Network path analysis system and method for network security anomaly detection

By collecting and calculating various network data indicators, network path anomalies are comprehensively judged, which solves the limitations of existing technologies in judging network security status and the problem of unreasonable resource allocation, and realizes accurate assessment and resource optimization of network security anomaly detection.

CN120956476AInactive Publication Date: 2025-11-14JIANGSU VOCATIONAL COLLEGE OF BUSINESS
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511128798.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-13
Publication Date
2025-11-14
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing technologies for detecting network security anomalies rely solely on the source and destination IP addresses of network data packets to determine network security status. This approach has limitations, as it cannot quantify the degree of network security anomalies and leads to inefficient resource allocation.

Method used

By collecting network path traffic data, switch data, packet data, and user data, we calculate traffic anomaly indicators, MAC address anomaly indicators, packet anomaly indicators, user behavior indicators, and path anomaly indicators. We then comprehensively calculate the network path anomaly index and combine it with the path anomaly rate and anomaly rate threshold to determine the network security anomaly level.

Benefits of technology

It enables the evaluation of network path operation status from multiple dimensions, improves the accuracy of assessment, timely detects network equipment failures and abnormal user behavior, reasonably adjusts traffic allocation strategies, improves resource utilization efficiency, and clearly classifies network security status levels.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120956476A_ABST
    Figure CN120956476A_ABST
Patent Text Reader

Abstract

The invention discloses a network path analysis system and method for network security anomaly detection, and relates to the field of data analysis, and the main scheme is that a network path comprehensive anomaly index Xh is calculated according to a network equipment anomaly index XAh, a user comprehensive risk index XBh and a path anomaly index XCh, and a network path can be comprehensively evaluated from a plurality of key dimensions; according to the method and the device, the problem that limitation is caused when the network security state is judged only through the source IP address and the destination IP address of the network data packet is solved, whether the network path is abnormal or not is judged according to the network path comprehensive abnormal index Xh and the path abnormal threshold XY, a flow distribution strategy can be reasonably adjusted, and the overall resource utilization efficiency of the network is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data analysis technology, specifically to a network path analysis system and method for detecting network security anomalies. Background Technology

[0002] In the field of enterprise network security protection, analyzing network path status to detect network security anomalies can help enterprises discover potential dangers in advance, accurately locate the root cause of security problems, optimize network security strategies, and enhance the overall security of the enterprise network.

[0003] Traditional methods for detecting network security anomalies through path analysis mainly involve deploying traffic monitoring tools on key network nodes such as routers and core switches to capture information such as the source IP address and destination IP address of network data packets. Then, based on this information, the size, direction, and distribution of traffic are statistically analyzed to determine the network security status.

[0004] Existing technologies still have the following shortcomings: network security threats may come from multiple sources, including network equipment failures, improper user operations, and abnormalities in the network path itself. Judging network security status solely by the source and destination IP addresses of network data packets has limitations and lacks quantitative indicators, making it impossible to determine the degree of network security anomalies, thus leading to unreasonable resource allocation. Summary of the Invention

[0005] (a) Technical problems to be solved

[0006] To address the shortcomings of existing technologies, this invention provides a network path analysis method for network security anomaly detection, based on network device anomaly indicators XA. h User Comprehensive Risk Indicator XB h and path anomaly index XC h Calculate the comprehensive anomaly index X of network paths h This addresses the limitations of relying solely on the source and destination IP addresses of network packets to determine network security status, which can stem from multiple sources, including network equipment malfunctions, improper user operations, and network path anomalies. Instead, it uses a path anomaly rate R and a set of anomaly rate thresholds to determine the level of network security anomalies, thus resolving the problem of insufficient quantitative indicators to assess the degree of network security anomalies and consequently, unreasonable resource allocation.

[0007] (II) Technical Solution

[0008] To achieve the above objectives, the present invention provides a network path analysis method for network security anomaly detection, comprising the following steps:

[0009] Step 1: Collect network path traffic data, switch data, packet data, user data, and path data;

[0010] Step 2: Calculate the traffic anomaly index WA based on traffic data h Calculate the MAC address anomaly indicator WB based on switch data h According to the traffic anomaly indicator WA h and MAC address anomaly indicator WB h Calculate network device anomaly indicators XA h ; Calculate the packet anomaly index WC based on packet data h WD, a user behavior metric calculated based on user data h According to the packet anomaly indicator WC h and user behavior metrics WD h Calculate the user's comprehensive risk index XB h ; Calculate the path anomaly index XC based on path data h According to the network device anomaly indicator XA h User Comprehensive Risk Indicator XB h and path anomaly index XC h Calculate the comprehensive anomaly index X of network paths h Preset path anomaly thresholds X and Y; based on the comprehensive network path anomaly index X h The path anomaly threshold XY is used to determine whether the network path is abnormal;

[0011] Step 3: Determine whether all network paths in the enterprise are abnormal according to the methods in Steps 1-2, and count the number of abnormal network paths R; calculate the path abnormality rate Y based on the number of abnormal network paths R; preset anomaly rate threshold set, and determine the network security anomaly level based on the path abnormality rate Y and the anomaly rate threshold set.

[0012] In the preferred embodiment of the network path analysis method for network security anomaly detection described above: Calculate the traffic anomaly index WA h The method is as follows:

[0013] Traffic data includes port traffic AA had Network path bandwidth capacity AB h and network path actual traffic AC h ;

[0014] Calculate the traffic anomaly index WA based on traffic data. h The formula used is:

[0015]

[0016] Among them, WA hThis is the traffic anomaly indicator for the h-th network path, where h is the sequence number corresponding to different network paths, and its value is a positive integer; AA had This represents the port traffic of the a-th device traversed by the h-th network path during the d-th time period; a is the sequence number of each device, ranging from [1, b]; b is the total number of devices, a positive integer; d is the sequence number of each time period, ranging from [1, f]; f is the total number of devices across different time periods, a positive integer; AB h The bandwidth capacity of the h-th network path; AC h This represents the actual traffic of the h-th network path.

[0017] In the preferred embodiment of the network path analysis method for network security anomaly detection described above: Calculate the network device anomaly index XA h The method is as follows:

[0018] Switch data includes the number of address changes (BA). hr BB actual number of access MAC addresses hr Number of MAC addresses of authorized devices BC hr ;

[0019] Calculate the MAC address anomaly index WB based on switch data. h The formula used is:

[0020]

[0021] Among them, WB h BA is an abnormal MAC address indicator for the h-th network path; hr Let be the number of times the address of the r-th switch traversed by the h-th network path changes within a unit time T, where r is the sequence number of the different switches, taking the value [1, s]; and s is the total number of switches in the h-th network path, taking the value of a positive integer; BB hr BC represents the actual number of access MAC addresses of the r-th switch traversed by the h-th network path; hr This represents the number of authorized devices whose MAC addresses are passed through by the r-th switch along the h-th network path.

[0022] According to the traffic anomaly indicator WA h and MAC address anomaly indicator WB h Calculate network device anomaly indicators XA h The formula used is:

[0023]

[0024] Among them, XA h This refers to the network device anomaly indicators for the h-th network path.

[0025] In the preferred embodiment of the network path analysis method for network security anomaly detection described above: Calculate the packet anomaly index WC h The method is as follows:

[0026] The data packet data includes the number of erroneous data packets (CB). h Number of retransmitted data packets (CC) h Data packet length CD hm and normal length range [CE] hm CF hm ];

[0027] Calculate the packet anomaly index WC based on packet data. h The formula used is:

[0028]

[0029] Among them, WC h This is an anomaly indicator for data packets on the h-th network path; CB h The number of erroneous packets on the h-th network path; CC h The number of retransmitted data packets for the h-th network path; CD hm Let m be the length of the m-th data packet in the h-th network path, where m is the sequence number of the different data packets, and its value is [1, C]. h CA h The total number of data packets, taking a positive integer value; CE hm This represents the lower limit of the normal length range for the m-th data packet in the h-th network path; CF hm This represents the upper limit of the normal length range for the m-th data packet in the h-th network path.

[0030] In the preferred embodiment of the network path analysis method for network security anomaly detection described above: calculating the user behavior indicator WD h The method is as follows:

[0031] User data includes the number of times a user logs in (DA). h Number of logins outside of working hours (DB) h Number of logins from different locations (DC) h Total number of resources accessed (DD) h and the number of resources exceeding the access permissions (DE) h ;

[0032] WD (User Behavior Indicators) are calculated based on user data. h The formula used is:

[0033]

[0034] Among them, WD hDA is the user behavior indicator for the h-th network path. n The number of user logins in the h-th network path; DB n The number of times a user logs in outside of working hours in the h-th network path; DC n DD represents the number of times a user logs in from a different location within the h-th network path; n DE represents the total number of resources accessed by users in the h-th network path; n This represents the number of resources accessed beyond the user's authorized access permissions in the h-th network path.

[0035] In the preferred embodiment of the network path analysis method for network security anomaly detection described above: Calculate the user's comprehensive risk index XB. h The method is as follows:

[0036] According to the data packet anomaly indicator WC h and user behavior metrics WD h Calculate the user's comprehensive risk index XB h The formula used is:

[0037] XB h =α1×WC h +α2×WD h

[0038] Among them, XB h ɑ1 is the comprehensive risk index for users on the h-th network path; ɑ1 is the packet anomaly index WC. h The weighting coefficients range from 0.3 to 0.7; α2 represents the user behavior metric WD. h The weighting coefficients are 0.3 to 0.7, and a1 + a2 = 1.

[0039] In the preferred embodiment of the network path analysis method for network security anomaly detection described above: calculate the path anomaly index XC. h The method is as follows:

[0040] Path data includes the number of redundant chains (EA). h Total number of chains EB h Path response time EC h Path response average time ED h Expected path length EF h Actual path length EG h Device vulnerability ratio score EH h ;

[0041] Calculate the path anomaly index XC based on path data. h The formula used is:

[0042]

[0043] Among them, XC h This is the path anomaly indicator for the h-th network path; EA h EB represents the number of redundant chains in the h-th network path. h EC represents the total number of links in the h-th network path; h ED represents the path response time of the h-th network path. h EF is the average path response time for the h-th network path; h Let h be the expected path length of the h-th network path; EG h EH represents the actual path length of the h-th network path. h Score the percentage of device vulnerabilities for the h-th network path.

[0044] In the preferred embodiment of the network path analysis method for network security anomaly detection described above, the method for determining whether a network path is abnormal is as follows:

[0045] According to the network device anomaly indicator XA h User Comprehensive Risk Indicator XB h and path anomaly index XC h Calculate the comprehensive anomaly index X of network paths h The formula used is:

[0046]

[0047] Among them, X h The comprehensive anomaly index for the h-th network path;

[0048] Based on the network path comprehensive anomaly index X h The method used to determine whether a network path is abnormal, based on the path anomaly threshold XY, is as follows:

[0049]

[0050] In the preferred embodiment of the network path analysis method for network security anomaly detection described above, the method for determining the level of network security anomaly is as follows:

[0051] The path anomaly rate Y is calculated based on the number of abnormal network paths R, using the following formula:

[0052]

[0053] Where i represents the total number of network paths;

[0054] The set of anomaly rate thresholds includes a high anomaly rate threshold YG, a low anomaly rate threshold YD, and a no-anomaly threshold YW;

[0055] The network security anomaly level is determined based on the path anomaly rate Y and the set of anomaly rate thresholds, using the following formula:

[0056]

[0057] The present invention also discloses a network path analysis system for network security anomaly detection, comprising: a data acquisition module capable of acquiring network path traffic data, switch data, packet data, user data and path data;

[0058] The metrics calculation module can calculate the traffic anomaly metric WA based on traffic data. h Calculate the MAC address anomaly indicator WB based on switch data h According to the traffic anomaly indicator WA h and MAC address anomaly indicator WB h Calculate network device anomaly indicators XA h ; Calculate the packet anomaly index WC based on packet data h WD, a user behavior metric calculated based on user data h According to the packet anomaly indicator WC h and user behavior metrics WD h Calculate the user's comprehensive risk index XB h ; Calculate the path anomaly index XC based on path data h According to the network device anomaly indicator XA h User Comprehensive Risk Indicator XB h and path anomaly index XC h Calculate the comprehensive anomaly index X of network paths h Preset path anomaly thresholds X and Y; based on the comprehensive network path anomaly index X h The path anomaly threshold XY is used to determine whether the network path is abnormal;

[0059] The judgment module is used to determine whether all network paths in the enterprise are abnormal according to the methods of the data collection module and the indicator calculation module, and count the number of abnormal network paths R; calculate the path abnormality rate Y based on the number of abnormal network paths R; and preset anomaly rate threshold set to determine the network security anomaly level based on the path abnormality rate Y and the anomaly rate threshold set.

[0060] (III) Beneficial Effects

[0061] This invention provides a network path analysis method for network security anomaly detection, which has the following beneficial effects:

[0062] (1) By collecting network path traffic data, switch data, packet data, user data and path data, the network path operation status can be evaluated from multiple dimensions, improving the accuracy of the evaluation.

[0063] (2) Calculate the network device anomaly index XA based on traffic data and switch data. h It can detect potential problems with network equipment hardware in a timely manner, which is beneficial for enterprises to maintain and replace hardware before it is completely damaged, reducing network downtime caused by equipment failure. It also calculates the comprehensive user risk index XB based on packet data and user data. h It can monitor whether users use data according to the prescribed permissions and purposes, promptly detect abnormal user behavior, and calculate the path anomaly index XC based on path data. h This facilitates rapid location of the fault path, providing a basis for fault diagnosis and recovery, based on the network device anomaly indicator XA. h User Comprehensive Risk Indicator XB h and path anomaly index XC h Calculate the comprehensive anomaly index X of network paths h It can comprehensively evaluate network paths from multiple key dimensions, solving the limitation of judging network security status solely based on the source and destination IP addresses of network packets. It also utilizes a comprehensive network path anomaly index X. h Using path anomaly thresholds X and Y to determine whether a network path is abnormal helps to rationally adjust traffic allocation strategies and improve the overall resource utilization efficiency of the network.

[0064] (3) The network security anomaly level can be determined based on the path anomaly rate R and the set of anomaly rate thresholds. This can clearly divide the network security status into different levels, solving the problem of lack of quantitative indicators, inability to judge the degree of network security anomaly, and thus unreasonable resource allocation. Attached Figure Description

[0065] Figure 1 This is a schematic diagram illustrating the working steps of the network path analysis method for network security anomaly detection according to the present invention. Detailed Implementation

[0066] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.

[0067] Please see the appendix Figure 1 This invention provides a network path analysis method for network security anomaly detection, comprising the following steps:

[0068] Step 1: Collect network path traffic data, switch data, packet data, user data, and path data.

[0069] Based on the content of step 1:

[0070] By collecting network path traffic data, switch data, packet data, user data, and path data, the operational status of the network path can be evaluated from multiple dimensions, improving the accuracy of the assessment.

[0071] Step 2: Calculate the traffic anomaly index WA based on traffic data h Calculate the MAC address anomaly indicator WB based on switch data h According to the traffic anomaly indicator WA h and MAC address anomaly indicator WB h Calculate network device anomaly indicators XA h ; Calculate the packet anomaly index WC based on packet data h WD, a user behavior metric calculated based on user data h According to the packet anomaly indicator WC h and user behavior metrics WD h Calculate the user's comprehensive risk index XB h ; Calculate the path anomaly index XC based on path data h According to the network device anomaly indicator XA h User Comprehensive Risk Indicator XB h and path anomaly index XC h Calculate the comprehensive anomaly index X of network paths h Preset path anomaly thresholds X and Y; based on the comprehensive network path anomaly index X h The path anomaly threshold XY is used to determine whether the network path is abnormal.

[0072] Step 2 includes the following steps:

[0073] Step 201: Calculate the flow anomaly index WA h The method is as follows:

[0074] Traffic data includes port traffic AA had Network path bandwidth capacity AB h and network path actual traffic AC h .

[0075] It should be noted that port traffic AA had This refers to the amount of data transmitted through a network device port, reflecting the data transmission between devices or network segments connected to that port. It is measured using network monitoring tools such as Ntop and Wireshark. Network path bandwidth capacity AB hThis refers to the maximum amount of data a network path can transmit per unit of time. It determines the data transmission capacity of the network path and is an inherent attribute of the network path. It depends on factors such as the performance of network devices and the physical characteristics of the link, and is measured using a network bandwidth tester. (Network path actual traffic AC) h It refers to the amount of data actually transmitted through the network path per unit of time, reflecting the data transmission status of the network path in actual operation, and is obtained by measuring network monitoring tools such as Ntop and Wireshark.

[0076] Calculate the traffic anomaly index WA based on traffic data. h The formula used is:

[0077]

[0078] Among them, WA h This is the traffic anomaly indicator for the h-th network path, where h is the sequence number corresponding to different network paths, and its value is a positive integer; AA had This represents the port traffic of the a-th device traversed by the h-th network path during the d-th time period; a is the sequence number of each device, ranging from [1, b]; b is the total number of devices, a positive integer; d is the sequence number of each time period, ranging from [1, f]; f is the total number of devices across different time periods, a positive integer; AB h The bandwidth capacity of the h-th network path; AC h This represents the actual traffic of the h-th network path.

[0079] It should be noted that this formula derives the traffic anomaly index WA by considering the dispersion of device port traffic and bandwidth utilization in the network path. h The higher the dispersion of traffic on device ports, the higher the probability of abnormal traffic patterns, and the higher the probability of abnormal traffic indicators (WA). h The higher the bandwidth utilization, the higher the risk of data breaches and network congestion. (WA, or Abnormal Traffic Index) h The higher.

[0080] Step 202: Calculate the network device anomaly indicator XA h The method is as follows:

[0081] Number of times the switch data address changes (BA) hr BB actual number of access MAC addresses hr Number of MAC addresses of authorized devices BC hr .

[0082] It should be noted that the number of address changes (BA) hrThis refers to the number of times the MAC address of a device connected to a switch port changes within a unit of time T. It is obtained by centrally managing and monitoring the switch using network management software such as SolarWinds or Zabbix. These systems can automatically collect and statistically analyze MAC address changes on switch ports and generate reports. The number of address changes (BA) within a unit of time T can be obtained by viewing these reports. hr Actual number of access MAC addresses (BB) hr This refers to the total number of MAC addresses corresponding to devices currently connected to the switch port. It is obtained by using network management software supporting SNMP, such as BigSister or JFFNMS, to retrieve and parse the MAC address table information from the switch's management information database, counting the parsed MAC addresses to obtain the actual number of connected MAC addresses (BB). hr SNMP is a widely used protocol in network management, allowing network administrators to manage network devices and collect and modify information about these devices. The number of authorized device MAC addresses (BC) hr This refers to the number of MAC addresses that a network administrator has pre-configured and allowed to access the network. It is obtained by: finding port security-related configurations in the switch's configuration file, which includes a list of authorized MAC addresses; counting the MAC addresses in the list gives the number of authorized device MAC addresses, BC. hr .

[0083] Calculate the MAC address anomaly index WB based on switch data. h The formula used is:

[0084]

[0085] Among them, WB h BA is an abnormal MAC address indicator for the h-th network path; hr Let be the number of times the address of the r-th switch traversed by the h-th network path changes within a unit time T, where r is the sequence number of the different switches, taking the value [1, s]; and s is the total number of switches in the h-th network path, taking the value of a positive integer; BB hr BC represents the actual number of access MAC addresses of the r-th switch traversed by the h-th network path; hr This represents the number of authorized devices whose network path h passes through the r-th switch.

[0086] It should be noted that this formula derives the MAC address anomaly index WB by comprehensively considering the frequency of address changes by the switch per unit time and the difference between the number of authorized MAC addresses and the number of actual access MAC addresses. hThe higher the frequency of address changes per unit time, and the greater the difference between the number of authorized MAC addresses and the number of actual access MAC addresses, the higher the security risk of the network path. This is indicated by the MAC address anomaly indicator WB. h The higher.

[0087] According to the traffic anomaly indicator WA h and MAC address anomaly indicator WB h Calculate network device anomaly indicators XA h The formula used is:

[0088]

[0089] Among them, XA h This refers to the network device anomaly indicators for the h-th network path.

[0090] It should be noted that this formula takes into account the traffic anomaly index WA. h and MAC address anomaly indicator WB h The impact of this was used to obtain the network device anomaly index XA. h .

[0091] Step 203: Calculate the packet anomaly index WC h The method is as follows:

[0092] The data packet data includes the number of erroneous data packets (CB). h Number of retransmitted data packets (CC) h Data packet length CD hm and normal length range [CE] hm CF hm ].

[0093] It should be noted that the number of erroneous data packets (CB) h This refers to the total number of erroneous data packets transmitted over a network due to various reasons such as physical link failures, electromagnetic interference, network congestion, and protocol errors. These errors may manifest as data corruption, loss, checksum mismatches, etc. This information is obtained using existing network analysis software such as Wireshark. Wireshark can capture data packets in the network, perform detailed analysis on the captured packets, and generate statistical information. This statistical information includes the number of different types of erroneous data packets, such as checksum errors and format errors. The total number of erroneous data packets of each type is then summed to obtain the error packet count (CB). h Number of retransmitted data packets (CC) hIn network communication, the number of data packets retransmitted by the sender due to packet loss, errors, or lack of acknowledgment from the receiver is the retransmission count. This is obtained by the network device's operating system, such as the router's IOS, which tracks retransmissions on its interfaces. The retransmission data from all devices along the network path is retrieved and aggregated through the device's CLI or network management interface, and this aggregated data is used as the retransmission count (CC). h Data packet length CD hm This refers to the length of the data portion contained in a data packet transmitted over a network, usually measured in bytes. It is obtained using software like Wireshark, which captures network data packets and directly displays the length of each captured packet. Normal length range [CE] hm CF hm [CE] refers to the reasonable range of data packet lengths for normal transmission under specific network environments and application scenarios. This range is usually determined by factors such as network protocol specifications, application requirements, and network performance optimization. The method for obtaining this range is as follows: use professional network protocol analysis software such as Wireshark or NAISnifferPortable to determine the network protocol type corresponding to the data packet; consult RFC documents to obtain the network protocol specification corresponding to that network protocol type; and then consult the network protocol specification to obtain the normal length range. hm CF hm Among them, RFC documents are a series of numbered documents that contain a wide range of Internet technology-related content, from basic network protocol specifications to operational guidelines for network applications.

[0094] Calculate the packet anomaly index WC based on packet data. h The formula used is:

[0095]

[0096] Among them, WC h This is an anomaly indicator for data packets on the h-th network path; CB h The number of erroneous packets on the h-th network path; CC h The number of retransmitted data packets for the h-th network path; CD hm Let m be the length of the m-th data packet in the h-th network path, where m is the sequence number of the different data packets, and its value is [1, C]. h CA h The total number of data packets, taking a positive integer value; CE hm This represents the lower limit of the normal length range for the m-th data packet in the h-th network path; CF hm This represents the upper limit of the normal length range for the m-th data packet in the h-th network path.

[0097] It should be noted that this formula derives the packet anomaly index WC by comprehensively considering the proportion of erroneous packets, the proportion of retransmitted packets, and the degree to which the packet length deviates from the normal range. h The higher the percentage of erroneous data packets, the percentage of retransmitted data packets, and the greater the deviation of data packet length from the normal range, the more severe the data packet transmission anomaly. The WC (Warnings Contents) index indicates this anomaly. h The higher.

[0098] Step 204: Calculate the user behavior metric WD h The method is as follows:

[0099] User data includes the number of times a user logs in (DA). h Number of logins outside of working hours (DB) h Number of logins from different locations (DC) h Total number of resources accessed (DD) h and the number of resources exceeding the access permissions (DE) h .

[0100] It should be noted that the user's login count DA h This refers to the total number of times a user attempts to log in to the system within a certain period, reflecting the frequency of user system usage. It is obtained by viewing the system logs, which are files or collections of data recording various events that occur within the system. These logs contain detailed information about system operation, such as user actions, system service startup and shutdown, hardware device status changes, application running status, and network connection activity. The methods for viewing system logs differ depending on the operating system. For Windows systems, system logs are viewed through the Event Viewer; for Linux systems, they are viewed through log management tools such as syslogd and journalctl. (Non-working hours login count DB) h This refers to the number of times a user logs in outside of pre-defined working hours. The method for obtaining this information is as follows: First, determine the company's working hours range. Then, extract user login times from system logs, determine whether each login occurred within working hours, and count the number of logins outside of working hours as the "non-working time login count" (DB). h Number of logins from different locations (DC) h This refers to the number of times a user logs in from a location other than their usual login location. The method for obtaining this information is as follows: First, the IP range of the enterprise's internal network is set as the range of users' commonly used IP addresses. Then, the IP address information of users logging in is obtained from the system logs. The obtained IP addresses are compared with the commonly used IP addresses, and the number of times the IP address is outside the commonly used range is summarized as the DC (Distributed Number of Off-site Logins). h Total number of resources accessed (DD)h This refers to the total number of resources accessed by a user within a certain time period, including files, database records, and network services. It reflects the user's activity level within the system. It is obtained by capturing network packets using Wireshark software, extracting resource access information from them, and then statistically analyzing the data. The number of resources accessed beyond the scope of user permissions (DE) is also included. h This refers to the number of times a user attempts to access resources outside their authorized scope. This metric is crucial for detecting user violations and potential security vulnerabilities. It is obtained by defining access permissions for each user in a permission management system, comparing the resources actually accessed by the user with their authorized scope, determining whether the user accessed resources beyond their authorized scope, and counting these accesses as the number of unauthorized resources (DE). h .

[0101] WD (User Behavior Indicators) are calculated based on user data. h The formula used is:

[0102]

[0103] Among them, WD h DA is the user behavior indicator for the h-th network path. n The number of user logins in the h-th network path; DB n The number of times a user logs in outside of working hours in the h-th network path; DC n DD represents the number of times a user logs in from a different location within the h-th network path; n DE represents the total number of resources accessed by users in the h-th network path; n This represents the number of resources accessed beyond the user's authorized access permissions in the h-th network path.

[0104] It should be noted that this formula derives the user behavior metric WD by calculating the geometric mean of the proportion of users logging in outside of working hours, the proportion of users logging in from different locations, and the proportion of users accessing resources beyond their authorized scope. h The higher the proportion of logins outside of working hours and the higher the proportion of logins from different locations, the higher the risk of user accounts being stolen. (WD) h The higher the value of the user behavior metric WD, the higher the proportion of access to resources beyond the scope of permissions, and the higher the risk of enterprise data leakage. h The higher.

[0105] Step 205: Calculate the user's comprehensive risk index XB h The method is as follows:

[0106] According to the data packet anomaly indicator WC h and user behavior metrics WD hCalculate the user's comprehensive risk index XB h The formula used is:

[0107] XB h =α1×WC h +α2×WD h

[0108] Among them, XB h ɑ1 is the comprehensive risk index for users on the h-th network path; ɑ1 is the packet anomaly index WC. h The weighting coefficient, ranging from 0.3 to 0.7, is based on the data packet anomaly index WC. h User comprehensive risk index XB h The degree of influence is determined; α2 is the user behavior indicator WD h The weighting coefficient, ranging from 0.3 to 0.7, is based on the user behavior metric WD. h User comprehensive risk index XB h The degree of influence is determined; and a1 + a2 = 1.

[0109] It should be noted that this formula uses a weighted formula to comprehensively consider the packet anomaly index (WC). h and user behavior metrics WD h The impact yields the user's comprehensive risk index XB. h .

[0110] Step 206: Calculate the path anomaly index XC h The method is as follows:

[0111] Path data includes the number of redundant chains (EA). h Total number of chains EB h Path response time EC h Path response average time ED h Expected path length EF h Actual path length EG h Device vulnerability ratio score EH h .

[0112] It should be noted that the number of redundant chains EA h This refers to the number of additional links (EAs) in a network path that have the same or similar functions as the main links, added to improve reliability. This is obtained through network topology mapping and analysis tools, such as SolarWindsNetworkTopologyMapper, a network topology mapping tool that can automatically discover and map the topology and analyze link information to obtain the number of redundant links (EA). h Total number of chains: EB hThis refers to the sum of all links that make up a network path, including primary and redundant links. It reflects the complexity of the network path and is obtained by scanning the network using network discovery tools such as Nmap and OpenNMS. Path response time (EC) h Path Response Time (ED) refers to the time elapsed from when the source node sends a request to when the destination node receives a response. It includes the time it takes for data packets to travel along the path and the processing latency of various network devices. It is an important indicator of network path performance and is measured using professional network performance monitoring tools such as PRTG Network Monitor. h This refers to the average value obtained after multiple measurements of path response time. It provides a more stable reflection of the network path's response characteristics. Measurements are obtained using network monitoring software, such as SolarWindsNetworkPerformanceMonitor, which can automatically perform multiple measurements and calculate the average path response time. Expected path length EF h This refers to the ideal path length set during the network design or planning phase based on network architecture and business requirements. It is typically measured in units such as hop count, physical distance, or number of links, and is obtained by reviewing network design schemes and planning documents. Actual path length EG h This refers to the actual number of links, hops, or physical distance that a data packet traverses from the source node to the destination node. It reflects the real-world operation of the network path and is obtained through network path tracing tools, such as Traceroute. Traceroute can trace the routing nodes a data packet passes through from the source to the destination and calculate the actual path length (EG) in hop count form by counting the number of nodes. h Device vulnerability ratio score (EH) h Vulnerability ratio score (EH) is a rating given based on the proportion of vulnerabilities found to the total number of items checked after performing vulnerability scans on network devices such as routers, switches, and firewalls in the network path. It is used to assess the security of network devices. The score is obtained by using professional vulnerability scanning tools, such as Nessus or OpenVAS, to scan the network devices and calculate the ratio of found vulnerabilities to the total number of items checked. When this ratio is less than 5%, the device vulnerability ratio score is considered low. h The equipment vulnerability ratio score is 1 point. When this ratio is between 5% and 10%, the equipment vulnerability ratio score is EH. h The score is 3 points. When this proportion is greater than 10%, the device vulnerability proportion score is EH. h The score is 5 points, where the total number of checks is determined by the vulnerability scanning tool based on its built-in checking mechanisms and plugin library.

[0113] Calculate the path anomaly index XC based on path data. h The formula used is:

[0114]

[0115] Among them, XC h This is the path anomaly indicator for the h-th network path; EA h EB represents the number of redundant chains in the h-th network path. h EC represents the total number of links in the h-th network path; h ED represents the path response time of the h-th network path. h EF is the average path response time for the h-th network path; h Let h be the expected path length of the h-th network path; EG h EH represents the actual path length of the h-th network path. h Score the percentage of device vulnerabilities for the h-th network path.

[0116] It should be noted that this formula derives the path anomaly index XC by comprehensively considering four aspects of network path: structural redundancy, response time, path length, and device security. h Wherein, ln is the logarithmic function. By using the logarithmic function, the combined influence of various factors can be smoothed out, thus reducing the path anomaly index XC. h It can more reasonably reflect abnormal situations in network paths.

[0117] Step 207: The method for determining whether a network path is abnormal is as follows:

[0118] According to the network device anomaly indicator XA h User Comprehensive Risk Indicator XB h and path anomaly index XC h Calculate the comprehensive anomaly index X of network paths h The formula used is:

[0119]

[0120] Among them, X h This is the comprehensive anomaly index for the h-th network path.

[0121] It should be noted that the formula operates by comprehensively considering the network device anomaly indicator XA. h User Comprehensive Risk Indicator XB h and path anomaly index XC h The impact of this was used to obtain the comprehensive anomaly index X of the network path. h Among them, XA h ×XB h ×XC h The synergistic effect of the three indicators was emphasized, (XA) h +XB h+XC h The arithmetic mean of the three indicators is calculated to reflect their average level, thus avoiding excessive influence on the final result due to any one indicator being too high or too low.

[0122] Based on the network path comprehensive anomaly index X h The method used to determine whether a network path is abnormal, based on the path anomaly threshold XY, is as follows:

[0123]

[0124] It should be noted that the method for determining the path anomaly threshold XY is as follows: collect data under normal operating conditions of different network paths, calculate the comprehensive anomaly index of the network path corresponding to different networks according to the above method, calculate the average value and standard deviation of these indicators, and use the average value plus twice the standard deviation as the reference value of the path anomaly threshold XY.

[0125] Combining the content of steps 201 to 207:

[0126] Calculate network device anomaly indicators XA based on traffic data and switch data. h It can detect potential problems with network equipment hardware in a timely manner, which is beneficial for enterprises to maintain and replace hardware before it is completely damaged, reducing network downtime caused by equipment failure. It also calculates the comprehensive user risk index XB based on packet data and user data. h It can monitor whether users use data according to the prescribed permissions and purposes, promptly detect abnormal user behavior, and calculate the path anomaly index XC based on path data. h This facilitates rapid location of the fault path, providing a basis for fault diagnosis and recovery, based on the network device anomaly indicator XA. h User Comprehensive Risk Indicator XB h and path anomaly index XC h Calculate the comprehensive anomaly index X of network paths h It can comprehensively evaluate network paths from multiple key dimensions, solving the limitation of judging network security status solely based on the source and destination IP addresses of network packets. It also utilizes a comprehensive network path anomaly index X. h Using path anomaly thresholds X and Y to determine whether a network path is abnormal helps to rationally adjust traffic allocation strategies and improve the overall resource utilization efficiency of the network.

[0127] Step 3: Determine whether all network paths in the enterprise are abnormal according to the methods in Steps 1-2, and count the number of abnormal network paths R; calculate the path abnormality rate Y based on the number of abnormal network paths R; preset anomaly rate threshold set, and determine the network security anomaly level based on the path abnormality rate Y and the anomaly rate threshold set.

[0128] Step 3 includes the following steps:

[0129] Step 301: The method for determining the level of network security anomalies is as follows:

[0130] The path anomaly rate Y is calculated based on the number of abnormal network paths R, using the following formula:

[0131]

[0132] Where i represents the total number of network paths.

[0133] It should be noted that this formula calculates the path anomaly rate Y by dividing the number of abnormal network paths R by the total number of network paths.

[0134] The set of anomaly rate thresholds includes a high anomaly rate threshold YG, a low anomaly rate threshold YD, and a no-anomaly threshold YW.

[0135] It should be noted that the methods for determining the high anomaly rate threshold YG, low anomaly rate threshold YD, and no anomaly threshold YW are as follows: Data from different periods of abnormal network operation are collected, and the path anomaly rate is calculated using the method described above. The top 20% of data are selected, and their average value is calculated as a reference value for the high anomaly rate threshold YG. The top 50% of data are selected, and their average value is calculated as a reference value for the low anomaly rate threshold YD. Abnormal network operation includes connectivity anomalies, high latency, and path anomalies. Data from different periods of normal network operation are collected, and the path anomaly rate is calculated using the method described above. The bottom 50% of data are selected, and their average value is calculated as a reference value for the no anomaly threshold YW.

[0136] The network security anomaly level is determined based on the path anomaly rate Y and the set of anomaly rate thresholds, using the following formula:

[0137]

[0138] Based on the content of step 301:

[0139] Determining the network security anomaly level based on the path anomaly rate R and the set of anomaly rate thresholds can clearly classify the network security status into different levels, solving the problem of insufficient quantitative indicators to determine the degree of network security anomalies, which leads to unreasonable resource allocation.

[0140] On the other hand, the present invention also discloses a network path analysis system for network security anomaly detection, used to implement the above-mentioned network path analysis method for network security anomaly detection, including:

[0141] The data acquisition module is capable of collecting network path traffic data, switch data, packet data, user data, and path data;

[0142] The metrics calculation module can calculate the traffic anomaly metric WA based on traffic data. h Calculate the MAC address anomaly indicator WB based on switch data h According to the traffic anomaly indicator WA h and MAC address anomaly indicator WB h Calculate network device anomaly indicators XA h ; Calculate the packet anomaly index WC based on packet data h WD, a user behavior metric calculated based on user data h According to the packet anomaly indicator WC h and user behavior metrics WD h Calculate the user's comprehensive risk index XB h ; Calculate the path anomaly index XC based on path data h According to the network device anomaly indicator XA h User Comprehensive Risk Indicator XB h and path anomaly index XC h Calculate the comprehensive anomaly index X of network paths h Preset path anomaly thresholds X and Y; based on the comprehensive network path anomaly index X h The path anomaly threshold XY is used to determine whether the network path is abnormal;

[0143] The judgment module is used to determine whether all network paths in the enterprise are abnormal according to the methods of the data collection module and the indicator calculation module, and count the number of abnormal network paths R; calculate the path abnormality rate Y based on the number of abnormal network paths R; and preset anomaly rate threshold set to determine the network security anomaly level based on the path abnormality rate Y and the anomaly rate threshold set.

[0144] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented in software, the above embodiments can be implemented, in whole or in part, as a computer program product. Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution.

[0145] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0146] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application.

Claims

1. A network path analysis method for network security anomaly detection, characterized in that: Includes the following steps: Step 1: Collect network path traffic data, switch data, packet data, user data, and path data; Step 2: Calculate the traffic anomaly index WA based on traffic data h Calculate the MAC address anomaly indicator WB based on switch data h According to the traffic anomaly indicator WA h and MAC address anomaly indicator WB h Calculate network device anomaly indicators XA h ; Calculate the packet anomaly index WC based on packet data h WD, a user behavior metric calculated based on user data h According to the packet anomaly indicator WC h and user behavior metrics WD h Calculate the user's comprehensive risk index XB h ; Calculate the path anomaly index XC based on path data h According to the network device anomaly indicator XA h User Comprehensive Risk Indicator XB h and path anomaly index XC h Calculate the comprehensive anomaly index X of network paths h Preset path anomaly thresholds X and Y; Based on the network path comprehensive anomaly index X h The path anomaly threshold XY is used to determine whether the network path is abnormal; Step 3: Determine whether all network paths in the enterprise are abnormal using the methods in Steps 1 and 2, and count the number of abnormal network paths R; calculate the path abnormality rate Y based on the number of abnormal network paths R. A preset set of anomaly rate thresholds is used to determine the network security anomaly level based on the path anomaly rate Y and the set of anomaly rate thresholds.

2. The network path analysis method for network security anomaly detection according to claim 1, characterized in that: Calculate the traffic anomaly index WA h The method is as follows: Traffic data includes port traffic AA had Network path bandwidth capacity AB h and network path actual traffic AC h ; Calculate the traffic anomaly index WA based on traffic data. h The formula used is: Among them, WA h This is the traffic anomaly indicator for the h-th network path, where h is the sequence number corresponding to different network paths, and its value is a positive integer; AA had This represents the port traffic of the a-th device traversed by the h-th network path during the d-th time period; a is the sequence number of each device, ranging from [1, b]; b is the total number of devices, a positive integer; d is the sequence number of each time period, ranging from [1, f]; f is the total number of devices across different time periods, a positive integer; AB h The bandwidth capacity of the h-th network path; AC h This represents the actual traffic of the h-th network path.

3. The network path analysis method for network security anomaly detection according to claim 2, characterized in that: Calculate network device anomaly indicators XA h The method is as follows: Switch data includes the number of address changes (BA). hr BB actual number of access MAC addresses hr Number of MAC addresses of authorized devices BC hr ; Calculate the MAC address anomaly index WB based on switch data. h The formula used is: Among them, WB h BA is an abnormal MAC address indicator for the h-th network path; hr Let be the number of times the address of the r-th switch traversed by the h-th network path changes within a unit time T, where r is the sequence number of the different switches, taking the value [1, s]; and s is the total number of switches in the h-th network path, taking the value of a positive integer; BB hr BC represents the actual number of access MAC addresses of the r-th switch traversed by the h-th network path; hr This represents the number of authorized devices whose MAC addresses are passed through by the r-th switch along the h-th network path. According to the traffic anomaly indicator WA h and MAC address anomaly indicator WB h Calculate network device anomaly indicators XA h The formula used is: Among them, XA h This refers to the network device anomaly indicators for the h-th network path.

4. The network path analysis method for network security anomaly detection according to claim 3, characterized in that: Calculate the packet anomaly index WC h The method is as follows: The data packet data includes the number of erroneous data packets (CB). h Number of retransmitted data packets (CC) h Data packet length CD hm and normal length range [CE] hm CF hm ]; Calculate the packet anomaly index WC based on packet data. h The formula used is: Among them, WC h This is an anomaly indicator for data packets on the h-th network path; CB h The number of erroneous packets on the h-th network path; CC h The number of retransmitted data packets for the h-th network path; CD hm Let m be the length of the m-th data packet in the h-th network path, where m is the sequence number of the different data packets, and its value is [1, C]. h CA h The total number of data packets, taking a positive integer value; CE hm This represents the lower limit of the normal length range for the m-th data packet in the h-th network path; CF hm This represents the upper limit of the normal length range for the m-th data packet in the h-th network path.

5. The network path analysis method for network security anomaly detection according to claim 4, characterized in that: Calculate user behavior metrics WD h The method is as follows: User data includes the number of times a user logs in (DA). h Number of logins outside of working hours (DB) h Number of logins from different locations (DC) h Total number of resources accessed (DD) h and the number of resources exceeding the access permissions (DE) h ; WD (User Behavior Indicators) are calculated based on user data. h The formula used is: Among them, WD h DA is the user behavior indicator for the h-th network path. n The number of user logins in the h-th network path; DB n The number of times a user logs in outside of working hours in the h-th network path; DC n DD represents the number of times a user logs in from a different location within the h-th network path; n DE represents the total number of resources accessed by users in the h-th network path; n This represents the number of resources accessed beyond the user's authorized access permissions in the h-th network path.

6. The network path analysis method for network security anomaly detection according to claim 5, characterized in that: Calculate the user's comprehensive risk index XB h The method is as follows: According to the data packet anomaly indicator WC h and user behavior metrics WD h Calculate the user's comprehensive risk index XB h The formula used is: XB h =α1×WC h +α2×WD h Among them, XB h ɑ1 is the comprehensive risk index for users on the h-th network path; ɑ1 is the packet anomaly index WC. h The weighting coefficients range from 0.3 to 0.7; α2 represents the user behavior metric WD. h The weighting coefficients are 0.3 to 0.7, and a1 + a2 = 1.

7. The network path analysis method for network security anomaly detection according to claim 6, characterized in that: Calculate the path anomaly index XC h The method is as follows: Path data includes the number of redundant chains (EA). h Total number of chains EB h Path response time EC h Path response average time ED h Expected path length EF h Actual path length EG h Device vulnerability ratio score EH h ; Calculate the path anomaly index XC based on path data. h The formula used is: Among them, XC h This is the path anomaly indicator for the h-th network path; EA h EB represents the number of redundant chains in the h-th network path. h EC represents the total number of links in the h-th network path; h ED represents the path response time of the h-th network path. h EF is the average path response time for the h-th network path; h Let h be the expected path length of the h-th network path; EG h EH represents the actual path length of the h-th network path. h Score the percentage of device vulnerabilities for the h-th network path.

8. The network path analysis method for network security anomaly detection according to claim 7, characterized in that: The method for determining whether a network path is abnormal is as follows: According to the network device anomaly indicator XA h User Comprehensive Risk Indicator XB h and path anomaly index XC h Calculate the comprehensive anomaly index X of network paths h The formula used is: Among them, X h The comprehensive anomaly index for the h-th network path; Based on the network path comprehensive anomaly index X h The method used to determine whether a network path is abnormal, based on the path anomaly threshold XY, is as follows:

9. The network path analysis method for network security anomaly detection according to claim 8, characterized in that: The method for determining the level of network security anomalies is as follows: The path anomaly rate Y is calculated based on the number of abnormal network paths R, using the following formula: Where i represents the total number of network paths; The set of anomaly rate thresholds includes a high anomaly rate threshold YG, a low anomaly rate threshold YD, and a no-anomaly threshold YW; The network security anomaly level is determined based on the path anomaly rate Y and the set of anomaly rate thresholds, using the following formula:

10. A network path analysis system for network security anomaly detection, characterized in that: include: The data acquisition module is capable of collecting network path traffic data, switch data, packet data, user data, and path data; The metrics calculation module can calculate the traffic anomaly metric WA based on traffic data. h Calculate the MAC address anomaly indicator WB based on switch data h According to the traffic anomaly indicator WA h and MAC address anomaly indicator WB h Calculate network device anomaly indicators XA h ; Calculate the packet anomaly index WC based on packet data h WD, a user behavior metric calculated based on user data h According to the packet anomaly indicator WC h and user behavior metrics WD h Calculate the user's comprehensive risk index XB h ; Calculate the path anomaly index XC based on path data h According to the network device anomaly indicator XA h User Comprehensive Risk Indicator XB h and path anomaly index XC h Calculate the comprehensive anomaly index X of network paths h Preset path anomaly thresholds X and Y; Based on the network path comprehensive anomaly index X h The path anomaly threshold XY is used to determine whether the network path is abnormal; The judgment module is used to determine whether all network paths in the enterprise are abnormal according to the methods of the data collection module and the indicator calculation module, and to count the number of abnormal network paths R; and to calculate the path abnormality rate Y based on the number of abnormal network paths R. A preset set of anomaly rate thresholds is used to determine the network security anomaly level based on the path anomaly rate Y and the set of anomaly rate thresholds.