Network security situation visualization method

By obtaining and filtering network situation information in real time, building a visual database and using advanced network models to identify threats, the data complexity and real-time problems in network security situation awareness are solved, and efficient and accurate threat identification and decision support are achieved.

CN120415872APending Publication Date: 2025-08-01HAINAN POWER GRID CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510730903.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-03
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

The existing network security situation awareness visualization technology has problems such as huge and complex data volume, difficulty in identifying threats, difficult analysis results, and insufficient real-time performance, resulting in insufficient detection accuracy and timeliness.

Method used

By obtaining network situation information in real time, filtering out data with visual characteristics, building a visual database, using graph convolutional neural network and long and short-term memory network to extract situation and timing features, combining cluster analysis and Markov chain model to identify potential threats, and visually display them.

Benefits of technology

It realizes rapid perception of dynamic changes in the network, accurately identify potential threats, improve the accuracy and efficiency of threat detection, optimize resource allocation, simplify the understanding of analysis results, and support rapid decision-making.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120415872A_ABST
    Figure CN120415872A_ABST
Patent Text Reader

Abstract

The invention provides a network security situation visualization method, and the method comprises the steps: S11, obtaining current network situation information in real time, screening the network situation information, obtaining situation information with visual features, and constructing a visual database; s12, performing feature extraction on the data in the visual database, analyzing the extracted features to distinguish security features and abnormal features, quantifying the network security state according to the abnormal features, and evaluating the threat degree of the network situation; s13, performing behavior detection on the data in the visual database, and identifying potential security threats in combination with threat degrees; and S14, carrying out visual display on analysis results of the steps S12 and S13. Through real-time acquisition, feature extraction, threat assessment and visual display, the problems of complex data, difficulty in threat identification and difficulty in understanding analysis results in network situation awareness are solved, and the efficiency and accuracy of network security management are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly to a method for visualizing network security situation. Background Art

[0002] With the rapid development of Internet technology and the continuous deepening of informatization construction, the network security threats faced by computer information systems are becoming increasingly serious. During the operation of existing computer systems, network security problems still cannot be completely overcome, and it is difficult to cope with the complex and changeable network attack environment. As a new technology, network situation visualization technology is the combination of network security situation awareness and visualization technology. It displays the situation contained in the network to users in the form of visual graphics, and with the help of the powerful processing ability of people in graphics and images, it realizes the analysis and detection of network abnormal behaviors. This method fully combines the advantages of the processing capabilities of computers and human brains in image processing, improves the comprehensive analysis ability of data, can effectively reduce the false alarm rate and missed alarm rate, improve the system detection efficiency, and reduce the response time. And this visualization method also has a certain predictive ability for some abnormal behaviors with obvious characteristics.

[0003] There are many problems in the existing network security situation awareness and visualization technology: First, the data volume is huge and complex, the direct analysis efficiency is low, and it is difficult to quickly extract key features; second, threat identification is difficult, and traditional methods are difficult to accurately distinguish normal and abnormal behaviors, resulting in insufficient detection accuracy and timeliness; third, the analysis results are difficult to intuitively understand, increasing the burden on analysts and affecting decision-making efficiency; fourth, the real-time performance is insufficient, and it is unable to quickly respond to the dynamic changes of the network environment. In this context, it is of great significance to study the data integration and visualization system based on network security situation awareness. Summary of the Invention

[0004] In view of this, the purpose of the present invention is to provide a method for visualizing network security situation, which solves the problems of complex data, difficult threat identification, difficult-to-understand analysis results, and insufficient real-time performance in the prior art by obtaining network situation information in real time and screening out data with visualization features.

[0005] To achieve the above-mentioned invention purpose, the present invention provides a method for visualizing network security situation, and the method includes:

[0006] S11. Obtain the current network situation information in real time, screen the network situation information, obtain the situation information with visualization features, and construct a visualization database;

[0007] S12. Extract the features of the data in the visualization database, analyze the extracted features to distinguish security features and abnormal features, quantify the network security status according to the abnormal features, and evaluate the threat level of the network situation;

[0008] S13. Detect the behavior of the data in the visualization database, and identify potential security threats in combination with the threat level;

[0009] S14. Visualize and display the analysis results of steps S12 and S13.

[0010] Furthermore, screen the network situation information, specifically including:

[0011] S21. Based on the network situation information, construct an original data matrix, perform a normalization operation on each element in the original data matrix to obtain a normalized matrix;

[0012] S22. Calculate the average value and standard deviation of the normalized matrix, and calculate the coefficient of variation of each element in the normalized matrix based on the average value and standard deviation;

[0013] S23. After sorting the coefficient of variation of each element in the normalized matrix according to the preset rules, screen out the target elements greater than or equal to the preset threshold.

[0014] Furthermore, construct a visualization database, specifically including:

[0015] S31. Calculate the correlation between each element in the original data matrix and the target element, and classify the elements with a correlation greater than or equal to the preset threshold as the situation information with visualization characteristics;

[0016] S32. Based on the preset rules, extract entity, relationship, and attribute information from the situation information with visualization characteristics to construct a network situation knowledge framework;

[0017] S33. Convert the entities and relationships in the network situation knowledge framework into a graph data structure, where the entities are used as nodes and the relationships are used as edges, and define a feature vector for each node;

[0018] S34. Construct an adjacency matrix and use the node feature vectors to describe the nodes and edges in the network situation knowledge framework to construct a visualization database based on the graph data.

[0019] Furthermore, extract features from the data in the visualization database, specifically including:

[0020] S41. Extract the situation feature of the graph data in the visualization database through a graph convolutional neural network to obtain a situation vector feature;

[0021] S42. Extract the time series feature of the graph data in the visualization database through a long short-term memory network to obtain a time series vector feature;

[0022] S43. Add the situation vector feature and the time series vector feature, process them through an activation function, and then perform feature fusion through a fully connected layer to complete the extraction of features.

[0023] Further, analyze the extracted features, specifically including:

[0024] S51. Randomly select N sample points from the extracted features as the initial clustering centers, and calculate the distance from each remaining sample point in the extracted features to each clustering center.

[0025] S52. Assign each sample point to the cluster where the clustering center with the closest distance to itself is located, and recalculate the center point of each cluster.

[0026] S53. Compare whether the new center point of each cluster is the same as the initial clustering center. If they are the same, the clustering process is completed. If not, return to step S52.

[0027] S54. Output the center point of each cluster, and perform similarity analysis on the center point of each cluster. If the similarity is greater than or equal to the preset threshold, it is determined as a security feature. If the similarity is less than the preset threshold, it is determined as an abnormal feature.

[0028] Further, evaluate the threat level of the network situation, specifically including:

[0029] S61. Analyze the data difference between the security feature and the abnormal feature, and use the ratio of the data difference to the extracted feature as the attack threat coefficient of the current network event.

[0030] S62. Perform anomaly assessment on the current network situation according to the attack threat coefficient, and classify the security risks faced by the network situation.

[0031] Further, perform behavior detection on the data in the visualization database, and identify potential security threats in combination with the threat level, specifically including:

[0032] S71. Use the key assets in the visualization database as the nodes of the attack graph. The edges of the attack graph represent possible attack paths. Use expert experience to evaluate the success probability and threat level of the attack paths, and use the obtained evaluation values as the weights of the edges.

[0033] S72. Convert the attack graph into a Markov chain model, and define the states of the key assets in the network as the states in the Markov chain, including normal state, suspicious state, and abnormal state. Each state corresponds to a node in the attack graph.

[0034] S73. Calculate the state transition probability of converting the security feature into the abnormal feature, construct a state transition matrix in combination with the threat level, and determine the current network state.

[0035] S74. Calculate the probabilities of transitioning from the current state to other states based on the state transition probability matrix and the weights of the edges, and identify the probabilities greater than or equal to the preset threshold as potential security threats.

[0036] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0037] A network security situation visualization method provided by the present invention can quickly perceive the dynamic changes in the network and provide support for timely response by obtaining network situation information in real time and screening out the data with visualization features; it can accurately identify potential threats and improve the accuracy of threat detection by distinguishing security features and abnormal features through feature extraction and analysis and quantifying the network security state; it can identify potential security threats, optimize resource allocation, and improve the efficiency of security management through behavior detection and threat level assessment; the analysis results are displayed in a visual form, making complex security data more intuitive and easy to understand, facilitating quick decision-making and situation understanding. The present invention solves the problems of complex data, difficult threat identification, difficult-to-understand analysis results, and insufficient real-time performance in the prior art by obtaining network situation information in real time and screening out the data with visualization features, significantly improving the efficiency and accuracy of network security situation awareness and providing strong support for network security management. Description of the Drawings

[0038] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0039] Figure 1 It is a schematic flowchart of a network security situation visualization method provided by an embodiment of the present invention. Detailed Embodiments

[0040] The following will further elaborate on the present invention in conjunction with the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the present invention, rather than limiting the present invention. Additionally, it should be noted that for the sake of description, only the parts related to the present invention are shown in the drawings rather than all the structures.

[0041] Refer to Figure 1 , this embodiment provides a network security situation visualization method, and the method includes:

[0042] S11. Obtain the current network situation information in real time, screen the network situation information, obtain the situation information with visualization features, and construct a visualization database.

[0043] In this embodiment, in order to cope with the complexity and real-time requirements of network situation information, the network situation information is obtained in real time and the situation information with visualization features is screened out to construct a visualization database, so as to convert complex data into structured information with visualization features, which is convenient for subsequent feature extraction, threat recognition and visualization display.

[0044] Specifically, the situation information with visualization features includes but is not limited to the following aspects: Network traffic data can be displayed in the form of traffic graphs, heat maps, etc., to help analysts identify traffic anomalies and potential attack behaviors, including the size, direction, protocol type, etc. of the traffic. Network node information can be displayed in the form of node status graphs, topology graphs, etc., to help analysts monitor key nodes of the network, including the status and performance indicators of network devices such as hosts, servers, routers, etc., such as CPU usage rate, memory usage rate, etc. Security event data can be displayed in the form of event timelines, attack path graphs, etc., to help analysts track and analyze security events, including event logs recorded by security devices such as intrusion detection systems (IDS), firewalls, etc., such as the source IP of the attack, attack type, attack time, etc. Threat intelligence data can be displayed in the form of threat maps, intelligence panels, etc., to help analysts understand the current threat situation, including known threat information, vulnerability information, malware characteristics, etc. Behavior pattern data can be displayed in the form of behavior pattern graphs, trend graphs, etc., to help analysts identify abnormal behaviors, including the patterns and trends of user behaviors, application behaviors, etc., such as login frequency, data access patterns, etc.

[0045] The screening of network situation information specifically includes:

[0046] S21. Based on the network situation information, construct an original data matrix, and perform a normalization operation on each element in the original data matrix to obtain a normalized matrix.

[0047] S22. Calculate the average value and standard deviation of the normalized matrix, and calculate the coefficient of variation of each element in the normalized matrix based on the average value and standard deviation.

[0048] S23. After sorting the coefficient of variation of each element in the normalized matrix according to a preset rule, screen out the target elements greater than or equal to the preset threshold.

[0049] In this embodiment, through the coefficient of variation method, the situation information with visualization features in the network situation information can be effectively screened out, that is, the key situation elements that have a greater impact on the network security situation, thereby reducing the data dimension and improving the efficiency and accuracy of subsequent analysis.

[0050] Specifically, collect network situation information from sources such as network devices and system logs, organize it into a structured data format to construct an original data matrix, apply a normalization formula to each element in the original data matrix, calculate the normalized values, and form a normalized matrix. Each element in the network situation information may have different dimensions and value ranges. The normalization operation can convert these data of different scales to the same scale, enabling data of different indicators to be compared on the same scale, facilitating subsequent comparison and analysis, such as between 0 and 1.

[0051] For each element in the normalized matrix, calculate its mean and standard deviation. Based on the mean and standard deviation, calculate the coefficient of variation for each element. The coefficient of variation is equal to the standard deviation divided by the mean. The coefficient of variation is a relative indicator that is not affected by the absolute values of the data and can measure the degree of dispersion of the data, reflecting the changes of each element in the network situation. It helps to identify elements that are sensitive to situation changes, screen out elements with high variability, and provide a data basis for subsequent situation awareness and analysis.

[0052] According to actual needs and experience, set a reasonable threshold for the coefficient of variation to distinguish key elements from non-key elements. Sort the coefficients of variation of each element in the normalized matrix in descending order, and then screen out the target elements whose coefficients of variation are greater than or equal to the preset threshold. The coefficient of variation screening process can help determine which elements have a significant impact on the network situation and are directly related to the security and stability of the network. Therefore, the target elements can intuitively reflect the operating state and security status of the network situation. In the situation information with visualization features, the priority can be determined according to the size of the coefficient of variation of the target elements. The larger the coefficient of variation of an element, the higher its visualization priority, and it should be displayed first.

[0053] Construct a visualization database, specifically including:

[0054] S31. Calculate the correlation between each element in the original data matrix and the target elements, and classify the elements whose correlation is greater than or equal to the preset threshold as situation information with visualization features.

[0055] S32. Based on preset rules, extract entity, relationship, and attribute information from the situation information with visualization features to construct a network situation knowledge framework.

[0056] S33. Convert the entities and relationships in the network situation knowledge framework into a graph data structure, where entities are nodes and relationships are edges, and define a feature vector for each node.

[0057] S34. Construct an adjacency matrix and use the node feature vectors to describe the nodes and edges in the network situation knowledge framework to construct a visualization database based on graph data.

[0058] In this embodiment, constructing a visualization database can present complex data in an intuitive and easy-to-understand manner, thereby helping users, network administrators, and security analysts quickly obtain key information, and providing timely and accurate situational information for subsequent visualization processing. By screening and focusing on key elements, the burden of data processing and storage is reduced, the performance and efficiency of the system are improved, and resources are prevented from being wasted on unimportant data.

[0059] Specifically, the elements in the original data matrix are processed such as cleaning and normalizing to ensure the quality and consistency of the data. The correlation between each element and the target element is calculated through a correlation algorithm. According to actual requirements and experience, a correlation threshold is set, such as 0.5 or 0.7, to screen out situational information with visualization characteristics. Rules are defined based on domain knowledge and expert experience for identifying and extracting entity, relationship, and attribute information, and the rules include regular expressions, pattern matching, natural language processing techniques, etc.

[0060] Using the defined rules, entities, relationships, and attributes are extracted from the situational information with visualization characteristics. Entities include devices, and user relationships include connections and attacks. Attributes include time and frequency. The extracted entity, relationship, and attribute information are integrated into a standardized network situational knowledge framework to form a structured knowledge representation. The entities are used as nodes in the graph, and the relationships are used as edges in the graph to construct a graph data model. A feature vector is defined for each node in the graph data model to describe the attributes and states of the node, such as device type, traffic characteristics, etc. The constructed graph data is stored in the database. An adjacency matrix is constructed to represent the connection relationships between nodes, and the elements in the matrix represent the weights or intensities between nodes. The feature vectors of the nodes are integrated into the graph data so that these information can be fully utilized during visualization and analysis, optimizing the query and storage performance of the graph database and ensuring the efficient access and processing of data.

[0061] S12: Extract features from the data in the visualization database, analyze the extracted features to distinguish security features and abnormal features, and quantify the network security status according to the abnormal features to evaluate the threat level of the network situation.

[0062] In this embodiment, extracting features from the data in the visualization database can identify the key features that are most valuable for network security situation awareness, reduce the data dimension, and improve the analysis efficiency. By quantifying the abnormal features, the network security status can be converted into specific numerical values or metrics, which is convenient for objective evaluation and comparison. Based on the quantification results, the threat level of the network situation can be evaluated, and appropriate protection measures can be taken in a timely manner.

[0063] Extracting features from the data in the visualization database specifically includes:

[0064] S41. Extract the situation features of the graph data in the visualization database through a graph convolutional neural network to obtain situation vector features.

[0065] S42. Extract the temporal features of the graph data in the visualization database through a long short-term memory network to obtain temporal vector features.

[0066] S43. Add the situation vector features and the temporal vector features, process them through an activation function, and perform feature fusion through a fully connected layer to complete the extraction of features.

[0067] In this embodiment, the graph convolutional neural network can effectively capture the spatial structure features in the graph data, such as the connection relationship and attribute information between nodes, so as to extract the situation vector features. The long short-term memory network can process time series data and capture the temporal features in the graph data, such as the change trend of network traffic over time, so as to extract the temporal vector features. By adding the situation vector features and the temporal vector features and performing feature fusion through an activation function and a fully connected layer, a more comprehensive and richer feature representation is obtained, improving the expression ability and discrimination of the features. By fusing the spatial and temporal features, the dynamic changes of the network situation can be more accurately reflected, improving the performance and generalization ability of the model, so as to capture various features and relationships in the network and provide stronger support for network security situation awareness.

[0068] Specifically, by extracting the situation features and temporal features of network traffic, DDoS attacks can be detected more accurately, improving the accuracy and timeliness of detection. By analyzing the situation features and temporal features of user behavior, abnormal user behaviors can be identified, such as frequent login failures, activities at abnormal times, etc., and potential security threats can be discovered in a timely manner. By capturing the spatial and temporal features in the network, network intrusion behaviors can be detected more effectively, improving the performance and reliability of the intrusion detection system.

[0069] Analyze the extracted features, specifically including:

[0070] S51. Randomly select N sample points from the extracted features as the initial cluster centers, and calculate the distance from each remaining sample point in the extracted features to each cluster center.

[0071] S52. Assign each sample point to the cluster where the cluster center closest to itself is located, and recalculate the center point of each cluster.

[0072] S53. Compare whether the new center point of each cluster is the same as the initial cluster center. If it is the same, the clustering process is completed. If it is different, return to step S52.

[0073] S54. Output the center point of each cluster, and conduct similarity analysis on the center points of each cluster. If the similarity is greater than or equal to the preset threshold, it is determined as a security feature; if the similarity is less than the preset threshold, it is determined as an abnormal feature.

[0074] In this embodiment, the clustering method divides similar data points into the same cluster by calculating the similarity or distance between data points, and divides dissimilar data points into different clusters. The grouping based on similarity can naturally divide the data into different categories. In network security, normal security features usually have similar patterns and behaviors, while abnormal features show different patterns and behaviors. Through clustering, these different patterns and behaviors can be divided into different clusters. The behaviors and patterns of normal security features are relatively consistent and usually form relatively dense clusters in the feature space. The behaviors and patterns of abnormal features are significantly different from those of normal features and usually appear as outliers or small clusters in the feature space. The center point (centroid) of each cluster represents the typical features of the cluster. By analyzing the center point, normal features and abnormal features can be identified. By calculating the similarity of the data points within the cluster, the stability and consistency of the cluster can be further confirmed. Clusters with high similarity usually represent normal features, while clusters with low similarity or outliers usually represent abnormal features.

[0075] Specifically, classify the network traffic features through a clustering algorithm to identify normal traffic and abnormal traffic, and improve the performance of the intrusion detection system. Cluster the user behavior features to identify normal user behaviors and abnormal user behaviors, and timely discover potential security threats. Cluster the state features of network devices to monitor the running status of the devices and timely discover device failures or abnormalities.

[0076] Evaluate the threat level of the network situation, specifically including:

[0077] S61. Analyze the data differences between security features and abnormal features, and use the ratio of the data differences to the extracted features as the attack threat coefficient of the current network event;

[0078] S62. Conduct abnormal assessment on the current network situation according to the attack threat coefficient, and classify the security risks faced by the network situation.

[0079] In this embodiment, by comparing the data differences between security features and abnormal features, normal behaviors and abnormal behaviors can be distinguished. The data differences can help identify potential threats, such as abnormal network traffic, user behaviors, or device states. By calculating the ratio of the data differences to the extracted features, the attack threat coefficient can be obtained, thereby quantifying the potential danger level of the current network event. Based on the attack threat coefficient, the security risks faced by the network situation can be classified, such as low risk, medium risk, high risk, etc.

[0080] S13. Conduct behavior detection on the data in the visualization database, and identify potential security threats in combination with the threat level. Specifically, it includes:

[0081] S71. Use the key assets in the visualization database as the nodes of the attack graph. The edges of the attack graph represent possible attack paths. Utilize expert experience to evaluate the success probability and threat level of the attack paths, and use the obtained evaluation values as the weights of the edges.

[0082] S72. Convert the attack graph into a Markov chain model. Define the states of the key assets in the network as the states in the Markov chain, including normal state, suspicious state, and abnormal state. Each state corresponds to a node in the attack graph.

[0083] S73. Calculate the state transition probability of converting security features into abnormal features, construct a state transition matrix in combination with the threat level, and determine the current network state.

[0084] S74. According to the state transition probability matrix and the weights of the edges, calculate the probability of transitioning from the current state to other states. Identify the probabilities greater than or equal to the preset threshold as potential security threats.

[0085] In this embodiment, by constructing an attack graph, the key assets and possible attack paths in the network are intuitively displayed, and it can be dynamically adjusted according to the changes in the network environment, and new attack paths and risks can be reflected in a timely manner. Evaluating the success probability and threat level of the attack paths can quantify the risks of each attack path, provide a scientific basis for security decision-making, and using the evaluation values as the weights of the edges can identify high-risk attack paths and take protective measures preferentially. Converting the attack graph into a Markov chain model can dynamically model the state changes of network assets, quantify the risks of attack paths, and support real-time evaluation and decision-making, thus effectively identifying and dealing with potential threats.

[0086] S14. Visually display the analysis results of steps S12 and S13.

[0087] In this embodiment, to visually display the analysis results of steps S12 and S13, first select a visualization tool, such as Gephi, D3.js, or Tableau, etc. Then, organize the processed data into the format required by the visualization tool, and design the visualization layout, including the representation of nodes and edges, as well as the visualization methods of weights and states. The interaction design allows users to interact with the visualization results through functions such as hover tips, filtering, and searching. Subsequently, use the selected tool to implement the design, construct a network diagram, and add interaction functions. After completing the visualization, display the results in the form of a dashboard or report, and conduct usability testing and user feedback collection to evaluate the effectiveness of the visualization and perform continuous optimization.

[0088] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for visualizing network security situation, characterized in that, The method includes: S11. Obtain the current network situation information in real time, screen the network situation information, obtain the situation information with visualization features, and construct a visualization database; S12. Extract features from the data in the visualization database, analyze the extracted features to distinguish security features and abnormal features, quantify the network security status according to the abnormal features, and evaluate the threat level of the network situation; S13. Conduct behavior detection on the data in the visualization database, and identify potential security threats in combination with the threat level; S14. Visualize and display the analysis results of steps S12 and S13.

2. The network security situation visualization method according to claim 1, characterized in that Screening the network situation information specifically includes: S21. Based on the network situation information, construct an original data matrix, perform normalization operations on each element in the original data matrix to obtain a normalized matrix; S22. Calculate the average value and standard deviation of the normalized matrix, and calculate the coefficient of variation of each element in the normalized matrix based on the average value and standard deviation; S23. After sorting the coefficient of variation of each element in the normalized matrix according to a preset rule, screen out the target elements greater than or equal to the preset threshold.

3. The network security situation visualization method according to claim 2, wherein Constructing the visualization database specifically includes: S31. Calculate the correlation between each element in the original data matrix and the target element, and divide the elements with a correlation greater than or equal to the preset threshold into situation information with visualization features; S32. Based on a preset rule, extract entity, relationship, and attribute information from the situation information with visualization features to construct a network situation knowledge framework; S33. Convert the entities and relationships in the network situation knowledge framework into a graph data structure, where entities are used as nodes and relationships are used as edges, and define feature vectors for each node; S34. Construct an adjacency matrix and use node feature vectors to describe the nodes and edges in the network situation knowledge framework to construct a visualization database based on graph data.

4. The network security situation visualization method according to claim 3, wherein, Extracting features from the data in the visualization database specifically includes: S41. Extract the situation features of the graph data in the visualization database through a graph convolutional neural network to obtain situation vector features; S42. Extract the time series features of the graph data in the visualization database through a long short-term memory network to obtain time series vector features; S43. Add the situation vector features and the time series vector features, process them through an activation function, and perform feature fusion through a fully connected layer to complete the extraction of features.

5. The network security situation visualization method according to claim 1, characterized in that, Analyzing the extracted features specifically includes: S51. Randomly select N sample points from the extracted features as initial clustering centers, and calculate the distance from each remaining sample point in the extracted features to each clustering center; S52. Assign each sample point to the cluster where the clustering center closest to itself is located, and recalculate the center point of each cluster; S53. Compare whether the new center point of each cluster is the same as the initial clustering center. If they are the same, the clustering process is completed. If they are different, return to step S52; S54. Output the center point of each cluster, perform similarity analysis on the center point of each cluster. If the similarity is greater than or equal to the preset threshold, it is determined as a security feature. If the similarity is less than the preset threshold, it is determined as an abnormal feature.

6. The network security situation visualization method according to claim 1, characterized in that Evaluate the threat level of the network situation, specifically including: S61. Analyze the data difference between security features and abnormal features, and use the ratio of the data difference to the extracted features as the attack threat coefficient of the current network event; S62. Conduct an abnormal evaluation of the current network situation according to the attack threat coefficient, and classify the security risks faced by the network situation.

7. The network security situation visualization method according to claim 6, wherein Conduct behavior detection on the data in the visualization database, and identify potential security threats in combination with the threat level, specifically including: S71. Use the key assets in the visualization database as the nodes of the attack graph. The edges of the attack graph represent possible attack paths. Use expert experience to evaluate the success probability and threat level of the attack paths, and use the obtained evaluation values as the weights of the edges; S72. Convert the attack graph into a Markov chain model, and define the states of the key assets in the network as the states in the Markov chain, including normal state, suspicious state, and abnormal state. Each state corresponds to a node in the attack graph; S73. Calculate the state transition probability of security features being converted into abnormal features, construct a state transition matrix in combination with the threat level, and determine the current network state; S74. According to the state transition probability matrix and the weights of the edges, calculate the probability of transitioning from the current state to other states, and identify the probability greater than or equal to the preset threshold as a potential security threat.

Citation Information

Cited By

  • Radiology department image data distributed storage method and system based on homomorphic encryption

    CN120892395A