Traffic monitoring method and device, electronic equipment and storage medium
By acquiring actual traffic data and mapping knowledge graphs of the monitored network, and combining them with traffic prediction models to identify and handle abnormal traffic, this system addresses the shortcomings of traditional network monitoring systems in data collection, feature analysis, and abnormal traffic handling. It achieves accurate monitoring and handling of abnormal traffic, thereby improving the accuracy and efficiency of network security protection.
Patent Information
- Application Number
- CN202511082589.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-04
- Publication Date
- 2025-12-09
AI Technical Summary
Existing network monitoring information analysis systems have shortcomings in data collection, feature parsing, security policy generation, and abnormal traffic handling, and cannot meet the needs of network monitoring information analysis in the current complex network environment.
By acquiring actual traffic data and mapping knowledge graphs of the monitoring network, the baseline traffic data range is determined. A pre-built traffic prediction model is used for comparison and prediction. The results of the first monitoring and the traffic prediction are combined to make a judgment, identify abnormal traffic, and take precise measures.
It enables precise monitoring and handling of abnormal traffic, improving the accuracy and efficiency of network security protection and adapting to changes in complex network environments.
Smart Images

Figure CN121098532A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present disclosure relates to the field of traffic analysis, and in particular, to a traffic monitoring method and device, an electronic device, and a storage medium. BACKGROUND
[0002] With the rapid development of Internet technology, network space has become an important place for people's life and work, but at the same time, network security problems are becoming increasingly serious. Network attack means are constantly renewed, and the scale of attacks is expanding, and traditional network monitoring information analysis systems are facing many challenges.
[0003] Traditional network monitoring information analysis systems have many shortcomings in data collection, feature analysis, security policy generation, and abnormal traffic disposal, and cannot meet the current network monitoring information analysis needs in complex network environments, and an urgent need for a network monitoring information analysis system based on big data is needed to solve these problems. SUMMARY
[0004] Therefore, the purpose of the present disclosure is to provide a traffic monitoring method, device, electronic device, and storage medium to solve the current problems.
[0005] To achieve the above purpose, the first aspect of the present disclosure provides a traffic monitoring method, which comprises: acquiring actual traffic data of a monitoring network and a mapping knowledge graph corresponding to the monitoring network, determining a reference traffic data range corresponding to the monitoring network according to the mapping knowledge graph; comparing the actual traffic data with the reference traffic data range to obtain a first monitoring result; inputting the actual traffic data into a pre-constructed traffic prediction model, processing via the traffic prediction model, and outputting a traffic prediction result; judging the monitoring network according to the first monitoring result and the traffic prediction result, determining that there is abnormal traffic in the monitoring network, and determining the duration of the abnormal traffic; determining a target disposal method according to the duration, and disposing the abnormal traffic according to the target disposal method.
[0006] Based on the same inventive concept, the second aspect of the present disclosure provides a traffic monitoring device, which comprises: an acquisition module configured to acquire actual traffic data of a monitoring network and a mapping knowledge graph corresponding to the monitoring network, and determine a reference traffic data range corresponding to the monitoring network according to the mapping knowledge graph; a comparison module configured to compare the actual traffic data with the reference traffic data range to obtain a first monitoring result; an input module configured to input the actual traffic data into a pre-constructed traffic prediction model, output a traffic prediction result via processing of the traffic prediction model; a judgment module configured to judge the monitoring network according to the first monitoring result and the traffic prediction result, determine that there is abnormal traffic in the monitoring network, and determine a duration of the abnormal traffic; a treatment module configured to determine a target treatment mode according to the duration, and treat the abnormal traffic according to the target treatment mode.
[0007] Based on the same inventive concept, a third aspect of the present disclosure provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable by the processor, wherein the processor implements the traffic monitoring method as described above when executing the computer program.
[0008] Based on the same inventive concept, a fourth aspect of the present disclosure provides a non-transitory computer-readable storage medium storing computer instructions for causing a computer to execute the traffic monitoring method as described above.
[0009] As can be seen from the above, the present disclosure provides a traffic monitoring method, device, electronic device, and storage medium, actual traffic data of a monitoring network and a mapping knowledge graph corresponding to the monitoring network are obtained, and a reference traffic data range corresponding to the monitoring network is determined according to the mapping knowledge graph. The reference traffic data range is a traffic data range corresponding to normal traffic determined in advance. The actual traffic data is compared with the reference traffic data range to obtain a first monitoring result. The actual traffic data is input into a pre-constructed traffic prediction model, and a traffic prediction result is output via processing of the traffic prediction model. The traffic prediction result obtained by using the pre-trained traffic prediction model is more accurate. The monitoring network is judged according to the first monitoring result and the traffic prediction result, and it is determined that there is abnormal traffic in the monitoring network. The first monitoring result and the traffic prediction result are used together to judge whether there is abnormal traffic in the monitoring network, and the monitoring of abnormal traffic is more accurate. The duration of the abnormal traffic is determined, a target treatment mode is determined according to the duration, and the abnormal traffic is treated according to the target treatment mode, thereby achieving accurate treatment of abnormal traffic. BRIEF DESCRIPTION OF DRAWINGS
[0010] In order to more clearly illustrate the technical solutions in the present disclosure or the related art, the drawings needed to be used in the embodiments or the related art description will be briefly introduced. Obviously, the drawings in the following description are only embodiments of the present disclosure, and other drawings can be obtained by those of ordinary skill in the art without creative effort based on these drawings.
[0011] Figure 1 Flow chart of the flow monitoring method of the embodiments of the present disclosure; Figure 2 Schematic diagram of the flow monitoring system of the embodiments of the present disclosure; Figure 3 Structural block diagram of the flow monitoring device of the embodiments of the present disclosure; Figure 4 Structural schematic diagram of the electronic device of the embodiments of the present disclosure. DETAILED DESCRIPTION
[0012] In order to make the purposes, technical solutions and advantages of the present disclosure clearer, the present disclosure will be further described in detail below with reference to specific embodiments and drawings.
[0013] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present disclosure should be understood as the general meanings understood by those skilled in the art to which the present disclosure belongs. The terms "first", "second" and the like used in the embodiments of the present disclosure do not represent any order, number or importance, but are only used to distinguish different components. The terms "include", "contain" and the like mean that the elements or objects before the terms cover the elements or objects listed after the terms and their equivalents, and do not exclude other elements or objects. The terms "connect" or "connected" and the like do not mean physical or mechanical connection, but can include electrical connection, whether direct or indirect. The terms "upper", "lower", "left", "right" and the like only represent relative positional relationships, and when the absolute positions of the described objects change, the relative positional relationships may also change accordingly.
[0014] With the rapid development of Internet technology, network space has become an important place for people's life and work, but at the same time, network security problems are becoming increasingly serious. Network attack means is constantly renewed, and the attack scale is increasingly expanding. The traditional network monitoring information analysis system is facing many challenges.
[0015] In the traditional network monitoring information analysis system, the data collection method is relatively single, and it is difficult to meet the collection needs of multi-source heterogeneous data. With the complex network environment, the relationship between network behavior characteristics and security events becomes more complex, and the traditional system cannot construct an effective mapping knowledge graph to accurately reflect this relationship, resulting in inaccurate monitoring and analysis of network security events.
[0016] In terms of feature analysis, the traditional system often uses a single analysis strategy, which cannot simultaneously consider the analysis of static and dynamic features. For static features, there is a lack of multi-dimensional statistical methods, making it difficult to extract a comprehensive and accurate analysis result set. For dynamic features, it is difficult to build a real-time tracking model, and it is not possible to capture key information such as behavior mutation points, threat propagation rates, and attack correlation degrees in a timely manner, resulting in delayed discovery and early warning of network abnormal behavior.
[0017] In terms of security policy generation, the traditional system is difficult to extract common patterns from different monitoring periods and network environments, and the constructed policy knowledge base lacks universality and adaptability, making it difficult to quickly generate feature analysis strategies that adapt to new monitoring scenarios. This makes the system inefficient when faced with new network environments and monitoring needs, as it needs to be redesigned and adjusted.
[0018] In terms of abnormal traffic disposal, the traditional system lacks real-time comparison capabilities for multi-dimensional monitoring indicators, making it difficult to detect abnormal indicators in a timely manner. Even if an abnormality is detected, the disposal scheme triggered is relatively single, lacking in specificity and flexibility, making it difficult to effectively deal with complex network security threats. In addition, the traditional system cannot dynamically adjust the disposal threshold according to actual conditions, resulting in poor adaptability and reliability of the system.
[0019] The traditional network monitoring information analysis system has many shortcomings in data collection, feature analysis, security policy generation, and abnormal traffic disposal, and cannot meet the current network monitoring information analysis needs in complex network environments. Therefore, a network monitoring information analysis system based on big data is needed to solve these problems.
[0020] Therefore, the present embodiment proposes a traffic monitoring method, as shown in Figure 1 The method comprises the following steps: Step 101, acquiring actual traffic data of a monitoring network and a mapping knowledge graph corresponding to the monitoring network, determining a reference traffic data range corresponding to the monitoring network according to the mapping knowledge graph; Step 102, comparing the actual traffic data with the reference traffic data range to obtain a first monitoring result; Step 103, inputting the actual traffic data into a pre-constructed traffic prediction model, processing via the traffic prediction model, and outputting a traffic prediction result; Step 104, judging the monitoring network according to the first monitoring result and the flow prediction result, determining that there is abnormal flow in the monitoring network, and determining the duration of the abnormal flow; Step 105, determining a target treatment mode according to the duration, and treating the abnormal flow according to the target treatment mode.
[0021] In specific implementation, actual flow data of a monitoring network and a mapping knowledge graph corresponding to the monitoring network are obtained, wherein the actual flow data represents network flow data in the monitoring network and can be obtained by a distributed probe cluster. The mapping knowledge graph is pre-constructed knowledge graph data, wherein the mapping knowledge graph includes network behavior characteristics, threat levels, and attack paths.
[0022] The actual flow data is compared with the reference flow data range to obtain a first monitoring result. The first monitoring result includes that the actual flow data is within the reference flow data range and that the actual flow data exceeds the reference flow data.
[0023] It can be understood that the actual flow data within the reference flow data range indicates that the current monitoring network does not contain abnormal flow. If the actual flow data exceeds the reference flow data range, it indicates that there is abnormal flow in the current monitoring network.
[0024] The actual flow data is input into a pre-constructed flow prediction model, and a flow prediction result is output by processing via the flow prediction model. The flow prediction model is a pre-trained neural network model.
[0025] In this embodiment, the flow prediction model is constructed using a stream computing engine. The engine takes Apache Flink as an example and is deployed as a distributed cluster architecture in the monitoring network, and real-time state tensors are received as input. The structure of the flow prediction model is a multi-layer neural network, including an input layer, a hidden layer, and an output layer.
[0026] The input layer receives a multi-dimensional state tensor, the hidden layer extracts and transforms data through neuron nodes, and the output layer outputs tracking indicators of the second analysis result set, which are flow prediction data, such as real-time change trend of flow characteristics (bandwidth growth rate per second), fluctuation amplitude of protocol distribution (minute-level change amount of TCP protocol proportion), abnormal increment of access frequency (difference between burst access peak value and historical average value), etc.
[0027] The tracking indicators are used to represent the real-time change trend of the features. For example, in the monitoring network, if the tracking indicators show that the traffic feature value rises from 1.2 Gbps to 1.8 Gbps within 10 seconds, and the TCP protocol proportion suddenly decreases by 15%, it may indicate the emergence of abnormal traffic.
[0028] For example, in the monitoring scene of the core network of an organization, the network has very high requirements for real-time and security, and needs to monitor the abnormal changes of the real-time traffic prediction model. The dynamic feature analysis strategy constructs a state tensor according to the running state of the monitoring system. For example, at a time t, the timestamp collected is June 16, 2025, 10:30:00, the traffic feature value is 1.2 Gbps in the peak period, the TCP protocol proportion is 85% in the protocol type distribution, the HTTP protocol proportion is 10%, the access frequency matrix shows that the core transaction server receives access requests from 200 different IPs in the past 5 minutes, and the number of abnormal connections is 5 (connection attempts that have not been authenticated). These data form a multi-dimensional tensor, where each dimension corresponds to the timestamp, the traffic feature value, the protocol type distribution, the access frequency matrix and the number of abnormal connections. The tensor is the state tensor, which contains the basic data of potential features such as behavior mutation point, threat propagation rate and attack correlation degree.
[0029] An evaluation function for constructing a traffic prediction model is used to measure the matching degree of the model output result and the actual network state. In the above scenario, the evaluation function may consider factors such as traffic change prediction error, protocol distribution identification accuracy, and abnormal connection detection rate. For example, if the model predicts that the traffic in the next minute is 1.3 Gbps, and the actual traffic is 1.35 Gbps, the error is 3.8%, and the evaluation function adjusts the performance score of the model according to the error value.
[0030] The traffic prediction model is updated using the back propagation algorithm, and the specific steps are as follows: when the tracking indicators output by the model deviate from the actual network state, the output error matrix of the traffic prediction model is calculated.
[0031] For example, in a certain period, the model predicts that the number of abnormal connections is 2, while the actual number of abnormal connections is 5, and the error matrix records the deviation value of this dimension as 3. According to the error matrix, the weight coefficient of the state tensor is adjusted, that is, the weight of the number of abnormal connections dimension in the state tensor is increased, so that the model pays more attention to the change of this dimension in subsequent calculations. The parameter set of the traffic prediction model is optimized by gradient descent method, such as adjusting the neuron weight and bias value of the hidden layer of the neural network, so that the tracking indicators output by the model gradually approach the actual network state. The optimization process is executed multiple times per second to ensure that the model can adapt to the dynamic changes of traffic in real time.
[0032] Based on the above example, during the morning peak period of a certain working day, the traffic characteristic value is collected in real time through the state tensor, specifically from 10:15:00 to 10:15:10, it rises rapidly from 1.2 Gbps to 1.6 Gbps, and the traffic change trend index output by the traffic prediction model shows an abnormal increase. The analysis space determines that the increase exceeds the normal fluctuation range, and the evaluation function calculates a large error value, triggering the back propagation algorithm to update the network parameters. After updating, the sensitivity of the model to traffic characteristics is improved, and when the traffic continues to rise to 1.7 Gbps at 10:15:20, the behavior mutation point signal is output in time, providing accurate early warning information.
[0033] During the entire implementation process, the multi-dimensional construction of the state tensor ensures comprehensive representation of network state, the real-time processing capability of the streaming computing engine meets the timeliness requirements of financial transaction networks, the definition of the analysis space provides a clear judgment benchmark for anomaly detection, and the combination of the evaluation function and the back propagation algorithm enables the model to have self-learning and adaptive capabilities. Through the traffic prediction model, subtle changes in traffic can be tracked in real time, potential threat propagation paths and attack-related behaviors can be discovered in time, for example, an alarm is issued when traffic abnormally increases at the initial stage of a distributed denial of service attack (DDoS), valuable response time is gained for network security protection, false positives or false negatives caused by static threshold settings are avoided, and the monitoring accuracy and effectiveness of the network monitoring system in a high-dynamic network environment are improved.
[0034] According to the first monitoring result and the traffic prediction result, the monitoring network is judged to determine that there is abnormal traffic in the monitoring network. At this time, the abnormal traffic needs to be disposed to ensure the normal operation of the business.
[0035] The duration of the abnormal traffic is determined, the target disposal method is determined according to the duration, and the abnormal traffic is disposed according to the target disposal method. The duration of the abnormal traffic represents the time for which the abnormal traffic has existed, i.e., the time corresponding to the threshold value exceeded. The target disposal method includes at least one of the following: traffic cleaning, connection blocking, and log retention.
[0036] The actual traffic data of the monitoring network and the mapping knowledge graph corresponding to the monitoring network are obtained through the above scheme, the reference traffic data range corresponding to the monitoring network is determined according to the mapping knowledge graph. The reference traffic data range is a traffic data range corresponding to normal traffic determined in advance. The actual traffic data is compared with the reference traffic data range to obtain a first monitoring result. The actual traffic data is input into a pre-constructed traffic prediction model, and a traffic prediction result is output through processing of the traffic prediction model. The traffic prediction result obtained by using the pre-trained traffic prediction model is more accurate. The monitoring network is judged according to the first monitoring result and the traffic prediction result, it is determined that there is abnormal traffic in the monitoring network, and the monitoring of abnormal traffic is more accurate by using the first monitoring result and the traffic prediction result to jointly judge whether there is abnormal traffic in the monitoring network. The duration of the abnormal traffic is determined, the target disposal mode is determined according to the duration, and the abnormal traffic is disposed according to the target disposal mode, thereby realizing accurate disposal of abnormal traffic.
[0037] In some embodiments, the step 104 of judging the monitoring network according to the first monitoring result and the traffic prediction result to determine that there is abnormal traffic in the monitoring network, and determining the duration of the abnormal traffic specifically includes: Step 1041, determining traffic change data according to the traffic prediction result and the actual traffic data; Step 1042, comparing the traffic change data with a preset change threshold to obtain a second monitoring result; Step 1043, in response to the first monitoring result that the actual traffic data is out of the reference traffic data range, and / or the second monitoring result that the traffic change data is greater than the preset change threshold, it is determined that there is abnormal traffic in the monitoring network, and the duration of the abnormal traffic is determined.
[0038] In a specific implementation, the flow change data is determined according to the flow prediction result and the actual flow data. Specifically, the flow prediction result and the actual flow data are subtracted to obtain the flow change data. The flow change data is determined based on a time window consistent with the division of the baseline data packet. That is, for a preset fixed time window (for example, a 5-minute window), the cumulative value of the flow prediction result and the cumulative value of the actual flow data in the window are calculated, and the difference between the two cumulative values is taken as the flow change data corresponding to the window. If it is a real-time monitoring scenario, a sliding time window (for example, a 1-minute sliding step) can be used to calculate the difference between the average predicted flow and the average actual flow in the current sliding window as the flow change data, so as to ensure that the calculation dimension of the flow change data matches the time granularity of the range of the baseline flow data, and accurately reflect the flow fluctuation in the same monitoring period.
[0039] A preset change threshold is obtained. Specifically, an analysis space can be constructed, which defines the value range of the tracking index. The flow change data is compared with the preset change threshold to obtain a second monitoring result. The second monitoring result is that the flow change data is less than the preset change threshold, or the flow change data is greater than the preset change threshold. When the flow change data is greater than the preset change threshold, it indicates that there is abnormal flow in the monitored network.
[0040] For example, for a certain monitored network, according to historical normal transaction data, the normal fluctuation range of the flow characteristic value is 0.8-1.5 Gbps, the normal range of the TCP protocol proportion is 80%-90%, the single-day peak value of the access frequency matrix is not more than 500 times / 5 minutes, and the normal threshold of the abnormal connection number is 10 / hour. The analysis space is a set of these normal value ranges. When the tracking index exceeds the range of the space, the system regards it as a potential behavior mutation point or threat signal.
[0041] If it is determined that the first monitoring result is that the actual flow data exceeds the baseline flow data range, and / or the second monitoring result is that the flow change data is greater than the preset change threshold, it indicates that there is abnormal flow in the monitored network, and the duration of the abnormal flow is determined.
[0042] That is, when it is determined that the actual flow data exceeds the baseline flow data range, or it is determined that the flow change data is greater than the preset change threshold, at least one of the two conditions is met, that is, it is determined that there is abnormal flow in the monitored network.
[0043] In some embodiments, the construction process of the mapping knowledge graph corresponding to the monitored network in step 101 specifically includes: In step 1011, historical monitoring data of the monitored network is obtained, and the historical monitoring data is divided to obtain a plurality of initial data packets. Step 1012, determine the feature data in each initial data packet, filter the plurality of initial data packets according to the feature data, and obtain a plurality of first data packets; Step 1013, determine a second data packet from the plurality of first data packets through window clustering, and take the second data packet as a reference data packet; Step 1014, obtain reference feature data corresponding to the reference data packet and a preset initial knowledge graph, input the reference feature data and the monitoring network into the initial knowledge graph, and obtain a mapping knowledge graph.
[0044] In specific implementation, historical monitoring data of the monitoring network is obtained, and the historical monitoring data is divided to obtain a plurality of initial data packets. Specifically, when dividing the historical monitoring data, a fixed time window can be used for division. Each initial data packet is a feature matrix, which covers feature information of dimensions such as traffic baseline, protocol proportion, and access peak, and presents the static features of the initial data packet in a structured manner. For example, the monitoring data is divided using a fixed time window, and each data window contains M initial data packets, where M is a fixed value set according to actual monitoring requirements.
[0045] Determine the feature data in each initial data packet, wherein the feature data includes traffic features, protocol features, and access features. According to the feature data, filter processing is performed on the plurality of initial data packets to obtain a plurality of first data packets.
[0046] In this embodiment, specifically, the feature data in each initial data packet can be determined through a multi-dimensional statistical framework, which includes a traffic feature analysis layer, a protocol type identification layer, and an access frequency statistical layer. The traffic feature analysis layer is used to analyze the traffic size, traffic change trend, and other features of the data packet. The protocol type identification layer identifies the protocol type used by the data packet by analyzing the protocol header information and the like of the data packet. The access frequency statistical layer statistically analyzes the access source, access target, and access frequency of the data packet, and provides analysis basis for subsequent data packet processing from multiple dimensions.
[0047] A second data packet is determined from the plurality of first data packets through window clustering, and the second data packet is taken as a reference data packet. The specific process includes: According to the traffic features, protocol features, and access features of the first data packet, window clustering is used for screening to select a second data packet, and the second data packet is taken as a reference data. In the screening process, the first data packet that is most balanced in terms of traffic features, protocol features, and access features is taken as a reference data packet. The reference data packet can comprehensively reflect the typical features in the data window.
[0048] Specifically, the traffic feature of the reference data packet needs to have the minimum deviation from the traffic baseline extracted by the multi-dimensional statistical method, the fluctuation amplitude is controlled within the preset threshold, and there is no abnormal fluctuation beyond the access peak. The proportion of each type of protocol in the protocol feature needs to have the highest matching degree with the protocol proportion baseline distribution extracted by static feature analysis, and the single protocol proportion deviates from the baseline value by not more than a preset range. The frequency, duration and other indicators of the access feature need to be consistent with the time distribution law of the access peak, there is no sudden high-frequency access or abnormal period access, and the interaction intensity of each node in the access frequency matrix is in a balanced state. The data packet that meets the above conditions has traffic, protocol, and access features that not only conform to the baseline indicators extracted by static analysis, but also remain stable and coordinated in their respective dimensions, and can be used as a reference for reflecting the normal network behavior of the current monitoring scene.
[0049] The baseline feature data corresponding to the reference data packet and the preset initial knowledge graph are obtained, and the baseline feature data and the monitoring network are input into the initial knowledge graph to obtain a mapping knowledge graph. Subsequently, the corresponding reference data packet can be selected from the mapping knowledge graph according to the current monitoring scene, and the baseline feature data corresponding to the reference data packet is used as the baseline traffic data range.
[0050] Among them, the traffic feature in the reference data packet selected from the mapping knowledge graph according to the monitoring scene has the highest degree of fit with the real-time traffic baseline of the current monitoring scene, and there is no obvious deviation from the normal traffic fluctuation range under the current scene. The distribution of each type of protocol in the protocol feature is consistent with the actual use law of the mainstream protocol in the current network environment, and conforms to the typical proportion of the protocol type under the scene; the frequency, path, etc. of the access feature are consistent with the normal access mode of the current monitoring scene, and the interaction state of each node in the access frequency matrix matches the conventional access intensity under the scene. At the same time, the reference data packet in the behavior mode layer of the mapping knowledge graph has the highest matching degree with the typical network behavior mode of the current monitoring scene, can accurately reflect the general characteristics of network behavior under the scene, and can be used as a reference for adapting to the current monitoring demand, providing actual basis data for subsequent feature analysis and security policy application.
[0051] In the embodiment, before obtaining the baseline feature data corresponding to the reference data packet and the preset initial knowledge graph, it can also be judged whether the number of processes reaches the preset maximum number of processes. If it reaches, the current reference data packet is output, and the preset initial knowledge graph is obtained. If it does not reach, the feature consistency division and processing of the remaining initial data packets are continued.
[0052] In some embodiments, the establishment process of the initial knowledge graph includes: First, the network behavior characteristics and security event time series monitoring data are obtained using a distributed probe cluster. To ensure the accuracy and independence of data collection, independent data collection nodes are configured for network behavior characteristics and security events respectively, and each node corresponds to a specific collection target to avoid mutual interference during data collection. Then, all collection nodes are coordinated through a clock synchronization protocol so that collection nodes distributed in different locations can work under a unified time reference, ensuring that the collected time series data have time consistency.
[0053] After obtaining the time series monitoring data, time delay detection is needed. Due to the complexity of the network environment, time offset may occur during data transmission, affecting subsequent analysis and processing. The collected data is corrected for time offset using the sliding window method.
[0054] Specifically, a suitable sliding window size is set, and the timestamps of the data within the window are analyzed and adjusted to synchronize the data between different indicators, laying the foundation for subsequent construction of the initial knowledge graph and integration of multi-dimensional monitoring indicators.
[0055] The correlation between various indicators is analyzed, and high-frequency feature combinations are mined. The clustering method extracts the feature rules of normal behavior, and the periodic pattern of traffic changes is learned with the help of a time series model. The deviation of real-time indicators from normal features is compared to capture sudden change points and define abnormal patterns. The constructed behavior pattern model is stored, and real-time data is matched with predefined patterns. The model parameters are continuously optimized based on actual disposal results, so that the behavior pattern model can accurately reflect normal and abnormal behavior patterns.
[0056] Threat assessment calculation is based on the constructed behavior pattern model and collected security event data to assess and quantify possible threats in the network, determine the level and impact range of threats. Attack path restoration is achieved by analyzing security event related data to trace the source and path of attacks, providing a basis for subsequent security protection and disposal.
[0057] Specifically, in threat assessment calculation, the collected security event data is compared with the normal behavior characteristics in the model based on the constructed behavior pattern model, the deviation of various network indicators is analyzed, different weights are assigned to these deviations and integrated to calculate the threat quantization. According to the quantization result, the threat level is divided, and the impact range of the threat is determined by combining the affected network nodes, service types, etc. In attack path restoration, time series analysis and correlation analysis are performed on security event related data, and the constructed knowledge graph is used to trace the propagation path and source node of the attack from the source of abnormal traffic based on connection information, timestamps, etc. in the data.
[0058] The knowledge graph is modeled in three layers. The behavior pattern layer extracts normal and abnormal behavior features through clustering. The threat assessment layer quantifies threat levels based on behavior patterns and security event data. The attack path layer traces the propagation path of security events through time series analysis. Real-time multi-dimensional monitoring indicators are input into the model to continuously optimize the three-layer structure, ensuring that the knowledge graph reflects the network state in real time.
[0059] After constructing the mapping knowledge graph, real-time multi-dimensional monitoring indicators of the actual monitoring environment are obtained. These multi-dimensional monitoring indicators include traffic characteristic values, protocol type distributions, access frequency matrices, and abnormal connection numbers, which reflect the network's running state and security situation from different dimensions. These real-time multi-dimensional monitoring indicators are input into the constructed mapping knowledge graph, enabling the mapping knowledge graph to update and improve in real time, thus more accurately reflecting the current network behavior characteristics and the mapping relationship of security events.
[0060] Through the above scheme, the deployment of the distributed probe cluster and the use of the clock synchronization protocol ensure the accuracy and time consistency of the time series monitoring data. The application of the time delay detection and sliding window method ensures the synchronization of the data. The analysis of the correlation between indicators and the construction of the mapping knowledge graph provide effective models and methods for network behavior analysis and security event assessment. The input of real-time multi-dimensional monitoring indicators enables the mapping knowledge graph to reflect the network state in real time, providing reliable data support for subsequent behavior feature analysis, security policy generation, and abnormal traffic disposal.
[0061] In some embodiments, the feature data in each initial data packet is determined in step 1012, and the plurality of initial data packets are filtered according to the feature data to obtain a plurality of first data packets, specifically including: Step 10A, determining the feature data in each initial data packet, wherein the feature data includes traffic characteristics, protocol characteristics, and access characteristics; Step 10B, for any two initial data packets, taking the any two initial data packets as target initial data packets, comparing the two target initial data packets according to the feature data, determining the feature consistency type between the two target initial data packets, and filtering the two target initial data packets according to the feature consistency type to obtain first initial data packets corresponding to the two target initial data packets; Step 10C, counting the first initial data packets corresponding to all target initial data packets to obtain a plurality of first data packets.
[0062] In the implementation, feature data in each initial data packet is determined, wherein the feature data includes traffic feature, protocol feature and access feature. The traffic feature includes traffic size of the data packet, traffic change per unit time, etc. The protocol feature includes protocol type adopted by the data packet and distribution of the protocol type in a protocol system. The access feature includes source address and target address of the access, time interval of the access, etc.
[0063] For any two initial data packets, the any two initial data packets are taken as target initial data packets. A preset similarity calculation algorithm is used to calculate consistency degree between the two target initial data packets, to obtain feature consistency type between the two target initial data packets. The feature consistency type includes high consistency, medium consistency and low consistency.
[0064] The two target initial data packets are filtered according to the feature consistency type, to obtain first initial data packets corresponding to the two target initial data packets. The specific process includes: In response to the feature consistency type being high consistency, both of the two target initial data packets are taken as first initial data packets. That is, if the feature consistency type is high consistency, the feature consistency is high, which can better reflect normal network behavior mode, and the data packet with high consistency is directly reserved.
[0065] Or, In response to the feature consistency type being medium consistency, interpolation conversion processing is performed on the two target initial data packets, to obtain first initial data packets. Specifically, a feature data curve corresponding to each target initial data packet is obtained, wherein the feature data curve includes traffic feature curve, protocol feature curve and access feature curve. Interpolation processing is performed on the feature data curve, to obtain a transition data packet sequence, a transition feature matrix corresponding to the transition data packet sequence is determined, the transition feature matrix is mapped to a low-dimensional space, to obtain a low-dimensional feature matrix. Principal component analysis is performed on the low-dimensional feature matrix, to obtain a target feature matrix, and then the target feature matrix is taken as a first initial data packet.
[0066] That is, interpolation and conversion operations are performed on the medium consistent data packet, the interpolation operation generates a new data packet using a feature fusion method, specifically, the feature curves of two adjacent target initial data packets are connected by piecewise linear interpolation to make the feature change of the adjacent target initial data packets more smooth, and a smooth transition data packet sequence is generated. The conversion operation updates the target initial data packet using an index reorganization method, maps the feature matrix of the transition data packet to a feature subspace, extracts core components through principal component analysis, removes redundant information, generates a simplified feature matrix, and then obtains a first initial data packet. The first initial data packet is composed of the simplified feature matrix.
[0067] Or, In response to the feature consistency type being low consistency, the two target initial data packets are deleted. That is, a high probability filtering operation is performed on the target initial data packet with low consistency. Since the features of the target initial data packet with low consistency are significantly different from those of other data packets, it may belong to abnormal data or noise data. After filtering, the influence of abnormal data on subsequent analysis can be reduced.
[0068] Through the above scheme, different feature consistency types of data packets are subjected to differential processing, effectively removing the interference of abnormal data and noise data, and retaining valuable feature information.
[0069] In some embodiments, the target treatment mode is determined according to the duration in step 105, specifically including: Step 1051, in response to the duration being less than a first preset time threshold, determining that the target treatment mode is traffic cleaning; or, Step 1052, in response to the duration being greater than a second preset time threshold, determining that the target treatment mode is connection blocking, wherein the second preset time threshold is greater than the first preset time threshold; or, Step 1053, in response to the duration being less than a third preset time threshold and the traffic change value exceeding a preset change threshold, determining that the target treatment mode is log retention.
[0070] In specific implementation, in response to the duration being less than the first preset time threshold, which indicates that the traffic first exceeds the threshold, the target treatment mode is determined to be traffic cleaning.
[0071] In response to the duration being greater than the second preset time threshold, wherein the second preset time threshold is greater than the first preset time threshold, which indicates that the abnormal traffic persists for a long time, the target treatment mode is determined to be connection blocking.
[0072] In response to the duration being less than the third preset time threshold and the traffic change value exceeding the preset change threshold, the target treatment mode is determined to be log retention. In specific implementation, in response to the duration being less than the first preset time threshold, which indicates that the traffic first exceeds the threshold, the target treatment mode is determined to be traffic cleaning.
[0071] In response to the duration being greater than the second preset time threshold, wherein the second preset time threshold is greater than the first preset time threshold, which indicates that the abnormal traffic persists for a long time, the target treatment mode is determined to be connection blocking.
[0072] In response to the duration being less than the third preset time threshold and the traffic change value exceeding the preset change threshold, the target treatment mode is determined to be log retention.
[0073] The following is described with a specific example, taking the monitoring scenario of a university campus network as an example. The network carries multiple types of business traffic such as teaching, scientific research, and student life on a daily basis. The mapping knowledge graph has been constructed through historical data, including the traffic characteristic baseline of normal teaching period (such as 8:00-12:00 on weekdays), the normal distribution proportion of various protocols (such as HTTP, TCP, and UDP), and the threshold range of access frequency matrix and abnormal connection number.
[0074] Multi-dimensional monitoring indicators collect real-time traffic characteristic values (such as current bandwidth occupancy, burst traffic peak value) of the campus network, protocol type distribution (such as whether the proportion of HTTP protocol suddenly increases at a certain time), access frequency matrix (such as whether the access frequency of a certain IP outside the campus to the server inside the campus is abnormal), and abnormal connection number (such as the number of connection requests of unauthenticated devices).
[0075] When the monitoring system obtains the above indicators in real time, it compares them with the baseline values in the mapping knowledge graph. For example, at 10:00 on a certain weekday, the system collects the current campus network export traffic characteristic value as 800 Mbps, while the traffic baseline threshold value of the mapping knowledge graph at this time period is 600 Mbps, which exceeds the preset alarm threshold value (here, taking 30% of the baseline value as an example, i.e. 780 Mbps), at this time the system determines that abnormal traffic is detected, and triggers the preset disposal scheme.
[0076] If it is the first time to detect that the traffic exceeds the threshold value, the system automatically starts the traffic cleaning strategy: by adjusting the filtering rules of the firewall, the bandwidth of the core business such as teaching platform and scientific research database is preferentially guaranteed (such as allocating 400 Mbps bandwidth for core business), and the non-critical business (such as video streaming media, file download) is set to speed limit threshold (such as limiting the bandwidth to within 200 Mbps), at the same time, the malicious data packets (such as DDoS attack data packets) in the abnormal traffic are identified and filtered through the traffic cleaning equipment.
[0077] If the abnormal traffic persists (such as the traffic always maintains above 800 Mbps within 30 minutes), the system will trigger the connection blocking strategy. At this time, the monitoring system will analyze the source of the abnormal traffic, if it is found that a certain type of abnormal connection (such as a large number of invalid connection requests from a certain IP address outside the campus) is the main cause of traffic overrun, then the suspicious connection is isolated, and its communication with the campus network is temporarily blocked to avoid abnormal traffic continuously occupying bandwidth resources. In this process, the system records the IP address, connection time, traffic characteristics, and other information of the blocked connection for subsequent tracing.
[0078] When a serious anomaly occurs (such as a sudden surge in traffic to 1.5 Gbps, accompanied by a large number of unknown protocol packets), the system triggers a log retention policy. At this time, the monitoring system saves the complete traffic log, including the source IP, target IP, protocol type, transmission time, data content fragment, and other information of each packet. These logs can be used for subsequent security event analysis, such as determining whether a network attack has occurred, and the specific path and means of the attack, by analyzing the logs.
[0079] In addition, the system also sets a statistical period (such as a 24-hour statistical cycle) to record the number of times the same alarm is triggered within that period. For example, in a certain week, the campus network triggered the "HTTP protocol proportion abnormally high" alarm every day from 16:00 to 17:00, and each time the alarm was triggered, the system could restore the protocol proportion to the normal range within 10 minutes through the traffic cleaning strategy, and the monitoring system still ran normally. At this time, the system adjusts the disposal threshold of the alarm: according to the actual distribution of HTTP protocol in the historical data of this period, the alarm threshold is raised from the original proportion of 70% to 75%, to avoid false alarms caused by normal business traffic fluctuations.
[0080] In the implementation process, the accuracy of the mapping knowledge graph directly affects the effectiveness of anomaly detection. For example, if a certain type of business system (such as an online exam platform) is added to the campus network, causing the HTTP protocol traffic proportion to naturally increase at a certain time, the protocol distribution baseline in the mapping knowledge graph needs to be updated in a timely manner to avoid the system misjudging normal traffic as abnormal. In addition, the priority and trigger conditions of the disposal scheme need to be flexibly configured according to the actual network environment. For example, during the exam period, the campus network needs to prioritize the bandwidth of the exam system, so the bandwidth allocation ratio of the traffic cleaning strategy for the exam system needs to be higher than that during daily teaching periods, and the trigger threshold of the connection blocking strategy will be correspondingly increased to reduce the impact on normal exam business.
[0081] Based on the same inventive concept, as shown in Figure 2 Another embodiment of the present disclosure provides a traffic monitoring system, which comprises a network behavior collection module, a behavior feature analysis module, a security policy generation module, and an abnormal traffic disposal module.
[0082] The static feature analysis strategy in this embodiment corresponds to the process of determining whether there is abnormal traffic by comparing the actual traffic data with the baseline traffic data range in the foregoing embodiment. The dynamic feature analysis strategy corresponds to the process of determining whether there is abnormal traffic by using a traffic prediction model in the foregoing embodiment.
[0083] The network behavior collection module collects network behavior characteristics and security event mapping knowledge graph through multi-source heterogeneous data collection and integrates multi-dimensional monitoring indicators. The multi-dimensional monitoring indicators include traffic characteristic values, protocol type distribution, access frequency matrix and abnormal connection number, and the mapping knowledge graph covers behavior pattern layer, threat assessment layer and attack path layer. The distributed probe cluster is used to obtain time series monitoring data of network behavior characteristics and security events, and data normalization processing is performed. The mapping knowledge graph is modeled, threat assessment is calculated and attack path is restored by analyzing the correlation between indicators. Real-time multi-dimensional monitoring indicators of the actual monitoring environment are obtained and input into the mapping knowledge graph.
[0084] In this embodiment, the deployment of the distributed probe cluster and the use of the clock synchronization protocol ensure the accuracy and time consistency of the time series monitoring data. The application of the delay detection and sliding window method ensures the synchronization of the data. The analysis of the correlation between indicators and the construction of the mapping knowledge graph provide effective models and methods for network behavior analysis and security event assessment. The input of real-time multi-dimensional monitoring indicators enables the mapping knowledge graph to reflect the network state in real time, providing reliable data support for subsequent behavior characteristic analysis, security policy generation and abnormal traffic disposal.
[0085] The behavior characteristic analysis module executes static characteristic analysis strategy and dynamic characteristic analysis strategy respectively. The static characteristic analysis strategy uses multi-dimensional statistical method to extract a first analysis result set, which includes traffic baseline, protocol proportion and access peak. The dynamic characteristic analysis strategy extracts a second analysis result set by constructing a traffic prediction model, including behavior mutation point, threat propagation rate and attack correlation degree.
[0086] In this embodiment, during the implementation of the entire static characteristic analysis strategy, the division of the fixed time window ensures the periodicity and regularity of data processing. The multi-dimensional statistical framework analyzes the data packets from multiple aspects to ensure the comprehensiveness of feature extraction. The hierarchical analysis method improves the accuracy and efficiency of data packet processing by gradually processing and screening. The differential processing of different types of data packets effectively removes the interference of abnormal data and noise data, and retains valuable feature information. The selection of reference data packets provides a typical reference for subsequent feature analysis, enabling the static characteristic analysis strategy to more accurately extract the first analysis result set, laying an important foundation for the overall function implementation of the behavior characteristic analysis module. Through the above detailed implementation, the static characteristic analysis strategy can effectively process and analyze the monitoring data, extract key information reflecting the static characteristics of network behavior, and provide strong support for subsequent security policy generation and abnormal traffic disposal.
[0087] The multi-dimensional construction of the state tensor ensures comprehensive representation of the network state, the real-time processing capability of the streaming computing engine meets the timeliness requirements of the financial transaction network, the definition of the analysis space provides a clear judgment benchmark for anomaly detection, and the combination of the evaluation function and the back propagation algorithm enables the model to have self-learning and adaptive capabilities. Through this dynamic feature analysis strategy, financial institutions can track subtle changes in transaction traffic in real time, timely detect potential threat propagation paths and attack-related behaviors, such as issuing an alert when there is an initial abnormal increase in traffic in a distributed denial of service attack (DDoS), to gain valuable response time for network security protection, while avoiding false positives or false negatives caused by static threshold settings, thereby improving the monitoring accuracy and effectiveness of the network monitoring system in a high-dynamic network environment.
[0088] The security policy generation module extracts common patterns from static feature analysis strategies and dynamic feature analysis strategies trained in different monitoring periods and different network environments, constructs a strategy knowledge base, and generates a feature analysis strategy that adapts to the new monitoring scenario based on the strategy knowledge base.
[0089] In some embodiments, in the security policy generation module, the implementation of generating a feature analysis strategy that adapts to the new monitoring scenario needs to complete operations such as strategy vector conversion, common pattern extraction, strategy knowledge base construction, and new scenario strategy generation. The following will be explained in conjunction with specific examples: The static feature analysis strategy and the dynamic feature analysis strategy are converted into a static strategy vector and a dynamic strategy vector, respectively. For example, in a certain enterprise local area network monitoring scenario, the static feature analysis strategy includes specific policy parameters such as "fixed time window size of 10 minutes" and "traffic baseline threshold set to 500 Mbps". These parameters are encoded into a set of numerical vectors according to a preset rule to form a static strategy vector; the dynamic feature analysis strategy includes parameters such as "streaming computing engine tracking network learning rate set to 0.01" and "state tensor update frequency of every 2 seconds", which are also encoded into a dynamic strategy vector. Subsequently, the two vectors are spliced in order to obtain a security policy vector that contains static and dynamic policy information. The vector represents the core parameters of the entire feature analysis strategy in the form of structured data.
[0090] For different monitoring periods and different network environment security policy vectors, the common patterns need to be extracted. Taking the Internet exit monitoring scene of a certain city as an example, this scene collects multiple sets of security policy vectors in the morning of weekdays (8:00-10:00, peak office traffic period), the afternoon of weekdays (14:00-16:00, another business traffic period) and all day on weekends (leisure traffic period). For each vector, the frequency of each policy parameter is calculated in turn. For example, in the strategy dimension of "analysis depth of protocol type identification layer", among the 100 strategy vectors in the morning of weekdays, 85 sets set the analysis depth to "three-layer protocol analysis", and the remaining 15 sets set it to "five-layer protocol analysis". When the second preset threshold is 70%, the frequency of "three-layer protocol analysis" (85%) exceeds the threshold, and it is determined that this strategy is more suitable for the morning of weekdays, and is considered as a common pattern.
[0091] The extracted common patterns are combined to form a strategy knowledge base. Still taking the city Internet exit monitoring as an example, the strategy knowledge base may contain common pattern combinations such as "in the morning of weekdays, the sliding window size of the traffic feature analysis layer is 5 minutes" and "in the weekend period, the threat propagation rate accounts for 40% in the evaluation function weight coefficient of the dynamic tracking model". The knowledge base is essentially a strategy template library based on historical monitoring data, providing a general feature analysis framework for new monitoring scenarios.
[0092] When facing a new monitoring scenario, an adaptive feature analysis strategy needs to be generated based on the strategy knowledge base. For example, a newly built industrial park needs to deploy a network monitoring system, and its basic indicators of the new monitoring scenario include: expected peak traffic 1.2 Gbps, main protocol types HTTP and TCP, and monitoring target is to identify abnormal file transmission behavior. Input these basic indicators into the strategy knowledge base, and the system matches the closest historical monitoring period and network environment through a similarity algorithm. Suppose the similarity to the monitoring data of a certain industrial park in the early stage of production is 92%, and the common patterns of this historical scenario include "traffic cleaning strategy speed limit threshold 1.5 Gbps" and "attack path restoration model sampling rate 20%".
[0093] The strategy is further adjusted in combination with special parameters of the new scene. The special parameters of the new scene include: the network topology structure is a "core switch + aggregation layer + access layer three-layer architecture", the security protection level is "third-level network security protection", and the monitoring target requirement is "the accuracy of abnormal file transmission identification is greater than or equal to 95%". Based on these parameters, the historical common mode is adjusted: because there are more access layer devices in the three-layer topology structure, the number of collection nodes of the distributed probe cluster is increased from 10 in the historical scene to 15 to cover more access points; because the third-level network security protection requires a higher log retention standard, the storage period of the log retention strategy is extended from 7 days in the history to 30 days; in view of the requirement of abnormal file transmission identification, a "file characteristic code matching module" is added in the dynamic feature analysis strategy, and the evaluation weight of threat propagation rate is increased from 40% in the history to 50% to strengthen the tracking ability of abnormal transmission behavior.
[0094] During the entire implementation process, the conversion of the strategy vector realizes the digital representation of the strategy, which is convenient for computer system processing and analysis; the extraction of the common mode avoids repeated development of the strategy by statistically analyzing a large amount of historical data and mining the general strategy law in different scenes; the construction of the strategy knowledge base forms a reusable strategy resource pool, which provides an efficient reference template for the generation of a new scene strategy; in combination with the adaptation process of the basic indicators and special parameters of the new scene, it is ensured that the generated feature analysis strategy can draw on historical experience and meet the individual needs of the current scene. For example, in the above industrial park case, the strategy generated through the process can make the network monitoring system have relatively accurate feature analysis ability at the initial deployment stage, without the need to start from zero to debug various strategy parameters, greatly shortening the system online period, while ensuring the matching degree of the strategy and the scene demand. This implementation mode realizes the rapid adaptation and efficient operation of the network monitoring system in different monitoring scenes through a data-driven strategy generation mechanism, and provides flexible and reliable strategy support for network security monitoring.
[0095] The abnormal flow processing module compares the multi-dimensional monitoring indicators in real time according to the mapping knowledge graph, and triggers a preset processing scheme when an abnormal indicator is detected.
[0096] In this embodiment, the abnormal flow processing module can realize real-time response to network anomalies based on the mapping knowledge graph, and perform hierarchical processing on abnormal conditions in combination with different levels of processing strategies (flow cleaning, connection blocking, log retention), while dynamically adjusting the processing threshold through statistical analysis to improve the adaptability and accuracy of the system. In the university campus network scene, this module can effectively cope with traffic fluctuations during the teaching peak period, sudden network attacks and various abnormal connection behaviors, while ensuring the normal operation of the business, providing data support for the tracing and analysis of network security events, and realizing the whole life cycle management and security protection of network flow.
[0097] Through the above scheme, the mapping knowledge graph of network behavior characteristics and security events is constructed through multi-source heterogeneous data collection, and multi-dimensional monitoring indicators are integrated, which can comprehensively and accurately reflect the relationship between network behavior and security events, and improve the monitoring and analysis accuracy of network security events.
[0098] The network behavior collection module acquires time series monitoring data through a distributed probe cluster and performs normalization processing, ensuring the accuracy and consistency of the data, and providing a reliable data foundation for subsequent analysis. By modeling behavior patterns, threat assessment calculations, and attack path restoration on the mapping knowledge graph, security risks behind network behavior can be deeply mined, providing strong support for the development of security policies.
[0099] The behavior characteristic analysis module executes static feature analysis strategy and dynamic feature analysis strategy respectively. The static feature analysis strategy uses multi-dimensional statistical method and hierarchical analysis method, which can extract comprehensive and accurate first analysis result set, including traffic baseline, protocol proportion and access peak value, etc. The dynamic feature analysis strategy can capture key information such as behavior mutation point, threat propagation rate and attack correlation degree by building a real-time tracking model, realizing comprehensive and real-time analysis of network behavior characteristics, and improving the discovery and early warning ability of network abnormal behavior.
[0100] The security policy generation module extracts common patterns from different monitoring periods and network environments, builds a strategy knowledge base, and generates feature analysis strategies that adapt to new monitoring scenarios based on the strategy knowledge base, improving the generality and adaptability of security policies. The system can quickly respond to new monitoring needs, reducing the cost of policy design and adjustment, and improving the work efficiency of the system.
[0101] The abnormal traffic disposal module compares multi-dimensional monitoring indicators in real time based on the mapping knowledge graph, which can detect abnormal indicators and trigger preset disposal schemes, including traffic cleaning strategy, connection blocking strategy and log retention strategy, etc. It realizes the accurate disposal of abnormal traffic. At the same time, by recording the number of triggers of the same alarm within the statistical period, and adjusting the disposal threshold according to the system running state, the adaptability and reliability of the system are improved, ensuring the stable operation of the system.
[0102] In addition, in the dynamic feature analysis strategy, a streaming computing engine is used to build a tracking network, and a backpropagation algorithm is used to update the tracking network, which can track the trend of changes in network behavior characteristics in real time, further improving the analysis ability and early warning accuracy of network dynamic behavior.
[0103] It should be noted that the method of the embodiments of the present disclosure can be executed by a single device, such as a computer or a server, etc. The method of the embodiments can also be applied to a distributed scenario, and be completed by multiple devices cooperating with each other. In the case of such a distributed scenario, one of the multiple devices can only execute one or more steps in the method of the embodiments of the present disclosure, and the multiple devices can interact with each other to complete the method.
[0104] It should be noted that some embodiments of the present disclosure have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order and still achieve desirable results. Additionally, the processes depicted in the figures do not necessarily require the particular order shown, or sequential order, to achieve the desired results. In certain implementations, multitasking and parallel processing can be advantageous.
[0105] Based on the same inventive concept, the present disclosure also provides a flow monitoring device corresponding to the method of any of the above embodiments.
[0106] Referring to Figure 3 , Figure 3 The flow monitoring device of the embodiments comprises: An acquisition module 301 configured to acquire actual flow data of a monitored network and a mapping knowledge graph corresponding to the monitored network, and determine a reference flow data range corresponding to the monitored network according to the mapping knowledge graph; A comparison module 302 configured to compare the actual flow data with the reference flow data range to obtain a first monitoring result; An input module 303 configured to input the actual flow data into a pre-constructed flow prediction model, and output a flow prediction result via processing by the flow prediction model; A judgment module 304 configured to judge the monitored network according to the first monitoring result and the flow prediction result, determine that there is abnormal flow in the monitored network, and determine a duration of the abnormal flow; A disposal module 305 configured to determine a target disposal method according to the duration, and dispose of the abnormal flow according to the target disposal method.
[0107] In some embodiments, the judgment module 304 is specifically configured to: determine flow change data according to the flow prediction result and the actual flow data; compare the flow change data with a preset change threshold to obtain a second monitoring result; In response to the first monitoring result being that the actual flow data exceeds the range of the reference flow data, and / or the second monitoring result being that the flow change data is greater than the preset change threshold, it is determined that there is abnormal flow in the monitored network, and a duration of the abnormal flow is determined.
[0108] In some embodiments, the apparatus further comprises a graph construction module, which is specifically configured to: Obtain historical monitoring data of a monitored network, divide the historical monitoring data to obtain a plurality of initial data packets; Determine feature data in each initial data packet, and filter the plurality of initial data packets according to the feature data to obtain a plurality of first data packets; Determine a second data packet from the plurality of first data packets through window clustering, and take the second data packet as a reference data packet; Obtain reference feature data corresponding to the reference data packet and a preset initial knowledge graph, input the reference feature data and the monitored network into the initial knowledge graph to obtain a mapping knowledge graph.
[0109] In some embodiments, the graph construction module is specifically configured to: Determine feature data in each initial data packet, wherein the feature data includes flow features, protocol features, and access features; For any two initial data packets, take the any two initial data packets as target initial data packets, compare the two target initial data packets according to the feature data, determine a feature consistency type between the two target initial data packets, filter the two target initial data packets according to the feature consistency type to obtain first initial data packets corresponding to the two target initial data packets; Statistically obtain first initial data packets corresponding to all target initial data packets to obtain a plurality of first data packets.
[0110] In some embodiments, the graph construction module is specifically configured to: In response to the feature consistency type being high consistency, both of the two target initial data packets are taken as first initial data packets; or, In response to the feature consistency type being medium consistency, the two target initial data packets are subjected to interpolation conversion processing to obtain first initial data packets; or, In response to the feature consistency type being low consistency, the two target initial data packets are subjected to deletion processing.
[0111] In some embodiments, the graph construction module is specifically configured to: In response to the feature consistency type being medium consistency, feature data curves corresponding to each target initial data packet are obtained, the feature data curves are subjected to interpolation processing, and a transition data packet sequence is obtained; A transition feature matrix corresponding to the transition data packet sequence is determined, the transition feature matrix is mapped to a low-dimensional space, and a low-dimensional feature matrix is obtained. The low-dimensional feature matrix is subjected to filtering processing through principal component analysis, and a target feature matrix is obtained, which is taken as a first initial data packet.
[0112] In some embodiments, the processing module 305 is specifically configured to: In response to the duration being less than a first preset time threshold, determining that the target processing mode is flow cleaning; or, In response to the duration being greater than a second preset time threshold, determining that the target processing mode is connection blocking, wherein the second preset time threshold is greater than the first preset time threshold; or, In response to the duration being less than a third preset time threshold and the flow change value exceeding a preset change threshold, determining that the target processing mode is log retention.
[0113] For the sake of convenience, the above-described apparatus is described in various modules with respective functions. Of course, in the implementation of the present disclosure, the functions of the modules can be implemented in one or more software and / or hardware.
[0114] The apparatus of the above-described embodiments is used to implement the corresponding flow monitoring method in any of the preceding embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be described here.
[0115] Based on the same inventive concept, the present disclosure also provides an electronic device corresponding to any of the above-described method embodiments, which comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the flow monitoring method of any of the above-described embodiments when executing the program.
[0116] Figure 4 A more specific hardware structure of an electronic device is shown, which can include a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are connected to each other through the bus 1050 for communication within the device.
[0117] The processor 1010 can be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an ASIC (Application Specific Integrated Circuit), or one or more integrated circuits, etc., for executing relevant programs to implement the technical solutions provided by the embodiments of the present specification.
[0118] The memory 1020 can be implemented in the form of a ROM (Read Only Memory), a RAM (Random Access Memory), a static storage device, a dynamic storage device, etc. The memory 1020 can store an operating system and other application programs, and when the technical solutions provided by the embodiments of the present specification are implemented by software or firmware, the relevant program codes are saved in the memory 1020 and called and executed by the processor 1010.
[0119] The input / output interface 1030 is configured to connect input / output modules to realize information input and output. The input / output modules can be configured as components in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. The input devices can include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output devices can include a display, a speaker, a vibrator, an indicator light, etc.
[0120] The communication interface 1040 is configured to connect a communication module (not shown in the figure) to realize the communication interaction between the device and other devices. The communication module can realize communication through a wired manner (such as USB, network cable, etc.) or through a wireless manner (such as mobile network, WIFI, Bluetooth, etc.).
[0121] The bus 1050 includes a channel for transmitting information between various components (such as the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040) of the device.
[0122] It should be noted that although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040, and the bus 1050, in the specific implementation process, the device can also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above device can also only contain the components necessary to implement the solutions of the embodiments of the present specification, and does not have to contain all the components shown in the figure.
[0123] The electronic device of the above embodiments is used to implement the corresponding flow monitoring method in any of the preceding embodiments, and has the beneficial effects of the corresponding method embodiments, which are not described here again.
[0124] Based on the same inventive concept, the disclosure also provides a non-transitory computer readable storage medium storing computer instructions for causing the computer to perform the traffic monitoring method according to any of the above embodiments.
[0125] The computer readable medium of the embodiments can include permanent and non-permanent, removable and non-removable media, which can realize information storage by any method or technology. The information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.
[0126] The computer instructions stored in the storage medium of the above embodiments are used to cause the computer to perform the traffic monitoring method according to any of the above embodiments, and have the beneficial effects of the corresponding method embodiments, which are not repeated here.
[0127] It can be understood that before using the technical solutions of the various embodiments of the disclosure, the type of personal information involved, the scope of use, the scenario of use, etc. will be informed to the user in an appropriate manner, and the authorization of the user will be obtained.
[0128] For example, in response to receiving the active request of the user, the user is sent prompt information to explicitly prompt the user that the operation requested to be performed will require obtaining and using the personal information of the user. Thus, the user can voluntarily choose whether to provide personal information to the software or hardware such as electronic devices, application programs, servers or storage media that perform the technical solutions of the disclosure according to the prompt information.
[0129] As an optional but not limited implementation manner, in response to accepting the active request of the user, the manner of sending prompt information to the user may, for example, be a pop-up window manner, and the prompt information can be presented in the form of text in the pop-up window. In addition, the pop-up window can also carry selection controls for the user to select "agree" or "disagree" to provide personal information to the electronic device.
[0130] It can be understood that the above notification and obtaining user authorization process is only illustrative, and does not limit the implementation of the present disclosure, and other ways meeting relevant laws and regulations can also be applied to the implementation of the present disclosure.
[0131] It should be understood by those of ordinary skill in the art that the above discussion of any embodiment is merely exemplary and is not intended to suggest the scope of the present disclosure (including claims) is limited to these examples; under the idea of the present disclosure, the above embodiments or technical features among different embodiments can also be combined, steps can be implemented in any order, and there are many other changes of different aspects of the embodiments of the present disclosure as described above, which are not provided in details for the sake of brevity.
[0132] In addition, in order to simplify the description and discussion, and so as not to make the embodiments of the present disclosure difficult to understand, the well-known power / ground connections of integrated circuit (IC) chips and other components can or can not be shown in the provided drawings. In addition, the apparatus can be shown in the form of a block diagram in order to avoid making the embodiments of the present disclosure difficult to understand, and this also takes into account the fact that the details of the implementation of these block diagram apparatus are highly dependent on the platform to be implemented to implement the embodiments of the present disclosure (i.e. these details should be fully within the understanding of those skilled in the art). Where specific details (e.g. circuits) are set forth in order to describe an exemplary embodiment of the present disclosure, it will be apparent to those skilled in the art that the present disclosure can be practiced without these specific details or with variations on these specific details. Therefore, these descriptions should be considered illustrative rather than limiting.
[0133] Although the present disclosure has been described in conjunction with specific embodiments thereof, many alternatives, modifications and variations will be apparent to those skilled in the art in light of the foregoing description. For example, other memory architectures (e.g. dynamic RAM (DRAM)) can use the embodiments discussed.
[0134] The embodiments of the present disclosure are intended to cover all such alternatives, modifications and variations as falling within the broad scope of the appended claims. Accordingly, any omission, modification, equivalent replacement, improvement, etc. made within the spirit and principle of the embodiments of the present disclosure should be included in the protection scope of the present disclosure.
Claims
1. A flow monitoring method, characterized in that, include: Obtain the actual traffic data of the monitoring network and the corresponding mapping knowledge graph of the monitoring network, and determine the baseline traffic data range of the monitoring network based on the mapping knowledge graph. The actual flow data is compared with the baseline flow data range to obtain a first monitoring result; The actual traffic data is input into a pre-built traffic prediction model, processed by the traffic prediction model, and the traffic prediction result is output. Based on the first monitoring result and the traffic prediction result, the monitoring network is judged to determine that there is abnormal traffic in the monitoring network and the duration of the abnormal traffic is determined. The target handling method is determined based on the duration, and the abnormal traffic is handled according to the target handling method.
2. The method according to claim 1, characterized in that, The step of judging the monitoring network based on the first monitoring result and the traffic prediction result, determining that there is abnormal traffic in the monitoring network, and determining the duration of the abnormal traffic includes: Based on the traffic prediction results and the actual traffic data, determine the traffic change data; The traffic flow change data is compared with a preset change threshold to obtain a second monitoring result; In response to the first monitoring result indicating that the actual traffic data exceeds the range of the baseline traffic data, and / or the second monitoring result indicating that the traffic change data is greater than the preset change threshold, it is determined that there is abnormal traffic in the monitoring network, and the duration of the abnormal traffic is determined.
3. The method according to claim 1, characterized in that, The process of constructing the mapping knowledge graph corresponding to the monitoring network includes: Historical monitoring data from the monitoring network is acquired, and the historical monitoring data is divided to obtain multiple initial data packets; The characteristic data in each initial data packet is determined, and the multiple initial data packets are filtered based on the characteristic data to obtain multiple first data packets; A second data packet is determined from the plurality of first data packets by window clustering, and the second data packet is used as a reference data packet; Obtain the baseline feature data and the preset initial knowledge graph corresponding to the baseline data packet, and input the baseline feature data and the monitoring network into the initial knowledge graph to obtain the mapping knowledge graph.
4. The method according to claim 3, characterized in that, The process of determining feature data in each initial data packet, filtering multiple initial data packets based on the feature data, and obtaining multiple first data packets includes: Determine the characteristic data in each initial data packet, wherein the characteristic data includes traffic characteristics, protocol characteristics, and access characteristics; For any two initial data packets, take these two initial data packets as target initial data packets, compare the two target initial data packets according to the feature data, determine the feature consistency type between the two target initial data packets, and filter the two target initial data packets according to the feature consistency type to obtain the first initial data packet corresponding to the two target initial data packets; The first initial data packet corresponding to all target initial data packets is counted to obtain multiple first data packets.
5. The method according to claim 4, characterized in that, The step of filtering the two target initial data packets according to the characteristic consistency type to obtain the first initial data packet corresponding to the two target initial data packets includes: In response to the characteristic consistency type being high consistency, both target initial data packets are used as the first initial data packet; or, In response to the characteristic consistency type being medium consistency, interpolation transformation is performed on the two target initial data packets to obtain the first initial data packet; or... In response to the characteristic consistency type being low consistency, the initial data packets of the two targets are deleted.
6. The method according to claim 5, characterized in that, In response to the characteristic consistency type being medium consistency, the two target initial data packets are subjected to interpolation transformation to obtain a first initial data packet, including: In response to the feature consistency type being medium consistency, the feature data curve corresponding to each target initial data packet is obtained, and the feature data curve is interpolated to obtain the transition data packet sequence; Determine the transition feature matrix corresponding to the transition data packet sequence, and map the transition feature matrix to a low-dimensional space to obtain a low-dimensional feature matrix; The low-dimensional feature matrix is filtered by principal component analysis to obtain the target feature matrix, which is then used as the first initial data packet.
7. The method according to claim 1, characterized in that, The step of determining the target handling method based on the duration includes: In response to the duration being less than a first preset time threshold, the target treatment method is determined to be flow cleaning; or, In response to the duration exceeding a second preset time threshold, the target handling method is determined to be connection blocking, wherein the second preset time threshold is greater than the first preset time threshold; or, In response to the duration being less than a third preset time threshold and the traffic change value exceeding a preset change threshold, the target handling method is determined to be log retention.
8. A flow monitoring device, characterized in that, include: The acquisition module is configured to acquire the actual traffic data of the monitoring network and the mapping knowledge graph corresponding to the monitoring network, and determine the baseline traffic data range corresponding to the monitoring network based on the mapping knowledge graph. The comparison module is configured to compare the actual flow data with the reference flow data range to obtain a first monitoring result; The input module is configured to input the actual traffic data into a pre-built traffic prediction model, process the traffic prediction model, and output the traffic prediction result. The judgment module is configured to judge the monitoring network based on the first monitoring result and the traffic prediction result, determine that there is abnormal traffic in the monitoring network, and determine the duration of the abnormal traffic; The handling module is configured to determine a target handling method based on the duration, and handle the abnormal traffic according to the target handling method.
9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, implements the method as claimed in any one of claims 1 to 7.
10. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores computer instructions for causing a computer to perform the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Method and apparatus for alarming
CN108985446A
Abnormity detection method, device and equipment and computer readable storage medium
CN111860897A
Data detection method and device, electronic equipment and storage medium
CN114357190A
Abnormal traffic identification method and device, electronic equipment and storage medium
CN115118511A
Host abnormal flow detection method, system and equipment based on access baseline
CN115361231A