A network data processing method

By predicting session health status and adjusting the network configuration parameter set, the problem of real-time maintenance of session health status in existing technologies is solved, enabling proactive maintenance of abnormal states and improving the protection and adaptability of cleaning equipment.

CN121530868BActive Publication Date: 2026-05-26HANGZHOU YOUYUN TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HANGZHOU YOUYUN TECH CO LTD
Filing Date
2026-01-14
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Existing cleaning equipment struggles to maintain session health in real time when faced with rapidly changing attack characteristics, leading to session delays, packet loss, or connection interruptions.

Method used

By determining the session's predicted health status at the next moment, and adjusting the network configuration parameter set based on the predicted health status, a closed-loop iterative mechanism for defense strategies is constructed to achieve proactive maintenance of abnormal states.

Benefits of technology

It effectively shortens attack response time, improves the system's adaptability and protection continuity in complex attack environments, and dynamically adjusts defense strategies to cope with constantly changing complex attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121530868B_ABST
    Figure CN121530868B_ABST
Patent Text Reader

Abstract

This application discloses a network data processing method, comprising: receiving traffic data at the current moment and performing defense detection on the traffic data; if the defense detection is passed, extracting a first data feature and a second data feature of the traffic data, and determining the session to which the traffic data belongs based on the first data feature; for each moment of a preset time period, determining a set of evaluation index values ​​at that moment based on the second data feature of all traffic data belonging to the session within a sliding window up to that moment and with a duration equal to the preset time period; determining the actual health status of the session at the current moment based on the set of evaluation index values ​​at the current moment, and determining the predicted health status of the session at the next moment; maintaining / adjusting the current values ​​of the system's network configuration parameter set based on the actual health status and the predicted health status, and updating the predicted health status. This application adjusts the network configuration parameter set based on the predicted health status, which can maintain the session health status in a timely manner.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security, and in particular to a network data processing method. Background Technology

[0002] With the rapid development of Internet technology, cyberattacks have become a major challenge threatening network stability and business continuity.

[0003] To address this issue, existing technologies typically deploy cleaning equipment between the client and the server. The cleaning equipment relies on preset defense strategies to identify and block abnormal traffic, and after determining that the traffic is normal, it performs health status maintenance on the corresponding session.

[0004] However, existing cleaning equipment mostly maintains session health status based on static or predefined rules. When attack characteristics change rapidly, it is difficult to maintain session health status in real time, resulting in problems such as session delays, packet loss, or connection interruptions. Summary of the Invention

[0005] In view of the above-mentioned defects or deficiencies in the prior art, it is desirable to provide a network data processing method that can proactively maintain abnormal states by determining the predicted health status of the session at the next moment and adjusting the current values ​​of the network configuration parameter set based on the predicted health status. This effectively solves the problem of difficulty in real-time maintenance of session health status in the prior art and improves the protection capability of the cleaning equipment.

[0006] In a first aspect, this application discloses a network data processing method applied to a network cleaning and defense system. The system includes a server, cleaning equipment, and a client. The method includes:

[0007] S1. The cleaning device receives traffic data from the client or server at the current moment and performs defense detection on the traffic data based on the defense strategy;

[0008] S2. If the traffic data passes the defense detection, then extract the first data feature and the second data feature of the traffic data, and determine the session to which the traffic data belongs based on the first data feature;

[0009] S3. Obtain a preset time period, which includes the current time and multiple times before the current time;

[0010] S4. For each moment in a preset time period, based on the second data characteristics of all traffic data belonging to the session within a sliding window up to that moment and with the same duration as the preset time period, determine the set of evaluation index values ​​for that moment. The set of evaluation index values ​​includes the values ​​of N preset evaluation indexes.

[0011] S5. Record the set of evaluation index values ​​at the current moment as the current index set, determine the actual health status of the session at the current moment based on the current index set, and determine the predicted health status of the session at the next moment based on the second data features at all moments within the preset time period and the set of evaluation index values ​​at all moments.

[0012] S6. Based on the actual health status and the predicted health status, maintain / adjust the current values ​​of the network configuration parameter set of the system, and update the predicted health status according to the adjustment result.

[0013] In conjunction with the first aspect, in one possible implementation, the first data feature includes a basic session identifier set and a target session identifier set. The basic session identifier set includes a 5-tuple, and the target session identifier set is determined based on the network protocol between the cleaning device and the client / server.

[0014] The session to which the traffic data belongs is determined based on the first data feature, specifically as follows:

[0015] Determine whether the basic session identifier set has a record and the target session identifier set has no record. If yes, discard the traffic data and send a retransmission request to the client. If no, obtain the session to which the traffic data belongs based on the basic session identifier set and the target session identifier set.

[0016] In conjunction with the first aspect, in one possible implementation, the session to which the traffic data belongs is obtained based on the basic session identifier set and the target session identifier set, specifically as follows:

[0017] Determine whether both the basic session identifier set and the target session identifier set have records. If so, select the session to which the traffic data belongs based on the basic session identifier set and the target session identifier set. If not, create a new session based on the basic session identifier set and the target session identifier set.

[0018] In conjunction with the first aspect, in one possible implementation, the actual health status of the session at the current moment is determined based on the current set of indicators, specifically as follows:

[0019] Get the current weight value of each evaluation indicator at the current moment;

[0020] Construct an evaluation model based on a Bayesian network, and input the current index set and the current weight values ​​corresponding to each evaluation index in the current index set into the evaluation model to obtain the output result at the current time.

[0021] The actual health status of the session at the current moment is determined based on the output results at the current moment, and the actual health status is any one of stable, fluctuating, or abnormal.

[0022] In conjunction with the first aspect, in one possible implementation, the predicted health status of the session at the next moment is determined based on the set of second data features and evaluation index values ​​at all times within the preset time period, specifically as follows:

[0023] Obtain the current weight value of each evaluation indicator at each moment within a preset time period;

[0024] For each moment within a preset time period, the set of evaluation index values ​​at that moment, and the current weight value corresponding to each evaluation index at that moment, are input into the evaluation model to obtain the output result at the corresponding moment.

[0025] The second data features, the set of evaluation index values, and the output results at all times within a preset time period are input into the prediction model. The predicted health status of the session at the next time moment is determined based on the output of the prediction model. The predicted health status is any one of stable, fluctuating, or abnormal.

[0026] In conjunction with the first aspect, in one possible implementation, the current values ​​of the network configuration parameter set of the system are maintained / adjusted based on the actual health status and the predicted health status, and the predicted health status is updated according to the adjustment result, specifically as follows:

[0027] When both the actual health status and the predicted health status are stable, the current values ​​of the network configuration parameter set are maintained unchanged.

[0028] When the actual health status and / or the predicted health status are unstable, the current value of the network configuration parameter set is adjusted, and the predicted health status is updated based on the current value of the adjusted network configuration parameter set. The instability refers to fluctuation / abnormality.

[0029] In conjunction with the first aspect, in one possible implementation, the current values ​​of the network configuration parameter set are adjusted, and the predicted health status is updated based on the adjusted current values ​​of the network configuration parameter set, specifically as follows:

[0030] Obtain the current values ​​of L adjustable indicators, which are selected from the N evaluation indicators;

[0031] From the set of network configuration parameters, select a subset of the influence parameters for each adjustable indicator;

[0032] Adjust the current value of each subset of influencing parameters until the difference between the change in the current value of the corresponding adjustable index and the preset first adjustment step size is less than the preset threshold, thus obtaining the current values ​​of multiple adjusted adjustable indices.

[0033] The current indicator set is updated using the current values ​​of L adjusted adjustable indicators, and the predicted health status is updated based on the updated current indicator set.

[0034] In conjunction with the first aspect, in one possible implementation, after updating the predicted health status based on the adjustment results, the method further includes:

[0035] S7. Based on the preset second adjustment step size, maintain / adjust the current weight value of each evaluation indicator at the current moment, and use the maintained / adjusted current weight value of each evaluation indicator at the current moment as the current weight value of the evaluation indicator at the next moment.

[0036] In conjunction with the first aspect, in one possible implementation where the traffic data is abnormal traffic, then after S7, the following is also included:

[0037] S8. Determine whether the defense strategy has failed. If so, iteratively update the defense strategy and re-receive the abnormal traffic after each update until the abnormal traffic can no longer pass the defense detection, thus obtaining the upgraded defense strategy.

[0038] In conjunction with the first aspect, one possible implementation, following S8, also includes:

[0039] S9. Determine a countermeasure strategy based on the upgraded defense strategy;

[0040] S10. Update the abnormal traffic according to the preset attack signature database and the countermeasure strategy;

[0041] S11. The cleaning equipment receives the updated abnormal traffic and performs defense detection on the updated abnormal traffic based on the upgraded defense strategy;

[0042] S12. Repeat steps S2 to S11 until the defense detection results meet the preset conditions.

[0043] In a second aspect, this application also provides a computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the method of any one of the first aspects described above.

[0044] Thirdly, this application also provides a computer program product containing instructions that, when executed, perform any of the methods described in the first aspect above.

[0045] Fourthly, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, it implements the method of any one of the first aspects above.

[0046] Compared with existing technologies, this application, by determining the predicted health status of the session at the next moment, can optimize the current value of the network configuration parameter set before the session health status becomes unstable, thereby reducing response latency, realizing dynamic and refined management of session health status, effectively shortening attack response time, and improving the system's adaptability and protection continuity in complex attack environments.

[0047] Furthermore, this application constructs a closed-loop iterative mechanism for the defense strategy, transforming the update of the defense strategy into a feedback-based dynamic optimization process. This addresses the limitation of static strategies in adapting to attack evolution. Moreover, this application exposes potential defense strategy weaknesses through targeted countermeasures, thereby enhancing the system's adaptability. This enables the cleaning equipment to dynamically adjust its defense strategy in the face of continuously changing and complex attacks, significantly improving the system's protection effectiveness and adaptability. Attached Figure Description

[0048] Other features, objects, and advantages of this application will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings:

[0049] Figure 1 This is a schematic diagram of the network cleaning and defense system of this application in one embodiment;

[0050] Figure 2 Here is a flowchart of the network data processing method of this application in one embodiment;

[0051] Figure 3 As one embodiment, this is a flowchart of the evaluation model determining the actual health status of a session at the current moment;

[0052] Figure 4 As one embodiment, a flowchart for determining the predicted health status of a session at the next moment;

[0053] Figure 5 This is a flowchart illustrating the user account verification process in one embodiment;

[0054] Figure 6 This is another flowchart of the network data processing method of this application in one embodiment;

[0055] Figure 7 This is a diagram of the internal structure of a computer device in one embodiment. Detailed Implementation

[0056] The present application will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings.

[0057] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. The present application will now be described in detail with reference to the accompanying drawings and embodiments. Furthermore, the term "and / or" in this document is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. The terms "first" and "second," etc., in the specification and claims of the embodiments of this application are used to distinguish different objects, not to describe a specific order of objects.

[0058] The following is an explanation of the terms used in this application:

[0059] Cleaning equipment: Security protection equipment used to filter and process network attack traffic;

[0060] Session maintenance: A mechanism used to maintain network connection status and manage session lifecycle;

[0061] Defense detection: Measures used to identify, filter, and block cyberattacks;

[0062] Countermeasures: Countermeasures refer to the targeted attack methods or technical solutions adopted by the attacker in order to bypass or undermine the defense strategies (such as rate limiting, behavior verification, signature recognition, etc.) deployed by the network system.

[0063] Health assessment: Health assessment refers to the process of analyzing the performance indicators and status parameters of network sessions to comprehensively judge whether their operation is stable and reliable, and to provide a basis for defense decisions.

[0064] Composite Session Identifier: A unique session identifier that integrates multi-dimensional information;

[0065] HTTP: Hypertext Transfer Protocol;

[0066] HTTPS: Hypertext Transfer Protocol Secure;

[0067] TCP: Transmission Control Protocol.

[0068] The method provided in this application embodiment can be applied to, for example... Figure 1 The network cleaning and defense system shown includes a server 30, a cleaning device 10, and a client 20.

[0069] like Figure 1 As shown, in the network cleaning and defense system provided in this application, server 30 is responsible for handling business logic, client 20 initiates requests to server 30, and cleaning device 10 is located between the two. One purpose is to receive and forward all traffic data between the two, which is composed of "requests" as the basic unit. Multiple logically related requests together constitute a "session"; another core function of cleaning device 10 is to build and maintain a complete "session" based on a series of related requests. By identifying and tracking the inherent connections between these requests, it ensures that multiple requests belonging to the same session can be correctly associated and processed, thereby maintaining the continuity and stability of the session's health status.

[0070] Specifically, the cleaning device 10 can be a firewall or a dedicated traffic cleaning device deployed at the network ingress.

[0071] Firstly, this application provides a network data processing method, applicable to, for example... Figure 1 The network cleaning and defense system shown is as follows: Figure 2 As shown, the method includes:

[0072] S1. The cleaning device 10 receives traffic data from the client 20 or the server 30 at the current moment and performs defense detection on the traffic data based on the defense strategy.

[0073] It should be noted that in this application, the number of traffic data at any given time is at least one. That is to say, the system of this application can process multiple traffic data at the same time. The processing flow of each traffic data is the same. To avoid cumbersome description, the following will use the processing flow of one traffic data as an example for explanation.

[0074] For example, the defense strategy includes at least one of the following: requiring client 20 / server 30 to retransmit, rate limiting, dropping traffic data, dropping connection sessions, or blacklisting IPs. After passing the defense detection, the traffic data can be forwarded to client 20 / server 30. It should be noted that passing the defense detection does not mean that the traffic data is not abnormal. It is also possible that the defense strategy failed, resulting in the failure to detect or defend against abnormal traffic data.

[0075] S2. If the traffic data passes the defense detection, extract the first data feature and the second data feature of the traffic data, and determine the session to which the traffic data belongs based on the first data feature.

[0076] Upon receiving traffic data at any given moment and completing the defense detection, this application extracts the first and second data features of the traffic data.

[0077] The first data feature can be understood as key information extracted from traffic data, which reflects the basic attributes and behavioral patterns of the traffic data. For example, the first data feature may include basic information such as the source IP address, destination IP address, protocol type, and port number of the traffic. It should be noted that data feature is a broad concept, which can be used to determine which existing session the traffic data belongs to, as well as to determine the current session health status or predict the session health status at the next moment. Therefore, the first data feature and the second data feature may partially overlap. Those skilled in the art can select different types of data features for session identification or session health status determination according to actual needs, and this application does not impose any limitations.

[0078] In one possible implementation, the first data feature is a composite session identifier constructed from multiple session identifiers. Specifically, it includes a basic session identifier set and a target session identifier set. The basic session identifier set includes a 5-tuple, and the target session identifier set is determined according to the network protocol between the cleaning device 10 and the client 20 / server 30. The basic session identifier set and the target session identifier set are responsible for generating unique and stable session identifiers for identifying, tracking, and maintaining the session health status of the session.

[0079] The basic session identifier set includes a five-tuple (source IP, source port, destination IP, destination port, protocol) and other existing identifiers used by the servers 30 to identify and track sessions. In one possible implementation, under a NAT (Network Address Translation) environment, the NAT device modifies the original address information in the basic session identifier set, causing the corresponding basic session identifiers to become invalid, making it difficult to accurately associate sessions. To address this, this application dynamically monitors the address mapping relationships performed by the NAT device (i.e., how the NAT device translates private IP addresses and ports of the internal network into public IP addresses and ports) and uses heuristic algorithms to infer these potential address translation relationships, thereby achieving correct session association even after passing through the NAT device. Furthermore, this application also combines the interaction behavior of data packets (request-response pattern) and the complete communication context, enabling the system to accurately restore and separate independent sessions even when the NAT device causes address confusion and port reuse (the same public port is used by multiple internal sessions in turn).

[0080] The target session identifier set is described below. Specifically, for the TCP protocol, the target session identifier set includes at least one of the following: TCP sequence number, acknowledgment number, SYN flag, ACK flag, FIN flag, TCP options, and initial window.

[0081] For the UDP protocol, the target session identifier set includes: based on time window and IP / port.

[0082] At least one of the following: bidirectional 5-tuple mapping relationship, UDP packet time interval, UDP packet time interval size distribution, and UDP packet payload semantic features;

[0083] For HTTP / HTTPS protocols, the target session identifier set includes: HTTP header fields such as Cookie, Session ID, and User-Agent, as well as client fingerprints such as browser characteristics and system information.

[0084] In this application, the principle of identifying and tracking sessions using the target session identifier set under the TCP protocol is as follows: By maintaining the continuity of TCP sequence numbers and acknowledgment numbers, the cleaning device 10 can accurately determine the health status of the session; by recording the change history of flags such as SYN, ACK, and FIN, the cleaning device 10 can assist in determining the health status of the session; this application introduces feature fingerprints on the basis of the existing basic session identifier set—the five-tuple. By extracting features such as TCP options and initial window, session fingerprints are generated, which can further improve the accuracy of session identification.

[0085] In this application, the principle of using the target session identifier set under the UDP protocol to identify and track sessions is as follows: First, a UDP pseudo-session is constructed based on a time window and IP / port combination; second, the forward and reverse data flows of the session are associated based on the bidirectional mapping relationship between the source IP, destination IP, source port, destination port, and transport layer protocol; furthermore, the time interval and size distribution of UDP packets can be analyzed to enhance the stability of the pseudo-session; finally, UDP payload semantic features can be extracted to associate different packets of the same service flow.

[0086] In this application, the target session identifier set under the HTTP / HTTPS protocol is used to identify and track sessions. This is mainly achieved by combining the transport layer, session layer, and application layer to construct a multi-layer identifier system. The identifiers at each layer work together. Specifically, the session affinity is maintained by analyzing the consistency of HTTP header fields (Cookie, Session ID, User-Agent, etc.). Furthermore, client fingerprints such as browser characteristics and system information are extracted to enhance the accuracy and stability of session identification. Finally, the session is maintained and tracked by the dynamic changes in fingerprint information.

[0087] This application reconstructs the generation and verification mechanism of session identifiers by integrating multiple elements such as timestamps, random strings, target information hashes, and client fingerprints. It effectively solves the problem that traditional session identifiers, due to their simple elements and obvious patterns, are easily forged, impersonated, or replayed by attackers, making it difficult for security devices to accurately identify legitimate sessions and allowing malicious traffic to bypass them.

[0088] Continuing with the explanation of the subsequent operations in step S2, after determining the basic session identifier set and the target session identifier set of the traffic data, the session to which the traffic data belongs is determined based on the first data feature, specifically as follows:

[0089] Determine whether there is a record in the basic session identifier set and no record in the target session identifier set. If so, discard the traffic data and send a retransmission request to the client. If not, obtain the session based on the basic session identifier set and the target session identifier set.

[0090] Based on the base session identifier set and the target session identifier set, the session is obtained as follows:

[0091] Determine whether both the basic session identifier set and the target session identifier set are recorded. If so, select the session to which the traffic data belongs based on the basic session identifier set and the target session identifier set. If not, create a new session based on the basic session identifier set and the target session identifier set.

[0092] Creating a new session is a common method that is known to those skilled in the art, and will not be described in detail in this application.

[0093] This application achieves dual filtering of traffic data by introducing a collaborative verification mechanism between a basic session identifier set and a target session identifier set. First, the basic session identifier set is used to determine whether the traffic data originates from a legitimate network connection. This process relies on standardized session identifiers provided by the five-tuple, enabling rapid filtering of invalid traffic data. Second, the target session identifier set is used to further verify the application-layer session context of the traffic data. This process dynamically defines identifiers based on the actual network protocol, thereby enhancing the ability to determine session integrity. When the basic session identifier set has a record but the target session identifier set does not, the system determines the traffic data to be invalid or potentially malicious and discards it directly, avoiding resource waste and security risks. Conversely, when both sets have records, the system selects the session to which the traffic data belongs for processing, ensuring that only complete and valid sessions proceed to subsequent steps. This conditional branching design optimizes the accuracy and real-time performance of session establishment, improving the adaptability and stability of the overall defense system.

[0094] After determining the assigned session in step S2, the method of this application further includes:

[0095] S3. Obtain a preset time period, which includes the current time and multiple times before the current time;

[0096] The preset time period can be set by those skilled in the art, and this application does not impose any limitation on it;

[0097] In one possible implementation, to adapt to different network environments, a sliding window with a variable time period is preset: a 5-minute window is used when the network is stable to ensure the accuracy of the evaluation, and a 30-second window is switched when the network fluctuates to improve real-time performance.

[0098] S4. For each moment in the preset time period, based on the second data characteristics of all traffic data belonging to the session within a sliding window up to that moment and with the same duration as the preset time period, determine the set of evaluation index values ​​for that moment. The set of evaluation index values ​​includes the values ​​of N preset evaluation indexes.

[0099] To improve the accuracy of the evaluation index values, this application selected M types of second data features:

[0100] Specifically, when the network protocol is TCP, the second data feature can be at least one of the following: source IP address, destination IP address, source port number, destination port number, TCP sequence number and acknowledgment number, TCP flag status and change history, sliding window size, and TCP option field. When the network protocol is UDP, the second data feature can be at least one of the following: packet time interval, packet size distribution, request-response pattern characteristics, application layer protocol-specific fields, session duration, traffic rate, and historical state change records. For HTTP / HTTPS protocols, the second data feature includes at least one of the following: cookie content, session ID, user-agent string, source IP address, HTTP request method, request URL and path, query parameters, Referer header information, Host header field, Accept series header fields, TLS protocol version and cipher suite under HTTPS, certificate information, ALPN negotiation protocol, HTTP / 2 stream identifier and frame type, request time interval, session duration, request content length distribution, client device fingerprint, geolocation information, and request sequence pattern established based on historical behavior.

[0101] In one possible implementation, the N evaluation metrics include at least one of the following: response time metrics, error rate metrics, or traffic characteristic metrics; specifically, response time metrics include average response time, response time variance, and long-tail metrics such as P95 / P99.

[0102] In other embodiments, the evaluation metrics may also include at least one of the following: session response success rate, response time change trend, error code distribution characteristics, request interception frequency, or session identifier validity period;

[0103] In one possible implementation, the evaluation metrics may also include: session identifier validity metrics, such as at least one of identifier survival rate and replacement success rate;

[0104] In one possible implementation, the evaluation metrics also include: session context consistency metrics, such as cookie state changes and / or session context coherence; resource utilization metrics that can indirectly reflect system performance changes; protocol interaction characteristic metrics, such as TCP connection state transitions and / or HTTP header changes; and user behavior pattern metrics, such as operation interval distribution and / or the randomness of request sequences.

[0105] It should be noted that the current value of each of the above evaluation indicators is obtained by selecting relevant quantities from M second data features and performing statistical analysis on the values ​​of the relevant quantities within a preset time period. The calculation method of each evaluation indicator is known to those skilled in the art through consultation, and will not be described in detail in this application. The following are examples illustrating the calculation methods of several evaluation indicators:

[0106] For example, when the preset time period is 5 minutes, the "average response time" metric for the current moment is calculated as the arithmetic mean of the response times of all requests in the session within the 5 minutes preceding the current moment; the "response time trend" is analyzed by fitting the overall slope of the response time series within the 5 minutes preceding the current moment using a linear regression method; and the "session context coherence" is evaluated by checking whether key cookie values ​​or identity fields such as the Authorization header field remain consistent in consecutive requests within the same session within the 5 minutes preceding the current moment.

[0107] In other words, when the preset time period is 5 minutes, the value of any evaluation index at any given moment is obtained by statistical analysis of the data characteristics of all traffic data in the preceding 5 minutes, including that moment.

[0108] S5. Record the set of evaluation index values ​​at the current moment as the current index set, determine the actual health status of the session at the current moment based on the current index set, and determine the predicted health status of the session at the next moment based on the second data features at all moments within the preset time period and the set of evaluation index values ​​at all moments.

[0109] like Figure 3 As shown, in S5, the actual health status of the session at the current moment is determined based on the current indicator set, specifically as follows:

[0110] S5.1.1 Obtain the current weight value of each evaluation indicator at the current moment;

[0111] The current weight value can be manually entered or generated by the system inside the cleaning equipment. The weight is used to characterize the proportion of the influence of the corresponding evaluation index on the evaluation result when using multiple evaluation indicators to evaluate the health status of the session.

[0112] In one possible implementation, the current weight value at the first moment is preset and input manually, and the current weight value at the next moment immediately following the first moment is adaptively adjusted by the system based on the session health status at the first moment. Similarly, the current weight value at each moment is adaptively adjusted by the system based on the session health status at the next moment immediately preceding the first moment. This value can be directly obtained from the system of the cleaning equipment by those skilled in the art.

[0113] S5.1.2 Construct an evaluation model based on Bayesian networks, and input the current set of indicators and the current weight values ​​corresponding to each evaluation indicator in the current set of indicators into the evaluation model to obtain the output results at the current time.

[0114] Specifically, the evaluation model based on Bayesian networks uses network status (bandwidth, packet loss, latency) and device load (CPU, memory, number of connections) as core parent nodes, various service quality indicators as intermediate nodes, and historical session health status over a preset time period as leaf nodes to simulate nonlinear dependencies between variables.

[0115] Among them, network status, equipment load and service quality indicators are all collected through the operation status interface of the cleaning equipment 10, and the service quality indicators can be set by those skilled in the art according to the actual situation.

[0116] S5.1.3 Determine the actual health status of the session at the current moment based on the output results at the current moment. The actual health status is any one of stable, fluctuating, or abnormal.

[0117] The output at the current moment is specifically a score of the session's health status at the current moment. In one possible implementation, after obtaining the score output by the evaluation model, this application divides the session's health status at the current moment into five levels based on the score: Good (80-100 points), Normal (60-80 points), Average (40-60 points), Poor (20-40 points), and Extremely Poor (0-20 points). Among them, sessions at the Good level are considered to be in a stable state; sessions at the Normal level are considered to be in a fluctuating state; and sessions at the Average, Poor, and Extremely Poor levels are considered to be in an abnormal state.

[0118] In this application, the actual health status of a session at any given moment, or the predicted health status mentioned below, refers to the overall health assessment of the session behavior. In one possible implementation, this application categorizes the status into "stable," "fluctuating," and "abnormal." Specifically: "stable" means that changes in the second data characteristic conform to historical patterns, and communication is stable and predictable; "fluctuating" means that the second data characteristic shows short-term deviations but remains within a controllable range, possibly caused by network jitter; "abnormal" means that the second data characteristic exhibits continuous or drastic pattern deviations, often indicating serious problems such as attacks, malfunctions, or connection interruptions.

[0119] The Bayesian network-based evaluation model in this application achieves dynamic and accurate evaluation of session health status by organically integrating the trend capture capability of time series analysis, the interference filtering capability of anomaly detection, and the uncertainty handling capability of probabilistic reasoning.

[0120] like Figure 4 As shown, in S5, the predicted health status of the session at the next moment is determined based on the set of second data features and evaluation index values ​​at all times within a preset time period. Specifically:

[0121] S5.2.1 Obtain the current weight value of each evaluation indicator at each moment within a preset time period;

[0122] The current weight value of each evaluation indicator at any given moment can be directly obtained from the cleaning equipment.

[0123] S5.2.2 For each moment within a preset time period, input the set of evaluation index values ​​at that moment, and the current weight value corresponding to each evaluation index at that moment, into the evaluation model to obtain the output result at the corresponding moment;

[0124] It is worth noting that at each moment, the evaluation metrics, data features, and weights of the evaluation metrics all have a current value. In other words, the current value mentioned in this application refers to the moment the statement is mentioned, and not necessarily the present moment. Furthermore, in fact, at each moment, the cleaning device of this application determines and stores the following parameters in real time: the second data feature of the session, the current value of each evaluation metric, the current weight value of each evaluation metric, and the output result. During prediction, the corresponding parameters from each moment in the previous time period can be directly retrieved without recalculation.

[0125] S5.2.3 Input the set of second data features, evaluation index values, and output results at all times within the preset time period into the prediction model;

[0126] S5.2.4 Determine the predicted health status of the session at the next moment based on the output of the prediction model;

[0127] Predicting session health status refers to the prediction of the session's potential state at the next moment, derived from the analysis of secondary data features at the current time. The prediction model is a Gradient Boosting Decision Tree (GBDT) model. This application predicts session health status in order to adjust the network configuration parameter set in advance to adapt to possible changes in session health status.

[0128] In one possible implementation, after determining the predicted health status of the session at the next moment, this application also predicts the resource requirements for the next moment based on the predicted health status. The resource requirements include network resources (upper limits for bandwidth, number of connections, file descriptors, etc.) to guide the cleaning device 10 to make adaptive resource allocation and policy adjustments for the session at the next moment.

[0129] This application introduces both predicted and actual health states, addressing the lag in response caused by relying solely on the current state in existing technologies. Specifically, by introducing predicted health states, strategy optimization can begin before attack characteristics evolve, thereby reducing response latency. Simultaneously, determining the actual health state corrects prediction biases and avoids prediction errors. Together, these two approaches enable dynamic and refined management of secondary data features, effectively shortening attack response time and improving the system's adaptability and continuity of protection in complex attack environments.

[0130] S6. Maintain / adjust the current values ​​of the system's network configuration parameter set based on the actual health status and the predicted health status, and update the predicted health status based on the adjustment results.

[0131] A network configuration parameter set refers to a set of variables used to characterize and regulate the performance of cleaning equipment. Its specific implementation forms include, but are not limited to: multicast control unit related parameters of the network card, the upper limit of the number of sessions supported by the system, the number of available file descriptors, traffic bandwidth limit threshold, packet forwarding rate limit, access control list rule set, new connection rate limit, maximum number of concurrent connections allowed per IP address, SYN cookie protection mechanism enable threshold, traffic shaping queue length, entries in blacklists and whitelists, session persistence timeout, TCP protocol window size, sensitivity parameters for traffic anomaly detection in DDoS protection module, server weight allocation in load balancing strategy, and at least one of the following: the strictness level of content filtering rules.

[0132] It should be noted that since the second data features extracted at each moment become fixed historical records after generation and cannot be changed, the actual health status at the current moment determined based on these second data features is also a fait accompli. For example, when the system identifies that the actual health status at the current moment is fluctuating or abnormal, this status itself is usually difficult to directly correct by retrospection. However, the solution proposed in this application, by dynamically adjusting the current values ​​of the network configuration parameter set, essentially optimizes the operating performance and protection capabilities of the cleaning equipment online. This means that in the next moment, the newly effective network configuration parameters will be able to improve the processing efficiency or defense strength of the cleaning equipment, thereby more effectively responding to ongoing or newly emerging network conditions, in order to improve the health status of the system in the expected direction in subsequent moments.

[0133] Updating predicted health status refers to recalculating the predicted health status based on the adjusted results.

[0134] The mechanism for adjusting the predicted health status in this application enables proactive prediction and adjustment of the session's health status. Therefore, this application can begin strategy optimization before the attack characteristics evolve, reducing response latency.

[0135] In one possible implementation, S6 maintains / adjusts the current values ​​of the system's network configuration parameter set based on the actual health state and the predicted health state, and updates the predicted health state based on the adjustment result, specifically as follows:

[0136] S61. When both the actual health status and the predicted health status are stable, maintain the current values ​​of the network configuration parameter set unchanged.

[0137] S62. When the actual health status and / or predicted health status is unstable, adjust the current value of the network configuration parameter set and update the predicted health status based on the adjusted current value of the network configuration parameter set. Unstable is defined as fluctuation / abnormal.

[0138] In one possible implementation, in S62, adjusting the current values ​​of the network configuration parameter set and updating the predicted health status based on the adjusted current values ​​of the network configuration parameter set specifically involves:

[0139] S621. Obtain the current values ​​of L adjustable indicators, which are selected from N evaluation indicators.

[0140] Among them, N evaluation indicators are quantitative representations of the system state calculated based on the second data characteristics. These indicators are divided into two categories: adjustable and non-adjustable. The values ​​of adjustable indicators can be actively guided by adjusting their corresponding specific network configuration parameters (i.e., the subset of influencing parameters); while the values ​​of non-adjustable indicators are mainly constrained by the external environment or inherent properties and are difficult to change effectively through parameter adjustment. It should be clarified that adjusting the set of network configuration parameters cannot change the established second data characteristics; its role is to optimize the operating performance and processing logic of the cleaning equipment itself.

[0141] S622. Select a subset of the influencing parameters for each adjustable indicator from the network configuration parameter set;

[0142] S623. Adjust the current value of each subset of influencing parameters until the difference between the change in the current value of the corresponding adjustable index and the preset first adjustment step size is less than the preset threshold, and obtain the current values ​​of multiple adjusted adjustable indices.

[0143] In other words, the value of each adjustable indicator is determined by a specific subset of influencing parameters. By adjusting the current values ​​of this subset of influencing parameters, the system's data processing capabilities and defense effectiveness in subsequent moments can be improved. This allows the second data features of the traffic data extracted by the system in the future to better reflect the true health status of the sessions, and ultimately improves the accuracy of the evaluation indicators calculated based on these future second data features and the reliability of the status determination.

[0144] To more clearly illustrate the adjustment logic in S623, the following example is provided: Assume that N evaluation metrics include session response success rate, response time trend, error code distribution characteristics, request interception frequency, and session identifier validity period. The system selects L=2 adjustable metrics, namely "response time trend" (current value increases by 0.5 seconds per second) and "5xx error code occurrence frequency" (current value is 15%), and sets their corresponding first adjustment step sizes to 0.1 seconds / second and 5% respectively, and the allowed difference threshold is 10% of the step size.

[0145] The system first identifies the subset of influencing parameters for each adjustable index: "response time variation trend" corresponds to the TCP initial window size and maximum retransmission count, and "5xx error code frequency" corresponds to the application layer timeout setting and request retries. Subsequently, the cleaning device 10 iteratively adjusts each subset of influencing parameters: the initial adjustment increases the TCP initial window from 16KB to 24KB and the application layer timeout from 2 seconds to 2.5 seconds. After the adjustment, the measured response time variation trend decreased to 0.42 seconds / second, and the 5xx error code frequency decreased to 12%. The difference between the change caused by this adjustment and the corresponding step size is calculated as follows: seconds / second and Both are greater than the set thresholds (0.01 seconds / second and 0.5%).

[0146] Cleaning equipment 10 underwent a second adjustment: the maximum number of TCP retransmissions was increased from 3 to 5, and the number of requested retries was increased from 2 to 3. After the adjustment, the response time trend was 0.35 seconds / second, and the 5xx error code frequency was 8%. The difference between this change and the step size was... seconds / second and It is still higher than the threshold. After several iterations, when an adjustment causes the response time trend to decrease to 0.21 seconds / second and the 5xx error code frequency to decrease to 6%, the calculated differences between the change and the step size are as follows: seconds / second and All values ​​are within the corresponding threshold range, at which point the adjustment stops, and the system records the values ​​of each subset of influencing parameters as the adjustment result.

[0147] S624. Update the current indicator set using the current values ​​of L adjusted adjustable indicators, update the output result at the current moment based on the updated current indicator set, and update the predicted health status based on the updated current indicator set.

[0148] Updating the current indicator set using the current values ​​of L adjusted adjustable indicators refers to reusing the second data feature to determine the value of each evaluation indicator at the current moment in a cleaning device that has updated the current values ​​of the network configuration parameter set.

[0149] In one possible implementation, the current value of the evaluation metric used to predict the next moment is replaced with the current value of the updated evaluation metric, while the other parameters remain unchanged. The session health status prediction for the next moment is then performed again to obtain the updated predicted health status.

[0150] It is worth mentioning that, in the technical solution of this application, although the system's prediction of the health status at the next moment (i.e., the updated predicted health status) cannot be guaranteed to be absolutely accurate after each update of network configuration parameters, it can provide a reliable trend expectation in most cases. This is because parameter optimization directly improves the system's processing capacity and defense posture, making the system more likely to maintain or tend towards a stable state in subsequent operations. Although there is still a small probability that the actual health status at the next moment will be unstable under the dynamic changes of the network environment, short-term fluctuations at individual moments are normal phenomena for the entire session lifecycle. By continuously updating the predicted status based on the latest data, this solution can provide system administrators with forward-looking decision-making basis, thereby achieving better resource allocation and risk intervention in most cases.

[0151] like Figure 6As shown, in one possible implementation, after updating the predicted health status based on the adjustment results, the following is also included:

[0152] S7. Based on the preset second adjustment step size, maintain / adjust the current weight value of each evaluation indicator at the current moment, and use the maintained / adjusted current weight value of each evaluation indicator at the current moment as the current weight value of the evaluation indicator at the next moment.

[0153] Taking S7 as an example: The initial weights for session response success rate are preset to 20% for immediate and 15% for cumulative; the initial weight for response time change trend is preset to 15%; the initial weight for error code distribution characteristics is preset to 20%; the initial weight for request interception frequency is preset to 20%; and the initial weight for session identifier validity period is preset to 10%. First, each evaluation indicator is increased according to a preset weight step size (e.g., 5%). When the number of error codes in the response exceeds a preset threshold, the initial weight for error code distribution characteristics is increased from 20% to 25%, and the weight for session identifier validity period is decreased by 5% to maintain overall weight balance. Then, the new weight configuration is used as the current weight configuration for the next moment. The actual health status of the session is determined again at the next moment. If it is still fluctuating / abnormal, the weights are iteratively adjusted according to the weight step size. At the next moment, the weight for response time change trend is increased from 15% to 20%, and the above steps are repeated, adjusting the current weight value in real time at each moment. The adjusted current weight value is then used to determine the actual health status of the session at the next moment.

[0154] In one possible implementation, if the traffic data is abnormal traffic, then after S7, it also includes:

[0155] S8. Determine if the defense strategy has failed. If so, iteratively update the defense strategy and re-receive abnormal traffic packets after each update until the abnormal traffic can no longer pass the defense detection, thus obtaining the upgraded defense strategy.

[0156] Specifically, this application utilizes a Q-learning-based reinforcement learning algorithm to update the defense strategy.

[0157] In one possible implementation, after S8, it also includes:

[0158] S9. Determine the countermeasure strategy based on the upgraded defense strategy;

[0159] The countermeasure strategy is an active verification mechanism generated based on the upgraded defense strategy. It can be implemented by simulating attack behavior patterns or constructing specific test traffic. This application improves the system's adaptability by exposing potential weaknesses in the defense strategy through targeted countermeasures.

[0160] Identifying the various upgraded defense strategies is the starting point for determining countermeasures. One possible approach is to analyze the network response characteristics generated when the upgraded defense strategies are executed by standardizing probe requests, distinguish the triggering conditions and behavior patterns of different defense strategies, and thus quickly identify possible defense strategy types.

[0161] Specifically, the process begins with basic feature detection. By sending standardized detection requests, the characteristics of the returned response headers, the distribution patterns of status codes, and changes in the response body content are analyzed to quickly obtain preliminary defense information. Next, deep feature mutation detection is performed, generating various mutation requests to test the sensitivity of the cleaning device 10 to different request frequencies, format changes, and request sequences, further determining the defense features. Finally, a high-frequency request stress test is conducted, sending requests at a controllable rate to identify rate-limiting thresholds and triggering conditions, thereby creating a complete profile of the upgraded defense strategy. Based on this profile, the type of upgraded defense strategy is then identified.

[0162] This application adopts a progressive detection strategy, gradually and deeply analyzing the defense mechanism, which can systematically reveal the detection rules, anomaly judgment logic and protection threshold of the upgraded defense strategy, providing a reliable basis for the selection of countermeasures.

[0163] In one possible implementation, the defense strategy types mainly include at least one of the following: DDoS defense mechanism, CC attack defense mechanism, or abnormal traffic defense mechanism.

[0164] After identifying the upgraded defense strategy, this application also maintains a rich library of defense mechanisms, covering various common defense strategies and their corresponding countermeasures. During the identification of the upgraded defense strategy, this application also provides a confidence score of 0-100% for the identification results, aiding in the accurate selection of subsequent countermeasures. In the design of the defense mechanism library, this application integrates multiple basic coping methods, supporting flexible combinations and parameter tuning among different countermeasures.

[0165] In one possible implementation, this application also dynamically selects the most suitable countermeasure based on the identification results of the upgraded defense strategy and the execution effects of historical countermeasure strategies. For complex multi-layered defense measures, the system can also implement strategy nesting—by layering and combining different types of countermeasures (such as basic countermeasures and enhanced countermeasures), the success rate of countermeasures can be improved through multi-dimensional adjustments.

[0166] In one possible implementation, in response to the upgraded defense strategy, this application also utilizes a Q-learning-based reinforcement learning framework to update the countermeasure strategy.

[0167] S10. Update abnormal traffic based on the preset attack signature database and countermeasures strategy;

[0168] A pre-defined attack signature database refers to a collection of data storing historical attack characteristics and related behavioral patterns. It can be regularly updated and expanded to maintain coverage of the latest threats. Updating abnormal traffic refers to generating highly realistic test traffic using information from the attack signature database and countermeasure strategies to reflect dynamic attack scenarios.

[0169] The process of updating abnormal traffic is as follows: Select new attack features from the preset attack feature library, update the abnormal traffic, and conduct attack tests using the determined countermeasures. If the attack is successful, the abnormal traffic update is complete; if it is unsuccessful, update the abnormal traffic again using the preset attack feature library and conduct attack tests again using the countermeasures. Repeat the above steps until the attack is successful and the abnormal traffic update is complete.

[0170] It should be noted that in this application, the defense and countermeasure strategies are updated based on a Q-learning reinforcement learning framework. During multiple rounds of training, the effectiveness of the strategies is continuously optimized through the interaction between the countermeasure and defense strategies. In other embodiments, this application also uses an improved Q-learning algorithm combined with Bayesian optimization to continuously learn the optimal strategy combination during interaction with the cleaning device 10. This learning mechanism takes into account multiple factors, including the identified defense mechanism type, session health status, and network environment characteristics.

[0171] S11. The cleaning equipment receives the updated abnormal traffic and performs defense detection on the updated abnormal traffic based on the upgraded defense strategy.

[0172] S12. Repeat steps S2 to S11 until the defense detection results meet the preset conditions.

[0173] The preset conditions can be reaching a preset number of times or the system's defense success rate reaching a preset value.

[0174] It is worth mentioning that S8~S11 disclose a process for upgrading the defense capabilities of the cleaning and defense system using abnormal traffic. Specifically, this application solves the problem of lack of proactive testing after the defense strategy is upgraded by constructing a closed-loop iterative verification mechanism. In S8, a countermeasure strategy is generated based on the upgraded defense strategy, ensuring that the countermeasures are closely related to the latest defense status, thereby simulating the attacker's behavior pattern. This allows this application to proactively detect potential policy vulnerabilities, avoiding insufficient adaptability caused by the disconnect between defense strategy updates and verification. In S10, updated abnormal traffic is generated by combining a preset attack feature library and countermeasure strategy, and then re-inputted into the cleaning device 10 for real-time verification. This process uses historical attack features and current countermeasure information to generate highly realistic test traffic, truly reflecting dynamic attack scenarios and overcoming the limitation of relying solely on passive traffic analysis to proactively detect policy vulnerabilities. By repeatedly executing steps S2 to S11, a closed-loop cycle of strategy optimization and verification is formed. The system can continuously adjust defense parameters and verify its robustness, significantly improving its adaptability and protection stability in the face of complex attacks.

[0175] In one possible implementation, this application also learns and provides feedback on the defense and countermeasure strategies: Specifically, after each abnormal traffic passes through the defense strategy, this application learns and updates the countermeasure strategy for that abnormal traffic through audit log records, in order to optimize subsequent defense type identification and countermeasure strategy selection, thereby continuously improving defense capabilities.

[0176] Steps S1-S7 disclosed in this application focus on real-time session health management. Based on current and historical traffic data, they dynamically evaluate and predict the session status at each moment and adjust network configuration parameters in real time. This is a continuous, time-sensitive real-time feedback process. Steps S8-S11, on the other hand, aim to iteratively optimize and enhance the defense strategy of the cleaning device itself. This process does not rely on dynamic real-time status management of specific sessions, nor does it need to be synchronized with real-time traffic data received at the "next moment." Instead, it is a training and testing process that can be executed asynchronously in the background. The input "abnormal traffic" can be historical datasets or specially generated test traffic. Only after the new defense strategy has been trained and verified will it be updated into the system for use by the real-time session management process of steps S1-S7 in future, preset-time defense detection.

[0177] In one possible implementation, after step S7, the method of this application further includes S8, performing post-defense on the traffic data based on the extracted first data features.

[0178] In this possible implementation, when the traffic data is abnormal, then after S8, it also includes:

[0179] S9. Record the post-defense strategy as the post-defense strategy. Determine whether the abnormal traffic has bypassed any of the following: defense detection, session management described in S1-S6, or post-defense. If not, end the process. If yes, the cleaning device 10 will re-receive the abnormal traffic that has passed the post-defense and simultaneously iterate and update the defense strategy and the post-defense strategy until the abnormal traffic can no longer pass the defense detection or the post-defense strategy, thus obtaining the upgraded defense strategy and the upgraded post-defense strategy.

[0180] S10. Determine the countermeasure strategy based on the upgraded defense strategy and the upgraded follow-up strategy. The countermeasure strategy can be a combination strategy.

[0181] S11. Update abnormal traffic based on the preset attack signature database and countermeasures strategy;

[0182] S12. The cleaning equipment receives the updated abnormal traffic and performs defense detection on the updated abnormal traffic based on the upgraded defense strategy.

[0183] S13. Repeat steps S2 to S12 until the defense detection results of the cleaning equipment meet the preset conditions. The preset conditions can be reaching a preset number of times or the success rate of the cleaning equipment's defense reaching a preset value. It is worth mentioning that, whether it is the initial defense detection or the post-defense in S8, as long as one defense is successful, the cleaning equipment can be considered to have successfully defended.

[0184] In one possible implementation, before updating the abnormal traffic based on a pre-defined attack signature database and countermeasures, such as... Figure 5 As shown, this application also includes: receiving abnormal traffic requests for updating user accounts;

[0185] The user account is sequentially verified for identity, authorization, and purpose.

[0186] Authentication specifically includes at least two of the following: password, certificate, and biometrics; requests that fail to authenticate are directly denied access, while requests that succeed in authentication proceed to the next authorization authentication step;

[0187] Authorization and authentication specifically include: assigning user accounts to preset roles and associating them with corresponding resource access permissions through the RBAC (Role-Based Access Control) model, thereby enabling fine-grained control over key operations such as countermeasure policy configuration and audit log query, and ensuring that user accounts can only perform corresponding functions within their authorized scope.

[0188] Authorization authentication is used to verify whether a user account has the permission to perform a specific operation. Unauthorized users request access denied, while authorized users request to proceed to the next step of verification.

[0189] Purpose verification specifically involves: real-time analysis and monitoring of user account behavior; verification of the legitimacy of the purpose of use through whitelisting, keyword matching, and semantic analysis; refusal of operation for illegal behavior; restriction of behavior for suspicious behavior; and permission for function calls for legitimate behavior; and manual review and confirmation for high-risk or ambiguous purposes of use.

[0190] In one possible implementation, this application also performs a detailed audit of the behavior of user requests that sequentially pass identity authentication, authorization authentication and purpose verification, and records it in the form of an audit log;

[0191] The audit logs record more than 15 fields, including operation time, user identity, target system, operation type, operation result, and IP address. They are stored with encryption and anti-tampering technology to ensure the integrity of the audit logs. Furthermore, this application also monitors the audit logs in real time, identifies abnormal usage patterns, and supports the generation of compliance reports to meet audit requirements.

[0192] In one possible implementation, this application also imposes rate limiting on user requests. Specifically, it sets a request rate cap for each user to prevent resource abuse.

[0193] It should be noted that although the operations of the method of the present invention are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all of the operations shown must be performed to achieve the desired result. On the contrary, the steps depicted in the flowchart may be performed in a different order. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.

[0194] On the other hand, this application also provides a computer-readable storage medium, which may be included in the cleaning apparatus 10 or exist independently without being assembled into the cleaning apparatus 10. The aforementioned computer-readable storage medium stores one or more programs that, when used by one or more processors, execute the methods described in this application. For example, it may execute... Figure 2 The steps of the method shown.

[0195] This application provides a computer program product including instructions that, when executed, cause the method described in this application to be performed. For example, it can execute... Figure 2 The steps of the method shown.

[0196] The following is for reference. Figure 7 , Figure 7 A schematic diagram of the structure of a computer system suitable for implementing the embodiments of this application is shown.

[0197] like Figure 7 As shown, the computer system includes a central processing unit (CPU) 701, which can perform various appropriate actions and processes based on programs stored in read-only memory (ROM) 702 or programs loaded from storage section 708 into random access memory (RAM) 703. RAM 703 also stores various programs and data required for the system's operating instructions. CPU 701, ROM 702, and RAM 703 are interconnected via bus 704. Input / output (I / O) interface 705 is also connected to bus 704.

[0198] The following components are connected to I / O interface 705: an input section 706 including a keyboard, mouse, etc.; an output section 707 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and speakers, etc.; a storage section 708 including a hard disk, etc.; and a communication section 709 including a network interface card such as a LAN card, modem, etc. The communication section 709 performs communication processing via a network such as the Internet. A drive 710 is also connected to I / O interface 705 as needed. A removable medium 711, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on drive 710 as needed so that computer programs read from it can be installed into storage section 708 as needed.

[0199] Specifically, according to embodiments of this application, the flowchart above refers to... Figure 2 The described process can be implemented as a computer software program. For example, embodiments of this application include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowchart. In such an embodiment, the computer program contains program code for performing the methods shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via communication section 709, and / or installed from removable medium 711. When the computer program is executed by central processing unit (CPU) 701, it performs the functions defined in the system of this application.

[0200] The above description is merely a preferred embodiment of this application and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of the invention involved in this application is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the inventive concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions disclosed in this application.

Claims

1. A network data processing method, characterized by, Applied to a network cleaning and defense system, the system includes a server, cleaning equipment, and a client, and the method includes: S1. The cleaning device receives traffic data from the client or server at the current moment and performs defense detection on the traffic data based on the defense strategy; S2. If the traffic data passes the defense detection, then extract the first data feature and the second data feature of the traffic data, and determine the session to which the traffic data belongs based on the first data feature; S3. Obtain a preset time period, which includes the current time and multiple times before the current time; S4. For each moment in a preset time period, based on the second data characteristics of all traffic data belonging to the session within a sliding window up to that moment and with the same duration as the preset time period, determine the set of evaluation index values ​​for that moment. The set of evaluation index values ​​includes the values ​​of N preset evaluation indexes. S5. The set of evaluation index values ​​at the current moment is denoted as the current index set. The actual health status of the session at the current moment is determined based on the current index set. The predicted health status of the session at the next moment is determined based on the second data features at all moments within the preset time period and the set of evaluation index values ​​at all moments. The actual health status is any one of stable, fluctuating, or abnormal. S6. Based on the actual health status and the predicted health status, maintain / adjust the current values ​​of the network configuration parameter set of the system, and update the predicted health status according to the adjustment result.

2. The method of claim 1, wherein, The first data feature includes a basic session identifier set and a target session identifier set. The basic session identifier set includes a 5-tuple, and the target session identifier set is determined based on the network protocol between the cleaning device and the client / server. The session to which the traffic data belongs is determined based on the first data feature, specifically as follows: Determine whether the basic session identifier set has a record and the target session identifier set has no record. If yes, discard the traffic data and send a retransmission request to the client. If no, obtain the session to which the traffic data belongs based on the basic session identifier set and the target session identifier set.

3. The method of claim 2, wherein, Based on the aforementioned basic session identifier set and target session identifier set, the session to which the traffic data belongs is obtained, specifically: Determine whether both the basic session identifier set and the target session identifier set have records. If so, select the session to which the traffic data belongs based on the basic session identifier set and the target session identifier set. If not, create a new session based on the basic session identifier set and the target session identifier set.

4. The method according to any one of claims 1-3, characterized in that, The actual health status of the session at the current moment is determined based on the current set of indicators, specifically as follows: Get the current weight value of each evaluation indicator at the current moment; Construct an evaluation model based on a Bayesian network, and input the current index set and the current weight values ​​corresponding to each evaluation index in the current index set into the evaluation model to obtain the output result at the current time. The actual health status of the session at the current moment is determined based on the output results at the current moment.

5. The method according to claim 4, characterized in that, The predicted health status of the session at the next moment is determined based on the set of second data features and evaluation index values ​​at all times within the preset time period, specifically as follows: Obtain the current weight value of each evaluation indicator at each moment within a preset time period; For each moment within a preset time period, the set of evaluation index values ​​at that moment, and the current weight value corresponding to each evaluation index at that moment, are input into the evaluation model to obtain the output result at the corresponding moment. The second data features, the set of evaluation index values, and the output results at all times within a preset time period are input into the prediction model. The predicted health status of the session at the next time moment is determined based on the output of the prediction model. The predicted health status is any one of stable, fluctuating, or abnormal.

6. The method according to claim 5, characterized in that, The current values ​​of the network configuration parameter set of the system are maintained / adjusted based on the actual health status and the predicted health status, and the predicted health status is updated according to the adjustment result, specifically as follows: When both the actual health status and the predicted health status are stable, the current values ​​of the network configuration parameter set are maintained unchanged. When the actual health status and / or the predicted health status are unstable, the current value of the network configuration parameter set is adjusted, and the predicted health status is updated based on the current value of the adjusted network configuration parameter set. The instability refers to fluctuation / abnormality.

7. The method according to claim 6, characterized in that, The current values ​​of the network configuration parameter set are adjusted, and the predicted health status is updated based on the adjusted current values ​​of the network configuration parameter set, specifically as follows: Obtain the current values ​​of L adjustable indicators, which are selected from the N evaluation indicators; From the set of network configuration parameters, select a subset of the influence parameters for each adjustable metric; Adjust the current value of each subset of influencing parameters until the difference between the change in the current value of the corresponding adjustable index and the preset first adjustment step size is less than the preset threshold, thus obtaining the current values ​​of multiple adjusted adjustable indices. The current indicator set is updated using the current values ​​of L adjusted adjustable indicators, and the predicted health status is updated based on the updated current indicator set.

8. The method according to claim 7, characterized in that, After updating the predicted health status based on the adjustment results, the following is also included: S7. Based on the preset second adjustment step size, maintain / adjust the current weight value of each evaluation indicator at the current moment, and use the maintained / adjusted current weight value of each evaluation indicator at the current moment as the current weight value of the evaluation indicator at the next moment.

9. The method according to claim 8, characterized in that, If the traffic data is abnormal, then after S7, it also includes: S8. Determine whether the defense strategy has failed. If so, iteratively update the defense strategy and re-receive the abnormal traffic after each update until the abnormal traffic can no longer pass the defense detection, thus obtaining the upgraded defense strategy.

10. The method according to claim 9, characterized in that, Following S8, it also includes: S9. Determine a countermeasure strategy based on the upgraded defense strategy; S10. Update the abnormal traffic according to the preset attack signature database and the countermeasure strategy; S11. The cleaning equipment receives the updated abnormal traffic and performs defense detection on the updated abnormal traffic based on the upgraded defense strategy; S12. Repeat steps S2 to S11 until the defense detection results meet the preset conditions.