Network security multi-target monitoring system and monitoring method based on monitoring data
By dividing the network into multiple sub-domains and deploying network traffic feature collection modules in each sub-domain, and through the network security multi-target monitoring system that monitors data, comprehensive monitoring and dynamic adaptation of the network are achieved, thereby improving security early warning capabilities and decision-making accuracy.
Patent Information
- Application Number
- CN202511031745.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-25
- Publication Date
- 2025-09-19
AI Technical Summary
Existing network security monitoring systems mostly use single-point monitoring methods, which cannot fully grasp the network security status, lack multi-target assessment, have difficulty adapting to dynamic changes in the network, and lack the ability to warn of potential threats, leading to security decision-making deviations and losses.
The network is divided into multiple sub-domains, and network traffic feature collection modules are deployed in each sub-domain. The security margin and margin index are calculated by monitoring the attack frequency and traffic data. The network security uniformity and change trend are evaluated by combining historical data and machine learning to achieve multi-target monitoring and early warning.
Achieve comprehensive collection of traffic in all parts of the network.
Smart Images

Figure CN120675807A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security, and in particular to a network security multi-target monitoring system and a monitoring method based on monitoring data. Background Art
[0002] In today's rapidly evolving digital age, the internet has become deeply integrated into every aspect of social life, becoming an indispensable infrastructure for economic operations, social governance, and cultural exchange. Businesses leverage the internet to achieve efficient operations and global business expansion, governments rely on the internet to improve public services and governance, and individuals enjoy convenient access to information and social interaction. However, with the widespread use of the internet, cybersecurity issues have become increasingly prominent, becoming a key factor hindering the healthy development of the internet.
[0003] Cyberattack methods are becoming increasingly diverse, complex, and intelligent. Traditional attack methods such as viruses, Trojans, and worms remain rampant, constantly mutating and upgrading to evade detection. New attack methods, such as distributed denial of service (DDoS) attacks, advanced persistent threats (APTs), and zero-day exploits, are constantly emerging, posing a significant challenge to cybersecurity. These attacks can not only lead to data leaks and financial losses for businesses and individuals, but can also severely damage critical national infrastructure, jeopardizing national security and social stability.
[0004] Currently, many network security monitoring systems use a single-point approach, monitoring only a specific node or portion of traffic on the network. This approach fails to provide a comprehensive view of the security status of the entire network and can easily miss potential security threats. For example, in a large enterprise network, monitoring only the core switch would prevent timely detection of abnormal behavior at the edge of the network, potentially providing attackers with an opportunity to exploit.
[0005] Existing monitoring technologies often focus on single security indicators, such as attack frequency and traffic volume, and lack a comprehensive assessment of multiple security objectives. Network security is a complex systems project, involving multiple factors such as network availability, confidentiality, and integrity. Focusing solely on a single indicator cannot accurately reflect the overall security status of a network and can easily lead to biased security decisions. For example, even if the attack frequency is high, if the network's defense capabilities are strong, the actual security risk may not be significant. Conversely, even if the attack frequency is low, if the network has serious vulnerabilities, it may still face a significant security threat.
[0006] The network environment is dynamic, with new applications, services, and devices constantly emerging and network topologies frequently adjusting. Existing monitoring technologies, mostly based on static rules and models, struggle to adapt to these dynamic changes. For example, when an enterprise introduces a new business system, existing monitoring systems may be unable to promptly identify the system's normal traffic patterns, misclassifying normal traffic as abnormal, generating numerous false positives. Alternatively, they may be unable to promptly detect new security vulnerabilities and attack methods, rendering security monitoring ineffective.
[0007] Many existing network security monitoring systems can only detect and alert security incidents that have already occurred, lacking the ability to provide early warning of potential security threats. Waiting until a security incident occurs before taking action often results in irreversible damage. For example, in APT attacks, attackers often remain lurking within the network for extended periods, gradually stealing sensitive information. Existing monitoring systems struggle to detect anomalies in the early stages of an attack, and by the time the attack is discovered, critical enterprise data may have already been compromised. Summary of the Invention
[0008] The purpose of the present invention is to overcome the deficiencies of the prior art and provide a network security multi-target monitoring method based on monitoring data, comprising the following steps:
[0009] Step 1: Divide the target monitoring network into multiple sub-network domains according to the data collection range of the network traffic feature collection module, and deploy the network traffic feature collection module in each sub-network domain;
[0010] Step 2: The network attack data monitoring and recording module monitors the attack frequency of the target monitoring network, and the network traffic feature collection module collects the first traffic data and the second traffic data of the subnet domain; and obtains the first abnormal feature and the second abnormal feature respectively based on the first traffic data and the second traffic data and the attack frequency;
[0011] Step 3: Obtaining a safety margin and a safety margin index of the corresponding subnet domain based on the first abnormal feature and the second abnormal feature;
[0012] Step 4: Obtain the security uniformity of the target monitoring network based on the security margins of each corresponding sub-network domain; obtain the security change trend of the target monitoring network based on the security margin index of each corresponding sub-network domain;
[0013] Step 5: According to the security uniformity of the target monitoring network in the same monitoring period and the security change trend of the target monitoring network in the historical monitoring data, the current change trend of the target monitoring network is obtained, and an early warning is issued according to the current change trend of the target monitoring network.
[0014] Furthermore, the network attack data monitoring and recording module monitors the attack frequency of the target monitoring network, and the network traffic feature collection module collects the first traffic data and the second traffic data of the subnet domain, including:
[0015] The attack frequency is the number of attacks within the attack period; the first flow data is the network flow of the target network with a set number of hops from the core node; and the second flow data is the network flow at the edge node of the target network.
[0016] Furthermore, obtaining the first abnormality feature and the second abnormality feature respectively based on the first traffic data and the second traffic data and the attack frequency includes:
[0017] The first abnormal feature is the correlation difference between the first flow data and the attack frequency; the second abnormal feature is the correlation difference between the second flow data and the attack frequency.
[0018] Furthermore, obtaining the safety margin and safety margin index of the corresponding subnet domain according to the first abnormal feature and the second abnormal feature includes:
[0019] A first safety margin corresponding to the first abnormal feature is obtained in the cloud database; a safety margin corresponding to the second abnormal feature is obtained in the cloud database based on the second abnormal feature; a second safety margin is obtained by taking the difference between the safety margin of the second abnormal feature and the first safety margin; the safety margin is the ability of the network to resist attacks per unit time; and a safety margin index of the corresponding subnet domain is obtained based on the ratio of the obtained first safety margin to the second safety margin.
[0020] Furthermore, the security uniformity of the target monitoring network is obtained according to the security margins of the corresponding sub-network domains, including:
[0021] The security uniformity of the target monitoring network is determined by the ratio of the difference between the maximum and minimum security margin differences between the security margins of each corresponding sub-network domain to the number of sub-network domains.
[0022] Furthermore, the security change trend of the target monitoring network is obtained according to the security margin index of each corresponding sub-network domain, including:
[0023] The security change trend of the target monitoring network is the change trend of the effects of different security protection strategies. If the security margin indexes of the corresponding subnet domains are consistent, the security change trend of the target monitoring network is stable; otherwise, it is unstable.
[0024] Furthermore, the current change trend of the target monitoring network is obtained based on the security uniformity of the target monitoring network in the same monitoring period and the security change trend of the target monitoring network in the historical monitoring data, including:
[0025] According to the security uniformity of the target monitoring network in the same monitoring period in the historical monitoring data and the security change trend of the target monitoring network, if the uniformity is uniform and the security change of the target monitoring network is stable, then the current change trend of the target monitoring network is stable; otherwise, the current change trend of the target monitoring network is unstable.
[0026] The network security multi-target monitoring system based on monitoring data applies the network security multi-target monitoring method based on monitoring data, including a network traffic feature acquisition module, a network attack data monitoring and recording module, a network security status assessment module, a communication module, a cloud data server, an early warning module and a data processing module;
[0027] The network traffic feature acquisition module, network attack data recording module, network security status assessment module, communication module, and early warning module are respectively connected to the data processing module; the cloud data server is in communication connection with the communication module;
[0028] The network traffic feature collection module is used to collect network traffic feature data;
[0029] The network attack data monitoring and recording module is used to record network attack data, including attack frequency, attack time point and attack duration;
[0030] The network security status assessment module is used to obtain the security margin and security uniformity according to the network traffic characteristic data and the network attack data within the assessment period.
[0031] Preferably, the network traffic feature collection module includes a front-stage feature data collection module, a back-stage feature data collection module and a data processing module;
[0032] The front-stage feature data acquisition module and the back-stage feature data acquisition module are respectively connected to the data processing module;
[0033] The front-stage characteristic data acquisition module is used to collect the first flow data; the rear-stage characteristic data acquisition module is used to collect the second flow data;
[0034] The data processing module is used to obtain a first abnormality feature based on the first flow data and to obtain a second abnormality feature based on the second flow data.
[0035] Preferably, the network security status assessment module is used to obtain the security margin and security uniformity according to the network traffic characteristic data and the network attack data within the assessment period, including:
[0036] According to the first abnormal feature, the second abnormal feature and the corresponding attack feature, the security margin of the corresponding sub-network domain of the target monitoring network is obtained; according to the security margin of each corresponding sub-network domain, the security uniformity of the target monitoring network is obtained.
[0037] The present invention has the following beneficial effects: it divides the target monitoring network into multiple sub-domains and deploys network traffic feature collection modules in each sub-domain. This division fully considers the different regions and functional characteristics of the network, ensuring comprehensive collection of traffic from all parts of the network.
[0038] Based on the first and second anomaly characteristics, the corresponding subnet domain's security margin and security margin index are derived. The security margin reflects the network's ability to resist attacks per unit time, while the security margin index measures the differences in security status at different locations within the subnet domain. This combined evaluation of these two indicators provides a more accurate understanding of the security status of each subnet domain, providing a basis for developing targeted security policies. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 It is a network security multi-target monitoring method based on monitoring data;
[0040] Figure 2 Schematic diagram of the safety margin and safety margin index calculation process. DETAILED DESCRIPTION
[0041] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings, but the protection scope of the present invention is not limited to the following.
[0042] The features and performance of the present invention are further described in detail below with reference to the embodiments.
[0043] like Figure 1 As shown in the figure, the network security multi-target monitoring method based on monitoring data
[0044] Step 1: Target monitoring network division and collection module layout
[0045] Based on the data collection scope of the network traffic feature collection module, advanced network topology analysis algorithms are used to accurately divide the target monitoring network into multiple sub-domains. During the division process, factors such as the network's physical structure, logical functions, and business types are fully considered to ensure that each sub-domain has relatively independent and clear characteristics. For example, for an enterprise network, sub-domains can be divided according to departments; for a data center network, they can be divided according to business systems. Subsequently, network traffic feature collection modules are deployed at the key nodes of each sub-domain. These key nodes are usually located at locations where network traffic converges or distributes, such as router interfaces, switch ports, etc., to ensure that the network traffic information of the sub-domain can be fully and accurately collected.
[0046] Step 2: Data monitoring and abnormal feature extraction
[0047] The Network Attack Data Monitoring and Recording module continuously monitors the attack frequency of the target network in real time. Attack frequency is defined as the number of attacks within an attack period. By utilizing network-based intrusion detection systems (IDS) and intrusion prevention systems (IPS), combined with advanced traffic analysis technology, it accurately counts the number of attacks within each attack period and records detailed attack information, including attack type, source, and target.
[0048] At the same time, the network traffic feature collection module collects primary and secondary traffic data for the subnet domain. The primary traffic data represents the network traffic at a set number of hops from the target network to the core node. This number should be determined based on network scale and actual needs, typically between 2 and 5 hops, to ensure that traffic characteristics in key areas surrounding the core node are captured. The secondary traffic data represents the network traffic at the target network's edge nodes. Edge nodes are the boundaries between the network and the outside world, and their traffic characteristics are crucial for detecting external attacks and abnormal behavior.
[0049] Based on the collected first and second traffic data and the attack frequency, a first anomaly characteristic and a second anomaly characteristic are respectively calculated. Specifically, the first anomaly characteristic is the difference in correlation between the first traffic data and the attack frequency. By constructing a mathematical model of the traffic data and the attack frequency, such as a correlation analysis model or a regression analysis model, the correlation between the two is calculated and then compared with a preset normal correlation threshold to obtain the correlation difference. Similarly, the second anomaly characteristic is the difference in correlation between the second traffic data and the attack frequency.
[0050] Step 3: Calculate safety margin and safety margin index, such as Figure 2 As shown:
[0051] Based on the first anomaly feature, a precise match and query is performed in the cloud database to obtain the corresponding first safety margin. The cloud database stores a large amount of historical data and security indicators verified by expert analysis. Through data mining and machine learning algorithms, a mapping relationship between anomaly features and safety margins is established. Similarly, based on the second anomaly feature, the corresponding safety margin of the second anomaly feature is obtained in the cloud database. Then, the difference between the safety margin of the second anomaly feature and the first safety margin is calculated to obtain the second safety margin. The safety margin is defined as the network's ability to resist attacks per unit time. It comprehensively considers multiple factors such as network bandwidth, device performance, and security policies.
[0052] The security margin index for the corresponding subnet domain is calculated based on the ratio of the first security margin to the second security margin. The security margin index is a relative indicator used to measure the differences in security status at different locations within a subnet domain. A larger value indicates a greater difference in security status at different locations within the subnet domain.
[0053] Step 4: Target monitoring network security uniformity and security change trend assessment
[0054] The security uniformity of the target monitoring network is calculated based on the security margins of each corresponding subnet domain. The specific method is to first find the maximum and minimum security margin differences between the security margins of each subnet domain, then calculate the difference between them. This difference is then divided by the number of subnet domains to obtain the security uniformity of the target monitoring network. The security uniformity reflects the degree of balance in the overall security status of the target monitoring network. The closer the value is to 0, the more uniform the network's security status; conversely, it indicates a security vulnerability.
[0055] Evaluate the security trends of the target monitoring network based on the security margin index of each corresponding subnet domain. This security trend primarily reflects the changing effectiveness of different security protection strategies. If the security margin indexes of the corresponding subnet domains are consistent, it indicates that the security trends of each subnet domain under different security protection strategies are similar, and the security trend of the target monitoring network is stable. Otherwise, it indicates that the effectiveness of the security protection strategies of different subnet domains varies, and the security trend of the target monitoring network is unstable.
[0056] Step 5: Determine and warn the current trend of changes in the target monitoring network
[0057] The current trend of the target monitoring network is comprehensively determined based on the security uniformity of the target monitoring network over the same monitoring period in the historical monitoring data and the security change trend of the target monitoring network. The specific rule is that if the security uniformity of the target monitoring network over the same monitoring period in the historical monitoring data is uniform and the security change of the target monitoring network is stable, then the current trend of the target monitoring network is stable; otherwise, the current trend of the target monitoring network is unstable.
[0058] When the target monitoring network's current trend is determined to be unstable, the early warning module immediately issues an early warning signal. This signal can be delivered through various means, such as audible alarms, SMS notifications, and email alerts. The early warning information should also include a detailed security analysis report, including the location of security vulnerabilities, potential attack types, and recommended countermeasures, allowing network administrators to take timely measures to safeguard network security.
[0059] Network security multi-target monitoring system based on monitoring data
[0060] The multi-target network security monitoring system based on monitoring data applies the aforementioned monitoring method and primarily includes a network traffic feature acquisition module, a network attack data monitoring and recording module, a network security status assessment module, a communication module, a cloud-based data server, an early warning module, and a data processing module. Each module communicates and exchanges data via a high-speed, stable network connection. The network traffic feature acquisition module, network attack data recording module, network security status assessment module, communication module, and early warning module are each connected to the data processing module to enable centralized data processing and analysis. The cloud-based data server communicates with the communication module, providing robust data storage and query support for the system.
[0061] Network traffic feature acquisition module: This module is a key part of the system for acquiring network traffic information, and includes a front-stage feature data acquisition module, a back-stage feature data acquisition module, and a data processing module. The front-stage feature data acquisition module and the back-stage feature data acquisition module are respectively connected to the data processing module. The front-stage feature data acquisition module is responsible for collecting the first traffic data, that is, the network traffic of the target network at a set number of hops from the core node; the back-stage feature data acquisition module is responsible for collecting the second traffic data, that is, the network traffic at the edge node of the target network. The data processing module performs preliminary processing and analysis on the collected first and second traffic data, and obtains the first and second abnormal features according to the preset algorithms and models, and sends these feature data to the data processing module for further processing.
[0062] The Network Attack Data Monitoring and Recording Module is primarily used to record network attack data in real time, including detailed information such as attack frequency, attack time, and attack duration. By utilizing various security devices deployed on the network, such as firewalls and intrusion detection systems, this module monitors attack activity in network traffic in real time and records and stores the detected attack data. This module also provides data analysis and statistical capabilities, enabling the classification and organization of attack data to provide strong support for subsequent security assessments and early warnings.
[0063] Network Security Status Assessment Module: During the assessment cycle, this module utilizes advanced security assessment algorithms and models based on network traffic signature data and network attack data to determine the security margins of the corresponding subdomains of the target monitoring network and the security uniformity of the target monitoring network. Specifically, this module receives anomaly signature data from the Network Traffic Signature Collection Module and attack data from the Network Attack Data Monitoring and Recording Module. Combined with historical data and security indicators from the cloud database, this module uses data mining, machine learning, and other techniques to calculate the security margins of each subdomain and further assess the security uniformity of the target monitoring network. Furthermore, this module analyzes security trends within the target monitoring network based on the security margin index of each subdomain.
[0064] Communication Module: Responsible for data communication between system modules and between the system and cloud data servers. It utilizes high-speed, stable network protocols and technologies to ensure real-time and accurate data transmission. Furthermore, the communication module features data encryption and security authentication to ensure data security during transmission and prevent data leakage and tampering.
[0065] Cloud Data Server: Serving as the system's data storage and management center, it stores extensive historical monitoring data, safety indicators, and mappings between anomaly characteristics and safety margins. Powerful data storage and management capabilities support data query, analysis, and mining. The Cloud Data Server also features data backup and recovery capabilities to ensure data security and reliability.
[0066] Early Warning Module: Based on the assessment results of the Network Security Status Assessment Module, if the current trend of the target monitored network is determined to be unstable, an early warning signal will be immediately issued. The early warning module supports multiple warning methods, such as audible alarms, SMS notifications, and email reminders, which can be flexibly configured according to user needs. The early warning module also generates detailed security status analysis reports to provide decision-making basis for network administrators.
[0067] Data Processing Module: As the system's core processing unit, it coordinates the work of various modules, receives data from modules such as the Network Traffic Feature Collection Module and the Network Attack Data Monitoring and Recording Module, and centrally processes and analyzes it. Using advanced data processing algorithms and models, it cleans, transforms, and mines the collected data, extracting valuable information and providing accurate data support for the Network Security Status Assessment Module. The Data Processing Module is also responsible for interacting with cloud-based data servers, storing processed data in cloud-based databases, and retrieving required historical data and security metrics from these databases.
[0068] Example 1: Enterprise Network Security Monitoring Scenario
[0069] A large manufacturing enterprise has a complex network architecture encompassing multiple subnets, including office, production, and R&D networks, with frequent data exchange between these subnets. As the enterprise's digital transformation progresses, the network stores and transmits large amounts of sensitive data, such as product design drawings, production process parameters, and customer information. A cyberattack could cause significant financial losses and reputational damage to the enterprise. Therefore, the enterprise urgently needs an effective multi-target network security monitoring system to ensure the secure and stable operation of its network.
[0070] According to the enterprise's network topology and business functions, the target monitoring network is divided into office sub-domain, production sub-domain and R&D sub-domain.
[0071] A network traffic feature collection module is deployed at the core switch port of the office subnet domain to collect network traffic within 3 hops away from the core node in the subnet domain as the first traffic data; a collection module is deployed at the edge router interface of the office subnet domain to collect network traffic at the edge node as the second traffic data.
[0072] Similarly, network traffic feature collection modules are deployed in the production sub-network domain and the R&D sub-network domain in the same manner to collect corresponding first traffic data and second traffic data.
[0073] The network attack data monitoring and recording module monitors the frequency of attacks on the enterprise network in real time, using firewalls and intrusion detection systems (IDS) deployed at the enterprise network perimeter to count the number of attacks. For example, on a particular day, monitoring revealed 50 external attacks on the office subnet, 30 on the production subnet, and 40 on the R&D subnet.
[0074] The network traffic feature collection module for each subnet domain transmits the collected first and second traffic data to the data processing module. Based on a preset algorithm, the data processing module calculates the difference in correlation between the first traffic data and the attack frequency as the first anomaly feature, and the difference in correlation between the second traffic data and the attack frequency as the second anomaly feature. For example, the calculated first anomaly feature for the office subnet domain is 0.2, and the second anomaly feature is 0.3.
[0075] The data processing module uploads the calculated first and second anomaly features to the cloud-based data server. Based on stored historical data and security indicators, the cloud-based data server uses data mining and machine learning algorithms to match each anomaly feature with a corresponding safety margin. For example, the first anomaly feature in the office subnet corresponds to a first safety margin of 80, while the second anomaly feature corresponds to a second safety margin of 70.
[0076] Calculating the difference between the second safety margin and the first safety margin yields a second safety margin of 70 - 80 = -10 for the office subnet. (The difference here represents a relative difference; the actual safety margin is taken as its absolute value for subsequent calculations, meaning the second safety margin is 10.) Using the ratio of the first safety margin to the second safety margin, we obtain a safety margin index for the office subnet of 80 / 10 = 8. Similarly, the safety margin indices for the production and R&D subnets are calculated to be 6 and 7, respectively.
[0077] Calculate the maximum and minimum differences between the safety margins of each subdomain. Assuming the safety margins for the office subdomain are 80, the production subdomain is 75, and the R&D subdomain is 78, the maximum difference is 80 - 75 = 5, and the minimum difference is 78 - 75 = 3. According to the security uniformity calculation formula, the security uniformity of the target monitoring network is (5 - 3) / 3 ≈ 0.67. Because the safety margin indices of the three subdomains are inconsistent, the security trend of the target monitoring network is considered unstable.
[0078] Querying the enterprise network's historical monitoring data revealed that the average security uniformity for the same monitoring period (e.g., the same time period each month) was 0.5, and the historical security trend was also unstable. Considering the current security uniformity of 0.67 and the unstable security trend, the early warning module issued an early warning signal and generated a detailed security status analysis report.
[0079] The report points out that office subnet domains may be at risk of external attack penetration, and recommends strengthening security protection for edge nodes in office subnet domains, such as adding firewall rules and deploying more advanced intrusion prevention systems (IPS). At the same time, due to the unstable trend of overall network security changes, it is recommended to conduct a comprehensive review and optimization of the security policy of the enterprise network.
[0080] Example 2: Financial institution network security monitoring scenario
[0081] A bank has a vast network system, encompassing multiple subnetworks, including its core business network, online banking network, and mobile banking network. This network handles a large number of customer transactions and sensitive information. Financial institutions have extremely high requirements for network security; any security breach could result in loss of customer funds and damage to their reputation. Therefore, a highly reliable and accurate multi-target network security monitoring system is required to ensure secure network operation.
[0082] Based on the bank's network architecture and business characteristics, the target monitoring network is divided into core business subdomains, online banking subdomains, and mobile banking subdomains.
[0083] A network traffic characteristics collection module is deployed on the core router interfaces of the core business subnet domain, collecting network traffic two hops away from the core node as primary traffic data. A collection module is deployed in front of the firewall connecting the core business subnet domain to the external network, collecting network traffic at edge nodes as secondary traffic data. Similar network traffic characteristics collection modules are deployed in the online banking and mobile banking subnet domains.
[0084] The network attack data monitoring and recording module monitors the frequency of attacks on the bank's network in real time. Using multi-layered security protection devices deployed at the bank's network perimeter, such as firewalls, web application firewalls (WAFs), and intrusion detection systems, it accurately counts the number of attacks. For example, on a single day, monitoring revealed that the core business subdomain experienced 20 internal illegal operation attempts and 10 external attacks, the online banking subdomain experienced 30 external DDoS attacks, and the mobile banking subdomain experienced 25 malware attacks.
[0085] The network traffic feature collection module for each subnet domain transmits the collected data to the data processing module. The data processing module uses a more complex data analysis algorithm, taking into account the impact of different types of attacks on traffic features, to calculate the primary and secondary anomaly features. For example, the primary anomaly feature for the core business subnet domain is 0.15, and the secondary anomaly feature is 0.25.
[0086] The data processing module uploads the anomaly signatures to a cloud-based data server. The cloud-based data server combines the financial institution's specific security requirements and historical data to assign a more precise safety margin to each anomaly signature. For example, the first safety margin for the core business subnet domain is 90, and the second safety margin is 80.
[0087] The difference between the second safety margin and the first safety margin is 80 - 90 = -10 (the absolute value is 10), and the safety margin index is 90 / 10 = 9. The safety margin indexes for the online banking subdomain and mobile banking subdomain are 7 and 8, respectively.
[0088] Calculate the maximum and minimum differences between the security margins of each subdomain. Assuming the security margins for the core business subdomain are 90, the online banking subdomain is 85, and the mobile banking subdomain is 88, then the maximum difference is 90 - 85 = 5, and the minimum difference is 88 - 85 = 3. The resulting security uniformity of the target monitoring network is (5 - 3) / 3 ≈ 0.67.
[0089] Since the security margin indexes of the three sub-network domains are inconsistent, the security change trend of the target monitoring network is judged to be unstable.
[0090] Querying historical monitoring data for the bank's network revealed an average security uniformity of 0.4 over the same monitoring period, and the historical security trend was also unstable. Considering the current security uniformity of 0.67 and the unstable security trend, the early warning module issued a high-level warning signal and generated a detailed security status analysis report.
[0091] The report indicates that online banking subdomains face a high risk of DDoS attacks and recommends immediately activating emergency response mechanisms, increasing bandwidth resources, and deploying professional DDoS protection equipment. At the same time, the report recommends conducting a comprehensive assessment and adjustment of the bank's overall network security strategy, strengthening internal security management and employee safety training.
Claims
1. A multi-target network security monitoring method based on monitoring data, characterized in that: The steps include: Step 1: Divide the target monitoring network into multiple sub-network domains according to the data collection range of the network traffic feature collection module, and deploy the network traffic feature collection module in each sub-network domain; Step 2: The network attack data monitoring and recording module monitors the attack frequency of the target monitoring network, and the network traffic feature collection module collects the first traffic data and the second traffic data of the subnet domain; and obtains the first abnormal feature and the second abnormal feature respectively based on the first traffic data and the second traffic data and the attack frequency; Step 3: Obtaining a safety margin and a safety margin index of the corresponding subnet domain based on the first abnormal feature and the second abnormal feature; Step 4: Obtain the security uniformity of the target monitoring network based on the security margins of each corresponding sub-network domain; obtain the security change trend of the target monitoring network based on the security margin index of each corresponding sub-network domain; Step 5: According to the security uniformity of the target monitoring network in the same monitoring period and the security change trend of the target monitoring network in the historical monitoring data, the current change trend of the target monitoring network is obtained, and an early warning is issued according to the current change trend of the target monitoring network.
2. The network security multi-target monitoring method based on monitoring data according to claim 1 is characterized in that: The network attack data monitoring and recording module monitors the attack frequency of the target monitoring network, and the network traffic feature collection module collects the first traffic data and the second traffic data of the subnet domain, including: The attack frequency is the number of attacks within the attack period; the first flow data is the network flow of the target network with a set number of hops from the core node; and the second flow data is the network flow at the edge node of the target network.
3. The network security multi-target monitoring method based on monitoring data according to claim 2 is characterized in that: The obtaining of the first abnormality feature and the second abnormality feature respectively based on the first traffic data and the second traffic data and the attack frequency includes: The first abnormal feature is the correlation difference between the first flow data and the attack frequency; the second abnormal feature is the correlation difference between the second flow data and the attack frequency.
4. The network security multi-target monitoring method based on monitoring data according to claim 3 is characterized in that: The obtaining of the safety margin and safety margin index of the corresponding subnet domain according to the first abnormal feature and the second abnormal feature includes: A first safety margin corresponding to the first abnormal feature is obtained in the cloud database; a safety margin corresponding to the second abnormal feature is obtained in the cloud database based on the second abnormal feature; a second safety margin is obtained by taking the difference between the safety margin of the second abnormal feature and the first safety margin; the safety margin is the ability of the network to resist attacks per unit time; and a safety margin index of the corresponding subnet domain is obtained based on the ratio of the obtained first safety margin to the second safety margin.
5. The network security multi-target monitoring method based on monitoring data according to claim 4 is characterized in that: The method of obtaining the security uniformity of the target monitoring network according to the security margins of the corresponding sub-network domains includes: The security uniformity of the target monitoring network is determined by the ratio of the difference between the maximum and minimum security margin differences between the security margins of each corresponding sub-network domain to the number of sub-network domains.
6. The network security multi-target monitoring method based on monitoring data according to claim 5 is characterized in that: The security change trend of the target monitoring network is obtained according to the security margin index of each corresponding sub-network domain, including: The security change trend of the target monitoring network is the change trend of the effects of different security protection strategies. If the security margin indexes of the corresponding subnet domains are consistent, the security change trend of the target monitoring network is stable; otherwise, it is unstable.
7. The network security multi-target monitoring method based on monitoring data according to claim 6 is characterized in that: The current change trend of the target monitoring network is obtained based on the security uniformity of the target monitoring network in the same monitoring period and the security change trend of the target monitoring network in the historical monitoring data, including: According to the security uniformity of the target monitoring network in the same monitoring period in the historical monitoring data and the security change trend of the target monitoring network, if the uniformity is uniform and the security change of the target monitoring network is stable, then the current change trend of the target monitoring network is stable; otherwise, the current change trend of the target monitoring network is unstable.
8. A network security multi-target monitoring system based on monitoring data, characterized in that: The network security multi-target monitoring method based on monitoring data according to any one of claims 1 to 7 is applied, comprising a network traffic feature acquisition module, a network attack data monitoring and recording module, a network security status assessment module, a communication module, a cloud data server, an early warning module and a data processing module; The network traffic feature acquisition module, network attack data recording module, network security status assessment module, communication module, and early warning module are respectively connected to the data processing module; the cloud data server is in communication connection with the communication module; The network traffic feature collection module is used to collect network traffic feature data; The network attack data monitoring and recording module is used to record network attack data, including attack frequency, attack time point and attack duration; The network security status assessment module is used to obtain the security margin and security uniformity according to the network traffic characteristic data and the network attack data within the assessment period.
9. The network security multi-target monitoring system based on monitoring data according to claim 8, characterized in that: The network traffic feature acquisition module includes a front-stage feature data acquisition module, a back-stage feature data acquisition module and a data processing module; The front-stage feature data acquisition module and the back-stage feature data acquisition module are respectively connected to the data processing module; The front-stage characteristic data acquisition module is used to collect the first flow data; the rear-stage characteristic data acquisition module is used to collect the second flow data; The data processing module is used to obtain a first abnormality feature based on the first flow data and to obtain a second abnormality feature based on the second flow data.
10. The network security multi-target monitoring system based on monitoring data according to claim 9 is characterized in that: The network security status assessment module is used to obtain security margin and security uniformity based on network traffic characteristic data and network attack data during the assessment period, including: According to the first abnormal feature, the second abnormal feature and the corresponding attack feature, the security margin of the corresponding sub-network domain of the target monitoring network is obtained; according to the security margin of each corresponding sub-network domain, the security uniformity of the target monitoring network is obtained.
Citation Information
Cited By
Forestry multi-target monitoring system and monitoring method based on monitoring data
CN120996534A
A protection monitoring system and method applied to network security
CN122554159A