Computer network security situation analysis method and device and electronic equipment
By laying distributed data acquisition nodes in the network, using dynamic aggregation algorithm and isolated forest algorithm to generate cumulative effect maps, and dynamically adjusting security thresholds in combination with reinforcement learning algorithms, the problem of difficult to identify the cumulative effect of micro attack behaviors in the existing technology is solved, and efficient network security situation awareness and protection are achieved.
Patent Information
- Application Number
- CN202510840790.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-23
- Publication Date
- 2025-08-15
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing network security protection technologies are difficult to dynamically identify and analyze the cumulative effects of micro attack behaviors, resulting in frequent occurrence of false alarms and missed reports, affecting the timeliness and accuracy of protection.
By laying distributed data acquisition nodes in the network, data on abnormal small-scale data packet transmission, port scanning behavior and small attack behavior for long-term sessions are collected, dynamic aggregation algorithm and isolated forest algorithm are used to generate cumulative effect maps, and combined with reinforcement learning algorithms to dynamically adjust security thresholds to automatically generate protection strategies.
Accurate time and space correlation analysis of micro attack behaviors is realized, the accuracy of network security situation awareness and the response speed of protection strategies is improved, false alarms and missed alarms are reduced, and efficient security protection of the network in complex environments is ensured.
Smart Images

Figure CN120498860A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a computer network security situation analysis method, device and electronic equipment. Background Art
[0002] With the rapid development of Internet technology, computer networks have become an indispensable infrastructure in all areas of society. However, with the expansion of network scale and the increase in complexity, network security threats have also shown a trend of diversification and concealment. Traditional security protection measures have become difficult to cope with modern complex attack behaviors. Micro-attack behaviors, such as small-scale data packet transmission anomalies, low-frequency port scans, and long-term sessions, usually do not cause system security alerts alone, but the cumulative effect of these behaviors within a certain time and space range may lead to serious security risks. Therefore, how to effectively identify and defend against these micro-attack behaviors has become an important topic in current network security research.
[0003] Existing network security protection technologies often rely on static rules or single anomaly detection methods, making it difficult to dynamically correlate and analyze micro-attack behaviors across time and space. This is particularly true when it comes to identifying the cumulative effects of these behaviors. Furthermore, existing systems lack intelligence in dynamically adjusting protection strategies, often relying on manually set security thresholds. This leads to frequent false positives and false negatives, compromising the timeliness and accuracy of protection. Therefore, there is an urgent need for a method that can dynamically identify and analyze the cumulative effects of micro-attack behaviors and automatically adjust protection strategies to improve the accuracy and efficiency of network security situational awareness. Summary of the Invention
[0004] Based on the above objectives, the present invention provides a computer network security situation analysis method, device and electronic equipment.
[0005] The computer network security situation analysis method includes the following steps: S1: Distributed data collection nodes are deployed in the network to collect data on abnormal small-scale data packet transmissions, port scanning behaviors, and micro-attack behaviors of long-term sessions. The data includes timestamps, event sources, and network node locations. S2: Aggregate the data collected in S1 and use a dynamic aggregation algorithm to analyze the correlation between microaggressions based on the timestamps of events and network node location information. Generate a cumulative effect graph to correlate microaggressions at different time points and locations. S3: Based on the cumulative effect graph generated in S2, a machine learning algorithm is used to train the time intervals, spatial distribution characteristics, and deviations from normal network behavior of micro-attack behaviors. This model is used to construct a cumulative effect identification model to output the risk value of potential security threats in the network. S4: Based on the cumulative effect identification model constructed in S3 and the current network status, it conducts a multi-dimensional assessment of the frequency, scale, and scope of the cumulative effect, and calculates the threat level of each network node; S5: Based on the threat level in S4 and real-time network traffic changes, the preset security threshold is dynamically adjusted through a reinforcement learning algorithm to adapt to fluctuations in different network environments. S6: When the threat level in S4 exceeds the dynamically adjusted security threshold, the corresponding protection strategy will be automatically generated and sent to the execution node.
[0006] Optionally, the S1 specifically includes: S11: Deploy distributed data collection nodes at predetermined node locations on the network. The predetermined nodes include high-traffic devices such as gateways, switches, and routers. Based on the analysis of the network topology, locations with high network data flow frequency and high vulnerability to attacks are selected as deployment points. S12: configuring a deep packet inspection module on the distributed data collection node to monitor data packets transmitted in the network in real time, extract characteristic information of small-scale data packets, including packet size, transmission rate, and protocol type; and monitor unauthorized or abnormal port scanning behavior in the network through ports, recording abnormal port connection requests and their sources; S13: A session tracking module is configured in the data collection node to continuously monitor long-term session connections in the network, record session durations and data traffic that deviate from normal connection behavior, and identify the source and destination addresses of abnormally long sessions; S14: Classify and process the data collected in S12 and S13, and mark the type information of data packet transmission anomalies, port scanning behaviors, and long-term session anomalies according to the characteristics of micro-attack behaviors.
[0007] Optionally, the S2 specifically includes: S21: Preprocess the micro-attack behavior data collected in S1, unify the timestamps of different network nodes into a standard time format, and record the occurrence time of each attack behavior in milliseconds. Combined with the location information of the network node where the event occurred, an initial data matrix is constructed. S22: Calculate the spatial distance between micro-aggressions based on the geographic or topological location information of the network nodes. Specifically, use the Euclidean distance formula to calculate the distance between two network nodes. S23: Perform temporal correlation analysis of micro-aggressions based on the set time window, and consider all events with timestamps falling within the same time window as related events; specifically, the time window size is set to ,like , then the two events are considered to be related in time; and the dynamic aggregation algorithm aggregates the events related in time and space to generate an event set ,in, Represents a group of events that are related in time and space; S24: Use the event set generated in S23 as vertices and the time intervals and spatial distances between events as edges to construct a cumulative effect graph ,in, represents an event in an event set, Represents the correlation edge between events.
[0008] Optionally, the S3 specifically includes: S31: Based on the cumulative effect graph generated by S2, extract the time interval, spatial distribution characteristics and deviation of micro-aggression behaviors and construct a feature vector ; S32: The eigenvector in S31 As the input of the training dataset, combined with the known micro-aggression behavior labels, a labeled dataset is constructed ,in, a label for aggressive behavior; S33: Train the labeled dataset in S32 based on the Isolation Forest algorithm. By randomly selecting features and split values, multiple decision trees are constructed to isolate data points. The training goal is to minimize the depth at which outliers are isolated in the tree, thereby identifying micro-attacks. S34: After the cumulative effect recognition model training is completed, the feature vector in S31 is input into the trained cumulative effect recognition model, and the cumulative effect risk value is output to quantify the cumulative effect of micro-aggression behaviors in the time and space dimensions.
[0009] Optionally, the S33 specifically includes: S331: First, the feature vector set in S32 Randomly select a feature from , and then randomly select a split value of the feature , used to construct the split nodes of the tree; S332: Split the data set recursively, selecting features each time and split point Finally, the data points are divided into two parts, and the distinction formula is: and ; Repeat the splitting process until each data point is isolated or the depth of the tree reaches the preset maximum depth , construct an isolation tree; S333: Isolation Forest calculates the path length of each data point isolated in the tree , used to judge the abnormality of data points. The path length refers to the number of splits experienced from the root node to the leaf node of an isolated data point; S334: Let the anomaly score of each data point be , specifically calculated by the following formula: ,in, is a data point The actual path length, is the expected path length, score The value is The value close to 1 indicates abnormality, and the value close to 0 indicates normality. S335: After training is completed, set a threshold ,when When , the data point is judged as abnormal behavior, otherwise it is normal behavior.
[0010] Optionally, the S4 specifically includes: S41: Based on the cumulative effect identification model built in S3, the frequency of micro-attack behaviors occurring on each network node is calculated, and the time window is set In a network node The number of incidents of microaggressions was , then the node The cumulative effect frequency , the formula is: ; S42: The cumulative effect on each network node is evaluated by analyzing the spatial range and temporal scalability of the attack behavior. Suppose the spatial distance covered by the attack behavior of a node is , time expansion is , then the node The cumulative effect size , the formula is: ; S43: The impact range is calculated based on the propagation effect of micro-attack behaviors on surrounding nodes. The correlation degree with its surrounding nodes is , the impact range The cumulative effect coefficient of the surrounding nodes is weighted and calculated using the formula: ,in, Representation node With node The correlation between and Node the frequency and magnitude of cumulative effects; S44: Frequency of combined cumulative effects ,scale and sphere of influence , computing nodes Threat Level , let the frequency weight of threat level be , the scale weight is and the influence range weight is , the threat level calculation formula is: .
[0011] Optionally, the S5 specifically includes: S51: The status of each node in the network As input to the reinforcement learning model, the state includes the threat level of the current node and real-time network traffic changes , set the reward function ,The optimization goal is to effectively reduce false positives and missed negatives after dynamically adjusted security thresholds; S52: Defining the action space of reinforcement learning models , that is, the security threshold adjustment actions that can be taken, including increasing or decreasing the adjustment range of the security threshold. Let the action set be , where each action Adjust the ratio corresponding to different thresholds; S53: Reinforcement learning algorithm through Q learning, according to the state and selected actions , update the Q value function ; S54: Based on the optimized strategy of S53, the threat level of the node is monitored in real time and network traffic changes After that, automatically adjust the safety threshold of each node , the adjustment formula is: ,in, is based on The magnitude of the adjustment determined by the value function.
[0012] Optionally, the S6 specifically includes: S61: When it is detected that the threat level of a network node exceeds the dynamically adjusted security threshold, a protection policy corresponding to the current threat level is matched from a pre-established protection policy rule base, wherein the rule base contains mappings between different threat levels and protection measures; S62: Generate a specific protection instruction set for the network node according to the matched protection policy, wherein the protection instruction set includes a packet filtering instruction, an access control adjustment instruction, a network node isolation instruction, and a security module activation instruction; S63: Sending the generated protection instruction set to the corresponding execution node through an encrypted secure channel. The secure channel uses an encryption protocol to ensure that the instructions are not intercepted or tampered with during transmission. S64: After receiving the protection instruction set, the execution node immediately executes corresponding protection measures according to the instruction content.
[0013] A computer network security situation analysis device, used to implement the above-mentioned computer network security situation analysis method, comprises: Data collection unit: used to collect real-time data on micro-attack behaviors in the network, including abnormal small-scale data packet transmission, port scanning behaviors, and long-term sessions; Data processing unit: used to receive data transmitted by the data acquisition unit, and perform data cleaning, time stamp standardization, and formatting on the data to generate initial cumulative effect data; Cumulative effect analysis unit: Based on the cleaned data provided by the data processing unit, it uses a dynamic aggregation algorithm to perform time series analysis and spatial distribution analysis on the data, identify the correlation between micro-aggression behaviors, and generate a cumulative effect graph; Cumulative effect identification model construction unit: Based on the cumulative effect graph, the isolation forest algorithm is used to train the time intervals, spatial distribution characteristics of micro-attack behaviors, and the degree of deviation from normal network behavior to build a cumulative effect identification model to output potential risk values; Threat Assessment Unit: The threat assessment unit combines the risk value of the cumulative effect identification model with the current network status to conduct a multi-dimensional assessment of the frequency, scale, and impact range of the cumulative effect, and calculates the threat level of each network node; Threshold Adjustment Unit: Based on the results of the threat assessment unit and real-time network traffic changes, it uses a reinforcement learning algorithm to dynamically adjust the security thresholds of network nodes. The adjusted thresholds serve as trigger conditions for generating protection strategies. Protection strategy generation unit: When the threat level of a node exceeds the security threshold dynamically adjusted by the threshold adjustment unit, the protection strategy generation unit automatically generates a corresponding protection strategy, which includes packet filtering, access control adjustment and network node isolation.
[0014] An electronic device includes a processor and a storage device, wherein the storage device stores a computer program, and when the computer program is run by the processor, it is used to execute the steps of the above-mentioned computer network security situation analysis method.
[0015] Beneficial effects of the present invention: The present invention, by adopting a dynamic aggregation algorithm and an isolation forest algorithm, can perform accurate temporal and spatial correlation analysis on micro-attack behaviors in the network, generate a cumulative effect graph, and thus identify potential threats that are difficult to detect with conventional detection methods. Based on a multi-dimensional evaluation of the cumulative effect, the threat level of different nodes in the network can be quantified in real time, ensuring that the system can accurately capture the cumulative effect of attack behaviors and improving the accuracy and precision of network security situation awareness.
[0016] The present invention uses a reinforcement learning algorithm, combined with threat levels and real-time network traffic changes, to adaptively and dynamically adjust security thresholds, reduce false positives and missed positives, and automatically generate protection strategies when threats exceed the thresholds. This greatly improves the response speed and effectiveness of protection strategies, ensuring that the network can still maintain efficient security protection capabilities in complex and changing environments. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only for the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0018] Figure 1 A schematic diagram of a computer network security situation analysis method according to an embodiment of the present invention; Figure 2 This is a schematic diagram of the composition of a computer network security situation analysis device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0019] The present invention is described in detail below with reference to the accompanying drawings and specific embodiments. It is also noted that, to provide a more detailed description, the following embodiments are best and preferred embodiments, and those skilled in the art may employ alternative methods for implementing certain known technologies. Furthermore, the accompanying drawings are intended only to provide a more detailed description of the embodiments and are not intended to limit the present invention.
[0020] It should be noted that references in the specification to "one embodiment," "an embodiment," "exemplary embodiments," "some embodiments," etc. indicate that the described embodiments may include specific features, structures, or characteristics, but not necessarily every embodiment will include such specific features, structures, or characteristics. Furthermore, when specific features, structures, or characteristics are described in conjunction with an embodiment, it is within the knowledge of persons skilled in the relevant art to implement such features, structures, or characteristics in conjunction with other embodiments (whether or not explicitly described).
[0021] In general, terms can be understood, at least in part, from their use in context. For example, depending at least in part on the context, the term "one or more" as used herein can be used to describe any feature, structure, or characteristic in the singular sense, or can be used to describe a combination of features, structures, or characteristics in the plural sense. Additionally, the term "based on" can be understood as not necessarily intended to convey an exclusive set of factors, but can instead, depending at least in part on the context, allow for the presence of other factors that are not necessarily explicitly described.
[0022] like Figure 1 As shown, the computer network security situation analysis method includes the following steps: S1: Distributed data collection nodes are deployed in the network to collect data on abnormal small-scale data packet transmissions, port scanning behaviors, and micro-attack behaviors such as long-term sessions. The data includes timestamps, event sources, and network node locations, and is encrypted and transmitted to a central data processing server. S2: Aggregate the data collected in S1 and use a dynamic aggregation algorithm to analyze the correlation between microaggressions based on the timestamps of events and network node location information. Generate a cumulative effect graph to correlate microaggressions at different time points and locations. S3: Based on the cumulative effect graph generated in S2, a machine learning algorithm is used to train the time intervals, spatial distribution characteristics, and deviations from normal network behavior of micro-attack behaviors. This model is used to construct a cumulative effect identification model to output the risk value of potential security threats in the network. S4: Based on the cumulative effect identification model constructed in S3 and the current network status, it conducts a multi-dimensional assessment of the frequency, scale, and scope of the cumulative effect, and calculates the threat level of each network node; S5: Based on the threat level in S4 and real-time network traffic changes, the preset security thresholds are dynamically adjusted through a reinforcement learning algorithm to adapt to fluctuations in different network environments and appropriately adjust security response strategies. S6: When the threat level in S4 exceeds the dynamically adjusted security threshold, a corresponding protection strategy will be automatically generated and sent to the execution node. The protection strategy includes packet filtering, access control adjustment, and network node isolation.
[0023] S1 specifically includes: S11: Deploy distributed data collection nodes at predetermined network node locations. These nodes include high-traffic devices such as gateways, switches, and routers. Based on the network topology analysis, select locations with high network data flow frequency and high vulnerability to attacks as deployment points to ensure that the entire network traffic is collected. S12: A deep packet inspection module is configured on the distributed data collection nodes to monitor data packets transmitted in the network in real time and extract characteristic information of small-scale data packets, including packet size, transmission rate, and protocol type. It also monitors unauthorized or abnormal port scanning behavior in the network through ports and records abnormal port connection requests and their sources. S13: A session tracking module is configured in the data collection node to continuously monitor long-term session connections in the network, record session durations and data traffic that deviate from normal connection behavior, and identify the source and destination addresses of abnormally long sessions; S14: Classify and process the data collected in S12 and S13, and mark the type information of data packet transmission anomalies, port scanning behaviors, and long-term session anomalies according to the characteristics of micro-attack behaviors. These marked data are uploaded to the central data processing server for further analysis through an encrypted transmission protocol. Through this deployment and collection method, the key nodes of possible micro-attack behaviors in the network can be effectively covered, and accurate monitoring of abnormal small-scale data packets, port scanning, and long-term session behaviors can be achieved, providing high-quality data support for subsequent cumulative effect analysis. At the same time, the real-time and reliability of data collection are improved through the distributed architecture.
[0024] Generating a cumulative effect graph in S2 specifically includes: S21: Preprocess the micro-attack behavior data collected in S1, unify the timestamps of different network nodes into a standard time format, record the occurrence time of each attack behavior in milliseconds, and build an initial data matrix based on the location information of the network node where the event occurred. Let the timestamp matrix be ,in Indicates the The timestamp of the event; S22: Calculate the spatial distance between micro-attack behaviors based on the geographic or topological location information of the network nodes. Specifically, use the Euclidean distance formula to calculate the distance between two network nodes. The formula is: ,in, Indicates the nodes and The distance between nodes, and Respectively The horizontal and vertical coordinates of the nodes, and Respectively The horizontal and vertical coordinates of each node are used to analyze their spatial correlation by calculating the spatial distance between nodes; S23: Perform temporal correlation analysis of micro-aggressions based on the set time window, and consider all events with timestamps falling within the same time window as related events; specifically, the time window size is set to ,like , then the two events are considered to be related in time; and the dynamic aggregation algorithm aggregates the events related in time and space to generate an event set ,in, Represents a group of events that are related in time and space; S24: Use the event set generated in S23 as vertices and the time intervals and spatial distances between events as edges to construct a cumulative effect graph ,in, represents an event in an event set, Represents the correlation edge between events and the weight of the edge By time interval and spatial distance Determine, the calculation formula is: ,in, Representing an event and events The weight between and is the adjustment coefficient of temporal and spatial correlation, and Respectively for events and events timestamp, Through this method, the correlation between micro-attack behaviors distributed in different time and space can be accurately analyzed, and a cumulative effect diagram can be dynamically generated, which provides more accurate correlation information for subsequent threat identification and improves the system's response capability and accuracy.
[0025] S3 specifically includes: S31: Based on the cumulative effect graph generated by S2, extract the time interval, spatial distribution characteristics and deviation of micro-aggression behaviors and construct a feature vector , specific event and events The time interval is , the spatial distance is , the normal network behavior characteristics are ,in Represents the behavioral characteristics of normal traffic in the network, and forms a vector by combining these characteristics ,in, Characterizes aggressive behavior. Indicates the degree of deviation between aggressive behavior and normal behavior; S32: The eigenvector in S31 As the input of the training dataset, combined with the known micro-aggression behavior labels, a labeled dataset is constructed ,in, a label for aggressive behavior; S33: Train the labeled dataset in S32 based on the Isolation Forest algorithm. By randomly selecting features and split values, multiple decision trees are constructed to isolate data points. The training goal is to minimize the depth at which outliers are isolated in the tree, thereby identifying micro-attacks. S34: After the training of the cumulative effect recognition model is completed, the feature vector in S31 is input into the trained cumulative effect recognition model, and the cumulative effect risk value is output to quantify the cumulative effect of micro-attack behaviors in the time and space dimensions; by adopting the isolation forest algorithm, the present invention can efficiently discover the abnormal cumulative effects in micro-attack behaviors. The isolation forest focuses on anomaly detection and can accurately identify attack behaviors that are significantly different from normal network behaviors. It also has the ability to process high-dimensional data and sparse data, thereby improving the accuracy and reliability of the system in identifying the cumulative effects of micro-attack behaviors.
[0026] S33 specifically identifies microaggressions including: S331: First, the feature vector set in S32 Randomly select a feature from , and then randomly select a split value of the feature , used to construct the split node of the tree, set the feature The value is in the interval If the split value is randomly selected satisfy ; S332: Split the data set recursively, selecting features each time and split point Finally, the data points are divided into two parts, and the distinction formula is: and ; Repeat the splitting process until each data point is isolated or the depth of the tree reaches the preset maximum depth , an isolation tree is constructed; the more times a data point is isolated, the more normal it is considered to be; the fewer times a data point is isolated, the more abnormal it is considered to be; S333: Isolation Forest calculates the path length of each data point isolated in the tree , used to judge the abnormality of data points. The path length refers to the number of splits experienced from the root node to the leaf node of an isolated data point. Isolation tree of samples, expected path length The calculation formula is: ,in, yes The harmonic number of data points is defined as: ; S334: Let the anomaly score of each data point be , specifically calculated by the following formula: ,in, is a data point The actual path length, is the expected path length, score The value is The value close to 1 indicates abnormality, and the value close to 0 indicates normality. S335: After training is completed, set a threshold ,when When , the data point is judged as abnormal behavior, otherwise it is normal behavior. Ultimately, the model can identify and distinguish the cumulative effects of normal behavior and abnormal micro-aggression behaviors.
[0027] S4 specifically includes: S41: Based on the cumulative effect identification model built in S3, the frequency of micro-attack behaviors occurring on each network node is calculated, and the time window is set In a network node The number of incidents of microaggressions was , then the node The cumulative effect frequency , the formula is: ,The frequency is used to measure the intensity of attack behaviors in a specified time period; S42: The cumulative effect on each network node is evaluated by analyzing the spatial range and temporal scalability of the attack behavior. Suppose the spatial distance covered by the attack behavior of a node is , time expansion is , then the node The cumulative effect size , the formula is: , this value is used to describe the coverage of attack behavior in time and space; S43: The impact range is calculated based on the propagation effect of micro-attack behaviors on surrounding nodes. The correlation degree with its surrounding nodes is , the impact range The cumulative effect coefficient of the surrounding nodes is weighted and calculated using the formula: ,in, Representation node With node The correlation between and Node the frequency and magnitude of cumulative effects; S44: Frequency of combined cumulative effects ,scale and sphere of influence , computing nodes Threat Level , let the frequency weight of threat level be , the scale weight is and the influence range weight is , the threat level calculation formula is: ; Through the threat level calculation formula, the threat level of each node in the network can be calculated according to the frequency, scale and impact range of each node, which is used for real-time monitoring and early warning; through multi-dimensional evaluation of the frequency, scale and impact range of cumulative effects, the system can comprehensively and accurately identify potential security threats in the network. This calculation process realizes the quantification of the threat level of each node in the network, which helps the network security management system to prioritize the protection of high-risk nodes and enhance the overall network security situation awareness capability.
[0028] S5 specifically includes: S51: The status of each node in the network As input to the reinforcement learning model, the state includes the threat level of the current node and real-time network traffic changes , set the reward function , the optimization goal is to effectively reduce false positives and false negatives after dynamically adjusted security thresholds. The reward function is expressed as: ,in, and are weight factors, representing the negative impact of false positives and false negatives on the system; S52: Defining the action space of reinforcement learning models , that is, the security threshold adjustment actions that can be taken, the actions include increasing or decreasing the adjustment range of the security threshold, and the action set is , where each action Adjust the ratio corresponding to different thresholds; S53: Reinforcement learning algorithm through Q learning, according to the state and selected actions , update the Q value function , and according to the reward function Adjust the action selection strategy, and the formula for updating the Q value is: ,in, is the learning rate, is the discount factor, is the next state, is the possible action to be taken in the next state. Through this update process, the system can dynamically learn the optimal security threshold adjustment strategy; S54: Based on the optimized strategy of S53, the threat level of the node is monitored in real time and network traffic changes After that, automatically adjust the safety threshold of each node , the adjustment formula is: ,in, is based on The adjustment range determined by the value function is continuously updated to ensure that the security threshold can adapt to the ever-changing network environment, thereby improving the system's responsiveness. By using a reinforcement learning algorithm, the present invention can adaptively adjust the security threshold according to the threat level and dynamic changes in traffic in the network. This method enables the system to always maintain efficient threat detection capabilities in the face of complex and fluctuating network environments, effectively reduce false alarms and missed alarms, and improve the overall security protection effect.
[0029] S6 specifically includes: S61: When it is detected that the threat level of a network node exceeds the dynamically adjusted security threshold, a protection strategy corresponding to the current threat level is matched from a pre-established protection strategy rule base. The rule base contains mappings between different threat levels and protection measures to ensure the accuracy of the protection strategy; S62: Generate a specific set of protection instructions for network nodes based on the matched protection policy. The protection instruction set includes packet filtering instructions, access control adjustment instructions, network node isolation instructions, and security module activation instructions. Packet filtering instructions are used to update firewall rules to block traffic from high-risk source addresses and specify packet characteristics to be filtered. Access control adjustment instructions are used to modify access control lists (ACLs) to restrict or prohibit access to specific ports and services. Network node isolation instructions are used to isolate threatened nodes from the network by modifying routing or switching policies to prevent the spread of threats. Security module activation instructions are used to activate an intrusion prevention system (IPS) or other security modules to strengthen detection and protection against abnormal behavior. S63: Send the generated protection instruction set to the corresponding execution node through an encrypted secure channel. The secure channel uses an encryption protocol to ensure that the instructions are not intercepted or tampered with during transmission, ensuring the effective implementation of the protection strategy. S64: After receiving the protection instruction set, the execution node immediately executes the corresponding protection measures according to the instruction content. The execution process includes updating local firewall rules, adjusting access control settings, activating security modules, and implementing node isolation to ensure that the protection strategy takes effect quickly. Through the above steps, when the threat level of the network node exceeds the dynamically adjusted security threshold, the system can automatically generate and issue accurate protection strategies, realizing the automation and real-time security protection. This method improves the response speed and effectiveness of protection measures, reduces the delay of human intervention, and enhances the overall security and robustness of the network.
[0030] like Figure 2 As shown, the computer network security situation analysis device is used to implement the above-mentioned computer network security situation analysis method, including: Data collection unit: used to collect micro-attack behavior data in the network in real time, including abnormal small-scale data packet transmission, port scanning behavior and long-term sessions. The data collection unit encrypts the collected data and transmits it to the central processing unit; Data processing unit: used to receive data transmitted by the data acquisition unit, and perform data cleaning, time stamp standardization, and formatting on it to generate initial cumulative effect data. The processed data is used for subsequent correlation analysis; Cumulative effect analysis unit: Based on the cleaned data provided by the data processing unit, the unit uses a dynamic aggregation algorithm to perform time series analysis and spatial distribution analysis on the data, identify the correlation between micro-aggression behaviors, and generate a cumulative effect graph for subsequent model construction; Cumulative effect identification model construction unit: Based on the cumulative effect graph, the isolation forest algorithm is used to train the time intervals, spatial distribution characteristics of micro-attack behaviors, and the degree of deviation from normal network behavior to build a cumulative effect identification model, which is used to output potential risk values and provide them to the threat assessment unit; Threat Assessment Unit: The threat assessment unit combines the risk value of the cumulative effect identification model with the current network status to conduct a multi-dimensional assessment of the frequency, scale, and impact range of the cumulative effect, calculates the threat level of each network node, and provides the threat level to the threshold adjustment unit; Threshold Adjustment Unit: Based on the results of the threat assessment unit and real-time network traffic changes, it uses a reinforcement learning algorithm to dynamically adjust the security thresholds of network nodes. The adjusted thresholds serve as trigger conditions for generating protection strategies. Protection strategy generation unit: When the threat level of a node exceeds the security threshold dynamically adjusted by the threshold adjustment unit, the protection strategy generation unit automatically generates a corresponding protection strategy, which includes packet filtering, access control adjustment, and network node isolation.
[0031] An electronic device includes a processor and a storage device, wherein the storage device stores a computer program, and when the computer program is run by the processor, it is used to execute the steps of the above-mentioned computer network security situation analysis method.
[0032] The present invention encompasses any alternatives, modifications, equivalents, and solutions that fall within the spirit and scope of the present invention. To provide a thorough understanding of the present invention, specific details are described in detail below in connection with the preferred embodiments of the present invention, but those skilled in the art will be able to fully understand the present invention without these detailed descriptions. Furthermore, to avoid unnecessary confusion regarding the essence of the present invention, well-known methods, processes, procedures, components, and circuits have not been described in detail.
[0033] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.
Claims
1. A computer network security situation analysis method, characterized in that: The following steps are involved: S1: Distributed data collection nodes are deployed in the network to collect data on abnormal small-scale data packet transmissions, port scanning behaviors, and micro-attack behaviors of long-term sessions. The data includes timestamps, event sources, and network node locations. S2: Aggregate the data collected in S1 and use a dynamic aggregation algorithm to analyze the correlation between microaggressions based on the timestamps of events and network node location information. Generate a cumulative effect graph to correlate microaggressions at different time points and locations. S3: Based on the cumulative effect graph generated in S2, a machine learning algorithm is used to train the time intervals, spatial distribution characteristics, and deviations from normal network behavior of micro-attack behaviors. This model is used to construct a cumulative effect identification model to output the risk value of potential security threats in the network. S4: Based on the cumulative effect identification model constructed in S3 and the current network status, it conducts a multi-dimensional assessment of the frequency, scale, and scope of the cumulative effect, and calculates the threat level of each network node; S5: Based on the threat level in S4 and real-time network traffic changes, the preset security threshold is dynamically adjusted through a reinforcement learning algorithm to adapt to fluctuations in different network environments. S6: When the threat level in S4 exceeds the dynamically adjusted security threshold, the corresponding protection strategy will be automatically generated and sent to the execution node.
2. The computer network security situation analysis method according to claim 1, characterized in that: Said S1 specifically includes: S11: Deploy distributed data collection nodes at predetermined node locations on the network. The predetermined nodes include high-traffic devices such as gateways, switches, and routers. Based on the analysis of the network topology, locations with high network data flow frequency and high vulnerability to attacks are selected as deployment points. S12: configuring a deep packet inspection module on the distributed data collection node to monitor data packets transmitted in the network in real time, extract characteristic information of small-scale data packets, including packet size, transmission rate, and protocol type; and monitor unauthorized or abnormal port scanning behavior in the network through ports, recording abnormal port connection requests and their sources; S13: A session tracking module is configured in the data collection node to continuously monitor long-term session connections in the network, record session durations and data traffic that deviate from normal connection behavior, and identify the source and destination addresses of abnormally long sessions; S14: Classify and process the data collected in S12 and S13, and mark the type information of data packet transmission anomalies, port scanning behaviors, and long-term session anomalies according to the characteristics of micro-attack behaviors.
3. The computer network security situation analysis method according to claim 1, characterized in that: The S2 specifically includes: S21: Preprocess the micro-attack behavior data collected in S1, unify the timestamps of different network nodes into a standard time format, and record the occurrence time of each attack behavior in milliseconds. Combined with the location information of the network node where the event occurred, an initial data matrix is constructed. S22: Calculate the spatial distance between micro-aggressions based on the geographic or topological location information of the network nodes. Specifically, use the Euclidean distance formula to calculate the distance between two network nodes. S23: Perform temporal correlation analysis of micro-aggressions based on the set time window, and consider all events with timestamps falling within the same time window as related events; specifically, the time window size is set to ,like , then the two events are considered to be related in time; and the dynamic aggregation algorithm aggregates the events related in time and space to generate an event set ,in, Represents a group of events that are related in time and space; S24: Use the event set generated in S23 as vertices and the time intervals and spatial distances between events as edges to construct a cumulative effect graph ,in, represents an event in an event set, Represents the correlation edge between events.
4. The computer network security situation analysis method according to claim 1, characterized in that: The S3 specifically includes: S31: Based on the cumulative effect graph generated by S2, extract the time interval, spatial distribution characteristics and deviation of micro-aggression behaviors and construct a feature vector ; S32: The eigenvector in S31 As the input of the training dataset, combined with the known micro-aggression behavior labels, a labeled dataset is constructed ,in, a label for aggressive behavior; S33: Train the labeled dataset in S32 based on the Isolation Forest algorithm. By randomly selecting features and split values, multiple decision trees are constructed to isolate data points. The training goal is to minimize the depth at which outliers are isolated in the tree, thereby identifying micro-attacks. S34: After the cumulative effect recognition model training is completed, the feature vector in S31 is input into the trained cumulative effect recognition model, and the cumulative effect risk value is output to quantify the cumulative effect of micro-aggression behaviors in the time and space dimensions.
5. The computer network security situation analysis method according to claim 4, characterized in that: The S33 specifically includes: S331: First, the feature vector set in S32 Randomly select a feature from , and then randomly select a split value of the feature , used to construct the split nodes of the tree; S332: Split the data set recursively, selecting features each time and split point Finally, the data points are divided into two parts, and the distinction formula is: and ; Repeat the splitting process until each data point is isolated or the depth of the tree reaches the preset maximum depth , construct an isolation tree; S333: Isolation Forest calculates the path length of each data point isolated in the tree , used to judge the abnormality of data points. The path length refers to the number of splits experienced from the root node to the leaf node of an isolated data point; S334: Let the anomaly score of each data point be , specifically calculated by the following formula: ,in, is a data point The actual path length, is the expected path length, score The value is The value close to 1 indicates abnormality, and the value close to 0 indicates normality. S335: After training is completed, set a threshold ,when When , the data point is judged as abnormal behavior, otherwise it is normal behavior.
6. The computer network security situation analysis method according to claim 1, characterized in that: The S4 specifically includes: S41: Based on the cumulative effect identification model built in S3, the frequency of micro-attack behaviors occurring on each network node is calculated, and the time window is set In a network node The number of incidents of microaggressions was , then the node The cumulative effect frequency , the formula is: ; S42: The cumulative effect on each network node is evaluated by analyzing the spatial range and temporal scalability of the attack behavior. Suppose the spatial distance covered by the attack behavior of a node is , time expansion is , then the node The cumulative effect size , the formula is: ; S43: The impact range is calculated based on the propagation effect of micro-attack behaviors on surrounding nodes. The correlation degree with its surrounding nodes is , the impact range The cumulative effect coefficient of the surrounding nodes is weighted and calculated using the formula: ,in, Representation node With node The correlation between and Node the frequency and magnitude of cumulative effects; S44: Frequency of combined cumulative effects ,scale and sphere of influence , computing nodes Threat Level , let the frequency weight of threat level be , the scale weight is and the influence range weight is , the threat level calculation formula is: .
7. The computer network security situation analysis method according to claim 1, characterized in that: The S5 specifically includes: S51: The status of each node in the network As input to the reinforcement learning model, the state includes the threat level of the current node and real-time network traffic changes , set the reward function ,The optimization goal is to effectively reduce false positives and missed negatives after dynamically adjusted security thresholds; S52: Defining the action space of reinforcement learning models , that is, the security threshold adjustment actions that can be taken, including increasing or decreasing the adjustment range of the security threshold. Let the action set be , where each action Adjust the ratio corresponding to different thresholds; S53: Reinforcement learning algorithm through Q learning, according to the state and selected actions , update the Q value function ; S54: Based on the optimized strategy of S53, the threat level of the node is monitored in real time and network traffic changes After that, automatically adjust the safety threshold of each node , the adjustment formula is: ,in, is based on The magnitude of the adjustment determined by the value function.
8. The computer network security situation analysis method according to claim 1, characterized in that: The S6 specifically includes: S61: When it is detected that the threat level of a network node exceeds the dynamically adjusted security threshold, a protection policy corresponding to the current threat level is matched from a pre-established protection policy rule base, wherein the rule base contains mappings between different threat levels and protection measures; S62: Generate a specific protection instruction set for the network node according to the matched protection policy, wherein the protection instruction set includes a packet filtering instruction, an access control adjustment instruction, a network node isolation instruction, and a security module activation instruction; S63: Sending the generated protection instruction set to the corresponding execution node through an encrypted secure channel. The secure channel uses an encryption protocol to ensure that the instructions are not intercepted or tampered with during transmission. S64: After receiving the protection instruction set, the execution node immediately executes corresponding protection measures according to the instruction content.
9. A computer network security situation analysis device, configured to implement the computer network security situation analysis method according to any one of claims 1 to 8, characterized in that: include: Data collection unit: used to collect real-time data on micro-attack behaviors in the network, including abnormal small-scale data packet transmission, port scanning behaviors, and long-term sessions; Data processing unit: used to receive data transmitted by the data acquisition unit, and perform data cleaning, time stamp standardization, and formatting on the data to generate initial cumulative effect data; Cumulative effect analysis unit: Based on the cleaned data provided by the data processing unit, it uses a dynamic aggregation algorithm to perform time series analysis and spatial distribution analysis on the data, identify the correlation between micro-aggression behaviors, and generate a cumulative effect graph; Cumulative effect identification model construction unit: Based on the cumulative effect graph, the isolation forest algorithm is used to train the time intervals, spatial distribution characteristics of micro-attack behaviors, and the degree of deviation from normal network behavior to build a cumulative effect identification model to output potential risk values; Threat Assessment Unit: The threat assessment unit combines the risk value of the cumulative effect identification model with the current network status to conduct a multi-dimensional assessment of the frequency, scale, and impact range of the cumulative effect, and calculates the threat level of each network node; Threshold Adjustment Unit: Based on the results of the threat assessment unit and real-time network traffic changes, it uses a reinforcement learning algorithm to dynamically adjust the security thresholds of network nodes. The adjusted thresholds serve as trigger conditions for generating protection strategies. Protection strategy generation unit: When the threat level of a node exceeds the security threshold dynamically adjusted by the threshold adjustment unit, the protection strategy generation unit automatically generates a corresponding protection strategy, which includes packet filtering, access control adjustment and network node isolation.
10. An electronic device, characterized in that: The method comprises a processor and a storage device, wherein a computer program is stored on the storage device, and when the computer program is run by the processor, the computer network security situation analysis method according to any one of claims 1 to 8 is executed.
Citation Information
Cited By
Tunnel anomaly detection and response method and equipment based on rail robot
CN120688702A