An intrusion detection system based on big data analysis
By constructing a communication feature library and generating cloud node sequences through random sampling sequences, and combining encrypted storage and decryption reproduction to verify access behavior, the problem of intruders masquerading as legitimate individuals to access the network is solved, thereby improving the data security of distributed storage and the reliability of intrusion detection.
Patent Information
- Application Number
- CN202511241951.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-02
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2045-09-02
AI Technical Summary
In existing technologies, intruders can easily bypass verification and access target nodes after posing as legitimate individuals. The lack of constraints on access behavior leads to poor data storage security in distributed storage. In particular, under traversal path probing attacks, intruders may read fragmented data and reassemble it.
The communication characteristics of the cloud storage database are captured by the capture module, a communication characteristic library is built, random sampling sequences and sampling data packets are generated, and cloud node sequences are generated by combining the corresponding relationships of cloud storage nodes. The sequences are then encrypted, stored, and decrypted for reproduction. An access confidence list is built for verification to determine abnormal access.
It improves data security and the reliability of intrusion detection. By using unpredictable communication characteristics and random sampling sequences, it dynamically constrains access behavior, blocks intruders who disguise themselves as legitimate individuals, and promptly detects abnormal access.
Smart Images

Figure CN120811756B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data protection, and more particularly to an intrusion detection system based on big data analytics. Background Technology
[0002] With the development of internet and cloud technologies, data can be uploaded from the sending end to cloud storage and shared with a designated receiving end, involving multi-terminal interaction. The security of data interaction is crucial. Traditional intrusion detection systems mostly use identity verification or anomaly detection based on static rule bases or single data sources, which are difficult to deal with complex attacks against distributed cloud storage environments, especially those that attempt to gain access by masquerading as legitimate individuals. This can easily lead to data tampering or loss. Therefore, intrusion detection technologies have gained significant attention.
[0003] Chinese Patent Publication No. CN107483413A discloses a cloud-based bidirectional intrusion detection system and method, and a cognitive radio network, comprising: initialization, data acquisition, data transmission, data processing, malicious behavior determination, internal attack determination, attack alert, and malicious user handling. This invention combines the ultra-large scale, dynamic resource expansion, and massive information processing capabilities of cloud computing, utilizing cloud computing to save time compared to proxy traversal intrusion detection methods in distributed networks. Depending on the attack target, intelligent agents and cloud servers detect attacks targeting the channel, while secondary nodes detect attacks targeting the terminal, simplifying the functions of secondary users and intelligent agents and saving significant communication costs associated with reporting data to the cloud server. The intelligent agents and cloud servers perform behavior detection on internal secondary users, solving the problem of potential internal attacks in cognitive radio networks.
[0004] However, the following problems still exist in the existing technology:
[0005] In existing technologies, after an intruder impersonates a legitimate identity, it is easy to bypass verification and access the target node. There is a lack of constraints on access behavior. In distributed storage, intruders may use traversal path probing attacks to traverse and access nodes, read fragmented data, and reassemble it, resulting in poor data storage security. Summary of the Invention
[0006] To address this, the present invention provides an intrusion detection system based on big data analysis to overcome the problems in existing technologies where intruders can easily bypass verification and access target nodes after masquerading as legitimate individuals, lack constraints on access behavior, and in distributed storage, intruders may employ traversal path probing attacks, traversing and accessing nodes to read fragmented data for reassembly, resulting in poor data storage security.
[0007] To achieve the above objectives, the present invention provides an intrusion detection system based on big data analysis, comprising:
[0008] The capture module is used to capture the communication characteristics of the cloud storage database at several sampling times according to a predetermined time interval and place them in the communication characteristic library;
[0009] The sampling module is used to acquire the data to be sent from the sending end, cut the data to be sent into segments, determine the number of segments, randomly generate a corresponding number of sampling intervals, arrange them to obtain a sampling sequence and record the completion timestamp, and encapsulate the sampling sequence, the completion timestamp and the identity identifier group into a sampling data packet.
[0010] The sequence generation module is used to call communication features at several sampling times from the communication feature library based on the sampled data packet, and generate a cloud node sequence by combining the range of each communication feature with the correspondence between each cloud storage node in the cloud storage database.
[0011] The slice storage module is used to encrypt and send the sampled data packets, and synchronously store each slice to the cloud storage database based on the cloud node sequence;
[0012] The reproduction module is used to decrypt the sampled data packets received by the receiving end, call the communication characteristics of several sampling times, reproduce the cloud node sequence, access each of the cloud storage nodes to obtain each of the slices, and combine to reproduce the data to be sent.
[0013] The verification module is used to receive sampled data packets, generate a communication feature database access confidence list and a cloud storage access confidence list corresponding to the identity group, and perform verification based on the access records of the communication feature database and the access records of the cloud storage database to determine whether there is any access anomaly.
[0014] The identity identifier group includes the receiver's identity identifier and the sender's identity identifier.
[0015] Furthermore, the crawling module crawls the communication characteristics of the cloud storage database at several sampling times, including:
[0016] It is used to capture the bandwidth utilization, node occupancy rate and packet loss rate of the cloud storage database at a certain sampling time according to a predetermined time interval;
[0017] This is used to sum the bandwidth utilization, node occupancy, and packet loss rate in a weighted manner to obtain the communication characteristics.
[0018] Furthermore, the sampling module is used to randomly generate a corresponding number of sampling intervals, which, after being arranged, result in a sampling sequence including:
[0019] Used to determine the number of slices;
[0020] The sampling intervals are randomly generated within a predetermined sampling interval range, and then sorted according to the generation order to obtain the sampling sequence.
[0021] The sampling interval is an integer multiple of the time interval.
[0022] Furthermore, the sequence generation module is used to retrieve communication features corresponding to several time points from the communication feature library based on the sampled data packets, including:
[0023] Used to call the completion timestamp, and the sampling time closest to the completion timestamp is determined from the communication feature library;
[0024] Used to call the sampling sequence, calling the sampling intervals in the sampling sequence one by one in reverse order, taking the sampling time as the starting time, and marking several sampling times one by one in the negative direction of the sampling time axis according to the called sampling intervals;
[0025] Communication features selected for each sampling time can be retrieved from the communication feature library;
[0026] The sampling time axis includes the sampling times corresponding to all communication features in the communication feature library.
[0027] Furthermore, the sequence generation module combines the correspondence between each communication feature range and each cloud storage node in the cloud storage database to generate a cloud node sequence, including:
[0028] Used to pre-build the correspondence between cloud storage nodes and communication feature ranges;
[0029] This is used to determine the range of communication features to which each communication feature falls based on the temporal order of the sampling time corresponding to the communication feature;
[0030] The cloud storage nodes corresponding to each of the aforementioned communication feature ranges are determined one by one, and the cloud storage nodes are arranged according to their corresponding numbers to obtain a cloud node sequence.
[0031] Among them, cloud storage nodes correspond one-to-one with communication feature ranges.
[0032] Furthermore, the slice storage module is used to store each slice to a cloud storage database based on a cloud node sequence, including:
[0033] Used to determine the cloud storage node to be stored based on the number in the cloud node sequence;
[0034] Used to store each of the slices to the corresponding cloud storage node;
[0035] Each slice is stored on a single cloud storage node.
[0036] Furthermore, the reproduction module is used to reproduce the cloud node sequence, access each of the cloud storage nodes to obtain each of the slices, and combine them to reproduce the data to be sent, including...
[0037] This is used to generate a cloud node sequence by combining the correspondence between each communication feature range and each cloud storage node in the cloud storage database;
[0038] This is used to access the cloud storage nodes corresponding to the labels one by one according to the cloud node sequence, obtain the slices in the cloud storage nodes, and combine the slices to reproduce the data to be sent.
[0039] Furthermore, the verification module generates a communication feature library access confidence list and a cloud storage access confidence list based on the sampled data packets, including:
[0040] Used to generate a communication feature database access confidence list corresponding to the identity group;
[0041] Used to retrieve communication features at several sampling times from the communication feature library based on the sampled data packets, and record the communication features at each sampling time into the communication feature library access confidence list;
[0042] Used to generate a cloud storage access confidence list corresponding to the identity group;
[0043] Used to determine the cloud node sequence based on the sampled data packet, and store the cloud node sequence in the cloud storage access confidence list;
[0044] Each identity group corresponds to a unique communication feature database access confidence list.
[0045] Furthermore, the verification module performs verification based on access records from the communication feature database and access records from the cloud storage database, including:
[0046] Used to determine the identity of the access object to the communication feature database, and to call the communication feature database access confidence list corresponding to the identity;
[0047] Used to obtain the access records of the accessed object, determine the obtained communication characteristics, and determine whether they all belong to the access confidence list of the communication characteristic library;
[0048] Used to determine the identity of the access object to the cloud storage database, and to call the cloud storage access confidence list corresponding to the identity;
[0049] This is used to obtain the access records of the accessed object, determine the accessed cloud node sequence number, and generate a real-time access sequence in real time according to the access order, so as to determine whether the real-time access sequence matches the cloud node sequence in the cloud storage access confidence list.
[0050] If the real-time access sequence is the same as the cloud node sequence or any subsequence of the cloud node sequence, then a match is determined.
[0051] Furthermore, the verification module determines whether there is an access anomaly by including:
[0052] If the abnormal conditions are met, the access is deemed abnormal;
[0053] If the abnormal conditions are not met, the access is determined to be normal;
[0054] The abnormal condition is that all the acquired communication features belong to the communication feature library access confidence list and the real-time access sequence matches the cloud node sequence in the cloud storage access confidence list.
[0055] Compared with existing technologies, this invention captures communication features at different sampling times using a capture module to construct a communication feature library. A sampling module generates random sampling sequences and constructs sampling data packets. A sequence generation module combines the correspondence between each communication feature range and each cloud storage node in the cloud storage database to generate a cloud node sequence. A slice storage module stores slices to the corresponding cloud storage nodes based on the cloud node sequence. A reproduction module, based on the sampling data packets received by the receiving end, calls the communication features at several sampling times to reproduce the cloud node sequence, accesses each cloud storage node to obtain each slice, and combines to reproduce the data to be sent. A verification module constructs a communication feature library access confidence list and a cloud storage access confidence list, verifies records, and determines whether there are any access anomalies. This invention utilizes the unpredictability of communication features to change the data interaction behavior between terminals, changes the cloud storage nodes under distributed storage, and incorporates data storage behavior and access behavior to cloud storage nodes into verification, thereby improving data security and the reliability of intrusion detection.
[0056] In particular, this invention captures the communication characteristics of cloud storage nodes to construct a communication characteristic library. In reality, the communication characteristics of cloud storage nodes are affected by various factors and are usually subject to certain changes, which are unpredictable. Furthermore, this invention randomly generates sampling intervals to generate sampling sequences, thereby constructing sampling data packets. When the sending end needs to send data, it calls the sampling sequence in the sampling data packet to sample the communication characteristics in the communication characteristic library. Due to the unpredictability of communication characteristics and the randomness of sampling sequences, the captured communication characteristics are different each time the sending end needs to send data. Consequently, the cloud node sequence constructed based on the communication characteristics is also different, and the storage location when storing slices based on the cloud node sequence is also different. Based on this, the data sending behavior of the sending end is unpredictable, and the storage location of each slice sent is different. This facilitates the subsequent setting of corresponding dynamic access logic for cloud storage nodes, and the dynamic access logic can be used as a constraint to verify whether there are any abnormalities in the access behavior, thereby improving data security and the reliability of intrusion detection.
[0057] In particular, the receiving end of this invention reproduces the cloud node sequence based on the sampled data packets and accesses the cloud storage database to obtain each slice. Due to the construction logic of the sampled data packets, the sampled data packets constructed by the sending end are different each time data is sent, which constrains the access behavior. The reproduction module reproduces the cloud node sequence and accesses the cloud storage database to obtain slices, making the access behavior of the cloud storage database different and unpredictable each time. Furthermore, the subsequent verification module also constructs a communication feature library access confidence list and a cloud storage access confidence list based on the sampled data packets to monitor the access behavior of the communication feature library, preventing intruders from masquerading as legitimate individuals and traversing the communication features in the communication feature library, thus blocking the possibility of reproducing the cloud node sequence. In addition, the access behavior of the cloud storage nodes is monitored. Since the access behavior of the cloud storage nodes is different each time the sending end sends data to be sent, even if an intruder masquerades as legitimate individuals and uses the form of traversing nodes to obtain slices, their access behavior can be captured, and anomalies can be detected in time, thereby improving data security and the reliability of intrusion access detection.
[0058] In particular, the entire data interaction process requires multi-terminal collaboration. For example, it is necessary to obtain a communication feature database in a specific way to construct a cloud node sequence, and then access the cloud storage database in a specific way to obtain slices based on the cloud node sequence. Combined with multi-dimensional verification, including verification of access behavior to the communication feature database and verification of access behavior to the cloud storage nodes, the data security and the reliability of intrusion detection can be improved. Attached Figure Description
[0059] Figure 1 This is a schematic diagram of the intrusion detection system based on big data analysis, as an embodiment of the invention.
[0060] Figure 2 A logic block diagram for determining whether a real-time access sequence matches a cloud node sequence in a cloud storage access confidence list, as an embodiment of the invention.
[0061] Figure 3 This is a logic block diagram for determining whether an access exception exists, according to an embodiment of the invention. Detailed Implementation
[0062] To make the objectives and advantages of the present invention clearer, the present invention will be further described below with reference to embodiments; it should be understood that the specific embodiments described herein are merely for explaining the present invention and are not intended to limit the present invention.
[0063] Preferred embodiments of the present invention will now be described with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are merely illustrative of the technical principles of the present invention and are not intended to limit the scope of protection of the present invention.
[0064] Furthermore, it should be noted that, in the description of this invention, unless otherwise explicitly specified and limited, the term "connection" should be interpreted broadly. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium; it can be a connection within two components. Those skilled in the art can understand the specific meaning of the above terms in this invention according to the specific circumstances.
[0065] Please see Figure 1 As shown, this is a schematic diagram of the intrusion detection system based on big data analysis according to an embodiment of the present invention. The intrusion detection system based on big data analysis according to an embodiment of the present invention includes:
[0066] The capture module is used to capture the communication characteristics of the cloud storage database at several sampling times according to a predetermined time interval and place them in the communication characteristic library;
[0067] The sampling module is used to acquire the data to be sent from the sending end, cut the data to be sent into segments, determine the number of segments, randomly generate a corresponding number of sampling intervals, arrange them to obtain a sampling sequence and record the completion timestamp, and encapsulate the sampling sequence, the completion timestamp and the identity identifier group into a sampling data packet. It can be understood that the completion timestamp is the timestamp corresponding to the time when the sampling sequence is generated.
[0068] The sequence generation module is used to call communication features at several sampling times from the communication feature library based on the sampled data packet, and generate a cloud node sequence by combining the range of each communication feature with the correspondence between each cloud storage node in the cloud storage database.
[0069] The slice storage module is used to encrypt and send the sampled data packets, and synchronously store each slice to the cloud storage database based on the cloud node sequence;
[0070] The reproduction module is used to decrypt the sampled data packets received by the receiving end, call the communication characteristics of several sampling times, reproduce the cloud node sequence, access each of the cloud storage nodes to obtain each of the slices, and combine to reproduce the data to be sent.
[0071] The verification module is used to receive sampled data packets, generate a communication feature database access confidence list and a cloud storage access confidence list corresponding to the identity group, and perform verification based on the access records of the communication feature database and the access records of the cloud storage database to determine whether there is any access anomaly.
[0072] The identity identifier group includes the receiver's identity identifier and the sender's identity identifier.
[0073] Specifically, there are no restrictions on the specific structure of the capture module, sampling module, sequence generation module, slice storage module, reproduction module, and verification module. For example, they can be composed of logic components, including field-programmable processors, computers, or microprocessors in computers, which will not be elaborated further.
[0074] Specifically, the capture module connects to the communication feature library and cloud storage nodes to capture communication features and store them in the communication feature library. The sampling module, sequence generation module, and slice storage module can be deployed on the sending end and hold the identity of the sending end to perform data interaction behavior in order to process the data of the sending end. The reproduction module can be deployed on the receiving end and hold the identity of the receiving end to perform data interaction behavior in order to process the data received by the receiving end. The verification module can connect to the communication feature library and cloud storage nodes to obtain access records.
[0075] Specifically, there are no restrictions on the methods for encrypting and decrypting the sampling data packets. For example, asymmetric encryption can be used, with the public key used to encrypt the sampling data packets and the private key used to decrypt them. This will not be elaborated further.
[0076] Specifically, there is no limitation on the specific form of the communication feature database. It can be a physical or virtual database, as long as it can store the required data. In implementation, an authentication mechanism can be added to the communication feature database to allow access to the database only after successful authentication.
[0077] Specifically, there are no restrictions on the form of the cloud storage database, which can consist of several storage nodes. In implementation, an authentication mechanism can be added to the cloud storage database to allow access only to those who have passed authentication.
[0078] Specifically, the capture module captures the communication characteristics of the cloud storage database at several sampling times, including:
[0079] It is used to capture the bandwidth utilization, node occupancy rate and packet loss rate of the cloud storage database at a certain sampling time according to a predetermined time interval;
[0080] This is used to sum the bandwidth utilization, node occupancy, and packet loss rate in a weighted manner to obtain the communication characteristics.
[0081] In practice, bandwidth utilization rate is the ratio of the network bandwidth actually used by the cloud storage database within a predetermined time interval to the maximum theoretically available bandwidth.
[0082] The node occupancy rate is the average storage occupancy rate within each cloud storage node of the cloud storage database.
[0083] The packet loss rate is the ratio of the number of data packets lost by the cloud storage database during network communication within a predetermined time interval to the total number of data packets that should have been successfully transmitted.
[0084] In practice, to ensure the capture density, the timing interval is selected within the range of [0.1s, 0.5s].
[0085] Specifically, the sampling module is used to randomly generate a corresponding number of sampling intervals, which, after being arranged, result in a sampling sequence including:
[0086] Used to determine the number of slices;
[0087] The sampling intervals are randomly generated within a predetermined sampling interval range, and then sorted according to the generation order to obtain the sampling sequence.
[0088] The sampling interval is an integer multiple of the time interval.
[0089] In practice, the sampling interval range is a closed interval, with the lower limit of the interval being 1 time interval and the upper limit of the interval being 10 time interval.
[0090] Specifically, the sequence generation module is used to retrieve communication features corresponding to several time points from the communication feature library based on the sampled data packets, including:
[0091] The completion timestamp is used to call the completion timestamp. The sampling time closest to the completion timestamp is determined from the communication feature library. In practice, the completion timestamp does not always coincide with the sampling time. Therefore, the sampling time closest to the completion timestamp is selected.
[0092] Used to call the sampling sequence, calling the sampling intervals in the sampling sequence one by one in reverse order, taking the sampling time as the starting time, and marking several sampling times one by one in the negative direction of the sampling time axis according to the called sampling intervals;
[0093] Communication features selected for each sampling time can be retrieved from the communication feature library;
[0094] The sampling time axis includes the sampling times corresponding to all communication features in the communication feature library.
[0095] In practice, taking a sampling sequence containing five sampling intervals as an example,
[0096] Sampling sequences: A2, A1, A3, A4, A5; where A1 represents a sampling interval with a value of 1 time interval, A2 represents a sampling interval with a value of 2 time intervals, A3 represents a sampling interval with a value of 3 time intervals, A4 represents a sampling interval with a value of 4 time intervals, and A5 represents a sampling interval with a value of 5 time intervals.
[0097] When the sampling intervals in the sampling sequence are called in reverse order, they are A5, A4, A3, A1, and A2 respectively.
[0098] Furthermore, in the process of marking several sampling moments one by one along the negative direction of the sampling time axis according to the called sampling interval, starting from the initial time, the sampling moment is marked after five time intervals in the negative direction of the sampling time axis, then after four time intervals in the negative direction of the sampling time axis, then after three time intervals in the negative direction of the sampling time axis, then after one time interval in the negative direction of the sampling time axis, and then after two time intervals in the negative direction of the sampling time axis.
[0099] This invention captures the communication characteristics of cloud storage nodes to construct a communication characteristic library. In reality, the communication characteristics of cloud storage nodes are affected by various factors and are usually subject to certain changes, which are unpredictable. Furthermore, this invention randomly generates sampling intervals to generate sampling sequences, thereby constructing sampling data packets. When the sending end needs to send data, it calls the sampling sequence in the sampling data packet to sample the communication characteristics in the communication characteristic library. Due to the unpredictability of communication characteristics and the randomness of sampling sequences, the captured communication characteristics are different each time the sending end needs to send data. Consequently, the cloud node sequence constructed based on the communication characteristics is also different, and the storage location when storing slices based on the cloud node sequence is also different. Based on this, the data sending behavior of the sending end is unpredictable, and the storage location of each slice sent is different. This facilitates the subsequent setting of corresponding dynamic access logic for cloud storage nodes, and the dynamic access logic can be used as a constraint to verify whether there are any abnormalities in the access behavior, thereby improving data security and the reliability of intrusion detection.
[0100] Specifically, the sequence generation module combines the correspondence between each communication feature range and each cloud storage node in the cloud storage database to generate a cloud node sequence, including:
[0101] Used to pre-build the correspondence between cloud storage nodes and communication feature ranges;
[0102] This is used to determine the range of communication features to which each communication feature falls based on the temporal order of the sampling time corresponding to the communication feature;
[0103] The cloud storage nodes corresponding to each of the aforementioned communication feature ranges are determined one by one, and the cloud storage nodes are arranged according to their corresponding numbers to obtain a cloud node sequence.
[0104] Among them, cloud storage nodes correspond one-to-one with communication feature ranges.
[0105] In practice, the range of communication features can be intervals, and the ranges of communication features need to be continuous to cover possible communication features.
[0106] In implementation, the interval length corresponding to the communication characteristic range can be determined based on the maximum and minimum communication characteristics within the historical period. First, the difference between the maximum and minimum communication characteristics is calculated, and the ratio of this difference to the number of cloud storage nodes is used to determine the interval length. This ensures that each cloud storage node has a corresponding communication characteristic range as much as possible. This will not be elaborated further.
[0107] In practice, each cloud storage node is assigned a unique identifier.
[0108] Specifically, the slice storage module is used to store each slice to a cloud storage database based on a cloud node sequence, including:
[0109] Used to determine the cloud storage node to be stored based on the number in the cloud node sequence;
[0110] Used to store each of the slices to the corresponding cloud storage node;
[0111] Each slice is stored on a single cloud storage node.
[0112] It is understandable that, since the number of slices corresponds to the sequence of cloud nodes, each slice can be stored separately to the corresponding cloud storage node.
[0113] In practice, for text-based data to be sent, after segmentation, the slices can be arranged according to the text order. The slices correspond to the numbers in the cloud node sequence according to the order. Then, the cloud storage nodes to be stored are determined sequentially according to the number order in the cloud node sequence, and the arranged slices are stored in sequence. For example, if the cloud storage node corresponding to the first number is determined, the first slice is extracted and stored in that cloud storage node. If the cloud storage node corresponding to the second number is determined, the second slice is extracted and stored in that cloud storage node. This will not be elaborated further.
[0114] The present invention reconstructs the cloud node sequence based on the sampled data packets and accesses the cloud storage database to obtain each slice. Due to the construction logic of the sampled data packets, the sampled data packets constructed by the sending end are different each time data is sent, which constrains the access behavior. The reconstructing module reconstructs the cloud node sequence to access the cloud storage database to obtain slices, making the access behavior of the cloud storage database different and unpredictable each time. Furthermore, the subsequent verification module also constructs a communication feature library access confidence list and a cloud storage access confidence list based on the sampled data packets to monitor the access behavior of the communication feature library, preventing intruders from masquerading as legitimate individuals and traversing the communication features in the communication feature library, thus blocking the possibility of reconstructing the cloud node sequence. In addition, the access behavior of the cloud storage nodes is monitored. Since the access behavior of the cloud storage nodes is different each time the sending end sends data to be sent, even if an intruder masquerades as legitimate individuals and uses the form of traversing nodes to obtain slices, their access behavior can be captured, and anomalies can be detected in time, thereby improving data security and the reliability of intrusion access detection.
[0115] Specifically, the reproduction module is used to reproduce the cloud node sequence, access each of the cloud storage nodes to obtain each of the slices, and combine them to reproduce the data to be sent, including...
[0116] This is used to generate a cloud node sequence by combining the correspondence between each communication feature range and each cloud storage node in the cloud storage database;
[0117] This is used to access the cloud storage nodes corresponding to the labels one by one according to the cloud node sequence, obtain the slices in the cloud storage nodes, and combine the slices to reproduce the data to be sent.
[0118] During implementation, the labels of the cloud node sequences are extracted one by one, and then the cloud storage nodes are accessed one by one according to the labels.
[0119] Specifically, the verification module generates a communication feature library access confidence list and a cloud storage access confidence list based on the sampled data packets, including:
[0120] Used to generate a communication feature database access confidence list corresponding to the identity group;
[0121] Used to retrieve communication features at several sampling times from the communication feature library based on the sampled data packets, and record the communication features at each sampling time into the communication feature library access confidence list;
[0122] Used to generate a cloud storage access confidence list corresponding to the identity group;
[0123] Used to determine the cloud node sequence based on the sampled data packet, and store the cloud node sequence in the cloud storage access confidence list;
[0124] Each identity group corresponds to a unique communication feature database access confidence list.
[0125] During implementation, once the receiving end reproduces the data to be sent, the corresponding cloud storage access confidence list and communication feature library access confidence list can be deleted so that they can be reconstructed in the next process.
[0126] Specifically, please refer to Figure 2 As shown, Figure 2 The present invention provides a logical block diagram for determining whether a real-time access sequence matches a cloud node sequence in a cloud storage access confidence list. The verification module performs verification based on access records from a communication feature library and access records from a cloud storage database.
[0127] Used to determine the identity of the access object to the communication feature database, and call the communication feature database access confidence list corresponding to the identity; in practice, both the sending end and the receiving end need to access the communication feature database, and then verify the identity to determine the identity group to which they belong, and then determine the communication feature database access confidence list and the cloud storage access confidence list.
[0128] Used to obtain the access records of the accessed object, determine the obtained communication characteristics, and determine whether they all belong to the access confidence list of the communication characteristic library;
[0129] Used to determine the identity of the access object to the cloud storage database, and to call the cloud storage access confidence list corresponding to the identity;
[0130] This is used to obtain the access records of the accessed object, determine the accessed cloud node sequence number, and generate a real-time access sequence in real time according to the access order, so as to determine whether the real-time access sequence matches the cloud node sequence in the cloud storage access confidence list.
[0131] If the real-time access sequence is the same as the cloud node sequence or any subsequence of the cloud node sequence, then a match is determined.
[0132] In practice, the communication feature library records the communication features invoked by the visitor as access records. Therefore, since the sender and receiver only invoke specific communication features, calls made by a person with a false identity may invoke other communication features and thus be identified by the verification module.
[0133] In practice, the cloud storage database records the cloud storage nodes accessed by the visitor and the access time, thereby determining the access order. The access sequence is obtained by arranging the cloud storage node numbers according to the access order. Since the access sequence is generated in real time, under normal circumstances, the access sequence generated by the receiving end during the access process is a subsequence of the cloud node sequence. After the access is completed, the access sequence is the same as the cloud node sequence.
[0134] Specifically, the verification module determines whether there is an access anomaly by including:
[0135] If the abnormal conditions are met, the access is deemed abnormal;
[0136] If the abnormal conditions are not met, the access is determined to be normal;
[0137] The abnormal condition is that all the acquired communication features belong to the communication feature library access confidence list and the real-time access sequence matches the cloud node sequence in the cloud storage access confidence list.
[0138] Specifically, the entire data interaction process of this invention requires multi-terminal collaboration. For example, it is necessary to obtain a communication feature database in a specific way to construct a cloud node sequence, and then access the cloud storage database to obtain slices based on the cloud node sequence in a specific access method. Combined with multi-dimensional verification, including verification of access behavior to the communication feature database and verification of access behavior to the cloud storage nodes, the data security and the reliability of intrusion access detection are improved.
[0139] The technical solution of the present invention has been described above with reference to the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will all fall within the scope of protection of the present invention.
Claims
1. An intrusion detection system based on big data analysis, characterized in that, include: The capture module is used to capture the communication characteristics of the cloud storage database at several sampling times according to a predetermined time interval and place them in the communication characteristic library; The sampling module is used to acquire the data to be sent from the sending end, cut the data to be sent into segments, determine the number of segments, randomly generate a corresponding number of sampling intervals, arrange them to obtain a sampling sequence and record the completion timestamp, and encapsulate the sampling sequence, the completion timestamp and the identity identifier group into a sampling data packet. The sequence generation module is used to call communication features at several sampling times from the communication feature library based on the sampled data packet, and generate a cloud node sequence by combining the range of each communication feature with the correspondence between each cloud storage node in the cloud storage database. The slice storage module is used to encrypt and send the sampled data packets, and synchronously store each slice to the cloud storage database based on the cloud node sequence; The reproduction module is used to decrypt the sampled data packets received by the receiving end, call the communication characteristics of several sampling times, reproduce the cloud node sequence, access each of the cloud storage nodes to obtain each of the slices, and combine to reproduce the data to be sent. The verification module is used to receive sampled data packets, generate a communication feature database access confidence list and a cloud storage access confidence list corresponding to the identity group, and perform verification based on the access records of the communication feature database and the access records of the cloud storage database to determine whether there is any access anomaly. The identity identifier group includes a receiver identity identifier and a sender identity identifier; The crawling module captures the communication characteristics of the cloud storage database at several sampling times, including: It is used to capture the bandwidth utilization, node occupancy rate and packet loss rate of the cloud storage database at a certain sampling time according to a predetermined time interval; This is used to sum the bandwidth utilization, node occupancy, and packet loss rate in a weighted manner to obtain the communication characteristics. The sequence generation module is used to retrieve communication features corresponding to several time points from the communication feature library based on the sampled data packets, including: Used to call the completion timestamp, and the sampling time closest to the completion timestamp is determined from the communication feature library; Used to call the sampling sequence, calling the sampling intervals in the sampling sequence one by one in reverse order, taking the sampling time as the starting time, and marking several sampling times one by one in the negative direction of the sampling time axis according to the called sampling intervals; Communication features selected for each sampling time can be retrieved from the communication feature library; The sampling time axis includes the sampling times corresponding to all communication features in the communication feature library.
2. The intrusion detection system based on big data analysis according to claim 1, characterized in that, The sampling module is used to randomly generate a corresponding number of sampling intervals, which, after being arranged, result in a sampling sequence including: Used to determine the number of slices; The sampling intervals are randomly generated within a predetermined sampling interval range, and then sorted according to the generation order to obtain the sampling sequence. The sampling interval is an integer multiple of the time interval.
3. The intrusion detection system based on big data analysis according to claim 1, characterized in that, The sequence generation module combines the correspondence between various communication feature ranges and the cloud storage nodes in the cloud storage database to generate a cloud node sequence, including: Used to pre-build the correspondence between cloud storage nodes and communication feature ranges; This is used to determine the range of communication features to which each communication feature falls based on the temporal order of the sampling time corresponding to the communication feature; The cloud storage nodes corresponding to each of the aforementioned communication feature ranges are determined one by one, and the cloud storage nodes are arranged according to their corresponding numbers to obtain a cloud node sequence. Among them, cloud storage nodes correspond one-to-one with communication feature ranges.
4. The intrusion detection system based on big data analysis according to claim 1, characterized in that, The slice storage module is used to store each slice to a cloud storage database based on a cloud node sequence. Used to determine the cloud storage node to be stored based on the number in the cloud node sequence; Used to store each of the slices to the corresponding cloud storage node; Each slice is stored on a single cloud storage node.
5. The intrusion detection system based on big data analysis according to claim 1, characterized in that, The reproduction module is used to reproduce the cloud node sequence, access each of the cloud storage nodes to obtain each of the slices, and combine them to reproduce the data to be sent. This is used to generate a cloud node sequence by combining the correspondence between each communication feature range and each cloud storage node in the cloud storage database; This is used to access the cloud storage nodes corresponding to the labels one by one according to the cloud node sequence, obtain the slices in the cloud storage nodes, and combine the slices to reproduce the data to be sent.
6. The intrusion detection system based on big data analysis according to claim 1, characterized in that, The verification module generates a communication feature library access confidence list and a cloud storage access confidence list based on the sampled data packets. Used to generate a communication feature database access confidence list corresponding to the identity group; Used to retrieve communication features at several sampling times from the communication feature library based on the sampled data packets, and record the communication features at each sampling time into the communication feature library access confidence list; Used to generate a cloud storage access confidence list corresponding to the identity group; Used to determine the cloud node sequence based on the sampled data packet, and store the cloud node sequence in the cloud storage access confidence list; Each identity group corresponds to a unique communication feature database access confidence list.
7. The intrusion detection system based on big data analysis according to claim 6, characterized in that, The verification module performs verification based on access records from the communication feature database and access records from the cloud storage database, including: Used to determine the identity of the access object to the communication feature database, and to call the communication feature database access confidence list corresponding to the identity; Used to obtain the access records of the accessed object, determine the obtained communication characteristics, and determine whether they all belong to the access confidence list of the communication characteristic library; Used to determine the identity of the access object to the cloud storage database, and to call the cloud storage access confidence list corresponding to the identity; This is used to obtain the access records of the accessed object, determine the accessed cloud node sequence number, and generate a real-time access sequence in real time according to the access order, so as to determine whether the real-time access sequence matches the cloud node sequence in the cloud storage access confidence list. If the real-time access sequence is the same as the cloud node sequence or any subsequence of the cloud node sequence, then a match is determined.
8. The intrusion detection system based on big data analysis according to claim 7, characterized in that, The verification module determines whether there is an access anomaly by including: If the abnormal conditions are met, the access is deemed abnormal; If the abnormal conditions are not met, the access is determined to be normal; The abnormal condition is that all the acquired communication features belong to the communication feature library access confidence list and the real-time access sequence matches the cloud node sequence in the cloud storage access confidence list.
Citation Information
Patent Citations
Bidirectional intrusion detection system and method based on cloud computing and cognitive radio network
CN107483413A
Secure communication method and device, electronic equipment and storage medium
CN116633582A
Cloud host data access security processing method and system
CN119382862A