A computer network alarm system and method
Patent Information
- Application Number
- CN202611191234.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-07
- Publication Date
- 2026-09-25
AI Technical Summary
[0003]然而,CN121644240B 公开的上述方案中报警阻断存在"中心研判再下发"的链式时延;即中心平台计算风险评价值,超阈值后才向攻击威胁路径中的通信节点发起定向探询,待返回探询响应信息判断存在攻击活动后,才进行主动隔离报警整个链路需经过检测、上报、研判再下发的流程,从而存在秒级时延,攻击在此窗口内持续扩散;尤其在加密流量场景下,访问行为特征采集面骤减,中心平台依赖的行为报警规则判别力下降,进一步拉长研判时延
1.该计算机网络报警系统及方法,通过在不解密前提下对加密流的多维元数据特征进行深度语义推断,从根本上突破了传统报警机制在加密流量灰色区域中判别力坍塌的瓶颈,该机制摒弃了对明文载荷的依赖,转而挖掘加密握手与传输时序中隐含的语义特征,使得系统能够在无需破解加密内容的情况下,精准辨识出隐藏于合法加密隧道中的异常行为,有效克服了传统方案因特征贫瘠导致的高误报与高漏报问题,大幅提升了在 TLS、QUIC等强加密场景下的报警触发精准度。
Smart Images

Figure CN122824488A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security protocol technology, specifically to a computer network alarm system and method. Background Technology
[0002] Currently, network security protocol-based alarm solutions generally evolve along the technical route of "network vulnerability assessment, attack path identification, behavioral feature matching, and threshold alarm." Patent publication number CN121644240B discloses a computer network alarm system and method. One type of solution, represented by this, binds all communication interaction modes with risk verification links between corresponding communication nodes to obtain a vulnerability relationship network of the decision network vulnerability distribution within the target communication network. It performs multi-step attack simulation on the vulnerability relationship network, identifying multiple attack threat paths from peripheral access points to internal protected resources, and determines the inherent threat value of each attack threat path based on the defense response characteristics of each path. By comparing access behavior characteristics with the basic threat level of corresponding communication nodes, it sets real-time access behavior alarm rules to determine the risk assessment value of the current overall threat status. When the risk assessment value exceeds a preset alarm trigger value, it initiates targeted probing to the communication nodes in the corresponding attack threat path, and determines whether attack activity exists based on the returned probing response information, while simultaneously performing proactive isolation alarms. This type of solution improves the accuracy of computer network alarms through a global vulnerability assessment mechanism.
[0003] However, the alarm blocking scheme disclosed in CN121644240B has a chain-like delay of "central assessment and then dissemination". That is, the central platform calculates the risk assessment value, and only after it exceeds the threshold does it initiate targeted probing to the communication nodes in the attack threat path. Only after the probing response information is returned and it is determined that there is attack activity will it actively isolate and issue an alarm. The entire link needs to go through the process of detection, reporting, assessment and then dissemination, which results in a delay of seconds. The attack continues to spread within this window. Especially in encrypted traffic scenarios, the scope of access behavior feature collection is drastically reduced, and the discriminative power of the behavior alarm rules relied upon by the central platform decreases, further lengthening the assessment delay. Summary of the Invention
[0004] To address the shortcomings of existing technologies, this invention provides a computer network alarm system and method, which solves the problems mentioned in the background section.
[0005] To achieve the above objectives, the present invention provides the following technical solution: a computer network alarm method, comprising the following steps: Step S1: Bind all communication interaction modes within the target communication network to the risk verification links between corresponding communication nodes to obtain a vulnerability relationship network. Perform multi-step attack simulation on the vulnerability relationship network to identify multiple attack threat paths from external access points to internal protected resources, and determine the initial inherent threat value of each attack threat path. ; Step S2: When the data stream flows through each hop device on the attack threat path, each hop device extracts the TLS or QUIC handshake metadata of the data stream, generates an authentication token containing a summary of the handshake metadata, and encapsulates the authentication token in the data stream packet and transmits it to the next hop device on the path; Step S3: Each hop device verifies the continuity of the received verification token. When a sudden change in handshake metadata is detected, an early termination is performed in this hop and a path-level alarm is generated. It no longer waits for judgment from the upstream or central platform. Step S4: Cluster all encrypted sessions according to quintuples, construct an encrypted session association graph based on the association relationships of the handshake metadata, and overlay this encrypted session association graph onto the weakness relationship network; connect the encrypted session association graph node set with the first... The intersection of the sets of encrypted sessions along each attack threat path is used to obtain a subgraph for that path; the density of the subgraph associated with the encrypted sessions along the path is then used to determine the subgraph. The inherent threat value of this path is dynamically adjusted according to Formula 1: in, Subgraph density influence coefficient This is the corrected inherent threat value. For the first The density of the encrypted session association graph subgraph along the attack threat path; Step S5: Preset subgraph density trigger threshold ,when At that time, adjust the stringency of the verification token continuity check for each hop device on the path in reverse according to Formula 2: in, The default drift tolerance threshold. This is the strictness adjustment factor. For the first The actual drift tolerance threshold used by each jump device on the path; Step S6: When the modified inherent threat value Greater than the preset alarm trigger threshold At that time, an active isolation alarm will be triggered.
[0006] Furthermore, the handshake metadata includes one or more of the following: ALPN tag, cipher suite identifier, JA3 / JA3S fingerprint, and 0-RTT usage flag.
[0007] Furthermore, the criteria for determining handshake metadata mutations are: inconsistent ALPN labels between two adjacent hops, or JA3 / JA3S fingerprint drift exceeding the current drift tolerance threshold of the path. Or, the 0-RTT flag may indicate an abnormal jump during non-first connection.
[0008] Furthermore, the edge weights of the encrypted session association graph are jointly determined by the following factors: the degree of sharing of JA3 fingerprints, the degree of sharing of certificate issuers, the similarity of TLS record length sequences, and the strength of temporal cooperation patterns.
[0009] Furthermore, subgraph density The calculation formula is: in, For the first The set of edges in the encrypted session association subgraph along the attack threat path. For the first The set of encrypted session nodes involved in the attack threat path.
[0010] Furthermore, the subgraph density influence coefficient The value range is [0.5, 2.0].
[0011] Furthermore, the subgraph density trigger threshold The preferred value is 0.6. The preferred value is 0.15. The value range is [0.1, 0.8].
[0012] A computer network alarm system, which applies the aforementioned computer network alarm method, includes: The path identification module is used to bind all communication interaction patterns within the target communication network with the risk verification links between corresponding communication nodes to obtain a vulnerability relationship network. This network is then used to perform multi-step attack simulations, identify attack threat paths, and determine the initial inherent threat value. ; The relay verification module is deployed on each hop device in the attack threat path. It is used to extract TLS or QUIC handshake metadata from the data stream, generate a verification token containing a summary of the handshake metadata, encapsulate the verification token in the data stream message and pass it to the next hop device, verify the continuity of the received verification token, and perform early termination in the current hop when a change in handshake metadata is detected. The association graph construction module is used to cluster all encrypted sessions by quintuples, construct an encrypted session association graph based on the association relationship of handshake metadata, and overlay the encrypted session association graph onto the weakness relationship network. The threat value correction module is used to connect the encrypted session association graph node set with the first... The intersection of the sets of encrypted sessions along each attack threat path yields a subgraph along that path, and the density of this subgraph is then used to determine the subgraph's subgraph structure. The inherent threat value of the path is dynamically adjusted according to Formula 1. Strictness adjustment module, used when At that time, adjust the strictness of the verification token continuity check of each hop device on the path in reverse according to Formula 2; The alarm trigger module is used when the corrected inherent threat value is displayed. Greater than the preset alarm trigger threshold At that time, an active isolation alarm will be triggered.
[0013] Furthermore, the verification token generated by the relay verification module contains the following fields: handshake_digest, hop_counter, timestamp, and attack threat path identifier; the verification token is transmitted by encapsulating it in the data stream message through an extended protocol header. handshake_digest: The digest of handshake metadata extracted in this hop, which is obtained by concatenating the ALPN tag, cipher suite identifier, JA3 / JA3S fingerprint, and 0-RTT usage flag and then calculating the cryptographic hash; hop_counter: Hop count counter, initially 0, increments with each hop; Timestamp: Used to detect replay attacks.
[0014] This invention provides a computer network alarm system and method, which has the following beneficial effects: 1. This computer network alarm system and method fundamentally overcomes the bottleneck of traditional alarm mechanisms' ability to discriminate in the gray area of encrypted traffic by performing deep semantic inference on the multidimensional metadata features of encrypted streams without decryption. This mechanism abandons the dependence on plaintext payload and instead mines the semantic features hidden in the encrypted handshake and transmission sequence, enabling the system to accurately identify abnormal behaviors hidden in legitimate encrypted tunnels without cracking the encrypted content. It effectively overcomes the high false alarm and high false negative problems caused by the lack of features in traditional solutions, and greatly improves the accuracy of alarm triggering in strong encryption scenarios such as TLS and QUIC.
[0015] 2. This computer network alarm system and method, by constructing a path-level collaborative inquiry and feedback mechanism, further places the output single-point semantic risk score into the global context of the attack threat path for verification and dynamic weight adjustment. This mechanism ensures that each node on the path is no longer evaluated in isolation, but confirms the authenticity of the attack activity through cross-node collaborative inquiry response, and feeds the confirmation result back to the front-end semantic inference process, thereby driving the model weight to continuously evolve with actual combat. This produces a synergistic multiplier effect of improved recognition accuracy and autonomous model evolution, resulting in a qualitative leap in the reliability and anti-evasion capability of the overall alarm system in complex network environments. Attached Figure Description
[0016] Figure 1 This is a schematic diagram illustrating the implementation process of steps S1-S6 of the present invention. Detailed Implementation
[0017] The embodiments of the present invention will be described in further detail below with reference to the accompanying drawings and examples. The following examples are for illustrative purposes only and should not be construed as limiting the scope of the invention.
[0018] like Figure 1 As shown, the present invention provides a technical solution: a computer network alarm method, comprising the following steps: Step S1, Attack Threat Path Identification and Initial Inherent Threat Value Determination: All communication interaction patterns within the target communication network are bound to the risk verification links between corresponding communication nodes to obtain a vulnerability relationship network for decision-making regarding network vulnerability distribution (i.e., binding all communication interaction patterns within the target communication network to the risk verification links between corresponding communication nodes to obtain a network for decision-making regarding network vulnerability distribution); multi-step attack simulation is performed on the vulnerability relationship network to identify multiple attack threat paths from external access points to internal protected resources, and the initial inherent threat value of each attack threat path is determined based on the defense response characteristics of each attack threat path. .
[0019] Step S2, Continuity verification and early termination based on the authentication token relay: When the data stream flows through each hop device on the attack threat path, each hop device extracts the TLS or QUIC handshake metadata of the data stream (handshake metadata includes: ALPN tag, cipher suite identifier, JA3 / JA3S fingerprint, 0-RTT usage flag; where JA3 / JA3S fingerprint refers to the client or server fingerprint string extracted and generated based on TLS handshake fields: TLS version, cipher suite, extended list, elliptic curve, etc., used to uniquely identify the TLS implementation library of the client or the TLS response characteristics of the server; 0-RTT refers to the zero round-trip time handshake mechanism of the QUIC protocol, which can send application data before the handshake is completed when reusing the session reuse of the historical connection context), and generates an authentication token containing a digest of the handshake metadata (the authentication token is a structured data packet generated by each hop device). The authentication token, which includes a summary of the handshake metadata, a hop count counter, a timestamp, and an attack threat path identifier, is encapsulated in the data stream message via an extended protocol header and transmitted. This authentication token is then encapsulated in the data stream message and transmitted to the next-hop device on the path. Each hop device verifies the continuity of the received authentication token. When a handshake metadata mutation is detected (a handshake metadata mutation refers to inconsistencies in the ALPN tags extracted by two adjacent hop devices, JA3 / JA3S fingerprint drift exceeding the current path tolerance threshold, or an abnormal jump in the 0-RTT usage flag during a non-first connection), early termination is performed on the current hop (early termination on the current hop means that each hop device immediately cuts off the data stream and generates a path-level alarm upon detecting a handshake metadata mutation, without waiting for further analysis from upstream or the central platform).
[0020] Step S3, Encrypted Session Association Graph Construction and Overlay: Cluster all encrypted sessions according to 5-tuples (existing technology, not elaborated here), construct an encrypted session association graph based on the association relationships of handshake metadata (an encrypted session association graph is an undirected graph with encrypted sessions as nodes and handshake metadata association relationships between sessions as edges, the edge weights being jointly determined by the degree of shared JA3 fingerprints, the degree of shared certificate issuers, the similarity of TLS record length sequences, and the strength of temporal cooperation patterns), and overlay it onto the weakness relationship network; wherein, the node set in the encrypted session association graph is connected to the first... The intersection of the sets of encrypted sessions along each attack threat path is used to obtain the subgraph along that path, which is then used for subsequent subgraph density calculations.
[0021] Step S4, Dynamically correct the inherent threat value based on subgraph density: based on the subgraph density of the encrypted session association graph on the path (subgraph density) It refers to the first The inherent threat value of a path is dynamically adjusted according to Equation 1, which is the ratio of the set of edges of the encrypted session association graph subgraph on the attack threat path to its maximum possible number of edges. in, For the first The initial inherent threat value of each attack threat path is obtained by multi-step attack deduction, reflecting the static risk at the topology level, and its value range is [0,1]. The subgraph density influence coefficient, with a value range of [0.5, 2.0], is configured by the network administrator according to the business scenario. When the value is less than 0.5, the impact of the encrypted session collaboration mode is underestimated, and distributed C2 cannot be effectively identified; When the value is greater than 2.0, even a slight aggregation of encrypted sessions can cause the threat value to exceed the limit, resulting in a higher false alarm rate. This is the corrected inherent threat value. For the first The density of the encrypted session association graph subgraph along the attack threat path is calculated using the following formula: in, For the first The set of edges in the encrypted session association subgraph along the attack threat path. For the first The set of encrypted session nodes involved in the attack threat path; The larger the value, the higher the degree of collaboration and aggregation of encrypted sessions on that path.
[0022] Step S5, subgraph density reverse adjustment of each jump verification strictness: when ( The preferred value is 0.6, which is a pre-configured subgraph density trigger threshold used to determine whether the encrypted session association graph on a certain attack threat path has entered the high-density alert zone. When this threshold is reached, the strictness of the verification token continuity check by each hop device on the path is synchronously increased—specifically, the JA3 / JA3S fingerprint drift tolerance threshold. Tighten according to formula 2: in, The default drift tolerance threshold is preferably 0.15; This is the strictness adjustment coefficient, with a value range of [0.1, 0.8]. For the first The drift tolerance threshold actually used by each hop device on the path. The higher the subgraph density, the smaller the threshold and the more stringent the verification.
[0023] Step S6, after correction, the path threat value exceeds the threshold to trigger an active isolation alarm: the corrected inherent threat value... With preset alarm trigger threshold When a comparison is performed, At that time, an active isolation alarm will be triggered.
[0024] The above steps S1 to S6 constitute a complete alarm method flow; wherein step S2 is continuously executed as the data stream flows through each hop device, and steps S3 to S5 can be carried out in parallel during the execution of step S2. When the corrected inherent threat value exceeds the threshold, the active isolation alarm of step S6 is triggered. Based on the above description, the present invention achieves one-time extraction and dual utilization of handshake metadata. The handshake metadata (ALPN tag, cipher suite identifier, JA3 / JA3S fingerprint, 0-RTT usage flag) extracted by each hop device is used on the one hand to generate the verification token of the current hop and realize the relay transmission with the data flow, and on the other hand as the source of edge features of the encrypted session association graph - that is, if two encrypted sessions share the same or highly similar handshake metadata, an edge is formed on the association graph; so that the same handshake metadata extraction action serves two technical aspects. Furthermore, it modifies the inherent threat value through subgraph density and inversely adjusts the verification strictness of each hop. Not only does it dynamically correct the inherent threat value through Equation 1, but it also reversely adjusts the strictness of each hop device's verification of the continuity of the verification token (i.e., the strictness of feedback execution) through Equation 2; thus forming a positive interlocking where the denser the encrypted session association graph, the stricter the verification of each hop in the path and the higher the inherent threat value.
[0025] Example 1; Cross-regional encrypted C2 channel detection in a financial cloud environment: The network topology is a 3-hop path, namely the border firewall, core switch and application server; The attack scenario involves a malicious script exploiting a legitimate CDN (Content Delivery Network) as cover to establish an encrypted C2 (Command and Control) channel with a custom ALPN (Application Layer Protocol Negotiation Extension) tag; the specific steps are as follows: Step S1 is executed as follows: Build a vulnerability network to identify attack threat paths. Initial inherent threat value . Step S2 execution (relay verification and early disconnection): S201: Border firewall extracts handshake metadata: ALPN="custom-c2", JA3 (client fingerprint based on TLSClientHello)="e7d705a3286e19ea42ef58292e70907e", 0-RTT (zero round-trip time handshake flag) = false, generates verification token. Encapsulated within a data stream packet and transmitted to the core switch; S202: The core switch extracts local handshake metadata: ALPN="custom-c2", JA3="e7d705a3286e19ea42ef58292e70907e", 0-RTT=false, and... If the comparison is consistent, generate Passed to the application server; S203: The application server extracts the handshake metadata for this hop: ALPN="standard-http", JA3="c5a…", and If the comparison reveals an inconsistency in the ALPN tag, it is determined that the handshake metadata has mutated, thereby triggering an early termination of the current hop and reporting a path-level alarm to the central platform.
[0026] Step S3 is executed (association graph construction): It was discovered that the C2 channel shares the same JA3 fingerprint with five other encrypted sessions, and the TLS record length sequence similarity is >0.85, forming a dense subgraph on the encrypted session association graph. Taking the intersection of the node set in the encrypted session association graph with the set of encrypted sessions along this path yields the path. The number of nodes in the subgraph on the graph. Number of sides .
[0027] Step S4 execution (threat value correction): Calculate the subgraph density: Pick According to Equation 1: Step S5 is executed (strictness adjustment): because ,Pick Then according to equation 2: That is, the JA3 fingerprint drift tolerance threshold for each hop device on this path is tightened from the default 0.15 to 0.075.
[0028] Step S6 is executed (alarm triggered): This triggers an active isolation alarm.
[0029] Example 2: Subgraph density inverse control verification of stringency: This embodiment examines subgraph density within a simulated financial cloud backbone network environment. Reverse adjustment of the verification strictness of each jump The specific process is as follows: A simulation environment is constructed to create a 4-hop attack threat path. : Each hop device along the path is equipped with a relay verification module, initially configured with a default drift tolerance threshold. Strictness adjustment coefficient =0.5, subgraph density trigger threshold Subgraph density influence coefficient Set the value to 1.0, which is the alarm trigger threshold. ; Within a 24-hour simulation window, a total of 1,200,000 encrypted sessions were injected with mixed traffic, categorized into four types based on their nature: Category A - Legitimate Browsing Sessions (82%): The browser establishes a connection with the web server, and the handshake metadata characteristics are as follows: JA3 is derived from the fingerprint databases of mainstream browsers such as Chrome / Edge / Firefox (more than 1,200 fingerprints in total), and the 0-RTT usage flag is used normally in accordance with the QUIC protocol specification; Category B - Legitimate API Sessions (12%): gRPC / HTTP2 calls between microservices, ALPN="h2", JA3 is taken from standard libraries such as Go-net, OpenSSL, and LibreSSL; Category C Suspicious Encrypted C2 Channels (4%): Encrypted external links generated by C2 frameworks such as CobaltStrike and Silver are simulated. The ALPN tag is a custom string (such as "custom-c2" or "x-mux"), JA3 is the tool's default fingerprint (single strong cipher suite, abnormal), and the 0-RTT usage flag changes abnormally. Category D - Legitimate Business Incidents (2%): Database backups, batch file synchronization, etc., will generate short-term high-density subgraphs for testing false alarm control.
[0030] All 1,200,000 encrypted sessions are clustered by quintuples, and a global encrypted session association graph is constructed based on the handshake metadata relationships. ,in, A set of encrypted session nodes; The set of edges between encrypted sessions; The edge construction criterion is two encrypted sessions. and An edge is established between two points if and only if at least two of the following association conditions are met (the weight of the edge is obtained by weighted summation of the association strength). ): Shared JA3 fingerprint: If the JA3 strings of two encrypted sessions are completely identical, the association will contribute a weight of 0.4; if the JA3 strings of the two sessions are in a fuzzy matching state (i.e. the first 8 bits of the MD5 hash value are the same), the association will contribute a weight of 0.2. Shared certificate issuer: If the server certificates corresponding to the two encrypted sessions are issued by the same Certificate Authority (CA), then the association will contribute a weight of 0.2. Similar TLS record length sequences: If the distance between the TLS record length sequences of two sessions is calculated using the Dynamic Time Warping (DTW) algorithm... satisfy If the condition is met, then the association will contribute a weight of 0.3. Temporal collaboration rule: If the time interval between the establishment of two encrypted sessions is less than 5 seconds, and the two sessions exhibit a periodic occurrence in time sequence, then the association will contribute a weight of 0.1. when At that time, edges are created on the association graph.
[0031] Connect the global association graph node set with Taking the intersection of the encrypted session sets, statistically, The platform carries a total of 18,432 encrypted sessions, of which: Sessions falling into Category C threat clusters: 1,472 (7.99% of all path sessions) Sessions falling into Category D business burst clusters: 368 (accounting for 2.00% of all path sessions) Class A / B legitimate sessions: 16,592 The 1,472 sessions in category C form a high-density subgraph on the association graph. , The number of edges in this subgraph is calculated according to the edge construction criteria. .
[0032] Calculate the density of subgraphs of type C: Class C subgraphs are nearly complete graphs, with density... This indicates that the handshake metadata of sessions within the cluster is highly consistent, which is a typical topological characteristic of distributed C2 channels.
[0033] Calculate the density of the D-class business burst subgraph: The 368 sessions of class D form a medium-density subgraph on the association graph. ,but: The density of the D-type subgraph is only 0.062. Although the sessions are clustered, the handshake metadata varies greatly (JA3 is different for different database nodes), so the density is far below the trigger threshold.
[0034] Pick Initial inherent threat value (Based on multi-step attack simulation, reflecting the static topology risk of this 4-hop path), calculate the path correction threat value corresponding to cluster C according to Equation 1: If this occurs, an active isolation alarm will be triggered.
[0035] For Class D business burst clusters, calculate according to Formula 1: If the subgraph density dynamic correction does not trigger an alarm, it avoids false alarms for legitimate business emergencies. This result verifies the ability of subgraph density dynamic correction to distinguish between legitimate high-density clusters and malicious high-density clusters.
[0036] because Trigger strictness adjustment, calculated as follows: JA3 drift tolerance thresholds for each jump device: This means that the JA3 fingerprint drift tolerance threshold for the four devices on this path has been tightened from the default 0.15 to 0.075. This means that if the Hamming distance of the first 8 bits of the MD5 of the JA3 fingerprint extracted by two adjacent hop devices exceeds 0.075, it is determined to be a mutation in the handshake metadata.
[0037] To visually demonstrate the gradient effect of strictness adjustment, the following table provides... and Complete correspondence (take) =0.15, =0.5): This correspondence is a handshake metadata extraction and dual-use interlocking relationship. In this specific context, the same handshake metadata drives the subgraph density calculation and serves as the object of continuity verification for each hop of the verification token; and the subgraph density, in turn, determines the stringency level of the verification.
[0038] exist The following is a step-by-step reconstruction of the relay verification for the first C2 session in the C cluster: Extract handshake metadata; ALPN="custom-c2", JA3="e7d705a3286e19ea42ef58292e70907e" (single strong cipher suite, anomalous), 0-RTT=true (using 0-RTT on first connection, violating QUIC protocol specification); Generate authentication token Encapsulated in the message and transmitted to .
[0039] Extract the handshake metadata for this hop; ALPN="custom-c2", JA3="e7d705a3286e19ea42ef58292e70907e", 0-RTT=true, and If the ALPN, JA3, and 0-RTT are consistent, the continuity check passes. Transmit to At this time because The path had already entered the L4 extremely tight gear at each jump, so although this jump was passed unanimously, Enter the "strictness=L4" flag in the middle.
[0040] Extract the handshake metadata for this hop; ALPN="standard-db" (expected database protocol), JA3="a4f…" (different from the previous JA3), 0-RTT=false, and Comparison: If the ALPN tags are inconsistent ("custom-c2" vs "standard-db"), then the first criterion for mutation determination is violated. JA3 fingerprint drift amount = 1.0> This violates clause 2 of the mutation determination criteria; If the 0-RTT flag changes abnormally during a non-first connection (true for the previous hop, false for this hop), then the third criterion for mutation judgment is violated; if all three judgment criteria are triggered simultaneously, the current hop will be prematurely terminated, the database front-end machine will immediately cut off the data flow, and report a path-level alarm to the central platform.
[0041] Because each step has entered the extremely tight L4 level, even the slightest difference in the JA3 fingerprint in the S204 (even if the first 8 bits of the MD5 have only a 1-bit Hamming distance difference, i.e., a drift of 0.001) will be affected. The stringent threshold is used to determine a mutation. This mechanism ensures that the C2 channel is deterministically blocked on the last hop before reaching the target asset, without waiting for the central platform to make a judgment.
[0042] To verify the effectiveness of the technique of adjusting the subgraph density in step S5 to verify the strictness of each jump, a control experiment was conducted in the same simulation environment: step S5 was turned off (i.e., each jump was kept constant and the default settings were used). , don’t follow (Tighten), the remaining steps S1-S4 and S6 remain unchanged, and the experimental results are compared with the statistical results (24-hour simulation window, 1,200,000 sessions): The comparison between enabling strictness adjustment and disabling strictness adjustment is shown in the table below: Control experiments show that after enabling step S5, as the verification strictness of each hop tightens with the subgraph density, C2 sessions that originally "passed by the edge" under the default threshold (whose JA3 fingerprints showed slight but anomalous drift between adjacent hops) were accurately identified as handshake metadata mutations, and the false negative rate dropped from 3.47% to 0.25%. After step S5 is enabled, the C2 session is prematurely terminated at the last hop before reaching the database front-end machine (3.2ms), while the link that requires waiting for the central platform to detect, analyze and then send the data (820ms) is much shorter. After enabling step S5, the number of false alarms increased slightly (12 times for Category D vs 8 times). This is because after the strictness was tightened, a small number of sessions in Category D legitimate business were misjudged due to natural fluctuations in JA3 fingerprints. However, the absolute value of the false alarm rate was only 0.001% (12 / 1,200,000), which is far below the business SLA requirement of ≤0.5% for the false interception rate of the financial core node. The accuracy of path-level alarms increased from 91.42% to 99.31%, which confirms the effect of bidirectional feedback of subgraph density. That is, subgraph density not only corrects the inherent threat value (step S4) but also tightens the verification strictness of each hop (step S5). Under the dual effect, the discriminative power is significantly improved.
[0043] In summary, this computer network alarm system and method fundamentally overcomes the bottleneck of traditional alarm mechanisms' ability to discriminate in the gray area of encrypted traffic by performing deep semantic inference on the multidimensional metadata features of encrypted streams without decryption. This mechanism abandons the dependence on plaintext payloads and instead mines the semantic features hidden in the encrypted handshake and transmission sequence, enabling the system to accurately identify abnormal behaviors hidden in legitimate encrypted tunnels without cracking the encrypted content. This effectively overcomes the high false alarm and high false negative problems caused by the lack of features in traditional solutions, and significantly improves the accuracy of alarm triggering in strong encryption scenarios such as TLS and QUIC.
[0044] By constructing a path-level collaborative inquiry and feedback mechanism, the output single-point semantic risk score is further placed in the global context of the attack threat path for verification and dynamic weight adjustment. This mechanism ensures that each node on the path is no longer evaluated in isolation, but confirms the authenticity of the attack activity through cross-node collaborative inquiry response, and feeds the confirmation result back to the front-end semantic inference process, thereby driving the model weight to continuously evolve with actual combat. This results in a synergistic multiplier effect of improved recognition accuracy and autonomous model evolution, enabling the overall alarm system to achieve a qualitative leap in reliability and anti-evasion capability in complex network environments.
[0045] The embodiments of the present invention are given for illustrative and descriptive purposes only, and are not intended to be exhaustive or to limit the invention to the forms disclosed. Many modifications and variations will be apparent to those skilled in the art. The embodiments were chosen and described in order to better illustrate the principles and practical application of the invention, and to enable those skilled in the art to understand the invention and to design various embodiments with various modifications suitable for a particular purpose.
Claims
1. A computer network alarm method, characterized in that: Includes the following steps: Step S1: Bind all communication interaction modes within the target communication network to the risk verification links between corresponding communication nodes to obtain a vulnerability relationship network. Perform multi-step attack simulation on the vulnerability relationship network to identify multiple attack threat paths from external access points to internal protected resources, and determine the initial inherent threat value of each attack threat path. ; Step S2: When the data stream flows through each hop device on the attack threat path, each hop device extracts the TLS or QUIC handshake metadata of the data stream, generates an authentication token containing a summary of the handshake metadata, and encapsulates the authentication token in the data stream packet and transmits it to the next hop device on the path; Step S3: Each hop device verifies the continuity of the received verification token. When a sudden change in handshake metadata is detected, an early termination is performed in this hop and a path-level alarm is generated. It no longer waits for judgment from the upstream or central platform. Step S4: Cluster all encrypted sessions according to quintuples, construct an encrypted session association graph based on the association relationships of the handshake metadata, and overlay this encrypted session association graph onto the weakness relationship network; connect the encrypted session association graph node set with the first... The intersection of the sets of encrypted sessions along each attack threat path is used to obtain a subgraph for that path; the density of the subgraph associated with the encrypted sessions along the path is then used to determine the subgraph. The inherent threat value of this path is dynamically adjusted according to Formula 1: in, Subgraph density influence coefficient This is the corrected inherent threat value. For the first The density of the encrypted session association graph subgraph along the attack threat path; Step S5: Preset subgraph density trigger threshold ,when At that time, adjust the stringency of the verification token continuity check for each hop device on the path in reverse according to Formula 2: in, The default drift tolerance threshold. This is the strictness adjustment factor. For the first The actual drift tolerance threshold used by each jump device on the path; Step S6: When the modified inherent threat value Greater than the preset alarm trigger threshold At that time, an active isolation alarm will be triggered.
2. The computer network alarm method according to claim 1, characterized in that: The handshake metadata includes one or more of the following: ALPN tag, cipher suite identifier, JA3 / JA3S fingerprint, and 0-RTT usage flag.
3. The computer network alarm method according to claim 1, characterized in that: The criteria for determining handshake metadata mutations are: inconsistent ALPN labels between two adjacent hops, or JA3 / JA3S fingerprint drift exceeding the current drift tolerance threshold of the path. Or, the 0-RTT flag may indicate an abnormal jump during non-first connection.
4. The computer network alarm method according to claim 1, characterized in that: The edge weights of the encrypted session association graph are jointly determined by the following factors: the degree of sharing of JA3 fingerprints, the degree of sharing of certificate issuers, the similarity of TLS record length sequences, and the strength of the temporal cooperation pattern.
5. A computer network alarm method according to claim 1, characterized in that: The subgraph density The calculation formula is: in, For the first The set of edges in the encrypted session association subgraph along the attack threat path. For the first The set of encrypted session nodes involved in the attack threat path.
6. A computer network alarm method according to claim 1, characterized in that: The subgraph density influence coefficient The value range is [0.5, 2.0].
7. A computer network alarm method according to claim 1, characterized in that: The subgraph density trigger threshold The preferred value is 0.
6. The preferred value is 0.
15. The value range is [0.1, 0.8].
8. A computer network alarm system, which applies the computer network alarm method according to any one of claims 1-7, characterized in that: include: The path identification module is used to bind all communication interaction patterns within the target communication network with the risk verification links between corresponding communication nodes to obtain a vulnerability relationship network. This network is then used to perform multi-step attack simulations, identify attack threat paths, and determine the initial inherent threat value. ; The relay verification module is deployed on each hop device in the attack threat path. It is used to extract TLS or QUIC handshake metadata from the data stream, generate a verification token containing a summary of the handshake metadata, encapsulate the verification token in the data stream message and pass it to the next hop device, verify the continuity of the received verification token, and perform early termination in the current hop when a change in handshake metadata is detected. The association graph construction module is used to cluster all encrypted sessions by quintuples, construct an encrypted session association graph based on the association relationship of handshake metadata, and overlay the encrypted session association graph onto the weakness relationship network. The threat value correction module is used to connect the encrypted session association graph node set with the first... The intersection of the sets of encrypted sessions along each attack threat path yields a subgraph along that path, and the density of this subgraph is then used to determine the subgraph's subgraph structure. The inherent threat value of the path is dynamically adjusted according to Formula 1. Strictness adjustment module, used when At that time, adjust the strictness of the verification token continuity check of each hop device on the path in reverse according to Formula 2; The alarm trigger module is used when the corrected inherent threat value is displayed. Greater than the preset alarm trigger threshold At that time, an active isolation alarm will be triggered.
9. A computer network alarm system according to claim 8, characterized in that: The verification token generated by the relay verification module includes the following fields: handshake_digest, hop_counter, timestamp, and path_id; the verification token is transmitted by encapsulating it in the data stream message through an extended protocol header. handshake_digest: The digest of handshake metadata extracted in this hop, which is obtained by concatenating the ALPN tag, cipher suite identifier, JA3 / JA3S fingerprint, and 0-RTT usage flag and then calculating the cryptographic hash; hop_counter: Hop count counter, initially 0, increments with each hop; Timestamp: Used to detect replay attacks.
Citation Information
Patent Citations
Computer network alerting system and method
CN121644240B