Enterprise-level network equipment abnormal flow control method and device, equipment and medium
By receiving and analyzing network traffic data, performing initial anomaly filtering and detection, and time-series adaptive protection, the problem of enterprise-level network devices being unable to identify new types of attacks is solved. This enables full-domain control over known and unknown abnormal traffic, reducing potential threat risks.
Patent Information
- Application Number
- CN202511674022.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-14
- Publication Date
- 2026-02-10
AI Technical Summary
Existing enterprise-level network equipment cannot flexibly respond to new attacks or abnormal traffic patterns in abnormal traffic control, resulting in malicious traffic not being identified and blocked in a timely manner, increasing the potential threat risks to enterprise-level network equipment.
By receiving network traffic data from a preset mirror port, performing initial anomaly filtering and adaptive protection against temporal variations, and combining initial anomaly detection information with dynamic anomaly perception information, the system implements full-domain inbound anomaly control for enterprise-level network devices, identifying and blocking known and unknown anomaly traffic.
It effectively reduces the risk of malicious traffic not being identified and blocked in a timely manner, and lowers the potential threat risks to enterprise-level network devices, such as the risk of security incidents and device downtime.
Smart Images

Figure CN121508969A_ABST
Abstract
Description
Technical Field
[0001] The embodiments disclosed herein relate to the field of computer technology, and more specifically to methods, apparatus, devices, and media for abnormal traffic control of enterprise-level network devices. Background Technology
[0002] Modern enterprises have extremely high requirements for the real-time performance and stability of their networks. Abnormal traffic can lead to business interruptions, impacting user experience and corporate reputation. Therefore, abnormal traffic control for enterprise-level network devices is particularly important. Enterprise-level network device abnormal traffic control is a technology for controlling abnormal traffic within network devices. Currently, the common approach to controlling abnormal traffic in network devices is to identify and control abnormal traffic through traffic detection technology using static signature databases (such as virus signatures and malicious IP blacklists).
[0003] However, when using the above methods to identify and control abnormal traffic on network devices, the following technical problems often arise: Traffic detection technologies that rely on static signature databases (such as virus signatures and malicious IP blacklists) to identify and control abnormal traffic on network devices often only detect known attack and abnormal traffic patterns. They depend on static, predefined attack signatures or IP address lists and cannot flexibly respond to new attack or abnormal traffic patterns. As a result, malicious traffic is not identified and blocked in a timely manner, which in turn increases the potential threat risks to enterprise-level network devices (such as increased risks of security incidents, data breaches, and device downtime).
[0004] The information disclosed in this background section is only intended to enhance the understanding of the background of the inventive concept, and therefore may contain information that does not form prior art known to those skilled in the art. Summary of the Invention
[0005] The summary portion of this disclosure is intended to provide a brief overview of the concepts, which will be described in detail in the detailed description portion. This summary portion is not intended to identify key or essential features of the claimed technical solutions, nor is it intended to limit the scope of the claimed technical solutions.
[0006] Some embodiments of this disclosure provide enterprise-level network device abnormal traffic control methods, apparatuses, electronic devices, and computer-readable media to address one or more of the technical problems mentioned in the background section above.
[0007] In a first aspect, some embodiments of this disclosure provide a method for abnormal traffic control of an enterprise-level network device. The method includes: receiving mirror network traffic data corresponding to a preset enterprise-level network device from a preset mirror port, wherein the mirror network traffic data includes an inflow sub-data sequence; performing initial anomaly filtering detection processing on the inflow sub-data sequence to obtain initial filtering anomaly detection information; performing time-series implicit change adaptive protection processing on the inflow sub-data sequence based on the initial filtering anomaly detection information to obtain dynamic anomaly perception information; and performing full-domain abnormal traffic inbound control processing on the preset enterprise-level network device based on the initial filtering anomaly detection information and the dynamic anomaly perception information.
[0008] Secondly, some embodiments of this disclosure provide an abnormal traffic control device for an enterprise-level network device. The device includes: a receiving unit configured to receive mirror network traffic data corresponding to a preset enterprise-level network device from a preset mirror port, wherein the mirror network traffic data includes an inflow sub-data sequence; an abnormal initial filtering detection unit configured to perform abnormal initial filtering detection processing on the inflow sub-data sequence to obtain initial filtering abnormal detection information; a time-series implicit change adaptive protection unit configured to perform time-series implicit change adaptive protection processing on the inflow sub-data sequence based on the initial filtering abnormal detection information to obtain dynamic abnormal perception information; and a control unit configured to perform full-domain abnormal traffic inbound control processing on the preset enterprise-level network device based on the initial filtering abnormal detection information and the dynamic abnormal perception information.
[0009] Thirdly, some embodiments of this disclosure provide an electronic device, including: one or more processors; and a storage device having one or more programs stored thereon, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any implementation of the first aspect above.
[0010] Fourthly, some embodiments of this disclosure provide a computer-readable medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the method described in any of the implementations of the first aspect above.
[0011] The above-described embodiments of this disclosure have the following beneficial effects: the abnormal traffic control method for enterprise-level network devices according to some embodiments of this disclosure reduces the potential threat risks to enterprise-level network devices. Specifically, the reason for the increase in potential threat risks to enterprise-level network devices is that traffic detection technology based on static signature databases (such as virus signatures, malicious IP blacklists) can only detect known attack and abnormal traffic patterns. It relies on static, predefined attack signatures or IP address lists and cannot flexibly respond to new attack or abnormal traffic patterns, resulting in malicious traffic not being identified and intercepted in a timely manner, thus increasing the potential threat risks to enterprise-level network devices (such as increased risks of security incidents, data leaks, and device downtime). Based on this, the abnormal traffic control method for enterprise-level network devices according to some embodiments of this disclosure first receives mirror network traffic data corresponding to a preset enterprise-level network device from a preset mirror port, wherein the mirror network traffic data includes an inflow sub-data sequence. Thus, network traffic data from the preset mirror port corresponding to the preset enterprise-level network device can be received. Then, the inflow sub-data sequence is subjected to initial anomaly filtering detection processing to obtain initial filtering anomaly detection information. Therefore, through initial anomaly filtering and detection, known anomalies or attack patterns can be quickly identified, yielding initial anomaly detection information. Next, based on this initial anomaly detection information, time-series covert adaptive protection processing is applied to the incoming sub-data sequences, resulting in dynamic anomaly perception information. This allows for the use of time-series covert adaptive protection processing to identify unknown attack patterns or covert attacks that static features cannot detect, obtaining dynamic anomaly perception information and achieving defense against unknown or covert attacks, thus significantly reducing the risk of malicious traffic not being identified and intercepted in a timely manner. Finally, based on the initial anomaly detection information and the dynamic anomaly perception information, full-domain inbound anomaly traffic control processing is performed on the aforementioned preset enterprise-level network devices. Thus, by combining initial anomaly detection information and dynamic anomaly perception information, full-domain control of inbound traffic to network devices can be achieved, realizing both control of known attack anomaly traffic and defense against unknown or covert attack anomaly traffic, thereby significantly reducing the risk of malicious traffic not being identified and intercepted in a timely manner, effectively mitigating potential threat risks to enterprise-level network devices (such as security incidents or device downtime) caused by the failure to identify malicious traffic in a timely manner. Attached Figure Description
[0012] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and elements are not necessarily drawn to scale.
[0013] Figure 1This is a flowchart of some embodiments of the enterprise-level network device abnormal traffic control method according to this disclosure; Figure 2 These are schematic diagrams of some embodiments of the enterprise-level network device abnormal flow control device according to this disclosure; Figure 3 This is a schematic diagram of the structure of an electronic device suitable for implementing some embodiments of the present disclosure. Detailed Implementation
[0014] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.
[0015] It should also be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings. Unless otherwise specified, the embodiments and features described in this disclosure can be combined with each other.
[0016] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.
[0017] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".
[0018] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.
[0019] This disclosure will now be described in detail with reference to the accompanying drawings and embodiments.
[0020] Figure 1 A flow 100 of some embodiments of an enterprise-level network device abnormal traffic control method according to the present disclosure is shown. This enterprise-level network device abnormal traffic control method includes the following steps: Step 101: Receive mirror network traffic data corresponding to the preset enterprise-level network device from the preset mirror port.
[0021] In some embodiments, the implementing entity of the enterprise-level network device abnormal traffic control method (e.g., a network security device) can receive mirrored network traffic data corresponding to a preset enterprise-level network device from a preset mirror port. The mirrored network traffic data includes an inflow sub-data sequence. The preset enterprise-level network device can be a physical or virtual device (e.g., a switch, router, etc.) designed and manufactured to meet the operational needs of medium to large organizations (such as enterprises, governments, schools, data centers) for connecting, transmitting, managing, amplifying, or protecting data signals. The preset mirror port can be a physical port configured on the preset enterprise-level network device. The physical port is used to replicate the original traffic of the popular preset enterprise-level network device. The inflow sub-data sequence can be a sequence arranged according to the timestamps corresponding to the inflow sub-data. Each inflow sub-data in the inflow sub-data sequence includes a timestamp, source address information, destination address information, source port information, destination port information, protocol information, protocol flags, and packet length information. The timestamp can be the time the packet was captured. The source address information can be the IP address that sent the packet to the preset enterprise-level network device. The destination address information can be the IP address of the pre-defined enterprise network device receiving the data packet. The source port information can represent the port number of the application or process responsible for sending the data stream on the sending device. The destination port information can be the port number (e.g., port 80 or 443) of the application or service to which the data packet is sent on the pre-defined enterprise network device. The protocol information can represent the communication protocol type used by the data packet, such as TCP, UDP, ICMP, etc. The protocol flags can be flags from the TCP protocol (e.g., SYN, ACK, FIN, RST, etc.). The data packet length indicates the size of the data packet (in bytes). The data packet length information can be the data packet length.
[0022] Step 102: Perform initial anomaly filtering and detection on the incoming sub-data sequence to obtain initial anomaly detection information.
[0023] In some embodiments, the aforementioned execution entity may perform anomaly initial filtering detection processing on the aforementioned inflow sub-data sequence to obtain initial filtering anomaly detection information.
[0024] In some optional implementations of certain embodiments, the aforementioned execution entity may perform initial anomaly filtering and detection processing on the aforementioned inflow sub-data sequence through the following steps to obtain initial anomaly detection information: The first step is to divide the above-mentioned inflow sub-data sequence into inflow sub-data group sequences based on a preset sliding window length and a preset sliding step size. For example, the preset sliding window length and the preset sliding step size can both be 100. The above-mentioned inflow sub-data sequence can be {inflow sub-data 1, ..., inflow sub-data 100, ..., inflow sub-data 200}. The inflow sub-data group sequences can be {{inflow sub-data 1, ..., inflow sub-data 99, inflow sub-data 100}, {inflow sub-data 101, ..., inflow sub-data 199, inflow sub-data 200}}.
[0025] The second step involves performing the following steps based on the incoming sub-data group sequence: The first sub-step involves performing the following steps for the first incoming sub-data group in the incoming sub-data sequence: In sub-step one, each inflow sub-data in the aforementioned inflow sub-data group undergoes protocol decoding anomaly detection processing to obtain port abuse inflow sub-data, thereby generating protocol decoding anomaly detection information as initial filtering anomaly detection sub-information. In practice, the aforementioned execution entity can determine the protocol information included in the inflow sub-data. Then, the aforementioned execution entity can obtain at least one port number corresponding to the aforementioned protocol information from a preset service file. Next, in response to determining that the port number represented by the target port information included in the inflow sub-data does not exist among the aforementioned at least one port number, the aforementioned execution entity can determine the source address information included in the inflow sub-data. Next, the aforementioned execution entity can determine the anomaly type information using a first preset anomaly type identifier. Then, the aforementioned execution entity can determine the source address information and the anomaly type information as protocol decoding anomaly detection information. The aforementioned first preset anomaly type identifier can be "initial filtering anomaly".
[0026] Sub-step two involves deleting the obtained inflow sub-data from at least one port abuse source, resulting in an inflow sub-data group after removing at least one port abuse source data as the inflow sub-data group to be clustered.
[0027] Sub-step three involves identifying at least one inflow sub-data group from the above-mentioned inflow sub-data group that has the same source port information, the same source address information, and the same target port information as a clustered inflow sub-data group.
[0028] Sub-step four involves performing attack anomaly detection processing on the determined clustered inflow sub-data clusters to obtain attack anomaly detection information as initial filtering anomaly detection sub-information. In practice, the aforementioned execution entity can determine the timestamps included in each inflow sub-data to be clustered in the clustered inflow sub-data cluster as target timestamps. Then, the aforementioned execution entity can determine the earliest timestamp among the target timestamps as the first timestamp. The latest timestamp among the target timestamps is determined as the second timestamp. Then, the time interval between the second timestamp and the first timestamp is determined as the target time interval. Then, the aforementioned execution entity can determine the number of clustered inflow sub-data in the clustered inflow sub-data cluster and the aforementioned target time interval as the flow rate. In response to determining that the flow rate is greater than a preset flow rate (e.g., 100 data entries / second), the aforementioned execution entity can determine the source address information and the first preset anomaly type identifier included in one clustered inflow sub-data cluster as attack anomaly detection information.
[0029] The second sub-step involves determining the obtained initial filter anomaly detection sub-information as the initial filter anomaly detection information.
[0030] Step 103: Based on the initial filtering anomaly detection information, perform time-series implicit change adaptive protection processing on the incoming sub-data sequence to obtain dynamic anomaly perception information.
[0031] In some embodiments, the execution entity may perform temporal implicit variation adaptive protection processing on the incoming sub-data sequence based on the aforementioned initial filtering anomaly detection information to obtain dynamic anomaly perception information. The aforementioned initial filtering anomaly detection information includes various initial filtering anomaly detection sub-information, each of which includes source address information and anomaly type information. The anomaly type information can be an anomaly type identifier.
[0032] In some optional implementations of certain embodiments, the aforementioned execution entity may perform temporal implicit variation adaptive protection processing on the aforementioned inflow sub-data sequence based on the aforementioned initial filtering anomaly detection information through the following steps to obtain dynamic anomaly perception information: The first step is to identify the source address information included in the initial filtering anomaly detection information as the anomaly source address information.
[0033] The second step is to update the above-mentioned inflow sub-data sequence based on the above-mentioned abnormal source address information, so as to obtain the updated inflow sub-data sequence.
[0034] The third step involves performing covert attack identification processing on the updated incoming sub-data sequence to obtain covert attack identification information. This covert attack identification information includes various covert attack identification sub-information, each of which includes source address information and anomaly type information.
[0035] Fourth, based on the aforementioned covert attack identification information, adaptive anomaly detection processing is performed on the aforementioned updated inflow sub-data sequence to obtain unknown anomaly detection information.
[0036] The fifth step is to identify the aforementioned covert attack identification information and the aforementioned unknown anomaly detection information as dynamic anomaly perception information.
[0037] In some optional implementations of certain embodiments, the aforementioned execution entity may update the aforementioned inflow sub-data sequence based on the aforementioned anomaly source address information through the following steps to obtain the updated inflow sub-data sequence: The first step is to iterate through the above-mentioned inflow sub-data sequence for each of the above-mentioned abnormal source address information, and delete at least one inflow sub-data that contains the above-mentioned abnormal source address information in the inflow sub-data sequence, so as to update the inflow sub-data sequence.
[0038] The second step is to determine the updated inflow sub-data sequence as the updated inflow sub-data sequence.
[0039] In addressing the technical challenges mentioned above, the application scenario of identifying covert attacks on enterprise-level network devices often presents the following challenges: Based on IP clustering and deep aggregation of behavior from the same source IP, covert attacks can be identified. However, the same source IP may exhibit different behavioral characteristics across different applications or services (different source ports). While traffic from the same source IP is typically analyzed as a single entity, different source ports may represent different service types with varying traffic, behavioral, and protocol characteristics. Ignoring these differences can lead to inaccurate covert attack identification, making it easy to miss attacks disguised within massive amounts of normal traffic, thus increasing the potential threat to enterprise-level network devices. This application scenario requires the following characteristics: It should be suitable for attacks that are concealed within massive amounts of normal traffic. To address these challenges, we have decided to adopt the following solution: In some optional implementations of certain embodiments, the aforementioned execution entity can perform covert attack identification processing on the updated inflow sub-data sequence through the following steps to obtain covert attack identification information: The first step is to group the update inflow sub-data sequences that contain the same source address information and the same source port information into a group to obtain each update inflow sub-data group; The second step is to perform the following steps for each of the above update inflow sub-data groups: The first sub-step involves determining the source address information included in one of the updated inflow sub-data groups as the target source address information. The second sub-step involves generating frequency characteristic information corresponding to the aforementioned update inflow sub-data groups. In practice, the executing entity can identify at least one update inflow sub-data group whose communication protocol type is TCP, as represented by the protocol information, as each target update inflow sub-data group. Then, the executing entity can determine the number of target update inflow sub-data groups with the protocol flag bit marked as SYN as the total number of requests, which serves as the frequency characteristic information.
[0040] The third sub-step involves generating traffic characteristic information corresponding to the aforementioned updated inflow sub-data group. In practice, the executing entity can determine the total number of bytes sent by summing the lengths of each data packet represented by the length information of each data packet included in the updated inflow sub-data group. Then, the executing entity can determine the average data packet length by the ratio of the total number of bytes sent to the number of updated inflow sub-data packets in the updated inflow sub-data group. Finally, the executing entity can determine the traffic characteristic information by combining the total number of bytes sent and the average data packet length.
[0041] The fourth sub-step involves generating behavioral distribution feature information corresponding to the aforementioned updated inflow sub-data group. In practice, the executing entity can determine the target port information included in the updated inflow sub-data group. Then, the executing entity can perform deduplication on each target port information. Next, the executing entity can determine the number of target port information in the deduplicated target port information as the total number of port distributions. Then, for each target port information in the deduplicated target port information, the executing entity can determine the port entropy value using the entropy value of the port represented by the target port information among the ports represented by the aforementioned target port information. Then, the executing entity can determine the total number of port distributions and the entropy values of each port as behavioral distribution feature information. As an example, each target port information can be "[80, 443, 443, 8080, 22, 22, 22, 445, 445]". The deduplicated target port information can be "[80, 443, 8080, 22, 445]".
[0042] The fifth sub-step involves generating protocol feature information corresponding to the aforementioned updated inflow sub-data group. In practice, the executing entity can deduplicate the various protocol information items included in the updated inflow sub-data group to obtain individual deduplicated protocol information items. Then, for each deduplicated protocol information item, the executing entity can determine the deduplicated protocol information item and its proportion within the total protocol information as protocol feature sub-information. Finally, the executing entity can define these determined protocol feature sub-information items as the protocol feature information.
[0043] The sixth sub-step involves generating feature snapshot information corresponding to the updated inflow sub-data group based on the aforementioned frequency feature information, traffic feature information, behavioral distribution feature information, and protocol feature information. In practice, the frequency feature information, traffic feature information, behavioral distribution feature information, and protocol feature information can be input into the autoencoder to obtain a feature vector combining these features, which serves as the feature snapshot information. Optionally, the executing entity can sequentially concatenate the frequency feature information, traffic feature information, behavioral distribution feature information, and protocol feature information to convert them into a vector as the feature snapshot information.
[0044] The seventh sub-step involves obtaining a baseline profile from the aforementioned preset enterprise-level network device, corresponding to the target source address information and source port information. This baseline profile can be a feature vector representing the behavioral characteristics (such as frequency characteristics, traffic characteristics, behavioral distribution characteristics, and protocol characteristics) of the device corresponding to the target source address information communicating with the preset enterprise-level network device in the application or service represented by the source port information under normal network activity conditions. This baseline profile can be obtained based on statistical analysis of a large amount of historical data.
[0045] The eighth sub-step involves generating covert attack identification sub-information corresponding to the target source address information, based on the aforementioned feature snapshot information and baseline profile. In practice, firstly, the similarity between the feature snapshot information and the baseline profile information can be determined as the target similarity. Then, in response to determining that the target similarity is less than a preset similarity, the executing entity can determine a second preset anomaly type identifier as anomaly type information. Then, the aforementioned target source address information and the determined anomaly type information can be used to determine the covert attack identification sub-information. The aforementioned second preset anomaly type identifier can be an identifier representing a covert attack (e.g., covert attack).
[0046] The third step is to identify each generated covert attack identification sub-information as covert attack identification information.
[0047] The above technical solution, combined with step 104 and related content, serves as an inventive point of this disclosure, addressing the technical problem that "the disguised behavior of attacks is easily missed in massive amounts of normal traffic, increasing the potential threat risk to enterprise-level network devices." Factors contributing to this increased risk often include: IP clustering and deep aggregation of behavior from the same source IP to identify covert attacks; the same source IP may exhibit different behavioral characteristics across different applications or services (different source ports); traffic from the same source IP is typically analyzed as a whole, but different source ports may represent different service types with varying traffic, behavioral, and protocol characteristics. Ignoring these differences can lead to poor accuracy in covert attack identification, making the disguised behavior of attacks easily missed in massive amounts of normal traffic, thus increasing the potential threat risk to enterprise-level network devices. Solving these factors can reduce the risk of disguised attacks being missed in massive amounts of normal traffic and reduce the potential threat risk to enterprise-level network devices. To achieve this effect, firstly, update inflow sub-data sequences containing the same source address and source port information are grouped together to obtain various update inflow sub-data groups. This allows update inflow sub-data to be grouped based on the same source address and source port information. Then, for each update inflow sub-data group, the following steps are performed: First, the source address information included in one update inflow sub-data within the group is determined as the target source address information. Then, frequency feature information corresponding to the update inflow sub-data group is generated. This allows frequency feature information (e.g., the total number of requests for that service type within a certain time) to be generated under the same source address and source port information, corresponding to the service type. Then, traffic feature information corresponding to the update inflow sub-data group is generated. This allows traffic feature information representing traffic characteristics (e.g., total number of bytes sent, average packet length) under the service type corresponding to the source port information of that group to be generated. Finally, behavioral distribution feature information corresponding to the update inflow sub-data group is generated. Therefore, behavioral distribution characteristic information under the service type corresponding to the source port information of the packet can be generated. Then, protocol characteristic information corresponding to the aforementioned updated inflow sub-data group is generated. Thus, protocol characteristic information of different protocols used by the service type of this packet can be generated. Then, based on the aforementioned frequency characteristic information, traffic characteristic information, behavioral distribution characteristic information, and protocol characteristic information, feature snapshot information corresponding to the aforementioned updated inflow sub-data group is generated.Therefore, multiple dimensions of features (frequency feature information, the aforementioned traffic feature information, the aforementioned behavior distribution feature information, and the aforementioned protocol feature information) can be fused into a feature vector or snapshot to obtain feature snapshot information. Next, a baseline profile corresponding to the aforementioned target source address information and source port information is obtained from the aforementioned preset enterprise-level network device. Thus, a normal behavior profile of the application or service represented by the source IP and source port information under the preset enterprise-level network device can be read. Based on the aforementioned feature snapshot information and the aforementioned baseline profile, covert attack identification sub-information corresponding to the aforementioned target source address information is generated. Therefore, it is possible to compare the baseline profile with the "multi-dimensional" features of "homogeneous" traffic (same IP, same port), taking into account the multi-dimensional features (frequency feature information, the aforementioned traffic feature information, the aforementioned behavior distribution feature information, and the aforementioned protocol feature information) of the same IP and same port, more accurately identifying abnormal situations that do not conform to normal behavior patterns, obtaining more accurate covert attack identification sub-information, and reducing the risk that disguised attack behavior is easily missed in massive normal traffic. Each generated covert attack identification sub-information is determined as covert attack identification information. This allows for the acquisition of more accurate covert attack identification information. Combining this with step 104, based on the aforementioned initial filtering anomaly detection information and dynamic anomaly perception information, comprehensive abnormal traffic inbound control processing is performed on the aforementioned preset enterprise-level network devices. Therefore, comprehensive abnormal traffic inbound control processing can be performed based on dynamic anomaly perception information that includes more accurate covert attack identification information, reducing potential threat risks to enterprise-level network devices.
[0048] In some optional implementations of certain embodiments, the aforementioned execution entity may perform adaptive anomaly detection processing on the aforementioned incoming update sub-data sequence based on the aforementioned covert attack identification information through the following steps to obtain unknown anomaly detection information: The first step is to identify each source address information included in the above covert attack identification information as a reference source address information.
[0049] The second step is to delete each update input sub-data that contains the aforementioned reference source address information in the update input sub-data sequence, so as to update the aforementioned update input sub-data sequence.
[0050] The third step involves adaptive anomaly detection processing on the updated inflow sub-data sequence to obtain unknown anomaly detection information. In practice, the execution entity can use the DBSCAN clustering algorithm to cluster the updated inflow sub-data sequence, obtaining at least one updated inflow sub-data cluster. Then, the execution entity can identify the updated inflow sub-data clusters that meet preset filtering conditions as unknown anomaly updated inflow sub-data clusters. The preset filtering condition can be minimizing the number of included updated inflow sub-data. Next, the execution entity can identify each source address information included in the unknown anomaly updated inflow sub-data cluster as an unknown anomaly source address information. Then, the execution entity can identify a first preset anomaly type identifier as the anomaly type information corresponding to each unknown anomaly source address information. Next, for each unknown anomaly source address information, the execution entity can identify the unknown anomaly source address information and the anomaly type information as unknown anomaly detection sub-information. Finally, the determined unknown anomaly detection sub-information can be identified as unknown anomaly detection information.
[0051] In addressing the technical problems mentioned above, the application scenario of identifying covert attacks on enterprise-level network devices often presents the following challenges: directly clustering the updated inflow sub-data sequence for adaptive anomaly detection mixes a large amount of normal and abnormal data, interfering with the clustering results and making it difficult to accurately identify truly abnormal data. The updated inflow sub-data is the data after initial filtering for anomaly detection and covert attack identification. Normal inflow sub-data constitutes the majority of the updated inflow sub-data sequence, potentially masking the characteristics of unknown abnormal traffic. This results in low efficiency and accuracy of adaptive anomaly detection, making it difficult to promptly identify and intercept new, unknown malicious traffic, thus increasing the potential threat risks to enterprise-level network devices. This application scenario requires the following characteristics: suitability for detecting new, unknown malicious traffic. Faced with these technical problems, we have decided to adopt the following solution: In some optional implementations of certain embodiments, the aforementioned execution entity can perform adaptive anomaly detection processing on the updated incoming sub-data sequence through the following steps to obtain unknown anomaly detection information: The first step is to determine the source address information of each source included in the updated incoming sub-data sequence as the set of source address information to be deduplicated.
[0052] The second step is to deduplicate the source address information mentioned above to obtain a deduplicated source address information set.
[0053] Third, based on the aforementioned deduplication source address information set, the updated inflow sub-data in the aforementioned updated inflow sub-data sequence is grouped to obtain at least one updated inflow sub-data group. Each updated inflow sub-data group corresponds to one deduplication source address in the aforementioned deduplication source address information set. For each deduplication source address in the aforementioned deduplication source address information set, at least one updated inflow sub-data in the updated inflow sub-data sequence containing the aforementioned deduplication source address is determined as an updated inflow sub-data group.
[0054] Fourth, for each of the at least one updated inflow sub-data groups mentioned above, generate the average packet length and port entropy information corresponding to the updated inflow sub-data group. In practice, the execution entity can determine the average packet length as the mean of the length information of each data packet included in the updated inflow sub-data group. Then, the execution entity can determine the target port information set as the target port information set as the target port information set. Next, the target port information set can be deduplicated to obtain a deduplicated target port information set. For each deduplicated target port information in the deduplicated target port information set, the frequency of the deduplicated target port information in the target port information set can be determined as the target frequency. Then, the execution entity can arrange the target frequencies from smallest to largest to obtain a target frequency sequence. Then, the target frequency sequence can be input into a preset port entropy calculation formula to obtain the port entropy as the port entropy information. The preset port entropy calculation formula uses... It can be represented as: Indicates the target frequency sequence of the th Target frequency, This can be the number of target port information in the target port information set. It can be the number of target frequencies in the target frequency sequence.
[0055] Fifth, in response to determining that the average packet length meets the first preset condition and the port entropy information meets the second preset condition, the updated inflow sub-data group is identified as a candidate abnormal inflow sub-data group. The first preset condition can be a packet length greater than a preset value. The second preset condition can be that the port entropy represented by the port entropy information is less than a first preset threshold (e.g., 1), indicating uneven traffic distribution concentrated on a few ports.
[0056] The sixth step involves generating a feature matrix corresponding to each of the identified candidate anomaly inflow sub-data groups. In practice, the execution entity can employ feature engineering techniques to convert the candidate anomaly inflow sub-data groups into feature matrices.
[0057] Step 7: Perform clustering analysis on the generated feature matrices to generate at least one abnormal inflow sub-data group. In practice, the DBSCAN clustering algorithm can be used to cluster the feature matrices to obtain at least one feature matrix cluster. In response to determining that at least one feature matrix cluster contains only one feature matrix, the feature matrix cluster containing only one feature matrix is identified as the target feature matrix cluster. For each target feature matrix cluster identified, the candidate abnormal inflow sub-data group corresponding to the target feature matrix cluster included in the target feature matrix cluster is identified as the abnormal inflow sub-data group.
[0058] Step 8: Based on the aforementioned at least one abnormal inflow sub-data group, generate unknown anomaly detection information. This unknown anomaly detection information includes at least one unknown anomaly detection sub-information, and each of these sub-information includes source address information and anomaly type information. In practice, for each of the aforementioned at least one abnormal inflow sub-data group, the executing entity can determine the third preset anomaly type identifier as the anomaly type information corresponding to that sub-data group. Then, the executing entity can determine the source address information and the anomaly type information corresponding to a single abnormal inflow sub-data group as unknown anomaly detection sub-information. Finally, the determined at least one unknown anomaly detection sub-information can be defined as unknown anomaly detection information.
[0059] The above technical solution, combined with step 104 and related content, serves as an inventive point of this disclosure, solving the technical problem that "unknown malicious traffic is not easily identified and intercepted in a timely manner, thus increasing the potential threat risk to enterprise-level network devices." Factors leading to increased potential threat risks to enterprise-level network devices often include: directly clustering the updated incoming sub-data sequence for adaptive anomaly detection processing mixes a large amount of normal and abnormal data, causing the clustering results to be interfered with by normal data, making it difficult to accurately identify truly abnormal data. The updated incoming sub-data is data after initial filtering anomaly detection and covert attack identification processing. Normal incoming sub-data constitutes the majority of the updated incoming sub-data sequence, potentially masking the characteristics of unknown abnormal traffic. The low detection efficiency and accuracy of adaptive anomaly detection make it difficult to identify and intercept new, unknown malicious traffic in a timely manner, thus increasing the potential threat risk to enterprise-level network devices. Solving these factors can further reduce the potential threat risk to enterprise-level network devices. To achieve this effect, firstly, the source address information included in the updated incoming sub-data sequence is determined as the set of source address information to be deduplicated. Next, the source address information is deduplicated to obtain a deduplicated source address information set. Based on this deduplicated source address information set, the updated inflow sub-data in the updated inflow sub-data sequence is grouped to obtain at least one updated inflow sub-data group, wherein each updated inflow sub-data group corresponds to one deduplicated source address in the deduplicated source address information set. Thus, massive, mixed inflow data sequences can be reorganized into structured groups according to their source address information, resulting in at least one updated inflow sub-data group. Then, for each updated inflow sub-data group, average packet length and port entropy information corresponding to that updated inflow sub-data group are generated. Subsequently, in response to determining that the average packet length meets a first preset condition and the port entropy information meets a second preset condition, the updated inflow sub-data group is identified as a candidate abnormal inflow sub-data group. Therefore, by filtering using average packet length and port entropy, those meeting the conditions can be identified as candidate abnormal inflow sub-data groups, which helps to filter potential abnormal traffic from a large amount of data, i.e., to filter candidate abnormal inflow sub-data groups. Then, for each of the identified candidate anomaly inflow sub-data groups, a feature matrix corresponding to that candidate anomaly inflow sub-data group is generated. Next, clustering analysis is performed on each generated feature matrix to generate at least one anomaly inflow sub-data group. Thus, clustering can be performed on a pre-screened, high-purity candidate anomaly dataset through clustering analysis.Since the input feature matrices already possess strong anomalous attributes, the clustering algorithm can more clearly divide these anomalous behaviors into different groups based on their inherent similarity. This allows for efficient identification of new malicious traffic even when facing complex traffic, distinguishing it from normal traffic and obtaining at least one anomalous inflow sub-data group. Subsequently, based on the aforementioned at least one anomalous inflow sub-data group, unknown anomaly detection information is generated. This unknown anomaly detection information includes at least one unknown anomaly detection sub-information, each of which includes source address information and anomaly type information. Furthermore, because the adaptive anomaly detection process for the updated inflow sub-data sequence employs a method of first grouping by source address and then performing rapid pre-screening using average packet length and port entropy, the scale of data requiring clustering is significantly reduced, improving the processing efficiency of adaptive anomaly detection. Meanwhile, by using the feature matrix corresponding to the selected candidate abnormal data group and performing cluster analysis, unknown anomaly detection information is generated. This avoids interference from a large amount of normal data on anomaly detection and improves the accuracy of unknown anomaly detection information. Combined with step 104, it can perform full-domain abnormal traffic inbound control processing based on dynamic anomaly perception information with higher accuracy unknown anomaly detection information, thereby reducing potential threat risks to enterprise-level network equipment.
[0060] Step 104: Based on the initial filtering anomaly detection information and dynamic anomaly perception information, perform full-domain anomaly traffic inbound control processing on the preset enterprise-level network devices.
[0061] In some embodiments, the aforementioned execution entity may perform full-domain abnormal traffic inbound control processing on the aforementioned preset enterprise-level network device based on the aforementioned initial filtering anomaly detection information and the aforementioned dynamic anomaly perception information.
[0062] In some optional implementations of certain embodiments, the aforementioned execution entity may perform full-domain abnormal traffic inbound control processing on the aforementioned preset enterprise-level network device based on the aforementioned initial filtering anomaly detection information and the aforementioned dynamic anomaly perception information through the following steps: The first step is to control the preset enterprise-level network device to intercept and discard data packets or network requests corresponding to the source address information included in the above-mentioned initial filtering anomaly detection information for each of the initial filtering anomaly detection sub-information.
[0063] The second step involves performing the following temporary isolation process on each covert attack identification sub-information included in the aforementioned dynamic anomaly detection information: The first sub-step involves obtaining the list of isolation zone ports corresponding to the aforementioned preset enterprise-level network devices. This isolation zone port list can be a pre-defined set of port numbers. These ports are designated as isolation zones to restrict network access from specific sources, preventing potential attacks from entering the preset enterprise-level network devices through these ports.
[0064] The second sub-step involves generating port access isolation control information for a preset time period based on the aforementioned isolation zone port list and the aforementioned covert attack identification sub-information. In practice, rule engine technology can be used to populate a preset rule template with the source address information included in the isolation zone port list and the covert attack identification sub-information as parameters. This preset rule template with populated parameters is then defined as the port access isolation control information. This port access isolation control information can be a structured instruction that specifies an access control rule. For example, the port access isolation control information could be: "Within the [preset time period], deny any access requests from the IP address [source address information] represented by the source address information included in the covert attack identification sub-information to all ports in the [isolation zone port list]."
[0065] The third sub-step involves sending the aforementioned port access isolation control information to the aforementioned preset enterprise-level network device, so that the preset enterprise-level network device can prevent the address corresponding to the source address information in the aforementioned covert attack identification sub-information from establishing communication with at least one port corresponding to the isolation zone port list.
[0066] The third step involves sending at least one unknown anomaly detection sub-information included in the aforementioned dynamic anomaly perception information to a preset security terminal associated with the aforementioned preset enterprise-level network device. The preset security terminal can be a terminal device used to receive the unknown anomaly detection sub-information from the dynamic anomaly perception information.
[0067] The above-described embodiments of this disclosure have the following beneficial effects: the abnormal traffic control method for enterprise-level network devices according to some embodiments of this disclosure reduces the potential threat risks to enterprise-level network devices. Specifically, the reason for the increase in potential threat risks to enterprise-level network devices is that traffic detection technology based on static signature databases (such as virus signatures, malicious IP blacklists) can only detect known attack and abnormal traffic patterns. It relies on static, predefined attack signatures or IP address lists and cannot flexibly respond to new attack or abnormal traffic patterns, resulting in malicious traffic not being identified and intercepted in a timely manner, thus increasing the potential threat risks to enterprise-level network devices (such as increased risks of security incidents, data leaks, and device downtime). Based on this, the abnormal traffic control method for enterprise-level network devices according to some embodiments of this disclosure first receives mirror network traffic data corresponding to a preset enterprise-level network device from a preset mirror port, wherein the mirror network traffic data includes an inflow sub-data sequence. Thus, network traffic data from the preset mirror port corresponding to the preset enterprise-level network device can be received. Then, the inflow sub-data sequence is subjected to initial anomaly filtering detection processing to obtain initial filtering anomaly detection information. Therefore, through initial anomaly filtering and detection, known anomalies or attack patterns can be quickly identified, yielding initial anomaly detection information. Next, based on this initial anomaly detection information, time-series covert adaptive protection processing is applied to the incoming sub-data sequences, resulting in dynamic anomaly perception information. This allows for the use of time-series covert adaptive protection processing to identify unknown attack patterns or covert attacks that static features cannot detect, obtaining dynamic anomaly perception information and achieving defense against unknown or covert attacks, thus significantly reducing the risk of malicious traffic not being identified and intercepted in a timely manner. Finally, based on the initial anomaly detection information and the dynamic anomaly perception information, full-domain inbound anomaly traffic control processing is performed on the aforementioned preset enterprise-level network devices. Thus, by combining initial anomaly detection information and dynamic anomaly perception information, full-domain control of inbound traffic to network devices can be achieved, realizing both control of known attack anomaly traffic and defense against unknown or covert attack anomaly traffic, thereby significantly reducing the risk of malicious traffic not being identified and intercepted in a timely manner, effectively mitigating potential threat risks to enterprise-level network devices (such as security incidents or device downtime) caused by the failure to identify malicious traffic in a timely manner.
[0068] Further reference Figure 2 As an implementation of the methods shown in the figures, this disclosure provides some embodiments of an enterprise-level network device abnormal traffic control device, which are similar to... Figure 1 Corresponding to the method embodiments shown, the device can be specifically applied to various electronic devices.
[0069] like Figure 2As shown, an enterprise-level network device abnormal traffic control device 200 in some embodiments includes: a receiving unit 201, an abnormal initial filtering detection unit 202, a time-series implicit change adaptive protection unit 203, and a control unit 204. The receiving unit is configured to receive mirror network traffic data corresponding to a preset enterprise-level network device from a preset mirror port, wherein the mirror network traffic data includes an inflow sub-data sequence; the abnormal initial filtering detection unit is configured to perform abnormal initial filtering detection processing on the inflow sub-data sequence to obtain initial filtering abnormal detection information; the time-series implicit change adaptive protection unit is configured to perform time-series implicit change adaptive protection processing on the inflow sub-data sequence based on the initial filtering abnormal detection information to obtain dynamic abnormal perception information; and the control unit is configured to perform full-domain abnormal traffic inbound control processing on the preset enterprise-level network device based on the initial filtering abnormal detection information and the dynamic abnormal perception information.
[0070] It is understandable that the units described in the device 200 are related to the reference. Figure 1 The steps in the method described above correspond to each other. Therefore, the operations, features, and beneficial effects described above for the method also apply to the device 200 and the units contained therein, and will not be repeated here.
[0071] The following is for reference. Figure 3 It shows a schematic diagram of the structure of an electronic device 300 suitable for implementing some embodiments of the present disclosure. Figure 3 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments of this disclosure.
[0072] like Figure 3 As shown, the electronic device 300 may include a processing unit (e.g., a central processing unit, a graphics processing unit, etc.) 301, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 302 or a program loaded from a storage device 308 into a random access memory (RAM) 303. The RAM 303 also stores various programs and data required for the operation of the electronic device 300. The processing unit 301, ROM 302, and RAM 303 are interconnected via a bus 304. An input / output (I / O) interface 305 is also connected to the bus 304.
[0073] Typically, the following devices can be connected to I / O interface 305: input devices 306 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 307 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 308 including, for example, magnetic tapes, hard disks, etc.; and communication devices 309. Communication device 309 allows electronic device 300 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 3 An electronic device 300 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively. Figure 3 Each box shown can represent a device or multiple devices as needed.
[0074] In particular, according to some embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, some embodiments of this disclosure include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via communication device 309, or installed from storage device 308, or installed from ROM 302. When the computer program is executed by processing device 301, it performs the functions defined in the methods of some embodiments of this disclosure.
[0075] It should be noted that, in some embodiments of this disclosure, the computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium may be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In some embodiments of this disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In some embodiments of this disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.
[0076] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future-developed networks.
[0077] The computer-readable medium may be contained within an electronic device or may exist independently, not assembled into the electronic device. The computer-readable medium carries one or more programs that, when executed by the electronic device, cause the electronic device to: receive mirror network traffic data corresponding to a preset enterprise-level network device from a preset mirror port, wherein the mirror network traffic data includes an inflow sub-data sequence; perform initial anomaly filtering and detection processing on the inflow sub-data sequence to obtain initial filtering anomaly detection information; based on the initial filtering anomaly detection information, perform time-series implicit adaptive protection processing on the inflow sub-data sequence to obtain dynamic anomaly perception information; and based on the initial filtering anomaly detection information and the dynamic anomaly perception information, perform full-domain abnormal traffic inbound control processing on the preset enterprise-level network device.
[0078] Computer program code for performing operations of some embodiments of this disclosure can be written in one or more programming languages or a combination thereof. Programming languages include object-oriented programming languages—such as Java, Smalltalk, and C++—and conventional procedural programming languages—such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0079] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0080] The units described in some embodiments of this disclosure can be implemented in software or hardware. The described units can also be housed in a processor; for example, a processor may be described as including a receiving unit, an anomaly initial filtering detection unit, a timing-based adaptive protection unit, and a control unit. The names of these units do not necessarily limit the specific unit; for example, the receiving unit may also be described as "a unit that receives mirrored network traffic data corresponding to a preset enterprise-level network device from a preset mirror port."
[0081] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), and so on.
[0082] The above description is merely a selection of preferred embodiments of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of the invention involved in the embodiments of this disclosure is not limited to technical solutions formed by specific combinations of technical features, but should also cover other technical solutions formed by arbitrary combinations of technical features or their equivalents without departing from the inventive concept. For example, technical solutions formed by substituting features with (but not limited to) technical features with similar functions disclosed in the embodiments of this disclosure.
Claims
1. A method for controlling abnormal traffic in enterprise-level network devices, comprising: Receive mirror network traffic data corresponding to a preset enterprise-level network device from a preset mirror port, wherein the mirror network traffic data includes an incoming sub-data sequence; The incoming sub-data sequence is subjected to initial anomaly filtering and detection processing to obtain initial anomaly detection information; Based on the initial filtering anomaly detection information, the incoming sub-data sequence is subjected to time-series implicit change adaptive protection processing to obtain dynamic anomaly perception information. Based on the initial filtering anomaly detection information and the dynamic anomaly perception information, the preset enterprise-level network device is subjected to full-domain abnormal traffic inbound control processing.
2. The method according to claim 1, wherein, Each inflow sub-data in the inflow sub-data sequence includes a timestamp, source address information, destination address information, source port information, destination port information, protocol information, protocol flag, and data packet length information. The initial anomaly detection processing performed on the inflow sub-data sequence yields initial anomaly detection information, including: Based on a preset sliding window length and a preset sliding step size, the inflow sub-data sequence is divided to obtain an inflow sub-data group sequence; Based on the inflow sub-data group sequence, perform the following steps: For the first inflow sub-data group in the inflow sub-data sequence, perform the following steps: Each inflow sub-data in the inflow sub-data group is subjected to protocol decoding anomaly detection processing to obtain port abuse inflow sub-data, so as to generate protocol decoding anomaly detection information as initial filtering anomaly detection sub-information; Remove the inflow sub-data from the inflow sub-data group after removing the inflow sub-data from the port abuse sub-data group, and obtain the inflow sub-data group after removing the inflow sub-data from the port abuse sub-data group as the inflow sub-data group to be clustered. At least one inflow sub-data group to be clustered that has the same source port information, the same source address information and the same target port information is identified as a clustered inflow sub-data cluster. Attack anomaly detection processing is performed on the determined clustered inflow sub-data clusters to obtain attack anomaly detection information as the initial filtering anomaly detection sub-information; The obtained sub-information of each initial filter anomaly detection is determined as the initial filter anomaly detection information.
3. The method according to claim 1, wherein, The initial filtering anomaly detection information includes various initial filtering anomaly detection sub-information, each of which includes source address information and anomaly type information. Furthermore, based on the initial filtering anomaly detection information, the incoming sub-data sequence undergoes temporal implicit variation adaptive protection processing to obtain dynamic anomaly perception information, including: The source address information included in the initial filtering anomaly detection information is determined as the anomaly source address information; Based on the address information of each anomaly source, the inflow sub-data sequence is updated to obtain the updated inflow sub-data sequence; The incoming updated sub-data sequence is processed for covert attack identification to obtain covert attack identification information. Based on the covert attack identification information, adaptive anomaly detection processing is performed on the updated inflow sub-data sequence to obtain unknown anomaly detection information; The covert attack identification information and the unknown anomaly detection information are identified as dynamic anomaly perception information.
4. The method according to claim 3, wherein, The step of updating the inflow sub-data sequence based on the address information of each anomaly source to obtain the updated inflow sub-data sequence includes: For each abnormal source address information in the various abnormal source address information, the inflow sub-data sequence is traversed, and at least one inflow sub-data containing the abnormal source address information is deleted in the inflow sub-data sequence to update the inflow sub-data sequence; The updated inflow sub-data sequence is determined as the updated inflow sub-data sequence.
5. The method according to claim 3, wherein, The covert attack identification information includes various covert attack identification sub-information. Each of the covert attack identification sub-information includes source address information and anomaly type information. Furthermore, based on the covert attack identification information, adaptive anomaly detection processing is performed on the updated inflow sub-data sequence to obtain unknown anomaly detection information, including: Each source address information included in the covert attack identification information is determined as a reference source address information; Delete each update-inflow sub-data that contains the reference source address information in the update-inflow sub-data sequence in order to update the update-inflow sub-data sequence; Adaptive anomaly detection processing is performed on the updated incoming sub-data sequence to obtain unknown anomaly detection information.
6. The method according to claim 1, wherein, The dynamic anomaly perception information includes covert attack identification information and unknown anomaly detection information. The initial filtering anomaly detection information includes various initial filtering anomaly detection sub-information, each of which includes source address information. The covert attack identification information includes various covert attack identification sub-information, each of which includes source address information. The unknown anomaly detection information includes at least one unknown anomaly detection sub-information, each of which includes source address information. The process of performing full-domain abnormal traffic inbound control on the preset enterprise-level network device based on the initial filtering anomaly detection information and the dynamic anomaly perception information includes: For each sub-information of the initial filtering anomaly detection information, the preset enterprise-level network device is controlled to intercept and discard data packets or network requests corresponding to the source address information included in the initial filtering anomaly detection sub-information. For each covert attack identification sub-information included in the dynamic anomaly perception information, the following temporary isolation process is performed: Obtain the list of isolated zone ports corresponding to the preset enterprise-level network device; Based on the list of isolated ports and the covert attack identification sub-information, port access isolation control information for a preset time period is generated. The port access isolation control information is sent to the preset enterprise-level network device so that the preset enterprise-level network device can prevent the address corresponding to the source address information in the covert attack identification sub-information from establishing communication with at least one port corresponding to the isolation zone port list; At least one unknown anomaly detection sub-information included in the dynamic anomaly perception information is sent to a preset security terminal associated with the preset enterprise-level network device.
7. An enterprise-level network device abnormal traffic control device, comprising: The receiving unit is configured to receive mirror network traffic data corresponding to a preset enterprise-level network device from a preset mirror port, wherein the mirror network traffic data includes an incoming sub-data sequence; An anomaly initial filtering detection unit is configured to perform anomaly initial filtering detection processing on the incoming sub-data sequence to obtain initial filtering anomaly detection information; The temporal implicit change adaptive protection unit is configured to perform temporal implicit change adaptive protection processing on the incoming sub-data sequence based on the initial filtering anomaly detection information to obtain dynamic anomaly perception information. The control unit is configured to perform full-domain abnormal traffic inbound control processing on the preset enterprise-level network device based on the initial filtering abnormality detection information and the dynamic abnormality perception information.
8. An electronic device, comprising: One or more processors; A storage device on which one or more programs are stored; When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any one of claims 1 to 6.
9. A computer-readable medium having a computer program stored thereon, wherein, When the program is executed by the processor, it implements the method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Detection method for network flow classification abnormity based on DBSCAN
CN114398971A
Network attack detection method and device and electronic equipment
CN120110728A
Network security threat research and judgment method, system and equipment and storage medium
CN120880765A