Business monitoring method, device and equipment and readable storage medium

By dynamically constructing a strong correlation between service statistics sets and real-time traffic monitoring data in network devices, the problem of real-time response to sudden or unknown security events in existing network traffic monitoring methods is solved, improving the efficiency and accuracy of network anomaly analysis and response, and reducing resource waste.

CN121792192APending Publication Date: 2026-04-03NEW H3C TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-29
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing network traffic monitoring methods are insufficient for real-time perception and response to sudden or unknown security events, and the pre-configuration of specific monitoring targets lacks dynamic adaptability, resulting in resource waste and system performance degradation.

Method used

By dynamically constructing a service statistics set that matches security services and packet IP address information in network devices, and initializing it based on underlying real-time traffic monitoring data, a strong correlation is established between security services and traffic monitoring data, enabling accurate identification of monitoring targets and resource optimization.

Benefits of technology

It improves the efficiency and accuracy of network anomaly analysis and response, reduces resource waste, and enables rapid identification and effective monitoring of potential security risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121792192A_ABST
    Figure CN121792192A_ABST
Patent Text Reader

Abstract

The invention provides a service monitoring method, device and equipment and a readable storage medium, and the method comprises the steps: dynamically constructing a service statistical set matched with a safety service and message IP address information under the condition that the safety service detects that a current message of network equipment has a potential safety risk; the service statistics is initialized based on the monitoring data matched with the IP address information of the message in the existing real-time flow monitoring data of the bottom layer, so that effective and intuitive strong association between various security service / modules and the real-time flow monitoring data of the bottom layer is established, and the security alarm and the network behavior context are effectively associated; the user can quickly judge whether the behavior harms the safety of the network equipment or not when analyzing and disposing the network abnormity, so that the studying and judging efficiency and the response accuracy are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication security technology, and in particular to a service monitoring method, apparatus, device, and readable storage medium. Background Technology

[0002] Currently, network traffic monitoring is mainly divided into two categories: traffic monitoring based on log recording and traffic monitoring based on traffic collection.

[0003] Traffic monitoring based on log recording relies on historical records such as generated access logs and session logs for delayed analysis, which is difficult to meet the needs of real-time perception and response to abnormal traffic behavior.

[0004] Traffic monitoring based on traffic collection typically requires pre-configuration of explicit monitoring targets, such as specified source / destination IPs, address groups, or application identifiers. That is, it relies on operations personnel to pre-determine which addresses or applications may pose a risk and manually enable corresponding monitoring policies. This pre-configured approach lacks dynamic adaptability, making it difficult to achieve timely and effective monitoring of sudden or unknown security events. Furthermore, the widespread activation of monitoring policies to cover potential risks leads to a large number of low-value or idle monitoring sets continuously consuming memory and computing resources, resulting in system performance degradation and resource waste. Summary of the Invention

[0005] In view of this, in order to solve the above-mentioned technical problems, this application provides a business monitoring method, device, equipment and readable storage medium, which realizes the accurate association between security business alarms and network behavior context, accurately focuses the monitoring object through the real-time detection results of security business, avoids the waste of resources caused by blind configuration, and improves the efficiency of equipment risk detection and response while ensuring high real-time performance and high accuracy.

[0006] Specifically, this application is implemented through the following technical solution: According to a first aspect of the embodiments of this application, a service monitoring method is provided, applied to a network device, the method comprising: For each security service policy that matches the currently received message, check whether there is a service statistics set under the security service that matches the message, based on the service information of the security service to which the security service policy belongs and the IP address information of the message. If no service statistics set matching the packet exists under the security service, traffic monitoring data matching the IP address information of the packet within a preset time period is obtained from the existing traffic monitoring set. Based on the traffic monitoring data, the IP address information of the packet, and the service information of the security service, a service statistics set matching the packet under the security service is constructed, and the communication characteristics corresponding to the packet and the current time are recorded in the service statistics set. The service statistics set is used to monitor packets under the security service that have the same IP address information as the currently received packet.

[0007] Optionally, the method further includes: If a service statistics set matching the message exists under this security service, then the communication characteristics and current time corresponding to the message are recorded in the existing service statistics set.

[0008] Optionally, constructing the service statistics set matching the message under the security service includes: Generate a first set, and configure an identifier attribute for the first set based on the service information of the security service, the IP address information of the packet, and the current time; Traffic monitoring data that match the IP address information of the packet within a preset time period in the traffic monitoring set are recorded sequentially into the first set according to time sequence to form the business statistics set.

[0009] Optionally, check if there exists a service statistics set under this security service that matches the message, including: The network device detects service statistics sets that meet the following conditions from existing service statistics sets: the identification attribute of the service statistics set includes service information of the security service to which the security service policy belongs, and also includes the IP address information of the packet. If a service statistics set that meets the conditions is detected, then there exists a service statistics set under the security service that matches the message; otherwise, there is no service statistics set under the security service that matches the message.

[0010] Optionally, the IP address information includes the source IP address, and the traffic monitoring data is monitoring data generated from packets sent by the network device indicated by the source IP address within a preset time period; Alternatively, the IP address information includes the target IP address, and the traffic monitoring data is monitoring data generated by packets sent to the network device indicated by the target IP address within a preset time period; Alternatively, the IP address information may include a source IP address and a destination IP address, and the traffic monitoring data may be monitoring data generated from messages sent by the network device indicated by the source IP address to the network device indicated by the destination IP address within a preset time period.

[0011] Optionally, before checking whether a service statistics set matching the message exists under the security service, the method further includes: Check whether the network device has enabled the security service policy associated traffic monitoring function; If so, check if there is a service statistics set under this security service that matches the message; If not, then based on the message and the service information of the security service to which the security service policy matches the message, a log record corresponding to the security service is generated.

[0012] Optionally, each traffic monitoring set is associated with at least one traffic identification field, and a field value is set for the traffic identification field; the traffic monitoring set is used to monitor packets entering the network device that match the field value to generate monitoring data; the traffic identification field includes at least the source IP address, the destination IP address, and the application identifier of the application to which the packet belongs; the step of obtaining traffic monitoring data matching the IP address information of the packet within a preset time period from an existing traffic monitoring set includes: When multiple target traffic monitoring sets are identified from the existing traffic monitoring sets, traffic monitoring data that matches the IP address information of the packet within a preset time period is extracted from each target traffic monitoring set; wherein, the traffic identification field and its field value associated with the target traffic monitoring set match the IP address information of the packet. To obtain target traffic monitoring data, the traffic monitoring data is extracted from the traffic monitoring data of each target traffic monitoring set. The target traffic monitoring data is used as the traffic monitoring data that matches the IP address information of the packet within the preset time period; wherein, any target traffic monitoring data is simultaneously matched with the traffic identification field and its value used by each target traffic monitoring set when matching the IP address information of the packet.

[0013] Optionally, the method further includes: If the traffic monitoring set does not exist, or if there is no traffic monitoring data matching the IP address information of the packet within a preset time period in the traffic monitoring set, a service statistics set matching the packet under the security service is constructed based on the service information of the security service to which the security service policy matches the packet, and the IP address information of the packet. The communication characteristics corresponding to the packet and the current time are recorded in the service statistics set.

[0014] Optionally, based on the service information of the security service to which the security service policy matches the message belongs, and the IP address information of the message, a service statistics set matching the message under the security service is constructed, including: A second set is generated, and an identification attribute is configured for the second set based on the service information of the security service, the IP address information of the packet, and the current time, so that the second set with the configured identification attribute is used as the service statistics set.

[0015] Optionally, the security business policy may include one of the following business types: threat detection, content security, behavior control, or application identification.

[0016] According to a second aspect of the embodiments of this application, a service monitoring device is provided, applied to a network device, the device comprising: The inspection module is configured to check, for each security service policy that matches the currently received packet, whether there is a service statistics set under the security service that matches the packet, based on the service information of the security service to which the security service policy belongs and the IP address information of the packet. The first construction module is configured to, if no service statistics set matching the packet exists under the security service, obtain traffic monitoring data matching the IP address information of the packet within a preset time period from an existing traffic monitoring set, and construct a service statistics set matching the packet under the security service based on the traffic monitoring data, the IP address information of the packet, and the service information of the security service, and record the communication characteristics corresponding to the packet and the current time into the service statistics set; wherein, the service statistics set is used to monitor packets under the security service that have the same IP address information as the currently received packet.

[0017] Optionally, the device further includes: The statistics set update module is configured to record the communication characteristics and current time corresponding to the message into the existing statistics set if a service statistics set matching the message exists under the security service.

[0018] Optionally, when the first construction module is configured to construct a service statistics set matching the message under the security service, it includes: Generate a first set, and configure an identifier attribute for the first set based on the service information of the security service, the IP address information of the packet, and the current time; Traffic monitoring data that match the IP address information of the packet within a preset time period in the traffic monitoring set are recorded sequentially into the first set according to time sequence to form the business statistics set.

[0019] Optionally, when the inspection module is configured to check whether a service statistics set matching the message exists under the security service, it includes: The network device detects service statistics sets that meet the following conditions from existing service statistics sets: the identification attribute of the service statistics set includes service information of the security service to which the security service policy belongs, and also includes the IP address information of the packet. If a service statistics set that meets the conditions is detected, then there exists a service statistics set under the security service that matches the message; otherwise, there is no service statistics set under the security service that matches the message.

[0020] Optionally, the IP address information includes the source IP address, and the traffic monitoring data is monitoring data generated from packets sent by the network device indicated by the source IP address within a preset time period; Alternatively, the IP address information includes the target IP address, and the traffic monitoring data is monitoring data generated by packets sent to the network device indicated by the target IP address within a preset time period; Alternatively, the IP address information may include a source IP address and a destination IP address, and the traffic monitoring data may be monitoring data generated from messages sent by the network device indicated by the source IP address to the network device indicated by the destination IP address within a preset time period.

[0021] Optionally, before checking whether a service statistics set matching the message exists under the security service, the device further includes a preprocessing module configured to: Check whether the network device has enabled the security service policy associated traffic monitoring function; If so, check if there is a service statistics set under this security service that matches the message; If not, then based on the message and the service information of the security service to which the security service policy matches the message, a log record corresponding to the security service is generated.

[0022] Optionally, each traffic monitoring set is associated with at least one traffic identification field, and a field value is set for the traffic identification field; the traffic monitoring set is used to monitor packets entering the network device that match the field value to generate monitoring data; the traffic identification field includes at least the source IP address, the destination IP address, and the application identifier of the application to which the packet belongs; when the first construction module is configured to obtain traffic monitoring data matching the IP address information of the packet within a preset time period from an existing traffic monitoring set, it includes: When multiple target traffic monitoring sets are identified from the existing traffic monitoring sets, traffic monitoring data that matches the IP address information of the packet within a preset time period is extracted from each target traffic monitoring set; wherein, the traffic identification field and its field value associated with the target traffic monitoring set match the IP address information of the packet. To obtain target traffic monitoring data, the traffic monitoring data is extracted from the traffic monitoring data of each target traffic monitoring set. The target traffic monitoring data is used as the traffic monitoring data that matches the IP address information of the packet within the preset time period; wherein, any target traffic monitoring data is simultaneously matched with the traffic identification field and its value used by each target traffic monitoring set when matching the IP address information of the packet.

[0023] Optionally, the device further includes a second building block configured to: If the traffic monitoring set does not exist, or if there is no traffic monitoring data matching the IP address information of the packet within a preset time period in the traffic monitoring set, a service statistics set matching the packet under the security service is constructed based on the service information of the security service to which the security service policy matches the packet, and the IP address information of the packet. The communication characteristics corresponding to the packet and the current time are recorded in the service statistics set.

[0024] Optionally, when the second construction module is configured to construct a service statistics set matching the packet under the security service based on the service information of the security service to which the security service policy matches the packet, and the IP address information of the packet, it includes: A second set is generated, and an identification attribute is configured for the second set based on the service information of the security service, the IP address information of the packet, and the current time, so that the second set with the configured identification attribute is used as the service statistics set.

[0025] Optionally, the security business policy may include one of the following business types: threat detection, content security, behavior control, or application identification.

[0026] According to a third aspect of the embodiments of this application, an electronic device is provided, the electronic device comprising: a memory and a processor; the memory being used to store a computer program; and the processor being used to execute the above-described business monitoring method by invoking the computer program.

[0027] According to a fourth aspect of the embodiments of this application, a computer-readable storage medium is provided, on which a computer program is stored, wherein the program, when executed by a processor, implements the above-described business monitoring method.

[0028] The technical solutions provided in this application embodiment may include the following beneficial effects: In the technical solution provided in this application, when a security service detects that a network device's current packet has a potential security risk, a service statistics set matching the security service and the packet's IP address information is dynamically constructed. Based on the monitoring data matching the packet's IP address information in the existing real-time traffic monitoring data at the underlying level, the service statistics are initialized. This establishes an effective and intuitive strong correlation between various security service services / modules and the underlying real-time traffic monitoring data, enabling a valid link between security alarms and network behavior context. This allows users to quickly determine whether a network anomaly poses a threat to the security of the network device when analyzing and handling network anomalies, thereby improving the efficiency of analysis and the accuracy of response.

[0029] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this application. Furthermore, no embodiment in this application needs to achieve all the effects described above. Attached Figure Description

[0030] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.

[0031] Figure 1A This is a flowchart illustrating a business monitoring method according to an exemplary embodiment of this application; Figure 1B This is a schematic diagram illustrating a traffic monitoring set associated with different message characteristics, as shown in an exemplary embodiment of this application; Figure 1C This is a flowchart illustrating the construction of a business statistics set according to an exemplary embodiment of this application; Figure 1D This is a flowchart illustrating another business monitoring method according to an exemplary embodiment of this application; Figure 2 This is a schematic diagram illustrating the construction process of a service statistics set matching a message under a security service, as shown in an exemplary embodiment of this application. Figure 3 This is a flowchart illustrating a business monitoring method according to an exemplary embodiment of this application; Figure 4 This is a schematic diagram of the structure of a business monitoring device shown in an exemplary embodiment of this application; Figure 5 This is a hardware schematic diagram of an electronic device illustrated in an exemplary embodiment of this application. Detailed Implementation

[0032] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims. It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another.

[0033] As cyberattacks become increasingly sophisticated and covert, granular monitoring of network traffic has become a crucial aspect of ensuring network security. Currently, traffic monitoring functions implemented in network devices can be mainly divided into two categories: log-based traffic monitoring and traffic collection-based traffic monitoring.

[0034] Log-based traffic monitoring relies on historical records such as access logs and session logs generated by the system or security components. By analyzing the stored log data offline, it enables the retrospection and statistics of network behavior. However, log data in this approach is susceptible to write performance, storage capacity, and logging policies, resulting in issues such as packet loss, truncation, or missing key fields. This leads to incomplete and inaccurate data. Furthermore, log generation and analysis typically have significant delays, making it difficult to meet the needs of real-time perception and response to abnormal traffic behavior. Essentially, it is a lagging analysis of historical data and cannot support proactive defense.

[0035] Traffic monitoring based on traffic acquisition extracts traffic characteristics (such as source IP address, destination IP address, application protocol, etc.) in real time by directly parsing network packets or using hardware acceleration units, and performs real-time and historical statistics on three core dimensions: the number of new connections, the number of concurrent connections, and the traffic throughput. This approach abstracts different statistical needs into independent traffic monitoring sets, maintaining lightweight counters for each type of monitoring condition (such as specific IP pairs, IP address groups, or application types) to record aggregation results. It eliminates the need to store original packets or complete session information, thus simplifying data management logic while ensuring high real-time performance and accuracy. However, such monitoring mechanisms typically require pre-configuration of specific monitoring objects, such as designated source / destination IPs, address groups, or application identifiers. This relies on operations personnel to pre-determine which addresses or applications may pose a risk and manually enable corresponding monitoring policies. This pre-defined monitoring method lacks dynamic adaptability and struggles to provide timely and effective monitoring of sudden or unknown security events (such as new types of attack traffic). Furthermore, the widespread activation of monitoring policies to cover potential risks leads to a large number of low-value or idle monitoring sets continuously consuming memory and computing resources, resulting in system performance degradation and resource waste.

[0036] In view of this, this application provides a service monitoring method applied to network devices. When a security service detects a potential security risk in a network device's current packets, it dynamically constructs a service statistics set matching the security service and the packet's IP address information. Based on existing real-time traffic monitoring data matching the packet's IP address information, it initializes the service statistics, thereby establishing an effective and intuitive strong correlation between various security service services / modules and the underlying real-time traffic monitoring data. This enables a valid link between security alarms and network behavior context, allowing users to quickly determine whether network anomalies are occasional false alarms, normal service fluctuations, or persistent threats with malicious intent, thus improving analysis efficiency and response accuracy. The network device refers to a network infrastructure device with security protection and traffic processing capabilities, such as a next-generation firewall, intrusion prevention system, unified threat management device, security gateway, or intelligent router / switch supporting security service plugins. It performs security functions such as access control, threat detection, application identification, and behavior auditing, and has a built-in general traffic monitoring module to support multi-dimensional traffic statistics.

[0037] Based on this, see Figure 1A An exemplary flowchart of a business monitoring method is shown, which may include at least the following steps: S101, for each security service policy that matches the currently received message, check whether there is a service statistics set under the security service that matches the message, based on the service information of the security service to which the security service policy belongs and the IP address information of the message. Security services refer to specific types of security monitoring functions or services pre-configured on network devices to perform targeted security analysis and handling of network traffic. Depending on the functional objectives, security services can include one of the following service types: threat detection, content security, behavior control, and application identification.

[0038] Among them, threat detection security services focus on identifying network attack behaviors, such as distributed denial-of-service (DDoS) attacks, advanced persistent threat (APT) activities, and command and control (C2) communications; content security services focus on protecting users from harmful content, with functions such as virus scanning, malicious URL (Uniform Resource Locator) filtering, and sensitive content detection; behavior control security services are used to manage network resource usage, supporting functions such as IP-based rate limiting, access control policies, and honeypot / decoy system deployment; and application identification security services identify and classify application protocols running on the network, such as HTTP (Hypertext Transfer Protocol), FTP (File Transfer Protocol), and DNS (Domain Name Service) application protocol identification.

[0039] The aforementioned security services operate logically independently, each maintaining its own policies, statistics, and response mechanisms. Simultaneously, a shared message processing pipeline can be used to perform parallel or serial multi-dimensional security service detection on the same message, thereby achieving multi-dimensional and collaborative security monitoring and response. The service information for this security service represents the configuration parameters and context information related to that security service, such as service name, detection mode, and response action.

[0040] Security service policies represent a set of rules pre-configured or dynamically issued in network devices to identify packets in network traffic that pose potential security risks. Each security service policy belongs to a specific type of security service and is used to perform feature matching and risk assessment on packets entering the network device based on the goals and analysis dimensions of that security service to determine whether the packet falls within the potential risk scope monitored by that security service. When a packet matches a security service policy, it means that the packet exhibits behavior consistent with predefined risk characteristics in the context of the current security service, such as the packet payload containing characteristic strings of common malware or requesting communication from a high-risk port. In this case, the corresponding processing logic of that security service is triggered.

[0041] These security business policies are not isolated rules, but rather the functional implementation vehicles for security services. Each security service achieves its detection objectives through its corresponding security business policy. For example, in threat detection security services, security business policies are used to identify abnormal traffic patterns. For instance, a security business policy might state, "If the number of SYN packets from the same source IP exceeds a threshold within a unit of time, it is determined to be a suspected SYN Flood attack." In content security services, security business policies are used to block malicious content. For instance, a security business policy might state, "If the Host field in an HTTP request contains a known malicious domain name, then block the connection and record the event." In behavior control security services (such as access control and traffic rate limiting), security business policies are used to constrain user or device behavior. For instance, a security business policy might state, "If a terminal accesses the financial system server outside of working hours, then trigger an alarm." In application identification security services, security business policies are used to assist in determining application types or abnormal behavior. For instance, a security business policy might state, "If traffic conforms to DNS protocol characteristics but uses a non-standard port, then it is marked as suspicious application behavior."

[0042] A business statistics set represents a data structure used for continuous monitoring of the same type of packets that match the same security business policies and have the same key message characteristics. Essentially, it is a collection of relevant statistical data gathered within a specified time window for packets of the same type with the same key message characteristics. This data is used to quantitatively analyze the behavioral trends, traffic volume, and security risk levels of these potentially security-risk packets, enabling early identification of abnormal traffic patterns, discovery of potential attack behaviors or security risks, shortening response time to risky behaviors, and improving overall security protection capabilities. This business statistics set should include at least the following three dimensions of real-time statistical monitoring indicators: New connection count: Represents the number of new connections initiated per unit of time; Concurrent connections: Represents the number of active connections existing simultaneously at the current moment; Throughput: Represents the total amount of data transmitted through a message per unit of time (usually measured in bytes or bit rate).

[0043] This business statistics set is a dynamic statistical data container built at the message dimension level under a security service. It is used to aggregate a class of communication behaviors with the same key message characteristics under that security service. Each business statistics set corresponds to a class of messages with the same key message characteristics under a security service. This business statistics set is not a static log, but a monitoring context entity that evolves over time. It is used to continuously record and analyze the behavior of messages with the same key message characteristics under that security service across multiple dimensions. Based on this, the business statistics set can use the business information of the security service, the IP address information of the messages, and the creation time of the statistics set as its identification attributes to uniquely identify the monitoring context, ensuring that the statistics of different services and different messages are isolated and do not interfere with each other. Based on the historical and real-time statistical data in this business statistics set, trend analysis, baseline modeling, and anomaly detection can be performed on the traffic behaviors with the same key message characteristics under that security service. This effectively identifies and responds to potential security events under the security service to which the business statistics set belongs, achieving refined, context-aware security monitoring and response.

[0044] The matching of currently received packets with the network device's local security service policies is based on the observable characteristics of the packets, which may include, but are not limited to: network layer information such as source IP address, destination IP address, and whether the IP address belongs to a predefined address group; transport layer information such as source port, destination port, and protocol type (TCP / UDP / ICMP, etc.); application layer information such as application protocol type (e.g., HTTP, DNS), URL, User-Agent, and payload characteristics (e.g., regular expression matching, hash fingerprint); and context information such as time window, session state, and historical behavior statistics.

[0045] Each security service policy that matches the currently received message can also be understood as follows: when the message is checked by any security service on the network device, the message meets the judgment rules in the security service policy associated with the security service under the analysis dimension of the security service, that is, the message exhibits behavior or attributes consistent with the predefined risk characteristics in the security service policy.

[0046] For each security service policy matching the currently received packet, based on the service information of the security service to which it belongs and the IP address information of the currently received packet, it is checked whether a service statistics set matching the security service and the IP address information of the currently received packet already exists. Specifically, when checking whether a service statistics set matching the packet under the security service exists, a service statistics set that meets the following conditions can be detected from the existing service statistics set within the network device: the identifier attribute of the service statistics set includes the service information of the security service to which the security service policy belongs and includes the IP address information of the packet, wherein the identifier attribute is used to uniquely identify which security service and which packet characteristics the statistics set belongs to; furthermore, if a service statistics set meeting the above conditions is detected, it is determined that a service statistics set matching the packet under the security service already exists, and there is no need to create a new service statistics set; otherwise, it is determined that a service statistics set matching the packet under the security service does not exist, and a new service statistics set matching the packet under the security service needs to be created.

[0047] To balance in-depth security monitoring with efficient utilization of system resources, network devices can be configured with a user-controllable switch to explicitly enable or disable the traffic monitoring function associated with security service policies. This switch allows operations personnel to flexibly decide whether to automatically trigger service statistics and continuous monitoring at the packet level under the security service when a security service policy is triggered, based on actual security policies, network load, or business scenario requirements. For example, this function can be enabled in highly sensitive areas to establish a strong correlation between security services and traffic monitoring sets for in-depth security event tracing, while it can be disabled in low-risk areas to reduce resource overhead.

[0048] Based on this, before checking whether the network device locally possesses a service statistics set matching the packet under the security service, it first checks whether the network device has enabled the security service policy-related traffic monitoring function. If so, it checks whether the network device locally possesses a service statistics set matching the packet under the security service. If not, based on the packet and the service information of the security service to which the security service policy matching the packet belongs, it generates a log record corresponding to the security service for alarm, auditing, or subsequent manual analysis. In this way, users can enable or disable deep monitoring as needed according to different network areas, service importance, or performance constraints, effectively controlling system overhead in high-concurrency scenarios. Furthermore, the configuration switch enables the network device to support both lightweight logging mode and context-aware continuous monitoring mode, forming a hierarchical response mechanism and improving device security.

[0049] S102, if there is no service statistics set matching the packet under the security service, then obtain traffic monitoring data matching the IP address information of the packet within a preset time period from the existing traffic monitoring set, and construct a service statistics set matching the packet under the security service based on the traffic monitoring data, the IP address information of the packet and the service information of the security service, and record the communication characteristics corresponding to the packet and the current time into the service statistics set; The traffic monitoring set is a data structure generated and maintained by a general traffic monitoring function in the network device that is different from the various security services that have been configured. This function does not belong to any specific security service, but is used as an underlying function to perform multi-dimensional statistics on packets that meet the set monitoring conditions. In this embodiment, it is used to provide historical behavior data support for security services.

[0050] Each traffic monitoring set is associated with at least one traffic identification field, and a field value is set for the traffic identification field as a monitoring condition. The traffic monitoring set is used to monitor packets entering the network device that match the field value to generate monitoring data, that is, to perform multi-dimensional monitoring on packets that meet the set monitoring conditions, wherein the multi-dimensional monitoring includes at least the three dimensions described in the previous embodiments: the number of new connections, the number of concurrent connections, and the traffic throughput. The traffic identification field is used to describe the key attributes of the packet, which may include, but is not limited to, the source IP address, the destination IP address, and the application identifier of the application to which the packet belongs. In this context, the source IP address represents the IP address of the message sender, the destination IP address represents the IP address of the message receiver, and the application identifier of the application to which the message belongs represents the identity information of the application or service that generated the message, such as the application name and process ID. By flexibly combining message features and their values, the traffic monitoring function can construct monitoring contexts of different granularities as needed (e.g., single IP, IP pairs, address groups, or application types). This allows for the efficient collection of basic behavioral data of network traffic without relying on specific security business logic, which can then be reused in subsequent security detection, business statistics set construction, and other scenarios.

[0051] For example, see Figure 1BThis diagram illustrates a traffic monitoring set associated with different packet characteristics, showcasing various flexibly definable traffic monitoring set types in network devices. Each type achieves refined statistics on specific communication behaviors by associating different packet characteristics and their characteristic values. As shown, a traffic monitoring set based on source IP address is used to monitor traffic meeting the specified source IP address (e.g., 203.0.113.45) in real-time and historical dimensions of new connection count, concurrent connection count, and traffic throughput. If no specified characteristic value for the source IP address is configured, this monitoring set will perform global statistics on traffic from all source IP addresses. Similarly, a traffic monitoring set based on destination IP address is used to monitor traffic meeting the specified destination IP address (e.g., 192.168.1.101) in real-time and historical dimensions of new connection count, concurrent connection count, and traffic throughput. If no specified characteristic value for the destination IP address is configured, it will default to monitoring traffic from all destination IP addresses. Traffic can be aggregated and statistically analyzed; or, a traffic monitoring set based on application identifiers can be used to perform real-time and historical statistical monitoring of traffic from specified identifiable applications (such as "HTTP", "DNS" or "WeChat") in three dimensions: new connection count, concurrent connection count, and traffic volume. The application identifier can be obtained through deep packet inspection, port identification or certificate fingerprinting, etc.; or, a traffic monitoring set based on address object groups can be used to perform unified multi-dimensional statistics on the traffic of all individual addresses in each address object group (such as "high-risk IP group" or "internal network server group"). When matching, the address group will be automatically expanded to monitor the new connection count, concurrent connection count, and traffic throughput of each IP in the group, either individually or in aggregate.

[0052] All of the above-mentioned traffic monitoring sets are maintained independently by the general traffic monitoring function in network devices and are not bound to any specific security service. However, the traffic monitoring data in the traffic monitoring set can be referenced as needed by each security service when constructing a service statistics set.

[0053] Traffic monitoring data matching the IP address information of the packet within a preset time period refers to historical monitoring data generated by the traffic monitoring function within the most recent historical time window earlier than the current time, monitoring each packet whose IP address information is the same as the IP address information of the currently received packet. It is understood that the known IP address information of the packet includes the source IP address and the destination IP address. However, in this embodiment, the specific IP field used in matching traffic monitoring data can be dynamically determined based on the analysis dimension of the security service to which the security service policy matching the currently received packet belongs. Since different security services focus on different communication behavior characteristics, the source IP address, destination IP address, or a combination of source and destination IP addresses can be dynamically selected as the matching basis during the traffic monitoring data matching process.

[0054] Based on this, traffic monitoring data matching the IP address information of the packet within a preset time period may include: when the IP address information includes a source IP address, the traffic monitoring data is monitoring data generated by packets sent by the network device indicated by the source IP address within the preset time period; when the IP address information includes a destination IP address, the traffic monitoring data is monitoring data generated by packets sent to the network device indicated by the destination IP address within the preset time period; when the IP address information includes both a source IP address and a destination IP address, the traffic monitoring data is monitoring data generated by packets sent by the network device indicated by the source IP address to the network device indicated by the destination IP address within the preset time period.

[0055] For example, the source IP address of the currently received message is 203.0.113.45, the destination IP address is 192.168.1.100, and the preset time period is one hour before the current time. Assuming the currently received packet is captured by security service S1, and security service S1 focuses on all outbound traffic from a high-risk IP, the source IP address of the currently received packet can be used as the matching basis. If no service statistics set for security service S1 is found that contains the IP field of the source IP address of the currently received packet, the existing traffic monitoring set is searched for monitoring data generated by all packets sent from source IP address 203.0.113.45 within the last hour, regardless of the destination IP address of the packet. For example, monitoring data generated for packet 1 (203.0.113.45 → destination IP address 8.8.8.8) and packet 2 (203.0.113.45 → destination IP address 10.10.10.5) within the last hour are all traffic monitoring data that match the IP address information of the packet within the preset time period.

[0056] Similarly, assuming that security service S1 focuses on abnormal access behavior of a specific host to the core server, this embodiment uses the source IP address and destination IP address of the currently received packet as the matching basis to search for the monitoring data generated in the existing traffic monitoring set within the last hour for all packets sent from source IP address 203.0.113.45 to destination IP address 192.168.1.100.

[0057] The communication characteristics corresponding to the message are used to reflect its communication behavior during network interaction, and may include the message header characteristics and the aggregated behavior characteristics of the communication flow to which the message belongs. For example, the message header characteristics represent the network / transport layer information carried by the message itself, such as source IP, destination IP, source port, destination port, protocol type, message length, etc., while the aggregated behavior characteristics represent the behavior characteristics associated with its communication flow, such as cumulative traffic bytes, session duration, egress interface, and receive timestamp, etc. For example, an example of the communication characteristics corresponding to a certain message is as follows: { Source IP: M1, Total data transfer (bytes): 12.5 MB Total number of messages: 8432 Last active time: 2025-12-10 16:10:23 Destination IP list: [A, B, C], Ports used: [80, 443, 53] Average session duration: 4.2 seconds. Abnormal behavior flag: false, ... } When recording the communication characteristics and current time corresponding to the message into the service statistics set, the communication characteristics of the message are extracted from the currently received message and combined with the current timestamp to record the communication characteristics into the service statistics set. Additionally, if the service statistics set maintains other dimensions such as new connections, concurrency, and traffic, if the message represents a newly established connection, the new connection count counter is incremented by 1; if it belongs to a data packet from an existing session, the concurrency dimension connection count may be maintained or adjusted; simultaneously, its payload bytes will be accumulated in the traffic dimension statistics. Furthermore, the timestamp can be used to construct a sliding time window, supporting time-series-based trend analysis or forensic backtracking to maintain the real-time performance and behavioral representativeness of the service statistics set, providing accurate input for subsequent dynamic baseline modeling and anomaly detection.

[0058] For each security service policy matching a currently received packet, if the network device does not have a matching service statistics set for the security service under that policy, a new service statistics set matching the packet's IP address information needs to be created. If traffic monitoring data matching the packet's IP address information within a preset time period is found in the existing traffic monitoring set, a new service statistics set is constructed based on this traffic monitoring data, combined with the security service's service information and the current packet's IP address information, to adapt to the security service and the packet's IP address information.

[0059] In constructing the service statistics set matching the message under the security service, a first set can be generated first. An identifier attribute can be configured for the first set based on the service information of the security service, the IP address information of the message, and the current time. For example, the identifier attribute can be a combination of the service information of the security service, the IP address information of the message, and the current time. This ensures that each service statistics set logically uniquely corresponds to a monitoring context of a security service and a message dimension, thereby enabling isolated, refined, and traceable independent statistics and analysis of potential risk behaviors of different security services and different messages. Furthermore, traffic monitoring data matching the IP address information of the message within a preset time period in the traffic monitoring set is recorded sequentially into the first set to form the service statistics set. This ensures that the service statistics set not only includes the real-time information of the current message but also fully inherits the historical traffic behavior sequence before the risk behavior occurred, thus establishing a strong correlation between the security service and the underlying traffic monitoring, enabling full-cycle retrospective analysis of risk events. For example, this business statistics set can reconstruct the historical communication behavior of attackers in the network, such as connection frequency, concurrent sessions, and traffic patterns of the source IP or source IP and destination IP pairs, in the minutes or even hours before the current packet triggers an alarm. This provides key contextual information for determining whether it belongs to advanced threats such as APT incubation, slow scanning, or lateral movement.

[0060] See Figure 1C The following is an exemplary flowchart for constructing a service statistics set. Taking the currently received packet with source IP address 203.0.113.45 and destination IP address 192.168.1.100 as an example, the matching security service policy belongs to security service S1. Using the source IP address as the matching basis, if it is found that there is no service statistics set on the network device with the identifier attribute including security service S1 and the IP field containing source IP 203.0.113.45, then a first set is created. The identifier attribute of the first set is set to {service: "S1 (such as URL filtering)", source IP: 203.0.113.45} or it can also include the creation time, such as its identifier attribute being set to {service: "S1 (such as URL filtering)", source IP: 203.0.113.45, creation time: T0}.

[0061] Furthermore, the statistical data for the first set is initialized, and it is checked whether a traffic monitoring set based on source IP 203.0.113.45 exists. If it exists and the existing traffic monitoring set includes monitoring data generated by all packets sent from source IP 203.0.113.45 within a preset time period, then the monitoring data is written into the first set in chronological order to form a service statistical set. The communication characteristics corresponding to the currently received packets are appended to the service statistical set as the latest record, and the indicator values ​​of the real-time monitoring dimension are updated. Afterward, the communication characteristics corresponding to packets captured under this security service S1 with source IP: 203.0.113.45 will be recorded in the service statistical set.

[0062] In this embodiment, a data structure called a service statistics set is introduced for security services. Without changing the existing security service logic and traffic monitoring architecture, when a security service detects that a current packet of a network device has a potential security risk, a service statistics set matching the security service and the packet's IP address information is dynamically constructed. The service statistics are initialized based on monitoring data matching the packet's IP address information from the underlying real-time traffic monitoring data. This allows for dynamic, on-demand, and context-aware linkage between the security service detection capability and the underlying general traffic monitoring capability. Furthermore, the security services of interest are specifically associated with the traffic monitoring function and statistics are performed to provide integrated data. This achieves a strong correlation between security events and network behavior context, enabling subsequent anomaly detection to be based on a complete behavioral sequence, thus improving the accuracy and interpretability of risk behavior judgment.

[0063] Compared to existing traffic-based monitoring methods that typically require pre-configuration of monitored objects, this application only initiates fine-grained statistics on the IP communication pairs to which a potentially risky packet belongs after it has been identified by security services. This eliminates the need for pre-deploying a large number of idle monitoring sets while ensuring accurate capture of abnormal traffic behavior, effectively balancing resource waste and monitoring blind spots. Furthermore, because the traffic monitoring module is decoupled from the security service module, various security services can reuse the same underlying monitoring data, facilitating horizontal scaling and policy iteration.

[0064] In some embodiments, when a service statistics set matching the message under the security service is detected, such as Figure 1D As shown, the method further includes the following steps: S103, if a service statistics set matching the message exists under the security service, then the communication characteristics and current time corresponding to the message are recorded in the service statistics set, so as to monitor messages with the same characteristics as the currently received message under the security service based on the service statistics set. That is, when a service statistics set already exists, the currently received message is used to update the service statistics set without creating a new service statistics set.

[0065] For example, when a packet from 203.0.113.45 to the database server 192.168.1.100 triggers an abnormal access behavior policy under the security service "Access Control", if it is found that a service statistics set has already been created locally on the network device with the identifier attribute {Service: "Access Control", Source IP: 203.0.113.45, Destination IP: 192.168.1.100, Creation Time: T1}, indicating that a service statistics set matching this packet already exists under this security service, then the communication characteristics corresponding to the currently received packet and its current time are recorded in the already created service statistics set.

[0066] Furthermore, given the real-time and rapidly evolving nature of cyberattacks, immediate responses are necessary to intervene in their early stages and effectively curb further risk spread. Therefore, when a security response is triggered by an existing business statistics set, the security incident analysis and response process corresponding to the security business to which that statistics set belongs is executed based on the monitoring records within that set. Upon completion of the security incident response, the business statistics set is deleted to free up system resources.

[0067] The methods for triggering security response operations can include at least one of the following: (1) statistical dimension threshold triggering, for example, when one or more indicators in the business statistics set exceed a preset static threshold, a response is immediately triggered; (2) timed triggering, for example, triggering once every 2 hours; (3) dynamic baseline deviation triggering: a dynamic baseline model (such as sliding window mean + standard deviation) is established based on historical behavior, and when the current statistical data deviates significantly from the normal range (such as Z-score > 3), it is judged as abnormal and a response is triggered; (4) monitoring record quantity threshold triggering, for example, the number of monitoring records in the business statistics set is detected to exceed a set threshold; (5) external event linkage triggering: receiving alarm signals from other security services, and triggering a response after secondary verification in combination with the local business statistics set context. The above triggering methods can be flexibly configured and combined according to the actual situation such as network environment, security policy level, and business sensitivity, so as to improve the accuracy and adaptability of security decisions while ensuring the timeliness of response.

[0068] Alternatively, the security service to which this service statistics set belongs can periodically or in real-time scan the statistical data of this set. If the service statistics set is found to meet the preset risk behavior judgment conditions, a security event is generated, and the corresponding handling actions for the security event are executed, such as issuing ACL rules to block the source IP, sending alarms, and recording forensic logs. After the security event is handled, the service statistics set is deleted to release the memory and computing resources it occupies. Subsequently, if the same IP pair exhibits abnormal behavior again, step S102 will be executed again to create a new service statistics set under this security service that matches the same IP.

[0069] For example, in the security service "DDoS detection", if a certain service statistics set has more than 1,000 "new connections" within 1 second, it is judged as a SYN Flood attack, triggering the automatic blocking of the source IP. After the security event has been handled, the security service module can actively notify the deletion of the service statistics set, or automatically clean it up through a timer / idle timeout mechanism to release memory resources and avoid invalid statistics sets from residing for a long time.

[0070] For example, in an APT attack, attackers probe the internal network with low-frequency connections. The first connection triggers a policy that creates a business statistics set; subsequent connections, once a day, are all recorded; after a week, the connection frequency suddenly increases to 10 times per minute, and the system, based on historical baselines, determines this as lateral movement, triggers an alarm, and blocks the connection; after the situation is resolved, the statistics set is deleted, and the system returns to a lightweight state.

[0071] In some embodiments, under certain circumstances, such as when a network device has just come online, or when a currently received packet has specific packet characteristics that have not appeared in the network before, there may be situations where the traffic monitoring set does not currently exist, or where there is no traffic monitoring data matching the IP address information of the packet within a preset time period in the traffic monitoring set. If this occurs, a service statistics set matching the packet under the security service can be constructed based on the service information of the security service to which the security service policy matches the packet, and the IP address information of the packet. The communication characteristics corresponding to the packet and the current time are recorded in the service statistics set. When constructing the service statistics set, a second set can be generated, and an identification attribute can be configured for the second set according to the service information of the security service, the IP address information of the packet, and the current time, so that the second set with the configured identification attribute is used as the service statistics set.

[0072] For example, in the case where the aforementioned network device does not locally possess service information with the identification attribute including security service S1 and the IP field contains the source IP 203.0.113.45, such as... Figure 1CAs shown, if no traffic monitoring set based on source IP 203.0.113.45 is detected, or if there is no traffic monitoring data generated by packets sent from source IP 203.0.113.45 within a preset time period in the traffic monitoring set based on source IP 203.0.113.45, then the identifier attribute of the constructed service statistics set can be set to {service: "S1 (such as URL filtering)", source IP: 203.0.113.45, creation time: T0}, and the currently received packets and their timestamps will be recorded in the service statistics set. Subsequently, packets captured under the security service S1 with source IP: 203.0.113.45 will be recorded in the service statistics set.

[0073] In some embodiments, to improve the accuracy of service statistics set construction and suppress statistical noise introduced by the coexistence of multiple granular monitoring strategies, the network device can perform data fusion processing on multiple matching traffic monitoring sets when constructing the service statistics set. Based on this, when obtaining traffic monitoring data matching the IP address information of the packet within a preset time period from an existing traffic monitoring set, see [reference needed]. Figure 2 The illustrative diagram illustrates a process for obtaining traffic monitoring data matching the IP address information of the packet within a preset time period, which can be achieved through the following steps: S201, when multiple target traffic monitoring sets are determined from the existing traffic monitoring sets, traffic monitoring data that matches the IP address information of the packet within a preset time period is extracted from each target traffic monitoring set; wherein, the traffic identification field and its field value associated with the target traffic monitoring set match the IP address information of the packet. S202, Obtain target traffic monitoring data based on the traffic monitoring data extracted from each target traffic monitoring set; S203, the target traffic monitoring data is used as the traffic monitoring data that matches the IP address information of the packet within the preset time period.

[0074] In this process, any target traffic monitoring data is simultaneously matched against the traffic identification field and its value used by each target traffic monitoring set when matching the IP address information of the packet, thereby ensuring that its source IP address and / or destination IP address are completely consistent with the currently received packet. By using the target traffic monitoring data as the traffic monitoring data that matches the IP address information of the packet within the preset time period, irrelevant traffic records introduced by broad matching (such as address groups or single IP dimensions) can be effectively filtered out, retaining only historical behavior data that is completely from the same source and destination as the current packet at the communication endpoint level, laying a reliable foundation for the subsequent construction of a high-precision service statistics set.

[0075] For example, the general traffic monitoring function of network devices is configured with the following traffic monitoring sets: Traffic monitoring set 1: The associated traffic identification fields and their values ​​are source IP address (including 203.0.113.45) and destination IP address (i.e., IP pair), used for fine-grained monitoring of communication between specific hosts; Traffic monitoring set 2: The associated traffic identification field and its field value are the address group (such as "high-risk external IP segment") to which the source IP address (including 203.0.113.45) belongs, which is used to aggregate and monitor outbound traffic of all source IPs in the address group; The IP address information of the currently received message includes the source IP address 203.0.113.45 and / or the destination IP address 192.168.10.20. If the source IP address information is selected as the matching basis, the target traffic monitoring set will be searched from the existing traffic monitoring sets. At the same time, traffic monitoring set 1 (because its source IP is a complete match) and traffic monitoring set 2 (because its source IP belongs to the predefined address group) will be matched.

[0076] In this situation, simply merging the monitoring data from two target traffic monitoring sets would result in a large amount of broad traffic unrelated to the communication of currently received packets (such as packets sent from the source IP to other destination IPs) being included in the statistics, leading to statistical noise and polluting the business context. Therefore, it is possible to obtain the traffic monitoring data of each of the two target traffic monitoring sets that match the packet IP address information within a preset time period, and calculate the intersection of their traffic monitoring data.

[0077] In this embodiment of the disclosure, when the currently received packet matches multiple traffic monitoring sets of different granularities, the intersection of traffic monitoring data that matches the IP address information of the packet in each target traffic monitoring set is obtained. Irrelevant traffic data introduced by broad matching is automatically filtered out to avoid noise interference, more realistically reflect the historical behavior pattern of a specific IP under a specific security service, improve the accuracy of the service statistics set, provide a reliable benchmark for anomaly detection, and thus enhance the security detection context restoration capability.

[0078] To enable those skilled in the art to better understand the business monitoring method provided in this application, it achieves refined, context-aware, and continuous monitoring of potentially risky packets under security services. It links the security service module and the traffic monitoring module to construct a security behavior statistics set based on IP communication pairs, thereby improving the accuracy and response efficiency of security detection without increasing additional resource overhead. See also Figure 3 An exemplary flowchart of a business monitoring method is shown, which includes the following processes: Security Service Hit (Log Ignore) 301: Multiple security service modules (such as security services under threat detection type: threat detection, virus detection, URL filtering, etc.) perform security checks on currently received packets. When a packet is captured by any security service and matches its built-in security service policy, a security service hit occurs, indicating that the packet has been determined by that security service to pose a potential threat to network device security. At this time, the regular log recording process will be ignored, and the system will instead enter a deep monitoring path based on service statistics sets. A security service hit can also be understood as a packet being identified by a security service and triggering its security service policy.

[0079] The activation check 302 for the security service policy-related traffic monitoring function determines whether the security service has configured and enabled the security service policy-related traffic monitoring function. If not enabled, proceed to process 309 to generate alarms or log records, and do not perform subsequent statistical modeling; if enabled, continue to the next step. Based on the activation control of this security service policy-related traffic monitoring function, flexible switching between lightweight response and in-depth business statistical monitoring is achieved, meeting the resource control needs of different scenarios.

[0080] Security service IP address information matching service statistics set check 303: For the currently received message, if the network device already has a service statistics set for the same security service and the same message characteristics, then proceed to process 308 to directly record the currently received message and its timestamp information into the service statistics set; if there is no service statistics set for the security service that matches the message IP address information, then a new service statistics set needs to be created, and proceed to process 304. Traffic monitoring set check 304: This checks whether one or more configured traffic monitoring sets exist, whose monitoring conditions match the IP address information of the current packet. A traffic monitoring set is a data structure maintained by a general traffic monitoring module independent of security services, used for multi-dimensional continuous statistics on traffic that conforms to specific packet characteristics. If a traffic monitoring set matching the IP address information of the currently received packet exists, proceed to process 305; otherwise, directly proceed to the second type of service statistics set creation process 307. Historical monitoring data extraction matching the IP address information of the message 305: Used to extract traffic monitoring data matching the IP address information of the message within a preset time period from the traffic monitoring set that matches the IP address information of the currently received message. The first type of business statistics set creation process 306: Based on the historical monitoring data extracted above, the IP address information of the current packet, and the business information of the security service to which it belongs, a new business statistics set is constructed. This statistics set can be uniquely identified by the triple {security service information, IP address information, creation time}, and the business monitoring set is initialized with the extracted historical monitoring data, while the currently received packets are recorded in the business statistics set.

[0081] The second type of business statistics set creation process 307: Based on the IP address information of the current packet and the business information of the security service to which it belongs, construct a new business statistics set.

[0082] Business statistics set update 308: Record the currently received messages and their timestamp information into the business statistics set.

[0083] Log recording process 309: Used to generate log records about the security service based on the currently received packets when the traffic monitoring function associated with the security service policy is not enabled.

[0084] In the above embodiments, by dynamically constructing a service statistics set bound to the IP address information of the packet when a security service hit occurs, and using existing traffic monitoring data for context initialization, on-demand linkage between security detection and traffic awareness is achieved. By reusing the real-time statistical data of the underlying general traffic monitoring module, there is no need to collect original packets or store complete sessions, reducing performance overhead. In addition, the resulting service statistics set naturally integrates historical behavior baselines and current events, making subsequent anomaly analysis continuous and interpretable, improving the accuracy of security detection and the efficiency of judgment.

[0085] For an example corresponding to the aforementioned business monitoring method, see [link to relevant documentation]. Figure 4 As shown, this application also provides an embodiment of a service monitoring device applied to a network device, the device comprising: The inspection module 401 is configured to check, for each security service policy that matches the currently received packet, whether there is a service statistics set under the security service that matches the packet, based on the service information of the security service to which the security service policy belongs and the IP address information of the packet. The first construction module 402 is configured to, if no service statistics set matching the packet exists under the security service, obtain traffic monitoring data matching the IP address information of the packet within a preset time period from the existing traffic monitoring set, and construct a service statistics set matching the packet under the security service based on the traffic monitoring data, the IP address information of the packet, and the service information of the security service, and record the communication characteristics corresponding to the packet and the current time into the service statistics set; wherein, the service statistics set is used to monitor packets under the security service that have the same IP address information as the currently received packet.

[0086] In some embodiments, the apparatus further includes: The statistics set update module 403 is configured to record the communication characteristics and current time corresponding to the message into the existing statistics set if a service statistics set matching the message exists under the security service.

[0087] In some embodiments, when the first construction module is configured to construct a service statistics set matching the message under the security service, it includes: Generate a first set, and configure an identifier attribute for the first set based on the service information of the security service, the IP address information of the packet, and the current time; Traffic monitoring data that match the IP address information of the packet within a preset time period in the traffic monitoring set are recorded sequentially into the first set according to time sequence to form the business statistics set.

[0088] In some embodiments, when the checking module is configured to check whether a service statistics set matching the message exists under the security service, it includes: The network device detects service statistics sets that meet the following conditions from existing service statistics sets: the identification attribute of the service statistics set includes service information of the security service to which the security service policy belongs, and also includes the IP address information of the packet. If a service statistics set that meets the conditions is detected, then there exists a service statistics set under the security service that matches the message; otherwise, there is no service statistics set under the security service that matches the message.

[0089] In some embodiments, the IP address information includes the source IP address, and the traffic monitoring data is monitoring data generated from packets sent by the network device indicated by the source IP address within a preset time period; Alternatively, the IP address information includes the target IP address, and the traffic monitoring data is monitoring data generated by packets sent to the network device indicated by the target IP address within a preset time period; Alternatively, the IP address information may include a source IP address and a destination IP address, and the traffic monitoring data may be monitoring data generated from messages sent by the network device indicated by the source IP address to the network device indicated by the destination IP address within a preset time period.

[0090] In some embodiments, before checking whether a service statistics set matching the message exists under the security service, the apparatus further includes a preprocessing module configured to: Check whether the network device has enabled the security service policy associated traffic monitoring function; If so, check if there is a service statistics set under this security service that matches the message; If not, then based on the message and the service information of the security service to which the security service policy matches the message, a log record corresponding to the security service is generated.

[0091] In some embodiments, each traffic monitoring set is associated with at least one traffic identification field, and a field value is set for the traffic identification field; the traffic monitoring set is used to monitor packets entering the network device that match the field value to generate monitoring data; the traffic identification field includes at least a source IP address, a destination IP address, and an application identifier of the application to which the packet belongs; when the first construction module is configured to obtain traffic monitoring data matching the IP address information of the packet within a preset time period from an existing traffic monitoring set, it includes: When multiple target traffic monitoring sets are identified from the existing traffic monitoring sets, traffic monitoring data that matches the IP address information of the packet within a preset time period is extracted from each target traffic monitoring set; wherein, the traffic identification field and its field value associated with the target traffic monitoring set match the IP address information of the packet. To obtain target traffic monitoring data, the traffic monitoring data is extracted from the traffic monitoring data of each target traffic monitoring set. The target traffic monitoring data is used as the traffic monitoring data that matches the IP address information of the packet within the preset time period; wherein, any target traffic monitoring data is simultaneously matched with the traffic identification field and its value used by each target traffic monitoring set when matching the IP address information of the packet.

[0092] In some embodiments, the device further includes a second building module configured to: If the traffic monitoring set does not exist, or if there is no traffic monitoring data matching the IP address information of the packet within a preset time period in the traffic monitoring set, a service statistics set matching the packet under the security service is constructed based on the service information of the security service to which the security service policy matches the packet, and the IP address information of the packet. The communication characteristics corresponding to the packet and the current time are recorded in the service statistics set.

[0093] In some embodiments, when the second construction module is configured to construct a service statistics set matching the packet under the security service based on the service information of the security service to which the security service policy matches the packet, and the IP address information of the packet, the configuration includes: A second set is generated, and an identification attribute is configured for the second set based on the service information of the security service, the IP address information of the packet, and the current time, so that the second set with the configured identification attribute is used as the service statistics set.

[0094] In some embodiments, the security business to which the security business policy belongs includes one of the following business types: threat detection type, content security type, behavior control type, and application identification type.

[0095] The specific implementation process of the functions and roles of each unit in the above device can be found in the implementation process of the corresponding steps in the above method, and will not be repeated here.

[0096] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this application according to actual needs. Those skilled in the art can understand and implement this without any inventive effort.

[0097] This application also provides an electronic device, the structural schematic diagram of which is shown below. Figure 5 As shown, the electronic device 500 includes at least one processor 501, a memory 702, and a bus 503. At least one processor 501 is electrically connected to the memory 502. The memory 502 is configured to store at least one computer-executable instruction, and the processor 501 is configured to execute the at least one computer-executable instruction to perform the steps of any service monitoring method provided in any embodiment or optional implementation of this application.

[0098] Furthermore, the processor 501 can be an FPGA (Field-Programmable Gate Array) or other devices with logic processing capabilities, such as an MCU (Microcontroller Unit) or a CPU (Central Processing Unit).

[0099] This application also provides another readable storage medium storing a computer program that, when executed by a processor, implements the steps of any business monitoring method provided in any embodiment or optional implementation of this application.

[0100] The readable storage media provided in this application include, but are not limited to, any type of disk (including floppy disk, hard disk, optical disk, CD-ROM, and magneto-optical disk), ROM (Read-Only Memory), RAM (Random Access Memory), EPROM (Erasable Programmable Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory, magnetic cards, or optical cards. In other words, readable storage media include any medium by which a device (e.g., a computer) stores or transmits information in a readable form.

[0101] Thus, specific embodiments of the subject matter have been described. Other embodiments are within the scope of the appended claims. In some cases, the actions recited in the claims may be performed in a different order and still achieve the desired result. Furthermore, the processes depicted in the drawings are not necessarily shown in a specific order or sequence to achieve the desired result. In some implementations, multitasking and parallel processing may be advantageous.

[0102] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.

Claims

1. A business monitoring method, characterized in that, Applied to network devices, the method includes: For each security service policy that matches the currently received message, check whether there is a service statistics set under the security service that matches the message, based on the service information of the security service to which the security service policy belongs and the IP address information of the message. If there is no service statistics set that matches the packet under the security service, then obtain the traffic monitoring data that matches the IP address information of the packet within a preset time period from the existing traffic monitoring set. Based on the traffic monitoring data, the IP address information of the packet, and the service information of the security service, a service statistics set matching the packet under the security service is constructed, and the communication characteristics and current time corresponding to the packet are recorded in the service statistics set. The service statistics set is used to monitor packets with the same IP address information as the currently received packets under the security service.

2. The method according to claim 1, characterized in that, The method further includes: If a service statistics set matching the message exists under this security service, then the communication characteristics and current time corresponding to the message are recorded in the existing service statistics set.

3. The method according to claim 1, characterized in that, The construction of the service statistics set matching the message under the security service includes: Generate a first set, and configure an identifier attribute for the first set based on the service information of the security service, the IP address information of the packet, and the current time; Traffic monitoring data that match the IP address information of the packet within a preset time period in the traffic monitoring set are recorded sequentially into the first set according to time sequence to form the business statistics set.

4. The method according to claim 1 or 3, characterized in that, Check if a service statistics set matching this message exists under this security service, including: The network device detects service statistics sets that meet the following conditions from existing service statistics sets: the identification attribute of the service statistics set includes service information of the security service to which the security service policy belongs, and also includes the IP address information of the packet. If a service statistics set that meets the conditions is detected, then there exists a service statistics set under the security service that matches the message; otherwise, there is no service statistics set under the security service that matches the message.

5. The method according to claim 1, characterized in that, The IP address information includes the source IP address, and the traffic monitoring data is the monitoring data generated by the packets sent by the network device indicated by the source IP address within a preset time period; Alternatively, the IP address information includes the target IP address, and the traffic monitoring data is monitoring data generated by packets sent to the network device indicated by the target IP address within a preset time period; Alternatively, the IP address information may include a source IP address and a destination IP address, and the traffic monitoring data may be monitoring data generated from messages sent by the network device indicated by the source IP address to the network device indicated by the destination IP address within a preset time period.

6. The method according to claim 1, characterized in that, Before checking whether a service statistics set matching the message exists under this security service, the method further includes: Check whether the network device has enabled the security service policy associated traffic monitoring function; If so, check if there is a service statistics set under this security service that matches the message; If not, then based on the message and the service information of the security service to which the security service policy matches the message, a log record corresponding to the security service is generated.

7. The method according to claim 1, characterized in that, Each traffic monitoring set is associated with at least one traffic identification field and a field value is set for that traffic identification field; the traffic monitoring set is used to monitor packets entering the network device that match the field value to generate monitoring data; The traffic identification field includes at least the source IP address, the destination IP address, and the application identifier of the application to which the packet belongs; The step of obtaining traffic monitoring data matching the IP address information of the packet within a preset time period from an existing traffic monitoring set includes: When multiple target traffic monitoring sets are identified from the existing traffic monitoring sets, traffic monitoring data that matches the IP address information of the packet within a preset time period is extracted from each target traffic monitoring set; wherein, the traffic identification field and its field value associated with the target traffic monitoring set match the IP address information of the packet. To obtain target traffic monitoring data, the traffic monitoring data is extracted from the traffic monitoring data of each target traffic monitoring set. The target traffic monitoring data is used as the traffic monitoring data that matches the IP address information of the packet within the preset time period; wherein, any target traffic monitoring data is simultaneously matched with the traffic identification field and its value used by each target traffic monitoring set when matching the IP address information of the packet.

8. The method according to claim 1, characterized in that, The method further includes: If the traffic monitoring set does not exist, or if there is no traffic monitoring data matching the IP address information of the packet within a preset time period in the traffic monitoring set, a service statistics set matching the packet under the security service is constructed based on the service information of the security service to which the security service policy matches the packet, and the IP address information of the packet. The communication characteristics corresponding to the packet and the current time are recorded in the service statistics set.

9. The method according to claim 8, characterized in that, Based on the service information of the security service to which the security service policy matches the message belongs, and the IP address information of the message, a service statistics set matching the message under the security service is constructed, including: A second set is generated, and an identification attribute is configured for the second set based on the service information of the security service, the IP address information of the packet, and the current time, so that the second set with the configured identification attribute is used as the service statistics set.

10. The method according to claim 1, characterized in that, The security business strategy encompasses one of the following business types: threat detection, content security, behavior control, and application identification.

11. A business monitoring device, characterized in that, Applied to network devices, the device includes: The inspection module is configured to check, for each security service policy that matches the currently received packet, whether there is a service statistics set under the security service that matches the packet, based on the service information of the security service to which the security service policy belongs and the IP address information of the packet. The first construction module is configured to, if no service statistics set matching the packet exists under the security service, obtain traffic monitoring data matching the IP address information of the packet within a preset time period from an existing traffic monitoring set, and construct a service statistics set matching the packet under the security service based on the traffic monitoring data, the IP address information of the packet, and the service information of the security service, and record the communication characteristics corresponding to the packet and the current time into the service statistics set; wherein, the service statistics set is used to monitor packets under the security service that have the same IP address information as the currently received packet.