Network abnormal traffic real-time detection method and system based on dynamic behavior chain
Patent Information
- Application Number
- CN202610020601.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-08
- Publication Date
- 2026-10-09
- Estimated Expiration
- 2046-01-08
AI Technical Summary
[0004]本申请目的是提供基于动态行为链的网络异常流量实时检测方法及系统,以解决现有技术中因缺乏行为时序逻辑建模导致隐蔽异常识别能力不足的问题
[0020] The real-time network abnormal traffic detection method based on dynamic behavior chains provided in this application acquires historical and real-time multidimensional data in IoT scenarios, uses a target digital twin model to reproduce normal interaction processes to construct an initial behavior benchmark library, and calibrates it by combining the temporal correlation features of historical behavior chains to form a high-fidelity target behavior benchmark library. On this basis, real-time multidimensional data is compared with this benchmark library, and difference information is extracted to identify abnormal behaviors that deviate from normal interaction logic, thereby achieving real-time and accurate detection of network abnormal traffic. This method overcomes the limitations of relying solely on static statistical feature modeling and improves the ability to identify hidden anomalies with temporal camouflage or gradual evolution characteristics.
Smart Images

Figure CN121841759B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network anomaly detection technology, and in particular to a method and system for real-time detection of network anomaly traffic based on dynamic behavior chains. Background Technology
[0002] In scenarios involving large-scale IoT connectivity, the network comprises a diverse range of devices that interact frequently, exhibiting highly dynamic and time-dependent communication behaviors. To ensure the secure and stable operation of the system, a technological means is urgently needed to sense and accurately identify abnormal traffic in real time.
[0003] Current solutions attempt to model device communication patterns by constructing behavioral profile models based on historical traffic statistics and using a sliding window mechanism to continuously compare current traffic with historical behavior to determine the presence of anomalies. However, such solutions struggle to effectively characterize the temporal logic and causal relationships between device behaviors during real-world interactions, resulting in limited ability to identify complex attacks or hidden anomalies. Especially when facing malicious traffic with slowly evolving behavior or mimicking normal interaction patterns, models relying solely on statistical features are prone to false negatives or misjudgments, failing to meet the real-time, accurate detection requirements of highly dynamic and adversarial scenarios. Summary of the Invention
[0004] The purpose of this application is to provide a method and system for real-time detection of abnormal network traffic based on dynamic behavior chains, so as to solve the problem that the lack of behavioral temporal logic modeling in the prior art leads to insufficient ability to identify hidden anomalies.
[0005] To address the aforementioned technical problems, in a first aspect, this application provides a method for real-time detection of abnormal network traffic based on dynamic behavior chains, including:
[0006] Acquire target historical datasets and real-time datasets in IoT access scenarios. The target historical datasets include historical protocol interaction data, historical transmission status data, and historical dynamic behavior chain data. The real-time datasets include real-time protocol interaction data, real-time transmission status data, and real-time dynamic behavior chain data.
[0007] Based on the historical protocol interaction data, historical transmission status data, and historical dynamic behavior chain data, the normal interaction process of the dynamic behavior chain is reproduced using the target digital twin model, and an initial behavior benchmark library of the dynamic behavior chain is generated.
[0008] Based on the temporal correlation characteristics of the historical dynamic behavior chain data, the initial behavior benchmark library is calibrated to generate the target behavior benchmark library;
[0009] The real-time protocol interaction data, real-time transmission status data, and real-time dynamic behavior chain data are compared with the target behavior benchmark library to obtain comparison difference information.
[0010] Based on the comparison difference information, abnormal interaction situations that do not conform to the normal interaction process of the dynamic behavior chain are identified, so as to realize the real-time detection of abnormal network traffic.
[0011] Secondly, this application provides a method and system for real-time detection of abnormal network traffic based on dynamic behavior chains, including:
[0012] The acquisition module is used to acquire target historical datasets and real-time datasets in IoT access scenarios. The target historical datasets include historical protocol interaction data, historical transmission status data, and historical dynamic behavior chain data. The real-time datasets include real-time protocol interaction data, real-time transmission status data, and real-time dynamic behavior chain data.
[0013] The generation module is used to reproduce the normal interaction process of the dynamic behavior chain based on the historical protocol interaction data, historical transmission status data and historical dynamic behavior chain data, and generate an initial behavior benchmark library of the dynamic behavior chain using the target digital twin model.
[0014] The calibration module is used to calibrate the initial behavior benchmark library based on the temporal correlation characteristics of the historical dynamic behavior chain data, and generate the target behavior benchmark library.
[0015] The comparison module is used to compare the real-time protocol interaction data, real-time transmission status data, and real-time dynamic behavior chain data with the target behavior benchmark library to obtain comparison difference information.
[0016] The identification module is used to identify abnormal interaction situations that do not conform to the normal interaction process of the dynamic behavior chain based on the comparison difference information, so as to realize the real-time detection of abnormal network traffic.
[0017] Thirdly, this application provides a computing device, including: a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are to be invoked and executed by the processing component to implement the steps of the real-time network abnormal traffic detection method based on dynamic behavior chains as described in the first aspect above.
[0018] Fourthly, this application provides a computer-readable storage medium storing a computer program that, when executed by a computer, can implement the steps of the real-time network abnormal traffic detection method based on dynamic behavior chains described in the first aspect above.
[0019] The beneficial effects of this application are:
[0020] The real-time network abnormal traffic detection method based on dynamic behavior chains provided in this application acquires historical and real-time multidimensional data in IoT scenarios, uses a target digital twin model to reproduce normal interaction processes to construct an initial behavior benchmark library, and calibrates it by combining the temporal correlation features of historical behavior chains to form a high-fidelity target behavior benchmark library. On this basis, real-time multidimensional data is compared with this benchmark library, and difference information is extracted to identify abnormal behaviors that deviate from normal interaction logic, thereby achieving real-time and accurate detection of network abnormal traffic. This method overcomes the limitations of relying solely on static statistical feature modeling and improves the ability to identify hidden anomalies with temporal camouflage or gradual evolution characteristics.
[0021] Furthermore, by analyzing the correlation and influence trends between protocol interaction and transmission status in the same sub-scenario, and combining the logical relationships and triggering conditions between nodes in the behavior chain, the parameters and logic of the digital twin model are finely adjusted to accurately reproduce the normal interaction process under various data combinations, and record the complete interaction sequence, state trajectory and connecting node information. Finally, a structured and semantically rich initial behavior benchmark library is formed. This initial behavior benchmark library not only reflects the surface communication mode, but also embeds the causal logic and temporal evolution law of device behavior, thereby overcoming the blind spot of abnormal perception caused by neglecting the inherent correlation of behavior in existing solutions, and enhancing the robustness and detection accuracy of the system in highly dynamic and highly adversarial environments. Attached Figure Description
[0022] To more clearly illustrate the technical solutions of the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0023] Figure 1 A flowchart illustrating the real-time network abnormal traffic detection method based on dynamic behavior chains provided in this application embodiment;
[0024] Figure 2 A schematic diagram illustrating a specific implementation of the real-time network abnormal traffic detection method based on dynamic behavior chains provided in this application embodiment;
[0025] Figure 3 This is a schematic diagram of the structure of a real-time network abnormal traffic detection system based on dynamic behavior chains provided in an embodiment of this application. Detailed Implementation
[0026] To address the problem that existing technologies struggle to characterize the temporal logic and causal dependencies of device interaction behavior in the highly dynamic environment of the Internet of Things (IoT), resulting in insufficient ability to identify hidden or progressively abnormal traffic, this application provides a real-time network abnormal traffic detection method based on dynamic behavior chains. This method integrates multi-dimensional historical data from protocol interactions, transmission states, and behavior chains to reproduce typical normal processes in a target digital twin model, forming an initial benchmark. Furthermore, it utilizes the inherent temporal correlation characteristics of the behavior chain for refined calibration, thereby establishing a target behavior benchmark library that closely approximates real-world operating conditions. Based on this, real-time multi-dimensional data is compared with this benchmark library to identify abnormal patterns deviating from normal logic at the interaction process level, achieving accurate and real-time detection of complex, disguised abnormal traffic.
[0027] To enable those skilled in the art to better understand the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments. Obviously, the described embodiments are merely some embodiments of the present application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0028] The core of this application is to provide a real-time network anomaly traffic detection method based on dynamic behavior chains. A flowchart of one specific implementation is shown below. Figure 1 As shown, the method includes:
[0029] Step 101: Obtain the target historical dataset and real-time dataset in the IoT access scenario. The target historical dataset includes historical protocol interaction data, historical transmission status data, and historical dynamic behavior chain data. The real-time dataset includes real-time protocol interaction data, real-time transmission status data, and real-time dynamic behavior chain data.
[0030] In this step, IoT access scenarios refer to specific application scenarios in which IoT devices access the network and engage in data interaction and business collaboration. These scenarios include smart park device access, industrial IoT device access, and other scenarios.
[0031] The target historical dataset refers to the historical data set used to construct the benchmark of the normal interaction process of the dynamic behavior chain. This data includes protocol interactions, transmission status and dynamic behavior chain-related data generated by various devices in the IoT access scenario within a preset time period.
[0032] Real-time datasets refer to the current data set used for real-time detection of abnormal network traffic. This data includes real-time protocol interactions, transmission status, and dynamic behavior chain-related data generated by various devices in IoT access scenarios.
[0033] Historical protocol interaction data refers to the historical data generated during the data interaction between various devices in an IoT access scenario based on communication protocols within a preset time period. This data includes information such as the protocol type, interaction instructions, interaction fields, and interaction sequence of the interaction between devices.
[0034] Historical transmission status data refers to the historical status data generated during the data transmission process of various devices in the IoT access scenario within a preset time period. This data includes information such as data transmission rate, latency, packet loss rate, and transmission link status.
[0035] Historical dynamic behavior chain data refers to the historical data generated during the operation of the dynamic behavior chain composed of various devices in the IoT access scenario within a preset time period. This data includes information such as the type of each behavior node in the dynamic behavior chain, the connection relationship between nodes, the node triggering order, and the timing characteristics.
[0036] Real-time protocol interaction data refers to the data generated during the real-time data interaction between various devices in an IoT access scenario based on communication protocols. This data includes information such as the protocol type, interaction commands, interaction fields, and interaction timing of the current real-time interaction between devices.
[0037] Real-time transmission status data refers to the status data generated by various devices in the IoT access scenario during the real-time data transmission process. This data includes information such as the current real-time data transmission rate, latency, packet loss rate, and transmission link status.
[0038] Real-time dynamic behavior chain data refers to the data generated during the real-time operation of the dynamic behavior chain composed of various devices in the IoT access scenario. This data includes information such as the type of each behavior node in the currently running dynamic behavior chain, the connection relationship between nodes, the node triggering order, and the timing characteristics.
[0039] In this embodiment, the coverage area of the IoT access scenario and the types of devices accessed within the scenario are first determined. The interaction and transmission data of various devices within the scenario are collected through the IoT access gateway and edge nodes to obtain the target historical dataset and real-time dataset.
[0040] Step 102: Based on the historical protocol interaction data, historical transmission status data, and historical dynamic behavior chain data, the normal interaction process of the dynamic behavior chain is reproduced using the target digital twin model to generate an initial behavior benchmark library for the dynamic behavior chain.
[0041] In this step, the target digital twin model refers to the digital twin model obtained by adjusting the model parameters and model logic based on the initial digital twin model.
[0042] A dynamic behavior chain refers to an ordered sequence of behaviors consisting of the interactive behaviors of multiple devices in an IoT access scenario. This behavior chain includes multiple behavioral units such as device data acquisition behavior, command response behavior, and business linkage behavior.
[0043] The normal interaction process of a dynamic behavior chain can be understood as the complete operation process of the dynamic behavior chain under normal circumstances. In this process, each behavior node starts and switches in a preset order, the protocol interaction between devices is smooth, and the transmission status is stable.
[0044] The initial behavior baseline library refers to the data set that records the characteristics of the normal interaction process of dynamic behavior chains.
[0045] In the embodiments of this application, such as Figure 2 As shown, step 102 specifically includes the following steps:
[0046] Step 201: Determine the correlation between historical protocol interaction data and historical transmission status data under the same IoT access sub-scenario, and analyze the impact trend of changes in different historical protocol interaction data on historical transmission status data.
[0047] In this step, the IoT access sub-scenario refers to the sub-scenarios under the IoT access scenario that are divided according to device type and business function. These sub-scenarios include the environmental monitoring sub-scenario of smart parks, the security linkage sub-scenario, etc.
[0048] The correlation refers to the correspondence between historical protocol interaction data and historical transmission status data within the same IoT access sub-scenario. This correlation includes the correspondence between protocol interaction commands and transmission rates, the correspondence between protocol interaction frequencies and transmission delays, etc.
[0049] The influencing trend refers to the pattern of changes in historical transmission status data caused by changes in historical protocol interaction data. This influencing trend includes trends such as the increase in transmission latency due to the increase in protocol interaction fields and the decrease in transmission packet loss rate due to the decrease in protocol interaction frequency.
[0050] In this embodiment, the boundary range of the same IoT access sub-scenario is first defined according to the device type and business function. Then, historical protocol interaction data and historical transmission status data within a preset time period are filtered within the same IoT access sub-scenario. Each set of historical protocol interaction data is then matched with the corresponding historical transmission status data to establish the correlation between the data.
[0051] Subsequently, key elements such as the number of fields and interaction frequency of historical protocol interaction data were simulated and modified in turn, and the corresponding changes in historical transmission status data were recorded simultaneously. Finally, based on the changes, the differences in historical transmission status data before and after the modification of different key elements were compared to obtain the trend of the impact of changes in historical protocol interaction data on historical transmission status data.
[0052] Step 202: Extract the node relationships and triggering conditions between different behavior nodes from the historical dynamic behavior chain data.
[0053] In this step, a behavior node refers to the basic behavior unit in a dynamic behavior chain, which includes device data acquisition nodes, instruction processing nodes, business linkage nodes, etc.
[0054] Node relationships refer to the connections between different behavioral nodes, including temporal relationships, logical dependencies, etc.
[0055] Triggering conditions refer to the key conditions for starting or switching behavior nodes. These triggering conditions include data acquisition completion conditions, instruction reception success conditions, and transmission status compliance conditions. A behavior node can only be started or switched when these conditions are met. Furthermore, the specific content of each condition is not specifically limited in the embodiments of this application, and can be set accordingly according to the actual situation.
[0056] In this embodiment, each behavior node is first extracted from historical dynamic behavior chain data, and the start time and completion time of each behavior node are marked. Then, based on the time marking of each behavior node, the chronological order of different behavior nodes is analyzed. Combined with the functional attributes of the behavior nodes, the logical dependency relationship between the nodes is determined, and thus the node relationship is obtained. Subsequently, the key data states before the start and switch of each behavior node are screened to determine the specific data conditions that can trigger the start or switch of the behavior node, and finally the triggering conditions are obtained.
[0057] Step 203: Based on the aforementioned correlation, influence trend, node relationship, and triggering conditions, adjust the model parameters and model logic of the pre-constructed initial digital twin model to obtain the target digital twin model.
[0058] In this step, the initial digital twin model refers to the digital twin model that has not undergone parameter and logic adjustments and is constructed based on general data presets for IoT access scenarios.
[0059] In this embodiment of the application, step 203 specifically includes the following steps:
[0060] Step 211: Identify the initial quantization parameters related to historical protocol interaction data and historical transmission status data in the initial digital twin model, as well as the initial node flow rules corresponding to historical dynamic behavior chain data.
[0061] In this step, the initial quantization parameters refer to the parameters related to historical protocol interaction data and historical transmission status data in the initial digital twin model. These initial quantization parameters include protocol field matching parameters, transmission rate reference parameters, transmission delay threshold parameters, etc., which are obtained based on general data presets for IoT access scenarios.
[0062] The initial node flow rules refer to the rules controlling the flow of nodes in the dynamic behavior chain in the initial digital twin model. These rules include node startup order rules, node switching trigger rules, etc., and are derived from the general operating logic preset of the dynamic behavior chain. Furthermore, the embodiments of this application do not specifically limit the specific content of each rule, and can be set accordingly according to the actual situation.
[0063] In this embodiment of the application, firstly, quantitative parameters related to field matching and interaction frequency of historical protocol interaction data, as well as quantitative parameters related to transmission rate and transmission delay of historical transmission status data, are selected from the initial digital twin model, and these parameters are determined as initial quantitative parameters; at the same time, logical rules related to the start order of dynamic behavior chain nodes and node switching conditions are selected, and these rules are determined as initial node flow rules.
[0064] Step 212: Based on the correlation and influence trend, adjust the parameter matching degree and parameter change range in the initial quantization parameters to obtain the target quantization parameters.
[0065] In this step, parameter matching degree refers to the degree of matching between the initial quantization parameters and historical protocol interaction data and historical transmission status data. This parameter matching degree includes the degree of fit between parameter values and historical data, the degree of adaptation between parameter types and historical data, etc.
[0066] The parameter variation range refers to the adjustable range of the initial quantization parameter. This parameter variation range includes the range of fluctuation of the parameter value and the range of the parameter change rate.
[0067] The target quantification parameter refers to the parameter obtained after adjusting the matching degree and change range of the initial quantification parameter. The target quantification parameter includes matching parameters that adapt to the correlation of historical data and change parameters that adapt to the influence trend of historical data.
[0068] In this embodiment of the application, based on the correlation, the numerical difference between the initial quantization parameter and the historical data is compared, and the adjustment range of the parameter matching degree is determined according to the magnitude and direction of the numerical difference. One specific adjustment method is: the larger the numerical difference, the larger the matching degree adjustment range; if the numerical difference is positive, the parameter is positively corrected; if the numerical difference is negative, the parameter is negatively corrected. This adjustment method makes the initial quantization parameter more closely match the actual characteristics of the historical data.
[0069] Based on the trend of influence, the direction and range of change of the initial quantization parameters are first clarified. The determined direction of change is used as the basis for adjustment and the range of change is used as the adjustment boundary. The magnitude of change of the initial quantization parameters is precisely adjusted so that the initial quantization parameters can accurately reflect the influence of changes in historical protocol interaction data on historical transmission status data. After the above adjustments, the target quantization parameters are obtained.
[0070] Step 213: Based on the node relationships, adjust the node flow order of the dynamic behavior chain in the initial node flow rule to obtain the target node flow rule.
[0071] In this step, the node flow sequence refers to the startup and switching order of each behavior node in the dynamic behavior chain. This node flow sequence includes starting the data acquisition node first and then starting the instruction processing node, completing the instruction response first and then performing business linkage, etc.
[0072] The target node flow rule refers to the rule obtained after adjusting the node flow order of the initial node flow rule. The target node flow rule includes flow order rules that adapt to node relationships, node switching trigger rules, etc.
[0073] In this embodiment of the application, firstly, the matching between the node flow order and the node relationship in the initial node flow rules is compared, and the flow order in the initial node flow rules that does not match the node relationship is deleted. Then, the flow order that matches the node temporal sequence relationship and logical dependency relationship is added, and finally the target node flow rules are obtained to ensure that there are no conflicts between the rules.
[0074] Step 214: Based on the triggering conditions, configure the logical judgment rules for the start and switch operations for each behavior node in the dynamic behavior chain, and combine them with the target node flow rules to form a target rule set.
[0075] In this step, the logical judgment rule refers to the judgment rule for controlling the start and switch of the behavior node. This rule includes the first logical judgment rule for the start operation and the second logical judgment rule for the switch operation.
[0076] The target rule set refers to the set of rules obtained by integrating logical judgment rules and target node flow rules. The target rule set includes the start judgment rules, switching judgment rules and node flow rules of behavior nodes.
[0077] In this embodiment of the application, step 214 specifically includes the following steps:
[0078] Step 221: Based on the relationship between the triggering conditions and each behavior node in the dynamic behavior chain, determine the start triggering condition and switch triggering condition for each behavior node.
[0079] In this step, the relationship between each behavior node can be understood as the temporal sequence and logical dependency between different behavior nodes. The conditions for starting and switching behavior nodes are related to the state of the associated nodes.
[0080] The trigger condition refers to the conditions for starting a behavior node. These conditions include data acquisition completion, instruction reception success, and completion of the preceding node. The behavior node can only start when these conditions are met.
[0081] The switching trigger condition refers to the conditions under which a behavior node can switch. These conditions include node task completion, transmission status compliance, and downstream node readiness. Only when these conditions are met can the behavior node switch to the next node.
[0082] In this embodiment, the correspondence between the triggering conditions and each behavior node is first analyzed, and the triggering conditions are divided into start-up triggering conditions and switch triggering conditions. Then, in combination with the association relationship of each behavior node, the prerequisite conditions that must be met before each behavior node starts are determined, and these prerequisite conditions are used as start-up triggering conditions. At the same time, the conditions that must be met for each behavior node to switch to the next node after completing the task are determined, and these conditions are used as switch triggering conditions.
[0083] Step 222: Configure the first logical judgment rule for the start operation of each behavior node according to the start trigger condition of each behavior node.
[0084] In this step, the first logical judgment rule refers to the judgment rule configured based on the start trigger condition of the behavior node, which is used to determine whether the start condition of the behavior node is met. This rule includes condition judgment logic, data verification logic, etc., and is adapted to the start requirements of each behavior node.
[0085] In this embodiment of the application, a logical judgment statement corresponding to the start trigger condition of each behavior node is set. For example, for the data collection completion condition, the judgment rule is set to determine that the condition is met when the amount of collected data reaches a preset threshold; thereby, the start trigger condition of each behavior node is converted into an executable first logical judgment rule.
[0086] Step 223: Based on the node flow direction of the dynamic behavior chain and the switching triggering conditions, configure a second logical judgment rule for the switching operation for each behavior node.
[0087] In this step, the node flow direction refers to the switching direction of behavior nodes in the dynamic behavior chain. The node flow direction includes the forward flow direction and the reverse flow direction.
[0088] In this step, the second logical judgment rule refers to the judgment rule based on the switching trigger condition of the behavior node and the node flow direction configuration, which is used to determine whether the switching condition of the behavior node is met. This rule includes condition judgment logic, flow direction verification logic, etc.
[0089] In this embodiment, the node flow direction of the dynamic behavior chain is first determined according to the target node flow rules, and the downstream node of each behavior node is marked. Then, for the switching trigger condition of each behavior node, combined with the node flow direction, a corresponding logical judgment statement is set. For example, for the transmission status compliance condition, the judgment rule is set to determine that the condition is met when the transmission delay is lower than a preset threshold and the downstream node is ready. Accordingly, the switching trigger condition and flow direction requirement of each behavior node are transformed into an executable second logical judgment rule.
[0090] Step 224: Analyze the execution priority of the first logical judgment rule and the second logical judgment rule on the same behavior node, and identify conflicting rules.
[0091] In this step, execution priority refers to the order in which the first logical judgment rule and the second logical judgment rule are executed on the same behavior node.
[0092] Conflict rules refer to rules in which the first and second logical judgment rules executed at the same behavior node contradict each other in terms of judgment logic or conditions.
[0093] In this embodiment, for the first and second logical judgment rules on the same behavior node, the operation flow of the behavior node is first analyzed to clarify the inherent logic that the node must first complete the start judgment and then perform the switch judgment. Based on this, the order of executing the start judgment first and then the switch judgment is determined to obtain the execution priority. Then, the judgment conditions and logic of the two types of rules are compared to identify the rules with contradictory judgment results. For example, for the same behavior node, the first logical judgment rule determines that its start condition is met, while the second logical judgment rule determines that its switch condition is not met. These contradictory rules are identified as conflicting rules.
[0094] Step 225: Based on the execution priority, adjust the conflict rules to obtain conflict-free rules, and combine them with the non-conflict rules to form an initial rule set;
[0095] In this step, a conflict-free rule refers to a rule obtained after adjusting conflicting rules, whose judgment logic and conditions no longer contradict other rules on the same behavior node.
[0096] Non-conflict rules refer to the first and second logical judgment rules that do not inherently contradict each other at the same behavior node, and can be used directly without adjustment.
[0097] The initial rule set refers to the set of rules obtained by integrating conflict-free rules and non-conflict rules. This rule set includes the start-up judgment rules and the switching judgment rules for behavior nodes.
[0098] In this embodiment, based on the execution priority, the judgment conditions or logic of the conflict rules are adjusted so that they no longer contradict other rules on the same behavior node, thus obtaining conflict-free rules; then the conflict-free rules and the non-conflict rules that did not contradict each other are summarized, and the rules are sorted according to the order of the behavior nodes to form an initial rule set.
[0099] Step 226: According to the target node flow rules, associate the initial rule set with each behavior node to form a target rule set.
[0100] In this embodiment, the flow order and downstream nodes of each behavior node are determined according to the target node flow rules; then, the first and second logical judgment rules in the initial rule set are allocated according to the one-to-one correspondence of the behavior node identifiers to obtain the rules associated with each behavior node, ensuring that each behavior node is associated with the corresponding start and switch judgment rules; finally, the associated rules are integrated with the target node flow rules to form the target rule set.
[0101] Step 215: Compare the change logic of the target quantization parameter with the target node flow rules and logical judgment rules of the target rule set to obtain the logical correspondence. Based on the logical correspondence, perform adaptability verification on the target quantization parameter and the target rule set to form a verification result.
[0102] The logic behind the changes in the target quantization parameters can be understood as the pattern of how the target quantization parameters change with historical data.
[0103] The logical correspondence can be understood as the matching relationship between the change logic of the target quantification parameters and the target node flow rules and logical judgment rules of the target rule set.
[0104] The verification result refers to the result obtained after verifying the adaptability of the target quantization parameters and the target rule set. The result includes both conflict-free and conflict-free adaptation.
[0105] In this embodiment, the change logic of the target quantification parameter is first extracted based on the correlation and influence trend. Then, the change logic is compared with the target node flow rules and logical judgment rules one by one. The focus is on analyzing the adaptability of the parameter change direction and magnitude with the node flow order and node dependency relationship, as well as whether the parameter change meets the threshold requirements of the start / switch conditions in the logical judgment rules. The adaptation or deviation between parameter change and node flow and trigger judgment is clarified. Finally, the logical correspondence is obtained based on the above analysis results.
[0106] Secondly, based on the logical correspondence, we check whether the target quantization parameters will cause the execution of the target rules to stall or the judgment results to be distorted under different scenarios such as extreme value changes and normal changes. Then we determine whether the target quantization parameters and the target rule set are compatible with each other and form a verification result.
[0107] Step 216: If the verification result is that there is no conflict, then based on the target quantization parameters and the target rule set, adjust the model parameters and model logic of the initial digital twin model to form the target digital twin model.
[0108] In this embodiment of the application, if the verification result is that there is no conflict in the adaptation, the target quantization parameters are updated to the parameter configuration of the initial digital twin model, and the target rule set is updated to the logical configuration of the initial digital twin model. Then, the updated initial digital twin model is tested, and the running effect of the model is verified by inputting historical data to ensure that the model can accurately reproduce the normal interaction process of the dynamic behavior chain. Finally, the model that passes the test run is determined as the target digital twin model.
[0109] If the verification result is an adaptation conflict, first locate the root cause of the conflict. Specifically, analyze whether there is a logical contradiction between the change logic of the target quantization parameter and the flow rule of the target node, or whether it does not match the condition threshold of the logical judgment rule. Then, make targeted adjustments according to the conflict type. If it is a logical contradiction between the parameter and the rule, optimize the change direction or magnitude of the target quantization parameter. If it is a mismatch between the parameter and the threshold of the rule, adjust the condition threshold of the logical judgment rule or the timing parameter of the flow rule of the target node.
[0110] After the above adjustments are completed, the updated target quantification parameter change logic and target rule set are re-verified for compatibility until a verification result without conflict is obtained; then the operations of updating parameters and rules, trial running the model, and determining the target digital twin model are performed.
[0111] Step 204: Based on the interaction logic of the dynamic behavior chain in the IoT access scenario, control the target digital twin model to reproduce the normal interaction process of the dynamic behavior chain under different data combinations, and record the interaction sequence, state change information and behavior node information of the dynamic behavior chain. The data combination consists of different historical protocol interaction data and historical transmission status data.
[0112] In this step, the interaction logic of the dynamic behavior chain refers to the interaction rules of each behavior node in the dynamic behavior chain. This logic includes the logic of node startup and switching, the logic of protocol interaction between devices, and the logic of transmission state changes, etc.
[0113] A data combination refers to a set of data consisting of different historical protocol interaction data and historical transmission status data. Each data combination corresponds to the operating state of a dynamic behavior chain.
[0114] In this step, the interaction sequence refers to the execution sequence of each behavior node in the normal interaction process of the dynamic behavior chain. This sequence includes the node's startup order, execution duration, completion status, etc.
[0115] State change information refers to the change curve of transmission state parameters in the normal interaction process of dynamic behavior chain. This change includes the changes in state parameters such as transmission rate, transmission delay, and packet loss rate.
[0116] Behavior node information refers to the connection information of each behavior node in the normal interaction process of the dynamic behavior chain. This information includes the trigger time of node switching, connection conditions, state changes, etc.
[0117] In this embodiment, the interaction logic of the dynamic behavior chain under the IoT access scenario is first determined based on the device interaction requirements of the IoT access scenario. Then, different historical protocol interaction data and historical transmission status data are combined into multiple data combinations. Subsequently, each data combination is input into the target digital twin model, and the model is controlled to run according to the interaction logic to reproduce the normal interaction process of the dynamic behavior chain under different data combinations.
[0118] Simultaneously, the startup sequence and execution duration of each behavior node during the reproduction process are recorded to obtain the interaction sequence. The real-time changes of transmission status parameters are recorded to obtain the status change information of transmission status. The trigger time and connection conditions of node switching are recorded to obtain the behavior node information.
[0119] Step 205: Integrate the interaction sequence, state change information and behavior node information of the dynamic behavior chain to form the initial behavior benchmark library of the dynamic behavior chain.
[0120] In this embodiment, the interaction sequence, state change information and behavior node information are classified according to the identifier of the data combination to ensure that the three types of information corresponding to the same data combination are grouped into the same data group; then a unified timestamp index is established for each type of data group to accurately align the start time and completion time of each behavior node in the interaction sequence with the sampling time of the transmission parameters in the state change information and the trigger time of node switching in the behavior node information.
[0121] Subsequently, based on the aligned timestamps, the status of the behavior node and the value of the transmission parameters corresponding to each time node are marked, clarifying the corresponding nodes and time associations between the three types of information; finally, all data that has completed timestamp alignment and association marking are grouped and archived according to the structured storage specifications to form the initial behavior benchmark library of the dynamic behavior chain.
[0122] The embodiments of this application can reproduce the interaction process that accurately reflects the normal operation state by constructing a target digital twin model, thereby generating an initial behavioral benchmark library, providing a precise foundation for subsequent calibration and anomaly detection.
[0123] Step 103: Based on the temporal correlation characteristics of the historical dynamic behavior chain data, the initial behavior benchmark library is calibrated to generate the target behavior benchmark library.
[0124] In this step, temporal correlation features refer to the set of features extracted from historical dynamic behavior chain data that are related to the time attributes of behavior nodes.
[0125] The target behavior benchmark library refers to the set of benchmark data obtained after calibrating the initial behavior benchmark library. This benchmark library corrects the deviation data in the initial behavior benchmark library that does not match the temporal characteristics of historical dynamic behavior chain data.
[0126] In this embodiment of the application, step 103 specifically includes the following steps:
[0127] Step 301: Extract temporal correlation features from the historical dynamic behavior chain data. The temporal correlation features include the temporal order of each behavior node in the dynamic behavior chain, the time interval range of adjacent behavior nodes, and the node repetition cycle characteristics.
[0128] In this step, the node timing sequence refers to the order in which each behavior node in the dynamic behavior chain is started and executed according to the actual running logic. This sequence can be that the data acquisition node starts before the instruction processing node, or the instruction processing node starts before the business linkage node, etc. The embodiment of this application does not limit the setting of this sequence, and it can be set according to the actual situation.
[0129] The time interval between adjacent behavior nodes refers to the time interval between the completion of the former and the start of the latter in a dynamic behavior chain. This time interval includes the time interval between the completion of the data acquisition node and the start of the instruction processing node, the time interval between the completion of the instruction processing node and the start of the business linkage node, etc.
[0130] The repetitive cycle characteristic of nodes refers to the repetitive execution time pattern of behavioral nodes with periodic operation attributes in a dynamic behavior chain. This characteristic includes the execution interval cycle of periodic data acquisition nodes, the operation cycle of periodic status monitoring nodes, etc., and is obtained based on the long-term operation time pattern analysis of historical dynamic behavior chain data.
[0131] In this embodiment, the start timestamp and completion timestamp of each behavior node are first extracted from historical dynamic behavior chain data. Then, the behavior nodes are arranged in chronological order according to their timestamps to obtain the node time sequence. Next, the difference between the completion timestamp and the start timestamp of adjacent behavior nodes is calculated, and the maximum and minimum values of the difference are statistically analyzed to determine the time interval range of adjacent behavior nodes. Subsequently, the execution time interval of behavior nodes with repetitive running attributes is statistically analyzed to obtain the node repetition cycle characteristics. Finally, the above three types of characteristics are integrated to form the time sequence association characteristics.
[0132] Step 302: Identify the deviation sequences in the interaction sequences of the initial behavior benchmark library that are inconsistent with the node temporal order, the deviation time data in the state change information that exceeds the time interval range, and the deviation node information in the behavior node information that is inconsistent with the node repetition periodic characteristics.
[0133] In this step, the node arrangement order refers to the order in which the behavior nodes are arranged in the interaction sequence of the initial behavior benchmark library.
[0134] Deviation sequence refers to an interaction sequence segment in the initial behavioral benchmark library where the node arrangement order is inconsistent with the node temporal order.
[0135] Deviation time data refers to the time data in the initial behavior baseline library that exceeds the time interval range of adjacent behavior nodes in the state change information.
[0136] Deviation node information refers to the node operation information in the initial behavioral benchmark library that is inconsistent with the node repetition cycle characteristics.
[0137] In this embodiment, the node arrangement order and node temporal order of the interaction sequence in the initial behavior benchmark library are compared node by node, and sequence segments with inconsistent order are marked to obtain the deviation sequence; then, the time interval data of adjacent behavior nodes in the state change information of the initial behavior benchmark library are extracted, and the time interval range is compared with a threshold to mark the deviation time data that exceeds the time interval range; then, the node running cycle data with repetition attribute is extracted from the behavior node information of the initial behavior benchmark library, and the data is compared with the node repetition cycle characteristics to mark the inconsistent node information as deviation node information.
[0138] Step 303: Based on the node time sequence, time interval range, and node repetition cycle characteristics, adjust the deviation sequence, deviation time data, and deviation node information to obtain the target behavior benchmark library.
[0139] In this embodiment of the application, firstly, based on the node temporal order, the node arrangement order of the deviation sequence is rearranged to adjust the deviation sequence to be consistent with the node temporal order; then, based on the time interval range of adjacent behavior nodes, the deviation time data is threshold-corrected to adjust the deviation time data that exceeds the time interval range to the time interval range.
[0140] Subsequently, based on the node repetition cycle characteristics, the running cycle of the deviation node information is corrected in a regular way to make it conform to the node repetition cycle characteristics; finally, the adjusted deviation sequence, deviation time data, deviation node information are integrated with the non-deviation data in the initial behavior benchmark library to form the target behavior benchmark library, where the non-deviation data refers to the original data in the initial behavior benchmark library that has not been marked as deviation sequence, deviation time data, or deviation node information.
[0141] This application embodiment accurately identifies deviation data in the initial behavioral benchmark library, and then makes targeted adjustments to the deviation data based on time series characteristics to generate a target behavioral benchmark library; the target behavioral benchmark library eliminates deviations that do not conform to historical time series characteristics, effectively improving the accuracy and fit of the data.
[0142] Step 104: Compare the real-time protocol interaction data, real-time transmission status data, and real-time dynamic behavior chain data with the target behavior benchmark library to obtain comparison difference information.
[0143] In this step, the comparison difference information refers to the set of difference data obtained by comparing the real-time protocol interaction data, real-time transmission status data, and real-time dynamic behavior chain data with the corresponding calibration data in the target behavior benchmark library. This information includes difference information in dimensions such as data content, temporal characteristics, and operating status.
[0144] In this embodiment of the application, step 104 specifically includes the following steps:
[0145] Step 401: Compare the real-time protocol interaction data, the real-time transmission status data, and the real-time dynamic behavior chain data with the calibrated interaction sequence, the calibrated status change information, and the calibrated behavior node information, respectively, to identify the first difference data, the second difference data, and the third difference data.
[0146] In this embodiment of the application, the calibrated interaction sequence refers to the dynamic behavior chain interaction sequence stored in the target behavior benchmark library after being calibrated by time-series features.
[0147] In this step, the calibrated state change information refers to the transmission state change trajectory data stored in the target behavior benchmark library after being calibrated by time-series characteristics.
[0148] The calibrated behavior node information refers to the behavior node operation information stored in the target behavior benchmark library after being calibrated by time-series features.
[0149] The first difference data refers to the difference data obtained by comparing the real-time protocol interaction data with the calibrated interaction sequence. This data includes difference information such as missing protocol interaction fields and disordered interaction command order.
[0150] The second difference data refers to the difference data obtained by comparing the real-time transmission status data with the status change information after calibration. This data includes difference information such as transmission rate deviation and transmission delay exceeding limits.
[0151] The third type of difference data refers to the difference data obtained by comparing the real-time dynamic behavior chain data with the calibrated behavior node information. This data includes differences such as node start-up time deviation and node repetition cycle discrepancy. The above three types of difference data correspond to differences in the three dimensions of protocol interaction, transmission status, and behavior nodes, respectively.
[0152] In this embodiment, a unified timestamp index is first established for the three types of real-time data and the corresponding calibration data in the target behavior benchmark library to achieve precise time alignment of the data; then, the real-time protocol interaction data and the calibrated interaction sequence are compared instruction by instruction and field by field to mark the parts with inconsistent field content or mismatched time sequence, and the first difference data is obtained.
[0153] Simultaneously, the real-time transmitted status data is compared with the calibrated status change information parameter by parameter and time interval by time interval, and the parts of the parameters that exceed the normal range or the time intervals that do not match are marked to obtain the second difference data; the real-time dynamic behavior chain data is compared with the calibrated behavior node information node by node and cycle by cycle, and the parts of the node start time deviation or cycle pattern that do not match are marked to obtain the third difference data.
[0154] Step 402: Integrate the first difference data, the second difference data, and the third difference data to form comparison difference information.
[0155] In this embodiment, a unified data identifier is first added to the first difference data, the second difference data, and the third difference data. The data identifier includes the timestamp of the data comparison, the corresponding device type, and the difference dimension. Then, the three types of difference data are classified and associated according to the data identifier to clarify the various types of difference content corresponding to the same timestamp and the same device. Finally, the classified and associated difference data is stored in a structured manner to form comparison difference information.
[0156] The embodiments of this application comprehensively reflect the deviation between real-time data and normal benchmark data by comparing difference information, providing a clear and accurate basis for subsequent anomaly identification and ensuring the reliability and accuracy of the anomaly detection process.
[0157] Step 105: Based on the comparison difference information, identify abnormal interaction situations that do not conform to the normal interaction process of the dynamic behavior chain, so as to realize real-time detection of abnormal network traffic.
[0158] In this step, an abnormal interaction situation refers to a situation where the real-time collected protocol interaction, transmission status, and dynamic behavior chain data deviate from the normal interaction process described by the target behavior benchmark library, thereby causing the dynamic behavior chain to run disorderly or interrupted. Such abnormal interaction situations include node startup failure caused by protocol command errors and process lag caused by transmission parameter exceeding limits.
[0159] In this embodiment of the application, step 105 specifically includes the following steps:
[0160] Step 501: Based on the various types of difference data in the comparison difference information, set the corresponding difference judgment conditions.
[0161] In this step, the various types of difference data refer to the first difference data, the second difference data, and the third difference data included in the comparison difference information.
[0162] In this step, the difference judgment criteria refer to the standards set for each type of difference data to determine whether the data deviates from the normal range. They are the basis for distinguishing between normal fluctuations and abnormal deviations in the difference data.
[0163] In this embodiment, for the first difference data in the comparison difference information, threshold conditions are set for the number of missing instructions and the number of times the instruction order is disordered, based on the protocol instruction specifications of the calibrated interaction sequence; for the second difference data, threshold conditions for the transmission rate and transmission delay are set based on the parameter fluctuation range of the calibrated state change information; for the third difference data, threshold conditions for the node start time deviation and repetition cycle deviation are set based on the operating rules of the calibrated behavior node information.
[0164] Step 502: Identify abnormal candidate data that do not meet the corresponding difference judgment conditions from various types of difference data.
[0165] In this step, abnormal candidate data refers to the difference data segments that exceed the threshold range set by the difference judgment conditions or do not conform to the logical judgment rules. The abnormal candidate data can be the first difference data that exceeds the instruction missing threshold, or the second difference data that exceeds the transmission delay threshold, etc.
[0166] In this embodiment, the first difference data is first compared item by item with the difference judgment conditions of the corresponding protocol interaction dimension, and data with the number of missing instructions exceeding the threshold and the number of times the instruction order is disordered exceeding the threshold are marked. Then, the second difference data is compared parameter by parameter with the difference judgment conditions of the corresponding transmission state dimension, and data with the transmission rate and transmission delay exceeding the threshold are marked. Next, the third difference data is compared feature by feature with the difference judgment conditions of the corresponding behavior node dimension, and data with the node start time deviation and repetition cycle deviation exceeding the threshold are marked. Finally, all the marked data are integrated to obtain abnormal candidate data.
[0167] Step 503: If at least one type of abnormal candidate data causes the normal interaction process of the dynamic behavior chain to be interrupted, it is determined that there is an abnormal interaction situation, so as to realize the real-time detection of abnormal network traffic.
[0168] In this embodiment, abnormal candidate data is input into the target digital twin model to simulate the impact of abnormal data on the normal interaction process of the dynamic behavior chain, and to monitor whether the behavior nodes in the dynamic behavior chain experience startup failure, switching stagnation, or running lag. If the monitoring results show that at least one type of abnormal candidate data causes the above situation and prevents the normal interaction process of the dynamic behavior chain from continuing, it is determined that there is an interaction anomaly. The network traffic generated by the device protocol interaction and data transmission corresponding to the interaction anomaly is the abnormal traffic.
[0169] The embodiments of this application achieve accurate mapping of differential data to abnormal situations, avoiding misjudgment and missed judgment, and providing a reliable basis for network abnormal traffic detection.
[0170] Figure 3 This is a schematic diagram of a specific implementation of the real-time network anomaly traffic detection system based on dynamic behavior chains provided in this application embodiment, with reference to... Figure 3 The system may include:
[0171] The acquisition module 31 is used to acquire the target historical dataset and the real-time dataset in the IoT access scenario. The target historical dataset includes historical protocol interaction data, historical transmission status data and historical dynamic behavior chain data. The real-time dataset includes real-time protocol interaction data, real-time transmission status data and real-time dynamic behavior chain data.
[0172] The generation module 32 is used to reproduce the normal interaction process of the dynamic behavior chain based on the historical protocol interaction data, historical transmission status data and historical dynamic behavior chain data, and generate an initial behavior benchmark library of the dynamic behavior chain using the target digital twin model.
[0173] The calibration module 33 is used to calibrate the initial behavior benchmark library based on the temporal correlation characteristics of the historical dynamic behavior chain data to generate the target behavior benchmark library.
[0174] The comparison module 34 is used to compare the real-time protocol interaction data, real-time transmission status data and real-time dynamic behavior chain data with the target behavior benchmark library to obtain comparison difference information.
[0175] The identification module 35 is used to identify abnormal interaction situations that do not conform to the normal interaction process of the dynamic behavior chain based on the comparison difference information, so as to realize the real-time detection of abnormal network traffic.
[0176] The network abnormal traffic real-time detection system based on dynamic behavior chain in this application embodiment is used to implement the aforementioned network abnormal traffic real-time detection method based on dynamic behavior chain. Therefore, the specific implementation of the network abnormal traffic real-time detection system based on dynamic behavior chain can be found in the embodiment section of the network abnormal traffic real-time detection method based on dynamic behavior chain above. The specific implementation can be referred to the description of the corresponding embodiment, and will not be repeated here.
[0177] This application also provides a computing device, including: a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are to be invoked and executed by the processing component to implement the steps of any of the above-described methods for real-time detection of abnormal network traffic based on dynamic behavior chains.
[0178] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a computer, implements the steps of any of the above-described methods for real-time detection of abnormal network traffic based on dynamic behavior chains.
[0179] In one exemplary embodiment, the aforementioned computer-readable storage medium may include, but is not limited to, various media capable of storing computer programs, such as USB flash drives, read-only memory, random access memory, portable hard drives, magnetic disks, or optical disks.
[0180] The embodiments of this application also provide a computer program product, which includes a computer program that, when executed by a processor, implements the steps in any of the embodiments of the real-time network abnormal traffic detection method based on dynamic behavior chains.
[0181] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0182] The above provides a detailed description of the real-time network abnormal traffic detection method and system based on dynamic behavior chains provided in this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the embodiments above are only for the purpose of helping to understand the method and its core ideas. It should be noted that those skilled in the art can make several improvements and modifications to this application without departing from the principles of this application, and these improvements and modifications also fall within the protection scope of this application.
Claims
1. A method for real-time detection of abnormal network traffic based on dynamic behavior chains, characterized in that, include: Acquire target historical datasets and real-time datasets in IoT access scenarios. The target historical dataset includes historical protocol interaction data, historical transmission status data, and historical dynamic behavior chain data. The real-time dataset includes real-time protocol interaction data, real-time transmission status data, and real-time dynamic behavior chain data. Protocol interaction data includes the protocol type, interaction commands, interaction fields, and interaction timing of interactions between devices. Transmission status data includes the data transmission rate, latency, packet loss rate, and transmission link status. Dynamic behavior chain data includes the type of each behavior node in the dynamic behavior chain, the connection relationship between nodes, the node triggering order, and timing characteristics. Based on the historical protocol interaction data, historical transmission status data, and historical dynamic behavior chain data, the normal interaction process of the dynamic behavior chain is reproduced using the target digital twin model, and an initial behavior benchmark library of the dynamic behavior chain is generated. The dynamic behavior chain refers to an ordered sequence of behaviors composed of the interaction behaviors of multiple devices in the Internet of Things access scenario. Based on the temporal correlation characteristics of the historical dynamic behavior chain data, the initial behavior benchmark library is calibrated to generate the target behavior benchmark library; The real-time protocol interaction data, real-time transmission status data, and real-time dynamic behavior chain data are compared with the target behavior benchmark library to obtain comparison difference information. Based on the comparison difference information, abnormal interaction situations that do not conform to the normal interaction process of the dynamic behavior chain are identified, so as to realize the real-time detection of abnormal network traffic. Based on the temporal correlation characteristics of the historical dynamic behavior chain data, the initial behavior benchmark library is calibrated to generate the target behavior benchmark library, including: Temporal correlation features are extracted from the historical dynamic behavior chain data. These temporal correlation features include the temporal order of each behavior node in the dynamic behavior chain, the time interval range of adjacent behavior nodes, and the node repetition cycle characteristics. Identify the deviation sequences in the interaction sequences of the initial behavior benchmark library that are inconsistent with the node temporal order, the deviation time data in the state change information that exceeds the time interval range, and the deviation node information in the behavior node information that is inconsistent with the node repetition period characteristics. Based on the node time sequence, time interval range, and node repetition period characteristics, the deviation sequence, deviation time data, and deviation node information are adjusted to obtain the target behavior benchmark library.
2. The method for real-time detection of abnormal network traffic based on dynamic behavior chains according to claim 1, characterized in that, Based on the historical protocol interaction data, historical transmission status data, and historical dynamic behavior chain data, the normal interaction process of the dynamic behavior chain is reproduced using the target digital twin model, generating an initial behavior benchmark library for the dynamic behavior chain, including: Determine the correlation between historical protocol interaction data and historical transmission status data in the same IoT access sub-scenario, and analyze the impact trend of changes in different historical protocol interaction data on historical transmission status data; Extract the node relationships and triggering conditions between different behavior nodes from the historical dynamic behavior chain data; Based on the aforementioned relationships, influence trends, node relationships, and triggering conditions, the model parameters and model logic of the pre-constructed initial digital twin model are adjusted to obtain the target digital twin model. Based on the interaction logic of the dynamic behavior chain in the IoT access scenario, the target digital twin model is controlled to reproduce the normal interaction process of the dynamic behavior chain under different data combinations, and the interaction sequence, state change information and behavior node information of the dynamic behavior chain are recorded. The data combination consists of different historical protocol interaction data and historical transmission status data. The interaction sequence, state change information, and behavior node information of the dynamic behavior chain are integrated to form the initial behavior benchmark library of the dynamic behavior chain.
3. The method for real-time detection of abnormal network traffic based on dynamic behavior chains according to claim 2, characterized in that, Based on the aforementioned relationships, influence trends, node relationships, and triggering conditions, the model parameters and logic of the pre-constructed initial digital twin model are adjusted to obtain the target digital twin model, including: Identify the initial quantization parameters related to historical protocol interaction data and historical transmission status data in the initial digital twin model, as well as the initial node flow rules corresponding to historical dynamic behavior chain data; Based on the aforementioned correlation and influence trend, the parameter matching degree and parameter change magnitude in the initial quantization parameters are adjusted to obtain the target quantization parameters; Based on the node relationships, the node flow order of the dynamic behavior chain in the initial node flow rule is adjusted to obtain the target node flow rule; Based on the triggering conditions, logical judgment rules for starting and switching operations are configured for each behavior node in the dynamic behavior chain, and combined with the target node flow rules, a target rule set is formed; The change logic of the target quantization parameter is compared with the target node flow rules and logical judgment rules of the target rule set to obtain a logical correspondence. Based on the logical correspondence, the adaptability of the target quantization parameter and the target rule set is verified to form a verification result. If the verification result is that there is no conflict, then based on the target quantization parameters and target rule set, the model parameters and model logic of the initial digital twin model are adjusted to form the target digital twin model.
4. The method for real-time detection of abnormal network traffic based on dynamic behavior chains according to claim 3, characterized in that, The logical judgment rules include a first logical judgment rule and a second logical judgment rule; Based on the triggering conditions, logical judgment rules for startup and switching operations are configured for each behavior node in the dynamic behavior chain. Combined with the target node flow rules, a target rule set is formed, including: Based on the relationship between the triggering conditions and each behavior node in the dynamic behavior chain, determine the start triggering condition and switch triggering condition for each behavior node; Based on the triggering conditions of each behavior node, configure the first logical judgment rule for the startup operation of each behavior node; Based on the node flow direction of the dynamic behavior chain and the switching triggering conditions, a second logical judgment rule for the switching operation is configured for each behavior node; Analyze the execution priority of the first and second logical judgment rules on the same behavior node, and identify conflicting rules; Based on the execution priority, the conflict rules are adjusted to obtain conflict-free rules, which are then combined with the non-conflict rules to form an initial rule set. Based on the target node flow rules, the initial rule set is associated with each behavior node to form the target rule set.
5. The method for real-time detection of abnormal network traffic based on dynamic behavior chains according to claim 1, characterized in that, The target behavior benchmark library includes calibrated interaction sequences, calibrated state change information, and calibrated behavior node information. The real-time protocol interaction data, real-time transmission status data, and real-time dynamic behavior chain data are compared with the target behavior benchmark library to obtain comparison difference information, including: The real-time protocol interaction data, the real-time transmission status data, and the real-time dynamic behavior chain data are compared with the calibrated interaction sequence, the calibrated status change information, and the calibrated behavior node information, respectively, to identify the first difference data, the second difference data, and the third difference data. The first difference data, the second difference data, and the third difference data are integrated to form comparison difference information.
6. The method for real-time detection of abnormal network traffic based on dynamic behavior chains according to claim 1, characterized in that, Based on the comparison difference information, abnormal interaction situations that do not conform to the normal interaction process of the dynamic behavior chain are identified to achieve real-time detection of abnormal network traffic, including: Based on the various types of difference data in the comparison difference information, set corresponding difference judgment conditions; Identify abnormal candidate data that do not meet the corresponding difference judgment conditions from various types of difference data; If at least one type of abnormal candidate data causes the normal interaction process of the dynamic behavior chain to be interrupted, then an abnormal interaction situation is determined to exist, so as to realize the real-time detection of abnormal network traffic.
7. A real-time network anomaly traffic detection system based on dynamic behavior chains, used to execute the real-time network anomaly traffic detection method based on dynamic behavior chains as described in any one of claims 1 to 6, characterized in that, include: The acquisition module is used to acquire target historical datasets and real-time datasets in IoT access scenarios. The target historical datasets include historical protocol interaction data, historical transmission status data, and historical dynamic behavior chain data. The real-time datasets include real-time protocol interaction data, real-time transmission status data, and real-time dynamic behavior chain data. The generation module is used to reproduce the normal interaction process of the dynamic behavior chain based on the historical protocol interaction data, historical transmission status data and historical dynamic behavior chain data, and generate an initial behavior benchmark library of the dynamic behavior chain using the target digital twin model. The calibration module is used to calibrate the initial behavior benchmark library based on the temporal correlation characteristics of the historical dynamic behavior chain data, and generate the target behavior benchmark library. The comparison module is used to compare the real-time protocol interaction data, real-time transmission status data, and real-time dynamic behavior chain data with the target behavior benchmark library to obtain comparison difference information. The identification module is used to identify abnormal interaction situations that do not conform to the normal interaction process of the dynamic behavior chain based on the comparison difference information, so as to realize the real-time detection of abnormal network traffic.
8. A computing device, characterized in that, It includes a processing component and a storage component; the storage component stores one or more computer instructions; the one or more computer instructions are invoked and executed by the processing component to implement the real-time network abnormal traffic detection method based on dynamic behavior chains as described in any one of claims 1 to 6.
9. A computer storage medium, characterized in that, The system contains a computer program that, when executed by a computer, implements the real-time network abnormal traffic detection method based on dynamic behavior chains as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Abnormal behavior detection method and device, terminal equipment and storage medium
CN114301645A
Network information security protection method and system based on artificial intelligence dynamic defense
CN120165968A