Intelligent dynamic protection system and method for network attack based on active detection
By comprehensively analyzing the login status, permissions, and browsing habits of online accounts, and using neural network models to identify potential risks, this approach solves the problems of high false positive rates and low protection efficiency in traditional methods, achieving highly efficient security protection for online accounts.
Patent Information
- Application Number
- CN202511396031.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-28
- Publication Date
- 2025-12-05
- Estimated Expiration
- 2045-09-28
AI Technical Summary
Existing technologies cannot effectively identify complex network attacks. Traditional methods lack multi-dimensional analysis, resulting in a high false positive rate and an inability to detect high-risk information leaks in a timely manner. They also lack effective sorting and prioritization mechanisms, leading to low security protection efficiency.
By acquiring information on network account login status, permissions, website browsing history, and hidden links, and combining this with a neural network prediction model, we can analyze information loss and identify and prioritize potential risks using multi-dimensional data analysis and neural network models.
It enables comprehensive and accurate assessment of online accounts, identifies potential risks, improves security protection efficiency, quickly identifies high-risk accounts and prioritizes their handling, and reduces the risk of information loss.
Smart Images

Figure CN120896782B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network protection, and in particular to an intelligent dynamic protection system and method for network attacks based on active detection. BACKGROUND
[0002] In today's digital age, network security problems are increasingly serious, especially the security of network accounts and the risk of information loss are widely concerned. The complexity and diversity of network environment make network attack means emerge in endlessly, and problems such as account login anomaly and information leakage occur frequently, which brings great loss to users and enterprises; traditional network security monitoring methods often only focus on single-dimensional information, such as password input situation or page access record, which is difficult to comprehensively and accurately evaluate the security status of network accounts. Such single-dimensional monitoring method has a high misjudgment rate, and some potential security risks are easily ignored. For example, only according to the password input error rate to judge whether there is an attack behavior, the input error caused by temporary negligence of the user may be misjudged as an attack behavior, and for some complex attack means, such as attack by imitating normal user behavior, it is difficult to effectively identify; at the same time, the existing network information loss evaluation method lacks comprehensive consideration of multiple factors such as account permissions, website browsing habits and attack situation, and cannot accurately quantify the severity of information leakage. When evaluating the importance of network information loss, the behavior differences of accounts with different permission levels on different pages and the amplification effect of account anomalies on information leakage risk are not fully considered. This leads to the fact that in actual application, some high-risk information leakage situations cannot be found in time, and effective protection measures cannot be taken.
[0003] In addition, when dealing with network account security problems, the traditional method lacks effective sorting and priority processing mechanism, and cannot prioritize accounts with higher risk, resulting in low security protection efficiency. When facing a large number of account security problems, it is difficult to quickly and accurately determine which accounts need to be focused on and processed, and some important security problems may not be solved in time;
[0004] Therefore, the present application provides an intelligent dynamic protection system and method for network attacks based on active detection. SUMMARY
[0005] In order to overcome the defects and deficiencies proposed in the background art, the present application provides an intelligent dynamic protection system and method for network attacks based on active detection.
[0006] In order to achieve the above purpose, the present application adopts the following technical solutions:
[0007] In the first aspect, the present application provides an intelligent dynamic protection method for network attacks based on active detection, comprising the following steps:
[0008] Step S1, obtaining network login situation, permission situation, corresponding website entering browsing situation and corresponding website link hiding situation of each network account;
[0009] Step S2, obtaining network login situation and login habit of network account to perform attack analysis of network account;
[0010] Step S3, performing importance analysis of network information loss based on permission situation, corresponding website browsing situation and attack analysis result of network account;
[0011] Step S4, performing network information loss anomaly analysis based on importance analysis result of network information loss, corresponding website link hiding situation and corresponding website entering browsing habit situation;
[0012] Step S5, performing sorting in combination with network information loss security analysis result, and performing checking processing of network account according to sorting result.
[0013] In an implementation manner of the present application, the network login situation of the network account includes login password input situation of the network account, wherein the login password input situation includes input duration and input error rate of the password, login anomaly analysis is performed through difference between network login and historical login habit, the permission situation includes access permission level situation of the corresponding network account, the corresponding website entering browsing situation includes mouse track situation of the corresponding login process, page staying duration situation and corresponding page type information, and the corresponding website link hiding situation includes hiding situation of important information of the corresponding account website, including size, position, secondary verification times of the important information link and access permission level situation of the important information, which is used to perform network information loss security analysis in combination with login habit of network attack personnel and hiding situation of important information of the website, and the size and position herein are position and area size in the network page, which is used to analyze hiding situation of the important information.
[0014] In an implementation manner of the present application, the attack analysis of the network account in the step S2 includes the following specific steps:
[0015] S21, obtaining input duration and input error rate of the password, historical input duration and average value of input error rate of the password, and simultaneously obtaining mouse track situation of the corresponding login process, historical data provides reference benchmark of normal behavior, which is convenient for subsequent anomaly detection, and time, accuracy and space data are combined to reduce single dimension misjudgment rate;
[0016] S22, calculate the password input time length anomaly coefficient by the standard deviation of the input time length of the password and the average value of the historical input time length of the password, calculate the password input error rate anomaly coefficient by the standard deviation of the input error rate of the password and the average value of the historical input error rate of the password, and obtain the corresponding password input anomaly by weighted sum of the password input time length anomaly coefficient and the password input error rate anomaly coefficient, eliminate the dimensional difference between different accounts by standard deviation normalization, and can allocate weight according to business requirements; The anomaly coefficient directly reflects the degree of deviation from normal behavior;
[0017] S23, obtain the mouse trajectory situation corresponding to the login process, divide the mouse trajectory into the trajectory of the content position of the corresponding access permission level of the account and the trajectory of the content position not of the corresponding access permission level of the account, discard the trajectory of the content position not of the corresponding access permission level of the account, obtain the intersection of the set composed of the trajectory points of the mouse during the access of the corresponding access permission level content of the account in the historical safe login process and the set composed of the trajectory points of the mouse during the access of the corresponding access permission level content of the account in this login process, and divide the intersection by the union of the two sets to obtain the access situation of the corresponding access permission level, subtract the access trajectory anomaly from 1 to obtain the access trajectory anomaly, exclude random trajectories of pages without permission, improve analysis accuracy, compare only trajectories within permission, avoid false positives caused by temporary tasks, and obtain the proportion of anomalies by subtracting the proportion of the intersection of the two sets from 1.
[0018] S24, obtain the account anomaly by weighted sum of the corresponding password input anomaly and the access trajectory anomaly, obtain the account anomaly result, and cover more comprehensive attack features by combining keyboard input and mouse behavior.
[0019] In an implementation manner of the present application, the importance analysis of the network information loss in the step S3 includes the following specific steps:
[0020] S31, obtain the page stay time length situation during access of the corresponding network account and the access permission level situation of the page type information of the corresponding network account, and simultaneously obtain the account anomaly analysis result corresponding to the login, record the stay time length of the user on various pages and the corresponding access permission level, combine the previously calculated account anomaly score, and form a multi-dimensional behavior portrait;
[0021] S32, obtain the page leakage situation by dividing the page stay time length during access by the page security time length, obtain the page leakage danger by multiplying the page leakage situation by the access permission level standard deviation situation of the page type information of the corresponding network account, and multiply the leakage situation by the permission level to highlight the risk amplification effect of high permission pages;
[0022] S33, multiplying the page leakage danger value by the account abnormality score to obtain a corresponding network information loss importance analysis result, the page leakage danger value and the account abnormality score are multiplied, and the severity of potential information leakage is quantified.
[0023] In an implementation manner of the present application, the network information loss abnormality analysis in the step S4 comprises the following specific contents:
[0024] S41, obtaining a link hiding condition of a corresponding website and a corresponding website entering browsing habit condition, and performing link discovery abnormality analysis;
[0025] The specific steps are as follows: obtaining the information amount, size, position, secondary verification times and access permission level condition of the important information link of the page, and the mouse trajectory condition and page staying time condition of the corresponding login process, predicting the information amount of important information leakage by a neural network prediction model, and obtaining the leakage abnormality by dividing the obtained important information leakage information amount by the safe leakage amount, wherein the safe leakage amount is set according to the actual situation, and the specific operation process is as follows: obtaining the mouse trajectory condition and page staying time condition data of historical network attacks, and the size, position and secondary verification times data of the corresponding historical information important information link, simultaneously obtaining the historical data leakage amount condition data, constructing a deep learning neural network with the input of the mouse trajectory condition and page staying time condition data of network attacks, and the size, position and secondary verification times data of the corresponding information important information link, and the output of the data leakage amount condition;
[0026] The historical data is divided into a 9:1 training set and a test set; the 90% weight and bias training set is input into the deep learning neural network model for training to obtain an initial deep learning neural network model; the 10% weight and bias test set is used to test the initial deep learning neural network model, and the output of the initial deep learning neural network model that meets the maximum data leakage amount condition accuracy is output as the deep learning neural network model, and the corresponding link information leakage abnormality result is multiplied by the information access permission level condition to obtain a corresponding link discovery abnormality analysis result;
[0027] S42, by the obtained link discovery anomaly analysis result and the corresponding network information loss importance analysis result, weighted sum of both, get network information loss anomaly analysis result, first through the acquisition website link hidden situation and website entering browsing habit situation link discovery anomaly analysis, using neural network prediction model to predict the information amount of important information leakage, and calculate the leakage anomaly, comprehensive consideration page important information link of multiple characteristics and login process mouse trajectory and page stay time length and other factors, can more accurately predict information leakage risk, then link discovery anomaly analysis result and network information loss importance analysis result are weighted and summed, get more comprehensive, accurate network information loss anomaly analysis result.
[0028] In an implementation form of the present application, the checking process of the network account in step S5 comprises the following specific contents:
[0029] The network information loss anomaly analysis result of all account login processes is obtained, and is compared with the set network information loss anomaly analysis threshold value. If the network information loss anomaly analysis result of the account login process is greater than or equal to the network information loss anomaly analysis threshold value, it indicates that the account login process is unsafe. If the network information loss anomaly analysis result of the account login process is less than the network information loss anomaly analysis threshold value, it indicates that the account login process is safe. For the account with unsafe login process, the personnel to which the account belongs is checked and inquired in descending order of the network information loss anomaly analysis result, and is sorted in combination with the network information loss security analysis result, and the network account is checked according to the sorting result. By comparing the network information loss anomaly analysis result with the set threshold value, it can be quickly judged whether the account login process is safe. For the account with unsafe login process, the account is checked and inquired in descending order of the anomaly analysis result, which can preferentially process the account with higher risk.
[0030] In a second aspect, the present application also provides a network attack intelligent dynamic protection system based on active detection, comprising:
[0031] A data acquisition module acquires the network login situation, the permission situation, the corresponding website entering browsing situation and the link hidden situation of the corresponding website of each network account.
[0032] An attack analysis module acquires the network login situation and the login habit of the network account to perform network account attack analysis.
[0033] An importance analysis module performs network information loss importance analysis based on the permission situation, the corresponding website browsing situation and the network account attack analysis result.
[0034] The information loss anomaly analysis module performs network information loss anomaly analysis based on the importance analysis result of the network information loss, the link hiding situation of the corresponding website, and the website entering browsing habit situation of the corresponding website.
[0035] The collation processing module performs collation processing of the network account according to the sorting result in combination with the security analysis result of the network information loss.
[0036] In a third aspect, the present application provides an electronic device, comprising a processor and a memory, wherein the memory stores a computer program that can be called by the processor, and the processor executes the intelligent dynamic protection method for network attack based on active detection by calling the computer program stored in the memory.
[0037] In a fourth aspect, the present application provides a computer readable storage medium storing instructions, which, when executed on a computer, cause the computer to execute the intelligent dynamic protection method for network attack based on active detection.
[0038] Compared with the prior art, the present application has the following advantages and beneficial effects:
[0039] The present application overcomes the drawbacks of the conventional method that only focuses on single-dimensional information and has a high misjudgment rate, can comprehensively consider account permissions, website browsing habits, attack situations and other factors, comprehensively and accurately assess the security status of the network account and the severity of information loss, effectively identify potential security risks, avoid missing complex attack means, and at the same time, the method has an effective sorting and priority processing mechanism, which can quickly determine the high-risk account that needs to be focused on and processed when facing a large number of account security problems, greatly improving the security protection efficiency, reducing the risk of network information loss, and ensuring the security of the network account. BRIEF DESCRIPTION OF DRAWINGS
[0040] Other features, objects and advantages of the present application will become more apparent from the following detailed description of the non-limiting embodiments, made with reference to the accompanying drawings:
[0041] Figure 1 FIG. 1 is a schematic diagram of the overall process of the method embodiment 1 of the present application;
[0042] Figure 2 FIG. 2 is a schematic diagram of the S2 step of the method embodiment 1 of the present application;
[0043] Figure 3 FIG. 3 is a schematic diagram of the S3 step of the method embodiment 1 of the present application;
[0044] Figure 4 FIG. 4 is a schematic diagram of the structure of the system embodiment 2 of the present application. DETAILED DESCRIPTION
[0045] In order to make the above objectives, characteristics and advantages of the present application more apparent, a detailed description of the specific embodiments of the present application will be given below with reference to the accompanying drawings.
[0046] In the following description, numerous specific details are set forth in order to provide a thorough understanding of the present application. The present application, however, can be practiced in a variety of ways beyond the specific details set forth herein without departing from the scope of the present application, and the present application can be practiced with other than the described implementations. It is therefore intended that the present application not be limited by the described implementation.
[0047] Secondly, the "one embodiment" or "embodiment" referred to herein means a specific feature, structure or characteristic that can be included in at least one implementation of the present application. "In one embodiment" appearing in different places in the specification does not mean the same embodiment, nor does it mean an embodiment that is independent of or mutually exclusive with other embodiments.
[0048] Embodiment 1
[0049] As shown in Figures 1 to 3 The present embodiment provides an intelligent dynamic protection method for network attacks based on active detection, which specifically includes the following steps:
[0050] Step S1, obtaining the network login situation, the permission situation, the corresponding website entering browsing situation and the link hiding situation of the corresponding website of each network account;
[0051] In the present embodiment, the network login situation of the network account includes the login password input situation of the network account, including the input duration and the input error rate of the password, and the login abnormality analysis is performed through the difference between the network login and the historical login habit. The permission situation includes the access permission level situation of the corresponding network account. The higher the access permission, the more important information in the corresponding network account, so that the damage caused by the attack on the account is greater. The corresponding website entering browsing situation includes the mouse trajectory situation of the corresponding login process, the page staying duration situation and the corresponding page type information. The link hiding situation of the corresponding website includes the hiding situation of the important information of the corresponding account website. The prior art often hides the important information of the website to avoid the loss of important information, including the size, position, secondary verification times and access permission level situation of the important information link, which are used to analyze the network information loss security in combination with the login habit of the network attack personnel and the hiding situation of the important information of the website. The size and position here are the position and area size in the network page, which are used to analyze the hiding situation of the important information.
[0052] Step S2, obtaining the network login situation and the login habit of the network account to perform attack analysis on the network account;
[0053] In the embodiment, the analysis of the attack analysis of the network account in step S2 includes the following specific steps:
[0054] S21, obtain the input duration and input error rate of the password, and the average value of the historical input duration and input error rate of the password, and simultaneously obtain the mouse track situation corresponding to the login process, the historical data provide a reference benchmark of normal behavior, facilitate subsequent anomaly detection, combine the time (input speed), accuracy (error times) and space (mouse track) data, and reduce the single dimension misjudgment rate;
[0055] S22, calculate the password input duration anomaly coefficient through the standard deviation of the password input duration and the average value of the historical password input duration, calculate the password input error rate anomaly coefficient through the standard deviation of the password input error rate and the average value of the historical password input error rate, weight and sum the password input duration anomaly coefficient and the password input error rate anomaly coefficient to obtain the corresponding password input anomaly, normalize through the standard deviation to eliminate the dimensional difference between different accounts (for example, some users are used to slow input), weights can be allocated according to business requirements (for example, the financial scene pays more attention to the error rate), and the anomaly coefficient directly reflects the degree of deviation from the normal behavior;
[0056] S23, obtain the mouse track situation corresponding to the login process, divide the mouse track into the track of the content position of the corresponding access permission level of the account and the track of the content position not of the corresponding access permission level of the account, and discard the track of the content position not of the corresponding access permission level of the account. The advantage of distinguishing and analyzing whether it is the content of the corresponding access permission level of the account is that the login personnel corresponding to the account rarely or even do not access the information not of the corresponding access permission level of the account when normally logging in. Thus, if the track is put into calculation as a whole, the information not of the corresponding access permission level of the account has no comparable historical basis, and there is a possibility that the information not of the corresponding access permission level of the account is accessed in this task. If the two are analyzed together, the accuracy of calculation is reduced. The intersection of the set of track points of the mouse when the content of the corresponding access permission level is accessed in the historical safe login process of the account and the set of track points of the mouse when the content of the corresponding access permission level is accessed in the login process is divided by the union of the two sets to obtain the access situation of the corresponding access permission level. The access track anomaly is obtained by subtracting the access situation of the corresponding access permission level from 1. Random track (such as accidental clicking of an advertisement) of a page without permission is excluded to improve the analysis accuracy. Only the track within the permission is compared to avoid misjudgment due to a temporary task (such as temporary authorized access). The proportion of the intersection of the two sets (i.e., the normal proportion) is subtracted from 1 to obtain the proportion of the anomaly. It should be noted that the allocation of the corresponding access permission level of the account is a conventional technical means of the prior art, and the access permission level of the corresponding information is the minimum access permission level of the corresponding allowed access account. For example, the allocation of the corresponding access permission level of the account is divided into level 1 (ordinary employee), level 2 (middle-level leader) and level 3 (high-level leader), and the accounts of levels 1, 2 and 3 can access the corresponding information. Thus, the access permission level of the corresponding information is level 1.
[0057] S24, obtain the account anomaly by weighted summation of the corresponding password input anomaly and the access track anomaly. The account anomaly result is obtained by comprehensively analyzing the keyboard input (password) and the mouse behavior (track) to cover more comprehensive attack features.
[0058] Step S3, perform importance analysis of network information loss based on the permission situation, the corresponding website browsing situation and the attack analysis result of the network account.
[0059] In the embodiment, the importance analysis of network information loss in step S3 includes the following specific steps.
[0060] S31, obtain the page stay duration condition when accessing the corresponding network account and the access permission level condition of the page category information of the corresponding network account, and simultaneously obtain the account anomaly analysis result of the corresponding login, form a multi-dimensional behavior portrait by recording the stay duration (such as second-level precision) of the user on various pages and the corresponding access permission level, and combining the account anomaly score calculated in advance;
[0061] S32, obtain the page leakage condition by dividing the page stay duration condition when accessing by the page security duration, wherein the page security duration is divided according to the number of characters on the page, and is calculated according to the reading speed of the personnel in the corresponding scene, the page security duration is preferably obtained by dividing the number of characters on the page by the reading speed of the personnel in the corresponding scene, obtain the page leakage danger by multiplying the page leakage condition by the access permission level standard deviation condition of the page category information of the corresponding network account, dynamically set according to the page character quantity divided by the scene reading speed, reflect the time required for normal reading of the user, multiply the leakage condition by the permission level, highlight the risk amplification effect of high permission page, wherein the standard deviation is the standard deviation of the access permission level of the page category information of the corresponding network account and the access permission level corresponding to the login account;
[0062] S33, obtain the importance analysis result of the corresponding network information loss by multiplying the page leakage danger condition by the account anomaly, multiply the page leakage danger value by the account anomaly score to quantify the severity of potential information leakage, highlight the amplification effect of account anomaly on page leakage danger;
[0063] Step S4, perform network information loss anomaly analysis based on the importance analysis result of the network information loss, the link hiding condition of the corresponding website, and the website entering browsing habit condition of the corresponding website;
[0064] In this embodiment, the network information loss anomaly analysis in step S4 includes the following specific contents:
[0065] S41, obtain the link hiding condition of the corresponding website and the website entering browsing habit condition of the corresponding website, and perform link discovery anomaly analysis;
[0066] The specific steps are as follows: obtaining the information amount, size, location, secondary verification times, and access permission level of important information links of the page, as well as the corresponding login process mouse trajectory and page stay time, predicting the information amount of important information leakage through a neural network prediction model, and obtaining the leakage anomaly by dividing the corresponding obtained important information leakage amount by the safe leakage amount, wherein the safe leakage amount is set according to the actual situation, and the setting of the safe leakage amount needs to consider multiple dimensions of factors, low sensitive information: this kind of information usually does not cause significant loss to enterprises or individuals, such as general news information, public product introduction, etc. For this kind of information, a relatively high proportion of leakage is allowed, generally, the safe leakage amount can be set to 10%-20% of the total amount of information, for example, a page containing 100MB product introduction documents, the safe leakage amount can be set to 10MB-20MB; medium sensitive information: involving customer's basic information (such as name, address, contact information), enterprise's ordinary business data, etc., the safe leakage amount should be strictly controlled, which can be set to 1%-5% of the total amount of information. Assuming that a database storing customer's basic information has a capacity of 500MB, the safe leakage amount can be set to 5MB-25MB; high sensitive information: including enterprise's core business secrets, financial data, personal sensitive identity information (such as ID number, bank card number) etc., once leaked, it may cause serious consequences. The safe leakage amount should be very low, usually 0.1%-1% of the total amount of information, for example, an enterprise's financial database has 200MB data, the safe leakage amount can be set to 0.2MB-2MB;
[0067] The neural network prediction model has important significance in predicting the information amount of important information leakage, which is trained based on a large amount of historical information leakage data, covering different types of important information such as business secrets and personal privacy, as well as various characteristic variables related to them, such as data access frequency, access source, system vulnerability, etc. In the training process, the model uses a multi-layer neural network structure to learn the potential laws and patterns in the information leakage data through complex calculations and adjustments of the weights between neurons. It can analyze the complex relationship between different characteristics and information leakage amount, such as which access source is more likely to cause large amount of information leakage, and which system vulnerability will significantly affect the amount of leaked information, etc. The specific operation process is as follows: obtaining the mouse trajectory and page stay time data of historical network attacks, as well as the size, location and secondary verification times data of corresponding historical information important information links, and obtaining the historical data leakage amount data, constructing a deep learning neural network with network attack mouse trajectory and page stay time data as input, and corresponding information important information link size, location and secondary verification times data as output;
[0068] The historical data is divided into a 9:1 training set and a test set; the 90% weight, bias training set is input into the deep learning neural network model for training to obtain an initial deep learning neural network model; the 10% weight, bias test set is used to test the initial deep learning neural network model, and the output of the initial deep learning neural network model that meets the maximum data leakage condition accuracy is output as the deep learning neural network model; the corresponding link information leakage anomaly result is multiplied by the access permission level of the information to obtain the corresponding link discovery anomaly analysis result;
[0069] S42, by obtaining the link discovery anomaly analysis result and the importance analysis result of the corresponding network information loss, the network information loss anomaly analysis result is obtained by weighted summation, first the link discovery anomaly analysis is carried out by obtaining the website link hiding condition and the website entering browsing habit condition, the information leakage amount of important information is predicted by using the neural network prediction model, and the leakage anomaly is calculated, considering the multiple characteristics of the page important information link and the mouse trajectory and page staying time of the login process and other factors, the information leakage risk can be more accurately predicted, then the link discovery anomaly analysis result and the importance analysis result of the network information loss are weighted and summed to obtain a more comprehensive and accurate network information loss anomaly analysis result, which helps to discover the abnormal situation of network information loss in time and take corresponding protection measures;
[0070] Step S5, sort according to the network information loss security analysis result, and perform network account checking processing according to the sorting result;
[0071] In this embodiment, the network account checking processing in step S5 includes the following specific contents:
[0072] The network information loss anomaly analysis result of all account login processes is compared with the set network information loss anomaly analysis threshold. If the network information loss anomaly analysis result of the account login process is greater than or equal to the network information loss anomaly analysis threshold, it indicates that the account login process is not safe. If the network information loss anomaly analysis result of the account login process is less than the network information loss anomaly analysis threshold, it indicates that the account login process is safe. For the account with an unsafe login process, the personnel to whom the account belongs is checked and inquired in descending order of the network information loss anomaly analysis result, combined with the network information loss security analysis result, and the network account is checked according to the sorting result. By comparing the network information loss anomaly analysis result with the set threshold, it can be quickly judged whether the account login process is safe. For the account with an unsafe login process, the account is checked and inquired in descending order of the anomaly analysis result, which can prioritize the account with higher risk, improve the efficiency and pertinence of security protection, and timely discover and solve potential network security problems to ensure the safe use of network accounts.
[0073] It should be noted that the acquisition method of the set weight parameter and the set threshold and other set parameters of the present application is to acquire the network login situation, the permission situation, the corresponding website entering and browsing situation, and the link hiding situation of the corresponding website of the historical corresponding network account, import the historical data into each step of the embodiment for network information loss anomaly analysis, and acquire the network account processing order result with the minimum actual loss. The acquired analysis result and processing order result are imported into the matlab fitting software for data fitting to obtain the value meeting the highest network account processing order result accuracy.
[0074] It should be noted that the embodiment has the following advantages and benefits: The embodiment overcomes the disadvantages of the traditional method of only focusing on single-dimensional information and high misjudgment rate, can comprehensively consider account permissions, website browsing habits, attack situations and other factors, comprehensively and accurately evaluate the security status of network accounts and the severity of information loss, effectively identify potential security risks, avoid missing complex attack methods, and at the same time, the method has an effective sorting and priority processing mechanism, which can quickly determine the high-risk account that needs to be focused on and processed when facing a large number of account security problems, greatly improve the security protection efficiency, reduce the risk of network information loss, and ensure the security of network accounts.
[0075] Embodiment 2
[0076] As Figure 4As shown, the embodiment provides an active detection-based network attack intelligent dynamic protection system, which is used for the implementation of the active detection-based network attack intelligent dynamic protection method of embodiment 1, and specifically includes: a data acquisition module, which acquires network login conditions, permission conditions, corresponding website entering and browsing conditions, and corresponding website link hiding conditions of each network account; an attack analysis module, which acquires network login conditions and login habits of the network account and performs attack analysis on the network account; an importance analysis module, which performs importance analysis on network information loss based on the permission conditions, corresponding website browsing conditions, and attack analysis results of the network account; an information loss anomaly analysis module, which performs network information loss anomaly analysis based on the importance analysis results of the network information loss, the corresponding website link hiding conditions, and the corresponding website entering and browsing habit conditions; and a checking processing module, which performs sorting in combination with the network information loss security analysis results, and performs checking processing on the network account according to the sorting results. The specific steps of each module of the embodiment of the system are the same as the specific steps of the method embodiment of embodiment 1, and will not be repeated here.
[0077] Embodiment 3
[0078] An electronic device of an embodiment of the present application includes a processor and a memory, wherein the memory stores a computer program that can be called by the processor, and the processor executes the active detection-based network attack intelligent dynamic protection method by calling the computer program stored in the memory. It should be noted that all computer programs of the active detection-based network attack intelligent dynamic protection method are implemented using C language.
[0079] Embodiment 4
[0080] The embodiment provides a computer readable storage medium, which stores an erasable computer program.
[0081] When the computer program runs on the computer device, the computer device executes the active detection-based network attack intelligent dynamic protection method described above.
[0082] The above-described embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented by software, the above-described embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions according to the embodiments of the present application are wholly or partially generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center through a wired network or / and a wireless network. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center, and the like, which includes one or more available medium collections. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium. The semiconductor medium can be a solid-state disk.
[0083] Those skilled in the art can clearly understand that the units and algorithm steps of the examples described in combination with the embodiments disclosed in the present application can be realized by electronic hardware or a combination of computer software and electronic hardware. Whether the functions are realized in hardware or software depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the present application.
[0084] Those skilled in the art can clearly understand that, for the convenience and brevity of the description, the specific working processes of the above-described system, device, and unit can refer to the corresponding processes in the foregoing method embodiments, which will not be described here.
[0085] In several embodiments provided in the present application, it should be understood that the disclosed system, device, and method can be implemented in other ways. For example, the above-described device embodiments are only schematic, for example, the division of units is only one, and actual implementation can have another division manner, for example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed units can be indirect coupling or communication connection through some interfaces, devices, or units, which can be electrical, mechanical, or other forms.
[0086] The units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Part or all of the units can be selected according to actual needs to achieve the purpose of the embodiment scheme.
[0087] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can be physically present alone, or two or more units can be integrated in one unit.
[0088] In the description of the specification, the description referring to the terms "one embodiment", "example", "specific example" and the like means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are contained in at least one embodiment or example of the present application. In the specification, the illustrative description of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.
[0089] The basic principles and main features of the present application and the advantages of the present application are shown and described above. It should be understood by those skilled in the art that the present application is not limited by the above embodiments, and the above embodiments and descriptions in the specification are only to illustrate the principles of the present application. Without departing from the spirit and scope of the present application, various changes and improvements of the present application can be made, and these changes and improvements all fall within the scope of the claimed present application. The scope of protection of the present application is defined by the appended claims and their equivalents.
Claims
1. A method for intelligent dynamic protection against network attacks based on active detection, characterized in that, It comprises the following steps: Step S1, obtaining the network login situation, the permission situation, the corresponding website entering browsing situation and the link hiding situation of the corresponding website of each network account; The network login situation of the network account includes the login password input situation of the network account, including the input duration and the input error rate of the password, the permission situation includes the access permission level situation of the corresponding network account, the corresponding website entering browsing situation includes the mouse trajectory situation of the corresponding login process, the page staying duration situation and the corresponding page type information, and the link hiding situation of the corresponding website includes the hiding situation of important information of the corresponding account website; Step S2, obtaining the network login situation and login habit of the network account for attack analysis of the network account; Step S3, based on the permission situation, the corresponding website entering browsing situation and the attack analysis result of the network account, the importance analysis of the network information loss is carried out; Step S4, based on the importance analysis result of the network information loss, the link hiding situation of the corresponding website and the corresponding website entering browsing situation, the network information loss anomaly analysis is carried out; Step S5, combining the network information loss anomaly analysis for sorting, and carrying out the checking treatment of the network account according to the sorting result.
2. The method of claim 1, wherein the method further comprises: The attack analysis of the network account comprises the following specific steps: S21, obtaining the input duration and the input error rate of the password, the historical input duration and the average value of the input error rate of the password, and simultaneously obtaining the mouse trajectory situation of the corresponding login process; S22, calculating the password input duration anomaly coefficient by the standard deviation of the password input duration and the average value of the historical password input duration, calculating the password input error rate anomaly coefficient by the standard deviation of the password input error rate and the average value of the historical password input error rate, and weighting and summing the password input duration anomaly coefficient and the password input error rate anomaly coefficient to obtain the corresponding password input anomaly; S23, obtaining the mouse trajectory situation of the corresponding login process, dividing the mouse trajectory into the trajectory of the content position of the corresponding access permission level of the account and the trajectory of the content position not of the corresponding access permission level of the account, discarding the trajectory of the content position not of the corresponding access permission level of the account, obtaining the intersection of the set composed of the trajectory points of the mouse during the access of the corresponding access permission level content of the account in the historical safe login process and the set composed of the trajectory points of the mouse during the access of the corresponding access permission level content in this login process, dividing the intersection by the union of the two sets to obtain the corresponding access permission level access situation, and obtaining the access trajectory anomaly by subtracting the corresponding access permission level access situation from 1; S24, weighting and summing the corresponding password input anomaly and the access trajectory anomaly to obtain the account anomaly, and obtaining the account anomaly result. 3.The method of claim 2, wherein, The importance analysis of the network information loss comprises the following specific steps: S31, obtaining the page staying duration situation during the access of the corresponding network account and the access permission level situation of the page type information of the corresponding network account, and simultaneously obtaining the account anomaly analysis result of the corresponding login; S32, obtaining the page leakage situation by dividing the page stay duration at the corresponding access time by the page security duration, and obtaining the page leakage danger by multiplying the page leakage situation by the access permission level standard deviation situation of the page category information of the corresponding network account; S33, obtaining the importance analysis result of the corresponding network information loss by multiplying the page leakage danger situation by the account anomaly.
4. The method of claim 3, wherein the method further comprises: The network information loss anomaly analysis includes the following specific contents: S41, obtaining the link hiding situation of the corresponding website and the website entering browsing situation, and performing link discovery anomaly analysis; S42, obtaining the network information loss anomaly analysis result by weighting and summing the link discovery anomaly analysis result and the importance analysis result of the corresponding network information loss.
5. The method of claim 4, wherein the method further comprises: The link discovery anomaly analysis includes the following specific contents: obtaining the information amount, size, location, secondary verification times and access permission level situation of the important information link of the page, and the mouse trajectory situation and page stay duration situation of the corresponding login process, predicting the information amount of important information leakage by a neural network prediction model, obtaining the leakage anomaly by dividing the corresponding obtained important information leakage information amount by the security leakage amount, obtaining the mouse trajectory situation and page stay duration situation data of historical network attacks, and the size, location and secondary verification times data of the corresponding historical information important information link, and simultaneously obtaining the historical data leakage amount situation data, constructing a deep learning neural network with the mouse trajectory situation and page stay duration situation data of network attacks as input, and the size, location and secondary verification times data of the corresponding information important information link as output; divide the historical data into a 9:1 training set and a test set; input the 90% weight and bias training set into the deep learning neural network model for training to obtain an initial deep learning neural network model; test the initial deep learning neural network model using the 10% weight and bias test set, and output the initial deep learning neural network model output that meets the maximum data leakage amount situation accuracy as the deep learning neural network model; obtaining the corresponding link discovery anomaly analysis result by multiplying the corresponding link information leakage anomaly result by the access permission level situation of the information.
6. The method of claim 5, wherein the method further comprises: The checking process of the network account includes the following specific contents: comparing the network information loss anomaly analysis result of the account login process with the set network information loss anomaly analysis threshold value, if the network information loss anomaly analysis result of the account login process is greater than or equal to the network information loss anomaly analysis threshold value, it means that the account login process is not safe, if the network information loss anomaly analysis result of the account login process is less than the network information loss anomaly analysis threshold value, it means that the account login process is safe, for the account with unsafe login process, the personnel to which the account belongs is checked and inquired in descending order of the network information loss anomaly analysis result, and the network account is checked according to the sorting result.
7. An active detection based intelligent dynamic protection system for network attacks, for implementing the active detection based intelligent dynamic protection method for network attacks according to any one of claims 1-6, characterized in that, The system includes: The data acquisition module acquires the network login condition, the permission condition, the corresponding website entering and browsing condition, and the link hiding condition of the corresponding website of each network account; The attack analysis module acquires the network login condition and the login habit of the network account to perform attack analysis on the network account; The importance analysis module performs importance analysis on the network information loss based on the permission condition, the corresponding website entering and browsing condition, and the attack analysis result of the network account; The information loss anomaly analysis module performs anomaly analysis on the network information loss based on the importance analysis result, the link hiding condition of the corresponding website, and the corresponding website entering and browsing condition; The check processing module performs sorting in combination with the anomaly analysis on the network information loss, and performs check processing on the network account according to the sorting result.
Citation Information
Patent Citations
Data safety monitoring system
CN112560027A
Automated Prediction Of Cybersecurity Vulnerabilities
US20230019180A1