Network abnormal behavior detection method and system based on multi-modal fusion
By employing a multimodal fusion-based network anomaly behavior detection method, this approach utilizes encrypted network traffic metadata and terminal behavior sequences to evaluate the information entropy consistency and traffic stability characteristics of high-strength encrypted data streams. This addresses the shortcomings in accuracy and reliability of detection systems in encrypted environments, enabling more efficient anomaly behavior identification.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SICHUAN UNIVERSITY OF SCIENCE AND ENGINEERING
- Filing Date
- 2026-04-21
- Publication Date
- 2026-05-19
AI Technical Summary
With encrypted transmission becoming the norm, existing network anomaly detection methods based on multimodal fusion lack core semantic communication content modalities, making it difficult for detection systems to reliably distinguish between normal encrypted communication and spoofing attacks, resulting in insufficient accuracy and reliability.
By acquiring encrypted network traffic metadata and terminal behavior sequences, the information entropy consistency and traffic stability characteristics of high-strength encrypted data streams are evaluated. The interlocking relationship between operational continuity characteristics and traffic stability characteristics is analyzed. Combined with the entropy coordination evaluation results, abnormal network behavior is identified.
It improves the accuracy and reliability of abnormal behavior detection in encrypted network environments, reduces the false positive rate, and enhances the overall effectiveness of network security monitoring.
Smart Images

Figure CN122069121A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network communication security technology, and more specifically, to a method and system for detecting abnormal network behavior based on multimodal fusion. Background Technology
[0002] In the field of network communication security, with the widespread adoption of encrypted transmission protocols for network traffic, the application of direct detection methods for communication content has been limited. To address this, existing technologies have shifted to relying on the fusion analysis of multi-dimensional information such as metadata of encrypted traffic, network session behavior characteristics, and associated terminal system behavior logs to identify potential abnormal behaviors and security threats. This approach aims to implement security monitoring when communication content cannot be parsed, by integrating observable signals from both the network and host layers.
[0003] However, with encrypted transmission becoming the norm, the communication content modality carrying core semantics is unavailable. The inherent correlation between the network behavior modality and the terminal behavior modality relied upon by existing multimodal fusion-based detection methods becomes indirect and fragile. This problem of insufficient coupling strength of multi-source information caused by the lack of fundamental modalities makes it difficult for the detection system to reliably distinguish between normal encrypted communication activities and carefully disguised covert attacks. It is also easy to misjudge high-strength legitimate encrypted data streams as abnormal, resulting in inherent defects in the accuracy and reliability of the detection results. Summary of the Invention
[0004] To overcome the aforementioned deficiencies of the prior art, the present invention provides a network abnormal behavior detection method and system based on multimodal fusion to solve the problems mentioned in the background art.
[0005] To achieve the above objectives, the present invention provides the following technical solution: Network anomaly detection methods based on multimodal fusion include: S1. Obtain the encrypted network traffic metadata of the entity to be detected, as well as the terminal behavior sequence of the entity to be detected; S2. Based on encrypted network traffic metadata, determine whether the network behavior of the entity to be detected belongs to a high-strength encrypted data stream; S3. When it is a high-strength encrypted data stream, evaluate the information entropy consistency of the high-strength encrypted data stream on multiple orthogonal feature dimensions to obtain the entropy coordination evaluation result. S4. Based on the terminal behavior sequence, extract the operation continuity features of the entity to be detected within the corresponding time period, and extract the traffic stability features of the high-strength encrypted data stream. S5. Analyze the interlocking relationship between operational continuity characteristics and flow stability characteristics, and combine the entropy coordination evaluation results to analyze the inherent consistency contradiction of flow stability characteristics. S6. Based on the comprehensive analysis results of the interlocking relationship and the contradiction of inherent consistency, identify whether the behavior of the entity to be detected is abnormal network behavior.
[0006] Furthermore, S1 includes: Collect encrypted network traffic metadata from traffic probes deployed at the network access locations of the entity to be inspected; Simultaneously, terminal behavior sequences are collected from the host agent installed on the entity to be tested; Based on the same time window and entity identifier, the collected encrypted network traffic metadata and terminal behavior sequence are spatiotemporally aligned and correlated.
[0007] Furthermore, S2 includes: Extract the duration, average data rate, and encryption protocol type of the data stream from the encrypted network traffic metadata; When the duration of the data stream exceeds the first preset threshold, the average data rate exceeds the second preset threshold, and the encryption protocol type belongs to the preset set of strong encryption protocols, the network behavior of the entity to be detected is determined to be a high-strength encrypted data stream.
[0008] Furthermore, S3 includes: The packet payload length distribution, packet arrival time interval distribution, and stream duration are selected as multiple orthogonal feature dimensions from high-strength encrypted data streams. Calculate the information entropy of the packet payload length distribution, the information entropy of the packet arrival time interval distribution, and the information entropy of the flow duration, respectively. Based on the statistical dispersion of multiple information entropies obtained from calculation, the consistency of information entropy of high-strength encrypted data streams across multiple orthogonal feature dimensions is evaluated, and entropy coordination evaluation results are generated.
[0009] Furthermore, S4 includes: The time intervals between adjacent operation events are identified from the terminal behavior sequence to form an operation interval sequence, and the statistical coefficient of variation of the operation interval sequence is calculated as an operation continuity feature. Meanwhile, the data rate change sequence of high-intensity encrypted data streams within the corresponding time period is extracted from the encrypted network traffic metadata, and the stationarity index of the data rate change sequence is calculated as a traffic stability feature.
[0010] Furthermore, S5 includes: The consistency of the direction of change and the synergy of the magnitude of change between the continuity characteristics of computational operations and the stability characteristics of flow within the corresponding time window are measured. The interlocking strength value is generated by weighted sum of the consistency measure of change direction and the synergy measure of change magnitude. When the interlock strength value is lower than the interlock threshold and the entropy coordination assessment result indicates low information entropy consistency, the deviation between the statistical characteristics of short-term data rate fluctuations and the statistical characteristics of long-term data rate trends is calculated based on the data rate change sequence. The degree of conflict between the distribution shape index and the stationarity index of the data rate change sequence is calculated, and the inherent consistency contradiction judgment result of the flow stability characteristics is generated based on the combination result of the deviation degree and the degree of conflict.
[0011] Furthermore, the consistency measure of change direction is obtained by calculating the Pearson correlation coefficient of the first-order difference sequence of the operational continuity feature and the flow stability feature within the corresponding time window; the synergy measure of change amplitude is obtained by calculating the cosine similarity of the normalized amplitude change sequence of the operational continuity feature and the flow stability feature within the corresponding time window.
[0012] Furthermore, an intrinsic consistency contradiction judgment result of the flow stability characteristics is generated based on the combination result of deviation degree and conflict degree, including comparing the deviation degree with a first contradiction threshold and comparing the conflict degree with a second contradiction threshold; when the deviation degree exceeds the first contradiction threshold and the conflict degree exceeds the second contradiction threshold, a judgment result indicating the existence of an intrinsic consistency contradiction is generated.
[0013] Furthermore, S6 includes: Map the interlocking relationship strength value and the result of the internal consistency contradiction judgment to a predefined multi-dimensional decision space; Based on the region where the interlocking relationship strength value is located in the multidimensional decision space, and the region where the internal consistency contradiction judgment result is located in the multidimensional decision space, the comprehensive landing point of the behavior pattern of the entity to be detected in the multidimensional decision space is determined. If the overall landing point is located within the pre-defined abnormal behavior association area in the multi-dimensional decision space, then the behavior of the entity to be detected is identified as abnormal network behavior.
[0014] On the other hand, the present invention provides a network abnormal behavior detection system based on multimodal fusion, comprising: The data acquisition module is used to acquire encrypted network traffic metadata of the entity to be detected, as well as the terminal behavior sequence of the entity to be detected. The strength judgment module is used to determine whether the network behavior of the entity to be detected belongs to a high-strength encrypted data stream based on encrypted network traffic metadata. The coordination evaluation module is used to evaluate the information entropy consistency of a high-strength encrypted data stream across multiple orthogonal feature dimensions when the data stream is high-strength encrypted, and to obtain the entropy coordination evaluation result. The feature extraction module is used to extract the operation continuity features of the entity to be detected within the corresponding time period based on the terminal behavior sequence, and to extract the traffic stability features of the high-intensity encrypted data stream. The fusion analysis module is used to analyze the interlocking relationship between operational continuity characteristics and flow stability characteristics, and, in conjunction with the entropy coordination evaluation results, analyze the inherent consistency contradictions of flow stability characteristics. The anomaly detection module is used to identify whether the behavior of the entity to be detected is abnormal network behavior based on the comprehensive analysis results of the interlocking relationship and the contradiction of inherent consistency.
[0015] Compared with the prior art, the present invention has the following beneficial effects: 1. By introducing a multi-layered deep feature association and internal contradiction analysis mechanism, the accuracy and reliability of abnormal behavior detection in encrypted network environments are effectively improved. First, a multi-dimensional information entropy consistency assessment is performed on high-strength encrypted data streams. This step can effectively identify disguised abnormal traffic because encrypted traffic generated by normal applications usually exhibits a consistent information entropy distribution across different orthogonal feature dimensions. Malicious traffic, on the other hand, often struggles to perfectly simulate this natural consistency across all dimensions, thus providing a more reliable traffic quality criterion for subsequent analysis.
[0016] 2. By extracting operation continuity features from terminal behavior sequences and traffic stability features from encrypted traffic, and then analyzing the interlocking relationship between the two, this design directly addresses the fundamental problem of the fragile correlation between behavior and traffic in an encrypted environment. By depicting the deep dynamic synergistic laws between behavior rhythm and traffic fluctuations, a coupling relationship far more robust than traditional time correlation or statistical correlation is established. At the same time, combined with the analysis of the inherent consistency contradictions of traffic stability features, it can reveal abnormal conflicts in the statistical characteristics of traffic from within, more accurately distinguishing between high-strength legitimate encryption applications and carefully disguised covert attacks, significantly reducing the false judgment rate, and thus effectively enhancing the overall effectiveness of network security monitoring devices when the content cannot be decrypted. Attached Figure Description
[0017] Figure 1 This is a flowchart of the network anomaly behavior detection method based on multimodal fusion of the present invention; Figure 2 This is a schematic diagram of the network abnormal behavior detection system based on multimodal fusion according to the present invention. Detailed Implementation
[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0019] Example 1: Figure 1 This invention presents a network anomaly behavior detection method based on multimodal fusion, comprising: S1. Obtain the encrypted network traffic metadata of the entity to be detected, as well as the terminal behavior sequence of the entity to be detected; S2. Based on encrypted network traffic metadata, determine whether the network behavior of the entity to be detected belongs to a high-strength encrypted data stream; S3. When it is a high-strength encrypted data stream, evaluate the information entropy consistency of the high-strength encrypted data stream on multiple orthogonal feature dimensions to obtain the entropy coordination evaluation result. S4. Based on the terminal behavior sequence, extract the operation continuity features of the entity to be detected within the corresponding time period, and extract the traffic stability features of the high-strength encrypted data stream. S5. Analyze the interlocking relationship between operational continuity characteristics and flow stability characteristics, and combine the entropy coordination evaluation results to analyze the inherent consistency contradiction of flow stability characteristics. S6. Based on the comprehensive analysis results of the interlocking relationship and the contradiction of inherent consistency, identify whether the behavior of the entity to be detected is abnormal network behavior.
[0020] S1. Obtain the encrypted network traffic metadata of the entity to be detected, as well as the terminal behavior sequence of the entity to be detected. Specifically, this is implemented as follows: The process of acquiring encrypted network traffic metadata of the entity under investigation is achieved through traffic probes deployed at the network access location of the entity. Specifically, the traffic probe connects to the mirror port of the core network switch or the traffic mirroring interface of the gateway device, thereby replicating all raw data packets flowing through the network node where the entity under investigation resides. The traffic probe parses the replicated raw data packets but does not decrypt the payload. The extracted metadata fields include the source Internet Protocol address, destination Internet Protocol address, source port number, destination port number, and transport layer protocol type. The metadata also includes the timestamp of each packet, packet length, Transmission Control Protocol (TCP) flags or User Datagram Protocol (UDP) characteristics, and protocol version, cipher suite, and server name indication information parsed from the plaintext portion of the Transport Layer Security (TLS) handshake phase. The timestamp accuracy is down to the millisecond level. These extracted fields are organized into traffic records and temporarily cached in the traffic probe's local storage.
[0021] Meanwhile, acquiring the terminal behavior sequence of the entity under investigation is accomplished by a host agent program installed and running on the entity's operating system. The host agent is configured to start automatically as a system service during installation and runs with the necessary permissions to monitor system activity. The terminal behavior sequence data collected by the host agent originates from event notification interfaces and application programming interface hooks provided by the operating system kernel. The types of operation events collected include file system creation, reading, modification, and deletion operations; process creation and termination events; network socket connection and binding operations; and read / write access to removable storage devices. Each collected operation event is encapsulated as a behavior record. Each behavior record contains fields such as the precise timestamp of the event, the process identifier and process name that triggered the event, the target object involved in the operation (e.g., the path of the accessed file), and the result status of the operation. The host agent formats and filters these behavior records in memory and sends them to the central analysis server through a secure intranet communication channel.
[0022] Based on the same time window and entity identifier, the collected encrypted network traffic metadata and terminal behavior sequences are spatiotemporally aligned and correlated. This step is performed on the central analysis server. A unique entity identifier is generated for the entity to be detected. The entity identifier is uniformly set during the initial configuration phase of the traffic probe and host agent, and can be the entity's hostname or media access control address. Both the encrypted network traffic metadata records from the traffic probe and the terminal behavior sequence records from the host agent carry the entity identifier during transmission. The central analysis server classifies the two types of data streams belonging to the same entity to be detected into different processing queues based on the entity identifier. The time window is divided using a fixed-interval sliding window mechanism, for example, using 1 minute as a basic time window length. The window length is determined based on statistical analysis of the duration of typical network sessions; for example, the window slides once every 30 seconds, thus forming overlapping continuous analysis periods. For a given time window, the server retrieves all encrypted network traffic metadata records and terminal behavior sequence records whose timestamps fall within the time window from the cache. The alignment process is based on precise timestamps. By establishing a mapping between the timestamps of encrypted network traffic metadata records and the timestamps of terminal behavior sequence records, network events occurring at similar times are associated with terminal operations. The result of this association is a series of fused records. Each fused record contains the temporal correspondence between one or more terminal behaviors and one or more network traffic metadata items within a time window, all belonging to the same entity identifier. These fused records form the basic data units for subsequent deep feature extraction and analysis. The entire alignment and association process is implemented using a time-series database and an association query algorithm.
[0023] S2. Based on encrypted network traffic metadata, determine whether the network behavior of the entity to be detected belongs to a high-strength encrypted data stream. The specific implementation is as follows: The duration of a data stream is extracted from the metadata of encrypted network traffic. A data stream is defined based on the five-tuple information of network communication: source Internet Protocol address, destination Internet Protocol address, source port number, destination port number, and transport layer protocol. The system aggregates a series of data packets with the same five-tuple information that are temporally consecutive into a logical data stream. The duration of a data stream is calculated by the difference between the timestamp of the first data packet and the timestamp of the last data packet in the stream. The timestamp precision is in milliseconds, and the duration unit is seconds. For example, a data stream that lasts for 60,000 milliseconds (60 seconds) has a duration of 60 seconds. In practice, data stream identification and duration calculation are implemented by maintaining a flow table. The flow table records the start time of each active data stream and calculates the final duration of the data stream when it ends or times out.
[0024] The average data rate of a data stream is extracted from the metadata of encrypted network traffic. The calculation of the average data rate depends on the total number of bytes in the data stream and its duration. The total number of bytes is obtained by summing the length fields of all packets belonging to the data stream; the packet length field is in bytes. The average data rate is calculated by dividing the total number of bytes by the duration of the data stream, with the result in bytes per second. For example, a data stream with a total data volume of 3,000,000 bytes and a duration of 60 seconds has an average data rate of 50,000 bytes per second, or 50 KB / s. This calculation is triggered at the end of the data stream to ensure that the total number of bytes used and the duration of the data stream are final values. The average data rate reflects the data throughput intensity of the communication session over time.
[0025] The encryption protocol type of a data stream is extracted from the encrypted network traffic metadata. The determination of the encryption protocol type is based on information parsed from the plaintext portion of the Transport Layer Security (TLS) handshake phase. The system examines the protocol version and cipher suite fields in the initial handshake packet of the data stream. The protocol version field identifies the broad protocol class, such as TLS version 1.2 or TLS version 1.3. The cipher suite field defines the specific combination of encryption, authentication, and key exchange algorithms. The system compares the parsed protocol version and cipher suite with a predefined set of strong encryption protocols. This predefined set of strong encryption protocols is a list pre-configured by the administrator, containing protocol versions and cipher suite combinations considered strong encryption standards. For example, the predefined set of strong encryption protocols might explicitly include cipher suites in TLS version 1.2 that use Encryption Advanced Standard (EAS) encryption with a key length of at least 256 bits, and all cipher suites in TLS version 1.3. If a data stream successfully establishes an encrypted session, and both the protocol version and cipher suite used in the data stream handshake phase are present in the predefined set of strong encryption protocols, then the data stream's encryption protocol type is determined to be strong encryption.
[0026] When the duration of a data stream exceeds a first preset threshold, the average data rate of the data stream exceeds a second preset threshold, and the encryption protocol type of the data stream belongs to a preset set of strong encryption protocols, the network behavior of the entity to be detected is determined to be a high-strength encrypted data stream. The first preset threshold is a duration value used to filter out communication sessions with longer durations. The first preset threshold is set based on distinguishing between short-term connections and long-term persistent connections. For example, the first preset threshold can be set to 30 seconds, a value determined by analyzing the duration distribution of ordinary web browsing traffic and file transfer traffic in historical network data. If the duration of a data stream is less than 30 seconds, the data stream is considered not to belong to the category of high-strength encrypted data streams that require special attention.
[0027] The second preset threshold is a data rate value used to filter communication sessions with higher data throughput. The second preset threshold is set to differentiate between low-bandwidth and high-bandwidth applications. For example, the second preset threshold can be set to 50 kilobytes per second (50KB / s). This value is determined based on observations of the average data rate of typical office applications in a network environment, as well as the known lower limit of data rate for large file transfers or media streaming applications. The system compares the calculated average data rate of the data stream with the second preset threshold; the unit of the average data rate must be uniformly converted to kilobytes per second before comparison.
[0028] The judgment process combines the above three conditions using a logical AND operation. After calculating the duration, average data rate, and encryption protocol type of a data stream, the central analysis server performs these comparisons sequentially. Only when all three conditions are met simultaneously—the data stream's duration exceeding a first preset threshold, the average data rate exceeding a second preset threshold, and the encryption protocol type being confirmed as belonging to a preset set of strong encryption protocols—will the system generate a judgment result, marking the network behavior of the entity under test as belonging to a high-strength encrypted data stream. This judgment result, as a Boolean flag or attribute label, is bound to the corresponding data stream information and the entity identifier of the entity under test, and passed to subsequent processing steps to trigger further analysis. All thresholds, including the first and second preset thresholds, are stored in the system's configuration file, allowing network administrators to calibrate and adjust them according to the bandwidth and application characteristics of the specific network environment. For example, the second preset threshold can be appropriately increased in a data center intranet. The preset set of strong encryption protocols also exists as a configurable policy file, allowing for updates to the recognized protocols and cipher suites as encryption technologies evolve.
[0029] S3. When the data stream is highly encrypted, the information entropy consistency of the highly encrypted data stream across multiple orthogonal feature dimensions is evaluated to obtain the entropy coordination evaluation result. The specific implementation is as follows: The packet payload length distribution is selected as the first orthogonal feature dimension from the high-strength encrypted data stream. Packet payload length refers to the byte length of the payload portion of each network packet. For a data stream identified as high-strength encrypted, the system extracts the payload length values of all packets in the stream. These payload length values are used to construct a probability distribution. This distribution is constructed by dividing the payload length values into a series of continuous intervals, for example, 10 bytes per interval. The proportion of packets falling into each interval relative to the total number of packets in the stream is then counted; this proportion represents the probability of that payload length interval occurring.
[0030] The arrival time interval (ATI) distribution of data packets in a highly encrypted data stream is selected as the second orthogonal feature dimension. The ATI refers to the time difference between the arrival of two consecutive data packets in the same data stream at the observation point. The system extracts the timestamps of all consecutive data packet pairs in the highly encrypted data stream and calculates the difference between adjacent timestamps to obtain the ATI value, in milliseconds. The ATI value is used to construct a probability distribution. This distribution is constructed by dividing the ATI value into intervals, for example, 1 millisecond intervals, and calculating the frequency of the ATI value occurring within each interval as the probability.
[0031] The stream duration is selected as the third orthogonal feature dimension from the high-strength encrypted data stream. The stream duration is a scalar value calculated in previous steps, measured in seconds. To calculate the information entropy of the stream duration, the system needs to convert it into a probability distribution. Specifically, the system maintains a set of historical high-strength encrypted data stream durations. Based on this set, a stream duration probability distribution is constructed. This distribution is built by dividing the historical duration values into multiple intervals and calculating the frequency of occurrence of duration values within each interval as the base probability. For the currently evaluated high-strength encrypted data stream, its stream duration value is mapped to the corresponding interval of this historical distribution, thus obtaining the probability of the current stream duration value appearing in that historical distribution.
[0032] Calculate the information entropy of the packet payload length distribution. The information entropy is calculated using the Shannon entropy definition. For a constructed packet payload length distribution, the calculation process is as follows: For each payload length interval in the distribution, take the probability value corresponding to that interval, calculate this probability value, multiply it by the logarithm of that probability value (base 2), and obtain an intermediate value. If the probability value of a certain interval is zero, then the intermediate value of that interval is defined as zero. Then, add the intermediate values calculated for all payload length intervals to obtain a sum. Finally, take the negative of this sum; the result is the information entropy of the packet payload length distribution. The information entropy of the packet payload length distribution is a dimensionless real number.
[0033] Calculate the information entropy of the data packet arrival time interval distribution. For the constructed data packet arrival time interval distribution, the calculation process is exactly the same as calculating the information entropy of the data packet payload length distribution: for each arrival time interval interval in the distribution, take the probability value corresponding to that interval, calculate the probability value multiplied by the logarithm of the probability value to the base 2, and obtain the median value; if the probability value is zero, the median value is zero; sum the median values of all intervals; take the negative of the sum to obtain the information entropy of the data packet arrival time interval distribution. The information entropy of the data packet arrival time interval distribution is a dimensionless real number.
[0034] Calculate the information entropy of the flow duration. For the probability of the current flow duration value obtained through historical distribution mapping, calculate the information entropy of the flow duration. The calculation process is as follows: Take the probability value corresponding to the current flow duration value, calculate this probability value and multiply it by the logarithm of this probability value to the base 2, obtaining an intermediate value. Then take the negative of this intermediate value; the result is the information entropy of the flow duration. The information entropy of the flow duration is a dimensionless real number.
[0035] Based on the calculated statistical dispersion of multiple information entropies, the consistency of information entropy in a high-strength encrypted data stream across multiple orthogonal feature dimensions is evaluated, generating an entropy consistency assessment result. Statistical dispersion measures the degree of dispersion among three values: the information entropy of packet payload length distribution, the information entropy of packet arrival time interval distribution, and the information entropy of stream duration. A specific method for calculating statistical dispersion is to calculate the standard deviation of these three information entropy values. The standard deviation is calculated as follows: First, the arithmetic mean of the three information entropy values is calculated. Then, the difference between each information entropy value and the arithmetic mean is calculated. Next, the square of each difference is calculated. Then, the arithmetic mean of the three squared values is calculated. Finally, the square root of this average of squared values is calculated, and the result is the standard deviation. The standard deviation is the quantified value of statistical dispersion.
[0036] The process of generating entropy consistency assessment results involves comparing the calculated statistical dispersion, i.e., the standard deviation, with a preset entropy consistency threshold. The entropy consistency threshold is a pre-defined value. It can be set based on offline analysis of a large number of known normal, highly encrypted data streams. For example, a large number of traffic samples from normal business activities such as video conferencing and encrypted file transfers are collected, and the standard deviation of the information entropy for each traffic sample is calculated, resulting in a set of standard deviation values. The statistical distribution of these standard deviation values is analyzed, and the entropy consistency threshold is set at a level that ensures the standard deviation of the vast majority of normal traffic samples is below this threshold. For example, the 95th percentile of these standard deviation values can be used as a candidate value for the entropy consistency threshold. If the standard deviation calculated for the current highly encrypted data stream is less than or equal to the entropy consistency threshold, the generated entropy consistency assessment result is high information entropy consistency. If the standard deviation calculated for the current highly encrypted data stream is greater than the entropy consistency threshold, the generated entropy consistency assessment result is low information entropy consistency. The entropy consistency assessment result is associated with the highly encrypted data stream as a classification label.
[0037] S4. Based on the terminal behavior sequence, extract the operation continuity features of the entity to be detected within the corresponding time period, and extract the traffic stability features of the high-strength encrypted data stream. The specific implementation is as follows: The time intervals between adjacent operation events are identified from a terminal behavior sequence to form an operation interval sequence. A terminal behavior sequence consists of a series of operation event records ordered by timestamps. The types of operation event records include file access, process creation, and network connection. The method for identifying adjacent operation events is to arrange the operation event records in the terminal behavior sequence sequentially according to their timestamps. For two consecutive operation event records in the sequence (i.e., the preceding and following operation event records), the difference between their timestamps is calculated. This timestamp difference is the time interval between adjacent operation events, measured in milliseconds. This calculation is performed for each pair of adjacent operation event records throughout the entire terminal behavior sequence, resulting in an operation interval sequence composed of multiple time interval values arranged sequentially. For example, if a terminal behavior sequence contains 5 operation event records with timestamps T1, T2, T3, T4, and T5, then the calculated time interval values are T2 - T1, T3 - T2, T4 - T3, and T5 - T4, which together form the operation interval sequence.
[0038] The statistical coefficient of variation (COP) of the operational interval sequence is used as a characteristic of operational continuity. The COP is the ratio of the standard deviation to the mean. The first step in calculating the COP of the operational interval sequence is to calculate the mean. The mean is calculated by summing all the time interval values in the sequence and then dividing by the total number of time interval values. The unit of the mean is milliseconds. The second step is to calculate the standard deviation. The standard deviation is calculated by calculating the difference between each time interval value and the mean; squaring each difference; summing all the squares; dividing this sum by the total number of time interval values; and taking the square root of the quotient. The unit of the standard deviation is milliseconds. The third step is to calculate the statistical coefficient of variation itself. The COP is calculated by dividing the standard deviation by the mean. The COP is a dimensionless value. The smaller the statistical coefficient of variation, the more regular and less volatile the time intervals between operational events, indicating higher operational continuity; conversely, the larger the statistical coefficient of variation, the more irregular and volatile the operational intervals, indicating lower operational continuity. This calculated statistical coefficient of variation is the characteristic of operational continuity.
[0039] Simultaneously, the data rate change sequence of high-strength encrypted data streams within the corresponding time period is extracted from the encrypted network traffic metadata. Data rate refers to the amount of data transmitted per unit time. One method for extracting the data rate change sequence is to use fixed-time window sampling. The corresponding time period refers to the time period aligned with the terminal behavior sequence. The corresponding time period is divided into several consecutive and non-overlapping fixed-length sub-windows, for example, each sub-window is 1 second long. The length of the sub-window can be adjusted according to the actual detection granularity requirements; for example, it can be set to 2 seconds or 500 milliseconds, based on the desired frequency of data rate changes. For high-strength encrypted data streams, within each sub-window, the sum of the lengths of all data packets within the sub-window's time range is accumulated to obtain the total number of bytes transmitted within the sub-window. Then, the total number of bytes is divided by the sub-window's duration to obtain the sub-window's data rate, in bytes per second. The data rate value for each sub-window is calculated and recorded in chronological order; these chronologically ordered data rate values constitute the data rate change sequence. For example, a 60-second high-strength encrypted data stream, using a 1-second sub-window, will generate 60 data rate values, which are arranged in chronological order to form a data rate change sequence.
[0040] The stationarity index of a data rate change series is calculated as a characteristic of flow stability. The stationarity index quantifies the stability of the statistical properties of a data rate change series over time. One method for calculating the stationarity index is to perform a unit root test. A specific implementation of the unit root test is the enhanced Dickey-Fuller test. The null hypothesis of the enhanced Dickey-Fuller test is that the data rate change series has a unit root, i.e., the series is non-stationary. The first step in calculating the stationarity index is to set up the test model. The test model considers the first lag term of the data rate change series and several lag terms of the difference of the data rate change series to eliminate residual autocorrelation. Whether to include a constant term and a time trend term in the model depends on whether the data rate change series exhibits a significant trend or a non-zero mean. The choice of model form can be determined by observing a line graph of the data rate change series or using information criteria such as the Akaike information criterion. The second step in calculating the stationarity index is to estimate the parameters of the test model and calculate the test statistic. The coefficients of the first lag term, the difference lag term, the constant term, and the time trend term in the model are estimated using the least squares method. Based on the estimated coefficients and model residuals, the enhanced Dickey-Fuller test statistic is calculated. The test statistic is calculated by subtracting 1 from the estimated first-order lag coefficient, divided by the standard error of that coefficient estimate. This calculation requires the use of the covariance matrix from the parameter estimates. The third step in calculating the stationarity index is to determine the significance level of the test and compare it with the critical value. The significance level is a pre-set probability value, such as 5%, used to control the risk of falsely rejecting the null hypothesis. Based on the selected significance level and the length of the data rate change sequence, the corresponding critical value is obtained from the enhanced Dickey-Fuller test critical value table. The calculated test statistic is compared with the critical value. If the test statistic is less than the critical value, the null hypothesis is rejected, and the data rate change sequence is considered stationary; if the test statistic is greater than or equal to the critical value, the null hypothesis cannot be rejected, and the data rate change sequence is considered non-stationary. The fourth step in calculating the stationarity index is to generate the stationarity index value. The stationarity index can be a binary result, for example, mapping "stationary" to the value 1 and "non-stationary" to the value 0. The stationarity index can also be a continuous value, such as the test statistic itself or the p-value of the hypothesis test. The p-value represents the probability of observing the current test statistic or a more extreme statistic if the null hypothesis is true. The smaller the p-value, the stronger the evidence to reject the null hypothesis, meaning the series is more likely to be stationary. In this embodiment, the p-value can be transformed mathematically, such as by taking the negative logarithm, to serve as the stationarity index, so that a larger index value represents higher stationarity. This calculated stationarity index is the flow stability characteristic.
[0041] The extraction of operational continuity features and traffic stability features both rely on the input data explicitly provided in previous steps. The extraction of operational continuity features depends entirely on the terminal behavior sequence. The extraction of traffic stability features depends entirely on the high-strength encrypted data stream portion of the encrypted network traffic metadata. The calculation processes for the two features are independent. All calculation steps utilize standard statistical methods. Key parameters such as sub-window length and significance level can be adjusted according to the actual network environment and detection sensitivity requirements. Adjusting the sub-window length is based on balancing the precision of feature extraction with computational overhead; adjusting the significance level is based on controlling the probability of Type I errors in statistical testing. Parameter adjustments are made within a reasonable range, for example, a sub-window length between 100 milliseconds and 5 seconds, and a significance level between 1% and 10%. Specific values are selected experimentally to achieve the optimal detection performance under specific network conditions.
[0042] S5. Analyze the interlocking relationship between operational continuity characteristics and flow stability characteristics, and combine the entropy coordination evaluation results to analyze the inherent consistency contradiction of flow stability characteristics. The specific implementation is as follows: This calculation measures the consistency of the changing directions of operational continuity features and flow stability features within a corresponding time window. The corresponding time window refers to the same time period on which the operational continuity features and flow stability features were extracted. The operational continuity features and flow stability features have already formed time series during their respective extraction processes. The consistency measure of changing directions is used to evaluate the consistency in the changing trends of the operational continuity feature series and the flow stability feature series. Calculating the consistency measure of changing directions first requires obtaining the first-order difference sequences of the operational continuity feature series and the flow stability feature series within the corresponding time window. The first-order difference sequence is calculated by subtracting the value of the preceding data point from the value of each data point, starting from the second data point, for the original feature series. Assuming the operational continuity feature sequence is C1, C2, ..., Cn, where n represents the total number of data points in the operational continuity feature sequence, i.e., the number of sub-windows used to calculate the operational continuity feature within the corresponding time window; and the flow stability feature sequence is S1, S2, ..., Sn, then the first-order difference sequence Dc of the operational continuity feature is C2-C1, C3-C2, ..., Cn-C(n-1), and the first-order difference sequence Ds of the flow stability feature is S2-S1, S3-S2, ..., Sn-S(n-1). The consistency measure of the direction of change is obtained by calculating the Pearson correlation coefficient between the first-order difference sequence Dc and the first-order difference sequence Ds. The Pearson correlation coefficient is calculated by calculating the covariance of the first-order difference sequence Dc and the first-order difference sequence Ds, and then dividing by the product of the standard deviations of the first-order difference sequence Dc and the first-order difference sequence Ds. The Pearson correlation coefficient ranges from -1 to +1. The Pearson correlation coefficient obtained from this calculation is a measure of the consistency of the direction of change.
[0043] This section calculates a metric for the compatibility of the amplitude changes of operational continuity features and flow stability features within a corresponding time window. This metric assesses the degree of matching between the operational continuity feature sequence and the flow stability feature sequence in terms of amplitude magnitude. Calculating this metric first requires obtaining the normalized amplitude change sequences of the operational continuity feature sequence and the flow stability feature sequence within the corresponding time window. The normalized amplitude change sequence is obtained by normalizing the amplitude of the original feature sequences. For the operational continuity feature sequence C1, C2, ..., Cn, the normalized amplitude change sequence Ac is calculated by first calculating the maximum value Cmax and the minimum value Cmin of the operational continuity feature sequence. Then, for each value Ci in the operational continuity feature sequence, where i is an index variable used to traverse each data point in the sequence, ranging from 1 to n, (Ci - Cmin) / (Cmax - Cmin) is calculated to obtain the normalized value. For the flow stability feature sequence S1, S2, ..., Sn, the normalized amplitude change sequence As is calculated using the same method. Normalization unifies the amplitude range of the two feature sequences to between 0 and 1. The cosine similarity measure of amplitude variation is obtained by calculating the cosine similarity between the normalized amplitude variation sequences Ac and As. The cosine similarity calculation process involves treating the normalized amplitude variation sequences Ac and As as two n-dimensional vectors, calculating their dot product, then calculating the magnitudes of the normalized amplitude variation sequences Ac and As respectively, and finally dividing the dot product by the product of the two magnitudes. The cosine similarity value ranges from -1 to +1. This calculated cosine similarity value is the cosine similarity measure of amplitude variation.
[0044] The interlock strength value is generated by a weighted sum of the consistency measure of change direction and the synergy measure of change amplitude. The weighted sum is a linear combination, in the form: Interlock Strength Value = w1 × Consistency Measure of Change Direction + w2 × Synergy Measure of Change Amplitude, where w1 and w2 are weighting coefficients. The weighting coefficients w1 and w2 are preset positive real numbers, satisfying w1 + w2 = 1. The setting of the weighting coefficients w1 and w2 reflects the relative importance of the consistency measure of change direction and the synergy measure of change amplitude in evaluating the interlock relationship. The acquisition of the weighting coefficients w1 and w2 can be optimized based on historical data analysis, aiming to maximize the distinguishability between the interlock strength values of normal behavior samples and abnormal behavior samples. The specific values of the weighting coefficients w1 and w2 are defined in the system configuration file. The calculated interlock strength value is a real number; a higher value indicates a stronger interlock relationship between the operational continuity characteristic and the flow stability characteristic.
[0045] When the interlock strength value is lower than the interlock threshold and the entropy coordination assessment result indicates low information entropy consistency, subsequent analysis is performed. The interlock threshold is a preset value used to determine whether the interlock strength is sufficient. The interlock threshold can be determined by statistically analyzing the distribution of interlock strength values corresponding to normal high-strength encrypted data streams in historical data. For example, collect a large number of interlock strength values under normal business scenarios, calculate the average and standard deviation of these interlock strength values, and set the interlock threshold to the average value minus k times the standard deviation, where k is a positive number, such as 2. Low information entropy consistency in the entropy coordination assessment result means that the output state of the entropy coordination assessment result is low information entropy consistency. When both of these conditions are met simultaneously, it indicates that further in-depth analysis of the inherent contradictions in the traffic stability characteristics is needed.
[0046] Based on the data rate change sequence, the deviation between the statistical characteristics of short-term data rate fluctuations and the statistical characteristics of long-term data rate trends is calculated. The data rate change sequence is the time series extracted in the previous steps. The statistical characteristics of short-term data rate fluctuations are used to capture the rapidly changing components in the data rate change sequence. One method to calculate the statistical characteristics of short-term data rate fluctuations is to first apply a high-pass filter to the data rate change sequence to highlight the volatile components, and then calculate the standard deviation of the fluctuation sequence. The statistical characteristics of the long-term data rate trend are used to capture the slowly changing baseline of the data rate change sequence. One method to calculate the statistical characteristics of the long-term data rate trend is to first apply a low-pass filter to the data rate change sequence to obtain a smooth trend, and then calculate the mean of the smoothed sequence. The deviation is used to quantify the degree of difference between the statistical characteristics of short-term data rate fluctuations and the statistical characteristics of long-term data rate trends. One way to calculate the deviation is to divide the standard deviation of the short-term data rate fluctuations by the mean of the long-term data rate trend to obtain the relative magnitude of the fluctuations with respect to the trend baseline. The deviation is a non-negative real number.
[0047] This section calculates the degree of conflict between the shape index and the stationarity index of a data rate change sequence. The shape index describes the probability distribution of data rate values. A commonly used shape index is skewness. Skewness is calculated as the ratio of the third central moment of the data rate change sequence to the cube of its standard deviation. The stationarity index is the flow stability characteristic calculated in the previous steps. The degree of conflict measures the logical inconsistency between the shape index and the stationarity index. One method for calculating the degree of conflict is to define a conflict function. For example, if the stationarity index is P and the shape index is Q, the degree of conflict can be calculated as |Q| × (1-P). Here, it is assumed that the stationarity index P has been normalized to between 0 and 1, where 1 represents perfect stationarity. The larger the absolute value of the shape index |Q|, the more anomalous the distribution shape. The degree of conflict is a non-negative real number.
[0048] The inherent consistency contradiction judgment result of traffic stability characteristics is generated based on the combined result of deviation and conflict degree. The combined result is formed by comparing the deviation degree with a first contradiction threshold and the conflict degree with a second contradiction threshold. The first and second contradiction thresholds are two independent preset values. The first contradiction threshold is used to determine whether the deviation degree is significant. The first contradiction threshold can be obtained based on statistical analysis of the data rate change sequence of normal high-strength encrypted data streams. For example, the deviation degree of a large number of normal sequences is calculated, and a high percentile of its distribution, such as the 95th percentile, is taken as the first contradiction threshold. The second contradiction threshold is used to determine whether the conflict degree is significant. The second contradiction threshold can be obtained based on a similar analysis of the conflict degree distribution of normal sequences. When the deviation degree exceeds the first contradiction threshold and the conflict degree exceeds the second contradiction threshold, a judgment result indicating the existence of an inherent consistency contradiction is generated. If the deviation degree does not exceed the first contradiction threshold or the conflict degree does not exceed the second contradiction threshold, a judgment result indicating the absence of an inherent consistency contradiction is generated. All thresholds, including the interlock threshold, the first contradiction threshold, and the second contradiction threshold, are stored in the system configuration.
[0049] S6. Based on the comprehensive analysis results of the interlocking relationship and the contradiction of inherent consistency, identify whether the behavior of the entity to be detected is abnormal network behavior. The specific implementation is as follows: The interlock strength value and the result of the internal consistency contradiction judgment are mapped to a predefined multidimensional decision space. The predefined multidimensional decision space is a mathematical model framework for comprehensive evaluation. In this embodiment, the multidimensional decision space is concretized as a two-dimensional coordinate system. The horizontal axis of the two-dimensional coordinate system represents the interlock strength value. The vertical axis of the two-dimensional coordinate system represents the result of the internal consistency contradiction judgment. The interlock strength value is a continuous real value calculated in the previous steps. The result of the internal consistency contradiction judgment is a binary judgment result, which can be represented by the value 1 to indicate the existence of an internal consistency contradiction and by the value 0 to indicate the absence of an internal consistency contradiction. The mapping process uses the interlock strength value as the horizontal axis value and the value of the internal consistency contradiction judgment result as the vertical axis value, thereby transforming the current state of the entity to be detected into a mapping point in the two-dimensional coordinate system.
[0050] Based on the regions where the interlock strength value and the internal consistency contradiction judgment result are located in the multidimensional decision space, the comprehensive landing point of the behavior pattern of the entity to be detected in the multidimensional decision space is determined. The region where the interlock strength value is located in the multidimensional decision space refers to the interval divided by the horizontal axis value. A preset interlock strength threshold is used to divide the horizontal axis into low interlock strength regions and high interlock strength regions. For example, points with interlock strength values below the threshold are considered to be in the low interlock strength region. Points with interlock strength values higher than or equal to the threshold are considered to be in the high interlock strength region. The interlock strength threshold is set based on the distribution of interlock strength values of normal network behavior samples in historical data. For example, a large number of interlock strength values under normal business scenarios are collected, the mean and standard deviation of these interlock strength values are calculated, and the interlock strength threshold is set to the mean minus twice the standard deviation.
[0051] The region where the internal consistency contradiction judgment result is located in the multidimensional decision space refers to the interval divided by the ordinate value. Since the internal consistency contradiction judgment result is binary, its region division is clear: points with a ordinate value of 1 are in the contradiction existence region; points with a ordinate value of 0 are in the contradiction non-existence region. The comprehensive landing point of the behavior pattern of the entity to be detected in the multidimensional decision space is the mapping point obtained by the mapping process.
[0052] If the overall endpoint falls within a pre-defined abnormal behavior association region in the multi-dimensional decision space, the behavior of the entity to be detected is identified as abnormal network behavior. The pre-defined abnormal behavior association region is a subspace within the multi-dimensional decision space. In a two-dimensional coordinate system, the pre-defined abnormal behavior association region is defined as a rectangular area. This rectangular area is defined by the lower and upper limits of the horizontal axis and the upper and lower limits of the vertical axis. For example, the abnormal behavior association region is defined as an area where the horizontal axis value is less than the interlocking relationship strength threshold and the vertical axis value is equal to 1. The definition of the abnormal behavior association region is based on the analysis of the distribution of historical behavior samples in the decision space.
[0053] The process of defining the anomalous behavior association region includes collecting training data samples. These training data samples contain known anomalous network behavior samples and known normal network behavior samples. For each training sample, the corresponding interlock strength value and inherent consistency contradiction judgment result are calculated through the preceding steps of this method, and mapped onto a two-dimensional decision space. Then, the distribution of anomalous and normal sample points in the decision space is analyzed. Based on the analysis of the sample point distribution, a boundary can be defined such that it can separate anomalous and normal sample points as effectively as possible. The region enclosed by this defined boundary is defined as the predefined anomalous behavior association region. The boundary can be a simple rectangle.
[0054] The final step in identifying whether the behavior of the entity to be detected constitutes abnormal network behavior is to determine its regional affiliation. This involves determining whether the mapping point, or the composite landing point, is located within a pre-defined abnormal behavior association region. If the composite landing point is within the abnormal behavior association region, the behavior of the entity to be detected is ultimately identified as abnormal network behavior. If the composite landing point is outside the abnormal behavior association region, the behavior of the entity to be detected is identified as normal network behavior. The identification result is output as either a final alarm signal or a Boolean label.
[0055] Example 2: Figure 2 A schematic diagram of the network anomaly detection system based on multimodal fusion of the present invention is provided. The network anomaly detection system based on multimodal fusion includes: The data acquisition module is used to acquire encrypted network traffic metadata of the entity to be detected, as well as the terminal behavior sequence of the entity to be detected. The strength judgment module is used to determine whether the network behavior of the entity to be detected belongs to a high-strength encrypted data stream based on encrypted network traffic metadata. The coordination evaluation module is used to evaluate the information entropy consistency of a high-strength encrypted data stream across multiple orthogonal feature dimensions when the data stream is high-strength encrypted, and to obtain the entropy coordination evaluation result. The feature extraction module is used to extract the operation continuity features of the entity to be detected within the corresponding time period based on the terminal behavior sequence, and to extract the traffic stability features of the high-intensity encrypted data stream. The fusion analysis module is used to analyze the interlocking relationship between operational continuity characteristics and flow stability characteristics, and, in conjunction with the entropy coordination evaluation results, analyze the inherent consistency contradictions of flow stability characteristics. The anomaly detection module is used to identify whether the behavior of the entity to be detected is abnormal network behavior based on the comprehensive analysis results of the interlocking relationship and the contradiction of inherent consistency.
[0056] All calculations involved in the embodiments are dimensionless numerical calculations, and the preset parameters and thresholds in the calculations are set by those skilled in the art according to the actual situation.
[0057] It should be noted that this invention can be deployed on the device itself to realize embedded applications, or it can run on a PC or other terminal with a user interface, thereby meeting various hardware environments and usage requirements.
[0058] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. A computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the processes or functions according to the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. Computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wireless or wired transmission; wired transmission methods include optical fiber, twisted pair, coaxial cable, etc.; wireless transmission includes infrared, microwave, etc. Computer-readable storage media can be any available medium that a computer can access or a data storage device such as a server or data center that contains one or more sets of available media. Available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media. Semiconductor media can be solid-state drives.
[0059] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and modules described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0060] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or modules may be electrical, mechanical, or other forms.
[0061] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical modules; they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0062] In addition, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module.
[0063] If a function is implemented as a software module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0064] The above are merely specific embodiments of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.
[0065] In conclusion, the above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A network anomaly behavior detection method based on multimodal fusion, characterized in that, include: S1. Obtain the encrypted network traffic metadata of the entity to be detected, as well as the terminal behavior sequence of the entity to be detected; S2. Based on encrypted network traffic metadata, determine whether the network behavior of the entity to be detected belongs to a high-strength encrypted data stream; S3. When it is a high-strength encrypted data stream, evaluate the information entropy consistency of the high-strength encrypted data stream on multiple orthogonal feature dimensions to obtain the entropy coordination evaluation result. S4. Based on the terminal behavior sequence, extract the operation continuity features of the entity to be detected within the corresponding time period, and extract the traffic stability features of the high-strength encrypted data stream. S5. Analyze the interlocking relationship between operational continuity characteristics and flow stability characteristics, and combine the entropy coordination evaluation results to analyze the inherent consistency contradiction of flow stability characteristics. S6. Based on the comprehensive analysis results of the interlocking relationship and the contradiction of inherent consistency, identify whether the behavior of the entity to be detected is abnormal network behavior.
2. The network anomaly behavior detection method based on multimodal fusion according to claim 1, characterized in that, S1 includes: Collect encrypted network traffic metadata from traffic probes deployed at the network access locations of the entity to be inspected; Simultaneously, terminal behavior sequences are collected from the host agent installed on the entity to be tested; Based on the same time window and entity identifier, the collected encrypted network traffic metadata and terminal behavior sequence are spatiotemporally aligned and correlated.
3. The network anomaly behavior detection method based on multimodal fusion according to claim 1, characterized in that, S2 include: Extract the duration, average data rate, and encryption protocol type of the data stream from the encrypted network traffic metadata; When the duration of the data stream exceeds the first preset threshold, the average data rate exceeds the second preset threshold, and the encryption protocol type belongs to the preset set of strong encryption protocols, the network behavior of the entity to be detected is determined to be a high-strength encrypted data stream.
4. The network anomaly behavior detection method based on multimodal fusion according to claim 1, characterized in that, S3 includes: The packet payload length distribution, packet arrival time interval distribution, and stream duration are selected as multiple orthogonal feature dimensions from high-strength encrypted data streams. Calculate the information entropy of the packet payload length distribution, the information entropy of the packet arrival time interval distribution, and the information entropy of the flow duration, respectively. Based on the statistical dispersion of multiple information entropies obtained from calculation, the consistency of information entropy of high-strength encrypted data streams across multiple orthogonal feature dimensions is evaluated, and entropy coordination evaluation results are generated.
5. The network anomaly behavior detection method based on multimodal fusion according to claim 1, characterized in that, S4 includes: The time intervals between adjacent operation events are identified from the terminal behavior sequence to form an operation interval sequence, and the statistical coefficient of variation of the operation interval sequence is calculated as an operation continuity feature. Meanwhile, the data rate change sequence of high-intensity encrypted data streams within the corresponding time period is extracted from the encrypted network traffic metadata, and the stationarity index of the data rate change sequence is calculated as a traffic stability feature.
6. The network abnormal behavior detection method based on multimodal fusion according to claim 1, characterized in that, S5 include: The consistency of the direction of change and the synergy of the magnitude of change between the continuity characteristics of computational operations and the stability characteristics of flow within the corresponding time window are measured. The interlocking strength value is generated by weighted sum of the consistency measure of change direction and the synergy measure of change magnitude. When the interlock strength value is lower than the interlock threshold and the entropy coordination assessment result indicates low information entropy consistency, the deviation between the statistical characteristics of short-term data rate fluctuations and the statistical characteristics of long-term data rate trends is calculated based on the data rate change sequence. The degree of conflict between the distribution shape index and the stationarity index of the data rate change sequence is calculated, and the inherent consistency contradiction judgment result of the flow stability characteristics is generated based on the combination result of the deviation degree and the degree of conflict.
7. The network anomaly behavior detection method based on multimodal fusion according to claim 6, characterized in that, The consistency measure of change direction is obtained by calculating the Pearson correlation coefficient of the first-order difference sequence of the operational continuity feature and the flow stability feature within the corresponding time window; the synergy measure of change amplitude is obtained by calculating the cosine similarity of the normalized amplitude change sequence of the operational continuity feature and the flow stability feature within the corresponding time window.
8. The network anomaly behavior detection method based on multimodal fusion according to claim 6, characterized in that, The inherent consistency contradiction judgment result of the flow stability characteristics is generated based on the combination result of deviation degree and conflict degree, including comparing the deviation degree with the first contradiction threshold and the conflict degree with the second contradiction threshold. When the deviation exceeds the first contradiction threshold and the conflict exceeds the second contradiction threshold, a judgment result indicating the existence of an inherent consistency contradiction is generated.
9. The network abnormal behavior detection method based on multimodal fusion according to claim 1, characterized in that, S6 include: Map the interlocking relationship strength value and the result of the internal consistency contradiction judgment to a predefined multi-dimensional decision space; Based on the region where the interlocking relationship strength value is located in the multidimensional decision space, and the region where the internal consistency contradiction judgment result is located in the multidimensional decision space, the comprehensive landing point of the behavior pattern of the entity to be detected in the multidimensional decision space is determined. If the overall landing point is located within the pre-defined abnormal behavior association area in the multi-dimensional decision space, then the behavior of the entity to be detected is identified as abnormal network behavior.
10. A network anomaly behavior detection system based on multimodal fusion, used to implement the network anomaly behavior detection method based on multimodal fusion as described in any one of claims 1-9, characterized in that, include: The data acquisition module is used to acquire encrypted network traffic metadata of the entity to be detected, as well as the terminal behavior sequence of the entity to be detected. The strength judgment module is used to determine whether the network behavior of the entity to be detected belongs to a high-strength encrypted data stream based on encrypted network traffic metadata. The coordination evaluation module is used to evaluate the information entropy consistency of a high-strength encrypted data stream across multiple orthogonal feature dimensions when the data stream is high-strength encrypted, and to obtain the entropy coordination evaluation result. The feature extraction module is used to extract the operation continuity features of the entity to be detected within the corresponding time period based on the terminal behavior sequence, and to extract the traffic stability features of the high-intensity encrypted data stream. The fusion analysis module is used to analyze the interlocking relationship between operational continuity characteristics and flow stability characteristics, and, in conjunction with the entropy coordination evaluation results, analyze the inherent consistency contradictions of flow stability characteristics. The anomaly detection module is used to identify whether the behavior of the entity to be detected is abnormal network behavior based on the comprehensive analysis results of the interlocking relationship and the contradiction of inherent consistency.