Feature library processing method, feature library updating method, electronic equipment and computer storage medium

By generating incremental feature library packages on a cloud server and constructing a judgment matrix using a layered analysis method on network devices, the problems of long upgrade times and insufficient targeted utilization of network device feature libraries are solved, thereby improving the feature recognition rate and security capabilities of devices and optimizing the utilization of feature data on the device side.

CN121664442APending Publication Date: 2026-03-13MAIPU COMM TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-09-13
Publication Date
2026-03-13

AI Technical Summary

Technical Problem

In existing technologies, the upgrade process of network device feature databases suffers from problems such as long full-scale upgrade time, high traffic consumption, and insufficient targeted use of feature data, which limits the improvement of network device security detection capabilities.

Method used

By generating incremental feature library packages on a cloud server, using the device attributes of network devices and the attributes of the feature library to construct a judgment matrix through a layered analysis method, a highly targeted incremental feature library package is generated, and incremental updates are performed on the network device side. At the same time, a temporary feature cache area is set up on the device side for real-time detection and updates.

Benefits of technology

This reduces feature database update time, improves feature recognition rate and security capabilities of network devices, optimizes feature data utilization efficiency, and reduces query pressure on cloud servers.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121664442A_ABST
    Figure CN121664442A_ABST
Patent Text Reader

Abstract

The invention discloses a feature library processing method, a feature library updating method, electronic equipment and a computer storage medium, and the feature library processing method is applied to a cloud server. Acquiring equipment attributes of to-be-updated network equipment and feature attributes of a to-be-updated local feature library; generating a feature library increment package of the local feature library to be updated by utilizing the equipment attribute and the feature attribute; and sending the feature library increment packet to the to-be-updated network equipment, so that the to-be-updated network equipment updates a local feature library. According to the method, the feature library incremental package for incremental updating is generated, so that the purpose of reducing the updating time can be achieved; and the feature library increment packet is generated by utilizing the equipment attribute of the network equipment to be updated and the feature attribute of the local feature library to be updated, and the data of the feature library increment packet has strong correlation with the network equipment and the feature library, so that the feature recognition rate of the network equipment and the effective rate of the features of the network equipment can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of deep packet inspection, and more particularly to feature library processing methods, feature library updating methods, electronic devices, and computer storage media. Background Technology

[0002] With the rapid development of the internet and the continuous expansion of network scale, the ever-increasing number of network attacks has significantly increased the configuration and maintenance costs of network equipment, posing a major challenge to the security capabilities of network devices. Therefore, Deep Packet Inspection (DPI) has been introduced. DPI works by deeply analyzing the content of data packets and identifying and classifying them using a signature database based on predefined rules and patterns. It can identify different applications, protocols, and services for management. By examining the header and payload of data packets, DPI helps network administrators understand the data being transmitted on the network and take appropriate measures. Therefore, a signature database is fundamental to network intrusion prevention. A signature database is a data file that stores certain characteristic information. Using the characteristic information stored in the database, network devices can effectively identify incoming traffic. Signature databases are typically used in conjunction with security detection, security defense, and other related business features to enhance the security detection capabilities of devices.

[0003] With the continuous development of cloud computing, the cloud has become the IT infrastructure connecting everything in the digital society. Many equipment manufacturers utilize cloud technology to deploy servers in the cloud, connecting network devices to these servers. The cloud servers store massive amounts of feature data, generating feature libraries. Traffic passing through the network devices queries the cloud server, providing attack protection. However, the large amount of query data not only increases the pressure on the cloud server but also affects the performance of the network devices. Therefore, some existing technologies offload the feature library to the network devices, with the cloud server primarily handling the sending of feature library update packages. However, the amount of data in a feature library is enormous, and the libraries contain a wide variety of types, including URL feature files, security defense feature files, application identification feature files, and antivirus feature files. Due to the limited memory of network devices, not all feature data can be stored within the device; only a limited amount of feature information is stored internally.

[0004] Currently, most feature library upgrades involve full upgrades, which delete the original feature data and import the new data from the upgrade package. Considering the vast variety and size of feature data, each full update requires significant time and bandwidth. Frequent upgrades lead to high bandwidth consumption and long processing times. Furthermore, the feature data used in network device upgrades is consistent and lacks specificity, resulting in some features being useful for network devices while others are irrelevant to user scenarios, leading to underutilization of feature data for network devices.

[0005] Therefore, considering the memory limitations of network devices, and how to effectively utilize cloud data and combine different influencing factors to provide different feature libraries for different devices in a targeted manner, thereby improving the basic feature library capabilities of network devices, is an urgent problem to be solved in this field. Summary of the Invention

[0006] The purpose of this invention is to overcome the shortcomings of the prior art and to provide a feature library processing method, a feature library updating method, an electronic device, and a computer storage medium.

[0007] The objective of this invention is achieved through the following technical solution:

[0008] A first aspect of the present invention provides a feature library processing method applied to a cloud server, the method comprising:

[0009] Obtain the device attributes of the network device to be updated and the feature attributes of the local feature library to be updated;

[0010] Using the device attributes and the feature attributes, generate the feature library incremental package to be updated for the local feature library;

[0011] The incremental packet of the feature library is sent to the network device to be updated so that the network device to be updated can update its local feature library.

[0012] Further, the device attributes include the application domain of the network device to be updated and / or the region where the network device to be updated is located; the feature attributes include the total number of feature hits for all network devices and / or the number of feature hits for the network device to be updated; before obtaining the device attributes of the network device to be updated and the feature attributes of the local feature library to be updated, the method further includes:

[0013] Establish a short connection with the network device to be updated;

[0014] The process of obtaining the device attributes of the network device to be updated and the feature attributes of the local feature library to be updated includes:

[0015] Receive and save device attributes reported by each network device;

[0016] Obtain feature hit data reported by each network device.

[0017] Further, the step of generating the incremental feature library package of the local feature library to be updated using the device attributes and the feature attributes includes:

[0018] Based on the aforementioned characteristic attributes and equipment attributes, a criterion layer is constructed using analytic hierarchy process (AHP) to establish a pairwise comparison judgment matrix.

[0019] Perform a consistency check on the judgment matrix; if it fails, adjust the matrix and perform the consistency check again.

[0020] Based on the calculation results of the weight values ​​of each indicator in the judgment matrix, the incremental feature library package to be updated is generated.

[0021] Furthermore, the network device is also equipped with a temporary feature cache area; the method further includes:

[0022] Obtain real-time features reported by network devices that were not detected in the temporary feature cache and local feature library;

[0023] The temporary deep packet detection results of the real-time features are generated using the feature library in the cloud.

[0024] The temporary deep packet inspection results are sent to the network device so that the network device can update its temporary feature cache based on the temporary deep packet inspection results.

[0025] A second aspect of the present invention provides a feature database update method applied to a network device, the method comprising:

[0026] Obtain the feature library incremental package sent by the cloud server, and use the feature library incremental package to incrementally update the local feature library; wherein, the feature library incremental package is generated by the cloud server using the device attributes of the network device and the feature attributes of the local feature library to be updated.

[0027] Furthermore, the device attributes include the application field of the network device to be updated and / or the region where the network device to be updated is located; the feature attributes include the total number of feature hits for all network devices and / or the number of feature hits for the network device to be updated;

[0028] Before obtaining the feature library incremental package sent by the cloud server and incrementally updating the local feature library using the feature library incremental package, the method further includes:

[0029] Establish a short connection to the cloud server;

[0030] Report the device attributes of this network device to the cloud server;

[0031] Report the feature hit data of this network device to the cloud server.

[0032] Furthermore, the incremental feature library package is generated by the cloud server using the device attributes of the network device and the feature attributes of the local feature library to be updated.

[0033] Furthermore, the network device is also equipped with a temporary feature cache area; the method further includes:

[0034] Report real-time features that were not detected in the local feature library and temporary feature cache to the cloud server;

[0035] The device receives temporary deep packet inspection results sent by the cloud server and updates its temporary feature cache based on these results; the temporary deep packet inspection results are generated by the cloud server's feature library based on real-time features.

[0036] A third aspect of the present invention provides an electronic device including a memory and a processor, wherein the memory stores computer instructions executable on the processor, and when the processor executes the computer instructions, it performs the steps of the feature library processing method as described in the first aspect, or performs the steps of the feature library updating method as described in the second aspect.

[0037] In a fourth aspect, the present invention provides a computer storage medium having computer instructions stored thereon, wherein when the computer instructions are executed, the steps of the feature library processing method as described in the first aspect are performed, or the steps of the feature library updating method as described in the second aspect are performed.

[0038] The beneficial effects of this invention are:

[0039] In an exemplary embodiment of the present invention, a network device can effectively identify passing traffic using a local feature library installed in the network device's deep packet inspection (DPI) system, thus solving the problem of large data volumes caused by placing the feature library solely on a cloud server. Simultaneously, the cloud server generates incremental feature library packets for incremental updates, reducing update time. Furthermore, these incremental feature library packets are generated using the device attributes of the network device to be updated and the feature attributes of the local feature library to be updated. Since the data in the incremental feature library packets is strongly correlated with both the network device and the feature library itself, this improves the network device's feature recognition rate and the effectiveness of its own features. Attached Figure Description

[0040] Figure 1 This is a schematic diagram of the network structure on which the feature library processing method and the feature library processing update method disclosed in an exemplary embodiment of the present invention are based;

[0041] Figure 2This is a flowchart of a feature library processing method disclosed in an exemplary embodiment of the present invention;

[0042] Figure 3 The flowchart for generating incremental feature library packages based on a feature library processing method disclosed in an exemplary embodiment of the present invention is as follows:

[0043] Figure 4 A flowchart of a temporary feature cache based on a feature library processing method disclosed in an exemplary embodiment of the present invention;

[0044] Figure 5 This is a flowchart of a feature library updating method disclosed in an exemplary embodiment of the present invention;

[0045] Figure 6 The flowchart for generating incremental feature library packages based on a feature library update method is disclosed as an exemplary embodiment of the present invention.

[0046] Figure 7 A flowchart of a temporary feature cache based on a feature library update method disclosed in an exemplary embodiment of the present invention;

[0047] Figure 8 This is a connection diagram of an electronic device provided in an exemplary embodiment of the present invention;

[0048] Figure 9 This is a schematic diagram of the connection of a computer storage medium provided in an exemplary embodiment of the present invention. Detailed Implementation

[0049] The technical solution of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0050] In the description of this invention, it should be noted that the directions or positional relationships indicated by terms such as "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer" are based on the directions or positional relationships shown in the accompanying drawings and are only for the convenience of describing this invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of this invention. Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.

[0051] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "joining" should be interpreted broadly. For example, they can refer to fixed connections, detachable connections, or integral connections; they can refer to mechanical connections or electrical connections; they can refer to direct connections or indirect connections through an intermediate medium; and they can refer to the internal communication between two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.

[0052] Furthermore, the technical features involved in the different embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.

[0053] In an exemplary embodiment of the present invention, a feature library processing method is provided. Wherein, Figure 1 The network architecture on which this exemplary embodiment method is based is illustrated: a local feature library (deep packet detection feature library for deep packet inspection) is installed on the network device, a user device accesses the network device and performs deep packet inspection on the data transmitted by the user device (wherein, the user device can be a PC or a mobile terminal), and the method is applied to a cloud server connected to the network device.

[0054] like Figure 2 As shown, the method includes the following sub-steps:

[0055] Obtain the device attributes of the network device to be updated and the feature attributes of the local feature library to be updated;

[0056] Using the device attributes and the feature attributes, generate the feature library incremental package to be updated for the local feature library;

[0057] The incremental packet of the feature library is sent to the network device to be updated so that the network device to be updated can update its local feature library.

[0058] Specifically, in this exemplary embodiment, the network device is connected to the user equipment. When the user equipment's traffic (i.e., the data transmitted by the user equipment) passes through the network device, the network device can effectively identify the passing traffic using a local feature library installed on the network device. For example, the network device's DPI depth detection module can calculate the hash value of the file and match it with the feature data in the local feature library. Based on the matching result and the configured execution status, the traffic is allowed or blocked. This approach can solve the problem of large data volume caused by placing the feature library only on a cloud server. Simultaneously, in this exemplary embodiment, the network device is also connected to a cloud server. The cloud server sends incremental feature library packets from the network device to the network device, and the network device uses these packets for incremental updates.

[0059] Among them, the cloud server generates incremental packages of feature library for incremental updates, which can reduce update time (i.e., incremental update method). Moreover, the incremental packages of feature library are generated using the device attributes of the network device to be updated and the feature attributes of the local feature library to be updated. Since the data of the incremental packages of feature library is strongly correlated with the network device itself and the feature library itself, it can improve the network device's own feature recognition rate and the effectiveness of the network device's own features.

[0060] It should be noted that the feature library update step can be either a scheduled update or a proactive update: a scheduled update means that the cloud server generates an incremental feature library package and sends it to the network device at regular intervals; a proactive update means that the cloud server generates an incremental feature library package and sends it directly to the network device, or the network device proactively obtains the incremental feature library package from the cloud server.

[0061] Meanwhile, the local feature library includes a URL feature library, a security defense feature library, an application identification feature library, and an anti-virus feature library. Different types of feature libraries correspond to different data matching detection rules and feature data.

[0062] More preferably, in an exemplary embodiment, the device attributes include the application domain of the network device to be updated and / or the region where the network device to be updated is located; the feature attributes include the total number of feature hits for all network devices and / or the number of feature hits for the network device to be updated; before obtaining the device attributes of the network device to be updated and the feature attributes of the local feature library to be updated, the method further includes:

[0063] Establish a short connection with the network device to be updated;

[0064] The process of obtaining the device attributes of the network device to be updated and the feature attributes of the local feature library to be updated includes:

[0065] Receive and save device attributes reported by each network device;

[0066] Obtain feature hit data reported by each network device.

[0067] Specifically, in this exemplary embodiment, the specific implementation methods of the device attributes of the network device and the feature attributes of the local feature library are disclosed, and the matching steps corresponding to the device attributes and feature attributes are disclosed, wherein:

[0068] The device attributes include the network device's application domain and / or the region where the network device is located. The network device's application domain can represent the domain of the user devices connected to the network device, and can be configured during network device startup (other basic configurations may include update frequency, etc.). The network device's region can be automatically obtained based on its IP address. Therefore, the cloud server can construct incremental feature database packets using the network device's application domain and / or the network device's region, i.e., constructing incremental feature database packets based on function and location, thereby increasing the probability of subsequent hits.

[0069] Correspondingly, the device attributes need to be reported by the network device to the cloud server. For the cloud server: first, a short connection is established with the network device to be updated, then the device attributes reported by the network device are received, and finally the device attributes are saved in the basic information table for subsequent data processing.

[0070] The feature attributes include the number of feature hits across all network devices and / or the number of feature hits of the network device to be updated. The number of feature hits across all network devices represents the total number of feature hits for all network devices; for example, feature A has a hit count of A1 across all network devices, and feature B has a hit count of B1 across all network devices. The number of feature hits of the network device to be updated represents the hit count for that specific network device; for example, feature A has a hit count of A2 on that specific network device, and feature B has a hit count of B2 on that specific network device. Therefore, the cloud server can construct incremental feature library packages using the number of feature hits across all network devices and / or the number of feature hits of the network device to be updated. That is, it constructs incremental feature library packages based on the number of feature hits (more hits indicate greater importance), thereby increasing the probability of subsequent hits.

[0071] Correspondingly, this feature attribute needs to be reported by the network device to the cloud server, while the cloud server only needs to obtain the feature hit data reported by the network device.

[0072] More preferably, in an exemplary embodiment, such as Figure 3 As shown, generating the incremental feature library package of the local feature library to be updated using the device attributes and the feature attributes includes:

[0073] Based on the aforementioned characteristic attributes and equipment attributes, a criterion layer is constructed using analytic hierarchy process (AHP) to establish a pairwise comparison judgment matrix.

[0074] Perform a consistency check on the judgment matrix; if it fails, adjust the matrix and perform the consistency check again.

[0075] Based on the calculation results of the weight values ​​of each indicator in the judgment matrix, the incremental feature library package to be updated is generated.

[0076] Specifically, in this exemplary embodiment, the cloud server employs the Analytic Hierarchy Process (AHP) algorithm to calculate the weights of feature data. AHP decomposes decision-related elements into multiple levels, such as objectives, criteria, and solutions, and performs qualitative and quantitative analysis based on these levels. The algorithm's criterion layer uses the device attributes and feature attributes (e.g., device attributes include the network device's application domain and / or the region where the network device is located; feature attributes include the number of feature hits for all network devices and / or the number of feature hits for the network device to be updated) as criteria, setting different values ​​for different criteria. For "generating the incremental feature library package of the local feature library to be updated based on the calculation results of the weight values ​​of each indicator in the judgment matrix," the implementation can be as follows: the algorithm calculates the weight value corresponding to each feature information; when performing incremental feature library updates, the top N values ​​with the weight values ​​are selected as the data basis for incremental feature library updates.

[0077] In other exemplary embodiments, the generation of incremental feature library packages can also take the form of updating the optimal features. The features reported by the device are sorted by hit, and the top-ranked features are packaged into an incremental feature library for full device updates. Compared with the optimal feature update method, the hierarchical analysis method of this exemplary embodiment can perform targeted feature updates for different devices, different groups of people, and different levels of attention.

[0078] Furthermore, in this exemplary embodiment, the criterion configuration is flexible. Users can calculate multi-dimensional weight values ​​through customization, thereby filtering the feature rule data they need. The feature library is then dynamically and incrementally updated to improve the device's feature recognition rate and the effectiveness of its own features. This fundamentally enhances the device's security capabilities.

[0079] Specifically, the various steps of the calculation using the analytic hierarchy process in this embodiment of the invention can be implemented in the following manner:

[0080] (1) Configure the criteria layer and calculate the indicator weight values. Based on the information reported by the network devices, the criteria layer indicators include four indicators: device application scenario, device region, total hit count, and local hit count (i.e., device attributes and feature attributes). Users compare these four indicators pairwise according to their needs, and provide different quantified values ​​(ranging from 1 to 9) based on their importance (quantification standards are shown in the table below), generating a judgment matrix between the target layer and the criteria layer (i.e., the pairwise comparison judgment matrix). Based on the pairwise indicator comparisons, the compared quantified values ​​are given.

[0081] Comparison of the two indicators Quantized value Row metrics are just as important as column metrics. 1 Row indicators are slightly more important than column indicators. 3 Row indicators are more important than column indicators. 5 Row indicators are significantly more important than column indicators. 7 Row ratio indicators are extremely important. 9 The median value between two adjacent judgments 2,4,6,8

[0082] (2) Determine if the weight values ​​are reasonable. Perform a consistency check on the above judgment matrix, calculate the CR value according to the corresponding formula, and determine whether the indicator quantification is reasonable and whether there are any contradictions. A CR value less than 0.1 is considered reasonable; otherwise, it needs to be adjusted, and the data size needs to be recalculated and adjusted.

[0083] (3) Perform a hierarchical overall ranking and calculate the quantization value corresponding to each indicator. For example, the quantization value of feature A is 0.8, and the quantization value of feature B is 0.3, etc.

[0084] Application scenarios High hit count of this machine Area Overall high hit rate Application scenarios 1 0.25 2 0.33 High hit count of this machine 4 1 8 2 Area 0.5 0.125 1 0.2 Overall high hit rate 3 0.5 5 1

[0085] (4) Calculate the weight value corresponding to each feature according to the above method. When performing incremental updates of the feature library, the feature with the highest weight value will be selected as the data basis for incremental updates of the feature library.

[0086] Based on the quantified values, the weight values ​​of the four indicators are calculated using the arithmetic mean method. The larger the weight value, the higher the priority. The order is: local high hit count > overall high hit count > application scenario > region.

[0087] Application scenarios High hit count of this machine Area Overall high hit rate Weight Application scenarios 1 0.25 2 0.33 0.12 High hit count of this machine 4 1 8 2 0.52 Area 0.5 0.125 1 0.2 0.061 Overall high hit rate 3 0.5 5 1 0.3

[0088] More preferably, in an exemplary embodiment, the network device is further provided with a temporary feature cache area;

[0089] like Figure 4 As shown, the method further includes:

[0090] Obtain real-time features reported by network devices that were not detected in the temporary feature cache and local feature library;

[0091] The temporary deep packet detection results of the real-time features are generated using the feature library in the cloud.

[0092] The temporary deep packet inspection results are sent to the network device so that the network device can update its temporary feature cache based on the temporary deep packet inspection results.

[0093] Specifically, in this exemplary embodiment, although the network device itself has a local feature library for deep packet inspection, when feature C in the traffic does not hit the local feature library, in order to prevent harmful data from passing through, the corresponding content of the data will still be sent to the cloud server for cloud query.

[0094] Therefore, to reduce high concurrency with the cloud server, a caching mechanism is implemented on the device. When traffic passes through the device, it first checks the temporary feature cache for virus information. If the temporary feature cache contains information, it is processed according to the status. If the temporary feature cache does not contain information, it queries the network device's local feature database. If the information is found, it is processed according to the result (the order of querying the local feature database and the temporary feature cache can be reversed). If no information is found, the request is sent to the cloud server for querying. The temporary deep packet inspection result obtained by the cloud server is saved in the temporary feature cache to avoid repeated queries to the cloud.

[0095] For cloud servers, once they obtain real-time features reported by network devices that are not detected in the local feature library and temporary feature cache, they use the feature library in the cloud to generate temporary deep packet inspection results for the real-time features (i.e., the cloud server's deep packet inspection module determines whether the real-time features are harmful), and finally send the temporary deep packet inspection results to the corresponding network devices.

[0096] Typically, the following situations require caching for judgment: (1) New features have not been updated and are inconsistent with the local feature library of the network device. (2) Rare features are used infrequently and have not been updated incrementally, so they do not correspond to the local feature library. (3) Normal files are sent frequently and are not in the local feature library.

[0097] Alternatively, the temporary feature cache can be cleared after the incremental update is completed.

[0098] In an exemplary embodiment of the present invention, a feature library update method is provided. Figure 1 The network architecture on which this exemplary embodiment method is based is illustrated: the local feature library is installed on a network device, the network device is connected to a user device and performs deep packet inspection on the data transmitted by the user device (wherein the user device may be a PC or a mobile terminal), and the method is based on the network device.

[0099] like Figure 5 As shown, the method includes:

[0100] Obtain the feature library incremental package sent by the cloud server, and use the feature library incremental package to incrementally update the local feature library; wherein, the feature library incremental package is generated by the cloud server using the device attributes of the network device and the feature attributes of the local feature library to be updated.

[0101] Specifically, in this exemplary embodiment, the network device is connected to the user equipment. When the user equipment's traffic and transmitted data pass through the network device, the network device can effectively identify the passing traffic using a local feature library installed on the network device. For example, the network device's DPI depth detection module can calculate the hash value of a file and match it with the feature data in the local feature library. Based on the matching result and the configured execution status, the traffic is allowed or blocked. This approach solves the problem of large data volumes caused by placing the feature library solely on a cloud server. Simultaneously, in this exemplary embodiment, the network device is also connected to a cloud server. The cloud server sends incremental feature library packets to the network device, and the network device uses these packets for incremental updates.

[0102] In this process, the cloud server generates incremental update packages for the feature library. The network device receives the incremental update packages sent by the cloud server and uses them to incrementally update its local feature library. This reduces update time (i.e., the incremental update method). Furthermore, the incremental update packages are generated using the device attributes of the network device to be updated and the feature attributes of the local feature library to be updated. Since the data in the incremental update packages is strongly correlated with the network device itself and the feature library itself, it can improve the network device's feature recognition rate and the effectiveness of the network device's own features.

[0103] It should be noted that the feature library update step can be either a scheduled update or a proactive update: a scheduled update means that the cloud server generates an incremental feature library package and sends it to the network device at regular intervals; a proactive update means that the cloud server generates an incremental feature library package and sends it directly to the network device, or the network device proactively obtains the incremental feature library package from the cloud server.

[0104] Meanwhile, the local feature library includes a URL feature library, a security defense feature library, an application identification feature library, and an anti-virus feature library. Different types of feature libraries correspond to different data matching detection rules and feature data.

[0105] More preferably, in an exemplary embodiment, the device attributes include the application domain of the network device to be updated and / or the region where the network device to be updated is located; the feature attributes include the total number of feature hits for all network devices and / or the number of feature hits for the network device to be updated;

[0106] Before obtaining the feature library incremental package sent by the cloud server and incrementally updating the local feature library using the feature library incremental package, the method further includes:

[0107] Establish a short connection to the cloud server;

[0108] Report the device attributes of this network device to the cloud server;

[0109] Report the feature hit data of this network device to the cloud server.

[0110] Specifically, in this exemplary embodiment, specific implementation methods of the device attributes of the network device and the feature attributes of the local feature library are disclosed, and matching steps corresponding to the device attributes and feature attributes are disclosed, wherein:

[0111] The device attributes include the network device's application domain and / or the region where the network device is located. The network device's application domain can represent the domain of the user devices connected to the network device, and can be configured during network device startup (other basic configurations may include update frequency, etc.). The network device's region can be automatically obtained based on its IP address. Therefore, the cloud server can construct incremental feature packages using the network device's application domain and / or region, representing the device attributes. This means constructing incremental feature packages based on function and location. The network device obtains these incremental feature packages and updates them, thereby increasing the probability of subsequent hits.

[0112] Correspondingly, the device attributes need to be reported by the network device to the cloud server (i.e., the network device access step). For the network device: first, a short connection is established with the cloud server, and the device attributes of the network device are reported for subsequent data processing by the cloud server.

[0113] The feature attributes include the number of feature hits across all network devices and / or the number of feature hits of the network device to be updated. The number of feature hits across all network devices represents the total number of feature hits for all network devices; for example, feature A is hit A1 across all network devices, and feature B is hit B1 across all network devices. The number of feature hits of the network device to be updated represents the number of feature hits for that specific network device; for example, feature A is hit A2 for that specific network device, and feature B is hit B2 for that specific network device. Therefore, the cloud server can construct incremental feature library packages using the number of feature hits across all network devices and / or the number of feature hits of the network device to be updated. That is, incremental feature library packages are constructed based on the number of feature hits (more hits indicate greater importance). Network devices obtain these incremental feature library packages for updates, thereby increasing the probability of subsequent hits.

[0114] Correspondingly, this feature attribute needs to be reported by the network device to the cloud server, while the network device only needs to report the feature hit data of the network device to the cloud server.

[0115] More preferably, in an exemplary embodiment, such as Figure 6 As shown, the incremental feature library package is generated by the cloud server using the device attributes of the network device and the feature attributes of the local feature library to be updated, and includes:

[0116] Based on the aforementioned characteristic attributes and equipment attributes, a criterion layer is constructed using analytic hierarchy process (AHP) to establish a pairwise comparison judgment matrix.

[0117] Perform a consistency check on the judgment matrix; if it fails, adjust the matrix and perform the consistency check again.

[0118] Based on the calculation results of the weight values ​​of each indicator in the judgment matrix, the incremental feature library package to be updated is generated.

[0119] Specifically, in this exemplary embodiment, the cloud server employs the Analytic Hierarchy Process (AHP) algorithm to calculate the weights of feature data. AHP decomposes decision-related elements into multiple levels, such as objectives, criteria, and solutions, and performs qualitative and quantitative analysis based on these levels. The algorithm's criterion layer uses the device attributes and feature attributes (e.g., device attributes include the network device's application domain and / or the region where the network device is located; feature attributes include the number of feature hits for all network devices and / or the number of feature hits for the network device to be updated) as criteria, setting different values ​​for different criteria. For "generating the incremental feature library package of the local feature library to be updated based on the calculation results of the weight values ​​of each indicator in the judgment matrix," the implementation can be as follows: the algorithm calculates the weight value corresponding to each feature information; when performing incremental feature library updates, the top N values ​​with the weight values ​​are selected as the data basis for incremental feature library updates.

[0120] In other exemplary embodiments, the generation of incremental feature library packages can also take the form of updating the optimal features. The features reported by the device are sorted by hit, and the top-ranked features are packaged into an incremental feature library for full device updates. Compared with the optimal feature update method, the hierarchical analysis method of this exemplary embodiment can perform targeted feature updates for different devices, different groups of people, and different levels of attention.

[0121] Therefore, in this exemplary embodiment, the criterion configuration is flexible. Users can calculate multi-dimensional weight values ​​through customization, thereby filtering out the feature rule data they need. The feature library is then updated dynamically and incrementally to improve the device's feature recognition rate and the effectiveness of its own features. This fundamentally enhances the device's security capabilities.

[0122] Specifically, the steps of hierarchical analysis can be implemented in the following way:

[0123] (1) Configure the criteria layer and calculate the indicator weight values. Based on the information reported by the network devices, the criteria layer information includes four indicators (i.e., device attributes and feature attributes): device application scenario, device region, overall high hit count, and local high hit count. Users compare these four indicators pairwise according to their needs, and based on their importance, provide different quantified values ​​(ranging from 1 to 9) to generate a judgment matrix (i.e., a pairwise comparison judgment matrix) between the target layer and the indicator layer. Quantified values ​​are then provided based on the pairwise comparisons.

[0124] Comparison of the two indicators Quantized value Row metrics are just as important as column metrics. 1 Row indicators are slightly more important than column indicators. 3 Row indicators are more important than column indicators. 5 Row indicators are significantly more important than column indicators. 7 Row ratio indicators are extremely important. 9 The median value between two adjacent judgments 2,4,6,8

[0125] (2) Determine if the weight values ​​are reasonable. Perform a consistency check on the above judgment matrix, calculate the CR value according to the corresponding formula, and determine whether the indicator quantification is reasonable and whether there are any contradictions. A CR value less than 0.1 is considered reasonable; otherwise, it needs to be adjusted, and the data size needs to be recalculated and adjusted.

[0126] (3) Perform a hierarchical overall sort and calculate the quantization value corresponding to each feature. For example, the quantization value of feature A is 0.8, the quantization value of feature B is 0.3, etc.

[0127]

[0128]

[0129] (4) Calculate the weight value corresponding to each feature according to the above method. When performing incremental updates of the feature library, the value of the feature with the highest weight value will be selected as the data basis for incremental updates of the feature library.

[0130] Application scenarios High hit count of this machine Area Overall high hit rate Weight Application scenarios 1 0.25 2 0.33 0.12 High hit count of this machine 4 1 8 2 0.52 Area 0.5 0.125 1 0.2 0.061 Overall high hit rate 3 0.5 5 1 0.3

[0131] More preferably, in an exemplary embodiment, the network device is further provided with a temporary feature cache area;

[0132] like Figure 7 As shown, the method further includes:

[0133] Report real-time features that were not detected in the local feature library and temporary feature cache to the cloud server;

[0134] The device receives temporary deep packet inspection results sent by the cloud server and updates its temporary feature cache based on these results; the temporary deep packet inspection results are generated by the cloud server's feature library based on real-time features.

[0135] Specifically, in this exemplary embodiment, although the network device itself has a local feature library for deep packet inspection, when feature C in the traffic does not hit the local feature library, in order to prevent harmful data from passing through, the corresponding content of the data will still be sent to the cloud server for cloud query.

[0136] Therefore, to reduce high concurrency with the cloud server, a caching mechanism is implemented on the device. When traffic passes through the device, it first checks the temporary feature cache for virus information. If the temporary feature cache contains information, it is processed according to the status. If the temporary feature cache does not contain information, it queries the network device's local feature database. If the information is found, it is processed according to the result (the order of querying the local feature database and the temporary feature cache can be reversed). If no information is found, the network device reports the real-time features not detected in the local feature database and the temporary feature cache to the cloud server. After receiving the temporary deep packet inspection results from the cloud server, the network device stores the temporary deep packet inspection results in the network device's temporary feature cache to avoid repeated queries to the cloud.

[0137] For network devices, if a feature is not detected in the local feature library and temporary feature cache, the feature (i.e., real-time feature) is sent directly to the cloud server. Finally, the temporary deep packet inspection result sent by the cloud server is stored in the temporary feature cache.

[0138] Typically, the following situations require caching for judgment: (1) New features have not been updated and are inconsistent with the local feature library of the network device. (2) Rare features are used infrequently and have not been updated incrementally, so they do not correspond to the local feature library. (3) Normal files are sent frequently and are not in the local feature library.

[0139] Alternatively, the temporary feature cache can be cleared after the incremental update is completed.

[0140] See Figure 8 Another exemplary embodiment of the present invention provides an electronic device including a memory and a processor, wherein the memory stores computer instructions executable on the processor, and when the processor executes the computer instructions, it performs the steps of the feature library processing method or the steps of the feature library updating method.

[0141] Wherein, if the electronic device executes the feature library processing method when its processor runs computer instructions, then the electronic device can be a cloud server; if the electronic device executes the feature library update method when its processor runs computer instructions, then the electronic device can be a network device.

[0142] See Figure 9Another exemplary embodiment of the present invention provides a computer storage medium storing computer instructions thereon, wherein when the computer instructions are executed, the steps of the feature library processing method or the steps of the feature library updating method are performed.

[0143] Obviously, the above embodiments are merely illustrative examples for clear explanation and are not intended to limit the implementation. Those skilled in the art can make other variations or modifications based on the above description. It is neither necessary nor possible to exhaustively list all possible implementations. However, obvious variations or modifications derived therefrom are still within the scope of protection of this invention.

Claims

1. A feature library processing method, characterized in that, Applied to cloud servers, the method includes: Obtain the device attributes of the network device to be updated and the feature attributes of the local feature library to be updated; Using the device attributes and the feature attributes, generate the feature library incremental package to be updated for the local feature library; The incremental packet of the feature library is sent to the network device to be updated so that the network device to be updated can update its local feature library.

2. The method according to claim 1, characterized in that: The device attributes include the application field of the network device to be updated and / or the region where the network device to be updated is located; the feature attributes include the total number of feature hits for all network devices and / or the number of feature hits for the network device to be updated; Before obtaining the device attributes of the network device to be updated and the feature attributes of the local feature library to be updated, the method further includes: Establish a short connection with the network device to be updated; The process of obtaining the device attributes of the network device to be updated and the feature attributes of the local feature library to be updated includes: Receive and save device attributes reported by each network device; Obtain feature hit data reported by each network device.

3. The method according to claim 1 or 2, characterized in that: The step of generating the incremental feature library package of the local feature library to be updated using the device attributes and the feature attributes includes: Based on the aforementioned characteristic attributes and equipment attributes, a criterion layer is constructed using analytic hierarchy process (AHP) to establish a pairwise comparison judgment matrix. Perform a consistency check on the judgment matrix; if it fails, adjust the matrix and perform the consistency check again. Based on the calculation results of the weight values ​​of each indicator in the judgment matrix, the incremental feature library package to be updated is generated.

4. The method according to claim 1, characterized in that: The network device is also equipped with a temporary feature cache area; the method further includes: Obtain real-time features reported by network devices that were not detected in the temporary feature cache and local feature library; The temporary deep packet detection results of the real-time features are generated using the feature library in the cloud. The temporary deep packet inspection results are sent to the network device so that the network device can update its temporary feature cache based on the temporary deep packet inspection results.

5. A feature library update method, characterized in that, Applied to network devices, the method includes: Obtain the feature library incremental package sent by the cloud server, and use the feature library incremental package to incrementally update the local feature library; wherein, the feature library incremental package is generated by the cloud server using the device attributes of the network device and the feature attributes of the local feature library to be updated.

6. The method according to claim 5, characterized in that: The device attributes include the application field of the network device to be updated and / or the region where the network device to be updated is located; the feature attributes include the total number of feature hits for all network devices and / or the number of feature hits for the network device to be updated; Before obtaining the feature library incremental package sent by the cloud server and incrementally updating the local feature library using the feature library incremental package, the method further includes: Establish a short connection to the cloud server; Report the device attributes of this network device to the cloud server; Report the feature hit data of this network device to the cloud server.

7. The method according to claim 5 or 6, characterized in that: The incremental feature library package is generated by the cloud server using the device attributes of the network device and the feature attributes of the local feature library to be updated.

8. The method according to claim 5, characterized in that: The network device is also equipped with a temporary feature cache area; the method further includes: Report real-time features that were not detected in the local feature library and temporary feature cache to the cloud server; The device receives temporary deep packet inspection results sent by the cloud server and updates its temporary feature cache based on these results; the temporary deep packet inspection results are generated by the cloud server's feature library based on real-time features.

9. An electronic device comprising a memory and a processor, wherein the memory stores computer instructions executable on the processor, characterized in that: When the processor executes the computer instructions, it performs the steps of the feature library processing method as described in any one of claims 1-4, or the steps of the feature library updating method as described in any one of claims 5-8.

10. A computer storage medium storing computer instructions thereon, characterized in that: When the computer instructions are executed, they perform the steps of the feature library processing method as described in any one of claims 1-4, or the steps of the feature library updating method as described in any one of claims 5-8.