Network security situation awareness and emergency response platform based on digital twinning
By comprehensively analyzing the data feature collections of multiple impact layers through digital twin technology, the accuracy and prediction problems of existing network security assessment methods are solved, real-time detection and prediction of potential risks are achieved, and the response efficiency of network security is improved.
Patent Information
- Application Number
- CN202511262652.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-05
- Publication Date
- 2025-10-03
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing network security assessment methods cannot accurately identify network anomalies and cannot predict potential risks, resulting in inaccurate detection results and missing the optimal response time.
A digital twin-based cybersecurity situational awareness and emergency response platform is used to comprehensively analyze data feature collections of multiple impact layers through data collection, fusion and modeling, situational awareness analysis and response modules, conduct real-time detection and risk prediction, and perform weighted analysis and alarm based on historical data and deviation anomaly coefficients.
It improves the accuracy of network security detection, enables prediction and timely response to potential risks, and reduces the occurrence of network security incidents.
Smart Images

Figure CN120750673A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of network detection technology, and specifically relates to a network security situation awareness and emergency response platform based on digital twins. Background Art
[0002] With the rapid development of information technology, cyberspace has become a critical infrastructure of modern society, and its security directly affects the interests of nations, businesses, and even individuals. However, cyberattacks are becoming increasingly complex and diverse, leading to numerous challenges for cybersecurity defense systems.
[0003] Existing methods for assessing and judging network security mostly set alarm parameter thresholds to determine whether they exceed the alarm parameter thresholds, thereby determining whether the network security is abnormal. Although this method can identify some network anomalies, due to the linkage between multiple parameters when the network is abnormal, when a certain parameter is affected, the parameters associated with it will also be affected accordingly. If a certain parameter is analyzed alone, an island effect may occur, resulting in inaccurate detection results. Moreover, when making existing network security judgments, most of them can only target network security situations that have already occurred, and cannot predict potential and hidden security risks, thus missing the best response time. Summary of the Invention
[0004] The purpose of the present invention is to provide a network security situation awareness and emergency response platform based on digital twins to solve the problems faced in the above-mentioned background technology.
[0005] The purpose of the present invention can be achieved through the following technical solutions: A digital twin-based cybersecurity situational awareness and emergency response platform, comprising: A data acquisition module, wherein the data acquisition module is used to obtain raw data information related to network security from multiple ports; A data fusion and digital twin modeling module, which is used to pre-process the acquired raw data information, construct a digital twin virtual model, and synchronously reflect the processed data on the digital virtual model; A situational awareness and analysis module, which analyzes data in a virtual model environment to detect network security status, including real-time network security detection and estimated network security risk detection; The response module performs a corresponding emergency response based on the judgment result.
[0006] Furthermore, the original data information includes data information from the network physical layer, data information from the service application layer, and data information from the security event layer.
[0007] Furthermore, the situational awareness analysis module performs real-time network security detection in the following manner: Data feature set A is constructed based on the data information of the network physical layer, data feature set B is constructed based on the data information of the business application layer, and data feature set C is constructed based on the data information of the security event layer. Each feature set contains multiple corresponding feature parameters. Each feature parameter is compared with the set security alarm threshold. When the set alarm threshold is exceeded, it is judged that there is an abnormality in network security and an alarm is issued; At the same time, for each feature parameter under each feature set, a benchmark value is formulated according to the historical data of each feature parameter, so as to obtain the deviation value of each feature parameter according to the deviation of each feature parameter from the benchmark value, and perform weighted analysis on the deviation value under the feature set to obtain the deviation anomaly coefficient of each data feature set, among which the deviation anomaly coefficients of data feature set A, data feature set B, and data feature set C are respectively 、 、 ; By formula Get outliers ; when When the network is judged to be abnormal, an alarm is issued. 、 as well as are their respective weight coefficients, The alarm threshold is set based on experience.
[0008] Furthermore, the situational awareness analysis module performs the following method on network security risk estimation detection: When no real-time alarm is issued, set a monitoring cycle During the detection period, according to the variation of the deviation anomaly coefficient of the data feature set, the deviation anomaly coefficient variation function of the data feature set A, data feature set B, and data feature set C over time is formulated respectively. 、 、 , and then derive the risk value of each data feature set 、 as well as , through the formula Obtain the comprehensive risk value of the network ; when When the network is judged to have security anomaly risk, an alarm response is issued, among which, 、 、 are their respective weight coefficients, The alarm threshold is set based on experience.
[0009] Furthermore, the risk value 、 as well as The method to obtain is: By formula Determine the risk value ,in, as well as is the preset coefficient, The function of the deviation anomaly coefficient threshold value proposed for the data feature set A over time, is the start time of the monitoring period, is the end time of the detection cycle, During the detection period The maximum first-order derivative of is the preset comparison value, is the deviation anomaly coefficient fluctuation value of the data feature set A; By formula Determine the risk value ,in, as well as is the preset coefficient, is the function of the deviation anomaly coefficient threshold value changing over time based on the feature set B, During the detection period The maximum first-order derivative of is the preset comparison value, is the deviation anomaly coefficient fluctuation value of the data feature set B; By formula Determine the risk value ,in, as well as is the preset coefficient, is the function of the deviation anomaly coefficient threshold value changing with time based on the feature set C, For the detection period The maximum first-order derivative of is the preset comparison value, is the deviation anomaly coefficient fluctuation value of the data feature set C.
[0010] Furthermore, the situational awareness analysis module is also used to assess the potential security risks of the network based on abnormal value conditions in the network's working state and non-working state.
[0011] Furthermore, the situational awareness analysis module assesses the potential security risks of the network by: According to the abnormal value of network working state and non-working state, During the time, abnormal values are collected and the formula Obtain the score S, and thus obtain the score value of the network in working state and non-working state 、 ; Then through the formula Determine potential risk scores; when When the network is judged to have potential security risks, an alarm is issued; To set the alarm threshold, It is an indicator function. When the condition in the brackets is met, the function value is 1, otherwise it is 0. as well as The reasonable value range of abnormal values under normal conditions set for the network, , is the threshold of the outlier change rate over time, For in time Outliers outside the The number of times, is the threshold value for the number of times the abnormal value exceeds the normal value, 、 、 as well as 、 All are preset weight coefficients.
[0012] Furthermore, the response module works as follows: Different levels of emergency alarm responses are set according to the corresponding alarm conditions. At the same time, the emergency alarm responses are converted into automated operations through the SOAR platform, and the execution status is synchronized in the digital twin model. The operation effect is fed back in real time, and the results after execution are recorded and optimized based on the results.
[0013] Beneficial effects of the present invention: The present invention can not only combine multiple data under the same impact layer for comprehensive analysis to improve detection accuracy, but also combine data between multiple impact layers for fusion analysis, judge the network security situation based on the correlation between them, and further improve detection accuracy.
[0014] The situational awareness analysis module of the present invention can perform real-time network security anomalies and network security anomaly risk predictions, and can also prejudge potential long-term network security risks, thereby providing timely alarm responses and reducing the occurrence of subsequent network security incidents.
[0015] Of course, any product implementing the present invention does not necessarily need to achieve all of the advantages described above at the same time. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0017] Figure 1 This is a module block diagram of the response platform of the present invention. DETAILED DESCRIPTION
[0018] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.
[0019] In one embodiment, a digital twin-based cybersecurity situational awareness and emergency response platform is disclosed, such as Figure 1 As shown, the response platform includes: Data acquisition module, which is used to obtain raw data information related to network security from multiple ports. The raw data information includes data information from the network physical layer, data information from the business application layer, and data information from the security event layer; The data fusion and digital twin modeling module is used to pre-process the acquired raw data information, build a digital twin virtual model, and synchronously reflect the processed data on the digital virtual model; Situational awareness and analysis module: This module analyzes data in a virtual model environment to detect network security status, including real-time network security detection and estimated network security risk detection; The response module performs corresponding emergency response based on the judgment results.
[0020] Through the above technical solution, the present application first uses a data acquisition module to obtain raw data information related to network security from multiple ports. These data include data information from the network physical layer, data information from the business application layer, and data information from the security event layer. For example, for the network physical layer, device status data (switch port status, router interface traffic, server network card link aggregation status, optical module luminous power, physical device temperature, etc.), signal and transmission data (CRC of Ethernet frame) can be obtained. For the business application layer, user behavior data, business traffic data, application interaction data and other data can be obtained. For the network security layer, attack detection data, violation and vulnerability data, malicious behavior data, log data, etc. can be obtained to form the original data information. The acquired data information is then pre-processed through data fusion and digital twin modeling modules. These pre-processing steps include but are not limited to data cleaning, correction, format conversion and parameter normalization to facilitate subsequent calculation and analysis. In addition, a digital twin virtual model of network security is constructed through data fusion and digital twin modeling modules, and the processed data are synchronously reflected on the digital virtual model. The virtual model can contain the original data after processing and before processing; then through the situation The perception analysis module analyzes data based on the virtual model environment to detect the network security status, including real-time network security detection and network security risk estimation detection. This not only combines multiple data under the same impact layer for comprehensive analysis to improve detection accuracy, but also combines data between multiple impact layers for fusion analysis, and judges the network security situation based on the correlation between them to further improve detection accuracy; and the situational awareness analysis module can perform real-time network security anomalies and network security anomaly risk prediction and evaluate potential network security anomalies, which can predict network security situations in advance, thereby early emergency response, reducing the occurrence of network security incidents, and ensuring response efficiency; finally, the response module makes corresponding emergency responses based on the judgment results to maintain the safe and stable operation of the entire network system.
[0021] The situational awareness analysis module uses the following method to detect network security in real time: constructing data feature set A based on the data information of the network physical layer, constructing data feature set B based on the data information of the business application layer, and constructing data feature set C based on the data information of the security event layer. Each feature set contains multiple corresponding feature parameters, and each feature parameter is compared with the set security alarm threshold. When the set alarm threshold is exceeded, it is judged that there is an abnormality in network security and an alarm is issued. At the same time, for each feature parameter under each feature set, a benchmark value is formulated according to the historical data of each feature parameter, so as to obtain the deviation value of each feature parameter according to the deviation of each feature parameter from the benchmark value, and perform weighted analysis on the deviation value under the feature set to obtain the deviation anomaly coefficient of each data feature set, among which the deviation anomaly coefficients of data feature set A, data feature set B, and data feature set C are respectively 、 、 ; By formula Get outliers ; when When the network is judged to be abnormal, an alarm is issued. 、 as well as are their respective weight coefficients, The alarm threshold is set based on experience.
[0022] The above scheme provides a method for real-time detection of network security. First, a data feature set A is constructed based on the data information of the network physical layer, a data feature set B is constructed based on the data information of the business application layer, and a data feature set C is constructed based on the data information of the security event layer. Each corresponding feature set contains corresponding multiple feature parameters. For example, the network physical layer corresponds to feature parameters such as router interface traffic, optical module luminous power, physical device temperature, transmission rate, etc. The business application layer corresponds to feature parameters such as application response time, database query frequency, user login times, business operation frequency, application layer protocol traffic, etc. The security event layer corresponds to feature parameters such as IDS alarm, user unauthorized operation frequency, virus / trojan killing information, log alarm times, etc. These characteristic parameters are respectively set with corresponding security alarm thresholds according to the historical security situation of the network. Each characteristic parameter is compared with the respective set security alarm threshold. When the set alarm threshold is exceeded, it is judged that there is an anomaly in network security and an alarm is issued. In this way, a single data is analyzed to determine whether the network is abnormal. At the same time, for each characteristic parameter under each feature set, a benchmark value is formulated according to the historical data of each characteristic parameter, so as to obtain the deviation value of each characteristic parameter according to the deviation of each characteristic parameter from the benchmark value. The deviation value under the feature set is weightedly analyzed to obtain the deviation anomaly coefficient of each data feature set, among which the deviation anomaly coefficients of data feature set A, data feature set B, and data feature set C are respectively 、 、 , through the formula Get outliers It can be seen that when the deviation anomaly coefficient is larger, the difference between the network and normal operation is greater, and the possibility of network security anomaly is greater. Therefore, the deviation anomaly coefficients between multiple impact layers are fused and analyzed to obtain the anomaly value ,when When the network is judged to be abnormal, an alarm is issued. 、 as well as are their respective weight coefficients, The alarm threshold is set based on experience. This method can combine multiple feature data under the same impact layer for comprehensive analysis to judge the network security situation. At the same time, it combines the deviation anomaly coefficients of multiple impact layers for fusion analysis to judge the network security situation, which can accurately and comprehensively improve the accuracy of detection.
[0023] The method for the situational awareness analysis module to detect network security risk is: when there is no real-time alarm, set a monitoring cycle During the detection period, according to the variation of the deviation anomaly coefficient of the data feature set, the deviation anomaly coefficient variation function of the data feature set A, data feature set B, and data feature set C over time is formulated respectively. 、 、 , and then derive the risk value of each data feature set 、 as well as , through the formula Obtain the comprehensive risk value of the network ; when When the network is judged to have security anomaly risk, an alarm response is issued, among which, 、 、 are their respective weight coefficients, The alarm threshold is set based on experience; By formula Determine the risk value ,in, as well as is the preset coefficient, The function of the deviation anomaly coefficient threshold value proposed for the data feature set A over time, is the start time of the monitoring period, is the end time of the detection cycle, During the detection period The maximum first-order derivative of is the preset comparison value, is the deviation anomaly coefficient fluctuation value of the data feature set A; By formula Determine the risk value ,in, as well as is the preset coefficient, is the function of the deviation anomaly coefficient threshold value changing over time based on the feature set B, During the detection period The maximum first-order derivative of is the preset comparison value, is the deviation anomaly coefficient fluctuation value of the data feature set B; By formula Determine the risk value ,in, as well as is the preset coefficient, is the function of the deviation anomaly coefficient threshold value changing with time based on the feature set C, For the detection period The maximum first-order derivative of is the preset comparison value, is the deviation anomaly coefficient fluctuation value of the data feature set C.
[0024] The above technical solution provides a specific method for the situational awareness analysis module to predict and detect network security risks. First, when there is no real-time alarm, a monitoring cycle is set. During the detection period, according to the variation of the deviation anomaly coefficient of the data feature set, the deviation anomaly coefficient variation function of the data feature set A, data feature set B, and data feature set C over time is formulated respectively. 、 、 , and then derive the risk value of each data feature set 、 as well as , through the formula Determine the risk value ,in, as well as is the preset coefficient, The function of the deviation anomaly coefficient threshold value proposed for the data feature set A over time, is the start time of the monitoring period, is the end time of the detection cycle, During the detection period The maximum first-order derivative of is the preset comparison value, is the deviation anomaly coefficient fluctuation value of the data feature set A, through the formula Determine the risk value ,in, as well as is the preset coefficient, is the function of the deviation anomaly coefficient threshold value changing over time based on the feature set B, During the detection period The maximum first-order derivative of is the preset comparison value, is the deviation anomaly coefficient fluctuation value of the data feature set B, through the formula Determine the risk value ,in, as well as is the preset coefficient, is the function of the deviation anomaly coefficient threshold value changing with time based on the feature set C, For the detection period The maximum first-order derivative of is the preset comparison value, is the deviation coefficient fluctuation value of the data feature set C; the weight coefficients and preset coefficients in the formula can be adaptively adjusted according to the actual network environment and security requirements. 、 、 And the preset comparison value 、 、 It can be formulated based on the historical network operation data in the corresponding environment. 、 、 It can be determined based on the variance data of each deviation abnormal coefficient in the monitoring period; For example, from the formula It can be seen that It indicates the deviation between the deviation anomaly coefficient threshold and the obtained deviation anomaly coefficient. When the deviation anomaly coefficient is higher than the threshold, it means that the possibility of network security risk is greater. Therefore, the larger its value is, the greater the possibility of network security risk is. The formula It shows the fluctuation and trend of the deviation from the abnormal coefficient during the detection period. Obviously, the larger the value, the greater the possibility of network security risk. The larger the value, the greater the possibility of network security risk. Therefore, we will conduct a comprehensive analysis based on the risk values of the three impact layers. Obtain the comprehensive risk value of the network ,when When a security anomaly risk is detected, the network is judged to have a security anomaly risk and an alarm response is issued. This method allows for comprehensive analysis of the deviation anomaly coefficient changes at each impact layer without a real-time alarm to predict network security risks. This allows for timely response to ensure network security and stability.
[0025] The situation awareness analysis module is also used to assess the potential security risks of the network based on the abnormal value of the network in the working state and the non-working state. The assessment method is as follows: based on the abnormal value of the network in the working state and the non-working state, During the time, abnormal values are collected and the formula Obtain the score S, and thus obtain the score value of the network in working state and non-working state 、 ; Then through the formula Determine potential risk scores; when When the network is judged to have potential security risks, an alarm is issued; To set the alarm threshold, It is an indicator function. When the condition in the brackets is met, the function value is 1, otherwise it is 0. as well as The reasonable value range of abnormal values under normal conditions set for the network, , is the threshold of the outlier change rate over time, For in time Outliers outside the The number of times, is the threshold value for the number of times the abnormal value exceeds the normal value, 、 、 as well as 、 All are preset weight coefficients.
[0026] The above scheme provides a specific method for evaluating the potential security of the network. The size of the network security risk can only be predicted by combining data in a short period of time, and it is impossible to judge the potential security situation of the network in the long term. Therefore, this application collects the abnormal value of the network in the working state and the non-working state, and obtains its abnormal value in the working state and the non-working state respectively. Rating value within time 、 , and the score S can be obtained by the formula It is concluded that, To set the alarm threshold, It is an indicator function. When the condition in the brackets is met, the function value is 1, otherwise it is 0. as well as The reasonable value range of abnormal values under normal conditions set for the network, , is the threshold of the outlier change rate over time, For in time Outliers outside the The number of times, is the threshold value for the number of times the abnormal value exceeds the normal value, 、 、 as well as 、 are all preset weight coefficients; from the formula, we can see that when When , it indicates that the abnormal value deviates from the normal operating range of the network. , this condition accounts for ;and It means that the rate of change of the abnormal value in unit time exceeds the threshold, indicating that the abnormal value changes more drastically and there may be abnormal conditions. , then the proportion of this condition in the comprehensive score is When the number of times the abnormal value GR exceeds the normal range is greater than the number threshold N, it means that GR frequently deviates from the normal range and the possibility of potential risks increases. , then the proportion of this condition in the comprehensive score is Comprehensive score It is composed of the weighted sum of the above three conditions. Exceeding the set score threshold When the network is affected by the security risk, it can be judged that there is a potential security risk in the network, and the weight coefficient can be adaptively adjusted according to different network environments and security requirements. 、 、 and threshold , making the expression adaptable to different network environments and security requirements, improving the accuracy and flexibility of risk assessment. By combining this approach with network scoring analysis in both working and non-working states, we can predict potential long-term network security risks, enabling timely alarm responses and reducing the occurrence of subsequent network security incidents.
[0027] The working method of the response module is: according to the corresponding alarm situation, different levels of emergency alarm response are set, and at the same time, the emergency alarm response is converted into automated operation through the SOAR platform, and the execution status is synchronized in the digital twin model, the operation effect is fed back in real time, and the results after execution are recorded, and optimization is performed based on the results.
[0028] The above solution provides a working method for the response module. When different alarms are generated, the model performs different types of emergency responses according to the alarm type. At the same time, different levels of emergency alarm responses are set. The emergency alarm response is converted into an automated operation through the SOAR platform, and the execution status is synchronized in the digital twin model. The operation effect is fed back in real time, and the results after execution are recorded. Optimization is performed based on the results. If the network security problem is not restored after execution, manual intervention is performed, and the model is optimized later to ensure the platform's detection and response capabilities.
[0029] The above content is merely an example and explanation of the concept of the present invention. Those skilled in the art may make various modifications or additions to the described specific embodiments or replace them in a similar manner. As long as they do not deviate from the concept of the invention or exceed the scope defined by the claims, they should all fall within the scope of protection of the present invention.
Claims
1. A cybersecurity situation awareness and emergency response platform based on digital twins, characterized by: The platform includes: A data acquisition module, wherein the data acquisition module is used to obtain raw data information related to network security from multiple ports; A data fusion and digital twin modeling module is used to pre-process the acquired raw data information, construct a digital twin virtual model, and synchronously reflect the processed data on the digital virtual model; A situational awareness and analysis module, which analyzes data in a virtual model environment to detect network security status, including real-time network security detection and estimated network security risk detection; The response module performs a corresponding emergency response based on the judgment result.
2. A digital twin-based network security situation awareness and emergency response platform according to claim 1, characterized in that: The original data information includes data information from the network physical layer, data information from the service application layer, and data information from the security event layer.
3. A digital twin-based network security situation awareness and emergency response platform according to claim 2, characterized in that: The method for the situation awareness analysis module to detect network security in real time is: Data feature set A is constructed based on the data information of the network physical layer, data feature set B is constructed based on the data information of the business application layer, and data feature set C is constructed based on the data information of the security event layer. Each feature set contains multiple corresponding feature parameters. Each feature parameter is compared with the set security alarm threshold. When the set alarm threshold is exceeded, it is judged that there is an abnormality in network security and an alarm is issued; At the same time, for each feature parameter under each feature set, a benchmark value is formulated according to the historical data of each feature parameter, so as to obtain the deviation value of each feature parameter according to the deviation of each feature parameter from the benchmark value, and perform weighted analysis on the deviation value under the feature set to obtain the deviation anomaly coefficient of each data feature set, among which the deviation anomaly coefficients of data feature set A, data feature set B, and data feature set C are respectively 、 、 ; By formula Get outliers ; when When the network is judged to be abnormal, an alarm is issued. 、 as well as are their respective weight coefficients, The alarm threshold is set based on experience.
4. A digital twin-based network security situation awareness and emergency response platform according to claim 3, characterized in that: The method for the situational awareness analysis module to detect network security risk estimation is as follows: When no real-time alarm is issued, set a monitoring cycle During the detection period, according to the variation of the deviation anomaly coefficient of the data feature set, the deviation anomaly coefficient variation function of the data feature set A, data feature set B, and data feature set C over time is formulated respectively. 、 、 , and then derive the risk value of each data feature set 、 as well as , through the formula Obtain the comprehensive risk value of the network ; when When the network is judged to have security anomaly risk, an alarm response is issued, among which, 、 、 are their respective weight coefficients, The alarm threshold is set based on experience.
5. A digital twin-based network security situation awareness and emergency response platform according to claim 4, characterized in that: The risk value 、 as well as The method to obtain is: By formula Determine the risk value ,in, as well as is the preset coefficient, The function of the deviation anomaly coefficient threshold value proposed for the data feature set A over time, is the start time of the monitoring period, is the end time of the detection cycle, During the detection period The maximum first-order derivative of is the preset comparison value, is the deviation anomaly coefficient fluctuation value of the data feature set A; By formula Determine the risk value ,in, as well as is the preset coefficient, is the function of the deviation anomaly coefficient threshold value changing over time based on the feature set B, During the detection period The maximum first-order derivative of is the preset comparison value, is the deviation anomaly coefficient fluctuation value of the data feature set B; By formula Determine the risk value ,in, as well as is the preset coefficient, is the function of the deviation anomaly coefficient threshold value changing with time based on the feature set C, For the detection period The maximum first-order derivative of is the preset comparison value, is the deviation anomaly coefficient fluctuation value of the data feature set C.
6. A digital twin-based network security situation awareness and emergency response platform according to claim 5, characterized in that: The situational awareness analysis module is also used to assess the potential security risks of the network based on abnormal value conditions in the network's working state and non-working state.
7. The digital twin-based network security situation awareness and emergency response platform according to claim 6 is characterized in that: The method by which the situational awareness analysis module assesses the potential security risks of the network is as follows: According to the abnormal value of network working state and non-working state, During the time, abnormal values are collected and the formula Obtain the score S, and thus obtain the score value of the network in working state and non-working state 、 ; Then through the formula Determine potential risk scores; when When the network is judged to have potential security risks, an alarm is issued; To set the alarm threshold, It is an indicator function. When the condition in the brackets is met, the function value is 1, otherwise it is 0. as well as The reasonable value range of abnormal values under normal conditions set for the network, , is the threshold of the outlier change rate over time, For in time Outliers outside the The number of times, is the threshold value for the number of times the abnormal value exceeds the normal value, 、 、 as well as 、 All are preset weight coefficients.
8. The digital twin-based network security situation awareness and emergency response platform according to claim 7 is characterized in that: The working method of the response module is: Different levels of emergency alarm responses are set according to the corresponding alarm conditions. At the same time, the emergency alarm responses are converted into automated operations through the SOAR platform, and the execution status is synchronized in the digital twin model, the operation effect is fed back in real time, and the results after execution are recorded and optimized based on the results.
Citation Information
Cited By
Network security situation awareness and emergency response system based on digital twinning
CN121841762A