IDC network security protection system and method based on abnormal traffic detection
Patent Information
- Application Number
- CN202610867661.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-16
- Publication Date
- 2026-09-15
Smart Images

Figure CN122764587A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data center network security technology, specifically to an IDC network security protection system and method based on abnormal traffic detection. Background Technology
[0002] With the deep integration of cloud computing, big data and 5G technologies, Internet Data Centers (IDCs), as key information infrastructure of the digital economy, carry the flow, storage and processing of massive heterogeneous business data. Network attacks targeting IDCs show a significant trend of increasingly complex attack vectors, disguised attack payloads and slower attack pace.
[0003] Traditional IDC network security protection systems mainly rely on anomaly detection methods based on traffic statistics, such as monitoring macro indicators like traffic rate mutations, connection thresholds, and packet length distribution, or deep packet inspection rule matching based on known attack signatures. However, when facing constructed modern network threats, there are blind spots in microstructure detection. Traditional methods focus on the statistical behavior of traffic, while ignoring the micro anomalies within individual data packets in terms of protocol state, payload structure, and option arrangement. Attackers can exploit this blind spot to perform low-rate data leakage, covert channel communication, or protocol stack fingerprinting by subtly altering the internal structure of data packets, while mimicking normal traffic statistical distribution. Such attacks are invisible in the macro statistical view but continuously erode the core assets of the IDC.
[0004] Furthermore, existing solutions lack the ability to represent the intrinsic correlation of multi-dimensional features. The protocol behavior, payload entropy change, and option combination of data packets are not isolated from each other, but together constitute a structured logical chain that represents the intent of the data packet. Traditional feature engineering methods treat each dimension feature as an independent variable input to the classifier, severing the spatial location correlation and logical temporal constraints between dimensions, so that attackers only need to perform compliance disguise on a certain isolated dimension to bypass detection.
[0005] Therefore, there is an urgent need for a new IDC network security protection mechanism that can penetrate macroscopic statistical appearances, start from the internal microstructure of a single data packet, and capture the logical relationships of multi-dimensional features. Summary of the Invention
[0006] The purpose of this invention is to overcome the shortcomings of existing technologies and provide an IDC network security protection system and method based on abnormal traffic detection. This system consists of a traffic capture and parsing module, a feature encoding module, a behavior learning module, a sequence alignment module, and a protection execution module. The system performs deep analysis on individual data packets, extracting multi-dimensional protocol state features, payload structure entropy values, and option field arrangements. These are encoded into state bases, entropy bases, and option bases respectively through a preset feature-base mapping table, and then spliced together according to spatial interleaving logic to generate a unique data packet gene map characterizing the internal structure of the data packet. During the learning phase, a reference genome is constructed based on the compliant traffic map. During the real-time detection phase, the gene deviation between the query gene map sequence and the reference gene map sequence is calculated. When the gene deviation exceeds the structural entropy mutation threshold, the protection execution module precisely blocks and alerts the data packet and its associated session, deepening the anomaly identification capability to the microstructure level of a single packet, achieving high-precision judgment of advanced threats such as protocol spoofing and covert channels.
[0007] To solve the above-mentioned technical problems, the present invention provides the following technical solution: On the one hand, an IDC network security protection system based on abnormal traffic detection, the system comprising: a traffic capture and parsing module, a feature encoding module, a behavior learning module, a sequence comparison module, and a protection execution module; The traffic capture and parsing module is used to capture real-time traffic entering the IDC and perform deep parsing on individual packets in the real-time traffic to extract multi-dimensional protocol state features, payload structure entropy values, and option field arrangements of individual packets. The feature encoding module receives the multi-dimensional protocol status features, payload structure entropy value and option field arrangement output by the traffic capture and parsing module. Based on the preset feature-base mapping table, it encodes each feature into the corresponding network base and splices all network bases according to spatial interleaving logic to generate a unique data packet gene map that characterizes the internal structure of the single data packet. The behavior learning module includes an initial learning unit and a normal gene bank unit. The initial learning unit is used to receive only the data packet gene map generated by compliant business traffic during the system initialization learning phase. It clusters the data packet gene map generated by compliant business traffic through a deep clustering algorithm, removes outlier maps, and then combines the data packet gene maps of all high-density clusters into a reference genome. The normal gene bank unit stores the reference genome generated by the initial learning unit. The sequence alignment module receives the data packet gene map generated by real-time traffic and performs local sequence alignment with the reference genome stored in the normal gene bank unit, and calculates the gene deviation of the data packet gene map generated by real-time traffic relative to the reference genome. The protection execution module determines that a single data packet corresponding to the data packet gene map is a micro-abnormality carrier when the gene deviation exceeds a preset structural entropy mutation threshold, and performs blocking and alarm operations on the single data packet corresponding to the data packet gene map.
[0008] Furthermore, the feature encoding module has a preset feature-base mapping table that stores the mapping relationship between specific feature combinations and specific characters. The specific feature combinations are the multidimensional protocol state features, payload structure entropy values, and option field arrangements extracted by the traffic capture and parsing module. The feature encoding module maps the multidimensional protocol state features to state bases, the payload structure entropy to entropy bases, and the option field arrangements to option bases, and splices them together in the spatial interleaving order of state bases, entropy bases, and option bases to generate the data packet gene map.
[0009] Furthermore, the multidimensional protocol state features include: the timing logic combination state of the TCP protocol header flag sequence, the continuous conversion logic of the TLS record layer content type and the handshake protocol message type, and the command and response code pairing state of the application layer protocol. The arrangement of the option fields includes: the type number, order of appearance, and field value of the optional fields in the IP header, and the option type number, order of appearance, and field value of the optional fields in the TCP header; The feature encoding module maps the multidimensional protocol state features and the logical order of the fields captured in the option field arrangement to network bases with positional constraints, so that the feature sequence determined by the protocol behavior logic maintains its original order in the data packet gene map.
[0010] Furthermore, the mapping relationship is as follows: In the multidimensional protocol state features, each sequential logical combination of the TCP protocol header flag sequence is mapped to a character, each continuous conversion logic of the TLS record layer content type and handshake protocol message type is mapped to a character, and each pairing state of the application layer protocol command and response code is mapped to a character. Each discrete quantization interval of the load structure entropy value is mapped to a character; In the arrangement of the option fields, each specific type number, order of appearance, and combination of field values for the optional fields in the IP header and TCP header are mapped to a single character.
[0011] Furthermore, the step of the behavior learning module generating the reference genome includes: During the system initialization and learning phase, only data packet gene map sample sets generated from compliant business traffic data packets are received; Calculate the sequence similarity between any two data packet gene maps in the data packet gene map sample set; Based on the sequence similarity, all data packet gene map sequences are clustered, and those with sequence similarity less than a preset density threshold are divided into low-density clusters. Outlier data packet gene maps in low-density clusters are identified as noise and removed. Sequences with similarity greater than a preset density threshold are classified into high-density clusters. The cluster center sequence and sequence members of the high-density clusters are used as reference genomes for compliant business and stored in the normal gene bank unit.
[0012] Furthermore, the sequence alignment module performs local sequence alignment as follows: The real-time generated data packet gene map is represented as the query gene map sequence. , length is ,Right now ; A reference gene map sequence in the reference genome is represented as follows: , length is ,Right now ,in, and All represent network bases; Build size is Score matrix Matrix elements Indicates and The highest score in the final local comparison is filled using a recursive formula: ,for , ,in, Network bases and The matching reward value, when equal hour The value is +1 otherwise the value is -1. The penalty for an open shot is 0.5. Take the maximum value in the matrix The gene deviation is used as the alignment score for the data packet gene map. pass Calculate, where, To query gene map sequences Compared with the reference gene sequence The highest score for a perfect match. ; When the gene deviation When the change in structural entropy exceeds the threshold, the sequence alignment module determines that the data packet contains a minor anomaly.
[0013] Furthermore, the process by which the feature encoding module maps the load structure entropy value to entropy bases includes: Divide the data packet payload into For the first equal-length block, the second equal-length block is... The first block is used to calculate the first... Byte entropy value of each block Byte entropy The calculation formula is: ,in, For the first byte values in each block Frequency of occurrence The byte length of each block is calculated to be... The entropy sequence corresponding to each block , will each The data is quantized to a preset discrete entropy value range, with each discrete entropy value range uniquely corresponding to an entropy base character, generating an entropy base sequence for the data packet. The entropy base sequence is the network base segment in the data packet gene map corresponding to the entropy dimension of the payload structure.
[0014] Furthermore, the traffic capture and parsing module is deployed at the mirror port of the IDC network switch to obtain copies of all original data packets entering the target server in a non-intrusive manner. The protection execution module works in conjunction with the border firewall. When it is determined that a single data packet corresponding to the data packet gene map is a micro-anomaly carrier, the module blocks the single data packet corresponding to the data packet gene map and the session to which the single data packet belongs on the network path of the traffic entering the target server.
[0015] On the other hand, the IDC network security protection method based on abnormal traffic detection has the following specific steps: S100: Capture real-time traffic entering the IDC, perform deep parsing on individual data packets in the real-time traffic, and extract multi-dimensional protocol state features, payload structure entropy values, and option field arrangements of individual data packets; S200. Based on the preset feature-base mapping table, the multidimensional protocol state features are mapped to state bases, the payload structure entropy value is mapped to entropy bases, the option field arrangement is mapped to option bases, and all network base units are spliced together according to the spatial interleaving order of state bases, entropy bases, and option bases to generate a unique data packet gene map that characterizes the internal structure of the single data packet. S300: The behavior learning module receives only the data packet gene map sample set generated by compliant business traffic, calculates the sequence similarity between any two data packet gene maps in the data packet gene map sample set, clusters all data packet gene maps based on the sequence similarity, and uses the cluster center map and map members of each high-density cluster as the reference genome of compliant business. S400: Receives the data packet gene map generated by real-time traffic, performs local sequence alignment with the reference genome stored in the normal gene bank unit, and calculates the gene deviation of the data packet gene map generated by real-time traffic relative to the reference genome. S500, the protection execution module determines whether the gene deviation exceeds the preset structural entropy mutation threshold. When it is determined that a single data packet corresponding to the data packet gene map is a micro-abnormality carrier, it performs blocking and alarm operations on the single data packet corresponding to the data packet gene map.
[0016] Compared with existing technologies, this IDC network security protection system and method based on abnormal traffic detection has the following advantages: I. This invention extracts the multidimensional protocol state features, payload structure entropy value, and option field arrangement of a single data packet through a traffic capture and parsing module. These are mapped to state bases, entropy bases, and option bases, respectively, and then spliced together according to spatial interleaving logic to generate a unique data packet gene map that characterizes the internal structure of the data packet. This extends the security detection granularity of data packets from the traditional traffic level down to the single-packet microstructure level. As long as an attacking data packet undergoes a small mutation in the protocol timing logic, payload structure entropy distribution, or option field combination, its data packet gene map will deviate significantly from the reference genome of legitimate services, thus being accurately captured by the sequence alignment module. This achieves single-packet-level immune recognition of micro-anomaly carriers.
[0017] Second, the sequence alignment module of this invention constructs a scoring matrix using a dynamic programming recursive formula. Under the premise of allowing local mismatches and gaps, it calculates the gene deviation between the real-time data packet gene map and the reference genome. Through matching reward values and gap penalty mechanisms, it can not only discover global sequence differences, but also accurately locate structural mutations in a specific dimension segment of the gene map and output quantifiable deviation values. It preserves the positional constraints and logical order between bases in each network, and can distinguish the different structural meanings when the same base combination appears in different positions, thus improving the rationality and interpretability of anomaly detection.
[0018] Other advantages, objectives and features of the invention will be set forth in part in the description which follows, and in part will be apparent to those skilled in the art from the following examination or study, or may be learned from the practice of the invention. Attached Figure Description
[0019] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the accompanying drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are merely some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without any creative effort.
[0020] Figure 1 This is a data flow diagram of the IDC network security protection system based on abnormal traffic detection in an embodiment of the present invention; Figure 2 This is a schematic diagram of the data packet gene map generation process in an embodiment of the present invention; Figure 3 This is a flowchart of an IDC network security protection method based on abnormal traffic detection in an embodiment of the present invention. Detailed Implementation
[0021] To better understand the above technical solutions, a detailed description of the solutions will be provided below in conjunction with the accompanying drawings and specific embodiments. Obviously, the described embodiments are merely some, not all, of the embodiments of the present invention. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0022] It should be noted that the specific values, network protocol types, threshold parameters, mapping table contents, and scenario examples described in this embodiment are all illustrative and intended only to help understand the technical solution and working principle of this invention, and do not constitute any limitation on the scope of protection of this invention. In actual deployment and application, those skilled in the art can adaptively adjust and configure the above-mentioned exemplary parameters according to factors such as the network environment, business traffic characteristics, and security policies of the IDC data center.
[0023] The IDC network security protection system based on abnormal traffic detection described in this invention is deployed in the uplink bypass of the IDC core switch to capture network traffic in a non-intrusive manner, such as... Figure 1 As shown, the system specifically includes: a traffic capture and parsing module, a feature encoding module, a behavior learning module, a sequence comparison module, and a protection execution module.
[0024] In one specific embodiment, the traffic capture and parsing module is deployed at the mirror port (SPAN port) of the IDC network switch. The IDC core switch copies a copy of all original data packets entering the target server cluster and sends it to the mirror port. The traffic capture and parsing module captures data packets on this port to obtain copies of all original data packets entering the target server in a non-intrusive manner, without causing delays or packet loss to the forwarding path of the original data packets, thus ensuring the continuity of IDC services.
[0025] During the initial learning phase of the system, a compliant reference genome is established for subsequent anomaly detection. IDC operations and maintenance personnel confirm that the network traffic is compliant business traffic, that is, normal business data that does not contain any known attacks and has no abnormal behavior. During this phase, the system only receives and processes these compliant business traffic. The initial learning unit of the behavior learning module will construct a reference genome based on the data packet gene map sample set generated by these compliant traffic using a deep clustering algorithm and store it in the normal gene library unit. After completing the initial learning, the system will switch to real-time detection mode to determine anomalies for each real-time traffic data packet entering the IDC.
[0026] like Figure 2 As shown, the traffic capture and parsing module performs deep parsing on each captured raw data packet.
[0027] The multi-dimensional protocol state features extracted from data packets by the traffic capture and parsing module specifically include: The TCP header flag sequence's temporal logic combination state: For a complete TCP session, a session state machine is maintained. For the current data packet, the traffic capture and parsing module extracts six flag bits from its TCP header: URG, ACK, PSH, RST, SYN, and FIN. The traffic capture and parsing module records the flag bit combination of the current data packet. For example, SYN=1 and ACK=0 represent a connection request. The current flag bit combination is compared temporally with the flag bit combination of the previous data packet in the same session. For example, in a standard TCP three-way handshake process, the temporal logic combination of the flag bits is: data packet 1 (SYN), data packet 2 (SYN+ACK), and data packet 3 (ACK). The traffic capture and parsing module encodes this continuous transition logic into a specific state. Combinations that do not conform to the standard protocol state transition logic will be extracted as a specific abnormal state feature.
[0028] The continuous conversion logic of TLS record layer content types and handshake protocol message types: For TLS encrypted traffic, the traffic capture and parsing module first parses the TLS record layer to obtain the content type of each TLS record. The content types include: change cipher specification, alarm, handshake, and application data. When the parsed TLS record content type is a handshake, the traffic capture and parsing module further performs deep parsing of the handshake protocol message in the record payload to obtain the specific type of the handshake protocol message. The handshake protocol message types include: client greeting, server greeting, certificate, server key exchange, client key exchange, completion, and other types conforming to the TLS protocol specification. The traffic capture and parsing module extracts the conversion order of continuously arriving TLS record content types and handshake protocol message types in the same TLS session as a core feature. In this embodiment, the continuous conversion logic sequence of a complete TLS handshake process is: handshake record, client greeting, handshake record, server greeting, handshake record, certificate, handshake record, server key exchange, handshake record, client key exchange, change cipher specification record, handshake record, completion, and application data record. The traffic capture and parsing module encodes the conversion logic sequence into a state base sequence. Any sequence that does not conform to the above standard conversion logic, such as a server greeting appearing before the client greeting is received, or application data appearing before the handshake phase is completed, is considered an abnormal protocol state feature and is extracted for subsequent base encoding.
[0029] Application layer protocol command and response code pairing status: For plaintext application layer protocols such as HTTP, the module parses request and response packets, extracts the request method and the corresponding response status code. The traffic capture and parsing module maintains a request-response pairing queue within a session and extracts the logical status of the pairing. In this embodiment, a normal request-response pairing status should be request sent, waiting, and response returned. If no response is detected that corresponds to the request, or if a response is generated only after multiple requests, these non-standard pairing statuses will be extracted as features.
[0030] The traffic capture and parsing module treats the payload portion of a data packet as a byte sequence. It first removes the network and transport layer headers to obtain the complete application layer payload. To calculate the payload structure entropy, the following operations are performed: Divide the data packet payload into In this embodiment, the block length is [number] equal-length blocks. The length is set to 32 bytes. If the last block is less than 32 bytes, zero padding will be used. For the Each block is divided into blocks, and its byte entropy value is calculated. Byte entropy The calculation formula is: ,in, For the first byte values in each block (The range of values is) The frequency of occurrence of [something] was calculated to obtain [something] with [something]. The entropy sequence corresponding to each block .
[0031] The traffic capture and parsing module parses the option fields of the IP header and TCP header respectively. For the IP header, it extracts the type number of each option, the order in which the options appear, and the specific values within the fields. For the TCP header, it similarly extracts the type number, the order in which the options appear, and the values within the fields. The traffic capture and parsing module organizes this information into an ordered list, completely preserving the original arrangement of the option fields in the data packet.
[0032] The feature encoding module receives the three-dimensional features output by the traffic capture and parsing module, and encodes them into a data packet gene map according to a preset feature-base mapping table.
[0033] In this embodiment, the mapping table is constructed as a multi-level mapping dictionary, and its mapping relationship is as follows: State base mapping: TCP flag sequence logic combination, TLS transition logic, application layer protocol request-response pairing state, each unique logical state is mapped to a unique character.
[0034] Entropy base mapping: quantizes each entropy value in the calculated load entropy value sequence to a preset discrete entropy value range.
[0035] Option base mapping: For IP / TCP option fields, each specific combination of type number, order of appearance, and field value is mapped to a single character.
[0036] After completing the mapping, the feature encoding module splices the three base sequences according to the preset state-entropy-option spatial interleaving logic, instead of aligning them position by position to form a new interleaved sequence.
[0037] During the system initialization learning phase, the behavior learning module only receives a data packet gene map sample set generated by compliant business traffic. Assuming the sample set contains M gene map sequences, the specific execution steps are as follows: Calculate the similarity between any two data packet gene map sequences. For two map sequences... and Its LCS length is denoted as Then sequence similarity : ,in, and Sequences and The length of the similarity is [0, 1], and the larger the value, the more similar the two sequences are.
[0038] Based on the calculated similarity matrix among all sample pairs, a density-based clustering algorithm is used for clustering. In this embodiment, the neighborhood radius... and minimum sample size ,Will Two spectra with a similarity greater than 0.85 are considered to be density-connected. =3 indicates that a cluster must contain at least 3 graph sequences. The algorithm iterates through all samples, searching for clusters with a radius of 3. Each sample contains core points of at least minPts samples, and density expansion is performed based on these core points to form multiple clusters. All sample points not falling into any cluster are marked as noise or outliers. All data packet genome maps marked as outliers are considered minor anomalies or rare variants in compliant operations and are removed from the reference samples. The genome sequences within all remaining high-density clusters (i.e., non-outliers), along with their cluster center sequences (the sequences within the cluster with the highest average similarity to all other members), together constitute the reference genome, which is stored in the normal gene pool unit.
[0039] The sequence alignment module receives data packets generated by real-time traffic to create gene maps (query gene map sequences). ), and compared with the reference genome (containing multiple reference gene map sequences) stored in the normal gene bank unit. In this embodiment, local sequence alignment is performed, assuming the query gene map sequence is... The length is ,Right now Suppose a reference gene map sequence in the reference genome. The length is ,Right now ,in, and Each represents a network base character.
[0040] Build size is Score matrix Matrix elements Indicates and The highest score in the final local alignment is achieved when the matrix boundaries are initialized to 0. .
[0041] for , The matrix is filled using a recursive formula. ,in, For network base matching reward function. When When a perfect match is achieved, ;when When mismatched, , To account for the penalty points for vacant positions, this embodiment is configured with... This is used to penalize insertions or deletions in the sequence. The first parameter 0 in the recursive formula indicates that local alignments can restart from any position. Through recursion, the matrix... When the matrix is filled, take the maximum value. This value is the query sequence. With reference sequence The best local alignment score between them The corresponding matrix position indicates the end of the best alignment segment.
[0042] To obtain the best local alignment score Then, the module calculates the gene deviation. ,in, For theoretically querying gene map sequences The highest possible score for a perfect match to a reference gene sequence is calculated by assigning +1 point to each base pair in this example, with no gaps. That is, the length of the query sequence and the gene deviation. The value range is [0, 1]. This indicates that the gene map of the real-time data packet completely matches a segment of the reference genome, meaning no microstructural abnormalities were found. The larger the value, the further it deviates from the normal baseline.
[0043] When the calculated gene deviation When the preset structural entropy mutation threshold is exceeded, the sequence alignment module determines that the data packet contains a micro-abnormal carrier and sends the determination result and the original information of the data packet to the protection execution module.
[0044] The protection execution module works in conjunction with the IDC boundary firewall or SDN controller. Upon receiving an alarm, the module extracts the five-tuple information (source IP, destination IP, source port, destination port, protocol type) of the abnormal data packet and dynamically generates a fine-grained flow rule. This rule instructs the boundary firewall or switch to block the data packet and its entire session along the network path leading to the target server. The protection execution module generates a detailed alarm log, including: the timestamp of the anomaly, the five-tuple information, the calculated genetic deviation, fragments of the data packet's genetic map, and the most similar fragment in the reference genome.
[0045] On the other hand, the present invention also provides an IDC network security protection method based on abnormal traffic detection, applicable to the aforementioned IDC network security protection system based on abnormal traffic detection, such as... Figure 3 As shown, the specific steps of this method are as follows: S100: Capture real-time traffic entering the IDC, perform deep parsing on individual data packets in the real-time traffic, and extract multi-dimensional protocol state features, payload structure entropy values, and option field arrangements of individual data packets; S200. Based on the preset feature-base mapping table, the multidimensional protocol state features are mapped to state bases, the payload structure entropy value is mapped to entropy bases, the option field arrangement is mapped to option bases, and all network base units are spliced together according to the spatial interleaving order of state bases, entropy bases, and option bases to generate a unique data packet gene map that characterizes the internal structure of the single data packet. S300: The behavior learning module receives only the data packet gene map sample set generated by compliant business traffic, calculates the sequence similarity between any two data packet gene maps in the data packet gene map sample set, clusters all data packet gene maps based on the sequence similarity, and uses the cluster center map and map members of each high-density cluster as the reference genome of compliant business. S400: Receives the data packet gene map generated by real-time traffic, performs local sequence alignment with the reference genome stored in the normal gene bank unit, and calculates the gene deviation of the data packet gene map generated by real-time traffic relative to the reference genome. S500, the protection execution module determines whether the gene deviation exceeds the preset structural entropy mutation threshold. When it is determined that a single data packet corresponding to the data packet gene map is a micro-abnormality carrier, it performs blocking and alarm operations on the single data packet corresponding to the data packet gene map.
[0046] In summary, the IDC network security protection system and method based on abnormal traffic detection provided by this invention encodes the microstructure of data packets into a gene map and uses sequence alignment algorithms from bioinformatics for anomaly measurement. This achieves high-precision and robust identification and protection against micro-abnormal traffic that is difficult to detect by traditional methods, effectively improving the overall network security level of IDC.
[0047] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention in any way. Although the present invention has been disclosed above with reference to preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or alterations to the above-disclosed technical content to create equivalent embodiments without departing from the scope of the present invention. Any simple modifications, equivalent changes and alterations made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the scope of the present invention.
Claims
1. An IDC network security protection system based on abnormal traffic detection, characterized in that, The system consists of: The traffic capture and parsing module is used to capture real-time traffic entering the IDC and perform deep parsing on individual packets in the real-time traffic to extract multi-dimensional protocol state features, payload structure entropy values, and option field arrangements of individual packets. The feature encoding module encodes each feature dimension into a corresponding network base according to a preset feature-base mapping table, and splices all network bases according to spatial interleaving logic to generate a data packet gene map characterizing the internal structure of the single data packet. The behavior learning module includes an initial learning unit and a normal gene bank unit. The initial learning unit only receives data packet gene maps generated by compliant business traffic, clusters the data packet gene maps generated by compliant business traffic, and combines all high-density clusters of data packet gene maps into a reference genome. The normal gene bank unit stores the reference genome generated by the initial learning unit. The sequence alignment module receives the data packet gene map generated by real-time traffic and performs local sequence alignment with the reference genome to calculate gene deviation. The protection execution module determines that a single data packet corresponding to the gene map of the data packet is a micro-abnormality carrier when the gene deviation exceeds the preset structural entropy mutation threshold, and performs blocking and alarm operations.
2. The IDC network security protection system based on abnormal traffic detection according to claim 1, characterized in that, The feature encoding module has a preset feature-base mapping table that stores the mapping relationship between specific feature combinations and specific characters. The specific feature combinations are the multidimensional protocol state features, payload structure entropy values, and option field arrangements extracted by the traffic capture and parsing module. The feature encoding module maps the multidimensional protocol state features to state bases, the payload structure entropy to entropy bases, and the option field arrangements to option bases, and splices them together in the spatial interleaving order of state bases, entropy bases, and option bases to generate the data packet gene map.
3. The IDC network security protection system based on abnormal traffic detection according to claim 2, characterized in that, The multidimensional protocol state features include: the timing logic combination state of the TCP protocol header flag sequence, the continuous conversion logic of the TLS record layer content type and handshake protocol message type, and the command and response code pairing state of the application layer protocol. The arrangement of the option fields includes: the type number, order of appearance, and field value of the optional fields in the IP header, and the option type number, order of appearance, and field value of the optional fields in the TCP header; The feature encoding module maps the multidimensional protocol state features and the logical order of the fields captured in the option field arrangement to network bases with positional constraints, so that the feature sequence determined by the protocol behavior logic maintains its original order in the data packet gene map.
4. The IDC network security protection system based on abnormal traffic detection according to claim 2, characterized in that, The mapping relationship is as follows: In the multidimensional protocol state features, each sequential logical combination of the TCP protocol header flag sequence is mapped to a character, each continuous conversion logic of the TLS record layer content type and handshake protocol message type is mapped to a character, and each pairing state of the application layer protocol command and response code is mapped to a character. Each discrete quantization interval of the load structure entropy value is mapped to a character; In the arrangement of the option fields, each specific type number, order of appearance, and combination of field values for the optional fields in the IP header and TCP header are mapped to a single character.
5. The IDC network security protection system based on abnormal traffic detection according to claim 1, characterized in that, The steps for the behavior learning module to generate the reference genome include: During the system initialization and learning phase, only data packet gene map sample sets generated from compliant business traffic data packets are received; Calculate the sequence similarity between any two data packet gene maps in the data packet gene map sample set; Based on the sequence similarity, all data packet gene map sequences are clustered, and those with sequence similarity less than a preset density threshold are divided into low-density clusters. Outlier data packet gene maps in low-density clusters are identified as noise and removed. Sequences with similarity greater than a preset density threshold are classified into high-density clusters. The cluster center sequence and sequence members of the high-density clusters are used as reference genomes for compliant business and stored in the normal gene bank unit.
6. The IDC network security protection system based on abnormal traffic detection according to claim 1, characterized in that, The sequence alignment module performs local sequence alignment as follows: The real-time generated data packet gene map is represented as the query gene map sequence. , length is ,Right now ; A reference gene map sequence in the reference genome is represented as follows: , length is ,Right now ,in, and All represent network bases; Build size is Score matrix Matrix elements Indicated by and The highest score in the final local comparison is filled using a recursive formula: ,for , ,in, Network bases and The matching reward value, when equal hour The value is +1 otherwise the value is -1. Penalty for open shots; Take the maximum value in the matrix The gene deviation is used as the alignment score of the data packet gene map. pass Calculate, where, To query gene map sequences Compared with the reference gene sequence The highest score for a perfect match. ; When the gene deviation When the change in structural entropy exceeds the threshold, the sequence alignment module determines that the data packet contains a micro-abnormal carrier.
7. The IDC network security protection system based on abnormal traffic detection according to claim 2, characterized in that, The process by which the feature encoding module maps the load structure entropy value to entropy bases includes: Divide the data packet payload into For the first equal-length block, the second equal-length block is... The first block is used to calculate the... Byte entropy value of each block byte entropy value The calculation formula is: ,in, For the first byte values in each block Frequency of occurrence The byte length of each block is calculated to be... The entropy sequence corresponding to each block , will each The data is quantized to a preset discrete entropy value range, with each discrete entropy value range uniquely corresponding to an entropy base character, generating an entropy base sequence for the data packet. The entropy base sequence is the network base segment in the data packet gene map corresponding to the entropy dimension of the payload structure.
8. The IDC network security protection system based on abnormal traffic detection according to claim 1, characterized in that, The traffic capture and parsing module is deployed at the mirror port of the IDC network switch to obtain copies of all original data packets entering the target server in a non-intrusive manner. The protection execution module works in conjunction with the border firewall. When it is determined that a single data packet corresponding to the data packet gene map is a micro-anomaly carrier, the module blocks the single data packet corresponding to the data packet gene map and the session to which the single data packet belongs on the network path of the traffic entering the target server.
9. An IDC network security protection method based on abnormal traffic detection, applicable to the IDC network security protection system based on abnormal traffic detection as described in any one of claims 1-8, characterized in that, The specific steps of this method are as follows: S100: Capture real-time traffic entering the IDC, perform deep parsing on individual data packets in the real-time traffic, and extract multi-dimensional protocol state features, payload structure entropy values, and option field arrangements of individual data packets; S200. Based on the preset feature-base mapping table, the multidimensional protocol state features are mapped to state bases, the payload structure entropy value is mapped to entropy bases, the option field arrangement is mapped to option bases, and all network base units are spliced together according to the spatial interleaving order of state bases, entropy bases, and option bases to generate a unique data packet gene map that characterizes the internal structure of the single data packet. S300: The behavior learning module receives only the data packet gene map sample set generated by compliant business traffic, calculates the sequence similarity between any two data packet gene maps in the data packet gene map sample set, clusters all data packet gene maps based on the sequence similarity, and uses the cluster center map and map members of each high-density cluster as the reference genome of compliant business. S400: Receives the data packet gene map generated by real-time traffic, performs local sequence alignment with the reference genome stored in the normal gene bank unit, and calculates the gene deviation of the data packet gene map generated by real-time traffic relative to the reference genome. S500, the protection execution module determines whether the gene deviation exceeds the preset structural entropy mutation threshold. When it is determined that a single data packet corresponding to the data packet gene map is a micro-abnormality carrier, it performs blocking and alarm operations on the single data packet corresponding to the data packet gene map.