A network intrusion detection method, device, computer equipment and storage medium
By calculating multi-dimensional intrusion detection indicators, the problem of low accuracy in network intrusion detection is solved, enabling flexible and accurate detection of network intrusions.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- GUANGZHOU POWER SUPPLY BUREAU GUANGDONG POWER GRID CO LTD
- Filing Date
- 2026-03-06
- Publication Date
- 2026-06-23
AI Technical Summary
In existing technologies, network intrusion detection has low accuracy and is difficult to adapt to changing intrusion scenarios.
By acquiring raw traffic data, multi-dimensional intrusion detection indicators are calculated, including indicator values for traffic status, traffic protocol, terminal interaction, and communication behavior dimensions, and then fused to determine the detection results.
It achieves accurate detection of network intrusions, can adapt to a variety of different network intrusion scenarios, and improves the flexibility and accuracy of detection.
Smart Images

Figure CN122268620A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network intrusion detection technology, and in particular to a network intrusion detection method, apparatus, computer equipment, and storage medium. Background Technology
[0002] The current network environment is becoming increasingly complex, and network intrusion methods based on communication traffic are constantly evolving, causing serious impacts on personal privacy and business operations.
[0003] The detection of network intrusion methods in related technologies generally includes detection modes based on specific port scanning and detection modes based on fixed attack signature matching. However, these methods have low detection accuracy when faced with ever-changing intrusion scenarios.
[0004] Therefore, how to accurately implement network intrusion detection based on communication traffic has become an urgent technical problem to be solved. Summary of the Invention
[0005] Therefore, it is necessary to provide a network intrusion detection method, apparatus, computer equipment, and storage medium to address the aforementioned technical problems.
[0006] Firstly, this application provides a network intrusion detection method, including:
[0007] Obtain raw traffic data;
[0008] Based on the raw traffic data, calculate the corresponding multi-dimensional intrusion detection index values; the multi-dimensional intrusion detection indexes include traffic status dimension indexes, traffic protocol dimension indexes, terminal interaction dimension indexes, and communication behavior dimension indexes in the raw traffic data.
[0009] The fusion result of the indicator values of traffic status dimension indicators, traffic protocol dimension indicators, terminal interaction dimension indicators and communication behavior dimension indicators is determined, and the detection result of the original traffic data is determined based on the fusion result.
[0010] In one embodiment, based on the raw traffic data, the corresponding multi-dimensional intrusion detection index values are calculated, including:
[0011] Based on the traffic status information of the original traffic data, the index values of the traffic status dimension indicators are determined. The traffic status dimension indicators characterize the fluctuation of the original traffic data.
[0012] Based on the traffic protocol information of the raw traffic data, the indicator values of the traffic protocol dimension indicators are determined. The traffic protocol dimension indicators characterize the deviation between the protocol usage pattern of the raw traffic data and the obtained standard protocol usage pattern.
[0013] Based on the terminal interaction information of the raw traffic data, the indicator values of the terminal interaction dimension indicators are determined; the terminal interaction dimension indicators characterize the terminal interaction situation of the raw traffic data.
[0014] Based on the communication behavior of the raw traffic data, determine the indicator values of the communication behavior dimension indicators;
[0015] The multi-dimensional intrusion detection index values are obtained based on the index values of the traffic status dimension index, the traffic protocol dimension index, the terminal interaction dimension index, and the communication behavior dimension index.
[0016] In one embodiment, the indicator values of the traffic status dimension indicators are determined based on the traffic status information of the original traffic data, including:
[0017] Define the preset time window;
[0018] Within the time window, determine the probability of each type of traffic fluctuation occurring, as well as the number of types of traffic fluctuation states.
[0019] Based on the probability and number of occurrences of traffic fluctuation states and the preset traffic fluctuation coefficient, the index values of the traffic state dimension indicators are calculated. The traffic state dimension indicators are used to reflect the characteristics of various traffic flows within a time window.
[0020] In one embodiment, the indicator values of traffic protocol dimension metrics are determined based on the traffic protocol information of the original traffic data, including:
[0021] Obtain the preset standard protocol usage mode. The standard protocol usage mode represents the relevant parameters of the communication protocol in normal traffic within the preset historical window.
[0022] Based on the degree of deviation between traffic protocol information and standard protocol usage patterns, as well as preset protocol characteristic coefficients, the index values of traffic protocol dimension indicators are determined. Traffic protocol dimension indicators are used to reflect abnormal characteristics of communication protocols in the original traffic data.
[0023] In one embodiment, the indicator values of the terminal interaction dimension indicators are determined based on the terminal interaction information of the raw traffic data, including:
[0024] Obtain the preset correlation coefficient, which represents the interaction between the terminals;
[0025] Determine the number of source terminal addresses and target terminal addresses in the raw traffic data, as well as the interaction probability between each source terminal address and its corresponding target terminal address within a preset time window;
[0026] The indicator values for the terminal interaction dimension are determined based on the interaction probability, the number of source terminal addresses, the number of target terminal addresses, and the correlation coefficient.
[0027] In one embodiment, the indicator values of the communication behavior dimension indicators are determined based on the communication behavior of the raw traffic data, including:
[0028] Based on various communication behaviors in the raw traffic data, determine the corresponding anomaly coefficients;
[0029] The index values of communication behavior dimension indicators are determined based on the anomaly coefficient.
[0030] In one embodiment, a corresponding fusion result is calculated based on multi-dimensional intrusion detection indicators, and the detection result of the original traffic data is determined based on the fusion result, including:
[0031] Determine the weight of each indicator in the multi-dimensional intrusion detection metrics;
[0032] Based on the weights corresponding to each indicator, the values of each indicator are weighted and summed to obtain the fusion result;
[0033] If the fusion result meets the preset anomaly detection conditions, the detection result is obtained, which indicates that the original traffic data has abnormal behavior.
[0034] Secondly, this application also provides an intrusion detection device, comprising:
[0035] The acquisition module is used to acquire raw traffic data;
[0036] The calculation module is used to calculate the corresponding multi-dimensional intrusion detection index values based on the raw traffic data. The multi-dimensional intrusion detection indexes include traffic status dimension indexes, traffic protocol dimension indexes, terminal interaction dimension indexes, and communication behavior dimension indexes in the raw traffic data.
[0037] The generation module is used to determine the fusion result of the indicator values of traffic status dimension indicators, traffic protocol dimension indicators, terminal interaction dimension indicators and communication behavior dimension indicators, and to determine the detection result of the original traffic data based on the fusion result.
[0038] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to perform the following steps:
[0039] Obtain raw traffic data;
[0040] Based on the raw traffic data, calculate the corresponding multi-dimensional intrusion detection index values; the multi-dimensional intrusion detection indexes include traffic status dimension indexes, traffic protocol dimension indexes, terminal interaction dimension indexes, and communication behavior dimension indexes in the raw traffic data.
[0041] The fusion result of the indicator values of traffic status dimension indicators, traffic protocol dimension indicators, terminal interaction dimension indicators and communication behavior dimension indicators is determined, and the detection result of the original traffic data is determined based on the fusion result.
[0042] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, performs the following steps:
[0043] The process involves acquiring raw traffic data; calculating the corresponding multi-dimensional intrusion detection metrics based on the raw traffic data; these multi-dimensional intrusion detection metrics include traffic state dimension metrics, traffic protocol dimension metrics, terminal interaction dimension metrics, and communication behavior dimension metrics from the raw traffic data; determining the fusion result of the values of the traffic state dimension metrics, traffic protocol dimension metrics, terminal interaction dimension metrics, and communication behavior dimension metrics; and determining the detection result of the raw traffic data based on the fusion result. The aforementioned network intrusion detection method, apparatus, computer equipment, and storage medium, through this application, can integrate multi-dimensional information to obtain accurate network intrusion detection results. Attached Figure Description
[0044] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0045] Figure 1 This is a diagram illustrating the application environment of a network intrusion detection method in one embodiment.
[0046] Figure 2 This is a flowchart illustrating a network intrusion detection method in one embodiment;
[0047] Figure 3 This is a flowchart illustrating the calculation of multi-dimensional intrusion detection metrics in one embodiment;
[0048] Figure 4 This is a flowchart illustrating the calculation of traffic status dimension indicators in one embodiment;
[0049] Figure 5This is a flowchart illustrating the calculation of traffic protocol dimension metrics in one embodiment;
[0050] Figure 6 This is a flowchart illustrating the process of calculating terminal interaction dimension metrics in one embodiment;
[0051] Figure 7 This is a flowchart illustrating a preferred embodiment of a network intrusion detection method.
[0052] Figure 8 This is a structural block diagram of a network intrusion detection device in one embodiment. Detailed Implementation
[0053] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0054] The network intrusion detection method provided in this application embodiment can be applied to, for example, Figure 1 In the application environment shown, terminal 102 communicates with server 104 via a network. A data storage system can store the data that server 104 needs to process. The data storage system can be integrated onto server 104 or placed on a cloud or other network server. The process involves acquiring raw traffic data, calculating the corresponding multi-dimensional intrusion detection indicators based on the raw traffic data, including traffic status dimension indicators, traffic protocol dimension indicators, terminal interaction dimension indicators, and communication behavior dimension indicators in the raw traffic data; finally, determining the fusion result of the traffic status dimension indicator, traffic protocol dimension indicator, terminal interaction dimension indicator, and communication behavior dimension indicator values, and determining the detection result of the raw traffic data based on the fusion result. Terminal 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, and IoT devices. IoT devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, projection devices, etc., as long as they can acquire raw traffic data. The head-mounted device can be a virtual reality (VR) device, an augmented reality (AR) device, smart glasses, etc. Server 104 can be a standalone physical server, a server cluster or distributed system consisting of multiple physical servers, or a cloud server that provides cloud computing services.
[0055] In one exemplary embodiment, such as Figure 2 As shown, a network intrusion detection method is provided, which is applied to... Figure 1 Taking the server in the example of this, the explanation includes:
[0056] S210, acquire raw traffic data.
[0057] Optionally, raw traffic data can be collected from the communication network in real time. This raw traffic data contains complete information about network interactions and is usually in the form of data packets or data streams. This raw traffic data includes, but is not limited to, header information and payload data of the data packets.
[0058] S220, calculate the corresponding multi-dimensional intrusion detection index values based on the raw traffic data; the multi-dimensional intrusion detection indexes include traffic status dimension indexes, traffic protocol dimension indexes, terminal interaction dimension indexes, and communication behavior dimension indexes in the raw traffic data.
[0059] Among them, the multi-dimensional intrusion detection index is calculated based on the raw traffic data. This multi-dimensional intrusion detection index is used to reflect whether intrusion behavior exists in the raw traffic data. The aforementioned traffic status dimension index is used to reflect the macro-statistical characteristics and change patterns of network traffic in time and space, as well as fluctuations. Normal traffic fluctuations and changes are usually regular, while anomalies caused by intrusion behavior will change this regularity. The traffic protocol dimension index is used to reflect the compliance and abnormal patterns of the communication protocols used in network traffic. The terminal interaction dimension index is used to reflect the communication relationships and behavioral patterns between terminals in the network, in order to detect whether the collected communication patterns deviate from the historical baseline or normal conditions. The communication behavior dimension index is used to reflect the behavioral intent of the specific instructions, requests, data, etc. transmitted during the communication process, in order to detect threats such as malicious commands and data leakage.
[0060] Optionally, the above-mentioned multi-dimensional intrusion detection indicators can be obtained by comprehensively considering the traffic status dimension indicators, traffic protocol dimension indicators, terminal interaction dimension indicators, and communication behavior dimension indicators.
[0061] S230, determine the fusion result of the indicator values of traffic status dimension indicators, traffic protocol dimension indicators, terminal interaction dimension indicators and communication behavior dimension indicators, and determine the detection result of the original traffic data based on the fusion result.
[0062] Optionally, the calculated values of traffic status dimension indicators, traffic protocol dimension indicators, terminal interaction dimension indicators, and communication behavior dimension indicators are fused together to obtain a comprehensive calculation result. The detection result of the original traffic data is determined based on the comprehensive calculation result, which reflects whether there is a network intrusion in the original traffic data.
[0063] Through the embodiments of this application, the original traffic data is detected from multiple dimensions, and multiple detection indicators are calculated. By combining the indicators of all dimensions, it is determined whether there is a network intrusion in the original traffic data. Compared with the relatively single detection method in the prior art, it can accurately and flexibly adapt to a variety of different scenarios and obtain more accurate detection results.
[0064] In one exemplary embodiment, such as Figure 3 As shown, based on the raw traffic data, the corresponding multi-dimensional intrusion detection metrics are calculated, including:
[0065] S310, Based on the traffic status information of the original traffic data, determine the traffic status dimension indicators, which characterize the fluctuation of the original traffic data.
[0066] Traffic status information includes the number of packets per unit time, total bytes, packet interval distribution, mean and variance of packet length, fluctuation range of traffic rate, connection duration, retransmission rate, and so on. This information exists in the form of structured data or logs, such as recording the source IP, destination IP, and protocol information of a single session in NetFlow format session logs, presenting traffic rate and packet length distribution numerical sequences aggregated by time windows, or packet header fields extracted from PCAP (Packet Capture) format. Raw traffic can be copied via switch port mirroring, network TAP device hardware, or captured using software tools like Wireshark and tcpdump. Statistical data can also be output from the NetFlow / sFlow protocol of network devices to perform statistical calculations on the raw traffic by time window and IP / port dimensions to obtain corresponding characteristic indicators.
[0067] In summary, traffic status information can reflect the actual consumption status of network resources, such as bandwidth usage and equipment load, as well as the regularity of communication behavior. The packet length distribution and rate fluctuation of normal traffic usually conform to a specific statistical model, and it is also the basis for distinguishing between normal and abnormal traffic. For example, the abnormal packet length and sudden rate changes that often occur in attack traffic will deviate from the physical characteristics of normal traffic.
[0068] In this embodiment of the application, the traffic status dimension index can be determined based on the traffic status information of the original traffic data. This traffic status dimension index characterizes the fluctuation and change of the original traffic data.
[0069] S320, based on the traffic protocol information of the original traffic data, determine the traffic protocol dimension index. The traffic protocol dimension index characterizes the deviation between the protocol usage pattern of the original traffic data and the obtained standard protocol usage pattern.
[0070] Traffic protocol information is a set of features surrounding various communication protocols in network traffic, such as TCP (Transmission Control Protocol), UDP (User Datagram Protocol), and HTTP (Hypertext Transfer Protocol). Specifically, it includes the frequency of protocol usage, the percentage of data packets corresponding to each protocol, the response time of protocol interactions, and the compliance of protocol fields (such as the combination logic of TCP flags). Traffic protocol information typically exists in the form of structured statistical data, such as a table of traffic percentages for each protocol by time window, session logs of protocol interactions (recording protocol type, interaction duration, and field parameters), or protocol header feature sequences extracted from data packets. In practical applications, protocol information can be directly extracted by parsing packet headers using packet capture tools (such as Wireshark), or by aggregating the traffic percentages and number of sessions for each protocol using the traffic statistics functions of network devices (such as NetFlow). Protocol analysis tools can then be used to classify the raw traffic by protocol type and statistically analyze its characteristics.
[0071] The above-mentioned standard protocol usage patterns are preset and follow fixed rules that conform to normal situations. For example, in normal scenarios such as web page access, HTTP / HTTPS is the main method, and the fields and durations of protocol interactions also conform to standard logic. However, abnormal intrusion behaviors are often accompanied by abnormal protocol usage (such as a sudden increase in the proportion of non-business protocols) and violations of protocol fields (such as illegal TCP flag combinations). Therefore, it is the core basis for identifying protocol-level intrusion behaviors.
[0072] One can understand the connection between traffic state information and traffic protocol information. Traffic protocol information is one of the subdivisions of traffic state information. Traffic state information covers the overall characteristics of traffic, such as rate and packet length, while traffic protocol information focuses on the protocol-related characteristics of traffic. The difference between the two is their scope: traffic state information is the overall set of characteristics of network traffic, while traffic protocol information is a set of characteristics only around the protocol dimension.
[0073] In this embodiment of the application, the traffic protocol information in the original traffic data is extracted by the above method, the deviation between the protocol usage mode of the original traffic data and the preset standard protocol usage mode is calculated based on the traffic protocol information, and then the above-mentioned traffic protocol dimension index is determined based on the deviation.
[0074] S330, based on the terminal interaction information of the raw traffic data, determines the terminal interaction dimension indicators; the terminal interaction dimension indicators characterize the terminal interaction status of the raw traffic data.
[0075] Among them, terminal interaction information is used to characterize the interaction between the source IP address and the destination IP address, such as interaction probability, number of interactions, IP geographical location, IP port correlation coefficient, etc.
[0076] In this embodiment, terminal interaction information is determined from the raw traffic data, and the corresponding indicator values for the terminal interaction dimension indicators are calculated based on the terminal interaction information. It can be understood that this embodiment uses a series of parameters to comprehensively characterize the terminal interaction situation, that is, various characteristics of IP interaction. This multi-dimensional fusion calculation can comprehensively and meticulously present the complex state of IP interaction.
[0077] S340 determines communication behavior dimension indicators based on the communication behavior of the raw traffic data.
[0078] Among them, the communication behavior of raw traffic data is used to characterize the communication behavior features such as the length of traffic packets and the direction of traffic in the raw traffic data.
[0079] In this embodiment of the application, the index value of the communication behavior dimension index is calculated based on the communication behavior extracted from the original traffic data.
[0080] S350 obtains multi-dimensional intrusion detection indicators based on traffic status indicators, traffic protocol indicators, terminal interaction indicators, and communication behavior indicators.
[0081] In this embodiment, the values of traffic status dimension indicators, traffic protocol dimension indicators, terminal interaction dimension indicators and communication behavior dimension indicators can be fused together, or the weights corresponding to each indicator can be preset first, and then the indicators can be weighted and fused together to finally obtain the above-mentioned multi-dimensional intrusion detection indicators.
[0082] By integrating and calculating multi-dimensional indicators as described in this application, abnormal characteristics of traffic in terms of fluctuations, protocols, IP interactions, and packet status are comprehensively and meticulously integrated. Subsequently, these multi-dimensional intrusion detection indicators can be compared with preset thresholds to determine whether intrusion behavior exists in the original traffic data, providing a comprehensive and accurate assessment basis for network security detection.
[0083] In one exemplary embodiment, such as Figure 4 As shown, based on the traffic status information of the raw traffic data, the traffic status dimension indicators are determined, including:
[0084] S410, Determine the preset time window.
[0085] The aforementioned time window can be set by relevant technical personnel according to actual needs, such as 10 seconds.
[0086] S420 determines the probability of each type of traffic fluctuation occurring within a time window, as well as the number of types of traffic fluctuation states.
[0087] Among them, traffic fluctuation status refers to the relatively stable change pattern of communication traffic in terms of rate, number of packets, and amount of data within a time window. For example, within a 10-second time window, there may be different states such as low-speed stability (the traffic rate remains at a low level and the fluctuation is minimal), high-speed burst (the number of data packets and the amount of bytes increase sharply in a short period of time), intermittent fluctuation (the traffic rate repeatedly switches between high and low ranges), and continuous decline (the amount of traffic data gradually decreases). These states are used to distinguish the operating rules of traffic in different time periods and are the basis for calculating traffic status dimension indicators.
[0088] The number of types of traffic fluctuation states mentioned above refers to the number of types of traffic fluctuation states within a time window.
[0089] S430 calculates the flow state dimension index based on the probability of flow fluctuations, the number of types, and the preset flow fluctuation coefficient. The flow state dimension index is used to reflect the characteristics of various flows within a time window.
[0090] In this embodiment of the application, the traffic state dimension index α is calculated by combining the probability of traffic fluctuation state occurrence, the number of types, and a preset traffic fluctuation coefficient, as follows:
[0091]
[0092] Where a is the preset flow fluctuation coefficient, p i Let be the probability of the i-th type of traffic fluctuation occurring within the time window t, and n be the number of types of traffic fluctuation states.
[0093] In this embodiment of the application, the above-mentioned flow fluctuation coefficient includes, but is not limited to, the following coefficient: ω i This is the time window weighting coefficient, which is set based on the length of the time window and the timeliness requirements of the traffic data. σ v The flow rate variation coefficient is calculated by dividing the standard deviation of the flow rate by the mean within a time window. This is the traffic burst delay coefficient, which is used to calculate the time difference between the moment of a traffic burst and the expected time (compared to historical burst patterns obtained in advance), and then normalized to obtain the traffic burst delay coefficient. This is the correlation coefficient between traffic historical trends. This coefficient represents the similarity between the traffic characteristics of the current window and the traffic characteristics of the same historical period. The similarity coefficient for traffic burst patterns represents the degree of fit between the packet length, rate, and other characteristics of the current traffic burst and a known burst pattern library. The flow smoothness coefficient is calculated as the deviation before and after smoothing the flow data using a moving average algorithm. This is the traffic time offset coefficient, which represents the offset between the current peak / valley time and the historical normal time. The packet priority influence coefficient is calculated by weighting the traffic data according to priority weights, taking into account the packet's Type of Service (TOS) field. The seasonal fluctuation coefficient of traffic flow is obtained by judging the pattern of traffic flow fluctuations in the same period of history (such as weekly or monthly). To determine the network neighbor node traffic influence coefficient, collect traffic data of neighbor nodes and calculate their correlation with the current node's traffic (such as the Pearson correlation coefficient).
[0094] In this embodiment of the application, at least one coefficient can be selected from the above multiple flow fluctuation coefficients according to actual needs, and the selected flow fluctuation coefficient is multiplied by the probability of the flow fluctuation state to obtain the above flow state dimension index.
[0095] In summary, this application introduces a series of coefficients that can accurately characterize different traffic characteristics to jointly calculate the residual traffic state dimension indicators. Specifically, the aforementioned time window weight coefficient is used to measure the importance of different time windows in the overall analysis, allowing the calculation to adapt to the time distribution characteristics of traffic; the traffic variation coefficient reflects the dispersion of traffic data itself, capturing the fluctuation of traffic size; the traffic burst delay coefficient focuses on the delay characteristics during traffic bursts, as abnormal intrusions may change the delay pattern; the traffic historical trend correlation coefficient correlates the current traffic with historical trends to determine whether it deviates from the normal historical pattern; the traffic burst pattern similarity coefficient compares the similarity of traffic burst patterns to identify abnormal bursts; the traffic smoothness coefficient reflects the smoothness of traffic transmission, as intrusions may disrupt smoothness; the traffic time offset coefficient considers the offset of traffic in the time dimension; the packet priority influence coefficient incorporates the effect of packet priority on traffic, as abnormal priority adjustments may imply intrusion; the traffic seasonal fluctuation coefficient adapts to the periodic changes in traffic caused by seasonal factors; and the network neighbor node traffic influence coefficient considers the impact of neighbor node traffic on the current traffic, as intrusion into neighbor nodes may transmit abnormalities.
[0096] In summary, the index values of traffic status dimension indicators can be calculated comprehensively and in detail, laying the foundation for subsequent traffic intrusion detection from the perspective of traffic fluctuation.
[0097] In one exemplary embodiment, such as Figure 5As shown, based on the traffic protocol information of the raw traffic data, the traffic protocol dimension indicators are determined, including:
[0098] S510 retrieves the preset standard protocol usage mode, which represents the relevant parameters of the communication protocol in normal traffic within the preset historical window.
[0099] The preset standard protocol usage mode is based on the relevant parameters of the communication protocol extracted from historical normal traffic, including but not limited to the expected frequency, frequency variance, protocol stability, protocol latency, etc. of historical normal protocols.
[0100] S520 determines the traffic protocol dimension index based on the degree of deviation between the traffic protocol information and the standard protocol usage mode, as well as the preset protocol characteristic coefficients. The traffic protocol dimension index is used to reflect the abnormal characteristics of the communication protocol in the original traffic data.
[0101] In this embodiment of the application, the traffic protocol dimension index β is calculated by fusing the aforementioned deviation level with a preset protocol feature coefficient to obtain the aforementioned traffic protocol dimension index, as follows:
[0102]
[0103] in, The protocol frequency is calculated directly by counting the number of data packets (or bytes) corresponding to the protocol within a set time window and comparing them with the total number of data packets (or bytes) within the window. The expected frequency of this protocol in historical normal traffic can be obtained by: extracting the historical normal traffic dataset, calculating the average frequency of this protocol under the same time period and business scenario, and using this average as the expected frequency. In summary, the expected frequency can be obtained through f. s and f e The above-mentioned degree of deviation was calculated, and b is the characteristic coefficient of the above-mentioned protocol.
[0104] Furthermore, the protocol characteristic coefficients include, but are not limited to, the following coefficients: This is the historical stability coefficient of the protocol. This coefficient is based on the frequency of the protocol in historical normal traffic. The variance of the frequency (reflecting the degree of fluctuation) is calculated and then normalized to obtain the stability coefficient (the closer the value is to 1, the more stable the protocol frequency). The historical stability coefficient of the protocol can be obtained by taking the frequency data of the protocol in the same scenario and time period in the historical normal traffic, calculating the mean and variance of these data (the variance reflects the degree of frequency fluctuation), and then performing normalization processing. The protocol response latency coefficient is calculated by taking the response latency of the protocol session in the current traffic (such as TCP round-trip time (RTT) or HTTP request-response time) and calculating its deviation rate from the historical average normal response latency. To use a difference coefficient for protocol options, parse the header option fields of the protocol in the current traffic (such as TCP window scaling and timestamp options), count the type and frequency of the options, and then compare them with the option characteristics of the protocol in historical normal traffic. The difference coefficient is obtained by calculating the difference using the cosine similarity algorithm. The service quality correlation coefficient is calculated by extracting the service quality parameters corresponding to the protocol in the current traffic, such as the IP's DSCP (Differentiated Services Code Point) field, QoS (Quality of Service) level, etc., statistically analyzing their distribution characteristics, and then performing a matching degree calculation (such as chi-square test) with the distribution of the service quality parameters of the protocol in historical normal traffic. The complement of the matching degree (1-matching degree) is the coefficient. The protocol user behavior correlation coefficient is calculated by collecting the behavioral characteristics of the user's IP, access port, and interaction duration currently using the protocol, performing clustering judgment with the behavioral characteristics database of historical normal users, calculating the distance between the current behavior and the normal cluster, and then normalizing the distance value to obtain the protocol user behavior correlation coefficient. The coefficient of variation (COP) is calculated by parsing encryption-related fields of the protocol in the current traffic, such as the TLS (Transport Layer Security) version and cipher suite, comparing them with the encryption configuration of the protocol in historical normal traffic, and then calculating the percentage of mismatches. To determine the protocol encryption method variation coefficient, we analyze the encryption-related fields of the target protocol in the current traffic (such as the TLS protocol version number, cipher suite type, and IPsec encryption algorithm identifier), and statistically analyze the actual configuration of these fields. We then retrieve the encryption configuration baseline (i.e., commonly used versions, suites / algorithms, etc.) for this protocol from historical normal traffic. Finally, we calculate the proportion of items in the current encryption configuration that do not match the baseline out of the total configuration items; this proportion is the protocol encryption method variation coefficient. The protocol session state transition coefficient is used for stateful protocols (such as TCP). It records the current session's state transition process, compares it with the protocol's standard state machine flow, and counts the number of abnormal state transitions. The number of abnormal transitions divided by the total number of state transitions is used as the protocol session state transition coefficient, representing the protocol traffic fingerprint difference. The coefficient is used to extract the fingerprint features of the current protocol traffic (such as packet length distribution, interaction time interval, and port combination), and perform hash similarity calculation with the fingerprint features of the protocol in historical normal traffic, using "1-similarity" as the difference coefficient.
[0105] In this embodiment, at least one coefficient can be selected from the above-mentioned multiple protocol feature coefficients according to actual needs, and the selected protocol feature coefficient is multiplied by the degree of deviation to obtain the index value of the above-mentioned traffic protocol dimension index.
[0106] In this embodiment, protocol-level anomalies in communication traffic are detected by the degree of protocol deviation. First, two key basic data are defined: the currently collected protocol frequency and the expected frequency of the protocol in historical normal traffic. The deviation of the current protocol frequency from the historical normal state is measured by the ratio of the difference between these two data to the expected frequency.
[0107] The aforementioned protocol historical stability coefficient assesses the stability of the protocol during its historical operation. Abnormal frequency fluctuations in a stable protocol are more likely to indicate intrusion. The protocol response latency coefficient focuses on the response latency during protocol transmission; intrusion may cause abnormal latency fluctuations. The protocol option usage difference coefficient reflects the difference between protocol option usage and the normal mode; abnormal option usage may be an intrusion tactic. The protocol service quality correlation coefficient correlates the protocol with service quality; abnormal service quality may stem from protocol tampering. The protocol user behavior correlation coefficient combines user behavior analysis with the protocol; unauthorized user behavior can cause protocol frequency deviations. The protocol encryption method variation coefficient detects abnormal changes in the protocol encryption method; intrusion may involve tampering with encryption to conceal malicious behavior. The protocol session state transition coefficient considers the rationality of protocol session state transitions; abnormal transitions may trigger intrusion. The protocol traffic fingerprint difference coefficient compares traffic fingerprint differences; abnormal fingerprints indicate abnormal protocol transmission. Therefore, by comprehensively calculating these coefficients, we can accurately capture the deviation of the protocol from its normal state in terms of frequency and multiple characteristic dimensions. In the future, traffic protocol dimension indicators can be combined with other indicators to provide key protocol-level evidence for judging whether communication traffic contains intrusion behavior, thus contributing to the accuracy and comprehensiveness of intrusion detection from a protocol perspective.
[0108] In one exemplary embodiment, such as Figure 6 As shown, based on the terminal interaction information of the raw traffic data, the terminal interaction dimension indicators are determined, including:
[0109] S610: Obtain the preset correlation coefficient, which represents the interaction between terminals.
[0110] The correlation coefficient mentioned above can be at least one of the following coefficients: The IP interaction weight coefficient is set according to the business priority corresponding to the IP interaction (such as the interaction weight between the server and the core terminal being high). The weight value is set manually or through training with historical abnormal data (such as the IP corresponding to abnormal interaction being weighted higher). The weight value is usually between 0 and 1. The IP geographic location correlation coefficient is calculated by querying the geographic locations (e.g., city, latitude and longitude) of source IPs and destination IPs in an IP address database, and then calculating the normalized value of their geographic distance (the greater the distance, the smaller the coefficient). Alternatively, it can be calculated by statistically analyzing the historical percentage of interactions between IPs in the same region. The current IP's geographic location matching degree is used as the coefficient for the IP geographic location correlation coefficient. To calculate the IP group interaction coefficient, IPs are categorized by business groups (such as office groups, server groups). The average interaction frequency between the source IPs and the destination IPs in historical normal traffic is calculated, and the IP group interaction coefficient is obtained using the current interaction frequency. The IP port correlation coefficient is calculated by statistically analyzing the port combinations used by the current IP pair (s, d) and querying the probability of that port combination appearing in historical normal traffic. The IP port correlation coefficient is calculated as 1 minus the historical probability. The IP routing path difference coefficient is calculated by using the traceroute tool to obtain the routing path nodes of the current IP pair (s,d), comparing them with the historical routing paths of the same IP pair, and then calculating the percentage of different nodes. This is the IP network topology fitness coefficient. Based on the current network topology (such as the subnet and layer where the IP resides), it determines whether the interaction between IP pairs (s, d) conforms to topology rules (e.g., IPs without cross-subnet interaction permissions communicating across subnets). If it conforms, the IP network topology fitness coefficient is 0; otherwise, it is normalized to a range of 0-1 according to the degree of violation. The IP session duration coefficient is calculated by comparing the duration of the current IP pair (s,d) session with the average session duration of the same IP pair in history, and taking the deviation rate as the IP session duration coefficient. To determine the IP network topology adaptability coefficient, the current network topology is defined (e.g., using network topology management tools to determine the subnet, VLAN (Virtual Local Area Network), device level, and preset communication rules for each IP, such as allowing office subnet IPs to only interact with IPs within the same subnet or designated server subnets). Then, the positions of source IPs and destination IPs within the topology are located, and their interaction is checked to ensure it conforms to the preset topology communication rules (e.g., interaction across unauthorized subnets or across levels is considered non-compliant). Finally, the degree of violation is quantified: if the rules are fully met, the IP network topology adaptability coefficient is 0; if there is a minor violation, the coefficient is 0.5; if there is a serious violation (e.g., unauthorized interaction between the core network and external subnets), the coefficient is 1. The interaction coefficient for the autonomous system to which the IP belongs is obtained by querying the autonomous systems (AS) to which the source IPs and destination IPs belong using WHOIS queries, calculating the interaction frequency of each AS pair in historical normal traffic, and dividing the current interaction frequency by the historical frequency. This is the IP geographic group migration coefficient, which tracks the historical geographic group of an IP (such as long-term affiliation with a certain city network segment). If the current geographic group of an IP does not match the historical group, the IP geographic group migration coefficient is 1; if they match, the IP geographic group migration coefficient is 0.
[0111] In this embodiment of the application, at least one coefficient can be selected from the above multiple correlation coefficients according to actual needs, and the selected correlation coefficient can be integrated with the interaction probability, the number of source terminal addresses, and the number of target terminal addresses to obtain the index value of the above terminal interaction dimension index.
[0112] S620, determine the number of source terminal addresses and the number of target terminal addresses in the raw traffic data, as well as the interaction probability between each source terminal address and its corresponding target terminal address within a preset time window.
[0113] S630 determines the terminal interaction dimension indicators based on the interaction probability, the number of source terminal addresses, the number of target terminal addresses, and the correlation coefficient.
[0114] The calculation of the terminal interaction dimension indicator γ is as follows:
[0115]
[0116] Among them, s mm d represents the number of source IP terminal addresses. mm For the number of target IP terminal addresses, the above s mm and d mmThe number of different IP addresses appearing within the current time window can be directly counted to obtain the result. The above q s,d The probability of interaction between the source terminal address and the target terminal address can be calculated in practice by counting the number of interactions between the source IP and the target IP within a set time window and dividing it by the total number of interactions between all IP pairs in that window. The interaction probability between the two can be obtained. c is the correlation coefficient mentioned above. After determining at least one correlation coefficient, the correlation coefficient can be substituted into the above formula to obtain the index value of the terminal interaction dimension index mentioned above.
[0117] In this embodiment, basic data is first determined, namely the interaction probability between the source terminal address and the target terminal address, and the number of source terminal addresses and the number of target terminal addresses are also specified. Then, at least one correlation coefficient is introduced to comprehensively characterize various characteristics of IP interactions as much as possible. The aforementioned IP interaction weight coefficient is used to measure the importance of different IP interactions in the overall analysis, highlighting the impact of key interactions. The IP geographic location correlation coefficient considers the role of the IP's geographic location on the interaction; abnormal cross-regional interactions may imply risks. The IP group interaction coefficient focuses on the interaction patterns between IP groups; abnormal interactions within a group may be a sign of intrusion. The IP port correlation coefficient reflects the correlation between IP port usage and interaction; abnormal port usage is often accompanied by intrusion. The IP routing path difference coefficient detects differences in IP routing paths; path tampering will change this coefficient. The IP network topology adaptation coefficient reflects the compatibility between the IP and the network topology; abnormal topology changes will affect the interaction. The IP session duration coefficient incorporates the impact of session duration on the interaction; abnormal session duration may be an intrusion behavior. The IP autonomous system interaction coefficient considers IP interactions between autonomous systems; intrusion into an autonomous system will propagate anomalies. The IP geographic group migration coefficient focuses on the migration of IPs between geographic groups; abnormal migration may be malicious behavior.
[0118] In summary, this embodiment can determine whether there is intrusion behavior in communication traffic from the perspective of terminal interaction indicators at the IP interaction level, thereby improving the accuracy and comprehensiveness of intrusion detection from the perspective of IP interaction and accurately identifying network security threats caused by abnormal IP interaction.
[0119] In one exemplary embodiment, communication behavior dimension metrics are determined based on the communication behavior of the raw traffic data, including:
[0120] Based on various communication behaviors in the raw traffic data, determine the corresponding anomaly coefficients;
[0121] The communication behavior dimension indicators are determined based on the anomaly coefficient.
[0122] Communication behavior refers to the data packet transmission status and data information of the data packets themselves (such as data packet length and data packet type) in the raw traffic data. The above-mentioned communication behavior dimension indicators are composed of at least one of the following anomaly coefficients: data packet length variation coefficient. The mean and standard deviation of data packet lengths within the current time window are statistically analyzed. The coefficient of variation of data packet length and the traffic direction asymmetry coefficient are then calculated using the standard deviation. The difference between the number of bytes sent and received in the same session is statistically analyzed. The ratio of |number of bytes sent - number of bytes received| / total number of bytes is used to obtain the traffic direction asymmetry coefficient and the traffic port distribution entropy coefficient. The usage frequency of each port within the current window is statistically analyzed and substituted into the entropy calculation formula. A higher entropy value indicates more disordered port usage; the coefficient of variation of traffic packet intervals is also analyzed. Calculate the mean and standard deviation of the data packet transmission interval, and obtain the coefficient of variation of the packet interval and the coefficient of variation of the data byte rate by dividing the standard deviation by the mean. The mean and standard deviation of the byte transfer rate per unit time are statistically analyzed. The coefficient of variation of the byte rate is calculated by dividing the standard deviation by the mean, which reflects the degree of rate fluctuation and the distribution coefficient of the data packet type. The percentage of different data packets within the current window is statistically analyzed and compared with the historical normal percentage. The percentage deviation is then calculated as the traffic packet type distribution coefficient and the traffic session creation rate coefficient. The number of newly created sessions per unit time is counted, and the traffic session creation rate coefficient is obtained by comparing it with the historical average normal session creation rate.
[0123] Furthermore, the aforementioned packet length variation coefficient reflects the dispersion of packet length. Normal traffic packet lengths typically have a reasonable distribution, while intrusions may increase length variation. The traffic direction asymmetry coefficient focuses on the symmetry of traffic transmission direction; abnormal unidirectional traffic surges may indicate intrusion. The traffic port distribution entropy coefficient reflects the disorder of port usage; malicious scanning or occupation of ports will change this coefficient. The traffic packet interval variation coefficient considers the variation in packet transmission intervals; abnormal intervals may indicate intrusion interfering with transmission timing. The traffic byte rate variation coefficient detects fluctuations in byte transmission rate; abnormal rate fluctuations may imply malicious data transmission. The traffic packet type distribution coefficient reflects the distribution characteristics of packet types; abnormal type distribution may indicate protocol tampering or illegal packet injection. The traffic session creation rate coefficient focuses on the frequency of session creation; abnormally high session creation rates may indicate intrusion behaviors such as brute-force attacks.
[0124] Among them, the above data packet length variation coefficient The calculations are as follows:
[0125]
[0126] in, The average interval of the current data packets is calculated by summing the time intervals of all adjacent data packets within a set time window and dividing by the number of intervals. To determine the average expected length of historical normal traffic packet intervals, we extract packet interval data under the same time period and business scenario from the historical normal traffic dataset and calculate its average value as the historical expected length. This is a data packet length sensitivity coefficient, manually set according to the sensitivity of the business scenario. For example, for businesses sensitive to packet length changes, such as file transfer, the coefficient is set to 1.2; for businesses not sensitive, such as ordinary web browsing, the coefficient is set to 0.8. Alternatively, it can be assigned a coefficient between 0 and 1.5 based on the historical proportion of intrusion incidents caused by abnormal packet lengths, with the coefficient varying according to the proportion. The packet length distribution morphology coefficient is calculated by statistically analyzing the current packet length distribution (e.g., normal or skewed distribution), then comparing it with the packet length distribution of historical normal traffic (e.g., using KL divergence), and finally using 1 - similarity as the packet length distribution morphology coefficient. The jitter coefficient is calculated by taking the variance of the current packet length to reflect the degree of jitter, and then dividing the current variance by the variance of the historical normal packet length. The packet length segmentation difference coefficient is calculated by dividing the packet length into segments (e.g., 0-100 bytes, 101-500 bytes), calculating the current traffic percentage of each segment, comparing it with the corresponding segment percentage of historical normal traffic, and calculating the average deviation of each segment percentage. This average deviation is then used as the packet length segmentation difference coefficient. This is the correlation coefficient between packet length and protocol. It queries the standard packet length range for the corresponding protocol (e.g., the typical packet length range for TCP). If the current packet length falls within this range, the coefficient is set to 0; otherwise, it is normalized to between 0 and 1 based on the degree of deviation. The packet length multi-flow comparison coefficient is calculated by collecting the average packet length of other normal traffic flows within the same time period, and then calculating the deviation rate (i.e., |current average - normal average| / normal average) between the current flow's average packet length and these normal flow averages. This deviation rate is the packet length multi-flow comparison coefficient. In summary, the packet length variation coefficient is calculated to measure abnormal fluctuations in packet length in communication traffic. First, the average value of the currently collected packet interval and the average expected length of the historical normal traffic packet interval are determined. The difference between these two values is then calculated and compared with L. e The ratio of the current data packet interval to the historical normal state is used to determine the deviation of the current data packet interval from the historical normal state.
[0127] Furthermore, the packet length sensitivity coefficient measures the system's sensitivity to changes in packet length; in sensitive systems, even minor length changes may reflect anomalies. The packet length distribution morphology coefficient focuses on the morphological characteristics of packet length distribution, such as whether it is a normal or skewed distribution; abnormal distribution morphology may indicate intrusion. The packet length jitter coefficient captures the jitter of packet length; abnormal jitter often indicates traffic interference. The packet length segment difference coefficient reflects the difference in packet length across different segments; abnormal segment differences may indicate malicious data injection. The packet length-protocol correlation coefficient considers the correlation between packet length and protocol; when the protocol is tampered with, the correlation between length and protocol will change. The packet length multi-stream comparison coefficient compares the current packet length with multi-stream data; abnormal lengths in multi-stream data may indicate intrusion.
[0128] The above-mentioned port distribution entropy coefficient The calculations are as follows:
[0129]
[0130] in, To determine the usage frequency of port p, count the number of data packets or sessions using port p within a set time window, then divide this number by the total number of data packets across all ports within the window to obtain the port's usage frequency. For port count, it directly counts the total number of all different ports appearing within the current time window. The port security risk coefficient is set based on a publicly available port security risk database (such as a list of high-risk ports and commonly used malicious ports). For example, the risk coefficient for high-risk ports is set to 0.9-1.0, for ordinary business ports to 0.2-0.5, and for ports that are not widely used to 0.1-0.3. The coefficient of variation for port-related services is calculated by querying the standard associated services for port p (e.g., HTTP for port 80), counting the actual service types carried by that port in the current traffic, and comparing the matching degree with the standard services. 1 - matching degree is used as the coefficient of variation for port-related services. This is the coefficient of variation for the port-to-protocol mapping. We obtain the standard protocol mapping for port p (e.g., port 443 corresponds to HTTPS), and parse the actual protocol used by that port in the current traffic. If it matches the standard mapping, the coefficient is 0; otherwise, it is normalized to between 0 and 1 according to the degree of deviation. The port traffic quality coefficient is calculated by statistically analyzing the proportion of abnormal packets (such as malformed packets and retransmission packets) in the traffic corresponding to port p. Combined with indicators such as packet loss rate and latency, these indicators are weighted and normalized to obtain the port traffic quality coefficient.
[0131] The port security risk coefficient mentioned above is used to measure the degree of security risk inherent in different ports. Abnormal use of high-risk ports requires more attention. The port-associated service variation coefficient focuses on whether the service associated with the port has changed. Service abnormalities are often accompanied by abnormal port usage. The port-to-protocol mapping variation coefficient reflects the variation of the mapping relationship between the port and the protocol. Under normal circumstances, the port-to-protocol mapping is relatively stable, but intrusion may tamper with this mapping. The port traffic quality coefficient considers the quality of the traffic transmitted by the port. Traffic quality abnormalities (such as packet loss, out-of-order delivery, etc.) will be reflected in this coefficient.
[0132] In summary, at least one anomaly coefficient can be selected according to actual needs, and the selected anomaly coefficient can be used as a communication behavior dimension indicator.
[0133] In an exemplary embodiment, a corresponding fusion result is calculated based on multi-dimensional intrusion detection indicators, and the detection result of the original traffic data is determined based on the fusion result, including:
[0134] Determine the weight of each indicator in the multi-dimensional intrusion detection metrics;
[0135] Based on the weights corresponding to each indicator, the indicators are weighted and summed to obtain the fusion result;
[0136] If the fusion result meets the preset anomaly detection conditions, the detection result is obtained, which indicates that the original traffic data has abnormal behavior.
[0137] In this embodiment, the weights corresponding to each indicator are first determined. The weights are used to measure the importance of different indicators in the comprehensive abnormal behavior calculation. They can be adjusted according to the actual network environment and security requirements. For example, if the network often faces protocol-level attacks, higher weights are assigned to traffic protocol dimension indicators. If the IP interaction risk is high, higher weights are assigned to terminal interaction dimension indicators. The weights are set by the operation and maintenance or relevant technical personnel. For example, the weight of the core indicator is set to 0.2, and the weight of the secondary indicator is set to 0.05.
[0138] The fusion result S is obtained by weighting and summing the various indicators based on their weights.
[0139]
[0140] in, The values of the above traffic status dimension indicators are: The values for the above traffic protocol dimension metrics are as follows: Let d be the indicator value of the aforementioned terminal interaction dimension indicator, and let d be the indicator value of the aforementioned communication behavior dimension indicator. As can be understood, as mentioned above, the communication behavior dimension indicator is determined by at least one selected abnormal coefficient. By merging all abnormal coefficients, the aforementioned d can be obtained. Furthermore, the abnormal coefficients can also be weighted and summed based on preset weights.
[0141] The anomaly detection condition is as follows: if the value of the fusion result is greater than the preset anomaly threshold, it is determined that there is abnormal behavior in the original traffic data, and an alarm is triggered so that it can be intercepted and processed in a timely manner; if it is lower than the threshold, it indicates that all dimensions of characteristics conform to the normal communication mode and is judged as normal traffic. In this way, communication traffic intrusion is detected from multiple links and systematically to ensure network security.
[0142] This application also provides a preferred embodiment of a network intrusion detection method, such as... Figure 7 The diagram shown is a flowchart of a network intrusion detection method in one embodiment.
[0143] S710, acquire raw traffic data;
[0144] S720 determines the indicator values of the traffic status dimension indicators based on the traffic status information of the raw traffic data;
[0145] S730 determines the indicator values of traffic protocol dimension indicators based on the traffic protocol information of the raw traffic data;
[0146] S740 determines the indicator values of terminal interaction dimension indicators based on the terminal interaction information of the raw traffic data.
[0147] S750 determines the indicator values of communication behavior dimension indicators based on the communication behavior of the raw traffic data;
[0148] S760 obtains the multi-dimensional intrusion detection index values based on the index values of traffic status dimension index, traffic protocol dimension index, terminal interaction dimension index, and communication behavior dimension index.
[0149] The S770 compares the values of multi-dimensional intrusion detection indicators with preset thresholds. If an indicator value is found to be greater than the preset threshold, it determines that there is abnormal behavior in the original traffic data and triggers an alarm.
[0150] By comprehensively considering multiple dimensions such as traffic fluctuations, protocols, terminal interactions, and data packet information, the indicators of traffic status dimension can be calculated to capture the complex patterns of dynamic traffic changes; by calculating the indicators of traffic protocol dimension, abnormal deviations in protocol usage can be identified; by calculating the indicators of terminal interaction dimension, the disorder of IP interaction mode can be focused; and by calculating the indicators of communication behavior dimension, anomalies can be deeply explored from the details of data packets and port distribution.
[0151] In summary, by combining multiple indicators from different dimensions, more accurate anomaly calculation results can be obtained, effectively reducing the probability of misjudgment and missed judgment, and accurately distinguishing between normal traffic fluctuations and real intrusion behavior.
[0152] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0153] Based on the same inventive concept, this application also provides an intrusion detection device for implementing the intrusion detection method described above. The solution provided by this device is similar to the implementation described in the above method; therefore, the specific limitations in one or more intrusion detection device embodiments provided below can be found in the limitations of the intrusion detection method described above, and will not be repeated here.
[0154] In one exemplary embodiment, such as Figure 8 As shown, an intrusion detection device is provided, comprising:
[0155] Module 81 is used to acquire raw traffic data;
[0156] The calculation module 82 is used to calculate the corresponding multi-dimensional intrusion detection index values based on the raw traffic data. The multi-dimensional intrusion detection index includes traffic status dimension index, traffic protocol dimension index, terminal interaction dimension index, and communication behavior dimension index in the raw traffic data.
[0157] The generation module 83 is used to determine the fusion result of the indicator values of traffic status dimension indicators, traffic protocol dimension indicators, terminal interaction dimension indicators and communication behavior dimension indicators, and to determine the detection result of the original traffic data based on the fusion result.
[0158] Each module in the aforementioned intrusion detection device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in the processor of a computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the corresponding operations of each module.
[0159] The aforementioned intrusion detection device can also implement any of the intrusion detection methods described above.
[0160] In one exemplary embodiment, a computer device is provided, including a memory and a processor, the memory storing a computer program that, when executed by the processor, implements any of the intrusion detection methods described above.
[0161] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements any of the intrusion detection methods described above.
[0162] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements any of the intrusion detection methods described above.
[0163] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.
[0164] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0165] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A network intrusion detection method, characterized in that, The method includes: Obtain raw traffic data; Based on the raw traffic data, the corresponding multi-dimensional intrusion detection index values are calculated; the multi-dimensional intrusion detection index includes traffic status dimension index, traffic protocol dimension index, terminal interaction dimension index, and communication behavior dimension index in the raw traffic data. The fusion result of the indicator values of the traffic status dimension indicator, the traffic protocol dimension indicator, the terminal interaction dimension indicator, and the communication behavior dimension indicator is determined, and the detection result of the original traffic data is determined based on the fusion result.
2. The method according to claim 1, characterized in that, The step of calculating the corresponding multi-dimensional intrusion detection index values based on the original traffic data includes: Based on the traffic status information of the original traffic data, the index value of the traffic status dimension index is determined, and the traffic status dimension index characterizes the fluctuation of the original traffic data. Based on the traffic protocol information of the original traffic data, the index value of the traffic protocol dimension index is determined. The traffic protocol dimension index characterizes the deviation between the protocol usage pattern of the original traffic data and the obtained standard protocol usage pattern. Based on the terminal interaction information of the raw traffic data, the index value of the terminal interaction dimension index is determined; the terminal interaction dimension index characterizes the terminal interaction status of the raw traffic data. Based on the communication behavior of the raw traffic data, determine the index value of the communication behavior dimension index; The multi-dimensional intrusion detection index value is obtained based on the index values of the traffic status dimension index, the traffic protocol dimension index, the terminal interaction dimension index, and the communication behavior dimension index.
3. The method according to claim 2, characterized in that, The step of determining the index value of the traffic status dimension index based on the traffic status information of the original traffic data includes: Define the preset time window; Within the time window, determine the probability of each type of traffic fluctuation state occurring, as well as the number of types of traffic fluctuation states. Based on the probability and number of occurrences of the traffic fluctuation state and the preset traffic fluctuation coefficient, the index value of the traffic state dimension index is calculated. The traffic state dimension index is used to reflect the characteristics of various traffic flows within the time window.
4. The method according to claim 2, characterized in that, The step of determining the indicator value of the traffic protocol dimension indicator based on the traffic protocol information of the original traffic data includes: Obtain the preset standard protocol usage mode, which represents the relevant parameters of the communication protocol in normal traffic within the preset historical window; Based on the degree of deviation between the traffic protocol information and the standard protocol usage mode, and the preset protocol characteristic coefficient, the index value of the traffic protocol dimension index is determined. The traffic protocol dimension index is used to reflect the abnormal characteristics of the communication protocol in the original traffic data.
5. The method according to claim 2, characterized in that, The step of determining the indicator value of the terminal interaction dimension indicator based on the terminal interaction information of the original traffic data includes: Obtain a preset correlation coefficient, which represents the interaction between terminals; Determine the number of source terminal addresses and the number of target terminal addresses in the original traffic data, as well as the interaction probability between each source terminal address and its corresponding target terminal address within a preset time window; The indicator value of the terminal interaction dimension indicator is determined based on the interaction probability, the number of source terminal addresses, the number of target terminal addresses, and the correlation coefficient.
6. The method according to claim 2, characterized in that, The step of determining the index value of the communication behavior dimension index based on the communication behavior of the original traffic data includes: Based on the various communication behaviors in the raw traffic data, the corresponding anomaly coefficients are determined; The index value of the communication behavior dimension index is determined based on the anomaly coefficient.
7. The method according to any one of claims 1 to 6, characterized in that, The step of calculating the corresponding fusion result based on the multi-dimensional intrusion detection indicators and determining the detection result of the original traffic data based on the fusion result includes: Determine the weight of each indicator in the multi-dimensional intrusion detection index; Based on the weights corresponding to each indicator, the values of each indicator are weighted and summed to obtain the fusion result; If the fusion result is found to meet the preset anomaly detection conditions, the detection result is obtained, which indicates that the original traffic data has abnormal behavior.
8. A network intrusion detection device, characterized in that, The device includes: The acquisition module is used to acquire raw traffic data; The calculation module is used to calculate the corresponding multi-dimensional intrusion detection index values based on the original traffic data; the multi-dimensional intrusion detection index includes traffic status dimension index, traffic protocol dimension index, terminal interaction dimension index and communication behavior dimension index in the original traffic data. The generation module is used to determine the fusion result of the indicator values of the traffic status dimension indicator, the traffic protocol dimension indicator, the terminal interaction dimension indicator, and the communication behavior dimension indicator, and to determine the detection result of the original traffic data based on the fusion result.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.