Network security situation awareness method and system
By analyzing the use of IP addresses and ports in network behavior records, filtering out abnormal communication pairs, dividing time windows, identifying transmission rate fluctuations, identifying abnormal paths, and integrating node association strength, the multi-dimensional analysis of network security situation awareness in the existing technology is solved, and efficient threat identification and evaluation is achieved.
Patent Information
- Application Number
- CN202510730061.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-03
- Publication Date
- 2025-07-18
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing network security situation awareness methods have shortcomings in the multi-dimensional analysis and precise classification of abnormal behaviors, and it is difficult to accurately identify complex threat patterns, resulting in inefficient threat positioning and the inability to fully identify key nodes, which affects the overall network security situation awareness capabilities.
By extracting the number of port usages, transmission direction and time interval values of the source IP address and the target IP address, filtering out abnormal communication pairs, dividing the time window to analyze transmission rate fluctuations, combining behavior change sequences, classifying fluctuations modes, identifying abnormal paths, integrating node association strengths, and generating global network threat situation evaluation results.
It improves the accuracy and comprehensiveness of abnormal behavior recognition, significantly improves threat response efficiency, can timely locate potential risk points, provide a visual overall picture of the network security situation, and enhances the comprehensiveness and accuracy of threat assessment.
Smart Images

Figure CN120342770A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network security situation awareness method and system. Background Art
[0002] The field of network security technology is a comprehensive discipline dedicated to protecting networks and data from unauthorized access, attacks, damage, or tampering. It covers multiple aspects from basic security policies, encryption algorithms to advanced security situation awareness, threat modeling, attack defense, etc. This field integrates technologies such as artificial intelligence, big data analysis, Internet of Things security, and cloud computing security. By real-time monitoring, analyzing, and predicting potential threats, it provides comprehensive protection capabilities for users, enterprises, and national-level networks. Network security technology not only involves the technical level but also includes content such as policies, regulations, user education, and awareness improvement, aiming to build a secure and trustworthy network environment.
[0003] Among them, the network security situation awareness method refers to the ability to comprehensively understand the network security status through data collection, analysis, and processing technologies. Supported by technologies such as big data, artificial intelligence, and machine learning, it extracts key information from multi-source data such as network traffic, log information, and user behavior for monitoring, identifying, predicting, and responding to security threats in the network. Its main uses include real-time warning, risk assessment, threat tracking, and attack traceability, helping network managers quickly judge and respond to complex security incidents, thereby ensuring the normal operation of the network system and data security.
[0004] In the existing technology for network security situation awareness, although the monitoring and assessment of threats can be completed through multi-source data extraction and analysis, there are obvious deficiencies in the multi-dimensional analysis and precise classification of abnormal behaviors. Simply relying on a single data source such as network traffic, log information, or user behavior easily ignores the fine-grained correlation features between multiple data, resulting in a weak ability to identify complex threat patterns. In the analysis of time series data, most existing methods are limited to the feature extraction of static or discrete points, lacking the comprehensive capture and pattern mining of the dynamic changes in communication behaviors, and it is difficult to accurately identify short-term abnormal fluctuations and complex behavior switching paths. There is a lack of in-depth tracking and priority classification of behavior pattern switching situations, which easily leads to low threat location efficiency. At the same time, it is unable to conduct multi-level assessments of the overall network threat situation. For the identification and extended correlation analysis of core nodes, the existing technology has insufficient processing capabilities in analyzing node association strength and global interaction relationships, resulting in the omission or misjudgment of key nodes, easily leading to incomplete identification of abnormal behaviors and inaccurate threat tracking, ultimately affecting the overall network security situation awareness ability and security protection effect, and increasing the risk of the network facing potential attacks. Summary of the Invention
[0005] To address the technical problems in the prior art in network security situation awareness, although threat monitoring and assessment can be completed through multi-source data extraction and analysis, there are obvious deficiencies in the multi-dimensional analysis and precise classification of abnormal behaviors. Simply relying on a single data source such as network traffic, log information, or user behavior easily ignores the fine-grained correlation features between multiple data, resulting in a weak ability to identify complex threat patterns. In the analysis of time-series data, most existing methods are limited to the feature extraction of static or discrete points, lacking the comprehensive capture and pattern mining of the dynamic changes in communication behaviors, making it difficult to accurately identify short-term abnormal fluctuations and complex behavior switching paths, lacking in-depth tracking and priority classification of behavior pattern switching situations, easily leading to low threat positioning efficiency, and at the same time being unable to conduct multi-level assessments of the overall network threat situation. For the identification and extended association analysis of core nodes, the prior art has insufficient processing capabilities in analyzing node association strength and global interaction relationships, resulting in the omission or misjudgment of key nodes, easily leading to incomplete identification of abnormal behaviors and inaccurate threat tracking, ultimately affecting the perception ability of the overall network security situation and the security protection effect, and increasing the potential attack risk faced by the network. The embodiments of the present invention provide a network security situation awareness method and system. The technical solutions are as follows: On the one hand, a network security situation awareness method is provided, and the method includes: S1: Based on network behavior records, extract the source IP address and the destination IP address, count the number of port usages, transmission directions, and time interval values, analyze the number of direction changes and time interval differences, screen abnormal communication pairs, and generate a set of abnormal communication pairs; S2: Based on the set of abnormal communication pairs, divide the communication record time series into continuous time windows, analyze the transmission rate within each window, extract the rate fluctuation range and frequency distribution values, screen unstable windows, and generate a set of unstable time windows; S3: Based on the set of unstable time windows, extract the packet records of each time window, calculate the amount of direction change, size fluctuation value, and adjacent time difference, combine the behavior change sequences, classify the fluctuation patterns, count the occurrence times, and generate a classification result of communication behavior patterns; S4: Based on the classification result of communication behavior patterns, extract the behavior pattern switching situations, mark the start and end positions of the switching paths, calculate the repetition times and duration, independently identify abnormal paths, classify the path priorities, and generate a set of abnormal behavior switching paths; S5: Based on the set of abnormal behavior switching paths, extract the path node features, count the node frequencies and interaction relationships, analyze the association strength, integrate the strong nodes as core nodes, expand the association range, and generate an evaluation result of the global network threat situation.
[0006] As a further solution of the present invention, the abnormal communication pair set includes an abnormal source IP address, an abnormal destination IP address, an abnormal port pair, an abnormal communication direction, and an abnormal time interval difference. The unstable time window set includes a rate fluctuation range, a frequency distribution value, and the start and end times of the unstable window. The classification result of the communication behavior pattern includes a classification of the behavior change sequence, a type of fluctuation pattern, and the occurrence frequency of the fluctuation pattern. The abnormal behavior switching path set includes the start and end positions of the path, the number of path repetitions, the duration of the path, and the classification of the priority of the abnormal path. The global network threat situation assessment result includes the characteristics of the core nodes, the node interaction frequency, the node association relationship, the analysis result of the association strength, and the extended association range.
[0007] As a further solution of the present invention, based on the network behavior records, the source IP address and the destination IP address are extracted, the number of port usages, the transmission direction, and the time interval value are statistically analyzed, the number of direction changes and the time interval difference are analyzed, and the steps for screening abnormal communication pairs and generating an abnormal communication pair set are specifically as follows: S101: Based on the network behavior records, the source IP address and the destination IP address are extracted, the transmission protocol and port number are parsed item by item, the number of port accesses in the communication pair is statistically analyzed, the number of independent ports is calculated, the communication pair entries are sorted, and a communication pair port statistics result is generated; S102: Based on the communication pair port statistics result, the bidirectional transmission records of each pair of source IP address and destination IP address are read, the data packet transmission direction is determined by comparing the direction identifiers in the records item by item, the time interval between adjacent data packets is analyzed, the number of direction switches is cumulatively statistically analyzed, and a direction change and time interval difference table is generated; S103: Based on the direction change and time interval difference table, the communication pairs with the number of direction switches exceeding the specified threshold and the time interval difference are screened, the number of port usages of the communication pairs is compared with the cumulative characteristics, the communication pairs that do not meet the screening criteria are excluded, the communication pairs that meet the screening conditions are sorted, and an abnormal communication pair set is generated.
[0008] As a further solution of the present invention, based on the abnormal communication pair set, the communication record time series is divided into continuous time windows, the transmission rate within each window is analyzed, the rate fluctuation range and the frequency distribution value are extracted, the unstable windows are screened, and the steps for generating an unstable time window set are specifically as follows: S201: Based on the abnormal communication pair set, the communication record timestamps are extracted, the records are arranged in chronological order, the continuous communication records are divided into time windows, the data packet size and quantity are cumulatively calculated, the transmission rate is calculated, and a time window transmission rate table is generated; S202: Based on the time window transmission rate table, the transmission rate is read item by item, the numerical difference of the transmission rate is calculated, the frequency of the rate value in the time window is statistically analyzed, the fluctuation range and the frequency distribution value are sorted and associated, and a rate fluctuation and frequency distribution table is generated; S203: Based on the rate fluctuation and frequency distribution table, read the time window fluctuation range and frequency distribution value item by item, filter out the unstable time windows whose fluctuation range exceeds the threshold, eliminate the windows that meet the stable criteria, organize the filtered entries, calculate the window instability score, and generate a set of unstable time windows.
[0009] As a further solution of the present invention, calculate the window instability score according to the formula: ; where represents the window instability score, represents the average value of the fluctuation range within the th time window, represents the global average value of the time window fluctuation range, represents the global standard deviation of the time window fluctuation range, represents the duration length of the th time window, represents the change value of the fluctuation range of the frequency distribution within the th time window, is the standard deviation influence weight, is the time window length influence weight, is the frequency distribution change influence weight.
[0010] As a further solution of the present invention, based on the set of unstable time windows, the steps of extracting the data packet records of each time window, calculating the direction change amount, size fluctuation value and adjacent time difference, combining the behavior change sequence, classifying the fluctuation mode, and counting the occurrence times to generate the communication behavior mode classification result are specifically as follows: S301: Based on the set of unstable time windows, extract the communication data packet records of the time windows, read the source IP address and destination IP address item by item, calculate the number of direction changes, and accumulate the size fluctuation value of the data packets to generate a time window behavior change data table; S302: Based on the time window behavior change data table, read the direction change amount and size fluctuation value item by item in the record order, combine the time stamp difference between adjacent records, and organize the direction change amount, size fluctuation value and time interval into item data to generate a behavior change sequence table; S303: Based on the behavior change sequence table, mark the behavior fluctuation mode by combining and comparing the three features, classify and count the occurrence times of each fluctuation mode, organize the statistical results into item data, and generate the communication behavior mode classification result.
[0011] As a further solution of the present invention, based on the classification result of the communication behavior pattern, the steps of extracting the behavior pattern switching situation, marking the start and end positions of the switching path, calculating the repetition times and the duration, independently identifying the abnormal path, classifying the path priority, and generating the abnormal behavior switching path set are specifically as follows: S401: Based on the classification result of the communication behavior pattern, read the behavior pattern time series item by item, compare adjacent pattern identifiers to extract the switching relationship, record the start pattern and end pattern of the path and the time mark, and generate the behavior pattern switching path set; S402: Based on the behavior pattern switching path set, analyze the paths item by item, count the repetition times of the same path, organize the repetition times and the duration into statistical items, and generate the path feature statistical data; S403: Based on the path feature statistical data, screen the paths, compare the repetition times and the duration to mark the abnormal feature paths, organize the abnormal path identifiers and classify them by priority, sort out the classification result and the abnormal items, calculate the abnormal value score of the path, and generate the abnormal behavior switching path set.
[0012] As a further solution of the present invention, calculate the abnormal value score of the path according to the formula: ; Wherein, represents the abnormal value score of the path, represents the repetition times of the path, represents the normal repetition times reference value of the path, is the absolute value of the difference between the two, represents the duration of the path, represents the normal duration reference value of the path, is the weight coefficient, represents the distance metric between paths, is the weight coefficient, is the adjustment coefficient.
[0013] As a further solution of the present invention, based on the abnormal behavior switching path set, the steps of extracting the path node features, counting the node frequency and the interaction relationship, analyzing the association strength, integrating the strong nodes as the core nodes, expanding the association range, and generating the global network threat situation assessment result are specifically as follows: S501: Based on the abnormal behavior switching path set, extract the start node and end node of the path, count the node appearance frequency and the number of interaction relationships, mark the node connection direction, organize the frequency and the relationship into tabular data, and generate the node frequency and interaction relationship table; S502: Based on the node frequency and interaction relationship table, read the node interaction data, analyze the interaction intensity between nodes, filter the nodes with interaction intensity and mark the core nodes, extract the associated data of the core nodes, organize the core nodes and the associated paths into a set, and generate a set of core nodes and associated paths; S503: Based on the set of core nodes and associated paths, read the core node records one by one, identify the indirect interaction paths between the core nodes and non-core nodes, expand the associated scope of the core nodes, merge the expanded nodes and paths, analyze the interaction characteristics and node associations, and generate a global network threat situation assessment result.
[0014] On the other hand, an electric vehicle status monitoring system is provided. The electric vehicle status monitoring system is used to execute the above-mentioned electric vehicle status monitoring method. The system includes: The network behavior record analysis module extracts the source IP address, target IP address, port number, transmission direction, and time interval value based on the network behavior record, counts the number of port uses, continuously counts the number of direction changes, calculates the time interval difference value item by item, performs multi-parameter mapping processing, and generates a network behavior record analysis result; The abnormal communication screening module extracts the number of direction changes and the time interval difference value based on the network behavior record analysis result, counts the direction change frequency and compares it with a threshold, screens the time interval difference distribution range and accumulates it, and performs multi-parameter intersection judgment on the source IP and target IP in combination with the screening result to generate a set of abnormal communication pairs; The unstable window parsing module divides the communication records into consecutive time windows in chronological order based on the set of abnormal communication pairs, extracts the transmission rate value within the time window, screens and summarizes the time windows whose rate changes exceed the threshold, and generates a set of unstable time windows; The behavior pattern classification module extracts the packet records within the time window based on the set of unstable time windows, classifies them according to the change range and counts the frequency, summarizes the classification patterns and frequencies, and generates a communication behavior pattern classification result; The abnormal path recognition module extracts the start and end positions of the pattern switching points in the classification sequence based on the communication behavior pattern classification result, counts the number of path repetitions between the switching points and calculates the duration, sorts the paths by priority and performs independent identification processing, and generates a set of abnormal behavior switching paths; The global threat assessment module extracts the interaction frequency and relationship of the path nodes based on the set of abnormal behavior switching paths, counts the interaction intensity and merges the intensity nodes, expands the associated scope of the intensity nodes, and generates a global network threat situation assessment result.
[0015] The beneficial effects brought by the technical solution provided by the embodiment of the present invention at least include: By extracting and counting the source IP address and destination IP address of network behavior records, analyzing the number of ports used, the transmission direction, and the time interval value, it is possible to achieve in-depth mining of communication direction and time characteristics. By analyzing the number of direction changes and the time interval difference, abnormal communication pairs can be effectively screened, improving the accuracy and comprehensiveness of preliminary abnormal behavior recognition. By dividing the communication record time series into continuous time windows and further analyzing the fluctuation range and frequency distribution value of the transmission rate within each window, abnormal communication fluctuations in the short term can be identified, locking in unstable time windows and laying a foundation for subsequent behavior pattern analysis. Within the time window, by combining multi-dimensional data such as the amount of direction change, size fluctuation value, and adjacent time difference, the behavior change sequence is combined and the fluctuation pattern is classified. Fine-grained features of communication behavior can be extracted through frequency statistics, effectively classifying and quantifying unstable communication behavior, enhancing the depth and accuracy of abnormal communication recognition. Based on the results of behavior pattern classification, by extracting the start and end positions of behavior pattern switching and marking the path, the repetition times and duration are further calculated, and abnormal paths with potential threats can be independently identified. Based on priority classification, targeted threat tracking is achieved, significantly improving the efficiency and comprehensiveness of threat response. By combining the extraction of path node characteristics and the statistical analysis of interaction relationships, the associated range can be expanded by integrating intensity nodes, key nodes in the global threat situation can be identified, and threat assessment across the entire scope can be completed, providing network managers with a visual and accurate overview of the network security situation, helping to timely locate potential risk points and optimize security protection measures. The overall processing logic, through in-depth analysis and integration layer by layer, maximally mines the associated characteristics between data, providing a more comprehensive, accurate, and efficient threat assessment ability. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 is a schematic diagram of the work flow of the present invention; Figure 2 is a detailed flowchart of S1 of the present invention; Figure 3 is a detailed flowchart of S2 of the present invention; Figure 4 is a detailed flowchart of S3 of the present invention; Figure 5 is a detailed flowchart of S4 of the present invention; Figure 6 is a detailed flowchart of S5 of the present invention; Figure 7 is a system flowchart of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0017] The technical solutions in the present invention will be described below with reference to the accompanying drawings.
[0018] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to indicate examples, illustrations or explanations. Any embodiment or design described as "example" in the present invention should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of the word "example" is intended to present the concept in a specific way. In addition, in the embodiments of the present invention, the meaning expressed by "and / or" can be both, or it can be either of the two.
[0019] In the embodiments of the present invention, "image" and "picture" can sometimes be used interchangeably. It should be noted that when the difference between them is not emphasized, the meanings they intend to express are the same. "of", "corresponding, relevant" and "corresponding" can sometimes be used interchangeably. It should be noted that when the difference between them is not emphasized, the meanings they intend to express are the same.
[0020] In the embodiments of the present invention, sometimes a subscript such as W1 may be written as a non-subscript such as W1. When the difference is not emphasized, the meanings to be expressed are consistent.
[0021] In order to make the technical problems, technical solutions and advantages to be solved by the present invention more clear, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.
[0022] See also Figure 1 The embodiment of the present invention provides a network security situation awareness method, and the processing flow of the method may include the following steps: S1: Based on the network behavior records, extract the source IP address and the destination IP address, count the number of port usage, transmission direction and time interval values, analyze the number of direction changes and time interval differences, filter abnormal communication pairs, and generate an abnormal communication pair set; S2: Based on the set of abnormal communication pairs, the communication record time series is divided into continuous time windows, the transmission rate in each window is analyzed, the rate fluctuation range and frequency distribution value are extracted, the unstable windows are screened, and the unstable time window set is generated; S3: Based on the unstable time window set, extract the data packet records of each time window, calculate the direction change, size fluctuation value and adjacent time difference, combine the behavior change sequence, classify the fluctuation pattern, count the number of occurrences, and generate the communication behavior pattern classification result; S4: Based on the communication behavior pattern classification results, extract the behavior pattern switching situation, mark the starting and ending positions of the switching path, calculate the number of repetitions and duration, independently identify abnormal paths, classify path priorities, and generate an abnormal behavior switching path set; S5: Based on the abnormal behavior switching path set, extract the path node features, count the node frequencies and interaction relationships, analyze the association strength, integrate the intensity nodes into core nodes, expand the association scope, and generate the global network threat situation assessment result.
[0023] The abnormal communication pair set includes the abnormal source IP address, abnormal target IP address, abnormal port pair, abnormal communication direction, and abnormal time interval difference. The unstable time window set includes the rate fluctuation range, frequency distribution value, start and end times of the unstable window. The classification result of the communication behavior pattern includes the classification of the behavior change sequence, the type of the fluctuation pattern, and the occurrence frequency of the fluctuation pattern. The abnormal behavior switching path set includes the start and end positions of the path, the number of path repetitions, the duration of the path, and the classification of the abnormal path priority. The global network threat situation assessment result includes the core node features, the node interaction frequency, the node association relationship, the analysis result of the association strength, and the expanded association scope.
[0024] Specifically, as Figure 2 shown, based on the network behavior records, extract the source IP address and the target IP address, count the number of port usages, the transmission direction, and the time interval value, analyze the number of direction changes and the time interval difference, and screen the abnormal communication pairs. The steps for generating the abnormal communication pair set are specifically as follows: S101: Based on the network behavior records, extract the source IP address and the target IP address, parse the transmission protocol and port number item by item, count the port access times in the communication pair, calculate the number of independent ports, sort out the communication pair entries, and generate the communication pair port statistics result; In the network behavior records, extract the source IP address and the target IP address of each data packet in a parsed-by-item manner, match the extraction results with the recorded communication pair table to identify new entries, add new labels to the unmatched entries, and distinguish and classify them in combination with the transmission protocol information (such as TCP, UDP) and port numbers. During the statistics of the port access times, take the combination of the source IP and the target IP as the unit, scan each record under this combination successively, accumulate the access times of each port, and form an access frequency list. For the calculation of the number of independent ports, count the ports under each source IP and target IP combination without repetition according to the uniqueness of the communication pair, and sort all the counting results in ascending order to facilitate the subsequent sorting out of the communication pair entries and generate the communication pair port statistics result. According to the counted access times, the number of independent ports, and the protocol type, file each item by the IP combination of the communication pair entries one by one to ensure that the statistical results can intuitively reflect the port usage distribution of each communication pair and lay a foundation for subsequent analysis.
[0025] S102: Based on the port statistics results of the communication pair, read the two-way transmission records of each pair of source IP addresses and destination IP addresses. By comparing the direction identifiers in the records one by one, determine the data packet transmission direction, analyze the time intervals between adjacent data packets, accumulate and count the number of direction switches, and generate a table of direction changes and time interval differences; Based on the port statistics results of the communication pair, extract the direction identifiers of data packet transmissions from the two-way transmission records of each pair of source IP and destination IP. Classify the data packets one by one based on this identifier. Define the transmission from the source IP to the destination IP as forward transmission, and the transmission from the destination IP to the source IP as reverse transmission. In the case of clear direction identifiers, by comparing the direction change situations of two consecutive records, accumulate and count the switching behaviors in the forward and reverse directions. To ensure fine-grained analysis of the data, while performing the direction switch statistics, calculate the difference between the timestamps of two adjacent records. Classify the time intervals into short intervals and long intervals, and record the number of direction switches in different intervals respectively, generating a table of direction changes and time interval differences. Adopt a two-dimensional statistical method to generate a multi-dimensional data table in units of communication pairs, clearly showing the transmission direction change characteristics and time interval distribution characteristics of each communication pair, providing a data basis for screening subsequent abnormal communication behaviors.
[0026] S103: Based on the table of direction changes and time interval differences, screen the communication pairs whose number of direction switches exceeds the specified threshold and time interval differences. Compare the port usage quantity of the communication pairs with the cumulative characteristics, eliminate the communication pairs that do not meet the screening criteria, organize the communication pairs that meet the screening conditions, and generate a set of abnormal communication pairs; According to the data statistically recorded in the table of direction changes and time interval differences, use the number of direction switches as the main screening condition, set the specified threshold for the number of direction switches, and perform joint screening in combination with the statistical value of the time interval difference. Take each communication pair as a unit, check one by one whether the number of its direction switches exceeds the specified threshold, and at the same time analyze the distribution characteristics of its short intervals and long intervals. Mark the communication pairs with significant time interval differences. After screening the communication pairs that meet the direction and time interval conditions, further compare the port usage quantity of this communication pair with the cumulative characteristics statistically recorded. Eliminate the communication pairs with too few ports or whose characteristic distributions do not conform to the abnormal pattern. When finally organizing the communication pairs that meet the screening conditions, classify and file the data with abnormal behaviors as the main line, and generate a set of abnormal communication pairs, ensuring that the behavior characteristics and screening basis of each communication pair can be clear, and ultimately used to guide the analysis and early warning of the network security situation.
[0027] Specifically, as Figure 3 shown, based on the set of abnormal communication pairs, divide the communication record time series into consecutive time windows, analyze the transmission rate within each window, extract the rate fluctuation range and frequency distribution values, and the steps to screen unstable windows and generate a set of unstable time windows are specifically as follows: S201: Extract the communication record timestamps based on the abnormal communication pair set, arrange the records in chronological order, divide the continuous communication records into time windows, accumulate the packet sizes and quantities, calculate the transmission rate, and generate a time window transmission rate table; First, sort all communication records according to the timestamps with millisecond-level precision to ensure the chronological order of the records is completely accurate. Then, segment the communication records according to the preset time window length (such as 5 seconds, 10 seconds, etc.), accurately classify all records into the corresponding windows, and at the same time merge and count the communication pairs in each time window. For each time window, calculate the cumulative size of all data packets one by one, extract the number of its communication data packets, combine the total data packet size and the total communication quantity of each time window in turn, calculate the actual transmission rate through the ratio of the two, and further record the number of communication pair types and the number of communication directions in each window to provide auxiliary information for the multi-dimensional rate table constructed in subsequent analysis, forming a time window transmission rate table. Among them, the transmission rate value corresponding to each time window is recorded as the main field, and auxiliary fields are also recorded, including the time range, cumulative data packet size, number of communication pairs, etc., for the accuracy and scalability of subsequent analysis.
[0028] S202: Based on the time window transmission rate table, read the transmission rate item by item, calculate the numerical difference of the transmission rate, count the frequency of the rate value in the time window, organize and correlate the fluctuation range and the frequency distribution value, and generate a rate fluctuation and frequency distribution table; Extract the transmission rate values in the time window one by one, calculate the rate difference between adjacent windows in chronological order, and store the rate change amplitude in turn to ensure that the calculation in each time window complies with the chronological order rule. Conduct statistical analysis on the transmission rate values in each window, record the occurrence frequency of each rate value, classify them by merging the adjacent rate frequencies to form the frequency distribution of different rate segments. For each time window, summarize the maximum, minimum, and average values of the transmission rate, calculate its rate fluctuation range, and integrate the fluctuation range and the frequency distribution value to form a complete table structure. During the process, set a grading range for the rate frequency distribution and add a field to record the proportion of communication abnormal records in each window to provide more comprehensive information support for the multi-dimensional analysis of rate fluctuation and frequency, and generate a rate fluctuation and frequency distribution table.
[0029] S203: Based on the rate fluctuation and frequency distribution table, read the time window fluctuation range and frequency distribution values item by item, filter out the unstable time windows whose fluctuation range exceeds the threshold, remove the windows that meet the stable standard, organize the filtered entries, calculate the window instability score, and generate a set of unstable time windows; Calculate the window instability score according to the formula: ; Among them, represents the window instability score, represents the average value of the fluctuation range within the th time window, represents the global average value of the fluctuation range of the time window, represents the global standard deviation of the fluctuation range of the time window, represents the th duration length of the time window, represents the change value of the fluctuation range of the th time window frequency distribution, is the standard deviation influence weight, is the time window length influence weight, is the frequency distribution change influence weight; Formula details and formula calculation derivation process: This formula is used to calculate the instability score of the th time window , and the result is used to identify the unstable time window whose fluctuation range exceeds the threshold; : The average value of the fluctuation range within the th time window, which is calculated by subtracting the minimum value from the maximum value of the data within this time window. Assuming , it reflects the degree of data fluctuation within this window; : The global average value of the fluctuation ranges of all time windows, which is obtained by calculating the average values of the fluctuation ranges of all time windows. Assuming , it reflects the average fluctuation level of the overall data; : The global standard deviation of the fluctuation ranges of all time windows, which is obtained by calculating the standard deviations of the fluctuation ranges of all time windows. Assuming , it reflects the degree of dispersion of the fluctuation ranges of the overall data; : The duration length of the th time window, which is obtained by recording the start and end times of this time window and calculating the time difference. Assuming (unit: minutes), it reflects the time span of this window; : The change value of the fluctuation range of the th time window frequency distribution, which is obtained by calculating the degree of change in the data frequency distribution within this time window. Assuming , it reflects the change situation of the data frequency distribution within this window; : The standard deviation affects the weight, adjusts the relative importance between the fluctuation ranges of different windows and the global stability. The setting value is based on the degree of emphasis on the influence of the standard deviation. Assume , and this value can be adjusted according to the sensitivity to the influence of the standard deviation; : The time window length affects the weight, adjusts the contributions of long and short windows to the fluctuation score. The setting value is based on the degree of emphasis on the influence of the time length. Assume , and this value can be adjusted according to the sensitivity to the influence of the time length; : The change in frequency distribution affects the weight, adjusts the sensitivity of the mutation of the frequency distribution to the fluctuation score. The setting value is based on the degree of emphasis on the change in frequency distribution. Assume , and this value can be adjusted according to the sensitivity to the change in frequency distribution; Substitute the parameters into the formula for calculation: Calculate : ; Calculate : ; Calculate the numerator part: ; Calculate : ; Calculate : ; Calculate the denominator part: ; Calculate the square root of the denominator: ; Calculate the instability score : ; The result indicates that the instability score of the nd time window is 2.21. This score is used to measure the degree of data fluctuation within this time window. The higher the value, the stronger the instability. By setting a threshold, it can be further determined whether this window belongs to the set of unstable time windows.
[0030] Specifically, as Figure 4 shown, based on the set of unstable time windows, the steps of extracting each time window data packet record, calculating the direction change amount, the magnitude fluctuation value, and the adjacent time difference, combining the behavior change sequence, classifying the fluctuation patterns, and counting the occurrence times to generate the classification result of the communication behavior pattern are specifically as follows: S301: Based on the set of unstable time windows, extract the communication data packet records of the time windows. Read the source IP address and destination IP address one by one, calculate the number of direction changes, accumulate the fluctuation value of the packet size, and generate a time window behavior change data table. Sort the communication data packet records of the time windows in timestamp order. Parse the source IP address and destination IP address contained in each record one by one. By comparing the changes in the source and destination IP addresses between the current record and the previous record, count the number of direction changes. Each change is recorded as a direction switch. Conduct a cumulative fluctuation analysis on the size of the transmitted data packets for each record. Calculate the single fluctuation value by taking the difference between the current packet size and the previous packet size, and sum up all the fluctuation values to obtain the cumulative fluctuation value. Number and organize the data within each time window according to the number of direction changes and the cumulative fluctuation value into behavior feature entries. To ensure data accuracy, perform data cleaning steps to remove outliers or duplicate records, and generate a time window behavior change data table. This data table contains fields such as time window number, number of direction changes, and cumulative fluctuation value, and can be directly used for subsequent analysis.
[0031] S302: Based on the time window behavior change data table, read the direction change amount and size fluctuation value one by one in the record order. Combine with the time difference between adjacent record timestamps, and organize the direction change amount, size fluctuation value, and time interval into entry data to generate a behavior change sequence table. Based on the time window behavior change data table, read the direction change amount and cumulative size fluctuation value in each record one by one in timestamp order. At the same time, extract the timestamps of adjacent records to calculate the time interval, and incorporate the time interval as the time dimension feature of the behavior change into the analysis. For each entry data, construct a feature entry table containing the direction change amount, size fluctuation value, and time interval, and organize the entries in chronological order into a complete behavior change sequence table. Mark the records with time intervals outside the abnormal range and remove interfering outliers to ensure that the sequence table can accurately reflect the dynamic characteristics of the behavior change. Each record in the sequence table is associated with the original time window through a unique identifier to further enhance data traceability, providing basic support for subsequent fluctuation pattern marking and statistics.
[0032] S303: Based on the behavior change sequence table, mark the behavior fluctuation patterns by comparing the combinations of three features, classify and count the occurrences of each fluctuation pattern, organize the statistical results into entry data, and generate the classification result of communication behavior patterns. The direction change, size fluctuation value and time interval in the behavior change sequence table are combined and analyzed as three features. Based on the matching rules between different features, the behavior fluctuation pattern category to which each record belongs is marked. In the marking process, a fixed range or threshold is defined. For example, a large direction change, a drastic fluctuation value and a short time interval are set as a high fluctuation pattern, a small direction change but a large fluctuation value are set as an abnormal fluctuation pattern, and the rest are classified as normal patterns. For each pattern, after classification is completed according to the pattern marking rules, the number of times it appears in the entire sequence table is counted, and the statistical results are organized in the form of entries, including pattern categories and their corresponding number of occurrences, to generate communication behavior pattern classification results, clarify the distribution characteristics and frequency of each behavior fluctuation pattern, and provide data support for abnormal fluctuation detection and trend analysis of network security situation.
[0033] Specifically, if Figure 5 As shown, based on the communication behavior pattern classification results, the behavior pattern switching situation is extracted, the starting and ending positions of the switching path are marked, the number of repetitions and the duration are calculated, the abnormal paths are independently identified, the path priorities are classified, and the steps of generating the abnormal behavior switching path set are as follows: S401: Based on the communication behavior pattern classification result, read the behavior pattern time series one by one, compare the adjacent pattern identifiers to extract the switching relationship, record the path start mode and end mode and time mark, and generate a behavior pattern switching path set; According to the time series in the communication behavior pattern classification results, the identifier of each behavior pattern is read in turn, and the pattern identifiers of two adjacent records are compared one by one to extract the switching relationship between the behavior patterns. During the extraction process, the starting mode, ending mode and specific time of the switching path are determined. By recording the path and corresponding time mark of each mode switch, a complete path entry is formed. During the path extraction process, the path switching event is associated with the actual time axis to generate an entry set containing the starting mode, ending mode and time label, and the repeated switching relationship is marked as a path that appears multiple times to facilitate subsequent path feature analysis. To ensure the accuracy of the path set, the data is screened and cleaned to eliminate invalid paths with too long a time span. At the same time, the unified format of the path record is standardized, and finally a behavior pattern switching path set is generated, laying a data foundation for subsequent path feature statistics and anomaly analysis.
[0034] S402: Based on the behavior pattern switching path set, analyzing the paths one by one, counting the number of repetitions of the same path, arranging the number of repetitions and the duration as statistical items, and generating path feature statistical data; Read the path records in the behavior pattern switching path set one by one. Use the start mode and end mode of each path as the path identifier, and count the number of times the same path identifier appears in the entire set. Record its cumulative repetition times. Calculate the duration of the path based on the time stamp of each path. Integrate and organize the duration of the path and the repetition times to form a statistical entry containing the path identifier, repetition times, and cumulative duration. During the analysis process, consider the different mode characteristics of path switching. For example, high-frequency switching paths are related to network abnormal behaviors. Therefore, pay more attention to the path identifiers that appear frequently, and eliminate the interference path data with short path duration and extremely low appearance frequency to ensure the accuracy of the statistical results, obtain the path feature statistical data, clarify the appearance frequency and duration of different paths, and provide basic data support for the subsequent screening of abnormal paths.
[0035] S403: Based on the path feature statistical data, screen the paths, compare the repetition times and duration to mark the abnormal feature paths, organize the abnormal path identifiers and classify them according to the priority, organize the classification results and the abnormal entries, calculate the abnormal value score of the path, and generate the set of abnormal behavior switching paths; Calculate the abnormal value score of the path according to the formula: ; Where, represents the abnormal value score of the path, represents the repetition times of the path, represents the normal repetition times benchmark value of the path, is the absolute value of the difference between the two, represents the duration of the path, represents the normal duration benchmark value of the path, is the weight coefficient, represents the distance metric between paths, is the weight coefficient, is the adjustment coefficient; Detailed explanation of the formula and the derivation process of the formula calculation: This formula is used to calculate the abnormal value score of the path , by quantifying the deviation of the path repetition times and duration, generate the abnormal behavior path identifier. According to the characteristics of the path, the formula considers factors such as the difference in path repetition times, the difference in duration, and the distance metric between paths, and combines the differences in characteristics in a weighted manner to evaluate the abnormality degree of the path. Through this calculation process, effective abnormal detection and priority classification of the path can be carried out; : The repetition times of the path, which represents the frequency of a certain path appearing within a specified time period, and is obtained through the path access data recorded by the system monitoring. For example, if the path A appears 50 times within a week, then ; : The repetition times benchmark value of the normal path, representing the average number of times the path is repeated under normal circumstances, obtained through statistical analysis of historical data. For example, if the average number of visits to the same type of path in the past 30 days is 40 times, then ; : The duration of the path, representing the total duration of path access, calculated through the timestamps in the path access log. Assuming the access duration of path A is 2 hours, then ; : The duration benchmark value of the normal path, representing the average duration of the path under normal circumstances, obtained through calculation of historical data. For example, if the historical average access duration of path A is 1.5 hours, then ; : The distance metric between paths, measuring the difference between paths. For example, it is calculated based on the geographical location or device differences of access. Assuming the difference metric between path A and path B is 2 (for example, calculated based on the differences in access location and device), then , 、 、 : The weight coefficient, used to adjust the relative importance of various parameters in the outlier score; : Used to adjust the impact of the path duration on the outlier score. By changing the duration of the path, it affects the sensitivity of the outlier score. Setting this value to 1.2 indicates that the duration has a relatively important impact on the outlier score; : Used to adjust the impact of the path difference degree on the outlier score. A value of 1.0 indicates that the path difference degree has a relatively balanced influence with other factors; : Used to adjust the impact of the repetition times. Setting it to 0.8 indicates that the path repetition times have a relatively minor impact on the outlier score; Substitute the actual parameter values for calculation: ; ; Calculate the final result: ; Result indicates that the abnormality degree of the path is relatively high. Since the repetition times of the path are significantly higher than the normal value ( while ), and the duration ( hours) also exceeds the benchmark value of the normal path ( hours), and the difference degree between paths ( ) indicates that this path may be significantly different from the normal path. The outlier score of this path is 4.27, indicating that there is abnormal behavior in this path, which is worthy of further priority classification and analysis. According to the calculation results, this path should be marked as an abnormal path with a higher priority and incorporated into the subsequent abnormal behavior detection process.
[0036] Specifically, as Figure 6 shown, the steps of extracting path node features, counting node frequencies and interaction relationships, analyzing the association strength, integrating the strength nodes as core nodes, and expanding the association range based on the abnormal behavior switching path set to generate the global network threat situation assessment result are specifically as follows: S501: Based on the abnormal behavior switching path set, extract the start node and end node of the path, count the node occurrence frequency and the number of interaction relationships, mark the node connection direction, organize the frequency and relationship into tabular data, and generate a node frequency and interaction relationship table; Parse the path data item by item from the abnormal behavior switching path set, extract the start node and end node of each path, take the number of occurrences of each node as an important indicator of the node frequency, mark the direction characteristics recorded in each path to clarify the connection direction of the nodes. For example, the connection from the start node to the end node can be marked as "forward connection", while the reverse interaction is marked as "reverse connection". Count the number of interaction relationships between each node and other nodes, and indicate the association density of the node in the overall network by recording the values of other nodes associated with the node. During the statistical process, clean the data to ensure the elimination of isolated or single-occurrence invalid node records, improve the accuracy of the statistical table, organize the node frequency, connection direction, and number of interaction relationships into structured tabular data, with each row corresponding to the frequency statistics and interaction relationship details of a node, and finally generate a node frequency and interaction relationship table to provide data support for subsequent analysis of interaction strength and core node identification.
[0037] S502: Based on the node frequency and interaction relationship table, read the node interaction data, analyze the interaction strength between nodes, screen the interaction strength nodes and mark the core nodes, extract the core node association data, and organize the core nodes and associated paths into a set to generate a core node and associated path set; Read the interaction data of each node from the node frequency and interaction relationship table, and calculate the interaction strength between nodes based on the number and direction information of node interaction relationships. For example, by counting the number of two-way interactions and the total amount of data transmission between two nodes, quantify the interaction strength, and filter out data points with significantly higher interaction strength than the node as interaction strength nodes, and further filter out nodes with high-frequency occurrence characteristics and mark them as core nodes. After filtering the core nodes, extract the path data directly associated with each core node, and further classify and organize the interaction direction and strength in the path to ensure that the collection data is structured and traceable, and generate a collection of core nodes and associated paths, including core node identification, path marking and interaction strength information, to provide a detailed analysis basis for subsequent global network threat assessment.
[0038] S503: Based on the core node and associated path set, read the core node records one by one, identify the indirect interaction path between the core node and the non-core node, expand the core node association range, merge and expand the nodes and paths, analyze the interaction characteristics and node associations, and generate a global network threat situation assessment result; Read core node records one by one from the core node and associated path set, and identify the indirect interaction paths between core nodes and non-core nodes by analyzing the interaction data of core nodes one by one. For example, by tracing the paths directly associated with core nodes, find the interaction links that extend the paths to non-core nodes, and add the indirect interaction paths to the interaction range of the nodes. The expanded node and path sets are merged and sorted to analyze their interaction characteristics, including parameters such as interaction directionality, path complexity, and data transmission volume between nodes. A node association graph is constructed to clarify the key position of core nodes in the interaction of the entire network. After the association range is expanded, based on the overall node and path interaction data, a comprehensive assessment of the threat situation in the global network is conducted, such as abnormal path distribution of nodes with high interaction intensity, or high-risk transmission behavior in indirect paths, to ultimately generate a global network threat situation assessment result.
[0039] like Figure 7 As shown, a network security situation awareness system includes: The network behavior record analysis module extracts the source IP address, target IP address, port number, transmission direction and time interval value based on the network behavior record, counts the number of port usage, continuously counts the number of direction changes, calculates the time interval difference value item by item, and performs multi-parameter mapping processing to generate the network behavior record analysis results; The abnormal communication screening module extracts the difference between the number of direction changes and the time interval based on the results of network behavior record analysis, counts the frequency of direction changes and compares it with the threshold, screens the distribution range of the time interval difference and accumulates it, and performs multi-parameter intersection judgment on the source IP and the target IP based on the screening results to generate an abnormal communication pair set; The unstable window parsing module divides the communication records into consecutive time windows in timestamp order based on the set of abnormal communications, extracts the transmission rate values within the time windows, filters out the time windows where the rate change exceeds the threshold and summarizes them to generate a set of unstable time windows; The behavior pattern classification module extracts the packet records within the time windows based on the set of unstable time windows, classifies them according to the change range and counts the frequencies, summarizes the classification patterns and frequencies to generate the communication behavior pattern classification results; The abnormal path recognition module extracts the start and end positions of the pattern switching points in the classification sequence based on the communication behavior pattern classification results, counts the number of path repetitions between the switching points and calculates the duration, sorts the paths by priority and performs independent identification processing to generate a set of abnormal behavior switching paths; The global threat assessment module extracts the interaction frequencies and relationships of the path nodes based on the set of abnormal behavior switching paths, counts the interaction intensities and merges the intensity nodes, expands the associated range of the intensity nodes to generate the global network threat situation assessment results.
[0040] The above are only the specific implementation manners of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A network security situation awareness method, characterized in that, It includes the following steps: S1: Based on network behavior records, extract the source IP address and the destination IP address, count the number of port usages, the transmission direction, and the time interval value, analyze the number of direction changes and the time interval difference, screen out abnormal communication pairs, and generate a set of abnormal communication pairs; S2: Based on the set of abnormal communication pairs, divide the communication record time series into continuous time windows, analyze the transmission rate within each window, extract the rate fluctuation range and the frequency distribution value, screen out unstable windows, and generate a set of unstable time windows; S3: Based on the set of unstable time windows, extract the packet records of each time window, calculate the direction change amount, the size fluctuation value, and the adjacent time difference, combine the behavior change sequences, classify the fluctuation patterns, count the occurrence times, and generate the classification result of communication behavior patterns; S4: Based on the classification result of communication behavior patterns, extract the behavior pattern switching situations, mark the start and end positions of the switching paths, calculate the repetition times and the duration, independently identify the abnormal paths, classify the path priorities, and generate a set of abnormal behavior switching paths; S5: Based on the set of abnormal behavior switching paths, extract the path node features, count the node frequencies and the interaction relationships, analyze the association strength, integrate the nodes with strong strength as the core nodes, expand the association range, and generate the global network threat situation assessment result.
2. The network security situation awareness method according to claim 1, characterized in that The set of abnormal communication pairs includes the abnormal source IP address, the abnormal destination IP address, the abnormal port pair, the abnormal communication direction, and the abnormal time interval difference. The set of unstable time windows includes the rate fluctuation range, the frequency distribution value, and the start and end times of the unstable windows. The classification result of communication behavior patterns includes the classification of behavior change sequences, the types of fluctuation patterns, and the occurrence frequencies of the fluctuation patterns. The set of abnormal behavior switching paths includes the start and end positions of the paths, the path repetition times, the path duration, and the classification of abnormal path priorities. The global network threat situation assessment result includes the core node features, the node interaction frequencies, the node association relationships, the analysis results of the association strength, and the expanded association range.
3. The network security situation awareness method according to claim 1, characterized in that, The steps of extracting the source IP address and the destination IP address based on network behavior records, counting the number of port usages, the transmission direction, and the time interval value, analyzing the number of direction changes and the time interval difference, screening out abnormal communication pairs, and generating a set of abnormal communication pairs are specifically as follows: S101: Based on network behavior records, extract the source IP address and the destination IP address, parse the transmission protocol and the port number item by item, count the port access times in the communication pairs, calculate the number of independent ports, organize the communication pair entries, and generate the communication pair port statistics result; S102: Based on the communication pair port statistics result, read the bidirectional transmission records of each pair of source IP address and destination IP address, determine the packet transmission direction by comparing the direction identifiers in the records item by item, analyze the time interval between adjacent packets, cumulatively count the number of direction changes, and generate a table of direction changes and time interval differences; S103: Based on the direction change and time interval difference table, screen communication pairs whose direction switching times exceed the specified threshold and time interval difference, compare the number of port uses and cumulative features of the communication pairs, eliminate communication pairs that do not meet the screening criteria, organize communication pairs that meet the screening conditions, and generate a set of abnormal communication pairs.
4. The network security situation awareness method according to claim 1, characterized in that Based on the set of abnormal communication pairs, the steps of dividing the communication record time series into continuous time windows, analyzing the transmission rate within each window, extracting the rate fluctuation range and frequency distribution value, and screening unstable windows to generate a set of unstable time windows are specifically as follows: S201: Based on the set of abnormal communication pairs, extract the communication record timestamps, arrange the records in chronological order, divide the continuous communication records into time windows, accumulate the data packet size and quantity, calculate the transmission rate, and generate a time window transmission rate table; S202: Based on the time window transmission rate table, read the transmission rate item by item, calculate the numerical difference of the transmission rate, count the frequency of the rate value in the time window, organize and correlate the fluctuation range and frequency distribution value, and generate a rate fluctuation and frequency distribution table; S203: Based on the rate fluctuation and frequency distribution table, read the fluctuation range and frequency distribution value of the time window item by item, screen unstable time windows whose fluctuation range exceeds the threshold, eliminate windows that meet the stable criteria, organize the screened entries, calculate the window instability score, and generate a set of unstable time windows.
5. The network security situation awareness method according to claim 4, characterized in that, Calculate the window instability score according to the formula: ; Among them, represents the window instability score, represents the average value of the fluctuation range within the th time window, represents the global average value of the time window fluctuation range, represents the global standard deviation of the time window fluctuation range, represents the duration of the th time window, represents the change value of the fluctuation range of the frequency distribution of the th time window, is the standard deviation influence weight, is the time window length influence weight, is the frequency distribution change influence weight.
6. The network security situation awareness method according to claim 1, characterized in that, Based on the set of unstable time windows, extract the data packet records of each time window, calculate the direction change amount, size fluctuation value, and adjacent time difference, combine the behavior change sequences, classify the fluctuation patterns, and count the occurrence times to generate the steps of the communication behavior pattern classification result are specifically as follows: S301: Based on the set of unstable time windows, extract the communication data packet records of the time window, read the source IP address and destination IP address item by item, calculate the number of direction changes, and accumulate the data packet size fluctuation value to generate a time window behavior change data table; S302: Based on the time window behavior change data table, read the direction change amount and size fluctuation value item by item in the record order, combine the time difference between adjacent record timestamps, organize the direction change amount, size fluctuation value, and time interval as item data, and generate a behavior change sequence table; S303: Based on the behavior change sequence table, mark the behavior fluctuation patterns by comparing the combination of the three features, classify and count the occurrence times of each fluctuation pattern, organize the statistical results as item data, and generate the communication behavior pattern classification result.
7. The network security situation awareness method according to claim 1, characterized in that Based on the communication behavior pattern classification result, extract the behavior pattern switching situation, mark the start and end positions of the switching path, calculate the repetition times and duration, independently identify the abnormal path, classify the path priority, and generate the steps of the abnormal behavior switching path set are specifically as follows: S401: Based on the communication behavior pattern classification result, read the behavior pattern time series item by item, compare and extract the switching relationship with the adjacent pattern identifier, record the start pattern, end pattern, and time mark of the path, and generate a set of behavior pattern switching paths; S402: Analyze each path one by one based on the set of behavior pattern switching paths, count the repetition times of the same paths, organize the repetition times and the duration as statistical entries, and generate path feature statistical data; S403: Based on the path feature statistical data, filter the paths, compare the repetition times and the duration to mark the paths with abnormal features, organize the abnormal path identifiers and classify them by priority, organize the classification results and the abnormal entries, calculate the abnormal value score of the paths, and generate a set of abnormal behavior switching paths.
8. The network security situation awareness method according to claim 7, wherein Calculate the abnormal value score of the paths according to the formula: ; Among them, represents the outlier score of the path, represents the number of repetitions of the path, represents the baseline value of the normal number of repetitions of the path, is the absolute value of the difference between the two, represents the duration of the path, represents the baseline value of the normal duration of the path, is the weight coefficient, represents the distance metric between paths, is the weight coefficient, is the adjustment coefficient.
9. The network security situation awareness method according to claim 1, wherein The steps for extracting path node features based on the set of abnormal behavior switching paths, counting the node frequencies and interaction relationships, analyzing the association strength, integrating the strength nodes as core nodes, and expanding the association range to generate the global network threat situation assessment result are specifically as follows: S501: Based on the set of abnormal behavior switching paths, extract the start node and end node of the path, count the occurrence frequency of the nodes and the number of interaction relationships, mark the connection direction of the nodes, and organize the frequency and relationships as tabular data to generate a node frequency and interaction relationship table; S502: Based on the node frequency and interaction relationship table, read the node interaction data, analyze the interaction strength between nodes, filter the nodes with interaction strength and mark the core nodes, extract the associated data of the core nodes, and organize the core nodes and the associated paths as a set to generate a set of core nodes and associated paths; S503: Based on the set of core nodes and associated paths, read each core node record one by one, identify the indirect interaction paths between the core nodes and non-core nodes, expand the association range of the core nodes, merge the expanded nodes and paths, analyze the interaction characteristics and node associations, and generate the global network threat situation assessment result.
10. A network security situation awareness system, characterized in that, According to the network security situation awareness method according to any one of claims 1-9, the system includes: The network behavior record analysis module extracts the source IP address, target IP address, port number, transmission direction, and time interval value based on the network behavior record, counts the number of port usages, continuously counts the number of direction changes, calculates the time interval difference value item by item, performs multi-parameter mapping processing, and generates a network behavior record analysis result; The abnormal communication screening module extracts the number of direction changes and the time interval difference value based on the network behavior record analysis result, counts the direction change frequency and compares it with the threshold, screens the time interval difference distribution range and accumulates it, and performs a multi-parameter intersection judgment on the source IP and target IP in combination with the screening result to generate a set of abnormal communication pairs; The unstable window parsing module divides the communication records into consecutive time windows in timestamp order based on the set of abnormal communication pairs, extracts the transmission rate value within the time window, screens the time windows with a rate change exceeding the threshold and summarizes them to generate a set of unstable time windows; The behavior pattern classification module extracts the packet records within the time window based on the set of unstable time windows, classifies them according to the change range and counts the frequency, summarizes the classification patterns and frequencies, and generates a communication behavior pattern classification result; Based on the classification result of the communication behavior pattern, the abnormal path recognition module extracts the start and end positions of the pattern switching points in the classification sequence, counts the number of path repetitions between the switching points, calculates the duration, sorts the paths by priority, and performs independent identification processing to generate a set of abnormal behavior switching paths; Based on the set of abnormal behavior switching paths, the global threat assessment module extracts the interaction frequency and relationship of the path nodes, counts the interaction intensity, merges the intensity nodes, expands the association range of the intensity nodes, and generates the global network threat situation assessment result.
Citation Information
Cited By
Data cycle monitoring method and system
CN120675905A
Intelligent flow scheduling method, device and equipment for AI data center switch and medium
CN120675927A
Network security threat assessment and traceability system based on big data
CN120785649A
Network security monitoring method and system applied to power monitoring system
CN120856438A
Network security monitoring method and system applied to power monitoring system
CN120856438B