A deep packet inspection-based network threat real-time identification method
By collecting and analyzing dormitory network traffic data in real time and dynamically adjusting detection strategies, the problem of identifying abnormal traffic at night in dormitory network security has been solved, achieving a balance between network security and user experience, and ensuring the stability and security of the dormitory network.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUANGZHOU FENGCHUAN NETWORK TECHNOLOGY CO LTD
- Filing Date
- 2025-07-25
- Publication Date
- 2026-05-15
AI Technical Summary
Existing technologies are insufficient to effectively address abnormal changes in network traffic distribution at night in dormitory building network security, especially fluctuations in the number of connected devices and abnormal aggregation of cross-floor communication patterns, which limits the accuracy of threat identification and affects students' network usage experience.
By collecting real-time network traffic data in dormitory buildings, extracting the frequency of cross-floor data packets and the concentration of communication periods, analyzing the frequency of device connection fluctuations and the distribution of communication protocols, dynamically adjusting detection strategies, optimizing device density changes and migration trajectory monitoring, triggering traffic limiting processes, and realizing dynamic adjustment of network bandwidth.
Effectively identify and respond to abnormal network traffic in dormitory buildings at night, ensure the safe and stable operation of the network, and take into account the network usage experience of students.
Smart Images

Figure CN120880732B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information technology, and in particular to a method for real-time identification of network threats based on deep packet inspection. Background Technology
[0002] In today's information age, campus network security has become a crucial area for safeguarding students' learning and living environment, its importance self-evident. Dormitories, as the core location for students' online activities, bear a large amount of network traffic and potential security risks, especially at night when students' online behavior patterns are complex and changeable, significantly increasing the difficulty of threat identification. Maintaining network security in this area is not only related to the protection of students' personal information but also directly affects the stability of the overall campus network environment. However, current solutions for dormitory network security often have limitations, mainly in their insufficient adaptability to dynamic environments. Many methods lack the ability to delve into the deep connections behind behavioral patterns when faced with sudden changes in network traffic distribution, making it difficult to cope with multi-dimensional and multi-layered anomalies, especially during nighttime hours when student network activity alternates between peaks and troughs. Existing mechanisms often cannot adjust strategies in time, leading to potential threats being overlooked or misjudged. Focusing on specific challenges, the core of dormitory network security lies in how to accurately capture abnormal changes in network traffic distribution. These abnormal changes often manifest as sudden fluctuations in the number of connected devices, which further triggers abnormal aggregations of cross-floor communication patterns. When abnormal fluctuations in device connectivity occur on a particular floor, a chain reaction occurs. On one hand, user devices on the affected floor will automatically or manually seek network access points on other floors to maintain connection stability, causing network traffic that was originally dispersed across floors to converge on that specific floor. On the other hand, the redistribution of network load disrupts the original traffic balance, altering data transmission paths across floors and creating abnormal communication aggregation patterns. Malicious actors often exploit this chaotic state to establish covert communication links between multiple floors, further exacerbating the abnormal aggregation of cross-floor communication and significantly increasing the concealment and complexity of threats. Because the linkage between fluctuations in the number of devices and abnormal communication patterns has not been effectively addressed, the accuracy of threat identification is limited, and it may also interfere with students' normal network usage experience, creating a conflict between security and convenience. Therefore, how to dynamically adjust detection strategies to address abnormal changes in dormitory network traffic distribution during nighttime hours to cope with fluctuations in the number of device connections and abnormal aggregation of cross-floor communication patterns, while simultaneously balancing the accuracy of threat identification with students' network usage experience, has become a critical issue that urgently needs to be addressed. Summary of the Invention
[0003] This invention provides a real-time network threat identification method based on deep packet inspection, mainly comprising:
[0004] By collecting network traffic data in the dormitory building in real time, the frequency of cross-floor data packets and the concentration of communication periods in different time windows of each floor are extracted to obtain the preliminary distribution of abnormal traffic peaks. The concentration of communication periods is the ratio of the total number of data packets to the network bandwidth capacity in the corresponding time window.
[0005] Based on the preliminary distribution of abnormal traffic peaks, analyze the frequency range of equipment connection fluctuations to determine the dynamic trend of equipment disconnection and reconnection rates between floors.
[0006] Based on the dynamic trend of device disconnection and reconnection rates, the duration distribution of abnormal sessions where communication traffic is concentrated between floors is obtained;
[0007] By analyzing the distribution of abnormal session durations in which communication traffic is concentrated between floors, we can determine the correlation between user equipment access preferences and fluctuations of target ports on different floors and traffic, and obtain preliminary identification results of potential anomalies.
[0008] If the preliminary identification results of potential anomalies show that the aggregation of communication patterns exceeds the preset threshold range, the sensitivity of capturing cross-floor data packet frequency will be dynamically adjusted to determine the location of abnormal traffic peaks under the characteristics of nighttime periods.
[0009] Based on the location of abnormal traffic peaks during the nighttime period, optimize real-time monitoring parameters for changes in floor equipment density and cross-floor equipment migration trajectories, and obtain dynamic rules for equipment disconnection and reconnection rates and data transmission directionality detection.
[0010] For dynamic rules, the abnormal response mechanism for target port access preferences is updated, the protocol type of the target communication data packet is parsed, and the proportion of the number of times each type of communication protocol is used to the total number of communication times is calculated to obtain the communication protocol distribution ratio. If the analysis result of the communication protocol distribution ratio does not match the preset threshold, the corresponding traffic restriction process is triggered to obtain the temporary protection strategy for the night period.
[0011] The allocation constraints of the concentration of communication periods are verified. Based on the upper limit of the transmission rate set for each protocol in the temporary protection strategy for nighttime periods, and combined with the proportion of each type of device collected in real time, the upper limit of the concentration of communication periods is adjusted to obtain the adjusted allocation constraint parameters. Based on the adjusted allocation constraint parameters, historical traffic fluctuation data and bandwidth utilization data at the corresponding time are extracted. The relationship between fluctuation amplitude and bandwidth utilization is fitted, the predicted bandwidth demand value is calculated, and the dynamic adjustment scheme of network bandwidth for nighttime periods is determined.
[0012] Furthermore, by collecting real-time network traffic data from the dormitory building, the frequency of cross-floor data packets and the concentration of communication periods for each floor within different time windows are extracted to obtain a preliminary distribution of abnormal traffic peaks. The concentration of communication periods is the ratio of the total number of data packets to the network bandwidth capacity within the corresponding time window, including:
[0013] The network traffic of the dormitory building is collected in segments, and the transmission frequency of cross-floor data packets within each time window is calculated to obtain the communication frequency distribution matrix of each floor. Based on the communication frequency distribution matrix, the ratio of the frequency difference between adjacent time windows to the frequency of the previous time window is calculated to obtain the frequency change rate. Time points where the change rate exceeds a preset threshold are marked as potential abnormal moments, and an abnormal moment sequence for each floor is generated. Based on the abnormal moment sequence, the communication period concentration index is obtained. By comparing the communication period concentration index with historical benchmark values, the floor locations where the concentration deviation exceeds the preset threshold and the corresponding abnormal moments are determined, and an abnormal traffic peak point distribution is generated.
[0014] Furthermore, based on the preliminary distribution of abnormal traffic peaks, the analysis of the frequency range of equipment connection fluctuations, and the determination of the dynamic trend of equipment disconnection and reconnection rates between floors, includes:
[0015] Based on the distribution of abnormal traffic peaks, the ratio of the number of connected devices on each floor to the total number of devices on that floor within each time window is calculated to obtain the time-series data of device density for each floor. The density abrupt change point is determined based on this data. At the density abrupt change point, the number of devices whose status changes from connected to disconnected and from disconnected to connected in the device connection status record is identified, and the ratio of disconnected devices to reconnected devices is calculated as the disconnection-to-reconnection rate at that moment. By comparing the differences in disconnection-to-reconnection rates between different floors at the same density abrupt change point, and the changing pattern of the disconnection-to-reconnection rate of each floor over time, the dynamic trend of the device disconnection-to-reconnection rate between floors is determined.
[0016] Furthermore, the dynamic trend of device disconnection and reconnection rates, and the acquisition of the distribution of abnormal session durations where communication traffic is concentrated between floors, include:
[0017] Based on the dynamic trend of the device disconnection and reconnection rate, extract device identification information within the period when the disconnection and reconnection rate exceeds a preset threshold, track the switching records of the device between access points on different floors, and construct a cross-floor device migration trajectory sequence; based on the cross-floor device migration trajectory sequence, count the device migration frequency between every two floors, calculate the ratio of migration frequency to the total number of inter-floor communication connections, and obtain the inter-floor connection density; extract communication data packets of floor combinations with connection density exceeding a preset threshold from the network log, and obtain the communication protocol distribution ratio; based on the communication protocol distribution ratio, record the data flow direction from the source floor to the target floor, obtain the data transmission directionality parameter, identify continuous data packet sequences using the same protocol and having the same transmission direction, calculate the time interval of each session, and generate an abnormal session duration distribution.
[0018] Furthermore, by analyzing the distribution of abnormal session durations through communication traffic aggregation across floors, the correlation characteristics between user equipment's target port access preferences and fluctuations and traffic correlation across different floors are analyzed to determine whether the aggregation of communication patterns deviates from a preset threshold range, thus obtaining preliminary identification results of potential anomalies, including:
[0019] Session records with abnormal session durations exceeding a preset threshold are extracted. Target port number information is parsed from these session records, and the proportion of access frequency for each port number to the total number of accesses on that floor is calculated to obtain the target port access preference distribution of the user device across different floors. Based on the target port access preference distribution, the correlation between access fluctuation values and traffic changes is calculated. Communication patterns with correlation values higher than the threshold are verified. The sum of the absolute values of the differences between the actual port access frequency distribution and the expected distribution is calculated as the deviation. If the deviation exceeds a preset threshold range, an abnormal clustering of communication patterns is determined, and a preliminary identification result of potential anomalies is obtained.
[0020] Furthermore, if the preliminary identification results of potential anomalies show that the aggregation of communication patterns exceeds a preset threshold range, the sensitivity to capturing cross-floor data packet frequencies is dynamically adjusted to determine the location of abnormal traffic peaks under nighttime characteristics, including:
[0021] If the preliminary identification results of potential anomalies show that the communication pattern aggregation exceeds the preset threshold range, then the time points where the change ratio exceeds the preset standard are extracted. For the time points, the ratio of the total number of data packets to the network capacity of the time period is calculated as the concentration degree of the communication period. The gradient change rate is obtained by dividing the difference of the concentration degree of adjacent time points by the time interval, and the time interval in which the gradient change rate reaches its maximum value is identified. By analyzing the distribution of the time interval with the largest gradient change rate in a specific period of night, the specific time when the data packet frequency reaches its peak and the corresponding floor number in the interval are determined, and the time and floor location information of the abnormal traffic peak point is obtained.
[0022] Furthermore, based on the location of abnormal traffic peaks during nighttime hours, the real-time monitoring parameters for changes in floor equipment density and cross-floor equipment migration trajectories are optimized to obtain dynamic rules for equipment disconnection and reconnection rates and data transmission directionality detection, including:
[0023] Based on the time and floor location information of the abnormal traffic peak point, the equipment density data sequence of the floor location within a specific time range before and after the peak time is extracted, the standard deviation of the sequence is calculated, and the standard deviation is adjusted according to a preset ratio and added to or subtracted from the average density value to obtain the dynamic threshold range for density monitoring.
[0024] The dynamic threshold range is used to determine the time of abnormal equipment density. At the time, the equipment migration records of the peak floor and its adjacent floors are extracted. The migration frequency in each time period is counted, and different weight values are assigned according to the time period to construct the time weight parameter for migration trajectory monitoring. The floor pair priority sequence is generated according to the time weight parameter, and the key floor pair list is formed by combining the upper limit of migration frequency. Dynamic rules for equipment disconnection and reconnection rate and data transmission directionality detection are obtained.
[0025] Furthermore, the abnormal response mechanism for target port access preferences is updated according to dynamic rules. The protocol type of the target communication data packets is parsed, and the proportion of each communication protocol's usage to the total number of communications is calculated to obtain the communication protocol distribution ratio. If the analysis result of the communication protocol distribution ratio does not match a preset threshold, the corresponding traffic restriction process is triggered to obtain a temporary protection strategy for the nighttime period, including:
[0026] Extract abnormal location data of key floors in the dynamic rules from the access logs within the monitoring time interval, calculate the ratio of the frequency of occurrence of the abnormal location to the average frequency of the same period in history, and obtain the abnormal deviation value; adjust the preset judgment threshold of the target port access preference according to the abnormal deviation value, re-evaluate the current port access frequency using the adjusted threshold, determine the list of ports whose access frequency exceeds the adjusted threshold, extract the communication protocol type corresponding to the port, calculate the proportion of traffic of each protocol to the total traffic, if the proportion of a certain protocol exceeds the preset upper limit threshold, traffic restriction is triggered, and a temporary protection policy for the night period is generated according to the protocol type that triggers traffic restriction and the corresponding rate upper limit.
[0027] The technical solutions provided by the embodiments of the present invention may include the following beneficial effects:
[0028] This invention discloses a real-time network threat identification method based on deep packet inspection. It collects real-time nighttime network traffic data, extracts cross-floor packet frequency and communication time concentration, and obtains the distribution of abnormal traffic peaks. Combining device access time windows and floor device density changes, it analyzes the dynamic trend of device disconnection and reconnection rates. Furthermore, it extracts the distribution ratio of communication protocols and data transmission directionality characteristics to obtain the distribution of abnormal session durations. Based on this, it constructs nighttime device type and communication behavior matching rules to determine whether the communication mode is abnormal. For abnormal situations, it dynamically adjusts monitoring parameters, updates detection rules, and triggers traffic restrictions. Finally, through temporary protection strategies and resource scheduling, it achieves dynamic adjustment of network bandwidth, continuously monitors inter-floor connection density, and cyclically updates the abnormal detection threshold. This invention can effectively identify and respond to abnormal network traffic in dormitory buildings at night, ensuring the safe and stable operation of the network. Attached Figure Description
[0029] Figure 1 This is a flowchart of a real-time network threat identification method based on deep packet inspection according to the present invention. Detailed Implementation
[0030] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this specification, and not all embodiments. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this specification.
[0031] like Figure 1 This embodiment of a real-time network threat identification method based on deep packet inspection may specifically include:
[0032] Step S101: By collecting network traffic data of the dormitory building in real time, extracting the frequency of cross-floor data packets and the concentration of communication periods in different time windows of each floor, and obtaining the preliminary distribution of abnormal traffic peak points.
[0033] A sliding time window method was used to collect network traffic in the dormitory building in segments. Based on preset monitoring rules, the transmission frequency of cross-floor data packets within each time window was calculated, obtaining the communication frequency distribution matrix for each floor from 22:00 to 6:00 the next day. For the communication frequency distribution matrix, the ratio of the frequency difference between adjacent time windows to the frequency of the previous time window was calculated as the frequency change rate. If the change rate exceeded a preset threshold, that time point was marked as a potential abnormal moment, resulting in an abnormal moment sequence for each floor. Based on the marked time points in the abnormal moment sequence, the total number of data packets within the corresponding time window was extracted. The total number of data packets in consecutive abnormal moments was accumulated and divided by the network bandwidth capacity of that period to obtain a communication period concentration index, determining the degree of traffic concentration. By comparing the communication period concentration index of each floor with historical benchmark values, the floor locations where the concentration deviation exceeded the preset threshold and the corresponding abnormal moments were determined, obtaining the distribution of abnormal traffic peak points for each floor during the nighttime period.
[0034] Specifically, the sliding time window mechanism plays a crucial role in network traffic monitoring.
[0035] Specifically, this mechanism continuously collects network data from the dormitory building at fixed time intervals, such as every 5 minutes. During the specific period from 10 PM to 6 AM the following day, students' network usage behavior exhibits unique patterns. The preset monitoring rules include special attention to cross-floor communication, because under normal circumstances, communication frequency within the same floor is much higher than cross-floor communication. When an abnormally high frequency of data packet transmission between the 5th and 12th floors is detected within a certain time window, this high-frequency cross-floor communication becomes a key monitoring target. The construction of the communication frequency distribution matrix involves statistically analyzing the number of communications between each floor.
[0036] In one possible implementation, assuming the dormitory building has 15 floors, the matrix would be a 15×15 two-dimensional structure, where each element represents the communication frequency between two floors within a specific time window. The frequency change rate is calculated using a relative change method: the difference between the frequency of the current time window and the frequency of the previous time window, divided by the frequency value of the previous time window. This calculation method can effectively identify sudden changes in traffic.
[0037] It should be noted that the process of marking abnormal time sequences relies on the reasonable setting of preset thresholds. When the frequency change rate of a certain time window exceeds the preset threshold, the system marks that time point as a potential abnormal time. These abnormal times are often concentrated in specific time periods, such as between 2:00 AM and 4:00 AM, and may involve large-scale file transfers or abnormal network activity. The calculation process of the communication period concentration index reflects the concept of traffic density.
[0038] Preferably, the system considers consecutive abnormal moments as an abnormal time period and calculates the total number of data packets within that period. Network bandwidth capacity, as the denominator, reflects the network's carrying capacity. When the concentration index is too high, it means that a large amount of data is being transmitted through the network in a short period, which may lead to network congestion or indicate abnormal behavior. Historical baseline values are established based on long-term data accumulation.
[0039] In one embodiment, the system collects communication concentration data for the same time period over the past 30 days and calculates its average value as a benchmark. When the current concentration index of a certain floor deviates from the historical benchmark value by more than a preset threshold, that floor is identified as the location of abnormal traffic. This comparative analysis method can effectively eliminate misjudgments caused by normal business fluctuations and improve the accuracy of anomaly detection.
[0040] Step S102: Based on the preliminary distribution of abnormal traffic peaks, analyze the frequency range of equipment connection fluctuations and determine the dynamic trend of equipment disconnection and reconnection rates between floors.
[0041] Based on the distribution of abnormal traffic peaks, device access time window data corresponding to the peak occurrence times are extracted. The ratio of the number of connected devices on each floor to the total number of devices on that floor within each time window is calculated to obtain the device density time-series data for each floor. For the device density time-series data, the absolute value of the difference between the density value of the current time window and the density value of the previous time window is calculated as the density change amplitude. If the density change amplitude exceeds a preset threshold, this moment is recorded as a density mutation point. The number of density mutation points occurring per unit time is counted to obtain the connection fluctuation frequency. Based on the density mutation point moment, device connection status records within 30 seconds before and after the mutation point are extracted from the access logs. The number of devices whose status changes from connected to disconnected and from disconnected to connected are identified, and the ratio of disconnected devices to reconnected devices is calculated as the disconnection-to-reconnection rate at that moment. By comparing the differences in disconnection-to-reconnection rates among different floors at the same density mutation point moment, and the changing pattern of the disconnection-to-reconnection rate of each floor over time, the dynamic trend of the device disconnection-to-reconnection rate among different floors is determined.
[0042] Specifically, there is a close correlation between the distribution of abnormal traffic peaks and device access behavior.
[0043] In one possible implementation, when the system detects a traffic peak on a certain floor at 3:00 AM, this moment becomes the key starting point for analysis. The device access time window is typically set at 5-minute intervals, and the system extracts device access records for the 15 minutes before and after the peak. The calculation of device density involves two key data points: the number of devices connected in real time and the total number of devices on that floor. Assuming there are 200 registered devices on the 8th floor, and 180 devices are connected within the peak time window, then the device density is 0.9. The formation process of the device density time-series data reflects the characteristics of dynamic monitoring.
[0044] Specifically, the system continuously records the device density value for each time window, forming a sequence that changes over time. The magnitude of density change is calculated using the absolute value of the difference between adjacent time windows. When the device density on the 8th floor suddenly drops from 0.9 to 0.3, the change magnitude reaches 0.6. Such a drastic change often indicates the occurrence of network anomalies. The identification of density abrupt change points relies on the reasonable setting of preset thresholds; typically, moments with a change magnitude exceeding 0.3 are marked as abrupt change points.
[0045] It's important to note that the statistical method for calculating connection fluctuation frequency directly reflects network stability. If 12 density abrupt changes occur within a one-hour observation period, the connection fluctuation frequency is approximately once every 5 minutes. This high-frequency fluctuation typically occurs during network device failures or large-scale device migrations. Access logs, as detailed records of device connection status, include connection timestamps, disconnection timestamps, and connection duration for each device.
[0046] For example, within a 30-second timeframe before and after a density abrupt change, the system accurately tracks changes in device status. If 50 devices change from connected to disconnected, and simultaneously 30 devices reconnect, the reconnection rate is 1.67. This ratio reflects the strength of the network's resilience. Comparative analysis between floors reveals the propagation characteristics of network problems.
[0047] In one embodiment, when a high disconnection and reconnection rate occurs on the 8th floor, similar phenomena may occur on the adjacent 7th and 9th floors at a later time. This phenomenon indicates that network faults have spatial propagation characteristics. This dynamic trend can be clearly observed by plotting the time series of disconnection and reconnection rates for each floor. Trend analysis not only focuses on the changing patterns of individual floors, but more importantly, it identifies the mutual influence patterns between floors. When multiple floors experience a simultaneous increase in disconnection and reconnection rates, it often points to a problem with the core network equipment; while an anomaly on a single floor may indicate a localized equipment failure.
[0048] Step S103: Based on the dynamic trend of the device disconnection and reconnection rate, obtain the distribution of the duration of abnormal sessions where communication traffic is concentrated between floors.
[0049] Based on the dynamic trend data of device disconnection and reconnection rates, device identification information for periods exceeding a preset threshold is extracted from logs. Switching records of these devices between access points on different floors are tracked to construct a cross-floor device migration trajectory sequence. According to this sequence, the migration frequency between every two floors is statistically analyzed, and the ratio of this migration frequency to the total number of communication connections between those two floors is used as the inter-floor connection density. This yields floor combinations with connection densities exceeding a preset threshold and their density values. Using these floor combinations, communication data packets between these floors are extracted from network logs. The protocol type of each data packet is parsed, and the proportion of each communication protocol's usage to the total usage is calculated to obtain the communication protocol distribution ratio. Simultaneously, the data flow direction from the source floor to the target floor is recorded to obtain data transmission directionality parameters. Based on the communication protocol distribution ratio and data transmission directionality parameters, consecutive data packet sequences using the same protocol and with the same transmission direction are identified as a session. The time interval from the first data packet to the last data packet in each session is calculated to obtain the duration distribution of abnormal sessions clustered between floors.
[0050] Specifically, the dynamic trend data of device disconnection and reconnection rates reflects the time-varying characteristics of network stability.
[0051] For example, when the disconnection and reconnection rate on the 5th floor suddenly jumps from 1.2 to 3.5 within a certain period, this drastic change indicates that the floor is experiencing severe network fluctuations. Device identification information contains key data such as the device's unique identifier, the user information it belongs to, and the device type. By extracting device information from these periods of high disconnection and reconnection rates, the problematic device group can be accurately located. The process of constructing cross-floor device migration trajectories involves a complete record of the device's switching behavior between different access points. Each trajectory includes elements such as a timestamp, source floor, target floor, and reason for switching. The calculation of inter-floor connection density reveals the degree of communication tightness between different floors.
[0052] In one possible implementation, assuming 500 device migrations occurred between floors 5 and 8 during the observation period, and the total number of communication connections between these two floors was 2000, then the connection density would be 0.25. This density value is significantly higher than the average of 0.05 for other floor pairs, indicating an unusually frequent interaction between these two floors. High connection density floor combinations often suggest specific business relationships or potential network problems.
[0053] It's important to note that the acquisition of communication data packets relies on a detailed network log recording mechanism. Network devices capture and store key information for each passing data packet, including source address, destination address, protocol type, timestamp, and packet size. The statistical process of compiling communication protocol distribution requires protocol parsing of a large number of data packets. Common protocol types include TCP, UDP, HTTP, and HTTPS, each playing a different role in network communication.
[0054] For example, if out of 1000 data packets, TCP accounts for 600, UDP for 300, and HTTP for 100, then the corresponding distribution ratios are 0.6, 0.3, and 0.1, respectively. Recording data transmission directionality parameters is crucial for understanding communication patterns.
[0055] Specifically, if the 5th floor sends 800 data packets to the 8th floor, while the 8th floor only sends 200 data packets to the 5th floor, this asymmetric transmission pattern may indicate a one-way large-volume data transmission, such as file downloads or video streaming. The session identification process is based on the principle of consistency between protocol type and transmission direction.
[0056] In one embodiment, consecutive TCP packets with the same source and destination ports and consistent transmission direction are considered to belong to the same session. Session duration is calculated from the timestamp of the first packet to the timestamp of the last packet. Normal web browsing sessions typically last from a few seconds to a few minutes, while abnormal sessions can last for hours. When a large number of long-duration sessions are concentrated between specific floor pairs, the resulting abnormal session duration distribution map will show obvious peaks; the duration ranges corresponding to these peaks are the abnormal characteristics that require close attention.
[0057] Step S104: By analyzing the distribution of abnormal session durations in communication traffic clustered between floors, analyze the correlation characteristics between user equipment target port access preferences and fluctuations and traffic correlation between different floors, determine whether the communication pattern clustering deviates from the preset threshold range, and obtain the preliminary identification results of potential anomalies.
[0058] By analyzing the distribution data of abnormal session durations, session records with durations exceeding a preset threshold are extracted. Target port number information is parsed from these records, and the frequency of access to different port numbers by devices on each floor is statistically analyzed. The proportion of each port number's access frequency to the total number of accesses on that floor is calculated, yielding the target port access preference distribution of user devices across different floors. Based on this distribution, the rate of change in port access frequency within adjacent time periods is calculated as the access fluctuation value. Simultaneously, traffic data for the corresponding time periods is acquired, and the correlation between access fluctuation values and traffic changes is calculated using the Pearson correlation coefficient, determining the correlation characteristic parameters between fluctuation and traffic. Based on the highly correlated time periods identified by the correlation characteristic parameters, the number of devices of each type within that time period is extracted from the device access logs. The proportion of each type of device to the total number of devices is calculated to obtain the device type distribution ratio. The port access patterns corresponding to each device type are compared with the actually observed communication behavior to construct matching rules between device types and communication behavior. The communication patterns in the current time period are verified by using matching rules. The sum of the absolute values of the differences between the actual port access frequency distribution and the expected distribution is calculated as the deviation. If the deviation exceeds the preset threshold range, it is determined that there is an abnormal clustering of communication patterns, and the preliminary identification results of potential anomalies are obtained.
[0059] Specifically, the distribution data on the duration of abnormal sessions provides an important foundation for subsequent analysis.
[0060] Specifically, when a session lasts for more than 3 hours, far exceeding the normal duration of web browsing or instant messaging, such abnormal sessions often imply specific network behavior patterns. The resolution of the target port number involves a deep inspection of network packets. Common ports include port 80 for HTTP services, port 443 for HTTPS encrypted transmission, and port 3389 for remote desktop connections. Statistical analysis revealed that devices on the 7th floor frequently accessed port 8080 at night, accounting for 45% of all accesses, forming a clear port access preference distribution. The temporal evolution of this port access preference distribution reveals dynamic changes in user behavior.
[0061] In one possible implementation, between 2 AM and 3 AM, the access frequency to port 8080 surged from 20 times per minute to 150 times per minute, resulting in an access fluctuation of 130 times per minute. Simultaneously, network traffic data showed a rise from 2 MB / s to 18 MB / s. The Pearson correlation coefficient measures the degree of linear correlation between two variables, with a value ranging from -1 to 1. A correlation coefficient of 0.92 indicates a strong positive correlation between port access fluctuations and traffic changes.
[0062] It should be noted that the application of correlation feature parameters directly affects the accuracy of subsequent anomaly identification. The identification of highly correlated periods is based on a correlation coefficient exceeding 0.8; these periods often correspond to special network activities such as batch data transmission or automated program execution. Device type classification typically includes categories such as personal computers, smartphones, tablets, and smart home devices. Device access logs during nighttime hours show that personal computers accounted for 60%, smartphones for 30%, and other devices for 10%. There is an inherent correspondence between device type and communication behavior.
[0063] For example, personal computers typically access a variety of ports, including web browsing, file transfer, and remote connections; while smartphones primarily focus on a few ports, such as instant messaging and social media applications. The process of constructing matching rules needs to comprehensively consider device type characteristics and actual observed communication behavior. When a large number of smartphone devices are found to frequently access file transfer-related ports at night, this behavior clearly deviates from the normal usage pattern of smartphones. The deviation is calculated by accumulating the absolute values of the differences, which quantifies the degree of difference between actual and expected behavior.
[0064] In one embodiment, the expected frequency of smartphone access to port 8080 is 5%, while the actual observed frequency is 35%, with a single deviation of 30%. The deviations of all ports are summed to obtain the total deviation. When the total deviation exceeds a preset threshold, such as 50%, the system determines that there is an abnormal aggregation of communication patterns. This determination mechanism can effectively identify abnormal behaviors that deviate from normal usage patterns, providing reliable early warning information for network security management and enabling early detection of potential network threats.
[0065] Step S105: If the preliminary identification results of potential anomalies show that the aggregation of communication patterns exceeds the preset threshold range, the sensitivity of capturing cross-floor data packet frequency is dynamically adjusted to determine the key location of abnormal traffic peak points under the characteristics of nighttime.
[0066] If the preliminary identification of potential anomalies indicates that the communication pattern aggregation exceeds a preset threshold range, the ratio of the actual aggregation degree to the threshold is calculated as a sensitivity adjustment coefficient. The sampling interval of cross-floor data packet frequency is divided by this adjustment coefficient from the preset baseline value to obtain a denser sampling frequency parameter. Cross-floor data packets are recaptured using the denser sampling frequency parameter. The number of data packets within each time window is counted, and the ratio of the difference in the number of data packets in adjacent time windows to the number in the previous window is calculated to obtain the dynamic change sequence of data packet frequency. Based on the dynamic change sequence of data packet frequency, time points where the change ratio exceeds a preset threshold are extracted. For these time points, the ratio of the total number of data packets to the network capacity of that period is calculated as the communication period concentration. The gradient change rate is obtained by dividing the difference in concentration between adjacent time points by the time interval, and the time interval where the gradient change rate reaches its maximum value is identified. By analyzing the distribution of the time interval with the largest gradient change rate from 22:00 to 6:00 the next day, the specific time when the data packet frequency reaches its peak and the corresponding floor number within this interval are determined, obtaining the time and floor location information of the abnormal traffic peak point.
[0067] Specifically, the initial identification of potential anomalies is a key signal that triggers the dynamic adjustment mechanism.
[0068] In one possible implementation, when the communication pattern aggregation reaches 80% and the preset threshold is 50%, the ratio of the actual aggregation to the threshold is 1.6. This ratio is used as the sensitivity adjustment coefficient. If the original sampling interval was 10 seconds, after adjustment it becomes 6.25 seconds, meaning the system collects data in shorter time intervals, improving its ability to detect abnormal behavior. This dynamic adjustment mechanism avoids the problem of missing instantaneous anomalies that might occur with a fixed sampling frequency. Increasing the sampling frequency directly affects the precision of data packet capture.
[0069] Specifically, at the adjusted sampling frequency, the system can capture more detailed changes. Suppose 120 cross-floor data packets are captured within a 6.25-second time window, and 200 are captured in the next window; the change ratio is calculated as 80 divided by 120, yielding 0.67. This ratio-based calculation method eliminates the influence of the base value and more accurately reflects the changing trend. The change ratios across multiple consecutive time windows constitute a dynamic sequence of data packet frequency changes, providing a time-series data foundation for subsequent analysis.
[0070] It should be noted that the calculation of communication period concentration involves an assessment of network resource utilization. If the total number of data packets at a certain point in time reaches 5000, and the network capacity for that period is 10000 data packets, then the concentration is 0.5. This metric reflects the actual network load. The calculation of the gradient rate of change reflects the speed of change in concentration. If the concentrations of two adjacent time points are 0.5 and 0.8 respectively, with a time interval of 12.5 seconds, then the gradient rate of change is 0.024 per second. The time interval during which the gradient rate of change reaches its maximum value often corresponds to the outbreak period of abnormal behavior.
[0071] In one embodiment, within a 5-minute interval from 3:15 AM to 3:20 AM, the gradient change rate gradually increased from 0.01 to 0.05, reaching its peak during the entire monitoring period. This rapid change indicates that a large number of devices generated intensive cross-floor communication behavior within a short period. The special characteristic of the nighttime period is that the reduction in normal business activities makes abnormal behavior easier to highlight. During the period from 10:00 PM to 6:00 AM the next day, network usage in the dormitory building showed obvious regularity, with most normal communication concentrated on social media and video entertainment. When the system detected that the data packet frequency from the 12th floor to the 5th floor reached its peak at 3:18 AM, transmitting 300 data packets per second, far exceeding the normal level of 30 packets per second, this time and floor combination was identified as the key location of the abnormal traffic peak. Through this multi-level analysis method, not only can the time point of the anomaly be identified, but the specific floor location can also be precisely located.
[0072] Step S106: Based on the key locations of abnormal traffic peaks under the characteristics of nighttime periods, optimize the real-time monitoring parameters for changes in floor equipment density and cross-floor equipment migration trajectories, and obtain dynamic rules for equipment disconnection and reconnection rates and data transmission directionality detection.
[0073] Based on the time and floor location information of the abnormal traffic peak, the device density data sequence for each floor location within 30 minutes before and after the peak time is extracted. The standard deviation of the sequence is calculated, and the standard deviation is multiplied by 2 as a fluctuation coefficient. This coefficient is then added to or subtracted from the average density value to obtain the dynamic threshold range for density monitoring. The dynamic threshold range is used to determine the time of abnormal device density. At these times, device migration records for the peak floor and its adjacent floors are extracted. The migration frequency within each time period is counted, with higher weights assigned to migration frequencies during nighttime and lower weights assigned to those during daytime, thus constructing a time weight parameter for migration trajectory monitoring. Based on the time weight parameter, the number of device disconnection and reconnection events in different time periods is weighted and calculated. The weighted disconnection and reconnection rate is obtained by multiplying the weight value by the number of events and summing the results. Simultaneously, the data flow information corresponding to the disconnection and reconnection events is extracted from the network logs, and the number of transmissions between each floor pair is counted. The floor pairs are then sorted in descending order of the number of transmissions to form a priority sequence. The monitoring time interval is determined by dividing the original interval by the rate value through the weighted disconnection and reconnection rate. The upper and lower limits of the density threshold are extracted from the dynamic threshold range. The upper limit of the migration frequency is set according to the maximum value of the migration frequency. The list of key floor pairs is formed by combining the top ten of the floor pair priority sequence. Dynamic rules for detecting device disconnection and reconnection rate and data transmission directionality are obtained.
[0074] Specifically, the accurate location of abnormal traffic peaks provides a crucial basis for subsequent parameter optimization.
[0075] In one possible implementation, once the system determines that the peak point for the 8th floor is 3:18 AM, it extracts equipment density data for the 30 minutes before and after that time. Assuming data is recorded every 5 minutes within these 60 minutes, a total of 12 density values are obtained: 0.7, 0.72, 0.75, 0.78, 0.85, 0.92, 0.88, 0.83, 0.79, 0.76, 0.73, and 0.71. The average of this data set is calculated to be 0.785, and the standard deviation is 0.067. Multiplying the standard deviation by 2 yields 0.134, thus determining the dynamic threshold range to be between 0.651 and 0.919. This threshold setting method based on statistical principles is adaptive. The standard deviation reflects the dispersion of the data, and the coefficient for multiplying by 2 is chosen based on the empirical rule of normal distribution, covering approximately 95% of the normal fluctuation range. When the equipment density exceeds this range, the system can promptly identify anomalies.
[0076] It should be noted that the time weighting parameters were designed to fully consider the time-of-day characteristics of network usage in the dormitory building. Device migration behavior at night differs significantly from that during the day; under normal circumstances, device migration should be less frequent at night.
[0077] Specifically, the system assigns a weight of 3 to the period from 22:00 to 6:00 the next day, and a weight of 1 to the period from 6:00 to 22:00. This differentiated weighting amplifies abnormal migration behavior at night in the calculation, improving detection sensitivity. The weighted calculation process for device disconnection and reconnection events highlights the importance of the time factor.
[0078] For example, if 50 disconnection and reconnection events occur between 2:00 AM and 3:00 AM, the weighted value for this time period is 150, since the weight is 3. However, if 50 events also occur between 2:00 PM and 3:00 PM, the weighted value is only 50. The weighted disconnection and reconnection rate is obtained by summing the weighted values for all time periods throughout the day and dividing by the number of time periods. Extracting data flow information involves deep analysis of network logs. Each disconnection and reconnection record contains the source and destination floor information of the device.
[0079] In one embodiment, statistics showed that the number of transmissions from the 8th floor to the 5th floor was 320, from the 8th floor to the 12th floor was 280, and from the 5th floor to the 3rd floor was 150. Arranging these transmissions in descending order of frequency, the resulting floor pair priority sequence was: 8-5, 8-12, 5-3... This sequence directly reflects the main path of abnormal communication. The dynamic rule generation process integrates the aforementioned parameters. The monitoring time interval is adjusted based on the weighted disconnection and reconnection rate. If the rate is 2.5, the original interval of 10 seconds divided by 2.5 yields a new interval of 4 seconds. The density threshold is directly adopted from 0.651 to 0.919 as calculated previously. The upper limit of migration frequency is set to 1.2 times the maximum migration frequency during the observation period to avoid misjudging normal peaks. The list of key floor pairs selects the top ten from the priority sequence; these floor pairs will be subject to stricter monitoring. The dynamic rules generated in this way maintain sensitivity to abnormal behavior while avoiding excessive alarms, achieving a balance between monitoring efficiency and accuracy.
[0080] Step S107: For dynamic rules, update the abnormal response mechanism for target port access preferences. If the analysis result of the communication protocol distribution ratio does not match the preset threshold, trigger the corresponding traffic restriction process to obtain a temporary protection strategy for the nighttime period.
[0081] For the key floor pair list and monitoring parameters in the dynamic rules, abnormal point data of the corresponding floor pairs within the monitoring time interval are extracted from the access logs. The ratio of the frequency of abnormal point occurrences to the historical average frequency for the same period is calculated to obtain the abnormal deviation value. Based on the abnormal deviation value, when the deviation is greater than 1, the preset judgment threshold of the target port access preference is multiplied by the reciprocal of the deviation to obtain a stricter response threshold. This response threshold is used to re-evaluate the current port access frequency and determine the list of ports whose access frequency exceeds the response threshold. From the list of ports whose access frequency exceeds the response threshold, the communication protocol types corresponding to these ports are extracted, and the proportion of traffic of each protocol to the total traffic is calculated. If the proportion of a certain protocol exceeds the preset upper limit threshold, traffic limiting is triggered, and the transmission rate upper limit of that protocol is set to the current rate multiplied by the preset limiting coefficient. Based on the protocol type that triggers traffic limiting and the corresponding rate upper limit, rate control is performed from 22:00 to 6:00 the next day. Combined with the key floor pair information, a temporary protection policy for the nighttime period is obtained, including protocol type, rate upper limit value, effective time period, and applicable floor range.
[0082] Specifically, the application of dynamic rules provides a flexible benchmark for anomaly detection.
[0083] In one possible implementation, the key floor list includes previously identified high-risk communication paths, such as floors 8 to 5 and 8 to 12. Monitoring parameters specify a 4-second sampling interval, enabling the system to intensively capture network activity data. The access log records detailed information for each anomalous event, including the time of occurrence, involved devices, and data traffic. When anomaly points from floors 8 to 5 occur 15 times within a certain time window, while the historical average for the same period is only 5 times, the calculated anomaly deviation is 3.0. The use of a ratio method in calculating the anomaly deviation is significant. This relative measurement eliminates the influence of differences in baselines across different time periods, allowing for adaptive adjustments to the anomaly judgment criteria between the early morning and daytime periods. When the deviation is greater than 1, it indicates that the current anomaly level exceeds historical normal levels, requiring the system to implement stricter monitoring measures.
[0084] It's important to note that the dynamic adjustment mechanism of the response threshold reflects the system's adaptive capability. The preset judgment threshold is typically determined based on the statistical characteristics of the network during normal operation; for example, the upper limit for port access frequency might be set at 100 times per minute. When the anomaly deviation is 3.0, the response threshold is adjusted to 100 divided by 3, approximately 33 times per minute. This adjustment makes the system more sensitive to port access behavior during periods of high anomaly incidence, enabling timely detection of potential threats. The assessment process for port access frequency involves continuous monitoring of real-time data.
[0085] Specifically, the system counts the number of accesses to each port within a monitoring time window. When the access frequency of port 8080 reaches 45 times per minute, exceeding the adjusted response threshold of 33 times, the port is added to the list of ports that need to be restricted. This list is dynamically updated to reflect real-time changes in abnormal network behavior. The identification of communication protocol types is based on the correspondence between port numbers and protocols.
[0086] For example, port 8080 is typically used for HTTP proxy services, and port 3389 corresponds to the remote desktop protocol. When the list of ports to be restricted contains a large number of file transfer-related ports, the system will focus on the traffic share of file transfer protocols such as FTP and SFTP. Assuming FTP protocol traffic accounts for 60% of the total traffic, and the preset upper limit is 30%, the system determines that traffic restriction for the FTP protocol is necessary. Traffic restriction is implemented using a rate control mechanism.
[0087] In one embodiment, the limiting factor is set to 0.3, meaning the transmission rate is reduced to 30% of its original value. If the current transmission rate of the FTP protocol is 10 Mbps, it will be reduced to 3 Mbps after the limit. This limit automatically takes effect at 22:00 at night, ensuring that abnormal traffic does not consume excessive network resources while preserving basic communication capabilities. The temporary protection policy was formulated by comprehensively considering information from multiple dimensions. The policy explicitly specifies that the transmission rate limit for the FTP protocol between the 8th and 5th floors is 3 Mbps, effective from 22:00 to 6:00 the next day, and applies only to key monitored floor pairs.
[0088] Step S108: Verify the allocation constraints of the concentration of communication time periods, determine the dynamic adjustment scheme of network bandwidth during nighttime periods, obtain feedback data on the frequency of cross-floor data packets, and cyclically update the detection threshold for the duration of abnormal sessions.
[0089] By setting upper limits for transmission rates for each protocol in the temporary protection strategy during nighttime hours, and combining this with real-time data on the proportion of different types of devices, the ratio of the number of devices affected by rate limiting to the total number of devices is calculated. If this ratio exceeds a preset threshold, the upper limit of the communication period concentration is multiplied by a preset adjustment coefficient to obtain the adjusted allocation constraint parameters. Based on the adjusted allocation constraint parameters, hourly traffic fluctuation data and corresponding bandwidth utilization data from the past 7 days are extracted. A linear regression method is used to fit the relationship between fluctuation amplitude and bandwidth utilization. The current traffic fluctuation amplitude is then substituted into the regression equation to calculate the predicted bandwidth demand.
[0090]
[0091] Bp represents the predicted bandwidth demand, Vf represents the current traffic fluctuation range, α represents the intercept parameter of the linear regression, β represents the regression coefficient (i.e., the influence of the fluctuation range on the bandwidth demand), and ε represents the random error term. This formula establishes a quantitative relationship between the fluctuation range and the bandwidth demand through linear regression. A dynamic adjustment scheme for network bandwidth during nighttime is determined. Network resources are redistributed using the bandwidth values determined by the dynamic adjustment scheme. The change in connection density between floors under the new bandwidth conditions is monitored. Simultaneously, the ratio of device access requests to successful accesses is calculated as the access success rate. The connection density is multiplied by the access success rate to obtain a matching degree index. The actual transmission frequency of cross-floor data packets under different matching degree conditions is recorded as feedback data. By analyzing the data packet frequency values for each time period in the feedback data, the corresponding abnormal session duration is extracted. These durations are sorted from smallest to largest, and the duration value located at a preset percentile is selected as the new detection threshold. The new threshold replaces the original threshold in the system, and the updated threshold is used for anomaly detection in the next monitoring cycle.
[0092] Specifically, the upper limit of the transmission rate in the temporary protection strategy is a core parameter for network management.
[0093] In one possible implementation, when the FTP protocol is limited to 3 Mbps and the HTTP protocol to 5 Mbps, these limits directly impact devices using the corresponding protocols. Real-time monitoring of device type distribution shows that personal computers account for 60% of the total devices, and 80% of these personal computers use FTP for file transfer. Calculating the proportion of affected devices, 60% multiplied by 80% yields 48% of devices being rate-limited. When this ratio exceeds a preset 40% threshold, the system determines that the constraint on the concentration of communication time periods needs adjustment. This adjustment reflects the system's dynamic balancing capability. The original upper limit of concentration might be set at 0.7, meaning 70% of traffic can be concentrated in a specific time period. When a large number of devices are affected by rate limiting, the adjustment factor is set to 0.8, adjusting the upper limit to 0.56. This adjustment forces traffic to be more dispersed over time, avoiding network congestion caused by rate limiting.
[0094] It should be noted that the application of linear regression in bandwidth prediction is based on the regularity of historical data. The system collects hourly data from the past 7 days, including traffic fluctuations and bandwidth utilization.
[0095] For example, historical data shows that when traffic fluctuation is 20%, bandwidth utilization is typically 65%; when the fluctuation is 40%, utilization reaches 85%. By fitting these data points using the least squares method, a regression equation is obtained. With the current traffic fluctuation at 35%, substituting this into the equation yields a predicted bandwidth utilization of 79%, thus determining that the bandwidth needs to be adjusted from 100Mbps to 126Mbps. The effectiveness of this dynamic bandwidth adjustment needs to be evaluated using multi-dimensional indicators.
[0096] Specifically, inter-floor connection density reflects the communication strength between different floors. Under new bandwidth conditions, a floor pair with a density value of 0.25 might drop to 0.20. The access success rate is calculated by considering the total number of access requests initiated by the device and the number of successful connections. Assuming there are 1000 access requests in a certain period, with 850 successful, the access success rate is 0.85. The matching degree metric, obtained by multiplying the connection density of 0.20 by the access success rate of 0.85, yields 0.17, a value that comprehensively reflects the quality of network connections. The collection of feedback data provides an empirical basis for threshold optimization.
[0097] In one embodiment, the system recorded the packet transmission frequency under different matching degree conditions. When the matching degree was 0.17, the frequency of cross-floor packets was 200 per second; when the matching degree dropped to 0.10, the frequency increased to 350 per second. This negative correlation indicates that abnormal traffic increases when network quality deteriorates. The statistical distribution of the duration of abnormal sessions showed obvious characteristics. By analyzing data from one week, it was found that most normal sessions lasted less than 5 minutes, while abnormal sessions often lasted more than 30 minutes. After sorting the durations of all detected abnormal sessions, the 90th percentile value was selected as a new threshold, for example, 45 minutes. This dynamically updated threshold can adapt to changes in network behavior, improving the accuracy and timeliness of anomaly detection.
[0098] Although the present invention has been described in detail above with general descriptions and specific embodiments, modifications or improvements can be made to it, which will be obvious to those skilled in the art. Therefore, all such modifications or improvements made without departing from the spirit of the present invention fall within the scope of protection claimed by the present invention.
Claims
1. A method for real-time identification of network threats based on deep packet inspection, characterized in that, The method includes: By collecting real-time network traffic data from the dormitory building, the frequency of cross-floor data packets and the concentration of communication periods in different time windows are extracted for each floor to obtain a preliminary distribution of abnormal traffic peaks. The concentration of communication periods is the ratio of the total number of data packets to the network bandwidth capacity within the corresponding time window. Based on the preliminary distribution of abnormal traffic peaks, the frequency range of device connection fluctuations is analyzed to determine the dynamic trend of device disconnection and reconnection rates between floors. Based on the dynamic trend of device disconnection and reconnection rates, the duration distribution of abnormal sessions where communication traffic is concentrated between floors is obtained. Through the duration distribution of abnormal sessions where communication traffic is concentrated between floors, the correlation characteristics between user device target port access preferences and fluctuations and traffic correlations in different floors are analyzed to determine whether the communication pattern concentration deviates from a preset threshold range, obtaining a preliminary identification result of potential anomalies. If the preliminary identification result of potential anomalies shows that the communication pattern concentration exceeds the preset threshold range, the sensitivity of capturing cross-floor data packet frequencies is dynamically adjusted to determine the location of abnormal traffic peaks under nighttime characteristics. Based on the location of abnormal traffic peaks under nighttime characteristics... The system optimizes real-time monitoring parameters for changes in floor equipment density and cross-floor equipment migration trajectories, and obtains dynamic rules for detecting equipment disconnection and reconnection rates and data transmission directionality. Based on these dynamic rules, it updates the abnormal response mechanism for target port access preferences, extracts communication data packets from floor combinations with connection densities exceeding a preset threshold from network logs, parses the protocol types of the data packets, and calculates the proportion of each protocol's usage to the total usage, obtaining the communication protocol distribution ratio. If the analysis result of the communication protocol distribution ratio does not match the preset threshold, the corresponding traffic limiting process is triggered, resulting in a temporary protection strategy for nighttime periods. The system verifies the allocation constraints of communication period concentration, adjusting the upper limit of communication period concentration based on the upper limit of transmission rates set for each protocol in the temporary protection strategy for nighttime periods, combined with the real-time collected proportion of each type of equipment, to obtain adjusted allocation constraint parameters. Based on the adjusted allocation constraint parameters, it extracts historical traffic fluctuation data and corresponding bandwidth utilization data, fits the relationship between fluctuation amplitude and bandwidth utilization, calculates the predicted bandwidth demand, and determines a dynamic adjustment scheme for network bandwidth during nighttime periods.
2. The method for real-time identification of network threats based on deep packet inspection according to claim 1, characterized in that, The method involves real-time collection of network traffic data from the dormitory building, extracting the frequency of cross-floor data packets and the concentration of communication periods for each floor within different time windows, to obtain a preliminary distribution of abnormal traffic peaks. The concentration of communication periods is the ratio of the total number of data packets to the network bandwidth capacity within the corresponding time window, including: The network traffic of the dormitory building is collected in segments, and the transmission frequency of cross-floor data packets within each time window is calculated to obtain the communication frequency distribution matrix of each floor. Based on the communication frequency distribution matrix, the ratio of the frequency difference between adjacent time windows to the frequency of the previous time window is calculated to obtain the frequency change rate. Time points where the change rate exceeds a preset threshold are marked as potential abnormal moments, and an abnormal moment sequence for each floor is generated. Based on the abnormal moment sequence, the communication period concentration index is obtained. By comparing the communication period concentration index with historical benchmark values, the floor locations where the concentration deviation exceeds the preset threshold and the corresponding abnormal moments are determined, and an abnormal traffic peak point distribution is generated.
3. The method for real-time identification of network threats based on deep packet inspection according to claim 1, characterized in that, The analysis of the frequency range of equipment connection fluctuations based on the preliminary distribution of abnormal traffic peaks, and the determination of the dynamic trend of equipment disconnection and reconnection rates between floors, includes: Based on the distribution of abnormal traffic peaks, the ratio of the number of connected devices on each floor to the total number of devices on that floor within each time window is calculated to obtain the time-series data of device density for each floor. The density abrupt change point is determined based on this data. At the density abrupt change point, the number of devices whose status changes from connected to disconnected and from disconnected to connected in the device connection status record is identified, and the ratio of disconnected devices to reconnected devices is calculated as the disconnection-to-reconnection rate at that moment. By comparing the differences in disconnection-to-reconnection rates between different floors at the same density abrupt change point, and the changing pattern of the disconnection-to-reconnection rate of each floor over time, the dynamic trend of the device disconnection-to-reconnection rate between floors is determined.
4. The method for real-time identification of network threats based on deep packet inspection according to claim 1, characterized in that, The dynamic trend of device disconnection and reconnection rates, and the acquisition of the distribution of abnormal session durations where communication traffic is concentrated between floors, include: Based on the dynamic trend of the device disconnection and reconnection rate, extract device identification information within the time period when the disconnection and reconnection rate exceeds a preset threshold, track the switching records of the device between access points on different floors, and construct a cross-floor device migration trajectory sequence; based on the cross-floor device migration trajectory sequence, count the device migration frequency between every two floors, calculate the ratio of migration frequency to the total number of inter-floor communication connections, and obtain the inter-floor connection density; based on the communication protocol distribution ratio, record the data flow direction from the source floor to the target floor, obtain the data transmission directionality parameter, identify continuous data packet sequences using the same protocol and having the same transmission direction, calculate the time interval of each session, and generate an abnormal session duration distribution.
5. The method for real-time identification of network threats based on deep packet inspection according to claim 1, characterized in that, The method analyzes the distribution of abnormal session durations by analyzing the aggregation of communication traffic across floors, identifies the correlation characteristics between user equipment's target port access preferences and fluctuations and traffic on different floors, determines whether the aggregation of communication patterns deviates from a preset threshold range, and obtains preliminary identification results of potential anomalies, including: Session records with abnormal session durations exceeding a preset threshold are extracted. Target port number information is parsed from these session records, and the proportion of access frequency for each port number to the total number of accesses on that floor is calculated to obtain the target port access preference distribution of the user device across different floors. Based on the target port access preference distribution, the correlation between access fluctuation values and traffic changes is calculated. Communication patterns with correlation values higher than the threshold are verified. The sum of the absolute values of the differences between the actual port access frequency distribution and the expected distribution is calculated as the deviation. If the deviation exceeds a preset threshold range, an abnormal clustering of communication patterns is determined, and a preliminary identification result of potential anomalies is obtained.
6. The method for real-time identification of network threats based on deep packet inspection according to claim 1, characterized in that, If the preliminary identification results of potential anomalies show that the aggregation of communication patterns exceeds a preset threshold range, the sensitivity to capturing cross-floor data packet frequencies is dynamically adjusted to determine the location of abnormal traffic peaks under nighttime characteristics, including: If the preliminary identification results of potential anomalies show that the communication pattern aggregation exceeds the preset threshold range, then the time points where the change ratio exceeds the preset standard are extracted. For the time points, the ratio of the total number of data packets to the network capacity of the time period is calculated as the concentration degree of the communication period. The gradient change rate is obtained by dividing the difference of the concentration degree of adjacent time points by the time interval, and the time interval in which the gradient change rate reaches its maximum value is identified. By analyzing the distribution of the time interval with the largest gradient change rate in a specific period of night, the specific time when the data packet frequency reaches its peak and the corresponding floor number in the interval are determined, and the time and floor location information of the abnormal traffic peak point is obtained.
7. The method for real-time identification of network threats based on deep packet inspection according to claim 1, characterized in that, The method optimizes real-time monitoring parameters for changes in floor equipment density and cross-floor equipment migration trajectories based on the location of abnormal traffic peaks during nighttime periods, and obtains dynamic rules for detecting equipment disconnection and reconnection rates and data transmission directionality, including: Based on the time and floor location information of the abnormal traffic peak point, the equipment density data sequence of the floor location within a specific time range before and after the peak time is extracted, the standard deviation of the sequence is calculated, and the standard deviation is adjusted according to a preset ratio and added to or subtracted from the average density value to obtain the dynamic threshold range for density monitoring. The dynamic threshold range is used to determine the time of abnormal equipment density. At the time, the equipment migration records of the peak floor and its adjacent floors are extracted. The migration frequency in each time period is counted, and different weight values are assigned according to the time period to construct the time weight parameter for migration trajectory monitoring. The floor pair priority sequence is generated according to the time weight parameter, and the key floor pair list is formed by combining the upper limit of migration frequency. Dynamic rules for equipment disconnection and reconnection rate and data transmission directionality detection are obtained.
8. The method for real-time identification of network threats based on deep packet inspection according to claim 1, characterized in that, The abnormal response mechanism for target port access preferences, based on dynamic rules, is updated. Communication data packets from floor combinations with connection density exceeding a preset threshold are extracted from network logs. The protocol type of the data packets is parsed, and the proportion of each protocol's usage to the total usage is calculated to obtain the communication protocol distribution ratio. If the analysis result of the communication protocol distribution ratio does not match the preset threshold, the corresponding traffic limiting process is triggered to obtain a temporary protection strategy for the nighttime period, including: Extract abnormal location data of key floors in the dynamic rules from the access logs within the monitoring time interval, calculate the ratio of the frequency of occurrence of the abnormal location to the average frequency of the same period in history, and obtain the abnormal deviation value; adjust the preset judgment threshold of the target port access preference according to the abnormal deviation value, re-evaluate the current port access frequency using the adjusted threshold, determine the list of ports whose access frequency exceeds the adjusted threshold, extract the communication protocol type corresponding to the port, calculate the proportion of traffic of each protocol to the total traffic, if the proportion of a certain protocol exceeds the preset upper limit threshold, traffic restriction is triggered, and a temporary protection policy for the night period is generated according to the protocol type that triggers traffic restriction and the corresponding rate upper limit.