Network monitoring method, computer readable storage medium and electronic device
By using a machine learning-based network monitoring method and manifold learning algorithm to generate ACL negative lists, the problem of difficult rule writing in traditional network monitoring is solved, realizing intelligent monitoring and security isolation of the network, and improving network security and stability.
Patent Information
- Application Number
- CN202511253824.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-03
- Publication Date
- 2025-11-21
AI Technical Summary
Traditional network monitoring methods rely on manual rule matching, which is difficult to write, cannot accurately monitor the network, and is difficult to cope with complex and ever-changing network environments and attack methods.
A machine learning-based approach is used to perform in-depth mining and analysis of network traffic data using manifold learning algorithms, automatically generating access control lists (ACLs) negative lists, and combining this with network operating modes for monitoring and isolation.
It enables real-time detection and isolation of abnormal traffic, improving network security and stability, reducing the need for manual intervention, and lowering management complexity and costs.
Smart Images

Figure CN121000480A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application relate to the technical field of communication, in particular to a network monitoring method, a computer readable storage medium and an electronic device. BACKGROUND
[0002] Currently, with the rapid development of Internet technology, network traffic data is growing explosively, and various abnormal traffic may exist in the network traffic data, such as network attacks, illegal access and malicious software propagation, etc. These abnormal traffic not only seriously threatens network security, but also may cause excessive consumption of network resources and decline of network performance.
[0003] Traditional network monitoring methods mostly rely on manual rule matching or simple statistical analysis, which has obvious limitations. First, the manual rule writing is time-consuming and laborious, and it is difficult to cover all possible abnormal behavior patterns, especially when facing new network attacks that are constantly evolving, the rule update often lags behind the occurrence of attacks. Second, although the statistical method can capture some obvious abnormal situations, it cannot timely isolate the network when facing attacks with strong concealment and low frequency. Therefore, the traditional network monitoring method is difficult to cope with complex and variable network environment and attack means.
[0004] In summary, there is no effective solution in the related art. SUMMARY
[0005] Embodiments of the present application provide a network monitoring method, a computer readable storage medium and an electronic device to at least solve the problem that the traditional network monitoring mostly relies on manual rule matching, which has a large rule writing difficulty and leads to inaccurate network monitoring, thereby achieving the effect of improving network security and stability.
[0006] According to an embodiment of the present application, a network monitoring method is provided, comprising: determining an access control list (ACL) blacklist according to key features and network behavior features corresponding to different traffic data; and monitoring the network according to the ACL blacklist and a network working mode.
[0007] According to another embodiment of the present application, a computer readable storage medium is also provided, which stores a computer program, wherein the computer program is set to execute the steps in any of the above method embodiments when running.
[0008] According to another embodiment of the present application, an electronic device is also provided, which comprises a memory and a processor, the memory stores a computer program, and the processor is set to run the computer program to execute the steps in the above method embodiments.
[0009] According to another embodiment of the present application, a computer program product is also provided, comprising a computer program which, when executed by a processor, implements the steps in the above method embodiments.
[0010] According to the above embodiments of the present application, a network monitoring method is provided. According to the respective key features and network behavior features of different traffic data, an access control list (ACL) negative list is determined. The network is monitored according to the ACL negative list and the network working mode. That is, by collecting and analyzing network traffic data in real time, the ACL negative list is automatically formed. The ACL negative list is combined with the network working mode. The network traffic data is processed according to the network working mode. When abnormal traffic is detected, the alarm mechanism can be triggered immediately and corresponding isolation measures can be taken to ensure the security and stability of the network. Therefore, the embodiments of the present application can solve the problem that the traditional network monitoring mostly relies on manual rule matching, which has a large rule writing difficulty, resulting in the inability to accurately monitor the network. Thus, the effect of improving the network security and stability is achieved. BRIEF DESCRIPTION OF DRAWINGS
[0011] Figure 1 is a hardware structure block diagram of a computer terminal according to the network monitoring method of the embodiments of the present application;
[0012] Figure 2 is a system architecture diagram of a system running the network monitoring method according to the embodiments of the present application;
[0013] Figure 3 is a flowchart of the network monitoring method according to the embodiments of the present application;
[0014] Figure 4 is a flowchart of generating an ACL configuration strategy based on network traffic data according to the embodiments of the present application;
[0015] Figure 5 is a flowchart of micro-isolation processing for network traffic according to the embodiments of the present application. DETAILED DESCRIPTION
[0016] Hereinafter, the embodiments of the present application will be described in detail with reference to the accompanying drawings and in conjunction with the embodiments.
[0017] It should be noted that the terms "first", "second", and the like in the specification and claims of the present application and the above drawings are used to distinguish similar objects, and do not necessarily have to describe a specific order or sequence.
[0018] The method embodiments provided in the embodiments of the present application can be executed in a mobile terminal, a computer terminal, or a similar computing device. Taking the case of running on a computer terminal, Figure 1This is a hardware structure block diagram of a computer terminal according to an embodiment of the network monitoring method of this application. For example... Figure 1 As shown, a computer terminal may include one or more ( Figure 1 Only one is shown in the diagram. A processor 102 (which may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.) and a memory 104 for storing data are also shown. The computer terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the computer terminal described above. For example, the computer terminal may also include components that are more complex than those described above. Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.
[0019] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the network monitoring method in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, thus implementing the above-described method. The memory 104 may include high-speed random access memory and non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to a computer terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0020] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by a communication provider for the computer terminal. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.
[0021] In traditional network monitoring methods, most of them rely on manual rule matching or simple statistical methods, which usually have the problems of difficult rule writing and statistical method lag, and are difficult to cope with complex and variable network environment and attack means. In view of this, the embodiment of the present application proposes a network monitoring method for automatically generating monitoring rules based on machine learning. Exemplarily, the system combines manifold learning algorithm (Manifold Learning) to deeply mine and analyze network traffic data, realize automatic abnormal traffic detection and security isolation function, and the network monitoring method at least includes the following steps:
[0022] (1) Collect network traffic data, extract low-dimensional features and cluster, generate access control list (Access Control List, ACL) negative list to monitor the network, wherein the ACL negative list can be called ACL blacklist;
[0023] Exemplarily, the low-dimensional features in the network traffic data are extracted to reduce the data dimension.
[0024] Specifically, the complex network traffic data is reduced to six-dimensional data group by using manifold learning algorithm, for example, the six-dimensional data group includes six key features of time, source IP, source port, destination IP, destination port and protocol.
[0025] The network traffic data after dimension reduction is clustered, and machine learning is performed according to time features, traffic features, behavior features, source end features and other features to generate ACL negative list.
[0026] (2) Detect and alarm abnormal network traffic, and perform access control on abnormal network traffic according to the configured network working mode;
[0027] Exemplarily, according to the network isolation (Network Isolation) network working mode (for example: initial mode, detection mode and monitoring mode), the abnormal network traffic is executed to pass, alarm or block processing.
[0028] Specifically, in the initial mode, no control is performed on the abnormal network traffic, and no alarm is generated;
[0029] In the detection mode, the abnormal network traffic generates an alarm, but does not block;
[0030] In the monitoring mode, the abnormal network traffic generates an alarm, and related data is discarded in real time to ensure the security and stability of the network.
[0031] (3) Show the network state of the system;
[0032] Exemplarily, the network traffic distribution, abnormal event statistics, performance trend chart, etc. are displayed on the display interface to support the decision analysis of the administrator.
[0033] Through the intelligent network monitoring method based on machine learning proposed in the above embodiments of the present application, the network traffic data is deeply mined and analyzed by adopting the manifold learning algorithm, and the abnormal traffic detection and network security isolation are realized. Further, the intelligent network monitoring method comprises: collecting and analyzing the network traffic data in real time, extracting low-dimensional features and clustering and machine learning, forming an ACL blacklist to monitor the network; automatically detecting and warning abnormal traffic; setting a network isolation working mode to alarm and isolate abnormal traffic; providing a visual report to facilitate the administrator to intuitively understand the network state and provide support for decision analysis.
[0034] Figure 2 The system architecture diagram of the network monitoring method according to the embodiments of the present application is shown in FIG. 1, which comprises a security management center (SMC) including three modules: a micro-isolation management module, a situation awareness module and a security Agent management module. Figure 2
[0035] The micro-isolation management module is used for security monitoring and policy and mode management. Exemplarily, the network traffic is detected and warned abnormally, and the abnormal traffic is controlled according to the network working mode configured in the mode management.
[0036] The situation awareness module is used for displaying the performance trend chart and the traffic map. Exemplarily, the network state is presented by the visual report, including the network traffic distribution, abnormal event statistics, performance trend chart, etc.
[0037] The security Agent management module collects and analyzes the network traffic data in real time, extracts low-dimensional features and clusters and machine learns, and forms an ACL blacklist to monitor the network.
[0038] Figure 3 The flowchart of the network monitoring method according to the embodiments of the present application is shown in FIG. 2, which comprises the following steps: Figure 3
[0039] Step S302, determining an access control list (ACL) blacklist according to the key features and network behavior features corresponding to different traffic data respectively;
[0040] In the embodiment, different flow data are collected, and the collected different flow data are subjected to dimension reduction processing. For example, a manifold learning algorithm is used to extract low-dimensional features corresponding to the different flow data, wherein the low-dimensional features correspond to key features, and the key features include at least one of the following: a timestamp, a source Internet Protocol (IP) address, a source port number, a destination IP address, a destination port number, and a transport layer protocol.
[0041] The extracted key features corresponding to the different flow data are arranged in a preset order to obtain different six-tuple data groups. The different six-tuple data groups are clustered, and the clustered six-tuple data groups are subjected to machine learning according to network behavior features to determine an Access Control List (ACL) blacklist, wherein the network behavior features include at least one of the following: a time feature, a behavior feature, a flow feature, and a source end feature.
[0042] In some embodiments, before determining the ACL blacklist according to the key features corresponding to the different flow data and the network behavior features, the method further includes: determining distances between data points corresponding to the different flow data by using a preset algorithm; constructing a neighborhood graph according to the distances between each pair of data points and determining shortest distances between each pair of data points on the neighborhood graph; obtaining a geodesic distance matrix according to the shortest distances; outputting the geodesic distance matrix to different flow data in a low-dimensional space by multidimensional scaling analysis; and extracting the key features corresponding to the different flow data.
[0043] In the embodiment, before generating the ACL blacklist according to the key features corresponding to the different flow data and the network behavior features to monitor the network, the flow data in the network are collected in real time by a flow collection device deployed in the network, and low-dimensional features corresponding to the flow data are extracted. For example, Figure 4 is a flow diagram of generating an ACL configuration strategy based on network flow data according to an embodiment of the present application, as Figure 4 shown, the first step is to collect flow data; the second step is to perform dimension reduction processing on the collected flow data by using a manifold learning algorithm (a preset algorithm) and extract low-dimensional features; for example, the low-dimensional features include six key features: a timestamp, a source IP address, a source port number, a destination IP address, a destination port number, and a transport layer protocol. The dimension reduction processing on the collected flow data includes the following steps:
[0044] (1) Construct a similarity measure: in the manifold learning algorithm, construct a similarity measure between data points corresponding to different flow data, which is achieved by calculating distances or adjacency relationships between the data points corresponding to the different flow data.
[0045] (2) Learning low-dimensional representation: Through the manifold learning algorithm, the low-dimensional representation of traffic data in high-dimensional space is learned, not only preserving the main structure and features of traffic data, but also removing redundant information and noise. The following takes the Isomap (Isometric Mapping) algorithm as an example to illustrate the learning of low-dimensional representation of traffic data in high-dimensional space, which includes the following steps:
[0046] A. Constructing a neighborhood graph: For each data point, determine the nearest neighbor to the data point and construct a neighborhood graph.
[0047] B. Computing geodesic distance: On the constructed neighborhood graph, compute the shortest path (shortest distance) between each pair of data points.
[0048] C. Applying MDS (Multi-dimensional Scaling): Determine the geodesic distance matrix according to the computed shortest path, and apply MDS to determine the low-dimensional representation of traffic data.
[0049] Through the Isomap algorithm in the above, the low-dimensional representation of traffic data in high-dimensional space can be learned.
[0050] (3) Output the dimensionality reduction result: The manifold learning algorithm outputs the dimensionality reduced traffic data, which has lower dimensionality and higher interpretability.
[0051] For example, in the dimensionality reduced traffic data, six key features are extracted, including timestamp, source IP address, source port number, destination IP address, destination port number, and transmission layer protocol. The six key features can reflect the basic properties and behavior patterns of network traffic.
[0052] Through the above examples, by using the manifold learning algorithm to extract the low-dimensional features of traffic data, not only the dimensionality of traffic data is reduced, but also the efficiency and accuracy of data processing are improved.
[0053] In some embodiments, according to the key features and network behavior features corresponding to different traffic data, an access control list (ACL) blacklist is determined, including: arranging the key features corresponding to the different traffic data according to a preset order to obtain different multi-dimensional data groups; clustering according to the similarity between different multi-dimensional data groups to obtain different data classes; and machine learning according to the network behavior features of different data classes to obtain the ACL blacklist.
[0054] In this embodiment, the key features corresponding to different traffic data are arranged in a preset order to obtain different tuple data, such as tuples arranged in the order of timestamp, source IP address, source port number, destination IP address, destination port number, and transport layer protocol, forming a six-tuple data set. The six-tuple data set is characterized by its simple structure and ease of processing and analysis.
[0055] In this embodiment, as Figure 4 As shown, the third step is cluster analysis, and adding corresponding workload labels to each cluster. For example, the extracted six-data set is clustered according to the transport layer protocol type, and corresponding workload labels are added to each cluster. The following uses the K-means clustering algorithm as an example to illustrate that clustering the extracted six-data set includes the following steps:
[0056] (1) Input data: Different six data sets are used as input data and input into the K-means clustering algorithm, with the transport layer protocol type field as the center point.
[0057] (2) Perform the K-means clustering algorithm: The clustering algorithm iteratively calculates the similarity between each pair of data points, and finally divides the different six-data sets into different clusters. The specific process includes the following:
[0058] A. Data initialization: Randomly select K data points of different protocol types as the initial cluster centers.
[0059] B. Iterative process:
[0060] b1. Calculate the distance of each data point to the K initial cluster centers and assign it to the cluster with the smallest distance.
[0061] b2. Update cluster center: Calculate the average position of all data points in each cluster and use it as the new cluster center.
[0062] b3. Repeat steps b1-b2 above until the number of iterations is reached or the cluster center no longer changes significantly.
[0063] (3) Output clustering results: The K-means clustering algorithm outputs different data classes, including the center point of each cluster (data class) and the data points contained therein.
[0064] The above method clusters different six-tuples according to the transport layer protocol type. By performing cluster analysis and adding corresponding workload labels to each cluster, it is not only easier to understand the traffic patterns and workload characteristics in the network, but also provides support for subsequent network optimization, performance monitoring and security management. This enables comprehensive monitoring and accurate analysis of network status, enhancing the comprehensiveness and accuracy of network monitoring.
[0065] In some embodiments, the different data classes are machine learned according to network behavior features to obtain an ACL blacklist, including: obtaining abnormal traffic data in each data class according to the network behavior features; extracting the source IP address of the abnormal traffic data in each data class and configuring it as an ACL blacklist.
[0066] In this embodiment, as shown in Figure 4 the fourth step: machine learning to form an ACL configuration strategy; for example, the six-element data group after clustering is further machine learned according to multiple network behavior features (such as time features, behavior features, traffic features, source features, etc.) to automatically form an ACL configuration strategy.
[0067] For example, machine learning according to multiple network behavior features to identify abnormal traffic data includes the following ways:
[0068] A. Abnormal traffic identification according to time features: for example, frequently logging in at non-working hours, logging in for more than 12 hours and continuously active, continuously using different IP addresses to log in within 10 minutes.
[0069] B. Abnormal traffic identification according to behavior features: for example, IP for 5 consecutive failed logins, same user continuously using different regional IP to log in.
[0070] C. Abnormal traffic identification according to traffic features: for example, high concurrency for 10 minutes, session packet size standard deviation exceeding 0.7.
[0071] D. Abnormal traffic identification according to source features: for example, using non-standard ports, lazy user suddenly active.
[0072] Through real-time collection and analysis of network traffic data, potential abnormal traffic such as DDoS attack and malicious software propagation can be discovered and warned in time, so as to effectively prevent abnormal traffic from causing damage to the network.
[0073] In this embodiment, the ACL blacklist is initially empty; for the abnormal traffic data identified in steps A-D above, the IP address of the abnormal traffic data is extracted and configured as an ACL blacklist.
[0074] Further, the ACL blacklist also includes a weight value of the abnormal traffic data, and the weight value of the abnormal traffic data is determined according to the number of identifications.
[0075] For example, the weight value corresponding to the abnormal traffic data is increased by 1 each time the abnormal traffic data is identified, and the weight value is decreased by 1 if no identification is made within 10 minutes; in the case where the weight value corresponding to the abnormal traffic data in the ACL blacklist is 0, the abnormal traffic data is automatically deleted from the ACL blacklist.
[0076] Through the above process, according to the clustered six-element data set, further machine learning is performed according to a plurality of network behavior characteristics, an ACL configuration strategy can be automatically formed, and dynamic adjustment is performed according to changes in the network state, so as to ensure the security and stability of the network and improve the network security protection capability.
[0077] In step S304, the network is monitored according to the ACL blacklist and the network working mode.
[0078] In this embodiment, according to the ACL blacklist generated in the above, the network is monitored according to the configured network working mode for abnormal traffic.
[0079] In some embodiments, monitoring the network according to the ACL blacklist and the network working mode includes: determining whether the source IP address in the different multi-element data set satisfies the ACL blacklist; in the case that the source IP address in the different multi-element data set satisfies the ACL blacklist, performing micro-isolation processing on the different multi-element data set according to the network working mode; and in the case that the source IP address in the different multi-element data set does not satisfy the ACL blacklist, releasing the respective traffic data of the different multi-element data set.
[0080] In this embodiment, Figure 5 is a flowchart of micro-isolation processing for network traffic according to an embodiment of the present application, as Figure 5 shown, the ACL blacklist is matched for different six-element data sets, it is determined whether the source IP address of the different six-element data sets exists in the ACL blacklist, access control is implemented for abnormal traffic, if the source IP address of the warning does not exist in the ACL blacklist, the traffic data corresponding to the warning is released; if the source IP address of the warning exists in the ACL blacklist, the traffic data corresponding to the different warnings is processed by micro-isolation according to the network working mode.
[0081] For example, access control is performed according to the network working mode configured in the micro-isolation management, wherein the network isolation network working mode at least includes one of the following: initial mode, detection mode and monitoring mode.
[0082] For example, in the initial mode, no control is performed on abnormal traffic, and no alarm is generated;
[0083] In the detection mode, an alarm is generated for abnormal traffic, but no blocking is performed;
[0084] In the monitoring mode, an alarm is generated for abnormal traffic, and related data is discarded in real time to ensure the security and stability of the network.
[0085] Through the above embodiments, by setting multiple network isolation network working modes including initial mode, detection mode and monitoring mode, the working mode can be flexibly adjusted according to the change of network state, ensuring the response speed and flexibility of the network. When abnormal traffic is detected, the system can immediately trigger an alarm and take corresponding isolation measures, effectively preventing the spread and damage of abnormal traffic, and the automated abnormal detection and security isolation functions reduce the need for manual intervention, reducing the complexity and cost of network management.
[0086] In some embodiments, in the case that the source IP address in the different multi-element data groups meets the ACL negative list, the different multi-element data groups are subjected to micro-isolation processing according to the network working mode, including: in response to the network working mode being in the initial mode, releasing the traffic data corresponding to each of the different multi-element data groups; in response to the network working mode being in the detection mode, releasing the traffic data corresponding to each of the different multi-element data groups and generating alarm information; and in response to the network working mode being in the monitoring mode, blocking and discarding the traffic data corresponding to each of the different multi-element data groups and generating alarm information.
[0087] In the present embodiment, if the source IP address of the early warning exists in the ACL negative list, the traffic data corresponding to each of the different early warnings is subjected to micro-isolation processing according to the network working mode, as shown in Figure 5 The network working mode of the current network is matched.
[0088] For example, if the network working mode is in the initial mode, the abnormal traffic corresponding to the early warning is released;
[0089] If the network working mode is in the detection mode, the abnormal traffic corresponding to the early warning is released and alarm information is generated;
[0090] If the network working mode is in the monitoring mode, the abnormal traffic corresponding to the early warning is blocked and discarded, and alarm information is generated.
[0091] In some embodiments, the embodiments of the present application can also visually display the network state and provide visual reports.
[0092] For example, a report template is created in the visualization tool, and the set visualization elements are embedded into the report template. The automatic generation and pushing mechanism of the report is set according to the data update frequency, for example, generating a report once a day, once a week or once a month.
[0093] For example, the visual display at least includes network traffic distribution, abnormal event statistics, performance trend chart, etc., and the specific implementation is as follows:
[0094] 1. Network traffic analysis
[0095] (1) Analyze the source, destination, size, protocol type, etc. of network traffic, identify the main characteristics and trends of network traffic.
[0096] (2) Calculate the distribution of network traffic, such as the proportion of network traffic in different time periods, different IP addresses, and different protocols.
[0097] 2. Abnormal event statistics
[0098] (1) Identify and record abnormal events in the system, such as network attacks, system crashes, performance degradation, etc.
[0099] (2) Classify, count, and statistically analyze abnormal events to determine the type, frequency, and impact range of abnormal events.
[0100] 3. Performance trend chart
[0101] (1) Monitor key performance indicators of the system, such as CPU usage, memory usage, disk I / O, etc.
[0102] (2) Analyze historical data of performance indicators to identify trends and patterns of performance changes and generate performance trend charts.
[0103] The above-mentioned visualization display can be designed according to the data analysis results, such as column chart, line chart, pie chart, scatter plot, heat map, etc. The title, label, legend, color, etc. of each visualization element can also be determined.
[0104] In some embodiments, the above-mentioned visualization display of network traffic distribution, abnormal event statistics, performance trend chart, etc. can be displayed through a situational awareness dashboard interface, which at least includes the following components:
[0105] (1) Dashboard: Overall status display of assets, threat events, etc. in the network from different statistical dimensions.
[0106] (2) Visual analysis: Including network analysis and asset topology relationship diagram.
[0107] (3) Asset security: Provide multi-dimensional display of asset information, including asset name, status, network, service, port, etc.
[0108] (4) Network threat events: Administrators can manage threat events discovered in the network uniformly.
[0109] (5) Asset collection: Security management center collects asset information through REST, SFTP interface.
[0110] In the above-mentioned embodiments, the administrator is provided with rich data support and analysis tools through the provided visual report, so that the administrator can intuitively understand the network status, make decisions quickly, and improve the management efficiency.
[0111] The above-mentioned embodiments of the present application provide a network monitoring method. According to the respective key features and network behavior features corresponding to different traffic data, an ACL blacklist is determined. The network is monitored according to the ACL blacklist and the network working mode. That is, by collecting and analyzing network traffic data in real time, the ACL blacklist is automatically formed. The ACL blacklist is combined with the network working mode. The network traffic data is processed according to the network working mode. When abnormal traffic is detected, the alarm mechanism can be triggered immediately and corresponding isolation measures can be taken to ensure the security and stability of the network. Therefore, the embodiments of the present application can solve the problem that the traditional network monitoring mostly relies on manual rule matching, which has a large rule writing difficulty, resulting in the inability to accurately monitor the network, thereby achieving the effect of improving the network security and stability.
[0112] The network monitoring method of the embodiments of the present application includes but is not limited to being applicable to the fields of endogenous security, network monitoring, network security isolation, network performance optimization, network operation and maintenance, core network, industrial control system, smart home and Internet of Things, etc.
[0113] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above-mentioned embodiments can be realized by means of software and a general hardware platform as necessary, and of course, it can also be realized by hardware, but in many cases, the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which is stored in a storage medium (such as a ROM / RAM, a magnetic disk, or an optical disk), and includes a plurality of instructions for causing a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in the various embodiments of the present application.
[0114] It should be noted that the above-mentioned modules can be realized by software or hardware. For the latter, the following implementation manners can be used, but are not limited thereto: the above-mentioned modules are located in the same processor; or the above-mentioned modules are located in different processors in any combination.
[0115] The embodiments of the present application also provide a computer readable storage medium, which stores a computer program. The computer program is configured to execute the steps in any of the above-mentioned method embodiments when running.
[0116] In an example embodiment, the computer readable storage medium described above can include, but is not limited to, a U disk, a Read-Only Memory (ROM), a Random Access Memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store computer programs.
[0117] Embodiments of the present application also provide an electronic device including a memory and a processor, the memory storing a computer program, and the processor being configured to execute the computer program to perform the steps in any of the method embodiments described above.
[0118] In an example embodiment, the electronic device described above can further include a transmission device connected to the processor and an input / output device connected to the processor.
[0119] According to yet another embodiment of the present disclosure, a computer program product is also provided, including a computer program which, when executed by a processor, implements the steps of the method described in various embodiments of the present disclosure.
[0120] The specific examples in the present embodiment can refer to the examples described in the above embodiments and example embodiments, which will not be repeated here.
[0121] Obviously, those skilled in the art should understand that the modules or steps of the present application described above can be realized by general computing devices, which can be concentrated on a single computing device or distributed on a network composed of multiple computing devices, and they can be realized by program codes executable by computing devices, so that they can be stored in storage devices and executed by computing devices, and in some cases, the steps shown or described can be executed in different order, or they can be manufactured into individual integrated circuit modules, or multiple modules or steps among them can be manufactured into a single integrated circuit module. Thus, the present application is not limited to any specific combination of hardware and software.
[0122] The above only describes the preferred embodiments of the present application and is not intended to limit the present application. For those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. within the principles of the present application shall be included in the protection scope of the present application.
Claims
1. A network monitoring method characterized by, The method comprises the following steps: According to the key features and network behavior features corresponding to different traffic data, an access control list (ACL) blacklist is determined; According to the ACL blacklist and network working mode, the network is monitored.
2. The method of claim 1, wherein, Among them, The key features include at least one of the following: timestamp, source Internet Protocol (IP) address, source port number, destination IP address, destination port number, and transmission layer protocol; the network behavior features include at least one of the following: time feature, behavior feature, traffic feature, and source end feature.
3. The method of claim 1, wherein, Before determining the ACL blacklist according to the key features and network behavior features corresponding to different traffic data, the method further comprises the following steps: Determine the distance between data points corresponding to different traffic data by a preset algorithm; Construct a neighborhood graph according to the distance between each pair of data points and determine the shortest distance between each pair of data points on the neighborhood graph; According to the shortest distance, a geodesic distance matrix is obtained, the geodesic distance matrix is output into a low-dimensional space by multidimensional scaling analysis, and the key features corresponding to different traffic data are extracted.
4. The method of claim 1, wherein, The method of determining the ACL blacklist according to the key features and network behavior features corresponding to different traffic data comprises the following steps: Arrange the key features corresponding to different traffic data according to a preset order to obtain different multivariate data groups; According to the similarity between different multivariate data groups, clustering is performed to obtain different data classes; According to the network behavior features, machine learning is performed on different data classes to obtain an ACL blacklist.
5. The method of claim 4, wherein, The method of machine learning on different data classes according to network behavior features to obtain an ACL blacklist comprises the following steps: According to the network behavior features, abnormal traffic data in each data class is obtained; Extract the source IP address of the abnormal traffic data in each data class and configure it as an ACL blacklist.
6. The method of claim 5, wherein, Among them, The ACL blacklist further includes a weight value of the abnormal traffic data, and the weight value of the abnormal traffic data is determined according to the number of identifications.
7. The method of claim 1, wherein, The method of monitoring the network according to the ACL blacklist and network working mode comprises the following steps: Determine whether the source IP address in the different multivariate data groups meets the ACL blacklist; If the source IP address in the different multivariate data groups meets the ACL blacklist, then according to the network working mode, the different multivariate data groups are subjected to micro-isolation processing; If the source IP address in the different multivariate data groups does not meet the ACL blacklist, then the traffic data corresponding to the different multivariate data groups is released.
8. The method of claim 7, wherein, If the source IP address in the different multivariate data groups meets the ACL blacklist, then according to the network working mode, the different multivariate data groups are subjected to micro-isolation processing, which comprises the following steps: In response to the network working mode being in an initial mode, the traffic data corresponding to the different multivariate data groups is released; In response to the network working mode being in a detection mode, the traffic data corresponding to the different multivariate data groups is released and an alarm information is generated. In response to the network working mode being in the monitoring mode, different multi-element data groups respectively corresponding traffic data are blocked and discarded, and alarm information is generated.
9. A computer-readable storage medium, characterized in that, The computer program is stored in the computer readable storage medium and is executed by the processor to implement the steps of the method in any one of claims 1-8.
10. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor executes the computer program to implement the steps of the method in any one of claims 1-8.
11. A computer program product comprising a computer program, characterized in that, The computer program is executed by the processor to implement the steps of the method in any one of claims 1-8. The computer program is executed by the processor to implement the steps of the method in any one of claims 1-8.