Data analysis management method and system based on ocean network security

By constructing the dynamic data flow and spatiotemporal feature tensor of the ocean network, conducting behavioral topology modeling and anomaly detection, reconstructing the attack path, and generating the optimal protection response plan, the dynamic and resource-constrained problems of the ocean network are solved, and efficient threat identification and protection are achieved.

CN120602232AActive Publication Date: 2025-09-05SHANDONG PROVINCIAL INST OF LAND & SPACE DATA & REMOTE SENSING TECH (SHANDONG PROVINCIAL SEA AREA DYNAMIC SURVEILLANCE & MONITORING CENT)

Patent Information

Application Number
CN202511093594.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-06
Publication Date
2025-09-05
Estimated Expiration
2045-08-06

AI Technical Summary

Technical Problem

The security protection of marine networks faces problems such as dynamic changes in nodes, high threat concealment, complex attack propagation paths, and limited resources. Existing technologies are difficult to adapt to marine scenarios, resulting in delayed threat identification, difficulty in tracing attack sources, and inefficient protection responses.

Method used

By collecting multi-source marine network equipment traffic and log data in real time, constructing dynamic heterogeneous data streams, extracting spatiotemporal correlation feature tensors, performing behavioral topology modeling and anomaly detection, reconstructing attack paths, combining multi-dimensional security assessment functions to make protection response decisions, and using a hybrid multi-objective optimization algorithm to generate the optimal protection plan.

Benefits of technology

It achieves dynamic adaptation to marine networks, improves the accuracy of anomaly identification, accurately locates threats, improves the efficiency of attack chain boundary identification, outputs customized protection solutions, and improves the security of marine facilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602232A_ABST
    Figure CN120602232A_ABST
Patent Text Reader

Abstract

The invention discloses a data analysis management method and system based on ocean network security, and relates to the technical field of ocean network security, and the technical key points comprise the following steps: collecting the flow and log data of multi-source ocean network equipment in real time, constructing a dynamic heterogeneous data stream, and extracting a space-time correlation feature tensor; behavior topology modeling is carried out on the space-time correlation feature tensor, a network behavior dynamic topological graph is generated, and topology stability measure is calculated; abnormal behavior detection is carried out based on topological stability measurement, an abnormal behavior cluster is identified through a multi-scale spectral clustering algorithm, and a high-risk threat area coordinate set is generated; the technical effects are that the dynamic topology modeling adapts to the characteristics of ocean network equipment movement, communication intermittence and the like, and the environment adaptability is improved; and manifold mapping and adaptive clustering are combined, so that the anomaly recognition accuracy is improved, the missing report rate is reduced, and accurate threat positioning is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of marine network security, and in particular to a data analysis and management method and system based on marine network security. Background Art

[0002] With the deep integration of marine economy and information technology, marine networks have become key infrastructure supporting core scenarios such as ocean shipping, seabed resource exploration, and marine environmental monitoring. Its network architecture covers heterogeneous equipment such as mobile ship terminals, underwater sensor nodes, shore-based control centers, and satellite / underwater acoustic communication links. It features dynamic node movement, complex communication environment (such as underwater signal attenuation and satellite transmission delay), and strong business relevance (such as deep coupling of navigation data and ship control). However, the security protection of marine networks faces multiple challenges: First, the network topology changes dynamically (such as ships sailing causing frequent access / exit of communication nodes), and traditional static baseline construction methods are difficult to adapt, which can easily lead to "normal behavior misjudgment"; second, threats are highly concealed, and attack behaviors are often mixed in complex communication noise (such as underwater sensor data packet loss and malicious tampering are difficult to distinguish), and existing detection technologies based on fixed feature libraries have a high false negative rate; third, the attack propagation path is complex, and threats can spread across subnets through satellite links (such as spreading from ship terminals to shore-based servers), and there is a lack of effective path tracking and boundary definition methods; fourth, protection resources are limited, and the computing power and bandwidth of ocean-going ships and underwater equipment are limited, making it difficult to support large-scale protection deployment. A precise balance must be achieved between resource consumption and protection effect. Existing network security technologies are mostly designed for fixed terrestrial networks and fail to fully consider the unique characteristics of marine scenarios. For example, traditional topology modeling ignores node mobility, resulting in distorted stability measurements; general clustering algorithms are not adapted to the nonlinear distribution of marine data, resulting in inaccurate anomaly detection; attack chain analysis lacks support for cross-subnet propagation; and protection decisions fail to incorporate multi-objective optimization logic under resource constraints. These shortcomings lead to delayed threat identification, difficulty in tracing attacks, and inefficient protection responses in marine networks. A comprehensive security management solution tailored to marine scenarios is urgently needed. Summary of the Invention

[0003] In view of the deficiencies in the prior art, the present invention provides a data analysis and management method and system based on marine network security to solve the problems in the above-mentioned background technology.

[0004] To achieve the above objectives, the present invention provides the following technical solution: a data analysis and management method based on marine network security, comprising the following steps: Collect multi-source marine network equipment traffic and log data in real time, build dynamic heterogeneous data streams, and extract spatiotemporal correlation feature tensors; Perform behavioral topology modeling on spatiotemporal correlation feature tensors, generate dynamic topological graphs of network behavior, and calculate topological stability measures; Abnormal behavior detection is performed based on topological stability measurement, and abnormal behavior clusters are identified through multi-scale spectral clustering algorithm to generate a coordinate set of high-risk threat areas; Reconstruct the attack path of the high-risk threat area coordinate set and generate the initial attack chain boundary using the spatiotemporal graph model matching algorithm; Construct a multi-dimensional security assessment function, use a hybrid multi-objective optimization algorithm to make evolutionary decisions on the initial attack chain boundary, output the optimal protection response plan and execute it.

[0005] In a preferred embodiment, the behavior topology modeling of the spatiotemporal correlation feature tensor is performed to generate a network behavior dynamic topology graph, and the topology stability measure is calculated, specifically: Parse the three-dimensional data of protocol type, packet size, and access frequency in the spatiotemporal correlation feature tensor and construct a dynamic attribute graph; Calculate the behavioral correlation matrix between nodes in the attribute graph and introduce persistent homology theory to extract topologically invariant features; Fusion of behavioral association matrix and topology invariant features to generate weighted network behavior dynamic topology graph; The rate of change of the Betti number of the topological graph on consecutive time slices is calculated as a measure of topological stability.

[0006] In a preferred embodiment, the abnormal behavior detection is performed based on the topological stability measure, and the abnormal behavior clusters are identified by the multi-scale spectral clustering algorithm to generate the high-risk threat area coordinate set, specifically: Map the topological stability measure to the Riemannian manifold space and construct the behavioral geodesic distance matrix; The spectral clustering algorithm modified by Mahalanobis distance is used to perform eigendecomposition on the behavioral geodesic distance matrix; Adaptively cluster feature vectors using a Dirichlet process mixture model to identify clusters of abnormal behaviors exceeding a risk threshold. Extract the IP coordinates, port vectors, and timestamps of nodes in the abnormal behavior cluster to generate a coordinate set of high-risk threat areas.

[0007] In a preferred embodiment, the attack path is reconstructed for the high-risk threat area coordinate set, and the initial attack chain boundary is generated using a spatiotemporal graph model matching algorithm, specifically: Analyze the spatiotemporal distribution of high-risk threat area coordinate sets and construct an attack causal graph model; Use random walk algorithm to simulate threat propagation paths and generate candidate attack chains; Calculate the graph structure similarity between the candidate attack chain and the historical attack pattern, and select the path with similarity higher than the preset value as the initial attack chain boundary.

[0008] In a preferred embodiment, the method for analyzing the spatiotemporal distribution of the high-risk threat area coordinate set and constructing the attack causal graph model is specifically as follows: Each high-risk threat coordinate point is used as a graph node, and the node attributes include the threat type weight; Calculate the transition probability between nodes based on time sequence and protocol correlation; The maximum information coefficient method is used to quantify the causal strength between nodes, and edges with strength exceeding the threshold are retained; The transition probability and causal strength are integrated to construct a weighted directed attack causal graph.

[0009] In a preferred embodiment, the multi-dimensional security assessment function is constructed, a hybrid multi-objective optimization algorithm is used to make an evolutionary decision on the initial attack chain boundary, and the optimal protection response solution is output and executed, specifically: Construct a multi-dimensional security assessment function that includes resource consumption, response time, and risk coverage; The initial attack chain boundary is encoded as a chromosome population, and the improved NSGA-Ⅲ algorithm is used for non-dominated sorting; The quantum rotating gate mechanism is introduced to perform adaptive crossover mutation and generate the Pareto optimal solution set; The optimal protection response plan is selected from the Pareto solution set based on the entropy weight TOPSIS method.

[0010] In a preferred embodiment, the initial attack chain boundary is encoded as a chromosome population, and the improved NSGA-III algorithm is used for non-dominated sorting, specifically: K-means++ is used to initialize the reference point set and dynamically adjust the reference point distribution; Introducing convolutional neural networks to predict the convergence trend of the solution set and adaptively adjust the crossover probability; A crowding operator based on topological structure similarity is designed to optimize the distribution of solution sets.

[0011] Compared with the existing technology, the present invention provides a data analysis and management method and system based on marine network security, which has the following beneficial effects: through dynamic topology modeling to adapt to the characteristics of marine network equipment mobility, communication intermittentness, etc., environmental adaptability is improved; combined with manifold mapping and adaptive clustering, the accuracy of anomaly identification is improved, the missed reporting rate is reduced, and precise threat positioning is achieved; based on causal graphs and path simulation to restore attack propagation, the accuracy of attack chain boundary identification is improved and the efficiency is improved; through multi-objective optimization to output customized protection solutions, the overall effectiveness is improved; the distributed closed-loop design improves deployment flexibility, forms a complete security link, and comprehensively breaks through the constraints of marine network dynamics, threat concealment and limited resources, providing efficient and safe protection for various marine facilities. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Figure 1 A flowchart of a data analysis and management method based on marine network security according to the present invention; Figure 2 A dynamic attribute graph modeling block diagram of the data analysis and management method based on marine network security of the present invention; Figure 3 A multi-objective optimization decision-making block diagram of the data analysis and management method based on marine network security of the present invention; Figure 4 A block diagram of topological stability measurement calculation for a data analysis and management method based on marine network security according to the present invention; Figure 5 This is a flowchart of the awareness module of the data analysis and management system based on marine network security of the present invention; Figure 6 This is a flowchart of the attack deduction module of the data analysis and management system based on marine network security of the present invention; Figure 7 This is a flowchart of the threat location module of the data analysis and management system based on marine network security of the present invention; Figure 8 This is a flowchart of a topology modeling module of a data analysis and management system based on marine network security according to the present invention; Figure 9 This is a flow chart of the dynamic perception module of the data analysis and management system based on marine network security of the present invention. DETAILED DESCRIPTION

[0013] In the present invention, unless otherwise specified, directions such as "up" and "down" are generally used with respect to the directions shown in the drawings, or with respect to the vertical, perpendicular or gravity directions; similarly, for ease of understanding and description, "left" and "right" are generally used with respect to the left and right shown in the drawings; "inside" and "outside" refer to the inside and outside relative to the outline of each component itself, but the above-mentioned directions are not used to limit the present invention.

[0014] Example 1, reference Figures 1 to 9 A data analysis and management method based on marine network security specifically includes the following steps: Collect multi-source marine network equipment traffic and log data in real time, build dynamic heterogeneous data streams, and extract spatiotemporal correlation feature tensors.

[0015] The behavior topology modeling of the spatiotemporal correlation feature tensor is performed to generate a network behavior dynamic topology graph and calculate the topology stability measure, specifically: Parse the three-dimensional data of protocol type, packet size, and access frequency in the spatiotemporal correlation feature tensor and construct a dynamic attribute graph; It should be noted that protocol type: distinguishes interaction rules such as TCP / UDP / ICMP. For example, specific protocols are often used for communication between ships and shore-based platforms, and abnormal protocols may indicate threats; data packet size: normal business data has a fixed size range. For example, the data returned by sensors is usually small, and abnormally large packets may contain malicious code; access frequency: normal communication between devices is periodic, such as underwater robots reporting data at regular intervals. Sudden frequency changes may be a precursor to an attack.

[0016] Dynamic Attribute Graph; Nodes: Represent entities in the marine network, such as ship terminals, underwater sensors, shore-based servers, communication ports, etc.; Edges: Represent the interaction relationship between nodes, such as data transmission and command issuance; Attributes: The weight of the edge integrates the above three-dimensional data, such as high frequency + specific protocol interaction has a higher weight; Dynamicity: The graph structure is updated over time (for example, if the movement of the ship causes the communication object to change, the edges in the graph will increase or decrease in real time).

[0017] Calculate the behavioral correlation matrix between nodes in the attribute graph and introduce persistent homology theory to extract topologically invariant features; It should be noted that the behavior association matrix quantifies the closeness of interaction between nodes. The matrix element A[i,j] represents the strength of the behavioral association between nodes i and j (calculated based on three-dimensional data. For example, the higher the interaction frequency and the higher the protocol matching degree, the larger the value). It reflects the basic relationship of "who frequently interacts with whom" in the network and provides a numerical basis for the topological structure.

[0018] Function: Extract "core features that are resistant to local perturbations" (i.e., topological invariants) from dynamically changing network structures.

[0019] Specific operation: By analyzing the birth and death of network connected branches at different scales (for example, temporary connections that disappear under small disturbances are filtered out, and long-term stable core connections are retained), the "skeleton structure" of the network is obtained.

[0020] Significance in marine scenarios: Marine network equipment (such as ships) is highly mobile and has frequent temporary connections, but core services (such as navigation data transmission) have stable topology. Persistent synchronization can filter out noise and preserve key structures.

[0021] Fusion of behavioral association matrix and topology invariant features to generate weighted network behavior dynamic topology graph; It should be noted that the "behavioral association matrix" (quantified interaction strength) is combined with the "topologically invariant features" (core structure) to form the final topological map.

[0022] Preserve the core nodes and connections extracted by persistent homology (to ensure topological stability); Use the weight value of the behavior association matrix to mark the importance of the edge (for example, the weight of the key business link is significantly higher than that of the ordinary link); Refresh the graph structure over time slices (e.g., every 10 minutes) to reflect temporal changes in network behavior.

[0023] The value of topology maps: They intuitively present the "behavioral patterns" of marine networks. Under normal circumstances, the core structure of the topology map (such as the communication links between shore-based and main vessels) is stable, and the weight distribution conforms to business rules. However, in abnormal situations, structural mutations may occur (such as unauthorized nodes accessing core links).

[0024] The rate of change of the Betti number of the topological graph on consecutive time slices is calculated as a measure of topological stability.

[0025] It should be noted that Betti-0 represents the number of connected branches (e.g., the network is divided into several independent parts); Betti-1 represents the number of rings (e.g., the number of closed communication loops, reflecting the network redundancy capability); in marine networks, the Betti number changes smoothly under normal conditions (e.g., the connected branches are stable and the key loops continue to exist).

[0026] Calculate the ratio of the difference in Betti numbers between consecutive time slices (e.g., t1 to t2, t2 to t3) to the time interval. A larger rate of change indicates a more significant deviation from the normal topology. For example, the sudden appearance of a large number of new connected branches may indicate a malicious node intrusion; a sudden decrease in the ring structure may indicate the severance of a critical link. Ultimately, the rate of change is used as a "topological stability measure" to provide a quantitative basis for subsequent anomaly detection (if it exceeds the threshold, it will be marked as suspicious).

[0027] In the second embodiment, abnormal behavior detection is performed based on topological stability measurement, and abnormal behavior clusters are identified through a multi-scale spectral clustering algorithm to generate a high-risk threat area coordinate set. Specifically, Map the topological stability measure to the Riemannian manifold space and construct the behavioral geodesic distance matrix; It's important to note that topological stability measures (such as the rate of change of the Betti number) reflect the nonlinear dynamics of network structure. Traditional Euclidean space struggles to capture these complex nonlinear relationships (for example, different types of attacks may lead to similar stability changes, but for different underlying reasons). Riemannian manifold space better fits the distribution characteristics of high-dimensional, nonlinear data and is particularly well-suited for describing data with inherent geometric structure, such as network behavior.

[0028] The topological stability measure of each time slice (which may be a multidimensional vector, such as the rate of change of Betti-0 and Betti-1) is regarded as a point on the manifold, and the "geodesic distance" between points (the shortest path on the manifold surface, not the straight-line distance) is calculated using differential geometry methods.

[0029] The matrix element D[i,j] represents the degree of difference in network behavior between the i-th time slice and the j-th time slice. Larger values ​​indicate a more significant divergence in network behavior patterns between the two time slices. Compared to traditional distance calculations (such as Euclidean distance), this matrix more accurately captures behavioral differences in marine networks that are "superficially similar but fundamentally different," such as topological changes caused by normal ship movement versus those caused by malicious intrusions.

[0030] The spectral clustering algorithm modified by Mahalanobis distance is used to perform eigendecomposition on the behavioral geodesic distance matrix; It should be noted that spectral clustering, a graph-theoretic clustering method, is effective for data with non-convex distributions and is particularly well-suited for clustering data with complex correlation structures, such as network behavior (traditional algorithms like K-means are prone to local optima when handling such data). Marine network data exhibits significant "feature correlation" and "scale differences" (for example, the range of access frequency values ​​is much larger than the value encoded by protocol type). The Mahalanobis distance eliminates the dimensionality effects of data of different dimensions and considers covariance between features (for example, specific protocol types are often associated with specific packet sizes), making distance calculations more consistent with real-world business logic. The Mahalanobis distance is used to weight the original geodesic distance matrix, highlighting the influence of key features (such as unusual protocol types). Spectral decomposition (calculating the eigenvalues ​​and eigenvectors of the Laplacian matrix) is performed on the modified distance matrix, mapping the high-dimensional distance matrix to a lower-dimensional space while preserving the core structural information of the data and providing more manageable eigenvectors for subsequent clustering.

[0031] Adaptively cluster feature vectors using a Dirichlet process mixture model to identify clusters of abnormal behaviors exceeding a risk threshold. It's important to note that traditional clustering algorithms (such as K-means) require a predefined number of clusters. However, the types of anomalies in marine networks are often unknown (e.g., new attack patterns). DPMM uses a nonparametric Bayesian approach to adaptively learn the number of clusters. The number of clusters automatically corresponds to the number of behavioral patterns present in the data, eliminating the need for manual pre-setting. Using the low-dimensional feature vectors derived from spectral decomposition as input, DPMM iteratively calculates the posterior probability that each sample belongs to a different cluster, ultimately clustering time slices with similar behavioral patterns into a single category (e.g., normal communication clusters, suspected scanning clusters, data leakage clusters, etc.). A "risk score" is calculated for each cluster (based on the degree to which the behavior within the cluster deviates from historical norms). When the score exceeds a preset risk threshold, the cluster is labeled as an anomalous behavior cluster. The risk threshold can be dynamically adjusted for different sea areas (e.g., nearshore vs. offshore) and device types (e.g., sensors vs. servers) to avoid misjudgments due to environmental variations.

[0032] Extract the IP coordinates, port vectors, and timestamps of nodes in the abnormal behavior cluster to generate a coordinate set of high-risk threat areas.

[0033] It should be noted that: from the time slice corresponding to the abnormal behavior cluster, the network nodes involved in the abnormal behavior are located and three types of core information are extracted: IP coordinates: network layer location (such as the public network IP of the ship terminal and the intranet IP of the underwater sensor); port vectors: transport layer identification (such as abnormally open port numbers and frequently interacting port combinations, such as port 21 (FTP) and port 3389 (Remote Desktop) being active at the same time may indicate an intrusion); timestamp: the specific time and duration of the abnormal behavior (used to analyze the attack rhythm, such as whether it is a continuous attack).

[0034] The composition of the high-threat area coordinate set: A coordinate set is a multidimensional set, with each element formatted as (IP address, port set, start time, end time, threat confidence), visually displaying the network location, resources involved, time range, and risk level of the threat. For example, {(192.168.1.105,[22,8080],10:23:15,10:45:30,0.92),...} indicates that the IP address generated high-confidence anomalous behavior on ports 22 and 8080 within the specified timeframe.

[0035] The attack path is reconstructed for the high-risk threat area coordinate set, and the initial attack chain boundary is generated using the spatiotemporal graph model matching algorithm, specifically: Analyze the spatiotemporal distribution of high-risk threat area coordinate sets and construct an attack causal graph model; It should be noted that the "spatiotemporal distribution characteristics" in the high-risk threat area coordinates include: Time dimension: The chronological relationship of timestamps of each high-risk coordinate point (for example, the anomaly at point A occurs at t1, and at point B at t2, t1 < t2 may imply the propagation from A to B); Space dimension: The network topology relationship between nodes (such as the network segment to which the IP address belongs, the port service dependency relationship, for example, a database server (port 3306) usually depends on an authentication server (port 8080)); Attribute dimension: The threat type association (for example, port scanning (access to abnormal ports) is often accompanied by brute force cracking (multiple failed logins)).

[0036] Composition of the attack causal graph model: Nodes: Each high-risk threat coordinate point (including attributes such as IP, port, timestamp, threat type, etc.); Directed edges: Represent the "possibility of causal association" between nodes, and the arrow direction reflects the chronological order or propagation direction; Edge weights: Incorporate factors such as time difference, network distance, threat type similarity, etc. to quantify the strength of the causal relationship (for example, nodes with a shorter time interval and a closer network distance have higher weights). Adaptation for the marine scenario: Considering the mobility of the ship network (such as dynamic IP address allocation) and the communication delay of underwater devices (there may be deviations in timestamps), a "spatiotemporal elasticity coefficient" is introduced into the causal graph to correct the causal judgment deviation caused by environmental characteristics.

[0037] Use the random walk algorithm to simulate the threat propagation path and generate candidate attack chains; It should be noted that the core role of the random walk algorithm: From the attack causal graph, based on the causal association strength (edge weights) between nodes, simulate the possible propagation paths of threats. The algorithm starts from the initial high-risk node (the node where the anomaly appears earliest), randomly selects the next node according to the edge weight probability, and repeats the iteration until no new node can be reached, forming a complete path.

[0038] Key parameter design: Limit on the number of walk steps: Set the maximum number of steps (such as 10 steps) according to the scale of the marine network (for example, a ship local area network usually contains 10 - 50 nodes) to avoid redundancy caused by overly long paths; Restart probability: Set a certain probability (such as 15%) to return from the current node to the starting point and start walking again to ensure coverage of multi-branch paths (for example, an attack may spread to multiple devices simultaneously); Weight decay factor: Reduce the influence of edge weights as the number of steps increases to simulate the energy decay of threat propagation (for example, the later nodes are less directly affected by the initial attack).

[0039] Generation of candidate attack chains: Through multiple random walks (such as 100 times), collect all non-repeating valid paths to form a set of candidate attack chains. Each candidate chain contains information such as a node sequence, total propagation time, cumulative threat intensity value, etc. (for example, [(A,t1)→(B,t2)→(C,t3)], total time consumption 30 minutes, intensity accumulation 0.85).

[0040] Calculate the graph structure similarity between the candidate attack chain and the historical attack pattern, and select the path with similarity higher than the preset value as the initial attack chain boundary.

[0041] It should be noted that the construction of the historical attack pattern library stores the typical path structure of known marine network attack cases (such as the chain structure of "port scanning → vulnerability exploitation → data theft"), and each pattern is saved in the form of a graph structure (including node type, edge relationship, key step sequence, etc.).

[0042] Graph structure similarity calculation method: adopt a weighted combination of "graph edit distance" and "node attribute matching degree". Graph edit distance: quantifies the minimum operations required to transform the candidate chain graph into the historical pattern graph (such as node addition / deletion, edge direction change). The smaller the value, the more similar the structure. Node attribute matching degree: compares the consistency of threat type, port service and other attributes of the corresponding nodes in the candidate chain and the historical pattern (if both contain the "SSH port (22) brute force cracking" node, the matching degree is high).

[0043] The method for analyzing the spatiotemporal distribution of the high-risk threat area coordinate set and constructing the attack causal graph model is specifically as follows: Each high-risk threat coordinate point is used as a graph node, and the node attributes include the threat type weight; It should be noted that: Basic identification: Each node corresponds to a specific threat point in the high-risk threat area coordinate set, contains core identification information (IP address, port number, timestamp), and uniquely determines the network location and time when the threat occurred; Threat type weight: A core attribute of a node, quantifying the risk level and type characteristics of the threat point. For example, type classification includes common marine network threat types such as port scanning (weight 0.3), brute force cracking (0.5), data leakage (0.8), and remote control (0.9). Weight calculation combines the destructiveness of the threat behavior (e.g., data leakage has a higher weight than port scanning), target importance (e.g., attacking navigation servers has a higher weight than attacking ordinary sensors), and frequency of occurrence (multiple anomalies from the same IP address are weighted cumulatively). Extended attributes include device type (ship terminal / underwater sensor / shore-based server), subnet (e.g., ship A's local area network / ocean communication network), and protocol type (e.g., satellite communication protocol / underwater acoustic communication protocol), providing a multi-dimensional basis for subsequent causal associations.

[0044] In view of the special characteristics of marine equipment, "mobility coefficient" (such as 0.8 for ship nodes and 0.2 for fixed shore-based nodes) and "communication stability" (such as underwater sensors may have an instability coefficient of 0.3 due to signal attenuation) are added to the node attributes to correct subsequent causal strength calculations.

[0045] Calculate the transition probability between nodes based on time sequence and protocol correlation; It should be noted that for two nodes u (timestamp t1) and v (timestamp t2), if t2 > t1 (v occurs after u), there is a possibility of propagation from u to v. The smaller the time interval Δt = t2 - t1, the higher the basic value of the transfer probability (for example, the basic value is 0.8 when Δt < 5 minutes and drops to 0.2 when Δt > 30 minutes). If t2 < t1, the probability of propagation from v to u is 0 (excluding the causal relationship of time reversal).

[0046] Analyze the protocol interaction relationships involved in nodes u and v. For example: If the abnormal port of u is 80 (HTTP) and the abnormal port of v is 3306 (MySQL), and there is a business call relationship from HTTP to the database between the two, the protocol correlation degree is 0.7; if u uses the ship-specific AIS protocol and v uses the ordinary TCP protocol with no business intersection, the correlation degree is 0.1.

[0047] The transfer probability P(u→v) from node u to v = α × time factor + (1 - α) × protocol correlation degree, where α is the weight coefficient (usually taken as 0.6, giving priority to time sequence).

[0048] For example: from u (t1 = 10:00, HTTP protocol) to v (t2 = 10:03, MySQL protocol), the time factor is 0.8 and the protocol correlation degree is 0.7, then P(u→v) = 0.6×0.8 + 0.4×0.7 = 0.76.

[0049] Adopt the maximum information coefficient method to quantify the causal strength between nodes, and retain the edges whose strength exceeds the threshold; It should be noted that MIC is an index to measure the non-linear correlation strength between two variables (the value range is 0 - 1), which can effectively capture the complex causal relationships in network threats (such as indirect effects of non-direct propagation, attack effects with delayed onset), and overcome the limitations of traditional linear correlation analysis.

[0050] Taking the multi-dimensional attributes (threat type, device type, subnet information, time difference, etc.) of nodes u and v as variables, calculate the MIC value between the two to obtain the basic causal strength. For example: If both u and v are of the "brute force cracking" type and belong to the same ship subnet, the MIC value is 0.8; if u is "port scanning" and v is "data leakage", but they belong to different subnets and have no protocol correlation, the MIC value is 0.2.[[ID=第十八条]]

[0051] Combining the transfer probability and the MIC value, calculate the final causal strength: the causal strength S(u→v) = P(u→v) × MIC(u,v). Set a threshold (such as 0.5, which can be dynamically adjusted according to the network scale), and only retain the directed edges where S(u→v) > the threshold, filtering out the redundant edges with weak associations to ensure the simplicity and effectiveness of the graph structure.

[0052] The transition probability and causal strength are integrated to construct a weighted directed attack causal graph.

[0053] It should be noted that the final composition of the graph structure is as follows: Node set: all high-risk threat coordinate points (including attribute information); Directed edge set: screened strong causal correlation edges, whose direction is determined by time sequence (from earlier occurrence nodes to later occurrence nodes); Edge weight: Using the fusion value S(u→v), it reflects both the transfer possibility (P) and the causal correlation (MIC). The higher the weight, the more credible the propagation path.

[0054] Dynamic update mechanism: As new high-risk threat coordinate points are added (such as new anomalies detected in real time), the attack causal graph will dynamically iterate: new nodes are added and their causal strength with existing nodes is calculated; if the weight of the new edge exceeds the threshold, it is added to the graph; and the weight of the existing edge is re-evaluated (for example, the new node may strengthen or weaken the existing causal relationship).

[0055] To address issues such as satellite communication delays and underwater equipment time lags, a "time elastic window" (such as allowing a time error of ±3 minutes) is introduced to avoid misjudgment of causal relationships due to communication delays; for mobile nodes (such as ships), the subnet association is corrected according to their navigation trajectory to ensure the accuracy of cross-regional propagation paths.

[0056] The multi-dimensional security assessment function is constructed, and a hybrid multi-objective optimization algorithm is used to make an evolutionary decision on the initial attack chain boundary, output the optimal protection response plan and execute it. Specifically, Construct a multi-dimensional security assessment function that includes resource consumption, response time, and risk coverage; It should be noted that this process is divided into four progressive steps, from building an assessment system to outputting the optimal solution, forming a complete decision-making optimization chain: building a multi-dimensional security assessment function that includes resource consumption, response time, and risk coverage; Design logic for evaluation dimensions: Aiming at the core demand for marine cybersecurity protection (rapidly covering risks with limited resources), three dimensions are designed that are mutually constrained and require coordinated optimization: Resource consumption function (f1): Quantifies the cost of various resources required to implement the protection plan, including: Hardware resources: such as the number of rules enabled in the firewall and the computing power utilization rate of the isolation device; communication resources: such as the bandwidth occupied by encrypted transmission (the bandwidth of marine satellite communications is usually limited); labor costs: such as the time cost of manual intervention (the human response delay is high in offshore scenarios); function form: f1=ω1×hardware utilization rate+ω2×bandwidth consumption+ω3×manpower hours (ω is the weight of each resource, which is dynamically adjusted according to the real-time resource shortage).

[0057] Response time function (f2): Measures the execution speed and effectiveness time of protective measures. Key indicators include: decision delay: the time from attack chain identification to solution generation; execution delay: the time it takes for the solution to be delivered to the device and take effect (ship-to-shore communication delay needs to be considered); threat containment time: the time from the execution of protection to the cessation of threat spread; function form: f2 = τ1 × decision delay + τ2 × execution delay + τ3 × containment time (τ is the time weight, and the τ3 weight is significantly increased in emergency threat scenarios).

[0058] Risk coverage function (f3): Evaluates the interception effect of the protection scheme on the attack chain. The core indicators include: key node protection rate: the protection coverage rate of core equipment in the attack chain (such as navigation servers); attack path blocking rate: the proportion of paths that are effectively cut off in the initial attack chain boundary; secondary threat prevention rate: the potential spread risk avoided by protection measures (such as preventing the attack from spreading to other ships); function form: f3=1-(λ1×proportion of unprotected nodes+λ2×proportion of unblocked paths+λ3×secondary risk probability) (the larger the value, the better the coverage effect).

[0059] There are natural contradictions among the three functions (for example, a solution with low resource consumption may have insufficient coverage, and a solution with fast response may consume too many resources), and a balance point needs to be found through multi-objective optimization.

[0060] The initial attack chain boundary is encoded as a chromosome population, and the improved NSGA-Ⅲ algorithm is used for non-dominated sorting; It's important to note that the chromosome encoding method converts the protection decision variables (e.g., the protection measures for each node: blocking, monitoring, or encryption) in the initial attack chain boundary into a gene sequence. For example, the gene locus corresponds to each node or path in the attack chain; the allele represents the specific protection action (e.g., 0 = no action, 1 = port blocking, 2 = traffic encryption, 3 = device isolation); and the chromosome length is equal to the number of nodes / paths requiring decision making in the attack chain (e.g., if there are 10 nodes, the chromosome length is 10). For example, the chromosome "1-2-3-0-1" means blocking node 1, encrypting node 2, isolating node 3, not taking action on node 4, and blocking node 5.

[0061] Improved core optimizations of the NSGA-III algorithm: NSGA-III is a classic algorithm for multi-objective optimization, with three improvements for marine scenarios: Dynamic adjustment of reference points: Dynamically adjusts the distribution of reference points based on the risk level of the attack chain (e.g., extremely high risk when involving nuclear-powered ships), prioritizing the optimization of high-risk dimensions; Improved convergence speed: Introduces attack chain topology complexity factors (e.g., the number of path branches), adopts a fast convergence strategy for simple attack chains, and employs a refined search for complex chains (multi-branch, cross-subnet); Enhanced constraint processing: Incorporates marine network-specific constraints (e.g., energy consumption limits for underwater sensors, latency constraints for satellite communications), and prioritizes eliminating solutions that violate hard constraints during sorting.

[0062] The initial chromosome population (i.e., candidate protection schemes) is classified according to "dominance relationship": if scheme A is better than scheme B in all three evaluation dimensions, then A dominates B. Through multiple rounds of comparison, the population is divided into different levels of non-dominated layers (the first layer is the optimal solution candidate, the second layer is the optimal solution candidate), providing direction for subsequent optimization.

[0063] The quantum rotating gate mechanism is introduced to perform adaptive crossover mutation and generate the Pareto optimal solution set; It should be noted that: the role of the quantum revolving door mechanism: drawing on the superposition state idea of ​​quantum computing, each gene locus represents the choice of protective action in the form of probability (for example, a node has a 30% probability of being blocked and a 50% probability of being monitored), and the probability distribution is adjusted through the quantum revolving door: rotation angle design: dynamic adjustment according to the dominance level of the current solution (the higher the dominance level, the smaller the rotation angle to avoid destroying high-quality solutions); adaptive strategy: increase the mutation probability for dimensions with slow convergence (such as stagnation of risk coverage improvement), and reduce the mutation amplitude for dimensions that have been well optimized (such as resource consumption).

[0064] Crossover and mutation operations are adapted to marine scenarios: Crossover operator: prioritizes retaining the protection genes of key paths in the attack chain (such as the path leading to the shore-based center) to ensure the stability of the core protection strategy; Mutation operator: sets a higher mutation probability for the protection genes of mobile nodes (such as ships) (because changes in the ship's position may cause the original plan to become invalid).

[0065] Generation of a Pareto-optimal solution set: Through multiple iterations (e.g., 50-100 generations), the algorithm converges to a set of "non-dominated solutions." Each solution in the solution set has a different emphasis on the three evaluation dimensions (e.g., Solution X has low resource consumption but medium coverage, while Solution Y has high coverage but slightly slower response). No solution is superior to others in all dimensions, forming an "optimal trade-off set."

[0066] The optimal protection response plan is selected from the Pareto solution set based on the entropy weight TOPSIS method.

[0067] It should be noted that the advantages of the entropy weight TOPSIS method are: it combines the entropy weight method (objective weighting) and the TOPSIS method (approximating the ideal solution), avoids the deviation of subjective weight setting, and is suitable for the decision-making needs of multiple stakeholders in the ocean network (such as shipping companies and maritime departments).

[0068] Specific implementation steps: Standardization processing: standardize the three evaluation index values ​​of each plan in the Pareto solution set (eliminate dimensional differences); entropy weight calculation: calculate the weight according to the degree of dispersion of the index value (for example, the weight is higher if the risk coverage fluctuates greatly); determination of ideal solution and negative ideal solution: the ideal solution is the combination of optimal values ​​of each dimension, and the negative ideal solution is the combination of worst values ​​of each dimension; closeness calculation: the closer each plan is to the ideal solution and the farther it is from the negative ideal solution, the higher the closeness; selection of the optimal plan: select the plan with the highest closeness as the final protection response plan.

[0069] Decision preference adjustment for ocean scenarios: Emergency scenarios (such as attacks that have endangered navigation safety): Increase the weight of response time through entropy weight correction; Resource-constrained scenarios (such as limited resources for ocean-going ships): Increase the weight of resource consumption; Protection of key facilities (such as submarine optical cable nodes): Increase the weight of risk coverage.

[0070] The initial attack chain boundary is encoded as a chromosome population, and the improved NSGA-III algorithm is used for non-dominated sorting, specifically: K-means++ is used to initialize the reference point set and dynamically adjust the reference point distribution; It should be noted that the limitations of traditional NSGA-III are: Traditional NSGA-III uses fixed reference points (e.g., evenly distributed in the target space). However, the optimization objectives of the marine cyber attack chain (resource consumption, response time, and risk coverage) vary significantly in importance in different scenarios (e.g., wartime scenarios focus more on response time, while daily scenarios focus more on resource consumption). Fixed reference points are difficult to adapt to such dynamic needs.

[0071] Advantages of K-means++ initialization: First, the Pareto optimal solutions of historical optimization cases are clustered (K-means++ algorithm) to identify dense areas of solutions in the target space. Initial reference points are set based on cluster centers, so that the reference points are naturally close to the actual distribution of valuable solutions, reducing ineffective searches. For example, if historical data shows a high proportion of solutions with "low resource consumption + medium coverage" (which meets the daily protection needs of ships), the initial reference points will be more densely distributed in this area.

[0072] Dynamic adjustment mechanism: After each iteration (e.g., 20 generations), the matching degree between the current population and the reference points is calculated. If the quality of the solution in a certain area continues to decline (e.g., convergence of the solution in a high-coverage area stagnates), the number of reference points in that area is automatically increased. The range of reference points is dynamically contracted or expanded (e.g., expanding the distribution of reference points in the resource consumption dimension as the attack chain scales up) based on real-time changes in the attack chain (e.g., adding new threat nodes causing target space offsets). Marine scenario adaptation: Preset reference point adjustment rules are implemented for different sea areas (nearshore / open-sea) and different ship types (commercial / military). For example, in the military ship scenario, the reference point density in the "high coverage" area is always maintained.

[0073] Introducing convolutional neural networks to predict the convergence trend of the solution set and adaptively adjust the crossover probability; It is important to note the role and challenges of crossover probability: Crossover probability (PC) controls the probability of exchanging genes between two parent chromosomes in the algorithm. A high PC can easily destroy high-quality genes, while a low PC can slow convergence. Traditional NSGA-III uses a fixed or linearly adjustable PC, which is difficult to adapt to the complex convergence dynamics of attack chain optimization.

[0074] The prediction mechanism of the convolutional neural network (CNN): Input design: The non-dominated layer distribution, objective function value matrix, and attack chain topology characteristics (such as the number of nodes and the number of path branches) of the current population are converted into a multidimensional feature graph as the CNN input; Output target: Predict the convergence indicators of the next generation population (such as the distribution entropy of the solution in the target space and the improvement of the optimal solution); Training data: The model is trained using the population status during the historical optimization process and the subsequent convergence results, so that it can accurately predict the impact of different PCs on convergence.

[0075] Adaptive adjustment strategy: If the CNN predicts "slow convergence" (e.g., a slow decrease in the solution distribution entropy), the Pc is increased (e.g., from 0.6 to 0.8) to enhance population diversity. If the prediction is "large fluctuations in solution quality" (e.g., large alternations in the optimal solution), the Pc is reduced (e.g., from 0.6 to 0.4) to stabilize high-quality genes. Special handling for marine scenarios: When the attack chain includes underwater sensor nodes (whose protection decisions are strongly constrained by energy consumption), the CNN will additionally input the "energy sensitivity" feature, so that the Pc adjustment focuses more on retaining low-energy solutions.

[0076] A crowding operator based on topological structure similarity is designed to optimize the distribution of solution sets.

[0077] It should be noted that the traditional crowding operator has a flaw: the traditional NSGA-III measures crowding by calculating the neighborhood density of the solution in the target space, but ignores the topological correlation of the attack chain protection scheme. Two solutions that are close to each other in the target space may correspond to very different protection topologies (for example, one blocking path A and the other blocking path B), resulting in insufficient actual diversity of the solution set.

[0078] Quantification of topological similarity: Each chromosome (protection scheme) is converted into a "protection topology graph" where nodes represent attack chain nodes and edges represent the synergistic relationships between protection measures (e.g., if nodes u and v are blocked simultaneously, a synergistic edge exists). The similarity between two protection topologies is calculated using the "graph edit distance": the smaller the distance, the more similar the topologies (e.g., if there is only one difference in protection node, the distance is 1). Combining the target space distance and topological similarity, a comprehensive crowding index is constructed: crowding = α × target space distance + (1-α) × (1-topological similarity), (α is the weight, usually 0.4, giving priority to ensuring topological diversity).

[0079] The optimization function of the operator: In non-dominated sorting, solutions with low congestion (spreading targets and large topological differences) are given higher selection priority. This prevents the emergence of a large number of redundant solutions in the population with similar target values ​​but identical protection logic, ensuring that the Pareto solution set includes a more diverse range of protection strategies (such as those focusing on node isolation and traffic encryption). Furthermore, for marine scenarios, the operator adds a weight for "subnet boundary protection" in the topological similarity calculation for cross-subnet attack chains (such as ship-satellite-shore base), ensuring that the solution set includes a sufficient number of cross-network collaborative protection solutions.

[0080] Example 2: Figures 5 to 9 The system of the data analysis and management method based on marine network security of the present invention is provided, including: Dynamic perception module, used to collect multi-source network data in real time and construct spatiotemporal correlation feature tensors; Topology modeling module, used to generate dynamic topology diagrams of network behavior and stability measures; Threat location module, used to identify abnormal behavior clusters and generate a set of high-risk threat area coordinates; Attack deduction module, used to reconstruct the attack path and generate the initial attack chain boundary; The decision optimization module is used to perform multi-objective optimization and output the optimal protection response plan.

[0081] The above formulas are all dimensionless and numerical calculations. The formulas are obtained by collecting a large amount of data and performing software simulation to obtain the most recent real situation. The preset parameters in the formulas are set by technicians in this field according to actual conditions.

[0082] The above embodiments may be implemented in whole or in part through software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments may be implemented in whole or in part in the form of a computer program product.

[0083] Those skilled in the art will appreciate that the modules and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0084] In addition, each functional module in each embodiment of the present application may be integrated into one processing module, or each module may exist physically separately, or two or more modules may be integrated into one module.

[0085] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

[0086] Finally: The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. A data analysis and management method based on marine network security, characterized in that: The following steps are involved: Collect multi-source marine network equipment traffic and log data in real time, build dynamic heterogeneous data streams, and extract spatiotemporal correlation feature tensors; Perform behavioral topology modeling on spatiotemporal correlation feature tensors, generate dynamic topological graphs of network behavior, and calculate topological stability measures; Abnormal behavior detection is performed based on topological stability measurement, and abnormal behavior clusters are identified through multi-scale spectral clustering algorithm to generate a coordinate set of high-risk threat areas; Reconstruct the attack path of the high-risk threat area coordinate set and generate the initial attack chain boundary using the spatiotemporal graph model matching algorithm; Construct a multi-dimensional security assessment function, use a hybrid multi-objective optimization algorithm to make evolutionary decisions on the initial attack chain boundary, output the optimal protection response plan and execute it.

2. The data analysis and management method based on marine network security according to claim 1 is characterized by: The behavior topology modeling of the spatiotemporal correlation feature tensor is performed to generate a network behavior dynamic topology graph and calculate the topology stability measure, specifically: Parse the three-dimensional data of protocol type, packet size, and access frequency in the spatiotemporal correlation feature tensor and construct a dynamic attribute graph; Calculate the behavioral correlation matrix between nodes in the attribute graph and introduce persistent homology theory to extract topologically invariant features; Fusion of behavioral association matrix and topology invariant features to generate weighted network behavior dynamic topology graph; The rate of change of the Betti number of the topological graph on consecutive time slices is calculated as a measure of topological stability.

3. The data analysis and management method based on marine network security according to claim 2 is characterized by: The abnormal behavior detection is performed based on the topological stability measurement, and the abnormal behavior clusters are identified by the multi-scale spectral clustering algorithm to generate the coordinate set of the high-risk threat area. Specifically: Map the topological stability measure to the Riemannian manifold space and construct the behavioral geodesic distance matrix; The spectral clustering algorithm modified by Mahalanobis distance is used to perform eigendecomposition on the behavioral geodesic distance matrix; Adaptively cluster feature vectors using a Dirichlet process mixture model to identify clusters of abnormal behaviors exceeding a risk threshold. Extract the IP coordinates, port vectors, and timestamps of nodes in the abnormal behavior cluster to generate a coordinate set of high-risk threat areas.

4. The data analysis and management method based on marine network security according to claim 3 is characterized by: The attack path is reconstructed for the high-risk threat area coordinate set, and the initial attack chain boundary is generated using the spatiotemporal graph model matching algorithm, specifically: Analyze the spatiotemporal distribution of high-risk threat area coordinate sets and construct an attack causal graph model; Use random walk algorithm to simulate threat propagation paths and generate candidate attack chains; Calculate the graph structure similarity between the candidate attack chain and the historical attack pattern, and select the path with similarity higher than the preset value as the initial attack chain boundary.

5. The data analysis and management method based on marine network security according to claim 4 is characterized in that: The method for analyzing the spatiotemporal distribution of the high-risk threat area coordinate set and constructing the attack causal graph model is specifically as follows: Each high-risk threat coordinate point is used as a graph node, and the node attributes include the threat type weight; Calculate the transition probability between nodes based on time sequence and protocol correlation; The maximum information coefficient method is used to quantify the causal strength between nodes, and edges with strength exceeding the threshold are retained; The transition probability and causal strength are integrated to construct a weighted directed attack causal graph.

6. The data analysis and management method based on marine network security according to claim 5 is characterized by: The multi-dimensional security assessment function is constructed, and a hybrid multi-objective optimization algorithm is used to make an evolutionary decision on the initial attack chain boundary, output the optimal protection response plan and execute it. Specifically, Construct a multi-dimensional security assessment function that includes resource consumption, response time, and risk coverage; The initial attack chain boundary is encoded as a chromosome population, and the improved NSGA-Ⅲ algorithm is used for non-dominated sorting; The quantum rotating gate mechanism is introduced to perform adaptive crossover mutation and generate the Pareto optimal solution set; The optimal protection response plan is selected from the Pareto solution set based on the entropy weight TOPSIS method.

7. The data analysis and management method based on marine network security according to claim 6 is characterized by: The initial attack chain boundary is encoded as a chromosome population, and the improved NSGA-III algorithm is used for non-dominated sorting, specifically: K-means++ is used to initialize the reference point set and dynamically adjust the reference point distribution; Introducing convolutional neural networks to predict the convergence trend of the solution set and adaptively adjust the crossover probability; A crowding operator based on topological structure similarity is designed to optimize the distribution of solution sets.

8. A data analysis and management system based on marine network security, used to implement the method described in any one of claims 1 to 7, characterized in that: include: Dynamic perception module, used to collect multi-source network data in real time and construct spatiotemporal correlation feature tensors; Topology modeling module, used to generate dynamic topology diagrams of network behavior and stability measures; Threat location module, used to identify abnormal behavior clusters and generate a set of high-risk threat area coordinates; Attack deduction module, used to reconstruct the attack path and generate the initial attack chain boundary; The decision optimization module is used to perform multi-objective optimization and output the optimal protection response plan.

Citation Information

Patent Citations

  • Computer network security intelligent analysis system and method based on big data

    CN117896137A

  • Network security management system based on big data

    CN119172150A

  • Multi-source heterogeneous ocean data intelligent fusion and ocean disaster prediction method and platform

    CN119623766A

  • Complexity-based ship dynamic clustering method

    CN119646557A

  • Intelligent maritime affair security situation awareness system and method

    CN120257200A

Cited By

  • Intelligent business process analysis method and system for multi-modal data

    CN121836330A