Network information security early warning system based on big data analysis
The network information security early warning system, which uses big data analysis technology, solves the problem that traditional detection methods are difficult to identify logic bombs and remote control bypasses. It achieves accurate identification and blocking of logic bombs and remote control bypasses, ensures stable system operation, and prevents the influence of greedy programs by optimizing resource allocation, thereby improving system performance and response speed.
Patent Information
- Application Number
- CN202510805516.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-17
- Publication Date
- 2025-09-05
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Traditional detection methods are unable to accurately locate logic bombs, remote control bypass communications and illegal communication behaviors, which lead to system performance degradation or paralysis. Traditional resource allocation methods are unable to effectively restrict greedy programs.
A network information security early warning system based on big data analysis is adopted, including data collection and processing, intelligent analysis and system evaluation and optimization modules. Through big data analysis technology, logic bombs can be detected, remote control bypass can be blocked, illegal communication behavior can be identified, and resource allocation can be optimized.
It achieves accurate identification and blocking of logic bombs, remote control bypass and illegal communications, ensures stable system operation, rationally allocates resources to prevent the influence of greedy programs, and improves system performance and response speed.
Smart Images

Figure CN120602169A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network information security technology, and in particular to a network information security early warning system based on big data analysis. Background Art
[0002] In the wave of digitalization, various systems are widely used in various key areas, from financial transaction systems to industrial control systems. The stable operation and information security of these systems are of paramount importance. However, with the continuous evolution of cyber attack techniques, a variety of new threats pose severe challenges to system security.
[0003] Logic bombs are hidden within normal program code. When triggered under specific conditions, they can cause severe damage to system data and functions. Traditional detection methods make it difficult to accurately locate them within massive amounts of code. Remote control bypass communications bypass normal security mechanisms, allowing attackers to remotely control critical systems. Traditional network protection equipment has difficulty detecting such covert communication behaviors. Illegal communications often rely on complex encryption and camouflage technologies to transmit sensitive information within the network, making them difficult to effectively identify using conventional detection methods. Furthermore, greedy programs can excessively occupy system resources, leading to decreased system performance or even paralysis, making it difficult to effectively restrict them using traditional resource allocation and management methods. Summary of the Invention
[0004] In view of the shortcomings of the existing technology, the present invention provides a network information security early warning system based on big data analysis to solve the problems raised in the above background technology.
[0005] To achieve the above objectives, the present invention is implemented through the following technical solutions: A network information security early warning system based on big data analysis, comprising: The data collection and processing module is used to collect network traffic data, system log data, and user behavior data in real time, and to clean, normalize, and extract features from the collected data; Big data intelligent analysis module, which is used to detect logic bombs in the system, block remote control bypass in the system, identify illegal communication behavior in the system, and defend against greedy programs in the system through big data analysis technology, and generate reports; The system early warning response module is used to detect abnormal behavior and send early warning information and event-specific solutions to management personnel in a timely manner; The system evaluation and optimization module is used to evaluate the results of warning information and actual events, and optimize the machine learning algorithm, system architecture and hardware configuration for specific scenarios.
[0006] Preferably, the data acquisition and processing module processes the collected data including the following steps: S1. Use the mean filling method to fill missing values with the mean for numerical data. The calculation formula is: , where For this feature non-missing values, is the number of non-missing values. If the loss rate is higher than 10%, the missing record will be deleted; S2. For each data point , detect its abnormal value, the calculation formula is: , where is the mean value of the feature, is the standard deviation of the feature, if , then the data point is considered as an outlier and deleted or corrected; S3. Delete completely duplicate data records by comparing key features of the data records; S4. Extract the characteristics of the number of bytes, number of connections, and transmission rate of the traffic, and calculate the entropy value of the traffic. The calculation formula is: , where The first The probability of occurrence of a state; S5. Extract the features of event type, timestamp, and operation result in the log, construct an event sequence, and use the bag-of-words model to convert the event sequence into a feature vector. S6. Extract the characteristics of the user's login time, operation frequency, and operation path, and calculate the Markov transition probability matrix of the user's behavior. The calculation formula is: , where From the state Transfer to state The number of times, is the total number of states, which is used as a feature.
[0007] Preferably, the big data intelligent analysis module detects logic bombs in the system including the following steps: 1) Obtain the data for constructing the event sequence, verify the data, check for duplicates, and check for errors, and set the behavior sequence as the posterior probability of the logic bomb behavior. threshold value; 2) Calculate the prior probability of normal behavior sequence and logic bomb behavior sequence. The prior probability calculation formula of the behavior sequence is: , where is the set of normal behavior sequences, is the number of events contained in a behavior sequence, The first in the normal behavior sequence events, the a priori probability calculation formula of the logic bomb behavior sequence is: , where is a collection of logic bomb behavior sequences, The first in the logic bomb behavior sequence events 3) Calculate the likelihood probability under normal behavior and logic bomb behavior. The likelihood probability calculation formula under normal behavior is: , the likelihood probability calculation formula under the logic bomb behavior is: , where For one dimensional behavior sequence vector, is the mean vector, is the covariance matrix; 4) Calculate the posterior probability that the behavior sequence is a logic bomb behavior. The calculation formula is: ,when When the set threshold is exceeded, the program corresponding to the behavior sequence is recorded as a potential logic bomb.
[0008] Preferably, the big data intelligent analysis module blocks the remote control bypass including the following steps: a. Perform spectrum analysis on network traffic and convert the time domain traffic data into frequency domain spectrum data. The calculation formula is: , where is the time domain traffic data, is the frequency domain spectrum data, is the data length, is a complex exponential function, that is, a kernel function, is the imaginary unit in complex number operations and satisfies ; b. Calculate the mean and standard deviation of the normal traffic spectrum. The calculation formula for the mean is: , where is the total number of data points in the normal traffic spectrum dataset, is the first data points, the standard deviation is calculated as follows: , where For the The difference between a data point and the mean; c. Set the dynamic threshold, the calculation formula is: , where is the threshold adjustment factor; d. Monitor the current traffic spectrum in real time. If it exceeds the dynamic threshold, it is determined to be abnormal remote control bypass communication and blocked.
[0009] Preferably, the big data intelligent analysis module identifies illegal communication behavior including the following steps: Ⅰ. Set the flow entropy value threshold value; II. Check the format, instruction set, and interaction process of the communication data. If it does not comply with the predefined communication protocol specifications, it will be marked as suspected illegal communication; III. Calculate the entropy value of suspected illegal communication using the following formula: , where The number of different states that the communication traffic is divided into, The communication flow is in the The probability of a state, and , where For the The number of times a state appears in the communication traffic data, is the total number of records of communication traffic data; IV. Real-time monitoring of the current traffic spectrum. If it exceeds the dynamic threshold, it is determined to be abnormal remote control bypass communication and blocked.
[0010] Preferably, the big data intelligent analysis module defends against greedy programs including the following steps: A. Real-time monitoring of the CPU usage of each program in the system , memory usage , and disk rate ; B. Set resource usage threshold 、 and ; C. When the CPU usage of a program , memory usage , and disk rate When one or more of them exceeds the threshold set by the response, resource weight is assigned to each program. , is the reallocation of system resources, and the calculation formula is: , where is the total amount of available resources in the system, is the number of programs, For the system The resource allocation weight of each program.
[0011] Preferably, the system evaluation and optimization module evaluates the results and optimizes the system including the following steps: α. Collect warning information from various data sources in the system, including but not limited to the time, type, and objects involved in the warning, and collect the corresponding actual event data to determine whether the event actually occurred and the severity of the event, and standardize and normalize the data; β, measures the difference between the predicted probability and the true label, and is calculated as: , where is the sample size, is the sample index, is the category index, is the number of categories, For the The samples belong to The true label of the class, The model predicts The samples belong to class probability; γ. Analyze the advantages and disadvantages of the early warning system based on the calculated evaluation indicators, and conduct an in-depth analysis of the reasons that lead to unsatisfactory evaluation indicators; δ. Optimize the machine learning algorithm based on the evaluation results; ε. Optimize system architecture and hardware configuration based on the evaluation results; ζ. Collect data again and use the calculation formula in step β to calculate the evaluation index and optimization results. If the evaluation result is still not ideal, repeat steps α to ε until a satisfactory effect is achieved.
[0012] Preferably, the reasons for the unsatisfactory evaluation index in step γ include but are not limited to improper feature selection, model overfitting or underfitting, data transmission delay, insufficient processing power, insufficient memory and poor CPU performance.
[0013] Preferably, in step δ, optimizing the machine learning algorithm comprises the following steps: δ1. Select features that are highly correlated with the event and remove redundant and irrelevant features. The calculation formula is: , where is the sample size, and For two variables, For variables No. observations, For variables No. observations, For variables The sample mean of For variables The sample mean of ; δ2. Convert the original features into more representative new features to reduce the feature dimension. The calculation formula is: , where is the final constructed matrix, is the identity matrix, is the weight matrix, is the transpose operator; δ3. Evaluate each model and select the model with the best evaluation index. The calculation formula is: , where is the coefficient of determination, which is used to measure the degree of fit of the regression model to the observed data, with a value range of 0-1, and The closer it is to 1, the higher the proportion of dependent variable variation that the model can explain, and the better the model fits the data. is the sample size, For the observations, For the The predicted value corresponding to the observed value, is the mean of all observations; δ4. Select the parameter combination with the best evaluation index as the final model parameters.
[0014] Preferably, in step ε, optimizing the system architecture and hardware configuration includes the following steps: ε1. Split the system into smaller, independent modules to reduce coupling between modules. Add a caching layer to the system to reduce frequent access to backend data sources. Based on performance data, identify the hardware components that are bottlenecks in the system. ε2. Based on the optimization strategy, draw a new system architecture diagram, clarify the interface definitions and communication protocols between modules, and decide whether to upgrade the hardware based on the bottleneck hardware situation; ε3. According to the optimization plan, reconstruct and develop the system code, conduct comprehensive testing on the optimized system, establish a complete monitoring mechanism, and perform performance testing on the optimized hardware configuration to verify whether the optimization effect achieves the expected goal.
[0015] The present invention provides a network information security early warning system based on big data analysis. It has the following beneficial effects: 1. The present invention comprehensively collects and deeply analyzes the massive amounts of data generated by system operation. In terms of detecting logic bombs, it uses big data analysis technology to deeply mine program code execution trajectories and system operation logs, accurately identifying potential logic bombs and eliminating hidden dangers in advance. To block remote control bypass, the system analyzes network traffic spectrum and communication patterns to monitor abnormal communication behavior in real time. Once remote control bypass communication is discovered, blocking measures are immediately implemented to ensure that system control is not illegally seized. In terms of identifying illegal communication behavior, big data analysis technology is used to analyze the characteristics of encrypted communication traffic and the correlation analysis of the behavior patterns of both communicating parties. It can accurately identify illegal behavior hidden in normal communication and effectively protect the security of sensitive information. In the case of greedy programs, the system uses big data technology to monitor resource usage in real time. Once abnormal resource usage is discovered, a resource allocation optimization mechanism based on the weighted fair queue algorithm is immediately activated to reasonably allocate resources, limit the excessive resource usage of greedy programs, and ensure stable system operation.
[0016] 2. This invention uses scientific evaluation metrics to quantitatively analyze the early warning system's performance in detecting logic bombs, blocking remote control bypasses, identifying illegal communications, and defending against greedy programs. This helps accurately determine the system's performance across various functions, identifying areas of excellence and deficiencies. Based on the issues identified in the evaluation results, the system evaluation and optimization module can perform targeted system optimizations, using principal component analysis and other methods for feature extraction to enhance the machine learning algorithm's ability to detect various threats. By optimizing the architecture, the system's overall performance and response speed are improved, enabling it to more efficiently detect and respond to various network security threats. By analyzing hardware performance data, hardware bottlenecks can be determined, providing the system with more robust hardware support, ensuring stable and efficient operation when processing massive amounts of data and complex calculations, and better utilizing the early warning system's functions. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 Schematic diagram of the system module of the present invention. DETAILED DESCRIPTION
[0018] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0019] like Figure 1 As shown, an embodiment of the present invention provides a network information security early warning system based on big data analysis, including: The data collection and processing module is used to collect network traffic data, system log data, and user behavior data in real time, and to clean, normalize, and extract features from the collected data; Big data intelligent analysis module, which is used to detect logic bombs in the system, block remote control bypass in the system, identify illegal communication behavior in the system, and defend against greedy programs in the system through big data analysis technology, and generate reports; The system early warning response module is used to detect abnormal behavior and send early warning information and event-specific solutions to management personnel in a timely manner; The system evaluation and optimization module is used to evaluate the results of warning information and actual events, and optimize the machine learning algorithm, system architecture and hardware configuration for specific scenarios.
[0020] In this embodiment, the data acquisition and processing module processes the collected data including the following steps: S1. Use the mean filling method to fill missing values with the mean for numerical data. The calculation formula is: , where For this feature non-missing values, is the number of non-missing values. If the loss rate is higher than 10%, the missing record will be deleted; S2. For each data point , detect its abnormal value, the calculation formula is: , where is the mean value of the feature, is the standard deviation of the feature, if , then the data point is considered as an outlier and deleted or corrected; S3. Delete completely duplicate data records by comparing key features of the data records; S4. Extract the characteristics of the number of bytes, number of connections, and transmission rate of the traffic, and calculate the entropy value of the traffic. The calculation formula is: , where The first The probability of occurrence of a state; S5. Extract the features of event type, timestamp, and operation result in the log, construct an event sequence, and use the bag-of-words model to convert the event sequence into a feature vector. S6. Extract the characteristics of the user's login time, operation frequency, and operation path, and calculate the Markov transition probability matrix of the user's behavior. The calculation formula is: , where From the state Transfer to state The number of times, is the total number of states, which is used as a feature.
[0021] Specifically, the collected data is standardized and normalized to ensure the efficiency and accuracy of subsequent data processing.
[0022] In this embodiment, the big data intelligent analysis module detects logic bombs in the system including the following steps: 1) Obtain the data for constructing the event sequence, verify the data, check for duplicates, and check for errors, and set the behavior sequence as the posterior probability of the logic bomb behavior. threshold value; 2) Calculate the prior probability of normal behavior sequence and logic bomb behavior sequence. The prior probability calculation formula of the behavior sequence is: , where is the set of normal behavior sequences, is the number of events contained in a behavior sequence, The first in the normal behavior sequence events, the a priori probability calculation formula of the logic bomb behavior sequence is: , where is a collection of logic bomb behavior sequences, The first in the logic bomb behavior sequence events 3) Calculate the likelihood probability under normal behavior and logic bomb behavior. The likelihood probability calculation formula under normal behavior is: , the likelihood probability calculation formula under the logic bomb behavior is: , where For one dimensional behavior sequence vector, is the mean vector, is the covariance matrix; 4) Calculate the posterior probability that the behavior sequence is a logic bomb behavior. The calculation formula is: ,when When the set threshold is exceeded, the program corresponding to the behavior sequence is recorded as a potential logic bomb.
[0023] Specifically, in terms of detecting logic bombs, big data analysis technology is used to conduct in-depth mining of program code execution trajectories and system operation logs, accurately identify potential logic bombs, and eliminate hidden dangers in advance. For system operation logs, natural language processing technology is used to convert unstructured log data into structured information, and extract key features related to logic bombs. When new program code and operation logs are entered into the system, the model will automatically compare sample features to determine whether there is a logic bomb.
[0024] In this embodiment, the big data intelligent analysis module blocks the remote control bypass including the following steps: a. Perform spectrum analysis on network traffic and convert the time domain traffic data into frequency domain spectrum data. The calculation formula is: , where is the time domain traffic data, is the frequency domain spectrum data, is the data length, is a complex exponential function, that is, a kernel function, is the imaginary unit in complex number operations and satisfies ; b. Calculate the mean and standard deviation of the normal traffic spectrum. The calculation formula for the mean is: , where is the total number of data points in the normal traffic spectrum dataset, is the first data points, the standard deviation is calculated as follows: , where For the The difference between a data point and the mean; c. Set the dynamic threshold, the calculation formula is: , where is the threshold adjustment factor; d. Monitor the current traffic spectrum in real time. If it exceeds the dynamic threshold, it is determined to be abnormal remote control bypass communication and blocked.
[0025] Specifically, to block remote control bypass, the system analyzes the network traffic spectrum and communication mode, monitors abnormal communication behavior in real time, and immediately implements blocking measures once remote control bypass communication is detected to ensure that system control is not illegally seized. The system uses advanced spectrum analysis tools to conduct a detailed analysis of the frequency distribution of network traffic, and uses the spectrum characteristics of normal communication traffic as a benchmark to establish a spectrum characteristic model. When new network traffic enters, its spectrum and model characteristics are compared in real time. Even extremely subtle frequency offsets or abnormal frequency bands can be accurately captured.
[0026] In this embodiment, the big data intelligent analysis module identifies illegal communication behavior including the following steps: Ⅰ. Set the flow entropy value threshold value; II. Check the format, instruction set, and interaction process of the communication data. If it does not comply with the predefined communication protocol specifications, it will be marked as suspected illegal communication; III. Calculate the entropy value of suspected illegal communication using the following formula: , where The number of different states that the communication traffic is divided into, The communication flow is in The probability of a state, and , where For the The number of times a state appears in the communication traffic data, is the total number of records of communication traffic data; IV. Real-time monitoring of the current traffic spectrum. If it exceeds the dynamic threshold, it is determined to be abnormal remote control bypass communication and blocked.
[0027] Specifically, in identifying illegal communication behaviors, by relying on big data analysis technology to analyze the characteristics of encrypted communication traffic and the correlation analysis of the behavior patterns of the communicating parties, it is possible to accurately identify illegal behaviors hidden in normal communications and effectively protect the security of sensitive information. The system will first build a huge normal communication traffic feature library, collect multi-dimensional feature data such as traffic size, frequency, protocol type, etc. of normal communications in different business scenarios. For encrypted communication traffic, deep learning algorithms are used to deeply explore the subtle features in the encrypted traffic packets. Even when the encryption keys are constantly changing, abnormal encryption patterns can be accurately captured.
[0028] In this embodiment, the big data intelligent analysis module defends against greedy programs including the following steps: A. Real-time monitoring of the CPU usage of each program in the system , memory usage , and disk rate ; B. Set resource usage threshold 、 and ; C. When the CPU usage of a program , memory usage , and disk rate When one or more of them exceeds the threshold set by the response, resource weight is assigned to each program. , is the reallocation of system resources, and the calculation formula is: , where is the total amount of available resources in the system, is the number of programs, For the system The resource allocation weight of each program.
[0029] Specifically, when faced with greedy programs, the system uses big data technology to monitor resource usage in real time. Once anomalies are detected, a resource allocation optimization mechanism based on a weighted fair queueing algorithm is immediately activated to rationally allocate resources, limit excessive resource usage by greedy programs, and ensure stable system operation. In this way, the system can fairly and reasonably allocate resources according to the weight ratio of each program. If a greedy program attempts to overuse resources, the mechanism will quickly take effect, reducing its resource allocation and allocating more resources to other normally running programs, thus preventing individual greedy programs from causing system performance crashes.
[0030] In this embodiment, the system evaluation and optimization module evaluates the results and optimizes the system, including the following steps: α. Collect warning information from various data sources in the system, including but not limited to the time, type, and objects involved in the warning, and collect the corresponding actual event data to determine whether the event actually occurred and the severity of the event, and standardize and normalize the data; β, measures the difference between the predicted probability and the true label, and is calculated as: , where is the sample size, is the sample index, is the category index, is the number of categories, For the The samples belong to The true label of the class, The model predicts The samples belong to class probability; γ. Analyze the advantages and disadvantages of the early warning system based on the calculated evaluation indicators, and conduct an in-depth analysis of the reasons that lead to unsatisfactory evaluation indicators; δ. Optimize the machine learning algorithm based on the evaluation results; ε. Optimize system architecture and hardware configuration based on the evaluation results; ζ. Collect data again and use the calculation formula in step β to calculate the evaluation index and optimization results. If the evaluation result is still not ideal, repeat steps α to ε until a satisfactory effect is achieved.
[0031] In this embodiment, the reasons for the unsatisfactory evaluation index in step γ include but are not limited to improper feature selection, model overfitting or underfitting, data transmission delay, insufficient processing power, insufficient memory and poor CPU performance.
[0032] In this embodiment, in step δ, optimizing the machine learning algorithm includes the following steps: δ1. Select features that are highly correlated with the event and remove redundant and irrelevant features. The calculation formula is: , where is the sample size, and For two variables, For variables No. observations, For variables No. observations, For variables The sample mean of For variables The sample mean of ; δ2. Convert the original features into more representative new features to reduce the feature dimension. The calculation formula is: , where is the final constructed matrix, is the identity matrix, is the weight matrix, is the transpose operator; δ3. Evaluate each model and select the model with the best evaluation index. The calculation formula is: , where is the coefficient of determination, which is used to measure the degree of fit of the regression model to the observed data, with a value range of 0-1, and The closer it is to 1, the higher the proportion of dependent variable variation that the model can explain, and the better the model fits the data. is the sample size, For the observations, For the The predicted value corresponding to the observed value, is the mean of all observations; δ4. Select the parameter combination with the best evaluation index as the final model parameters.
[0033] In this embodiment, in step ε, optimizing the system architecture and hardware configuration includes the following steps: ε1. Split the system into smaller, independent modules to reduce coupling between modules. Add a caching layer to the system to reduce frequent access to backend data sources. Based on performance data, identify the hardware components that are bottlenecks in the system. ε2. Based on the optimization strategy, draw a new system architecture diagram, clarify the interface definitions and communication protocols between modules, and decide whether to upgrade the hardware based on the bottleneck hardware situation; ε3. According to the optimization plan, reconstruct and develop the system code, conduct comprehensive testing on the optimized system, establish a complete monitoring mechanism, and perform performance testing on the optimized hardware configuration to verify whether the optimization effect achieves the expected goal.
[0034] Specifically, the system evaluation and optimization module uses scientific evaluation metrics to quantitatively analyze the early warning system's performance in detecting logic bombs, blocking remote control bypasses, identifying illegal communications, and defending against greedy programs. This helps accurately determine the system's performance across various functions, identifying areas of excellence and areas of weakness. Based on the issues identified in the evaluation results, the system evaluation and optimization module can perform targeted system optimization, using principal component analysis and other methods for feature extraction to improve the machine learning algorithm's ability to detect various threats. By optimizing the architecture, the system's overall performance and response speed are improved, enabling it to more efficiently detect and respond to various network security threats. By analyzing hardware performance data, it can determine whether hardware bottlenecks exist, providing the system with more powerful hardware support, ensuring that the system can operate stably and efficiently when processing massive amounts of data and complex calculations, and better utilizing the early warning system's functions.
[0035] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. A network information security early warning system based on big data analysis, characterized in that: include: The data collection and processing module is used to collect network traffic data, system log data, and user behavior data in real time, and to clean, normalize, and extract features from the collected data; Big data intelligent analysis module, which is used to detect logic bombs in the system, block remote control bypass in the system, identify illegal communication behavior in the system, and defend against greedy programs in the system through big data analysis technology, and generate reports; The system early warning response module is used to detect abnormal behavior and send early warning information and event-specific solutions to management personnel in a timely manner; The system evaluation and optimization module is used to evaluate the results of warning information and actual events, and optimize the machine learning algorithm, system architecture and hardware configuration for specific scenarios.
2. A network information security early warning system based on big data analysis according to claim 1, characterized in that: The data acquisition and processing module processes the collected data and includes the following steps: S1. Use the mean filling method to fill missing values with the mean for numerical data. The calculation formula is: , where For this feature non-missing values, is the number of non-missing values. If the loss rate is higher than 10%, the missing record will be deleted; S2. For each data point , detect its abnormal value, the calculation formula is: , where is the mean value of the feature, is the standard deviation of the feature, if , then the data point is considered as an outlier and deleted or corrected; S3. Delete completely duplicate data records by comparing key features of the data records; S4. Extract the characteristics of the number of bytes, number of connections, and transmission rate of the traffic, and calculate the entropy value of the traffic. The calculation formula is: , where The first The probability of occurrence of a state; S5. Extract the features of event type, timestamp, and operation result in the log, construct an event sequence, and use the bag-of-words model to convert the event sequence into a feature vector. S6. Extract the characteristics of the user's login time, operation frequency, and operation path, and calculate the Markov transition probability matrix of the user's behavior. The calculation formula is: , where From the state Transfer to state The number of times, is the total number of states, which is used as a feature.
3. The network information security early warning system based on big data analysis according to claim 1 is characterized in that: The big data intelligent analysis module detects logic bombs in the system including the following steps: 1) Obtain the data for constructing the event sequence, verify the data, check for duplicates, and check for errors, and set the behavior sequence as the posterior probability of the logic bomb behavior. threshold value; 2) Calculate the prior probability of normal behavior sequence and logic bomb behavior sequence. The prior probability calculation formula of the behavior sequence is: , where is the set of normal behavior sequences, is the number of events contained in a behavior sequence, The first in the normal behavior sequence events, the a priori probability calculation formula of the logic bomb behavior sequence is: , where is a collection of logic bomb behavior sequences, The first in the logic bomb behavior sequence events 3) Calculate the likelihood probability under normal behavior and logic bomb behavior. The likelihood probability calculation formula under normal behavior is: , the likelihood probability calculation formula under the logic bomb behavior is: , where For one dimensional behavior sequence vector, is the mean vector, is the covariance matrix; 4) Calculate the posterior probability that the behavior sequence is a logic bomb behavior. The calculation formula is: ,when When the set threshold is exceeded, the program corresponding to the behavior sequence is recorded as a potential logic bomb.
4. The network information security early warning system based on big data analysis according to claim 1 is characterized in that: The big data intelligent analysis module blocks remote control bypass including the following steps: a. Perform spectrum analysis on network traffic and convert the time domain traffic data into frequency domain spectrum data. The calculation formula is: , where is the time domain traffic data, is the frequency domain spectrum data, is the data length, is a complex exponential function, that is, a kernel function, is the imaginary unit in complex number operations and satisfies ; b. Calculate the mean and standard deviation of the normal traffic spectrum. The calculation formula for the mean is: , where is the total number of data points in the normal traffic spectrum dataset, is the first data points, the standard deviation is calculated as follows: , where For the The difference between a data point and the mean; c. Set the dynamic threshold, the calculation formula is: , where is the threshold adjustment factor; d. Monitor the current traffic spectrum in real time. If it exceeds the dynamic threshold, it is determined to be abnormal remote control bypass communication and blocked.
5. The network information security early warning system based on big data analysis according to claim 1 is characterized in that: The big data intelligent analysis module identifies illegal communication behavior including the following steps: Ⅰ. Set the flow entropy value threshold value; II. Check the format, instruction set, and interaction process of the communication data. If it does not comply with the predefined communication protocol specifications, it will be marked as suspected illegal communication; III. Calculate the entropy value of suspected illegal communication. The calculation formula is: , where The number of different states that the communication traffic is divided into, The communication flow is in The probability of a state, and , where For the The number of times a state appears in the communication traffic data, is the total number of records of communication traffic data; IV. Real-time monitoring of the current traffic spectrum. If it exceeds the dynamic threshold, it is determined to be abnormal remote control bypass communication and blocked.
6. The network information security early warning system based on big data analysis according to claim 1 is characterized in that: The big data intelligent analysis module defense against greedy programs includes the following steps: A. Real-time monitoring of the CPU usage of each program in the system , memory usage , and disk rate ; B. Set resource usage threshold 、 and ; C. When the CPU usage of a program , memory usage , and disk rate When one or more of them exceeds the threshold set by the response, resource weight is assigned to each program. , is the reallocation of system resources, and the calculation formula is: , where is the total amount of available resources in the system, is the number of programs, For the system The resource allocation weight of each program.
7. The network information security early warning system based on big data analysis according to claim 1 is characterized in that: The system evaluation and optimization module evaluates the results and optimizes the system, including the following steps: α. Collect warning information from various data sources in the system, including but not limited to the time, type, and objects involved in the warning, and collect the corresponding actual event data to determine whether the event actually occurred and the severity of the event, and standardize and normalize the data; β, measures the difference between the predicted probability and the true label, and is calculated as: , where is the sample size, is the sample index, is the category index, is the number of categories, For the The samples belong to The true label of the class, The model predicts The samples belong to class probability; γ. Analyze the advantages and disadvantages of the early warning system based on the calculated evaluation indicators, and conduct an in-depth analysis of the reasons that lead to unsatisfactory evaluation indicators; δ. Optimize the machine learning algorithm based on the evaluation results; ε. Optimize system architecture and hardware configuration based on the evaluation results; ζ. Collect data again and use the calculation formula in step β to calculate the evaluation index and optimization results. If the evaluation result is still not ideal, repeat steps α to ε until a satisfactory effect is achieved.
8. The network information security early warning system based on big data analysis according to claim 7 is characterized in that: The reasons for the unsatisfactory evaluation indicators in step γ include but are not limited to improper feature selection, model overfitting or underfitting, data transmission delay, insufficient processing power, insufficient memory and poor CPU performance.
9. The network information security early warning system based on big data analysis according to claim 7 is characterized in that: In step δ, optimizing the machine learning algorithm includes the following steps: δ1. Select features that are highly correlated with the event and remove redundant and irrelevant features. The calculation formula is: , where is the sample size, and For two variables, For variables No. observations, For variables No. observations, For variables The sample mean of For variables The sample mean of ; δ2. Convert the original features into more representative new features to reduce the feature dimension. The calculation formula is: , where is the final constructed matrix, is the identity matrix, is the weight matrix, is the transpose operator; δ3. Evaluate each model and select the model with the best evaluation index. The calculation formula is: , where is the coefficient of determination, which is used to measure the degree of fit of the regression model to the observed data, with a value range of 0-1, and The closer it is to 1, the higher the proportion of dependent variable variation that the model can explain, and the better the model fits the data. is the sample size, For the observations, For the The predicted value corresponding to the observed value, is the mean of all observations; δ4. Select the parameter combination with the best evaluation index as the final model parameters.
10. The network information security early warning system based on big data analysis according to claim 7 is characterized in that: In step ε, optimizing the system architecture and hardware configuration includes the following steps: ε1. Split the system into smaller, independent modules to reduce coupling between modules. Add a caching layer to the system to reduce frequent access to backend data sources. Based on performance data, identify the hardware components that are bottlenecks in the system. ε2. Based on the optimization strategy, draw a new system architecture diagram, clarify the interface definitions and communication protocols between modules, and decide whether to upgrade the hardware based on the bottleneck hardware situation; ε3. According to the optimization plan, reconstruct and develop the system code, conduct comprehensive testing on the optimized system, establish a complete monitoring mechanism, and perform performance testing on the optimized hardware configuration to verify whether the optimization effect achieves the expected goal.
Citation Information
Cited By
Intelligent network information security early warning method and system based on big data
CN122268677A
A method and system for intelligent network information security early warning based on big data
CN122268677B