Network intrusion tracing method and system based on behavior analysis
By constructing an attack activity propagation graph and calculating multi-dimensional behavioral analysis indicators, the shortcomings of network intrusion detection systems in tracing the source and responding to attacks are addressed, enabling accurate identification and dynamic defense against attack behaviors.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HANGZHOU JIYONG TECHNOLOGY CO LTD
- Filing Date
- 2025-12-30
- Publication Date
- 2026-04-14
AI Technical Summary
Existing network intrusion detection systems struggle to effectively identify new, mutated, or multi-hop attack behaviors, have weak source tracing capabilities, and exhibit delayed response to defense strategies, lacking time-series correlation analysis based on behavioral evolution.
By constructing an attack activity propagation graph, calculating the attack propagation coefficient and behavioral impulse factor between nodes, tracing attack paths and generating a set of potential attack sources, and combining the source tracing traffic overflow index and attack intensity adjustment coefficient, a dynamic defense strategy is triggered.
It improves the accuracy and interpretability of attack path tracing, dynamically identifies potential attack sources, enhances real-time response capabilities, and enables precise location and rapid defense against hidden attack sources.
Smart Images

Figure CN121864408A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, specifically to a network intrusion tracing method and system based on behavior analysis. Background Technology
[0002] With the continuous expansion of network system scale and the increasing complexity of application scenarios, network intrusion methods are becoming more diversified, highly concealed, and have longer attack chains. Traditional intrusion detection systems that rely on feature matching or static rules are struggling to effectively identify new, mutated, or multi-hop attack behaviors, and their source tracing capabilities are weak, making it difficult to accurately locate attack source nodes and limiting the real-time performance and accuracy of defense strategies. In recent years, detection methods based on behavior analysis have gradually gained attention. These methods identify potential attack activities by modeling the behavioral patterns of network entities and mining abnormal interaction features. However, existing methods still suffer from problems in intrusion source tracing, such as incomplete attack path modeling, difficulty in dynamically depicting attack propagation relationships, lack of temporal correlation analysis based on behavioral evolution, inability to effectively deduce attack sources, and delayed defense response and difficulty in dynamically adjusting strategies based on attack intensity. Therefore, there is an urgent need for an intrusion source tracing technology that integrates behavior modeling, propagation graph calculation, and temporal analysis to improve the accuracy of attack behavior identification, the precision of attack source location, and to achieve dynamic response of defense mechanisms. Summary of the Invention
[0003] In view of the shortcomings of the prior art described above, the purpose of this invention is to provide a network intrusion tracing method and system based on behavior analysis to solve the above-mentioned technical problems.
[0004] To achieve the above objectives, the present invention provides the following technical solution: a network intrusion tracing method based on behavior analysis, comprising:
[0005] S1: Based on network node traffic data, access logs, and interaction behavior information, construct an attack activity propagation graph and calculate the attack propagation coefficient between nodes;
[0006] S2: Based on the behavioral data and attack propagation coefficient of each node in the attack activity propagation graph, calculate the behavioral impulse factor of the node to determine the attack participating nodes;
[0007] S3: Calculate the time propagation coefficient of the attack path and construct the attack time trajectory based on the interaction time difference characteristics and behavioral impulse factors between nodes;
[0008] S4: Calculate the source tracing traffic overflow index based on the traffic rate between nodes, the attack propagation coefficient, and the time propagation coefficient, and generate a set of potential attack sources;
[0009] S5: Calculate the attack strength adjustment coefficient based on the source traffic overflow index and traffic rate, and trigger the defense strategy response mechanism based on the attack strength adjustment coefficient.
[0010] The present invention is further configured such that S1 includes:
[0011] Using each entity in the network as a node, and based on traffic data and log analysis, potential attack propagation paths between network entities are identified as connection edges to construct an attack activity propagation graph;
[0012] For each connection edge in the attack propagation graph, by analyzing the interaction information between nodes, and combining traffic time delay, interaction frequency, physical distance and information propagation radius, a corresponding attack propagation coefficient is calculated and assigned.
[0013] The present invention is further configured such that S2 includes:
[0014] After the attack activity propagation graph is fully constructed, for each node in the graph, calculate the behavior impulse factor of the node at a preset time.
[0015] The behavioral impulse factor is calculated based on the probability of abnormal behavior between nodes, the attack propagation coefficient, and the physical distance between nodes.
[0016] When a node's behavior pulse factor exceeds a preset pulse threshold, the node is identified as an attack participant exhibiting abnormal behavior.
[0017] The present invention is further configured such that S3 includes:
[0018] Attack path tracing is performed based on the attack activity propagation graph and attack participating nodes;
[0019] The time propagation coefficient of each path is calculated based on the behavioral impulse factor of the attacking nodes and the time difference of node interaction.
[0020] The attack time trajectory is constructed based on the time propagation coefficient.
[0021] The present invention is further configured such that S4 includes:
[0022] Backtracking of attack sources based on attack time trajectory and source tracing path data;
[0023] Calculate the source tracing traffic overflow index for each node based on the attack propagation coefficient, time propagation coefficient, and traffic rate between nodes;
[0024] When the source tracing traffic overflow index of a node exceeds the preset source tracing threshold, the node is marked as a potential attack source and included in the potential attack source set.
[0025] The present invention is further configured such that S5 includes:
[0026] Based on the source traffic overflow index and the set of potential attack sources, select potential attack source nodes to be responded to;
[0027] The real-time traffic rates of potential attack source nodes and their associated nodes are aggregated and normalized to generate a dynamic traffic adjustment factor.
[0028] Calculate the attack intensity adjustment coefficient based on the source traffic overflow index and the traffic dynamic adjustment factor;
[0029] When the attack intensity adjustment coefficient is greater than the preset defense threshold, the defense strategy response mechanism is triggered.
[0030] The present invention is further configured to sort the attack time trajectory according to the time propagation coefficient, and determine the initial position of the potential attack source node in the attack propagation path based on the sorting result.
[0031] The present invention is further configured such that the method also includes: visualizing and outputting the propagation path formed by the attack time trajectory and the set of potential attack sources in the form of a network topology diagram.
[0032] The present invention also provides a network intrusion tracing system based on behavior analysis, the system comprising:
[0033] Attack Modeling Module: S1: Based on network node traffic data, access logs, and interaction behavior information, construct an attack activity propagation graph and calculate the attack propagation coefficient between nodes;
[0034] Behavior recognition module: S2: Based on the behavior data and attack propagation coefficient of each node in the attack activity propagation graph, calculate the behavior impulse factor of the node to determine the attack participating nodes;
[0035] Time Trajectory Module: S3: Calculates the time propagation coefficient of the attack path and constructs the attack time trajectory based on the interaction time difference characteristics and behavioral impulse factors between nodes;
[0036] Source tracing and assessment module: S4: Calculates the source tracing traffic overflow index based on the traffic rate between nodes, attack propagation coefficient, and time propagation coefficient, and generates a set of potential attack sources;
[0037] Response Decision Module: S5: Calculates the attack intensity adjustment coefficient based on the source traffic overflow index and traffic rate, and triggers the defense strategy response mechanism based on the attack intensity adjustment coefficient.
[0038] This invention provides a network intrusion tracing method and system based on behavior analysis. The method comprises: S1: Constructing an attack activity propagation graph and calculating the attack propagation coefficient between nodes based on network node traffic data, access logs, and interaction behavior information; S2: Calculating the behavioral impulse factor of each node in the attack activity propagation graph based on its behavioral data and attack propagation coefficient, thus identifying attack-involved nodes; S3: Calculating the time propagation coefficient of the attack path and constructing an attack time trajectory based on the interaction time difference characteristics and behavioral impulse factor between nodes; S4: Calculating the tracing traffic overflow index based on the traffic rate, attack propagation coefficient, and time propagation coefficient between nodes, generating a set of potential attack sources; S5: Calculating the attack intensity adjustment coefficient based on the tracing traffic overflow index and traffic rate, and triggering a defense strategy response mechanism based on the attack intensity adjustment coefficient. The beneficial effects include:
[0039] 1. Improve the accuracy of source tracing: By constructing an attack activity propagation graph and introducing multi-dimensional behavioral analysis indicators such as attack propagation coefficient, behavioral impulse factor, and time propagation coefficient, the propagation process of network attacks can be accurately depicted, improving the accuracy and interpretability of attack path tracing.
[0040] 2. Dynamically identify attack sources: By combining the source tracing traffic overflow index with the attack time trajectory, potential attack source nodes that are upstream in the attack propagation chain in the network can be effectively identified, enabling dynamic tracking and location of hidden attack sources.
[0041] 3. Enhanced real-time response capability: By constructing an attack intensity adjustment coefficient and a dynamic traffic adjustment mechanism, the system can sense changes in attack intensity in real time and dynamically trigger defense strategies based on preset defense thresholds, effectively shortening attack response latency.
[0042] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description
[0043] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. In the drawings:
[0044] Figure 1 A flowchart illustrating a network intrusion tracing method based on behavior analysis is shown as an exemplary embodiment of the present invention;
[0045] Figure 2 This is a schematic diagram illustrating the structure of a network intrusion tracing system based on behavior analysis, as an exemplary embodiment of the present invention. Detailed Implementation
[0046] The embodiments of the present invention will be described below with reference to the accompanying drawings and preferred embodiments. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific embodiments, and various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be understood that the preferred embodiments are only for illustrating the present invention and not for limiting the scope of protection of the present invention.
[0047] It should be noted that the illustrations provided in the following embodiments are only schematic representations of the basic concept of the present invention. Therefore, the drawings only show the components related to the present invention and are not drawn according to the actual number, shape and size of the components in the actual implementation. In the actual implementation, the form, quantity and proportion of each component can be arbitrarily changed, and the layout of the components may also be more complex.
[0048] In the following description, numerous details are explored to provide a more thorough explanation of embodiments of the invention. However, it will be apparent to those skilled in the art that embodiments of the invention may be practiced without these specific details. In other embodiments, well-known structures and devices are shown in block diagram form rather than in detail to avoid obscuring embodiments of the invention.
[0049] Example 1
[0050] A network intrusion tracing method based on behavior analysis, such as Figure 1 As shown, it includes:
[0051] S1: Based on network node traffic data, access logs, and interaction behavior information, construct an attack activity propagation graph and calculate the attack propagation coefficient between nodes;
[0052] S2: Based on the behavioral data and attack propagation coefficient of each node in the attack activity propagation graph, calculate the behavioral impulse factor of the node to determine the attack participating nodes;
[0053] S3: Calculate the time propagation coefficient of the attack path and construct the attack time trajectory based on the interaction time difference characteristics and behavioral impulse factors between nodes;
[0054] S4: Calculate the source tracing traffic overflow index based on the traffic rate between nodes, the attack propagation coefficient, and the time propagation coefficient, and generate a set of potential attack sources;
[0055] S5: Calculate the attack strength adjustment coefficient based on the source traffic overflow index and traffic rate, and trigger the defense strategy response mechanism based on the attack strength adjustment coefficient.
[0056] The present invention is further configured such that S1 includes:
[0057] Using each entity in the network as a node, and based on traffic data and log analysis, potential attack propagation paths between network entities are identified as connection edges to construct an attack activity propagation graph;
[0058] For each connection edge in the attack activity propagation graph, by analyzing the interaction information between nodes and combining traffic time delay, interaction frequency, physical distance, and information propagation radius, a corresponding attack propagation coefficient is calculated and assigned. Specifically, this embodiment provides a method for constructing an attack activity propagation graph based on network behavior data for subsequent behavior analysis and source tracing modeling. This method integrates traffic data, interaction behavior, and physical deployment information to quantify the potential attack propagation capabilities between devices. It collects multi-source heterogeneous data from the target network environment, including network traffic data involving key communication information such as source IP, destination IP, transmission protocol, and timestamps; behavior log data covering user behavior trajectories such as login logs, access control records, and operation command history; node location information, including network topology and the physical deployment location of devices; and node interaction frequency data obtained based on time window statistics. The above multi-dimensional data provides the necessary structural foundation and behavioral semantic support for the subsequent construction of the attack activity propagation graph. Each host, server, and security device in the network is abstracted as a graph node v. i Construct an attack activity propagation graph. If node v in the attack activity propagation graph... i With v j If communication or reachability exists between nodes, a directed edge is added to the graph, and the attack propagation coefficient between nodes is calculated. The attack propagation coefficient is used to measure the impact of an attack on node v. i With node v j The propagation strength and probability between them are used as edge weights in the attack propagation graph; the calculation logic for the attack propagation coefficient is as follows: APC ij For node v i With node v j The attack propagation coefficient between them, T ij For node v i to node v j Average propagation delay, interactivity (v i ,v j ) represents the node v within the preset statistical window. i With node v j Communication frequency, d ij The physical mesh distance between nodes, rij T represents the radius of information propagation. ij It can be calculated from the communication timestamp difference; r ij It can be configured according to network device type and topology characteristics; by using the attack propagation coefficient calculation formula to combine time delay, interaction frequency and topological distance, it can more accurately measure the propagation potential of an attack in the network, rather than relying solely on a single communication behavior.
[0059] The present invention is further configured such that S2 includes:
[0060] After the attack activity propagation graph is fully constructed, for each node in the graph, calculate the behavior impulse factor of the node at a preset time.
[0061] The behavioral impulse factor is calculated based on the probability of abnormal behavior between nodes, the attack propagation coefficient, and the physical distance between nodes.
[0062] When a node's behavior pulse factor exceeds a preset pulse threshold, the node is identified as an attack participant exhibiting abnormal behavior. Specifically, this embodiment provides a node behavior analysis method based on an attack activity propagation graph to identify attack participants. The node's behavior pulse factor describes the degree of abnormality of a node in the attack activity propagation graph at a certain moment. The calculation logic of the behavior pulse factor is as follows: BPF(v i ,t) represents node v i The behavioral impulse factor P at time t ij (t represents node v) i With node v j The probability of abnormal behavior at time t, λ ij For the adjustment coefficient, N(v) i ) represents the combination of adjacent nodes; the probability of abnormal behavior P ij (t) Based on a sliding time window, the frequency of anomalous operations is statistically analyzed in the node interaction sequence, and a Bayesian anomaly probability model is introduced to obtain λ. ij This is used to adjust the influence of propagation distance on the judgment of abnormal behavior, and its value range is [0,1]; if a node v i The behavior impulse factor BPF(v) at any time t i The t value is greater than the preset pulse threshold θ pulse If a node is identified as an attack participant, it is marked as such. The extracted attack participants serve as the foundation for constructing the attack propagation path, providing key inputs for identifying the attack timeline and potential source nodes, and enhancing the logical integrity and verifiability of the tracing chain.
[0063] The present invention is further configured such that S3 includes:
[0064] Attack path tracing is performed based on the attack activity propagation graph and attack participating nodes;
[0065] The time propagation coefficient of each path is calculated based on the behavioral impulse factor of the attacking nodes and the time difference of node interaction.
[0066] Attack time trajectories are constructed based on time propagation coefficients. Specifically, after constructing the attack activity propagation graph and detecting abnormal behavior, attack path tracing is further performed based on the identified attack participants in the attack activity propagation graph. The time propagation coefficient is calculated based on the behavioral impulse factors of the identified attack participants and their interaction time differences with adjacent nodes. This coefficient quantifies the temporal characteristics of attack propagation, reflects the temporal order of interactions between nodes and their impact on attack propagation, and, combined with the intensity of abnormal behavior and time differences, assists in identifying key nodes in the attack path, enabling accurate tracing of the attack source. The calculation logic of the time propagation coefficient is as follows: TPC ij For node v i With node v j The time propagation coefficient between them, TimeImpact(v) i ,v j ) is node v i With node v j The effect function of the time difference between attacks on attack propagation, ξ ij For adjustment coefficients; TimeImpact(v i ,v j ξ is used to quantify the promoting or inhibiting effect of node interaction time difference on attack propagation, calculated based on the time difference of node interaction; ij The weights of physical distance and propagation radius on time propagation are used to balance the values in the range of [0,1]. By statistically analyzing and sorting the time propagation coefficients of each side on all attack propagation paths, a time series trajectory reflecting the dynamics of attack propagation is formed, namely the attack time trajectory. This trajectory effectively reveals the spatiotemporal propagation order and key propagation nodes of the attack event. Combined with the intensity of behavioral anomalies and the time difference of node interactions, it can accurately depict the temporal order and spatial path of attack propagation, effectively reveal the dynamic process of the attack, and improve the timeliness and accuracy of attack path tracking.
[0067] The present invention is further configured such that S4 includes:
[0068] Backtracking of attack sources based on attack time trajectory and source tracing path data;
[0069] Calculate the source tracing traffic overflow index for each node based on the attack propagation coefficient, time propagation coefficient, and traffic rate between nodes;
[0070] When the source tracing traffic overflow index of a node exceeds a preset source tracing threshold, the node is marked as a potential attack source and added to the potential attack source set. Specifically, based on the aforementioned constructed attack time trajectory and source tracing path data, the source tracing traffic overflow index of each node in the network is calculated to identify potential attack source nodes. The attack time trajectory sorts the abnormal behavior and interaction time sequence of each node in the network by calculating the time propagation coefficient between attack participating nodes, forming a path sequence reflecting the attack propagation time sequence. The source tracing path data is based on the attack activity propagation graph and combined with the attack time trajectory to extract multiple possible attack propagation paths from the network topology. This data includes information such as the connection relationship between nodes, attack propagation coefficient, and time propagation coefficient, describing the spatial propagation path of the attack behavior and the mutual influence between nodes. The calculation logic of the source tracing traffic overflow index is as follows: STFI(v i ) is node v i Source tracing traffic overflow index, FlowRate ij For node v i With node v j The flow rate between, θ ij A preset traffic anomaly threshold is set; the preset traffic anomaly threshold θ ij Used to indicate the degree of traffic anomaly; when the source tracing traffic overflow index STFI(v) of a node... i When the value exceeds the preset tracing threshold, the node is determined to be a potential attack source and added to the potential attack source set for subsequent defense response and tracking analysis. By integrating attack propagation capabilities, temporal propagation characteristics, traffic anomaly degree and spatial information, the attack suspicion of the node is comprehensively evaluated to achieve more accurate and comprehensive attack source location.
[0071] The present invention is further configured such that S5 includes:
[0072] Based on the source traffic overflow index and the set of potential attack sources, select potential attack source nodes to be responded to;
[0073] The real-time traffic rates of potential attack source nodes and their associated nodes are aggregated and normalized to generate a dynamic traffic adjustment factor.
[0074] Calculate the attack intensity adjustment coefficient based on the source traffic overflow index and the traffic dynamic adjustment factor;
[0075] When the attack intensity adjustment coefficient exceeds the preset defense threshold, the defense strategy response mechanism is triggered. Specifically, based on the source traffic overflow index and potential attack source set obtained in the previous steps, this step aims to quantitatively assess the current attack intensity and dynamically adjust the network defense strategy accordingly. The current potential attack source node to be responded to is selected, and the real-time traffic rates of this node and its neighboring nodes are aggregated and standardized to obtain a traffic dynamic adjustment factor. Combining the source traffic overflow index of the selected node and the traffic dynamic adjustment factor, the attack intensity adjustment coefficient at the current moment is calculated. The calculation logic for the attack intensity adjustment coefficient is as follows: RAIAC(v i ,t) represents node v i The attack intensity adjustment coefficient at time t, A(t) is the set of potential attack sources, and δ is the adjustment factor. For flow dynamic adjustment factor, For flow characteristic transformation function; flow characteristic transformation function Used for standardizing real-time traffic rates, for example... The numerical stability can be enhanced by using the Sigmoid function. The calculation logic for the flow dynamic adjustment factor is as follows: μ is the average flow rate, and σ is the scaling parameter; σ controls the smoothness of the function and the sensitivity to numerical discrimination, with a value range of [5, 30] and a unit of Mbps; the attack strength adjustment coefficient RAIAC(v) is calculated in real time within each preset time window. i When the attack intensity adjustment coefficient exceeds the preset defense threshold, the system automatically triggers a defense response mechanism. The defense operations include: blocking or limiting abnormal traffic by dynamically configuring access control lists or application software-defined network policies; temporarily isolating nodes whose attack intensity adjustment coefficient exceeds the preset defense threshold and exceeds the allowable deviation limit to prevent further spread of the attack; and coordinating with intrusion detection systems, firewalls, and other security systems to enhance the overall collaborative response capability of the defense system. The attack intensity adjustment coefficient, by comprehensively considering source tracing data, attack intensity, and abnormal traffic characteristics, can perceive the activity and spread trend of attack activities in real time, guiding the system to adjust the defense intensity as needed.
[0076] The present invention further comprises sorting the attack time trajectory according to the time propagation coefficient, and determining the initial position of the potential attack source node in the attack propagation path based on the sorting result. Specifically, in this embodiment, based on the attack time trajectory obtained in the previous step, the time propagation coefficients corresponding to each edge on the path are sorted. The time propagation coefficient reflects the propagation intensity and order of the attack behavior in the time dimension. By sorting the time propagation coefficients, the sequential relationship and key nodes of the attack propagation can be clearly revealed. Each node in the attack path is arranged from largest to smallest according to the time propagation coefficient of its corresponding edge. The node with the larger time propagation coefficient is regarded as the precursor node of the attack propagation, representing the position where the attack occurred earlier in the path. Through this sorting result, the starting position of the potential attack source node in the attack propagation path, i.e., the initial attack point, can be determined. This method helps to improve the accuracy of attack tracing and the ability to reconstruct the time sequence, providing an effective basis for subsequent defense strategy deployment and tracking analysis.
[0077] The invention is further configured such that the method includes: visually outputting the propagation path formed by the attack time trajectory and the set of potential attack sources in the form of a network topology diagram; specifically, in this embodiment, based on the attack time trajectory and the set of potential attack sources constructed in the aforementioned steps, a network topology diagram reflecting the attack propagation path is further generated; the topology diagram graphically displays each node in the network and the attack propagation relationship between them, where nodes represent entities in the network and edges represent potential attack propagation paths; the path nodes in the attack time trajectory, their time propagation coefficients, and the source traffic overflow index are mapped onto the topology diagram, and the attack participation degree and attack propagation intensity of the nodes are identified by visual elements such as different colors, sizes, or line types; potential attack source nodes are highlighted with markers for easy and rapid identification; this visualization output supports the dynamic display of the temporal relationship and spatial distribution of attack propagation, assisting security personnel in real-time monitoring of the attack situation, analyzing propagation paths, and guiding the deployment of targeted defense measures, thereby improving the efficiency and accuracy of network security response.
[0078] Example 2
[0079] Please see Figure 2 This exemplary network intrusion tracing system based on behavior analysis includes:
[0080] Attack Modeling Module: S1: Based on network node traffic data, access logs, and interaction behavior information, construct an attack activity propagation graph and calculate the attack propagation coefficient between nodes;
[0081] Behavior recognition module: S2: Based on the behavior data and attack propagation coefficient of each node in the attack activity propagation graph, calculate the behavior impulse factor of the node to determine the attack participating nodes;
[0082] Time Trajectory Module: S3: Calculates the time propagation coefficient of the attack path and constructs the attack time trajectory based on the interaction time difference characteristics and behavioral impulse factors between nodes;
[0083] Source tracing and assessment module: S4: Calculates the source tracing traffic overflow index based on the traffic rate between nodes, attack propagation coefficient, and time propagation coefficient, and generates a set of potential attack sources;
[0084] Response Decision Module: S5: Calculates the attack intensity adjustment coefficient based on the source traffic overflow index and traffic rate, and triggers the defense strategy response mechanism based on the attack intensity adjustment coefficient.
[0085] It should be noted that the network intrusion tracing system based on behavior analysis provided in the above embodiments and the network intrusion tracing method based on behavior analysis provided in the above embodiments belong to the same concept. The specific ways in which each module and unit performs operations have been described in detail in the method embodiments, and will not be repeated here. In practical applications, the network intrusion tracing system based on behavior analysis provided in the above embodiments can be assigned to different functional modules as needed, that is, the internal structure of the system can be divided into different functional modules to complete all or part of the functions described above, and this is not a limitation here.
[0086] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
Claims
1. A network intrusion tracing method based on behavioral analysis, characterized in that, include: S1: Based on network node traffic data, access logs, and interaction behavior information, construct an attack activity propagation graph and calculate the attack propagation coefficient between nodes; S2: Based on the behavioral data and attack propagation coefficient of each node in the attack activity propagation graph, calculate the behavioral impulse factor of the node to determine the attack participating nodes; S3: Calculate the time propagation coefficient of the attack path and construct the attack time trajectory based on the interaction time difference characteristics and behavioral impulse factors between nodes; S4: Calculate the source tracing traffic overflow index based on the traffic rate between nodes, the attack propagation coefficient, and the time propagation coefficient, and generate a set of potential attack sources; S5: Calculate the attack strength adjustment coefficient based on the source traffic overflow index and traffic rate, and trigger the defense strategy response mechanism based on the attack strength adjustment coefficient.
2. The network intrusion tracing method based on behavior analysis according to claim 1, characterized in that, S1 includes: Using each entity in the network as a node, and based on traffic data and log analysis, potential attack propagation paths between network entities are identified as connection edges to construct an attack activity propagation graph; For each connection edge in the attack propagation graph, by analyzing the interaction information between nodes, and combining traffic time delay, interaction frequency, physical distance and information propagation radius, a corresponding attack propagation coefficient is calculated and assigned.
3. The network intrusion tracing method based on behavior analysis according to claim 1, characterized in that, S2 includes: After the attack activity propagation graph is fully constructed, for each node in the graph, calculate the behavior impulse factor of the node at a preset time. The behavioral impulse factor is calculated based on the probability of abnormal behavior between nodes, the attack propagation coefficient, and the physical distance between nodes. When a node's behavior pulse factor exceeds a preset pulse threshold, the node is identified as an attack participant exhibiting abnormal behavior.
4. The network intrusion tracing method based on behavior analysis according to claim 1, characterized in that, S3 includes: Attack path tracing is performed based on the attack activity propagation graph and attack participating nodes; The time propagation coefficient of each path is calculated based on the behavioral impulse factor of the attacking nodes and the time difference of node interaction. The attack time trajectory is constructed based on the time propagation coefficient.
5. The network intrusion tracing method based on behavior analysis according to claim 1, characterized in that, S4 includes: Backtracking of attack sources based on attack time trajectory and source tracing path data; Calculate the source tracing traffic overflow index for each node based on the attack propagation coefficient, time propagation coefficient, and traffic rate between nodes; When the source tracing traffic overflow index of a node exceeds the preset source tracing threshold, the node is marked as a potential attack source and included in the potential attack source set.
6. The network intrusion tracing method based on behavior analysis according to claim 1, characterized in that, S5 includes: Based on the source traffic overflow index and the set of potential attack sources, select potential attack source nodes to be responded to; The real-time traffic rates of potential attack source nodes and their associated nodes are aggregated and normalized to generate a dynamic traffic adjustment factor. Calculate the attack intensity adjustment coefficient based on the source traffic overflow index and the traffic dynamic adjustment factor; When the attack intensity adjustment coefficient is greater than the preset defense threshold, the defense strategy response mechanism is triggered.
7. The network intrusion tracing method based on behavior analysis according to claim 5, characterized in that, The attack time trajectories are sorted according to the time propagation coefficient, and the initial position of the potential attack source node in the attack propagation path is determined based on the sorting results.
8. The network intrusion tracing method based on behavior analysis according to claim 1, characterized in that, The method also includes: visualizing and outputting the propagation path formed by the attack time trajectory and the set of potential attack sources in the form of a network topology diagram.
9. A network intrusion tracing system based on behavior analysis, used to implement the network intrusion tracing method based on behavior analysis as described in any one of claims 1-8, characterized in that, include: Attack Modeling Module: S1: Based on network node traffic data, access logs, and interaction behavior information, construct an attack activity propagation graph and calculate the attack propagation coefficient between nodes; Behavior recognition module: S2: Based on the behavior data and attack propagation coefficient of each node in the attack activity propagation graph, calculate the behavior impulse factor of the node to determine the attack participating nodes; Time Trajectory Module: S3: Calculates the time propagation coefficient of the attack path and constructs the attack time trajectory based on the interaction time difference characteristics and behavioral impulse factors between nodes; Source tracing and assessment module: S4: Calculates the source tracing traffic overflow index based on the traffic rate between nodes, attack propagation coefficient, and time propagation coefficient, and generates a set of potential attack sources; Response Decision Module: S5: Calculates the attack intensity adjustment coefficient based on the source traffic overflow index and traffic rate, and triggers the defense strategy response mechanism based on the attack intensity adjustment coefficient.