A firewall-based network intrusion detection method and system
By analyzing periods of network instability and user online status on the campus network, suspected intrusion periods were identified. By combining the intensity of abnormal behavior with traffic relationships, the accuracy problem of campus network intrusion detection was solved, enabling accurate assessment of network intrusion risks and threat levels.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJING BOHAN TECH CO LTD
- Filing Date
- 2026-01-22
- Publication Date
- 2026-05-19
AI Technical Summary
Existing campus network intrusion detection methods rely on fixed preset traffic thresholds, which can lead to traffic fluctuations when students and teachers frequently access the internet or conduct online classes, resulting in misjudgments and affecting the accuracy of detection results.
By identifying periods of network instability, analyzing user online status and traffic, and filtering out suspected intrusion periods, the risk and threat level of network intrusion can be comprehensively assessed by combining the intensity of abnormal user behavior and traffic relationships.
It improves the accuracy of network intrusion detection, reduces the possibility of false positives, and enables in-depth analysis of abnormal user traffic to accurately determine the nature and severity of network intrusions.
Smart Images

Figure CN121567475B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data information transmission technology, and specifically to a network intrusion detection method and system based on a firewall. Background Technology
[0002] The campus network is a typical multi-user, multi-tasking environment. Network usage patterns vary among different groups, such as students and teachers, at different times. For example, students frequently access the internet during breaks or when submitting assignments, while teachers experience significant traffic fluctuations during online lectures. This situation affects the results of network intrusion detection on the campus network.
[0003] Firewalls can monitor and audit access to the campus network. All access to the campus network passes through the firewall. The firewall records the corresponding access and makes log entries, while also providing statistical data on network usage. When suspicious activity occurs, the firewall can issue appropriate alerts and provide detailed information on whether the network is being monitored or attacked.
[0004] The existing method for detecting network intrusion on campus networks involves monitoring campus network traffic and comparing it to a preset traffic threshold. This preset threshold is a fixed value; when the campus network traffic exceeds the threshold, it indicates an anomaly and a network intrusion is suspected. However, in many situations, different groups, such as students and teachers, frequently access the internet. For example, students often use the internet during breaks or when submitting assignments, and teachers generate significant traffic fluctuations during online lectures. Simply comparing traffic to a fixed threshold can easily lead to misjudgments, thus affecting the accuracy of campus network intrusion detection results. Summary of the Invention
[0005] To address the low accuracy of existing campus network intrusion detection methods, this invention aims to provide a firewall-based network intrusion detection method and system. The specific technical solution adopted is as follows:
[0006] In a first aspect of the present invention, a firewall-based network intrusion detection method is provided, comprising:
[0007] Identify the network instability period within the associated time period at the current moment, where the network instability period represents the period during which the total traffic of the campus network is unstable;
[0008] Based on the online status of users at each time during the network instability period and the instability of the total campus network traffic, the possibility of network intrusion during the network instability period is obtained, so as to filter out suspected intrusion periods;
[0009] Based on the active times of each user during the suspected intrusion period, and the correlation between user traffic during the active times and the total traffic of the campus network, the intensity of abnormal behavior of each user during the suspected intrusion period is obtained.
[0010] Based on the probability of the suspected intrusion period and the intensity of abnormal behavior of each user, the network intrusion risk of the suspected intrusion period is obtained;
[0011] Based on the network intrusion risk of each suspected intrusion period in the associated time period, the degree of network intrusion threat at the current moment is obtained.
[0012] In one exemplary embodiment, the process of obtaining the possibility includes:
[0013] The degree of network anomaly during the unstable period of the campus network is obtained from the instability of the total campus network traffic during the unstable period.
[0014] The online user stability at each time point is obtained by considering the degree of overlap between the online users at each time point and their adjacent time points during the network instability period; the online user stability is positively correlated with the degree of user overlap.
[0015] The target stability of online users during the network instability period is determined by the stability of online users at each time point during the network instability period.
[0016] Based on the degree of network anomaly and the stability of online user targets, the probability of network intrusion during the period of network instability is obtained; the probability is positively correlated with the degree of network anomaly and negatively correlated with the stability of online user targets.
[0017] In an exemplary embodiment, the process of obtaining the network anomaly level includes:
[0018] Determine the difference in total campus network traffic between the unstable network period and the adjacent preceding period, the degree of fluctuation in total campus network traffic during the unstable network period, and the range of total campus network traffic during the unstable network period;
[0019] The degree of network anomaly during the unstable period is obtained based on the difference in total campus network traffic, the degree of fluctuation in total campus network traffic, and the range of total campus network traffic. The degree of network anomaly is positively correlated with the difference in total campus network traffic, the degree of fluctuation in total campus network traffic, and the range of total campus network traffic.
[0020] In an exemplary embodiment, the process of obtaining the degree of user overlap includes:
[0021] The intersection-union ratio of the sets of users who are online at each time point with those at adjacent times is used as the degree of user overlap at each time point.
[0022] In an exemplary embodiment, the process of screening suspected intrusion periods includes: determining network instability periods with a probability greater than a preset probability threshold as suspected intrusion periods.
[0023] In an exemplary embodiment, the process of obtaining the intensity of the abnormal behavior includes:
[0024] The target active time period is obtained by filtering the active time periods of the user in the suspected intrusion period, and the active time period consists of consecutive active moments in time sequence;
[0025] Isolated active moments of the user during the suspected intrusion period, and active moments during the target active period, are considered as suspected abnormal moments of the user during the suspected intrusion period.
[0026] Based on the number of suspected abnormal moments for a user and the difference in user traffic between the suspected abnormal moments and adjacent moments, abnormal characteristics of users during the suspected intrusion period are obtained; the abnormal characteristics are positively correlated with both the number of suspected abnormal moments and the difference in user traffic.
[0027] The correlation between user traffic at active times and total campus network traffic at the same time is determined to obtain the correlation between user behavior and intrusion behavior for users during the suspected intrusion period;
[0028] By integrating the abnormal features and correlation, the intensity of abnormal behavior of users during the suspected intrusion period is obtained; the intensity of abnormal behavior is positively correlated with both the abnormal features and the correlation.
[0029] In an exemplary embodiment, the process of obtaining the correlation degree includes:
[0030] Determine the user traffic target sequence and the campus network total traffic target sequence; the user traffic target sequence is composed of the user traffic at each active moment of the user during the suspected intrusion period arranged in chronological order, and the campus network total traffic target sequence is composed of the campus network total traffic at each active moment of the same user during the suspected intrusion period arranged in chronological order;
[0031] Determine the correlation coefficient between the target sequence of user traffic and the target sequence of total campus network traffic;
[0032] Determine the number of active moments in which the target user traffic sequence and the target total campus network traffic sequence show the same trend at the same active moment;
[0033] The user's correlation degree is obtained based on the correlation coefficient and the number of active moments; the correlation degree is positively correlated with both the correlation coefficient and the number of active moments.
[0034] In one exemplary embodiment, the process of acquiring the network intrusion risk includes:
[0035] Based on the intensity of abnormal behavior of each user during the suspected intrusion period, suspected abnormal users are selected for the suspected intrusion period.
[0036] Determine the maximum intensity of abnormal behavior among the intensity of abnormal behavior of each suspected abnormal user during the suspected intrusion period;
[0037] Based on the probability of network intrusion during the suspected intrusion period, the network intrusion risk during the suspected intrusion period is obtained by considering the number of suspected abnormal users and the intensity of the maximum abnormal behavior during the suspected intrusion period; the network intrusion risk is positively correlated with the probability of network intrusion during the suspected intrusion period, the number of suspected abnormal users, and the intensity of the maximum abnormal behavior.
[0038] In an exemplary embodiment, the process of obtaining the network intrusion threat level includes:
[0039] Intrusion periods are determined by filtering the network intrusion risks of each suspected intrusion period;
[0040] The impact weight of network intrusion risk for each intrusion period is determined by the duration of each intrusion period; the impact weight is positively correlated with the duration of the intrusion period.
[0041] Based on the impact weight of network intrusion risk in each intrusion period, the network intrusion risk in each intrusion period is weighted and summed to obtain the overall performance of network intrusion risk.
[0042] The network intrusion threat level is obtained by combining the total duration of the intrusion period in the associated time period with the overall performance of the network intrusion risk; the network intrusion threat level is positively correlated with both the total duration of the intrusion period and the overall performance of the network intrusion risk.
[0043] In a second aspect of the present invention, a firewall-based network intrusion detection system is provided, comprising: a memory and a processor; the memory is connected to the processor; the memory is used to store program instructions; the processor is used to implement the above-described firewall-based network intrusion detection method when the program instructions are executed.
[0044] This invention offers the following advantages: It uses network instability periods within a relevant timeframe as the basis for analysis. Based on the online status of users during these periods and the overall instability of the campus network traffic, it identifies the likelihood of network intrusion during these periods, thus determining suspected intrusion periods. During network intrusion attacks, the active times of users within these suspected intrusion periods, and the correlation between user traffic during these active times and the overall campus network traffic, reveal the intensity of abnormal behavior for each user during the suspected intrusion periods. Combining the likelihood of network intrusion with the intensity of abnormal behavior for each user, a comprehensive analysis is conducted to determine the network intrusion risk during the suspected intrusion periods. Finally, a comprehensive analysis of the network intrusion risk for each suspected intrusion period within the relevant timeframes yields the current level of network intrusion threat. This invention delves into the abnormal network traffic of individual users and, combined with the relationship with the overall campus network traffic, ultimately determines the level of network intrusion threat. This allows for accurate determination of the existence and severity of network intrusion, significantly reducing the possibility of false positives and improving the accuracy of campus network intrusion detection results. Attached Figure Description
[0045] Figure 1 This is a flowchart of a firewall-based network intrusion detection method provided in one embodiment of the present invention;
[0046] Figure 2 This is a flowchart illustrating the process of obtaining the possibility of network intrusion during periods of network instability, provided in one embodiment of the present invention.
[0047] Figure 3 This is a flowchart of obtaining the intensity of abnormal behavior provided in one embodiment of the present invention;
[0048] Figure 4 This is a flowchart illustrating the process of obtaining network intrusion risks according to an embodiment of the present invention;
[0049] Figure 5 This is a flowchart illustrating the process of obtaining the network intrusion threat level according to an embodiment of the present invention. Detailed Implementation
[0050] To further illustrate the technical means and effects adopted by the present invention to achieve its intended purpose, the specific implementation methods, structures, features, and effects of the present invention are described in detail below with reference to the accompanying drawings and preferred embodiments. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics in one or more embodiments can be combined in any suitable form.
[0051] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. All data and information collected in this application have been obtained with full consent.
[0052] This embodiment provides a firewall-based network intrusion detection method, targeting the following specific scenario: the firewall can monitor and audit access to the campus network. All access to the campus network passes through the firewall. The firewall is controlled to record the corresponding access and make log entries, while also providing statistical data on network usage. When suspicious actions occur, the firewall can issue appropriate alarms and provide detailed information on whether the network is being monitored or attacked.
[0053] Within the campus network, the firewall itself already possesses traffic export capabilities such as NetFlow / sFlow. By enabling NetFlow on the firewall, each unidirectional flow is sent in real-time to a dedicated traffic collector / time-series database, thus obtaining the time series of the total campus network traffic. Subsequently, combined with the campus network's authentication system (802.1X, DHCP, Radius, campus card, etc.), each flow record is mapped to a specific user identifier (such as student ID, personal ID, etc.), and then aggregated by user in the database to obtain the time series of traffic for each user. The traffic of each user is defined as user traffic. It should be understood that the total campus network traffic and user traffic are sampled synchronously, and the sampling frequency is set according to the actual situation, such as once per second.
[0054] This embodiment provides a firewall-based network intrusion detection method, such as... Figure 1 As shown, it includes the following steps:
[0055] Step S1: Determine the network instability period within the associated time period at the current moment;
[0056] Step S2: Based on the number of users online at each time during the network instability period and the overall network traffic instability, determine the possibility of network intrusion during the network instability period, and filter out suspected intrusion periods.
[0057] Step S3: Based on the active times of each user during the suspected intrusion period, and the correlation between user traffic during the active times and the total traffic of the campus network, obtain the intensity of abnormal behavior of each user during the suspected intrusion period;
[0058] Step S4: Based on the probability of the suspected intrusion period and the intensity of abnormal behavior of each user, obtain the network intrusion risk of the suspected intrusion period;
[0059] Step S5: Based on the network intrusion risk of each suspected intrusion period in the associated time period, obtain the network intrusion threat level at the current moment.
[0060] The following detailed explanation of each step, in conjunction with the accompanying drawings, is provided.
[0061] Step S1: Determine the network instability period in the associated time period at the current moment.
[0062] Campus networks are typical multi-user, multi-tasking environments. Network usage patterns vary among students, teachers, and other users at different times. For example, students frequently access the internet during breaks or when submitting assignments, while teachers experience significant traffic fluctuations during online lectures. These normal activities may manifest as short-term fluctuations and instability within the overall traffic sequence. Simultaneously, malicious network behavior can also trigger sudden traffic spikes. These attacks create traffic surges through a large number of requests or data packets, leading to noticeable periods of network instability within a short period. Therefore, it is necessary to first identify the periods of network instability based on the total campus network traffic, and then conduct in-depth analysis of these periods to identify any malicious activity, thereby improving the accuracy of attack detection.
[0063] This embodiment uses the current moment as the analysis object to determine the associated time period. In an exemplary embodiment, the current moment and the preceding period adjacent to the current moment are considered as the associated time period, for example, the current moment and the preceding hour adjacent to the current moment are considered as the associated time period. Therefore, the associated time period contains multiple moments. The total campus network traffic sequence of the associated time period of the current moment is obtained. The total campus network traffic sequence is composed of the total campus network traffic at each moment within the associated time period arranged chronologically. For ease of explanation, this embodiment first normalizes the total campus network traffic at each moment in the total campus network traffic sequence (this embodiment uses maximum and minimum value normalization), so that the value of the total campus network traffic at each moment in the total campus network traffic sequence is within the range of 0-1, and the dimensions are eliminated, making the total campus network traffic at each moment a dimensionless data point, facilitating subsequent data processing. The total campus network traffic involved in subsequent processing is the normalized dimensionless data.
[0064] The network instability periods within the associated time period are identified, representing periods where the total campus network traffic is unstable. In an exemplary embodiment, for any given moment within the associated time period, the absolute value of the difference between the total campus network traffic at that moment and the total campus network traffic at the next adjacent moment is calculated, and this difference is taken as the campus network traffic instability at that moment. This yields the campus network traffic instability for each moment within the associated time period. It should be understood that, using the above method, the campus network traffic instability for the last moment within the associated time period cannot be obtained; therefore, the campus network traffic instability for the last moment within the associated time period is set to 0.
[0065] This embodiment presets a traffic instability threshold, which is used to determine whether the total campus network traffic instability is high at each moment, thereby obtaining the moments when the total campus network traffic is unstable. The value range of this preset traffic instability threshold is 0-1, and the specific value is set according to the actual judgment needs. In this embodiment, it is set to 0.6. Moments in the associated time period that are greater than or equal to this preset traffic instability threshold are identified as moments when the total campus network traffic is unstable. Time-series consecutive moments when the total campus network traffic is unstable constitute network unstable time periods, thus obtaining several network unstable time periods. It should be understood that time-series isolated moments when the total campus network traffic is unstable (i.e., neither of its left nor right adjacent moments are network unstable time periods) are very likely to be noise data. Therefore, this embodiment does not treat isolated moments when the total campus network traffic is unstable as a separate network unstable time period. It should be understood that there may be only one network unstable time period within the associated time period, or there may be at least two network unstable time periods. In special cases, there may not be any network unstable time periods. If there are no network unstable time periods, it means that the total campus network traffic within the associated time period at the current moment is always in a stable state, and it is directly determined that there is no network intrusion at the current moment, and no further data processing is performed.
[0066] The moments when the total traffic is below the preset traffic instability threshold are considered stable moments for the campus network. Consecutive stable moments are then considered stable network periods, resulting in several stable periods. The periods adjacent to unstable periods are then considered stable network periods. Stable network periods reflect data when traffic changes are stable, while unstable periods reflect data when traffic changes are unstable. A greater difference between an unstable period and its adjacent stable periods indicates a higher likelihood of abnormal network behavior.
[0067] Step S2: Based on the number of users online at each time during the network instability period and the overall network traffic instability, the possibility of network intrusion during the network instability period is determined, and suspected intrusion periods are selected.
[0068] Cyberattacks often cause drastic fluctuations in traffic. For example, in a DDoS attack, attackers send a large number of meaningless requests, causing a sharp increase in traffic. This traffic pattern contrasts sharply with normal, relatively stable traffic patterns. Therefore, for any period of network instability, there is a close correlation between the instability of the total campus network traffic during that period and the likelihood of a network intrusion. Furthermore, the number of users online at each moment during the period of network instability is also closely related to the likelihood of a network intrusion. Therefore, based on the number of users online at each moment during the period of network instability and the instability of the total campus network traffic, the likelihood of a network intrusion during that period can be determined. In an exemplary embodiment, such as... Figure 2 As shown below, a specific process for determining the possibility of network intrusion during periods of network instability is presented:
[0069] Step S21: Based on the instability of the total campus network traffic during periods of network instability, determine the degree of network anomaly during those periods.
[0070] For any network instability period, taking the b-th network instability period as an example, the network anomaly level of the b-th network instability period is obtained based on the instability of the total campus network traffic during the b-th network instability period. The more unstable the total campus network traffic, the higher the network anomaly level. In an exemplary embodiment, the average value of the total campus network traffic at each moment in the b-th network instability period is calculated as the average value of the total campus network traffic during the b-th network instability period. Then, the average value of the total campus network traffic at each moment in the preceding period adjacent to the b-th network instability period (i.e., the preceding stable period adjacent to the b-th network instability period) is calculated and defined as the associated average value of the total campus network traffic during the b-th network instability period. The absolute value of the difference between the average value of the total campus network traffic during the b-th network instability period and the associated average value of the total campus network traffic is calculated as the difference in total campus network traffic between the b-th network instability period and the preceding period adjacent to it. It should be understood that if there is no stable network period before the b-th unstable network period, this embodiment can adopt the following method: calculate the average of the average total campus network traffic of each stable network period in the associated period as the global average traffic of the stable network period; calculate the absolute value of the difference between the average total campus network traffic of the b-th unstable network period and the global average traffic of the stable network period as the difference in total campus network traffic between the b-th unstable network period and its adjacent preceding period. The greater the difference in total campus network traffic between the b-th unstable network period and its adjacent preceding period, the greater the relative difference in total campus network traffic of the b-th unstable network period, and the higher the degree of network anomaly in the b-th unstable network period; the two are positively correlated.
[0071] To obtain the fluctuation level of the total campus network traffic during the b-th period of network instability, in an exemplary embodiment, the fluctuation level is represented by the standard deviation. The standard deviation of the total campus network traffic at each moment during the b-th period of network instability is calculated as the fluctuation level of the total campus network traffic during the b-th period of network instability. A higher fluctuation level of the total campus network traffic during the b-th period of network instability indicates a higher degree of network anomaly during that period, and the two are positively correlated.
[0072] Obtain the maximum and minimum values of the total campus network traffic at each time point during the b-th period of network instability. Calculate the difference between these two values as the range of the total campus network traffic during the b-th period of network instability. A higher range of the total campus network traffic during the b-th period of network instability indicates a greater fluctuation in the total campus network traffic and a higher degree of network anomaly during the b-th period of network instability; the two are positively correlated.
[0073] Therefore, by combining the difference in total campus network traffic between the b-th unstable network period and its adjacent previous period, the degree of fluctuation in total campus network traffic during the b-th unstable network period, and the range of total campus network traffic during the b-th unstable network period, the degree of network anomaly during the b-th unstable network period is obtained. Based on the logical analysis above, the following is a specific calculation method for the degree of network anomaly during the b-th unstable network period:
[0074] ;
[0075] in, This indicates the degree of network anomaly during the b-th period of network instability. Let b be the difference in total campus network traffic between the b-th period of network instability and its adjacent preceding period. This indicates the degree of fluctuation in total campus network traffic during the b-th period of network instability. This represents the maximum value of the total campus network traffic at each time point during the b-th period of network instability. Let represent the minimum total campus network traffic at each time point during the b-th period of network instability. This represents the extreme level of total campus network traffic during the b-th period of network instability. The degree of network anomaly is obtained by averaging the three parameters. The higher the degree of network anomaly during the b-th period of network instability, the more likely there is a strong anomaly or attack.
[0076] Step S22: Based on the degree of overlap between the online users at each time point and their adjacent time points during the network instability period, the online user stability at each time point is obtained.
[0077] The total traffic of the campus network consists of the behavior of a large number of users (such as students and teachers). Abnormal network traffic is usually directly related to user behavior. For example, if abnormal traffic occurs at a certain time, and the user differences are large at this time, it may indicate that there is a DDoS attack or unauthorized access.
[0078] Taking the i-th moment within the b-th period of network instability as an example, we obtain the set of online users at the i-th moment. Online users are those who are currently online, and the set of online users at the i-th moment can be composed of the IDs of each user who is online at the i-th moment. This allows us to obtain the set of online users at each moment within the b-th period of network instability.
[0079] This section calculates the overlap between the online users at time i and its adjacent times within the b-th period of network instability. Specifically, if time i is the first time in the time sequence, the time adjacent to it is the next time, i.e., the second time; if time i is the last time in the time sequence, the time adjacent to it is the previous time, i.e., the second-to-last time; otherwise, the times adjacent to time i are its left and right adjacent times, i.e., the (i-1)th time and the (i+1)th time. The following example illustrates this: the times adjacent to time i are the (i-1)th time and the (i+1)th time.
[0080] Obtain the union of the online user sets at time i and its adjacent time points, i.e., the union of the online user sets at time i, i-1, and i+1. Also obtain the intersection of the online user sets at time i and its adjacent time points, i.e., the intersection of the online user sets at time i, i.e., the intersection of the online user sets at time i, i.e., the intersection-union ratio. Then calculate the ratio of the intersection to the union, i.e., the intersection-union ratio, and use the result as the degree of overlap of online users at time i and its adjacent time points. A higher degree of overlap indicates more users are simultaneously present at time i and its adjacent time points, resulting in higher online user stability at time i; the two are positively correlated. Based on the above logical analysis, the following is a specific method for calculating the online user stability at time i: use the degree of overlap of online users at time i and its adjacent time points as the online user stability at time i.
[0081] Step S23: Determine the target stability of online users during the period of network instability based on the stability of online users at each moment during the period of network instability.
[0082] Step S22 obtains the online user stability at each moment during the b-th network instability period, thereby determining the target online user stability for the b-th network instability period. In an exemplary embodiment, the minimum value of the online user stability at each moment during the b-th network instability period is taken, i.e., the minimum online user stability. To improve the reliability and security of determining the possibility of network intrusion during the b-th network instability period, the minimum online user stability during the b-th network instability period is used as the target online user stability for the b-th network instability period.
[0083] Step S24: Based on the degree of network anomaly and the stability of online user targets, determine the possibility of network intrusion during periods of network instability.
[0084] Based on the degree of network anomaly and the stability of online user targets during the b-th network instability period, the probability of network intrusion during the b-th network instability period is obtained. The higher the degree of network anomaly during the b-th network instability period, the greater the traffic fluctuation within that period, and the higher the probability of network intrusion; the two are positively correlated. Conversely, the lower the stability of online user targets during the b-th network instability period, the more drastic the changes in online users, and the higher the probability of network intrusion; the two are inversely correlated. Based on the above logic, the following is one method for calculating the probability of network intrusion during the b-th network instability period:
[0085] ;
[0086] in, This indicates the possibility of network intrusion during the b-th period of network instability. This represents the target stability of online users during the b-th period of network instability, which is the minimum stability of online users during the b-th period of network instability.
[0087] Using the above process, we can determine the probability of network intrusion during various periods of network instability. The higher the probability, the more likely there are a large number of unknown intrusion behaviors.
[0088] Then, based on the probability of network intrusion during each period of network instability, suspected intrusion periods are selected from these periods. The higher the probability, the more likely it is to be a suspected intrusion period. In an exemplary embodiment, a preset probability threshold is used to compare the probability of network intrusion during each period of network instability. The preset probability threshold ranges from 0 to 1, and the specific value is set according to actual needs. As an example, this embodiment uses 0.6. By comparing the probability of network intrusion during each period of network instability with the preset probability threshold, periods with a probability greater than the preset probability threshold are identified as suspected intrusion periods, thus obtaining several suspected intrusion periods. It should be understood that if no suspected intrusion period exists, this embodiment can directly determine that there is no network intrusion at the current moment, and no further data processing is performed.
[0089] Step S3: Based on the active times of each user during the suspected intrusion period, and the correlation between user traffic during the active times and the total traffic of the campus network, obtain the intensity of abnormal behavior of each user during the suspected intrusion period.
[0090] Campus networks are complex multi-user environments. The suspected intrusion periods obtained through the above steps can only determine that there are abnormal traffic fluctuations within the relevant time period, but cannot distinguish whether the abnormality is due to the attack behavior of a few malicious users or the high concurrency of business of most normal users. For example, high traffic during course selection week and DDoS attacks may both be classified as suspected intrusion periods, which may lead to fluctuations in normal user behavior and fluctuations in attack behavior being very similar. Therefore, after obtaining the suspected intrusion periods, further analysis of user behavior is required.
[0091] First, this embodiment normalizes the user traffic of each user within the associated time period at the current moment. In an exemplary embodiment, the maximum and minimum values (minimum value is 0) of the user traffic of all users within the associated time period at the current moment are obtained. Then, the maximum and minimum value normalization method is used to normalize the user traffic of each user within the associated time period at the current moment, so that the user traffic of each user within the associated time period at the current moment is dimensionless data. The user traffic mentioned below is dimensionless data.
[0092] Let the y-th suspected intrusion time period represent any suspected intrusion time period, and let the h-th user represent any single user. It should be understood that each user is a user who has an online record during the corresponding suspected intrusion time period.
[0093] The active moments of the h-th user during the y-th suspected intrusion period are determined, where an active moment represents a moment with high network traffic. In an exemplary embodiment, a preset traffic threshold is established, with a value ranging from 0 to 1. The specific value can be set according to actual needs, such as setting it to 0. Then, for the h-th user's traffic value at each moment during the y-th suspected intrusion period, if the user traffic value is greater than 0, indicating the presence of network traffic at that moment, it is determined to be an active moment; if the user traffic value is equal to 0, indicating the absence of network traffic at that moment, it is determined to be an inactive moment. Thus, the active moments of the h-th user during the y-th suspected intrusion period are obtained.
[0094] Then, based on the active times of the h-th user during the y-th suspected intrusion period, and the correlation between user traffic during those active times and the total campus network traffic, the intensity of the abnormal behavior of the h-th user during the y-th suspected intrusion period is obtained. In an exemplary embodiment, as follows... Figure 3 As shown below, a specific process for obtaining the intensity of abnormal behavior is given:
[0095] Step S31: Filter out the target active time period from the user's active time period during the suspected intrusion period.
[0096] Based on the active moments of the h-th user during the y-th suspected intrusion period, consecutive active moments in time will constitute an active period, thus yielding several active periods. It should be understood that isolated active moments, i.e., those whose left and right adjacent moments are not active moments, will not be considered as separate active periods.
[0097] Then, the target active period is obtained by filtering the active periods of the h-th user in the y-th suspected intrusion period. The target active period is the active period that matches the intrusion situation. Typically, when an intrusion occurs, attackers send a large number of small packets in a very short time interval to probe the target, such as through rapid port scanning, worm self-propagation, or control flow of distributed attacks. Therefore, active periods with potential network intrusion are usually short periods. Accordingly, the target active period is a short active period. Specifically, the active periods in the y-th suspected intrusion period containing an active number equal to or less than a preset number are defined as the target active period. Here, the preset number is a small value; for example, the preset number is 2, meaning an active period containing 2 active moments is defined as the target active period.
[0098] Step S32: Select isolated active moments of the user during the suspected intrusion period and active moments during the target active period as suspected abnormal moments of the user during the suspected intrusion period.
[0099] Since isolated active moments also fit the scenario of attackers committing network intrusions within extremely short time intervals, the isolated active moments of the h-th user in the y-th suspected intrusion period, and the active moments of the h-th user in the target active period in the y-th suspected intrusion period, are taken as the suspected abnormal moments of the h-th user in the y-th suspected intrusion period.
[0100] Step S33: Based on the number of suspected abnormal moments for a user and the difference in user traffic between the suspected abnormal moments and their adjacent moments, obtain the abnormal characteristics of the user during the suspected intrusion period.
[0101] The number of suspected abnormal moments for the h-th user during the y-th suspected intrusion period is counted. The more suspected abnormal moments the h-th user has during the y-th suspected intrusion period, the more obvious the abnormal characteristics of the h-th user during the y-th suspected intrusion period are. The two are positively correlated.
[0102] The greater the difference in user traffic between the suspected abnormal moment and its adjacent moments within the suspected intrusion period for the h-th user in the y-th suspected intrusion period, the more significant the jump in network traffic at the suspected abnormal moment, and the more obvious the abnormal characteristics of the h-th user in the y-th suspected intrusion period, with a positive correlation between the two. Specifically, if the suspected abnormal moment is an isolated active moment, the absolute value of the difference between the suspected abnormal moment and its left and right adjacent moments is calculated, and then the average of these two absolute differences is taken as the user traffic difference between the suspected abnormal moment and its adjacent moments. If the suspected abnormal moment belongs to one of the active moments in the target active period, the average of the user traffic of the two active moments in the target active period is calculated, and then the absolute value of the difference between this average and the user traffic of the left and right adjacent moments in the target active period is calculated, and then the average of these two absolute differences is taken as the user traffic difference corresponding to the target active period in which the suspected abnormal moment is located. It should be understood that if the suspected abnormal moment only has left or right adjacent moments, then only the user traffic difference with one adjacent moment is calculated.
[0103] Based on the above calculation, we can obtain the user traffic difference corresponding to each isolated active moment of the h-th user in the y-th suspected intrusion period, as well as the user traffic difference corresponding to each target active period. We calculate the average of the user traffic difference corresponding to each isolated active moment and the user traffic difference corresponding to each target active period, and use this average as the overall user traffic difference between the h-th user's suspected abnormal moment and its adjacent moments in the y-th suspected intrusion period.
[0104] It should be understood that, based on the specific implementation method described above, since the user traffic during inactive times is 0, the difference in user traffic is essentially the value of user traffic during suspected abnormal times, including: the value of user traffic during isolated active times, and the average value of user traffic during two active times in the target active period.
[0105] Based on the number of suspected abnormal moments for the h-th user during the y-th suspected intrusion period, and the overall difference in user traffic between the h-th user's suspected abnormal moments during the y-th suspected intrusion period and their adjacent moments, the abnormal characteristics of the h-th user during the y-th suspected intrusion period are obtained. Based on the above logical analysis, a specific calculation method for the abnormal characteristics is given below:
[0106] ;
[0107] in, This represents the abnormal characteristics of the h-th user within the y-th suspected intrusion time period; This represents the number of suspected abnormal moments for the h-th user during the y-th suspected intrusion period; This represents the total number of times during the y-th suspected intrusion period, i.e., the duration of the y-th suspected intrusion period. Since the suspected intrusion period is the actual time period selected, its value is not 0. This represents the percentage of suspected abnormal moments for the h-th user during the y-th suspected intrusion period, relative to the total duration of the y-th suspected intrusion period. It is equivalent to... The normalization can also be understood as the density of high-frequency jumps in the h-th user during the y-th suspected intrusion period; This represents the overall difference in user traffic between the suspected abnormal moment of the h-th user in the y-th suspected intrusion period and its adjacent moments.
[0108] The higher the density of high-frequency jumps of the h-th user during the y-th suspected intrusion period, and the greater the overall difference in user traffic between the h-th user's suspected abnormal moments and adjacent moments during the y-th suspected intrusion period, it indicates that the h-th user frequently changes its behavior pattern by requesting or closing network connections within a short period during the y-th suspected intrusion period. In other words, the more unpredictable the h-th user's behavior, the more likely this behavior is an abnormal behavior pattern driven by an attack program.
[0109] Step S34: Determine the correlation between user traffic during a user's active time and the total campus network traffic at the same time, and obtain the correlation between user behavior and intrusion behavior for users suspected of intrusion during the intrusion period.
[0110] In a multi-user environment like a campus network, normal high-traffic activities and malicious attack traffic fluctuations can be very similar, especially during high-concurrency periods such as course selection and exams, which are prone to generating similar attack-like traffic fluctuations. For example, students simultaneously selecting courses may generate a large amount of network traffic, leading to significant traffic fluctuations. Therefore, this embodiment further analyzes the correlation between these user behaviors and malicious attack behaviors to determine which traffic fluctuations are genuine malicious attacks and which are normal user operations.
[0111] In an exemplary embodiment, the user traffic of the h-th user at each active moment during the y-th suspected intrusion period is sorted chronologically to form the target sequence of user traffic for the h-th user during the y-th suspected intrusion period. For each active moment of the h-th user during the y-th suspected intrusion period, the total campus network traffic of the h-th user at each active moment during the y-th suspected intrusion period is obtained and sorted chronologically to obtain the target sequence of total campus network traffic corresponding to each active moment of the h-th user during the y-th suspected intrusion period. For ease of description, this is defined as the target sequence of total campus network traffic for the h-th user during the y-th suspected intrusion period.
[0112] Obtain the correlation coefficient between the target user traffic sequence of user h in the suspected intrusion period y and the target total campus network traffic sequence of user h in the suspected intrusion period y. In an exemplary embodiment, the correlation coefficient is specifically the Pearson correlation coefficient, that is, calculate the Pearson correlation coefficient between the target user traffic sequence of user h in the suspected intrusion period y and the target total campus network traffic sequence of user h in the suspected intrusion period y. The larger the Pearson correlation coefficient, the more similar the changes of the two sequences, and the higher the correlation between the user behavior of user h in the suspected intrusion period y and the intrusion behavior, indicating a positive correlation. To facilitate subsequent data processing, the Pearson correlation coefficient needs to be normalized. Since the Pearson correlation coefficient ranges from -1 to 1, the normalization method can be: (Pearson correlation coefficient + 1) / 2. The Pearson correlation coefficient mentioned below refers to the normalized result.
[0113] For any active moment of the h-th user during the y-th suspected intrusion period, the traffic change trend of that active moment in the user traffic target sequence and the campus network total traffic target sequence is obtained. This allows us to determine whether the two traffic change trends are the same at that active moment, thus obtaining the number of active moments with the same traffic change trend. In an exemplary embodiment, the least squares method is used to perform curve fitting on the user traffic target sequence and the campus network total traffic target sequence, respectively. Then, the slope of each active moment in the two curves is obtained, with the slope being positive, 0, or negative. For any active moment, if the slope of that active moment in the two curves has the same sign (e.g., both positive, both negative, or both 0), then the two traffic change trends at that active moment are considered the same; otherwise, the two traffic change trends are not the same. This yields the number of active moments with the same traffic change trend for the h-th user during the y-th suspected intrusion period.
[0114] The more active moments with the same traffic change trend for user h during suspected intrusion period y, the higher the correlation between user behavior and intrusion behavior for user h during suspected intrusion period y; the two are positively correlated. Therefore, based on the Pearson correlation coefficient corresponding to user h during suspected intrusion period y, and the number of active moments with the same traffic change trend for user h during suspected intrusion period y, the correlation between user behavior and intrusion behavior for user h during suspected intrusion period y can be obtained. Based on the above logical analysis, a specific calculation method for the correlation is given below:
[0115] ;
[0116] in, This represents the correlation between the user behavior of the h-th user during the y-th suspected intrusion period and the intrusion behavior. This represents the number of active moments in which the traffic change trend of the h-th user is the same during the y-th suspected intrusion period. This represents the number of active moments of the h-th user during the y-th suspected intrusion period. When the value is 0, the value 1 is used to replace the denominator in the calculation to avoid the problem of the denominator being 0; This represents the percentage of active moments with the same traffic change trend out of the total number of active moments, which is equivalent to... Normalization, Let Pearson's correlation coefficient represent the target sequence of user traffic for user h during suspected intrusion period y and the target sequence of total campus network traffic for user h during suspected intrusion period y.
[0117] The larger the Pearson correlation coefficient between the user traffic target sequence of user h in the suspected intrusion period y and the total campus network traffic target sequence of user h in the suspected intrusion period y, the more the behavior of user h matches the intrusion behavior. The more active moments in the suspected intrusion period y where the traffic change trend of user h is the same, the more active moments that user h exhibits characteristics consistent with intrusion behavior. User h is more likely to be a potential malicious attacker in the suspected intrusion period y, and the higher the correlation between its behavior and the intrusion behavior.
[0118] Step S35: Combine abnormal features and correlation to obtain the intensity of abnormal behavior of users during the suspected intrusion period.
[0119] The stronger the anomalous features of the h-th user during the y-th suspected intrusion period, the higher the intensity of the anomalous behavior of the h-th user during the y-th suspected intrusion period; the two are positively correlated. Similarly, the stronger the correlation between the user behavior of the h-th user during the y-th suspected intrusion period and the intrusion behavior, the higher the intensity of the anomalous behavior of the h-th user during the y-th suspected intrusion period; the two are also positively correlated. Based on the above logical analysis, in an exemplary embodiment, the anomalous features of the h-th user during the y-th suspected intrusion period are calculated. The correlation between user behavior and intrusion behavior targeting the h-th user during the y-th suspected intrusion time period. The average value is used as the result to determine the intensity of abnormal behavior of the h-th user in the y-th suspected intrusion period.
[0120] Step S4: Based on the probability of the suspected intrusion period and the intensity of abnormal behavior of each user, obtain the network intrusion risk of the suspected intrusion period.
[0121] The network intrusion risk for the y-th suspected intrusion period is obtained by combining the probability of network intrusion during the y-th suspected intrusion period with the intensity of abnormal behavior of each user during the y-th suspected intrusion period. In an exemplary embodiment, such as Figure 4 As shown below, a specific process for obtaining network intrusion risks is illustrated:
[0122] Step S41: Based on the intensity of abnormal behavior of each user during the suspected intrusion period, filter out suspected abnormal users during the suspected intrusion period.
[0123] A high correlation between a single user's behavior and intrusion activity may indicate a certain level of security threat, but this does not necessarily mean an attack will occur. Furthermore, the risk intensity of a security threat posed by a single user differs from that posed by multiple users. Therefore, quantifying network intrusion risk requires considering the potential attack behaviors of multiple users to improve the accuracy of attack prediction and enable timely protective measures.
[0124] For the y-th suspected intrusion period, suspected abnormal users for the y-th suspected intrusion period are obtained by filtering based on the intensity of abnormal behavior of each user during the y-th suspected intrusion period. The higher the intensity of abnormal behavior, the more likely the user is to be a suspected abnormal user. In an exemplary embodiment, this embodiment presets an abnormal behavior intensity threshold, which is used to compare with the abnormal behavior intensity of each user to identify users with higher abnormal behavior intensity. The value range of this preset abnormal behavior intensity threshold is 0-1, and the specific value is set according to the actual judgment needs; this embodiment uses 0.6 as an example.
[0125] The intensity of abnormal behavior of each user during the suspected intrusion period y is compared with a preset abnormal behavior intensity threshold. Users whose abnormal behavior intensity is greater than or equal to the preset threshold are identified as suspected abnormal users during the suspected intrusion period y. The more suspected abnormal users there are during the suspected intrusion period y, the higher the network intrusion risk during that period; the two are positively correlated.
[0126] Step S42: Determine the maximum abnormal behavior intensity among the abnormal behavior intensities of each suspected abnormal user during the suspected intrusion period.
[0127] The maximum abnormal behavior intensity is determined from the abnormal behavior intensity of each suspected abnormal user during the y-th suspected intrusion period. The greater the maximum abnormal behavior intensity, the higher the network intrusion risk during the y-th suspected intrusion period, and the two are positively correlated.
[0128] Step S43: Based on the possibility of network intrusion during the suspected intrusion period, the network intrusion risk during the suspected intrusion period is obtained by considering the number of suspected abnormal users and the intensity of the maximum abnormal behavior during the suspected intrusion period.
[0129] Based on the probability of a network intrusion during the y-th suspected intrusion period, the network intrusion risk for the y-th suspected intrusion period is obtained by considering the number of suspected abnormal users and the maximum intensity of abnormal behavior corresponding to the y-th suspected intrusion period. A higher probability of a network intrusion during the y-th suspected intrusion period corresponds to a higher network intrusion risk, and the two are positively correlated. Based on the above logical analysis, the following is a specific method for calculating the network intrusion risk for the y-th suspected intrusion period:
[0130] ;
[0131] in, This represents the network intrusion risk during the y-th suspected intrusion period. This indicates the possibility of a network intrusion during the y-th suspected intrusion period. This represents the number of suspected abnormal users during the y-th suspected intrusion period. This represents the number of users during the y-th suspected intrusion period. When the value is 0, the value 1 is used to replace the denominator in the calculation to avoid the problem of the denominator being 0; This represents the percentage of suspected abnormal users during the y-th suspected intrusion period, which is equivalent to... Normalization, This represents the maximum abnormal behavior intensity among the abnormal behavior intensities of all suspected abnormal users during the y-th suspected intrusion time period. Together, they characterize the intensity of attack activities during the y-th suspected intrusion period. The greater the network intrusion risk during the y-th suspected intrusion period, the more widespread the malicious activity, the larger the attack scale, and the greater the network intrusion risk, thus requiring more close attention.
[0132] Through the above process, the network intrusion risk of each suspected intrusion period in the associated time period is obtained.
[0133] Step S5: Based on the network intrusion risk of each suspected intrusion period in the associated time period, obtain the network intrusion threat level at the current moment.
[0134] A comprehensive analysis of network intrusion risks during each suspected intrusion period within a related timeframe is performed to determine the level of network intrusion threat at the current moment. In an exemplary embodiment, such as... Figure 5 As shown below, a specific process for obtaining the level of network intrusion threat is presented:
[0135] Step S51: Filter out the intrusion periods based on the network intrusion risk of each suspected intrusion period.
[0136] Based on the network intrusion risk of each suspected intrusion period within the associated time period, intrusion periods are selected from these suspected intrusion periods. The higher the network intrusion risk, the higher the probability that a suspected intrusion period is an intrusion period. In an exemplary embodiment, the network intrusion risk of each suspected intrusion period is compared with a preset network intrusion risk threshold. The suspected intrusion period corresponding to a network intrusion risk greater than or equal to the preset network intrusion risk threshold is taken as the intrusion period. The preset network intrusion risk threshold ranges from 0 to 1, and its specific value is set according to actual judgment needs; this embodiment uses 0.6 as an example.
[0137] Network intrusions typically don't happen instantly; they can be a gradual process involving multiple stages, such as reconnaissance, penetration, privilege escalation, and lateral movement. Each stage can manifest through different user behaviors and traffic patterns, thus requiring comprehensive analysis of multiple intrusion periods to reflect the actual network security threat at any given moment.
[0138] Step S52: Determine the impact weight of network intrusion risk for each intrusion period based on the duration of each intrusion period.
[0139] For any intrusion period, taking the r-th intrusion period as an example, the longer the duration of the r-th intrusion period, the greater its impact on the current network intrusion threat level; that is, the greater the impact weight of the network intrusion risk of the r-th intrusion period. Therefore, the impact weight is positively correlated with the duration of the intrusion period. In an exemplary embodiment, the sum of the durations of all intrusion periods within the associated time period is obtained, and the ratio of the duration of the r-th intrusion period to this sum of durations is calculated. The result is used as the impact weight of the network intrusion risk of the r-th intrusion period, ensuring that the sum of the impact weights of all intrusion periods within the associated time period is 1.
[0140] Step S53: Based on the impact weight of network intrusion risk in each intrusion period, the network intrusion risk in each intrusion period is weighted and summed to obtain the overall performance of network intrusion risk.
[0141] Based on the impact weight of network intrusion risk in each intrusion period within the associated time period, the network intrusion risks of each intrusion period within the associated time period are weighted and summed to obtain the overall network intrusion risk performance corresponding to the associated time period. The stronger the overall network intrusion risk performance, the higher the degree of network intrusion threat received at the current moment, and the two are positively correlated.
[0142] Step S54: Combine the total duration of the intrusion period in the associated time period with the overall performance of network intrusion risk to obtain the degree of network intrusion threat.
[0143] By integrating and analyzing the total duration of intrusion periods within the associated timeframes with the overall network intrusion risk performance corresponding to those periods, the level of network intrusion threat at the current moment can be determined. The longer the total duration of intrusion periods within the associated timeframes, the higher the level of network intrusion threat at the current moment; the two are positively correlated. Based on the above logical analysis, the following is a specific method for calculating the level of network intrusion threat at the current moment:
[0144] ;
[0145] in, This indicates the level of network intrusion threat currently being faced. This indicates the total duration of the intrusion period within the associated time period. Indicates the duration of the associated time period. This represents the percentage of total intrusion time in the associated time period, indicating the intrusion coverage rate within that period. It is equivalent to... Normalization, The number of intrusion periods within the associated time period. The influence weight of the r-th intrusion period within the associated time period. This represents the network intrusion risk during the r-th intrusion period within the associated timeframe. This represents the overall performance of network intrusion risk during the corresponding time period.
[0146] The higher the intrusion coverage during the associated time period, and the stronger the overall network intrusion risk during the associated time period, the more it indicates that the network is currently under high-intensity attack. Firewalls and security protection systems must be highly vigilant and take more stringent security measures.
[0147] Through the above process, the level of network intrusion threat received at the current moment is obtained. This level of threat allows for accurate quantification of the network attack intensity at that moment. A higher level of threat indicates a higher attack intensity, signifying a more severe security threat and a greater likelihood of more intrusions or attacks. In an exemplary embodiment, three preset ranges can be used to represent high, medium, and low attack intensity, respectively. For example, these ranges could be [0.6, 1], [0.3, 0.6], and [0, 0.3]. Based on the range of the current network intrusion threat level, the attack intensity is determined, facilitating timely implementation of relevant security measures.
[0148] In subsequent specific applications, this embodiment can also determine the K value (neighborhood size) in the LOF (Local Outlier Factor) algorithm based on the degree of network intrusion threat at the current moment, and use the LOF algorithm to determine abnormal traffic, which usually represents network intrusion, attack or malicious behavior.
[0149] The higher the level of network intrusion threat at any given moment, the smaller the K value in the LOF algorithm typically needs to be. This focuses the attention on a more localized neighborhood at the current moment, making it more sensitive to identifying sudden, localized anomalies and helping firewall systems more quickly identify network attacks or other intrusion behaviors. Therefore, the updated K value at the current moment is:
[0150] ;
[0151] in, The updated K value at the current moment. The preset initial value for K is 8 in this embodiment. This represents the function for rounding up.
[0152] Will Using the current neighborhood size as a reference, the LOF algorithm is executed on each user's traffic time-series sub-window and the total campus network traffic window to obtain the LOF anomaly score for each traffic flow. A higher LOF anomaly score indicates a more likely anomalous traffic flow. In an exemplary embodiment, traffic with an LOF anomaly score greater than or equal to 0.7 is considered anomalous. Once anomalous traffic is detected, the firewall should trigger corresponding protective measures according to pre-defined policies. Specifically: blocking IP addresses: temporarily blocking or blacklisting based on the IP address of the attack source; limiting bandwidth: limiting bandwidth for anomalous traffic to prevent resource exhaustion; increasing the strictness of traffic checks: improving the accuracy and frequency of network traffic analysis and enhancing the firewall's ability to analyze traffic patterns; alarming and logging: for detected anomalies, the system should promptly trigger alarms and record detailed attack logs. This not only helps defend against current attacks but also provides useful information for subsequent security analysis and attack tracing.
[0153] This embodiment also provides a firewall-based network intrusion detection system, including: a memory and a processor; the memory is connected to the processor, and the memory is used to store program instructions; the processor is used to implement the steps in the above-described firewall-based network intrusion detection method embodiment when the program instructions are executed.
[0154] In one exemplary embodiment, the present invention provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps described in the embodiments of the firewall-based network intrusion detection method.
[0155] It should be noted that the order of the above embodiments of the present invention is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. The processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0156] The various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments.
Claims
1. A network intrusion detection method based on a firewall, characterized in that, include: Identify the network instability period within the associated time period at the current moment, where the network instability period represents the period during which the total traffic of the campus network is unstable; Based on the online status of users at each time during the network instability period and the instability of the total campus network traffic, the possibility of network intrusion during the network instability period is obtained, so as to filter out suspected intrusion periods; Based on the active times of each user during the suspected intrusion period, and the correlation between user traffic during the active times and the total traffic of the campus network, the intensity of abnormal behavior of each user during the suspected intrusion period is obtained. Based on the probability of the suspected intrusion period and the intensity of abnormal behavior of each user, the network intrusion risk of the suspected intrusion period is obtained; Based on the network intrusion risk of each suspected intrusion period in the associated time period, the degree of network intrusion threat at the current moment is obtained; The process of obtaining the possibility includes: The degree of network anomaly during the unstable period of the campus network is obtained from the instability of the total campus network traffic during the unstable period. The online user stability at each time point is obtained by considering the degree of overlap between the online users at each time point and their adjacent time points during the network instability period; the online user stability is positively correlated with the degree of user overlap. The target stability of online users during the network instability period is determined by the stability of online users at each time point during the network instability period. Based on the network anomaly level and the stability of online user targets, the probability of network intrusion during the network instability period is obtained; the probability is positively correlated with the network anomaly level and negatively correlated with the stability of online user targets. The process of obtaining the network anomaly level includes: Determine the difference in total campus network traffic between the unstable network period and the adjacent preceding period, the degree of fluctuation in total campus network traffic during the unstable network period, and the range of total campus network traffic during the unstable network period; The degree of network anomaly during the period of network instability is obtained based on the differences in total campus network traffic, the degree of fluctuation in total campus network traffic, and the range of total campus network traffic. The degree of network anomaly is positively correlated with the differences in total campus network traffic, the degree of fluctuation in total campus network traffic, and the range of total campus network traffic. The process of obtaining the degree of user overlap includes: The intersection-union ratio of the sets of users who are online at each time point with those at adjacent times is used as the degree of user overlap at each time point.
2. The network intrusion detection method based on a firewall as described in claim 1, characterized in that, The screening process for suspected intrusion periods includes: identifying network instability periods with a probability greater than a preset probability threshold as suspected intrusion periods.
3. The network intrusion detection method based on a firewall as described in claim 1, characterized in that, The process of obtaining the intensity of the abnormal behavior includes: The target active time period is obtained by filtering the active time periods of the user in the suspected intrusion period, and the active time period consists of consecutive active moments in time sequence; Isolated active moments of the user during the suspected intrusion period, and active moments during the target active period, are considered as suspected abnormal moments of the user during the suspected intrusion period. Based on the number of suspected abnormal moments for a user and the difference in user traffic between the suspected abnormal moments and adjacent moments, abnormal characteristics of users during the suspected intrusion period are obtained; the abnormal characteristics are positively correlated with both the number of suspected abnormal moments and the difference in user traffic. The correlation between user traffic at active times and total campus network traffic at the same time is determined to obtain the correlation between user behavior and intrusion behavior for users during the suspected intrusion period; By integrating the abnormal features and correlation, the intensity of abnormal behavior of users during the suspected intrusion period is obtained; the intensity of abnormal behavior is positively correlated with both the abnormal features and the correlation.
4. The network intrusion detection method based on a firewall as described in claim 3, characterized in that, The process of obtaining the correlation degree includes: Determine the user traffic target sequence and the campus network total traffic target sequence; the user traffic target sequence is composed of the user traffic at each active moment of the user during the suspected intrusion period arranged in chronological order, and the campus network total traffic target sequence is composed of the campus network total traffic at each active moment of the same user during the suspected intrusion period arranged in chronological order; Determine the correlation coefficient between the target sequence of user traffic and the target sequence of total campus network traffic; Determine the number of active moments in which the target user traffic sequence and the target total campus network traffic sequence show the same trend at the same active moment; The user's correlation degree is obtained based on the correlation coefficient and the number of active moments; the correlation degree is positively correlated with both the correlation coefficient and the number of active moments.
5. The network intrusion detection method based on a firewall as described in claim 1, characterized in that, The process of acquiring the network intrusion risk includes: Based on the intensity of abnormal behavior of each user during the suspected intrusion period, suspected abnormal users are selected for the suspected intrusion period. Determine the maximum intensity of abnormal behavior among the intensity of abnormal behavior of each suspected abnormal user during the suspected intrusion period; Based on the probability of network intrusion during the suspected intrusion period, the network intrusion risk during the suspected intrusion period is obtained by considering the number of suspected abnormal users and the intensity of the maximum abnormal behavior during the suspected intrusion period; the network intrusion risk is positively correlated with the probability of network intrusion during the suspected intrusion period, the number of suspected abnormal users, and the intensity of the maximum abnormal behavior.
6. The network intrusion detection method based on a firewall as described in claim 1, characterized in that, The process of obtaining the network intrusion threat level includes: Intrusion periods are identified by filtering network intrusion risks during each suspected intrusion period; The impact weight of network intrusion risk for each intrusion period is determined by the duration of each intrusion period; the impact weight is positively correlated with the duration of the intrusion period. Based on the impact weight of network intrusion risk in each intrusion period, the network intrusion risk in each intrusion period is weighted and summed to obtain the overall performance of network intrusion risk. The network intrusion threat level is obtained by combining the total duration of the intrusion period in the associated time period with the overall performance of the network intrusion risk; the network intrusion threat level is positively correlated with both the total duration of the intrusion period and the overall performance of the network intrusion risk.
7. A firewall-based network intrusion detection system, characterized in that, include: Memory and processor; The memory is connected to the processor; The memory is used to store program instructions; The processor is configured to implement the firewall-based network intrusion detection method according to any one of claims 1-6 when program instructions are executed.