Network security situation awareness method and system based on artificial intelligence

Through the artificial intelligence-based network security situation awareness method, using machine learning and deep learning algorithms for threat detection and situation prediction, the problem that traditional network security protection methods are difficult to cope with complex network attacks is solved, and real-time perception and automatic response to network security situations are achieved.

CN120223358AInactive Publication Date: 2025-06-27LIAONING ZHONGFEI NETWORK TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510237544.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-03
Publication Date
2025-06-27
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional cybersecurity protection methods are difficult to effectively deal with complex and changeable cyber attacks, such as advanced persistent threats (APTs) and zero-day vulnerability attacks, and it is difficult to detect potential security threats in a timely and accurate manner, making it difficult to grasp the cybersecurity situation in a comprehensive and real-time manner.

Method used

Using artificial intelligence-based network security situation awareness methods, through steps such as data collection, preprocessing, artificial intelligence modeling and analysis, situation evaluation and visualization, response and decision support, machine learning and deep learning algorithms are used to perform abnormal detection, threat classification and situation prediction, and automatically trigger security strategies to deal with threats.

Benefits of technology

It greatly improves the detection capabilities of new and advanced persistent threats, realizes real-time and comprehensive perception and assessment of network security situations, supports automatic response and decision-making suggestions, and ensures network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223358A_ABST
    Figure CN120223358A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, in particular to a network security situation awareness method and system based on artificial intelligence, and the method comprises the following steps: 1, data collection: collecting multi-source data such as network traffic, system logs and threat intelligence, and providing basic materials for subsequent analysis; 2, data preprocessing, cleaning, normalization and feature extraction are carried out, so that the data are more regular and effective, and subsequent artificial intelligence model processing is facilitated; the network security situation awareness system based on artificial intelligence can perform deep analysis and mining on massive network security data by utilizing machine learning and deep learning algorithms, and can automatically learn and identify unknown attack modes and abnormal behaviors compared with a traditional detection method based on rules, so that the network security situation awareness system based on artificial intelligence can be applied to the field of network security situation awareness. And the detection capability on novel threats and advanced continuous threats is greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and specifically to a network security situation awareness method and system based on artificial intelligence. Background Art

[0002] In today's digital age, with the rapid development of information technology, the network has penetrated into all aspects of social life. Whether it is the daily operation of enterprises, the public services of the government, or the personal life and entertainment, they all highly rely on the network. However, with the extensive application of the network, network security issues have become increasingly prominent and are facing unprecedented challenges.

[0003] Traditional network security protection means, such as firewalls, intrusion detection systems (IDS) and intrusion prevention systems (IPS), mainly focus on preventing known threats and identifying and blocking attacks through preset rules and feature libraries. However, in the face of increasingly complex and changeable network attack means, such as advanced persistent threats (APT), zero-day vulnerability attacks, etc., these traditional methods seem inadequate. Attackers can use newly emerged vulnerabilities and technologies to bypass traditional protection mechanisms and conduct concealed and persistent attacks on network systems, causing huge losses to organizations and individuals.

[0004] In addition, with the continuous expansion of the network scale and the sharp increase in data traffic, the security data in the network shows the characteristics of being massive, multi-source, and heterogeneous. Traditional security analysis methods are difficult to efficiently process and analyze these large-scale data, and cannot timely and accurately discover potential security threats, resulting in the network security situation being difficult to be comprehensively and real-time grasped. Therefore, a network security situation awareness method and system based on artificial intelligence are proposed. Summary of the Invention

[0005] In view of this, the present invention provides a network security situation awareness method and system based on artificial intelligence to solve or alleviate the technical problems existing in the prior art and at least provide a beneficial option.

[0006] The technical solution of the present invention is realized as follows: A network security situation awareness method based on artificial intelligence includes the following steps:

[0007] Step 1, data collection, collecting multi-source data such as network traffic, system logs, and threat intelligence to provide basic materials for subsequent analysis;

[0008] Step 2, data preprocessing, cleaning, normalizing, and extracting features to make the data more regular and effective, facilitating subsequent processing by artificial intelligence models;

[0009] Step 3, artificial intelligence modeling and analysis, using machine learning and deep learning algorithms for anomaly detection, threat classification, and situation prediction to discover potential security threats and trends;

[0010] Step 4, Situation Assessment and Visualization: Quantitatively evaluate the network security situation and display it in an intuitive form to help administrators quickly understand the security status;

[0011] Step 5, Response and Decision Support: Automatically trigger security policies to address threats, provide decision-making suggestions for administrators, and ensure network security.

[0012] Further preferably, in Step 1, network probes are deployed at key network nodes to collect traffic information in the network in real time, including source IP, destination IP, port number, traffic volume, transmission protocol, etc. System logs are collected from network devices and security devices such as servers, firewalls, intrusion detection systems (IDS), and intrusion prevention systems (IPS). By collaborating with third-party threat intelligence platforms, the latest threat intelligence globally is obtained, including malicious IP addresses, malware characteristics, vulnerability information, etc.

[0013] Further preferably, in Step 2, noise, duplicate data, and invalid data are removed from the collected data. Data from different sources and in different formats are normalized to have a unified format and standard. Representative features are extracted from the preprocessed data for subsequent analysis and modeling.

[0014] Further preferably, in Step 3, machine learning algorithms are used to model network traffic and system log data to identify abnormal behavior patterns. By training an autoencoder model, normal network traffic data is encoded and decoded. When the input traffic data has a large difference from the reconstructed result of the model, it is determined as abnormal traffic. Deep learning algorithms are used to classify the collected threat intelligence data and abnormal events to determine the type and severity of threats. Based on time series analysis and machine learning algorithms, the development trend of the network security situation is predicted.

[0015] Further preferably, in Step 4, according to the results of anomaly detection, threat classification, and situation prediction, factors such as the importance of network assets, the severity of threats, and the occurrence probability are comprehensively considered to quantitatively evaluate the network security situation, generate a network security situation value, and display the results of the network security situation assessment in intuitive forms such as charts, reports, and maps to help security administrators quickly understand the security status of the network.

[0016] Further preferably, in Step 5, according to the results of the network security situation assessment, the system automatically triggers corresponding security policies and measures, such as blocking malicious IP addresses, restricting network traffic, isolating infected devices, etc., provides decision-making suggestions and references for security administrators, and helps them formulate reasonable network security policies and emergency response plans.

[0017] An artificial intelligence-based network security situation awareness system, comprising the following modules:

[0018] Data acquisition module: Collect network traffic, system logs, and threat intelligence data through different sub-modules respectively;

[0019] Data preprocessing module: Clean, normalize, and extract features from the collected data to improve data quality;

[0020] Artificial intelligence analysis module: Use algorithms for anomaly detection, threat classification, and situation prediction to deeply mine security information in the data;

[0021] Situation assessment and visualization module: Assess the network security situation and visually display the results to enhance the intuitiveness of situation awareness;

[0022] Response and decision support module: Automatically respond to security events and provide decision-making references for administrators to formulate strategies;

[0023] Database module: Store various types of data and model parameters to provide data support for system operation and analysis.

[0024] Further preferably, the data acquisition module includes:

[0025] Network traffic acquisition sub-module: Responsible for deploying network probes, collecting network traffic data in real time, and transmitting the data to the data preprocessing module;

[0026] System log acquisition sub-module: Collect system log data from various network devices and security devices through log collection tools and send it to the data preprocessing module;

[0027] Threat intelligence acquisition sub-module: Interface with third-party threat intelligence platforms, regularly obtain the latest threat intelligence data, and store it in the local database;

[0028] The data preprocessing module includes:

[0029] Data cleaning sub-module: Clean the collected data to remove noise, duplicate data, and invalid data;

[0030] Data normalization sub-module: Normalize data from different sources and in different formats to make it have a unified format and standard;

[0031] Data feature extraction sub-module: Extract representative features from the preprocessed data to provide data support for subsequent artificial intelligence modeling and analysis.

[0032] Further preferably, the artificial intelligence analysis module includes:

[0033] Anomaly Detection Sub-module: Uses machine learning algorithms to model network traffic and system log data, and identify abnormal behavior patterns;

[0034] Threat Classification Sub-module: Utilizes deep learning algorithms to classify the collected threat intelligence data and abnormal events, and determine the type and severity of threats;

[0035] Situation Prediction Sub-module: Based on time series analysis and machine learning algorithms, predicts the development trend of the network security situation;

[0036] The said Situation Assessment and Visualization Module includes:

[0037] Situation Assessment Sub-module: According to the results of anomaly detection, threat classification and situation prediction, comprehensively consider factors such as the importance of network assets, the severity and occurrence probability of threats, and quantitatively evaluate the network security situation;

[0038] Visualization Display Sub-module: Displays the results of network security situation assessment in intuitive forms such as charts, reports and maps, to help security administrators quickly understand the security status of the network.

[0039] Further preferably, the said Response and Decision Support Module includes:

[0040] Automated Response Sub-module: According to the results of network security situation assessment, the system automatically triggers corresponding security policies and measures to achieve a rapid response to network security events;

[0041] Decision Support Sub-module: Provides decision-making suggestions and references for security administrators to help them formulate reasonable network security policies and emergency response plans.

[0042] Due to the adoption of the above technical solutions in the embodiments of the present invention, it has the following advantages:

[0043] First, the network security situation awareness system based on artificial intelligence of the present invention can utilize machine learning and deep learning algorithms to deeply analyze and mine massive network security data. Compared with traditional rule-based detection methods, it can automatically learn and identify unknown attack patterns and abnormal behaviors, greatly improving the detection ability for new threats and advanced persistent threats.

[0044] Second, based on time series analysis and machine learning algorithms, predict the development trend of the network security situation. By analyzing historical data and the current security status, predict the possible types of attacks, attack times, and attack targets in the future, providing an opportunity for security administrators to respond in advance. Moreover, it can quantitatively evaluate the network security situation and display the evaluation results in an intuitive visual way. According to the results of the network security situation evaluation, automatically trigger corresponding security policies and measures to achieve a rapid response to network security incidents.

[0045] The above summary is only for the purpose of the specification and is not intended to be limiting in any way. In addition to the illustrative aspects, embodiments, and features described above, further aspects, embodiments, and features of the present invention will become readily apparent by reference to the drawings and the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] To more clearly illustrate the technical solutions in the embodiments of the present application or in the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0047] Figure 1 is the method flowchart of the present invention;

[0048] Figure 2 is the system module diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0049] In the following, only some exemplary embodiments are simply described. As those skilled in the art can recognize, the described embodiments can be modified in various different ways without departing from the spirit or scope of the present invention. Therefore, the drawings and the description are considered to be exemplary in nature rather than restrictive.

[0050] The embodiments of the present invention will be described in detail below with reference to the drawings.

[0051] As Figure 1-2 shown, the embodiments of the present invention provide a network security situation awareness method based on artificial intelligence, including the following steps:

[0052] Step 1: Data collection, collect multi-source data such as network traffic, system logs, and threat intelligence to provide basic materials for subsequent analysis;

[0053] Step 2: Data preprocessing, clean, normalize, and extract features to make the data more regular and effective, facilitating subsequent processing by the artificial intelligence model;

[0054] Step 3: Artificial intelligence modeling and analysis, using machine learning and deep learning algorithms for anomaly detection, threat classification, and situation prediction to discover potential security threats and trends;

[0055] Step 4: Situation assessment and visualization, quantitatively assessing the network security situation and presenting it in an intuitive form to help administrators quickly understand the security status;

[0056] Step 5: Response and decision support, automatically triggering security policies to address threats and providing decision-making suggestions for administrators to ensure network security.

[0057] In one embodiment, in Step 1, network probes are deployed at key network nodes to collect traffic information in the network in real time, including source IP, destination IP, port number, traffic volume, transmission protocol, etc. System logs are collected from network devices and security devices such as servers, firewalls, intrusion detection systems (IDS), and intrusion prevention systems (IPS). By collaborating with third-party threat intelligence platforms, the latest threat intelligence globally is obtained, including malicious IP addresses, malware characteristics, vulnerability information, etc.

[0058] In one embodiment, in Step 2, noise, duplicate data, and invalid data in the collected data are removed. Data from different sources and in different formats are normalized to have a unified format and standard. Representative features are extracted from the preprocessed data for subsequent analysis and modeling.

[0059] In one embodiment, in Step 3, machine learning algorithms are used to model network traffic and system log data to identify abnormal behavior patterns. By training an autoencoder model, normal network traffic data is encoded and decoded. When the input traffic data has a large difference from the reconstruction result of the model, it is determined as abnormal traffic. Deep learning algorithms are used to classify the collected threat intelligence data and abnormal events to determine the type and severity of threats. Based on time series analysis and machine learning algorithms, the development trend of the network security situation is predicted.

[0060] In one embodiment, in Step 4, according to the results of anomaly detection, threat classification, and situation prediction, factors such as the importance of network assets, the severity of threats, and the occurrence probability are comprehensively considered to quantitatively assess the network security situation, generate a network security situation value, and present the results of the network security situation assessment in intuitive forms such as charts, reports, and maps to help security administrators quickly understand the security status of the network.

[0061] In one embodiment, in step five, according to the results of network security situation assessment, the system automatically triggers corresponding security policies and measures, such as blocking malicious IP addresses, restricting network traffic, isolating infected devices, etc., providing decision-making suggestions and references for security administrators to help them formulate reasonable network security policies and emergency response plans.

[0062] An artificial intelligence-based network security situation awareness system includes the following modules:

[0063] Data collection module: Collect network traffic, system logs, and threat intelligence data through different sub-modules respectively;

[0064] Data preprocessing module: Clean, normalize, and extract features from the collected data to improve data quality;

[0065] Artificial intelligence analysis module: Use algorithms for anomaly detection, threat classification, and situation prediction to deeply mine security information in the data;

[0066] Situation assessment and visualization module: Evaluate the network security situation and visually display the results to enhance the intuitiveness of situation awareness;

[0067] Response and decision support module: Automatically respond to security events and provide decision-making references for administrators to formulate policies;

[0068] Database module: Store various types of data and model parameters to provide data support for system operation and analysis.

[0069] In one embodiment, the data collection module includes:

[0070] Network traffic collection sub-module: Responsible for deploying network probes to collect network traffic data in real time and transmit the data to the data preprocessing module;

[0071] System log collection sub-module: Collect system log data from various network devices and security devices through log collection tools and send it to the data preprocessing module;

[0072] Threat intelligence collection sub-module: Interface with third-party threat intelligence platforms to regularly obtain the latest threat intelligence data and store it in the local database;

[0073] The data preprocessing module includes:

[0074] Data cleaning sub-module: Clean the collected data to remove noise, duplicate data, and invalid data;

[0075] Data normalization sub-module: Normalize data from different sources and in different formats to make it have a unified format and standard;

[0076] Data Feature Extraction Sub-module: Extract representative features from the pre-processed data to provide data support for subsequent artificial intelligence modeling and analysis.

[0077] In one embodiment, the artificial intelligence analysis module includes:

[0078] Anomaly Detection Sub-module: Use machine learning algorithms to model network traffic and system log data to identify abnormal behavior patterns;

[0079] Threat Classification Sub-module: Use deep learning algorithms to classify the collected threat intelligence data and abnormal events to determine the type and severity of threats;

[0080] Situation Prediction Sub-module: Based on time series analysis and machine learning algorithms, predict the development trend of network security situations;

[0081] The Situation Assessment and Visualization Module includes:

[0082] Situation Assessment Sub-module: According to the results of anomaly detection, threat classification, and situation prediction, comprehensively consider factors such as the importance of network assets, the severity of threats, and the occurrence probability, and quantitatively evaluate the network security situation;

[0083] Visualization Display Sub-module: Display the results of network security situation assessment in the form of intuitive charts, reports, maps, etc. to help security administrators quickly understand the security status of the network.

[0084] In one embodiment, the Response and Decision Support Module includes:

[0085] Automated Response Sub-module: According to the results of network security situation assessment, the system automatically triggers corresponding security policies and measures to achieve a rapid response to network security events;

[0086] Decision Support Sub-module: Provide decision-making suggestions and references for security administrators to help them formulate reasonable network security policies and emergency response plans.

[0087] As described above, it is only the specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of various changes or substitutions, and these should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A network security situation awareness method based on artificial intelligence, characterized by: The following steps are involved: Step 1: Data collection: Collect multi-source data such as network traffic, system logs, and threat intelligence to provide basic materials for subsequent analysis; Step 2: Data preprocessing, cleaning, normalization and feature extraction to make the data more regular and effective, which is convenient for subsequent artificial intelligence model processing; Step 3: AI modeling and analysis, using machine learning and deep learning algorithms to detect anomalies, classify threats, and predict trends to discover potential security threats and trends; Step 4: Situation assessment and visualization: quantitatively assess the network security situation and display it in an intuitive form to help administrators quickly understand the security status; Step 5: Response and decision support: automatically trigger security policies to respond to threats, provide decision-making suggestions to administrators, and ensure network security.

2. The network security situation awareness method based on artificial intelligence according to claim 1 is characterized by: In step one, network probes are deployed at key network nodes to collect real-time traffic information in the network, including source IP, destination IP, port number, traffic size, transmission protocol, etc. System logs are collected from network devices and security devices such as servers, firewalls, intrusion detection systems (IDS), intrusion prevention systems (IPS), etc. By cooperating with third-party threat intelligence platforms, the latest threat intelligence worldwide is obtained, including malicious IP addresses, malware features, vulnerability information, etc.

3. The network security situation awareness method based on artificial intelligence according to claim 1 is characterized by: In the step 2, noise, duplicate data and invalid data are removed from the collected data, data from different sources and in different formats are normalized to have a unified format and standard, and representative features are extracted from the preprocessed data for subsequent analysis and modeling.

4. The network security situation awareness method based on artificial intelligence according to claim 1 is characterized in that: In the step three, a machine learning algorithm is used to model the network traffic and system log data, and abnormal behavior patterns are identified. By training the autoencoder model, normal network traffic data is encoded and decoded. When the input traffic data is significantly different from the reconstruction result of the model, it is determined to be abnormal traffic. The collected threat intelligence data and abnormal events are classified using a deep learning algorithm to determine the type and severity of the threat. Based on time series analysis and machine learning algorithms, the development trend of the network security situation is predicted.

5. The network security situation awareness method based on artificial intelligence according to claim 1 is characterized by: In step 4, based on the results of anomaly detection, threat classification and situation prediction, the network security situation is quantitatively evaluated and a network security situation value is generated, by comprehensively considering factors such as the importance of network assets, the severity of threats and the probability of occurrence. The results of the network security situation evaluation are presented in the form of intuitive charts, reports and maps, etc., to help security administrators quickly understand the security status of the network.

6. The network security situation awareness method based on artificial intelligence according to claim 1 is characterized by: In step five, based on the results of the network security situation assessment, the system automatically triggers corresponding security policies and measures, such as blocking malicious IP addresses, limiting network traffic, isolating infected devices, etc., to provide decision-making suggestions and references for security administrators, helping them to formulate reasonable network security strategies and emergency response plans.

7. An artificial intelligence-based network security situation awareness system, supporting an artificial intelligence-based network security situation awareness method as described in any one of claims 1 to 6, characterized in that: Includes the following modules: Data collection module: collects network traffic, system logs and threat intelligence data through different sub-modules; Data preprocessing module: cleans, normalizes and extracts features of collected data to improve data quality; Artificial intelligence analysis module: uses algorithms to detect anomalies, classify threats, and predict trends, and deeply mines security information in data; Situation Assessment and Visualization Module: Assess network security situation and visualize the results to enhance the intuitiveness of situation awareness; Response and decision support module: automatically respond to security incidents and provide decision references for administrators to formulate policies; Database module: stores various data and model parameters to provide data support for system operation and analysis.

8. The network security situation awareness system based on artificial intelligence according to claim 7 is characterized by: The data acquisition module comprises: Network traffic collection submodule: responsible for deploying network probes, collecting network traffic data in real time, and transmitting the data to the data preprocessing module; System log collection submodule: collects system log data from various network devices and security devices through log collection tools, and sends it to the data preprocessing module; Threat intelligence collection submodule: connects with the third-party threat intelligence platform to regularly obtain the latest threat intelligence data and store it in the local database; The data preprocessing module comprises: Data cleaning submodule: cleans the collected data to remove noise, duplicate data and invalid data; Data normalization submodule: normalizes data from different sources and formats to make them have a unified format and standard; Data feature extraction submodule: extracts representative features from the preprocessed data to provide data support for subsequent artificial intelligence modeling and analysis.

9. The network security situation awareness system based on artificial intelligence according to claim 7 is characterized by: The artificial intelligence analysis module includes: Anomaly detection submodule: Use machine learning algorithms to model network traffic and system log data to identify abnormal behavior patterns; Threat classification submodule: Use deep learning algorithms to classify the collected threat intelligence data and abnormal events to determine the type and severity of the threat; Situation prediction submodule: Based on time series analysis and machine learning algorithms, it predicts the development trend of network security situation; The situation assessment and visualization module includes: Situation Assessment Submodule: Based on the results of anomaly detection, threat classification and situation prediction, the importance of network assets, severity of threats and probability of occurrence are comprehensively considered to quantitatively assess the network security situation; Visual display submodule: Displays the results of network security situation assessment in the form of intuitive charts, reports, maps, etc., to help security administrators quickly understand the security status of the network.

10. The network security situation awareness system based on artificial intelligence according to claim 7 is characterized by: The response and decision support module includes: Automatic response submodule: Based on the results of network security situation assessment, the system automatically triggers corresponding security policies and measures to achieve rapid response to network security incidents; Decision support submodule: Provides decision-making suggestions and references for security administrators to help them formulate reasonable network security strategies and emergency response plans.