Traffic abnormal behavior detection and tracing method and system based on multi-agent graph

CN122824433APending Publication Date: 2026-09-25BEIJING RONGXIN DATAINFO SCI & TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202610862103.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-15
Publication Date
2026-09-25

AI Technical Summary

Technical Problem

然而,该方案在以下方面存在不足:第一,其知识图谱为单一中心化构建,缺乏多智能体协同机制,无法充分利用不同检测视角的互补信息,导致对复杂攻击模式的检测能力有限;第二,该方案仅实现异常诊断功能,未涉及异常行为的传播路径分析和溯源定位,在网络安全事件的闭环处置中存在功能缺口

Benefits of technology

[0017]本发明公开的一种基于多智能体图谱的流量异常行为检测与溯源方法及系统,首先部署多个功能智能体并以图结构组织为多智能体图谱,进而由数据采集智能体实时采集网络流量行为数据,由特征提取智能体进行多维度特征提取生成行为特征向量,随后由关系建模智能体构建流量行为关系图并与多智能体图谱融合,由异常判别智能体基于融合图谱中节点行为偏离度输出异常检测结果,最终在检测到异常时由溯源分析智能体沿融合图谱边逆向追溯异常传播路径以定位异常源节点。本发明通过多智能体协作机制与图谱结构驱动的协同检测溯源能力,有效克服了传统单一检测模型对复杂攻击模式识别能力不足以及缺乏溯源能力的缺陷,同时通过多级阈值分级响应、多模态决策融合、外部威胁情报协同、检测意图驱动的动态能力编排以及流量噪声特征利用等技术手段,进一步提升了异常检测的精确度、鲁棒性和实时性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122824433A_ABST
    Figure CN122824433A_ABST
Patent Text Reader

Abstract

The application provides a traffic abnormal behavior detection and tracing method and system based on a multi-agent graph, organizes each functional agent into a node of a multi-agent graph in a graph structure, takes data flow and control flow between agents as a graph edge, then collects network traffic behavior data in real time by a data collection agent, extracts multi-dimensional features by a feature extraction agent to generate a behavior feature vector, subsequently constructs a traffic behavior relationship graph by a relationship modeling agent and fuses the graph with the multi-agent graph, outputs an abnormal detection result based on a node behavior deviation degree in the fused graph by an abnormality discrimination agent, and finally traces an abnormal propagation path along the fused graph edge in reverse to locate an abnormal source node when an abnormality is detected; the application realizes accurate identification and efficient tracing of network traffic abnormal behavior through a multi-agent cooperation and graph structure driven collaborative detection and tracing mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and more specifically, to a method and system for detecting and tracing abnormal traffic behavior based on multi-agent graphs. Background Technology

[0002] With the widespread application of cloud computing, the Internet of Things, and 5G communication technologies, network traffic is growing exponentially, and network attack methods are becoming increasingly complex and covert. Traditional traffic anomaly detection methods based on signature matching or single statistical models suffer from prominent problems such as low detection accuracy, high false positive rate, and inability to effectively trace the source of attacks when facing new types of attacks such as advanced persistent threats, distributed denial-of-service attacks, and zero-day exploits.

[0003] In the prior art, Chinese patent CN120729739A discloses a method and system for intelligent diagnosis of abnormal data in communication networks based on knowledge graphs. This method constructs a knowledge graph of communication networks by integrating multi-source heterogeneous data and dynamically updates the entity states, relation weights, and attribute values ​​in the knowledge graph using an incremental learning mechanism, thereby achieving intelligent diagnosis of abnormal data in communication networks. However, this solution has the following shortcomings: First, its knowledge graph is constructed in a single centralized manner, lacking a multi-agent collaborative mechanism, and cannot fully utilize complementary information from different detection perspectives, resulting in limited detection capabilities for complex attack patterns; second, this solution only implements the abnormal diagnosis function and does not involve the analysis of the propagation path and source tracing of abnormal behavior, leaving a functional gap in the closed-loop handling of network security incidents.

[0004] Chinese patent CN120498844B discloses a method and system for detecting network traffic anomalies based on knowledge graphs. This method acquires network traffic characteristics through protocol awareness and constructs a traffic knowledge graph for anomaly detection. However, this solution has the following drawbacks: the knowledge graph is constructed statically, making it impossible to adjust the graph structure and detection strategy in real time according to the dynamic changes in the detection task; furthermore, this solution also lacks the ability to trace the propagation chain of abnormal behavior, making it unable to quickly locate the source of the attack after an anomaly is detected.

[0005] Therefore, there is an urgent need for a technical solution that can achieve accurate detection and efficient source tracing of abnormal network traffic behavior through multi-agent collaboration and graph structure-driven approaches. Summary of the Invention

[0006] In view of the above problems, the purpose of this invention is to provide a method and system for detecting and tracing abnormal network traffic behavior based on multi-agent graphs. Through multi-agent collaborative work and a graph structure-driven detection and tracing mechanism, it can achieve high-precision detection of abnormal network traffic behavior and provide complete tracing capabilities from anomaly discovery to source location.

[0007] The first aspect of this invention provides a method for detecting and tracing abnormal traffic behavior based on multi-agent graphs, comprising: Deploy multiple functional agents, including at least a data acquisition agent, a feature extraction agent, a relationship modeling agent, an anomaly detection agent, and a source tracing analysis agent. Organize each functional agent into a graph structure as a graph node of the multi-agent graph, and use the data flow and control flow between each functional agent as the graph edge of the multi-agent graph to construct the multi-agent graph. The data acquisition agent collects traffic behavior data from the network traffic of the target network in real time. The feature extraction agent performs multi-dimensional feature extraction on the traffic behavior data to generate a behavior feature vector. The relationship modeling agent constructs a traffic behavior relationship graph based on the behavior feature vector, and then fuses the traffic behavior relationship graph with the multi-agent graph to obtain a fused graph. The anomaly detection agent outputs anomaly detection results based on the behavioral deviation of each node in the fused graph. When the anomaly detection result indicates the presence of abnormal behavior, the source analysis agent traces the propagation path of the abnormal behavior backward along the graph edges in the fused graph to locate the anomaly source node.

[0008] In this scheme, the step of outputting anomaly detection results based on the behavioral deviation degree of each graph node in the fused graph by the anomaly discrimination agent includes: calculating the behavioral deviation degree value of each graph node in the fused graph; comparing the behavioral deviation degree value with a preset first deviation threshold; when the behavioral deviation degree value is lower than the first deviation threshold, determining the graph node as a normal node; when the behavioral deviation degree value is greater than or equal to the first deviation threshold and lower than a second deviation threshold, determining the graph node as a suspicious node and triggering an enhanced monitoring mode, wherein the second deviation threshold is greater than the first deviation threshold; when the behavioral deviation degree value is greater than or equal to the second deviation threshold, determining the graph node as an abnormal node, triggering an anomaly alarm, and sending a source tracing start command to the source tracing analysis agent.

[0009] In this scheme, the step of outputting anomaly detection results based on the behavioral deviation of each graph node in the fused graph by the anomaly discrimination agent further includes: analyzing the behavioral feature vectors of each graph node in the fused graph using an anomaly detection algorithm based on a statistical distribution model through a first detection path deployed in the anomaly discrimination agent to generate a first discrimination result and a first confidence level; analyzing the structural features and node attributes of the fused graph using an anomaly detection model based on a graph neural network through a second detection path deployed in the anomaly discrimination agent to generate a second discrimination result and a second confidence level; obtaining the first discrimination result, the first confidence level, the second discrimination result, and the second confidence level through a fusion arbitration unit in the anomaly discrimination agent; when the first discrimination result is consistent with the second discrimination result and both the first confidence level and the second confidence level are higher than a preset confidence level threshold, the consistent discrimination result is output as the final anomaly detection result; when the first discrimination result is inconsistent with the second discrimination result, the first confidence level and the second confidence level are compared, and the discrimination result with the higher confidence level is selected as the final anomaly detection result.

[0010] This solution also includes: establishing a collaborative interaction protocol with an external threat intelligence system, obtaining real-time threat intelligence data from the external threat intelligence system through the collaborative interaction protocol; mapping the real-time threat intelligence data into threat intelligence graph nodes, and connecting the threat intelligence graph nodes to the fusion graph through associated edges; when the anomaly detection agent outputs anomaly detection results, cross-validating the anomaly detection results based on the threat feature information provided by the threat intelligence graph nodes, and increasing the confidence level of the anomaly detection results when the abnormal behavior features in the anomaly detection results match the threat feature information.

[0011] This solution further includes: receiving a detection intent description, which indicates the target type and priority of the current detection task; decomposing the detection intent description into multiple atomic detection intents through an intent parsing unit, each atomic detection intent corresponding to an independently executable detection subtask; retrieving matching functional capability atoms from a pre-built capability atom library based on each atomic detection intent, where each functional capability atom is a standardized encapsulation of a callable functional unit of each functional agent; assembling and sorting the retrieved functional capability atoms according to the current operating environment state and the priority of attention to generate an execution pipeline for the current detection task; distributing the execution pipeline to the corresponding functional agents for execution, and dynamically adjusting the execution pipeline based on execution feedback. The capability atom library is pre-constructed in the following way: the callable functional units of each functional agent are functionally decomposed, each functional unit is labeled with a functional tag and a resource consumption tag, and the labeled functional units are standardized and encapsulated in a unified interface format to form a set of functional capability atoms that can be retrieved and called.

[0012] This scheme further includes: acquiring traffic noise characteristic data of the target network through the data acquisition agent, the traffic noise characteristic data including the jitter amplitude of the data packet arrival interval and the frequency of traffic rate fluctuation; inputting the traffic noise characteristic data as a network state detection signal to the anomaly detection agent, the anomaly detection agent identifying the underlying congestion state and the queue depth change trend of the intermediate forwarding nodes of the target network based on the traffic noise characteristic data; using the underlying congestion state and the queue depth change trend as auxiliary discrimination features, jointly analyzing them with the behavior deviation, and outputting the anomaly detection result.

[0013] A second aspect of the present invention provides a traffic anomaly behavior detection and tracing system based on a multi-agent graph, comprising a memory and a processor. The memory includes a traffic anomaly behavior detection and tracing method program based on a multi-agent graph. When the processor executes the traffic anomaly behavior detection and tracing method program based on a multi-agent graph, it performs the following steps: Deploy multiple functional agents, including at least a data acquisition agent, a feature extraction agent, a relationship modeling agent, an anomaly detection agent, and a source tracing analysis agent. Organize each functional agent into a graph structure as a graph node of the multi-agent graph, and use the data flow and control flow between each functional agent as the graph edge of the multi-agent graph to construct the multi-agent graph. The data acquisition agent collects traffic behavior data from the network traffic of the target network in real time. The feature extraction agent performs multi-dimensional feature extraction on the traffic behavior data to generate a behavior feature vector. The relationship modeling agent constructs a traffic behavior relationship graph based on the behavior feature vector, and then fuses the traffic behavior relationship graph with the multi-agent graph to obtain a fused graph. The anomaly detection agent outputs anomaly detection results based on the behavioral deviation of each node in the fused graph. When the anomaly detection result indicates the presence of abnormal behavior, the source analysis agent traces the propagation path of the abnormal behavior backward along the graph edges in the fused graph to locate the anomaly source node.

[0014] In this scheme, the step of outputting anomaly detection results based on the behavioral deviation degree of each graph node in the fused graph by the anomaly discrimination agent includes: calculating the behavioral deviation degree value of each graph node in the fused graph; comparing the behavioral deviation degree value with a preset first deviation threshold; when the behavioral deviation degree value is lower than the first deviation threshold, determining the graph node as a normal node; when the behavioral deviation degree value is greater than or equal to the first deviation threshold and lower than a second deviation threshold, determining the graph node as a suspicious node and triggering an enhanced monitoring mode, wherein the second deviation threshold is greater than the first deviation threshold; when the behavioral deviation degree value is greater than or equal to the second deviation threshold, determining the graph node as an abnormal node, triggering an anomaly alarm, and sending a source tracing start command to the source tracing analysis agent.

[0015] In this scheme, the step of outputting anomaly detection results based on the behavioral deviation of each graph node in the fused graph by the anomaly discrimination agent further includes: analyzing the behavioral feature vectors of each graph node in the fused graph using an anomaly detection algorithm based on a statistical distribution model through a first detection path deployed in the anomaly discrimination agent to generate a first discrimination result and a first confidence level; analyzing the structural features and node attributes of the fused graph using an anomaly detection model based on a graph neural network through a second detection path deployed in the anomaly discrimination agent to generate a second discrimination result and a second confidence level; obtaining the first discrimination result, the first confidence level, the second discrimination result, and the second confidence level through a fusion arbitration unit in the anomaly discrimination agent; when the first discrimination result is consistent with the second discrimination result and both the first confidence level and the second confidence level are higher than a preset confidence level threshold, the consistent discrimination result is output as the final anomaly detection result; when the first discrimination result is inconsistent with the second discrimination result, the first confidence level and the second confidence level are compared, and the discrimination result with the higher confidence level is selected as the final anomaly detection result.

[0016] A third aspect of the present invention provides a computer-readable storage medium comprising a method program for detecting and tracing abnormal traffic behavior based on a multi-agent graph. When the method program is executed by a processor, it implements the steps of a method for detecting and tracing abnormal traffic behavior based on a multi-agent graph as described in any of the preceding claims.

[0017] This invention discloses a method and system for detecting and tracing abnormal traffic behavior based on a multi-agent graph. First, multiple functional agents are deployed and organized into a multi-agent graph. Then, a data acquisition agent collects network traffic behavior data in real time. A feature extraction agent extracts multi-dimensional features to generate behavioral feature vectors. Subsequently, a relationship modeling agent constructs a traffic behavior relationship graph and merges it with the multi-agent graph. An anomaly detection agent outputs anomaly detection results based on the deviation of node behavior in the fused graph. Finally, when an anomaly is detected, a source tracing analysis agent traces the anomaly propagation path backward along the edges of the fused graph to locate the source node. This invention effectively overcomes the shortcomings of traditional single detection models in recognizing complex attack patterns and lacking source tracing capabilities through a multi-agent collaboration mechanism and graph-structure-driven collaborative detection and tracing capabilities. Furthermore, through multi-level threshold hierarchical response, multi-modal decision fusion, external threat intelligence collaboration, dynamic capability orchestration driven by detection intent, and utilization of traffic noise features, the accuracy, robustness, and real-time performance of anomaly detection are further improved. Attached Figure Description

[0018] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly described below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope.

[0019] Figure 1 The flowchart of a traffic anomaly behavior detection and source tracing method based on multi-agent graph of the present invention is shown; Figure 2 The flowchart illustrates an anomaly detection method based on multi-level threshold hierarchical response provided by an embodiment of the present invention. Figure 3 The flowchart illustrates an anomaly detection method based on multimodal decision fusion provided by an embodiment of the present invention. Figure 4 The diagram shows a block diagram of a traffic anomaly behavior detection and tracing system based on multi-agent graph according to the present invention. Detailed Implementation

[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0021] Unless otherwise defined, all terms (including technical and scientific terms) used in embodiments of this invention have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. It should also be understood that terms such as those defined in a common dictionary should be interpreted as having a meaning consistent with their meaning in the context of the relevant art, and not as being interpreted in an idealized or highly formalized sense, unless expressly defined in this embodiment of the invention.

[0022] The terms "first," "second," and similar words used in the embodiments of this invention do not indicate any order, quantity, or importance, but are merely used to distinguish different components. Similarly, the terms "a," "one," or "the" do not indicate a quantity limitation, but rather indicate the presence of at least one. Likewise, the terms "including" or "comprising" mean that the element or object preceding the word encompasses the elements or objects listed after the word and their equivalents, without excluding other elements or objects. The terms "connected" or "linked" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. The steps preceding or following the steps in the method of the embodiments of this invention are not necessarily performed precisely in sequence. Instead, various steps can be processed in reverse order or simultaneously. Furthermore, other operations can be added to these processes, or one or more steps can be removed from them.

[0023] In addition, the functional modules in the various embodiments of the present invention can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0024] Figure 1 The flowchart of a traffic anomaly behavior detection and source tracing method based on multi-agent graphs according to the present invention is shown.

[0025] like Figure 1 As shown, the first aspect of this invention discloses a method for detecting and tracing abnormal traffic behavior based on a multi-agent graph, the method comprising: S102, deploy multiple functional agents, the multiple functional agents including at least a data acquisition agent, a feature extraction agent, a relationship modeling agent, an anomaly detection agent and a source analysis agent, organize each functional agent as a graph node of the multi-agent graph in a graph structure, and use the data flow and control flow between each functional agent as the graph edge of the multi-agent graph to construct the multi-agent graph; S104, The data acquisition agent collects traffic behavior data from the network traffic of the target network in real time; S106, The feature extraction agent performs multi-dimensional feature extraction on the traffic behavior data to generate a behavior feature vector. S108, the relationship modeling agent constructs a traffic behavior relationship graph based on the behavior feature vector, and fuses the traffic behavior relationship graph with the multi-agent graph to obtain a fused graph; S110, the anomaly detection agent outputs the anomaly detection result based on the behavioral deviation of each graph node in the fused graph; S112, when the anomaly detection result indicates the existence of abnormal behavior, the source analysis agent traces the propagation path of the abnormal behavior in reverse along the graph edges in the fused graph to locate the anomaly source node.

[0026] It should be noted that, in this embodiment, to address the problem that existing network traffic anomaly detection schemes either rely on a single model or lack source tracing capabilities, this case designs a multi-agent graph architecture. The key point of this approach is to change the traditional serial process of "detect first, then analyze" to an integrated parallel mechanism of "detection and source tracing." Specifically, the data acquisition agent is deployed at key network traffic convergence points, such as the mirror port of a core switch or the traffic egress of a border router, to capture and parse the basic fields of IP packets in real time, such as the five-tuple information, protocol type, payload length, and transmission rate, while simultaneously capturing the window negotiation value and flag sequence during the TCP handshake process. After obtaining this raw data, the feature extraction agent does not simply count the data, but extracts feature components from four dimensions: communication frequency, traffic volume, timing jitter, and protocol compliance. For example, the number of communication times per unit time for source IP-destination IP pairs, the byte entropy value of a single flow, the standard deviation of packet intervals, and the anomaly ratio of TCP option fields, etc., and then concatenates these components into a multi-dimensional behavioral feature vector. The task of the relation modeling agent is to "weave" these discrete feature vectors into a meaningful graph—each IP address or communication endpoint corresponds to a graph node, the communication relationships between nodes correspond to graph edges, and the edge weights comprehensively reflect the regularity of communication volume, communication frequency, and communication patterns. This traffic behavior relationship graph is then fused with the initially constructed multi-agent graph, essentially giving the agent network a pair of "eyes" that can see the global traffic situation. The anomaly detection agent uses this fused graph to determine anomalies by calculating the degree of deviation of each node from its historical baseline—the higher the deviation, the more suspicious the node's behavior. Once an anomaly is determined, the source tracing analysis agent traces back along the edges in the graph, starting from the anomaly node and hopping upstream to find the communication initiator until the initial attack or infection source is found. Through the above scheme, the entire system achieves an end-to-end automated closed loop from traffic perception, feature modeling, relation graph construction, anomaly detection to source localization.

[0027] Figure 2The flowchart illustrates an anomaly detection method based on multi-level threshold hierarchical response provided by an embodiment of the present invention.

[0028] like Figure 2 As shown in the embodiment of the present invention, the step of outputting anomaly detection results by the anomaly discrimination agent based on the behavioral deviation of each graph node in the fused graph includes: Calculate the behavioral deviation value of each node in the fused graph; The behavior deviation value is compared with a preset first deviation threshold. When the behavior deviation value is lower than the first deviation threshold, the graph node is determined to be a normal node. When the deviation value of the behavior is greater than or equal to the first deviation threshold and lower than the second deviation threshold, the map node is determined to be a suspicious node and the enhanced monitoring mode is triggered, wherein the second deviation threshold is greater than the first deviation threshold. When the deviation value of the behavior is greater than or equal to the second deviation threshold, the graph node is determined to be an abnormal node, an abnormal alarm is triggered, and a source tracing start command is sent to the source tracing analysis agent.

[0029] It's important to note that the accuracy of anomaly detection directly determines the availability of the entire system—too many false alarms will overwhelm maintenance personnel; too many missed alarms will render the system ineffective. This is actually an old problem in the field of network security, known as "alarm fatigue." This embodiment addresses this pain point by introducing a multi-level threshold mechanism. The behavior deviation value is calculated as the Euclidean distance between the current node's behavior feature vector and the historical baseline vector, which is generally constructed using the moving average of the most recent seven days. The first deviation threshold is usually set between 0.25 and 0.35, and experience shows that this range can cover more than 95% of normal traffic fluctuations; the second deviation threshold is set between 0.55 and 0.65, and values ​​exceeding this can generally be considered malicious behavior. Note that in actual deployment, these two thresholds are not static; the system will fine-tune them at the end of each detection cycle based on the false alarm rate and missed alarm rate of the previous cycle, with the adjustment step size defaulting to 0.02. When a node is deemed suspicious, the system automatically triggers an enhanced monitoring mode. In this mode, the sampling frequency increases from once per minute to once every five seconds, and the feature extraction dimensions expand from the default four to six, adding two new dimensions: application layer protocol deep analysis and DNS query pattern analysis. This allows for more refined secondary discrimination of nodes in the "grey area" without significantly increasing the overall system computational load. Using these techniques effectively avoids the false positives caused by a one-size-fits-all threshold approach, achieving a better balance between alarm accuracy and recall.

[0030] Figure 3The flowchart illustrates an anomaly detection method based on multimodal decision fusion provided by an embodiment of the present invention.

[0031] like Figure 3 As shown in the embodiment of the present invention, the step of outputting anomaly detection results based on the behavioral deviation of each graph node in the fused graph by the anomaly discrimination agent further includes: S302, through the first detection path deployed in the anomaly discrimination intelligent body, the behavior feature vectors of each graph node in the fused graph are analyzed by an anomaly detection algorithm based on a statistical distribution model, and a first discrimination result and a first confidence level are generated; S304, through the second detection path deployed in the anomaly discrimination intelligent body, the structural features and node attributes of the fused graph are analyzed using an anomaly detection model based on graph neural network, and a second discrimination result and a second confidence level are generated; S306, the first discrimination result, the first confidence level, the second discrimination result and the second confidence level are obtained through the fusion arbitration unit in the anomaly discrimination intelligent body. When the first discrimination result is consistent with the second discrimination result and both the first confidence level and the second confidence level are higher than the preset confidence level threshold, the consistent discrimination result is output as the final anomaly detection result. S308, when the first discrimination result is inconsistent with the second discrimination result, compare the first confidence level with the second confidence level, and select the discrimination result with higher confidence level as the final anomaly detection result output.

[0032] It should be noted that relying solely on a single detection path for anomaly detection in complex network environments has certain limitations. Statistical models are insufficiently sensitive to subtle anomalies at the protocol level, while graph neural networks are prone to overfitting when node data is sparse; both paths have their own blind spots. Therefore, this embodiment sets up two heterogeneous detection paths within the anomaly detection agent, improving the reliability of the detection through complementary verification.

[0033] The first detection path is a statistical discrimination path, employing an improved kernel density estimation anomaly scoring algorithm. This path constructs a probability density distribution model for the multi-dimensional feature vectors of each node, and the confidence level is represented by the complementary cumulative probability of the current observation in the distribution; the smaller the probability corresponding to the observation, the lower the probability that it was generated by the normal model, and the higher the corresponding confidence level.

[0034] The second detection path is a graph structure discrimination path, implemented using a two-layer graph convolutional network. The path takes the adjacency matrix and node attribute matrix of the fused graph as input, and outputs the anomaly probability of each node as the discrimination result. The confidence score is directly taken from the softmax probability value output by the model.

[0035] The fusion arbitration unit is responsible for making a comprehensive decision on the results of the two paths: when the results of the two paths are consistent and the confidence levels are both higher than a preset threshold, the final judgment result is directly output; when the results are inconsistent, the better path is selected based on its confidence level. The confidence threshold is usually set to 0.7. If it is lower than this threshold, it indicates that the confidence levels of the two path judgments are insufficient. In this case, a conclusion is not forcibly output, but the relevant indicators are marked as awaiting manual review and pushed to the security analyst's workbench for further verification.

[0036] In a real-world test environment of an enterprise intranet containing approximately 50,000 network nodes and generating an average of 3 million communication records per day, this dual-path fusion mechanism improved the detection accuracy by approximately 12 percentage points compared to a single statistical path and the recall rate by approximately 8 percentage points compared to a single graph neural network path, resulting in a more stable and reliable overall discrimination effect.

[0037] According to an embodiment of the present invention, the method further includes: establishing a collaborative interaction protocol with an external threat intelligence system, obtaining real-time threat intelligence data from the external threat intelligence system through the collaborative interaction protocol; mapping the real-time threat intelligence data into threat intelligence graph nodes, and connecting the threat intelligence graph nodes to the fusion graph through associated edges; when the anomaly detection agent outputs anomaly detection results, cross-validating the anomaly detection results based on the threat feature information provided by the threat intelligence graph nodes, and increasing the confidence level of the anomaly detection results when the abnormal behavior features in the anomaly detection results match the threat feature information.

[0038] It should be noted that while this system possesses relatively comprehensive anomaly detection capabilities, relying solely on internal data for independent judgment may still miss attack clues that can only be identified through external threat information. In real-world network security protection scenarios, internal detection models struggle to cover all unknown threat types; introducing external, trusted threat information can significantly improve the accuracy and reliability of judgments.

[0039] To this end, this system establishes an external collaborative interaction mechanism to achieve data exchange and joint verification with professional threat intelligence systems. The collaborative interaction protocol follows the STIX 2.1 standard, clearly defining the threat indicator format, data transmission cycle, and identity verification rules. In actual deployment, HTTPS two-way authentication is used to ensure communication security, and the default data transmission interval is set to five minutes. The threat intelligence accessed by the system mainly includes malicious IP address databases, malicious domain name blacklists, and known attack signature hash values. After standardization, the above intelligence data is mapped to threat intelligence graph nodes, and associated with corresponding communication nodes in the fused graph through graph edges of related types.

[0040] Now let's talk about the cross-validation logic. When the anomaly detection agent marks a certain IP as an anomalous node, if there is a matching malicious record for that IP in the threat intelligence graph, the confidence level of the corresponding anomaly result will be directly upgraded from suspected to confirmed. If no matching record is found in the threat intelligence, the original confidence level will remain unchanged, and the possibility of anomaly will not be directly ruled out because it is not included in the intelligence database.

[0041] This mechanism can fully leverage the high credibility of external intelligence while taking into account the limitations of the intelligence database's coverage, avoiding the misjudgment of valid anomalies as normal due to incomplete intelligence, thereby improving the accuracy of judgments and reducing the probability of missed reports.

[0042] According to an embodiment of the present invention, the method further includes: receiving a detection intent description, the detection intent description being used to indicate the target type and attention priority of the current detection task; decomposing the detection intent description into multiple atomic detection intents through an intent parsing unit, each atomic detection intent corresponding to an independently executable detection subtask; retrieving matching functional capability atoms from a pre-built capability atom library according to each atomic detection intent, the functional capability atoms being standardized encapsulations of callable functional units of each functional agent; assembling and sorting the retrieved functional capability atoms according to the current operating environment state and the attention priority to generate an execution pipeline for the current detection task; distributing the execution pipeline to the corresponding functional agents for execution, and dynamically adjusting the execution pipeline according to execution feedback; the capability atom library is pre-built in the following manner: functionally decomposing the callable functional units of each functional agent, labeling each functional unit with a functional tag and a resource consumption tag, and standardizing and encapsulating the labeled functional units in a unified interface format to form a set of functional capability atoms that can be retrieved and called.

[0043] It should be noted that network security detection requirements are dynamic and ever-changing. For different threat types such as DDoS attacks, data breaches, and zero-day vulnerabilities, the detection focus and strategies need to be flexibly adjusted. Manually configuring and switching detection rules one by one is insufficient for quickly responding to real-time changes in the attack landscape. Therefore, this embodiment introduces an intent-driven dynamic reconfiguration mechanism to improve system adaptability and response efficiency.

[0044] The detection intent description can be entered in natural language, such as "Focus on monitoring abnormal external connection behavior of the database server and reduce the detection priority of ordinary web traffic," or it can be generated through configuration options in the management console. The system decomposes the detection intent through the intent parsing unit. The internally maintained intent atomic mapping table can decompose a complex detection intent into several independently executable atomic detection intents. Taking monitoring abnormal database external connections as an example, it can be decomposed into atomic intents such as database service port traffic identification, external network connection pattern analysis, and abnormal data transmission detection during non-business periods.

[0045] The system pre-defines a capability atom library, which encapsulates over forty standardized functional capability atoms. Each atom is labeled with a function tag and a resource consumption tag. Function tags include port identification, traffic statistics, and connection graph analysis, while resource consumption tags include CPU consumption level and memory usage level. The strategy assembly engine adaptively selects matching capability atoms based on the atom detection intent list and the current operating environment status, such as CPU utilization and remaining memory: when system resources are sufficient, a high-precision version is invoked, such as the complete inference model of a graph convolutional network; when resources are scarce, a lightweight version is automatically switched to, such as enabling only the statistical analysis model. The capability atom library is pre-built as follows: the callable functional units provided by each functional agent are functionally decomposed, and each functional unit is assigned a function tag and a resource consumption tag. The function tag describes the technical function implemented by the unit, and the resource consumption tag describes the CPU and memory overhead required for the unit's execution. The labeled functional units are then standardized and encapsulated in a unified interface format to form a set of functional capability atoms that can be retrieved and invoked by the intent parsing unit.

[0046] Through the aforementioned intent-driven dynamic orchestration mechanism, the system has been upgraded from a fixed-strategy detection tool to an intelligent detection platform that can adapt to different scenarios and resource states, maintaining stable and efficient detection capabilities in large-scale, highly dynamic network environments.

[0047] According to an embodiment of the present invention, the method further includes: acquiring traffic noise characteristic data of the target network through the data acquisition agent, the traffic noise characteristic data including jitter amplitude of data packet arrival interval and traffic rate fluctuation frequency; inputting the traffic noise characteristic data as a network state detection signal to the anomaly discrimination agent, the anomaly discrimination agent identifying the underlying congestion state of the target network and the queue depth change trend of intermediate forwarding nodes based on the traffic noise characteristic data; using the underlying congestion state and the queue depth change trend as auxiliary discrimination features, performing joint analysis with the behavior deviation, and outputting the anomaly detection result. The jitter amplitude is compared with a preset jitter threshold, and when the jitter amplitude exceeds the jitter threshold, it is determined that the target network has an underlying congestion state; the traffic rate fluctuation frequency is compared with a preset frequency threshold, and when the traffic rate fluctuation frequency exceeds the frequency threshold, it is determined that the queue depth of the intermediate forwarding nodes is increasing; wherein, the jitter threshold and the frequency threshold are pre-calibrated based on the statistical distribution characteristics under historical normal traffic conditions.

[0048] It should be noted that in traditional network traffic detection schemes, traffic noise is usually regarded as invalid interference data, and related processing methods mainly focus on filtering, smoothing, and denoising to try to eliminate such features. However, from the perspective of network operation mechanism, traffic noise is not a meaningless signal, but an important basis for truly reflecting the status of underlying network nodes and the quality of link transmission. Therefore, this embodiment does not adopt conventional denoising strategies, but preserves and makes in-depth use of traffic noise characteristics. Specifically, the jitter amplitude of the packet arrival interval can intuitively reflect the queue scheduling and congestion status of intermediate nodes such as routers and switches: under normal load conditions, the jitter value usually remains within 2 milliseconds; when a node is congested and the queue is piled up, the jitter amplitude will rise significantly to more than 5 milliseconds, accompanied by sawtooth periodic fluctuations. The frequency of traffic rate fluctuation can characterize the window adjustment behavior of the TCP congestion control mechanism: under normal conditions, the fluctuation frequency is about 1 to 2 times per second. If the frequency suddenly rises to a high-frequency oscillation of 5 to 10 times per second, it usually indicates that there is continuous packet loss and retransmission behavior in intermediate nodes. Specifically, the anomaly detection agent compares the jitter amplitude with a preset jitter threshold. When the jitter amplitude exceeds the jitter threshold, it determines that the target network has a low-level congestion state. It also compares the traffic rate fluctuation frequency with a preset frequency threshold. When the traffic rate fluctuation frequency exceeds the frequency threshold, it determines that the queue depth of the intermediate forwarding node is increasing. The jitter threshold and the frequency threshold are pre-calibrated based on the statistical distribution characteristics under historical normal traffic conditions. For example, the 95th percentile of the corresponding characteristics under historical normal traffic conditions is taken as the threshold calibration value.

[0049] The anomaly detection agent jointly judges the above noise characteristics and behavior deviation: when the node behavior deviation is high and the jitter amplitude and rate fluctuation frequency of the corresponding network path are synchronously abnormal, it can more accurately determine the real network attack behavior and effectively eliminate interference from normal scenarios such as equipment failure and instantaneous traffic surge.

[0050] This noise signature utilization mechanism offers a significant advantage in detecting slow, congestion-type stealth attacks such as Slowloris. These attacks exhibit mild behavior and show little deviation from conventional patterns, but they leave stable and identifiable feature fingerprints along the traffic noise dimension, thus enabling the effective detection of silent anomalies that are difficult to identify using traditional methods.

[0051] According to an embodiment of the present invention, the method further includes: when the data acquisition agent detects that the proportion of encrypted traffic in the network traffic of the target network exceeds a preset encryption ratio threshold, triggering an encrypted traffic enhancement detection mode; under the encrypted traffic enhancement detection mode, the feature extraction agent extracts at least one of the following features: cipher suite negotiation sequence features during the TLS handshake phase, length distribution entropy features of encrypted data packets, and the ratio of the duration of the encrypted session to the amount of data; under the encrypted traffic enhancement detection mode, the anomaly discrimination agent processes the behavioral feature vector using an anomaly classifier trained on encrypted traffic.

[0052] It should be noted that while the widespread use of encrypted traffic enhances data transmission security, it also provides a covert channel for malicious communication. Statistics show that encrypted traffic currently accounts for over 85% of network traffic, and some malicious programs utilize encrypted tunnels to conceal C2 communication behavior, making them difficult to identify effectively using traditional detection methods. Therefore, this embodiment sets up a dedicated enhanced detection mechanism to address this high-frequency and high-risk detection blind spot of encrypted traffic. For example, the system sets an encrypted traffic ratio threshold of 60%. When the proportion of encrypted traffic in the target network exceeds this threshold, it automatically switches from the standard detection mode to the enhanced encrypted traffic detection mode. In this mode, the system focuses on extracting two typical features: first, the cipher suite negotiation sequence during the TLS handshake phase. Normal browsers have fixed priority and degradation rules for their negotiation sequences, while the simplified TLS libraries used by malicious programs typically have shorter sequences and abnormal combination methods, making them easy to distinguish; second, the length distribution entropy of encrypted data packets. Normal webpage access traffic exhibits a multi-peak distribution characteristic, while the length of C2 heartbeats and command packets is relatively fixed, resulting in significantly lower entropy values. In addition, for DDoS attack scenarios, when the system identifies typical attack characteristics such as ICMP floods and SYN floods, it will also activate the corresponding DDoS detection enhancement module, focusing on in-depth analysis of traffic symmetry deviation and source address dispersion, to further improve the detection reliability in complex attack scenarios.

[0053] According to an embodiment of the present invention, the method further includes: after the source tracing analysis agent traces the propagation path of the abnormal behavior in reverse along the graph edges in the fusion graph and locates the abnormal source node, based on the behavioral feature vector and communication mode of the abnormal source node, it infers the potential subsequent attack target node of the abnormal source node in the forward direction along the fusion graph and generates potential threat warning information.

[0054] It should be noted that traditional source tracing analysis typically only completes the reverse tracing of abnormal paths, terminating the process after locating the attack source, tracing the propagation chain, and generating an analysis report, making it difficult to achieve a complete security loop. This embodiment further extends the handling logic, treating the located abnormal source node as a situational prediction signal source, and predicting the potential attack range based on its historical behavioral characteristics. In specific implementation, after identifying the abnormal source node, the source tracing analysis agent continues to extract behavioral characteristics such as its communication object set, communication frequency distribution, and protocol usage preferences, starting from that node. It then traverses nodes in the same subnet or with similar communication relationships along the forward correlation edges of the fused graph, calculating the corresponding attack risk score. The system marks nodes with scores higher than the forward tracing threshold (default value 0.4) as potential attack targets and generates early warning information, pushing it to the security operations and maintenance end to enable proactive defense measures such as firewall policy adjustments, enhanced log auditing, and critical port control. Through the above forward inference mechanism, this solution upgrades traditional post-event source tracing capabilities to pre-event early warning capabilities, achieving threat propagation prediction and proactive defense while completing source tracing and location.

[0055] According to an embodiment of the present invention, the method further includes: acquiring the current available computing resource constraint value of the system in real time, the current available computing resource constraint value including the percentage of remaining computing power of the central processing unit and the available memory capacity; using the current available computing resource constraint value as a strategy selection parameter; when the current available computing resource constraint value is lower than a first resource threshold, enabling a lightweight detection mode, wherein only the first detection path in the anomaly detection agent is enabled in the lightweight detection mode, and the feature extraction dimension of the feature extraction agent is reduced to a preset core feature subset; when the current available computing resource constraint value is between the first resource threshold and a second resource threshold, enabling a balanced detection mode; and when the current available computing resource constraint value is higher than the second resource threshold, enabling a full detection mode.

[0056] It should be noted that in actual production environments, the detection system is typically deployed on the same physical machine or virtual machine cluster as the business system. Computational resources such as CPU and memory have defined limits and cannot be used indefinitely. Therefore, this embodiment uses parameterized resource constraints, allowing the system to adaptively adjust the detection intensity based on real-time remaining resources. The system uses operating system performance counters to collect the remaining CPU computing power percentage and available memory capacity every 30 seconds. When CPU availability is below 15% or available memory is below 512MB (the first resource threshold), it automatically enters a lightweight detection mode: only the statistical model detection path is enabled, and the feature extraction dimensions are reduced to three core features: communication frequency, traffic volume, and protocol compliance, while ensuring that the detection accuracy is not less than 80% of the full detection mode. When CPU availability is between 15% and 40%, the system adopts a balanced detection mode; when CPU availability is above 40%, it switches to full detection mode, with the two detection paths working in parallel.

[0057] This adaptive resource scheduling strategy enables the system to operate stably in resource-constrained scenarios such as edge gateways and small branch nodes, avoiding the impact on business traffic transmission caused by excessive resource consumption of detection tasks.

[0058] According to an embodiment of the present invention, the method further includes: before the relationship modeling agent constructs the traffic behavior relationship graph, the feature extraction agent applies a time sliding window of a preset duration to the traffic behavior data, independently extracts multi-dimensional features within each time sliding window, and generates a sub-behavior feature vector corresponding to the time sliding window; the relationship modeling agent constructs sub-traffic behavior relationship graphs according to the sub-behavior feature vectors corresponding to each time sliding window, and splices the sub-traffic behavior relationship graphs in time sequence according to the time order of the time sliding window to generate a time-enhanced traffic behavior relationship graph.

[0059] It's important to note that network attacks are not static snapshots—they evolve over time, from initial reconnaissance to vulnerability scanning, penetration and exploitation, lateral movement, and finally, data theft or destruction. Each step leaves a distinct trace in network traffic. Snapshot-style analysis at a single point in time can easily miss the entire attack chain. This embodiment introduces a time-sliding window mechanism to capture this temporal dynamic. The window length is typically five minutes, with a one-minute sliding step—ensuring four minutes of data overlap between adjacent windows. This guarantees analytical granularity without losing long-term behavioral patterns due to excessively short windows. Behavioral feature vectors are independently extracted within each window, and subgraphs are constructed. These subgraphs are then assembled chronologically into a time-enhanced relational graph. The timestamp information on the edges allows the attribution analysis agent to not only know "where the attack came from" but also "at what point in time did the attack pass through which node," reconstructing the complete attack timeline. In testing, incorporating time-series splicing improved the accuracy of attribution analysis for multi-stage attacks by approximately 15%.

[0060] Please see Figure 4 The present invention also provides a traffic anomaly behavior detection and tracing system 4 based on multi-agent graphs. The system includes a memory 401 and a processor 402. The memory includes a traffic anomaly behavior detection and tracing method program based on multi-agent graphs. When the traffic anomaly behavior detection and tracing method program based on multi-agent graphs is executed by the processor, it implements the following steps: Deploy multiple functional agents, including at least a data acquisition agent, a feature extraction agent, a relationship modeling agent, an anomaly detection agent, and a source tracing analysis agent. Organize each functional agent into a graph structure as a graph node of the multi-agent graph, and use the data flow and control flow between each functional agent as the graph edge of the multi-agent graph to construct the multi-agent graph. The data acquisition agent collects traffic behavior data from the network traffic of the target network in real time. The feature extraction agent performs multi-dimensional feature extraction on the traffic behavior data to generate a behavior feature vector. The relationship modeling agent constructs a traffic behavior relationship graph based on the behavior feature vector, and then fuses the traffic behavior relationship graph with the multi-agent graph to obtain a fused graph. The anomaly detection agent outputs anomaly detection results based on the behavioral deviation of each node in the fused graph. When the anomaly detection result indicates the presence of abnormal behavior, the source analysis agent traces the propagation path of the abnormal behavior backward along the graph edges in the fused graph to locate the anomaly source node.

[0061] It should be noted that at the system implementation level, the various functional agents can be deployed on the same physical server to work collaboratively via inter-process communication, or they can be distributed across multiple servers for asynchronous communication via network message queues (such as Kafka or RabbitMQ), depending on the scale and performance requirements of the target network. Memory and processor are the fundamental hardware support for system operation. Memory can use DDR4 dynamic random access memory, and the processor can be a Xeon series central processing unit supporting the AVX-512 instruction set to accelerate matrix operations in graph neural networks. After the program in the system is loaded into memory, the processor executes the above steps one by one, forming a closed loop from data acquisition to source tracing and localization.

[0062] According to an embodiment of the present invention, the step of outputting anomaly detection results based on the behavioral deviation degree of each graph node in the fused graph by the anomaly discrimination agent includes: calculating the behavioral deviation degree value of each graph node in the fused graph; comparing the behavioral deviation degree value with a preset first deviation threshold; when the behavioral deviation degree value is lower than the first deviation threshold, determining the graph node as a normal node; when the behavioral deviation degree value is greater than or equal to the first deviation threshold and lower than a second deviation threshold, determining the graph node as a suspicious node and triggering an enhanced monitoring mode, wherein the second deviation threshold is greater than the first deviation threshold; when the behavioral deviation degree value is greater than or equal to the second deviation threshold, determining the graph node as an abnormal node, triggering an anomaly alarm, and sending a source tracing start command to the source tracing analysis agent.

[0063] It should be noted that when multi-level threshold determination is implemented at the system level, the initial values ​​of the threshold parameters can be fixed in the configuration file and optimized by the administrator according to the actual network environment. The system also provides a web management interface to display a real-time comparison view of the deviation curves and threshold lines of each node, allowing maintenance personnel to intuitively observe the system's detection status.

[0064] According to an embodiment of the present invention, the step of outputting anomaly detection results based on the behavioral deviation of each graph node in the fused graph by the anomaly discrimination agent further includes: analyzing the behavioral feature vectors of each graph node in the fused graph using an anomaly detection algorithm based on a statistical distribution model through a first detection path deployed in the anomaly discrimination agent to generate a first discrimination result and a first confidence level; analyzing the structural features and node attributes of the fused graph using an anomaly detection model based on a graph neural network through a second detection path deployed in the anomaly discrimination agent to generate a second discrimination result and a second confidence level; obtaining the first discrimination result, the first confidence level, the second discrimination result, and the second confidence level through a fusion arbitration unit in the anomaly discrimination agent; when the first discrimination result is consistent with the second discrimination result and both the first confidence level and the second confidence level are higher than a preset confidence level threshold, outputting the consistent discrimination result as the final anomaly detection result; when the first discrimination result is inconsistent with the second discrimination result, comparing the first confidence level and the second confidence level, and selecting the discrimination result with the higher confidence level as the final anomaly detection result.

[0065] Note that in actual system deployment, the statistical distribution model and the graph neural network model can run on different CPU cores, utilizing multi-core parallel processing to reduce the total time consumption of the two paths. The fusion arbitration unit, as an independent microservice module, exchanges data with the two detection paths through the gRPC interface, ensuring decoupling and scalability.

[0066] The present invention also provides a computer-readable storage medium having a computer program stored thereon, the computer-readable storage medium including a traffic anomaly behavior detection and source tracing method program based on multi-agent graph, the traffic anomaly behavior detection and source tracing method program based on multi-agent graph being executed by a processor to implement the steps of the traffic anomaly behavior detection and source tracing method based on multi-agent graph as described above.

[0067] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A method for detecting and tracing abnormal traffic behavior based on multi-agent graphs, characterized in that, include: Deploy multiple functional agents, including at least a data acquisition agent, a feature extraction agent, a relationship modeling agent, an anomaly detection agent, and a source tracing analysis agent. Organize each functional agent into a graph structure as a graph node of the multi-agent graph, and use the data flow and control flow between each functional agent as the graph edge of the multi-agent graph to construct the multi-agent graph. The data acquisition agent collects traffic behavior data from the network traffic of the target network in real time. The feature extraction agent performs multi-dimensional feature extraction on the traffic behavior data to generate a behavior feature vector. The relationship modeling agent constructs a traffic behavior relationship graph based on the behavior feature vector, and then fuses the traffic behavior relationship graph with the multi-agent graph to obtain a fused graph. The anomaly detection agent outputs anomaly detection results based on the behavioral deviation of each node in the fused graph. When the anomaly detection result indicates the presence of abnormal behavior, the source analysis agent traces the propagation path of the abnormal behavior backward along the graph edges in the fused graph to locate the anomaly source node.

2. The method for detecting and tracing abnormal traffic behavior based on multi-agent graphs according to claim 1, characterized in that, The anomaly detection result is output by the anomaly discrimination agent based on the behavioral deviation of each graph node in the fused graph, including: Calculate the behavioral deviation value of each node in the fused graph; The behavior deviation value is compared with a preset first deviation threshold. When the behavior deviation value is lower than the first deviation threshold, the graph node is determined to be a normal node. When the deviation value of the behavior is greater than or equal to the first deviation threshold and lower than the second deviation threshold, the map node is determined to be a suspicious node and the enhanced monitoring mode is triggered, wherein the second deviation threshold is greater than the first deviation threshold. When the deviation value of the behavior is greater than or equal to the second deviation threshold, the graph node is determined to be an abnormal node, an abnormal alarm is triggered, and a source tracing start command is sent to the source tracing analysis agent.

3. The method for detecting and tracing abnormal traffic behavior based on multi-agent graphs according to claim 1, characterized in that, The step of outputting anomaly detection results based on the behavioral deviation of each node in the fused graph by the anomaly discrimination agent also includes: By using the first detection path deployed within the anomaly discrimination intelligent body, an anomaly detection algorithm based on a statistical distribution model is employed to analyze the behavioral feature vectors of each node in the fused graph, generating a first discrimination result and a first confidence level. By using the second detection path deployed within the anomaly discrimination intelligent body, an anomaly detection model based on graph neural networks is employed to analyze the structural features and node attributes of the fused graph, generating a second discrimination result and a second confidence level. The first discrimination result, the first confidence level, the second discrimination result, and the second confidence level are obtained by the fusion arbitration unit in the anomaly discrimination intelligent body. When the first discrimination result is consistent with the second discrimination result and both the first confidence level and the second confidence level are higher than the preset confidence level threshold, the consistent discrimination result is output as the final anomaly detection result. When the first discrimination result is inconsistent with the second discrimination result, the first confidence level and the second confidence level are compared, and the discrimination result with the higher confidence level is selected as the final anomaly detection result output.

4. The method for detecting and tracing abnormal traffic behavior based on multi-agent graphs according to claim 1, characterized in that, Also includes: Establish a collaborative interaction protocol with an external threat intelligence system, and obtain real-time threat intelligence data from the external threat intelligence system through the collaborative interaction protocol; The real-time threat intelligence data is mapped to threat intelligence graph nodes, and the threat intelligence graph nodes are connected to the fusion graph through associated edges; When the anomaly detection agent outputs anomaly detection results, it performs cross-validation on the anomaly detection results based on the threat feature information provided by the threat intelligence graph nodes. When the abnormal behavior features in the anomaly detection results match the threat feature information, the confidence level of the anomaly detection results is increased.

5. The method for detecting and tracing abnormal traffic behavior based on multi-agent graphs according to claim 1, characterized in that, Also includes: Receive a detection intent description, which indicates the target type and priority of the current detection task; The intent parsing unit decomposes the detection intent description into multiple atomic detection intents, each atomic detection intent corresponding to an independently executable detection subtask. According to the atomic detection intentions described above, matching functional capability atoms are retrieved from a pre-built capability atom library, wherein the functional capability atoms are standardized encapsulations of the callable functional units of each functional agent; Based on the current operating environment status and the aforementioned attention priority, the retrieved functional capability atoms are assembled and sorted to generate an execution pipeline for the current detection task; The execution pipeline is distributed to the corresponding functional agents for execution, and the execution pipeline is dynamically adjusted based on the execution feedback. The capability atom library is pre-constructed in the following way: the callable functional units of each functional agent are functionally decomposed, each functional unit is labeled with a functional tag and a resource consumption tag, and the labeled functional units are standardized and encapsulated in a unified interface format to form a set of functional capability atoms that can be retrieved and called.

6. The method for detecting and tracing abnormal traffic behavior based on multi-agent graphs according to claim 1, characterized in that, Also includes: The data acquisition agent obtains traffic noise characteristic data of the target network, including the jitter amplitude of the data packet arrival interval and the frequency of traffic rate fluctuation. The traffic noise feature data is input as a network state detection signal to the anomaly detection agent, which then identifies the underlying congestion state of the target network and the queue depth change trend of intermediate forwarding nodes based on the traffic noise feature data. The underlying congestion state and the queue depth change trend are used as auxiliary discriminative features, and are jointly analyzed with the behavior deviation to output the anomaly detection result.

7. A traffic anomaly behavior detection and source tracing system based on multi-agent graph, characterized in that, The system includes a memory and a processor. The memory includes a program for detecting and tracing abnormal traffic behavior based on a multi-agent graph. When the processor executes the program for detecting and tracing abnormal traffic behavior based on a multi-agent graph, it performs the following steps: Deploy multiple functional agents, including at least a data acquisition agent, a feature extraction agent, a relationship modeling agent, an anomaly detection agent, and a source tracing analysis agent. Organize each functional agent into a graph structure as a graph node of the multi-agent graph, and use the data flow and control flow between each functional agent as the graph edge of the multi-agent graph to construct the multi-agent graph. The data acquisition agent collects traffic behavior data from the network traffic of the target network in real time. The feature extraction agent performs multi-dimensional feature extraction on the traffic behavior data to generate a behavior feature vector. The relationship modeling agent constructs a traffic behavior relationship graph based on the behavior feature vector, and then fuses the traffic behavior relationship graph with the multi-agent graph to obtain a fused graph. The anomaly detection agent outputs anomaly detection results based on the behavioral deviation of each node in the fused graph. When the anomaly detection result indicates the presence of abnormal behavior, the source analysis agent traces the propagation path of the abnormal behavior backward along the graph edges in the fused graph to locate the anomaly source node.

8. A traffic anomaly behavior detection and source tracing system based on multi-agent graphs according to claim 7, characterized in that, The anomaly detection result is output by the anomaly discrimination agent based on the behavioral deviation of each graph node in the fused graph, including: Calculate the behavioral deviation value of each node in the fused graph; The behavior deviation value is compared with a preset first deviation threshold. When the behavior deviation value is lower than the first deviation threshold, the graph node is determined to be a normal node. When the deviation value of the behavior is greater than or equal to the first deviation threshold and lower than the second deviation threshold, the map node is determined to be a suspicious node and the enhanced monitoring mode is triggered, wherein the second deviation threshold is greater than the first deviation threshold. When the deviation value of the behavior is greater than or equal to the second deviation threshold, the graph node is determined to be an abnormal node, an abnormal alarm is triggered, and a source tracing start command is sent to the source tracing analysis agent.

9. A traffic anomaly behavior detection and source tracing system based on multi-agent graphs according to claim 7, characterized in that, The step of outputting anomaly detection results based on the behavioral deviation of each node in the fused graph by the anomaly discrimination agent also includes: By using the first detection path deployed within the anomaly discrimination intelligent body, an anomaly detection algorithm based on a statistical distribution model is employed to analyze the behavioral feature vectors of each node in the fused graph, generating a first discrimination result and a first confidence level. By using the second detection path deployed within the anomaly discrimination intelligent body, an anomaly detection model based on graph neural networks is employed to analyze the structural features and node attributes of the fused graph, generating a second discrimination result and a second confidence level. The first discrimination result, the first confidence level, the second discrimination result, and the second confidence level are obtained by the fusion arbitration unit in the anomaly discrimination intelligent body. When the first discrimination result is consistent with the second discrimination result and both the first confidence level and the second confidence level are higher than the preset confidence level threshold, the consistent discrimination result is output as the final anomaly detection result. When the first discrimination result is inconsistent with the second discrimination result, the first confidence level and the second confidence level are compared, and the discrimination result with the higher confidence level is selected as the final anomaly detection result output.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, The computer-readable storage medium includes a method program for detecting and tracing abnormal traffic behavior based on a multi-agent graph. When the method program is executed by a processor, it implements the steps of a method for detecting and tracing abnormal traffic behavior based on a multi-agent graph as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • A knowledge graph-based network traffic anomaly detection method and system

    CN120498844B

  • Communication network abnormal data intelligent diagnosis method and system based on knowledge graph

    CN120729739A