An abnormal communication link detection method for an internal and external network access boundary
Patent Information
- Application Number
- CN202610848950.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-12
- Publication Date
- 2026-09-25
AI Technical Summary
[0002]随着政企网络、工业控制网络以及数据中心网络规模的不断扩大,内网与外网之间的访问边界已成为网络安全防护的重要环节;现有技术通常通过防火墙、入侵检测系统、流量审计系统或安全网关对边界通信行为进行监测,其主要依据源IP地址、目标IP地址、端口号、协议类型、访问频率及流量特征等信息识别异常通信行为;当出现异常流量、异常连接或违规访问时,系统通过规则匹配、特征检测或行为分析方式发出安全告警,从而实现对网络边界的安全防护;然而,随着网络架构的复杂化以及攻击手段的隐蔽化,大量异常通信行为已经不再表现为流量异常或协议异常,而是通过合法节点、合法协议以及合法访问路径完成通信,使得传统基于流量特征或访问特征的检测方法难以准确识别
[0037]本发明通过在内外网访问边界部署多源采集探针,实时捕获外网请求、边界放行日志、内网响应以及内部横向访问行为,并在时序归并引擎中进行两级关联,生成边界多路径会话轨迹;该轨迹以节点序列、边的时间差及协议类型为基本要素,完整表征一次通信行为从外网发起、经过边界设备放行、内网响应到内部横向传播的全过程,从而实现对链路中每个节点的角色行为、节点间路径及会话顺序的精细化监控;本发明不仅可以捕获单次异常事件,还能还原整个通信链路的动态传播路径,实现链路级别的全流程可视化,为后续异常检测和溯源分析提供高精度基础数据。
Smart Images

Figure CN122824431A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication link detection technology, and in particular to an abnormal communication link detection method for the boundary between internal and external network access. Background Technology
[0002] With the continuous expansion of government and enterprise networks, industrial control networks, and data center networks, the access boundary between the internal and external networks has become a crucial link in network security protection. Existing technologies typically monitor boundary communication behavior through firewalls, intrusion detection systems, traffic auditing systems, or security gateways. These systems primarily identify abnormal communication behavior based on information such as source IP address, destination IP address, port number, protocol type, access frequency, and traffic characteristics. When abnormal traffic, abnormal connections, or unauthorized access occur, the system issues security alerts through rule matching, feature detection, or behavior analysis, thereby achieving security protection of the network boundary. However, with the increasing complexity of network architectures and the sophistication of attack methods, many abnormal communication behaviors no longer manifest as abnormal traffic or protocol anomalies. Instead, they complete communication through legitimate nodes, legitimate protocols, and legitimate access paths, making traditional detection methods based on traffic or access characteristics difficult to accurately identify.
[0003] In real-world network environments, attackers often exploit existing legitimate communication paths to establish covert communication links through methods such as node role substitution, access privilege overstepping, communication role reversal, and gradual path migration. Such communication behaviors typically appear normal at the single-session level, but from the perspective of the continuous evolution of multiple sessions, the role positioning of the communication nodes in the link has changed, thus forming a persistent abnormal communication path. Most existing technologies detect single connections or individual sessions, lacking the comprehensive analytical capabilities to analyze the historical role patterns of communication nodes, role drift behavior, and cross-session path continuity characteristics, making it difficult to detect abnormal communication links that are long-term latent, continuously reused, and gradually evolving. Summary of the Invention
[0004] This invention provides a method for detecting abnormal communication links at the boundary between internal and external networks. By analyzing the evolution of communication node roles and the continuation behavior of abnormal links, it can achieve accurate identification and continuous tracking of hidden abnormal communication links.
[0005] A method for detecting abnormal communication links at the boundary between internal and external network access includes the following steps:
[0006] S1: At the boundary between internal and external network access, multi-source communication events are collected in real time, including external network request records, boundary access logs, internal network response behavior records, and internal lateral access behavior records. These events are then merged according to source node, target node, protocol type, access order, and time correlation to generate a boundary multi-path session trajectory. The boundary multi-path session trajectory represents the actual propagation process of communication behavior on both sides of the internal and external network boundary.
[0007] S2: Using the boundary multipath session trajectory as input, identify the link roles undertaken by each communication node during historical access and establish corresponding historical role benchmarks; compare the communication nodes in the current boundary multipath session trajectory with the historical role benchmarks to identify communication behaviors with role substitution, role overstepping, role missing, and role reversal phenomena, and generate link role drift results; locate the abnormal communication link candidate set formed by changes in the legitimate link usage based on the link role drift results;
[0008] S3: Using the candidate set of abnormal communication links as input, perform cross-time correlation tracking on candidate links in different sessions, identify persistent communication behaviors formed by repeatedly using the same role drift path, construct abnormal communication link continuation paths, and generate abnormal communication link detection results based on the abnormal communication link continuation paths.
[0009] Optionally, S1 specifically includes:
[0010] S11: Deploy a first collection probe at the inbound traffic mirroring port of the internal / external network access boundary to capture all data packets sent from the external network to the internal network in real time, extract the five-tuple information, timestamp, and payload length of each data packet to form an external network request record; deploy a second collection probe at the log output interface of the boundary device to receive the pass, deny, and NAT translation logs generated by the firewall or gateway device in real time to form a boundary pass log; deploy a third collection probe at the outbound traffic mirroring port of the internal / external network access boundary to capture data packets of the internal network responding to external network requests in real time, extract the five-tuple information, timestamp, and response status code of the response data packets to form an internal network response behavior record; deploy a fourth collection probe at the mirroring port of the internal network core switch or on the security agent of each host terminal to collect the lateral access data packets between internal hosts in real time, extract the source IP, destination IP, protocol type, port, and access time to form an internal lateral access behavior record; the five-tuple information includes the source IP address, destination IP address, source port, destination port, and transport layer protocol;
[0011] S12: The external network request records, boundary access logs, internal network response behavior records and internal lateral access behavior records are uniformly summarized into the time-series merging engine. The source IP address, target IP address and transport layer protocol type are used as the first-level association key values. Records belonging to the same communication pair and whose timestamp difference is less than the preset association window threshold are temporarily stored in the same session buffer.
[0012] S13: Within the session buffer, perform the second-level association according to the access order.
[0013] Optionally, S13 specifically includes:
[0014] For external network request records, find the earliest internal network response behavior record that appears after the external network request record and whose target IP matches the source IP of the external network request record. If it exists and the timestamp difference is less than the request-response timeout threshold, then associate it as a complete request-response pair.
[0015] For the release actions recorded in the boundary release log, insert them as intermediate proof nodes between the corresponding requests and responses;
[0016] For internal lateral access behavior records, they are concatenated with the associated request-response pairs in chronological order. When the timestamp of an internal lateral access behavior record is after the external request record and belongs to the same source IP or target IP, the internal lateral access behavior record is used as an extension path of the corresponding session trajectory.
[0017] Optionally, S1 further includes arranging multiple request-response pairs and lateral access records obtained after the first-level association and the second-level association, which belong to the same source node, the same target node, the same protocol type, and are temporally continuous, in ascending order of time, and using the time difference as the edge weight between each record to generate a directed graph-like boundary multipath session trajectory; the boundary multipath session trajectory includes node sequence, edge timestamp difference, and protocol type label to fully characterize the entire process of a communication behavior from external network initiation, boundary access, internal network response, and internal lateral propagation.
[0018] Optionally, S2 specifically includes:
[0019] S21: Using the boundary multipath session trajectory as input, extract all communication nodes involved in the boundary multipath session trajectory within a predetermined historical time window. For each communication node, count the total number of times it initiates a connection as a source node, the total number of times it is connected as a target node in the historical boundary multipath session trajectory, and the hop count distribution relative to the trajectory start node in each session trajectory. Based on the statistical results, classify the link role of each communication node into one or more combinations of pure initiator role, pure responder role, relay forwarder role, and mixed role. Construct the historical role benchmark of the communication node by the role type and frequency of occurrence of each communication node in different sessions.
[0020] S22: Compare each communication node in the current boundary multipath session trajectory with the corresponding historical role benchmark to determine whether role drift has occurred, and identify role drift as role substitution, role offside, role missing or role reversal;
[0021] S23: For identified role replacements, record the identity mapping relationship between the original role node and the replaced node; for identified role overstepping, record the overstepping node, the type of super-privilege role reached by the overstepping, and the time period of the overstepping; for identified role missing, mark the position of the missing node in the expected session trajectory and the duration of the missing information; for identified role reversal, record the role before reversal, the role after reversal, and the turning point time of the reversal; store all identification results in a structured manner according to the timeline of the session trajectory to generate link role drift results;
[0022] S24: Based on the link role drift results, extract all communication links in which the communication node that has experienced role drift participates, assign a corresponding basic drift weight value to each link according to the drift type, and accumulate the weights of multiple drifts or multiple drift types that occur on the same link to obtain the comprehensive drift weight of the link; mark the links whose comprehensive drift weight exceeds the preset drift threshold as abnormal communication link candidate set; each link in the abnormal communication link candidate set is accompanied by the corresponding drift type combination, drift weight value, and timestamps of the first and last drift occurrences.
[0023] Optionally, the historical role baseline includes a probability distribution vector of role types and a conditional probability matrix of role transitions. The conditional probability matrix of role transitions quantifies the role change pattern of each communication node in the historical multipath session trajectory. The rows represent the current role state of the communication node, and the columns represent the possible role state of the communication node in the next session.
[0024] Optionally, S22 specifically includes:
[0025] Calculate the relative entropy between the role vector of the actual performance of the communication node in the current session and the probability distribution vector in the historical role benchmark;
[0026] Calculate the deviation between the role transition probability of the communication node in the current session relative to the previous hop node and the corresponding conditional probability in the historical role baseline;
[0027] When the relative entropy exceeds the preset character deviation threshold or the deviation value exceeds the preset conversion deviation threshold, the character drift judgment is triggered, and the drift is identified as character substitution, character offside, character missing or character reversal according to the specific manifestation of the drift.
[0028] Optionally, S3 specifically includes:
[0029] S31: Using the candidate set of abnormal communication links as input, extract complete information for each candidate link at each occurrence, including the source node set, target node set, role drift type vector, drift time window, and path node sequence of the candidate link in the boundary multipath session trajectory; standardize and encode all candidate links according to the corresponding path node sequence to form a drift path fingerprint with node role identifier as the basic unit;
[0030] S32: Set a time-sliding window, compare the drift path fingerprints of all candidate links in the window pairwise, use the longest common subsequence algorithm to calculate the similarity between any two candidate links on the role drift type sequence, and compare the edit distance of the path node sequence; when the similarity exceeds the preset reuse threshold and the edit distance is less than the preset path difference tolerance value, it is determined that the corresponding two candidate links are reused for the same role drift path.
[0031] Optionally, S3 further includes concatenating all candidate links determined to reuse the same role's drift path in chronological order, extracting the start timestamp, end timestamp, drift type vector, and drift weight value of each candidate link in sequence, and filling time interval values between adjacent candidate links to form an abnormal communication link continuation path with time axis continuity; and generating an abnormal communication link detection result based on the abnormal communication link continuation path.
[0032] Optionally, the generation of the abnormal communication link detection result specifically includes:
[0033] For each abnormal communication link continuation path, the persistence strength is calculated, and the persistence strength is equal to the ratio of the number of candidate links included in the abnormal communication link continuation path to the total duration.
[0034] When the persistence intensity exceeds the preset persistence threshold, a high-risk alarm is output along with the complete evolution trajectory of the abnormal communication link continuation path;
[0035] When the persistence intensity is lower than the preset persistence threshold, but there is a high-weight drift type in the path of the abnormal communication link, a medium-risk warning is output and the starting node and target node of the corresponding path are marked; the abnormal communication link detection results are output to the interface of the boundary security controller in a structured data format, and the abnormal communication link detection results include at least the abnormal link identifier, the list of involved nodes, the drift type statistics, the duration and the alarm level.
[0036] The beneficial effects of this invention are:
[0037] This invention deploys multi-source acquisition probes at the boundary between internal and external networks to capture external network requests, boundary access logs, internal network responses, and internal lateral access behavior in real time. A two-level correlation is then performed using a time-series merging engine to generate a boundary multi-path session trajectory. This trajectory, based on node sequence, edge time difference, and protocol type, comprehensively characterizes the entire process of a communication activity, from external network initiation, boundary device access, internal network response, to internal lateral propagation. This enables fine-grained monitoring of the role and behavior of each node in the link, the paths between nodes, and the session order. This invention can not only capture single abnormal events but also reconstruct the dynamic propagation path of the entire communication link, achieving full-process visualization at the link level and providing high-precision foundational data for subsequent anomaly detection and source tracing analysis.
[0038] This invention constructs a node historical role benchmark, including a role probability distribution vector and a role transition conditional probability matrix, to quantitatively analyze the deviation of node roles in the current session. Role drift type is determined by relative entropy and conditional probability deviation. Combining drift path fingerprinting, longest common subsequence, and path edit distance algorithms, candidate links are tracked for reuse across sessions, concatenated to form abnormal communication link continuation paths, and alarms are generated based on persistence strength and drift weight. Through role drift and link continuation path analysis, this invention achieves high-precision, traceable detection of abnormal communication links at the internal and external network boundaries, improving the accuracy and reliability of security protection. Attached Figure Description
[0039] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only for this invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0040] Figure 1 This is a schematic diagram of the method flow according to an embodiment of the present invention;
[0041] Figure 2 This is a schematic diagram of link drift in an embodiment of the present invention. Detailed Implementation
[0042] The present invention will now be described in detail with reference to the accompanying drawings and specific embodiments. Those skilled in the art may employ other alternative methods to implement some well-known technologies; moreover, the accompanying drawings are only for more specific description of the embodiments and are not intended to specifically limit the present invention.
[0043] like Figures 1-2 As shown, a method for detecting abnormal communication links at the boundary between internal and external networks includes the following steps:
[0044] S1: At the boundary between internal and external networks, collect multi-source communication events in real time, including external network request records, boundary access logs, internal network response behavior records, and internal lateral access behavior records. Merge these events according to source node, target node, protocol type, access order, and time correlation to generate a boundary multi-path session trajectory. The boundary multi-path session trajectory represents the actual propagation process of communication behavior on both sides of the internal and external network boundary.
[0045] S1 specifically includes:
[0046] S11, Multi-source data acquisition: To capture the full picture of the communication link at the boundary between internal and external network access, this invention deploys multiple real-time acquisition probes at different network nodes to capture inbound and outbound traffic at the boundary and internal lateral access behavior, specifically including:
[0047] S111: Deploy the first acquisition probe at the inbound traffic mirroring port at the boundary between the internal and external networks to capture all data packets sent from the external network to the internal network in real time; for each data packet, extract the following information to form an external network request record, represented as:
[0048] ;
[0049] in, For external network request logs, The source IP address of the data packet. The destination IP address of the data packet. The source port number. The target port number. For transport layer protocol types, such as TCP / UDP, For packet capture timestamps, This is the length of the data packet payload, i.e., the number of bytes.
[0050] S112: Deploy a second data collection probe at the log output interface of the border device to receive pass / reject and NAT translation logs in real time, forming a border pass log, represented as:
[0051] ;
[0052] in, For border clearance logs, To mark whether to allow or deny, For logging timestamps, use edge devices such as firewalls and gateways.
[0053] S113: Deploy a third acquisition probe at the outbound traffic mirroring port at the boundary between the internal and external networks to capture data packets from the internal network responding to external network requests in real time, and extract the following information to form an internal network response behavior record, represented as:
[0054] ;
[0055] in, For internal network response behavior logging, In response, a status code, such as an HTTP status code or a TCP ACK flag, This is the timestamp for packet capture.
[0056] S134: Deploy a fourth data collection probe on the mirror port of the core switch in the internal network or on each host terminal to collect lateral access data packets between internal hosts in real time, forming lateral access records, represented as follows:
[0057] ;
[0058] in, For lateral access records, This is a timestamp for lateral access behavior.
[0059] The above four types of data collection can ensure that the entire process of communication behavior, from initiation on the external network to response on the internal network and lateral propagation within the network, is completely captured.
[0060] S12, Initial Session Merging: Record the collected external network request records. Border clearance log Internal network response behavior logs With internal lateral access records The data is aggregated into the time-series merging engine, where initial session association is performed according to the first-level association rules, including:
[0061] Using source IP, destination IP, and transport layer protocol type as the first-level association key, pairs of communication devices belonging to the same communication pair and whose timestamp difference is less than a preset association window threshold are associated with each other. The records are temporarily stored in the same session buffer, as shown below:
[0062] ;
[0063] in, For session buffer, For record Time difference with reference record The threshold for the session association time window ranges from 0.1 to 5. Communication at the internal and external network boundaries typically involves RTT latency; for example, the round-trip time between the internal network and the boundary firewall, or between the boundary and the external network, is generally tens to hundreds of milliseconds. Setting a lower limit for the window ensures that records for a single request-response are not split into different session buffers. Common application protocols such as HTTP / TCP may have intervals of tens of milliseconds to several seconds during connection establishment, handshake, and request-response processes. For applications with long connections or batch requests, the window can be appropriately increased to ensure that data packets within the same session are not split. A time window that is too small may cause the same logical session to be split into multiple buffers, increasing the complexity of subsequent association; a time window that is too large may mix unrelated sessions into the same buffer, reducing the accuracy of abnormal link location.
[0064] S12 aggregates the multi-source communication records collected, including external network request records, border access logs, internal network response behavior records, and internal lateral access behavior records, into the time-series merging engine. The engine uses the source IP, destination IP, and transport layer protocol type as the primary association key, and temporarily stores records belonging to the same communication pair and with a time difference less than the session association time window threshold into the same session buffer, thereby aggregating multiple events that are temporally continuous and belong to the same logical communication. In the session buffer, the records are arranged in chronological order, providing a basis for subsequent secondary access sequence association. At the same time, this initial merging can ensure that cross-node, cross-protocol, or cross-session segment communication behaviors can be processed uniformly, thus laying the foundation for the construction of border multi-path session trajectories.
[0065] S13, Second-level access sequence association: in the session buffer Within this framework, further secondary associations are established based on the access order, including:
[0066] S131: For each external network request record Find the earliest internal network response record. ,satisfy Then and The relationship forms a complete request-response pair;
[0067] S132: For boundary clearance logs Insert it into the corresponding request-response pair as an intermediate proof node;
[0068] S133: Internal lateral access records ,like If they belong to the same source / target IP, they are concatenated to the corresponding request-response pair to form a session extension path.
[0069] S14, Session Trajectory Generation: Arrange the request-response pairs and lateral access records that have undergone secondary associations in ascending order of time to construct a directed graph-like boundary multipath session trajectory, represented as:
[0070] ;
[0071] in, The boundary multipath session trajectory is in the form of a directed graph. , Each edge includes the time difference between nodes. and protocol type tags , trajectory It can fully characterize the entire process of a communication, from initiation on the external network, through boundary access, internal network response, and then to internal lateral propagation.
[0072] S2: Using the boundary multipath session trajectory as input, identify the link roles undertaken by each communication node during the historical access process and establish corresponding historical role benchmarks; compare the communication nodes in the current boundary multipath session trajectory with the historical role benchmarks to identify communication behaviors with role substitution, role overstepping, role missing and role reversal phenomena, and generate link role drift results; locate the abnormal communication link candidate set formed by changes in the legitimate link usage based on the link role drift results.
[0073] S2 specifically includes:
[0074] S21, Historical Role Benchmark Construction: Based on Boundary Multipath Session Trajectory As input, extract the predetermined historical time window. All communication nodes involved in the trajectory For each node The statistical analysis of its role and behavior in the historical trajectory includes:
[0075] S211: The total number of times a node acts as an initiator, expressed as:
[0076] ;
[0077] in, This is a set of multi-path session trajectories at historical boundaries. The historical time window length is used to limit the range of historical boundary multi-path session trajectory data participating in historical role statistical analysis. The window should not be too short, otherwise the probability distribution of node roles will be unstable and easily interfered with by occasional behavior. The window should not be too long, otherwise the deviation between historical behavior and current behavior may be too large, reducing the sensitivity of role drift detection. The value range is 7-10, which can cover the daily business activity cycle and ensure that the node role statistics are representative. This indicates the number of times a node appears as a source. For the single communication node to be analyzed, A collection of historical nodes Represents the set of all communication nodes. Indicates the first A multi-path conversation trajectory along a historical boundary. This indicates an indicator function that, when the condition within the parentheses is true, When the condition inside the parentheses is not true, This is used to count the number of times a node appears in historical sessions. The source node represents the historical boundary multipath session trajectory. The starting communication node in the process.
[0078] S212: The total number of times a node acts as a receiver, expressed as:
[0079] ;
[0080] in, This indicates the number of times a node appears as a target. The target node identifier represents the historical boundary multipath session trajectory. The termination communication node in the process.
[0081] S213: The hop count distribution of a node relative to the starting node of each historical session trajectory is represented as follows:
[0082] ;
[0083] in, For the node hop count sequence, Node hop count represents the number of hops in a node. In the The hop count in the multipath session trajectory of a historical boundary. This indicates the number of multipath session trajectories at the historical boundary.
[0084] S215: Based on the statistical results, the link role of each node is classified into one or more of the following types:
[0085] Initiator role: The node primarily initiates connections;
[0086] Pure responder role: The node primarily receives connections;
[0087] Relay forwarder role: The node acts as an intermediate hop node multiple times in the trajectory;
[0088] Hybrid roles: Nodes simultaneously exhibit initiation, response, and relay behaviors;
[0089] Build historical role benchmarks for each node, including:
[0090] (1) Character probability distribution vector:
[0091] ;
[0092] in, Let be the probability distribution vector of the role, representing the node. A vector composed of the probability of each character type appearing within a historical time window. For the probability of the initiator role, For the probability of responder roles, For the probability of a relay role, For mixed character probabilities;
[0093] (2) Role switching conditional probability matrix:
[0094] ;
[0095] in, Indicates that the node is from the role Convert to character The conditional probability, , These represent the character's state before and after the role transition. As the initiator, As a responder, As a relayer, As a hybrid character, This is a role transition conditional probability matrix, used to describe the pattern of role changes for each node in the historical multipath session trajectory. The rows of the matrix represent the node's role state in the current session, and the columns represent the possible role states the node may have in the next session. Each matrix element... This indicates that the node's current role is In this case, the next session will change to a different role. The conditional probability matrix can be used to quantify the stability and transition patterns of a node's role in its historical trajectory, thereby determining whether an abnormal role drift has occurred in the current session.
[0096] This step constructs a historical role baseline for each communication node by statistically analyzing the initiation, reception, and relay behaviors of each communication node in the historical boundary multipath session trajectory. This baseline includes a role probability distribution vector and a role transition conditional probability matrix, which are used to quantify the role types and transition patterns of nodes in the historical trajectory. This allows for the determination of whether a node has experienced role drift in the current session, providing a basis for detecting abnormal communication links.
[0097] S22, Comparison of current role with historical baseline: The current boundary multipath session trajectory is compared. Each node Its historical role benchmark The comparison is performed to calculate the node role deviation, including:
[0098] S221: Character probability deviation, expressed as:
[0099] ;
[0100] in, For the current boundary multipath session trajectory, This is the set of communication nodes in the current trajectory. For nodes Historical role probability vector For nodes The conditional probability matrix of historical role transformation For nodes in the current session Actual performance of the role probability, For nodes Characters in the historical character probability vector probability, Represents a node The deviation of the character probability, i.e., the relative entropy.
[0101] S222: Role switching deviation, expressed as:
[0102] ;
[0103] in, This represents the probability of role switching in the current session. For the probability of role switching in historical conversations, Represents a node Role switching deviation.
[0104] S223: When relative entropy or conversion deviation This triggers a character drift detection, which is further identified as character substitution, character offside, character missing, or character reversal based on the specific manifestation of the deviation.
[0105] in, The relative entropy is the threshold for role deviation. It measures the degree of deviation between the current role probability vector and the historical probability vector. If the threshold is too low, normal business fluctuations may be misjudged as role drift. If the threshold is too high, real anomalies may be missed. Therefore, the value range is 0.3-0.7. The role conversion deviation threshold is used to measure the deviation between the current conversion probability and the historical conditional probability. The threshold setting needs to take into account the normal role conversion frequency of the node. The threshold can be appropriately reduced for low-frequency nodes and appropriately increased for high-frequency conversion nodes. The value range is 0.2-0.5.
[0106] After obtaining the historical role baseline of the communication nodes, this step compares and analyzes the actual role behavior of each communication node in the current boundary multipath session trajectory with its historical role behavior. By calculating the degree of deviation between the current role distribution and the historical role distribution, as well as the degree of difference between the current role transition pattern and the historical role transition pattern, it determines whether the node still maintains its normal historical role positioning. When the role characteristics or role change patterns of the node currently deviate significantly from the historical pattern, it is determined that the node has experienced role drift. Further, based on the drift behavior, it is identified as role substitution, role overstepping, role absence, or role reversal. This reveals situations where the communication node, although still participating in normal communication, has undergone abnormal changes in its actual responsibility in the link, providing a basis for the generation of subsequent abnormal communication link candidate sets.
[0107] S23, Structuring of Character Drift Results: For each identified character drift type, the results are stored in a structured manner, including:
[0108] Role replacement: Records the mapping relationship between the original role node and the node being replaced;
[0109] Role offside: Records the offside event, the target role type, and the time period in which it occurred;
[0110] Role Missing: Mark the location and duration of the missing node in the session track;
[0111] Role reversal: Records the character before the reversal, the character after the reversal, and the time of the turning point;
[0112] All records are sorted according to the session trajectory timeline, forming a node-level link role drift result set. , represented as:
[0113] ;
[0114] in, This is a set of link role drift results at the node level. To replace the event record for the character, Recording offside events for characters. Record events related to missing characters. Record the role reversal event.
[0115] S24, Generation of candidate sets of abnormal communication links: based on link role drift results Extract all communication links involving the drifting nodes and assign them a base drift weight, represented as:
[0116] ;
[0117] in, For link-to-link drift weights, The base weight for a single drift is 0.2-0.5. The value should not be too high for a single event to avoid false alarms due to normal fluctuations.
[0118] The same link may experience multiple or different types of drift, and the weights are accumulated to form the link's overall drift weight. ;
[0119] If the overall drift weight of the link exceeds the preset threshold ,Right now If the link is identified as an abnormal communication link candidate, it will be marked with a drift type combination, weight value, and timestamps of the first and last drifts, thus forming an abnormal communication link candidate set. ;
[0120] in, For link-to-link drift weights, For the candidate set of abnormal communication links, As a link drift threshold, combined with the basic weight of a single event. The maximum number of drifts that may occur on the link is set to ensure that the threshold is higher than the occasional single or double drifts to reduce the false alarm rate. If the threshold is lower than the typical normal fluctuation weight accumulated by the total weight, it is easy to misjudge normal links as abnormal. If the threshold is too high, abnormal links may be missed. The value range is 1.0-1.5.
[0121] S3: Taking the candidate set of abnormal communication links as input, perform cross-time correlation tracking on candidate links in different sessions, identify persistent communication behaviors formed by repeatedly using the same role drift path, construct abnormal communication link continuation path, and generate abnormal communication link detection results based on the abnormal communication link continuation path.
[0122] S3 specifically includes:
[0123] S31, Drift path fingerprint generation: using candidate sets of abnormal communication links As input, extract complete information for each candidate link at each occurrence, including:
[0124] Source node set: ;
[0125] Target node set: ;
[0126] Character drift type vector: ;
[0127] Drift occurrence time window: ;
[0128] Path node sequence: ;
[0129] All candidate links are standardized and encoded according to the path node sequence to form a drift path fingerprint with node role identifier as the basic unit, represented as:
[0130] ;
[0131] in, This represents the set of nodes in the candidate link that are responsible for initiating communication. Indicates the number of source nodes. This represents the set of nodes in the candidate link that perform the function of receiving communication. Indicates the number of target nodes. This represents the set of all role drift events involved in the current candidate link. Indicates the number of drift events. This represents the sequence formed by arranging all nodes traversed by the candidate link in the order of communication. Indicates the total number of path nodes. This indicates the timestamp at which the system first recognized the current character's drift event, i.e., the start time of the drift. This indicates the timestamp of the last time the system detected the current character's drift event, i.e., the time the drift ended. The drift path fingerprint represents the feature identifier of the character's drift path obtained after standardized encoding. This method encodes path nodes and their corresponding drift type sequences into vector form for subsequent similarity comparison. First, it reads the path node sequence of candidate links and determines the role type of each node in the current session according to the communication order. Then, it de-identifies and standardizes the node identity information, retaining only the node's relative position in the link, role identifier, and drift type identifier. Next, it generates an encoding unit for each node according to a fixed format: node number—role identifier—drift type identifier. Finally, it concatenates these encoding units in the path order to obtain the drift path fingerprint. This method does not directly rely on specific IP addresses or hostnames but preserves the link role structure and drift pattern, enabling it to determine whether the same role drift path has been reused even if the node address changes in different sessions.
[0132] S32, Cross-session correlation tracing: Performing cross-temporal correlation tracing on candidate links appearing in different sessions, including:
[0133] S321: Set a sliding window that spans time The drift path fingerprint of all candidate links within the window. Perform pairwise comparisons;
[0134] in, The sliding window spans time and is used to limit the similarity comparison of candidate links within a certain time range. Network attacks or abnormal behaviors usually occur consecutively in a short period of time. Multiple candidate links may have time intervals, but the continuity will not be very long. If the window is too short, it may miss continuous reuse behavior across sessions. If the window is too long, it will increase the amount of computation and may misclassify irrelevant candidate links as duplicates. The value range is 5-30.
[0135] S322: For character drift type sequences, use the longest common subsequence algorithm to calculate the similarity between any two links. , represented as:
[0136] ;
[0137] The longest common subsequence algorithm is a classic sequence matching algorithm used to measure the similarity between two sequences. It finds the longest common subsequence in two sequences while keeping the relative order of elements unchanged. The algorithm finds the length of the longest common subsequence that keeps the order and repeats in the two sequences, and then divides this length by the larger of the lengths of the two sequences for normalization.
[0138] Calculate the edit distance for the path node sequence. , represented as:
[0139] ;
[0140] in, , For drift path fingerprint, , A sequence of path nodes. Indicates the similarity of character drift type sequences. Indicates the edit distance of the path node sequence;
[0141] S323: When and When two candidate links are used repeatedly, it is determined that they are using the same role drift path.
[0142] in, A threshold value of 0.7-0.9 is set to determine the reuse threshold for drift paths. This threshold can capture highly similar reused paths while avoiding false positives from occasional similar sequences. The tolerance value for path sequence differences is 1-2, which allows for minor changes in normal paths while still identifying it as a reuse of the same role's drift path.
[0143] S33, Construction of Abnormal Communication Link Continuation Paths: Candidate links identified as reusing the same role's drift path are connected in sequence according to their occurrence time to form continuous abnormal communication link continuation paths. , represented as:
[0144] ;
[0145] Fill time intervals between adjacent candidate links. ;
[0146] The continuation path includes:
[0147] Initiation Session Identifier: The session to which the first candidate link belongs;
[0148] End-of-session identifier: The session to which the last candidate link belongs;
[0149] Total duration: ;
[0150] Drift Evolution Sequence: A sequence of vectors representing the drift types of characters arranged in chronological order;
[0151] Drift weight change curves at each stage: sampling points The corresponding weights for each drift event.
[0152] in, This represents the set of continuous abnormal communication link continuation paths formed by sequentially connecting candidate links that are determined to reuse the same role's drift path. To represent the total number of candidate links in the continuation path, each element represents an attribute of the corresponding candidate path. For candidate link number The drift path fingerprint of a link is generated by encoding the path node sequence and the role drift type, and is used to uniquely identify the role drift pattern of the link. For the first The start time of each candidate link drift event. For the first The end time of each candidate link drift event. For the first The drift weights of the candidate links, The time interval between adjacent links.
[0153] S34, Generation of abnormal communication link detection results: based on the abnormal communication link continuation path Generate abnormal communication link detection results, including:
[0154] S341: The strength of computational persistence is expressed as:
[0155] ;
[0156] in, This indicates the persistence strength of abnormal communication links, measuring how frequently the same abnormal communication path is reused per unit of time. The greater the persistence strength, the more frequently abnormal communication links are reused in a short period of time, and the stronger the persistence of the abnormal behavior. The number of candidate links included in the path. The total duration of the continuous path;
[0157] S342: If Output a high-risk alarm, along with a complete evolutionary trajectory of the continuation path. However, if there are high-weight drift types within the path, output a medium-risk warning and mark the starting node and the target node;
[0158] in, The threshold for determining persistence intensity is defined as follows: role-shifting paths in normal business communication typically have strong randomness and low reuse frequency, while abnormal communication behaviors such as boundary bypassing, covert proxies, lateral penetration, and long-term dwell communication often continuously reuse established role-shifting paths, thus having a higher path reuse density. The persistence intensity threshold ranges from 0.05 to 0.20, which can effectively identify abnormal communication behaviors with continuous reuse characteristics, while avoiding misjudging occasional repeated accesses in normal business as high-risk anomalies, thereby balancing detection sensitivity and false alarm control.
[0159] High-weight drift types include role overstepping, role reversal, and role replacement at critical nodes. These types of drifts usually mean a substantial change in the boundaries of responsibilities in the communication path, making it easier to deal with high-risk security events such as boundary bypassing, privilege abuse, establishment of covert proxy channels, and lateral penetration and spread. Therefore, they are assigned higher risk weights when calculating the overall drift weight of the link and the alarm level.
[0160] S343: Output the abnormal communication link detection results to the boundary security controller interface in the form of structured data. The fields should include at least the abnormal link identifier, the list of involved nodes, the drift type statistics, the total duration, and the alarm level.
[0161] This invention encompasses any substitutions, modifications, equivalent methods, and solutions made within the spirit and scope of this invention. To provide the public with a thorough understanding of this invention, specific details are described in detail in the following preferred embodiments; however, those skilled in the art will fully understand the invention even without these details. Furthermore, to avoid unnecessary misunderstanding of the essence of this invention, well-known methods, processes, procedures, components, and circuits are not described in detail.
[0162] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A method for detecting abnormal communication links at the boundary of internal and external network access, characterized in that, Includes the following steps: S1: At the boundary between internal and external network access, multi-source communication events are collected in real time, including external network request records, boundary access logs, internal network response behavior records, and internal lateral access behavior records. These events are then merged according to source node, target node, protocol type, access order, and time correlation to generate a boundary multi-path session trajectory. The boundary multi-path session trajectory represents the actual propagation process of communication behavior on both sides of the internal and external network boundary. S2: Using the boundary multipath session trajectory as input, identify the link roles undertaken by each communication node during historical access and establish corresponding historical role benchmarks; compare the communication nodes in the current boundary multipath session trajectory with the historical role benchmarks to identify communication behaviors with role substitution, role overstepping, role missing, and role reversal phenomena, and generate link role drift results; locate the abnormal communication link candidate set formed by changes in the legitimate link usage based on the link role drift results; S3: Using the candidate set of abnormal communication links as input, perform cross-time correlation tracking on candidate links in different sessions, identify persistent communication behaviors formed by repeatedly using the same role drift path, construct abnormal communication link continuation paths, and generate abnormal communication link detection results based on the abnormal communication link continuation paths.
2. The abnormal communication link detection method for internal and external network access boundaries according to claim 1, characterized in that, S1 specifically includes: S11: Deploy a first collection probe at the inbound traffic mirroring port of the internal / external network access boundary to capture all data packets sent from the external network to the internal network in real time, extract the five-tuple information, timestamp, and payload length of each data packet to form an external network request record; deploy a second collection probe at the log output interface of the boundary device to receive the pass, deny, and NAT translation logs generated by the firewall or gateway device in real time to form a boundary pass log; deploy a third collection probe at the outbound traffic mirroring port of the internal / external network access boundary to capture data packets of the internal network responding to external network requests in real time, extract the five-tuple information, timestamp, and response status code of the response data packets to form an internal network response behavior record; deploy a fourth collection probe at the mirroring port of the internal network core switch or on the security agent of each host terminal to collect the lateral access data packets between internal hosts in real time, extract the source IP, destination IP, protocol type, port, and access time to form an internal lateral access behavior record; the five-tuple information includes the source IP address, destination IP address, source port, destination port, and transport layer protocol; S12: The external network request records, boundary access logs, internal network response behavior records and internal lateral access behavior records are uniformly summarized into the time-series merging engine. The source IP address, target IP address and transport layer protocol type are used as the first-level association key values. Records belonging to the same communication pair and whose timestamp difference is less than the preset association window threshold are temporarily stored in the same session buffer. S13: Within the session buffer, perform the second-level association according to the access order.
3. The abnormal communication link detection method for internal and external network access boundaries according to claim 2, characterized in that, S13 specifically includes: For external network request records, find the earliest internal network response behavior record that appears after the external network request record and whose target IP matches the source IP of the external network request record. If it exists and the timestamp difference is less than the request-response timeout threshold, then associate it as a complete request-response pair. For the release actions recorded in the boundary release log, insert them as intermediate proof nodes between the corresponding requests and responses; For internal lateral access behavior records, they are concatenated with the associated request-response pairs in chronological order. When the timestamp of an internal lateral access behavior record is after the external request record and belongs to the same source IP or target IP, the internal lateral access behavior record is used as an extension path of the corresponding session trajectory.
4. The abnormal communication link detection method for internal and external network access boundaries according to claim 3, characterized in that, S1 further includes arranging multiple request-response pairs and lateral access records obtained after the first-level association and the second-level association, which belong to the same source node, the same target node, the same protocol type, and are temporally continuous, in ascending order of time, and using the time difference between each record as the edge weight to generate a directed graph-form boundary multipath session trajectory; the boundary multipath session trajectory includes node sequence, edge timestamp difference, and protocol type label to fully characterize the entire process of a communication behavior from external network initiation, boundary access, internal network response, and internal lateral propagation.
5. The abnormal communication link detection method for internal and external network access boundaries according to claim 1, characterized in that, S2 specifically includes: S21: Using the boundary multipath session trajectory as input, extract all communication nodes involved in the boundary multipath session trajectory within a predetermined historical time window. For each communication node, count the total number of times it initiates a connection as a source node, the total number of times it is connected as a target node in the historical boundary multipath session trajectory, and the hop count distribution relative to the trajectory start node in each session trajectory. Based on the statistical results, classify the link role of each communication node into one or more combinations of pure initiator role, pure responder role, relay forwarder role, and mixed role. Construct the historical role benchmark of the communication node by the role type and frequency of occurrence of each communication node in different sessions. S22: Compare each communication node in the current boundary multipath session trajectory with the corresponding historical role benchmark to determine whether role drift has occurred, and identify role drift as role substitution, role offside, role missing or role reversal; S23: For identified role replacements, record the identity mapping relationship between the original role node and the replaced node; for identified role overstepping, record the overstepping node, the type of super-privilege role reached by the overstepping, and the time period of the overstepping; for identified role missing, mark the position of the missing node in the expected session trajectory and the duration of the missing information; for identified role reversal, record the role before reversal, the role after reversal, and the turning point time of the reversal; store all identification results in a structured manner according to the timeline of the session trajectory to generate link role drift results; S24: Based on the link role drift results, extract all communication links in which the communication node that has experienced role drift participates, assign a corresponding basic drift weight value to each link according to the drift type, and accumulate the weights of multiple drifts or multiple drift types that occur on the same link to obtain the comprehensive drift weight of the link; mark the links whose comprehensive drift weight exceeds the preset drift threshold as abnormal communication link candidate set; each link in the abnormal communication link candidate set is accompanied by the corresponding drift type combination, drift weight value, and timestamps of the first and last drift occurrences.
6. The abnormal communication link detection method for internal and external network access boundaries according to claim 5, characterized in that, The historical role baseline includes a probability distribution vector of role types and a conditional probability matrix of role transitions. The conditional probability matrix of role transitions quantifies the role change pattern of each communication node in the historical multipath session trajectory. The rows represent the current role state of the communication node, and the columns represent the possible role state of the communication node in the next session.
7. The abnormal communication link detection method for internal and external network access boundaries according to claim 5, characterized in that, S22 specifically includes: Calculate the relative entropy between the role vector of the actual performance of the communication node in the current session and the probability distribution vector in the historical role benchmark; Calculate the deviation between the role transition probability of the communication node in the current session relative to the previous hop node and the corresponding conditional probability in the historical role baseline; When the relative entropy exceeds the preset character deviation threshold or the deviation value exceeds the preset conversion deviation threshold, the character drift judgment is triggered, and the drift is identified as character substitution, character offside, character missing or character reversal according to the specific manifestation of the drift.
8. The abnormal communication link detection method for internal and external network access boundaries according to claim 1, characterized in that, S3 specifically includes: S31: Using the candidate set of abnormal communication links as input, extract complete information for each candidate link at each occurrence, including the source node set, target node set, role drift type vector, drift time window, and path node sequence of the candidate link in the boundary multipath session trajectory; standardize and encode all candidate links according to the corresponding path node sequence to form a drift path fingerprint with node role identifier as the basic unit; S32: Set a time-sliding window, compare the drift path fingerprints of all candidate links in the window pairwise, use the longest common subsequence algorithm to calculate the similarity between any two candidate links on the role drift type sequence, and compare the edit distance of the path node sequence; when the similarity exceeds the preset reuse threshold and the edit distance is less than the preset path difference tolerance value, it is determined that the corresponding two candidate links are reused for the same role drift path.
9. The abnormal communication link detection method for internal and external network access boundaries according to claim 8, characterized in that, S3 further includes connecting all candidate links that are determined to reuse the same role's drift path in sequence according to the time of occurrence, extracting the start timestamp, end timestamp, drift type vector and drift weight value of each candidate link in sequence, and filling the time interval value between two adjacent candidate links to form an abnormal communication link continuation path with time axis continuity. An abnormal communication link detection result is generated based on the abnormal communication link continuation path.
10. The abnormal communication link detection method for internal and external network access boundaries according to claim 8, characterized in that, The generation of the abnormal communication link detection result specifically includes: For each abnormal communication link continuation path, the persistence strength is calculated, and the persistence strength is equal to the ratio of the number of candidate links included in the abnormal communication link continuation path to the total duration. When the persistence intensity exceeds the preset persistence threshold, a high-risk alarm is output along with the complete evolution trajectory of the abnormal communication link continuation path; When the persistence intensity is lower than the preset persistence threshold, but there is a high-weight drift type in the path of the abnormal communication link, a medium-risk warning is output and the starting node and target node of the corresponding path are marked; the abnormal communication link detection results are output to the interface of the boundary security controller in a structured data format, and the abnormal communication link detection results include at least the abnormal link identifier, the list of involved nodes, the drift type statistics, the duration and the alarm level.