security of the network and reduce the number of network anomalies, the network response behavior and traffic execution object in the network are first determined by synchronously collecting the original traffic data in the network, providing a more comprehensive basis for subsequent anomaly identification. Then, the preset supervision rules are used to synchronously supervise the network response behavior and traffic execution object, and the traffic anomaly level of the original traffic data is determined. Then, based on the traffic anomaly level, the corresponding level protection model is matched to achieve hierarchical protection. A stricter optimization strategy is adopted for high-level anomalies, and a relatively mild processing method is adopted for low-level anomalies. It can not only efficiently eliminate the abnormal characteristics of different levels, but also minimize the interference with normal network traffic and ensure the continuity of network services. Finally, through retrospective analysis, the cause of the anomaly is excavated and security enhancement processing is performed. In this way, not only the current anomaly problem can be solved, but also network security vulnerabilities can be made up from the root, and the network's resistance to similar anomalies can be improved, the level of network security protection can be continuously improved, and the ever-changing network security threats can be effectively responded to.
[0044] Example 10: On the basis of Example 9, the system for monitoring and protecting network traffic anomalies, the data processing module includes: a rule construction unit, configured to synchronously collect mirrored traffic on the network to obtain real-time mirrored data in the network, obtain a plurality of mirrored data values contained in the real-time mirrored data, construct a visual histogram of the real-time mirrored data, identify curve features of the visual histogram, and determine a probability distribution rule for the real-time mirrored data; a data processing unit, configured to construct a data distribution graph of the real-time mirror data using the probability distribution rule, and determine, in the data distribution graph, a plurality of data distribution areas of the real-time mirror data and data volume information corresponding to each of the data distribution areas; a mirror flipping unit, configured to construct a mirror flipping rule for the real-time mirror data according to the regional position relationship between different data distribution areas, and flip the corresponding data volume information in each data distribution area using the mirror flipping rule to obtain the original traffic data of the network; The behavior analysis unit is used to perform behavior analysis on each of the original traffic data to obtain the response behavior of the original traffic data of the network, and to perform performance analysis on each of the response behaviors to obtain the traffic execution object corresponding to the original traffic data.
[0045] In this example, real-time mirror data represents a mirrored representation of existing data on the network. The purpose of collecting mirror data is: first, to ensure the authenticity and integrity of the original data; second, to minimize the impact on the normal operation of the network; In this example, the mirror data value represents the data value contained in the real-time mirror data; In this example, the probability distribution rule represents the distribution rule of the mirror data value in the real-time mirror data, including: discrete probability distribution, continuous probability distribution, normal distribution, Bernoulli distribution, binomial distribution, uniform distribution, Poisson distribution, exponential distribution, etc.; In this example, the data distribution graph represents a result of expressing the distribution of mirror data values in the real-time mirror data in a graphical manner; In this example, the data distribution region represents a region in the data distribution graph that contains mirror data values; In this example, the mirror flip rule is used to restore mirrored data. This rule is not a supervised flip. The flipping process involves flipping each data distribution area separately. The positional relationship between the flipped results is then determined based on the real-time mirrored data. This is then rearranged to obtain the original traffic data. In this example, behavior analysis represents the execution behavior corresponding to the original traffic data, and performance analysis represents the function presented by the response behavior.
[0046] The working principle and beneficial effects of the above technical solution are as follows: real-time mirror data is obtained through mirror traffic collection, and the probability distribution rules are determined by combining the curve feature analysis of the visual histogram to intuitively reflect the inherent distribution law of the data, so as to match the corresponding probability distribution rules for the real-time mirror data. Then, based on the probability distribution rules, a data distribution map is constructed and the data distribution area is divided, so as to present the distribution of data in different intervals and the corresponding data volume. Then, according to the regional position relationship, a mirror flipping rule is constructed and the data volume information is flipped to obtain the original traffic data, so as to restore the real traffic situation in the network to the greatest extent, reduce information loss in the data collection and processing process, and ensure the integrity of the original traffic data. Finally, through behavior analysis and performance analysis, the response behavior and traffic execution object are respectively obtained, which realizes the accurate extraction from the original traffic data to the key features, provides a specific and clear analysis object for subsequent anomaly identification, ensures the pertinence and effectiveness of anomaly supervision and protection, and makes the starting point of the entire protection process more accurate and reliable.
[0047] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.
Claims
1. A method for monitoring and protecting network traffic anomalies, characterized in that: include: Step 1: Collecting raw traffic data in the network in real time, and identifying the network response behavior and the corresponding traffic execution object corresponding to each raw traffic data; Step 2: using preset supervision rules to identify anomalies of the network response behavior and the traffic execution object, and obtaining a traffic anomaly level corresponding to each raw traffic data; Step 3: Based on the traffic anomaly level, the corresponding raw traffic data is input into a level protection model for anomaly optimization to eliminate the abnormal features of each raw traffic data; Step 4: Perform a retrospective analysis on the original traffic data according to the abnormal characteristics to obtain the abnormal cause corresponding to the original traffic data, and perform corresponding security enhancement processing on the network according to the abnormal cause.
2. A method for monitoring and protecting network traffic anomalies according to claim 1, characterized in that: The step 1 comprises: Step 11: synchronously collecting mirrored traffic on the network to obtain real-time mirrored data in the network, obtaining a plurality of mirrored data values contained in the real-time mirrored data, constructing a visual histogram of the real-time mirrored data, identifying curve features of the visual histogram, and determining a probability distribution rule for the real-time mirrored data; Step 12: constructing a data distribution graph of the real-time mirror data using the probability distribution rule, and determining a plurality of data distribution areas of the real-time mirror data and data volume information corresponding to each of the data distribution areas in the data distribution graph; Step 13: constructing a mirror flip rule for the real-time mirror data based on the regional position relationship between different data distribution areas, and using the mirror flip rule to flip the corresponding data volume information in each data distribution area to obtain the original traffic data of the network; Step 14: Perform behavioral analysis on each of the original traffic data to obtain the response behavior of the original traffic data of the network, and perform performance analysis on each of the response behaviors to obtain the traffic execution object corresponding to the original traffic data.
3. A method for monitoring and protecting network traffic anomalies according to claim 2, characterized in that: The step 14 comprises: Step 141: Determine the IP address and protocol type of the traffic source based on the raw traffic data, filter historical traffic data for the same IP address, and when the historical traffic data and the raw traffic data exhibit a continuous pattern, connect the historical traffic data with the raw traffic data based on the protocol type to generate output traffic data for the IP address. Step 142: Identify multiple access locations of the output traffic data in the network, construct an access behavior corresponding to each access location based on data information contained in the output traffic data, and identify the network's response to each access behavior to obtain multiple response behaviors of the network to the original traffic data; Step 143: Perform performance analysis on each of the response behaviors respectively to obtain a behavior result corresponding to each of the access behaviors, and construct a result endpoint included in the behavior result to determine a traffic execution object corresponding to the original traffic data.
4. A method for monitoring and protecting network traffic anomalies according to claim 1, characterized in that: The step 2 comprises: Step 21: Obtain updated network security regulations from the big data, use the updated network security regulations to adjust existing supervision rules to generate preset supervision rules, identify multiple independent rules included in the preset supervision rules, and establish the supervision focus of the preset supervision rules based on the rule requirements corresponding to each independent rule; Step 22: Analyzing each of the network response behaviors and the traffic execution objects using the preset supervision rules to obtain a plurality of first supervision results for each of the network response behaviors and a plurality of second supervision results for each of the traffic execution objects; Step 23: Filtering a plurality of first supervision results of targets that do not match the supervision focus, constructing a first abnormal feature of the network response behavior, filtering a plurality of second supervision results of targets that do not match the supervision focus, and constructing a second abnormal feature of the traffic execution object; Step 24: Determine a first abnormality level of the network response behavior based on the first supervision result, determine a second abnormality level of the traffic execution object based on the second supervision result, and perform abnormal superposition on the target first supervision result and the target second supervision result based on the first abnormality level and the second abnormality level to obtain the traffic abnormality level corresponding to the original traffic data.
5. A method for monitoring and protecting network traffic anomalies according to claim 1, characterized in that: The step 3 comprises: Step 31: Inputting the corresponding raw traffic data into the corresponding model layer of the hierarchical protection model according to the traffic anomaly level, identifying the abnormal pattern of the raw traffic data at the model layer, and identifying several optimization methods of the abnormal pattern in the big data; Step 32: In the model layer, each optimization method is used to perform optimization simulation on the original traffic data to obtain the optimization defects and optimization advantages corresponding to each optimization method, select the target optimization method with the smallest optimization defect, and match each optimization advantage with the target optimization defect of the target optimization method to obtain the compensation optimization method of the target optimization method; Step 33: Use the compensation optimization method to compensate for the defects of the target optimization method to obtain the protection optimization method of the original traffic data, identify several abnormal features of the original traffic data in the model layer, and use the protection optimization method to optimize the original traffic data in the model layer until the original traffic data does not contain abnormal features.
6. A method for monitoring and protecting network traffic anomalies according to claim 5, characterized in that: Also includes: When the traffic anomaly level belongs to a high-risk anomaly level, the original traffic data is divided into a plurality of sub-data segments, and the segment anomaly level corresponding to each sub-data segment is identified; Each of the sub-data segments is input into a corresponding model layer according to the segment abnormality level for abnormality optimization.
7. A method for monitoring and protecting network traffic anomalies according to claim 1, characterized in that: The step 4 comprises: Step 41: identifying an abnormal data segment corresponding to each abnormal feature in the original traffic data, performing enhancement processing on each abnormal data segment, and obtaining a data weight of each abnormal data segment in the original traffic data; Step 42: setting a corresponding dimensionality reduction number for each abnormal data segment according to the data weight, performing dimensionality reduction processing on the corresponding abnormal data segment according to the dimensionality reduction number, obtaining key information of each abnormal data segment, and tracking the key information in the network; Step 43: Based on the tracing path corresponding to each key information, construct the abnormal cause corresponding to the abnormal traffic data, expand the abnormal cause in the network, obtain the network-related node of the abnormal cause, and enhance each of the network-related nodes according to the abnormal cause until the abnormal cause is eliminated in the network.
8. A method for monitoring and protecting network traffic anomalies according to claim 1, characterized in that: Also includes: Obtaining historical anomaly level reports of the network and extracting anomaly level content from big data; Constructing a model hierarchical framework based on the historical anomaly reports and the anomaly level content; According to the abnormality level, corresponding data processing functions and data optimization functions are added to the corresponding model layer to generate a hierarchical protection model of the network.
9. A system for monitoring and protecting network traffic anomalies, characterized in that: include: A data processing module is used to collect raw traffic data in the network in real time, and respectively identify the network response behavior and the corresponding traffic execution object corresponding to each piece of raw traffic data; an anomaly identification module, configured to identify anomalies of the network response behavior and the traffic execution object respectively using preset supervision rules, and obtain a traffic anomaly level corresponding to each of the raw traffic data; An abnormality optimization module, configured to input the corresponding raw traffic data into a level protection model based on the traffic abnormality level to perform abnormality optimization and eliminate abnormal features of each raw traffic data; The enhancement elimination module is used to perform a retrospective analysis on the original traffic data according to the abnormal characteristics, obtain the abnormal cause corresponding to the original traffic data, and perform corresponding security enhancement processing on the network according to the abnormal cause.
10. A system for monitoring and protecting network traffic anomalies according to claim 9, characterized in that: The data processing module comprises: a rule construction unit, configured to synchronously collect mirrored traffic on the network to obtain real-time mirrored data in the network, obtain a plurality of mirrored data values contained in the real-time mirrored data, construct a visual histogram of the real-time mirrored data, identify curve features of the visual histogram, and determine a probability distribution rule for the real-time mirrored data; a data processing unit, configured to construct a data distribution graph of the real-time mirror data using the probability distribution rule, and determine, in the data distribution graph, a plurality of data distribution areas of the real-time mirror data and data volume information corresponding to each of the data distribution areas; a mirror flipping unit, configured to construct a mirror flipping rule for the real-time mirror data according to the regional position relationship between different data distribution areas, and flip the corresponding data volume information in each data distribution area using the mirror flipping rule to obtain the original traffic data of the network; The behavior analysis unit is used to perform behavior analysis on each of the original traffic data to obtain the response behavior of the original traffic data of the network, and to perform performance analysis on each of the response behaviors to obtain the traffic execution object corresponding to the original traffic data.
Citation Information
Patent Citations
Network security monitoring system and method thereof
CN118944974A
Intelligent network flow anomaly detection and automatic isolation system
CN119363388A
Network anomaly monitoring system and method based on data analysis
CN120320974A
System and method for automated network monitoring and detection of network anomalies
US20180020015A1