基于流量交互图分析的Web服务威胁检测方法OA
Web service threat detection method based on traffic interaction graph analysis
随着Web服务应用功能的不断扩展,其面临的安全威胁日益严峻,对服务安全性与可靠性的要求也逐步提高.在服务资源规模持续增长的同时,攻击面不断扩大,攻击者的能力不断增强,使得未知威胁与群体性攻击逐渐增多.特别是在实际网络环境中存在大量无标签流量数据的情况下,实现Web服务流量的轻量化交互关系表征、有效检测多源威胁,以及在无标签环境下构建具备良好的可解释性的检测模型,成为突破当前安全瓶颈的关键.为此,提出了一种基于流量分析的轻量化流量交互图构建方法,以实现高效表征.通过引入结构熵博弈划分机制,实现了对流量交互图社区的自适应划分.在此基础上,通过分析社区子图的拓扑特性,并借助图指标排序识别关键社区.进一步提出了一种基于Z分数的威胁顶点自适应检测方法,以有效识别关键社区中的高威胁顶点.同时,提出基于结构熵的群体威胁检测方法,以精准发现群体威胁实体.该方法无须依赖先验知识与数据标签,兼具对未知威胁的适应能力、对加密流量的鲁棒性、模型的可解释性.在公开数据集与实际网络流量数据上的测试结果表明,该方法能够有效识别多种威胁Web服务可用性的实体与攻击行为,具有较高的检测准确率和实际工程应用价值.
With the continuous expansion of Web service functionalities,the security threats they face have become increasingly severe,leading to growing demands for service security and reliability.As service resources scale up,the attack surface widens,and attacker capabilities strengthen,resulting in a rise in unknown threats and swarm at-tack.Particularly in real-world network environments where large amounts of unlabeled traffic data exist,key chal-lenges include achieving lightweight characterization of Web service traffic interactions,effectively detecting multi-source threats,and constructing a detection model with good interpretability in an unlabeled environment.These is-sues are critical to overcoming current security bottlenecks.To address these challenges,a lightweight traffic inter-action graph construction method based on traffic analysis for efficient characterization was proposed.By introduc-ing the structural entropy game partitioning mechanism,the adaptive partitioning of the communities in the traffic interaction graph has been achieved.On this basis,the topological characteristics of communities subgraphs were analyzed,and key communities were identified through graph metric ranking.Furthermore,a Z-score-based adap-tive threat vertex detection method was proposed to effectively identify high-threat vertices in key communities.Si-multaneously,a structural entropy-based swarm threat detection method was introduced to accurately detect swarm threat entities.The proposed method operates without relying on prior knowledge or data labels,while maintaining adaptability to unknown threats,robustness to encrypted traffic,and good interpretability.Experimental results on public datasets and real-world network traffic data demonstrated that the method could effectively identify various entities and attack behaviors that threaten the availability of Web services,achieving high detection accuracy and practical engineering application value.
余北缘;曾广杰;彭浩;刘建伟;李洪亮;谭学士
北京航空航天大学网络空间安全学院,北京 100191北京航空航天大学计算机学院,北京 100191北京航空航天大学网络空间安全学院,北京 100191北京航空航天大学网络空间安全学院,北京 100191奇安信科技集团股份有限公司,北京 100088奇安信科技集团股份有限公司,北京 100088
信息技术与安全科学
Web安全威胁检测流量交互图结构信息理论
Web securitythreat detectiontraffic interaction graphstructural information theory
《网络与信息安全学报》 2026 (2)
41-54,14
国家重点研发计划资助项目(No.2024YFB3108901)国家自然科学基金资助项目(No.U21B2021,No.62472015,No.62202027) The National Key Research and Development Program of China(No.2024YFB3108901),The National Natural Science Foundation of China(No.U21B2021,No.62472015,No.62202027)
评论