A method and system for network traffic anomaly supervision protection

By collecting and analyzing network traffic data in real time, and optimizing anomaly characteristics using supervision rules and graded protection models, the problems of low accuracy and high false negative rate of traditional monitoring methods are solved, achieving efficient network security protection and anomaly handling.

CN120729630BActive Publication Date: 2026-01-20深圳市生态环境智能管控中心
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511180645.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-08-22
Publication Date
2026-01-20
Estimated Expiration
2045-08-22

AI Technical Summary

Technical Problem

Traditional network traffic monitoring methods have low accuracy and high false negative rates, making it difficult to accurately identify unknown attacks and thus hindering effective network protection and recovery.

Method used

By collecting network traffic data in real time, identifying response behaviors and execution objects, using preset supervision rules to identify anomalies and assign levels, inputting the data into the level protection model for optimization, and retrospectively analyzing the causes of anomalies and performing security enhancement processing.

Benefits of technology

It enables efficient identification and elimination of network anomalies, improves network security protection, reduces the number of network anomalies, enhances the ability to identify unknown attacks, and ensures the continuity of network services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120729630B_ABST
    Figure CN120729630B_ABST
Patent Text Reader

Abstract

The application provides a method and system for network traffic anomaly supervision protection, comprising: collecting original traffic data in a network in real time, determining network response behavior corresponding to the original traffic data and a corresponding traffic execution object, using a preset supervision rule to perform anomaly identification on the network response behavior and the traffic execution object respectively, obtaining a traffic anomaly level corresponding to each original traffic data, inputting the original traffic data into a level protection model for anomaly optimization, eliminating anomaly characteristics of each original traffic data, then performing backtracking analysis on the original traffic data to obtain an anomaly reason corresponding to the original traffic data, performing corresponding security enhancement processing on the network according to the anomaly reason, compensating for network security vulnerabilities from the root cause, improving the resistance of the network to similar anomalies, continuously improving the network security protection level, and effectively responding to changing network security threats.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security supervision, in particular to a method and system for network traffic anomaly supervision and protection. BACKGROUND

[0002] With the rapid development of the Internet, network attack events also occur frequently, and normal network services cannot be provided due to different types of attack means adopted by attackers, so a series of malicious phenomena such as network paralysis, data leakage, privacy leakage, etc. often occur, and because the attack means of the attacker cannot be determined in a short time, the network is difficult to recover, which seriously threatens network security. The traditional network traffic monitoring method mostly uses single rule matching or simple threshold judgment, which can limit the amount of information obtained by the attacker to a certain extent, but this way not only has low measurement accuracy, high false negative rate and weak identification ability for unknown attacks, but also cannot accurately track the attack means of the attacker, and the network is easy to fall into risk again, therefore, how to effectively maintain network security and repair network defects has become a problem to be solved.

[0003] Therefore, the present application provides a method and system for network traffic anomaly supervision and protection. SUMMARY

[0004] The method and system for network traffic anomaly supervision and protection of the present application can supervise and protect the traffic data in the network in real time, not only can protect the network security, but also can repair the defects in the network in time, reduce the occurrence of network anomaly phenomenon.

[0005] The present application provides a method for network traffic anomaly supervision and protection, comprising:

[0006] Step 1: Real-time acquisition of original traffic data in the network, identification of corresponding network response behavior and corresponding traffic execution object of each original traffic data;

[0007] Step 2: Using a preset supervision rule to identify the network response behavior and the traffic execution object, respectively, to obtain the traffic anomaly level corresponding to each original traffic data;

[0008] Step 3: Based on the traffic anomaly level, input the corresponding original traffic data into a level protection model for anomaly optimization, and eliminate the anomaly characteristics of each original traffic data;

[0009] Step 4: According to the anomaly characteristics, backtracking analysis is performed on the corresponding original traffic data, the anomaly reason corresponding to the original traffic data is obtained, and the network is subjected to corresponding security enhancement processing according to the anomaly reason.

[0010] In an implementable mode,

[0011] The step 1 comprises:

[0012] Step 11: synchronously mirror traffic collection on the network to obtain real-time mirror data in the network, acquire a plurality of mirror data values contained in the real-time mirror data, construct a visual histogram of the real-time mirror data, identify curve features of the visual histogram, and determine a probability distribution rule of the real-time mirror data;

[0013] Step 12: constructing a data distribution graph of the real-time mirror data by using the probability distribution rule, determining a plurality of data distribution regions of the real-time mirror data in the data distribution graph, and data volume information corresponding to each data distribution region;

[0014] Step 13: constructing a mirror flip rule of the real-time mirror data according to a region position relationship between different data distribution regions, respectively flipping the data volume information corresponding to each data distribution region by using the mirror flip rule, and obtaining original traffic data of the network;

[0015] Step 14: respectively performing behavior analysis on each original traffic data to obtain response behaviors of the original traffic data of the network, and respectively performing performance analysis on each response behavior to obtain a traffic execution object corresponding to the original traffic data.

[0016] In an implementable mode,

[0017] The step 14 comprises:

[0018] Step 141: determining an IP address and a protocol type of a traffic source according to the original traffic data, screening historical traffic data of the same IP address, when the historical traffic data and the original traffic data present a continuous feature, connecting the historical traffic data and the original traffic data according to the protocol type, and generating output traffic data of the IP address;

[0019] Step 142: identifying a plurality of access locations of the output traffic data in the network, constructing an access behavior corresponding to each access location based on data information contained in the output traffic data, and identifying a response of the network to each access behavior to obtain a plurality of response behaviors of the network to the original traffic data;

[0020] Step 143: respectively performing performance analysis on each response behavior to obtain a behavior result corresponding to each access behavior, and constructing a result terminal point contained in the behavior result to determine a traffic execution object corresponding to the original traffic data.

[0021] In an implementable mode,

[0022] The step 2 comprises:

[0023] Step 21: Obtain updated network security regulations in big data, adjust existing supervision rules by using the updated network security regulations to generate preset supervision rules, identify a plurality of independent rules contained in the preset supervision rules, and establish supervision focuses of the preset supervision rules according to rule requirements corresponding to each independent rule;

[0024] Step 22: Perform rule analysis on each network response behavior and each traffic execution object by using the preset supervision rules respectively, to obtain a plurality of first supervision results of each network response behavior, and a plurality of second supervision results of each traffic execution object;

[0025] Step 23: Screen a plurality of target first supervision results that do not match the supervision focus, to construct first abnormal characteristics of the network response behavior, and screen a plurality of target second supervision results that do not match the supervision focus, to construct second abnormal characteristics of the traffic execution object;

[0026] Step 24: Determine a first abnormal level of the network response behavior according to the first supervision results, determine a second abnormal level of the traffic execution object according to the second supervision results, and perform abnormal superposition on the target first supervision results and the target second supervision results according to the first abnormal level and the second abnormal level, to obtain a traffic abnormal level corresponding to the original traffic data.

[0027] In an implementable mode,

[0028] The step 3 comprises:

[0029] Step 31: Input the original traffic data corresponding to the traffic abnormal level into a corresponding model layer in the level protection model, identify an abnormal mode of the original traffic data in the model layer, and identify a plurality of optimization modes of the abnormal mode in big data;

[0030] Step 32: Optimize and simulate the original traffic data by using each optimization mode in the model layer, to obtain an optimization defect and an optimization advantage corresponding to each optimization mode, screen a target optimization mode with the minimum optimization defect, match each optimization advantage with a target optimization defect of the target optimization mode respectively, and obtain a compensation optimization mode of the target optimization mode;

[0031] Step 33: defect compensation is performed on the target optimization mode by using the compensation optimization mode to obtain a protection optimization mode of the original traffic data, a plurality of abnormal features of the original traffic data are identified in the model layer, and the original traffic data is optimized in the model layer by using the protection optimization mode until the original traffic data does not contain abnormal features.

[0032] In an implementable mode,

[0033] Further comprising:

[0034] When the traffic anomaly level belongs to a high-risk anomaly level, the original traffic data is divided into a plurality of sub-data segments, and a segment anomaly level corresponding to each sub-data segment is identified;

[0035] According to the segment anomaly level, each sub-data segment is input into a corresponding model layer for anomaly optimization.

[0036] In an implementable mode,

[0037] The step 4 comprises:

[0038] Step 41: identifying an abnormal data segment corresponding to each abnormal feature in the original traffic data, respectively enhancing each abnormal data segment to obtain a data weight of each abnormal data segment in the original traffic data;

[0039] Step 42: setting a corresponding dimension reduction dimension for the corresponding abnormal data segment according to the data weight, performing dimension reduction processing on the corresponding abnormal data segment according to the dimension reduction dimension to obtain key information of each abnormal data segment, and tracking the key information in the network;

[0040] Step 43: constructing an abnormal reason corresponding to the abnormal traffic data according to a tracking path corresponding to each key information, expanding the abnormal reason in the network to obtain a network association node of the abnormal reason, respectively enhancing each network association node according to the abnormal reason until the network eliminates the abnormal reason.

[0041] In an implementable mode,

[0042] Further comprising:

[0043] Obtaining a historical anomaly level report of the network and extracting an anomaly level content in big data;

[0044] Constructing a model layered framework according to the historical anomaly report and the anomaly level content;

[0045] According to the abnormal level, corresponding data processing function and data optimization function are added to the corresponding model layer, and a level protection model of the network is generated.

[0046] The application provides a system for network traffic anomaly supervision protection, comprising:

[0047] A data processing module is configured to collect original traffic data in a network in real time, and identify network response behavior and traffic execution object corresponding to each original traffic data, respectively.

[0048] An anomaly identification module is configured to identify the network response behavior and the traffic execution object according to a preset supervision rule, and obtain a traffic anomaly level corresponding to each original traffic data.

[0049] An anomaly optimization module is configured to input the original traffic data into a level protection model based on the traffic anomaly level, and perform anomaly optimization to eliminate anomaly characteristics of each original traffic data.

[0050] An enhancement elimination module is configured to perform backtracking analysis on the original traffic data according to the anomaly characteristics, obtain an anomaly reason corresponding to the original traffic data, and perform corresponding security enhancement processing on the network according to the anomaly reason.

[0051] In an implementable manner,

[0052] The data processing module comprises:

[0053] A rule construction unit is configured to collect real-time mirror data in the network by synchronously performing mirror traffic collection on the network, obtain a plurality of mirror data values contained in the real-time mirror data, construct a visual histogram of the real-time mirror data, identify curve characteristics of the visual histogram, and determine a probability distribution rule of the real-time mirror data.

[0054] A data processing unit is configured to construct a data distribution graph of the real-time mirror data by using the probability distribution rule, determine a plurality of data distribution regions of the real-time mirror data and data volume information corresponding to each data distribution region in the data distribution graph.

[0055] A mirror flipping unit is configured to construct a mirror flipping rule of the real-time mirror data according to a region position relationship between different data distribution regions, flip the data volume information corresponding to each data distribution region by using the mirror flipping rule, and obtain original traffic data of the network.

[0056] The behavior analysis unit is configured to perform behavior analysis on each of the original traffic data to obtain response behaviors of the original traffic data of the network, and perform performance analysis on each of the response behaviors to obtain a traffic execution object corresponding to the original traffic data.

[0057] The above technical solution has the following beneficial effects: in order to improve the security of the network and reduce the number of network anomalies, the network response behaviors and the traffic execution objects in the network are determined by synchronously collecting the original traffic data in the network, which provides a more comprehensive basis for subsequent anomaly identification, then the network response behaviors and the traffic execution objects are synchronously supervised by using preset supervision rules, the traffic anomaly level of the original traffic data is determined, then the corresponding level protection model is matched based on the traffic anomaly level, hierarchical protection is realized, higher level anomalies are processed by using a more strict optimization strategy, and lower level anomalies are processed by using a relatively mild processing method, which can not only efficiently eliminate different level anomaly characteristics, but also maximally reduce the interference on normal network traffic, guarantee the continuity of network services, finally, the abnormal reasons are mined by backtracking analysis and security enhancement processing, so that not only the current abnormal problems can be solved, but also the network security vulnerabilities can be compensated from the root cause, the network resistance to similar anomalies is improved, the network security protection level is continuously improved, and the constantly changing network security threats are effectively coped with.

[0058] Other features and advantages of the present application will be set forth in the following description, and in part will become apparent to those skilled in the art from the description, or can be learned by practice of the present application. The objects and other advantages of the present application can be achieved and obtained by means of the structure particularly pointed out in the written description and the appended drawings.

[0059] The technical solutions of the present application will be further described in detail below with the help of the drawings and examples. BRIEF DESCRIPTION OF DRAWINGS

[0060] The accompanying drawings are included to provide a further understanding of the present application, and constitute a part of the specification, and are used to explain the present application together with the embodiments of the present application, and do not constitute a limitation on the present application. In the drawings:

[0061] Figure 1 A workflow schematic diagram of a method for network traffic anomaly supervision and protection in an embodiment of the present application;

[0062] Figure 2 A composition schematic diagram of a system for network traffic anomaly supervision and protection in an embodiment of the present application. DETAILED DESCRIPTION

[0063] The preferred embodiments of the present application are described below in conjunction with the accompanying drawings, in which it is understood that the preferred embodiments described below are merely used to illustrate and explain the present application, and are not used to limit the present application.

[0064] Embodiment 1

[0065] The embodiment provides a method for network traffic anomaly supervision protection, as shown in the method comprises the following steps: Figure 1

[0066] Step 1: Collecting original traffic data in a network in real time, identifying network response behavior and traffic execution object corresponding to each original traffic data respectively;

[0067] Step 2: Identifying anomalies of the network response behavior and the traffic execution object respectively by using preset supervision rules, obtaining traffic anomaly level corresponding to each original traffic data;

[0068] Step 3: Inputting the corresponding original traffic data into a level protection model based on the traffic anomaly level to optimize anomalies, eliminating anomaly features of each original traffic data;

[0069] Step 4: Carrying out backtracking analysis on the corresponding original traffic data according to the anomaly features, obtaining anomaly reasons corresponding to the original traffic data, and carrying out corresponding security enhancement processing on the network according to the anomaly reasons.

[0070] In this example, the network response behavior represents the behavior corresponding to the original traffic data;

[0071] In this example, the traffic execution object represents the object acted on by the original traffic data;

[0072] In this example, the purpose of simultaneously supervising the network response behavior and the traffic execution object is to avoid one-sidedness that may exist in single-dimensional analysis;

[0073] In this example, the traffic anomaly level represents the anomaly level of the original traffic data;

[0074] In this example, the level protection model represents a model for optimizing protection of original traffic data with different traffic anomaly levels;

[0075] In this example, the backtracking analysis represents an analysis process for finding anomaly reasons of the original traffic data;

[0076] In this example, the security enhancement processing represents a process for eliminating anomaly reasons in the network.

[0077] ​The working principle and beneficial effects of the above technical solution are as follows: in order to improve the security of the network and reduce the number of network anomalies, first, the original traffic data in the network is synchronously collected to determine the network response behavior and traffic execution object in the network, thereby providing a more comprehensive basis for subsequent anomaly identification; then, the network response behavior and traffic execution object are synchronously supervised by using a preset supervision rule, and the traffic anomaly level of the original traffic data is determined; then, a corresponding level protection model is matched based on the traffic anomaly level, hierarchical protection is realized, a more stringent optimization strategy is adopted for high-level anomalies, and a relatively mild processing mode is adopted for low-level anomalies, which can not only efficiently eliminate different levels of anomaly characteristics, but also minimize the interference to normal network traffic, thereby guaranteeing the continuity of network services; finally, the anomaly reason is mined through backtracking analysis and security enhancement processing, so that not only the current anomaly problem can be solved, but also the network security vulnerability can be compensated from the root cause, the network resistance to similar anomalies can be improved, the network security protection level can be continuously improved, and the changing network security threats can be effectively responded to.

[0078] Embodiment 2

[0079] On the basis of embodiment 1, the method for network traffic anomaly supervision and protection, the step 1 comprises:

[0080] Step 11: synchronously collecting mirror traffic of the network to obtain real-time mirror data in the network, acquiring a plurality of mirror data values contained in the real-time mirror data, constructing a visual histogram of the real-time mirror data, identifying the curve characteristics of the visual histogram, and determining the probability distribution rule of the real-time mirror data;

[0081] Step 12: constructing a data distribution graph of the real-time mirror data by using the probability distribution rule, determining a plurality of data distribution regions of the real-time mirror data in the data distribution graph, and data volume information corresponding to each data distribution region;

[0082] Step 13: constructing a mirror flip rule of the real-time mirror data according to the region position relationship between different data distribution regions, respectively flipping the corresponding data volume information in each data distribution region by using the mirror flip rule, and obtaining the original traffic data of the network;

[0083] Step 14: respectively analyzing the behavior of each original traffic data to obtain the response behavior of the original traffic data of the network, and respectively analyzing the performance of each response behavior to obtain the traffic execution object corresponding to the original traffic data.

[0084] In this example, the real-time mirror data represents a mirror presentation of existing data in the network, and the purpose of collecting the mirror data is: first, to ensure the authenticity and integrity of the original data, and second, to reduce the impact on the normal operation of the network.

[0085] In this example, the mirror data value represents a data value contained in the real-time mirror data.

[0086] In this example, the probability distribution rule represents a distribution rule of the mirror data value in the real-time mirror data, including: discrete probability distribution, continuous probability distribution, normal distribution, Bernoulli distribution, binomial distribution, uniform distribution, Poisson distribution, exponential distribution, etc.

[0087] In this example, the data distribution graph represents a result of expressing the distribution of the mirror data value in the real-time mirror data in a graphical manner.

[0088] In this example, the data distribution area represents an area containing the mirror data value in the data distribution graph.

[0089] In this example, the mirror flip rule represents a rule for restoring the mirror data, and the rule is not a supervised flip. The flip process is: flip each data distribution area respectively, and then determine the positional relationship between different flip results according to the real-time mirror data, so as to rearrange the flip results and obtain the original traffic data.

[0090] In this example, the behavior analysis represents the execution behavior corresponding to the original traffic data, and the performance analysis represents the function presented by the response behavior.

[0091] The working principle and beneficial effects of the above technical solution are: real-time mirror data is obtained by mirror traffic collection, and the probability distribution rule is determined by analyzing the curve characteristics of the visual histogram, which intuitively reflects the internal distribution law of the data, so as to match the corresponding probability distribution rule for the real-time mirror data. Then, the data distribution graph is constructed based on the probability distribution rule and the data distribution area is divided, so as to obtain the distribution of data in different intervals and the corresponding data amount. Then, the mirror flip rule is constructed according to the regional positional relationship and the data amount information is flipped to obtain the original traffic data, which restores the real traffic situation in the network to the greatest extent, reduces the information loss in the data collection and processing process, and ensures the integrity of the original traffic data. Finally, the response behavior and the traffic execution object are obtained through behavior analysis and performance analysis, respectively, which realizes the accurate extraction of key features from the original traffic data, provides specific and explicit analysis objects for subsequent anomaly identification, ensures the pertinence and effectiveness of anomaly supervision and protection, and makes the starting point of the entire protection process more accurate and reliable.

[0092] Embodiment 3:

[0093] On the basis of embodiment 2, the method for network traffic anomaly supervision and protection, the step 14 comprises:

[0094] Step 141: determining the IP address and protocol type of the traffic source according to the original traffic data, screening the historical traffic data with the same IP address, and when the historical traffic data and the original traffic data present continuous characteristics, connecting the historical traffic data and the original traffic data according to the protocol type to generate the output traffic data of the IP address;

[0095] Step 142: identifying a plurality of access locations of the output traffic data in the network, constructing the access behavior corresponding to each of the access locations based on the data information contained in the output traffic data, and identifying the response of the network to each of the access behaviors to obtain a plurality of response behaviors of the network to the original traffic data;

[0096] Step 143: performing performance analysis on each of the response behaviors respectively to obtain the behavior result corresponding to each of the access behaviors, and constructing the result terminal point contained in the behavior result to determine the traffic execution object corresponding to the original traffic data.

[0097] In this example, when the historical traffic data and the original traffic data present continuous characteristics, it indicates that the original traffic data and the historical traffic data have the same source, and they are continuous data;

[0098] In this example, the data information represents the data presented in the output traffic data when an access location is accessed.

[0099] The working principle and beneficial effects of the above technical solution are as follows: firstly, the historical traffic data with the same IP address is screened, and the output traffic data is generated by connecting the continuous characteristics and the protocol type, the dispersed original traffic and the historical data are associated into a complete traffic sequence, the continuous interaction process of the same IP at different times is completely captured, then the access location is identified based on the output traffic data, and the access behavior corresponding to each location is constructed, then the response of the network to these behaviors is combined, finally the behavior result is obtained by analyzing the performance of the response behavior, and the traffic execution object is determined from the result terminal point, ensuring that the abnormal identification can focus on specific behaviors and objects, and then the subsequent level protection and backtracking analysis are more targeted, thereby improving the effectiveness of the entire network traffic anomaly supervision and protection system from the source.

[0100] Embodiment 4:

[0101] On the basis of embodiment 1, the method for network traffic anomaly supervision and protection, the step 2 comprises:

[0102] Step 21: Obtain updated network security regulations in big data, adjust existing supervision rules using the updated network security regulations to generate preset supervision rules, identify a plurality of independent rules contained in the preset supervision rules, and establish supervision focus of the preset supervision rules according to rule requirements corresponding to each independent rule;

[0103] Step 22: Perform rule analysis on each network response behavior and each traffic execution object using the preset supervision rules respectively, to obtain a plurality of first supervision results of each network response behavior, and a plurality of second supervision results of each traffic execution object;

[0104] Step 23: Screen a plurality of target first supervision results that do not match the supervision focus, to construct first abnormal characteristics of the network response behavior, and screen a plurality of target second supervision results that do not match the supervision focus, to construct second abnormal characteristics of the traffic execution object;

[0105] Step 24: Determine a first abnormal level of the network response behavior according to the first supervision results, determine a second abnormal level of the traffic execution object according to the second supervision results, and perform abnormal superposition on the target first supervision results and the target second supervision results according to the first abnormal level and the second abnormal level, to obtain a traffic abnormal level corresponding to the original traffic data.

[0106] In this example, the existing supervision rules represent the currently used supervision rules. Whenever updated network security regulations appear in big data, the existing supervision rules are automatically updated to generate preset supervision rules, so that the rules can keep up with new requirements and new specifications in the network security field, and avoid missed judgment of new network threats due to rule lag;

[0107] In this example, the supervision focus represents the supervision content when the independent rules supervise the network response behavior and the traffic execution object;

[0108] In this example, the first supervision result represents the result obtained when the network response behavior is supervised, and the second supervision result represents the result obtained when the traffic execution object is supervised;

[0109] In this example, the first abnormal level represents the abnormal level of the network response behavior, and the second abnormal level represents the abnormal level of the traffic execution object,

[0110] The working principle and beneficial effects of the above technical solutions are as follows: in order to realize efficient supervision, the first task is to determine the traffic anomaly level of the original traffic data. First, the existing rules are adjusted to generate preset supervision rules in combination with the updated network security regulations in big data. Then, rule analysis is performed on network response behavior and traffic execution objects respectively to obtain first and second supervision results. Target results that do not match the supervision focus are screened out, and first and second abnormal features are constructed to achieve the purpose of accurately locating abnormal points from complex data. This object-dimension analysis method reduces the interference of irrelevant information, making the identification of abnormal features more accurate and reliable. Further, by determining the first and second abnormal levels and performing abnormal superposition, the final traffic anomaly level is obtained. In this way, the possible one-sidedness of single-dimensional judgment is avoided, and the abnormality degree of the original traffic data is more comprehensively reflected, laying a solid foundation for subsequent protection work.

[0111] Embodiment 5:

[0112] Based on embodiment 1, the method for network traffic anomaly supervision and protection, step 3, comprises:

[0113] Step 31: input the corresponding original traffic data into the corresponding model layer of the level protection model according to the traffic anomaly level, identify the abnormal pattern of the original traffic data in the model layer, and identify several optimization methods of the abnormal pattern in big data;

[0114] Step 32: optimize and simulate the original traffic data in the model layer using each optimization method to obtain the optimization defects and advantages corresponding to each optimization method, screen the target optimization method with the smallest optimization defect, match each optimization advantage with the target optimization defect of the target optimization method, and obtain the compensation optimization method of the target optimization method;

[0115] Step 33: compensate for the defects of the target optimization method using the compensation optimization method to obtain the protection optimization method of the original traffic data, identify several abnormal features of the original traffic data in the model layer, and optimize the original traffic data in the model layer using the protection optimization method until the original traffic data does not contain abnormal features.

[0116] In this example, the abnormal pattern represents the pattern presented when the original traffic data is abnormal;

[0117] In this example, the optimization method represents a method for eliminating the abnormality of the original traffic data;

[0118] In this example, the optimization defect representation presents the defect content after the original traffic data is optimized by the optimization method, and the optimization advantage representation presents the optimal optimization content after the original traffic data is optimized by the optimization direction.

[0119] The working principle and beneficial effects of the above technical solution are as follows: firstly, the original traffic data is input into the corresponding model layer according to the traffic anomaly level, so that anomalies of different levels can be adaptively processed, blind optimization is avoided, and the accuracy of the optimization direction is improved; then, different optimization methods are simulated to analyze their optimization defects and advantages, the target optimization method with the smallest optimization defect is screened out, and the advantages of other methods are combined for defect compensation to form a more perfect protection optimization method, which reduces the residual anomalies caused by incomplete optimization; the original traffic data is continuously optimized by the protection optimization method until there is no anomaly feature, which ensures that the anomaly feature is completely eliminated and avoids repeated anomalies caused by partial optimization; in this way, complete elimination can be achieved, which provides a strong guarantee for the safety of network traffic and creates good conditions for subsequent backtracking analysis and security enhancement processing.

[0120] Embodiment 6

[0121] Based on embodiment 5, the method for network traffic anomaly supervision and protection further comprises:

[0122] When the traffic anomaly level belongs to a high-risk anomaly level, the original traffic data is divided into a plurality of sub-data segments, and the segment anomaly level corresponding to each sub-data segment is identified;

[0123] According to the segment anomaly level, each sub-data segment is input into the corresponding model layer for anomaly optimization.

[0124] The working principle and beneficial effects of the above technical solution are as follows: when the original traffic data belongs to a high-risk anomaly level, it is divided into a plurality of sub-data segments for anomaly optimization, which improves the optimization efficiency on the basis of ensuring the optimization quality and guarantees the safety of the network environment.

[0125] Embodiment 7

[0126] Based on embodiment 1, the method for network traffic anomaly supervision and protection, the step 4 comprises:

[0127] Step 41: identifying the anomaly data segment corresponding to each anomaly feature in the original traffic data, respectively performing enhancement processing on each anomaly data segment to obtain the data weight of each anomaly data segment in the original traffic data;

[0128] Step 42: setting a corresponding dimension reduction dimension for the abnormal data segment according to the data weight, performing dimension reduction processing on the corresponding abnormal data segment according to the dimension reduction dimension, and obtaining key information of each abnormal data segment, and tracking the key information in the network;

[0129] Step 43: constructing an abnormal reason corresponding to the abnormal traffic data according to the tracking path corresponding to each key information, expanding the abnormal reason in the network, obtaining a network association node of the abnormal reason, and respectively performing enhancement processing on each network association node according to the abnormal reason until the network eliminates the abnormal reason.

[0130] In this example, the data weight represents the importance of the abnormal data segment in the original traffic data.

[0131] In this example, the dimension reduction dimension is related to the data weight, the greater the data weight, the greater the dimension reduction dimension, and the dimension reduction dimension corresponding to the abnormal data segment with the largest data weight is the same as the dimension of the abnormal data segment, and the remaining abnormal data segments are less than this dimension.

[0132] In this example, the network association node represents a network node having an association relationship with the abnormal reason.

[0133] The working principle and beneficial effects of the above technical solution are as follows: by identifying the abnormal data segment corresponding to the abnormal feature and assigning a data weight, the importance of key abnormal information can be highlighted, and irrelevant information in massive data can be avoided. Then, the dimension reduction dimension is set for the abnormal data segment according to the data weight and dimension reduction processing is performed, the core information is retained while the data complexity is simplified, the key information is extracted, and finally the abnormal reason is constructed on the tracking path, and the network association node is found by expanding the abnormal reason. These nodes are enhanced until the abnormal reason is eliminated. In this way, the current abnormality can be handled, and the associated potential risk points can be investigated and reinforced, and the abnormal reason can be prevented from reproducing in other nodes of the network, thereby improving the security protection capability of the network as a whole.

[0134] Embodiment 8:

[0135] On the basis of embodiment 1, the method for network traffic anomaly supervision and protection further comprises:

[0136] obtaining a historical abnormal level report of the network, and extracting an abnormal level content in big data;

[0137] constructing a model layered framework according to the historical abnormal report and the abnormal level content;

[0138] adding corresponding data processing functions and data optimization functions to the corresponding model layer according to the abnormal level, and generating a level protection model of the network.

[0139] The working principle and beneficial effects of the above technical solution are: the abnormal supervision is realized by constructing a model, and the model is updated with the progress of the times, ensuring the effectiveness of the supervision and improving the supervision quality.

[0140] Embodiment 9:

[0141] The embodiment provides a system for network traffic anomaly supervision and protection, as shown in Figure 2 The system comprises:

[0142] A data processing module is configured to collect original traffic data in a network in real time, and identify network response behavior and a traffic execution object corresponding to each original traffic data, respectively.

[0143] An anomaly identification module is configured to identify the network response behavior and the traffic execution object according to a preset supervision rule, to obtain a traffic anomaly level corresponding to each original traffic data.

[0144] An anomaly optimization module is configured to input the original traffic data corresponding to the traffic anomaly level into a level protection model for anomaly optimization, to eliminate the anomaly characteristics of each original traffic data.

[0145] An enhancement elimination module is configured to perform backtracking analysis on the original traffic data according to the anomaly characteristics, to obtain an anomaly reason corresponding to the original traffic data, and to perform corresponding security enhancement processing on the network according to the anomaly reason.

[0146] In this example, the network response behavior represents the behavior corresponding to the original traffic data.

[0147] In this example, the traffic execution object represents the object acted on by the original traffic data.

[0148] In this example, the purpose of simultaneously supervising the network response behavior and the traffic execution object is to avoid the possible one-sidedness of single-dimensional analysis.

[0149] In this example, the traffic anomaly level represents the anomaly level of the original traffic data.

[0150] In this example, the level protection model represents a model for optimizing and protecting original traffic data of different traffic anomaly levels.

[0151] In this example, backtracking analysis represents an analysis process for finding the anomaly reason of the original traffic data.

[0152] In this example, the security enhancement processing represents a process for eliminating the anomaly reason in the network.

[0153] The working principle and beneficial effects of the technical solution are as follows: in order to improve the security of the network and reduce the number of network anomalies, first, the original traffic data in the network is synchronously collected to determine the network response behavior and traffic execution object in the network, thereby providing a more comprehensive basis for subsequent anomaly identification; then, the network response behavior and traffic execution object are synchronously supervised by using a preset supervision rule, the traffic anomaly level of the original traffic data is determined, and then a corresponding level protection model is matched based on the traffic anomaly level, thereby realizing hierarchical protection, adopting a more stringent optimization strategy for high-level anomalies and a relatively mild processing mode for low-level anomalies, efficiently eliminating abnormal characteristics of different levels and minimizing interference with normal network traffic, thereby guaranteeing the continuity of network services; finally, the anomaly reason is mined through backtracking analysis and security enhancement processing, so that not only the current anomaly problem can be solved, but also network security vulnerabilities can be remedied from the root cause, the network resistance to similar anomalies can be improved, the network security protection level can be continuously improved, and the constantly changing network security threats can be effectively responded to.

[0154] Embodiment 10:

[0155] Based on the system for network traffic anomaly supervision and protection in embodiment 9, the data processing module comprises:

[0156] A rule construction unit is configured to synchronously collect mirror traffic of the network to obtain real-time mirror data in the network, acquire a plurality of mirror data values contained in the real-time mirror data, construct a visual histogram of the real-time mirror data, identify curve characteristics of the visual histogram, and determine a probability distribution rule of the real-time mirror data.

[0157] A data processing unit is configured to construct a data distribution graph of the real-time mirror data by using the probability distribution rule, determine a plurality of data distribution regions of the real-time mirror data and data volume information corresponding to each data distribution region in the data distribution graph.

[0158] A mirror flipping unit is configured to construct a mirror flipping rule of the real-time mirror data according to a region position relationship between different data distribution regions, flip the data volume information corresponding to each data distribution region by using the mirror flipping rule, and obtain original traffic data of the network.

[0159] A behavior analysis unit is configured to perform behavior analysis on each original traffic data to obtain a response behavior of the original traffic data of the network, and perform performance analysis on each response behavior to obtain a traffic execution object corresponding to the original traffic data.

[0160] In this example, the real-time mirror data represents a mirror presentation of existing data in the network, and the purpose of collecting the mirror data is to: first, ensure the authenticity and integrity of the original data, and second, reduce the impact on the normal operation of the network.

[0161] In this example, the mirror data value represents a data value contained in the real-time mirror data.

[0162] In this example, the probability distribution rule represents a distribution rule of the mirror data value in the real-time mirror data, including: discrete probability distribution, continuous probability distribution, normal distribution, Bernoulli distribution, binomial distribution, uniform distribution, Poisson distribution, exponential distribution, etc.

[0163] In this example, the data distribution graph represents a result of expressing the distribution of the mirror data value in the real-time mirror data in a graphical manner.

[0164] In this example, the data distribution area represents an area containing the mirror data value in the data distribution graph.

[0165] In this example, the mirror flip rule represents a rule for restoring the mirror data, and the rule is not a supervised flip. The flip process is: flip each data distribution area respectively, and then determine the positional relationship between different flip results according to the real-time mirror data, so as to rearrange the flip results and obtain the original traffic data.

[0166] In this example, the behavior analysis represents the execution behavior corresponding to the original traffic data, and the performance analysis represents the function presented by the response behavior.

[0167] The working principle and beneficial effects of the above technical solution are: real-time mirror data is obtained by mirror traffic collection, and the probability distribution rule is determined by analyzing the curve characteristics of the visual histogram to intuitively reflect the internal distribution law of the data, so as to match the corresponding probability distribution rule for the real-time mirror data, then the data distribution graph is constructed based on the probability distribution rule and the data distribution area is divided, the distribution of the data in different intervals and the corresponding data amount are obtained, then the mirror flip rule is constructed according to the regional positional relationship and the data amount information is flipped to obtain the original traffic data, which restores the real traffic situation in the network to the greatest extent, reduces the information loss in the data collection and processing process, and ensures the integrity of the original traffic data. Finally, the response behavior and the traffic execution object are obtained through behavior analysis and performance analysis, respectively, which realizes the accurate extraction of key features from the original traffic data, provides specific and explicit analysis objects for subsequent anomaly identification, ensures the pertinence and effectiveness of anomaly supervision and protection, and makes the starting point of the entire protection process more accurate and reliable.

[0168] Obviously, many modifications and variations of the present application are possible in light of the above teachings. It is, therefore, to be understood that within the scope of the appended claims and their equivalents, the application can be practiced otherwise than as specifically described.

Claims

1. A method for monitoring and protecting against network traffic anomalies, characterized in that, include: Step 1: Collect raw traffic data in the network in real time, and identify the network response behavior and the corresponding traffic execution object for each piece of raw traffic data; Step 2: Use preset supervision rules to identify anomalies in the network response behavior and the traffic execution object to obtain the traffic anomaly level corresponding to each piece of original traffic data; Step 3: Based on the traffic anomaly level, input the corresponding original traffic data into the graded protection model for anomaly optimization to eliminate the abnormal characteristics of each piece of original traffic data; Step 4: Perform backtracking analysis on the corresponding original traffic data based on the abnormal characteristics to obtain the abnormal cause corresponding to the original traffic data, and perform corresponding security enhancement processing on the network based on the abnormal cause; Step 1 includes: Step 11: Synchronously collect mirror traffic from the network to obtain real-time mirror data in the network, obtain several mirror data values ​​contained in the real-time mirror data, construct a visual histogram of the real-time mirror data, identify the curve features of the visual histogram, and determine the probability distribution rules of the real-time mirror data. Step 12: Construct a data distribution map of the real-time mirror data using the probability distribution rules, and determine several data distribution regions of the real-time mirror data and the data volume information corresponding to each data distribution region in the data distribution map; Step 13: Construct a mirror flipping rule for the real-time mirrored data based on the regional location relationship between different data distribution areas, and use the mirror flipping rule to flip the corresponding data volume information in each data distribution area to obtain the original traffic data of the network; Step 14: Perform behavioral analysis on each of the original traffic data to obtain the response behavior of the original traffic data of the network, and perform performance analysis on each of the response behaviors to obtain the traffic execution object corresponding to the original traffic data.

2. The method for monitoring and protecting against network traffic anomalies as described in claim 1, characterized in that, Step 14 includes: Step 141: Determine the IP address and protocol type of the traffic source based on the original traffic data, filter historical traffic data with the same IP address, and when the historical traffic data and the original traffic data show continuous characteristics, connect the historical traffic data and the original traffic data according to the protocol type to generate the output traffic data of the IP address; Step 142: Identify several access locations of the output traffic data in the network, construct access behavior corresponding to each access location based on the data information contained in the output traffic data, and identify the network's response to each access behavior to obtain several response behaviors of the network to the original traffic data. Step 143: Perform performance analysis on each of the aforementioned response behaviors to obtain the behavior results corresponding to each of the aforementioned access behaviors, and construct the result endpoint contained in the behavior results to determine the traffic execution object corresponding to the original traffic data.

3. The method for monitoring and protecting against network traffic anomalies as described in claim 1, characterized in that, Step 2 includes: Step 21: Obtain updated cybersecurity regulations from big data, adjust existing supervision rules using the updated cybersecurity regulations to generate preset supervision rules, identify several independent rules contained in the preset supervision rules, and establish the supervision focus of the preset supervision rules according to the rule requirements corresponding to each independent rule; Step 22: Utilize the preset supervision rules to perform rule analysis on each network response behavior and each traffic execution object to obtain several first supervision results for each network response behavior and several second supervision results for each traffic execution object; Step 23: Filter several target first supervision results that do not match the supervision focus, construct the first abnormal feature of the network response behavior, filter several target second supervision results that do not match the supervision focus, and construct the second abnormal feature of the traffic execution object; Step 24: Determine the first anomaly level of the network response behavior based on the first supervision result, determine the second anomaly level of the traffic execution object based on the second supervision result, and perform anomaly superposition on the first supervision result and the second supervision result of the target based on the first anomaly level and the second anomaly level to obtain the traffic anomaly level corresponding to the original traffic data.

4. The method for monitoring and protecting against network traffic anomalies as described in claim 1, characterized in that, Step 3 includes: Step 31: Input the corresponding raw traffic data into the corresponding model layer in the level protection model according to the traffic anomaly level. In the model layer, identify the anomaly pattern of the raw traffic data and identify several optimization methods of the anomaly pattern in big data. Step 32: In the model layer, each optimization method is used to optimize and simulate the original traffic data to obtain the optimization defects and optimization advantages corresponding to each optimization method. The target optimization method with the smallest optimization defect is selected, and each optimization advantage is matched with the target optimization defect of the target optimization method to obtain the compensation optimization method of the target optimization method. Step 33: Use the compensation optimization method to compensate for defects in the target optimization method to obtain the protection optimization method for the original traffic data. Identify several abnormal features of the original traffic data in the model layer. Optimize the original traffic data in the model layer using the protection optimization method until the original traffic data no longer contains abnormal features.

5. The method for monitoring and protecting against network traffic anomalies as described in claim 4, characterized in that, Also includes: When the traffic anomaly level is high-risk, the original traffic data is divided into several sub-data segments, and the segment anomaly level corresponding to each sub-data segment is identified. Based on the anomaly level of the segment, each of the sub-data segments is input into the corresponding model layer for anomaly optimization.

6. The method for monitoring and protecting against network traffic anomalies as described in claim 1, characterized in that, Step 4 includes: Step 41: Identify the abnormal data segment corresponding to each of the abnormal features in the original traffic data, perform enhancement processing on each of the abnormal data segments respectively, and obtain the data weight of each of the abnormal data segments in the original traffic data. Step 42: Set the corresponding dimensionality reduction factor for the corresponding abnormal data segment according to the data weight, perform dimensionality reduction processing on the corresponding abnormal data segment according to the dimensionality reduction factor, obtain the key information of each abnormal data segment, and track the key information in the network. Step 43: Based on the tracking path corresponding to each key information, construct the cause of the anomaly corresponding to the abnormal data segment, expand the cause of the anomaly in the network to obtain the network association node of the cause of the anomaly, and perform enhancement processing on each network association node according to the cause of the anomaly until the network eliminates the cause of the anomaly.

7. The method for monitoring and protecting against network traffic anomalies as described in claim 1, characterized in that, Also includes: Obtain historical anomaly level reports for the network and extract anomaly level content from big data; A hierarchical framework for the model is constructed based on the historical anomaly level reports and the anomaly level content. Based on the anomaly level, corresponding data processing and data optimization functions are added to the corresponding model layer to generate the network's graded protection model.

8. A system for monitoring and protecting against network traffic anomalies, characterized in that, include: The data processing module is used to collect raw traffic data in the network in real time and identify the network response behavior and the corresponding traffic execution object for each piece of raw traffic data. Anomaly identification module is used to identify anomalies in the network response behavior and the traffic execution object using preset supervision rules, and to obtain the traffic anomaly level corresponding to each original traffic data. An anomaly optimization module is used to input the corresponding original traffic data into the graded protection model based on the traffic anomaly level to perform anomaly optimization and eliminate the abnormal characteristics of each original traffic data. The enhancement and elimination module is used to perform backtracking analysis on the corresponding original traffic data based on the abnormal characteristics, obtain the abnormal cause corresponding to the original traffic data, and perform corresponding security enhancement processing on the network based on the abnormal cause. The data processing module includes: The rule construction unit is used to synchronously collect mirror traffic from the network to obtain real-time mirror data in the network, obtain several mirror data values ​​contained in the real-time mirror data, construct a visual histogram of the real-time mirror data, identify the curve features of the visual histogram, and determine the probability distribution rules of the real-time mirror data. The data processing unit is used to construct a data distribution map of the real-time mirror data using the probability distribution rules, and to determine several data distribution regions of the real-time mirror data and the data volume information corresponding to each data distribution region in the data distribution map. The mirror flipping unit is used to construct mirror flipping rules for the real-time mirrored data based on the regional positional relationship between different data distribution areas, and to flip the corresponding data volume information in each data distribution area using the mirror flipping rules to obtain the original traffic data of the network. The behavior analysis unit is used to perform behavior analysis on each of the original traffic data to obtain the response behavior of the original traffic data of the network, and to perform performance analysis on each of the response behaviors to obtain the traffic execution object corresponding to the original traffic data.

Citation Information

Patent Citations

  • Network security monitoring system and method thereof

    CN118944974A

  • Intelligent network flow anomaly detection and automatic isolation system

    CN119363388A