Network security situation awareness method and system based on big data analysis

Through the network security situation awareness method based on big data analysis, using technologies such as self-attention time convolution networks and support vector machines to collect and analyze network data in real time, generate network status tags and evaluate security levels, solving the problem that traditional network security defense strategies are difficult to cope with complex network attacks, and achieving intelligent perception and effective response to network security situations.

CN120223378AInactive Publication Date: 2025-06-27SHANGHAI FOUR-LEAF CRUCI INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510322415.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-19
Publication Date
2025-06-27
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional network security defense strategies are difficult to effectively resist complex and diverse cyber attack methods, and have shortcomings in real-time monitoring, dynamic analysis and rapid response to network problems, which can easily lead to user data leakage and service interruption.

Method used

The network security situation awareness method based on big data analysis is adopted, and the original network data is collected in real time through network traffic monitoring probes and deep packet detection equipment, and the network traffic analysis model and protocol analysis model are trained using self-attention time convolution networks and support vector machines to generate network status tags and evaluate network security levels, output situation awareness instructions and generate security situation reports.

Benefits of technology

It realizes intelligent perception, evaluation and response to the network security situation, improves network security protection effect, ensures the safe and stable operation of broadband services, and provides effective decision-making support for security managers.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The invention relates to a network security situation awareness method and system based on big data analysis, and belongs to the technical field of network security. The method comprises the steps of collecting original network data which comprises original network data flow and original protocol data in broadband service, training a network security situation awareness model based on a preset network security situation awareness standard set, the network security situation awareness model comprises a network flow analysis model and a protocol analysis model, generating a network state label through the network security situation awareness model, and evaluating a network security level through a rating rule according to the network state label. And outputting a network security situation awareness instruction through an instruction control script according to the network security level, generating a network security situation report through an automatic reporting tool according to the original network data, the network state label and the network security level, and displaying the network security situation report through a data visualization tool.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention belongs to the field of network security technology, and particularly relates to a network security situation awareness method and system based on big data analysis. With the rapid development of the Internet, network security issues have become increasingly prominent, especially in broadband services involving large-scale data transmission and processing. Traditional network security defense strategies are often limited by fixed rules and preset feature libraries, making it difficult to effectively resist increasingly complex and diverse network attack means, and their protection effects are often limited. In addition, traditional network security defense strategies have deficiencies in aspects such as real-time monitoring, dynamic analysis, and rapid response to network problems, and situations such as user data leakage and service interruption are likely to occur.

[0002] To solve the above problems existing in the prior art, the present invention provides a network security situation awareness method and system based on big data analysis. Network status labels are generated through a network security situation awareness model according to the originally collected network data in real time. The network security level is evaluated according to the network status labels, and network security situation awareness instructions are output according to the network security level, realizing intelligent perception, evaluation, and response to the network security situation, thereby effectively ensuring the safe and stable operation of broadband services and providing a safe and stable network environment for broadband users. A network security situation report is generated through an automated reporting tool according to the original network data, the network status labels, and the network security level and displayed through a data visualization tool, facilitating security management personnel to quickly view and analyze the network security situation.

[0003] The object of the present invention can be achieved through the following technical solutions: A network security situation awareness method based on big data analysis,

[0004] including:

[0005] S1: Real-time collect original network data through a network traffic monitoring probe and a deep packet inspection device, and the original network data includes the original network data stream and original protocol data in broadband services;

[0006] S2: Preset a network security situation awareness standard set, train a network security situation awareness model according to the network security situation awareness standard set. The network security situation awareness standard set includes a network traffic standard set and a protocol analysis standard set. The network security situation awareness model includes a network traffic analysis model and a protocol analysis model. Train the network traffic analysis model through a self-attention time convolutional network and a support vector machine according to the network traffic standard set, and train the protocol analysis model through a TF-IDF algorithm and a support vector machine according to the protocol analysis standard set;

[0007] S3: Obtain network data through preprocessing based on the original network data, generate network status labels through the network security situation awareness model based on the network data, where the network status labels include network traffic status labels and protocol status labels, and evaluate the network security level according to the network status labels through a rating rule;

[0008] S4: Output network security situation awareness instructions through an instruction control script according to the network security level, where the network security situation awareness instructions include firewall configuration instructions and intrusion detection system response instructions;

[0009] S5: Obtain a network security situation report through an automated reporting tool according to the original network data, the network status labels, and the network security level, and display the network security situation report through a data visualization tool.

[0010] Preferably, the specific steps of training the network traffic analysis model in step S2 include:

[0011] S2-11: Obtain historical network traffic data, obtain historical network traffic standard data through preprocessing based on the historical network traffic data, obtain the network traffic standard set according to the historical network traffic standard data, where the network traffic standard set includes normal traffic and abnormal traffic, and divide the network traffic standard set into a network traffic training set and a network traffic test set;

[0012] S2-12: Construct a self-attention time convolutional network by adding a self-attention mechanism to a self-attention residual block, where the self-attention residual block is a residual block in a time convolutional network;

[0013] S2-13: Extract network traffic feature vectors through the self-attention time convolutional network according to the network traffic standard set;

[0014] S2-14: Select network traffic key feature vectors through the PCA algorithm according to the network traffic feature vector set;

[0015] S2-15: Identify the normal traffic and the abnormal traffic through training a support vector machine according to the network traffic key feature vector set;

[0016] S2-16: Train an initial network traffic analysis model through the self-attention time convolutional network and the support vector machine according to the network traffic training set, test the initial network traffic analysis model according to the network traffic test set to obtain an initial network traffic analysis model test result, and calculate an initial network traffic analysis model comprehensive score through an initial network traffic analysis model evaluation index;

[0017] S2-17: The network traffic analysis model is obtained by determining through the comprehensive score of the initial network traffic analysis model reaching or exceeding the threshold. When the comprehensive score of the network traffic analysis model reaches or exceeds the set threshold of 0.9, the network traffic analysis model is obtained.

[0018] Preferably, the step S2-13 specifically includes:

[0019] S2-131: Calculate the query vector, key vector, and value vector through the weight matrix according to the historical network traffic standard data;

[0020] S2-132: Calculate the feature similarity through the attention weight according to the historical network traffic standard data, and the feature similarity is the feature similarity of each element in the historical network traffic standard data;

[0021] S2-133: Calculate the network traffic feature vector set through the weighted value vector according to the historical network traffic standard data.

[0022] Preferably, the step of training the protocol analysis model in S2 specifically includes:

[0023] S2-21: Obtain the historical protocol interaction text data, preprocess it according to the historical protocol interaction text data to obtain the historical protocol interaction text standard data, obtain the protocol analysis standard set according to the historical protocol interaction text standard data, the protocol analysis standard set includes normal protocol interaction texts and abnormal protocol interaction texts, and divide the protocol analysis standard set into a protocol analysis training set and a protocol analysis test set;

[0024] S2-22: Extract features through the TF-IDF algorithm according to the protocol analysis standard set to obtain the protocol data feature vector set;

[0025] S2-23: Select features through the PCA algorithm according to the protocol data feature vector set to obtain the protocol data key feature vector set;

[0026] S2-24: Identify the normal protocol interaction texts and the abnormal protocol interaction texts through training the support vector machine according to the protocol analysis key feature vectors;

[0027] S2-25: Train the initial protocol analysis model through the TF-IDF algorithm and the support vector machine according to the protocol analysis training set, test the initial protocol analysis model according to the protocol analysis test set to obtain the test result of the initial protocol analysis model, and calculate the comprehensive score of the initial protocol analysis model through the evaluation index of the initial protocol analysis model;

[0028] S2-26: Determine the protocol analysis model based on the comprehensive score of the initial protocol analysis model passing the threshold: When the comprehensive score of the initial protocol analysis model reaches or exceeds the set threshold of 0.9, obtain the protocol analysis model.

[0029] Preferably, the step S2-22 specifically includes:

[0030] S2-221: Calculate the term frequency based on the historical protocol interaction text standard data through the total number of protocol data words and the number of protocol term occurrences;

[0031] S2-222: Calculate the inverse document frequency based on the historical protocol interaction text standard data through the total number of protocol documents and the number of documents containing the term; S2-223: Calculate the protocol data feature vector set based on the historical protocol interaction text standard data through the feature term weights;

[0032] Preferably, the step S3 specifically includes:

[0033] S3-1: Obtain network data by preprocessing the original network data, and the preprocessing includes data cleaning, data format standardization, and data normalization;

[0034] S3-2: Output the network traffic status label based on the network data through the network traffic analysis model;

[0035] S3-3: Output the protocol status label based on the network data through the protocol analysis model;

[0036] S3-4: Evaluate the network security level based on the network traffic status label and the protocol status label through the rating rule; When the network traffic status label is normal and the protocol status label is normal, the network security level is the third-level network security level; When the network traffic status label is normal and the protocol status label is abnormal, the network security level is the first-level network security level; When the network traffic status label is abnormal and the protocol status label is normal, the network security level is the second-level network security level; When the network traffic status label is abnormal and the protocol status label is abnormal, the network security level is the zero-level network security level.

[0037] Preferably, the instruction control script in the step S4 specifically includes:

[0038] When the network security level is the zero - level network security level, both a firewall configuration instruction and an intrusion detection system response instruction are output; when the network security level is the first - level network security level, an intrusion detection system response instruction is output; when the network security level is the second - level network security level, a firewall configuration instruction is output; when the network security level is the third - level network security level, no instruction is output.

[0039] A network security situation awareness system based on big data analysis, including a data acquisition module, a data pre - processing module, a network security situation awareness module, an automated response module, and a reporting and visualization module. The data acquisition module includes a network traffic monitoring probe and a deep packet inspection device, which are used to collect raw network data in real time. The raw network data includes the raw network data stream and raw protocol data in broadband services. The data pre - processing module is used to perform data cleaning, data format standardization, and data normalization on the raw network data to obtain network data. The network security situation awareness module trains a network security situation awareness model based on a preset network security situation awareness standard set, generates a network traffic status label and a protocol status label according to the network data through the network security situation awareness model, and evaluates the network security level according to the network traffic status label and the protocol status label through a rating rule. The automated response module outputs a situation awareness instruction through an instruction control script according to the network security level. The situation awareness instruction includes a firewall configuration instruction and an intrusion detection system response instruction. The reporting and visualization module obtains a network security situation report through an automated reporting tool according to the raw network data, the network status label, and the network security level, and the network security situation report is displayed through a data visualization tool.

[0040] An electronic device includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the above - mentioned network security situation awareness method based on big data analysis. A storage medium containing computer - executable instructions is used to execute the above - mentioned network security situation awareness method based on big data analysis when executed by a computer processor.

[0041] The beneficial effects of the present invention are as follows:

[0042] (1) Through the network traffic monitoring probe and the deep packet inspection device, the raw network data stream and raw protocol data in broadband services are collected in real time, which can comprehensively judge the network security status. Training a network security situation awareness model based on a preset network security situation awareness standard set to realize network security situation awareness is convenient for timely and accurately judging the network security status and taking response strategies to maintain the network security environment.

[0043] (2) By adding the self-attention mechanism to the self-attention residual block to construct a self-attention temporal convolutional network, it is possible to focus on the important information of network traffic data and more effectively process the internal relationships in network traffic data;

[0044] (3) By using the TF-IDF algorithm to extract the features of protocol interaction text data, it is possible to identify text patterns different from normal protocol interactions, thereby providing support for network security situation awareness;

[0045] (4) According to the network traffic feature vector set and the protocol data feature vector set, through the PCA algorithm for feature selection to obtain the network traffic key feature vector set and the protocol data key feature vector set, it is possible to reduce the feature dimension and improve the efficiency of the network traffic analysis model and the protocol analysis model;

[0046] (5) By training a support vector machine according to the network traffic key feature vector set and the protocol data key feature vector set, it is possible to improve the accuracy and efficiency of network traffic data detection and protocol interaction text data detection;

[0047] (6) By generating network state labels through the network security situation awareness model and evaluating the network security level through the rating rules, it is possible to monitor the network security status in real time; according to the network security level, output network security situation awareness instructions through the instruction control script, it is possible to maintain the network environment security in a timely manner;

[0048] (7) By using an automated reporting tool to generate a network security situation report and intuitively display the network security situation through a data visualization tool, it is convenient for security management personnel to view and analyze the network security situation, providing effective decision-making support for security management personnel.

[0049] For the convenience of those skilled in the art to understand, the present invention will be further described below.

[0050] To further elaborate on the technical means and effects adopted by the present invention to achieve the predetermined invention purpose, the following will be described in detail with reference to the preferred embodiments regarding the specific implementation manners, structures, features, and effects of the present invention.

[0051] A network security situation awareness method based on big data analysis, comprising:

[0052] S1: Real-time collect raw network data through network traffic monitoring probes and deep packet inspection devices, and the raw network data includes raw network data streams and raw protocol data in broadband services;

[0053] S2: Train a network security situation awareness model based on a preset network security situation awareness standard set. The network security situation awareness standard set includes a network traffic standard set and a protocol analysis standard set. The network security situation awareness model includes a network traffic analysis model and a protocol analysis model. Train the network traffic analysis model according to the network traffic standard set through a self-attention time convolutional network and a support vector machine, and train the protocol analysis model according to the protocol analysis standard set through the TF-IDF algorithm and a support vector machine;

[0054] S3: Preprocess the original network data to obtain network data. Generate network status labels according to the network data through the network security situation awareness model. The network status labels include network traffic status labels and protocol status labels. Evaluate the network security level according to the network status labels through a rating rule;

[0055] S4: Output network security situation awareness instructions according to the network security level through an instruction control script. The network security situation awareness instructions include firewall configuration instructions and intrusion detection system response instructions;

[0056] S5: Obtain a network security situation report through an automated reporting tool according to the original network data, the network status labels, and the network security level. The network security situation report is displayed through a data visualization tool.

[0057] In step S1, real-time collect network data streams and protocol data in broadband services through network traffic monitoring probes and deep packet inspection devices, which is convenient for network security situation awareness, enables the system to respond to network abnormal behaviors in a timely manner, and effectively maintains a stable and secure network environment.

[0058] In step S2, train a network security situation awareness model based on a preset network security situation awareness standard set. The network security situation awareness standard set includes a network traffic standard set and a protocol analysis standard set. The network security situation awareness model includes a network traffic analysis model and a protocol analysis model; In this embodiment, train the network traffic analysis model according to the network traffic standard set through a self-attention time convolutional network and a support vector machine, which is specifically implemented through the following steps:

[0059] S2-11: Obtain historical network traffic data. The historical network traffic data includes packet size and transmission rate. Preprocess the historical network traffic data to obtain historical network traffic standard data. The preprocessing includes data cleaning, data format standardization, and data normalization. Obtain the network traffic standard set according to the historical network traffic standard data. The network traffic standard set includes normal traffic and abnormal traffic. Divide the network traffic standard set into a network traffic training set and a network traffic test set;

[0060] S2-12: Construct a self-attention temporal convolutional network by adding a self-attention mechanism to a self-attention residual block, where the self-attention residual block is a residual block in a temporal convolutional network;

[0061] S2-13: Extract network traffic feature vectors through the self-attention temporal convolutional network according to the network traffic standard set, which specifically includes the following steps:

[0062] S2-131: Calculate query vectors, key vectors, and value vectors through a weight matrix according to the historical network traffic standard data. The query vector is the information correlation between the element xi in the historical network traffic standard data and other elements in the historical network traffic standard data. The key vector is the index of the element xi in the historical network traffic standard data. The value vector is the matching value of the query vector and the key vector. The calculation formula is: qi = Wq·xi ki = Wk·xi vi = Wv·xi where xi is the i-th element in the historical network traffic standard data, qi is the query vector of the i-th element in the historical network traffic standard data, ki is the key vector of the i-th element in the historical network traffic standard data, vi is the value vector of the i-th element in the historical network traffic standard data, Wq is the weight matrix of the query vector, Wk is the weight matrix of the key vector, and Wv is the weight matrix of the value vector; S2-132: Calculate feature similarity through attention weights according to the historical network traffic standard data. The feature similarity is the feature similarity of each element in the historical network traffic standard data. The calculation formula is: where dk is the dimension of the key vector, qi is the query vector of the i-th element in the historical network traffic standard data, is the transpose of the key vector of the j-th element in the historical network traffic standard data, and αij is the similarity between the query vector of the i-th element in the historical network traffic standard data and the key vector of the j-th element in the historical network traffic standard data; S2-133: Calculate the network traffic feature vector set through weighted value vectors according to the historical network traffic standard data. The weighted value vector is the information at all positions in the historical network traffic standard data. The calculation formula is: where αij is the similarity between the query vector of the i-th element in the historical network traffic standard data and the key vector of the j-th element in the historical network traffic standard data, vi is the value vector of the j-th element in the historical network traffic standard data, and N is the number of elements in the historical network traffic standard data;

[0063] S2-14: Select network traffic key feature vectors through the PCA algorithm according to the network traffic feature vector set;

[0064] S2-15: Identify the normal traffic and the abnormal traffic by training a support vector machine based on the set of key network traffic feature vectors;

[0065] S2-16: Train an initial network traffic analysis model through the self-attention time convolutional network and the support vector machine based on the network traffic training set, test the initial network traffic analysis model according to the network traffic test set to obtain the test results of the initial network traffic analysis model, and calculate the comprehensive score of the initial network traffic analysis model through the evaluation indexes of the initial network traffic analysis model. The evaluation indexes of the initial network traffic analysis model include the accuracy of the initial network traffic analysis model, the recall rate of the initial network traffic analysis model, and the F1 value of the initial network traffic analysis model. The calculation formula is: Sc1 = a1 * ACC1 + b1 * R1 + c1 * F11, where ACC1 is the accuracy of the initial network traffic analysis model, R1 is the recall rate of the initial network traffic analysis model, F11 is the F1 value of the initial network traffic analysis model, TP1 is the number of samples that the initial network traffic analysis model correctly predicts as abnormal traffic for samples that are actually abnormal traffic, FP1 is the number of samples that the initial network traffic analysis model wrongly predicts as abnormal traffic for samples that are actually normal traffic, TN1 is the number of samples that the initial network traffic analysis model correctly predicts as normal traffic for samples that are actually normal traffic, FN1 is the number of samples that the initial network traffic analysis model wrongly predicts as normal traffic for samples that are actually abnormal traffic, a1 is the weight of the accuracy of the initial network traffic analysis model, b1 is the weight of the recall rate of the initial network traffic analysis model, c1 is the weight of the F1 value of the initial network traffic analysis model, and Sc1 is the comprehensive score of the initial network traffic analysis model;

[0066] S2-17: Obtain the network traffic analysis model through threshold determination according to the comprehensive score of the initial network traffic analysis model; when the comprehensive score of the initial network traffic analysis model reaches or exceeds the set threshold of 0.9, obtain the network traffic analysis model.

[0067] In this embodiment, train the protocol analysis model through the TF-IDF algorithm and the support vector machine according to the protocol analysis standard set, which is specifically implemented through the following steps:

[0068] S2-21: Obtain historical protocol interaction text data, preprocess the historical protocol interaction text data to obtain historical protocol interaction text standard data. The preprocessing includes data cleaning, data format standardization, and data normalization. Obtain the protocol analysis standard set according to the historical protocol interaction text standard data. The protocol analysis standard set includes normal protocol interaction text and abnormal protocol interaction text. Divide the protocol analysis standard set into a protocol analysis training set and a protocol analysis test set;

[0069] S2-22: Perform feature extraction on the protocol analysis standard set through the TF-IDF algorithm to obtain a protocol data feature vector set, which specifically includes the following steps:

[0070] S2-221: Calculate the term frequency according to the historical protocol interaction text standard data through the total number of protocol data words and the number of protocol term occurrences. The number of protocol term occurrences is the number of times a protocol term in the historical protocol interaction text standard data appears in a single protocol document of the historical protocol interaction text standard data. The total number of protocol data words is the total number of words in a single protocol document of the historical protocol interaction text standard data. The term frequency is the frequency of a protocol term in the historical protocol interaction text standard data appearing in a single protocol document of the historical protocol interaction text standard data. The calculation formula is: TF(t) = S / n, where TF(t) is the term frequency, t is the protocol term in the historical protocol interaction text standard data, S is the number of protocol term occurrences, and n is the total number of protocol data words;

[0071] S2-222: Calculate the inverse document frequency based on the total number of protocol documents and the number of documents containing the term in the historical protocol interaction text standard data. The number of documents containing the term is the number of documents in the historical protocol interaction text standard data that contain the protocol term. The total number of protocol documents is the total number of documents in the historical protocol interaction text standard data. The inverse document frequency is the importance of the protocol term in the historical protocol interaction text standard data for distinguishing different protocol document categories. The calculation formula is: IDF(t) = log(p / w), where IDF(t) is the inverse document frequency, p is the total number of protocol documents, w is the number of documents containing the term, and t is the protocol term in the historical protocol interaction text standard data; S2-223: Obtain the protocol data feature vector set by calculating the feature term weights based on the historical protocol interaction text standard data. The feature term weight is the importance of the protocol term in the historical protocol interaction text standard data for a single protocol document. The calculation formula is: TF-IDF(t) = TF(t) * IDF(t), where TF-IDF(t) is the feature term weight, TF(t) is the term frequency, and IDF(t) is the inverse document frequency;

[0072] S2-23: Perform feature selection on the protocol data feature vector set through the PCA algorithm to obtain the protocol data key feature vector set;

[0073] S2-24: Identify the normal protocol interaction text and the abnormal protocol interaction text by training a support vector machine based on the protocol analysis key feature vector;

[0074] S2-25: Analyze the training set according to the protocol, train the initial protocol analysis model through the TF-IDF algorithm and the support vector machine, test the initial protocol analysis model according to the protocol analysis test set to obtain the test result of the initial protocol analysis model, and calculate the comprehensive score of the initial protocol analysis model through the evaluation index of the initial protocol analysis model. The evaluation index of the initial protocol analysis model includes the accuracy rate of the initial protocol analysis model, the recall rate of the initial protocol analysis model, and the F1 value of the initial protocol analysis model. The calculation formula is: Sc2 = a2 * ACC2 + b2 * R2 + c2 * F12, where ACC2 is the accuracy rate of the initial protocol analysis model, R2 is the recall rate of the initial protocol analysis model, F12 is the F1 value of the initial protocol analysis model, TP2 is the number of samples that the initial protocol analysis model correctly predicts the samples of abnormal protocol interaction text as abnormal protocol interaction text, FP2 is the number of samples that the initial protocol analysis model wrongly predicts the samples of normal protocol interaction text as abnormal protocol interaction text, TN2 is the number of samples that the initial protocol analysis model correctly predicts the samples of normal protocol interaction text as normal protocol interaction text, FN2 is the number of samples that the initial protocol analysis model wrongly predicts the samples of abnormal protocol interaction text as normal protocol interaction text, b2 is the recall rate weight of the initial protocol analysis model, c2 is the F1 value weight of the initial protocol analysis model, and Sc2 is the comprehensive score of the initial protocol analysis model;

[0075] S2-26: Obtain the protocol analysis model through threshold determination according to the comprehensive score of the initial protocol analysis model; when the comprehensive score of the initial protocol analysis model reaches or exceeds the set threshold of 0.9, obtain the protocol analysis model.

[0076] In step S3, preprocess the original network data to obtain network data, generate network status labels through the network security situation awareness model according to the network data. The network status labels include network traffic status labels and protocol status labels, and evaluate the network security level according to the network status labels. The specific implementation steps are as follows:

[0077] S3-1: Preprocess the original network data to obtain network data. The preprocessing includes data cleaning, data format standardization, and data normalization;

[0078] S3-2: Output the network traffic status label according to the network data through the network traffic analysis model;

[0079] S3-3: Output the protocol status label according to the network data through the protocol analysis model;

[0080] S3-4: Evaluate the network security level according to the network traffic status label and the protocol status label through a rating rule; when the network traffic status label is normal and the protocol status label is normal, the network security level is a level-three network security level; when the network traffic status label is normal and the protocol status label is abnormal, the network security level is a level-one network security level; when the network traffic status label is abnormal and the protocol status label is normal, the network security level is a level-two network security level; when the network traffic status label is abnormal and the protocol status label is abnormal, the network security level is a level-zero network security level. In step S4, output a network security situation awareness instruction through an instruction control script according to the network security level, and the network security situation awareness instruction includes a firewall configuration instruction and an intrusion detection system response instruction; the instruction control script includes: when the network security level is a level-zero network security level, output both the firewall configuration instruction and the intrusion detection system response instruction; when the network security level is a level-one network security level, output the intrusion detection system response instruction; when the network security level is a level-two network security level, output the firewall configuration instruction; when the network security level is a level-three network security level, do not output an instruction.

[0081] In step S5, obtain a network security situation report through an automated reporting tool according to the original network data, the network status label, and the network security level, and the network security situation report is displayed through a data visualization tool, which is specifically implemented through the following steps:

[0082] S5-1: Obtain the network security situation analysis result, and the network security situation analysis result includes the original network data, the network traffic status label, the protocol status label, and the network security level;

[0083] S5-2: Generate a network security situation report through an automated reporting tool according to the network security situation analysis result;

[0084] S5-3: Create a chart through the data visualization tool Power BI according to the network security situation report to visually display the network security situation data. In this embodiment, visually displaying the network security situation data through the data visualization tool facilitates security managers to quickly understand and analyze the network security situation. A network security situation awareness system based on big data analysis includes a data collection module, a data preprocessing module, a network security situation awareness module, an automated response module, and a report and visualization module; the data collection module includes a network traffic monitoring probe and a deep packet inspection device for real-time collection of raw network data, and the raw network data includes the raw network data stream and raw protocol data in broadband services; the data preprocessing module is used to perform data cleaning, data format standardization, and data normalization on the raw network data to obtain network data; the network security situation awareness module trains a network security situation awareness model based on a preset network security situation awareness standard set, generates a network traffic status label and a protocol status label according to the network data through the network security situation awareness model, and evaluates the network security level according to the network traffic status label and the protocol status label through a rating rule; the automated response module outputs a situation awareness instruction through an instruction control script according to the network security level, and the situation awareness instruction includes a firewall configuration instruction and an intrusion detection system response instruction; the report and visualization module obtains a network security situation report through an automated report tool according to the raw network data, the network status label, and the network security level, and the network security situation report is displayed through a data visualization tool. The computer storage medium of the embodiment of the present invention can adopt any combination of one or more computer-readable media. The computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0085] A computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take many forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0086] Computer program code for carrying out operations of the present invention may be written in one or more programming languages or combinations thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on the remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0087] As described above, the above are only the preferred embodiments of the present invention, and there is no any form of limitation to the present invention. Although the present invention has been disclosed above with the preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some modifications or decorations equivalent to the equivalent embodiments by using the disclosed technical content within the scope of the technical solution of the present invention. However, any simple modification, equivalent change, and decoration made to the above embodiments based on the technical essence of the present invention without departing from the content of the technical solution of the present invention still fall within the scope of the technical solution of the present invention.

Claims

1. A network security situation awareness method based on big data analysis, characterized in that: include: S1: collecting original network data in real time through network traffic monitoring probes and deep packet inspection equipment, wherein the original network data includes original network data flows and original protocol data in broadband services; S2: Preset a network security situation awareness standard set, train a network security situation awareness model according to the network security situation awareness standard set, the network security situation awareness standard set includes a network traffic standard set and a protocol analysis standard set, the network security situation awareness model includes a network traffic analysis model and a protocol analysis model, train the network traffic analysis model through a self-attention temporal convolutional network and a support vector machine according to the network traffic standard set, and train the protocol analysis model through a TF-IDF algorithm and a support vector machine according to the protocol analysis standard set; S3: obtaining network data through preprocessing the original network data, generating a network status label through the network security situation awareness model according to the network data, wherein the network status label includes a network traffic status label and a protocol status label, and evaluating the network security level through a rating rule according to the network status label; S4: Outputting network security situation awareness instructions through an instruction control script according to the network security level, wherein the network security situation awareness instructions include firewall configuration instructions and intrusion detection system response instructions; S5: Obtain a network security situation report through an automated reporting tool according to the original network data, the network status tag, and the network security level, and display the network security situation report through a data visualization tool.

2. The network security situation awareness method based on big data analysis according to claim 1 is characterized in that: The training of the network traffic analysis model in step S2 specifically includes: S2-11: Acquire historical network traffic data, obtain historical network traffic standard data through preprocessing according to the historical network traffic data, obtain the network traffic standard set according to the historical network traffic standard data, the network traffic standard set includes normal traffic and abnormal traffic, and divide the network traffic standard set into a network traffic training set and a network traffic test set; S2-12: constructing a self-attention temporal convolutional network by adding a self-attention mechanism to a self-attention residual block, wherein the self-attention residual block is a residual block in the temporal convolutional network; S2-13: extracting features through the self-attention temporal convolutional network according to the network traffic standard set to obtain a network traffic feature vector set; S2-14: performing feature selection based on the network traffic feature vector set by using a PCA algorithm to obtain a network traffic key feature vector set; S2-15: Identify the normal traffic and the abnormal traffic by training a support vector machine according to the network traffic key feature vector set; S2-16: According to the network traffic training set, an initial network traffic analysis model is obtained by training the self-attention temporal convolutional network and the support vector machine; according to the network traffic test set, the initial network traffic analysis model is tested to obtain an initial network traffic analysis model test result; according to the initial network traffic analysis model test result, a comprehensive score of the initial network traffic analysis model is calculated by using the initial network traffic analysis model evaluation index; S2-17: The network traffic analysis model is obtained according to the comprehensive score of the initial network traffic analysis model through threshold determination. When the comprehensive score of the network traffic analysis model reaches or exceeds the set threshold of 0.9, the network traffic analysis model is obtained.

3. The network security situation awareness method based on big data analysis according to claim 2 is characterized in that: The step S2-13 specifically includes: S2-131: Obtain a query vector, a key vector, and a value vector by calculating a weight matrix according to the historical network traffic standard data; S2-132: Calculating feature similarity based on the historical network traffic standard data by using attention weights, where the feature similarity is the feature similarity of each element in the historical network traffic standard data; S2-133: Obtain a network traffic feature vector set based on the historical network traffic standard data by calculating a weighted value vector.

4. The network security situation awareness method based on big data analysis according to claim 1 is characterized in that: The training of the protocol analysis model in step S2 specifically includes: S2-21: Acquire historical protocol interaction text data, obtain historical protocol interaction text standard data through preprocessing according to the historical protocol interaction text data, obtain the protocol analysis standard set according to the historical protocol interaction text standard data, the protocol analysis standard set includes normal protocol interaction text and abnormal protocol interaction text, and divide the protocol analysis standard set into a protocol analysis training set and a protocol analysis test set; S2-22: extracting features by using the TF-IDF algorithm according to the protocol analysis standard set to obtain a protocol data feature vector set; S2-23: performing feature selection by using a PCA algorithm according to the protocol data feature vector set to obtain a key feature vector set of the protocol data; S2-24: Analyzing key feature vectors of the protocol and identifying the normal protocol interaction text and the abnormal protocol interaction text by training a support vector machine; S2-25: obtaining an initial protocol analysis model through the TF-IDF algorithm and the support vector machine training according to the protocol analysis training set, testing the initial protocol analysis model according to the protocol analysis test set to obtain an initial protocol analysis model test result, and obtaining an initial protocol analysis model comprehensive score through initial protocol analysis model evaluation index calculation according to the initial protocol analysis model test result; S2-26: Obtain the protocol analysis model according to the comprehensive score of the initial protocol analysis model through threshold determination: when the comprehensive score of the initial protocol analysis model reaches or exceeds the set threshold of 0.9, the protocol analysis model is obtained.

5. The network security situation awareness method based on big data analysis according to claim 4 is characterized in that: The step S2-22 specifically includes: S2-221: Calculate the term frequency by using the total number of terms in the protocol data and the number of terms in the protocol according to the historical protocol interaction text standard data; S2-222: Calculate the inverse document frequency based on the total number of protocol documents and the number of documents containing the term according to the historical protocol interaction text standard data; S2-223: Obtain the protocol data feature vector set by calculating feature term weights according to the historical protocol interaction text standard data.

6. The network security situation awareness method based on big data analysis according to claim 1 is characterized in that: The step S3 specifically includes: S3-1: obtaining network data through preprocessing according to the original network data, wherein the preprocessing includes data cleaning, data format standardization, and data normalization; S3-2: Outputting the network traffic status label through the network traffic analysis model according to the network data; S3-3: Outputting the protocol status label through the protocol analysis model according to the network data; S3-4: Evaluate the network security level according to the network traffic status label and the protocol status label through rating rules; when the network traffic status label is normal and the protocol status label is normal, the network security level is the third-level network security level; when the network traffic status label is normal and the protocol status label is abnormal, the network security level is the first-level network security level; when the network traffic status label is abnormal and the protocol status label is normal, the network security level is the second-level network security level; when the network traffic status label is abnormal and the protocol status label is abnormal, the network security level is the zero-level network security level.

7. The network security situation awareness method based on big data analysis according to claim 1 is characterized in that: The instruction control script in step S4 specifically includes: when the network security level is the zero network security level, outputting the firewall configuration instruction and the intrusion detection system response instruction at the same time; when the network security level is the first network security level, outputting the intrusion detection system response instruction; when the network security level is the second network security level, outputting the firewall configuration instruction; when the network security level is the third network security level, no instruction is output.

8. A network security situation awareness system based on big data analysis, comprising a data acquisition module, a data preprocessing module, a network security situation awareness module, an automated response module, and a reporting and visualization module, characterized in that: The data acquisition module includes a network traffic monitoring probe and a deep packet inspection device, which is used to collect original network data in real time, and the original network data includes original network data flow and original protocol data in broadband services; The data preprocessing module is used to perform data cleaning, data format standardization and data normalization on the original network data to obtain network data; The network security situation awareness module trains a network security situation awareness model based on a preset network security situation awareness standard set, generates network traffic status labels and protocol status labels through the network security situation awareness model according to the network data, and evaluates the network security level through rating rules according to the network traffic status labels and the protocol status labels; the automated response module outputs situation awareness instructions through an instruction control script according to the network security level, and the situation awareness instructions include firewall configuration instructions and intrusion detection system response instructions; the reporting and visualization module obtains a network security situation report through an automated reporting tool according to the original network data, the network status label and the network security level, and the network security situation report is displayed through a data visualization tool.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, it implements the network security situation awareness method based on big data analysis as described in any one of claims 1-7.

10. A storage medium containing computer executable instructions, characterized in that: The computer executable instructions, when executed by a computer processor, are used to execute the network security situation awareness method based on big data analysis as described in any one of claims 1 to 7.

Citation Information

Cited By

  • Network security detection early warning method and system and storage medium

    CN121396681A

  • Network security detection and early warning method and system, and storage medium

    CN121396681B