Network early warning method based on endpoint perception and big data attack and defense analysis

By combining distributed sensor networks and deep learning with big data streaming processing methods, the problem of insufficient recognition of abnormal behavior and attack signs of endpoint devices in existing network security protection technologies has been solved, comprehensive perception and timely warning of network attacks have been achieved, and network security defense capabilities have been improved.

CN120769263APending Publication Date: 2025-10-10内蒙古自治区人力资源和社会保障厅综合保障中心(内蒙古自治区人力资源和社会保障宣传中心)

Patent Information

Application Number
CN202510866532.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-26
Publication Date
2025-10-10

AI Technical Summary

Technical Problem

Existing network security protection methods are unable to comprehensively and accurately identify abnormal behavior of endpoint devices and signs of network attacks, resulting in insufficient timeliness and accuracy of network warnings.

Method used

Multi-source heterogeneous endpoint data is collected through distributed sensor networks, and real-time analysis is performed using deep learning anomaly detection models. Network traffic data is captured in combination with big data streaming processing methods, and abnormal behaviors and attack signs are analyzed through graph model fusion to predict attack paths and types.

Benefits of technology

It has achieved comprehensive perception, accurate prediction and timely warning of network attacks, and improved network security defense capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120769263A_ABST
    Figure CN120769263A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and particularly discloses a network early warning method based on endpoint perception and big data attack and defense analysis, which comprises the following steps: deeply acquiring multi-source heterogeneous endpoint data of endpoint equipment based on a distributed sensor network; performing real-time dynamic analysis on the acquired multi-source heterogeneous endpoint data, and identifying abnormal behavior data on endpoint equipment; real-time capturing and deep analysis are carried out on network traffic data of all endpoint devices based on a big data stream processing method, and all potential network attack signs in the network are identified; carrying out fusion analysis on the abnormal behavior data on the endpoint equipment and all potential network attack signs in the network, and predicting network attack types and occurrence probabilities of all attack paths; obtaining a risk early warning result based on the predicted network attack types and occurrence probabilities of all attack paths; comprehensive perception, accurate prediction and timely early warning of network attacks can be realized, and the network security defense capability is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a network early warning method based on endpoint perception and big data attack and defense analysis. Background Art

[0002] In today's digital age, network security has become a crucial issue. With the continuous development of network technology and the increasing diversity of its application scenarios, the means and methods of network attacks are becoming increasingly complex and diverse. Traditional network security protection mainly relies on firewalls, intrusion detection systems, and other means.

[0003] However, these methods often have limitations when facing increasingly complex network attacks. For example, the Chinese invention patent, entitled "A Host Security Defense-in-Depth Method and Apparatus," with publication number CN118157922A, primarily involves host security monitoring based on endpoint detection; employing whitelists to monitor network traffic, host processes, and host folders; conducting intrusion data analysis and network data flow monitoring on deployed virtualized hosts; monitoring website applications for malicious attack behavior; and issuing early warnings when unauthorized intrusions or risks are detected. This patent discloses a defense-in-depth approach based on the principles of prediction, detection, collaboration, defense, response, and traceability, implementing multi-dimensional security coverage across the seven layers of the OSI model. When one security measure fails, the next one immediately takes effect. Network security measures are strengthened as the defense chain lengthens, significantly enhancing host reliability. However, the patent suffers from technical deficiencies such as incomplete and in-depth data collection, making it difficult to obtain heterogeneous endpoint data from multiple sources, resulting in an inaccurate understanding of endpoint device status. Furthermore, the patent's abnormal behavior detection fails to promptly and effectively identify subtle anomalies on endpoint devices, making it easy to miss potential security threats. Analyzing network traffic data in real time and performing in-depth analysis is difficult, making it impossible to quickly and accurately identify potential signs of network attacks. Furthermore, the lack of effective integration methods for comprehensive analysis of abnormal endpoint device behavior and signs of network attacks makes it difficult to comprehensively and accurately predict attack paths, types, and probabilities, thus impacting the timeliness and accuracy of network warnings.

[0004] Therefore, the present invention proposes a network early warning method based on endpoint perception and big data attack and defense analysis. Summary of the Invention

[0005] The present invention provides a network early warning method based on endpoint perception and big data attack and defense analysis. In step S1, multi-source heterogeneous endpoint data is collected through a distributed sensor network to ensure the comprehensiveness and accuracy of the data. Step S2 uses a deep learning anomaly detection model to analyze data in real time and quickly identify abnormal behavior of endpoint devices. Step S3 captures and parses network traffic data based on a big data streaming processing method to promptly discover potential signs of network attacks. Step S4 integrates and analyzes abnormal behavior data and attack signs to accurately predict the attack path, type and probability of occurrence. Step S5 obtains risk warning results based on the prediction results, providing timely and effective reference for network security protection. It can achieve comprehensive perception, accurate prediction and timely warning of network attacks, effectively improving network security defense capabilities.

[0006] The present invention provides a network early warning method based on endpoint perception and big data attack and defense analysis, comprising:

[0007] S1: Deeply collect multi-source heterogeneous endpoint data of endpoint devices based on distributed sensor networks;

[0008] S2: Introducing a deep learning-based anomaly detection model to perform real-time dynamic analysis on collected multi-source heterogeneous endpoint data to identify abnormal behavior data on endpoint devices;

[0009] S3: Based on big data streaming processing methods, it captures and deeply analyzes network traffic data from all endpoint devices in real time to identify all potential signs of network attacks;

[0010] S4: Fusion analysis of abnormal behavior data on endpoint devices and all potential network attack signs in the network to predict the types and probability of network attacks along all attack paths.

[0011] S5: Obtain risk warning results based on the types and occurrence probabilities of network attacks along all predicted attack paths.

[0012] Preferably, a network early warning method based on endpoint perception and big data attack and defense analysis, S1: In-depth collection of multi-source heterogeneous endpoint data of endpoint devices based on a distributed sensor network, including:

[0013] S101: A distributed sensor network is built using a distributed hierarchical architecture, where the distributed hierarchical architecture includes a core layer, a convergence layer, and an access layer;

[0014] S102: Based on the distributed sensor network and the data collection agent, the system logs, process operation detailed record information, network connection status information, and hardware performance parameters of the endpoint device are deeply collected as multi-source heterogeneous endpoint data of the endpoint device.

[0015] Preferably, the network early warning method based on endpoint awareness and big data attack and defense analysis, S2: introduce a deep learning-based anomaly detection model to perform real-time dynamic analysis on the collected multi-source heterogeneous endpoint data, identify abnormal behavior data on the endpoint device, including:

[0016] S201: Based on massive normal behavior data and abnormal behavior data, a deep learning model is established.

[0017] S202: Based on the anomaly detection model, real-time dynamic analysis is performed on the collected multi-source heterogeneous endpoint data, and abnormal behavior data on the endpoint device is identified.

[0018] Preferably, the network early warning method based on endpoint awareness and big data attack and defense analysis, S3: based on big data streaming processing method, real-time capture and deep analysis of network traffic data of all endpoint devices, identify all potential network attack signs in the network, including:

[0019] S301: Based on the big data streaming processing method, real-time capture of network traffic data of all endpoint devices;

[0020] S302: Construct a traffic model based on probability and statistics theory;

[0021] S303: Use the traffic model based on probability and statistics theory to model and deeply analyze abnormal phenomena in the network traffic data of all endpoint devices, and identify all potential network attack signs in the network.

[0022] Preferably, the network early warning method based on endpoint awareness and big data attack and defense analysis, S4: fusion analysis of abnormal behavior data on the endpoint device and all potential network attack signs in the network, prediction of network attack types and occurrence probability of all attack paths, including:

[0023] S401: Fusion analysis of abnormal behavior data on the endpoint device and all potential network attack signs in the network, identify all association rules;

[0024] S402: Take the abnormal behavior data on the endpoint device as the node attribute of the corresponding endpoint device, and take all potential network attack signs in the network and all association rules as the edge attribute of the corresponding connection relationship, and construct a graph model containing all endpoint devices and corresponding node attributes, network nodes and corresponding connection relationships, and all edge attributes;

[0025] S403: Based on the graph model, predict the network attack types and occurrence probability of all attack paths.

[0026] Preferably, the network early warning method based on endpoint perception and big data attack and defense analysis, S403: the network attack types and occurrence probabilities of all attack paths predicted based on the graph model, including:

[0027] Use heuristic search algorithms to crawl and reason about the graph model to infer all attack paths;

[0028] Based on each attack path, the abnormal behavior data on all endpoint devices, all potential network attack signs in the network, and all association rules are serially marked to obtain the attack information index path of each attack path;

[0029] Based on the attack pattern and purpose identification model, the attack information index path of each attack path is analyzed to identify all types of network attacks;

[0030] The attack information index path of each attack path is analyzed to determine the occurrence probability of each attack path.

[0031] Preferably, the network early warning method based on endpoint perception and big data attack and defense analysis uses a heuristic search algorithm to crawl and reason on the graph model to infer all attack paths, including:

[0032] Obtain the security risk assessment value of each node in the graph model;

[0033] The heuristic function h(n) is constructed based on the network structure of the graph model and the security risk assessment value of each node in the graph model:

[0034]

[0035] Where n is the current node in the graph model, e t is the target node in the graph model, E is the target node set in the graph model, α is the distance factor weight, d(n,e t ) is the current node n and the target node e in the graph model t The shortest path distance between them, β is the safety factor weight, and S(n) is the safety risk assessment value of the current node in the graph model;

[0036] Based on the link attribute value of each minimum unit link in the graph model, the attack transmission tendency of each minimum unit link in the graph model is calculated, and the actual cost function g(n) is constructed based on the attack transmission tendency of each minimum unit link in the graph model:

[0037]

[0038] Where, e ij is the minimum unit link between the i-th node and the j-th node in the graph model, path(n,et ) is the current node n and the target node e in the graph model t The shortest path between ij is the attack transmission tendency of the minimum unit link between the i-th node and the j-th node in the graph model;

[0039] All attack paths are searched in the graph model based on the heuristic function and the actual cost function.

[0040] Preferably, the network early warning method based on endpoint perception and big data attack and defense analysis searches for all attack paths in the graph model based on heuristic functions and actual cost functions, including:

[0041] Determine the start node and target node set in the graph model based on the security risk assessment value of each node in the graph model;

[0042] Taking all the starting nodes in the graph model as the first current node, and taking the sum of the output value of the heuristic function and the output value of the actual cost function as the minimum principle, selection and expansion are carried out in the target node set to search out all attack paths.

[0043] Preferably, the network early warning method based on endpoint perception and big data attack and defense analysis analyzes the attack information index path of each attack path to determine the occurrence probability of each attack path, including:

[0044] Based on the historical attack record data of all endpoint devices, the probability of each minimum unit link in the attack information index path of each attack path under the premise of the previous minimum unit link is evaluated;

[0045] The occurrence probability of each attack path is calculated based on the conditional occurrence probability of each minimum unit link in the attack information index path under the premise of the previous minimum unit link.

[0046] Preferably, the network early warning method based on endpoint perception and big data attack and defense analysis, S5: obtaining risk early warning results based on the types and occurrence probabilities of network attacks along all predicted attack paths, including:

[0047] S501: Perform risk prediction based on the pre-built risk prediction model and the predicted network attack types and occurrence probabilities of all attack paths to obtain predicted risk values ​​for all predicted attack paths;

[0048] S502: When the predicted risk value of the attack path exceeds the set risk threshold, the risk warning mechanism is triggered and a risk warning result is obtained.

[0049] The beneficial effects of the present invention compared to the prior art are as follows: Step S1 collects multi-source heterogeneous endpoint data through a distributed sensor network to ensure the comprehensiveness and accuracy of the data. Step S2 uses a deep learning anomaly detection model to analyze data in real time and quickly identify abnormal behavior of endpoint devices. Step S3 captures and parses network traffic data based on a big data streaming processing method to promptly detect potential signs of network attacks. Step S4 integrates and analyzes abnormal behavior data and attack signs to accurately predict the attack path, type and probability of occurrence. Step S5 obtains risk warning results based on the prediction results, providing timely and effective reference for network security protection. It can achieve comprehensive perception, accurate prediction and timely warning of network attacks, effectively improving network security defense capabilities.

[0050] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purpose and other advantages of the present invention can be achieved and obtained through the structures specifically pointed out in this application document.

[0051] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0052] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:

[0053] Figure 1 This is a flow chart of a network early warning method based on endpoint perception and big data attack and defense analysis in an embodiment of the present invention;

[0054] Figure 2 1 is an execution logic diagram of step S1 in an embodiment of the present invention;

[0055] Figure 3 Flowchart of the execution method of step S2 in an embodiment of the present invention;

[0056] Figure 4 Flowchart of the execution method of step S3 in an embodiment of the present invention;

[0057] Figure 5 Flowchart of the execution method of step S4 in an embodiment of the present invention;

[0058] Figure 6 4 is a flow chart of the execution method of step S5 in an embodiment of the present invention. DETAILED DESCRIPTION

[0059] The preferred embodiments of the present application are described below in conjunction with the accompanying drawings, it should be understood that the preferred embodiments described herein are merely intended to illustrate and explain the present application, and are not intended to limit the present application.

[0060] Embodiment 1

[0061] The present application provides a network early warning method based on endpoint awareness and big data attack and defense analysis, referring to Figure 1 , comprising:

[0062] S1: Collecting multi-source heterogeneous endpoint data of endpoint devices based on a distributed sensor network;

[0063] S2: Introducing an abnormality detection model based on deep learning to perform real-time dynamic analysis on the collected multi-source heterogeneous endpoint data, and identifying abnormal behavior data on the endpoint devices;

[0064] S3: Based on a big data stream processing method, real-time capturing and deep analysis of network traffic data of all endpoint devices to identify all potential network attack signs in the network;

[0065] S4: Fusion analysis of abnormal behavior data on the endpoint devices and all potential network attack signs in the network to predict the network attack types and occurrence probabilities of all attack paths;

[0066] S5: Obtaining a risk warning result based on the predicted network attack types and occurrence probabilities of all attack paths.

[0067] In this embodiment, the distributed sensor network refers to a network composed of multiple sensor nodes distributed in different locations, which work cooperatively to collect and transmit data. For example, in a large enterprise network, a network composed of sensors deployed in various offices, server rooms, etc. for collecting device information.

[0068] In this embodiment, the endpoint device refers to a terminal device connected to the network, such as a personal computer, a mobile phone, a server, etc. For example, a desktop computer used by an employee for office work is an endpoint device.

[0069] In this embodiment, multi-source heterogeneous endpoint data refers to data from different sources with different formats and structures, such as system logs from the operating system, process running detailed record information from the application, network connection state information from the network module, and hardware performance parameters from the hardware monitoring.

[0070] In this embodiment, the abnormality detection model based on deep learning refers to a model constructed using deep learning technology for detecting abnormal conditions in data. For example, a neural network model trained with a large amount of normal and abnormal data to identify whether the behavior of an endpoint device is abnormal.

[0071] In this embodiment, abnormal behavior data on an endpoint device refers to data that is different from a normal behavior pattern exhibited by the endpoint device, for example, a computer suddenly and frequently sends a large amount of data to the outside during abnormal working hours.

[0072] In this embodiment, all potential network attack signs in the network refer to various signs that may indicate that the network is under or about to be attacked, such as abnormal traffic patterns, suspicious connection requests, etc. For example, a large number of frequent connection attempts from unfamiliar IP addresses appear in the network.

[0073] In this embodiment, an attack path refers to a series of steps and paths that an attacker may take from launching an attack to achieving the target, for example, the process of invading a terminal device, obtaining permissions, and then further infiltrating the internal network.

[0074] In this embodiment, the network attack type and occurrence probability of the attack path refers to the type of attack (such as DDoS attack, SQL injection, etc.) that may occur on a specific attack path and the probability of such attack occurring. For example, the probability of an SQL injection attack occurring on a certain attack path is 30%.

[0075] In this embodiment, obtaining a risk warning result based on the predicted network attack types and occurrence probabilities for all attack paths refers to obtaining warning information about network risks based on the predicted attack types and occurrence probabilities for multiple attack paths. For example, if the probability of high-risk attacks occurring on multiple critical attack paths is predicted to be high, a serious risk warning may be issued.

[0076] The beneficial effects of the above technology are as follows: Step S1 collects multi-source heterogeneous endpoint data through a distributed sensor network to ensure the comprehensiveness and accuracy of the data. Step S2 uses a deep learning anomaly detection model to analyze data in real time and quickly identify abnormal behavior of endpoint devices. Step S3 captures and parses network traffic data based on big data streaming processing methods to promptly detect potential signs of network attacks. Step S4 integrates and analyzes abnormal behavior data and attack signs to accurately predict the attack path, type, and probability of occurrence. Step S5 obtains risk warning results based on the prediction results, providing timely and effective reference for network security protection. It can achieve comprehensive perception, accurate prediction, and timely warning of network attacks, effectively improving network security defense capabilities.

[0077] Example 2:

[0078] Based on Example 1, a network early warning method based on endpoint perception and big data attack and defense analysis, S1: Based on a distributed sensor network, in-depth collection of multi-source heterogeneous endpoint data of endpoint devices, reference Figure 2 ,include:

[0079] S101: A distributed sensor network is built using a distributed hierarchical architecture, where the distributed hierarchical architecture includes a core layer, a convergence layer, and an access layer;

[0080] S102: Based on the distributed sensor network and the data collection agent, the system logs, process operation detailed record information, network connection status information, and hardware performance parameters of the endpoint device are deeply collected as multi-source heterogeneous endpoint data of the endpoint device.

[0081] In this embodiment, the distributed sensor network is built using a distributed layered architecture. This involves constructing a network structure consisting of multiple sensor nodes in a layered manner, with different layers having different functions and responsibilities. For example, the core layer is responsible for overall control and data integration, the aggregation layer is responsible for collecting and aggregating data within a certain area, and the access layer directly connects to sensor nodes to obtain raw data.

[0082] In this embodiment, the data collection agent is a software program specifically used to collect data. For example, it can be installed on an endpoint device to collect relevant data of the device according to set rules and frequencies.

[0083] In this embodiment, the system log of the endpoint device refers to information recording various events and operations during the operation of the endpoint device operating system, such as system startup, shutdown, error information, etc.

[0084] In this embodiment, the detailed record information of the process operation of the endpoint device includes detailed information such as the start, stop, and resource usage of the process, for example, the CPU and memory usage occupied by an application.

[0085] In this embodiment, the network connection status information of the endpoint device refers to the relevant information about the connection between the device and the network, such as whether it is connected, the connected IP address, the connection speed, etc. For example, the signal strength and speed of the wireless network to which the device is currently connected.

[0086] In this embodiment, the hardware performance parameters of the endpoint device refer to indicators that reflect the hardware performance of the device, such as CPU temperature, hard disk read / write speed, graphics card performance, etc. For example, the current operating frequency and temperature of the computer CPU.

[0087] The beneficial effects of the above technical solution include: Step S101 utilizes a distributed layered architecture to build a distributed sensor network, resulting in a clear network structure and distinct layers, improving the efficiency and stability of data collection. Step S102 utilizes the distributed sensor network and data collection agent to comprehensively collect multifaceted data from endpoint devices, ensuring data diversity and integrity. This enables the construction of an efficient and stable sensor network, enabling comprehensive and in-depth collection of multi-source, heterogeneous data from endpoint devices, providing a rich and accurate data foundation for subsequent network early warning analysis.

[0088] Example 3:

[0089] Based on Example 1, a network early warning method based on endpoint perception and big data attack and defense analysis, S2: Introducing an anomaly detection model based on deep learning to perform real-time dynamic analysis on the collected multi-source heterogeneous endpoint data to identify abnormal behavior data on the endpoint device, refer to Figure 3 ,include:

[0090] S201: Conduct in-depth training based on massive normal behavior data and abnormal behavior data to establish an anomaly detection model;

[0091] S202: Perform real-time dynamic analysis on the collected multi-source heterogeneous endpoint data based on the anomaly detection model to identify abnormal behavior data on the endpoint device.

[0092] In this embodiment, massive normal behavior data and abnormal behavior data refer to a large amount of data related to normal and abnormal operations of endpoint devices, such as the operation records of thousands of computers during normal use and abnormal operation records when attacked or malfunctioning.

[0093] In this embodiment, deep training based on massive amounts of normal and abnormal behavior data to build an anomaly detection model involves utilizing a large amount of normal and abnormal behavior data, using specific algorithms and techniques to enable the model to learn and understand normal and abnormal patterns, thereby building a model capable of determining whether new data is abnormal. For example, using a deep learning algorithm, the model can be trained on a large amount of normal computer Internet behavior data and abnormal data during virus attacks to build a model capable of identifying whether new computer operations are abnormal.

[0094] In this embodiment, real-time dynamic analysis of collected multi-source, heterogeneous endpoint data based on an anomaly detection model is performed to identify abnormal behavior data on endpoint devices. This means using an established anomaly detection model to instantly and continuously analyze newly collected endpoint device data from various sources and in various forms to identify any abnormalities within the device. For example, the established model can be used to analyze multi-source data collected in real time, such as system logs and network traffic from a particular computer, to determine whether there are any abnormal access requests or signs of system crashes.

[0095] The beneficial effects of the above technical solution include: Step S201 establishes an anomaly detection model through deep training on massive data, resulting in excellent generalization and accuracy. Step S202 utilizes the trained anomaly detection model to analyze real-time collected data, enabling rapid and accurate identification of abnormal behavior on endpoint devices. This enables efficient and accurate detection of abnormal behavior on endpoint devices, providing critical anomaly data support for network early warning.

[0096] Example 4:

[0097] Based on Example 1, a network early warning method based on endpoint perception and big data attack and defense analysis, S3: Based on the big data streaming method, the network traffic data of all endpoint devices is captured in real time and deeply analyzed to identify all potential network attack signs in the network, refer to Figure 4 ,include:

[0098] S301: Capture network traffic data of all endpoint devices in real time based on a big data streaming processing method;

[0099] S302: Constructing a traffic model based on probability statistics theory;

[0100] S303: Use a traffic model based on probability statistics theory to model and deeply analyze abnormal phenomena in the network traffic data of all endpoint devices to identify all potential signs of network attacks in the network.

[0101] In this embodiment, capturing network traffic data from all endpoint devices in real time based on a big data streaming method involves using technologies that can rapidly process continuous data streams to promptly obtain information such as the volume and direction of data generated by all endpoint devices during network communications. For example, using technologies such as Flume or Kafka can capture real-time network traffic data generated by all employees' computers while they are online.

[0102] In this embodiment, endpoint device network traffic data refers to information such as the amount of data transmission, transmission direction, and transmission protocol generated by endpoint devices (such as computers and mobile phones) when interacting with the network. For example, it may include which websites a computer visited within an hour, the amount of data downloaded and uploaded, etc.

[0103] In this embodiment, constructing a traffic model based on probability and statistics theory refers to establishing a mathematical model for describing and analyzing network traffic characteristics and patterns based on the principles and methods of probability and statistics. For example, by analyzing a large amount of historical network traffic data, a model can be established that can predict peak and low traffic periods, as well as the probability of different traffic levels.

[0104] In this embodiment, a traffic model based on probability and statistics theory is used to model and deeply analyze anomalies in the network traffic data of all endpoint devices, thereby identifying all potential signs of network attacks in the network. This means using the constructed traffic model to analyze and interpret patterns in the real-time network traffic data of endpoint devices that do not conform to normal traffic patterns, thereby discovering possible signs of network attacks. For example, if the network traffic of a device suddenly increases significantly within a certain period of time, far exceeding the normal range predicted by the model, it may be a sign of a potential DDoS attack.

[0105] The beneficial effects of the above technical solution include: Step S301 utilizes big data streaming processing methods to capture network traffic data in real time, ensuring data timeliness and integrity. Step S302 constructs a traffic model based on probability and statistics theory, providing a scientific method and basis for analyzing anomalies. Step S303 uses the traffic model to model and deeply analyze anomalies, accurately identifying potential signs of network attacks. This enables real-time processing of network traffic data and effective identification of potential attack signs, improving the timeliness and accuracy of network warnings.

[0106] Example 5:

[0107] On the basis of Example 1, a network early warning method based on endpoint perception and big data attack and defense analysis, S4: Fusion analysis of abnormal behavior data on endpoint devices and all potential network attack signs in the network, predicting the types and occurrence probabilities of network attacks for all attack paths, reference Figure 5 ,include:

[0108] S401: Perform fusion analysis on abnormal behavior data on endpoint devices and all potential network attack signs in the network to identify all association rules;

[0109] S402: Abnormal behavior data on endpoint devices is used as node attributes of the corresponding endpoint devices, and all potential network attack signs and all association rules in the network are used as edge attributes of the corresponding connection relationships, thereby constructing a graph model that includes all endpoint devices and corresponding node attributes, network nodes and corresponding connection relationships, and all edge attributes;

[0110] S403: The network attack types and occurrence probabilities of all attack paths predicted based on the graph model.

[0111] In this embodiment, a fusion analysis of abnormal behavior data on endpoint devices and all potential network attack indicators is performed to identify all association rules. This involves combining the abnormal behavior data from endpoint devices with data on various network indicators that indicate a possible attack, conducting in-depth research and processing to identify the inherent connections and patterns between them. For example, if a certain endpoint device is experiencing an abnormally large amount of data upload behavior, and there is also an abnormal increase in traffic on a specific port in the network, the fusion analysis can identify a correlation between the two, indicating that they may be different manifestations of an organized network attack. This is the identified association rule.

[0112] In this embodiment, an association rule refers to the relationship between features or events that frequently occur together in a dataset. For example, if, during data analysis of endpoint devices, it is discovered that whenever a specific process is running on the device, a specific network connection status is also likely to occur, this connection between the two is an association rule.

[0113] In this embodiment, a graph model is a model structure that uses nodes and edges to represent relationships between data. Nodes represent objects, and edges represent relationships between objects. For example, in network security analysis, nodes can be endpoint devices, and edges can represent communication paths between devices or attack propagation paths.

[0114] The beneficial effects of the above technical solution include: Step S401 performs a fusion analysis of abnormal behavior data and potential network attack signs to identify association rules, providing a foundation for subsequent model construction. Step S402 constructs a graph model using abnormal behavior data as node attributes and potential network attack signs and association rules as edge attributes, intuitively presenting the complex relationships within the network. Step S403 performs predictions based on the graph model, enabling a more comprehensive and accurate determination of attack paths, types, and occurrence probabilities. Through fusion analysis and graph model construction, a deep understanding and accurate prediction of network attacks are achieved, improving the accuracy and reliability of network early warnings.

[0115] Example 6:

[0116] Based on Example 5, the network early warning method based on endpoint perception and big data attack and defense analysis, S403: The network attack types and occurrence probabilities of all attack paths predicted based on the graph model include:

[0117] Use heuristic search algorithms to crawl and reason about the graph model to infer all attack paths;

[0118] Based on each attack path, the abnormal behavior data on all endpoint devices, all potential network attack signs in the network, and all association rules are serially marked to obtain the attack information index path of each attack path;

[0119] Based on the attack pattern and purpose identification model, the attack information index path of each attack path is analyzed to identify all types of network attacks;

[0120] The attack information index path of each attack path is analyzed to determine the occurrence probability of each attack path.

[0121] In this embodiment, the attack path refers to the series of steps and nodes that the attacker takes from the starting point to the target point in the network. For example, the process from the entry device invaded by an external hacker, passing through several intermediate servers, and finally reaching the target database.

[0122] In this embodiment, based on each attack path, abnormal behavior data from all endpoint devices, all potential network attack indicators in the network, and all association rules are concatenated and marked to obtain an attack information index path for each attack path. This means that along each possible attack path, the abnormal behavior data of the endpoint devices, potential attack indicators, and association rules associated with it are sequentially concatenated and marked, forming a path that clearly reflects the relevant information of the attack path. For example, an attack path sequentially concatenates the abnormal login behavior of device A, the suspicious increase in network traffic, and the association rules between the two, and marks them accordingly, forming the attack information index path for that attack path.

[0123] In this embodiment, the attack pattern and purpose identification model is a model used to determine the attack method (such as DDoS attack, SQL injection, etc.) and the attacker's intention (such as stealing data, destroying the system, etc.). For example, by analyzing and learning from a large number of known attack cases, a model is established that can determine the attack pattern and purpose based on the attack characteristics.

[0124] In this embodiment, based on the attack pattern and purpose identification model, the attack information index path of each attack path is analyzed to identify the types of all network attacks. This means using the aforementioned model to conduct a detailed study and judgment of the relevant information path of each attack path to determine the specific attack type. For example, by analyzing the various information in the index path of a certain attack path, the model determines that it is a SQL injection attack.

[0125] In this embodiment, the attack information index path of an attack path is formed by concatenating and labeling various key information involved in the attack path (such as abnormal behavior data, attack signs, association rules, etc.), which is used to comprehensively reflect the characteristics and related information of the attack path. For example, the attack information index path of an attack path may include the concatenation and labeling of information such as abnormal IP connection records of devices, abnormal traffic on specific ports, and the associations between them.

[0126] The beneficial effects of the above technical solution include: using a heuristic search algorithm to crawl the inference graph model, it can efficiently infer attack paths and improve the speed of early warning. By concatenating attack information index paths that mark attack paths, it provides clear and specific clues for subsequent analysis. Based on the attack pattern and purpose recognition model, it can identify attack types, enhancing the accuracy and professionalism of attack classification. Determining the probability of each attack path provides a quantitative decision-making basis for network security defense. The ability to accurately predict attack paths, types, and occurrence probabilities provides comprehensive, in-depth, and effective support for network early warning and defense.

[0127] Example 7:

[0128] On the basis of embodiment 6, the network early warning method based on endpoint awareness and big data attack and defense analysis uses heuristic search algorithm to crawl and infer the graph model to speculate all attack paths, including:

[0129] Obtain the security risk assessment value of each node in the graph model;

[0130] Based on the network structure of the graph model and the security risk assessment value of each node in the graph model, a heuristic function h(n) is constructed:

[0131]

[0132] In the formula, n is the current node in the graph model, e t is the target node in the graph model, E is the target node set in the graph model, a is the distance factor weight, d(n, e t ) is the shortest path distance between the current node n and the target node e t in the graph model, β is the security factor weight, and S(n) is the security risk assessment value of the current node in the graph model.

[0133] Based on the link attribute value of each minimum unit link in the graph model, the attack transmission tendency degree of each minimum unit link in the graph model is calculated, and based on the attack transmission tendency degree of each minimum unit link in the graph model, an actual cost function g(n) is constructed:

[0134]

[0135] In the formula, e ij is the minimum unit link between the i-th node and the j-th node in the graph model, path(n, e t ) is the shortest path between the current node n and the target node e t in the graph model, ω ij is the attack transmission tendency degree of the minimum unit link between the i-th node and the j-th node in the graph model.

[0136] Based on the heuristic function and the actual cost function, all attack paths in the graph model are searched.

[0137] In this embodiment, obtaining the security risk assessment value of each node in the graph model means determining the quantitative value of the security risk faced by each node representing an endpoint device or a network element in the graph model. For example, a server represented by a certain node is evaluated as having high security risk, and its security risk assessment value may be 80 (assuming that 0-100 represents the risk degree, and 100 is the highest risk).

[0138] In this embodiment, the attack propagation propensity of each minimum unit link in the graph model is calculated based on the link attribute values ​​of each minimum unit link in the graph model. This means that based on the relevant characteristic values ​​of the most basic link representing the connection relationship in the graph model, the probability of this link propagating an attack when attacked is calculated. For example, if a link's attribute values ​​indicate high bandwidth, a large number of connected devices, and low security, then its attack propagation propensity is likely to be high. The following is an example of a simple calculation method: Assume that bandwidth, number of connected devices, and security are represented by values ​​from 1 to 10, with higher bandwidth indicating higher values, more connected devices indicating higher values, and lower security indicating lower values. A link has a bandwidth of 8, 7 connected devices, and a security of 2. Attack propagation propensity = bandwidth × 0.3 + number of connected devices × 0.3 - security × 0.4. This calculates that the link has a high attack propagation propensity. The specific weights and calculation method can be adjusted according to actual circumstances.

[0139] In this embodiment, the minimum unit link is the part of the graph model that represents the most basic connection between two nodes. For example, in a network topology graph model, the line directly connecting two adjacent routers or endpoint devices is considered a minimum unit link.

[0140] In this embodiment, the link attribute value of the minimum unit link refers to a value describing the characteristics of the minimum unit link, such as bandwidth, delay, packet loss rate, security level, etc. For example, the bandwidth attribute value of a minimum unit link is 100 Mbps, and the security level attribute value is low.

[0141] The beneficial effects of the above technical solution include: obtaining node security risk assessment values ​​provides key data for constructing heuristic functions, making the search more targeted. The constructed heuristic function comprehensively considers distance and security risk factors, effectively guiding the search direction and improving search efficiency. The attack transmission propensity of each minimum unit link is calculated and the actual cost function is constructed, accurately reflecting the attack transmission characteristics of the link. Searching for attack paths based on the heuristic function and the actual cost function enables a more comprehensive and accurate inference of all possible attack paths. Through scientific function construction and path search methods, the accuracy and efficiency of attack path inference are improved, providing strong support for network early warning.

[0142] Example 8:

[0143] Based on Example 7, the network early warning method based on endpoint perception and big data attack and defense analysis searches for all attack paths in the graph model based on heuristic functions and actual cost functions, including:

[0144] Determine the start node and target node set in the graph model based on the security risk assessment value of each node in the graph model;

[0145] Taking all the starting nodes in the graph model as the first current node, and taking the sum of the output value of the heuristic function and the output value of the actual cost function as the minimum principle, selection and expansion are carried out in the target node set to search out all attack paths.

[0146] In this embodiment, determining the starting node and target node sets in the graph model based on the security risk assessment value of each node in the graph model refers to selecting a set of starting nodes that are considered to be the attack initiation location and nodes that are likely to be the final target of the attack based on the security risk assessment values ​​of each node in the graph model. For example, if certain nodes have extremely high security risk assessment values, they may be identified as starting nodes, while certain nodes containing important data or critical services may be identified as elements of the target node set.

[0147] In this embodiment, all starting nodes in the graph model are used as the first current nodes. Based on the principle of minimizing the sum of the output value of the heuristic function and the output value of the actual cost function, selection and expansion are performed within the target node set to search for all possible attack paths. This means that all determined starting nodes are used as the initial analysis points. Then, based on the principle of minimizing the sum of the expected optimal path value calculated by the heuristic function and the actual cost value calculated by the actual cost function, the next node is selected from the target node set for path extension and exploration, thereby finding all possible attack paths. For example, given a starting node A and a target node set {B, C, D}, the sum of the heuristic function and the actual cost function from A to B, A to C, and A to D is calculated, and the path with the smallest sum is selected for expansion. This process is repeated until all possible attack paths are found.

[0148] The beneficial effects of the above technical solution include: determining the starting and target node sets based on the node's security risk assessment value, clarifying the scope and direction of path search. Selecting and expanding based on the principle of minimizing the sum of the output values ​​of the heuristic function and the actual cost function enables optimal selection when searching for attack paths, improving search accuracy and efficiency. This allows for more accurate and efficient search of all possible attack paths within the graph model, providing a more reliable basis for network early warning.

[0149] Example 9:

[0150] Based on Example 6, the network early warning method based on endpoint perception and big data attack and defense analysis analyzes the attack information index path of each attack path to determine the occurrence probability of each attack path, including:

[0151] Based on the historical attack record data of all endpoint devices, the probability of each minimum unit link in the attack information index path of each attack path under the premise of the previous minimum unit link is evaluated;

[0152] The occurrence probability of each attack path is calculated based on the conditional occurrence probability of each minimum unit link in the attack information index path under the premise of the previous minimum unit link.

[0153] In this embodiment, the historical attack record data of the endpoint device refers to the relevant records of various attacks that the endpoint device has experienced in the past, including information such as the time, type, source, and impact of the attack. For example, a computer may have a detailed record of virus attacks, network intrusions, etc.

[0154] In this embodiment, based on historical attack records for all endpoint devices, the probability of each minimum unit link in the attack information index path occurring conditionally under the previous minimum unit link is evaluated. This means that based on the historical attack patterns of all endpoint devices, the probability of the next minimum unit link occurring on a particular attack path, given that the previous minimum unit link has already occurred, is inferred. For example, in an attack path, if the first link is known to be a device being tentatively connected to by an external IP address, the probability of the second link being a login attempt to the device, in this case, is estimated based on historical data.

[0155] In this embodiment, the conditional occurrence probability of each minimum unit link in the attack information index path under the premise of the previous minimum unit link means that in a specific attack information index path, the occurrence of a certain minimum unit link is conditional on the occurrence of its previous minimum unit link, and the probability of occurrence under this condition is calculated.

[0156] In this embodiment, the probability of occurrence of each attack path is calculated based on the conditional probability of occurrence of each minimum unit link in the attack information index path of each attack path under the premise of the previous minimum unit link. This is to comprehensively consider the conditional probability of each link in the attack path and obtain the overall probability of occurrence of the entire attack path by multiplication or other methods.

[0157] The beneficial effects of the above technical solution include: By evaluating the probability of a conditional occurrence based on historical attack record data, the probability assessment is backed by actual data, making it more accurate and reliable. By calculating the probability of each attack path, the probability of each attack path is determined, providing a more detailed picture of the likelihood of the attack path. The ability to scientifically and accurately determine the probability of each attack path provides more valuable quantitative information for network early warning, contributing to more effective network security defense and risk response.

[0158] Example 10:

[0159] On the basis of Example 1, a network early warning method based on endpoint perception and big data attack and defense analysis, S5: obtaining risk early warning results based on the network attack types and occurrence probabilities of all predicted attack paths, refer to Figure 6 ,include:

[0160] S501: Perform risk prediction based on the pre-built risk prediction model and the predicted network attack types and occurrence probabilities of all attack paths to obtain predicted risk values ​​for all predicted attack paths;

[0161] S502: When the predicted risk value of the attack path exceeds the set risk threshold, the risk warning mechanism is triggered and a risk warning result is obtained.

[0162] In this embodiment, the predicted risk value of an attack path refers to a quantitative value of the risk level that the attack path may bring, which is predicted through analysis and evaluation of the attack path. For example, the predicted risk value of an attack path may be assessed as 80 (assuming that 0-100 represents the risk level, with 100 being the highest risk).

[0163] In this embodiment, the risk threshold is a predetermined threshold used to determine whether the risk reaches a threshold at which action needs to be taken. For example, the risk threshold is set to 60. When the predicted risk value exceeds 60, it is considered necessary to take corresponding measures.

[0164] In this embodiment, the risk warning mechanism is a set of processes and measures that are automatically activated when a risk is predicted to exceed a certain level, used to notify relevant personnel and take appropriate action. For example, this includes sending an alert email, text message notification to the administrator, and automatically launching a protection program.

[0165] In this embodiment, the risk warning result is the final output generated by the risk warning mechanism, including the specific risk situation, recommended response measures, and other information. For example, the risk warning result may be "The predicted risk value of a certain attack path is 85. It is recommended to immediately disconnect the relevant connection and conduct a system inspection."

[0166] The beneficial effects of the above technical solution include: Step S501 utilizes a pre-built risk prediction model to predict risk based on the type and probability of attack paths, enabling a comprehensive and integrated assessment of risk conditions. Step S502 triggers an early warning mechanism when the predicted risk value exceeds a set threshold, ensuring timely detection of high-risk attack paths and improving the timeliness and effectiveness of early warnings. Accurately assessing the risk of attack paths and issuing timely warnings provides strong support for network security protection, reducing the likelihood of network attacks and the resulting losses.

[0167] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.

Claims

1. A network early warning method based on endpoint perception and big data attack and defense analysis, characterized in that: include: S1: Deeply collect multi-source heterogeneous endpoint data of endpoint devices based on distributed sensor networks; S2: Introducing a deep learning-based anomaly detection model to perform real-time dynamic analysis on collected multi-source heterogeneous endpoint data to identify abnormal behavior data on endpoint devices; S3: Based on big data streaming processing methods, it captures and deeply analyzes network traffic data from all endpoint devices in real time to identify all potential signs of network attacks; S4: Fusion analysis of abnormal behavior data on endpoint devices and all potential network attack signs in the network to predict the types and probability of network attacks along all attack paths. S5: Obtain risk warning results based on the types and occurrence probabilities of network attacks along all predicted attack paths.

2. The network early warning method based on endpoint perception and big data attack and defense analysis according to claim 1 is characterized in that: S1: Based on a distributed sensor network, we collect multi-source heterogeneous endpoint data from endpoint devices, including: S101: A distributed sensor network is built using a distributed hierarchical architecture, where the distributed hierarchical architecture includes a core layer, a convergence layer, and an access layer; S102: Based on the distributed sensor network and the data collection agent, the system logs, process operation detailed record information, network connection status information, and hardware performance parameters of the endpoint device are deeply collected as multi-source heterogeneous endpoint data of the endpoint device.

3. The network early warning method based on endpoint perception and big data attack and defense analysis according to claim 1 is characterized in that: S2: Introducing a deep learning-based anomaly detection model to perform real-time dynamic analysis on collected multi-source heterogeneous endpoint data, identifying abnormal behavior data on endpoint devices, including: S201: Conduct in-depth training based on massive normal behavior data and abnormal behavior data to establish an anomaly detection model; S202: Perform real-time dynamic analysis on the collected multi-source heterogeneous endpoint data based on the anomaly detection model to identify abnormal behavior data on the endpoint device.

4. The network early warning method based on endpoint perception and big data attack and defense analysis according to claim 1 is characterized in that: S3: Based on big data streaming methods, it captures and deeply analyzes network traffic data from all endpoint devices in real time, identifying all potential network attack signs in the network, including: S301: Capture network traffic data of all endpoint devices in real time based on a big data streaming processing method; S302: Constructing a traffic model based on probability statistics theory; S303: Use a traffic model based on probability statistics theory to model and deeply analyze abnormal phenomena in the network traffic data of all endpoint devices to identify all potential signs of network attacks in the network.

5. The network early warning method based on endpoint perception and big data attack and defense analysis according to claim 1 is characterized in that: S4: Fusion analysis of abnormal behavior data on endpoint devices and all potential network attack signs in the network is performed to predict the types and probability of network attacks along all attack paths, including: S401: Perform fusion analysis on abnormal behavior data on endpoint devices and all potential network attack signs in the network to identify all association rules; S402: Abnormal behavior data on endpoint devices is used as node attributes of the corresponding endpoint devices, and all potential network attack signs and all association rules in the network are used as edge attributes of the corresponding connection relationships, thereby constructing a graph model that includes all endpoint devices and corresponding node attributes, network nodes and corresponding connection relationships, and all edge attributes; S403: The network attack types and occurrence probabilities of all attack paths predicted based on the graph model.

6. The network early warning method based on endpoint perception and big data attack and defense analysis according to claim 5 is characterized in that: S403: The network attack types and occurrence probabilities of all attack paths predicted based on the graph model include: Use heuristic search algorithms to crawl and reason about the graph model to infer all attack paths; Based on each attack path, the abnormal behavior data on all endpoint devices, all potential network attack signs in the network, and all association rules are serially marked to obtain the attack information index path of each attack path; Based on the attack pattern and purpose identification model, the attack information index path of each attack path is analyzed to identify all types of network attacks; The attack information index path of each attack path is analyzed to determine the occurrence probability of each attack path.

7. The network early warning method based on endpoint perception and big data attack and defense analysis according to claim 6 is characterized in that: Use heuristic search algorithms to crawl and reason about the graph model and infer all attack paths, including: Obtain the security risk assessment value of each node in the graph model; The heuristic function h(n) is constructed based on the network structure of the graph model and the security risk assessment value of each node in the graph model: Where n is the current node in the graph model, e t is the target node in the graph model, E is the target node set in the graph model, α is the distance factor weight, d(n,e t ) is the current node n and the target node e in the graph model t The shortest path distance between them, β is the safety factor weight, and S(n) is the safety risk assessment value of the current node in the graph model; Based on the link attribute value of each minimum unit link in the graph model, the attack transmission tendency of each minimum unit link in the graph model is calculated, and the actual cost function g(n) is constructed based on the attack transmission tendency of each minimum unit link in the graph model: Where, e ij is the minimum unit link between the i-th node and the j-th node in the graph model, path(n,e t ) is the current node n and the target node e in the graph model t The shortest path between ij is the attack transmission tendency of the minimum unit link between the i-th node and the j-th node in the graph model; All attack paths are searched in the graph model based on the heuristic function and the actual cost function.

8. The network early warning method based on endpoint perception and big data attack and defense analysis according to claim 7 is characterized in that: Based on the heuristic function and the actual cost function, all attack paths are searched in the graph model, including: Determine the start node and target node set in the graph model based on the security risk assessment value of each node in the graph model; Taking all the starting nodes in the graph model as the first current node, and taking the sum of the output value of the heuristic function and the output value of the actual cost function as the minimum principle, selection and expansion are carried out in the target node set to search out all attack paths.

9. The network early warning method based on endpoint perception and big data attack and defense analysis according to claim 6 is characterized in that: Analyze the attack information index path of each attack path to determine the occurrence probability of each attack path, including: Based on the historical attack record data of all endpoint devices, the probability of each minimum unit link in the attack information index path of each attack path under the premise of the previous minimum unit link is evaluated; The occurrence probability of each attack path is calculated based on the conditional occurrence probability of each minimum unit link in the attack information index path under the premise of the previous minimum unit link.

10. The network early warning method based on endpoint perception and big data attack and defense analysis according to claim 1 is characterized in that: S5: Obtain risk warning results based on the types and occurrence probabilities of network attacks for all predicted attack paths, including: S501: Perform risk prediction based on the pre-built risk prediction model and the predicted network attack types and occurrence probabilities of all attack paths to obtain predicted risk values ​​for all predicted attack paths; S502: When the predicted risk value of the attack path exceeds the set risk threshold, the risk warning mechanism is triggered and a risk warning result is obtained.

Citation Information

Patent Citations

  • Host security depth defense method and device

    CN118157922A

Cited By

  • Industrial end node data tamper-proofing method and system based on Internet of Things

    CN121125353A