错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Terminal Anomaly Discovery Technology Based on Service Behavior Deviation

  • Lu Chen,
  • Tao Zhang,
  • Yuanyuan Ma,
  • Mu Chen

摘要

The main existing network security problem of the current power marketing terminal is that the abnormal business behavior of the legitimate power marketing terminal cannot be perceived, and there is a risk of using it as a springboard to attack the power intranet caused by “one authentication, always trust”. Therefore, this paper aims at the lack of “one-time authentication, always trust” behavior monitoring and evaluation technology of legal terminals in the existing terminal protection architecture, and studies the terminal anomaly discovery technology based on the degree of business behavior deviation. First of all, with the goal of real-time network traffic compression and formalized representation of behavior timing patterns of business terminals, a business timing symbolization method based on multivariate Gaussian mixture distribution is studied to simplify and symbolize the terminal behavior timing. Then, the terminal behavior symbolized data is reconstructed in a multi-dimensional standard format using the Gramian Angular Field. Finally, a terminal anomaly evaluation model of behavior deviation degree is proposed, and the detection result of the terminal is obtained through the calculation of behavior deviation to reflect the abnormality and credibility of the terminal. As a result, real-time monitoring and abnormal behavior identification of legitimate terminals being exploited are solved. The experimental results show that the method proposed in this article can accurately describe the characteristics of the original time series, accurately detect abnormal terminal behavior, and meet performance requirements.