A network behavior identification method and device, electronic equipment and storage medium

CN122802173APending Publication Date: 2026-09-22BEIJING DUYOU INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510338900.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-20
Publication Date
2026-09-22

AI Technical Summary

Technical Problem

[0002]面对网络环境的异构性、高延迟性以及潜在的安全威胁多样性,传统的流量识别技术已难以满足需求,导致网络防护效果显著不足

Benefits of technology

[0009]采用本公开的方案,能够精准识别正常流量与恶意攻击流量,有效提升网络安全防护能力。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122802173A_ABST
    Figure CN122802173A_ABST
Patent Text Reader

Abstract

The present disclosure provides a network behavior identification method and device, electronic equipment and storage medium, relates to the technical field of network security, especially to the fields of big data, data analysis, threat detection, and can be used in application scenarios such as network attack protection. The specific implementation scheme is: generating the real-time behavior sequence of each target object according to the real-time network traffic data; inputting the real-time behavior sequence into a pre-trained behavior scoring model to obtain a behavior score; and determining the network behavior attribute of each target object according to the multi-dimensional features and the behavior score corresponding to each target object. The present scheme can accurately identify normal traffic and malicious attack traffic, and effectively improve the network security protection capability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of cybersecurity technology, particularly to the fields of big data, data analysis, and threat detection, and can be used in application scenarios such as network attack protection. Specifically, it relates to a network behavior recognition method, device, electronic device, and storage medium. Background Technology

[0002] Faced with the heterogeneity, high latency, and diverse potential security threats in the network environment, traditional traffic identification technologies are no longer sufficient to meet the needs, resulting in significantly inadequate network protection. Summary of the Invention

[0003] This disclosure provides a method, apparatus, electronic device, and storage medium for network behavior recognition.

[0004] According to a first aspect of this disclosure, a network behavior recognition method is provided, comprising: generating a real-time behavior sequence for each target object based on real-time network traffic data; inputting the real-time behavior sequence into a pre-trained behavior scoring model to obtain a behavior score; and determining the network behavior attributes of each target object based on the multi-dimensional features and behavior score corresponding to each target object.

[0005] According to a second aspect of this disclosure, a network behavior recognition device is provided, comprising: a sequence generation module for generating a real-time behavior sequence for each target object based on real-time network traffic data; a score generation module for inputting the real-time behavior sequence into a pre-trained behavior scoring model to obtain a behavior score; and an attribute determination module for determining the network behavior attributes of each target object based on the multi-dimensional features and behavior score corresponding to each target object.

[0006] According to a third aspect of this disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform any of the methods described in the embodiments of this disclosure.

[0007] According to a fourth aspect of this disclosure, a non-transitory computer-readable storage medium is provided storing computer instructions, wherein the computer instructions are used to cause the computer to perform any of the methods according to embodiments of this disclosure.

[0008] According to a fifth aspect of this disclosure, a computer program product is provided, including a computer program that, when executed by a processor, implements any of the methods according to embodiments of this disclosure.

[0009] The solution disclosed herein can accurately identify normal traffic and malicious attack traffic, effectively improving network security protection capabilities.

[0010] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0011] The accompanying drawings are provided to better understand this solution and do not constitute a limitation of this disclosure. Wherein:

[0012] Figure 1 This is a flowchart illustrating a network behavior recognition method according to an embodiment of the present disclosure;

[0013] Figure 2 This is a schematic diagram of the structure of a network behavior recognition device according to an embodiment of the present disclosure;

[0014] Figure 3 This is a schematic diagram of a scenario based on the network behavior recognition method according to an embodiment of this disclosure;

[0015] Figure 4 This is a structural diagram of an electronic device used to implement the network behavior recognition method of the embodiments of this disclosure. Detailed Implementation

[0016] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0017] In this document, the term "and / or" merely describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. The term "at least one" in this document indicates any combination of at least two of a plurality of elements. For example, including at least one of A, B, and C can mean including any one or more elements selected from the set consisting of A, B, and C. The terms "first" and "second" in this document refer to and distinguish between multiple similar technical terms, not to restrict the order or to limit there to only two. For example, "first feature" and "second feature" refer to two categories / two features; the first feature can be one or more, and the second feature can also be one or more.

[0018] Furthermore, to better illustrate this disclosure, numerous specific details are set forth in the following detailed description. Those skilled in the art will understand that this disclosure can be practiced without certain specific details. In some instances, methods, means, components, and circuits well known to those skilled in the art have not been described in detail in order to highlight the main points of this disclosure.

[0019] Before introducing the technical solutions of the embodiments of this disclosure, the technical terms that may be used in this disclosure will be further explained:

[0020] Distributed Denial of Service (DDoS) attacks are a common type of network security attack. This type of attack primarily uses malicious traffic to consume network or network device resources, thereby causing websites to malfunction or online services to fail.

[0021] In the face of challenges such as heterogeneous network environments and the increasing frequency of DDoS attacks, traditional protection methods struggle to distinguish between normal user traffic and malicious attack traffic.

[0022] In order to at least partially solve one or more of the above-mentioned problems and other potential problems, this disclosure proposes a network behavior recognition method that can accurately identify normal traffic and malicious attack traffic, and effectively improve network security protection capabilities.

[0023] This disclosure provides a method for network behavior recognition. Figure 1 This is a flowchart illustrating a network behavior recognition method according to an embodiment of the present disclosure. This method can be applied to a network behavior recognition device. The network behavior recognition device is located in an electronic device. The electronic device includes, but is not limited to, fixed devices and / or mobile devices. For example, fixed devices include, but are not limited to, servers, which can be cloud servers or ordinary servers. Mobile devices include, but are not limited to, network behavior management devices, which can be mobile phones, tablets, etc. In some possible implementations, the network behavior recognition method can also be implemented by a processor calling computer-readable instructions stored in memory. Figure 1 As shown, the network behavior recognition method includes the following steps.

[0024] S101. Generate a real-time behavior sequence for each target object based on real-time network traffic data.

[0025] S102. Input the real-time behavior sequence into the pre-trained behavior scoring model to obtain the behavior score.

[0026] S103. Determine the network behavior attributes of each target object based on the multidimensional features and behavior scores corresponding to each target object.

[0027] Here, real-time network traffic data refers to real-time data packets or streams transmitted in the network, including information such as source Internet Protocol (IP) address, destination IP address, protocol type, request frequency, and accessed content. This data reflects network behavior and activity.

[0028] Here, the target object refers to the object in the network that needs to be identified or analyzed, which can be an IP address, user, device, server, etc. Each target object can represent a user.

[0029] Here, a real-time behavior sequence is time-series data generated based on the network activity of a target object, which can record changes in its behavior over time. For example, a real-time behavior sequence can refer to a sequence formed by arranging the request frequency, page types accessed, and protocols used by a target object in chronological order within a certain period of time.

[0030] In this embodiment, real-time network traffic data can be acquired first. For example, real-time network traffic data can be collected through network device logs or traffic capture tools. Subsequently, the real-time network traffic data can be preprocessed to extract behavioral information related to the target object. For example, the preprocessing process can include target object identification, data filtering, and time synchronization. During target object identification, when the target object is an IP address, traffic can be categorized according to each IP address; when the target object is a user account, it can be categorized according to the account information contained in the data; when the target object is a specific device, it can also be categorized according to the device identifier. The data filtering process can filter out irrelevant traffic and then select the required traffic data according to the target object. The time synchronization process can standardize the timestamps of the network traffic to ensure that the behavioral sequence can be generated in the correct chronological order. Next, features related to the target object's behavior can be extracted according to preset dimensions. For example, features can include: time-dimensional features, spatial-dimensional features, protocol-dimensional features, behavioral patterns, etc. Finally, the extracted features are combined in chronological order to generate a real-time behavioral sequence. The above is merely an illustrative example and is not intended to limit all possible scenarios for generating real-time behavior sequences; it is simply not an exhaustive list.

[0031] Here, a pre-trained behavior scoring model refers to a model trained using historical network behavior data based on machine learning or deep learning methods. This model can evaluate the behavioral characteristics of a target object based on the input behavior sequence, thereby identifying normal behavior and potentially threatening behavior.

[0032] Here, the behavior score is a score output by the behavior scoring model, used to quantify the degree of anomalousness of the target object's behavior. It can be a numerical value or a probability. The numerical score identifies the outlier value of the object; the probability score indicates the probability that the object's behavior is anomalous.

[0033] In this embodiment, the generated real-time behavior sequence can first be formatted into an input format supported by the model. For example, the sequence can be formatted into a fixed-length feature vector or a time-series matrix. Then, a pre-trained behavior scoring model is loaded, and the formatted real-time behavior sequence is input into the model to perform model inference. Finally, the result obtained from the model inference is used as the behavior score.

[0034] Here, multidimensional features can be used to describe various attributes or indicators of the target object's network behavior, reflecting the target object's behavior from multiple perspectives. For example, multidimensional features may include request frequency, target address type, whether a proxy service is used, packet size distribution, etc.

[0035] Here, network behavior attributes refer to the behavioral categories of a target object. These attributes are determined through a comprehensive analysis of multidimensional features and behavioral scores, and can be used to characterize the threat level of the object, thereby helping the system to take further targeted protective measures. For example, network behavior attributes can include normal network behavior, potentially risky network behavior, and malicious network behavior.

[0036] In this embodiment of the disclosure, multidimensional features and behavior scores can be combined to determine network behavior attributes by designing specific rules or using models. For example, attributes can be determined based on features and scores by setting thresholds and logical conditions. Specifically, for real-time data, where it is necessary to quickly determine the network behavior attributes of each target object, multidimensional features and scores can be combined, and rules can be dynamically executed using a rule engine to output behavior attributes in real time; alternatively, real-time multidimensional features and scores can be input into a trained classification model to quickly generate prediction results.

[0037] The technical solution of this disclosure, through analysis of real-time network traffic, can dynamically track changes in the behavior of target objects and quickly detect potential abnormal behaviors. Real-time capture of the target object's behavior sequence provides timely data support for subsequent analysis, reducing the impact of potential threats on the system. By introducing a pre-trained behavior scoring model, potential patterns can be extracted from complex behavior sequences, distinguishing between normal and abnormal behaviors, thereby reducing false positive and false negative rates. By using behavior scoring as a quantitative indicator, the system can be provided with intuitive and fine-grained judgment criteria, facilitating further analysis and decision-making. The combination of multi-dimensional features and behavior scoring allows for the evaluation of the target object's behavior from multiple perspectives, effectively avoiding misjudgments that may be caused by a single indicator. Comprehensive analysis of real-time network traffic data enables more accurate identification of complex behavior patterns, improving the accuracy of network behavior attribute determination and facilitating the adoption of differentiated network protection strategies for different network behavior attributes, thereby effectively enhancing network security protection capabilities.

[0038] In some embodiments, the network behavior recognition method further includes: implementing a network control strategy that matches the network behavior attributes of the target object.

[0039] Here, network control policy refers to a set of network management or protection measures corresponding to the identification results of network behavior attributes, which can ensure network security and efficient use of resources. For example, when network behavior attributes include normal network behavior, potentially risky network behavior, and malicious network behavior, for normal network behavior, the target object can be allowed to access network resources normally without any restrictions; for potentially risky network behavior, the target object can be listed as a key monitoring object, its subsequent behavior recorded, or its traffic isolated to avoid potential impact on other parts of the network; for malicious network behavior, the target object's bandwidth and access frequency can be restricted, or its network connection can be directly prohibited, or it can be blacklisted to permanently prohibit its access to network resources, etc. The above are merely illustrative examples and do not represent all possible scenarios for network control policies; they are simply not exhaustive.

[0040] In this embodiment, a corresponding network control policy can first be matched based on the network behavior attributes of the target object. Then, the access control configurations of network protection devices or application services, such as firewalls, gateways, and traffic balancers, are dynamically updated according to the matched policy. Specifically, if the behavior attributes of the target object change, its network control policy is updated promptly.

[0041] In this way, dynamically adjusting control strategies based on the network behavior attributes of the target can avoid a one-size-fits-all approach to protection, thereby achieving refined management. Targeted protection against different types of malicious behavior can effectively reduce potential threats to the system, thus ensuring network security and optimizing resource utilization.

[0042] In some embodiments, the network behavior recognition method further includes: acquiring historical network traffic data; determining normal behavior sequences based on the historical network traffic data; and using the normal behavior sequences as training samples to train an initial model to generate a behavior scoring model.

[0043] Here, the initial model refers to the base model used for initial training during the generation of the behavior scoring model. It is typically an untrained or poorly trained machine learning or deep learning model. This model can learn the feature distribution of normal behavior in network traffic through training, thereby generating a final model that can provide behavior scores.

[0044] In this embodiment, historical traffic logs are first collected from network devices such as firewalls, routers, and traffic monitoring tools. Then, historical network traffic data is generated through data cleaning and preprocessing. Next, normal behavior samples conforming to the defined parameters are extracted from the historical network traffic data to form time series data. Then, the normal behavior sequences are organized into feature vectors and labeled to generate model training samples. These training samples are then input into an initial large model, enabling the model to learn the feature distribution of normal behavior. Finally, the trained model can score the input behavior sequences; this score reflects whether the target object's behavior deviates from the normal pattern.

[0045] Thus, using historical normal behavior sequences as training samples enables the model to more accurately learn the feature distribution of normal behavior. By extracting normal behavior sequences from historical traffic data, it is unnecessary to pre-label a large number of malicious behavior samples, and the statistical characteristics of normal behavior make it suitable for application in situations facing unknown threats or where malicious behavior samples are scarce. By learning the characteristics of normal behavior, the model can effectively distinguish the behavior of normal users, avoiding misclassifying normal traffic as malicious behavior, thereby improving the user experience.

[0046] In some embodiments, determining a normal behavior sequence based on historical network traffic data includes: extracting a historical behavior sequence for each preset object based on historical network traffic data; and traversing the historical network traffic data to determine the historical behavior sequences of all preset objects as normal behavior sequences.

[0047] Here, "predefined objects" refers to specific target objects in historical network traffic data that have been predefined by humans or rules and can be used for analysis. These predefined objects can be users, devices, applications, IP addresses, domain names, etc., in the network, and can be used to distinguish the source or behavioral characteristics of traffic. In particular, predefined objects are filtered trusted objects, that is, objects without malicious or abnormal behavior.

[0048] In this embodiment of the disclosure, preset objects can be defined first. For example, all devices in a subnet can be defined as preset objects by a range of source IP addresses; certain user accounts can be defined as preset objects by their IdentityDocument (ID) or Media Access Control (MAC) address; and certain specific services can be defined as preset objects by their target port and protocol. These are merely illustrative examples and are not intended to limit the scope of all possible definitions of preset objects; they are simply not exhaustive. Subsequently, network traffic can be assigned to the corresponding preset objects. Next, features corresponding to the preset objects can be extracted from historical network traffic data, and these features can be arranged chronologically to generate a behavioral sequence for each preset object.

[0049] In this embodiment of the disclosure, for each preset object, its historical behavior sequence can be obtained, and then the behavior data of these objects can be traversed to form a set of normal behavior sequences, thereby generating a normal behavior sequence.

[0050] Thus, by defining and extracting behaviors from predefined objects, reliable historical behavioral data can be quickly filtered out, accurately reflecting the characteristics of normal network traffic. By dividing the data into predefined objects, the entire historical data is decomposed into multiple independent behavioral sequences, reducing the complexity of data processing. Traversing the historical behavioral sequences of predefined objects can be processed in parallel, significantly improving data extraction and processing efficiency in large-scale data scenarios.

[0051] In some embodiments, extracting the historical behavior sequence of each preset object based on historical network traffic data includes: extracting historical access requests corresponding to the preset object based on historical network traffic data; extracting historical interaction features between the preset object and any service port based on historical access requests; and traversing historical access requests to use the historical interaction features with each service port as a historical behavior sequence.

[0052] Here, an access request refers to a communication record in network traffic. Each access request records a data interaction or communication behavior between a preset object and a target service. In particular, access requests usually contain key information about the network communication.

[0053] In this embodiment of the disclosure, access requests related to a preset object can be filtered from historical network traffic data. These access requests may include fields such as source IP address, destination IP address, service port, protocol type, and timestamp. For example, traffic log tools or database query languages ​​can be used to filter data and extract historical access requests corresponding to the preset object.

[0054] Here, a service port refers to a port number used in network communication to identify a specific service or application. It is part of the network protocol and can be used to distinguish different services running on a device. In particular, there is a one-to-one correspondence between service ports and interaction types; that is, a service port can reflect the interaction type between a preset object and a target service.

[0055] Here, interaction features refer to the behavioral data features generated when a preset object communicates with a service port, which can describe the communication pattern or attributes between the preset object and the target service.

[0056] In this embodiment of the disclosure, communication records of a preset object can be categorized by service port based on the target port number in the access request, and interaction features can then be extracted from the access requests corresponding to each service port. For example, feature extraction can be implemented using traffic processing tools or database statistics functions. For example, interaction features may include access frequency, data volume, connection duration, etc.

[0057] In this embodiment of the disclosure, all service ports of a preset object can be analyzed one by one, their corresponding interaction features can be extracted, and then the interaction features of each service port can be arranged in chronological order to generate a historical behavior sequence.

[0058] Thus, by extracting interaction features by service port, the behavior of a predefined object can be refined to the specific service interaction level. Extracting interaction features by service port can adapt to different scenarios and improve the applicability of behavior analysis. Historical network traffic data can be used to extract interaction features in batches using scripts or automated tools, saving time on manual annotation and analysis. Through analysis refined to the port level, the normal behavioral characteristics of different service ports can be distinguished, significantly reducing the false positive rate.

[0059] In some embodiments, determining a normal behavior sequence based on historical network traffic data includes: extracting a historical behavior sequence for each object based on historical network traffic data; and selecting historical behavior sequences that conform to a normal behavior pattern from all historical behavior sequences as normal behavior sequences.

[0060] Here, "object" refers to the entity that generates traffic in the network, which can be distinguished by identification information in historical network traffic data. Specifically, the objects here are unfiltered, encompassing all objects in the historical network traffic data.

[0061] In this embodiment of the disclosure, historical traffic logs can be traversed, and all access requests for each object can be filtered out based on the identifier of that object. The access requests are then organized in chronological order, and their behavioral characteristics are extracted to generate a historical behavior sequence.

[0062] In this embodiment of the disclosure, the process of filtering historical behavior sequences that conform to normal behavior patterns can default all objects to trusted objects, i.e., objects without malicious or abnormal behavior. For example, when acquiring historical network traffic data, malicious attack records within the corresponding time period can be acquired simultaneously, thus all objects within the time period in which no malicious attacks occurred can be considered trusted. Furthermore, normal behavior can also be filtered based on preset rules or statistical thresholds. For example, thresholds can be set from multiple dimensions such as access frequency, data volume, and target distribution, and filtering can be achieved by comparing with the thresholds. Even further, clustering algorithms can be used to automatically identify normal behavior and eliminate behavior sequences that deviate from the normal distribution. For example, behavioral features can be used as input features, and clusters containing the majority of samples in the clustering results can be defined as normal behavior. The above are merely illustrative examples and do not limit all possible situations in the filtering process; they are simply not exhaustive.

[0063] Thus, by selecting behavioral sequences that conform to normal patterns, the model training set contains only normal behavioral data, effectively preventing the model from learning features of abnormal behaviors, thereby improving the ability to detect unknown anomalies. The selection process also reduces noise in the training data, thus minimizing the impact of abnormal behavioral data in the training set, lowering the false positive rate in actual detection, and improving the model's generalization ability. Network behavioral features may change over time (e.g., user habits, device traffic patterns), and by periodically re-selecting normal behavioral sequences from historical data, normal behavioral patterns can be dynamically updated, improving the model's adaptability to new behavioral patterns.

[0064] In some embodiments, generating a real-time behavior sequence for each target object based on real-time network traffic data includes: extracting real-time access requests corresponding to the target object based on real-time network traffic data; extracting real-time interaction features between the target object and any service port based on the real-time access requests; and traversing the real-time access requests to use the real-time interaction features between the target object and each service port as a real-time behavior sequence.

[0065] In this embodiment of the disclosure, the process of extracting real-time access requests corresponding to the target object based on real-time network traffic data can be achieved by using a real-time network traffic monitoring tool to capture real-time network traffic data, then viewing the metadata of each access request, and finally filtering out access requests related to the target object.

[0066] In this embodiment of the disclosure, the process of extracting real-time interaction features between a target object and any service port based on real-time access requests can first analyze the service ports accessed by each target object in the real-time access requests, and then statistically analyze the interaction features by service port. For example, interaction features may include: the number of requests from the target object to a certain port per minute, the amount of data transmitted between the target object and each port, the number of target IPs for each port in the target object's access requests, etc. The above is merely an illustrative example and is not intended to limit all possible cases of interaction features; it is simply not exhaustive.

[0067] In this embodiment of the disclosure, the process of traversing real-time access requests and taking the real-time interaction features between the target object and each service port as a real-time behavior sequence can traverse all service ports accessed by the target object, organize the interaction features of each port according to time windows, and finally arrange the real-time interaction features in chronological order to construct a complete real-time behavior sequence.

[0068] Thus, by extracting behavioral sequences in real time, the communication activities of target objects can be dynamically monitored. Extracting features by port refines the behavioral description of the target object; the usage characteristics of different ports can reflect different behavioral patterns, significantly improving the accuracy of anomaly detection. By traversing all service ports, multi-dimensional behavioral sequences of the target object can be generated, suitable for multi-service behavioral modeling in complex network environments. The interaction features contained in the real-time behavioral sequences provide contextual information for abnormal behavior, facilitating subsequent source tracing analysis.

[0069] In some embodiments, the network behavior attribute of each target object is determined based on the multidimensional features and behavior score corresponding to each target object, including: determining the network behavior attribute as normal network behavior when the behavior score is less than a first score threshold.

[0070] Here, the first scoring threshold is a predefined numerical limit used to distinguish between normal and abnormal behavior of a target object. In particular, the first scoring threshold usually needs to be dynamically adjusted according to changes in the actual network environment to adapt to new behavioral patterns or anomaly types.

[0071] In this embodiment, the behavior score can be compared with a first scoring threshold. If the score is less than the first scoring threshold, the target object's behavior is determined to be normal network behavior. Conversely, if the score is greater than or equal to the first scoring threshold, it proves that the target object's behavior may be abnormal and requires further analysis or labeling as abnormal behavior.

[0072] In this way, behavioral scoring quantifies the behavior of target objects, standardizes behavioral assessment criteria, avoids subjective judgment, and improves the objectivity and consistency of the assessment. The first scoring threshold can be dynamically adjusted based on historical data, making the boundary between normal and abnormal behavior more precise, thereby reducing false positives and false negatives. Simplifying the complexity of multi-dimensional features into a single behavioral score makes the determination of abnormal behavior more direct. Abnormal objects can be quickly identified through simple threshold comparison. The method of generating behavioral scores and comparing thresholds involves relatively low computational cost, making it suitable for large-scale data processing and real-time analysis scenarios. In real-time traffic monitoring, behavioral scores can be quickly calculated and behavioral attributes determined, allowing for rapid implementation of corresponding network control strategies and effectively improving network security protection capabilities.

[0073] In some embodiments, the network behavior attribute of each target object is determined based on the multidimensional features and behavior score corresponding to each target object, including: determining the network behavior attribute as a potential risk network behavior when the behavior score is greater than or equal to a first score threshold; determining an auxiliary score based on the multidimensional features of the target object with potential risk network behavior; and determining potential risk network behavior with an auxiliary score greater than a second score threshold as malicious network behavior.

[0074] In this embodiment, the auxiliary score is a detailed score calculated by comprehensively analyzing the characteristics of a target object that has been marked as having potentially risky network behavior, combined with other dimensions. For example, auxiliary information such as the target object's geographical location, device type, and request header information can be obtained, and then analyzed based on this auxiliary information to generate an auxiliary score according to preset rules. Specifically, weights or rules can be set for specific features to calculate the auxiliary score by combining features; alternatively, machine learning models such as classification models or anomaly detection models can be used to perform in-depth analysis of multi-dimensional features to generate an auxiliary score; furthermore, the behavioral changes of the target object can be analyzed in conjunction with the time dimension, such as a sudden increase in request frequency or a sudden expansion of the target IP distribution, and then a score can be assigned according to the magnitude of the change. The above are merely illustrative examples and are not intended to limit all possible situations for determining the auxiliary score; they are simply not exhaustive.

[0075] In this embodiment of the disclosure, a behavioral score can be compared with a first scoring threshold. If the score is greater than or equal to the first scoring threshold, the target object's behavior is determined to be a potentially risky network behavior. Next, for target objects with behavioral scores higher than the first scoring threshold, a more granular auxiliary score is calculated and compared with a second scoring threshold. If the score is less than the second scoring threshold, the target object's behavior is determined to be a potentially risky behavior; conversely, if the score is greater than or equal to the second scoring threshold, the target object's behavior is determined to be malicious behavior.

[0076] Thus, by combining behavioral scoring and auxiliary scoring, normal behavior, potentially risky behavior, and malicious behavior can be more accurately distinguished, further reducing the possibility of false alarms and improving the accuracy of malicious behavior detection. Auxiliary scoring provides a higher level of behavioral analysis capabilities, enabling the identification of complex malicious behavior patterns, which helps in responding to new types of attacks and enhancing network security protection capabilities.

[0077] In some embodiments, the network behavior recognition method further includes using real-time behavior sequences with network behavior attributes of normal network behavior as new training samples to optimize the behavior scoring model.

[0078] In this embodiment, after collecting real-time behavior sequences, the sequences can be cleaned and organized to generate new training data. This new training data is then added to an existing normal sample dataset. Specifically, if historical training samples exist, they can be merged with the new samples to form a more comprehensive training dataset. The new dataset is then input into the behavior scoring model to retrain it. Finally, the optimized behavior scoring model is redeployed into the system for real-time calculation of the target object's behavior score.

[0079] Thus, by continuously introducing new normal behavior samples, the model can dynamically adapt to various changes in the real network environment, reducing false positives for normal behavior. Introducing new normal samples prevents the model from overfitting to historical data. Regularly updating the model ensures it still has good generalization ability for future network behaviors. Through an adaptive optimization mechanism, the model performance is automatically optimized using real-time data, reducing the need for manual intervention. Furthermore, the security system can self-learn, becoming more intelligent and accurate over time.

[0080] In some implementations, potential DDoS attack traffic can be identified by analyzing user behavior sequence analysis and statistically analyzing user behavior patterns when accessing different interfaces.

[0081] First, a data collection and preprocessing process is performed. Specifically, in network traffic, access requests from each IP address are captured, and information such as the access timestamp, target interface, and request frequency is recorded. This data is then cleaned and standardized for subsequent analysis.

[0082] Next, the behavioral sequences are modeled. Specifically, a sequence model of user access behavior can be established, including modeling the behavioral sequences of normal users and identifying features such as the order, frequency, and proportion of their access to interfaces. For example, these features can be trained using machine learning algorithms to generate a behavioral scoring model.

[0083] Furthermore, the trained model is used for anomaly detection. Specifically, a behavioral scoring model is used to detect real-time traffic and identify access sequences that do not conform to normal behavior patterns. For example, if an IP address accesses a specific interface with an abnormally high frequency, that traffic may be flagged as an anomaly.

[0084] Furthermore, auxiliary scores are determined for objects corresponding to abnormal traffic through multi-dimensional feature analysis. Specifically, auxiliary scores for objects are determined by comprehensively analyzing features from other dimensions such as geographic location, device type, and request header information.

[0085] Furthermore, after determining the object's attributes based on auxiliary scoring, real-time response and blocking are implemented. Specifically, based on behavioral scoring and auxiliary scoring, the object is determined to be normal, risky, or malicious. Once potential attack traffic is identified, a response mechanism is immediately triggered, dynamically adjusting network policies to block or restrict traffic and protect server resources.

[0086] Finally, a continuous monitoring and feedback mechanism should be established. Specifically, through this mechanism, the behavioral sequence model can be continuously updated and optimized to improve detection accuracy and response speed.

[0087] This disclosure provides a network behavior recognition device, such as... Figure 2 As shown, the device may include: a sequence generation module 201, used to generate a real-time behavior sequence for each target object based on real-time network traffic data; a score generation module 202, used to input the real-time behavior sequence into a pre-trained behavior scoring model to obtain a behavior score; and an attribute determination module 203, used to determine the network behavior attributes of each target object based on the multi-dimensional features and behavior score corresponding to each target object.

[0088] In some embodiments, the network behavior recognition device further includes: a policy enforcement module ( Figure 2 (Not shown in the image), used to implement network control strategies that match the network behavior attributes of the target object.

[0089] In some embodiments, the network behavior recognition device further includes: a data acquisition module ( Figure 2 (Not shown in the image), used to obtain historical network traffic data; Normal sequence module ( Figure 2 (Not shown in the image), used to determine normal behavior sequences based on historical network traffic data; model training module ( Figure 2 (not shown in the image) is used to train the initial model using normal behavior sequences as training samples to generate a behavior scoring model.

[0090] In some embodiments, the normal sequence module includes: a first historical sequence submodule, configured to extract the historical behavior sequence of each preset object based on historical network traffic data; and a first normal sequence submodule, configured to traverse the historical network traffic data and take the historical behavior sequences of all preset objects as normal behavior sequences.

[0091] In some embodiments, the first historical sequence submodule is configured to: extract historical access requests corresponding to a preset object based on historical network traffic data; extract historical interaction features between the preset object and any service port based on the historical access requests; and traverse the historical access requests, taking the historical interaction features with each service port as a historical behavior sequence.

[0092] In some embodiments, the normal sequence module includes: a second historical sequence submodule, used to extract the historical behavior sequence of each object based on historical network traffic data; and a second normal sequence submodule, used to filter out historical behavior sequences that conform to the normal behavior pattern from all historical behavior sequences as normal behavior sequences.

[0093] In some embodiments, the sequence generation module 201 includes: a traffic data parsing submodule, used to extract real-time access requests corresponding to the target object based on real-time network traffic data; an interaction feature extraction submodule, used to extract real-time interaction features between the target object and any service port based on the real-time access requests; and a behavior sequence generation submodule, used to traverse the real-time access requests and take the real-time interaction features between the target object and each service port as a real-time behavior sequence.

[0094] In some embodiments, the attribute determination module 203 includes: a first attribute determination submodule, configured to determine that the network behavior attribute is normal network behavior when the behavior score is less than a first score threshold.

[0095] In some embodiments, the attribute determination module 203 includes: a second attribute determination submodule, configured to determine a network behavior attribute as a potential risk network behavior when the behavior score is greater than or equal to a first score threshold; an auxiliary score determination submodule, configured to determine an auxiliary score based on the multidimensional characteristics of the target object with potential risk network behavior; and a third attribute determination submodule, configured to determine potential risk network behavior with an auxiliary score greater than a second score threshold as malicious network behavior.

[0096] In some embodiments, the network behavior recognition device further includes: a model optimization module ( Figure 2 (Not shown in the image) is used to take real-time behavior sequences with network behavior attributes of normal network behavior as new training samples to optimize the behavior scoring model.

[0097] The specific functions and examples of each module and submodule of the apparatus in this disclosure can be found in the relevant descriptions of the corresponding steps in the above method embodiments, and will not be repeated here.

[0098] The network behavior recognition device in this embodiment can dynamically track changes in the behavior of target objects by analyzing real-time network traffic, and quickly detect possible abnormal behaviors. Real-time capture of the target object's behavior sequence provides timely data support for subsequent analysis, reducing the impact of potential threats on the system. By introducing a pre-trained behavior scoring model, potential patterns can be extracted from complex behavior sequences, distinguishing between normal and abnormal behaviors, thereby reducing false positive and false negative rates. By setting behavior scores as quantitative indicators, the system can be provided with intuitive and fine-grained judgment criteria, facilitating further analysis and decision-making. The combination of multi-dimensional features and behavior scores allows for the evaluation of the target object's behavior from multiple perspectives, effectively avoiding misjudgments that may be caused by a single indicator. Through comprehensive analysis, complex behavior patterns can be identified more accurately, improving the accuracy of network behavior attribute determination and helping to adopt differentiated network protection strategies for different network behavior attributes.

[0099] This disclosure provides a scenario illustration of a network behavior recognition method, such as... Figure 3 As shown.

[0100] As previously described, the network behavior recognition method provided in this disclosure is applied to electronic devices. Electronic devices are intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers.

[0101] Specifically, the electronic device may perform the following operations:

[0102] Based on real-time network traffic data, generate a real-time behavior sequence for each target object;

[0103] The real-time behavior sequence is input into a pre-trained behavior scoring model to obtain a behavior score;

[0104] Based on the multidimensional features and behavior scores corresponding to each target object, the network behavior attributes of each target object are determined;

[0105] Based on the network behavior attributes of the target object, implement network control strategies that match its network behavior attributes.

[0106] It should be understood that Figure 3 The scene diagrams shown are merely illustrative and not restrictive; those skilled in the art can interpret them based on... Figure 3Even with various obvious changes and / or substitutions to the examples, the resulting technical solutions still fall within the scope of this disclosure.

[0107] The acquisition, storage, and application of user personal information involved in the technical solution disclosed herein comply with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0108] According to embodiments of this disclosure, this disclosure also provides an electronic device, a readable storage medium, and a computer program product.

[0109] Figure 4 A schematic block diagram of an example electronic device 400 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0110] like Figure 4 As shown, device 400 includes a computing unit 401, which can perform various appropriate actions and processes based on a computer program stored in read-only memory (ROM) 402 or a computer program loaded from storage unit 408 into random access memory (RAM) 403. RAM 403 may also store various programs and data required for the operation of device 400. The computing unit 401, ROM 402, and RAM 403 are interconnected via bus 404. Input / output (I / O) interface 405 is also connected to bus 404.

[0111] Multiple components in device 400 are connected to I / O interface 405, including: input unit 406, such as keyboard, mouse, etc.; output unit 407, such as various types of monitors, speakers, etc.; storage unit 408, such as disk, optical disk, etc.; and communication unit 409, such as network card, modem, wireless transceiver, etc. Communication unit 409 allows device 400 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0112] The computing unit 401 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 401 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, digital signal processors (DSPs), and any suitable processor, controller, microcontroller, etc. The computing unit 401 performs the various methods and processes described above, such as network behavior recognition methods. For example, in some embodiments, the network behavior recognition method may be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 408. In some embodiments, part or all of the computer program may be loaded and / or installed on device 400 via ROM 402 and / or communication unit 409. When the computer program is loaded into RAM 403 and executed by the computing unit 401, one or more steps of the network behavior recognition method described above may be performed. Alternatively, in other embodiments, the computing unit 401 may be configured to perform a network behavior recognition method by any other suitable means (e.g., by means of firmware).

[0113] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-chip (SoCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0114] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0115] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory, read-only memory, erasable programmable read-only memory (EPROM), flash memory, optical fiber, compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0116] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a cathode ray tube (CRT) or liquid crystal display (LCD) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0117] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.

[0118] Computer systems can include clients and servers. Clients and servers are generally located far apart and typically interact via communication networks. Client-server relationships are created by computer programs running on the respective computers and having a client-server relationship with each other. Servers can be cloud servers, servers in distributed systems, or servers incorporating blockchain technology.

[0119] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.

[0120] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. A method for network behavior recognition, comprising: Based on real-time network traffic data, generate a real-time behavior sequence for each target object; The real-time behavior sequence is input into a pre-trained behavior scoring model to obtain a behavior score; Based on the multidimensional features corresponding to each target object and the behavior score, the network behavior attributes of each target object are determined.

2. The method according to claim 1, wherein, The method further includes: Based on the network behavior attributes of the target object, implement a network control strategy that matches the network behavior attributes of the target object.

3. The method according to claim 1 or 2, wherein, The method further includes: Obtain historical network traffic data; Determine the normal behavior sequence based on the historical network traffic data; The normal behavior sequence is used as training samples to train the initial model to generate the behavior scoring model.

4. The method according to claim 3, wherein, The step of determining the normal behavior sequence based on the historical network traffic data includes: Based on the historical network traffic data, extract the historical behavior sequence of each preset object; Traverse the historical network traffic data and take the historical behavior sequence of all preset objects as the normal behavior sequence.

5. The method according to claim 4, wherein, The step of extracting the historical behavior sequence of each preset object based on the historical network traffic data includes: Based on the historical network traffic data, extract the historical access requests corresponding to the preset object; Based on the historical access requests, extract the historical interaction features between the preset object and any service port; The historical access requests are traversed, and the historical interaction characteristics with each service port are used as the historical behavior sequence.

6. The method according to claim 3, wherein, The step of determining the normal behavior sequence based on the historical network traffic data includes: Based on the historical network traffic data, extract the historical behavior sequence of each object; Historical behavior sequences that conform to the normal behavior pattern are selected from all the historical behavior sequences and designated as the normal behavior sequences.

7. The method according to claim 1, wherein, The step of generating a real-time behavior sequence for each target object based on real-time network traffic data includes: Based on the real-time network traffic data, extract the real-time access request corresponding to the target object; Based on the real-time access request, extract the real-time interaction features between the target object and any service port; The real-time access requests are iterated through, and the real-time interaction characteristics between the target object and each service port are used as the real-time behavior sequence.

8. The method according to claim 1, wherein, The step of determining the network behavior attributes of each target object based on the multidimensional features corresponding to each target object and the behavior score includes: If the behavior score is less than the first score threshold, the network behavior attribute is determined to be normal network behavior.

9. The method according to claim 1, wherein, The step of determining the network behavior attributes of each target object based on the multidimensional features corresponding to each target object and the behavior score includes: If the behavior score is greater than or equal to a first score threshold, the network behavior attribute is determined to be a potentially risky network behavior. Auxiliary scores are determined based on the multidimensional characteristics of target objects exhibiting the aforementioned potential risk network behaviors; The potential risk network behaviors whose auxiliary scores are greater than the second scoring threshold are identified as malicious network behaviors.

10. The method according to claim 1, wherein, The method further includes: The real-time behavior sequences with the network behavior attribute of normal network behavior are used as new training samples to optimize the behavior scoring model.

11. A network behavior recognition device, comprising: The sequence generation module is used to generate a real-time behavior sequence for each target object based on real-time network traffic data. The rating generation module is used to input the real-time behavior sequence into a pre-trained behavior rating model to obtain a behavior rating. The attribute determination module is used to determine the network behavior attributes of each target object based on the multidimensional features corresponding to each target object and the behavior score.

12. An electronic device, comprising: At least one processor; as well as A memory that is communicatively connected to at least one processor; wherein, The memory stores instructions that can be executed by at least one processor to enable the at least one processor to perform the method of any one of claims 1-10.

13. A non-transitory computer-readable storage medium storing computer instructions, wherein, Computer instructions are used to cause a computer to perform the method according to any one of claims 1-10.

14. A computer program product comprising a computer program stored on a storage medium, wherein the computer program, when executed by a processor, implements the method according to any one of claims 1-10.