Defense matrix method for network attack traffic identification
By constructing a network attack identification and defense matrix model and combining it with a honeypot system to track abnormal behavior, the problem of low identification rate and high false alarm rate of 0-day and 1-day vulnerabilities in existing technologies has been solved, and efficient network attack traffic identification and self-learning capabilities have been achieved.
Patent Information
- Application Number
- CN202511387536.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-26
- Publication Date
- 2025-11-18
AI Technical Summary
Existing network intrusion detection technologies have low accuracy in identifying 0-day and 1-day vulnerabilities, high false alarm rates, poor self-maintenance capabilities, and difficulty in effectively responding to network attack traffic.
A network attack identification and defense matrix model is constructed. Network attacks are identified through traffic analysis, attack feature matching, and behavior pattern matrix model. A honeypot system is used to track abnormal behavior and dynamically expand the feature database to reduce the false alarm rate.
It effectively reduced the false positive rate of network attack traffic, improved the ability to identify 0-day and 1-day vulnerabilities, reduced the time cost of manual verification, and enhanced self-learning capabilities.
Smart Images

Figure CN120979812A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the technical field of network traffic attack defense, specifically relating to a defense matrix method for identifying network attack traffic. Background Technology
[0002] Most existing IDC intrusion detection technologies on the market rely on vulnerability signature matching, while a small number of IDC products use abnormal behavior analysis for detection.
[0003] Vulnerability signature matching is time-sensitive, with high accuracy in identifying network attack traffic targeting hot vulnerabilities, requiring frequent updates to the vulnerability database. However, it has low accuracy in identifying network traffic targeting 0-day and 1-day vulnerabilities, and signature variations frequently lead to bypasses of detection. It is also insensitive to backend service behavior, focusing only on characteristic values contained in data traffic, resulting in a high false positive rate.
[0004] Anomaly behavior analysis and detection: Possesses sensitive business behavior detection capabilities, enabling timely and effective detection of all abnormal behaviors occurring on the server. It has a certain ability to identify 0-day and 1-day vulnerabilities. Essentially, it judges data traffic behavior through the response status of the business system. This requires a high level of proficiency in server operation status and business processes, and necessitates continuous updating of the anomaly behavior analysis database by personnel. Furthermore, the self-maintenance capabilities of IDC products are relatively poor.
[0005] Therefore, based on the shortcomings of the two existing network intrusion detection technologies mentioned above, this invention discloses a defense matrix method for identifying network attack traffic. Summary of the Invention
[0006] This invention discloses a defense matrix method for identifying network attack traffic, which effectively reduces the false alarm rate of network attack traffic and reduces the time cost of manual verification.
[0007] This invention is achieved through the following technical solution:
[0008] A defense matrix method for identifying network attack traffic includes the following steps:
[0009] Step 1: Collect traffic data and perform traffic parsing to obtain traffic identifiers;
[0010] Step 2: Identify and match features in traffic identifiers based on the attack feature knowledge base, and calculate the attack feature matching danger value based on the matching results. If the attack feature matching danger value is greater than or equal to the risk threshold, proceed to step 4; if the attack feature matching danger value is less than the risk threshold, proceed to step 3.
[0011] Step 3: Establish a behavior pattern matrix model, define the behavior chain of traffic through the behavior pattern matrix model, and calculate the hazard value of the behavior chain. If the hazard value of the behavior chain is greater than or equal to the risk threshold, proceed to step 4; if the hazard value of the behavior chain is less than the risk threshold, proceed to step 5.
[0012] Step 4: Identify dangerous traffic and proxy it to the honeypot system. The honeypot system tracks subsequent traffic behavior, extracts the stages and traffic characteristics of abnormal behavior, and saves the traffic characteristics of abnormal behavior to the behavior pattern matrix model for dynamic iterative expansion of the behavior pattern matrix model.
[0013] Step 5: Proxy the output of traffic that is determined to be non-dangerous.
[0014] To better realize the present invention, step 2 further includes:
[0015] Step 2.1: Cache the traffic identifier and extract the feature values from the traffic;
[0016] Step 2.2: Based on the external POC and attack feature knowledge base, perform similarity matching between the extracted traffic feature values and the attack features in the attack feature knowledge base.
[0017] Step 2.3: Assign feature weights based on the matching results;
[0018] Step 2.4: Establish an attack feature matching hazard value function and calculate the attack feature matching hazard value using the attack feature matching hazard value function; if the attack feature matching hazard value is greater than or equal to the risk threshold, proceed to step 4; if the attack feature matching hazard value is less than the risk threshold, proceed to step 3.
[0019] To better realize the present invention, the attack feature matching danger value function is further defined as follows:
[0020]
[0021] Where: E(x, n) represents the attack feature matching hazard value function; x represents the attack feature value count variable; n represents the upper limit of the attack feature value count; K represents the feature value; M T This represents the weights used to assign feature values in the inverse similarity matrix; K represents the weight of the x-th eigenvalue. x This represents the eigenvalue of the x-th feature.
[0022] To better realize the present invention, further, the traffic identifier is decomposed based on the request body structure, wherein the request body structure includes the request method, request path, request client, and request cross-site information.
[0023] To better realize the present invention, step 3 further includes:
[0024] Step 3.1: Establish a behavior pattern matrix model, which is used to divide the behavior of traffic into several stages and determine whether the behavior of each stage is normal or abnormal.
[0025] Step 3.2: Assign a unique identifier (ID) to each behavior, with each ID corresponding to multiple different feature values;
[0026] Step 3.3: Calculate the myopia value corresponding to the traffic behavior in the current stage using the feature value corresponding to the identifier ID, and take the smallest myopia value as the behavior ID in the current stage;
[0027] Step 3.4: Repeat steps 3.1-3.3 above to obtain the behavior IDs of traffic behavior in several consecutive stages, and obtain the behavior chain of the current traffic based on the behavior IDs;
[0028] Step 3.5: Establish the behavior chain hazard value function. Calculate the behavior chain hazard value of the current traffic using the behavior chain hazard value function. If the behavior chain hazard value is greater than or equal to the risk threshold, proceed to step 4; if the behavior chain hazard value is less than the risk threshold, proceed to step 5.
[0029] To better realize the present invention, the hazard value function of the behavior chain is further defined as follows:
[0030]
[0031] Where: E represents the hazard value of the behavior chain; i represents the index of the identifier ID; m represents the number of identifier IDs; ID i The identifier ID represents the i-th action; This represents the average value of all identifier IDs on the current behavior chain.
[0032] To better realize the present invention, step 4 further includes:
[0033] Step 4.1: Identify traffic deemed dangerous and proxy it to the honeypot system. Record the honeypot system's response status to traffic with dangerous identification and analyze the impact of the traffic on the server.
[0034] Step 4.2: Compare the response status data of the honeypot system with the behavior pattern matrix model to obtain the stages and feature values where abnormal behavior exists;
[0035] Step 4.3: Save the feature values to the behavior pattern matrix model to dynamically expand the behavior pattern matrix model in real time.
[0036] To better implement the present invention, in step 1, traffic data is collected by a traffic receiver and virtual cached. When the traffic receiver obtains the response status code of the traffic or the periodic flood threshold, the cache of the traffic receiver is released.
[0037] Compared with the prior art, the present invention has the following advantages and beneficial effects:
[0038] (1) This invention extends and innovates upon the network attack matrix model, analyzing network attack behavior and network defense behavior from the perspective of the network security team, and constructing a network attack identification and defense matrix model. This model covers almost all possible behaviors generated by network traffic, including normal business behavior and abnormal attack behavior. By analyzing multiple data features contained in the data traffic, it matches a unique behavior item in the matrix model, connects the matched behavior items at each stage, constructs the visitor's behavior chain, and thus identifies attack traffic in the network.
[0039] (2) The defense matrix model constructed in this invention is highly targeted at data traffic feature variants, 0-day and 1-day vulnerabilities. Through the built-in honeypot system, dangerous data traffic is proxied to the observation space, providing server security. Further analysis of data traffic behavior patterns and subsequent behavior chains of traffic with the same identifier can dynamically expand the 0-day vulnerability feature values, greatly improving the self-learning capability of the defense matrix model. Furthermore, through strict danger value calculation methods and behavior chain observation of the honeypot system, the false positive rate of network attack traffic caused by feature values is effectively reduced, reducing the time cost of manual verification. Attached Figure Description
[0040] Figure 1 This is a schematic diagram of the process steps of the present invention. Detailed Implementation
[0041] Example 1:
[0042] This embodiment presents a defense matrix method for identifying network attack traffic, such as... Figure 1 As shown, it includes the following steps:
[0043] Step 1: Collect traffic data and perform traffic parsing to obtain traffic identifiers;
[0044] Step 2: Identify and match features in traffic identifiers based on the attack feature knowledge base, and calculate the attack feature matching danger value based on the matching results. If the attack feature matching danger value is greater than or equal to the risk threshold, proceed to step 4; if the attack feature matching danger value is less than the risk threshold, proceed to step 3.
[0045] Step 3: Establish a behavior pattern matrix model, define the behavior chain of traffic through the behavior pattern matrix model, and calculate the hazard value of the behavior chain. If the hazard value of the behavior chain is greater than or equal to the risk threshold, proceed to step 4; if the hazard value of the behavior chain is less than the risk threshold, proceed to step 5.
[0046] Step 4: Identify dangerous traffic and proxy it to the honeypot system. The honeypot system tracks subsequent traffic behavior, extracts the stages and traffic characteristics of abnormal behavior, and saves the traffic characteristics of abnormal behavior to the behavior pattern matrix model for dynamic iterative expansion of the behavior pattern matrix model.
[0047] Step 5: Proxy the output of traffic that is determined to be non-dangerous.
[0048] Furthermore, step 2 specifically includes:
[0049] Step 2.1: Cache the traffic identifier and extract the feature values from the traffic;
[0050] Step 2.2: Based on the external POC and attack feature knowledge base, perform similarity matching between the extracted traffic feature values and the attack features in the attack feature knowledge base.
[0051] Step 2.3: Assign feature weights based on the matching results;
[0052] Step 2.4: Establish an attack feature matching hazard value function and calculate the attack feature matching hazard value using the attack feature matching hazard value function; if the attack feature matching hazard value is greater than or equal to the risk threshold, proceed to step 4; if the attack feature matching hazard value is less than the risk threshold, proceed to step 3.
[0053] Furthermore, the attack feature matching hazard value function is:
[0054]
[0055] Where: E(x, n) represents the attack feature matching hazard value function; x represents the attack feature value count variable; n represents the upper limit of the attack feature value count; K represents the feature value; M T This represents the weights used to assign feature values in the inverse similarity matrix; K represents the weight of the x-th eigenvalue. x This represents the eigenvalue of the x-th feature.
[0056] Furthermore, the traffic identifier is decomposed based on the request body structure, which includes the request method, request path, request client, and cross-site request information.
[0057] Step 3 specifically includes:
[0058] Step 3.1: Establish a behavior pattern matrix model, which is used to divide the behavior of traffic into several stages and determine whether the behavior of each stage is normal or abnormal.
[0059] Step 3.2: Assign a unique identifier (ID) to each behavior, with each ID corresponding to multiple different feature values;
[0060] Step 3.3: Calculate the myopia value corresponding to the traffic behavior in the current stage using the feature value corresponding to the identifier ID, and take the smallest myopia value as the behavior ID in the current stage;
[0061] Step 3.4: Repeat steps 3.1-3.3 above to obtain the behavior IDs of traffic behavior in several consecutive stages, and obtain the behavior chain of the current traffic based on the behavior IDs;
[0062] Step 3.5: Establish the behavior chain hazard value function. Calculate the behavior chain hazard value of the current traffic using the behavior chain hazard value function. If the behavior chain hazard value is greater than or equal to the risk threshold, proceed to step 4; if the behavior chain hazard value is less than the risk threshold, proceed to step 5.
[0063] Furthermore, the hazard value function of the behavior chain is:
[0064]
[0065] Where: E represents the hazard value of the behavior chain; i represents the index of the identifier ID; m represents the number of identifier IDs; ID i The identifier ID represents the i-th action; This represents the average value of all identifier IDs on the current behavior chain.
[0066] Furthermore, step 4 specifically includes:
[0067] Step 4.1: Identify traffic deemed dangerous and proxy it to the honeypot system. Record the honeypot system's response status to traffic with dangerous identification and analyze the impact of the traffic on the server.
[0068] Step 4.2: Compare the response status data of the honeypot system with the behavior pattern matrix model to obtain the stages and feature values where abnormal behavior exists;
[0069] Step 4.3: Save the feature values to the behavior pattern matrix model to dynamically expand the behavior pattern matrix model in real time.
[0070] Furthermore, in step 1, traffic data is collected and virtually cached by a traffic receiver. When the traffic receiver obtains the response status code of the traffic or the periodic flood threshold, the cache of the traffic receiver is released.
[0071] Example 2:
[0072] This embodiment is an improvement on embodiment 1, specifically as follows:
[0073] Step 1: Collect traffic data through a network traffic receiver and perform simple traffic parsing to obtain traffic identifiers related to Src IP, Dst IP, Src Port, and Dst Port. Use virtual caching technology to store short-term data of the parsed traffic. Release the traffic receiver's cache upon receiving a response status code or a short-term flood threshold.
[0074] Step 2: Identify and deeply analyze the cached traffic identifiers from Step 1. Based on the request body structure, extract relevant traffic information, including: request method, request path, client, cross-site scripting (XSS) information, etc. Use an attack signature knowledge base for feature matching to extract feature values from the traffic: K = [k1, k2, k3, ..., k n The attack signature knowledge base is a set of features for various vulnerabilities. Then, using an external Proof-of-Concept (PoC) and the latest synchronized attack signature knowledge base, the feature values are matched for similarity, and feature weights are assigned based on the matching results: M = [m1, m2, m3, ..., m...]. n ].
[0075] Calculate the attack signature matching risk value:
[0076]
[0077] If the attack feature matches the danger value and reaches or exceeds the risk threshold, proceed to step 4; otherwise, proceed to step 3.
[0078] Step 3: The custom behaviors established based on the behavior pattern matrix model have growth potential, and the deep learning KNN algorithm is used to automatically obtain the feature variants of the attack behaviors.
[0079] Behavior Pattern Matrix Model: Custom behaviors divide traffic behavior patterns into multiple stages, each with normal and abnormal behaviors. Each behavior has a unique identifier (ID), and these IDs correspond to multiple distinct feature values. The model calculates the myopia value corresponding to the traffic behavior in the current stage using the feature values associated with the ID, and takes the smallest myopia value as the behavior ID for that stage. This process is repeated iteratively to obtain behavior IDs for multiple stages, thus acquiring the behavior chain of the network traffic. The danger value of each behavior chain is then calculated.
[0080]
[0081] If the hazard value of the behavior chain reaches or exceeds the risk threshold, proceed to step 4; otherwise, proceed to step 5.
[0082] Step 4: Tag all traffic with the specified network identifier and proxy it to the honeypot system to track subsequent network traffic behavior. Record the honeypot system's response status to data traffic with that network identifier and analyze the impact of its behavior on the server. Record and extract the characteristics of traffic with the same network identifier in the honeypot system, compare the honeypot system response analysis data with the behavior pattern matrix model to obtain the impact stage of abnormal behavior. Save the data to the attack signature knowledge base to dynamically expand the matrix model and output the intercepted signal.
[0083] Step 5: Proximize traffic that is determined to be non-dangerous.
[0084] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any way. Any simple modifications or equivalent changes made to the above embodiments based on the technical essence of the present invention shall fall within the protection scope of the present invention.
Claims
1. A defense matrix method for identifying network attack traffic, characterized in that, Includes the following steps: Step 1: Collect traffic data and perform traffic parsing to obtain traffic identifiers; Step 2: Identify and match features in traffic identifiers based on the attack feature knowledge base, calculate the attack feature matching danger value based on the matching results, and if the attack feature matching danger value is greater than or equal to the risk threshold, proceed to step 4. If the attack feature matches a danger value less than the risk threshold, proceed to step 3; Step 3: Establish a behavior pattern matrix model, define the behavior chain of traffic through the behavior pattern matrix model, and calculate the hazard value of the behavior chain. If the hazard value of the behavior chain is greater than or equal to the risk threshold, proceed to step 4. If the hazard value of the behavior chain is less than the risk threshold, proceed to step 5; Step 4: Identify dangerous traffic and proxy it to the honeypot system. The honeypot system tracks subsequent traffic behavior, extracts the stages and traffic characteristics of abnormal behavior, and saves the traffic characteristics of abnormal behavior to the behavior pattern matrix model for dynamic iterative expansion of the behavior pattern matrix model. Step 5: Proxy the output of traffic that is determined to be non-dangerous.
2. The defense matrix method for identifying network attack traffic according to claim 1, characterized in that, Step 2 specifically includes: Step 2.1: Cache the traffic identifier and extract the feature values from the traffic; Step 2.2: Based on the external POC and attack feature knowledge base, perform similarity matching between the extracted traffic feature values and the attack features in the attack feature knowledge base. Step 2.3: Assign feature weights based on the matching results; Step 2.4: Establish an attack feature matching hazard value function and calculate the attack feature matching hazard value using the attack feature matching hazard value function; if the attack feature matching hazard value is greater than or equal to the risk threshold, proceed to step 4; if the attack feature matching hazard value is less than the risk threshold, proceed to step 3.
3. The defense matrix method for identifying network attack traffic according to claim 2, characterized in that, The attack feature matching hazard value function is: Where: E(x, n) represents the attack feature matching hazard value function; x represents the attack feature value count variable; n represents the upper limit of the attack feature value count; K represents the feature value; M T This represents the weights used to assign feature values in the inverse similarity matrix; K represents the weight of the x-th eigenvalue. x This represents the eigenvalue of the x-th feature.
4. The defense matrix method for identifying network attack traffic according to claim 3, characterized in that, The traffic identifier is decomposed based on the request body structure, which includes the request method, request path, request client, and cross-site request information.
5. A defense matrix method for identifying network attack traffic according to any one of claims 1-4, characterized in that, Step 3 specifically includes: Step 3.1: Establish a behavior pattern matrix model, which is used to divide the behavior of traffic into several stages and determine whether the behavior of each stage is normal or abnormal. Step 3.2: Assign a unique identifier (ID) to each behavior, with each ID corresponding to multiple different feature values; Step 3.3: Calculate the myopia value corresponding to the traffic behavior in the current stage using the feature value corresponding to the identifier ID, and take the smallest myopia value as the behavior ID in the current stage; Step 3.4: Repeat steps 3.1-3.3 above to obtain the behavior IDs of traffic behavior in several consecutive stages, and obtain the behavior chain of the current traffic based on the behavior IDs; Step 3.5: Establish the behavior chain hazard value function. Calculate the behavior chain hazard value of the current traffic using the behavior chain hazard value function. If the behavior chain hazard value is greater than or equal to the risk threshold, proceed to step 4; if the behavior chain hazard value is less than the risk threshold, proceed to step 5.
6. A defense matrix method for identifying network attack traffic according to claim 5, characterized in that, The hazard value function for the behavioral chain is: Where: E represents the hazard value of the behavior chain; i represents the index of the identifier ID; m represents the number of identifier IDs; ID i The identifier ID represents the i-th action; This represents the average value of all identifier IDs on the current behavior chain.
7. A defense matrix method for identifying network attack traffic according to any one of claims 1-4, characterized in that, Step 4 specifically includes: Step 4.1: Identify traffic deemed dangerous and proxy it to the honeypot system. Record the honeypot system's response status to traffic with dangerous identification and analyze the impact of the traffic on the server. Step 4.2: Compare the response status data of the honeypot system with the behavior pattern matrix model to obtain the stages and feature values where abnormal behavior exists; Step 4.3: Save the feature values to the behavior pattern matrix model to dynamically expand the behavior pattern matrix model in real time.
8. A defense matrix method for identifying network attack traffic according to any one of claims 1-4, characterized in that, In step 1, traffic data is collected and virtually cached by a traffic receiver. When the traffic receiver obtains the response status code of the traffic or the periodic flood threshold, the traffic receiver's cache is released.
Citation Information
Patent Citations
Network security protection method, device and storage medium
CN107426242A
Active defense method, system and equipment based on internet access lock and medium
CN118054973A
Defense system for complex collaborative attack in power distribution network
CN119324807A
Intelligent tracking and blocking method and system for network attack chain
CN120474841A
Edge side attack aggregation analysis method based on flow self-learning
CN120639490A