An FTTR network data anomaly analysis method, system and device

By constructing terminal device profiles and real-time behavior analysis, combined with deep packet inspection and cross-network filtering tags, the problem of traditional monitoring mechanisms in FTTR-B networks being unable to detect cross-network data anomalies has been solved. This enables dynamic anomaly detection and threat identification in FTTR-B networks, improving network security and stability.

CN121486712BActive Publication Date: 2026-04-10SICHUAN TIANYI COMHEART TELECOM
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SICHUAN TIANYI COMHEART TELECOM
Filing Date
2026-01-05
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

In FTTR-B networks, traditional monitoring mechanisms struggle to detect and locate cross-network data anomalies in a timely manner, and they also find it difficult to flexibly adjust monitoring strategies to adapt to dynamic changes in business operations, thus threatening network security and stability.

Method used

By acquiring the target terminal device's local area network and internet historical behavior, a device profile is constructed, real-time data is analyzed, deep packet inspection technology is used to analyze behavioral anomalies, and cross-network filtering tags and data fences are used for anomaly analysis and threat identification.

Benefits of technology

It improves the accuracy and flexibility of cross-network data anomaly identification, enabling timely detection and handling of abnormal behavior, and enhancing network security and stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121486712B_ABST
    Figure CN121486712B_ABST
Patent Text Reader

Abstract

The application discloses an FTTR network data exception analysis method, system and equipment, which is applied to an FTTR-B network and comprises the following steps: acquiring local area network history behaviors and Internet history behaviors of a target terminal device in a target FTTR network; obtaining a target terminal device portrait according to the local area network history behaviors and the Internet history behaviors; analyzing real-time data in the target FTTR network to obtain a target behavior of the target terminal device; and judging whether the target behavior is abnormal according to the target behavior and the target terminal device portrait. At least, the problem that many enterprises access the Internet through FTTR-B while carrying out local area network networking, and it is difficult to discover and locate data exceptions across networks in time and to flexibly adjust monitoring strategies to adapt to business dynamic changes if only relying on traditional monitoring mechanisms is solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to the technical field of Internet, in particular to an FTTR network data anomaly analysis method, system and device. BACKGROUND

[0002] FTTR is a new type of network access technology widely used in the current communication field. With the advent of the information age, traditional broadband access methods gradually cannot meet the demand for high bandwidth, high stability and low delay. Government and enterprise users have increasingly high requirements for network infrastructure, and need faster, more stable and safer network connections. With the increasing demand of small and micro enterprises for high bandwidth, low latency and stable network connection, the FTTR-B full optical networking solution emerges as the times require. FTTR-B extends optical fibers directly to each room or office area of an enterprise through a main gateway plus multiple full optical slave gateways, thereby replacing the traditional copper cable / ethernet wiring structure, resulting in increasingly diverse data flow categories, with frequent data shuttling across subnets / gateways, VLANs or different service categories. Traditional network monitoring and anomaly detection methods mainly rely on static rules or simple statistical features, and monitor single network segments or typical traffic characteristics. Such an approach often fails to comprehensively capture anomalies when faced with complex, heterogeneous and cross-network data flows: on the one hand, rules and configurations need to be defined and fixed in advance and do not have dynamic adaptation capabilities; on the other hand, static statistics cannot reflect the multi-dimensional, cross-temporal and cross-business data correlation and mutation characteristics, resulting in poor reliability and flexibility of anomaly detection.

[0003] Especially in the enterprise-level full optical networking environment constructed by FTTR-B, since many enterprises now access the Internet through FTTR-B while conducting local area network networking, if only relying on traditional monitoring mechanisms, once cross-network data anomalies occur, it is often difficult to discover and locate them in a timely manner, and it is also difficult to flexibly adjust the monitoring strategy to adapt to business dynamics, thereby causing major hidden dangers to network security, stability and service quality assurance. SUMMARY

[0004] The FTTR network data anomaly analysis method, system and device provide an FTTR network cross-network data anomaly analysis scheme, and at least solve the problem that many enterprises now access the Internet through FTTR-B while conducting local area network networking, if only relying on traditional monitoring mechanisms, once cross-network data anomalies occur, it is often difficult to discover and locate them in a timely manner, and it is also difficult to flexibly adjust the monitoring strategy to adapt to business dynamics.

[0005] On the one hand, an FTTR network data anomaly analysis method is applied to an FTTR-B network, comprising:

[0006] obtain a local area network history behavior and an Internet history behavior of the target terminal device in the target FTTR network;

[0007] obtain a portrait of the target terminal device according to the local area network history behavior and the Internet history behavior;

[0008] analyze real-time data in the target FTTR network to obtain a target behavior of the target terminal device;

[0009] determine whether the target behavior is abnormal according to the target behavior and the portrait of the target terminal device.

[0010] Optionally, the obtaining of the local area network history behavior and the Internet history behavior of the target terminal device in the target FTTR network comprises:

[0011] obtaining a MAC address and / or an IP address of the target terminal device according to a unique identifier of the target terminal device in the target FTTR network;

[0012] obtaining the local area network history behavior and the Internet history behavior of the target terminal device in the target FTTR network according to the MAC address and / or the IP address of the target terminal device.

[0013] Optionally, the obtaining of the portrait of the target terminal device according to the local area network history behavior and the Internet history behavior comprises:

[0014] obtaining a connection frequency of the target terminal device with a local area network device in the target FTTR network and a feature of first data transmitted by the target terminal device according to the local area network history behavior;

[0015] obtaining a connection frequency of the target terminal device with an Internet device in the Internet and a feature of second data transmitted by the target terminal device according to the Internet history behavior;

[0016] obtaining a local area network label of the target terminal device according to the connection frequency of the target terminal device with the local area network device in the target FTTR network and the feature of the first data transmitted by the target terminal device;

[0017] obtaining an Internet label of the target terminal device according to the connection frequency of the target terminal device with the Internet device in the Internet and the feature of the second data transmitted by the target terminal device;

[0018] obtaining a cross-network filtering label of the target terminal device according to the first data and the second data, based on a difference between associated data in the first data and the second data;

[0019] obtaining the portrait of the target terminal device according to at least one of the local area network label, the Internet label and the cross-network filtering label of the target terminal device.

[0020] Optionally, according to the first data and the second data, a cross-network filtering label of the target terminal device is obtained based on a difference between the associated data in the first data and the second data, including:

[0021] According to the first data and the second data, based on semantic analysis and / or keyword matching, the data associated with at least part of the data in the first data in the second data is obtained as the fourth data;

[0022] According to the fourth data, the data associated with the fourth data in the first data is obtained as the third data;

[0023] According to the third data and the fourth data, the difference data of the third data and the fourth data is obtained;

[0024] According to the difference data of the third data and the fourth data, the cross-network filtering label of the target terminal device is obtained.

[0025] Optionally, the real-time data in the target FTTR network is parsed to obtain the target behavior of the target terminal device, including:

[0026] In response to receiving a connection request initiated by the source device, the connection request is parsed to obtain source device information and target device information, and a connection is established with the source device and the target device, respectively;

[0027] In response to receiving a data packet sent by the source device, the data packet is parsed to obtain the real-time behavior corresponding to the data packet;

[0028] When the target terminal device is one of the source device and the target device, the target behavior of the target terminal device is obtained according to the real-time behavior.

[0029] Optionally, according to the target behavior and the target terminal device portrait, it is judged whether the target behavior is abnormal, including:

[0030] All target behaviors of the target terminal device within a real-time time window are obtained through a sliding time window;

[0031] According to all target behaviors, the data transmission content corresponding to all target behaviors is obtained;

[0032] According to the data transmission content corresponding to all target behaviors, it is judged whether there is an associated behavior in all target behaviors;

[0033] When there is an associated behavior, it is judged whether the associated behavior belongs to a cross-network transmission behavior;

[0034] When the associated behavior belongs to a cross-network transmission behavior, it is judged whether the associated behavior is abnormal through the cross-network filtering label.

[0035] According to the cross-network filtering label of at least part of terminal devices in the target FTTR network, a data fence is established; the target terminal device belongs to the terminal device;

[0036] According to the data fence, data transmitted across the network in the target FTTR network is analyzed for abnormalities.

[0037] Optionally, the method further comprises:

[0038] When the target behavior is abnormal, a threat index of the target behavior is obtained according to the target behavior and / or data associated with the target behavior;

[0039] According to the threat index of the target behavior, the connection of the target terminal device with the local area network and / or the Internet is optionally cut off.

[0040] In another aspect, an FTTR network data anomaly analysis system is applied to an FTTR-B network for deployment, based on an FTTR gateway device and terminal devices connected to the FTTR gateway device:

[0041] The FTTR gateway device is configured to:

[0042] Obtain local area network historical behaviors and Internet historical behaviors of a target terminal device in a target FTTR network; the target terminal device belongs to the terminal device;

[0043] Obtain a portrait of the target terminal device according to the local area network historical behaviors and the Internet historical behaviors;

[0044] Obtain a target behavior of the target terminal device by analyzing real-time data in the target FTTR network;

[0045] Determine whether the target behavior is abnormal according to the target behavior and the portrait of the target terminal device.

[0046] In another aspect, a computer device comprises a memory and a processor, the memory stores a computer program, and the processor executes the computer program to implement the above method.

[0047] In another aspect, a computer storage medium stores a computer program, and a processor executes the computer program to implement the above method.

[0048] Compared with the prior art, the present application has the following advantages and beneficial effects:

[0049] The application discloses an FTTR network data anomaly analysis method, system and device, which is applied to an FTTR-B network and comprises the following steps: acquiring local area network historical behaviors and Internet historical behaviors of a target terminal device in a target FTTR network; obtaining a target terminal device portrait according to the local area network historical behaviors and the Internet historical behaviors; analyzing real-time data in the target FTTR network to obtain a target behavior of the target terminal device; and judging whether the target behavior is abnormal according to the target behavior and the target terminal device portrait. The application at least solves the problem that many enterprises access the Internet through FTTR-B while performing local area network networking, and it is difficult to find and locate data anomalies across networks in time and to flexibly adjust monitoring strategies to adapt to business dynamic changes if only relying on traditional monitoring mechanisms. BRIEF DESCRIPTION OF DRAWINGS

[0050] In order to more clearly illustrate the technical solutions in the specific embodiments or prior art of the present application, the drawings needed to be used in the specific embodiments or prior art description will be briefly introduced below. In all the drawings, similar elements or parts are generally identified by similar reference numerals. In the drawings, each element or part is not necessarily drawn according to the actual scale.

[0051] Figure 1 A flowchart of the FTTR network data anomaly analysis method in the application;

[0052] Figure 2 A structural schematic diagram of the device in the application.

[0053] In the drawings, 101 is a processor, 102 is a communication bus, 103 is a network interface, 104 is a user interface, and 105 is a memory.

[0054] The implementation, functional features and advantages of the application will be further described with reference to the drawings in combination with the embodiments. DETAILED DESCRIPTION

[0055] In order to enable those skilled in the art to better understand the present disclosure scheme, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in combination with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, not all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by those skilled in the art without creative labor should belong to the scope of protection of the present disclosure.

[0056] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0057] Embodiment 1

[0058] As Figure 1 shown, an FTTR network data anomaly analysis method applied to an FTTR-B network includes:

[0059] S1, obtaining local area network historical behavior and Internet historical behavior of a target terminal device in a target FTTR network.

[0060] In the FTTR network, the behavior of each terminal device has a certain regularity. In order to understand the normal behavior mode of the target device, it is necessary to first collect the historical behavior data of the device in the local area network and the Internet.

[0061] Optionally, the local area network historical behavior and the Internet historical behavior are behaviors of the target terminal device in data transmission and data exchange through the target FTTR network; further, each behavior in the local area network historical behavior and the Internet historical behavior includes a connection behavior and a data exchange behavior, the connection behavior can include connection object, connection duration and the like, and the data exchange behavior can include data exchange object, data exchange content and the like.

[0062] Specifically, the local area network behavior at least includes one or more of the following behaviors of the target terminal device in the local area network: communication history, access to internal network resources, and the like, such as accessing a shared folder, using a printer and the like office equipment.

[0063] Specifically, the Internet behavior at least includes one or more of the following behaviors: external website accessed by the device, use of external application, content of download / upload behavior, and the like.

[0064] S2, obtaining a target terminal device portrait according to the local area network historical behavior and the Internet historical behavior.

[0065] In the above steps, by analyzing the local area network history behavior and Internet history behavior of the target terminal device, a behavior portrait of the target terminal device, i.e., a target terminal device portrait, can be constructed. The behavior portrait of the target terminal device is a set of data or label sets describing the regular behavior characteristics of the device based on the historical behavior data of the device. Specifically, the target terminal device portrait can include typical activity patterns, behavior preferences, access periodicity, network resource consumption, etc.

[0066] Further, the device portrait can be further refined by machine learning or deep learning methods to make it more dynamic. When the behavior of the target terminal device changes, the target terminal device portrait will be automatically updated.

[0067] S3, analyzing real-time data in the target FTTR network to obtain the target behavior of the target terminal device.

[0068] In the above steps, by deep packet inspection (DPI) technology, the data flow in the network is analyzed in real time, and the data packets related to the target terminal device are identified through the header information of the data packets. Then, the current behavior of the target terminal device is analyzed according to the data packets related to the target terminal device.

[0069] S4, determining whether the target behavior is abnormal according to the target behavior and the target terminal device portrait.

[0070] In the above steps, by comparing the real-time behavior of the target terminal device with its historical behavior portrait, it is determined whether the current behavior deviates from the regular behavior pattern, and whether there is an abnormal behavior.

[0071] Optionally, the abnormality determination can be based on the target behavior of the target terminal device exceeding the range of the target terminal device portrait or conflicting with the label of the target terminal device portrait in some indicators, such as access frequency, data transmission volume, access time, data transmission content, etc.

[0072] Further, the determination of abnormal behavior is not limited to a single behavior pattern, but can also be based on the multidimensional changes of the behavior, such as time, frequency, resource usage, etc.

[0073] By means of the above scheme, the behavior portrait of the device is formed through the historical behavior of the target terminal device, the abnormal behavior of the target device can be accurately judged, the misjudgment and missed judgment problems in the traditional method are avoided, and the compatibility and accuracy of the abnormal identification are improved; meanwhile, the cross-network behavior of the FTTR internal network and the Internet can be processed, through comprehensive analysis of the behavior mode of the device in two different network environments, the problem that many enterprises access the Internet through FTTR-B while performing local area network networking is solved, if only relying on the traditional monitoring mechanism, once the cross-network data anomaly occurs, it is often difficult to find and locate in time, and it is also difficult to flexibly adjust the monitoring strategy to adapt to the dynamic changes of the business.

[0074] Embodiment 2

[0075] This embodiment is based on embodiment 1, a FTTR network data anomaly analysis method, applied to FTTR-B network, comprising:

[0076] S1, obtaining the local area network historical behavior and the Internet historical behavior of the target terminal device in the target FTTR network.

[0077] In the FTTR network, the behavior of each terminal device has certain regularity, in order to understand the normal behavior mode of the target device, the historical behavior data of the device in the local area network and the Internet needs to be collected first.

[0078] Optionally, the local area network historical behavior and the Internet historical behavior are behaviors of the target terminal device in data transmission and data exchange through the target FTTR network; further, each behavior in the local area network historical behavior and the Internet historical behavior includes connection behavior and data exchange behavior, the connection behavior can include connection object, connection duration and the like, and the data exchange behavior can include data exchange object, data exchange content and the like.

[0079] Specifically, the local area network behavior at least includes one or more of the following behaviors of the target terminal device in the local area network, such as accessing shared folders, using printers and other office equipment, etc.

[0080] Specifically, the Internet behavior at least includes one or more of the following behaviors, such as external website access, external application use, download / upload behavior content, etc.

[0081] Optionally, obtaining the local area network historical behavior and the Internet historical behavior of the target terminal device in the target FTTR network comprises:

[0082] According to the unique identifier of the target terminal device in the target FTTR network, the MAC address and / or IP address of the target terminal device are obtained;

[0083] According to the MAC address and / or IP address of the target terminal device, the local area network history behavior and the Internet history behavior of the target terminal device in the target FTTR network are obtained.

[0084] Optionally, the unique identifier of the target terminal device in the target FTTR network can be the unique identifier of the target terminal device, or the unique identifier of the user using the target terminal device.

[0085] S2, according to the local area network history behavior and the Internet history behavior, the target terminal device portrait is obtained.

[0086] In the above steps, by analyzing the local area network history behavior and the Internet history behavior of the target terminal device, the behavior portrait of the target terminal device, i.e., the target terminal device portrait, can be constructed. The behavior portrait of the target terminal device is a set of data sets or label sets describing the regular behavior characteristics of the device based on the historical behavior data of the device. Specifically, the target terminal device portrait can include typical activity patterns, behavior preferences, access periodicity, network resource consumption, etc.

[0087] Further, the device portrait can be further refined by machine learning or deep learning methods, so as to be more dynamic. When the behavior of the target terminal device changes, the target terminal device portrait will be automatically updated.

[0088] Optionally, according to the local area network history behavior and the Internet history behavior, the target terminal device portrait is obtained, including:

[0089] According to the local area network history behavior, the connection frequency of the target terminal device and the local area network device in the target FTTR network and the characteristics of the first data transmitted are obtained;

[0090] According to the Internet history behavior, the connection frequency of the target terminal device and the Internet device in the Internet and the characteristics of the second data transmitted are obtained;

[0091] According to the connection frequency of the target terminal device and the local area network device in the target FTTR network and the characteristics of the first data transmitted, the local area network label of the target terminal device is obtained;

[0092] According to the connection frequency of the target terminal device and the Internet device in the Internet and the characteristics of the second data transmitted, the Internet label of the target terminal device is obtained;

[0093] According to the first data and the second data, based on the difference of the associated data in the first data and the second data, the cross-network filtering label of the target terminal device is obtained;

[0094] According to at least one of the local area network label, the Internet label and the cross-network filtering label of the target terminal device, the target terminal device portrait is obtained.

[0095] Optionally, the LAN label and the Internet label at least include the connection frequency and / or the data type of the target terminal device to the devices in the LAN and the devices on the Internet. An example of a typical LAN label can be: LAN, printer A, 5-10 times per month, contract file; wherein LAN represents that the label is a LAN label, printer A represents the device connected by the target terminal device, 5-10 times per month represents the connection frequency, and contract file represents the data type. Further, printer A can be replaced by printer, at which time the label is used to represent the type of the device connected by the target terminal device, and overfitting can be avoided.

[0096] Optionally, according to the first data and the second data, the cross-network filtering label of the target terminal device is obtained based on the difference between the associated data in the first data and the second data, including:

[0097] According to the first data and the second data, the data associated with at least part of the data in the first data in the second data is obtained as the fourth data based on semantic analysis and / or keyword matching;

[0098] According to the fourth data, the data associated with the fourth data in the first data is obtained as the third data;

[0099] According to the third data and the fourth data, the difference data of the third data and the fourth data is obtained;

[0100] According to the difference data of the third data and the fourth data, the cross-network filtering label of the target terminal device is obtained.

[0101] Optionally, an example of a typical cross-network filtering label can be: cross-network filtering, ID number + age; wherein LAN represents that the label is a LAN label, and ID number + age represents data of ID number or age; further, ID number + age can be replaced by ID number + age + gender.

[0102] Optionally, an example of obtaining the cross-network filtering label of the target terminal device based on the difference between the associated data in the first data and the second data according to the first data and the second data, including:

[0103] According to the first data and the second data, wherein the first data can be "Xiaowang, ID number: 110101xxxxxxxx1234, age 28, currently living in B district of A city, working in a law firm; Xiaoli, ID number: 110101xxxxxxxx5678, age 25, currently living in B district of A city, working in an IT company", and the second data can be "Xiaozhao, currently living in C district of A city, working in an IT company; Xiaoli, currently living in B district of A city, working in an IT company", based on semantic analysis and / or keyword matching, the cosine similarity threshold is set to 50%, and the data associated with at least part of the data in the first data in the second data is obtained as fourth data, and the fourth data is "Xiaoli, currently living in B district of A city, working in an IT company";

[0104] According to the fourth data, the data associated with the fourth data in the first data is obtained as third data, and specifically, the third data is "Xiaoli, ID number: 110101xxxxxxxx5678, age 25, currently living in B district of A city, working in an IT company";

[0105] According to the third data and the fourth data, the difference data of the third data and the fourth data is obtained, and specifically, the difference data is "ID number: 110101xxxxxxxx5678, age 25";

[0106] According to the difference data of the third data and the fourth data, the cross-network filtering label of the target terminal device is obtained, and specifically, according to the difference data and the preset label classification, it can be obtained that the label corresponding to the difference data is ID number and age, and based on the label corresponding to the difference data, a typical cross-network filtering label: cross-network filtering, ID number+age can be obtained.

[0107] Optionally, the third data includes at least all the data of the fourth data.

[0108] Optionally, the local area network history behavior and the Internet history behavior are distinguished by the following method:

[0109] In response to receiving a connection request initiated by a device, the connection request is parsed to obtain source device information and target device information, and a connection is established with the source device and the target device, respectively;

[0110] When the source device and the target device of the data packet are both terminal devices in the target FTTR network, the data in the data packet is obtained as local area network behavior data, and when one of the source device and the target device of the data packet is another device on the Internet, the data in the data packet is obtained as Internet behavior data.

[0111] S3, parse real-time data in the target FTTR network to obtain target behavior of the target terminal device.

[0112] In the above steps, the data flow in the network is analyzed in real time through deep packet inspection (DPI) technology, the data packet related to the target terminal device is identified through the header information of the data packet, and the current behavior of the target terminal device is analyzed according to the data packet related to the target terminal device.

[0113] Optionally, the real-time data in the target FTTR network is analyzed to obtain the target behavior of the target terminal device, including:

[0114] In response to receiving a connection request initiated by the source device, the connection request is analyzed to obtain source device information and target device information, and a connection is established with the source device and the target device, respectively;

[0115] In response to receiving a data packet sent by the source device, the data packet is analyzed to obtain the real-time behavior corresponding to the data packet;

[0116] When the target terminal device is one of the source device and the target device, the target behavior of the target terminal device is obtained according to the real-time behavior.

[0117] S4, according to the target behavior and the target terminal device portrait, it is judged whether the target behavior is abnormal.

[0118] In the above steps, by comparing the real-time behavior of the target terminal device with its historical behavior portrait, it is judged whether the current behavior deviates from the regular behavior pattern, and whether there is an abnormal behavior.

[0119] Optionally, the abnormality judgment can be based on the target behavior of the target terminal device exceeding the range of the target terminal device portrait or conflicting with the label of the target terminal device portrait in some indicators, such as access frequency, data transmission volume, access time, data transmission content, etc.

[0120] Further, the judgment of abnormal behavior is not limited to a single behavior pattern, but can also be based on the multidimensional changes of the behavior, such as time, frequency, resource use, etc.

[0121] Optionally, according to the target behavior and the target terminal device portrait, it is judged whether the target behavior is abnormal, including:

[0122] All target behaviors of the target terminal device within the real-time time window are obtained through a sliding time window;

[0123] According to all target behaviors, the data transmission content corresponding to all target behaviors is obtained;

[0124] According to the data transmission content corresponding to all target behaviors, it is judged whether there is an associated behavior in all target behaviors;

[0125] When the association behavior exists, judging whether the association behavior belongs to the cross-network transmission behavior;

[0126] When the association behavior belongs to the cross-network transmission behavior, judging whether the association behavior exists abnormally through the cross-network filtering label.

[0127] Since many network behaviors, especially the behaviors of cross-network transmission, cannot be recognized by a single behavior and need to be comprehensively recognized by considering behaviors in a period of time, we obtain all target behaviors in a real-time time window, i.e., in a real-time sliding time window, to comprehensively recognize the target behaviors, so as to solve the above problems.

[0128] Optionally, the method further comprises the following steps:

[0129] According to the cross-network filtering label of at least part of the terminal devices in the target FTTR network, a data fence is established; the target terminal device belongs to the terminal devices;

[0130] According to the data fence, data transmitted in the target FTTR network is analyzed abnormally.

[0131] Optionally, according to the cross-network filtering label of at least part of the terminal devices in the target FTTR network, a data fence is established, comprising at least one of the following methods:

[0132] According to the cross-network filtering label of at least part of the terminal devices in the target FTTR network, the cross-network filtering label is directly configured as a filtering label of the data fence to establish the data fence;

[0133] Specifically, if the cross-network filtering label of the terminal device A is an ID number and an age, and the cross-network filtering label of the terminal device B is an ID number and a gender, the cross-network filtering label is directly configured as a filtering label of the data fence, i.e., the filtering label of the data fence is an ID number, an age, and a gender;

[0134] According to the cross-network filtering label of at least part of the terminal devices in the target FTTR network, the cross-network filtering label is classified and expanded to obtain an expanded filtering label, and the expanded filtering label is configured as a filtering label of the data fence to establish the data fence;

[0135] Specifically, if the cross-network filtering label of the terminal device A is an ID number and shopping data, and the cross-network filtering label of the terminal device A is an ID number, a gender, and a mobile phone number, the cross-network filtering label is classified and expanded to obtain an expanded filtering label, including personal information, contact information, and commercial data, and the expanded filtering label is configured as a filtering label of the data fence, i.e., the filtering label of the data fence is all labels under the personal information, the contact information, and the commercial data.

[0136] Data fence is a method for data protection, the core idea of which is to isolate and monitor sensitive data by setting a virtual or physical "fence", so as to realize effective filtering and protection of sensitive data; the key to filtering sensitive data by using data fence is to set restrictions and rules to ensure that sensitive data can only be processed and accessed in authorized environments. In order to filter sensitive data by using data fence, it is necessary to first determine which data is sensitive data, such as personal information, contact information, financial data or company business secrets, research and development data, etc. By means of data classification, data tagging and other technical means, sensitive data and non-sensitive data are distinguished, so as to facilitate subsequent filtering and protection. For the present scheme, the data filtered out by the target terminal device when transmitting data from the internal network to the external network, i.e. the difference data, is generally sensitive data. Further, the present scheme tags sensitive data with labels for identification and filtering during processing and transmission. Further, by classifying and expanding the cross-network filtering labels, the reliability of the data fence can be further improved, and the existence of sensitive data that cannot be covered by the data fence due to the limitations of the historical data of different terminal devices can be avoided.

[0137] Optionally, the method further comprises:

[0138] When the target behavior is abnormal, a threat index of the target behavior is obtained according to the target behavior and / or data associated with the target behavior.

[0139] According to the threat index of the target behavior, the connection between the target terminal device and the local area network and / or the Internet can be optionally cut off.

[0140] Optionally, after the step of cutting off the connection between the target terminal device and the local area network and / or the Internet according to the threat index of the target behavior, the method further comprises:

[0141] When the connection between the target terminal device and the local area network is cut off, a mirror device of the target terminal device is configured in the local area network, and all requests directed to the target terminal device are redirected to the mirror device, so as to ensure the stability of the local area network.

[0142] Optionally, the method further comprises:

[0143] According to the abnormality degree of at least part of the terminal devices in the target FTTR network, a risk index of the target FTTR network is obtained based on a preset index system.

[0144] By adopting the above scheme, the problem that if only relying on a traditional monitoring mechanism, once cross-network data abnormity occurs, it is often difficult to discover and locate in time and to flexibly adjust the monitoring strategy to adapt to business dynamic changes is further solved, the security of cross-network transmission data of enterprises is improved, and external threats can be effectively prevented from attacking the internal LAN of enterprises by using devices with cross-network data transmission authority.

[0145] Embodiment 3

[0146] This embodiment is based on embodiments 1 and 2, and is a FTTR network data abnormity analysis system, which is applied to FTTR-B network for deployment, based on FTTR gateway device and terminal device connected with the FTTR gateway device:

[0147] The FTTR gateway device is configured to:

[0148] Obtain the LAN history behavior and the Internet history behavior of the target terminal device in the target FTTR network; the target terminal device belongs to the terminal device;

[0149] Obtain the portrait of the target terminal device according to the LAN history behavior and the Internet history behavior;

[0150] Obtain the target behavior of the target terminal device by analyzing real-time data in the target FTTR network;

[0151] Judge whether the target behavior is abnormal according to the target behavior and the portrait of the target terminal device.

[0152] Optionally, obtaining the LAN history behavior and the Internet history behavior of the target terminal device in the target FTTR network comprises:

[0153] Obtain the MAC address and / or IP address of the target terminal device according to the unique identifier of the target terminal device in the target FTTR network;

[0154] Obtain the LAN history behavior and the Internet history behavior of the target terminal device in the target FTTR network according to the MAC address and / or IP address of the target terminal device.

[0155] Optionally, obtaining the portrait of the target terminal device according to the LAN history behavior and the Internet history behavior comprises:

[0156] Obtain the connection frequency of the target terminal device and the LAN device in the target FTTR network and the characteristics of the first data transmitted according to the LAN history behavior of the target terminal device;

[0157] Obtain the connection frequency of the target terminal device and the Internet device in the Internet and the characteristics of the second data transmitted according to the Internet history behavior of the target terminal device;

[0158] obtaining a LAN label of the target terminal device according to a connection frequency of the target terminal device with a LAN device in the target FTTR network and a feature of first data transmitted;

[0159] obtaining an Internet label of the target terminal device according to a connection frequency of the target terminal device with an Internet device in the Internet and a feature of second data transmitted;

[0160] obtaining a cross-network filtering label of the target terminal device according to the first data and the second data, based on a difference between associated data in the first data and the second data;

[0161] obtaining a portrait of the target terminal device according to at least one of the LAN label, the Internet label and the cross-network filtering label of the target terminal device.

[0162] Optionally, the obtaining of the cross-network filtering label of the target terminal device according to the first data and the second data, based on the difference between the associated data in the first data and the second data, comprises:

[0163] obtaining, according to the first data and the second data, fourth data associated with at least part of the data in the first data in the second data based on semantic analysis and / or keyword matching;

[0164] obtaining, according to the fourth data, third data associated with the fourth data in the first data;

[0165] obtaining, according to the third data and the fourth data, difference data of the third data and the fourth data;

[0166] obtaining the cross-network filtering label of the target terminal device according to the difference data of the third data and the fourth data.

[0167] Optionally, the obtaining of the target behavior of the target terminal device by analyzing real-time data in the target FTTR network comprises:

[0168] in response to receiving a connection request initiated by a source device, analyzing the connection request to obtain source device information and target device information, and establishing a connection with the source device and the target device respectively;

[0169] in response to receiving a data packet sent by the source device, analyzing the data packet to obtain real-time behavior corresponding to the data packet;

[0170] when the target terminal device is one of the source device and the target device, obtaining the target behavior of the target terminal device according to the real-time behavior.

[0171] Optionally, the judging of whether the target behavior is abnormal according to the target behavior and the portrait of the target terminal device comprises:

[0172] obtaining all target behaviors of the target terminal device in the real-time time window through a sliding time window;

[0173] obtaining data transmission content corresponding to the all target behaviors according to the all target behaviors;

[0174] judging whether there is an associated behavior in the all target behaviors according to the data transmission content corresponding to the all target behaviors;

[0175] judging whether the associated behavior belongs to a cross-network transmission behavior when the associated behavior exists;

[0176] judging whether the associated behavior is abnormal through a cross-network filtering tag when the associated behavior belongs to the cross-network transmission behavior.

[0177] Optionally, the method further comprises:

[0178] establishing a data fence according to the cross-network filtering tag of at least part of the terminal devices in the target FTTR network; the target terminal device belongs to the terminal devices;

[0179] performing abnormal analysis on data transmitted in the target FTTR network according to the data fence.

[0180] Optionally, the method further comprises:

[0181] obtaining a threat index of the target behavior according to the target behavior and / or data associated with the target behavior when the target behavior is abnormal;

[0182] selectively cutting off the connection between the target terminal device and the local area network and / or the Internet according to the threat index of the target behavior.

[0183] Embodiment 4

[0184] The embodiment provides a device, the computer device comprising a memory and a processor, the memory storing a computer program, and the processor executing the computer program to implement any of the above methods.

[0185] Specifically, as shown in Figure 2 , the method comprises the following steps. Figure 2As shown in a structural schematic diagram of an apparatus in the present application, the computer device can include a processor 101, such as a central processing unit (CPU), a communication bus 102, a user interface 104, a network interface 103, and a memory 105. The communication bus 102 is used to realize the connection and communication between the components. The user interface 104 can include a display, an input unit such as a keyboard, and can further include a standard wired interface, a wireless interface. The network interface 103 can optionally include a standard wired interface, a wireless interface (such as a wireless fidelity (WIreless-FIdelity, WI-FI) interface). The memory 105 can be a storage device independent of the aforementioned processor 101, and can be a high-speed random access memory (RAM) memory, or a stable non-volatile memory (NVM), such as at least one disk memory; the processor 101 can be a general-purpose processor, including a central processing unit, a network processor, etc., and can also be a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, a discrete hardware component.

[0186] Those skilled in the art can understand that the structures shown in the present application do not constitute a limitation on electronic devices, and can include more or fewer components than the drawings, or combine certain components, or different component arrangements. Figure 2

[0187] As shown in the memory 105 as a storage medium, the memory 105 can include an operating system, a network communication module, a user interface module, and an application program for implementing an FTTR network data anomaly analysis method. Figure 2

[0188] In the electronic device shown in the present application, the network interface 103 is mainly used for data communication with a network server; the user interface 104 is mainly used for data interaction with a user; the processor 101 and the memory 105 in the present application can be arranged in the electronic device, and the electronic device calls the application program stored in the memory 105 for implementing an FTTR network data anomaly analysis method through the processor 101 to realize the above method. Figure 2 Embodiment 5

[0189] The present embodiment provides a computer readable storage medium, and the computer readable storage medium stores a computer program, and a processor executes the computer program to realize any of the above methods.

[0190] ​​​

[0191] In some embodiments, the computer readable storage medium can be FRAM, ROM, PROM, EPROM, EEPROM, flash memory, magnetic surface memory, optical disc, or CD-ROM memory, etc. It can also be various devices including one or any combination of the above memories. The computer can be various computing devices including smart terminals and servers.

[0192] In the above embodiments of the present disclosure, the description of each embodiment is focused on, and the parts not described in detail in a certain embodiment can be referred to the relevant description of other embodiments.

[0193] In several embodiments provided in the present application, it should be understood that the disclosed technical contents can be implemented by other ways. Among them, the above-described device embodiments are only schematic, for example, the division of units can be a logical function division, and actual implementation can have another division way, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point, the coupling or direct coupling or communication connection between the units or modules shown or discussed can be indirect coupling or communication connection through some interfaces, and can be electrical or other forms.

[0194] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed to multiple units. Part or all of the units can be selected according to actual needs to achieve the purpose of the present embodiment scheme.

[0195] In addition, each functional unit in each embodiment of the present disclosure can be integrated in one processing unit, or each unit can exist physically independently, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of software functional unit.

[0196] The integrated unit, if implemented in the form of a software function unit and sold or used as an independent product, can be stored in a computer-readable nonvolatile storage medium. Based on such understanding, the technical solutions of the present disclosure, essentially or in other words, the part that contributes to the prior art or the whole or part of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a nonvolatile storage medium, including a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute all or part of the steps of the methods in the various embodiments of the present disclosure. The aforementioned nonvolatile storage medium includes: a U disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store program codes.

[0197] The above is only the preferred embodiment of the present disclosure, and it should be pointed out that for those skilled in the art, without departing from the principles of the present disclosure, a number of improvements and refinements can be made, and these improvements and refinements should be considered as the protection scope of the present disclosure.

Claims

1. An FTTR network data anomaly analysis method, characterized in that, Applied to FTTR-B network, comprising: Obtaining the local area network history behavior and the Internet history behavior of the target terminal device in the target FTTR network; According to the local area network history behavior, obtaining the connection frequency of the target terminal device and the local area network device in the target FTTR network and the characteristics of the first data transmitted; According to the Internet history behavior, obtaining the connection frequency of the target terminal device and the Internet device in the Internet and the characteristics of the second data transmitted; According to the first data and the second data, based on semantic analysis and / or keyword matching, obtaining the data associated with at least part of the data in the first data in the second data as the fourth data; According to the fourth data, obtaining the data associated with the fourth data in the first data as the third data; According to the third data and the fourth data, obtaining the difference data of the third data and the fourth data; According to the difference data of the third data and the fourth data, obtaining the cross-network filtering label of the target terminal device; According to the cross-network filtering label of the target terminal device, obtaining the target terminal device portrait; Analyzing real-time data in the target FTTR network to obtain the target behavior of the target terminal device; According to the target behavior and the target terminal device portrait, judging whether the target behavior is abnormal. 2.The FTTR network data anomaly analysis method of claim 1, wherein, Obtaining the local area network history behavior and the Internet history behavior of the target terminal device in the target FTTR network, comprising: According to the unique identifier of the target terminal device in the target FTTR network, obtaining the MAC address and / or IP address of the target terminal device; According to the MAC address and / or IP address of the target terminal device, obtaining the local area network history behavior and the Internet history behavior of the target terminal device in the target FTTR network. 3.The FTTR network data anomaly analysis method of claim 1, wherein, Analyzing real-time data in the target FTTR network to obtain the target behavior of the target terminal device, comprising: In response to receiving a connection request initiated by a source device, parsing the connection request to obtain source device information and target device information, and establishing a connection with the source device and the target device respectively; In response to receiving a data packet sent by the source device, parsing the data packet to obtain real-time behavior corresponding to the data packet; When the target terminal device is one of the source device and the target device, according to the real-time behavior, obtaining the target behavior of the target terminal device.

4. The FTTR network data anomaly analysis method of claim 1, wherein, According to the target behavior and the target terminal device portrait, judging whether the target behavior is abnormal, comprising: Obtaining all target behaviors of the target terminal device within a real-time time window through a sliding time window; According to all target behaviors, obtaining the data transmission content corresponding to all target behaviors; According to the data transmission content corresponding to all target behaviors, judging whether there is an associated behavior in all target behaviors; When there is an associated behavior, judging whether the associated behavior belongs to cross-network transmission behavior; When the associated behavior belongs to cross-network transmission behavior, judging whether the associated behavior is abnormal through the cross-network filtering label.

5. The FTTR network data anomaly analysis method of claim 4, wherein, Further comprising: According to the cross-network filtering label of at least part of the terminal devices in the target FTTR network, establishing a data fence; The target terminal device belongs to the terminal device; According to the data fence, performing abnormal analysis on the data transmitted across the network in the target FTTR network.

6. The FTTR network data anomaly analysis method of claim 1, wherein, Further comprising: When the target behavior is abnormal, a threat index of the target behavior is obtained according to the target behavior and / or data associated with the target behavior; According to the threat index of the target behavior, the connection of the target terminal device with the local area network and / or the Internet can be selected to be cut off.

7. An FTTR network data anomaly analysis system, characterized in that, The application is applied to FTTR-B network for deployment, based on FTTR gateway device and terminal device connected with the FTTR gateway device: The FTTR gateway device is configured to: Obtain the local area network history behavior and the Internet history behavior of the target terminal device in the target FTTR network; the target terminal device belongs to the terminal device; According to the local area network history behavior, obtain the connection frequency of the target terminal device with the local area network device in the target FTTR network and the characteristics of the first data transmitted; According to the Internet history behavior, obtain the connection frequency of the target terminal device with the Internet device in the Internet and the characteristics of the second data transmitted; According to the first data and the second data, based on semantic analysis and / or keyword matching, obtain the data associated with at least part of the data in the first data in the second data as the fourth data; According to the fourth data, obtain the data associated with the fourth data in the first data as the third data; According to the third data and the fourth data, obtain the difference data of the third data and the fourth data; According to the difference data of the third data and the fourth data, obtain the cross-network filtering label of the target terminal device; According to the cross-network filtering label of the target terminal device, obtain the target terminal device portrait; Parse real-time data in the target FTTR network to obtain the target behavior of the target terminal device; According to the target behavior and the target terminal device portrait, judge whether the target behavior is abnormal.

8. An apparatus, comprising: The device includes a memory and a processor, the memory stores a computer program, and the processor executes the computer program to realize the method of any one of claims 1-6.

Citation Information

Patent Citations

  • Network communication method and device, electronic equipment and nonvolatile storage medium

    CN117692711A

  • Cross-platform shared data security protection method and device

    CN120074936A