IPv6 address network space situation awareness method based on data collection
By collecting and analyzing data in the IPv6 network, identifying abnormal traffic behaviors and potential threats, and building dynamic situation awareness charts, it solves the problem that traditional detection methods are difficult to identify abnormal traffic, and achieves efficient security monitoring and response to IPv6 networks.
Patent Information
- Application Number
- CN202411786787.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-05
- Publication Date
- 2025-06-20
AI Technical Summary
In IPv6 networks, traditional signature-based traffic detection methods are difficult to efficiently identify and classify abnormal traffic, resulting in difficulty in timely discovering and responding to potential threats.
Using a data collection-based method, data is collected through network sensors and traffic monitoring devices, IPv6 scanning tools are used to detect IPv6 address space, obtain active IP addresses and service information, and combined with geographic location and timestamp data, use Spark data analysis tools and SVM models to identify abnormal traffic behaviors and potential threats, and finally build a dynamic situational awareness chart through Echarts.
It realizes efficient identification and classification of abnormal traffic in IPv6 networks, timely discovers potential threats, and improves the security monitoring and response capabilities of IPv6 networks.
Smart Images

Figure CN120185847A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the technical field of IPv6 situation awareness, and more specifically, relates to an IPv6 address cyberspace situation awareness method based on data collection. Background Art
[0002] With the rapid development of the Internet and the gradual exhaustion of IPv4 addresses, the IPv6 protocol has been widely adopted. Compared with IPv4, IPv6 provides a much wider address space and more functions. However, the complexity and huge address space of the IPv6 network also bring a series of new challenges, especially in terms of network security and situation awareness.
[0003] Compared with the IPv4 network, the IPv6 network traffic is more complex. Due to its huge address space, malicious traffic can be more dispersed and concealed, which increases the detection difficulty. Traditional signature-based traffic detection methods are inadequate in the face of unknown threats and zero-day attacks. Therefore, how to efficiently identify and classify abnormal traffic in the IPv6 network to achieve timely discovery and response to potential threats has become a core technical issue in the IPv6 address cyberspace situation awareness. Summary of the Invention
[0004] The present invention provides an IPv6 address cyberspace situation awareness method based on data collection, aiming to efficiently identify and classify abnormal traffic in the IPv6 network, so as to achieve timely discovery and response to potential threats.
[0005] The IPv6 address cyberspace situation awareness method based on data collection includes the following steps:
[0006] Step 1: Use network sensors and traffic monitoring devices to collect network data, actively detect the entire IPv6 address space through an IPv6 scanning tool to obtain active IP addresses and service information, and use public network resources to obtain domain name registration information and geographical location data related to IPv6 addresses;
[0007] Step 2: Preprocess the obtained network data, active IP addresses, service information, domain name registration information, and geographical location data;
[0008] Step 3: Based on the Spark data analysis tool, process the preprocessed data to identify abnormal traffic behaviors;
[0009] Step 4: Use the SVM model to classify the behaviors of IPv6 addresses to identify potential threats;
[0010] Step 5: Combine geographical location and timestamp data to analyze the spatio-temporal distribution of network events;
[0011] Step 6: Based on the abnormal traffic behavior, potential threats, and the spatio-temporal distribution of network events, use the Echarts visualization tool to construct a dynamic situation awareness chart to display the global situation of the IPv6 network.
[0012] The present invention realizes the efficient identification and classification of abnormal traffic in the IPv6 network through the following steps, so as to discover potential threats in a timely manner: First, use network sensors and traffic monitoring devices to collect network data, and actively detect the entire IP v address space through an IPv6 scanning tool to obtain active IP addresses and service information, and at the same time use public resources to obtain the domain name registration information and geographical location data of the IP v 6 addresses. Subsequently, preprocess this data to ensure its uniform format and validity. Then, process the preprocessed data based on the Spark big data analysis tool to identify abnormal traffic behavior from it. On this basis, use the support vector machine (SVM) model to classify the behavior of IPv6 addresses to identify potential threats. Combine geographical location and timestamp data to further analyze the spatio-temporal distribution of network events. Finally, based on the identified abnormal traffic behavior, potential threats and their spatio-temporal distribution, use the Echarts visualization tool to construct a dynamic situation awareness chart to intuitively display the overall security situation of the IPv6 network. This method comprehensively improves the security monitoring and response capabilities of the IPv6 network through multi-level data processing and analysis.
[0013] Preferably, step 3 includes the following steps:
[0014] Data import: Import the preprocessed data into the Spark environment, where the preprocessed data includes active IP addresses, service information, domain name registration information, and geographical location data;
[0015] Feature extraction: Extract key features from the preprocessed data, including: IP address, port number, protocol type, packet size, and transmission time;
[0016] Time window division: Use the sliding window technique to divide the traffic data by time. In each time window, the feature set F is used to construct the feature subset F wt :
[0017]
[0018] In the formula: represents the feature subset within the time window w t ; f i represents a single feature in the feature set F; Δt represents the window length; t represents the current time;
[0019] Traffic Aggregation and Feature Statistics:
[0020]
[0021] Where: C requets represents the number of requests within the time window;
[0022]
[0023] Where: packet_size represents the packet size in the network traffic data; S total represents the total packet size within the time window;
[0024]
[0025] Where: S avg represents the average packet size within the time window;
[0026] P protocol ={TCP:N TCP ,UDP:N UDP ,…};
[0027] Where: P protocol represents the distribution of different protocols within the time window; N TCP represents the number of TCP protocol packets within the time window; N UDP represents the number of UDP protocol packets within the time window;
[0028] Anomaly Detection: Use z-score to perform anomaly detection on the extracted features. Measure the deviation degree of the data point from the mean through z-score, and then compare based on the deviation degree and the set threshold to filter out the abnormal traffic with a z-score value greater than the threshold;
[0029] Pattern Recognition: Adopt k-means clustering to perform pattern recognition on the abnormal traffic, and output the identified abnormal traffic behaviors and their features. The output data includes IP address, time window, number of requests, total packet size, average packet size, and abnormal pattern.
[0030] Preferably, the anomaly detection includes the following steps:
[0031] Data Standardization: Standardize the extracted features;
[0032] Calculate the Mean and Standard Deviation: For each extracted feature, extract its mean and standard deviation in the historical data;
[0033] Calculate z-score: For the feature value of each time window, calculate the z-score value to measure the deviation degree between the feature value and its mean:
[0034]
[0035] Where: z feature represents the z-score value of the feature; f i represents a single feature in the feature set F; μ feature represents the mean of the feature; σ feature represents the standard deviation of the feature;
[0036] Determine the threshold: Set the threshold of the z-score according to historical data and dynamically adjust the threshold of the z-score at different time periods or different network states;
[0037] Anomaly detection: According to the calculated z-score value and the set threshold, determine whether the feature value is abnormal. If the comprehensive z-score value is greater than the threshold, the traffic corresponding to the feature value is considered abnormal traffic:
[0038]
[0039] Where: z combined represents the comprehensive z-score value, which is the comprehensive z-score value of traffic-related features within the same time window; z featurei represents the z-score value of the i-th feature; w i represents the weight of the i-th feature; m represents the total number of features.
[0040] Preferably, the specific steps for determining the threshold are as follows:
[0041] Statistical analysis: Conduct statistical analysis on the comprehensive z-score values in historical data, and calculate the mean and variance of the comprehensive z-score values;
[0042] Set the initial threshold: Set the initial threshold based on the mean and variance of the comprehensive z-score values:
[0043] Threshold initial = μ z-history + k·σ z-history ;
[0044] Where: Threshold initial represents the set initial threshold; μ z-history represents the mean of the historical comprehensive z-score values; σ z-history represents the standard deviation of the historical comprehensive z-score values; k represents the adjustment factor, and its value is 2 or 3;
[0045] Real-time monitoring: Monitor the distribution of the comprehensive z-score values of real-time data, and calculate the mean and standard deviation of the real-time data;
[0046] Adjust the threshold: Adjust the initial threshold according to the statistical characteristics of the real-time data:
[0047] Threshold adjusted = α·Threshold initial +(1 - α)·(μ z-real + j·σ z-real );
[0048] Where: Threshold adjusted represents the adjusted threshold; α represents the smoothing factor, and its value range is from 0 to 1; μ z-real represents the mean value of the comprehensive z-score value of the real-time data; σ z-real represents the standard deviation of the comprehensive z-score value of the real-time data.
[0049] Preferably, the input feature vectors of the SVM include: active IPv6 addresses, service information, domain name registration information, geographical location data, and abnormal traffic behavior; among which, the kernel function of the SVM model adopts the Gaussian kernel function.
[0050] Preferably, step 5 includes the following steps:
[0051] Data aggregation and labeling: Aggregate the timestamp and geographical location data with the network event data to form a comprehensive data set including time, location, and event type;
[0052] Event time analysis: Calculate the moving average of the time series using the moving average:
[0053]
[0054] Where: MA t represents the moving average at time t; n represents the window size; E t-i is the number of events at time t - i;
[0055] Geographical distribution analysis: Use the heat map technology to display the distribution density of events in the geographical space, and use the clustering algorithm to identify the spatial aggregation areas of events;
[0056] Spatio-temporal correlation analysis: Based on the results of the event analysis and the results of the geographical distribution analysis, use the spatio-temporal hotspot analysis method to identify the spatio-temporal hotspot areas and time periods, and construct a spatio-temporal adjacency matrix to represent the spatio-temporal adjacency relationship:
[0057]
[0058] Where: l i and l j represent geographical locations; t iand t j represent a time point;
[0059] Spatio-temporal pattern recognition: Based on event quantity data, geographical location data, timestamp data, and a spatio-temporal weight matrix, a spatio-temporal autoregressive model is used to identify spatio-temporal distribution patterns.
[0060] The beneficial effects of the present invention include:
[0061] The present invention realizes the efficient identification and classification of abnormal traffic in the IPv6 network through the following steps, so as to discover potential threats in a timely manner: First, network sensors and traffic monitoring devices are used to collect network data, and the entire IPv6 address space is actively detected through an IPv6 scanning tool to obtain active IP addresses and service information. At the same time, domain name registration information and geographical location data of IPv6 addresses are obtained using public resources. Subsequently, these data are preprocessed to ensure their uniform format and validity. Then, the preprocessed data is processed based on the Spark big data analysis tool to identify abnormal traffic behaviors from it. On this basis, a support vector machine (SVM) model is used to classify the behaviors of IPv6 addresses to identify potential threats. Combining geographical location and timestamp data, the spatio-temporal distribution of network events is further analyzed. Finally, based on the identified abnormal traffic behaviors, potential threats, and their spatio-temporal distribution, a dynamic situation awareness chart is constructed using the Echarts visualization tool to intuitively display the overall security situation of the IPv6 network. This method comprehensively improves the security monitoring and response capabilities of the IPv6 network through multi-level data processing and analysis. Description of the Drawings
[0062] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0063] Figure 1 It is the overall step block diagram provided by the embodiment of the present invention. Detailed Embodiments
[0064] In order to make the technical problems, technical solutions, and beneficial effects to be solved by the present application clearer, the following further details the present application in conjunction with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0065] See Figure 1 as shown, and further illustrate the optimal embodiment of the present invention;
[0066] An IPv6 address cyberspace situation awareness method based on data collection, comprising the following steps:
[0067] Step 1: Use network sensors and traffic monitoring devices to collect network data, actively probe the entire IPv6 address space through an IPv6 scanning tool to obtain active IP addresses and service information, and use public network resources to obtain domain name registration information and geographical location data related to IPv6 addresses;
[0068] Step 2: Preprocess the obtained network data, active IP addresses, service information, domain name registration information, and geographical location data; clean the data, delete duplicate data, and process missing values and outliers;
[0069] Step 3: Based on the data processed and preprocessed by the Spark data analysis tool, identify abnormal traffic behaviors;
[0070] Step 4: Use the SVM model to classify the behaviors of IPv6 addresses to identify potential threats;
[0071] Step 5: Combine geographical location and timestamp data to analyze the spatio-temporal distribution of network events;
[0072] Step 6: Based on abnormal traffic behaviors, potential threats, and the spatio-temporal distribution of network events, use the Echarts visualization tool to construct a dynamic situation awareness chart to display the overall situation of the IPv6 network.
[0073] The present invention realizes the efficient identification and classification of abnormal traffic in the IPv6 network through the following steps, so as to discover potential threats in a timely manner: First, use network sensors and traffic monitoring devices to collect network data, and actively probe the entire IPv6 address space through an IPv6 scanning tool to obtain active IP addresses and service information, and at the same time use public resources to obtain the domain name registration information and geographical location data of IPv6 addresses. Subsequently, preprocess these data to ensure their uniform format and effectiveness. Then, based on the Spark big data analysis tool, process the preprocessed data to identify abnormal traffic behaviors. On this basis, use the support vector machine (SVM) model to classify the behaviors of IPv6 addresses to identify potential threats. Combine geographical location and timestamp data to further analyze the spatio-temporal distribution of network events. Finally, based on the identified abnormal traffic behaviors, potential threats, and their spatio-temporal distribution, use the Echarts visualization tool to construct a dynamic situation awareness chart to intuitively display the overall security situation of the IPv6 network. This method comprehensively improves the security monitoring and response capabilities of the IPv6 network through multi-level data processing and analysis.
[0074] As a possible implementation manner of this embodiment, step 3 includes the following steps:
[0075] Data Import: Import the preprocessed data into the Spark environment. The preprocessed data includes active IP addresses, service information, domain name registration information, and geographical location data.
[0076] Feature Extraction: Extract key features from the preprocessed data, including: IP address, port number, protocol type, packet size, and transmission time.
[0077] Time Window Partitioning: Use the sliding window technique to partition the traffic data by time. In each time window, the feature set F is used to construct the feature subset F within the current time window. wt :
[0078]
[0079] Where: represents the feature subset within the time window w. t f i represents a single feature in the feature set F; Δt represents the window length; t represents the current time.
[0080] Traffic Aggregation and Feature Statistics:
[0081]
[0082] Where: C requets represents the number of requests within the time window.
[0083]
[0084] Where: packet_size represents the packet size in the network traffic data; S total represents the total packet size within the time window.
[0085]
[0086] Where: S avg represents the average packet size within the time window.
[0087] P protocol ={TCP:N TCP ,UDP:N UDP ,…};
[0088] Where: P protocol represents the distribution of different protocols within the time window; N TCP represents the number of TCP protocol packets within the time window; N UDP represents the number of UDP protocol packets within the time window.
[0089] Anomaly detection: Use the z-score to perform anomaly detection on the extracted features. The z-score measures the degree of deviation of a data point from the mean, and then based on the degree of deviation and a set threshold for comparison, filter out the abnormal traffic with a z-score value greater than the threshold;
[0090] Pattern recognition: Use k-means clustering to perform pattern recognition on the abnormal traffic, and output the identified abnormal traffic behaviors and their characteristics. The output data includes IP address, time window, number of requests, total packet size, average packet size, and abnormal patterns.
[0091] In this embodiment, the Spark environment is used for data processing, which can process large-scale data and ensure the efficiency of data processing. Extract key features from the preprocessed data to ensure the multi-dimensionality and comprehensiveness of the analysis; through the sliding window technique and the aggregation and statistics of traffic data, the changing trend of network traffic can be dynamically analyzed, and useful statistical features can be extracted; through the z-score method for anomaly detection, abnormal traffic can be detected in a timely manner, and the k-means clustering method can effectively identify and classify abnormal traffic patterns, which helps to identify and warn of potential threats.
[0092] As a possible implementation manner of this embodiment, the anomaly detection includes the following steps:
[0093] Data standardization: Standardize the extracted features;
[0094] Calculate the mean and standard deviation: For each extracted feature, extract its mean and standard deviation in the historical data;
[0095] Calculate the z-score: For the feature values of each time window, calculate the z-score value to measure the degree of deviation between the feature value and its mean:
[0096]
[0097] In the formula: z feature represents the z-score value of the feature; f i represents a single feature in the feature set F; μ feature represents the mean of the feature; σ feature represents the standard deviation of the feature;
[0098] Determine the threshold: Set the threshold of the z-score according to the historical data, and dynamically adjust the threshold of the z-score in different time periods or different network states;
[0099] Anomaly Detection: Based on the calculated z-score value and the set threshold, determine whether the eigenvalue is abnormal. If the combined z-score value is greater than the threshold, the traffic corresponding to this eigenvalue is considered abnormal traffic:
[0100]
[0101] where: z combined represents the combined z-score value, which is the combined z-score value of traffic-related features within the same time window; z featurei represents the z-score value of the i-th feature; w i represents the weight of the i-th feature; m represents the total number of features.
[0102] As a possible implementation of this embodiment, the specific steps for determining the threshold are as follows:
[0103] Statistical Analysis: Conduct statistical analysis on the combined z-score values in historical data, and calculate the mean and variance of the combined z-score values;
[0104] Set the Initial Threshold: Set the initial threshold based on the mean and variance of the combined z-score values:
[0105] Threshold initial = μ z-history + k·σ z-history ;
[0106] where: Threshold initial represents the set initial threshold; μ z-history represents the mean of the historical combined z-score values; σ z-history represents the standard deviation of the historical combined z-score values; k represents the adjustment factor, with a value of 2 or 3;
[0107] Real-time Monitoring: Monitor the distribution of the combined z-score values of real-time data, and calculate the mean and standard deviation of the real-time data;
[0108] Adjust the Threshold: Adjust the initial threshold according to the statistical characteristics of the real-time data:
[0109] Threshold adjusted = α·Threshold initial +(1 - α)·(μ z-real + k·σ z-real );
[0110] where: Threshold adjusted represents the adjusted threshold; α represents the smoothing factor, with a value range of 0 to 1; μ z-realrepresents the mean of the comprehensive z-score values of real-time data; σ z-real represents the standard deviation of the comprehensive z-score values of real-time data.
[0111] In this embodiment, statistical analysis is performed based on historical data to set an initial threshold to ensure the basic stability of the initial detection; by real-time monitoring and dynamically adjusting the threshold, it can timely adapt to changes in the network state and improve the real-time performance and accuracy of anomaly detection.
[0112] As a possible implementation manner of this embodiment, the input feature vectors of the SVM include: active IPv6 addresses, service information, domain name registration information, geographical location data, and abnormal traffic behaviors; the kernel function of the SVM model adopts a Gaussian kernel function.
[0113] As a possible implementation manner of this embodiment, step 5 includes the following steps:
[0114] Data aggregation and marking: Aggregate the timestamp and geographical location data with the network event data to form a comprehensive data set including time, location, and event type;
[0115] Event time analysis: Calculate the moving average of the time series using the moving average:
[0116]
[0117] In the formula: MA t represents the moving average at time t; n represents the window size; E t-i is the number of events at time t - i;
[0118] Geographical distribution analysis: Use heat map technology to display the distribution density of events in the geographical space, and use clustering algorithms to identify the spatial aggregation areas of events;
[0119] Spatio-temporal correlation analysis: Based on the results of event analysis and geographical distribution analysis, use spatio-temporal hotspot analysis methods to identify spatio-temporal hotspot areas and time periods, and construct a spatio-temporal adjacency matrix to represent spatio-temporal adjacency relationships:
[0120]
[0121] In the formula: l i and l j represent geographical locations; t i and t j represent time points;
[0122] Spatio-temporal pattern recognition: Based on the event quantity data, geographical location data, timestamp data, and spatial weight matrix, use a spatio-temporal autoregressive model to identify spatio-temporal distribution patterns;
[0123] The steps for determining the spatio-temporal adjacency relationship are as follows:
[0124] Set a distance threshold D. If the Euclidean distance between two location points is less than the preset distance threshold D, they are considered to be spatially adjacent;
[0125] Preset a time window T. If the time difference between two events is within the preset time window T, they are considered to be temporally adjacent;
[0126] Comprehensive spatio-temporal adjacency: Combining the definitions of spatial adjacency and temporal adjacency, if two times simultaneously meet the adjacency conditions in terms of space and time, they are considered to be spatio-temporally adjacent.
[0127] In this embodiment, aggregating timestamp and geographical location data with network event data to form a comprehensive dataset helps with all-round analysis. Using the moving average method for time series analysis can smooth data fluctuations and reveal long-term trends. Utilizing heatmaps and clustering algorithms can visually display the event distribution density and identify spatial aggregation regions for facilitating spatial situation awareness; by constructing a spatio-temporal adjacency matrix, identifying spatio-temporal hot regions and time periods, and revealing the spatio-temporal distribution pattern of events.
[0128] Therefore, through the comprehensive application of various technical means such as big data processing, feature extraction, anomaly detection, pattern recognition, and spatio-temporal analysis, the present invention can achieve efficient, accurate, and comprehensive situation awareness of the IPv6 address network space. This not only improves the ability of network security monitoring but also enhances the early warning and prevention capabilities for potential threats, providing strong technical support for network security management.
[0129] As a possible implementation manner of this embodiment, the specific steps of the spatio-temporal pattern recognition are as follows:
[0130] Initialization: Determine the initial parameters α, β, and γ of the model.
[0131] Time autoregression: For each time step t, calculate the time autoregression part βXt-1.
[0132] Spatial autoregression: Calculate the spatial autoregression part γWXt-1, where WXt-1 represents applying the spatial weight matrix W to the event quantity matrix Xt-1 at the previous time step.
[0133] Error term processing: Introduce a random error term ∈t, assuming it follows a normal distribution ∈t ∼ N(0,σ2).
[0134] Model training
[0135] Parameter estimation: Use data fitting methods (such as the least squares method, maximum likelihood estimation) to estimate the model parameters α, β, and γ.
[0136] Iterative optimization: Use optimization algorithms (such as gradient descent, Newton's method) to iteratively optimize the parameters and minimize the prediction error.
[0137] Pattern recognition: By analyzing the model parameters β and γ, identify patterns in time and space. For example, a larger β indicates strong autocorrelation in time, and a larger γ indicates strong autocorrelation in space.
[0138] As a possible implementation of this embodiment, step 6 includes the following steps:
[0139] Before constructing the dynamic situation awareness chart, relevant data needs to be prepared, including: abnormal traffic behavior data, potential threat classification results, spatio-temporal distribution data of network events, geographical location and timestamp data;
[0140] Aggregate and label all relevant data for clear display in the chart:
[0141] Data aggregation: Integrate data from different sources into a comprehensive dataset, ensuring that each record contains all necessary attributes (such as timestamp, geographical location, abnormal behavior, threat category, etc.).
[0142] Data labeling: Add labels (such as abnormal traffic type, threat level, etc.) to each record according to the data attributes for easy differentiation and display in the chart.
[0143] According to the display requirements, select suitable Echarts chart types, including but not limited to:
[0144] Geographical heat map: Display the geographical distribution of abnormal traffic and threats.
[0145] Time series chart: Display the time variation trend of network events.
[0146] Scatter plot / bubble chart: Display the distribution and correlation of different types of threats.
[0147] Dynamic chart: Real-time update and display the changes in the network situation.
[0148] Integrate all charts into a page or dashboard, ensuring data consistency and interactivity between different charts:
[0149] Layout design: Reasonably arrange the layout of the charts on the page to ensure the intuitiveness and aesthetics of information display.
[0150] Interactivity: Enhance the user experience through interactive tools (such as zooming, filtering, linking, etc.), enabling users to easily explore and analyze the data.
[0151] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.
Claims
1. An IPv6 address network space situation awareness method based on data collection, characterized in that: The following steps are involved: Step 1: Use network sensors and traffic monitoring devices to collect network data, use IPv6 scanning tools to actively detect the entire IPv6 address space, obtain active IP addresses and service information, and use public network resources to obtain domain name registration information and geographic location data related to IPv6 addresses; Step 2: Preprocess the acquired network data, active IP addresses, service information, domain name registration information, and geographic location data; Step 3: Identify abnormal traffic behavior based on the data processed and preprocessed by the Spark data analysis tool; Step 4: Use the SVM model to classify the behavior of IPv6 addresses and identify potential threats; Step 5: Combine geographic location and timestamp data to analyze the spatiotemporal distribution of network events; Step 6: Based on abnormal traffic behavior, potential threats, and the spatiotemporal distribution of network events, use the Echarts visualization tool to build a dynamic situation awareness chart to display the global situation of the IPv6 network.
2. The method for IPv6 address network space situation awareness based on data collection according to claim 1, characterized in that: The step 3 comprises the following steps: Data import: Import the preprocessed data into the Spark environment, where the preprocessed data includes active IP addresses, service information, domain name registration information, and geographic location data; Feature extraction: Extract key features from the preprocessed data, including: IP address, port number, protocol type, packet size, and transmission time; Time window division: Use sliding window technology to divide traffic data by time. In each time window, the feature set F is used to construct the feature subset in the current time window. Where: Indicates that in time window w t The feature subset within i represents a single feature in the feature set F; Δt represents the window length; t represents the current time; Traffic aggregation and feature statistics: Where: C requets Indicates the number of requests within the time window; Where: packet_size represents the size of the data packet in the network traffic data; S total Indicates the total size of packets within the time window; Where: S avg Indicates the average packet size within the time window; P protocol ={TCP:N TCP ,UDP:N UDP ,…}; Where: P protocol represents the distribution of different protocols in the time window; N TCP Indicates the number of TCP protocol packets in the time window; N UDP Indicates the number of UDP protocol packets in the time window; Anomaly detection: Use z-score to detect anomalies on the extracted features. The z-score is used to measure the degree of deviation between the data point and the mean. The deviation is then compared with the set threshold to filter out abnormal traffic with a z-score value greater than the threshold. Pattern recognition: k-means clustering is used to perform pattern recognition on abnormal traffic, and the identified abnormal traffic behavior and its characteristics are output. The output data includes IP address, time window, number of requests, total packet size, average packet size, and abnormal pattern.
3. The method for IPv6 address network space situation awareness based on data collection according to claim 2 is characterized in that: The anomaly detection comprises the following steps: Data standardization: standardize the extracted features; Calculate the mean and standard deviation: For each extracted feature, extract its mean and standard deviation in the historical data; Calculate the z-score: For each feature value in each time window, calculate the z-score value to measure the degree of deviation between the feature value and its mean: Where: z feature Indicates the z-score value of the feature; f i Represents a single feature in the feature set F; μ feature represents the mean of the feature; σ feature represents the standard deviation of the feature; Determine the threshold: Set the z-score threshold based on historical data, and dynamically adjust the z-score threshold in different time periods or under different network conditions; Anomaly detection: Based on the calculated z-score value and the set threshold, determine whether the feature value is abnormal. If the comprehensive z-score value is greater than the threshold, the traffic corresponding to the feature value is considered to be abnormal traffic: Where: z combined Represents the comprehensive z-score value, which is the comprehensive z-score value of traffic-related features in the same time window; represents the z-score value of the i-th feature; w i represents the weight of the i-th feature; m represents the total number of features.
4. The method for IPv6 address network space situation awareness based on data collection according to claim 3 is characterized in that: The specific steps of determining the threshold are as follows: Statistical analysis: Perform statistical analysis on the comprehensive z-score values in historical data and calculate the mean and variance of the comprehensive z-score values; Set the initial threshold: Set the initial threshold based on the mean and variance of the comprehensive z-score value: Threshold initial =μ z-history +k·σ z-history ; Where: Threshold initial Indicates the initial threshold set; μ z-history Represents the mean of the historical comprehensive z-score value; σ z-history represents the standard deviation of the historical comprehensive z-score value; k represents the adjustment factor, which takes a value of 2 or 3; Real-time monitoring: monitor the comprehensive z-score value distribution of real-time data and calculate the mean and standard deviation of real-time data; Adjust the threshold: Adjust the initial threshold based on the statistical characteristics of real-time data: Threshold adjusted =α·Threshold initial +(1-α)·(μ z-real +k·σ z-real ); Where: Threshold adjusted represents the adjusted threshold; α represents the smoothing factor, ranging from 0 to 1; μ z-real Represents the mean of the comprehensive z-score value of real-time data; σ z-real Indicates the standard deviation of the comprehensive z-score value of real-time data.
5. The method for IPv6 address network space situation awareness based on a data set according to claim 1, characterized in that: The input feature vector of the SVM includes: active IPv6 addresses, service information, domain name registration information, geographic location data and abnormal traffic behavior; wherein the kernel function of the SVM model adopts a Gaussian kernel function.
6. The method for IPv6 address network space situation awareness based on a data set according to claim 1, characterized in that: The step 5 comprises the following steps: Data aggregation and tagging: Aggregate timestamp and geolocation data with network event data to form a comprehensive dataset containing time, location, and event type; Event Time Analysis: Using Moving Average to calculate the moving average of a time series: Where: MA t represents the moving average of time t; n represents the window size; E t-i is the number of events at time ti; Geographic distribution analysis: Use heat map technology to display the distribution density of events in geographic space, and use clustering algorithms to identify spatial clustering areas of events; Spatiotemporal association analysis: Based on the results of event analysis and geographic distribution analysis, the spatiotemporal hotspot analysis method is used to identify spatiotemporal hotspot areas and time periods, and a spatiotemporal adjacency matrix is constructed to represent the spatiotemporal adjacency relationship: Where: l i and l j Indicates geographical location; i and t j Indicates a point in time; Spatiotemporal pattern recognition: Based on event quantity data, geographic location data, timestamp data and spatial weight matrix, a spatiotemporal autoregressive model is used to identify spatiotemporal distribution patterns.
Citation Information
Cited By
IPv6 network reconstruction problem identification model generation method based on neural network
CN120956580A