Network security big data state evaluation method based on pattern recognition
Through multimodal feature extraction and hierarchical pattern recognition, combined with self-coded networks and graph neural networks, a network security state evaluation model is built, which solves the problem of difficulty in detecting unknown attacks and predicting attack trends in the existing technology, and achieves efficient and accurate network security protection.
Patent Information
- Application Number
- CN202510427354.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-07
- Publication Date
- 2025-07-11
AI Technical Summary
The existing network security situation evaluation methods are difficult to detect unknown attacks, adapt to the evolution of attack methods, predict attack development trends, analyze large-scale network data in real time, and the computing resources are consumed, making it difficult to effectively deal with complex network threats.
Through multimodal feature extraction, cross-domain feature fusion, hierarchical pattern recognition and timing attack chain construction, combining self-coding networks, graph neural networks and Bayesian evaluation methods, a network security state evaluation model is constructed to generate an adaptive defense strategy.
It realizes accurate detection of unknown threats, reduces false alarm rates and missed alarm rates, improves the detection ability of complex attack behaviors, provides forward-looking decision-making basis and adaptive defense, and improves network security protection effects.
Smart Images

Figure CN120301637A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a method for evaluating the state of network security big data based on pattern recognition. Background Art
[0002] With the rapid development of the Internet and digital technologies, the scale and complexity of network security threats have been continuously escalating, and the attack methods are characterized by strong concealment, high automation, and long duration. For example, advanced persistent threats (APTs) often use means such as social engineering, zero-day vulnerabilities, and malicious code injection for long-term latency and gradually penetrate the target system, making it difficult for traditional security devices to effectively perceive their attack trajectories. In addition, new threats such as distributed denial of service attacks (DDoS), malware propagation, phishing, and supply chain attacks have posed great network security challenges to enterprises and government agencies.
[0003] The existing network security situation assessment methods are mainly based on static rule matching, machine learning modeling, or deep learning detection, but there are still significant limitations in practical applications: (1) The rule matching method is difficult to detect unknown attacks, requires manual update of the feature library by experts, and lacks the ability to detect variant attacks and zero-day vulnerabilities; (2) The machine learning method based on artificial feature engineering has insufficient generalization ability, is difficult to adapt to the continuous evolution of attack techniques, and the feature extraction depends on expert experience, with limitations; (3) Lack of temporal correlation analysis, making it difficult to predict the development trend of attacks, resulting in difficulty in identifying multi-step attack behaviors such as APT attacks and supply chain attacks; (4) High consumption of computing resources, making it difficult to analyze large-scale network data in real time. Although the existing deep learning models can improve the detection accuracy, they are limited by the computing cost and are difficult to be efficiently applied in the actual environment. Summary of the Invention
[0004] The present invention provides a method for evaluating the state of network security big data based on pattern recognition.
[0005] A method for evaluating the state of network security big data based on pattern recognition includes the following steps:
[0006] S1, multi-modal feature extraction of network security big data: Extract multi-modal features from multi-source data, where the multi-modal features include network traffic features, user behavior features, abnormal access features, and threat intelligence labels, and perform data preprocessing on the features, including normalization, de-duplication, and time alignment, to generate an initial feature matrix;
[0007] S2, Feature Fusion and Abnormal Pattern Extraction: Perform cross-domain feature fusion on the generated initial feature matrix, including screening highly relevant features using an information gain-based method and constructing a reduced-dimensional comprehensive feature space using an autoencoder network to generate an abnormal pattern representation matrix, where the abnormal pattern representation matrix is used for subsequent attack behavior analysis;
[0008] S3, Hierarchical Pattern Recognition and Attack Behavior Classification: Based on the abnormal pattern representation matrix, use a multi-level pattern recognition method to classify attack behaviors, where:
[0009] In the first layer, use a clustering-based method for unsupervised anomaly detection to preliminarily screen high-risk behaviors;
[0010] In the second layer, use an attack behavior classification model based on a graph neural network to perform fine-grained attack classification on the screened high-risk behaviors and generate attack category labels;
[0011] S4, Temporal Attack Chain Construction: Based on the generated attack category labels, construct an attack chain in combination with timestamp information, including: calculating the time dependence between different attack events, using a Markov model to predict the development trend of attacks, and forming a temporal attack chain model;
[0012] S5, Network Security State Assessment: Based on the constructed temporal attack chain model, assess the network security state, specifically including: calculating the attack propagation path, predicting potential attack targets, and quantifying the overall network security situation through a Bayesian risk assessment method to generate a security state score;
[0013] S6, Adaptive Security Defense Strategy Generation: According to the security state score, match predefined defense strategy templates, generate adaptive security defense strategies, and issue dynamic defense instructions to firewalls, intrusion detection systems, and security information and event management systems to achieve network security protection optimization.
[0014] Optionally, the S1 includes:
[0015] S11, Data Source Access and Feature Extraction: Obtain multi-source data from the network security environment, including network traffic logs, system event logs, host behavior logs, and threat intelligence data;
[0016] For different data sources, extract basic features, including network traffic features (such as packet size, protocol type), user behavior features (such as login frequency, access path), abnormal access features (such as illegal port scanning, long sessions), and threat intelligence labels (such as known malicious IPs, attack pattern labels);
[0017] S12, Feature Normalization and Data Alignment: Perform normalization processing on the extracted features, including converting numerical features to a standard range to ensure the comparability of different types of data;
[0018] Adopt an event-driven approach to align the timestamps of system logs and network traffic data, ensuring consistency in the time dimension for different data sources;
[0019] Process duplicate data and null value data to ensure data integrity.
[0020] S13, Feature Denoising and Outlier Handling: Use statistical methods to detect outliers in the data, and combine with the sliding window method to smooth the mutated data. Reduce the data dimension through the principal component analysis method, reduce redundant information, and improve the data analysis efficiency.
[0021] S14, Feature Matrix Generation: Based on the data processed in S11 to S13, construct a multi-modal feature matrix, where each column represents different types of features, and each row represents the network status data within a time window;
[0022] Use the hash coding method to numerically process categorical data to ensure that the feature matrix can be directly input into the subsequent analysis module.
[0023] Optionally, the S2 includes:
[0024] S21, Cross-Domain Feature Screening: Calculate the influence weights of each feature on the network security status, and screen out the features with important influences, including abnormal access frequency, attack target distribution, and network traffic mutation, to ensure that the selected features can effectively represent the network abnormal state.
[0025] S22, Feature Fusion and Dimensionality Reduction: Use an autoencoder network to fuse the features, construct a low-dimensional feature space, and retain the main information of the original data.
[0026] S23, Abnormal Pattern Preclassification: Use the clustering analysis method to preliminarily classify the abnormal pattern representation matrix, and group similar abnormal behaviors into one category;
[0027] Calculate the degree of abnormality for each category, and screen out the high-risk categories.
[0028] Optionally, the S3 includes:
[0029] S31, Unsupervised Anomaly Detection: Use a clustering-based method to perform clustering analysis on the abnormal pattern representation matrix, preliminarily screen possible attack behaviors, and calculate the anomaly degree of the clustering center;
[0030] S32, Attack Behavior Classification Based on Graph Neural Network: Construct an attack behavior graph, where the nodes of the graph represent different attack events, and the edges represent the association relationships between events. Use a graph neural network to classify the attack behaviors and generate attack category labels.
[0031] Optionally, the S4 includes:
[0032] S41, Attack Event Time Correlation Analysis: Calculate the time dependence between different attack events, analyze the sequence of attack development, adopt a Markov model to predict the potential development direction of the attack;
[0033] S42, Temporal Attack Chain Construction: Combine time series analysis methods to construct an attack chain representing the complete process of an attack from the initial stage to the final target, generate a temporal attack chain model, and provide input for subsequent security state assessment.
[0034] Optionally, the S5 includes:
[0035] S51, Attack Propagation Path Analysis: Calculate the propagation path of an attack in the network, analyze the possible affected range of the attack, adopt a path calculation algorithm to determine high-risk network nodes;
[0036] S52, Quantitative Security Situation Assessment: Combine the attack propagation path, attack category, and network structure to calculate the security state score of the network, adopt the Bayesian method to evaluate the potential impact of future attacks.
[0037] Optionally, the S6 includes:
[0038] S61, Matching Defense Strategy Template: According to the security state score, match a suitable defense strategy template, adopt a rule matching method to select the optimal defense plan;
[0039] S62, Adaptive Security Defense Optimization: Adopt a reinforcement learning method to adjust the defense strategy according to historical defense effects, improve the defense effect, generate the final security defense instruction, and send it to relevant security devices such as firewalls and intrusion detection systems.
[0040] Advantages of the present invention:
[0041] In the present invention, through multi-source data collection and cross-domain feature fusion, a more accurate network security state assessment mechanism is established. By using network traffic logs, system event logs, host behavior logs, and threat intelligence data, a multi-modal feature matrix is constructed, and the information gain method is used to screen high-value features to avoid the influence of redundant data on the assessment accuracy. Feature dimensionality reduction is performed through an autoencoder network to reduce noise interference and improve the ability to extract abnormal patterns. At the same time, a hierarchical pattern recognition method is adopted, combining unsupervised clustering and graph neural networks to achieve fine-grained classification of network attack behaviors, improve the ability to detect unknown threats, and reduce the false alarm rate and missed alarm rate.
[0042] The present invention calculates the transition probability of attack behaviors based on a Markov model, establishes a time correlation model for attack events, and solves the problem in the prior art that it is difficult to capture the development trend of attacks. Through the alignment of time windows of attack events, the consistency of multi-source data is ensured, and by analyzing the attack propagation path, an attack behavior graph is constructed to form a time-series attack chain. On this basis, by dynamically updating the attack chain, the attack situation assessment result is adjusted in real time, improving the detection ability for complex attack behaviors such as APT (Advanced Persistent Threat) attacks and multi-step attacks, and providing a forward-looking decision-making basis for security operation and maintenance.
[0043] The present invention adopts a security situation scoring method, combines factors such as the attack propagation range and historical attack success rate to quantify the network security status, and optimizes the defense strategy through reinforcement learning to ensure that the defense system can adaptively adjust the strategy and improve the security protection effect. Based on the Bayesian evaluation method, potential attack targets are predicted, and the optimized security defense strategy is sent to firewalls, intrusion detection systems, and security information and event management systems to achieve an intelligent and automated protection system. By real-time monitoring the security status and adjusting the defense parameters, the defense ability of the system against complex attacks is improved, providing efficient and accurate security guarantees for security operation and maintenance in a large-scale network environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only those of the present invention. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings without creative efforts.
[0045] Figure 1 It is a schematic flowchart of the method according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0046] The present invention will be described in detail below with reference to the drawings and specific embodiments. At the same time, it should be noted here that in order to make the embodiments more detailed, the following embodiments are the best and preferred embodiments. For some well-known technologies, those skilled in the art can also adopt other alternative methods for implementation; moreover, the drawings are only for more specific description of the embodiments and are not intended to specifically limit the present invention.
[0047] It should be noted that in the specification, references to "one embodiment", "an embodiment", "exemplary embodiments", "some embodiments", etc. indicate that the described embodiments may include specific features, structures, or characteristics, but not necessarily every embodiment includes such specific features, structures, or characteristics. Additionally, when describing a specific feature, structure, or characteristic in combination with an embodiment, implementing such feature, structure, or characteristic in combination with other embodiments (whether explicitly described or not) should be within the knowledge of those skilled in the relevant art.
[0048] Generally, terms can be understood, at least in part, from their use in context. For example, at least in part depending on the context, the term "one or more" as used herein can be used to describe any feature, structure, or characteristic in a singular sense, or can be used to describe a combination of features, structures, or characteristics in a plural sense. Additionally, the term "based on" can be understood as not necessarily intended to convey a set of exclusive factors, but rather, at least in part depending on the context, can allow for the existence of other factors that are not necessarily explicitly described.
[0049] As Figure 1 shown, a method for evaluating the state of network security big data based on pattern recognition includes the following steps:
[0050] S1, extraction of multi-modal features of network security big data: Extract multi-modal features from multi-source data (including network traffic logs, system event logs, host behavior logs, and threat intelligence data). The multi-modal features include network traffic features, user behavior features, abnormal access features, and threat intelligence tags, and perform data preprocessing on the features, including normalization, deduplication, and time alignment, to generate an initial feature matrix;
[0051] S2, feature fusion and abnormal pattern extraction: Perform cross-domain feature fusion on the generated initial feature matrix, including screening highly correlated features based on an information gain method, and using an autoencoder network to construct a reduced-dimensional comprehensive feature space to generate an abnormal pattern representation matrix, where the abnormal pattern representation matrix is used for subsequent attack behavior analysis;
[0052] S3, hierarchical pattern recognition and attack behavior classification: Based on the abnormal pattern representation matrix, use a multi-level pattern recognition method to classify attack behaviors, where:
[0053] In the first layer, an unsupervised anomaly detection method based on clustering is used to preliminarily screen high-risk behaviors;
[0054] In the second layer, an attack behavior classification model based on a graph neural network is used to perform fine-grained attack classification on the screened high-risk behaviors and generate attack category labels;
[0055] S4, Temporal Attack Chain Construction: Based on the generated attack category labels, construct an attack chain in combination with timestamp information, including: calculating the temporal dependence relationship between different attack events, using a Markov model to predict the development trend of attacks, and forming a temporal attack chain model;
[0056] S5, Network Security State Assessment: Based on the constructed temporal attack chain model, assess the network security state, specifically including: calculating the attack propagation path, predicting potential attack targets, and quantifying the overall network security situation through the Bayesian risk assessment method to generate a security state score;
[0057] S6, Generation of Adaptive Security Defense Strategies: According to the security state score, match predefined defense strategy templates, generate adaptive security defense strategies, and issue dynamic defense instructions to firewalls, intrusion detection systems, and security information and event management systems to achieve network security protection optimization.
[0058] S1 includes:
[0059] S11, Data Source Access and Feature Extraction: Obtain multi-source data from the network security environment, including network traffic logs, system event logs, host behavior logs, and threat intelligence data;
[0060] For different data sources, extract basic features, including network traffic features (such as packet size, protocol type), user behavior features (such as login frequency, access path), abnormal access features (such as illegal port scanning, long sessions), and threat intelligence labels (such as known malicious IPs, attack pattern labels);
[0061] S12, Feature Normalization and Data Alignment: Perform normalization processing on the extracted features, including converting numerical features to a standard range to ensure the comparability of different types of data;
[0062] Adopt an event-driven method to align the timestamps of system logs and network traffic data to ensure the consistency of different data sources in the time dimension;
[0063] Process duplicate data and null data to ensure data integrity.
[0064] S13, Feature Denoising and Outlier Handling: Use statistical methods to detect outliers in the data, and combine the sliding window method to smooth the mutation data. Reduce the data dimension through the principal component analysis method to reduce redundant information and improve the data analysis efficiency;
[0065] Construct an abnormal feature annotation mechanism to preliminarily identify abnormal patterns and provide input for subsequent analysis.
[0066] S14, Feature Matrix Generation: Based on the data processed in S11 to S13, construct a multi-modal feature matrix, where each column represents different types of features and each row represents the network state data within a time window;
[0067] Use the hash coding method to numerically process categorical data to ensure that the feature matrix can be directly input into the subsequent analysis module.
[0068] Through multi-modal feature extraction of network security big data, the access, feature extraction, normalization, alignment, noise reduction, and feature matrix construction of multi-source data are completed, ensuring the high-quality input of network security big data and providing a basis for subsequent abnormal pattern recognition.
[0069] S2 includes:
[0070] S21, Cross-Domain Feature Screening: Calculate the influence weights of each feature on the network security state, and screen out the features with important influences, including abnormal access frequency, attack target distribution, and network traffic mutation, to ensure that the selected features can effectively represent the network abnormal state.
[0071] S22, Feature Fusion and Dimensionality Reduction: Use an autoencoder network to fuse features, construct a low-dimensional feature space, and maintain the main information of the original data;
[0072] Train the autoencoder network so that it can automatically learn the latent representation of the data, reduce noise interference, and improve the generalization ability of the model;
[0073] Generate an abnormal pattern representation matrix, where each sample point represents the comprehensive network state within a time window.
[0074] S23, Abnormal Pattern Preclassification: Use the clustering analysis method to preliminarily classify the abnormal pattern representation matrix and group similar abnormal behaviors into one category;
[0075] Calculate the degree of abnormality of each category, screen out high-risk categories, and provide input for subsequent attack behavior recognition;
[0076] Through feature fusion and abnormal pattern extraction, feature screening, feature fusion, and dimensionality reduction are achieved, and the abnormal patterns are preliminarily classified, laying a foundation for subsequent attack behavior classification and network state evaluation.
[0077] S3 includes:
[0078] S31, Unsupervised Anomaly Detection: Use a clustering-based method to perform clustering analysis on the abnormal pattern representation matrix, preliminarily screen possible attack behaviors, calculate the anomaly degree of the cluster center, and determine which categories belong to potential attack behaviors;
[0079] S32, Attack behavior classification based on graph neural network: Construct an attack behavior graph, where the nodes of the graph represent different attack events and the edges represent the association relationships between events. Use graph neural network to classify attack behaviors and generate attack category labels.
[0080] Through hierarchical pattern recognition and attack behavior classification, unsupervised anomaly detection and attack behavior classification based on graph neural network are achieved, improving the accuracy of attack behavior recognition and providing input for subsequent attack chain modeling.
[0081] S4 includes:
[0082] S41, Temporal correlation analysis of attack events: Calculate the time dependence relationship between different attack events, analyze the sequence of attack development, and use the Markov model to predict the potential development direction of the attack;
[0083] Regard network attacks as a time series event and use the Markov transition probability matrix to describe the transition relationship between different attack events. The calculation formula is as follows:
[0084]
[0085] Among them, A t represents the attack event that occurs at time t (such as port scanning, brute force cracking, SQL injection, etc.), A t+1 represents the attack event that may occur at time t + 1, N(A t , A t+1 ) represents the historical occurrence times of the transition from attack event A t to attack event A t+1 , ∑ j N(A t , A j ) represents the sum of all possible transition times from attack event A t occurring, P(A t+1 |A t ) is the probability that the attack transfers from event A t to event A t+1 ;
[0086] S42, Temporal attack chain construction: Combine time series analysis methods to construct an attack chain, representing the complete process of the attack from the initial stage to the final goal, and generate a temporal attack chain model, providing input for subsequent security state assessment;
[0087] Through the construction of the temporal attack chain, the time correlation relationship between attack events is established, and the temporal attack chain is constructed, improving the prediction ability of the attack development.
[0088] S5 includes:
[0089] S51, Attack Propagation Path Analysis: Calculate the propagation path of an attack in the network, analyze the possible affected scope of the attack, adopt a path calculation algorithm to determine high-risk network nodes;
[0090] S52, Quantitative Security Posture Assessment: Combine the attack propagation path, attack category, and network structure to calculate the security state score of the network, and adopt the Bayesian method to evaluate the potential impact of future attacks;
[0091] Through network security state assessment, attack propagation path analysis and quantitative security posture assessment are realized, improving the understanding of the network security state and providing a basis for the generation of subsequent defense strategies.
[0092] S6 includes:
[0093] S61, Matching Defense Strategy Templates: According to the security state score, match appropriate defense strategy templates, and adopt a rule matching method to select the optimal defense plan;
[0094] S62, Adaptive Security Defense Optimization: Adopt a reinforcement learning method to adjust the defense strategy according to historical defense effects, improve the defense effect, generate the final security defense instructions, and send them to relevant security devices, such as firewalls and intrusion detection systems;
[0095] Through the generation of adaptive security defense strategies, the adaptive optimization of defense strategies is realized, improving the network defense ability and enhancing the security of the system.
[0096] The present invention covers any substitutions, modifications, equivalent methods, and solutions made on the essence and scope of the present invention. To enable the public to have a thorough understanding of the present invention, specific details are described in detail in the following preferred embodiments of the present invention, and those skilled in the art can fully understand the present invention without these detailed descriptions. In addition, well-known methods, processes, procedures, components, and circuits are not described in detail to avoid unnecessary confusion to the essence of the present invention.
[0097] The above are only the preferred embodiments of the present invention. It should be noted that for those of ordinary skill in the art, several improvements and refinements can be made without departing from the principle of the present invention, and these improvements and refinements should also be regarded as the protection scope of the present invention.
Claims
1. A method for evaluating the status of network security big data based on pattern recognition, characterized in that It includes the following steps: S1. Multi-modal feature extraction of network security big data: Extract multi-modal features from multi-source data. The multi-modal features include network traffic features, user behavior features, abnormal access features, and threat intelligence labels, and perform data preprocessing on the features, including normalization, duplicate removal, and time alignment, to generate an initial feature matrix; S2. Feature fusion and abnormal pattern extraction: Perform cross-domain feature fusion on the generated initial feature matrix, including screening highly relevant features based on an information gain method, and using an autoencoder network to construct a reduced-dimensional comprehensive feature space to generate an abnormal pattern representation matrix, where the abnormal pattern representation matrix is used for subsequent attack behavior analysis; S3. Hierarchical pattern recognition and attack behavior classification: Based on the abnormal pattern representation matrix, use a multi-level pattern recognition method to classify attack behaviors, where: In the first layer, an unsupervised anomaly detection method based on clustering is used to preliminarily screen high-risk behaviors; In the second layer, an attack behavior classification model based on a graph neural network is used to perform fine-grained attack classification on the screened high-risk behaviors and generate attack category labels; S4. Temporal attack chain construction: Based on the generated attack category labels, construct an attack chain in combination with timestamp information, including: calculating the time dependence between different attack events, using a Markov model to predict the development trend of attacks, and forming a temporal attack chain model; S5. Network security status evaluation: Based on the constructed temporal attack chain model, evaluate the network security status, specifically including: calculating the attack propagation path, predicting potential attack targets, and quantifying the overall network security situation through a Bayesian risk assessment method to generate a security status score; S6. Generation of adaptive security defense strategies: According to the security status score, match predefined defense strategy templates, generate adaptive security defense strategies, and send dynamic defense instructions to firewalls, intrusion detection systems, and security information and event management systems to achieve network security protection optimization.
2. The method for evaluating the state of network security big data based on pattern recognition according to claim 1, characterized in that The S1 includes: S11. Data source access and feature extraction: Obtain multi-source data from the network security environment, including network traffic logs, system event logs, host behavior logs, and threat intelligence data; For different data sources, extract basic features, including network traffic features, user behavior features, abnormal access features, and threat intelligence labels; S12. Feature normalization and data alignment: Perform normalization processing on the extracted features, including converting numerical features to a standard range, and using an event-driven method to align the timestamps of system logs and network traffic data; S13. Feature noise reduction and outlier processing: Use statistical methods to detect outliers in the data, and combine a sliding window method to smooth the mutation data, and reduce the data dimension through a principal component analysis method to reduce redundant information; S14. Feature matrix generation: Construct a multi-modal feature matrix based on the data processed in S11 to S13; Use a hash coding method to numerically process categorical data.
3. The method for evaluating the state of network security big data based on pattern recognition according to claim 2, characterized in that The S2 includes: S21, Cross-domain feature screening: Calculate the influence weights of each feature on the network security status, and screen out the features with important influences, including abnormal access frequency, attack target distribution, and network traffic mutation; S22, Feature fusion and dimensionality reduction: Use an autoencoder network to fuse the features, construct a low-dimensional feature space, and retain the main information of the original data; S23, Abnormal pattern pre-classification: Use the clustering analysis method to preliminarily classify the abnormal pattern representation matrix, and group similar abnormal behaviors into one category; Calculate the degree of abnormality of each category, and screen out high-risk categories.
4. A method for evaluating the state of network security big data based on pattern recognition according to claim 3, characterized in that, The above S3 includes: S31, Unsupervised anomaly detection: Use a clustering-based method to perform clustering analysis on the abnormal pattern representation matrix, preliminarily screen attack behaviors, and calculate the anomaly degree of the cluster center; S32, Attack behavior classification based on graph neural network: Construct an attack behavior graph, where the nodes of the graph represent different attack events, and the edges represent the association relationships between events. Use a graph neural network to classify the attack behaviors and generate attack category labels.
5. A method for evaluating the state of network security big data based on pattern recognition according to claim 4, characterized in that The above S4 includes: S41, Attack event time correlation analysis: Calculate the time dependence relationship between different attack events, analyze the sequence of attack development, and use a Markov model to predict the potential development direction of the attack; S42, Temporal attack chain construction: Combine time series analysis methods to construct an attack chain, which represents the complete process of an attack from the initial stage to the final target, generate a temporal attack chain model, and provide input for subsequent security status evaluation.
6. A method for evaluating the state of network security big data based on pattern recognition according to claim 5, characterized in that, The above S5 includes: S51, Attack propagation path analysis: Calculate the propagation path of the attack in the network, analyze the possible affected range of the attack, and use a path calculation algorithm to determine high-risk network nodes; S52, Security situation quantitative assessment: Combine the attack propagation path, attack category, and network structure to calculate the security status score of the network, and use the Bayesian method to evaluate the potential impact of future attacks.
7. A method for evaluating the state of network security big data based on pattern recognition according to claim 6, characterized in that, The above S6 includes: S61, Match the defense strategy template: According to the security status score, match a suitable defense strategy template, and use a rule matching method to select the optimal defense plan; S62, Adaptive security defense optimization: Use reinforcement learning methods to adjust the defense strategy according to historical defense effects, improve the defense effect, generate the final security defense instruction, and send it to relevant security devices, such as firewalls and intrusion detection systems.
Citation Information
Patent Citations
Network security risk assessment method
CN118631581A
Computer network anomaly detection method
CN118784364A
Network security assessment method and device, equipment, storage medium and product
CN118972114A
Network attack and defense decision support method and system based on artificial intelligence
CN119155099A
Network attack link tracking and threat situation reasoning method based on knowledge graph
CN119544327A
Cited By
Industrial internet security situation analysis method and system based on support vector regression
CN120498903A
Method for determining security state of gateway request behavior, computing device and storage medium
CN120528705A
Response processing method and system for network security event
CN120658497A
Network situation monitoring system and method
CN120729633A
A network situation monitoring system and method
CN120729633B