Network security situation awareness system and method

A network security and situational awareness technology, applied in the field of network security, can solve problems such as weak pertinence, low analysis efficiency, and complexity, and achieve the effect of wide data collection, strong perception ability, and strong pertinence

Inactive Publication Date: 2020-10-02
黑龙江省网络空间研究中心 +1
View PDF5 Cites 7 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

[0002] Situational awareness is an environment-based, dynamic, and holistic ability to understand security risks. It is based on security big data and is a way to improve the ability to discover, identify, understand, analyze, and respond to security threats from a global perspective. Ultimately, It is for decision-making and action, and for the implementation of security capabilities. With the importance of network security highlighted, situational awareness has begun to emerge in the field of network security. At this stage, facing the risk of failure of traditional security defense systems, situational awareness can fully perceive network security. Threat situation, insight into the health status of network and application operation, complete network attack traceability and evidence collection through full traffic analysis technology, and help security personnel take targeted response measures. The existing network security situation awareness method is too complicated and the analysis efficiency is not high , the pertinence is not strong, therefore, we propose a network security situational awareness method and system

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Network security situation awareness system and method
  • Network security situation awareness system and method
  • Network security situation awareness system and method

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0027] The following clearly and completely describes the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only some of the embodiments of the present invention, but not all of them. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without making creative efforts belong to the protection scope of the present invention.

[0028] The invention provides a technical solution: refer to figure 1 , image 3 and Figure 4 As shown, a network security situational awareness system includes a data acquisition module for extensive collection of network security data, including network structure data, network service data, vulnerability data, threat data, intrusion data, and user anomaly data;

[0029] The situation assessment module is used to conduct situation assessment on the collected data. When conducting situation assessment, it is necessary to establis...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

PUM

No PUM Login to view more

Abstract

The invention relates to a network security situation awareness system and a network security situation awareness method. The network security situation awareness method comprises the steps of 1, acquiring data, and widely acquiring network security data; 2, carrying out situation assessment on the collected data, establishing assessment of multiple levels and multiple angles during situation assessment, assessing service security, data security, infrastructure security and overall security conditions of the network, and selecting different assessment methods for different application backgrounds and different network scales; 3, carrying out situation prediction on the preliminarily evaluated data to prevent large-scale security events; and 4, analyzing the problem data and proposing a corresponding analysis report. The method is high in pertinence and wide in data acquisition range, and can perform comprehensive acquisition and subsequent perception on network structure data, networkservice data, vulnerability data, threat data, intrusion data and user abnormal data.

Description

technical field [0001] The invention relates to the technical field of network security, and relates to a network security situation awareness system and method. Background technique [0002] Situational awareness is an environment-based, dynamic, and holistic ability to understand security risks. It is based on security big data and is a way to improve the ability to discover, identify, understand, analyze, and respond to security threats from a global perspective. Ultimately, It is for decision-making and action, and for the implementation of security capabilities. With the importance of network security highlighted, situational awareness has begun to emerge in the field of network security. At this stage, facing the risk of failure of traditional security defense systems, situational awareness can fully perceive network security. Threat situation, insight into the health status of network and application operation, complete network attack traceability and evidence collect...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to view more

Application Information

Patent Timeline
no application Login to view more
Patent Type & Authority Applications(China)
IPC IPC(8): H04L29/06
CPCH04L63/1416H04L63/1425H04L63/1433
Inventor 曲家兴谷俊涛马遥树彬孙恕潘天贺
Owner 黑龙江省网络空间研究中心
Who we serve
  • R&D Engineer
  • R&D Manager
  • IP Professional
Why Eureka
  • Industry Leading Data Capabilities
  • Powerful AI technology
  • Patent DNA Extraction
Social media
Try Eureka
PatSnap group products