Portable network security risk intelligent detection system
The portable intelligent network security risk detection system solves the problems of complex equipment deployment and limited identification capabilities in existing technologies, enabling high-precision detection and rapid defense strategy generation in complex network environments, and improving on-site emergency response capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUODIAN DADU RIVER POWER ENG
- Filing Date
- 2026-05-07
- Publication Date
- 2026-06-02
AI Technical Summary
Existing network security detection systems are bulky and complex to deploy in on-site inspections, temporary testing, and emergency response, making them difficult to deploy quickly and use flexibly. They also have limited ability to identify unknown attacks and complex multi-stage attacks, lack automatic discovery and real-time risk assessment of network assets, and cannot effectively generate defense strategies on portable devices. In particular, they have poor adaptability in industrial control networks and information technology innovation environments.
A portable intelligent network security risk detection system is adopted. It acquires raw data through the traffic collection and parsing module, identifies network protocols and communication behaviors through the protocol auditing and behavior analysis module, identifies assets and assesses risks through the asset discovery and risk assessment module, identifies potential malicious traffic through the threat detection module, generates defense policies through the policy generation module, and displays the results using the visualization and interaction module.
It improves the detection accuracy and response efficiency in complex network environments without affecting business operations, enables the rapid generation of cost-effective defense strategies, and enhances the emergency decision-making efficiency and equipment stability of portable devices on site.
Smart Images

Figure CN122137688A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing technology, specifically to a portable intelligent network security risk detection system. Background Technology
[0002] Current network security operations and risk detection typically rely on fixed-deployment security equipment or centralized security management platforms. These platforms collect and analyze network traffic, host logs, and security events to identify and address network attacks, abnormal behaviors, and security vulnerabilities. Common techniques include feature-based rule-based intrusion detection, firewall access control, vulnerability scanning, and security auditing. Simultaneously, some existing systems have begun to incorporate machine learning or big data analytics to classify network traffic or identify known attack patterns. In specific scenarios such as industrial control networks, security detection tools have emerged that parse and audit industrial control protocols to monitor abnormal operations and unauthorized access to control commands. These technologies, to a certain extent, improve network security protection levels and can meet the basic security detection and risk management needs of daily network operation environments.
[0003] However, existing cybersecurity risk detection technologies still have many shortcomings in practical applications. First, existing security detection systems mostly adopt centralized deployment or fixed installation methods, resulting in large equipment size and complex deployment, making them difficult to adapt to application scenarios requiring rapid deployment and flexible use, such as on-site inspections, temporary testing, and emergency response. Second, existing detection methods still mainly rely on rule matching and static feature analysis, with limited ability to identify unknown attacks, attack variants, and complex multi-stage attacks, making it difficult to achieve high accuracy and low false alarm rates in complex network environments. In addition, existing technologies typically rely on manual configuration or offline statistics for asset identification and risk assessment, lacking the ability to automatically discover, dynamically monitor, and conduct real-time risk assessment of network assets, leading to insufficient matching between security policies and actual network conditions. Furthermore, when acquiring asset information, existing systems often use brute-force active scanning with fixed frequencies and standard features, which easily generates a large amount of network noise and is intercepted by existing IDS / IPS and other security devices; while in terms of passive monitoring, they lack the ability to deeply mine hidden assets and abnormal communication channels in complex traffic, severely limiting the depth and breadth of asset information collection. Furthermore, most existing systems only provide risk alerts or problem lists, making it difficult to generate actionable defense strategy recommendations based on specific assets, vulnerabilities, and threat scenarios. Security personnel still need to rely on experience for manual analysis and decision-making, resulting in low response efficiency. In addition, existing systems that include automated strategy generation are mostly based on globally optimal planning algorithms under ideal conditions, which have extremely high computational complexity. When these algorithms are directly ported to portable testing devices, the limited computing resources and battery life of portable devices can easily lead to decision-making timeouts, device lag, or even system crashes due to computational bottlenecks when faced with massive alerts and sudden threats, making it impossible to output effective defense strategies within the critical emergency response window. Especially in industrial control networks and domestic IT innovation environments, existing general-purpose security testing products lack deep parsing capabilities for industrial control protocols and have poor adaptability to domestic software and hardware environments, further limiting their application effectiveness in complex field environments. Summary of the Invention
[0004] In view of this, this application provides a portable intelligent network security risk detection system. Its main purpose is to address the shortcomings of current security detection systems, which mostly employ centralized or fixed deployment methods. These systems are large, complex to deploy, and difficult to adapt to application scenarios requiring rapid deployment and flexible use, such as on-site inspections, temporary testing, and emergency response. Secondly, existing detection methods still rely primarily on rule matching and static feature analysis, offering limited capabilities in identifying unknown attacks, attack variants, and complex multi-stage attacks, making it difficult to achieve high accuracy and low false alarm rates in complex network environments. Furthermore, existing technologies typically rely on manual configuration or offline statistics for asset identification and risk assessment, lacking the ability for automatic discovery, dynamic monitoring, and real-time risk assessment of network assets, resulting in insufficient alignment between security policies and actual network conditions. Moreover, existing systems often employ brute-force active scanning with fixed frequencies and standard features when acquiring asset information, easily generating significant network noise that is intercepted by existing IDS / IPS and other security devices. In terms of passive monitoring, they lack the ability to deeply mine hidden assets and abnormal communication channels within complex traffic, severely limiting the depth and breadth of asset information collection. Furthermore, most existing systems only provide risk alerts or problem lists, making it difficult to generate actionable defense strategy recommendations based on specific assets, vulnerabilities, and threat scenarios. Security personnel still need to rely on experience for manual analysis and decision-making, resulting in low response efficiency. In addition, existing systems that include automated strategy generation are mostly based on globally optimal planning algorithms under ideal conditions, which have extremely high computational complexity. When these algorithms are directly ported to portable testing devices, the limited computing resources and battery life of portable devices can easily lead to decision-making timeouts, device lag, or even system crashes due to computational bottlenecks when faced with massive alerts and sudden threats, making it impossible to output effective defense strategies within the critical emergency response window. Especially in industrial control networks and domestic IT innovation environments, existing general-purpose security testing products lack deep parsing capabilities for industrial control protocols and have poor adaptability to domestic software and hardware environments, further limiting their application effectiveness in complex field environments.
[0005] In the first aspect, this application provides a portable intelligent network security risk detection system, including: a traffic collection and parsing module, a protocol auditing and behavior analysis module, an asset discovery and risk assessment module, a threat detection module, a policy generation module, and a visualization and interaction module; The traffic acquisition and parsing module is used to acquire the raw data packet stream of the target network through the bypass mirror interface to generate a raw traffic dataset. Based on the raw traffic dataset, deep packet inspection and protocol feature matching are performed to extract session identification information, protocol field information, and behavioral feature information. Based on the session identification information, the protocol field information, and the behavioral feature information, a structured traffic record is constructed to obtain structured traffic data. The protocol auditing and behavior analysis module is used to identify network protocol types and communication behaviors based on the structured traffic data, perform auditing analysis on key protocol fields and operational behaviors, and obtain protocol behavior event data and abnormal behavior marker data. The asset discovery and risk assessment module is used to extract communication endpoint identification information and device behavior characteristics from the structured traffic data, identify asset nodes in the target network and generate initial asset data, analyze the communication relationship and behavior pattern between assets based on the initial asset data and the protocol behavior event data, construct asset association relationships, assess the exposure degree and frequency of abnormal behavior of each asset based on the asset association relationships, calculate the corresponding asset risk score, and generate asset risk assessment data. The threat detection module is used to input the structured traffic data, the abnormal behavior marker data, and the asset risk assessment data into the threat identification model for classification and analysis, so as to identify potential malicious traffic and attack behavior and generate threat identification result data. The strategy generation module is used to perform security correlation reasoning based on the threat identification result data and the asset risk assessment data, determine the set of defense strategies corresponding to the threats and assets, and output strategy suggestion data. The visualization and interaction module is used to correlate and display the structured traffic data, the asset risk assessment data, the threat identification result data, and the strategy suggestion data to obtain a visualized output of risk positioning, threat tracking, and strategy prompts.
[0006] By employing the above technical solutions, this application provides a portable intelligent network security risk detection system. Compared with existing technologies, this application utilizes a traffic acquisition and parsing module to collect raw traffic datasets from the target network via bypass access, performs protocol identification and deep parsing on the raw traffic datasets, and extracts session identifier information, protocol field information, and behavioral feature information to generate structured traffic data. A protocol auditing and behavior analysis module is used to identify network protocol types and communication behaviors based on the structured traffic data, and to audit and analyze key protocol fields and operational behaviors to obtain protocol behavior event data and abnormal behavior marker data. An asset discovery and risk assessment module is used to extract communication endpoint identifier information and device behavior features from the structured traffic data, identify asset nodes in the target network and generate initial asset data, and then combine the initial asset data with protocol behavior events... The system comprises four modules: a data processing module and a threat detection module. The former analyzes the communication relationships and behavioral patterns between assets, constructs asset associations, assesses the exposure level and frequency of abnormal behavior of each asset based on these associations, calculates the corresponding asset risk score, and generates asset risk assessment data. The latter uses structured traffic data, abnormal behavior marker data, and asset risk assessment data as input into a threat identification model for classification and analysis to identify potential malicious traffic and attack behaviors, generating threat identification results data. The latter uses a strategy generation module to perform security correlation reasoning based on threat identification results data and asset risk assessment data, determine the set of defense strategies corresponding to threats and assets, and output strategy suggestion data. The former uses visualization and interaction modules to correlate and display structured traffic data, asset risk assessment data, threat identification results data, and strategy suggestion data, providing visualized outputs of risk location, threat tracking, and strategy prompts.
[0007] By adopting the above technical solution, this application collects full network traffic and performs deep protocol parsing through a bypass method. This system can acquire fine-grained communication information without affecting business operations, achieving comprehensive perception and real-time analysis of network behavior, thereby improving the ability to detect abnormal traffic and hidden threats. This application uses protocol auditing and behavior analysis mechanisms to parse and correlate key fields and operational behaviors of general network protocols and industrial control protocols, effectively identifying illegal operations and abnormal communication behaviors, and improving detection accuracy in complex network scenarios, especially industrial control environments. This application automatically identifies network assets and constructs correlation models by fusing traffic characteristics and protocol behavior data. This system can comprehensively assess asset exposure levels and abnormal behaviors, achieving dynamic quantification of asset risks and helping to promptly identify high-risk nodes. This application innovatively integrates dynamic adaptive covert active detection with deep passive analysis technology based on DPI and machine learning. Active detection can dynamically adjust strategies and masquerading data packets based on the target network response characteristics, significantly reducing the risk of false alarms and interception. Passive detection can extract high-dimensional features from massive network flows and accurately identify hidden assets, achieving high-precision, in-depth panoramic mapping of network assets without affecting business operations. This application innovatively introduces an intelligent planning mechanism based on secure ontology graph network reasoning and bounded rationality (BR) to address the physical characteristics of portable devices with limited computing resources and response time. This mechanism abandons the traditional energy-intensive global optimal solution path and can quickly calculate the most cost-effective and satisfactory solution defense strategy combination within a set time window and computing power boundary, greatly improving the emergency decision-making efficiency and equipment stability of portable devices in complex field environments.
[0008] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description
[0009] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0010] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0011] Figure 1This is a schematic diagram of the structure of a portable intelligent network security risk detection system according to some embodiments of this specification; Figure 2 This is a schematic diagram of the business hierarchy of a portable intelligent network security risk detection system according to some embodiments of this specification; Figure 3 This is a schematic diagram of a network full traffic analysis flowchart according to some embodiments of this specification; Figure 4 This is a schematic diagram illustrating the process of deep parsing data packets according to some embodiments of this specification; Figure 5 This is a schematic diagram illustrating data processing according to some embodiments of the network asset detection model shown in this specification; Figure 6 This is an overall framework diagram of the threat identification and detection module shown in some embodiments of this specification; Figure 7 This is a flowchart illustrating network traffic classification according to some embodiments of this specification; Figure 8 This is a schematic diagram of the process for classifying the traffic flow to be detected according to some embodiments of this specification; Figure 9 This is a flowchart illustrating network traffic classification according to other embodiments of this specification; Figure 10 This is a schematic diagram of the process for predicting pcap packets to be detected according to some embodiments of this specification; Figure 11 This is a schematic diagram illustrating the composition and relationships of AG-SO according to some embodiments of this specification; Figure 12 This is a schematic diagram of a security knowledge graph instantiated from Neo4j, as shown in some embodiments of this specification. Detailed Implementation
[0012] The following description, in conjunction with the accompanying drawings, illustrates exemplary embodiments of this application, including various details to aid understanding. These should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this application. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description. It should be noted that, unless otherwise specified, the embodiments and features described herein can be combined with each other.
[0013] like Figure 1As shown, a portable intelligent network security risk detection system of this application includes a traffic acquisition and parsing module 101, a protocol auditing and behavior analysis module 102, an asset discovery and risk assessment module 103, a threat detection module 104, a policy generation module 105, and a visualization and interaction module 106.
[0014] First, according to Figure 2 The business hierarchy structure of this system will be described, such as... Figure 2 As shown, the portable intelligent network security risk detection system adopts a layered architecture design, which includes, from bottom to top, a hardware acquisition layer, a traffic acquisition and protocol parsing layer, a threat detection and behavior analysis layer, a data processing and retrieval layer, and a business application display layer. The layers collaborate with each other through structured data interfaces to realize the detection, analysis, and decision support of network security risks.
[0015] Specifically, the system's underlying layer is the network interface card (NIC) hardware layer, used to support high-speed data acquisition. In this embodiment, a network interface device supporting multiple queues and hardware offloading capabilities can be used to meet the on-site network full-traffic acquisition requirements. This layer accesses the target network via bypass mirroring, ensuring real-time acquisition of communication data without affecting the original communication link, providing the raw data foundation for upper-layer parsing.
[0016] The traffic acquisition and protocol parsing layer includes a data acquisition module based on DPDK / XDP and a deep protocol parsing module based on DPI. The DPDK / XDP acquisition mechanism bypasses the traditional kernel network stack to achieve high-speed, low-latency packet capture. The DPI protocol parsing module performs L2 to L7 layer parsing on the acquired raw packets, identifying common network protocols and industrial control protocols. During parsing, session identifiers, protocol fields, and behavioral characteristics are extracted and converted into unified structured records. The parsed structured traffic data is transmitted to the upper layer for threat detection and behavioral analysis.
[0017] The threat detection and behavior analysis layer may include a threat detection module 104 and an I2-I7 layer protocol parsing and behavior recognition module. The system performs multi-dimensional feature analysis on structured traffic data, combining rule matching and intelligent models to identify abnormal communication patterns, such as unauthorized access, abnormal control commands, or potential attack behaviors. The behavior analysis results generate threat event data and anomaly marker information, which are then correlated with asset information to provide a basis for risk assessment.
[0018] The data processing and retrieval layer can include structured data storage, anomaly behavior analysis, and DFI / DPI retrieval modules. The system can uniformly store and index traffic records, behavior logs, and threat data. Through deep traffic indexing (DFI) and protocol content retrieval, it enables rapid querying and correlation analysis of historical events. The anomaly behavior analysis module can continuously mine stored data based on statistical models or machine learning algorithms to discover potential risk trends.
[0019] In some embodiments, the business application presentation layer may include five components: traffic statistics and analysis, threat event analysis, online asset analysis, protocol audit display, and defense strategy recommendations. This layer presents the network operation status, asset risk distribution, and threat correlations through a graphical interface, and provides interactive analysis capabilities, enabling users to quickly locate risk sources and obtain defense recommendations, thus achieving a closed loop of security detection and decision-making.
[0020] The following section details the functions performed by each module in this portable intelligent network security risk detection system.
[0021] The traffic acquisition and parsing module 101 is used to acquire the raw communication traffic of the target network through a bypass access method, perform protocol identification and deep parsing on the raw communication traffic, extract network session information, protocol field information and behavioral feature information, and generate structured traffic data.
[0022] In some embodiments, the traffic acquisition and parsing module 101 can connect to the target network via a bypass access method, such as acquiring raw communication data packets through a mirror port or traffic replication device, thereby acquiring the full network traffic without affecting business communication. The acquired raw communication traffic first undergoes protocol identification processing, using deep packet inspection technology to parse the data packets at the link layer, network layer, and application layer, identifying various protocol types including general network protocols and industrial control protocols. Subsequently, network session identification information, key protocol fields, and communication behavior characteristics are extracted, and the parsing results are converted into data records in a unified format, thereby generating structured traffic data to provide basic data support for subsequent auditing and analysis.
[0023] In some embodiments, the traffic acquisition and parsing module 101 can also be used for: The raw data packet stream of the target network is collected based on the bypass mirror interface to generate the raw traffic dataset; Perform deep packet inspection and protocol feature matching based on the original traffic dataset to extract session identification information and protocol field information; Structured traffic records are constructed based on session identifier information and protocol field information to obtain structured traffic data.
[0024] In some embodiments, the system can access the target network via a bypass mirroring interface to achieve non-intrusive collection of network communication data. Specifically, data packets in the target link can be copied to the collection interface of the detection device in real time via a switch mirroring port or a traffic replication device. After receiving the mirrored data, the collection module buffers and reorders the data packets to form a continuous raw data packet stream, and aggregates them according to a preset time window or data volume threshold to generate a raw traffic dataset. This collection process does not participate in the data forwarding of the original communication link, thereby avoiding impact on existing network services.
[0025] Based on the raw traffic dataset, the system can perform deep packet inspection (DPI) processing. This process includes parsing the link layer, network layer, and transport layer information of the data packets, and identifying the application layer protocol type by combining protocol feature matching rules. Protocol feature matching can be performed based on protocol identifier fields, port features, or message structure patterns, thereby extracting the source address, destination address, port information, session identifier, and key protocol fields corresponding to each communication session. Through the above parsing process, the raw data packets are transformed into a set of communication features with clear semantic identifiers.
[0026] After obtaining session identification information and protocol field information, the system can organize the parsing results according to a predefined data model, associating and integrating data records within the same session to form structured traffic records. These structured records may include basic session attributes, communication direction, protocol field content, and time-series information. Through unified format encapsulation, structured traffic data is generated for subsequent processing such as protocol auditing, behavior analysis, and threat detection.
[0027] In some embodiments, the traffic acquisition and parsing module 101 can also be used for: The original communication traffic is subjected to industrial control protocol identification based on the multi-protocol parsing rules to obtain the corresponding identification results; Based on the identification results, extract the key control command fields; Based on the key control instruction fields, generate industrial control behavior parsing data.
[0028] In some embodiments, the system can perform industrial control protocol identification processing based on the collected raw communication traffic. Specifically, the parsing module pre-establishes a multi-protocol parsing rule base, which includes message characteristics, field structures, and identification flags of various industrial control protocols. The system scans the raw communication data packets packet by packet, comparing the data packets with the protocol characteristics in the parsing rule base by matching protocol identifier fields, port characteristics, or message structure patterns, thereby identifying the industrial control protocol types that meet the conditions and generating the corresponding protocol identification result. This identification result can indicate the protocol category to which the data packet belongs and its parsing template.
[0029] After obtaining the protocol identification results, the system can perform field-level parsing of the data packet payload according to the corresponding parsing template to extract key instruction information related to control behavior. For example, fields such as opcodes, register addresses, data area contents, or control command parameters can be parsed. The field extraction process is based on the protocol specification for offset positioning and data decoding to ensure that the extracted results are consistent with the original communication semantics, thereby forming a set of instruction fields that can characterize control behavior.
[0030] Subsequently, the system can construct industrial control behavior analysis data based on key control instruction fields. Specifically, instruction fields from the same session or the same controlled object are associated and organized, recording information such as instruction type, execution time, communication direction, and target object to form a structured behavior record. This behavior record is used to describe the operational characteristics during industrial control communication, providing basic data for subsequent anomaly detection or behavior auditing.
[0031] like Figure 3 As shown, the traffic acquisition and parsing module 101 can adopt a hierarchical analysis structure to perform multi-stage parsing and behavior extraction processing on the acquired raw network traffic, thereby forming structured data that can be used for subsequent threat detection and asset analysis. The system first receives mirrored data packets from the target network through the traffic acquisition unit. The acquisition unit performs buffer management and sequential organization on the received data to maintain communication timing consistency, and inputs the organized data packets into the basic analysis module. The output of this stage is a continuous stream of data packets, providing raw input for subsequent parsing.
[0032] In some embodiments, the basic analysis module is used to perform protocol identification and communication attribute parsing of data packets, and may include the following sub-processing units: Session creation processing: The system classifies data packets into sessions based on source address, destination address, port information and protocol identifier, and establishes communication session records, thereby organizing discrete data packets into logical communication streams.
[0033] Protocol identification processing: The parsing unit determines the network protocol type of the data packet by matching protocol feature fields or port rules, and associates it with the corresponding parsing template.
[0034] Internal and external network identification and processing: The system determines the attributes of communication endpoints based on address ranges or policy rules to distinguish the direction of internal and external network communication.
[0035] Active IP identification and processing: By statistically analyzing communication behavior, the active nodes currently participating in communication are identified, providing basic data for asset analysis.
[0036] Country identification processing: The system matches IP addresses with geographic information databases to identify the regional attributes of the communication source.
[0037] Application identification processing: Identify service types through application layer protocol feature analysis to describe the purpose of communication.
[0038] Asset identification and processing: Combining device behavior characteristics and communication patterns, the entities involved in the communication are classified as assets.
[0039] Network segment identification and processing: The system identifies the network segment to which the network belongs based on address division rules to assist in network topology analysis.
[0040] The above processing generates stream and data packet records with multidimensional attribute identifiers and transmits them to the advanced analysis module.
[0041] The protocol auditing and behavior analysis module 102 is used to identify network protocol types and communication behaviors based on structured traffic data, perform audit analysis on key protocol fields and operational behaviors, and obtain protocol behavior event data and abnormal behavior marker data.
[0042] In some embodiments, the advanced analysis module performs behavior extraction and security analysis on the basic parsing results, mainly including: Metadata processing: Used to convert communication attributes into unified structured metadata for subsequent storage and retrieval.
[0043] Feature extraction processing: used to extract statistical and pattern features from conversation behavior to form analysis vectors.
[0044] Behavioral analysis and processing: Identify operational behavior patterns based on communication sequences to provide a basis for anomaly detection.
[0045] File parsing and processing: extracting or marking features from identifiable file transfer content.
[0046] Alarm generation and processing: An alarm record is generated when abnormal behavior is detected.
[0047] Blocking: Mark communication behaviors that need to be restricted according to policy rules.
[0048] The advanced analytics module outputs structured behavioral data packets, including behavioral identification data and related information such as domain names, to support threat detection and policy decisions.
[0049] In some embodiments, the processed data is output in a standardized structure, such as communication behavior records, Protocol attribute information and domain name association data can be used as input for the subsequent threat detection module 104 and asset analysis module to achieve overall system linkage.
[0050] In some embodiments, the protocol auditing and behavior analysis module 102 can perform protocol type identification and behavior analysis based on structured traffic data. This module parses key fields, such as opcodes, address parameters, or control commands, through a protocol feature matching mechanism, and generates protocol behavior logs by combining communication timing and access patterns. Based on this, the parsed behavior is compared with preset rules or behavior models to identify abnormal access, unauthorized operations, or potential attack behaviors, outputting corresponding protocol behavior event data and abnormal behavior marker data, providing a basis for risk assessment and threat detection.
[0051] In some embodiments, the protocol auditing and behavior analysis module 102 can also be used for: Based on the structured traffic data matching protocol feature library, determine the network protocol type of the structured traffic data; Based on the protocol type, key operation fields and communication behavior sequences are parsed to generate protocol behavior logs; Abnormal access or unauthorized operations are identified based on the protocol behavior logs, and abnormal behavior tagging data is obtained.
[0052] In some embodiments, the system can perform protocol type identification processing based on the aforementioned generated structured traffic data. Specifically, the system pre-establishes a protocol feature library, which stores identification rules corresponding to different network protocols, including protocol identifier fields, port ranges, packet structure patterns, or field combination features. The parsing module matches the protocol field information in the structured traffic data with the protocol feature library, determines the network protocol type of each traffic record through rule comparison, and associates the corresponding parsing template with the record, thereby completing the protocol type identification.
[0053] After determining the protocol type, the system parses key fields in the structured traffic data according to the associated parsing template and reconstructs the communication behavior sequence according to the communication time order. The parsing process may include extracting fields such as operation codes, command parameters, access addresses, and status response information, and combining them with session identification information to form a continuous operation record. By associating and organizing multiple records within the same session, a protocol behavior log reflecting the communication process is generated to describe the operation trajectory and interaction pattern of both communicating parties.
[0054] Based on protocol behavior logs, the system performs abnormal behavior identification and processing. Specifically, the behavior logs are compared with preset access rules, operation legality constraints, or behavior baseline models to detect the existence of abnormal access paths, unauthorized operations, illegal command combinations, or abnormal timing behaviors. When behavioral characteristics inconsistent with the rules or baselines are detected, the system generates corresponding abnormal behavior tag data and stores it in association with the original session records for subsequent risk assessment and threat analysis.
[0055] like Figure 4As shown, the system first receives link-layer data packets from the traffic acquisition module. These packets contain physical addresses and frame structure information. The parsing module identifies and strips the link-layer frame header to obtain the upper-layer network data content and transmits the parsing results to the network layer parsing unit.
[0056] During the network layer parsing phase, the system can parse data packets according to the network layer protocol format, such as extracting source address, destination address, and protocol identifier fields. The parsing results are used to determine the subsequent transport layer processing path, while retaining necessary network attribute information. The system can perform parsing on transport layer data according to network layer instructions, identifying port numbers, communication directions, and session attributes. Using this information, a communication context is established, and the application layer payload is then handled by the application layer parsing unit.
[0057] The application layer parsing stage is a key step in industrial control protocol identification. The system can input application layer load data into the parsing rule matching module to determine its protocol type and field structure.
[0058] In this embodiment, the parsing rule base is constructed using an AC automaton based on multi-pattern matching. During the preprocessing stage, the system converts the industrial control protocol rule strings into a finite state machine structure. By introducing turn functions, failure functions, and output functions, a protocol state tree is established, enabling various protocol rules to be organized in a unified structure.
[0059] When application layer data enters the matching stage, the system first performs sequential matching based on the redirection function to locate the rule fields. If the current matching fails, it automatically jumps to a state node where matching can continue through the failure function. When the matching is successful, the corresponding parsing result is generated through the output function. This matching process can identify multiple protocol features in parallel while traversing data packets, thereby achieving multi-rule matching in a single scan, improving parsing efficiency and meeting the real-time requirements of industrial communication.
[0060] like Figure 4 As shown, when inconsistencies occur in fields during rule matching, the parsing process returns to the previous matchable state via a failure function, without rescanning data packets. This mechanism reduces the overhead of repeated matching and ensures the continuity of the parsing process. When a rule match is successful, the system extracts key field data, including control commands, parameter information, and session identifiers, based on the corresponding protocol template, and generates a structured parsing result. This result serves as input for subsequent behavior analysis and threat detection.
[0061] The asset discovery and risk assessment module 103 is used to identify asset nodes in the network by combining structured traffic data and protocol behavior event data, construct asset association relationships, calculate asset risk levels based on asset exposure characteristics and abnormal behavior, and generate asset risk assessment data.
[0062] In some embodiments, the asset discovery and risk assessment module 103 can identify network devices, hosts, or control nodes by analyzing communication endpoint information in structured traffic data, and establish a communication relationship model between assets by combining protocol behavior event data. The module calculates asset risk scores by statistically analyzing asset exposure characteristics, access frequency, and the occurrence of abnormal behavior, thereby achieving a quantitative assessment of asset security status and generating asset risk assessment data, thus providing support for subsequent threat correlation analysis and defense decisions.
[0063] In some embodiments, the asset discovery and risk assessment module 103 can also be used for: Based on structured traffic data, communication endpoint identification information and device behavior characteristics are extracted to identify asset nodes in the target network and generate initial asset data; Based on initial asset data and protocol behavior event data, analyze the communication relationships and behavioral patterns between assets to construct asset association data; Based on asset correlation data, assess the exposure level and frequency of abnormal behavior of each asset, calculate the corresponding asset risk score, and generate asset risk assessment data.
[0064] In some embodiments, the system can perform asset identification processing based on the aforementioned structured traffic data. Specifically, the parsing module extracts communication endpoint identification information from the structured traffic records, including source address, destination address, port number, device identification field, and session attributes, and combines this with device behavior characteristics exhibited during communication, such as access patterns, protocol usage, and interaction frequency, to identify entities participating in communication within the network. By aggregating and organizing records with the same identification characteristics, corresponding asset node description information is formed, thereby generating initial asset data. The initial asset data is used to characterize the basic attributes and communication characteristics of each network entity.
[0065] After obtaining initial asset data, the system performs correlation analysis with protocol behavior event data. Specifically, by matching session identifiers and time series information, it analyzes the communication paths, access directions, and operation types between different asset nodes to identify the interaction relationships and behavioral patterns between assets. For example, it can statistically analyze information such as access frequency, command call relationships, and behavior duration between assets. By structuring the above relationship data, asset correlation data is constructed to describe the communication topology and behavioral characteristics between network assets.
[0066] Based on asset relationship data, the system performs risk assessment. Specifically, by analyzing the exposure of each asset in communication relationships, such as the proportion of external access, the openness of critical services, and the frequency of abnormal behavior, and combining this with preset risk assessment rules or scoring models, the system quantitatively assesses each asset node. The assessment results are expressed in the form of risk scores, reflecting the security status and potential risk level of the assets, thereby generating asset risk assessment data to provide a basis for subsequent threat detection and defense decisions.
[0067] In some embodiments, the asset discovery and risk assessment module 103 can also be used for: Based on the results of active detection and passive traffic analysis, fused asset information is obtained; Perform deduplication and consistency checks on the merged asset information to obtain the corresponding check results; The asset risk status data is updated based on the verification results to obtain the updated asset risk status data.
[0068] In some embodiments, the system can acquire asset-related information through a combination of active probing and passive traffic analysis. Active probing involves sending probe packets or access requests to the target network to obtain information such as device identifiers, service availability, and response characteristics. Passive traffic analysis, based on collected communication data, extracts communication endpoint attributes and behavioral characteristics from structured traffic records. The system matches and integrates these two types of information according to device identifiers, address information, or time-related relationships, merging data from different acquisition methods for the same asset to obtain fused asset information. This fusion result can simultaneously reflect the asset's static attributes and dynamic communication characteristics.
[0069] After obtaining the merged asset information, the system performs deduplication and consistency verification. Specifically, by comparing asset identification fields, network addresses, protocol characteristics, and historical records, duplicate or conflicting data items are identified and corrected or merged according to preset priority rules or consistency constraints. During the verification process, it can detect whether there are contradictory records in asset attributes, such as address changes or inconsistent service statuses, and generate corresponding verification results to ensure the integrity and accuracy of asset data.
[0070] Based on the verification results, the system updates the asset risk status. Specifically, it compares the verified asset attributes with existing risk assessment records, and updates risk indicators according to changes in asset exposure, abnormal communication behavior, or service status, thereby recalculating or adjusting the asset's risk status. The updated risk status data is written to the asset management record to reflect the asset's current security posture and provide real-time basis for subsequent threat detection and strategy generation.
[0071] like Figure 5As shown, the asset discovery and risk assessment module 103 can acquire network asset information by classifying and judging the detection targets, and adopt a combination of active detection and passive collection methods. The collected results are then uniformly organized and verified to provide a reliable data foundation for subsequent risk assessment.
[0072] Specifically, the system first analyzes the network environment to be detected to determine whether the target belongs to an internal network. If the target is an internal network, the system further determines whether to enable active detection based on the configured policy; if the target is an external network or active detection cannot be performed directly, the system uses system retrieval or passive collection methods to obtain asset information. This step is used to select an appropriate asset discovery path while ensuring network security and accessibility.
[0073] When active detection is not enabled or supplementary information is needed, the system initiates a passive data collection mechanism, automatically collecting network asset-related data by monitoring local area network communication traffic. The collected traffic data is saved in a standard data packet format, and asset attribute information such as device addresses, communication ports, and protocol characteristics is extracted through parsing. The parsing results are stored in a unified data format, providing raw asset data for subsequent fusion analysis.
[0074] In terms of passive detection, this module combines deep packet inspection (DPI) with unsupervised learning algorithms to construct a model for recognizing hidden assets and abnormal communication patterns. The system extracts multi-dimensional feature vectors from structured traffic data. This includes the load size distribution. Arrival time for private room Non-standard port protocol distribution and traffic information entropy The system inputs feature vectors into a pre-deployed density clustering algorithm to establish high-dimensional clusters of normal communication patterns of internal network assets. When outlier communication features outside the core clusters are detected, the system can effectively identify hidden devices or abnormal communication patterns not in the traditional asset list, greatly improving the accuracy and sensitivity of internal network asset identification.
[0075] When active probing is enabled, the system can sequentially perform multi-layered network probing, such as: confirming the reachability of the target host by sending ICMP probe packets; sending TCP connection requests to reachable hosts to identify open ports and basic service information; and sending application-layer request packets to probe the application attributes of the target device. The results of these probes are used to obtain the device's online status, service characteristics, and application identifiers, and the obtained asset information is recorded as structured data.
[0076] To address the issue of traditional active probing being prone to network noise and interception, this system introduces a dynamic adaptive covert probing algorithm during active probing. Instead of using data packets with fixed frequencies and standard characteristics, the system employs an intelligent data packet construction strategy for camouflage probing. Specifically, the system dynamically adjusts the probing time interval and concurrency based on the target network segment's response characteristics (such as response latency and packet loss rate). The calculation model is as follows:
[0077] in, For dynamic detection intervals, Based on the detection interval, The target response delay change rate, This represents the current packet loss rate of the link. and For environmental perception weighting coefficients, This introduces a Gaussian random jitter factor. Through this mechanism, the system can achieve low-frequency covert detection in different time periods. Simultaneously, the intelligent packet construction strategy simulates real business traffic characteristics by randomizing the TCP window size, initial sequence number, and IP ID fields, thereby reducing the risk of being identified by security protection devices.
[0078] When asset information cannot be directly obtained through network probing, the system uses a built-in search mechanism to perform network information retrieval on specified targets, obtaining publicly available data or configuration records related to the assets and storing them locally to supplement the asset information sources. The system can uniformly summarize asset information obtained through active probing, passive collection, and retrieval, and determine whether duplicate records exist by comparing device identifiers, address attributes, and service characteristics. If duplicate assets are found, deduplication and consistency processing are performed; if no duplicates are found, they are directly organized into standard asset entries. This process ensures the accuracy and completeness of asset information.
[0079] The merged and verified asset information is organized according to a unified classification rule, including equipment attributes, service information, and communication characteristics, and written into the asset database. This asset data serves as input to the risk assessment module, used for subsequent calculations of asset exposure levels and security risk grades.
[0080] The threat detection module 104 is used to input structured traffic data, abnormal behavior marker data and asset risk assessment data into the threat identification model for classification and analysis, identify potential malicious traffic and attack behaviors, and generate threat identification result data.
[0081] In some embodiments, the threat detection module 104 can take structured traffic data, abnormal behavior marker data, and asset risk assessment data as input, and perform classification and predictive analysis through a threat identification model. This model can use machine learning or deep learning algorithms to model traffic characteristics and identify malicious communication patterns, attack behaviors, or abnormal traffic features. After combining asset risk information for comprehensive judgment, threat identification result data is generated to characterize potential attack types and their impact scope.
[0082] In some embodiments, the threat detection module 104 can also be used for: Traffic feature vectors are extracted from structured traffic data to generate threat detection input data; Based on the threat detection input data, a machine learning or deep learning model is invoked to perform classification prediction and obtain the threat category result; Potential attack behaviors are identified by combining threat category results with anomalous behavior marker data, generating threat identification result data.
[0083] In some embodiments, the system can perform feature extraction processing before threat detection based on the aforementioned generated structured traffic data. Specifically, the parsing module extracts statistical and protocol features related to communication behavior from the structured traffic records, such as session duration, number of data packets, transmission direction distribution, port usage, and key field patterns, and encodes and normalizes them according to a preset feature template to form a traffic feature vector that can be processed by the model. Multiple feature vectors can be organized by time window or session granularity to generate threat detection input data that reflects the comprehensive characteristics of communication behavior.
[0084] Based on threat detection input data, the system invokes a pre-trained classification model to perform threat prediction analysis. The model can employ machine learning or deep learning, and its training process establishes a mapping relationship between features and threat categories based on historical traffic samples. During the prediction phase, the model receives input data and outputs corresponding classification results, indicating whether the traffic belongs to normal communication or a specific type of threat behavior, thus obtaining the threat category result.
[0085] After obtaining the threat category results, the system performs comprehensive judgment processing by combining the abnormal behavior tag data. Specifically, by correlating the model prediction results with the abnormal behavior tags generated during the protocol audit phase, communication records that simultaneously meet the threat characteristics and abnormal behavior conditions are identified, thereby reducing false positives or false negatives. Finally, the attack behaviors confirmed by the comprehensive judgment are recorded in a structured form to generate threat identification result data, which is used to describe the potential attack type, associated sessions, and scope of impact.
[0086] In some embodiments, the threat detection module 104 can also be used for: The model parameters of the threat detection model are updated based on the historical threat identification results of the structured traffic data to obtain the updated threat detection model; Real-time traffic prediction is performed using the updated threat detection model to obtain the corresponding prediction results; Based on the prediction results, output real-time dynamic threat alert data for traffic.
[0087] In some embodiments, the system can perform model update processing based on historical threat identification results. Specifically, the system extracts sample records related to historical threat identification from stored structured traffic data, including confirmed threat category identifiers, corresponding traffic characteristics, and behavioral context information. By inputting the above sample data into the model update module, the parameters of the original threat detection model are iteratively adjusted so that the model can reflect the latest threat feature distribution. The model update process can be completed using batch training or incremental learning methods to obtain an updated threat detection model, thereby improving the ability to identify new or variant threats.
[0088] Based on the updated threat detection model, the system performs predictive processing on real-time collected communication traffic. Specifically, the real-time generated traffic feature vector is input into the updated model, which classifies and judges the traffic behavior according to the current parameters and outputs the corresponding prediction results to indicate whether the real-time communication has threat characteristics and its category.
[0089] After obtaining the prediction results, the system performs alarm generation. Specifically, it matches the prediction results with preset alarm rules and generates alarm information for traffic records identified as potential threats. Alarm data may include threat category, associated session identifier, occurrence time, and affected assets, and is dynamically output to the monitoring interface or log system, thereby enabling continuous monitoring and alerts for real-time threat events.
[0090] like Figure 6 As shown, the threat detection module 104 can adopt a multi-engine collaborative detection structure. By combining rule matching and intelligent analysis, it performs threat identification and event generation processing on structured traffic data, and interacts with the data storage system through a communication interface to achieve continuous detection and result management.
[0091] The threat detection module 104 establishes a bidirectional connection with the external data storage unit via a communication interface. This interface receives analysis data from the structured traffic processing module and writes detection results to the database. The database stores threat samples, behavior records, and historical alarm information to support rule loading and model invocation during the detection process. This interface ensures data consistency and real-time synchronization between the detection module and the data layer.
[0092] The threat detection module 104 can be internally configured with a rule-based detection unit for performing feature matching based on predefined rules. The rule base can store various threat behavior patterns and protocol characteristic descriptions. During detection, input traffic records are compared with the rule base; when a match is found, a corresponding threat event identifier is generated. This process is suitable for the rapid identification of known attack patterns and features fast response and strong interpretability.
[0093] Building upon rule-based detection, the threat detection module 104 can incorporate a machine learning detection unit for classifying and analyzing traffic characteristics. This unit uses a pre-trained model to predict and judge the statistical characteristics of communication behavior, identifying potential abnormal patterns. Machine learning detection can discover behavioral deviations not covered by rules, thus supplementing rule-based detection capabilities.
[0094] The threat detection module 104 may also include a deep learning detection unit for performing high-dimensional feature analysis on complex communication sequences. By modeling temporal behavior or combinations of multiple features, it detects potential attack chains or covert threat behaviors. This unit is suitable for identifying multi-stage or variant attacks, improving overall detection accuracy.
[0095] In this embodiment, the system fuses the results of rule-based detection, machine learning detection, and deep learning detection, and generates a unified threat assessment result through consistency judgment or priority strategy. This fusion mechanism reduces the false positive rate and improves the reliability of identification in complex attack scenarios.
[0096] To ensure continuous operation of the detection function, a daemon component is set up in the module. This component is responsible for monitoring the running status of each detection unit, automatically restarting it when the detection process is abnormally interrupted, and performing resource management and logging operations, thereby ensuring the stability and real-time performance of the threat detection process.
[0097] In some embodiments, the threat events determined by the comprehensive assessment can be output in a structured form, including threat category, associated traffic identifier and time information, and written to a data storage system for alarm display and subsequent policy generation.
[0098] like Figure 7 As shown, the threat detection module 104 includes a classification processing flow based on heterogeneous integrated machine learning, used to perform high-precision threat identification on unknown network traffic. This flow is mainly divided into an offline model building stage and an online classification and detection stage. The specific algorithm implementation logic is as follows: 1. Dataset preprocessing and feature engineering: The system first performs deep analysis on a historical dataset (containing both normal traffic and threat samples). The structure analyzer and the parsing analyzer work together to analyze the raw traffic packet sequences. This is transformed into a numerical feature vector. To accurately characterize covert threats, the features extracted by the system not only include traditional time statistics (such as packet interval time) but also incorporate application-layer payload information entropy features. For any packet payload... Its information entropy The calculation model is as follows:
[0099] in, For information entropy, For a specific byte pattern in the payload The probability of occurrence. Combining connection duration, uplink / downlink byte ratio, etc., the system constructs a [structure / mechanism] for each session. dimensional initial feature vector .
[0100] Furthermore, to meet the real-time detection requirements of portable devices, a principal component analysis (PCA) dimensionality reduction algorithm is introduced internally into the analytical analyzer. By calculating the eigenvalue decomposition of the sample covariance matrix, the truncation of the first... The projection matrix is composed of the eigenvectors corresponding to the largest eigenvalues. Compress high-dimensional feature data into training input data. :
[0101] in, The low-dimensional feature data after dimensionality reduction (i.e., training input data). For the projection matrix, For high-dimensional feature data, This is the feature mean vector, which significantly reduces the computational complexity of subsequent classifiers while preserving core information.
[0102] 2. Classifier construction and model training: Based on the dimensionality-reduced training input data The system employs a heterogeneous classifier ensemble strategy to build a classification model. In this embodiment, the classifier pool includes at least kernel support vector machines and random forests. For the kernel support vector machine classifier, the goal is to find the optimal classification hyperplane in high-dimensional space. This is achieved by introducing a Gaussian radial basis function. To handle nonlinear flow boundaries, where, For Gaussian radial basis functions, For kernel function parameters, For the sample and The objective function for optimizing the square of the Euclidean distance between them is constructed as follows:
[0103] The constraints are:
[0104] in, It is the normal vector. For bias terms, The penalty coefficient is... As slack variables, Let be the feature vector of the i-th sample. For mapping functions, The total number of training samples, For traffic labeling, the system constructs multiple decision trees based on Gini impurity for the random forest classifier, with nodes... The impurity of the Gini coefficient is calculated as follows:
[0105] in, For nodes The impurity value of the Gini. For nodes Total number of categories included For nodes Belongs to the category The percentage of samples.
[0106] 3. Online detection and dynamic fusion output: During the online operation phase, the system collects unknown network traffic in real time, processes it using the same structure and parsing analyzer, and then generates online detection input data. .Will Input the established ensemble classification model. To overcome the limitations of a single classifier, the system introduces a dynamic weighted soft voting mechanism in the output stage. Assume the classification model contains... There are 3 basic classifiers, and the output sample of each classifier belongs to the threat category. posterior probability The system calculates the final comprehensive threat confidence score. :
[0107] in, Input data for online detection, Number of basic classifiers For the l-th base classifier, pair the samples Category The posterior probability, The weights of the l-th base classifier are... This is the overall threat confidence score.
[0108] Among them, weight The scores are dynamically assigned based on the F1-Score of each classifier during the cross-validation phase, and the following conditions are met: Ultimately, the system will The corresponding category is used as the final classification result. When a threat is identified, the system converts the classification result, confidence score, and associated traffic characteristics into structured threat identification data, which is then transmitted to the result management unit through the output interface to achieve automated threat alerts.
[0109] like Figure 8 As shown, during real-time operation, the threat detection module 104 performs classification and result management processing on the traffic to be detected to avoid redundant analysis and improve detection efficiency. In some embodiments, the system can first receive records of the traffic to be detected from the traffic acquisition and parsing module 101. These records may include structured information such as session identifiers, communication characteristics, and behavioral attributes, which are used to uniquely identify the current communication flow.
[0110] Furthermore, the system can query the local detection record database based on the session identifier to determine whether a corresponding classification result already exists for the traffic to be detected. When a detection entry matching the traffic record exists in the database, the system directly reads the existing classification information, avoiding repeated execution of model prediction.
[0111] When no corresponding detection record exists in the database, the system loads a pre-trained classification model and inputs the feature vector of the traffic to be detected into the model to perform predictive analysis. The classification model outputs a corresponding threat category label or normal status indicator based on the communication behavior characteristics. The system can generate a corresponding classification label for the traffic to be detected based on the model's prediction results, and associate this label with the session identifier in the traffic record to form a complete detection record.
[0112] In some embodiments, the generated detection records are written to a local database for subsequent queries and statistical analysis. This database entry operation enables persistent storage of detection results and provides a basis for identifying duplicate traffic. After the database entry is completed, the current traffic detection process ends, and the system enters the next traffic processing cycle.
[0113] like Figure 9 As shown, the threat detection module 104 executes a traffic classification processing flow based on deep sequence learning to identify highly covert, cross-session, and complex network attack behaviors. This flow is logically divided into an offline model training phase and an online detection inference phase.
[0114] 1. Offline Stage: Data Preprocessing and Feature Tensor Quantization The system first performs high-dimensional vectorization processing on the historical known dataset. The parsing module truncates and pads the session payload and protocol fields of the raw traffic to a fixed length. To enable deep learning models to handle unstructured byte streams, the system introduces word embedding and byte-pair encoding (BPE) algorithms. This transforms discrete byte sequences... Through embedding matrix Mapped to a continuous dense feature matrix :
[0115] in, The size of the dictionary in bytes. For embedded dimensions, Let be a real number space. The characteristic matrix is... As standard input data for subsequent deep learning models.
[0116] 2. Offline Stage: Deep Learning Model Construction: Based on the matrix data mentioned above, the system constructs a hybrid neural network structure that integrates one-dimensional spatiotemporal convolution (1D-CNN) and multi-head self-attention mechanism.
[0117] (1) Local Spatial Feature Extraction: The model front end uses multi-scale one-dimensional convolutional kernels to capture malicious signatures in the traffic. For a window size of... convolution kernel Its convolution mapping process is as follows:
[0118] in, Let i be the local eigenvector. To correct the linear unit, For convolution kernel, For a local segment of the input sequence, This is a bias term.
[0119] After max pooling, the output is a set of local feature vectors. .
[0120] (2) Global Temporal Feature Extraction: A self-attention layer is introduced in the backend of the model to calculate contextual dependencies across data packets. A query matrix is generated through linear transformation. Key matrix Sum matrix The calculation model for attention weights is as follows:
[0121] in, For querying the matrix, The key matrix, For value matrices, Scaling factor This is the transpose of the key matrix. This is a normalized exponential function. This mechanism enables the model to automatically focus on a small number of critical messages that pose a threat within an extremely long communication sequence.
[0122] 3. Offline Phase: Model Training and Parameter Optimization During the model training phase, addressing the critical technical challenge of extreme imbalance between normal and malicious traffic samples in the cybersecurity field, the system employs a focal loss function instead of the traditional cross-entropy loss during backpropagation optimization.
[0123] in, The value of the focus loss function. The total number of categories, This is the category balance coefficient. Adjusting parameters for easy and difficult samples (usually) ), To predict probabilities for the model, The system uses the Adam adaptive moment estimator to iteratively update the model weight parameters through gradient descent, providing the true labels. :
[0124] in, For the updated model parameters, These are the model parameters at the current time step t. For learning rate, This is the first-order moment estimate after bias correction. This is the second-order moment estimate after bias correction. It is a very small constant value.
[0125] After training converges, the parameters with the highest generalization ability are fixed into a model file and loaded into memory for later use.
[0126] 4. Online Phase: Preprocessing and Real-time Inference Analysis: During the system's online operation, the collected unknown traffic is first preprocessed using the same byte-level embedding logic to generate the tensor matrix required for online inference. The system loads the saved deep learning model file and performs... Perform forward propagation inference. At the model's output, use the Softmax normalization function to calculate which predefined threat categories the unknown traffic segment belongs to. The posterior probability distribution:
[0127] in, For posterior probability, The predicted labels for the model, For predefined threat categories, For new input traffic data, The logistic regression value is the output of the fully connected layer. This represents the logistic regression value for category i. The system sets the confidence threshold. If and only if If so, the traffic is identified as threatening traffic.
[0128] 5. Result Output: Ultimately, the system converts model outputs exceeding the threshold into structured threat identification records, including information obtained through... The mapped threat category identifier, associated five-tuple traffic identifier, and high-precision timestamp are transmitted to the threat detection result management unit to trigger automated defense strategies.
[0129] like Figure 10 As shown, the threat detection module 104 supports performing classification detection processing on offline collected traffic files to achieve historical traffic retrospective analysis and threat identification.
[0130] In some embodiments, the system can first read the timestamp or index information of the pcap file to be detected. The timestamp is used to uniquely identify the file's source and generation time, and serves as the basis for subsequent deduplication. The system can query the local detection record database based on the timestamp to determine whether the pcap file has already undergone detection processing. When a corresponding record exists in the database, the system directly terminates the current detection process to avoid duplicate analysis.
[0131] When a detection record is missing, the system can locate the pcap file in local storage based on the timestamp and load its contents. This file contains the original network packet sequence for subsequent parsing and classification. The system performs preprocessing operations on the read pcap file, including session reassembly, field parsing, and feature encoding. The preprocessing results are converted into a unified format traffic identifier file or feature representation to adapt to the input requirements of the classification model. The system loads a pre-trained classification model and inputs the preprocessed data into the model to perform predictive analysis. The model outputs corresponding classification labels based on traffic characteristics to represent potential threat categories or normal communication states. The system associates the prediction results with the corresponding traffic identifiers to form a complete classification record. This record may contain information such as traffic identifier, threat category, and detection time.
[0132] In some embodiments, the generated classification records are written to a detection database for persistent management of the detection results. This database can be used for historical analysis, alarm generation, or policy reasoning. Once the database entry is complete, the offline traffic detection process ends.
[0133] The strategy generation module 105 is used to perform security correlation reasoning based on threat identification result data and asset risk assessment data, determine the set of defense strategies corresponding to threats and assets, and output strategy suggestion data.
[0134] In some embodiments, the policy generation module 105 can perform security correlation analysis based on threat identification results and asset risk assessment data. The module can match detected threats with affected assets based on a pre-built security knowledge correlation model or policy rule base, and infer corresponding defensive measures, such as access control, integrity verification, or policy hardening recommendations. By prioritizing candidate policies, it outputs actionable policy recommendation data to support on-site security response.
[0135] In some embodiments, the policy generation module 105 can also be used for: Based on the threat identification results, a security knowledge association model is matched to determine the relationship between relevant threats and assets; Based on the relationship between threats and assets, a set of actionable defense strategies is derived. The strategy priority evaluation results are obtained by evaluating the set of defense strategies. Based on the strategy priority evaluation results, the optimal strategy combination is selected from the set of defense strategies, and strategy suggestion data is generated based on the optimal strategy combination.
[0136] In some embodiments, the system can perform security correlation analysis based on threat identification results data. Specifically, the threat category, location of occurrence, and associated session information from the threat identification results are input into a security knowledge correlation model. The model stores correlation rules between threat types, attack paths, and asset attributes. By matching these rules, the system determines the correspondence between threat events and related assets, thereby obtaining threat-asset relationship data describing the threat propagation path, scope of impact, and characteristics of the target assets.
[0137] After obtaining the relationship between threats and assets, the system performs policy reasoning. Specifically, based on the asset's importance level, threat type, and behavioral characteristics, it retrieves corresponding policy rules from a pre-defined defense policy library and performs reasoning analysis based on the relationship between threats and assets to generate multiple combinations of executable defense measures. These may include access control adjustments, communication blocking suggestions, or enhanced monitoring measures. This process forms a set of defense policies used to describe candidate response plans for the current threat situation.
[0138] Subsequently, the system performs optimization processing on the set of defense strategies. Specifically, by evaluating indicators such as the risk reduction effect, implementation cost, and impact on business operations of each strategy, the strategies are ranked and analyzed to obtain a strategy priority evaluation result. Based on this evaluation result, the system selects strategy combinations that meet preset optimization conditions from the candidate set and organizes the selection results into structured strategy suggestion data. The strategy suggestion data is used to guide users in performing security response operations, thereby achieving threat handling and risk control.
[0139] like Figure 11 As shown, the policy generation module 105 can establish a security reasoning model based on the correlation between threats, assets, and security requirements to determine defense strategies for the current risk state. This model achieves targeted generation of security measures by describing threat propagation paths, vulnerability exploitation conditions, and risk formation mechanisms.
[0140] In some embodiments, the system can first determine potential threat behaviors based on threat identification results and analyze their exploitation conditions. Threat behaviors typically rely on a vulnerable environment that has met preconditions, and when a vulnerability is exploited, it may have subsequent effects, such as privilege escalation or service interruption. By recording the dependencies between threats and vulnerabilities, the system maps them to risk propagation paths, providing a basis for subsequent risk assessments.
[0141] Specifically, when threats exploit vulnerabilities and act on target assets, they introduce or amplify risk factors. Risk factors describe changes in the security status of an asset after an attack, such as an increased exposure surface or reduced business availability. The system performs correlation analysis between threat behavior and asset attributes to determine the formation and scope of impact of risk factors.
[0142] The system can determine security requirements based on the importance level of assets and business attributes. For example, critical assets need to meet integrity, availability, or access control requirements. There is a constraint relationship between risk factors and security requirements; when risks increase, security measures are needed to reduce the impact of threats in order to meet established security objectives.
[0143] The system can select applicable control measures from a security measure library based on risk factors and security requirements, such as access restrictions, behavior monitoring, or communication isolation. A security reasoning mechanism evaluates the risk reduction effect of each measure, forming a candidate set of defense strategies. The strategy generation process considers threat types, asset attributes, and risk propagation relationships to ensure the strategies are targeted and executable.
[0144] Once the generated defense strategies are applied to assets, they can reduce risk factors and weaken threat propagation paths. The system continuously monitors changes in asset and threat status, provides feedback and evaluation on the effectiveness of the strategies, and adjusts the strategy combinations as necessary, thereby forming a dynamic security protection closed loop.
[0145] like Figure 12 As shown, the system can first model the assets in the target network environment. The assets include at least operating system assets, such as the Windows operating system, and log data assets generated by the operating system.
[0146] The system uses the operating system and its log data as the foundational asset objects for security analysis, and models potential malicious targets related to these assets. Malicious targets may include, but are not limited to, process destruction; exposure of covert communication channels; and damage, deletion, or tampering with log data. Through this modeling approach, the specific impacts of attack behaviors on the assets are clarified, providing a semantic basis for subsequent risk reasoning.
[0147] In some embodiments, the system can identify the type of security risk currently faced by an asset based on the analysis results of the log data, combined with a traffic anomaly detection and threat identification model. The system can uniformly map various detection results related to log anomalies and asset behavior deviations into a "data abuse" risk semantic, used to describe at least one of the following security states: log data is accessed abnormally, log data is called by unauthorized processes, and log data is used to support subsequent attack behaviors. By introducing the intermediate risk semantic node of "data abuse," the system achieves abstract fusion of multi-source detection results, improving the consistency and reasonability of risk expression.
[0148] After identifying the security risks, the system can further combine the vulnerability knowledge base and the attack pattern knowledge base to perform reasoning analysis on the causes of the risks. Specifically, the system associates the risk semantics with at least one vulnerability node, which includes vulnerability types defined in the Common Vulnerability Enumeration (CWE), such as vulnerabilities caused by improper resource lifecycle management or insufficient randomness. The system further introduces the Attack Pattern Library (CAPEC), using the vulnerabilities as preconditions for attacks, and reasoning on the exploitation relationship between attack patterns and vulnerabilities, thereby determining how the attack path affects assets and log data. Through the above reasoning process, the system can clearly identify the preconditions, exploitation methods, and potential harms of attack behavior in the current risk scenario. During the reasoning analysis, the policy generation module 105 introduces a security ontology reasoning engine based on graph neural networks (GNN). Figure 12 The security ontology model shown instantiates currently threatened assets, vulnerabilities that meet preconditions (such as CWE nodes), and specific threat actions (such as CAPEC nodes) into nodes in a knowledge graph. The inference engine calculates the weights of connected paths from threat nodes to asset nodes using a graph walking algorithm, thereby quantifying the risk factors of different attack paths and using this to recommend a set of candidate defense strategies.
[0149] After completing the attack path reasoning, the system can automatically determine the security requirements that need to be met in the current scenario based on the impact of the attack on assets and log data.
[0150] In this embodiment, security requirements may include at least: log data integrity requirements, log data auditability requirements, and log data continuous availability requirements. These security requirements serve as constraints on the selection of defense strategies, defining the security objectives that the subsequently generated defense strategies must meet.
[0151] Based on a pre-built security ontology, the system infers the relationship between security requirements, defense methods, and defense strategies to generate a set of candidate defense strategies. In this embodiment, the security ontology includes at least detection-based security methods, preventative security methods, and remedial security methods.
[0152] Based on security measures, the system can further recommend specific defense strategies, including file integrity monitoring strategies, vulnerability assessment strategies, and log synchronization and redundancy protection strategies. The system determines whether these defense strategies meet the established security requirements, filters out qualified defense strategies, and forms a candidate set of defense strategies.
[0153] In some embodiments, since this system is a portable intelligent network security risk detection system, its computing resources, network bandwidth, and decision-making time are strictly limited during on-site emergency response. Therefore, when inputting the generated defense strategy candidate set into the intelligent planning module, the system introduces a bounded rationality (BR) intelligent planning mechanism. The system establishes a strategy utility evaluation model under time, cognitive, and information constraints. Assume the candidate strategy set is... For any strategy Its risk reduction utility is defined as The resource cost required for execution is (Including CPU usage and network blocking costs for portable devices), execution time is... Bounded rationality intelligent programming seeks a satisfactory solution within the constraints, and its heuristic objective function is:
[0154]
[0155] in, For dynamic weights based on asset importance, For the set of all possible strategies, For any single strategy, For the final selected subset of strategies, For strategy The risk reduction effect, The resource cost required to execute strategy s This represents the maximum available resources for the current portable system. The time taken to execute strategy s, This represents the maximum tolerable response time.
[0156] The system uses a greedy heuristic algorithm in Within a time window, the solution is obtained quickly. Through the above method, the strategy generation module 105 can avoid decision-making timeouts or computing power overload caused by excessive pursuit of global theoretical optimality in complex network environments. It ensures that in the event of a sudden threat, it can output the most urgently needed defense strategy suggestions with minimal resource consumption, and achieve automated closed-loop processing.
[0157] Through the above methods, the strategy generation module 105 can achieve automated closed-loop processing from security risk identification and attack path reasoning to defense strategy recommendation, thereby improving the pertinence, interpretability, and executability of defense strategy generation.
[0158] The visualization and interaction module 106 is used to correlate and display structured traffic data, asset risk assessment data, threat identification results data and strategy suggestion data, and obtain visualized outputs of risk positioning, threat tracking and strategy prompts.
[0159] In some embodiments, the visualization and interaction module 106 can uniformly display the structured traffic data, asset risk assessment data, threat identification results data, and policy suggestion data generated by the system. This module presents network traffic trends, asset risk distribution, and threat correlations through a graphical interface, and provides interactive query and tracking functions, enabling users to intuitively locate risk sources, analyze attack paths, and view corresponding policy prompts, thereby improving security response efficiency.
[0160] In some embodiments, the visualization and interaction module 106 can also be used for: Generate a network traffic situation map based on structured traffic data; A risk distribution view is generated based on asset risk assessment data and threat identification results. An interactive strategy suggestion interface is generated based on the strategy suggestion data to achieve a visual display of the strategy.
[0161] In some embodiments, the system can perform network traffic situation visualization processing based on structured traffic data. Specifically, it aggregates and analyzes statistical information such as communication time, traffic volume, protocol type, and communication direction in the structured traffic records, and groups them according to preset time windows or asset dimensions. The system maps the processed statistical results into graphical representations, such as traffic change curves, communication topology relationships, or protocol distribution maps, thereby generating a network traffic situation map to reflect the communication status and changing trends of the target network in different time periods.
[0162] Based on asset risk assessment data and threat identification results, the system performs risk visualization generation. Specifically, by associating and organizing the risk levels, threat categories, and related events of asset nodes, a comprehensive data set including risk weights and impact scope is formed. The system then constructs a risk distribution model based on this data set and converts it into graphical display objects, such as risk level partitions, asset risk identifiers, or threat association views, thereby generating a risk distribution view to intuitively present the security status and threat distribution of various assets in the network.
[0163] After obtaining the policy recommendation data, the system performs interactive policy display processing. Specifically, the defensive measures, applicable conditions, and priority information in the policy recommendations are structured and organized to generate user-interactive interface elements. Users can view policy details, associate them with threat backgrounds, or perform recommended actions through the interface. The system dynamically updates the displayed content to link the policy with the current threat status, thus forming an interactive policy prompt interface to support users in making security decisions and responses.
[0164] Finally, it should be understood that the embodiments described in this specification are merely illustrative of the principles of the embodiments described herein. Other variations may also fall within the scope of this specification. Therefore, alternative configurations of the embodiments described herein are intended to be illustrative rather than limiting, and should be considered consistent with the teachings of this specification. Accordingly, the embodiments described herein are not limited to those explicitly introduced and described herein.
Claims
1. A portable intelligent network security risk detection system, characterized in that, The system includes: a traffic acquisition and parsing module, a protocol auditing and behavior analysis module, an asset discovery and risk assessment module, a threat detection module, a policy generation module, and a visualization and interaction module; The traffic acquisition and parsing module is used to acquire the raw data packet stream of the target network through the bypass mirror interface to generate a raw traffic dataset. Based on the raw traffic dataset, deep packet inspection and protocol feature matching are performed to extract session identification information, protocol field information, and behavioral feature information. Based on the session identification information, the protocol field information, and the behavioral feature information, a structured traffic record is constructed to obtain structured traffic data. The protocol auditing and behavior analysis module is used to identify network protocol types and communication behaviors based on the structured traffic data, perform auditing analysis on key protocol fields and operational behaviors, and obtain protocol behavior event data and abnormal behavior marker data. The asset discovery and risk assessment module is used to extract communication endpoint identification information and device behavior characteristics from the structured traffic data, identify asset nodes in the target network and generate initial asset data, analyze the communication relationship and behavior pattern between assets based on the initial asset data and the protocol behavior event data, construct asset association relationships, assess the exposure degree and frequency of abnormal behavior of each asset based on the asset association relationships, calculate the corresponding asset risk score, and generate asset risk assessment data. The threat detection module is used to input the structured traffic data, the abnormal behavior marker data, and the asset risk assessment data into the threat identification model for classification and analysis, so as to identify potential malicious traffic and attack behavior and generate threat identification result data. The strategy generation module is used to perform security correlation reasoning based on the threat identification result data and the asset risk assessment data, determine the set of defense strategies corresponding to the threats and assets, and output strategy suggestion data. The visualization and interaction module is used to correlate and display the structured traffic data, the asset risk assessment data, the threat identification result data, and the strategy suggestion data to obtain a visualized output of risk positioning, threat tracking, and strategy prompts.
2. The portable intelligent network security risk detection system according to claim 1, characterized in that, The traffic acquisition and parsing module is also used for: The original communication traffic is processed for industrial control protocol identification according to the multi-protocol parsing rules to obtain the corresponding identification results. Based on the parsing template corresponding to the recognition result, extract the key control instruction fields; Based on the key control instruction fields, generate industrial control behavior parsing data; The industrial control protocol identification and processing adopts the AC automaton algorithm based on multi-pattern matching. By introducing a turning function, a failure function and an output function, a protocol state tree is established, and multiple protocol features are identified in parallel in a single scan.
3. The portable intelligent network security risk detection system according to claim 1, characterized in that, The protocol auditing and behavior analysis module is specifically used for: Based on the structured traffic data matching protocol feature library, determine the network protocol type of the structured traffic data; Based on the protocol type, key operation fields and communication behavior sequences are parsed to generate a protocol behavior log; Based on the protocol behavior log, abnormal access or unauthorized operation is identified, and the abnormal behavior tag data is obtained.
4. The portable intelligent network security risk detection system according to claim 1, characterized in that, The asset discovery and risk assessment module is also used for: Based on the results of active detection and passive traffic analysis, fused asset information is obtained; The merged asset information is subjected to deduplication and consistency checks to obtain the corresponding check results; The asset risk assessment data is updated based on the verification results to obtain the updated asset risk assessment data. In the active probing process, a dynamic adaptive covert probing algorithm is introduced to dynamically adjust the probing time interval and concurrency based on the response characteristics of the target network segment, and to randomize the TCP window size, initial sequence number and IP ID field of the probing packets to simulate the characteristics of real business traffic.
5. The portable intelligent network security risk detection system according to claim 4, characterized in that, When performing passive flow analysis, the asset discovery and risk assessment module is also used for: A multidimensional feature vector is extracted from the structured traffic data. The multidimensional feature vector includes the load size distribution, packet arrival time, non-standard port protocol distribution, and traffic information entropy. The multidimensional feature vectors are input into a pre-deployed density clustering algorithm to establish a high-dimensional cluster of the normal communication mode of internal network assets; When outlier communication features that are outside the high-dimensional clusters are detected, covert devices or abnormal communication patterns are identified.
6. The portable intelligent network security risk detection system according to claim 1, characterized in that, The threat detection module is specifically used for: Based on the structured traffic data, traffic feature vectors are extracted to generate threat detection input data; Based on the threat detection input data, the threat identification model is invoked to perform classification prediction and obtain the threat category result; Based on the threat category results and the abnormal behavior tagging data, potential malicious traffic and attack behaviors are identified, and the threat identification result data is generated.
7. The portable intelligent network security risk detection system according to claim 6, characterized in that, The threat detection module is also used for: The model parameters of the threat detection model are updated based on the historical threat identification results of the structured traffic data to obtain the updated threat detection model; Real-time traffic prediction is performed using the updated threat detection model to obtain the corresponding prediction results; Based on the prediction results, real-time dynamic threat alert data for traffic is output.
8. The portable intelligent network security risk detection system according to claim 1, characterized in that, The strategy generation module is specifically used for: Based on the threat identification results, a security knowledge association model is matched to determine the relevant threat-asset relationship; Based on the relationship between the threats and assets, a set of executable defense strategies is derived. The set of defense strategies is evaluated for strategy priority to obtain strategy priority evaluation results. Based on the strategy priority evaluation results, the optimal strategy combination is selected from the set of defense strategies, and the strategy suggestion data is generated based on the optimal strategy combination.
9. The portable intelligent network security risk detection system according to claim 8, characterized in that, The strategy generation module is also used for: A bounded rationality intelligent programming mechanism is introduced to establish a strategy utility evaluation model for any strategy in the candidate strategy set. The strategy utility evaluation model includes the risk reduction utility of the strategy, the resource cost required for execution, and the execution time. The resource cost required for execution includes the CPU usage cost of portable devices and the network blocking cost. A heuristic objective function is constructed based on the strategy utility evaluation model. The heuristic objective function weights the risk mitigation utility with dynamic weights based on asset importance and is subject to the constraints of the available resources of the current portable system and the maximum tolerable response time. A greedy heuristic algorithm is used to solve the heuristic objective function within a preset time window, and a satisfactory solution is obtained within the constraint boundary. The strategy combination corresponding to the satisfactory solution is taken as the optimal strategy combination.
10. The portable intelligent network security risk detection system according to claim 8, characterized in that, The strategy generation module is also used for: A secure ontology reasoning engine based on graph neural networks is used to construct a knowledge graph. The threatened assets, vulnerable nodes, and attack pattern nodes are instantiated as corresponding nodes in the knowledge graph. The graph walking algorithm is used to calculate the weight of the connected path from the attack pattern node to the asset node. The risk factors of different attack paths are quantified based on the connected path weights, and the set of defense strategies is recommended in reverse based on the quantification results.
11. The portable intelligent network security risk detection system according to any one of claims 1-10, characterized in that, The visualization and interaction module is specifically used for: Based on the structured traffic data, communication time, traffic volume, protocol type and communication direction are aggregated and analyzed according to a preset time window or asset dimension, and the statistical results are mapped into traffic change curves, communication topology relationships or protocol distribution maps to generate network traffic situation maps. Based on the asset risk assessment data and the threat identification results data, the asset risk scores, threat category results and asset associations of the asset nodes are linked and organized to form a comprehensive data set. A risk distribution model is constructed based on the comprehensive data set, and a risk distribution view is generated based on the risk distribution model. Based on the strategy suggestion data, the defense measures, applicable conditions and priority information are structured and organized to generate interface elements, forming an interactive strategy prompt interface.