Network security situation real-time perception and visual display system

The network security situation awareness system, which integrates real-time data collection, intelligent analysis and situation assessment, and automatic decision-making and disposal, solves the problem of insufficient ability to identify new or unknown threats in existing technologies, achieves efficient security situation profiling and rapid response, and improves the automation and intelligence level of network security.

CN120639445APending Publication Date: 2025-09-12李师谦
View PDF 0 Cites 5 Cited by

Patent Information

Application Number
CN202510957399.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-11
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

The existing network security situation awareness system has limited ability to identify new or unknown threats in terms of threat detection and situation understanding, and lacks the ability to correlate multi-source security events and restore the overall threat chain, making it difficult to form a comprehensive, accurate, and real-time security situation portrait. In addition, the response decision-making is slow and the execution efficiency is low, making it difficult to meet the needs of rapid closed-loop disposal.

Method used

The real-time data acquisition module, intelligent analysis and situation assessment module, three-dimensional visualization display module and automatic decision-making and disposal module are used to realize real-time collection, intelligent analysis, intuitive display and automated decision-making of multi-source data. Combined with unsupervised anomaly detection, supervised machine learning and time series event correlation analysis, a multi-dimensional security indicator system is constructed for automated disposal.

Benefits of technology

It improves the accuracy of identifying unknown anomalies and known threats, enhances the ability to restore multi-stage attack links, realizes real-time and accurate global situation profiling and rapid closed-loop management, improves security situation understanding and decision-making efficiency, and reduces manual burden.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120639445A_ABST
    Figure CN120639445A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of network security, and discloses a network security situation real-time perception and visual display system, which comprises the following modules: a real-time data acquisition module, an intelligent analysis and situation evaluation module, a three-dimensional visual display module and an automatic decision processing module. According to the system, dual mechanisms of unsupervised anomaly detection and a supervised machine learning model are fused through an intelligent analysis and situation evaluation module, the recognition precision of unknown anomaly and known threats is improved, and warning, abnormal traffic and asset vulnerability are deeply correlated by using a time sequence event correlation analysis technology; according to the method and the system, the real-time and accurate global situation portrait is formed, meanwhile, a multi-dimensional safety index quantification system is constructed by means of a situation evaluation unit, and a scientific basis is provided for risk hotspot identification and early warning in combination with threat intelligence, asset vulnerability, service criticality and topology dynamic calculation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network security technology, and specifically relates to a real-time perception and visualization display system for network security situation. Background Art

[0002] The rapid development of information technology has profoundly changed the way society operates. Cyberspace has become an important carrier of the country's critical infrastructure and economic and social activities. At the same time, network security threats continue to escalate, and attack methods are becoming increasingly complex, covert, and large-scale. New risks such as advanced persistent threats, ransomware, and supply chain attacks are emerging in an endless stream, which has put higher demands on the real-time perception, accurate analysis, and rapid response capabilities of network security.

[0003] As a key support for improving active defense capabilities, the development and application of network security situation awareness technology has attracted much attention. However, current network security situation awareness systems still have many defects in actual deployment and application. In terms of threat detection and situation understanding, existing methods have limited ability to identify increasingly complex network attack behaviors, especially new or unknown threats. They are also insufficient in analyzing the correlation between multi-source security events and restoring the overall threat chain, making it difficult to form a comprehensive, accurate, and real-time security situation portrait. There is often a lack of scientific, dynamic, and multi-dimensional quantitative methods for security situation assessment, making it difficult to effectively support the accurate identification and early warning of risk hotspots. In terms of situation presentation, there are generally problems such as low information density, poor intuitiveness, and insufficient interactive flexibility. It is difficult to clearly and dynamically reflect the global security status, risk distribution, and threat evolution process in complex network environments. In addition, in the handling of security incidents, response decisions are slow and execution efficiency is low, making it difficult to meet the practical needs of rapid closed-loop handling of security incidents. The level of automation and intelligence needs to be improved urgently. Summary of the Invention

[0004] The purpose of the present invention is to provide a real-time perception and visualization display system for network security situation to solve the problems raised in the above background technology.

[0005] In order to achieve the above-mentioned object, the present invention provides the following technical solution: a network security situation real-time perception and visualization display system, comprising the following modules: a real-time data acquisition module, an intelligent analysis and situation assessment module, a three-dimensional visualization display module, and an automatic decision-making and disposal module; The real-time data acquisition module is used to collect multi-source data and connect with the external threat intelligence platform, and process the collected multi-source data; The intelligent analysis and situation assessment module is used to analyze and detect abnormal behaviors and quantitatively assess the security situation; The three-dimensional visualization display module is used to intuitively present and interactively control the network security status, improving security personnel's understanding and control efficiency of the network security situation; The automatic decision-making and handling module is used to make automatic decisions and handle security incidents, thereby achieving rapid closed-loop handling of security incidents.

[0006] Preferably, the real-time data acquisition module includes a multi-source data access unit and a threat intelligence access unit; the multi-source data access unit adopts data packet capture technology to implement full-flow mirroring collection of core links and border nodes, fully supports IPv6 protocol and encrypted traffic metadata analysis, combines encrypted traffic metadata and traffic behavior feature analysis technology to identify potential abnormal behavior patterns in traffic, and for device log collection, through standardized log collection agents, realizes full docking of heterogeneous devices such as firewalls, intrusion detection systems, servers, and terminals; the threat intelligence access unit constructs a multi-source intelligence fusion interface to realize docking with public threat intelligence platforms and industry intelligence sharing networks.

[0007] Preferably, the real-time data acquisition module includes an edge preprocessing unit, which is used to clean, compress and unify the data format, and adopt a combination of rule matching engine and pattern recognition technology to identify and filter invalid traffic, repeated alarms and known benign data in real time, and at the same time establish unified data rules to convert and map raw data from different sources and different formats.

[0008] Preferably, the intelligent analysis and situation assessment module includes a real-time stream processing unit, which is used to perform real-time analysis on the pre-processed data, use an unsupervised anomaly detection algorithm based on an autoencoder to identify unknown abnormal behavior patterns that deviate from the normal baseline, and combine a supervised machine learning model based on a convolutional neural network to detect known threats that match historical malicious behavior characteristics; at the same time, the time series event correlation analysis technology is applied to preliminarily correlate and aggregate scattered alarm events, traffic anomaly indicators and asset vulnerability status, identify event sequences with potential causal relationships or belonging to the same attack activity, and provide clues input for subsequent in-depth analysis of multi-stage attack behaviors.

[0009] Preferably, the intelligent analysis and situation assessment module includes a situation assessment unit, which is used to build a security indicator system, conduct quantitative assessment of the security situation, and design a multi-dimensional security indicator set covering network availability, threat frequency, and asset risk index. In addition, the module combines the asset vulnerability status, business system criticality, network topology, user behavior baseline, historical attack patterns and current threat intelligence during the assessment to provide early warning of potential attack hotspots and high-risk vulnerabilities that may be exploited.

[0010] Preferably, the three-dimensional visualization display module includes a multi-dimensional situation modeling unit, which is used to construct a dynamic three-dimensional display model, which can render the device status, traffic flow and attack path in real time, and intuitively represent the security risk level through color gradient, and streamline animation to display the attack traffic propagation path.

[0011] Preferably, the three-dimensional visualization display module includes an interactive display unit, which provides a visualization editing tool, allowing users to flexibly customize the display dimensions according to their own business needs, such as displaying the security situation by dimensions such as region, business system, threat type, etc., and supports template saving and sharing.

[0012] Preferably, the automatic decision-making and handling module includes an intelligent decision-making unit for evaluating the threat level when the system is attacked by combining multiple factors such as the scope of attack impact, asset importance, and difficulty of threat exploitation, and automatically matching the optimal handling plan according to the characteristics of the security incident. When matching the handling plan, the reinforcement learning strategy evaluation framework is combined with the analysis of historical handling effect data to continuously improve the recommendation accuracy and ensure the effectiveness and pertinence of the handling strategy. Before executing the automated handling, a risk report is produced based on the impact of the handling measures on the business.

[0013] Preferably, the automatic decision-making and disposal module includes an automated disposal unit, which issues disposal instructions according to the intelligent decision-making unit, and links defense execution with firewalls, WAFs, terminal security management systems and other equipment to achieve operations such as attack traffic blocking, suspicious account locking, and vulnerability patch push. When the disposal is successful, a disposal report is automatically generated and displayed through a three-dimensional visualization display module. When a disposal conflict or execution failure is detected, an alarm is automatically triggered.

[0014] The beneficial effects of the present invention are as follows: This system integrates the dual mechanisms of unsupervised anomaly detection and supervised machine learning models through intelligent analysis and situation assessment modules to improve the accuracy of identifying unknown anomalies and known threats. It also uses time series event correlation analysis technology to deeply correlate alarms, abnormal traffic and asset vulnerabilities, enhance the ability to restore multi-stage attack links, and form a real-time and accurate global situation portrait. At the same time, it relies on the situation assessment unit to build a multi-dimensional security indicator quantification system, and combines threat intelligence, asset vulnerability, business criticality and topology dynamic calculation to provide a scientific basis for risk hotspot identification and early warning; through dynamic three-dimensional models, color gradients and streamlined animations are used to intuitively present device status, attack paths and risk levels, improve situation understanding and decision-making efficiency, automatically match the optimal disposal plan when encountering security incidents, and link firewalls, WAFs and other devices to perform automated blocking and isolation operations and generate reports, significantly shortening response time, achieving efficient closed-loop management of security incidents, and reducing manual burden. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] Figure 1 This is a system block diagram of the present invention. DETAILED DESCRIPTION

[0016] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0017] like Figure 1 As shown, the embodiment of the present invention provides a real-time perception and visualization display system for network security situation, including the following modules: real-time data acquisition module, intelligent analysis and situation assessment module, three-dimensional visualization display module, and automatic decision-making and disposal module; The real-time data collection module is used to collect multi-source data and connect with external threat intelligence platforms, while also processing the collected multi-source data; The intelligent analysis and situation assessment module is used to analyze and detect abnormal behaviors and quantitatively assess security situations; The 3D visualization display module is used to intuitively present and interactively control the network security status, improving security personnel's understanding and control efficiency of the network security situation; The automatic decision-making and handling module is used to make automated decisions and handle security incidents, achieving rapid closed-loop handling of security incidents.

[0018] The real-time data acquisition module collects internal multi-source security data and external threat intelligence data, and the intelligent analysis and situation assessment module dynamically detects, analyzes and quantitatively evaluates abnormal network behavior. The three-dimensional visualization display module then intuitively presents the security situation assessment results and event information. The final automatic decision-making and disposal module makes automated decisions and disposal executions on identified security incidents based on the aforementioned analysis and evaluation results, driving efficient and rapid closed-loop management of security incidents.

[0019] Among them, the real-time data collection module includes a multi-source data access unit and a threat intelligence access unit; the multi-source data access unit uses packet capture technology to implement full-flow mirroring collection of core links and border nodes, fully supports IPv6 protocol and encrypted traffic metadata analysis, and combines encrypted traffic metadata and traffic behavior feature analysis technology to identify potential abnormal behavior patterns in traffic. For device log collection, through standardized log collection agents, it realizes the full docking of heterogeneous devices such as firewalls, intrusion detection systems, servers, and terminals; the threat intelligence access unit builds a multi-source intelligence fusion interface to achieve docking with public threat intelligence platforms and industry intelligence sharing networks.

[0020] By building a threat intelligence access unit to synchronize the latest threat intelligence data in real time, these external threat intelligence can provide important reference for the system's situation analysis and help discover potential security risks in advance.

[0021] Among them, the real-time data acquisition module includes an edge preprocessing unit, which is used to clean, compress and unify the data format. It adopts a combination of rule matching engine and pattern recognition technology to identify and filter invalid traffic, repeated alarms and known benign data in real time. At the same time, it establishes unified data rules to convert and map raw data from different sources and different formats.

[0022] The data processed by the edge preprocessing unit contains standardized core fields, forming a unified and standardized intermediate data format, providing a consistent and standardized data base for subsequent processing, and eliminating the analysis obstacles caused by data format differences.

[0023] Among them, the intelligent analysis and situation assessment module includes a real-time stream processing unit, which is used to perform real-time analysis of pre-processed data, use an unsupervised anomaly detection algorithm based on an autoencoder to identify unknown abnormal behavior patterns that deviate from the normal baseline, and combine it with a supervised machine learning model based on a convolutional neural network to detect known threats that match historical malicious behavior characteristics; at the same time, the time series event correlation analysis technology is used to preliminarily correlate and aggregate scattered alarm events, traffic anomaly indicators and asset vulnerability status, identify event sequences with potential causal relationships or belonging to the same attack activity, and provide clues for subsequent in-depth analysis of multi-stage attack behaviors.

[0024] Through the dual supervision mechanism of unsupervised learning algorithms and supervised learning models, accurate identification of abnormal situations in traffic can be achieved, thereby conducting comprehensive detection of known and unknown threats.

[0025] Among them, the intelligent analysis and situation assessment module includes a situation assessment unit. The situation assessment module is used to build a security indicator system, conduct quantitative assessment of the security situation, and design a multi-dimensional security indicator set covering network availability, threat frequency, and asset risk index. In the assessment, it combines the asset vulnerability status, business system criticality, network topology, user behavior baseline, historical attack patterns and current threat intelligence to provide early warning of potential attack hotspots and high-risk vulnerabilities that may be exploited.

[0026] By designing a situation assessment unit, we can achieve quantitative assessment of the security situation, provide a basis for security management, and enable security personnel to deploy defense measures in advance to reduce the possibility and impact of security incidents.

[0027] Among them, the three-dimensional visualization display module includes a multi-dimensional situation modeling unit, which is used to build a dynamic three-dimensional display model. It can render the device status, traffic flow and attack path in real time, and intuitively represent the security risk level through color gradient, and display the attack traffic propagation path through streamline animation.

[0028] By displaying the security situation using a three-dimensional model and using different colors and animations to represent different security data, the network security status is more intuitive.

[0029] Among them, the three-dimensional visualization display module includes an interactive display unit. The interactive display unit provides a visual orchestration tool that allows users to flexibly customize the display dimensions according to their own business needs, such as displaying the security situation by dimensions such as region, business system, and threat type, and supports template saving and sharing.

[0030] Through highly flexible custom design, different users can quickly configure personalized display views according to their own needs, thereby improving work efficiency.

[0031] Among them, the automatic decision-making and disposal module includes an intelligent decision-making unit for assessing the threat level when the system is attacked by combining multiple factors such as the scope of attack impact, asset importance, and difficulty of threat exploitation. It automatically matches the optimal disposal plan according to the characteristics of the security incident. When matching the treatment plan, it is based on the reinforcement learning strategy evaluation framework combined with the analysis of historical disposal effect data to continuously improve the accuracy of recommendations and ensure the effectiveness and pertinence of the disposal strategy. Before executing automated disposal, a risk report is produced based on the impact of the disposal measures on the business.

[0032] By combining multiple factors such as the scope of attack impact and historical processing effect data, a disposal plan is automatically generated to achieve rapid processing of security incidents.

[0033] Among them, the automatic decision-making and disposal module includes an automated disposal unit. The automated disposal unit issues disposal instructions based on the intelligent decision-making unit, and links defense execution with firewalls, WAFs, terminal security management systems and other equipment to achieve operations such as attack traffic blocking, suspicious account locking, and vulnerability patch push. When the disposal is successful, a disposal report is automatically generated and displayed through a three-dimensional visualization display module. When a disposal conflict or execution failure is detected, an alarm is automatically triggered.

[0034] Through the automated handling of security incidents, the efficiency of responding to security incidents is improved, and through the production of disposal reports, data support is provided for the evaluation of the disposal effect and experience summary of security incidents, which facilitates the continuous optimization of disposal processes and strategies.

[0035] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus.

[0036] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.

Claims

1. Network security situation real-time perception and visualization display system, characterized by: It includes the following modules: real-time data acquisition module, intelligent analysis and situation assessment module, 3D visualization display module, and automatic decision-making and disposal module; The real-time data acquisition module is used to collect multi-source data and connect with the external threat intelligence platform, and process the collected multi-source data; The intelligent analysis and situation assessment module is used to analyze and detect abnormal behaviors and quantitatively assess the security situation; The three-dimensional visualization display module is used to intuitively present and interactively control the network security status, improving security personnel's understanding and control efficiency of the network security situation; The automatic decision-making and handling module is used to make automatic decisions and handle security incidents, thereby achieving rapid closed-loop handling of security incidents.

2. The network security situation real-time perception and visualization display system according to claim 1 is characterized by: The real-time data acquisition module includes a multi-source data access unit and a threat intelligence access unit; the multi-source data access unit uses data packet capture technology to implement full-flow mirroring collection of core links and border nodes, fully supports IPv6 protocol and encrypted traffic metadata analysis, combines encrypted traffic metadata and traffic behavior feature analysis technology to identify potential abnormal behavior patterns in traffic, and for device log collection, through standardized log collection agents, realizes full docking of heterogeneous devices such as firewalls, intrusion detection systems, servers, and terminals; the threat intelligence access unit constructs a multi-source intelligence fusion interface to achieve docking with public threat intelligence platforms and industry intelligence sharing networks.

3. The network security situation real-time perception and visualization display system according to claim 1 is characterized by: The real-time data acquisition module includes an edge preprocessing unit, which is used to clean, compress and unify the data format. It uses a combination of a rule matching engine and pattern recognition technology to identify and filter invalid traffic, repeated alarms and known benign data in real time. At the same time, it establishes unified data rules to convert and map raw data from different sources and in different formats.

4. The network security situation real-time perception and visualization display system according to claim 1 is characterized by: The intelligent analysis and situation assessment module includes a real-time stream processing unit, which is used to perform real-time analysis on pre-processed data, use an unsupervised anomaly detection algorithm based on an autoencoder to identify unknown abnormal behavior patterns that deviate from the normal baseline, and combine it with a supervised machine learning model based on a convolutional neural network to detect known threats that match historical malicious behavior characteristics; at the same time, it uses time series event correlation analysis technology to preliminarily correlate and aggregate scattered alarm events, traffic anomaly indicators and asset vulnerability status, identify event sequences with potential causal relationships or belonging to the same attack activity, and provide clues for subsequent in-depth analysis of multi-stage attack behaviors.

5. The network security situation real-time perception and visualization display system according to claim 1 is characterized by: The intelligent analysis and situation assessment module includes a situation assessment unit, which is used to build a security indicator system, conduct a quantitative assessment of the security situation, and design a multi-dimensional security indicator set covering network availability, threat frequency, and asset risk index. In addition, the module combines the asset vulnerability status, business system criticality, network topology, user behavior baseline, historical attack patterns, and current threat intelligence during the assessment to provide early warning of potential attack hotspots and high-risk vulnerabilities that may be exploited.

6. The network security situation real-time perception and visualization display system according to claim 1 is characterized by: The three-dimensional visualization display module includes a multi-dimensional situation modeling unit, which is used to construct a dynamic three-dimensional display model, which can render the device status, traffic flow and attack path in real time, and intuitively represent the security risk level through color gradient, and streamline animation to display the attack traffic propagation path.

7. The network security situation real-time perception and visualization display system according to claim 1 is characterized by: The three-dimensional visualization display module includes an interactive display unit, which provides a visualization editing tool that allows users to flexibly customize display dimensions according to their own business needs, such as displaying security status by region, business system, threat type and other dimensions, and supports template saving and sharing.

8. The network security situation real-time perception and visualization display system according to claim 1 is characterized by: The automatic decision-making and disposal module includes an intelligent decision-making unit for evaluating the threat level when the system is attacked by combining multiple factors such as the scope of attack impact, asset importance, and difficulty of threat exploitation, and automatically matching the optimal disposal plan according to the characteristics of the security incident. When matching the disposal plan, it is based on the reinforcement learning strategy evaluation framework combined with the analysis of historical disposal effect data to continuously improve the accuracy of recommendations and ensure the effectiveness and pertinence of the disposal strategy. Before executing the automated disposal, a risk report is produced based on the impact of the disposal measures on the business.

9. The network security situation real-time perception and visualization display system according to claim 1 is characterized by: The automatic decision-making and disposal module includes an automated disposal unit, which issues disposal instructions according to the intelligent decision-making unit, and links defense execution with firewalls, WAFs, terminal security management systems and other equipment to achieve operations such as attack traffic blocking, suspicious account locking, and vulnerability patch push. When the disposal is successful, a disposal report is automatically generated and displayed through a three-dimensional visualization display module. When a disposal conflict or execution failure is detected, an alarm is automatically triggered.

Citation Information

Cited By

  • Network space security intelligent monitoring and analysis system

    CN121530762A

  • Network security situation awareness and analysis platform based on AI

    CN121547300A

  • Network autonomous operation and maintenance method and device fusing topology discovery and situation awareness

    CN121567544A

  • Device, method, medium and equipment for guaranteeing safe operation of rail transit signal system

    CN121608780A

  • Network situation display and auxiliary decision-making system

    CN121966997A