Network security management and control system, method and device, storage medium and program product
By combining multi-dimensional fingerprint feature vectors and security management models, accurate identification of video network assets and real-time monitoring of abnormal behavior are achieved, solving the problems of unauthorized device access and network attacks in video networks and improving the proactive security defense capabilities of video networks.
Patent Information
- Application Number
- CN202511461360.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-13
- Publication Date
- 2025-12-09
AI Technical Summary
Existing technologies cannot effectively identify video asset types and manufacturers, and unauthorized device access leads to network resource consumption and information leakage. Network attacks are difficult to detect and block in real time, and video network security threat solutions lack self-learning and dynamic adaptation capabilities.
By sending probe message sequences to target devices through the asset identification unit, extracting multi-dimensional fingerprint feature vectors, and combining them with the security management model of the behavior analysis unit, the system can monitor and generate control policies in real time, including alarms and rate limiting, thereby achieving accurate identification of network assets and real-time perception of abnormal behavior.
It enhances the proactive security defense capabilities of video networks, enabling accurate identification of network assets and real-time detection of abnormal behavior, dynamic adjustment of security policies, and prevention of unauthorized device access and network attacks.
Smart Images

Figure CN121098613A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to, but is not limited to, the field of network security technology, and in particular to a network security management system, method, apparatus, storage medium, and program product. Background Technology
[0002] With the rapid development of smart cities and intelligent transportation, the scale of video surveillance networks has expanded dramatically, with massive numbers of network video recorders (NVRs) and network cameras (IP cameras, IPCs) connecting to the network. Currently, video networks face severe security challenges: traditional IT (Information Technology) security equipment cannot effectively identify the type and manufacturer of video assets; unauthorized devices (such as privately connected cameras) occupy network resources, steal video streams, causing business interruptions and information leaks; and network attacks targeting video devices (such as malicious streaming and denial-of-service attacks) are difficult to detect and block in real time.
[0003] Most related technologies rely on static policies or simple rules, lacking the ability to learn from and dynamically adapt to the behavior of video assets, thus failing to effectively address increasingly complex video network security threats. More importantly, there is currently no integrated solution that deeply integrates efficient and accurate video asset identification technology with intelligent network status monitoring and security control. Summary of the Invention
[0004] The following is an overview of the subject matter described in detail herein. This overview is not intended to limit the scope of the claims.
[0005] This disclosure provides a network security management system, including: an asset identification unit, a behavior analysis unit, and a decision generation unit, wherein: The asset identification unit is configured to send multiple probe message sequences to the target device and receive the probe response from the target device, extract the values of multiple feature fields from the probe response of the target device, fuse the values of the multiple feature fields into a multidimensional fingerprint feature vector, calculate the similarity between the multidimensional fingerprint feature vector and the fingerprint feature vector of a pre-stored known device, and send a first notification to the decision generation unit when the calculated similarity is lower than a first similarity threshold. The behavior analysis unit is configured to extract feature data from the network traffic of the target device; input the feature data into a pre-trained security management model; determine whether there is an anomaly in the network traffic of the target device based on the output of the security management model; and when an anomaly is determined, send a second notification to the decision generation unit. The decision generation unit is configured to receive the first notification and / or the second notification, and generate a control strategy according to a pre-set response rule. The control strategy includes at least one of the following: generating alarm information for the target device, or limiting the flow of the target device.
[0006] This disclosure also provides a network security management method, including: Send multiple probe message sequences to the target device and receive the probe response from the target device. The multiple probe message sequences are used to obtain the values of feature fields of the target device at multiple layers in the TCP / IP model. The detection response of the target device is analyzed and the values of multiple feature fields are extracted. The extracted values of multiple feature fields are converted into numerical form and normalized. The normalized feature field values are then fused into a multidimensional fingerprint feature vector. Calculate the similarity between the multidimensional fingerprint feature vector and the fingerprint feature vector of a pre-stored known device. When the calculated similarity is lower than a first similarity threshold, generate an alarm message for the target device and / or limit the flow of the target device.
[0007] This disclosure also provides a network security management method, including: Acquire network traffic of the target device, and extract time-series feature data and session connection feature data from the network traffic of the target device; The time series feature data is input into a time series model, and the reconstruction error of the target device is calculated based on the output of the time series model; the session connection feature data is input into a density clustering model, and the reachability distance between the target device and its nearest neighbor is determined based on the output of the density clustering model. An alarm message for the target device is generated and / or the target device is rate-limited when any of the following conditions are met: the reconstruction error of the target device is greater than a first error threshold, the reachability distance between the target device and its nearest neighbor is greater than a first distance threshold, or the fusion anomaly score of the target device is greater than a first score threshold. The fusion anomaly score is calculated based on the reconstruction error of the target device and the reachability distance between the target device and its nearest neighbor.
[0008] This disclosure also provides a network security management method, including: Multiple probe message sequences are sent to the target device and the probe response from the target device is received. The values of multiple feature fields are extracted from the probe response of the target device. The values of the multiple feature fields are fused into a multidimensional fingerprint feature vector. The similarity between the multidimensional fingerprint feature vector and the fingerprint feature vector of a known device that is stored in advance is calculated. Feature data is extracted from the network traffic of the target device; the feature data is input into a pre-trained security management model, and the network traffic of the target device is determined to be abnormal based on the output of the security management model; When the calculated similarity is lower than the first similarity threshold and / or when it is determined that the network traffic of the target device is abnormal, a control policy is generated according to the pre-set response rules. The control policy includes at least one of the following: generating alarm information for the target device and limiting the traffic of the target device.
[0009] This disclosure also provides a network security management device, including a memory; and a processor connected to the memory, the memory being used to store instructions, the processor being configured to execute the steps of the network security management method as described in any embodiment of this disclosure based on the instructions stored in the memory.
[0010] This disclosure also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the network security management method described in any embodiment of this disclosure.
[0011] This disclosure also provides a program product including instructions that, when executed by a computer, perform a network security management method as described in any embodiment of this disclosure.
[0012] The network security management system, method, apparatus, storage medium, and program product disclosed herein, through an asset identification unit, sends multiple probe message sequences to a target device and extracts values of multiple feature fields from the probe response of the target device; the values of the multiple feature fields are fused into a multi-dimensional fingerprint feature vector, and the similarity between the multi-dimensional fingerprint feature vector and the fingerprint feature vector of a pre-stored known device is calculated. Based on the calculated similarity, it is determined whether the target device is a suspicious device; a behavior analysis unit extracts feature data from the network traffic of the target device; the feature data is input into a pre-trained security management model, and based on the output of the security management model, it is determined whether the network traffic of the target device is abnormal. This provides a network security management system integrating active scanning, automatic identification, intelligent monitoring, and dynamic control. Through multi-dimensional feature fusion and machine learning technology, this system achieves accurate confirmation of network assets, real-time perception of abnormal behavior, and automatic distribution of security policies, fundamentally improving the network's proactive security defense capabilities.
[0013] Other features and advantages of this disclosure will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the disclosure. Other advantages of this disclosure may be realized and obtained by means of the methods described in the description and the accompanying drawings. Attached Figure Description
[0014] The accompanying drawings are used to provide an understanding of the technical solutions of this disclosure and form part of the specification. They are used together with the embodiments of this disclosure to explain the technical solutions of this disclosure and do not constitute a limitation on the technical solutions of this disclosure.
[0015] Figure 1A This is a schematic diagram of the structure of a network security management system provided as an exemplary embodiment of the present disclosure.
[0016] Figure 1B A schematic diagram of another network security management system provided as an exemplary embodiment of this disclosure.
[0017] Figure 2 This is a flowchart illustrating a network security management method provided as an exemplary embodiment of the present disclosure.
[0018] Figure 3 A flowchart illustrating another network security management method provided as an exemplary embodiment of this disclosure.
[0019] Figure 4 This is a schematic diagram of a network security management device provided as an exemplary embodiment of the present disclosure. Detailed Implementation
[0020] This disclosure describes several embodiments, but these descriptions are exemplary and not limiting, and it will be apparent to those skilled in the art that many more embodiments and implementations are possible within the scope of the embodiments described herein. Although many possible combinations of features are shown in the drawings and discussed in the detailed description, many other combinations of the disclosed features are also possible. Unless specifically limited, any feature or element of any embodiment may be used in combination with, or may replace, any feature or element of any other embodiment.
[0021] This disclosure includes and contemplates combinations of features and elements known to those skilled in the art. The embodiments, features, and elements disclosed in this disclosure may also be combined with any conventional features or elements to form a unique inventive scheme as defined by the claims. Any feature or element of any embodiment may also be combined with features or elements from other inventive schemes to form another unique inventive scheme as defined by the claims. Therefore, it should be understood that any feature shown and / or discussed in this disclosure may be implemented individually or in any suitable combination. Therefore, the embodiments are not limited except by the limitations imposed by the appended claims and their equivalents. Furthermore, various modifications and changes may be made within the scope of the appended claims.
[0022] Furthermore, in describing representative embodiments, the specification may have presented methods and / or processes as a specific sequence of steps. However, the method or process should not be limited to the specific order of steps described herein, to the extent that the method or process does not depend on the specific order of steps described herein. As will be understood by those skilled in the art, other sequences of steps are also possible. Therefore, the specific order of steps set forth in the specification should not be construed as a limitation of the claims. Moreover, the claims relating to the method and / or process should not be limited to the steps performed in the order written, and those skilled in the art will readily understand that these orders can be varied and still remain within the spirit and scope of the embodiments disclosed herein.
[0023] like Figure 1A As shown, this disclosure provides a network security management system, including: an asset identification unit 1011, a behavior analysis unit 1012, and a decision generation unit 1013, wherein: The asset identification unit 1011 is configured to send multiple probe message sequences to the target device and receive the probe response from the target device, extract the values of multiple feature fields from the probe response of the target device, fuse the values of multiple feature fields into a multidimensional fingerprint feature vector, calculate the similarity between the multidimensional fingerprint feature vector and the fingerprint feature vector of a pre-stored known device, and send a first notification to the decision generation unit 1013 when the calculated similarity is lower than a first similarity threshold. The behavior analysis unit 1012 is configured to extract feature data from the network traffic of the target device, input the feature data into a pre-trained security management model, determine whether there is an anomaly in the network traffic of the target device based on the output of the security management model, and send a second notification to the decision generation unit 1013 when it is determined that there is an anomaly. The decision generation unit 1013 is configured to receive a first notification and / or a second notification, and generate a control policy according to a pre-set response rule. The control policy includes at least one of the following: generating alarm information for the target device, or limiting the flow of the target device.
[0024] The network security management system of this disclosure embodiment sends multiple probe message sequences to the target device and receives the probe response from the target device through the asset identification unit 1011. It extracts the values of multiple feature fields from the probe response of the target device, fuses the values of multiple feature fields into a multi-dimensional fingerprint feature vector, calculates the similarity between the multi-dimensional fingerprint feature vector and the fingerprint feature vector of a pre-stored known device, and determines whether the target device is a suspicious device based on the similarity calculation result. The behavior analysis unit 1012 extracts feature data from the network traffic of the target device, inputs the feature data into a pre-trained security management model, and determines whether there is anomaly in the network traffic of the target device based on the output of the security management model. The decision generation unit 1013 alarms or controls the target device according to the corresponding notification. It provides a network security management system that integrates active scanning, automatic identification, intelligent monitoring and dynamic control. The system achieves accurate confirmation of network assets, real-time perception of abnormal behavior and automatic distribution of security policies through multi-dimensional feature fusion and machine learning technology, fundamentally improving the network's proactive security defense capability.
[0025] In this embodiment of the disclosure, the generated control policy includes, but is not limited to, generating alarm information for the target device and rate limiting the target device. In this embodiment, rate limiting the target device can be achieved by limiting the target device's maximum network traffic to a small value (i.e., limiting the target device from consuming excessive network traffic), or by limiting the target device's maximum network traffic to 0 (i.e., isolating the target device or adding it to a blacklist). In other examples, other control policies may be used as needed, and this disclosure does not limit these.
[0026] In this embodiment of the disclosure, the target device can be a video capture device in a video network, such as a network video recorder (NVR) or a network camera (IPC); however, this disclosure does not limit this. The following description uses a video capture device in a video network as an example. The network security management system of this embodiment can fundamentally improve the proactive security defense capabilities of video networks and effectively protect video network security.
[0027] In this embodiment of the disclosure, when sending a probe message sequence to a target device or obtaining the network traffic of the target device, the probe message sequence can be sent or the network traffic can be obtained through the target network address, for example, through the IP address of the target device. However, this disclosure does not limit this.
[0028] In some exemplary embodiments, the network security management system can be configured with multiple levels, for example, such as Figure 1BAs shown, the network security management and control system may include: a perception layer 102, a cognitive decision layer 101, an execution layer 103, and a presentation layer 104. The perception layer 102 is the data input layer, including two directions: bypass and / or serial network traffic monitoring and active packet detection. The aforementioned asset identification unit 1011, behavior analysis unit 1012, and decision generation unit 1013 may be set in the cognitive decision layer 101.
[0029] In this embodiment of the disclosure, when the perception layer 102 acquires the network traffic of the target device, it can acquire the network traffic of the target device through bypass monitoring or serial deployment. The bypass monitoring is used to analyze alarms, and the serial deployment is used to block in real time.
[0030] In this embodiment of the disclosure, the cognitive decision layer 101 is the core processing layer of the system, including an asset identification unit 1011, a behavior analysis unit 1012, and a decision generation unit 1013. The asset identification unit 1011 includes a multi-dimensional active detection module, a feature fingerprint generation module, and an asset fingerprint database. The behavior analysis unit 1012 may include a traffic parsing and feature extraction module, a time series baseline modeling module, a density clustering baseline modeling module, a decision fusion module, and a behavior baseline database. The decision generation unit 1013 includes a policy rule engine module, a preset policy module, and a control instruction generation module.
[0031] The multi-dimensional active detection module is configured to send multiple detection message sequences to the target device and receive the detection response from the target device. The feature fingerprint generation module is configured to extract the values of multiple feature fields from the detection response of the target device; fuse the values of multiple feature fields into a multi-dimensional fingerprint feature vector; calculate the similarity between the multi-dimensional fingerprint feature vector and the fingerprint feature vector of a pre-stored known device; compare the calculated similarity with a preset first similarity threshold to determine whether the target device is a suspicious device; and the asset fingerprint database is configured to store the fingerprint feature vectors of known devices.
[0032] The traffic parsing and feature extraction module is configured to extract time-series feature data and session connection feature data from acquired network traffic (including network traffic from the target device and normal network traffic of a preset duration in the preset video surveillance network). The time-series baseline modeling module is configured to train a time-series model using the time-series feature data extracted from the normal network traffic of the preset video surveillance network of a preset duration, and input the time-series feature data extracted from the network traffic of the target device into the trained time-series model. The density clustering baseline modeling module is configured to train a density clustering model using the session connection feature data extracted from the normal network traffic of the preset video surveillance network of a preset duration, and input the time-series feature data extracted from the network traffic of the target device into the trained time-series model. Session connection feature data extracted from network traffic is input into a trained density clustering model. The decision fusion module is configured to obtain the reconstruction error of the target device based on the output of the time series model, and the reachability distance between the target device and its nearest neighbor based on the output of the density clustering model. A fusion anomaly score for the target device is calculated based on the reconstruction error and the reachability distance. The reconstruction error, reachability distance, and fusion anomaly score are compared with a first error threshold, a first distance threshold, and a first score threshold to determine whether the network traffic of the target device is abnormal. A behavior baseline library is configured to store the first error threshold, the first distance threshold, and the first score threshold. In this embodiment, the first error threshold, the first distance threshold, and the first score threshold can be dynamically adjusted as needed. In this embodiment, the preset duration can be set as needed, and this disclosure does not limit it. For example, the preset duration can be 7 days.
[0033] The policy rule engine module is configured to receive a first notification from the asset identification unit 1011 and / or a second notification from the behavior analysis unit 1012, and generate a control policy based on pre-set response rules. The preset policy module is configured to store the pre-set response rules. The control command generation module is configured to generate corresponding control commands based on the control policies generated by the policy rule engine module, such as adding illegally accessed target devices to a blacklist and blocking them, limiting or isolating source IPs that initiate abnormal traffic, and pushing alarm events to the management console. In this embodiment, the pre-set response rules can be dynamically adjusted as needed.
[0034] In this embodiment of the disclosure, the cognitive decision layer 101 may further include a sample buffer pool 1014, which is configured to store false alarm samples and normal behavior samples.
[0035] In this embodiment, the asset identification unit 1011 identifies an "asset change event" and sends a first notification to the decision generation unit 1013; the behavior analysis unit 1012 detects an "abnormal behavior event" and sends a second notification to the decision generation unit 1013; after analysis and identification, the decision generation unit 1013 "feeds back (false alarm / new normal sample)" to the sample buffer pool, and the sample buffer pool feeds back "incremental learning trigger" to the behavior analysis unit 1012. The execution layer 103 is responsible for action output, distributing the security policies generated by the previous layer to firewalls, switches, etc. The presentation layer 104 is a management console, displaying asset views, alarm displays, and policy management, etc.
[0036] In this embodiment of the disclosure, the asset identification unit 1011 is used to actively discover and accurately identify video assets in the network.
[0037] In this embodiment of the disclosure, the asset identification unit 1011 sends multiple probe message sequences to the target device, including but not limited to TCP SYN packets, UDP, Internet Control Message Protocol (ICMP), and video application protocols such as Real Time Streaming Protocol (RTSP), Real Time Transport Protocol (RTP), Open Network Video Interface Forum (ONVIF), and HTTP-FLV (Flash Video over HTTP) discovery requests.
[0038] In this embodiment of the disclosure, the asset identification unit 1011 sends multiple probe message sequences to the target device. This can be a periodic scan or a triggered scan. That is, this disclosure supports periodic scanning to update the asset database and triggers a special scan when a new device is detected to be connected.
[0039] In this embodiment, the asset identification unit 1011 uses a weighted feature fingerprint generation algorithm based on multi-response fusion to generate a multi-dimensional fingerprint feature vector. This algorithm is not a simple matching algorithm, but rather a weighted calculation that integrates the device's response message features (such as the protocol handshake process, banner information, and supported encoding formats), network layer features (such as the initial time to live (TTL) and response time), and link layer features (Organizationally Unique Identifier (OUI) vendor code, i.e., the first 24 bits of the MAC address, used to identify the company or organization that manufactured the device) to generate a high-precision, uniquely identifying multi-dimensional fingerprint feature vector.
[0040] In this embodiment, after generating a multi-dimensional fingerprint feature vector, the asset identification unit 1011 intelligently compares the generated multi-dimensional fingerprint feature vector with a built-in feature library (covering MAC addresses, protocol types, and device models from mainstream manufacturers). This not only identifies the device type (NVR, IPC, video platform, etc.), manufacturer, and IP / MAC address, but also calculates a credibility score. For devices with low feature matching or unauthorized devices (such as those with mismatched IP and MAC addresses or illegally counterfeited devices), an "illegal intrusion" label is automatically added and an alarm is reported.
[0041] In this embodiment of the disclosure, the behavior analysis unit 1012 is used to learn normal traffic patterns and detect anomalies in real time.
[0042] In this embodiment of the disclosure, the behavior analysis unit 1012 adopts an unsupervised learning algorithm based on time series and density clustering. This algorithm performs long-term self-learning on the extracted features and automatically constructs a behavior baseline model for each video asset and each group of video streams without the need for a large amount of manual annotation.
[0043] In this embodiment of the disclosure, the behavior analysis unit 1012 extracts time series feature data and session connection feature data to deeply analyze video streaming protocols (RTSP, RTP, HTTP-FLV, etc.). The time series feature data is used to train a time series model, and the session connection feature data is used to train a density clustering model.
[0044] In this embodiment, the behavior analysis unit 1012 accurately identifies deviation behaviors such as "abnormal streaming," "video flooding attacks," and "video silence" by comparing real-time traffic with a behavior baseline. Simultaneously, the behavior analysis unit 1012 continuously analyzes unknown new behaviors, and after security verification, dynamically optimizes and adjusts the behavior baseline model, demonstrating adaptive capabilities.
[0045] In this embodiment, the decision generation unit 1013 is used to implement dynamic policy control. This unit has a pre-built policy library providing rich initial security policy templates, such as blacklists / whitelists based on IP / MAC / device type, and traffic rate limiting policies. This unit can automatically receive "illegal asset" information from the asset identification unit 1011 and "abnormal behavior" information from the behavior analysis unit 1012, and automatically or suggest response actions according to pre-built rules, including but not limited to: automatically adding IPs that illegally intrude into the device to the blacklist and blocking them; limiting or isolating the source IPs that initiate abnormal traffic pulling; and automatically generating new security policy rules and distributing them to network devices (such as firewalls and switches).
[0046] In this embodiment of the disclosure, multiple units work together. The decision generation unit 1013 continuously monitors the effect of strategy execution and feeds the results back to the behavior analysis unit 1012, forming a continuously self-optimizing intelligent security closed loop.
[0047] In some exemplary embodiments, multiple probe message sequences are sent in ascending order of the layers in the TCP / IP model. These multiple layers include at least two of the following layers: link layer, network layer, transport layer, and application layer. The link layer's characteristic fields include at least one of the following: vendor code; the network layer's characteristic fields include at least one of the following: response time and initial TTL value; the transport layer's characteristic fields include at least one of the following: open port number and TCP window size; and the application layer's characteristic fields include at least one of the following: application banner string, preset application layer protocol field value, and supported audio and video encoding formats.
[0048] In this embodiment of the disclosure, the asset identification unit 1011 can send a series of probe message sequences ordered according to preset rules to the target device (target IP address) and collect its response data. The probe sequences can follow the principle of "from bottom layer to top layer, from general to specific" to maximize information collection efficiency and minimize network overhead, specifically including: (1) Address Resolution Protocol (ARP) probe (if applicable). Within the local area network, first send an ARP request to obtain the target's MAC address. This step can complete the collection of link layer information first.
[0049] (2) Network layer probing. Send ICMP Echo Request (via Ping command) messages to obtain network layer characteristics such as response time and initial TTL value.
[0050] (3) Transport layer probing. Send TCP SYN packets or UDP packets to a series of preset ports (such as 554, 80, 8000, etc.) of the target IP to probe the port open status and service banner information.
[0051] (4) Application Layer Probing. Based on the preliminary results of the preceding steps, specific application protocol requests are selectively sent. For example: (I) If port 80 is detected to be open, send an HTTP GET request.
[0052] (II) If port 554 is detected to be open, a standard RTSP OPTIONS request is sent.
[0053] (III) Send a Device Discovery Protocol (WS Discovery) probe message to the standard ONVIF port.
[0054] The embodiments disclosed herein employ a strategy of "identifying the vendor first, then conducting precise detection," such as making a preliminary judgment based on MAC OUI first, and then sending ONVIF or proprietary protocol requests for the specific vendor. This greatly reduces the number of detection packets and achieves efficient and low-interference precise identification.
[0055] Next, the asset identification unit 1011 extracts the values of multiple feature fields from the detection response of the target device. For example, the asset identification unit 1011 parses and extracts the following multi-dimensional feature vectors from all collected response messages: (1) Link layer feature (F_mac): Extract the MAC address and parse its OUI vendor code, and map the OUI vendor code to a predefined enumerated value (e.g., Hikvision vendor is mapped to 1, Dahua vendor is mapped to 2, and Unknown vendor is mapped to 0). This feature is a high-weight static feature.
[0056] (2) Network layer features (F_network): (I) Extract the Round-Trip Time (RTT) value of ICMP response messages; (II) Infer the initial TTL value of the operating system or network device (such as 128, 64, 255, etc.) based on the TTL value of the response message. This feature is a medium-weight semi-static feature.
[0057] (3) Transport layer features (F_transport): (I) Record the set of open ports and combine the detected open port numbers into a feature set; (II) Extract the TCP window size value from the TCP SYN ACK response message.
[0058] (4) Application layer features (F_application): (I) Extract banner string information (such as "Server: DSS / 7.0.0") from various application layer service responses, and use regular expressions or keyword matching to extract key information (including software name and version number); (II) Protocol-specific fields, such as: (i) RTSP: Extract supported RTSP methods (such as OPTIONS, DESCRIBE, SETUP, PLAY methods, etc.) from the Public header field; (ii) ONVIF: Parse the WS Discovery response and extract device model, manufacturer name, serial number, etc.; (iii) HTTP: Extract the Server header and supported methods (such as GET, POST, etc.); (iv) Extract supported audio and video encoding formats (such as H.264, H.265, G.711, etc.) from the SDP description or other protocol interaction messages.
[0059] In some exemplary embodiments, the asset identification unit 1011 fuses the values of multiple feature fields into a multidimensional fingerprint feature vector, including: The values of the extracted feature fields are converted into numerical form and then normalized. The normalized feature field values are weighted and fused into a multidimensional fingerprint feature vector.
[0060] To address the issues of single identification dimension, insufficient accuracy, and susceptibility to deception in existing technologies, the asset identification unit 1011 of this disclosure integrates a fingerprint generation algorithm to generate a highly robust and highly unique multi-dimensional fingerprint feature vector by combining multi-level and multi-protocol response information from the device. This serves as a "digital ID card" for video assets, effectively resisting forgery and deception.
[0061] This fingerprint generation algorithm does not rely on single-dimensional features. Instead, it extracts heterogeneous multi-dimensional features from the link layer, network layer, transport layer, and application layer, assigning different weights to different features based on their stability and discriminative power. Finally, through weighted calculation and fusion, a fixed-length feature vector (i.e., fingerprint) is generated. This effectively integrates the diverse and heterogeneous response information of devices into a calculable and comparable quantitative indicator, achieving accurate and efficient identification of video assets and providing a reliable decision-making data foundation for subsequent security policy control. Static and immutable features (such as MACOUI) are given higher weights.
[0062] In this embodiment, the asset identification unit 1011 converts the extracted heterogeneous features into numerical form and normalizes them to a uniform numerical scale (e.g., the [0, 1] interval) for subsequent mathematical operations. For example, for continuous numerical features (such as RTT), Min-Max scaling can be used for normalization, setting the minimum value of the feature to 0, the maximum value to 1, and proportionally setting the feature values between the minimum and maximum values to values between 0 and 1. For categorical features (such as OUI enumeration values, port numbers), they can be converted to values between 0 and 1 according to predefined mapping values. For text features (such as banner strings), they can be matched using a predefined dictionary and converted into existing bits or specific encoded values. After obtaining the normalized feature field values, all normalized feature field values are concatenated sequentially to form an initial multidimensional feature vector V_raw.
[0063] In this embodiment of the disclosure, a weight coefficient W_i can be assigned to each feature component in the initial multidimensional feature vector V_raw. The weight coefficient of each feature component is pre-set based on the stability and discriminativeness of the feature or obtained through machine learning training. Among them: high-weight features correspond to static and unchanging features, including MAC OUI and device model; medium-weight features correspond to semi-static features, including open port set and supported protocol methods; low-weight features correspond to dynamic and easily changing features, including RTT and version number in the banner.
[0064] In this embodiment of the disclosure, the final multidimensional fingerprint feature vector V_fingerprint can be calculated using the following formula: V_fingerprint = W * (V_raw / ||V_raw||); Where * denotes element-wise multiplication (i.e., Hadamard product), and ||V_raw|| is the norm of the original feature vector, which is the normalized and weighted feature vector.
[0065] The final generated multidimensional fingerprint feature vector V_fingerprint is a fixed-length, dense numerical vector, which is the unique feature fingerprint of the video asset.
[0066] After the asset identification unit 1011 calculates a new multidimensional fingerprint feature vector, it can compare the similarity of the new multidimensional fingerprint feature vector with the fingerprint feature vector of a known device that has been stored in advance. The similarity comparison determines whether the corresponding device is an unknown model device or a suspicious device.
[0067] In this embodiment of the disclosure, when comparing the similarity of a new multidimensional fingerprint feature vector with a pre-stored fingerprint feature vector of a known device, cosine similarity or Euclidean distance can be used for similarity comparison; however, this disclosure does not limit this.
[0068] In this embodiment of the disclosure, the first similarity threshold can be a static threshold or a dynamic threshold (i.e., it can be dynamically adjusted as needed). For example, the first similarity threshold can be set to 0.96; however, this disclosure does not limit this.
[0069] If the calculated similarity is higher than the first similarity threshold, it is determined to be a known asset type and manufacturer. If it contains new feature information, the feature library is automatically updated. If the calculated similarity is lower than the first similarity threshold, it is marked as "unknown model" or "suspicious device" and reported to the management and control platform for alarm. At the same time, a more in-depth manual analysis process can be triggered to enrich the feature library.
[0070] In some exemplary embodiments, the security management model includes a time series model and a density clustering model, and the feature data includes time series feature data and session connection feature data.
[0071] The behavior analysis unit 1012 is specifically configured to: extract time-series feature data and session connection feature data from the network traffic of the target device; input the time-series feature data into a time-series model, and obtain the reconstruction error of the target device based on the output of the time-series model; input the session connection feature data into a density clustering model, and obtain the reachability distance between the target device and its nearest neighbor based on the output of the density clustering model; and send a second notification to the decision generation unit 1013 when any of the following conditions are met: The reconstruction error of the target device is greater than the first error threshold, the reachability distance between the target device and the nearest neighbor is greater than the first distance threshold, and the fusion anomaly score of the target device is greater than the first score threshold. The fusion anomaly score is calculated based on the reconstruction error of the target device and the reachability distance between the target device and the nearest neighbor.
[0072] In this embodiment of the disclosure, the security management model includes two models: a time series model and a density clustering model. However, in other examples, the security management model may include only one of the two models, the time series model and the density clustering model, as needed. This disclosure does not impose any restrictions on this.
[0073] For example, when the security management model only includes a time series model, the feature data includes: time series feature data. The behavior analysis unit 1012 is specifically configured to: extract time series feature data from the network traffic of the target device; input the time series feature data into the time series model; obtain the reconstruction error of the target device based on the output of the time series model; and send a second notification to the decision generation unit 1013 when the reconstruction error of the target device is greater than a first error threshold.
[0074] For example, when the security management model only includes a density clustering model, the feature data includes: session connection feature data. The behavior analysis unit 1012 is specifically configured to: extract session connection feature data from the network traffic of the target device; input the session connection feature data into the density clustering model, and obtain the reachability distance between the target device and the nearest neighbor based on the output of the density clustering model; when the reachability distance between the target device and the nearest neighbor is greater than a first distance threshold, send a second notification to the decision generation unit 1013.
[0075] In this embodiment of the disclosure, in order to solve the problems that video network traffic behavior is complex and variable, difficult to accurately describe by fixed rules, and that normal behavior patterns evolve dynamically with business development, the behavior analysis unit 1012 aims to autonomously learn the normal behavior patterns of each video asset and business flow without manual intervention and annotation, construct a dynamic baseline, and detect abnormal behaviors that deviate from the baseline in real time, including but not limited to malicious streaming, flood attacks, video stream interruption, and abnormal protocol interaction behaviors.
[0076] The behavior analysis unit 1012 of this embodiment adopts a dual-model collaborative analysis architecture, which realizes multi-dimensional and multi-perspective monitoring of video network traffic through parallel processing and decision fusion of time series model and density clustering model.
[0077] The time series model focuses on learning the regularity of traffic behavior from a time dimension, including periodic characteristics, trend changes, and short-term dependencies, effectively identifying abnormal fluctuations in traffic metrics over time. The density clustering model focuses on learning the distribution characteristics of normal session connections from a feature space dimension, keenly identifying outliers and abnormal sessions that do not conform to the mainstream distribution pattern. The behavior analysis unit 1012 makes a comprehensive judgment based on the outputs of the two models, generates a final anomaly determination conclusion, and supports the dynamic adaptive updating of the baseline (including the first error threshold, the first distance threshold, the first score threshold, etc.) through incremental learning.
[0078] In this embodiment of the disclosure, the time-series feature data includes traffic indicator sequence data, session protocol indicator sequence data, and video frame feature sequence data. The traffic indicator sequence data represents the amount of traffic per unit time. For example, the traffic indicator sequence data can aggregate the following indicators within a preset fixed time window (denoted as Tw, such as 5 minutes) to form a multi-dimensional time series: bytes per second, packets per second, connections per second, etc. The session protocol indicator sequence represents one or more session protocols per unit time. For example, taking RTSP as an example, it represents the number of requests such as request to negotiate transmission parameters (SETUP), request to start data transmission (PLAY), and request to close the connection (TEARDOWN). The video frame feature sequence represents the number of video frames (Fi), average frame size (Sf), etc., per unit time.
[0079] In this embodiment, the session connection feature data includes: communication endpoint feature data, protocol instruction sequence feature data, connection statistics feature data, and access behavior feature data. Specifically, the communication endpoint feature data is used to hash and anonymize the five-tuple information (source IP address, destination IP address, source port number, destination port number, and protocol number) of the TCP / IP model. The protocol instruction sequence feature data is used to encode the protocol instruction sequence within the session into a fixed-length vector (using a word embedding model). The connection statistics feature data includes session duration (Td), total data transmission volume (Dtotal), and average packet size (Sp). The access behavior feature data represents the number of accesses to different destination IPs per unit time (used to identify scanning behavior).
[0080] In some exemplary implementations, the time series model and the density clustering model are pre-trained using the following method: Extract time-series feature data and session connection feature data of network traffic from a preset video surveillance network; A time series model is trained using time series feature data, and a density clustering model is trained using session connection feature data. During training, the optimization objective of the time series model is to minimize the reconstruction error, which is the average of the sum of the squared magnitudes of the error vectors of the input time series feature data at each time point. The density clustering model obtains the clustering results by calculating the core distance and reachability distance.
[0081] In this embodiment of the disclosure, the time series model can be an autoencoder model based on a long short-term memory network (LSTM-Autoencoder); however, this disclosure does not limit it. Let the input multivariate time series be X=[ , ,..., At each specific time t, the data points It is not a single number, but a set containing multiple different features. The time window division adopts an overlapping sliding window strategy, meaning that at a certain moment, the multivariate time series input to the model is X=[ , ,..., At the next time step, the multivariate time series input to the model can be X=[ , ,..., The encoder (function f_enc) processes the entire input sequence X. After processing, it outputs a "summary" h = f_enc(X) representing the core information of the sequence. The decoder (function g_dec) restores and reconstructs the original time series data, generating a reconstructed new sequence. =g_dec(h). Training process: The model is trained using historical normal time period data. The optimization objective is to minimize the reconstruction error, where the reconstruction error is expressed as L = (1 / T)*∑|| – || 2 That is, the sum of the squared magnitudes of the N-dimensional error vectors at all time points T, and then the average. The trained time series model learns to encode normal traffic patterns into the latent space.
[0082] During anomaly detection, the reconstruction error of the sequence within the window is calculated in real time: E = (1 / T) * ∑ || – || 2 If E > θ_ts (dynamic threshold), an abnormal alarm will be triggered.
[0083] In this embodiment of the disclosure, the density clustering model can be a model based on the OPTICS (Ordering Points To Identify the Clustering Structure) algorithm; however, this disclosure is not limited thereto. The density clustering model is used to process session connection feature data D = { , ,..., The OPTICS algorithm is a density-based clustering algorithm that identifies cluster structures in data by calculating the core distance and reachability distance of each point, and generates a sorted list and reachability map to identify the density distribution structure of the data.
[0084] During anomaly detection, for the new session connection feature data d_new, the reachable distance r_reach(d_new) to its nearest neighbor is calculated. If r_reach(d_new) > θ_cluster (the first distance threshold), it is identified as an outlier and an anomaly alarm is triggered. Considering the large volume of video network session data, strategies such as downsampling and feature selection can be used to optimize the computational efficiency of the OPTICS algorithm.
[0085] In this embodiment, the behavior analysis unit 1012 can perform weighted fusion of the outputs of the time series model and the density clustering model. This disclosure improves the accuracy and robustness of anomaly detection by using LSTM-Autoencoder to process multivariate time series and OPTICS algorithm to process high-dimensional session features, and by weighted fusion of the two.
[0086] In some exemplary implementations, the fusion anomaly score is calculated according to the following formula: s_final = α * (s_ts / θ_ts) + β * (s_c / θ_cluster), where s_final is the fusion anomaly score, α and β are two weighting coefficients, and α + β = 1, s_ts is the reconstruction error of the target device, θ_ts is the first error threshold, s_c is the reachable distance between the target device and its nearest neighbor, and θ_cluster is the first distance threshold.
[0087] For example, define the anomaly score s_ts = E for the time series model and the anomaly score s_c = r_reach for the density clustering model. A weighted fusion strategy is used to calculate the comprehensive anomaly score: s_final = α * (s_ts / θ_ts) + β * (s_c / θ_cluster), where the weight coefficients α and β satisfy α + β = 1 and can be adjusted based on the model's historical accuracy. If s_final > θ_final (the first score threshold), a comprehensive anomaly alarm is generated.
[0088] In some exemplary embodiments, the network security management system further includes: a sample buffer pool 1014, and the decision generation unit 1013 is further configured to: Collect false alarm samples and normal behavior samples, and store the collected false alarm samples and normal behavior samples in sample buffer pool 1014; When the number of samples in the sample buffer pool 1014 exceeds the preset threshold, the sample data in the sample buffer pool 1014 is used to perform incremental learning and fine-tuning on the time series model and density clustering model.
[0089] This embodiment of the disclosure can establish a feedback mechanism to collect false alarm samples and confirmed new normal behavior samples, and store the collected samples in a sample buffer pool 1014. When the number of samples in the sample buffer pool exceeds a preset size value N_retrain, an incremental learning process is initiated: For time series models, load the existing model weights, perform iterative training with a small number of epochs using 1014 data points from the sample buffer pool, and fine-tune with a small learning rate to prevent catastrophic forgetting.
[0090] For density clustering models, incremental clustering algorithms (such as Bayesian-Gaussian Mixture) or periodic full recalculation are used to update the density clustering model (optionally performed during off-peak hours at night). Dynamic thresholds θ_ts, θ_cluster, and θ_final are periodically adjusted to achieve adaptive evolution of the baseline.
[0091] This embodiment of the disclosure adopts a dual-model collaborative architecture, combining time series analysis and temporal unsupervised learning with density clustering analysis to achieve comprehensive monitoring of both the "temporal domain" and "feature domain" of video network traffic, overcoming the limitations of a single model. The entire process requires no manual annotation, and dynamic optimization of the baseline is achieved through feedback mechanisms and incremental learning, significantly reducing operation and maintenance costs and improving system adaptability.
[0092] The operation process of the network security management system in this embodiment can be divided into two main stages: the initial deployment stage and the continuous operation stage. Its core is an intelligent closed loop of "Perception-Cognition-Decision-Action-Evolution" (PCDAE), which can block abnormal traffic in real time and actively isolate illegal assets, effectively ensuring the security of video networks.
[0093] The goal of the initial deployment phase is to build an initial asset database and behavior baseline, laying the foundation for subsequent intelligent monitoring of the system.
[0094] First, connect the system to the critical links of the video surveillance network (such as the core switch) in either bypass or serial mode. Then configure the network scanning range (IP network segment), the built-in signature databases of mainstream vendors, the initial security policy template (such as blacklists and whitelists), and the initial algorithm parameters (such as scanning frequency and time window length T).
[0095] After system startup, a proactive full-network scan is immediately performed, conducting multi-dimensional probing of target IPs using a "pre-judgment, then probe" strategy. A weighted feature fingerprint generation algorithm is used to generate a feature fingerprint (V_fingerprint) for each responding device, and this fingerprint is compared with a built-in feature library to identify the device manufacturer and type, and calculate a credibility score. Identified legitimate assets are entered into the asset information database. Devices that cannot be identified or have low credibility are marked as "suspicious" and added to the pending review database. This step outputs an initial video asset list and device fingerprint database.
[0096] Next, the system enters a "learning mode" lasting several days (e.g., 7 days). It performs deep analysis of network traffic, extracting time-series and session connection features. For the time-series model, it uses the initial 7 days of normal traffic data to train an LTM-Autoencoder model, minimizing the reconstruction error L and establishing an initial traffic behavior baseline for each asset. For the density clustering model, it uses normal session connection data from the same period to run the OPTICS algorithm, generating a reachability graph and establishing a density baseline for the normal session distribution. Based on the distribution of the initial baseline, it automatically calculates and sets the dynamic initial thresholds (θ_ts, θ_cluster, θ_final) for each model. This step outputs an initial behavioral baseline model (LSTM-AE model parameters, OPTICS sorting structure) and dynamic thresholds.
[0097] Based on the "suspicious" assets identified in the aforementioned steps, a preliminary isolation or observation strategy is generated, and a rich set of security strategy templates are preloaded.
[0098] After initialization, the system automatically switches from "learning mode" to "monitoring mode" and enters the continuous operation phase. This phase still constitutes a PCDAE closed loop, which is the core of the system's daily work, forming a perpetual intelligent closed loop.
[0099] Perception - Continuous data acquisition: The system continuously bypasses and monitors or analyzes network traffic in series.
[0100] Cognition – Real-time analysis and anomaly detection: Path A (asset cognition) and Path B (behavioral cognition) are processed in parallel. For Path A (asset cognition), the asset identification unit 1011 performs scans and updates the asset database according to a preset period (e.g., every 24 hours) or trigger conditions (new IP detected). Any newly discovered suspicious device immediately generates an event. For Path B (behavioral cognition), the behavioral analysis unit 1012 extracts features from real-time traffic. The behavioral analysis unit 1012 calculates a comprehensive anomaly score s_final. If s_final > θ_final, an abnormal behavior event is generated. Output of this step: Security events (including "illegal asset access" and "abnormal behavior").
[0101] Decision - Intelligent Policy Generation: Receives security events from the "Cognition" layer and automatically generates specific control policies (e.g., adding illegal IPs to the blacklist, or limiting the rate of abnormal source IPs) based on a pre-defined response rule base (e.g., IF Event Type == "Illegal Asset" THEN Action == "Block"). Output of this step: Executable security policy instructions.
[0102] Action – Policy execution: The system automatically sends policy instructions to network execution devices (such as firewalls and switches) via API interfaces (such as RESTful APIs and SOAP APIs). The network devices execute the policies to achieve real-time blocking or isolation of threats.
[0103] Evolution – Feedback and Optimization: The system continuously collects false alarms (alarms confirmed as normal after action) and newly confirmed normal behavior samples, storing them in a sample buffer. When the number of samples in the buffer exceeds a preset size N_retrain, an incremental learning process is initiated: the time series model is fine-tuned with new samples; the density clustering model is updated using incremental clustering or periodic full recalculation; and thresholds are adjusted: based on the new baseline distribution, all thresholds (θ_ts, θ_cluster, θ_final) are dynamically adjusted periodically. Through incremental learning, the system's behavioral baseline, algorithm model, and decision thresholds evolve accordingly, continuously adapting to network changes, becoming increasingly intelligent, and the false alarm rate continuously decreases.
[0104] like Figure 2 As shown in the embodiments of this disclosure, a network security management method is also provided, including: Step 210: Send multiple probe message sequences to the target device and receive the probe response from the target device. The multiple probe message sequences are used to obtain the values of characteristic fields of the target device at multiple layers in the TCP / IP model. Step 220: Analyze the detection response of the target device and extract the values of multiple feature fields. Convert the extracted values of multiple feature fields into numerical form and normalize them. Then, fuse the normalized feature field values into a multidimensional fingerprint feature vector. Step 230: Calculate the similarity between the multidimensional fingerprint feature vector and the fingerprint feature vector of a pre-stored known device. When the calculated similarity is lower than the first similarity threshold, generate alarm information for the target device and / or limit the flow of the target device.
[0105] The network security management method provided in this disclosure sends multiple probe message sequences to a target device and receives the probe response from the target device. It extracts the values of multiple feature fields from the probe response of the target device, merges the values of multiple feature fields into a multi-dimensional fingerprint feature vector, calculates the similarity between the multi-dimensional fingerprint feature vector and the fingerprint feature vector of a pre-stored known device, and determines whether the target device is a suspicious device based on the similarity calculation result. This method can achieve accurate identification of network assets and fundamentally improve the network's proactive security defense capabilities.
[0106] In some exemplary embodiments, multiple probe message sequences are sent in ascending order of the TCP / IP model layers, which include at least two of the following layers: link layer, network layer, transport layer, and application layer. The link layer's characteristic fields include at least one of the following: vendor code; the network layer's characteristic fields include at least one of the following: response time, initial TTL value; the transport layer's characteristic fields include at least one of the following: open port number, TCP window size; and the application layer's characteristic fields include at least one of the following: application banner string, preset application layer protocol field value, and supported audio and video encoding formats.
[0107] In some exemplary embodiments, the values of multiple extracted feature fields are converted into numerical form and normalized according to at least one of the following methods: min-maximum scaling, numerical mapping, and dictionary matching.
[0108] like Figure 3 As shown in the embodiments of this disclosure, a network security management method is also provided, including: Step 310: Obtain the network traffic of the target device, and extract time-series feature data and session connection feature data from the network traffic of the target device; Step 320: Input the time series feature data into the time series model, and calculate the reconstruction error of the target device based on the output of the time series model; input the session connection feature data into the density clustering model, and determine the reachability distance between the target device and its nearest neighbor based on the output of the density clustering model; Step 330: When any of the following conditions are met, generate alarm information for the target device, and / or limit the flow of the target device: the reconstruction error of the target device is greater than the first error threshold, the reachability distance between the target device and the nearest neighbor is greater than the first distance threshold, or the fusion anomaly score of the target device is greater than the first score threshold. The fusion anomaly score is calculated based on the reconstruction error of the target device and the reachability distance between the target device and the nearest neighbor.
[0109] The network security management method provided in this disclosure extracts time-series feature data and session connection feature data from the network traffic of a target device; inputs the time-series feature data into a time-series model and calculates the reconstruction error of the target device based on the output of the time-series model; inputs the session connection feature data into a density clustering model and determines the reachability distance between the target device and its nearest neighbor based on the output of the density clustering model; and determines whether there are any anomalies in the network traffic of the target device based on the outputs of the time-series model and the density clustering model. This method can achieve real-time perception of abnormal behavior of network devices and fundamentally improve the proactive security defense capability of the network.
[0110] In some exemplary implementations, the fusion anomaly score is calculated according to the following formula: s_final = α * (s_ts / θ_ts) + β * (s_c / θ_cluster), where s_final is the fusion anomaly score, α and β are two weighting coefficients, and α + β = 1, s_ts is the reconstruction error of the target device, θ_ts is the first error threshold, s_c is the reachable distance between the target device and its nearest neighbor, and θ_cluster is the first distance threshold.
[0111] In some exemplary implementations, the time series model and the density clustering model are pre-trained using the following method: Extract time-series feature data and session connection feature data of network traffic from a preset video surveillance network; A time series model is trained using the time series feature data, and a density clustering model is trained using the session connection feature data. During the training process, the optimization objective of the time series model is to minimize the reconstruction error, which is the average of the sum of the squared magnitudes of the error vectors of the input time series feature data at each time point. The density clustering model obtains the clustering results by calculating the core distance and the reachability distance.
[0112] In some exemplary embodiments, the method further includes: Collect false alarm samples and normal behavior samples, and store the collected false alarm samples and normal behavior samples in the sample buffer pool; When the number of samples in the sample buffer pool exceeds a preset threshold, the sample data in the sample buffer pool is used to perform incremental learning and fine-tuning on the time series model and the density clustering model.
[0113] This disclosure also provides a network security management method, including: Multiple probe message sequences are sent to the target device and the probe response from the target device is received. The values of multiple feature fields are extracted from the probe response of the target device. The values of the multiple feature fields are fused into a multidimensional fingerprint feature vector. The similarity between the multidimensional fingerprint feature vector and the fingerprint feature vector of a known device that is stored in advance is calculated. Feature data is extracted from the network traffic of the target device; the feature data is input into a pre-trained security management model, and the network traffic of the target device is determined to be abnormal based on the output of the security management model; When the calculated similarity is lower than the first similarity threshold and / or when it is determined that the network traffic of the target device is abnormal, a control policy is generated according to the pre-set response rules. The control policy includes at least one of the following: generating alarm information for the target device and limiting the traffic of the target device.
[0114] In this embodiment, the specific network security management methods can be referred to the above description, and will not be repeated here.
[0115] This disclosure also provides a network security management device, including a memory; and a processor connected to the memory, the memory being used to store instructions, the processor being configured to execute the steps of the network security management method as described in any embodiment of this disclosure based on the instructions stored in the memory.
[0116] like Figure 4As shown, in one example, the network security management device may include: a processor 410, a memory 420, a bus system 430, and a transceiver 440. The processor 410, memory 420, and transceiver 440 are connected via the bus system 430. The memory 420 stores instructions, and the processor 410 executes the instructions stored in the memory 420 to control the transceiver 440 to send and receive signals. Specifically, under the control of the processor 410, the transceiver 440 can send multiple probe message sequences to the target device and receive the probe response from the target device. The processor 410 parses the probe response from the target device and extracts the values of multiple feature fields. The extracted feature field values are converted into numerical forms and normalized. The normalized feature field values are fused into a multi-dimensional fingerprint feature vector. The similarity between the multi-dimensional fingerprint feature vector and the fingerprint feature vector of a pre-stored known device is calculated. When the calculated similarity is lower than a first similarity threshold, an alarm message is generated for the target device, and / or, rate limiting is applied to the target device. Alternatively, transceiver 440 may acquire network traffic of the target device under the control of processor 410. Processor 410 extracts time-series feature data and session connection feature data from the network traffic of the target device; inputs the time-series feature data into a time-series model, calculates the reconstruction error of the target device based on the output of the time-series model; inputs the session connection feature data into a density clustering model, determines the reachability distance between the target device and its nearest neighbor based on the output of the density clustering model; and generates alarm information for the target device and / or performs rate limiting on the target device when any of the following conditions are met: the reconstruction error of the target device is greater than a first error threshold, the reachability distance between the target device and its nearest neighbor is greater than a first distance threshold, or the fusion anomaly score of the target device is greater than a first score threshold, wherein the fusion anomaly score is calculated based on the reconstruction error of the target device and the reachability distance between the target device and its nearest neighbor.
[0117] It should be understood that processor 410 can be a central processing unit (CPU), or it can be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), off-the-shelf programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor, etc.
[0118] Memory 420 may include read-only memory and random access memory, and provides instructions and data to processor 410. A portion of memory 420 may also include non-volatile random access memory. For example, memory 420 may also store device type information.
[0119] In addition to a data bus, the bus system 430 may also include a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 4 The general labeled all buses as Bus System 430.
[0120] In implementation, the processing performed by the processing device can be accomplished through integrated logic circuits in the hardware of the processor 410 or through software instructions. That is, the method steps of this embodiment can be executed by a hardware processor, or by a combination of hardware and software modules within the processor. The software modules can reside in random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, or other storage media. This storage medium is located in memory 420, and the processor 410 reads information from memory 420 and, in conjunction with its hardware, completes the steps of the aforementioned method. To avoid repetition, further details are omitted here.
[0121] This disclosure also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, implements the network security management method as described in any embodiment of this disclosure. The network security management method driven by executing executable instructions is essentially the same as the network security management method provided in the above embodiments of this disclosure, and will not be described in detail here.
[0122] In some possible implementations, various aspects of the network security management method provided in this disclosure may also be implemented in the form of a program product, which includes program code. When the program product is run on a computer device, the program code is used to cause the computer device to perform the steps in the network security management method according to various exemplary embodiments of this disclosure described above. For example, the computer device may execute the network security management method described in the embodiments of this disclosure.
[0123] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0124] It will be understood by those skilled in the art that all or some of the steps, systems, or apparatuses disclosed above, and their functional modules / units, can be implemented as software, firmware, hardware, or suitable combinations thereof. In hardware implementations, the division between functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed collaboratively by several physical components. Some or all components may be implemented as software executed by a processor, such as a digital signal processor or microprocessor, or as hardware, or as an integrated circuit, such as an application-specific integrated circuit (ASIC). Such software may be distributed on a computer-readable medium, which may include computer storage media (or non-transitory media) and communication media (or transient media). As is known to those skilled in the art, the term computer storage media includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disc (DVD) or other optical disc storage, magnetic cartridges, magnetic tape, disk storage or other magnetic storage devices, or any other medium that can be used to store desired information and can be accessed by a computer. Furthermore, it is well known to those skilled in the art that communication media typically contain computer-readable instructions, data structures, program modules, or other data in modulated data signals such as carrier waves or other transmission mechanisms, and may include any information delivery medium.
[0125] It should be noted that the above embodiments or implementation methods are merely exemplary and not restrictive. Therefore, this disclosure is not limited to the content specifically shown and described herein. Various modifications, substitutions, or omissions can be made to the form and details of the implementations without departing from the scope of this disclosure.
Claims
1. A network security management and control system, characterized in that, include: The unit comprises an asset identification unit, a behavior analysis unit, and a decision generation unit, wherein: The asset identification unit is configured to send multiple probe message sequences to the target device and receive the probe response from the target device, extract the values of multiple feature fields from the probe response of the target device, fuse the values of the multiple feature fields into a multidimensional fingerprint feature vector, calculate the similarity between the multidimensional fingerprint feature vector and the fingerprint feature vector of a pre-stored known device, and send a first notification to the decision generation unit when the calculated similarity is lower than a first similarity threshold. The behavior analysis unit is configured to extract feature data from the network traffic of the target device; input the feature data into a pre-trained security management model; determine whether there is an anomaly in the network traffic of the target device based on the output of the security management model; and when an anomaly is determined, send a second notification to the decision generation unit. The decision generation unit is configured to receive the first notification and / or the second notification, and generate a control strategy according to a pre-set response rule. The control strategy includes at least one of the following: generating alarm information for the target device, or limiting the flow of the target device.
2. The network security management and control system according to claim 1, characterized in that, The security management model includes a time series model and a density clustering model; the feature data includes time series feature data and session connection feature data; and the behavior analysis unit is specifically configured as follows: Time-series feature data and session connection feature data are extracted from the network traffic of the target device; the time-series feature data is input into the time-series model, and the reconstruction error of the target device is obtained based on the output of the time-series model; the session connection feature data is input into the density clustering model, and the reachability distance between the target device and its nearest neighbor is obtained based on the output of the density clustering model; when any one of the following conditions is met, the second notification is sent to the decision generation unit: The reconstruction error of the target device is greater than a first error threshold, the reachable distance between the target device and its nearest neighbor is greater than a first distance threshold, and the fusion anomaly score of the target device is greater than a first score threshold. The fusion anomaly score is calculated based on the reconstruction error of the target device and the reachable distance between the target device and its nearest neighbor.
3. The network security management and control system according to claim 2, characterized in that, The fusion anomaly score is calculated according to the following formula: s_final = α * (s_ts / θ_ts) + β * (s_c / θ_cluster), where s_final is the fusion anomaly score, α and β are both weighting coefficients, and α + β = 1, s_ts is the reconstruction error of the target device, θ_ts is the first error threshold, s_c is the reachable distance between the target device and its nearest neighbor, and θ_cluster is the first distance threshold.
4. The network security management and control system according to claim 2, characterized in that, The time-series feature data includes at least one of the following: traffic indicator sequence data, session protocol indicator sequence data, and video frame feature sequence data, wherein the traffic indicator sequence data is used to represent the traffic volume per unit time, the session protocol indicator sequence data is used to represent the number of one or more session protocol requests per unit time, and the video frame feature sequence data includes at least one of the following: the number of video frames per unit time and the average video frame size; The session connection feature data includes at least one of the following: communication endpoint feature data, protocol instruction sequence feature data, connection statistics feature data, and access behavior feature data. The communication endpoint feature data includes the five-tuple information of the TCP / IP model. The protocol instruction sequence feature data includes the protocol instruction sequence within the session. The connection statistics feature data includes at least one of the following: session duration, total data transmission volume, and average packet size. The access behavior feature data includes the number of times different destination addresses are accessed per unit time.
5. The network security management and control system according to claim 2, characterized in that, The time series model and density clustering model are pre-trained using the following method: Extract first time-series feature data and first session connection feature data from normal network traffic of a preset duration in a preset video surveillance network; The time series model is trained using the first time series feature data, and the density clustering model is trained using the first session connection feature data. During the training process, the optimization objective of the time series model is to minimize the reconstruction error. The reconstruction error is the average of the sum of the squared magnitudes of the error vectors of the input first time series feature data at each time point. The density clustering model obtains the clustering result by calculating the core distance and the reachability distance.
6. The network security management and control system according to claim 5, characterized in that, Also includes: The sample buffer pool, the decision generation unit is further configured as follows: Collect false alarm samples and normal behavior samples, and store the collected false alarm samples and normal behavior samples in the sample buffer pool; When the number of samples in the sample buffer pool exceeds a preset threshold, the sample data in the sample buffer pool is used to perform incremental learning and fine-tuning on the time series model and the density clustering model.
7. The network security management and control system according to claim 2, characterized in that, The time series model is an autoencoder model based on a long short-term memory network, and the density clustering model is a density-based clustering algorithm model.
8. The network security management and control system according to claim 1, characterized in that, Multiple probe message sequences are sent in ascending order of the TCP / IP model layers, which include at least two of the following layers: link layer, network layer, transport layer, and application layer. The link layer's characteristic fields include at least one of the following: vendor code; the network layer's characteristic fields include at least one of the following: response time and initial lifetime; the transport layer's characteristic fields include at least one of the following: open port number and TCP window size; and the application layer's characteristic fields include at least one of the following: application banner string, preset application layer protocol field value, and supported audio and video encoding formats.
9. The network security management and control system according to claim 1, characterized in that, The asset identification unit fuses the values of multiple feature fields into a multidimensional fingerprint feature vector, including: The extracted values of the multiple feature fields are converted into numerical form and normalized. The normalized feature field values are weighted and fused into a multidimensional fingerprint feature vector.
10. A network security management and control method, characterized in that, include: Send multiple probe message sequences to the target device and receive the probe response from the target device. The multiple probe message sequences are used to obtain the values of feature fields of the target device at multiple layers in the TCP / IP model. The detection response of the target device is analyzed and the values of multiple feature fields are extracted. The extracted values of multiple feature fields are converted into numerical form and normalized. The normalized feature field values are then fused into a multidimensional fingerprint feature vector. Calculate the similarity between the multidimensional fingerprint feature vector and the fingerprint feature vector of a pre-stored known device. When the calculated similarity is lower than a first similarity threshold, generate an alarm message for the target device and / or limit the flow of the target device.
11. A network security management and control method, characterized in that, include: Acquire network traffic of the target device, and extract time-series feature data and session connection feature data from the network traffic of the target device; The time series feature data is input into a pre-trained time series model, and the reconstruction error of the target device is calculated based on the output of the time series model; the session connection feature data is input into a pre-trained density clustering model, and the reachability distance between the target device and its nearest neighbor is determined based on the output of the density clustering model. An alarm message for the target device is generated and / or the target device is rate-limited when any of the following conditions are met: the reconstruction error of the target device is greater than a first error threshold, the reachability distance between the target device and its nearest neighbor is greater than a first distance threshold, or the fusion anomaly score of the target device is greater than a first score threshold. The fusion anomaly score is calculated based on the reconstruction error of the target device and the reachability distance between the target device and its nearest neighbor.
12. A network security management and control method, characterized in that, include: Multiple probe message sequences are sent to the target device and the probe response from the target device is received. The values of multiple feature fields are extracted from the probe response of the target device. The values of the multiple feature fields are fused into a multidimensional fingerprint feature vector. The similarity between the multidimensional fingerprint feature vector and the fingerprint feature vector of a known device that is stored in advance is calculated. Feature data is extracted from the network traffic of the target device; the feature data is input into a pre-trained security management model, and the network traffic of the target device is determined to be abnormal based on the output of the security management model; When the calculated similarity is lower than the first similarity threshold and / or when it is determined that the network traffic of the target device is abnormal, a control policy is generated according to the pre-set response rules. The control policy includes at least one of the following: generating alarm information for the target device and limiting the traffic of the target device.
13. A network security management and control device, characterized in that, The method includes a memory; and a processor connected to the memory, the memory being used to store instructions, the processor being configured to perform the steps of the network security management method as described in any one of claims 10 to 12 based on the instructions stored in the memory.
14. A computer-readable storage medium, characterized in that, It stores a computer program that, when executed by a processor, implements the network security management method as described in any one of claims 10 to 12.
15. A computer program product, characterized in that, The instructions include, when the computer program product is executed by a computer, the instructions perform the network security management method as described in any one of claims 10 to 12.