Network security alarm optimization method and system based on deep learning and multi-dimensional correlation analysis
Through deep learning and multi-dimensional correlation analysis methods, combined with the LSTM model, a network security alarm system is built, which solves the problem of high false alarm rate, realizes accurate identification of alarms and reduces false alarm rate, and improves operation and maintenance efficiency.
Patent Information
- Application Number
- CN202510414677.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2025-07-25
AI Technical Summary
The existing network security alarm system has a high false alarm rate, which causes operation and maintenance personnel to be misreported by alarm interference, and cannot effectively respond to alarms caused by new attacks and normal network behavior, affecting the efficiency of security incident handling.
Using a method based on deep learning and multi-dimensional correlation analysis, we use the method to mine association rules from four dimensions: time, alarm type, asset IP and judgment results, and combine the long and short-term memory network (LSTM) model to build a deep learning model to initially judge whether the alarm is a false alarm, and optimize the model through a feedback mechanism.
It reduces the false alarm rate of network security alarms, improves the work efficiency of operation and maintenance personnel, can accurately identify normal alarms and false alarms, reduces false alarm interference, and enhances the ability to respond to complex network environments.
Smart Images

Figure CN120378278A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of detection and protection in network security, and specifically to a network security alarm optimization method and system based on deep learning and multi-dimensional correlation analysis. Background Art
[0002] In the process of digitalization, network security is an important guarantee for the stable operation of various industries. With the expansion of network applications and the innovation of attack means, network security alarm systems are facing severe challenges, and the high false alarm rate has become a prominent problem. Currently, most alarm systems rely on traditional detection technologies such as rule matching and feature recognition. These methods have a certain detection ability for known attacks, but are powerless in the face of new attacks. At the same time, the network environment is complex, and normal network behaviors such as software updates and configuration changes are also likely to trigger alarm rules, resulting in false alarms. The high false alarm rate seriously interferes with security operation and maintenance work. Security personnel need to spend a lot of energy dealing with false alarms, and real security threats are easily ignored, greatly increasing the risk of security incidents.
[0003] Therefore, how to optimize network security alarms, reduce the false alarm rate of network security alarms, and prevent operation and maintenance personnel from being interfered by false alarms is a technical problem that needs to be solved urgently at present. Summary of the Invention
[0004] The technical task of the present invention is to provide a network security alarm optimization method and system based on deep learning and multi-dimensional correlation analysis to solve the problems of how to optimize network security alarms, reduce the false alarm rate of network security alarms, and prevent operation and maintenance personnel from being interfered by false alarms.
[0005] The technical task of the present invention is realized in the following way. A network security alarm optimization method based on deep learning and multi-dimensional correlation analysis is as follows:
[0006] Alarm information collection and storage: Collect comprehensive and accurate alarm information and processing information from each key node of the network and store them.
[0007] Multi-dimensional correlation analysis: Starting from four dimensions of time, alarm type, asset IP, and judgment result, use the Apriori algorithm to mine the association rules between time, alarm type, asset IP, and judgment result, and then judge whether a new alarm is a false alarm.
[0008] Deep learning model construction and training: Shuffle the alarm data and divide it into a training set and a test set according to a preset ratio. Build a deep learning model by building a neural network and setting hyperparameters, and use the training set to train the deep learning model.
[0009] False Alarm Judgment and Feedback: When a new alarm log is generated by the host, based on the association rules generated by multi-dimensional correlation analysis, initially judge whether the alarm is a false alarm.
[0010] Preferably, the alarm information collection and storage are as follows:
[0011] Data Collection: In order to collect alarm information in a specified area, it is necessary to comprehensively evaluate the network architecture of the specified area, determine the key nodes in the network, and select the corresponding data collectors according to the specificities and interface types of different devices in the network; at the same time, plan the deployment locations of the data collectors and the data transmission paths, and transmit the collected data to the data processing center in a timely and stable manner; among them, the types of alarm information to be collected are also clarified before collection. In addition to common network traffic anomaly data, port scan alarms, and system privilege change reminders, potential security threat alarms should also be considered; and detailed collection strategies should be formulated for each type of alarm information to determine the collection frequency and depth to ensure that the collected alarm information is comprehensive and accurate.
[0012] Processing Information Association Collection: While collecting alarm information, establish a collection mechanism for the corresponding processing information for the alarm, specifically: when security personnel process the alarm, record the corresponding measures taken and the judgment result feedback through the management platform to ensure that the processing information can be accurately associated with the alarm information, providing a basis for subsequent analysis of the processing effect and optimization of the alarm judgment model; among them, the measures taken include isolating the infected host, blocking suspicious network connections, installing security patches, and removing malware.
[0013] Data Transmission and Storage: Use a data transmission protocol to transmit the collected alarm information and processing information from each data collector to the central data storage server; during the transmission process, encrypt the data to prevent the data from being stolen or tampered with during transmission, and select the corresponding database management system to store the collected data, such as the relational database MySQL or the non-relational database MongoDB, and then make a reasonable selection according to the characteristics of the data and the query requirements to improve the storage and retrieval efficiency.
[0014] Preferably, the multi-dimensional correlation analysis is as follows:
[0015] Determine the definition of alarm information association analysis dimensions, specifically: the time dimension records the specific time when the alarm is generated, and is used to determine the association rule between false alarms and time through analysis of historical alarm false alarm information; the alarm type dimension records the alarm type to which each alarm information belongs, and is used to determine the association rule between false alarms and alarm types through analysis of historical alarm false alarm information; the asset IP dimension records the asset IP associated with each alarm information, and is used to determine the association rule between false alarms and asset IP through analysis of historical alarm false alarm information; the judgment result dimension records the judgment result information associated with each alarm information, which is divided into two judgment results: false alarm and non-false alarm; and is used to determine the association rule between false alarms and judgment result information through analysis of historical alarm false alarm information;
[0016] Data cleaning and preprocessing: Clean and preprocess the collected alarm data to remove duplicate, erroneous or incomplete data records; standardize the data to unify the format and measurement units of data of different dimensions;
[0017] Multi-dimensional association rule mining: including item set support calculation, association rule confidence calculation and false positive judgment rules; among them, item set support calculation is as follows:
[0018] Define item sets: combine different values of alarm type, asset IP, judgment result and time into item sets;
[0019] Calculate support: Support indicates the frequency of occurrence of any item set in the data set. For each item set, calculate the number of times the corresponding item set appears in all alarm data, and then divide it by the total number of alarms to obtain the support of the corresponding item set.
[0020] Set support threshold: Set a support threshold according to the actual situation. Only item sets with support greater than the support threshold are considered frequent item sets.
[0021] The calculation of association rule confidence is as follows:
[0022] Generate association rules: For frequent item sets, generate association rules between different dimensions;
[0023] Calculate confidence: Confidence indicates the probability that the conclusion is true when the premise conditions are met. For each association rule, calculate its confidence;
[0024] Set confidence threshold: Set a confidence threshold. Only association rules with confidence greater than the confidence threshold are considered valid rules.
[0025] The false alarm judgment rule is specifically as follows: When a new alarm is generated, according to the alarm type, asset IP, and time information, match the previously generated association rules; if the information of the new alarm can match the association rules with a relatively high confidence level, and the judgment results corresponding to the corresponding association rules are all false alarms, then this new alarm is very likely to be a false alarm, and the alarm is marked as a false alarm; on the contrary, if the judgment results corresponding to the matched rules are all non-false alarms, then this new alarm is most likely a non-false alarm, and the alarm is marked as a non-false alarm; then the alarm is transmitted to the deep learning model for further judgment.
[0026] Preferably, the construction of the neural network and the setting of hyperparameters are specifically as follows:
[0027] When using the long short-term memory network (LSTM) for false alarm judgment, first determine the number of layers of the network according to the time series of alarm data to better capture long-term dependencies; at the same time, reasonably set the number of LSTM units in each layer. The number of units determines the ability of the deep learning model to learn features. Too few units may lead to insufficient learning ability, and too many may cause overfitting; finally, connect the layers in sequence. The input layer receives the alarm data processed by multi-dimensional association analysis. The data is transmitted between layers, and finally the output layer outputs the judgment result on whether the alarm is normal or a false alarm;
[0028] The learning rate is a key hyperparameter. The learning rate determines the step size of parameter update during the training process of the deep learning model; in the training of the alarm false alarm model, if the learning rate is too large, the model may skip the optimal solution during the training process, resulting in non-convergence; if the learning rate is too small, the model training speed will be extremely slow, consuming a lot of time; in the training of the model, through experiments, find the appropriate value that can make the model loss function decrease rapidly, so as to improve the performance of model training;
[0029] The model training is specifically as follows:
[0030] Select the loss function and optimizer: According to the characteristics of the binary classification task of alarm judgment, select the cross-entropy loss function to accurately measure the difference between the model prediction value and the true value; and select the Adam optimizer to continuously adjust the model parameters through iterative calculation, so that the loss function gradually converges to the minimum value;
[0031] Iterative training: Input the training set data into the deep learning model in batches in an orderly manner. First, perform forward propagation to calculate the prediction value of the model; then calculate the error between the prediction value and the true value through the loss function; finally, perform backpropagation to adjust the model parameters according to the error to achieve the learning and optimization of the model; among them, during the training process, closely refer to the results of multi-dimensional association analysis and dynamically adjust the training strategy.
[0032] More preferably, the alarm false alarm judgment and feedback are specifically as follows:
[0033] Based on the association rules generated by multi-dimensional association analysis, initially judge whether the alarm is a false alarm:
[0034] If the confidence level of the corresponding association rule exceeds the set threshold, add the corresponding mark;
[0035] Input the new alarm into the trained deep learning model. The deep learning model makes real-time judgments on the new alarm according to the learned alarm patterns and feature differences, and outputs the result of whether the corresponding alarm is a normal alarm or a false alarm;
[0036] Feed back the judgment result to the security operation and maintenance personnel, and at the same time record the actual alarm situation and the judgment result, and regularly compare and analyze the judgment result and the actual situation;
[0037] At the same time, re-label the alarms with incorrect situations, and regularly send them together with the correct alarm data to the central data storage server as training data to re-mine the association rules and train the model, so as to improve the accuracy of false alarm judgment.
[0038] A network security alarm optimization system based on deep learning and multi-dimensional association analysis, the system includes:
[0039] An alarm information collection and storage module, which is used to collect comprehensive and accurate alarm information and processing information from various key nodes of the network and store them;
[0040] A multi-dimensional association analysis module, which is used to start from four dimensions of time, alarm type, asset IP and judgment result, and use the Apriori algorithm to mine the association rules between time, alarm type, asset IP and judgment result, and then judge whether the new alarm is a false alarm;
[0041] A deep learning model construction and training module, which is used to randomly shuffle the alarm data and divide it into a training set and a test set according to a preset ratio, construct a deep learning model by building a neural network and setting hyperparameters, and use the training set to train the deep learning model;
[0042] An alarm false alarm judgment and feedback module, which is used to initially judge whether the alarm is a false alarm according to the association rules generated by multi-dimensional association analysis when a new alarm log is generated on the host.
[0043] Preferably, the alarm information collection and storage module includes:
[0044] The data collection sub-module is used to comprehensively evaluate the network architecture of a specified area in order to collect alarm information in that area, determine the key nodes in the network, and select corresponding data collectors according to the specificities and interface types of different devices in the network. At the same time, plan the deployment locations of the data collectors and the data transmission paths to transmit the collected data to the data processing center in a timely and stable manner. Among them, the types of alarm information to be collected are also clarified before collection. In addition to common network traffic anomaly data, port scan alarms, and system privilege change reminders, potential security threat alarms should also be considered. And formulate detailed collection strategies for each type of alarm information to determine the collection frequency and depth to ensure that the collected alarm information is comprehensive and accurate.
[0045] The processing information association collection sub-module is used to establish a collection mechanism for processing information corresponding to the alarms while collecting alarm information. Specifically, when security personnel process an alarm, record the corresponding measures taken and the judgment result feedback through the management platform to ensure that the processing information can be accurately associated with the alarm information, providing a basis for subsequent analysis of the processing effect and optimization of the alarm judgment model. Among them, the measures taken include isolating the infected host, blocking suspicious network connections, installing security patches, and removing malware.
[0046] The data transmission and storage sub-module is used to transmit the collected alarm information and processing information from each data collector to the central data storage server using a data transmission protocol. During the transmission process, encrypt the data to prevent the data from being stolen or tampered with during transmission, and select an appropriate database management system to store the collected data, such as the relational database MySQL or the non-relational database MongoDB, and make a reasonable selection according to the characteristics of the data and the query requirements to improve the storage and retrieval efficiency.
[0047] The multi-dimensional association analysis module includes:
[0048] The alarm information association analysis dimension definition sub-module is used to define the time dimension, alarm type dimension, asset IP dimension, and judgment result dimension. Among them, the time dimension records the specific moment when the alarm occurs and is used to judge the association rule between false alarm information and time through the analysis of historical alarm false alarm information. The alarm type dimension records the alarm type to which each alarm information belongs and is used to judge the association rule between false alarm information and alarm type through the analysis of historical alarm false alarm information. The asset IP dimension records the asset IP associated with each alarm information and is used to judge the association rule between false alarm information and asset IP through the analysis of historical alarm false alarm information. The judgment result dimension records the judgment result information associated with each alarm information, which is divided into two judgment results: false alarm and non-false alarm. Through the analysis of historical alarm false alarm information, it is used to judge the association rule between false alarm information and judgment result information.
[0049] The data cleaning and preprocessing sub-module is used to clean and preprocess the collected alarm data, eliminating duplicate, incorrect or incomplete data records; and standardize the data to unify the formats and measurement units of data in different dimensions;
[0050] The multi-dimensional association rule mining sub-module is used for item set support calculation, association rule confidence calculation and false alarm judgment rules.
[0051] Preferably, the deep learning model construction and training module includes:
[0052] The neural network construction sub-module is used to use the long short-term memory network (LSTM) when making false alarm judgments. First, determine the number of layers of the network according to the time series of the alarm data to better capture long-term dependencies; at the same time, reasonably set the number of LSTM units in each layer. The number of units determines the ability of the deep learning model to learn features. Too few units may lead to insufficient learning ability, while too many may cause overfitting; finally, connect the layers in sequence. The input layer receives the alarm data processed by multi-dimensional association analysis. The data is transmitted between the layers, and finally the output layer outputs the judgment result on whether the alarm is normal or a false alarm;
[0053] The hyperparameter setting sub-module is used to adopt the learning rate to determine the step size of parameter update in the training process of the deep learning model; in the training of the alarm false alarm model, if the learning rate is too large, the model may skip the optimal solution during training, resulting in non-convergence; if the learning rate is too small, the model training speed will be extremely slow, consuming a large amount of time; in the training model, the appropriate value that can make the model loss function decrease rapidly can be found through experiments, so as to improve the performance of model training;
[0054] The model training sub-module is used to select the loss function and optimizer: according to the characteristics of the binary classification task of alarm judgment, select the cross-entropy loss function to accurately measure the difference between the model prediction value and the true value; and select the Adam optimizer to continuously adjust the model parameters through iterative calculation, so that the loss function gradually converges to the minimum value; and input the training set data into the deep learning model in batches in an orderly manner. First, perform forward propagation to calculate the prediction value of the model; then calculate the error between the prediction value and the true value through the loss function; finally, perform backpropagation to adjust the model parameters according to the error to achieve the learning and optimization of the model; among them, during the training process, closely refer to the results of multi-dimensional association analysis and dynamically adjust the training strategy;
[0055] The specific working process of the alarm false alarm judgment and feedback module is as follows: When a new alarm log is generated by the host, first, according to the association rules generated by multi-dimensional association analysis, initially judge whether the alarm is a false alarm: If the confidence level of the corresponding association rule exceeds the set threshold, add the corresponding mark; then input it into the trained deep learning model. The deep learning model makes a real-time judgment on the new alarm according to the learned alarm patterns and feature differences, and outputs the result of whether the new alarm is a normal alarm or a false alarm; then feedback the judgment result to the security operation and maintenance personnel, and at the same time record the actual alarm situation and judgment result. Regularly compare and analyze the judgment result and the actual situation; at the same time, re-label the alarms with incorrect situations, and send them to the alarm information collection and storage module together with the correct alarm data regularly as training data, and re-mine the association rules and train the model, so as to improve the correct rate of false alarm judgment.
[0056] An electronic device includes: a memory and at least one processor;
[0057] Wherein, the memory stores computer execution instructions;
[0058] The at least one processor executes the computer execution instructions stored in the memory, so that the at least one processor executes the network security alarm optimization method based on deep learning and multi-dimensional association analysis as described above.
[0059] A computer-readable storage medium stores computer execution instructions therein. When the processor executes the computer execution, the network security alarm optimization method based on deep learning and multi-dimensional association analysis as described above is implemented.
[0060] The network security alarm optimization method and system based on deep learning and multi-dimensional association analysis of the present invention have the following advantages:
[0061] (1) The present invention can collect alarm information related to the host and corresponding processing information, construct a comprehensive alarm data model through multi-dimensional association analysis, and introduce a deep learning algorithm on this basis, so that it can accurately identify alarm patterns, master the feature differences between normal alarms and false alarms, and thus judge whether the newly generated alarm log of the host is a false alarm, reducing the false alarm rate of alarms;
[0062] (2) The present invention uses a deep learning algorithm to perform deep learning analysis on multi-dimensional alarm data. When a new alarm log is generated by the host, it will quickly use the trained deep learning model to intelligently analyze the new alarm, and then judge whether the alarm is a false alarm by comparing it with historical alarm patterns and features;
[0063] (3) The present invention addresses the problem of excessively high false alarm rates in existing alarms. By combining deep learning and multi-dimensional alarm analysis, it reduces the false alarm rate of received alarms, prevents operation and maintenance personnel from being disturbed by false alarms, thereby minimizing the false alarm rate of alarms received by the host and improving the work efficiency of security personnel;
[0064] (4) The present invention uses multi-dimensional association analysis to mine association rules from alarm data, deeply exploring the potential connections between alarm data from multiple dimensions such as time, alarm type, and asset IP. For example, by analyzing the association patterns of multiple alarm types within a specific IP range during a specific time period, the authenticity of alarms can be judged more accurately;
[0065] (5) The present invention uses a large amount of labeled alarm data to train a deep model, learning the characteristic differences between normal and false alarms, such as accurately distinguishing the characteristics of normal network traffic fluctuations and abnormal DDoS attack traffic, thereby significantly reducing the false alarm rate and enabling security operation and maintenance personnel to focus on handling real security threats;
[0066] (6) The present invention uses a continuous feedback optimization mechanism to incorporate new alarm situations and processing results into the training data, enabling the model and analysis method to keep up with the times. At the same time, the deep learning model has a powerful self-learning ability and can continuously adapt to new network behavior patterns and security threat characteristics. Multi-dimensional association analysis can also analyze newly emerging alarm data from different angles, mining its association relationship with existing data, thus always maintaining the ability to effectively respond to complex and changing network environments;
[0067] (7) The present invention adopts an association rule mining algorithm to mine association rules between different dimensions from the preprocessed data. According to the association rules obtained from the association analysis, the alarm information is screened, and alarms with high relevance are marked as false alarms, thereby reducing the probability of alarm false alarms;
[0068] (8) Based on the alarm feature data generated by multi-dimensional association analysis, the present invention divides the training set and test set proportionally, constructs an LSTM network to capture time series dependencies, and balances the learning ability and overfitting risk by adjusting the number of network layers and units. When setting hyperparameters such as the learning rate, cross-validation is used to optimize the training efficiency, and the cross-entropy loss function and Adam optimizer are selected for model iteration. At the same time, by using a deep learning model to judge whether newly generated alarms on the host are false alarms, and through incremental training, the model ability is further improved, the false alarm rate of alarms is greatly reduced, and the work efficiency of security operation and maintenance personnel is improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0069] The present invention will be further described below with reference to the accompanying drawings.
[0070] Appendix Figure 1Schematic diagram of the structure of a network security alert optimization system based on deep learning and multi-dimensional correlation analysis;
[0071] Appendix Figure 2 Flowchart of the working process of a network security alert optimization system based on deep learning and multi-dimensional correlation analysis. Specific implementation manners
[0072] The network security alert optimization method and system based on deep learning and multi-dimensional correlation analysis of the present invention will be described in detail below with reference to the accompanying drawings of the specification and specific embodiments.
[0073] Embodiment 1:
[0074] This embodiment provides a network security alert optimization method based on deep learning and multi-dimensional correlation analysis. The method is as follows:
[0075] S1. Alarm information collection and storage: Comprehensively and accurately collect alarm information and processing information from various key nodes of the network and store them; these information are the original data sources for subsequent multi-dimensional correlation analysis and deep learning model training, and their quality and integrity directly affect the accuracy of the entire system's judgment of alarm false positives; by collecting rich alarm data, sufficient information is provided for the system to learn the patterns of normal and abnormal alarms, thereby effectively reducing the false positive rate and improving the efficiency and reliability of network security protection; after the alarm information is collected, the alarm information needs to be sent to the alarm false positive judgment and feedback module to judge whether the alarm information is a false alarm;
[0076] S2. Multi-dimensional correlation analysis: Deeply mine and correlate alarm information from multiple perspectives, which can more comprehensively and accurately understand the security situation behind the alarm; starting from the four dimensions of time, alarm type, asset IP, and judgment result, use the Apriori algorithm to mine the association rules between time, alarm type, asset IP, and judgment result, and then judge whether a new alarm is a false alarm; for example, combining the frequency of alarm false positives in the time dimension with the alarm type can more accurately judge the rule of whether certain alarm types are false alarms in a specific time period;
[0077] S3. Deep learning model construction and training: Shuffle the alarm data and divide it into a training set and a test set according to a preset ratio. Construct a deep learning model by building a neural network and setting hyperparameters, and use the training set to train the deep learning model. Among them, the training set data is mainly used to train the model, and the test set data is mainly used to verify the model. For example, 75% is used as the training set and 25% is used as the test set. The construction and training of the deep learning model play a key role in the entire system. Although the multi-dimensional correlation analysis module can mine the correlation rules between alarm data, in the face of complex and changeable network security scenarios, the powerful self-learning and pattern recognition capabilities of the deep learning model are still required to accurately identify alarm patterns, judge whether an alarm is a false alarm, and based on the feedback alarm data, through model training, learn the characteristic differences between normal alarms and false alarms, providing strong support for the accurate judgment of new alarms.
[0078] S4. False alarm judgment and feedback of alarms: When a new alarm log is generated by the host, initially judge whether the alarm is a false alarm according to the correlation rules generated by multi-dimensional correlation analysis.
[0079] The alarm information collection and storage in step S1 of this embodiment are specifically as follows:
[0080] S101. Data collection: In order to be able to collect alarm information in the specified area, it is necessary to comprehensively evaluate the network architecture in the specified area, determine the key nodes in the network, and select the corresponding data collector according to the specificities and interface types of different devices in the network. At the same time, plan the deployment location of the data collector and the data transmission path, and transmit the collected data to the data processing center in a timely and stable manner. Among them, the types of alarm information to be collected are also clarified before collection. In addition to common network traffic anomaly data, port scan alarms, and system privilege change reminders, potential security threat alarms should also be considered. And formulate detailed collection strategies for each type of alarm information, determine the collection frequency and depth, and ensure that the collected alarm information is comprehensive and accurate.
[0081] S102. Associated collection of processing information: While collecting alarm information, establish a collection mechanism for processing information corresponding to the alarm. Specifically, when security personnel process an alarm, record the corresponding measures taken and the judgment result feedback through the management platform to ensure that the processing information can be accurately associated with the alarm information, providing a basis for subsequent analysis of the processing effect and optimization of the alarm judgment model. Among them, the measures taken include isolating the infected host, blocking suspicious network connections, installing security patches, and removing malicious software.
[0082] S103. Data Transmission and Storage: Use a data transmission protocol to transfer the collected alarm information and processing information from each data collector to the central data storage server; during the transmission process, encrypt the data to prevent it from being stolen or tampered with during transmission, and select an appropriate database management system to store the collected data, such as the relational database MySQL or the non-relational database MongoDB, and make a reasonable selection according to the characteristics of the data and query requirements, so as to improve the storage and retrieval efficiency.
[0083] The multi-dimensional association analysis in step S2 of this embodiment is specifically as follows:
[0084] S201. Determine the definition of the alarm information association analysis dimension, specifically: The time dimension records the specific moment when the alarm occurs, and is used to judge the association rule between the false alarm and time through the analysis of historical alarm false alarm information; the alarm type dimension records the alarm type to which each alarm information belongs, and is used to judge the association rule between the false alarm and the alarm type through the analysis of historical alarm false alarm information; the asset IP dimension records the asset IP associated with each alarm information, and is used to judge the association rule between the false alarm and the asset IP through the analysis of historical alarm false alarm information; the judgment result dimension records the judgment result information associated with each alarm information, which is divided into two judgment results: false alarm and non-false alarm; through the analysis of historical alarm false alarm information, it is used to judge the association rule between the false alarm and the judgment result information;
[0085] S202. Data Cleaning and Preprocessing: Clean and preprocess the collected alarm data, eliminate duplicate, incorrect or incomplete data records; and standardize the data to unify the formats and measurement units of data in different dimensions; for example, unify the time formats recorded by different devices into the standard time format, identify the alarm types according to a unified classification standard, standardize the management of asset IP addresses, and classify the judgment results according to standards such as success, failure, and partially resolved;
[0086] S203. Multi-dimensional Association Rule Mining: Includes item set support calculation, association rule confidence calculation, and false alarm judgment rules; specifically as follows:
[0087] S20301. The item set support calculation is specifically as follows:
[0088] ① Define the item set: Combine different value combinations of alarm type, asset IP, judgment result, and time into an item set; for example, {alarm type = intrusion detection alarm, asset IP = 192.168.1.100, judgment result = non-false alarm, time = 2024-10-01 09:00:00};
[0089] ② Calculate support: Support indicates the frequency of any itemset appearing in the dataset; for each itemset, calculate the number of times the corresponding itemset appears in all alarm data, and then divide by the total number of alarms to obtain the support of the corresponding itemset; for example, in 1000 alarm data, {alarm type = intrusion detection alarm, asset IP = 192.168.1.100} appears 50 times, so the support is 0.05;
[0090] ③ Set the support threshold: Set a support threshold according to the actual situation. Only item sets with support greater than the support threshold are considered frequent item sets; for example, set the support threshold to 0.03, then item sets with support greater than 0.03 will be retained for subsequent analysis;
[0091] S20302. The calculation of the confidence of association rules is as follows:
[0092] ① Generate association rules: For frequent item sets, generate association rules between different dimensions; for example, from the frequent item set {alarm type = intrusion detection alarm, asset IP = 192.168.1.100, judgment result = not a false alarm, time = 2024-10-01 09:00:00}, the rule "If the alarm type is intrusion detection alarm and the asset IP is 192.168.1.100 and the time is 2024-10-01 09:00:00, then the judgment result is not a false alarm" can be generated;
[0093] ② Calculate confidence: Confidence indicates the probability that the conclusion holds under the premise conditions. Calculate the confidence for each association rule; for example, for the rule "If the alarm type is intrusion detection alarm and the asset IP is 192.168.1.100, then the judgment result is not a false alarm", calculate the proportion of alarms with the judgment result of not a false alarm among all alarms where the alarm type is intrusion detection alarm and the asset IP is 192.168.1.100. Suppose there are 80 alarms that meet the premise conditions, and 60 of them have the judgment result of not a false alarm, then the confidence of this rule is 60 / 80 = 0.75;
[0094] ③ Set the confidence threshold: Set a confidence threshold. Only association rules with confidence greater than the confidence threshold are considered valid rules; for example, set the confidence threshold to 0.7, then association rules with confidence greater than 0.7 will be retained;
[0095] S20303. The false alarm judgment rule is specifically as follows: When a new alarm is generated, match the previously generated association rules according to the alarm type, asset IP, and time information. If the information of the new alarm can match an association rule with a relatively high confidence level, and the judgment results corresponding to the corresponding association rule are all false alarms, then this new alarm is very likely to be a false alarm, and the alarm is marked as a false alarm. On the contrary, if the judgment results corresponding to the matched rules are all non-false alarms, then this new alarm is very likely to be a non-false alarm, and the alarm is marked as a non-false alarm. Then, the alarm is transmitted to the deep learning model for further judgment.
[0096] The construction of the neural network and the setting of hyperparameters in step S3 of this embodiment are specifically as follows:
[0097] ① When using a long short-term memory network (LSTM) for false alarm judgment, first determine the number of layers of the network according to the time series of alarm data to better capture long-term dependencies. At the same time, reasonably set the number of LSTM units in each layer. The number of units determines the learning ability of the deep learning model. Too few units may lead to insufficient learning ability, while too many units may cause overfitting. Finally, connect the layers in sequence. The input layer receives the alarm data processed by multi-dimensional association analysis. The data is transmitted between the layers, and finally the output layer outputs the judgment result on whether the alarm is normal or a false alarm.
[0098] ② The learning rate is a key hyperparameter. The learning rate determines the step size of parameter update in the training process of the deep learning model. In the training of the alarm false alarm model, if the learning rate is too large, the model may skip the optimal solution during training, resulting in non-convergence. If the learning rate is too small, the training speed of the model will be extremely slow, consuming a large amount of time. In the training of the model, through experiments, find a suitable value that can make the loss function of the model decrease rapidly, thereby improving the training performance of the model.
[0099] The model training in step S3 of this embodiment is specifically as follows:
[0100] ① Select the loss function and optimizer: According to the characteristics of the binary classification task of alarm judgment, select the cross-entropy loss function to accurately measure the difference between the predicted value and the true value of the model. And select the Adam optimizer to continuously adjust the model parameters through iterative calculation, so that the loss function gradually converges to the minimum value.
[0101] ② Iterative training: Input the training set data into the deep learning model in batches in an orderly manner. First, perform forward propagation to calculate the predicted value of the model. Then, calculate the error between the predicted value and the true value through the loss function. Finally, perform backpropagation to adjust the model parameters according to the error, realizing the learning and optimization of the model. Among them, during the training process, closely refer to the results of multi-dimensional association analysis and dynamically adjust the training strategy.
[0102] The alarm false alarm judgment and feedback in step S4 of this embodiment are specifically as follows:
[0103] S401. According to the association rules generated by multi-dimensional association analysis, initially judge whether the alarm is a false alarm:
[0104] If the confidence level of the corresponding association rule exceeds the set threshold, add the corresponding mark;
[0105] S402. Input the new alarm into the trained deep learning model. The deep learning model makes real-time judgments on the new alarm according to the learned alarm patterns and feature differences, and outputs the result of whether the corresponding alarm is a normal alarm or a false alarm;
[0106] S403. Feed back the judgment result to the security operation and maintenance personnel, and at the same time record the actual alarm situation and judgment result, and regularly compare and analyze the judgment result and the actual situation;
[0107] At the same time, re-label the alarms with incorrect situations, and regularly send them to the central data storage server together with the correct alarm data as training data to re-mine the association rules and train the model, so as to improve the accuracy of false alarm judgment.
[0108] Embodiment 2:
[0109] As shown in the appendix Figure 1 and 2 This embodiment provides a network security alarm optimization system based on deep learning and multi-dimensional association analysis. The system includes:
[0110] An alarm information collection and storage module, which is used to collect comprehensive and accurate alarm information and processing information from each key node of the network and store them;
[0111] A multi-dimensional association analysis module, which is used to start from four dimensions of time, alarm type, asset IP, and judgment result, and use the Apriori algorithm to mine the association rules between time, alarm type, asset IP, and judgment result, and then judge whether the new alarm is a false alarm;
[0112] A deep learning model construction and training module, which is used to shuffle the alarm data and divide it into a training set and a test set according to a preset ratio, construct a deep learning model by building a neural network and setting hyperparameters, and use the training set to train the deep learning model;
[0113] An alarm false alarm judgment and feedback module, which is used to, when a new alarm log is generated by the host, first judge whether the alarm is a false alarm according to the association rules generated by multi-dimensional association analysis.
[0114] The alarm information collection and storage module in this embodiment includes:
[0115] The data collection sub-module is used to comprehensively evaluate the network architecture of a specified area in order to collect alarm information in the specified area, determine the key nodes in the network, and select corresponding data collectors according to the specificities and interface types of different devices in the network; at the same time, plan the deployment locations of the data collectors and the data transmission paths, and transmit the collected data to the data processing center in a timely and stable manner; among them, the types of alarm information to be collected are also clarified before collection. In addition to common network traffic anomaly data, port scan alarms, and system privilege change reminders, potential security threat alarms should also be considered; and detailed collection strategies are formulated for each type of alarm information to determine the collection frequency and depth, ensuring that the collected alarm information is comprehensive and accurate.
[0116] The processing information association collection sub-module is used to establish a collection mechanism for processing information corresponding to the alarms while collecting alarm information. Specifically, when security personnel process an alarm, record the corresponding measures taken and the judgment result feedback through the management platform to ensure that the processing information can be accurately associated with the alarm information, providing a basis for subsequent analysis of the processing effect and optimization of the alarm judgment model; among them, the measures taken include isolating the infected host, blocking suspicious network connections, installing security patches, and removing malware.
[0117] The data transmission and storage sub-module is used to transmit the collected alarm information and processing information from each data collector to the central data storage server using a data transmission protocol; during the transmission process, encrypt the data to prevent the data from being stolen or tampered with during transmission, and select an appropriate database management system to store the collected data, such as the relational database MySQL or the non-relational database MongoDB, and then make a reasonable selection according to the characteristics of the data and the query requirements, thereby improving the storage and retrieval efficiency.
[0118] The multi-dimensional correlation analysis module in this embodiment includes:
[0119] The alarm information correlation analysis dimension definition sub-module is used to define the time dimension, alarm type dimension, asset IP dimension, and judgment result dimension. Among them, the time dimension records the specific moment when the alarm is generated, and through the analysis of historical alarm false alarm information, it is used to judge the correlation rule between false alarms and time. The alarm type dimension records the alarm type to which each alarm information belongs, and through the analysis of historical alarm false alarm information, it is used to judge the correlation rule between false alarms and alarm types. The asset IP dimension records the asset IP associated with each alarm information, and through the analysis of historical alarm false alarm information, it is used to judge the correlation rule between false alarms and asset IPs. The judgment result dimension records the judgment result information associated with each alarm information, which is divided into two judgment results: false alarm and non-false alarm. Through the analysis of historical alarm false alarm information, it is used to judge the correlation rule between false alarms and judgment result information.
[0120] The data cleaning and preprocessing sub-module is used to clean and preprocess the collected alarm data, eliminate duplicate, incorrect, or incomplete data records, and perform standardization processing on the data to unify the formats and measurement units of data in different dimensions.
[0121] The multi-dimensional association rule mining sub-module is used for item set support calculation, association rule confidence calculation, and false alarm judgment rules. Among them, the item set support calculation is as follows:
[0122] ① Define the item set: Combine different value combinations of alarm types, asset IPs, judgment results, and time into item sets. For example, {alarm type = intrusion detection alarm, asset IP = 192.168.1.100, judgment result = non-false alarm, time = 2024-10-01 09:00:00};
[0123] ② Calculate the support: The support represents the frequency of a certain item set appearing in the dataset. For each item set, calculate the number of times it appears in all alarm data, and then divide by the total number of alarms to obtain the support of this item set. For example, in 1000 alarm data records, {alarm type = intrusion detection alarm, asset IP = 192.168.1.100} appears 50 times, then the support is 0.05;
[0124] ③ Set the support threshold: Set a support threshold according to the actual situation. Only item sets with a support greater than this threshold are considered frequent item sets. For example, set the support threshold to 0.03, then item sets with a support greater than 0.03 will be retained for subsequent analysis;
[0125] The association rule confidence calculation is as follows:
[0126] ① Generate association rules: For frequent item sets, generate association rules between different dimensions; for example, from the frequent item set {Alarm type = Intrusion detection alarm, Asset IP = 192.168.1.100, Judgment result = Non-false alarm, Time = 2024-10-01 09:00:00}, the rule "If the alarm type is an intrusion detection alarm and the asset IP is 192.168.1.100 and the time is 2024-10-01 09:00:00, then the judgment result is non-false alarm" can be generated;
[0127] ② Calculate confidence: Confidence represents the probability that the conclusion holds under the premise conditions. For each association rule, calculate its confidence; for example, for the rule "If the alarm type is an intrusion detection alarm and the asset IP is 192.168.1.100, then the judgment result is non-false alarm", calculate the proportion of alarms with a non-false alarm judgment result among all alarms where the alarm type is an intrusion detection alarm and the asset IP is 192.168.1.100; assume there are 80 alarms that meet the premise conditions, and 60 of them have a non-false alarm judgment result, then the confidence of this rule is 60 / 80 = 0.75;
[0128] ③ Set the confidence threshold: Set a confidence threshold, and only association rules with a confidence greater than this threshold are considered valid rules; for example, set the confidence threshold to 0.7, then association rules with a confidence greater than 0.7 will be retained;
[0129] The false alarm judgment rule is as follows:
[0130] When a new alarm is generated, match the previously generated association rules based on its alarm type, asset IP, and time information; if the information of the new alarm can match an association rule with a relatively high confidence, and the judgment results corresponding to this rule are all false alarms, then this new alarm is very likely to be a false alarm, and mark the alarm as a false alarm; conversely, if the judgment results corresponding to the matched rule are all non-false alarms, then this new alarm is probably a non-false alarm, and mark the alarm as a non-false alarm; then these alarms need to be transmitted to the deep learning model construction and training module for further judgment.
[0131] The deep learning model construction and training module in this embodiment includes:
[0132] The neural network construction sub-module is used to use the long short-term memory network (LSTM) when making false alarm judgments. First, the number of layers of the network needs to be determined according to the time series of the alarm data to better capture long-term dependencies. At the same time, the number of LSTM units in each layer should be reasonably set. The number of units determines the ability of the deep learning model to learn features. Too few units may lead to insufficient learning ability, while too many may cause overfitting. Finally, the layers are connected in sequence. The input layer receives the alarm data processed by multi-dimensional correlation analysis. The data is transmitted between the layers, and finally the output layer outputs the judgment result on whether the alarm is normal or a false alarm.
[0133] The hyperparameter setting sub-module is used to determine the step size of parameter update in the training process of the deep learning model by using the learning rate. In the training of the alarm false alarm model, if the learning rate is too large, the model may skip the optimal solution during training, resulting in non-convergence. If the learning rate is too small, the training speed of the model will be extremely slow, consuming a lot of time. In the training model, through experiments, a suitable value that can make the loss function of the model drop rapidly can be found, so as to improve the performance of model training.
[0134] The model training sub-module is used to select the loss function and optimizer: According to the characteristics of the binary classification task of alarm judgment, the cross-entropy loss function is selected to accurately measure the difference between the predicted value and the true value of the model. And the Adam optimizer is selected to continuously adjust the model parameters through iterative calculation, so that the loss function gradually converges to the minimum value. And the training set data is input into the deep learning model in batches in an orderly manner. First, forward propagation is performed to calculate the predicted value of the model. Then, the error between the predicted value and the true value is calculated through the loss function. Finally, backpropagation is performed to adjust the model parameters according to the error, realizing the learning and optimization of the model. Among them, during the training process, closely refer to the results of multi-dimensional correlation analysis and dynamically adjust the training strategy.
[0135] The specific working process of the alarm false alarm judgment and feedback module in this embodiment is as follows: When the host generates a new alarm log, first, according to the association rules generated by multi-dimensional correlation analysis, initially judge whether the alarm is a false alarm: If the confidence of the corresponding association rule exceeds the set threshold, add the corresponding mark. Then input it into the trained deep learning model. The deep learning model makes a real-time judgment on the new alarm according to the learned alarm patterns and feature differences, and outputs the result of whether the new alarm is a normal alarm or a false alarm. Then, the judgment result is fed back to the security operation and maintenance personnel, and at the same time, the actual alarm situation and judgment result are recorded. Regularly compare and analyze the judgment results and the actual situation. At the same time, re-label the alarms with incorrect situations, and send them to the alarm information collection and storage module together with the correct alarm data as training data at regular intervals to re-mine the association rules and train the model, so as to improve the accuracy of false alarm judgment.
[0136] Embodiment 3:
[0137] This embodiment also provides an electronic device, including: a memory and at least one processor;
[0138] Wherein, the memory stores computer-executable instructions;
[0139] The at least one processor executes the computer-executable instructions stored in the memory, so that the at least one processor executes the network security alert optimization method based on deep learning and multi-dimensional correlation analysis according to any one of the present invention.
[0140] The processor may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), off-the-shelf programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor may be a microprocessor or the processor may also be any conventional processor, etc.
[0141] The memory can be used to store computer programs and / or modules. The processor realizes various functions of the electronic device by running or executing the computer programs and / or modules stored in the memory, and by calling the data stored in the memory. The memory mainly includes a program storage area and a data storage area. Among them, the program storage area can store an operating system, application programs required for at least one function, etc.; the data storage area can store data created according to the use of the terminal, etc. In addition, the memory may further include high-speed random access memory, and may also include non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash memory card, at least one magnetic disk storage period, a flash memory device, or other volatile solid-state storage devices.
[0142] Embodiment 4:
[0143] This embodiment also provides a computer-readable storage medium, in which multiple instructions are stored. The instructions are loaded by the processor to enable the processor to execute the network security alert optimization method based on deep learning and multi-dimensional correlation analysis in any one of the embodiments of the present invention. Specifically, a system or device equipped with a storage medium may be provided, on which software program code for implementing the functions of any one of the above embodiments is stored, and the computer (or CPU or MPU) of the system or device is made to read and execute the program code stored in the storage medium.
[0144] In this case, the program code read from the storage medium itself can implement the functions of any one of the above embodiments. Therefore, the program code and the storage medium storing the program code constitute a part of the present invention.
[0145] Examples of storage media for providing program code include floppy disks, hard disks, magneto-optical disks, optical disks (such as CD-ROM, CD-R, CD-RW, DVD-ROM, DVD-RAM, DVD-RW, DVD+RW), magnetic tapes, non-volatile memory cards, and ROMs. Optionally, the program code can be downloaded from a server computer via a communication network.
[0146] In addition, it should be clear that not only can the actual operations be completed in part or in whole by executing the program code read by the computer, but also by means of instructions based on the program code to cause an operating system or the like operating on the computer to complete the actual operations, thereby implementing the functions of any one of the above embodiments.
[0147] Furthermore, it can be understood that the program code read from the storage medium is written into the memory provided in the expansion board inserted into the computer or into the memory provided in the expansion unit connected to the computer, and then based on the instructions of the program code, the CPU or the like installed on the expansion board or the expansion unit is caused to execute part or all of the actual operations, thereby implementing the functions of any one of the above embodiments.
[0148] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.
Claims
1. A network security alert optimization method based on deep learning and multi-dimensional correlation analysis, characterized in that, The method is as follows: Alarm information collection and storage: Collect comprehensive and accurate alarm information and handling information from each key node of the network and store them; Multi-dimensional correlation analysis: Starting from the four dimensions of time, alarm type, asset IP, and judgment result, use the Apriori algorithm to mine the correlation rules between time, alarm type, asset IP, and judgment result, and then judge whether the new alarm is a false alarm; Deep learning model construction and training: Shuffle the alarm data and divide it into a training set and a test set according to a preset ratio. Build a deep learning model by building a neural network and setting hyperparameters, and use the training set to train the deep learning model; Alarm false alarm judgment and feedback: When a new alarm log is generated by the host, initially judge whether the alarm is a false alarm according to the correlation rules generated by multi-dimensional correlation analysis.
2. The network security alert optimization method based on deep learning and multi-dimensional correlation analysis according to claim 1, characterized in that The specific process of alarm information collection and storage is as follows: Data collection: Conduct a comprehensive evaluation of the network architecture in the specified area, determine the key nodes in the network, and select the corresponding data collectors according to the specific features and interface types of different devices in the network; at the same time, plan the deployment locations of the data collectors and the data transmission paths, and transmit the collected data to the data processing center in a timely and stable manner; among them, the types of alarm information to be collected are also clarified before collection. In addition to network traffic anomaly data, port scan alarms, and system privilege change reminders, potential security threat alarms should also be considered; and detailed collection strategies should be formulated for each type of alarm information to determine the collection frequency and depth to ensure that the collected alarm information is comprehensive and accurate; Associated collection of handling information: While collecting alarm information, establish a collection mechanism for handling information corresponding to the alarms. Specifically: When security personnel handle the alarms, record the corresponding measures taken and the feedback of the judgment results through the management platform to ensure that the handling information can be accurately associated with the alarm information; among them, the measures taken include isolating the infected host, blocking the suspicious network connection, installing security patches, and removing malware; Data transmission and storage: Use a data transmission protocol to transmit the collected alarm information and handling information from each data collector to the central data storage server; during the transmission process, encrypt the data, and select an appropriate database management system to store the collected data, and then make a reasonable selection according to the characteristics of the data and the query requirements.
3. The network security alert optimization method based on deep learning and multi-dimensional correlation analysis according to claim 1, wherein The specific process of multi-dimensional correlation analysis is as follows: Determine the definition of the correlation analysis dimension for alarm information, specifically: The time dimension records the specific moment when the alarm is generated, and through the analysis of historical false alarm information of alarms, it is used to judge the correlation rule between false alarms and time; The alarm type dimension records the alarm type to which each alarm information belongs, and through the analysis of historical false alarm information of alarms, it is used to judge the correlation rule between false alarms and alarm types; The asset IP dimension records the asset IP associated with each alarm information, and through the analysis of historical false alarm information of alarms, it is used to judge the correlation rule between false alarms and asset IPs; The judgment result dimension records the judgment result information associated with each alarm information, which is divided into two judgment results: false alarm and non-false alarm; Through the analysis of historical false alarm information of alarms, it is used to judge the correlation rule between false alarms and judgment result information; Data cleaning and preprocessing: Clean and preprocess the collected alarm data, and eliminate duplicate, incorrect or incomplete data records; And perform standardization processing on the data to unify the formats and measurement units of data in different dimensions; Multi-dimensional association rule mining: including item set support calculation, association rule confidence calculation, and false alarm judgment rules; Among them, the item set support calculation is specifically as follows: Define item sets: Combine different value combinations of alarm types, asset IPs, judgment results, and time into item sets; Calculate support: Support represents the frequency of any item set appearing in the dataset; For each item set, calculate the number of times the corresponding item set appears in all alarm data, and then divide by the total number of alarms to obtain the support of the corresponding item set; Set the support threshold: Set a support threshold according to the actual situation, and only item sets with support greater than the support threshold are considered frequent item sets; The association rule confidence calculation is specifically as follows: Generate association rules: For frequent item sets, generate association rules between different dimensions; Calculate confidence: Confidence represents the probability that the conclusion holds when the preconditions are met. For each association rule, calculate its confidence; Set the confidence threshold: Set a confidence threshold, and only association rules with confidence greater than the confidence threshold are considered valid rules; The false alarm judgment rule is specifically: When a new alarm is generated, match the previously generated association rules according to the alarm type, asset IP, and time information; If the information of the new alarm can match an association rule with a relatively high confidence, and the judgment results corresponding to the corresponding association rule are all false alarms, then this new alarm is very likely to be a false alarm, and mark the alarm as a false alarm; On the contrary, if the judgment results corresponding to the matched rule are all non-false alarms, then this new alarm is probably a non-false alarm, and mark the alarm as a non-false alarm; Then transmit the alarm to the deep learning model for further judgment.
4. The network security alert optimization method based on deep learning and multi-dimensional correlation analysis according to claim 1, characterized in that Build a neural network and set hyperparameters specifically as follows: When making false alarm judgments, use a long short-term memory network. First, determine the number of layers of the network according to the time series of alarm data to better capture long-term dependencies; At the same time, reasonably set the number of LSTM units in each layer. The number of units determines the ability of the deep learning model to learn features; Finally, connect each layer in sequence. The input layer receives the alarm data processed by multi-dimensional correlation analysis. The data is transmitted between layers, and finally the output layer outputs the judgment result on whether the alarm is normal or a false alarm. The learning rate is a key hyperparameter that determines the step size of parameter updates in the deep learning model during training. The model training is as follows: Select the loss function and optimizer: According to the characteristics of the binary classification task of alarm judgment, select the cross-entropy loss function to accurately measure the difference between the model prediction value and the true value; and select the Adam optimizer to continuously adjust the model parameters through iterative calculation to gradually converge the loss function to the minimum value. Iterative training: Input the training set data into the deep learning model batch by batch. First, perform forward propagation to calculate the prediction value of the model; then calculate the error between the prediction value and the true value through the loss function; finally, perform backpropagation to adjust the model parameters according to the error to achieve the learning and optimization of the model. Among them, during the training process, closely refer to the multi-dimensional correlation analysis results and dynamically adjust the training strategy.
5. The network security alert optimization method based on deep learning and multi-dimensional correlation analysis according to any one of claims 1-4, characterized in that The alarm false alarm judgment and feedback are as follows: According to the association rules generated by multi-dimensional correlation analysis, initially judge whether the alarm is a false alarm: If the confidence level of the corresponding association rule exceeds the set threshold, add the corresponding mark. Input the new alarm into the trained deep learning model. The deep learning model makes a real-time judgment on the new alarm according to the learned alarm patterns and feature differences, and outputs the result on whether the corresponding alarm is a normal alarm or a false alarm. Feed back the judgment result to the security operation and maintenance personnel, and at the same time record the actual alarm situation and judgment result, and regularly compare and analyze the judgment result and the actual situation. At the same time, re-label the alarms with incorrect situations and regularly send them to the central data storage server together with the correct alarm data as training data to re-mine the association rules and train the model, so as to improve the accuracy of false alarm judgment.
6. A network security alert optimization system based on deep learning and multi-dimensional correlation analysis, characterized in that, The system includes: An alarm information collection and storage module for collecting comprehensive and accurate alarm information and processing information from various key nodes of the network and storing them. A multi-dimensional correlation analysis module for starting from four dimensions of time, alarm type, asset IP, and judgment result, mining the association rules between time, alarm type, asset IP, and judgment result through the Apriori algorithm, and then judging whether the new alarm is a false alarm. A deep learning model construction and training module for randomly shuffling the alarm data and dividing it into a training set and a test set according to a preset ratio, constructing a deep learning model by building a neural network and setting hyperparameters, and training the deep learning model using the training set. An alarm false alarm judgment and feedback module for initially judging whether the alarm is a false alarm according to the association rules generated by multi-dimensional correlation analysis when a new alarm log is generated on the host.
7. The network security alert optimization system based on deep learning and multi-dimensional correlation analysis according to claim 6, characterized in that The alarm information collection and storage module includes: The data collection submodule is used to comprehensively evaluate the network architecture of the designated area, identify the key nodes in the network, and select the corresponding data collector according to the specific and interface types of different devices in the network; at the same time, plan the deployment location and data transmission path of the data collector, and transmit the collected data to the data processing center in a timely and stable manner; before collection, the types of alarm information that need to be collected are also clearly defined. In addition to network traffic anomaly data, port scan alarms and system permission change reminders, potential security threat alarms should also be considered; and a detailed collection strategy is formulated for each type of alarm information, and the frequency and depth of collection are determined to ensure that the collected alarm information is comprehensive and accurate; The processing information association collection submodule is used to establish a processing information collection mechanism corresponding to the alarm while collecting alarm information. Specifically, when security personnel handle the alarm, the corresponding measures taken and the judgment result feedback are recorded through the management platform to ensure that the processing information and the alarm information can be accurately associated; the measures taken include isolating infected hosts, blocking suspicious network connections, installing security patches, and removing malicious software; The data transmission and storage submodule is used to transmit the collected alarm information and processing information from each data collector to the central data storage server using the data transmission protocol; during the transmission process, the data is encrypted and the corresponding database management system is selected to store the collected data, and then a reasonable selection is made according to the characteristics of the data and the query requirements; The multi-dimensional correlation analysis module includes: The alarm information association analysis dimension definition submodule is used to define the time dimension, alarm type dimension, asset IP dimension and judgment result dimension; among them, the time dimension records the specific time when the alarm is generated, and is used to judge the association rule between false alarms and time through the analysis of historical alarm false alarm information; the alarm type dimension records the alarm type to which each alarm information belongs, and is used to judge the association rule between false alarms and alarm types through the analysis of historical alarm false alarm information; the asset IP dimension records the asset IP associated with each alarm information, and is used to judge the association rule between false alarms and asset IP through the analysis of historical alarm false alarm information; the judgment result dimension records the judgment result information associated with each alarm information, which is divided into two judgment results: false alarm and non-false alarm; through the analysis of historical alarm false alarm information, it is used to judge the association rule between false alarms and judgment result information; The data cleaning and preprocessing submodule is used to clean and preprocess the collected alarm data, remove duplicate, erroneous or incomplete data records, and standardize the data to unify the format and measurement unit of data of different dimensions; The multi-dimensional association rule mining submodule is used for item set support calculation, association rule confidence calculation and false alarm judgment rules.
8. The network security alert optimization system based on deep learning and multi-dimensional correlation analysis according to claim 6 or 7, characterized in that, The deep learning model building and training modules include: A neural network construction sub-module, which uses a long short-term memory network for false alarm judgment. First, it is necessary to determine the number of layers of the network according to the time series of alarm data to better capture long-term dependencies. At the same time, reasonably set the number of LSTM units in each layer. The number of units determines the ability of the deep learning model to learn features. Finally, connect each layer in sequence. The input layer receives the alarm data processed by multi-dimensional correlation analysis. The data is transmitted between layers, and finally the output layer outputs the judgment result of whether the alarm is normal or a false alarm. A hyperparameter setting sub-module, which is used to adopt a learning rate to determine the step size of parameter update in the training process of the deep learning model. A model training sub-module, which is used to select a loss function and an optimizer: According to the characteristics of the binary classification task of alarm judgment, select the cross-entropy loss function to accurately measure the difference between the predicted value and the true value of the model; and select the Adam optimizer to continuously adjust the model parameters through iterative calculation to make the loss function gradually converge to the minimum value; and input the training set data into the deep learning model in batches in an orderly manner. First, perform forward propagation to calculate the predicted value of the model; then calculate the error between the predicted value and the true value through the loss function; finally, perform backward propagation to adjust the model parameters according to the error to achieve the learning and optimization of the model. Among them, during the training process, closely refer to the multi-dimensional correlation analysis results and dynamically adjust the training strategy. The specific working process of the alarm false alarm judgment and feedback module is as follows: When a new alarm log is generated by the host, first, according to the association rules generated by multi-dimensional correlation analysis, initially judge whether the alarm is a false alarm: If the confidence level of the corresponding association rule exceeds the set threshold, add the corresponding mark; then input it into the trained deep learning model. The deep learning model makes a real-time judgment on the new alarm according to the learned alarm patterns and feature differences, and outputs the result of whether the new alarm is a normal alarm or a false alarm; then feedback the judgment result to the security operation and maintenance personnel, and at the same time record the actual alarm situation and judgment result. Regularly compare and analyze the judgment results and the actual situation; at the same time, re-label the alarms with incorrect situations and send them to the alarm information collection and storage module together with the correct alarm data as training data to re-mine the association rules and train the model, so as to improve the accuracy of false alarm judgment.
9. An electronic device, characterized in that, Including: A memory and at least one processor; Wherein, the memory stores computer execution instructions; The at least one processor executes the computer execution instructions stored in the memory, so that the at least one processor executes the network security alarm optimization method based on deep learning and multi-dimensional correlation analysis as described in any one of claims 1 to 5.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer execution instructions. When the processor executes the computer execution, the network security alarm optimization method based on deep learning and multi-dimensional correlation analysis as described in any one of claims 1 to 5 is implemented.