Network information security protection method based on edge computing
By using edge computing to build detection groups and assess threat levels, the problem of delayed identification of cross-node network attacks is solved, and precise protection against multi-target collaborative attacks controlled by the same threat actor is achieved, thus improving the efficiency of network security protection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHANDONG WEIPING INFORMATION SECURITY EVALUATION TECH CO LTD
- Filing Date
- 2026-03-16
- Publication Date
- 2026-05-19
AI Technical Summary
Existing network information security protection solutions lack the ability to analyze the correlation of cross-node network targets, making it difficult to identify related network targets controlled by the same threat and distributed across multiple edge nodes. This results in a lag in the identification of cross-node range-wide coordinated attacks and low protection efficiency.
The network information security protection method based on edge computing identifies abnormal network targets, obtains comprehensive anomaly values, assesses the threat level and danger level, and implements a hierarchical and progressive protection strategy by constructing a first detection group and a second detection group. This includes group detection, anomaly labeling, similarity matching, and threat level assessment.
It accurately identifies the correlation characteristics of cross-node range attacks, improves the efficiency and accuracy of network attack identification, prevents threat actors from evading monitoring, and achieves effective protection against multi-target coordinated attacks by the same threat actor.
Smart Images

Figure CN122069097A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security protection technology, specifically a network information security protection method based on edge computing. Background Technology
[0002] Network information security protection is a core technical means to ensure the stable operation of network systems, secure data transmission, and normal realization of business functions. By verifying the access identity of network targets, detecting transmission protocols, monitoring behavior status, and managing resource load, it can promptly identify and intercept security threats such as unauthorized access, malicious attacks, and data theft, providing reliable security for various business applications. Most existing network information security protection solutions use a single edge node as an independent monitoring unit. The anomaly judgment of network targets relies on isolated monitoring dimensions. When identifying potential threat targets, they usually only mark abnormal targets within a node individually, lacking the ability to analyze the correlation of network targets across nodes. It is difficult to accurately identify related network targets controlled by the same threat and distributed across multiple edge nodes. As a result, when facing cross-node range coordinated attacks launched by threat actors, it is impossible to capture the correlation and scale characteristics of the attack in a timely manner. Often, passive protection can only be carried out after the attack has caused substantial impact. The attack identification is lagging and the protection efficiency is low. To address these shortcomings, this invention proposes a network information security protection method based on edge computing. Summary of the Invention
[0003] The purpose of this invention is to provide a network information security protection method based on edge computing to solve the problems mentioned in the background art.
[0004] The objective of this invention can be achieved through the following technical solutions: The network information security protection method based on edge computing includes the following steps: S1, obtain the number of network targets requested for connection by each edge node in the target area during the current time period; S2, pair each edge node with each network target to construct the first detection group, and construct the second detection group based on the application anomaly value of each network target in each edge node in the first detection group; S3, obtain the comprehensive anomaly value of each network target in the second detection group, and select the anomaly benchmark in each edge node based on the comprehensive anomaly value of each network target; S4. Based on the anomaly baseline of each edge node, obtain similar network targets among other network targets, and obtain the threat level and danger level based on the similarity level and the number of similar network targets. S5 implements corresponding protection strategies for network targets with different threat levels and danger grades, as well as highly similar network targets.
[0005] Preferably, the method for constructing the first detection group and the second detection group is as follows: Based on the number of edge nodes and the total number of network targets applying for connection, the number of nodes to be detected in the first detection group is set, that is, the number of network targets that each edge node needs to detect; Based on the application time of each network target, a time series is constructed by sorting the multiple network targets for which each edge node has applied for connection. Multiple network targets that meet the node detection count are extracted according to the sorting order as the network targets that the edge nodes in the first detection group need to detect; If there are network targets in the time series that have not been extracted into the first detection group, the network targets that have not been extracted are assigned to the adjacent edge nodes that have not met the node detection count. If there are no edge nodes that have not met the node detection count, the network targets that have not been extracted are assigned to the second detection group. Starting from any edge node in the first detection group, the edge nodes are sorted according to the nearest network distance without repetition. The network target with the highest application anomaly value is selected from the network targets detected by all edge nodes in the first detection group and enters the second detection group. The edge nodes are grouped together with at least two adjacent edge nodes and combined with the network targets that have not been extracted to form a second detection group; If all unextracted network targets have been allocated or there are no unextracted network targets, then a second detection group is constructed by grouping the network targets in three adjacent edge nodes.
[0006] Preferably, the method for obtaining the application outlier is as follows: Obtain the historical request count for each network target. If there is no historical request count, obtain the data type, data format, and transmission protocol type that the network target needs to transmit. If the network target has a history of application counts, then the network target's historical connection data is further obtained. The network target's historical connection data includes historical connection time, historical connection duration, and historical data transmission size. The historical connection time of the network target is compared with the current connection time. If there is a deviation between the current connection time and the historical connection time, the connection time is marked as abnormal; otherwise, it is not marked as abnormal. Based on historical transmission data, obtain the baseline value and fluctuation range of historical transmission data, and compare the size of the data to be transmitted in this connection with the baseline value and fluctuation range of historical transmission data: If the transmitted data is not within the fluctuation range, then mark the transmitted data as abnormal; otherwise, do not mark it as abnormal. The abnormal value of the application was obtained by combining the abnormal time and abnormal data transmission.
[0007] Preferably, the method for obtaining comprehensive outliers is as follows: The actual transmission protocol of the target network is compared with the preset whitelist of edge nodes to obtain the transmission protocol compliance value; Retrieve the identity authentication records of the network target, including device identifier registration status, permission application approval results, and dynamic key verification pass rate, and obtain the identity verification value; Real-time data collection of CPU utilization, memory usage, and bandwidth consumption of the corresponding edge nodes when the network target requests a connection; calculation of the estimated increase in the load of the edge nodes due to the network target's connection request; and obtaining the load impact value. The encryption method and encryption strength of data transmission between the network target and the edge node are detected, and the encryption security value is obtained.
[0008] The comprehensive anomaly value is obtained based on the application anomaly value, transmission protocol compliance value, identity verification value, load impact value, and encryption security value.
[0009] Preferably, the method for obtaining the similarity of the other network targets is as follows: Obtain the access layer features, behavioral operation features, and target association features of the anomaly benchmark; Following the feature extraction criteria consistent with the aforementioned anomaly benchmark, for all other network targets, the access layer features, behavioral operation features, and target association features of each network target to be compared are obtained one by one. For each type of behavioral feature, a similarity score is obtained using a preset similarity calculation rule; The similarity scores are normalized and weight coefficients are set for each similarity score. The similarity between the abnormal benchmark and each network target is obtained by weighted summation. The obtained similarity is compared with a set similarity threshold to obtain the number of network targets similar to the abnormal benchmark and the degree of similarity.
[0010] Preferably, the access layer features of the anomaly benchmark include the actual access IP address, IP location, proxy server usage records, and access device fingerprint information; The behavioral characteristics include the timing pattern of connection initiation, port scanning sequence, data transmission format, and types of transmission protocols used. The target association features include the type of edge node that prioritizes connection requests, the type of data requested for access, and the flow characteristics of data transmission.
[0011] Preferably, the method for obtaining the threat level and danger grade of the network target is as follows: Obtain the number of edge nodes involved in the similar network target, and obtain the attack range ratio based on the total number of edge nodes in the target area and the number of edge nodes involved; Based on the arrangement order of the second detection group, the network distance between the edge nodes that contain the similar network targets in the arrangement order is obtained; A threat level calculation model is constructed based on historical protection data. The comprehensive similarity of each of the similar network targets and the number factor of the similar network targets are input into the threat level calculation model to obtain the initial threat level. The final threat level is obtained based on the initial threat level and the network distance between each of the network targets and the edge nodes. The threat level is divided into five consecutive intervals, and these five consecutive intervals are set as five progressively increasing danger levels, arranged sequentially from extremely low danger level to extremely high danger level, to obtain the danger level of the similar network target and the anomaly benchmark.
[0012] Preferably, the protection strategy includes: For network targets with extremely low risk levels and threat levels, normal network connection is permitted, but the behavioral characteristics of the network targets must be continuously collected and compared periodically. For network targets with low risk levels and threat levels, normal connections are allowed, but the number of dynamic key verifications is increased, and abnormal behavior is monitored in real time. For network targets with medium risk level and threat level, access permissions are restricted, deep inspection is performed on the data packets that the network targets need to transmit, and an independent isolated transmission channel is established. For network targets with high risk level and threat level and extremely high risk level and threat level, the connection request of the network target is blocked, the network target with established connection is forcibly taken offline, the data transmission link with the edge node is cut off, similar network targets in the target area are batch marked and isolated, and the source is traced.
[0013] The beneficial effects of this invention are: 1. This invention identifies multiple abnormal network targets by constructing a first detection group and a second detection group for hierarchical detection. It identifies related network targets controlled by the same threat actor through multi-feature dimension similarity matching, and assesses the threat level and danger level of abnormal network targets. Finally, it implements a hierarchical and progressive differentiated protection strategy, which effectively solves the technical problems of lagging identification of wide-range network attacks, high false negative rate of multi-target coordinated attacks by the same threat actor, and lack of targeted protection strategies in the prior art. It accurately captures the correlation characteristics of cross-node wide-range attacks launched by the same threat actor, avoids the threat actor from evading monitoring by changing IPs, disguising devices, etc., and greatly improves the identification efficiency and accuracy of wide-range network attacks.
[0014] Of course, any product implementing this invention does not necessarily need to achieve all of the advantages described above at the same time. Attached Figure Description
[0015] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0016] Figure 1 This is a block diagram of the network information security protection system based on edge computing of the present invention.
[0017] Figure 2 This is a flowchart illustrating the steps of the network information security protection method based on edge computing of the present invention.
[0018] Figure 3 This is a schematic diagram of the first and second detection groups of the network information security protection method based on edge computing of the present invention. Detailed Implementation
[0019] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0020] Please see Figure 1-2As shown, this invention is a network information security protection system based on edge computing. The system includes a data acquisition module, a data detection module, a data analysis module, and a protection decision module. First, the data acquisition module is mainly used to obtain the number of network targets requesting connection received by each edge node in the target area during different time periods. During long-distance data transmission, the downstream device needs to actively connect to edge nodes to complete the data transmission service when transmitting data to targets in other areas. Based on the daily operating characteristics of edge nodes and various network targets in the target area, the peak periods of historical network connection requests, and the computing power load threshold of edge nodes, the current time period adapted to the security monitoring requirements is set, and the start and end times of the time period are obtained. By defining time points, an effective monitoring window can be obtained. Due to the peak and valley fluctuations in connection requests in edge computing networks, fixed or dynamically adapted time periods can avoid insufficient sample size and inability to reflect the true connection status due to excessively short monitoring time, or data redundancy and occupation of the limited computing power of edge nodes due to excessively long time. Through the access request monitoring unit and network traffic acquisition module built into each edge node, the connection request signal of the access port is monitored in real time, the packet information is parsed and the core identifier of the network target is extracted, and the number of connection requests is counted for each edge node. Thus, the number of network targets requesting connections for each edge node in the target area during the current time period, as well as the connection request information of each network target, the content and format of the data to be transmitted, are obtained.
[0021] Please refer to Figure 3 As shown, the data detection module is mainly used to perform group detection on network targets requesting connections to each edge node. Specifically, the group detection is mainly divided into a first detection group and a second detection group. First, the number of edge nodes in the target area and the total number of network targets requesting connections to each edge node are counted. Based on the total number of network targets requesting connections and the total number of edge nodes, the average number of network targets that each edge node needs to deal with can be obtained, that is, the average number of network targets that a single edge node requests to connect with. This average number is the number of nodes detected by the first detection group. For example, if there are 25 edge nodes in the target area and the total number of network targets requesting connections is 100, then on average, each edge node is requested to connect by four network targets. In reality, there are some edge nodes with a large number of requests, such as having to deal with the requests of ten network targets, and there are also some edge nodes with only two network targets requesting connections. When an edge node is dealing with a large number of network targets requesting connections, there are bound to be some network targets with suspicious or malicious requests, whose actual purpose is to attack or steal certain data. Therefore, in order to reduce the workload of edge nodes and reduce such malicious attacks, a first detection group is constructed to detect each network target. If the average value is not an integer, for example, if the total number of edge nodes is thirty and the total number of network targets applying for connection is one hundred and thirty, the obtained average value is approximately 4.33. Then, the integer part of the average value is taken as the node detection count, i.e., the value is four. After obtaining the node detection count, the network targets applying for connection by each edge node are sorted according to the order of application time. The earlier the application time, the higher the sorting time, and the later the application time, the lower the sorting time, thus obtaining a time series. After obtaining the time series, the network targets in the time series are extracted according to the node detection count. For example, if an edge node applies for connection to six network targets, and the application times are 10:01:20 AM, 10:01:23 AM, 10:01:30 AM, 10:01:40 AM, 10:01:48 AM, and 10:01:52 AM, and the node detection count is four, then all network targets from 10:01:20 AM to 10:01:40 AM are extracted as the network targets that the edge node needs to detect in the first detection group. The remaining two network targets are then assigned to edge nodes that do not have enough detection capacity. For example, if a detection node only has three network targets applying, the network targets applied at 10:01:48 AM are assigned to that detection node in chronological order. If another detection node also only has three network targets applying, the remaining network targets applied at 10:01:52 AM are assigned to that other detection node. If there are no more edge nodes with available slots, the unassigned network targets are automatically added to the second detection group and await the construction of the second detection group.
[0022] After completing the construction of the first detection group, each edge node performs edge computing on its respective network targets to obtain application anomalies. Specifically, each edge node first calls the historical interaction logs of the network targets stored locally to extract the historical application counts of each network target. Edge nodes usually cache recent network target access logs locally, which contain core information such as application time, access status, and interaction data. These logs can be directly retrieved. If there are no historical application count records for the network target in the local logs, that is, the network target is a new network target that is accessing for the first time, the edge node captures the connection request packets of the network target in real time through the local port monitoring module, and extracts basic attribute information such as the data type to be transmitted, the data format to be transmitted, and the type of transmission protocol from them. This establishes an initial feature profile for the newly applied network target, avoiding gaps in anomaly screening due to the lack of historical data. If a network target has a history of connection requests, each edge node further extracts the target's historical connection data from its local logs. This historical data includes historical connection time, historical connection duration, and historical data transmission size. Subsequently, the edge node activates its local lightweight computing unit to compare the deviation between the historical connection time and the current connection time. The edge node then uses a time-series analysis algorithm to statistically analyze the concentrated periods and fluctuation ranges of the network target's historical connection times. The time-series analysis algorithm involves extracting all historical connection time data for the network target from the edge node's locally cached historical logs, sorting the timestamps chronologically, performing basic statistical calculations on the timestamps to obtain the mean or median of historical connection times, and determining the network target's regular connection periods. Then, it obtains the historical connection times and the mean. The standard deviation of the deviation value is used to obtain the normal fluctuation range of the network target's connection time. Then, the time when the network target initiates the connection this time is compared with the normal time period and fluctuation range calculated above. If it exceeds the range, it is directly marked as a connection time abnormality; otherwise, it is not marked. Subsequently, the amount of data that the network target needs to transmit in this connection request is locally compared with the baseline value and fluctuation range. If the amount of data transmitted this time exceeds the fluctuation range, it is further marked as a transmission data abnormality; otherwise, it is not marked. If the network target is marked as having both connection time abnormality and transmission data abnormality, the request abnormality value for the network target is set to 1. If there is only one abnormality, it is marked as 0.5. If there are no abnormalities, it is set to 0. The request abnormality value for each network target is obtained, and the results are stored locally and synchronized to adjacent edge nodes.
[0023] After the first detection group completes its work, starting from any edge node, the edge nodes are sorted according to the network distance between them, following the principle of non-repeating nearest distance. For example, starting from edge node A, if the nearest network distance to edge node A is edge node B, then edge node B is placed after edge node A. When filtering edge nodes for the nearest network distance to edge node B, edge node A needs to be excluded. If the nearest network distance to edge node B is edge node C, then edge node C is placed after edge nodes A and B. When filtering edge nodes for the nearest network distance to edge node C, edge nodes A and B need to be excluded. This process continues until all edge nodes are sorted. The network distance is obtained as follows: Starting from a certain edge node, lightweight heartbeat probe messages carrying a sending timestamp are periodically sent to other edge nodes. The edge node receiving the heartbeat probe message immediately returns a response message containing the receiving timestamp and the return timestamp after capturing the message. After receiving the returned response message at the starting point, the one-way data transmission delay between edge nodes is obtained based on the difference between the sending and returning timestamps. At the same time, the routing information in the probe message transmission path is parsed according to the routing protocol configured by the edge node to obtain the routing hop count between edge nodes. In addition, the bandwidth occupancy status data of the corresponding link during the probe message transmission process is collected in real time to calculate the link bandwidth utilization rate. The acquired one-way data transmission delay, routing hop count, and link bandwidth utilization are normalized and mapped to a standard range of zero to one. The shorter the transmission delay, the fewer the routing hop count, and the lower the bandwidth utilization, the smaller the normalized value of the corresponding indicator. Corresponding weight coefficients are set for one-way data transmission delay, routing hop count, and link bandwidth utilization. The weight coefficient for one-way data transmission delay is the highest, followed by routing hop count, and the weight coefficient for bandwidth utilization is the lowest. The comprehensive network distance value between edge nodes is obtained by weighted summation. The smaller this value, the tighter the network connection between nodes and the higher the communication efficiency.
[0024] After arranging the edge nodes as described above, extract the network target with the highest application anomaly value from each edge node. Then, extract the network targets with the highest application anomaly values from three adjacent edge nodes in the order of arrangement and combine them. For example, if the order of arrangement is edge node A, edge node B, edge node C, edge node D, edge node E, edge node F, ..., then combine the network targets with the highest application anomaly values from edge nodes A, B, and C in sequence and assign them to one edge node for subsequent comprehensive anomaly detection. If there are network targets that have not been assigned to the first detection point, prioritize combining the network targets that have not been assigned to the first detection point with the two network targets with the highest application anomaly values. For example, edge nodes A and B are grouped with the network targets that have not been assigned to the first detection point. This continues until the network targets that have not been assigned to the first detection point are assigned. If multiple network targets with the same application anomaly value appear in the first detection group, then multiple network targets are selected simultaneously. If the last group has less than three network targets during the combination process, then the detection is performed according to the number of network targets that have less than three network targets. In summary, the construction of the second detection group is completed. By constructing the second detection group, the network targets with the highest application anomalies in the first detection group are grouped together for comprehensive anomaly detection. Since the order of arrangement is based on the nearest network distance between edge nodes, if the difference in comprehensive anomalies of network targets in the same group in the second detection group is small, it indicates that the coverage of this type of network attack is a range attack based on adjacent edge nodes. This is more conducive to identifying range network attacks in existing technologies and better protecting the security of network data.
[0025] After the second detection group is constructed, each edge node performs edge computing on the network targets with high application anomalies to obtain the comprehensive anomaly value of each network target; Specifically, the edge node locally retrieves a preset security protocol whitelist and loads it into its local cache. It then compares the actual transmission protocol of the target network with the preset whitelist of the edge node to determine the degree of matching. Based on the marked compliance level, it generates a transmission protocol compliance value: a full match and compliance corresponds to a transmission protocol compliance value of 0, with lower values indicating better compliance; a partial match and compliance corresponds to a transmission protocol compliance value of 0.3; and a non-compliant and non-matching transmission protocol corresponds to a transmission protocol compliance value of 0.8. If it is a clearly malicious protocol, the maximum value of 1.0 is directly taken.
[0026] Subsequently, the edge node retrieves the locally cached network target identity authentication file, which is pre-synchronized to the node by the cloud management platform. It compares the device identification registration status, permission application approval results, and dynamic key verification pass rate. If there are no abnormalities in all three dimensions, it is judged as fully compliant, and the corresponding identity verification value is 0. If there is only one abnormality, it is judged as partially compliant, and the corresponding identity verification value is 0.3. If there are two or more abnormalities, it is judged as non-compliant, and the corresponding identity verification value is 0.8. If forged identity credentials are detected, the maximum value of identity verification value of 1.0 is directly taken.
[0027] Then, the edge node collects its own core load data in real time through its built-in resource monitoring module, including real-time CPU utilization, real-time memory usage, and real-time bandwidth usage. At the same time, it retrieves the locally preset load threshold parameters. If the estimated increment of each parameter does not exceed 70% of the load threshold, it is judged as low impact. If the estimated increment exceeds 70% but does not reach 90% of the load threshold, it is judged as medium impact. If the estimated increment reaches or exceeds 90% of the load threshold, it is judged as high impact. Based on the defined load impact level, a load impact value is generated: the load impact value corresponding to low impact is 0, and the lower the value, the smaller the impact on the node load. The load impact value corresponding to medium impact is 0.3, and the load impact value corresponding to high impact is 0.8. If the estimated increment directly causes the node load to exceed the threshold limit, the maximum value of 1.0 is directly taken.
[0028] Finally, the edge node retrieves the locally preset encryption security standard library and loads it into the local cache. Through the locally built-in encryption protocol parsing module, the edge node captures the encryption negotiation messages and initial transmission data frames during the data transmission link establishment process between the network target and the node in real time, and accurately extracts the core encryption feature information. All dimensions meet the standard requirements for high security, core dimensions meet the requirements but non-core dimensions have slight deviations for medium security, core dimensions have violations or weak encryption behavior for low security, and plaintext transmission or the use of disabled encryption algorithms for no security. According to the defined encryption security level, a quantified encryption security value is generated: the encryption security value corresponding to high security is 0, the lower the value, the better the encryption security, the encryption security value corresponding to medium security is 0.3, the encryption security value corresponding to low security is 0.8, and no security is directly taken as the maximum value of 1.0.
[0029] The transmission protocol compliance value, identity verification value, load impact value, encryption security value, and application anomaly value are normalized to eliminate dimensions. Weight coefficients are set for each transmission protocol compliance value, identity verification value, load impact value, and encryption security value. The maximum weights for transmission protocol compliance value and identity verification value are set to 0.3, identity verification value to 0.25, load impact value to 0.2, encryption security value to 0.15, and application anomaly value to 0.1. The comprehensive anomaly value of the network target is then calculated.
[0030] The data analysis module is used to extract various features of the abnormal benchmark after obtaining it. These features include access layer features, behavioral operation features, and target association features. Access layer features include the actual access IP address, IP location, proxy server usage records, and access device fingerprint information. Behavioral operation features include the timing pattern of connection initiation, port scan sequence, data transmission format, and type of transmission protocol used. Target association features include the type of edge node that prioritizes connection requests, the type of data requested, and the flow characteristics of data transmission. After obtaining the access layer features, behavioral operation features, and target association features of the abnormal benchmark, for all network targets of the non-abnormal benchmark, each edge node is extracted according to the same feature extraction standards, dimensions, and precision as the abnormal benchmark. The local monitoring module extracts the access layer features, behavioral operation features, and target association features of each network target to be compared one by one and constructs a comparison feature set for each non-abnormal benchmark network target. Then, the abnormal benchmark feature set and the comparison feature set are compared. Different similarity calculation rules are adopted for the different characteristics of the three types of features: access layer, behavioral operation, and target association. The specific calculation rules include: Access layer feature similarity calculation: IP address and location similarity: If the IP address of the target to be compared is completely identical to that of the anomaly baseline, the similarity score is 1; if the IP addresses are different but belong to the same subnet, the score is 0.8; if the IP locations are in the same city-level region but different subnets, the score is 0.5; if the locations are in the same province but different cities, the score is 0.3; if the locations are in different provinces or unrelated, the score is 0.1; if both use proxy servers and the proxy nodes are in the same location, an additional 0.1 similarity bonus is added.
[0031] Device fingerprint similarity: For each overlap between the abnormal baseline and the network target's operating system version, hardware unique identifier, and MAC address, 0.3 is awarded; for all three overlaps, 0.9 is awarded; for each overlap between the browser kernel and network configuration parameters, 0.05 is awarded; and for all secondary feature overlaps, 0.2 is awarded. The final device fingerprint similarity = core feature overlap score + secondary feature matching score (total score not exceeding 1; if it exceeds 1, it is taken as 1). If virtual machine or emulator running traces are found in both, an additional 0.1 bonus is awarded.
[0032] Behavioral operation feature similarity calculation: Connection time pattern similarity: Using 10-minute time slices, record the number of connections between the abnormal baseline and the network target within each slice, and calculate the overlap of the time series. The overlap is 1.0 for ≥90%, 0.8 for 80% to 90%, 0.6 for 70% to 80%, 0.4 for 60% to 70%, and 0.2 for less than 60%. If both connections are initiated during the same vulnerable period, an additional 0.1 is added.
[0033] Port scan sequence similarity: The longest common subsequence algorithm is used to calculate the length of the longest matching sequence between the port scan order of the target to be compared and the abnormal benchmark. Similarity = length of the longest matching sequence divided by the total length of the abnormal benchmark scan sequence. If the scanning strategies are the same, an additional 0.15 bonus is added. If the core ports scanned are completely overlapping, an additional 0.1 bonus is added. Protocol preference and message format similarity: 0.8 if the transmission protocol type and common port range are completely identical, 0.5 if the protocol type is the same but the common ports are different; 0.3 if the protocol types are different but both are uncommon protocols; 0.1 if the protocol types are unrelated; 0.7 if the core fields of the message format overlap is greater than or equal to 80%, 0.4 if it is between 60% and 80%, and 0.1 if it is less than 60%. An additional 0.2 is added if both use the same type of encrypted tunnel protocol.
[0034] Attack behavior operation similarity: If there are completely identical malicious operation types and the operation process is the same, take 1.0; if the malicious operation types are the same but the process is different, take 0.7; if there are only partially similar malicious operations, take 0.4; if there are no similar malicious operations, take 0.1.
[0035] Target-related feature similarity calculation: Similarity of preferred edge node types: If the edge node types of the abnormal baseline and the network target are completely consistent, the value is 0.8; if the core edge node types overlap but the secondary edge node types are different, the value is 0.5; if the edge node types are unrelated, the value is 0.1; if the connection is initiated across multiple edge nodes and the connected node topology paths are consistent, an additional 0.15 is added. Similarity of requested data resources: 0.7 if the core data resource categories are completely identical, 0.4 if some core categories overlap, and 0.1 if there are no overlapping categories; if all are directed to transmit sensitive data in a specific format, an additional 0.1 is added.
[0036] In summary, the similarity scores for all the aforementioned feature dimensions are normalized to eliminate dimensions. Based on the fact that behavioral operation features best reflect the inherent habits of threat actors, access layer features are easily disguised, and target association features exhibit common logic in coordinated attacks, weight coefficients are set for each feature dimension: The similarity weight of access layer features accounts for 0.3, of which IP address and location similarity accounts for 0.15, device fingerprint similarity accounts for 0.15, and behavioral operation feature similarity weight accounts for 0.5, of which port scan sequence similarity and attack behavior operation similarity each account for 0.2, protocol preference and message format similarity each account for 0.05, target association feature similarity weight accounts for 0.2, preferred connection edge node type similarity accounts for 0.12, and requested access data resource similarity accounts for 0.08. The similarity value is calculated by weighted summation: , Finally, a comprehensive similarity value is obtained between the network target to be compared and the abnormal benchmark. The higher the score, the higher the probability that the two belong to the same hacker or the same threat.
[0037] Based on historical threat event data from edge computing networks, preset similarity thresholds are established: similarity greater than or equal to 0.8 is considered high similarity, similarity between 0.5 and 0.79 is considered heavy similarity, and similarity less than 0.5 is considered low similarity. The comprehensive similarity values of each network target to be compared are compared with the threshold range to filter out network targets of different similarity levels: targets with a similarity greater than or equal to 0.8 are considered high similarity targets, which are determined to be highly suspected of being controlled by the same threat actor and are directly included in the list of associated threat targets; targets with a similarity between 0.5 and 0.79 are considered to be moderately suspected of being associated and need to be further verified in conjunction with their comprehensive outlier values; targets with a comprehensive similarity less than 0.5 are considered to be unrelated or weakly related and exclude the possibility of being controlled by the same threat actor. After the screening is completed, the number of network targets of different similarity levels for each anomaly benchmark is counted.
[0038] The aforementioned technical means can further identify the attack methods and network targets of the same hacker or threat actor covering a wide range of edge nodes, thereby achieving more accurate network protection.
[0039] After obtaining the number of similar network targets with different degrees of similarity to the anomaly baseline, the threat level and danger level are determined based on the number of similar network targets for each anomaly baseline. First, the total number of edge nodes involved in the similar network targets is counted through the cooperative communication links between edge nodes. At the same time, obtain the total number of edge nodes in the target area. Acquire attack range percentage : Through formula , The value was then normalized. Based on the order of the second detection group, the edge nodes corresponding to all similar network targets were extracted. The network distance between these nodes and the edge node where the abnormal baseline is located was calculated one by one. If multiple similar targets are distributed on the same edge node, the network distance between that node and the baseline node is taken as the unified distance value of the group of similar network targets. If similar targets are distributed across multiple edge nodes, the average distance between all involved nodes and the baseline node is calculated as the overall network distance adjustment parameter. ; Collect the comprehensive similarity scores of all similar targets and the abnormal benchmark, and calculate the mean similarity score. If similar network targets have high similarity, medium similarity, and low similarity, then a weighted average is used for calculation, with a weight of 0.5 for high similarity targets, 0.3 for medium similarity targets, and 0.2 for low similarity targets. Count the number of similar targets at different similarity levels, including the number of high similarity targets. Medium similarity Low similarity Construct a weighted similarity factor The formula is , Subsequently, similarity factor By performing normalization processing and obtaining similarity factor, we can avoid judging the threat solely by quantity. If we directly count the total number of similar targets, there will be unreasonable situations where three low-similarity targets and one high-similarity target have the same number but are judged to have the same threat scale. After weighted calculation, the contribution of one high-similarity target is much greater than that of three low-similarity targets, which can accurately reflect the quality of the threat scale. That is, the high-similarity target is the core carrier of the threat, more likely to be controlled by the same threat actor, and contributes more to the threat scale. The low-similarity targets are only potential related objects. Based on historical protection data cached locally on edge nodes, a lightweight threat level calculation model is constructed. The historical data cached locally on edge nodes includes the average comprehensive similarity of historical similar targets, weighted similarity factor, attack range percentage, and the correspondence between network distance and the severity of actual threat events. Severity is quantified in a 0-1 range, with 1 being the most severe. A lightweight linear regression algorithm is used to train the model, resulting in an initial threat level calculation function. Initial Threat Level Where a, b, and c are model weight coefficients, obtained by fitting historical data. It is 0.5. It is 0.3. The value is 0.2, meaning that the number of similarities has the greatest impact on the threat scale, followed by the similarity association strength, and finally the attack range. The lightweight linear regression algorithm training model is constructed by extracting valid samples from the historical protection data cached locally on the edge nodes. Each sample contains the mean of the comprehensive similarity of three independent variables. Mean, weighted similarity factor attack range percentage With one dependent variable, namely the severity of the actual threat event, outliers such as missing data and extreme values are removed. All variables are normalized, and then the core form of the linear regression model is set as follows: , The error term represents minor, unincluded interference factors. The loss function is the mean squared error, calculated as the average squared difference between the model's predicted initial threat level and the actual threat severity. The core of model training is minimizing this loss function to ensure the predicted values closely approximate the true values. A lightweight gradient descent method is used iteratively to solve this problem, gradually adjusting the model's parameters. , , The values of the parameters are selected until the loss function converges to a preset threshold. Then, iteration stops and the optimal coefficients are locked. The model is validated using reserved historical test samples. If the prediction error is less than or equal to 5%, the final value will be included. , , The coefficient model is fixed to the local edge nodes; if the error exceeds the standard, the model is returned to the preprocessing stage to optimize the samples and then retrained.
[0040] Introducing network distance parameters The initial threat level is dynamically adjusted, and an adjustment coefficient is designed. The closer the nodes are, the larger the adjustment coefficient and the higher the threat level. hour, ,when hour, ,when hour, Ultimate Threat Level Under the same initial threat level, similar targets near the node pose a greater threat than those far from the node.
[0041] Ultimate Threat Level It is divided into five consecutive numerical intervals, corresponding to five progressively increasing danger levels: extremely low, low, medium, high, and extremely high. The extremely low danger level is: The number of similar targets is extremely small, the average comprehensive similarity is low, the attack range is less than or equal to 10%, the distance between the node where the similar target is located and the baseline node is far, the threat coverage is small, the correlation strength is weak, the possibility of coordinated attack is extremely low, and there is no substantial impact on the edge computing network. Low risk level: The similar targets are mainly of low or medium similarity, with an attack range of 10% to 20%, and the distance between the node where the similar target is located and the baseline node is medium. They pose a slight potential threat, but there are no clear signs of coordinated attacks. There may only be probing attacks by a single target. Medium risk level: There are a small number of highly similar targets, with a weighted similarity factor of 0.4-0.6, an attack range of 20% to 40%, and the nodes where similar targets are located are close to or at a medium distance from the baseline node. They have a certain scale of threat, and similar targets may form small-scale coordinated attacks, which can easily affect the normal operation of some edge nodes. High risk level: The criteria for judgment are: a large number of highly similar targets, a weighted similarity factor of 0.6-0.8, an attack range of 40% to 60%, a close distance between the nodes where most similar targets are located and the baseline node, a significant threat scale, and similar targets having clear collaborative attack capabilities, which can easily cause significant security risks to multiple edge nodes in the target area. Extremely high danger level: The large number of highly similar targets, the weighted similarity factor > 0.8, the attack range ratio > 60%, and the close proximity of all similar target nodes to the baseline node constitute a large-scale high-risk threat. Similar targets can launch cross-node coordinated attacks, which may lead to the paralysis of the edge computing network in the target area and the large-scale leakage of core data, posing a fatal threat to network security.
[0042] The protection decision module is mainly used to carry out corresponding network security protection based on the threat level and danger level of multiple network targets belonging to the same type of network attack. For network targets with extremely low danger level and threat level, the network targets are allowed to connect normally, but the behavioral characteristics of the network targets need to be continuously collected and compared periodically. For network targets with low risk levels and threat levels, normal connections are allowed, but the number of dynamic key verifications is increased, and abnormal behavior is monitored in real time. For network targets with medium risk level and threat level, access permissions are restricted, deep inspection is performed on the data packets that the network targets need to transmit, and an independent isolated transmission channel is established. For network targets with high risk level and threat level and extremely high risk level and threat level, the connection request of the network target is blocked, the network target with established connection is forcibly taken offline, the data transmission link with the edge node is cut off, similar network targets in the target area are batch marked and isolated, and the source is traced.
[0043] The above description is merely an example and illustration of the concept of the present invention. Those skilled in the art can make various modifications or additions to the specific embodiments described or use similar methods to replace them, as long as they do not deviate from the concept of the invention or exceed the scope defined in the claims, they should all fall within the protection scope of the present invention.
Claims
1. A network information security protection method based on edge computing, characterized in that, Includes the following steps: S1, obtain the number of network targets requested for connection by each edge node in the target area during the current time period; S2, pair each edge node with each network target to construct the first detection group, and construct the second detection group based on the application anomaly value of each network target in each edge node in the first detection group; S3, obtain the comprehensive anomaly value of each network target in the second detection group, and select the anomaly benchmark in each edge node based on the comprehensive anomaly value of each network target; S4. Based on the anomaly baseline of each edge node, obtain similar network targets among other network targets, and obtain the threat level and danger level based on the similarity level and the number of similar network targets. S5 implements corresponding protection strategies for network targets with different threat levels and danger grades, as well as highly similar network targets.
2. The network information security protection method based on edge computing according to claim 1, characterized in that, The method for constructing the first detection group and the second detection group is as follows: Based on the number of edge nodes and the total number of network targets applying for connection, the number of nodes to be detected in the first detection group is set, that is, the number of network targets that each edge node needs to detect; Based on the application time of each network target, a time series is constructed by sorting the multiple network targets for which each edge node has applied for connection. Multiple network targets that meet the node detection count are extracted according to the sorting order as the network targets that the edge nodes in the first detection group need to detect; If there are network targets in the time series that have not been extracted into the first detection group, the network targets that have not been extracted are assigned to the adjacent edge nodes that have not met the node detection count. If there are no edge nodes that have not met the node detection count, the network targets that have not been extracted are assigned to the second detection group. Starting from any edge node in the first detection group, the edge nodes are sorted according to the nearest network distance without repetition. The network target with the highest application anomaly value is selected from the network targets detected by all edge nodes in the first detection group and enters the second detection group. The edge nodes are grouped together with at least two adjacent edge nodes and combined with the network targets that have not been extracted to form a second detection group; If all unextracted network targets have been allocated or there are no unextracted network targets, then a second detection group is constructed by grouping the network targets in three adjacent edge nodes.
3. The network information security protection method based on edge computing according to claim 2, characterized in that, The method for obtaining the application anomaly value is as follows: Obtain the historical request count for each network target. If there is no historical request count, obtain the data type, data format, and transmission protocol type that the network target needs to transmit. If the network target has a history of application counts, then the network target's historical connection data is further obtained. The network target's historical connection data includes historical connection time, historical connection duration, and historical data transmission size. The historical connection time of the network target is compared with the current connection time. If there is a deviation between the current connection time and the historical connection time, the connection time is marked as abnormal; otherwise, it is not marked as abnormal. Based on historical transmission data, obtain the baseline value and fluctuation range of historical transmission data, and compare the size of the data to be transmitted in this connection with the baseline value and fluctuation range of historical transmission data: If the transmitted data is not within the fluctuation range, then mark the transmitted data as abnormal; otherwise, do not mark it as abnormal. The abnormal value of the application was obtained by combining the abnormal time and abnormal data transmission.
4. The network information security protection method based on edge computing according to claim 3, characterized in that, The method for obtaining comprehensive outliers is as follows: The actual transmission protocol of the target network is compared with the preset whitelist of edge nodes to obtain the transmission protocol compliance value; Retrieve the identity authentication records of the network target, including device identifier registration status, permission application approval results, and dynamic key verification pass rate, and obtain the identity verification value; Real-time data collection of CPU utilization, memory usage, and bandwidth consumption of the corresponding edge nodes when the network target requests a connection; calculation of the estimated increase in the load of the edge nodes due to the network target's connection request; and obtaining the load impact value. The encryption method and encryption strength of data transmission between the network target and the edge node are detected, and the encryption security value is obtained. The comprehensive anomaly value is obtained based on the application anomaly value, transmission protocol compliance value, identity verification value, load impact value, and encryption security value.
5. The network information security protection method based on edge computing according to claim 1, characterized in that, The similarity acquisition method for the other network targets is as follows: Obtain the access layer features, behavioral operation features, and target association features of the anomaly benchmark; Following the feature extraction criteria consistent with the aforementioned anomaly benchmark, for all other network targets, the access layer features, behavioral operation features, and target association features of each network target to be compared are obtained one by one. For each type of behavioral feature, a similarity score is obtained using a preset similarity calculation rule; The similarity scores are normalized and weight coefficients are set for each similarity score. The similarity between the abnormal benchmark and each network target is obtained by weighted summation. The obtained similarity is compared with a set similarity threshold to obtain the number of network targets similar to the abnormal benchmark and the degree of similarity.
6. The network information security protection method based on edge computing according to claim 5, characterized in that, The access layer characteristics of the anomaly baseline include the actual access IP address, IP location, proxy server usage records, and access device fingerprint information; The behavioral characteristics include the timing pattern of connection initiation, port scanning sequence, data transmission format, and types of transmission protocols used. The target association features include the type of edge node that prioritizes connection requests, the type of data requested for access, and the flow characteristics of data transmission.
7. The network information security protection method based on edge computing according to claim 1, characterized in that, The method for obtaining the threat level and danger grade of the network target is as follows: Obtain the number of edge nodes involved in the similar network target, and obtain the attack range ratio based on the total number of edge nodes in the target area and the number of edge nodes involved; Based on the arrangement order of the second detection group, the network distance between the edge nodes that contain the similar network targets in the arrangement order is obtained; A threat level calculation model is constructed based on historical protection data. The comprehensive similarity of each of the similar network targets and the number factor of the similar network targets are input into the threat level calculation model to obtain the initial threat level. The final threat level is obtained based on the initial threat level and the network distance between each of the network targets and the edge nodes. The threat level is divided into five consecutive intervals, and these five consecutive intervals are set as five progressively increasing danger levels, arranged sequentially from extremely low danger level to extremely high danger level, to obtain the danger level of the similar network target and the anomaly benchmark.
8. The network information security protection method based on edge computing according to claim 1, characterized in that, The protection strategy includes: For network targets with extremely low risk levels and threat levels, normal network connection is permitted, but the behavioral characteristics of the network targets must be continuously collected and compared periodically. For network targets with low risk levels and threat levels, normal connections are allowed, but the number of dynamic key verifications is increased, and abnormal behavior is monitored in real time. For network targets with medium risk level and threat level, access permissions are restricted, deep inspection is performed on the data packets that the network targets need to transmit, and an independent isolated transmission channel is established. For network targets with high risk level and threat level and extremely high risk level and threat level, the connection request of the network target is blocked, the network target with established connection is forcibly taken offline, the data transmission link with the edge node is cut off, similar network targets in the target area are batch marked and isolated, and the source is traced.