Network security situation awareness method and system

By standardizing the parsing of multi-source heterogeneous logs and analyzing them with a dynamic baseline correlation engine, and combining knowledge graphs and graph neural networks, a network security situation awareness system is constructed. This system solves the problem of insufficient threat awareness under complex cross-regional attacks and enables efficient identification of unknown threats and formulation of defense strategies.

CN120915595AActive Publication Date: 2025-11-07TONGFANG KNOWLEDGE DIGITAL PUBLISHING TECH CO LTD

Patent Information

Application Number
CN202511395859.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-28
Publication Date
2025-11-07
Estimated Expiration
2045-09-28

AI Technical Summary

Technical Problem

Existing network security situation awareness systems are unable to fully grasp the attack situation when faced with complex attacks that cross regions and systems, making it difficult to formulate effective defense strategies, especially in terms of insufficient ability to deal with zero-day attacks and unknown threats.

Method used

By collecting multi-source heterogeneous logs, performing standardized parsing, and then using a dynamic baseline association engine for real-time analysis, a basic knowledge graph is constructed, and rule-based reasoning and embedding reasoning are performed. Combined with graph neural network GAT to optimize threat data, a network attack threat value is generated.

Benefits of technology

It increases the probability of detecting unknown threats and new types of attacks, ensures the reliability and accuracy of analytical data, can quickly identify high-threat areas and attack types, provides a clear basis for developing targeted protection strategies, and improves the efficiency of network security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915595A_ABST
    Figure CN120915595A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security monitoring, and discloses a network security situation awareness method and system, and the method comprises the steps: collecting a multi-source heterogeneous log, carrying out the standardized analysis, and obtaining log event data; performing real-time analysis by utilizing a dynamic baseline association engine based on the log event data to obtain log association alarm data, analyzing a triple from the log association alarm data, constructing a basic knowledge graph based on the triple, performing rule reasoning and embedded reasoning, and integrating reasoning results to form a situation-enhanced security situation knowledge graph; threat data are extracted according to the security situation knowledge graph, the threat data are optimized in combination with a graph neural network GAT to obtain a final network attack threat value, network security situation awareness is carried out based on the network attack threat value, and the threat data comprise comprehensive criticality and an attack influence range. According to the invention, the efficiency and effect of network security management can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of network security monitoring, and particularly relates to a network security situation awareness method and system. BACKGROUND

[0002] With the increasing size of the network and the increasingly complex topology, the difficulty of network security management increases dramatically. In the early stage, network security protection mainly relies on single detection technology, such as intrusion detection technology, malicious code detection technology, etc. These technologies discover problems in the network from their own specific perspective, but ignore the correlation between different types of security elements, and cannot fully and timely understand the threats in the network, let alone predict potential risks.

[0003] At present, in the existing network security situation awareness system, the traditional network situation awareness technology mainly detects and analyzes based on known attack patterns, and the response ability to zero-day attacks and unknown threats is seriously insufficient. Since these attack patterns have not been detected, there is a lack of corresponding rules and features for detection, which makes the network security face a major risk. For example, when a new zero-day exploit attack occurs, the traditional situation awareness system often has difficulty in discovering and defending in time; In addition, part of the network situation awareness technology usually runs on a single perception node, and it is difficult for each node to share information and cooperatively analyze, which cannot show the attack process implemented by the attacker on the whole network system from the whole, and it is difficult to provide the network security intelligence with overall and global perspective, which leads to the inability to fully grasp the attack situation and develop effective defense strategies when facing complex attacks across regions and systems.

[0004] Therefore, the present application provides a network security situation awareness method to solve the above technical problems. SUMMARY

[0005] The purpose of the present application is to provide a network security situation awareness method and system to solve the technical problem that the prior art cannot fully grasp the attack situation and develop effective defense strategies when facing complex attacks across regions and systems.

[0006] In order to solve the above technical problems, the present application provides a network security situation awareness method, comprising: responding to the collected multi-source heterogeneous logs and performing standardized analysis to obtain log event data; performing real-time analysis based on the log event data by using a dynamic baseline correlation engine to obtain log correlation alarm data, wherein the dynamic baseline correlation engine distinguishes abnormal events by obtaining a dynamic baseline of event types in a log sample sequence, and quantifies correlation of abnormal events, quantifies event correlation by fusing conditional probability and time decay correlation degree function, judges whether an event chain is formed, and matches the formed event chain with an attack chain template to generate the log correlation alarm data, the attack chain template is based on the MITRE ATT&CK framework, and is obtained by combining actual attack event chain combinations in history; parsing triplets from the log correlation alarm data, constructing a basic knowledge graph based on the triplets, and performing rule reasoning and embedding reasoning, and integrating reasoning results to form a security situation knowledge graph with enhanced situation; extracting threat data from the security situation knowledge graph and optimizing the threat data by combining a graph neural network GAT to obtain a final network attack threat value, and performing network security situation awareness based on the network attack threat value, wherein the threat data includes comprehensive harm degree and attack impact range.

[0007] In some embodiments, in response to collecting multi-source heterogeneous logs and performing standardized parsing, log event data is obtained, further comprising: defining a unified log field, the unified log field including log timestamp, event subject, event action and event object; mapping logs of different sources and formats to the unified log field by using regular expressions to convert structured log events; performing timestamp normalization processing on all structured log events by using NTP protocol, and transmitting through Kafka message queue to output standard events, forming a unified standardized log event data set.

[0008] In some embodiments, the dynamic baseline correlation engine distinguishes abnormal events by obtaining a dynamic baseline of event types in a log sample sequence, further comprising: selecting log event data corresponding to normal sample data in historical data, and defining event types of each log event data to form a log sample sequence; based on the log sample sequence, calculating a probability density function of normal event frequency by using a Gaussian kernel estimation method; based on the probability density function, setting a significance level, and calculating an upper limit and a lower limit of a confidence interval corresponding to the significance level, so that the integral value of the probability density function from negative infinity to the lower limit is equal to half of the significance level, and the integral value from the upper limit to positive infinity is also equal to half of the significance level; According to the upper limit and the lower limit, a dynamic baseline of the event type at a specified time is obtained, wherein the dynamic baseline is an interval defined by the upper limit and the lower limit.

[0009] In some embodiments, the correlation is quantified for abnormal events, further comprising: Defining a correlation degree function to measure the correlation between events, the correlation degree function fusing the conditional probability between event types and a factor simulating the influence of the interval between event occurrence times in an exponential decay manner; The time window for defining the correlation between events is preset to a fixed length.

[0010] In some embodiments, the correlation between events is quantified by fusing the conditional probability and the correlation degree function with time decay, it is determined whether an event chain is formed, the event chain formed is matched with an attack chain template to generate the log correlation alarm data, further comprising: From the historical attack log, the number of times that the second event type occurs after the first event type occurs and within a preset time window, and the total number of times that the first event type occurs are counted; The conditional probability of the second event type after the first event type occurs is calculated; Based on the conditional probability and the actual time interval between the first event and the second event to be analyzed, the correlation degree between the first event and the second event is calculated; When the correlation degree reaches a preset correlation degree threshold, it is determined that the first event and the second event are correlated and an event chain is formed; The edit distance similarity between the event chain and the attack chain template is calculated; When the edit distance similarity reaches a preset similarity threshold, log correlation alarm data is generated, wherein the log correlation alarm data includes a set of correlated events, a correlation degree, and matched attack chain template identification information.

[0011] In some embodiments, triplets are parsed from the log correlation alarm data, a basic knowledge graph is constructed based on the triplets and rule-based reasoning and embedding reasoning are performed, and the reasoning results are integrated to form a security situation knowledge graph with enhanced situation, further comprising: Defining a knowledge graph, the entity types of the knowledge graph including network assets, users, and attack behaviors; Extracting triplets consisting of head entities, relationships, and tail entities from the log correlation alarm data; Storing all parsed triplets to a graph database, wherein the head entities and the tail entities are nodes, and the relationships are edges between nodes, forming a basic knowledge graph; Hidden relationships are deduced through rule-based reasoning, and potential relationships are obtained through embedding reasoning; Integrate the hidden relationship and the potential relationship into the base knowledge graph to obtain the security posture knowledge graph.

[0012] In some embodiments, the hidden relationship is derived by rule reasoning, and the potential relationship is derived by embedding reasoning, further comprising: In rule reasoning, a hidden relationship is derived from the base knowledge graph according to a pre-defined event chain formation rule; In embedding reasoning, entities and relationships in the base knowledge graph are mapped to a low-dimensional vector space by using a TransE model, and vector representations of the entities and relationships are trained by vector operations; For real-time triples, if the distance between the sum of the head entity vector and the relationship vector and the tail entity vector is less than a pre-set distance threshold, it is determined that there is a potential relationship between the head entity and the tail entity.

[0013] In some embodiments, threat data is extracted from the security posture knowledge graph, and a graph attention network GAT is used to optimize the threat data to obtain a final network attack threat value, further comprising: The comprehensive harm degree and the attack influence range are obtained from the security posture knowledge graph; The vector representations of entities and relationships in the security posture knowledge graph are input into a graph attention network; For attack behaviors and associated network assets in the security posture knowledge graph, the attention weight of the attack behavior on the network asset is calculated, wherein the attention weight is calculated through an attention mechanism including vector splicing, linear transformation and an activation function, and all network asset nodes are normalized; The information of the network asset nodes associated with the attack behavior is aggregated by the graph attention network to obtain an enhanced feature vector of the attack behavior; The final network attack threat value is obtained by combining the comprehensive harm degree, the attack influence range and the enhanced feature vector through an activation function.

[0014] In some embodiments, the comprehensive harm degree and the attack influence range are obtained, further comprising: For attack behaviors in the security posture knowledge graph, if it is a vulnerability exploitation type attack, a common vulnerability scoring system is used to score and obtain a harm degree through normalization processing; If it is a non-vulnerability exploitation type attack, a harm degree is pre-defined according to historical attack harm degrees; the comprehensive harm degree is composed of the harm degree obtained by processing and the pre-defined harm degree; The attack influence range is obtained by comparing the sum of the number of network assets directly affected by the attack behavior and the number of network assets indirectly affected in the knowledge graph with the total number of network assets.

[0015] Based on the same concept, the application also provides a network security situation awareness system, comprising: A log acquisition module configured to acquire log event data in response to collected multi-source heterogeneous logs and perform standardized analysis; A data analysis module configured to perform real-time analysis based on the log event data using a dynamic baseline correlation engine to obtain log correlation alarm data, wherein the dynamic baseline correlation engine distinguishes abnormal events by obtaining the dynamic baseline of event types in the log sample sequence, quantifies the correlation of abnormal events, quantifies event correlation by fusing conditional probability and time decay correlation function, judges whether an event chain is formed, matches the formed event chain with an attack chain template to generate the log correlation alarm data, and the attack chain template is based on the MITRE ATT&CK framework and is obtained by combining actual attack event chain combinations in history; A rule reasoning module configured to parse triples from the log correlation alarm data, build a basic knowledge graph based on the triples, and perform rule reasoning and embedding reasoning, and integrate the reasoning results to form a situation-enhanced security situation knowledge graph; A situation awareness module configured to extract threat data from the security situation knowledge graph and optimize the threat data by combining a graph neural network GAT to obtain a final network attack threat value, and perform network security situation awareness based on the network attack threat value, wherein the threat data includes comprehensive harm degree and attack influence range.

[0016] Compared with the prior art, the application has the beneficial effects that: The application discloses a network security situation awareness method and system, which performs correlation degree calculation, attack chain template matching and other operations on events to generate log correlation alarm data containing rich and accurate information such as associated event set, correlation degree and template identifier, ensures a reliable data source for subsequent analysis, avoids analysis result deviation caused by poor data quality (such as incomplete data and inaccurate correlation), and uses correlation degree threshold and similarity threshold to filter out events that are truly associated and highly matched with the attack chain template from a large number of log events, filter out meaningless isolated events or false positive events, reduce the data amount for subsequent processing, and improve the efficiency and pertinence of security analysis.

[0017] Through the basic knowledge graph, the triples in the log correlation alarm data are integrated, entities such as network assets, users and attack behaviors and their explicit relationships are organized in the form of a graph structure, hidden relationships are derived through rule reasoning, potential relationships are embedded in reasoning, and these relationships are integrated into the basic knowledge graph to form a security posture knowledge graph, which further supplements the indirect and potential correlations between entities. Embedded reasoning can mine threat relationships with potential correlations without explicit rules by means of vector operation of the TransE model. The combination of the two enables the knowledge graph to have the ability to reason threats from different dimensions and improves the discovery probability of unknown threats and new attacks.

[0018] Based on the calculated network attack threat value, the threat distribution and change trend of different assets and different attack types are displayed through a heat map and a time series chart visualization tool, so that security personnel can intuitively and quickly grasp the network security posture and identify areas and attack types with high threats, thereby providing a clear and intuitive basis for formulating targeted protection strategies and improving the efficiency and effectiveness of network security management. BRIEF DESCRIPTION OF DRAWINGS

[0019] Other features, objects and advantages of the present application will become more apparent from the following detailed description of non-limiting embodiments made with reference to the accompanying drawings: Figure 1 is a flowchart of a network security posture perception method in some embodiments of the present application; Figure 2 is a flowchart of a network security posture perception system in some embodiments of the present application. DETAILED DESCRIPTION

[0020] In order to make the purposes, technical solutions and advantages of the present application more clear, the present application will be further described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the scope of protection of the present application.

[0021] The terms used in the embodiments of the present application are only for the purpose of describing specific embodiments, and are not intended to limit the present application. The singular forms "a", "an" and "the" used in the embodiments of the present application and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise. "Multiple" generally includes at least two.

[0022] It should be understood that the term "and / or" as used herein merely describes an associated relationship between associated objects, and indicates that there can be three relationships, for example, A and / or B, which can represent three cases of A alone, A and B together, and B alone. In addition, the character " / " herein generally represents an "or" relationship between the front and rear associated objects.

[0023] It should be understood that although the terms first, second, third, etc. can be used in embodiments of the present application to describe, these descriptions should not be limited to these terms. These terms are only used to distinguish the description. For example, without departing from the scope of the embodiments of the present application, the first can also be referred to as the second, and similarly, the second can also be referred to as the first.

[0024] Depending on the context, the word "if" as used herein can be interpreted as "when" or "upon" or "in response to determining" or "in response to detecting". Similarly, depending on the context, the phrase "if it is determined" or "if (a stated condition or event) is detected" can be interpreted as "when it is determined" or "in response to determining" or "when (a stated condition or event) is detected" or "in response to detecting (a stated condition or event)".

[0025] It should also be noted that the terms "comprising", "including", or any other variant thereof are intended to cover non-exclusive inclusion, so that a product or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such product or device. Without more limitations, the element defined by the sentence "including a…" does not exclude the presence of other identical elements in the product or device including the element.

[0026] In particular, it should be noted that the symbols and / or numbers present in the description, if not marked in the description of the drawings, are not drawing reference numbers.

[0027] Referring to Figure 1 A network security situation awareness method comprises: S101, in response to the collected multi-source heterogeneous logs and the standardized analysis, obtaining log event data; S102, real-time analysis is performed on the log event data based on the dynamic baseline correlation engine to obtain log correlation alarm data, wherein the dynamic baseline correlation engine distinguishes abnormal events by obtaining a dynamic baseline of event types in a log sample sequence, quantifies correlation of abnormal events, quantifies event correlation by fusing conditional probability and time decay correlation function, judges whether an event chain is formed, matches the formed event chain with an attack chain template to generate the log correlation alarm data, and the attack chain template is based on the MITRE ATT&CK framework and is obtained by combining actual attack event chain combinations in history; S103, triplets are parsed from the log correlation alarm data, a basic knowledge graph is constructed based on the triplets, rule reasoning and embedding reasoning are performed, and a security situation knowledge graph with enhanced situation is formed by integrating reasoning results; S104, threat data is extracted according to the security situation knowledge graph, the threat data is optimized by combining a graph neural network GAT to obtain a final network attack threat value, and network security situation awareness is performed based on the network attack threat value, wherein the threat data includes comprehensive harm degree and attack influence range.

[0028] Specifically, in the embodiments of the present application, in response to the collected multi-source heterogeneous logs and standardized analysis, log event data is obtained, including defining a unified log field structure, which includes log timestamp, event subject, event action and event object; using regular expressions to map logs from different sources and with different formats to the unified field structure, converting them into structured log events; using network time protocol for timestamp normalization processing of all structured log events to ensure time sequence consistency; the parsed and normalized data is transmitted through a message queue, output as a standard event, forming a unified standardized log event data set. Based on the log event data, a dynamic baseline correlation engine is used for real-time analysis to obtain log correlation alarm data. The dynamic baseline correlation engine distinguishes abnormal events by obtaining the dynamic baseline of event types in the log sample sequence, the process includes: selecting event logs corresponding to historical normal data to define event types and constitute a sample sequence, calculating the probability density function of normal event occurrence frequency based on the sequence using kernel density estimation method, setting the significance level according to the function and calculating the upper and lower limits of the corresponding confidence interval to determine the dynamic baseline; after identifying abnormal events deviating from the dynamic baseline, the correlation of abnormal events is quantified, the correlation closeness between events is calculated through the correlation degree function of fusing conditional probability between event types and time decay factor, and whether the events form an event chain is judged according to whether the correlation degree reaches a preset threshold; the formed event chain is matched with a preset attack chain template, the attack chain template is obtained based on the MITRE ATT&CK framework and combined with historical attack event chains, the similarity between the event chain and the template is calculated using the edit distance algorithm, and if the similarity reaches a set threshold, log correlation alarm data containing the associated event set, correlation degree and template identifier is generated. Triples are parsed from the log correlation alarm data, a basic knowledge graph is constructed based on the triples and rule reasoning and embedding reasoning are performed, and the reasoning results are integrated to form a situation-enhanced security situation knowledge graph, including: defining a knowledge graph with network assets, users and attack behaviors as entity types, extracting triples composed of head entities, relationships and tail entities from alarm data; storing all triples in a graph database to build a basic knowledge graph with entities as nodes and relationships as edges; hidden relationships are derived through predefined event chain rules for rule reasoning, and at the same time, TransE embedding model is used to map entities and relationships to low-dimensional vector space, vector representation is obtained through vector operation training and potential relationships are inferred accordingly; hidden relationships and potential relationships are integrated into the basic knowledge graph to form an enhanced security situation knowledge graph.According to the security situation knowledge graph, threat data is extracted, and a graph neural network GAT is combined to optimize the threat data to obtain a final network attack threat value. Network security situation awareness is performed based on the network attack threat value. The threat data includes a comprehensive harm degree and an attack influence range. The process includes: for an attack behavior identified in the knowledge graph, if the attack behavior belongs to a vulnerability exploitation type attack, a harm degree is obtained by scoring and normalizing according to a common vulnerability scoring system; if the attack behavior belongs to a non-vulnerability exploitation type attack, a harm degree is preset according to historical data; and a comprehensive harm degree is formed by comprehensively combining the two harm degrees; the number of assets directly and indirectly affected by the attack behavior is counted, and an attack influence range is obtained by comparing the number of assets with a total number of assets; a vector representation of entities and relationships in the knowledge graph is input into a graph attention network, attention weights between the attack behavior and associated assets are calculated, and an enhanced feature vector of the attack behavior is obtained after aggregation of associated node information; the network attack threat value is obtained by combining the comprehensive harm degree, the attack influence range and the enhanced feature vector, and is mapped through an activation function, and is used to generate a visualized situation awareness result.

[0029] For example, collect multi-source logs from servers, firewalls and application systems, and after parsing, obtain a standardized event: the timestamp is October 15, 2023 14:05:30, the event subject is user "admin", the event action is "execute", and the event object is "command rm -rf / tmp". In dynamic baseline analysis, assuming that the frequency of "command execution" type events in the historical normal sample is dynamically baseline [5 times / minute, 20 times / minute], and 50 times of the event are detected within 1 minute, it is determined to be abnormal. In correlation analysis, it is found that the event and another abnormal event "user admin logs in from IP 192.168.1.100" occur within 10 seconds, the conditional probability is 0.8, the time decay factor is 0.95, the correlation degree result is 0.76, which exceeds the threshold value 0.5, and an event chain is formed. The attack chain template matched with the event chain is "initial access -> execution", the edit distance similarity is 0.75, which exceeds the threshold value 0.7, and an alarm data is generated. From which the triplets (admin, execute, rm -rf / tmp), (admin, login, 192.168.1.100) are parsed. After constructing the basic knowledge graph, it is found through rule reasoning that (rm-rf / tmp, belongs to, malicious command) is a hidden relationship, and the vector distance calculated by the TransE model is 0.8, which is less than the threshold value 1.0, and it is inferred that (192.168.1.100, source, foreign IP) is a potential relationship. The security situation knowledge graph is obtained after integration. Extract threat data: the "malicious command execution" behavior belongs to a non-exploitation attack, and the preset harm degree is 0.7; directly affects 1 asset, indirectly affects 3 assets, and the total number of assets is 100, and the attack influence range is 0.04. The attention weight of the attack behavior on the associated assets in the GAT network is 0.6, and the enhanced feature vector is [0.1, 0.3,..., 0.05] (100 dimensions), and the final threat value is calculated as 0.7x0.04xsigmoid(0.6xenhanced feature vector)=0.025. The value is used to generate a heat map to show that the threat level of the corresponding asset area has increased.

[0030] In some applications, in response to the collected multi-source heterogeneous logs and standardized parsing, log event data is obtained, including defining a unified log field, the unified log field including a log timestamp, an event subject, an event action and an event object; using regular expressions to map logs of different sources and formats to the unified log field, and converting into structured log events; performing timestamp normalization processing on all structured log events using an NTP protocol, and transmitting through a Kafka message queue, outputting standard events, and forming a unified standardized log event data set.

[0031] For example, collect multi-source heterogeneous logs from web servers, firewalls and database systems, and the original log formats are "2023-10-15T14:05:30Z user=admin action=execute command='rm -rf / tmp'", "15 / Oct / 2023:14:05:30+0800 192.168.1.1 DENY TCP 123.45.67.89:443" and "20231015140530|DB_QUERY|admin|SELECT * FROM users", respectively. After defining the uniform log fields including timestamp, subject, action and object, the mapping is parsed by regular expression, and the standardized events are obtained as follows: the timestamp is October 15, 2023, 14:05:30, the subject is admin, the action is execute, and the object is the command rm -rf / tmp; the timestamp is October 15, 2023, 14:05:30, the subject is 192.168.1.1, the action is deny, and the object is TCP connection 123.45.67.89:443; the timestamp is October 15, 2023, 14:05:30, the subject is admin, the action is query, and the object is the database table users. The time synchronization normalization is performed on all events by using the NTP protocol to unify the timestamps to the UTC time zone. Finally, the structured events are transmitted through the Kafka message queue to form a log event data set containing three standardized records.

[0032] In some applications, the dynamic baseline correlation engine distinguishes abnormal events by obtaining a dynamic baseline of an event type in a log sample sequence, including selecting log event data corresponding to normal sample data in historical data, and defining an event type of each log event data to form a log sample sequence; based on the log sample sequence, a Gaussian kernel estimation method is used to calculate a probability density function of a normal event frequency; based on the probability density function, a significance level is set, and an upper limit and a lower limit of a confidence interval corresponding to the significance level are calculated, so that the integral value of the probability density function from negative infinity to the lower limit is equal to half of the significance level, and the integral value from the upper limit to positive infinity is also equal to half of the significance level; according to the upper limit and the lower limit, a dynamic baseline of the event type at a specified time is obtained, wherein the dynamic baseline is an interval defined by the upper limit and the lower limit.

[0033] For example, the log event data generated during the normal operation of the past seven days is selected, the event type is defined as "user login", and a log sample sequence containing 10080 samples (one sample point per minute) is formed; the probability density function of the "user login" event frequency is calculated based on the sequence using the Gaussian kernel estimation method; the upper limit of the 95% confidence interval is calculated to be 20 times / minute and the lower limit is 5 times / minute, where the integral value of the probability density function from negative infinity to 5 times / minute is 0.025, and the integral value from 20 times / minute to positive infinity is also 0.025; thus, the dynamic baseline of the "user login" event at the current time is obtained as the interval range [5 times / minute, 20 times / minute]; when the real-time monitoring of the "user login" event frequency is 30 times / minute, the value exceeds the dynamic baseline range, and the abnormal event is identified.

[0034] In some applications, the correlation of abnormal events is quantified, including defining a correlation degree function to measure the correlation degree between events, the correlation degree function fuses the conditional probability between event types and a factor that simulates the influence of the time interval between event occurrences in an exponential decay manner; the time window for defining the correlation relationship between events is preset to a fixed length.

[0035] For example, two abnormal events are detected: event A is "user admin abnormal login" and occurs at 14:05:30; event B is "sensitive file access" and occurs at 14:05:38. The preset time window is 30 seconds, and the time interval between the two events is 8 seconds within the window. The conditional probability of event B occurring within 30 seconds after event A is 0.6 according to the historical attack log statistics. The time decay coefficient is set to 0.1, and the time decay factor is e to the power of -0.1 times 8, which is approximately equal to 0.45. The correlation degree function value is calculated as 0.6 x 0.45 = 0.27. The correlation degree threshold is set to 0.2, and since 0.27 is greater than 0.2, it is determined that the two abnormal events have significant correlation, and the correlation degree value is recorded for subsequent event chain construction.

[0036] In some applications, the correlation of events is quantified by fusing the conditional probability with the time-decay correlation function, to determine whether an event chain is formed, and to match the formed event chain with an attack chain template to generate the log correlation alarm data, including counting the number of times that a second event type occurs within a preset time window after the occurrence of a first event type, and the total number of occurrences of the first event type, from historical attack logs; calculating the conditional probability of the second event type after the occurrence of the first event type; based on the conditional probability and the actual time interval between the first event and the second event to be analyzed, calculating the correlation between the first event and the second event; when the correlation reaches a preset correlation threshold, determining that the first event and the second event are correlated and forming an event chain; calculating the edit distance similarity between the event chain and the attack chain template; when the edit distance similarity reaches a preset similarity threshold, generating log correlation alarm data, wherein the log correlation alarm data includes a set of correlated events, a correlation degree, and matched attack chain template identification information.

[0037] For example, from historical attack logs, it is found that after the occurrence of an "abnormal login" event within a 30-second time window, the "sensitive file access" event occurred 85 times, while the "abnormal login" event occurred a total of 100 times, and the conditional probability is calculated to be 0.85; the current monitoring shows that the abnormal login event occurred at 14:05:30, and the sensitive file access event occurred at 14:05:40, with a time interval of 10 seconds; the time decay coefficient is set to 0.1, and the time decay factor is the natural constant negative decay coefficient raised to the power of the time interval, which is approximately 0.37; the correlation value is 0.85 x 0.37 ≈ 0.31; the correlation threshold is set to 0.3, and since 0.31 is greater than 0.3, it is determined that the two events are correlated and form an event chain containing two events; the event chain is matched with the "initial access → execution" attack chain template in the MITRE ATT&CK framework, and the edit distance similarity is calculated: the event chain length is 4, the template length is 5, the operation number is 2, and the similarity is 1-2÷5=0.6; the similarity threshold is set to 0.55, and since 0.6 is greater than 0.55, the matching is successful; the log correlation alarm data is generated, including the detailed information of the two events, the correlation value 0.31, and the matched ATT&CK tactic identification TA0001 and TA0002.

[0038] In some of the applications, triples are parsed from the log correlation alert data, a base knowledge graph is constructed based on the triples and rule-based reasoning and embedding-based reasoning are performed, and the reasoning results are integrated to form a security situation knowledge graph with enhanced situation, including defining a knowledge graph, the entity types of the knowledge graph including network assets, users, and attack behaviors; triples composed of head entities, relationships, and tail entities are extracted from the log correlation alert data; all parsed triples are stored in a graph database, where the head entities and the tail entities are nodes and the relationships are edges between the nodes, forming a base knowledge graph; hidden relationships are derived through rule-based reasoning, and potential relationships are obtained through embedding-based reasoning; the hidden relationships and the potential relationships are integrated into the base knowledge graph to obtain the security situation knowledge graph.

[0039] For example, triples (user admin, execute, command rm -rf / tmp), (IP address 192.168.1.100, initiate, unauthorized access), and (web server, run, application service) are parsed from the log correlation alert data; these triples are stored in a Neo4j graph database to form a base knowledge graph containing 5 nodes and 3 edges; a hidden relationship (command rm -rf / tmp, belongs to, dangerous operation) is discovered through rule-based reasoning; at the same time, TransE embedding model is used to map entities and relationships to a 100-dimensional vector space, and after calculating the vector representation, it is found that the vector distance of the potential relationship (IP address 192.168.1.100, source, malicious IP segment) is 0.8, which is less than the preset threshold 1.0; the two new relationships are added as edges to the base knowledge graph, adding 2 nodes and 2 edges, to obtain a security situation knowledge graph containing 7 nodes and 5 edges, enhancing the representation ability of the network security situation.

[0040] In some of the applications, hidden relationships are derived through rule-based reasoning, and potential relationships are obtained through embedding-based reasoning, including in rule-based reasoning, forming rules according to predefined event chains, and deriving hidden relationships from the base knowledge graph; in embedding-based reasoning, TransE model is used to map entities and relationships in the base knowledge graph to a low-dimensional vector space, and vector representations of entities and relationships are trained through vector operations; for real-time triples, if the distance between the sum of the head entity vector and the relationship vector and the tail entity vector is less than the preset distance threshold, it is determined that there is a potential relationship between the head entity and the tail entity.

[0041] For example, in the rule reasoning process, based on the predefined rule "if a user executes a specific command and the command is marked as a dangerous operation, the user may have malicious intent", from the base knowledge graph containing (user admin, execute, command rm -rf / tmp), the hidden relationship (user admin, have, malicious intent) is inferred. In the embedding reasoning process, the TransE model is used to map entities and relationships in the graph to a 50-dimensional vector space. After training, the vector of the entity "IP address 192.168.1.100" is [0.2, -0.3,..., 0.1], the vector of the relationship "source" is [0.4, 0.2,..., -0.3], and the vector of the entity "malicious IP segment" is [0.6, -0.1,..., 0.4]. The head entity vector plus the relationship vector is [0.6, -0.1,..., 0.1], and the Euclidean distance with the tail entity vector is 0.7, which is less than the preset threshold 1.0, so it is determined that there is a potential relationship (IP address 192.168.1.100, source, malicious IP segment). The two new relationships obtained by reasoning are integrated into the base knowledge graph to enhance the knowledge representation of the security posture.

[0042] In some applications, threat data is extracted from the security posture knowledge graph and combined with a graph neural network GAT to optimize the threat data to obtain a final network attack threat value, including obtaining the comprehensive harm degree and the attack impact range from the security posture knowledge graph; the vector representation of entities and relationships in the security posture knowledge graph is input into a graph attention network; for attack behaviors and associated network assets in the security posture knowledge graph, the attention weight of the attack behavior on the network asset is calculated, wherein the attention weight is calculated through an attention mechanism including vector splicing, linear transformation and activation function, and all network asset nodes are normalized; the information of the network asset nodes associated with the attack behavior is aggregated through the graph attention network to obtain an enhanced feature vector of the attack behavior; the comprehensive harm degree, the attack impact range and the enhanced feature vector are combined, and the final network attack threat value is obtained through an activation function mapping.

[0043] For example, the comprehensive harm degree of the attack behavior "data theft" is 0.8 and the attack influence range is 0.3 obtained from the security posture knowledge graph; the 100-dimensional vector representation of all entities and relationships in the knowledge graph is input into the graph attention network; the attention weight is calculated for the attack behavior "data theft" and the three network assets (database server, file server and application server) associated with it: the attack behavior vector [0.1, 0.2,..., 0.3] is spliced with the database server vector [0.4, 0.1,..., 0.2], and after processing by the linear transformation matrix W (dimension 50x200) and the parameter vector a (dimension 50x1), the intermediate value 0.6 is obtained using the LeakyReLU activation function, and then the attention weight of the database server is obtained by normalizing all associated assets through softmax, which is 0.4; the same method is used to calculate the attention weights of the file server and the application server, which are 0.35 and 0.25 respectively; after aggregating the node information of the three assets, the enhanced feature vector of the attack behavior is obtained as [0.2, 0.3,..., 0.1]; combined with the comprehensive harm degree 0.8, the attack influence range 0.3 and the enhanced feature vector, the network attack threat value 0.72 is obtained by mapping through the sigmoid activation function, which is used to quantify the overall threat degree of this attack.

[0044] In some applications, the comprehensive harm degree and the attack influence range are obtained, including for the attack behavior in the security posture knowledge graph, if it is a vulnerability exploitation type attack, the harm degree is obtained by scoring using the Common Vulnerability Scoring System and normalized processing; if it is a non-vulnerability exploitation type attack, the harm degree is predefined according to the historical attack harm degree; the comprehensive harm degree is composed of the harm degree obtained by processing and the predefined harm degree; the sum of the number of network assets directly affected by the attack behavior and the number of network assets indirectly affected is calculated, and then compared with the total number of network assets to obtain the attack influence range.

[0045] For example, two attack behaviors are identified in the security posture knowledge graph: the first is a vulnerability exploitation type attack "CVE-2021-34527 exploit", which has a CVSS score of 8.8 (full score 10), and a normalized hazard degree of 0.88; the second is a non-vulnerability exploitation type attack "brute force attack", and the hazard degree is predefined as 0.7 according to the average loss degree caused by this type of attack in historical data; the comprehensive hazard degree is composed of the two hazard degree values. The number of network assets directly affected by the vulnerability exploitation attack is 2 (web server and database server), and the number of network assets indirectly affected is 5 (connected application servers and terminal devices), and the total number of network assets is 100, and the attack influence range is calculated as (2+5) / 100=0.07. The attack influence range value and the comprehensive hazard degree value will be used as input parameters for subsequent calculation of network attack threat values.

[0046] Another embodiment of the network security posture perception method of the application is described below: A unified log field is defined, including log timestamp t, event subject (user, process, device, etc.), event action (login, access, modification, etc.), and event object (file, database table, network port, etc.). Different sources and formats of logs are mapped to log fields using regular expressions (text logs) to convert them into structured log events. NTP protocol is used for all structured log events, and the timestamp of each structured log event is normalized. The parsed data is transmitted through a Kafka message queue, and the output standard event is represented as , i is the event number, and the final log event data containing different events and unified standardization is .

[0047] The dynamic baseline of the event type in the log sample sequence is obtained to distinguish abnormal events, and the process is as follows: Select normal sample data that has been running continuously for a week and has no security events in the historical data, and obtain the corresponding log event data. Define the event type of each log event data , and form the log sample sequence , where m is the number of samples. Based on the collected log sample sequence , the probability density function of the normal event frequency is estimated using Gaussian kernel , and the formula is as follows: ; Wherein, represents the event frequency value, is the jth log sample sequence in the log sample sequence, , and h is the bandwidth parameter. Specifically, the bandwidth parameter h is determined by cross-validation method, the sample is divided into training set and validation set, and then different h values are traversed, and the log likelihood of the validation set is calculated: The h that can maximize the log likelihood is selected, and the final bandwidth parameter can make the estimated probability density function most consistent with the data distribution of the validation set; Based on the probability density function , set the significance level , and calculate the upper and lower limits of the 95% confidence interval , and satisfy , , thus the dynamic baseline of the event type in the log sample sequence at time t is obtained: ; Specifically, the dynamic baseline is updated every hour with the latest normal data to ensure synchronization with the system state, and the normal event data that meets the dynamic baseline in subsequent real-time analysis will be continuously supplemented to the normal sample set; Collect the current log event data L with a 1-minute time window, and based on the dynamic baseline corresponding to different events in the log event data L, the frequency of each event type is counted , if does not belong to the dynamic baseline , the event corresponding to the log event data is marked as an abnormal event, and the event correlation analysis is performed on the abnormal event; The process of correlating and quantifying abnormal events is as follows: Correlate and quantify abnormal events, define a correlation degree function to measure the correlation degree between events, and the formula is: ; Wherein, represents the correlation closeness, represents the conditional probability, represents the time decay coefficient, represents the time interval between the occurrence of events and , , represents a preset time interval, which is 30 seconds, and e is a natural constant; And extract from the historical attack log the number of times that event type occurs within time interval (30 seconds) after event type occurs, and the total number of times that event type occurs, and use these two data to calculate the conditional probability, which will be used as the basis data for calculating the correlation degree in the next step. The conditional probability is expressed as: representing the type of event in the historical attack log after the time interval in which the type of event occurred, representing the type of event occurred; Then, using the obtained conditional probability and the current event to be analyzed and the time interval , the correlation of the event and is calculated again , which will be used to determine whether the two events can form an event chain; when (threshold ) is met, the event and are associated to form an event chain, which is matched with an attack chain template (based on the MITRE ATT&CK framework, combined with the event chain summary of historical attacks) to calculate the similarity using the edit distance: when , log correlation alarm data A is generated, including the associated event set, correlation degree, and template identification information; Specifically, the content of the log correlation alarm data A is: the associated event set, i.e. the events corresponding to the event chain and , the correlation degree and the template identification (the identification information of the matched attack chain template), which is based on the MITRE ATT&CK framework and combined with the attack event chain summary of historical attacks; In summary, attack chain templates are summarized by analyzing historical attack event chains, and typical step sequences from the beginning to the end of attack behavior under different attack scenarios are sorted out, such as a certain type of attack first obtains initial permissions through "phishing" (belongs to the initial access technology in MITRE ATT&CK), then expands the scope of influence through "lateral movement", and then implements "data theft" and other operations. These steps with logical order and in line with the rules of attack evolution are combined to form an attack chain template.

[0048] Triplet is parsed from log correlation alarm data, basic knowledge graph is constructed using triplet, rule reasoning and embedding reasoning are performed, and reasoning results are integrated to form a security situation knowledge graph with enhanced situation; The process of constructing the basic knowledge graph is: A knowledge graph is defined, and entities are divided into three categories of network assets D, users U, and attack behaviors C, and triplets are extracted from log correlation alert data A , (head entity , relation , tail entity ); Specifically, log correlation alert data A is obtained, the log correlation alert data includes a correlation event set, a correlation degree, and template identification information, and specific alert content is selected from the correlation event set of A, such as "user admin executed unauthorized command 'rm-rf / tmp' on host web-01 at 2025-09-08 11:00"; Each alert is parsed to extract triplets in the form of "head entity, relation, tail entity" , wherein the head entity and the tail entity belong to the three types of entities of "network assets D, users U, and attack behaviors C", and the relation describes the connection between entities, such as operation, initiation, and targeting; For example, the above alert can be parsed to obtain three triplets (admin, operation, web-01), (admin, initiation, unauthorized command execution), and (unauthorized command execution, targeting, web-01); Then, all triplets parsed from the log correlation alert data A are input into a graph database (such as Neo4j) for storage, the graph database takes the head entity and the tail entity of each triplet as nodes (included in the entity set V), and takes the relation as the edge between the nodes (included in the relation set E), through the storage operation of the graph database, the basic knowledge graph G=(V,E) is formed, V is the entity set, and E is the relation set; The process of rule reasoning and embedding reasoning is as follows: Rule reasoning uses the pre-defined event chain to form rules according to the constructed basic knowledge graph G, when the event chain is formed, the relation in the triplet is a hidden relation; Embedding reasoning uses the TransE model to map entities and relations in the basic knowledge graph G to a 100-dimensional vector space, and trains through vector operations (the training process is to minimize the loss function of the TransE model), so as to obtain vector representations of entities and relations, according to the vector representations of entities and relations, for real-time triplets , if , it is considered that there is a potential relation between the head entity and the tail entity ; By integrating the hidden relationships derived from rule-based reasoning and the latent relationships obtained from embedded reasoning into the basic knowledge graph G, a final security posture knowledge graph containing the reasoned entity relationships is obtained. ; Specifically, for the underlying knowledge graph G stored in the graph database, the hidden relation triples obtained from rule reasoning and the latent relation triples obtained from embedding reasoning are added to the graph database as new nodes (entities) and edges (relationships), and the head entities in the new triples are checked. Tail-end entity If the node already exists in the graph database's node set, establish the relationship edge between them directly; otherwise, create the entity node first, and then establish the relationship edge. The resulting log-related alarm data is a crucial source of information for analyzing the security posture. The predefined event chain rules upon which rule-based reasoning is based are derived from summarizing the processes and characteristics of network attacks. In actual security threat analysis, reasoning about hidden attack relationships through event chains is a practical method. The TransE model is a classic model for knowledge graph embedding reasoning, widely used and validated in knowledge graph representation learning and relation reasoning tasks. Applying it to the embedding reasoning of security posture knowledge graphs is technically reasonable and feasible.

[0049] Threat data is extracted from the security situation knowledge graph and optimized by the graph neural network GAT to obtain the final network attack threat value. Network security situation awareness is then performed based on the attack threat value. Threat data includes overall severity and the scope of the attack. For security situation knowledge graphs If attack behavior C is a vulnerability exploitation attack, the severity is obtained using CVSS scoring normalization. If the attack is not an exploit-based attack, the severity level is predefined based on the severity of historical attacks. The final overall hazard level is expressed as ; Among them, the degree of harm By collecting relevant data on non-exploitation attack incidents from historical data, including the losses caused by the attacks and the importance of the assets affected, statistical analysis is performed on this data. Based on different attack types and scenario factors, the severity values ​​of corresponding attack behaviors are predefined. Subsequently, when the security situation knowledge graph... When a non-exploitation attack (C) occurs, the predefined severity level is directly matched. ; Meanwhile, statistical knowledge graphs The number of assets directly affected by the attack C and the number of assets indirectly affected , combining the total number of network assets , calculating the attack impact range ; Specifically, extracting threat data is the basis for subsequent calculation of attack threat value, comprehensive harm degree and attack impact range are important inputs for calculating attack threat value. In the field of network security, CVSS score is an effective means to measure the harm degree of vulnerability, which is used to determine the harm degree of vulnerability exploitation type attack, and the harm degree of non-vulnerability exploitation type attack is predefined according to historical attack harm degree, which is consistent with the practice of assessing threats based on historical experience in actual security analysis, and the attack impact range is calculated by counting the number of assets affected by the attack, which is also an effective way to assess attack threat from the perspective of the scale of affected assets. The vector representation of the entities and relationships obtained in the security posture knowledge graph is taken as the input of the graph attention network, and the attention weight between entities in the security posture knowledge graph is learned through the graph attention network to more accurately capture the influence of attack behavior on assets: For attack behavior C and its associated network assets D in the security posture knowledge graph , the attention weight of attack behavior C on network assets D is calculated , and the formula is: ; Wherein, is the parameter vector of the attention mechanism, is the weight matrix, and are the feature vectors of attack behavior C and network assets D respectively, represents vector splicing, is the activation function, is the normalization operation on all neighbor asset nodes of Collect historical network security event data, including the affected assets when the attack behavior occurs, and use these data as labels to train the GAT network. Use the trained graph attention network to optimize the acquisition of threat data; For attack behavior C in the security posture knowledge graph , aggregate the information of its associated asset nodes through the GAT network to obtain the enhanced feature vector of attack behavior C ; Combine the previously obtained attack behavior comprehensive harm degree (taking for vulnerability exploitation type and for non-vulnerability exploitation type) and attack impact range to obtain the final attack threat value: ; wherein, is an activation function for mapping the result to a range, making the threat value more interpretable; Specifically, the attack threat value is calculated The comprehensive harm degree obtained in the foregoing is integrated , the attack influence range and the enhanced feature vector The result is the core data for network security situation awareness. Finally, based on the calculated attack threat value , the threat values of all attack behaviors in the network are summarized and analyzed, and the threat distribution and change trend of different assets and different attack types are displayed through a visualization tool (such as a heat map and a time series chart), so as to realize real-time awareness of the network security situation. The darker the color in the heat map, the higher the threat value, and the more serious the network security situation in the region, which needs to be focused on and protected.

[0050] For the method steps disclosed in the above embodiments, the method steps are described as a combination of a series of actions for the purpose of simple description, but those skilled in the art should know that the embodiments of the present application are not limited by the order of the described actions, because according to the embodiments of the present application, certain steps can be performed in other order or simultaneously. Secondly, those skilled in the art should know that the embodiments described in the specification all belong to preferred embodiments, and the actions involved are not necessarily necessary for the embodiments of the present application.

[0051] As shown in Figure 2 , the present application also provides a network security situation awareness system, comprising: A log acquisition module 201 configured to acquire log event data in response to collected multi-source heterogeneous logs and perform standardized analysis; A data analysis module 202 configured to perform real-time analysis based on the log event data using a dynamic baseline correlation engine to obtain log correlation alarm data, wherein the dynamic baseline correlation engine distinguishes abnormal events by obtaining the dynamic baseline of event types in the log sample sequence, and quantifies the correlation of abnormal events, quantifies event correlation by fusing conditional probability and time decay correlation function, judges whether an event chain is formed, matches the formed event chain with an attack chain template to generate the log correlation alarm data, and the attack chain template is based on the MITRE ATT&CK framework and is obtained by combining actual attack event chain combinations in history; The rule reasoning module 203 is configured to parse triples from the log correlation alarm data, construct a basic knowledge graph based on the triples, and perform rule reasoning and embedding reasoning, and integrate the reasoning results to form a security situation knowledge graph with enhanced situation awareness; The situation awareness module 204 is configured to extract threat data from the security situation knowledge graph and optimize the threat data by combining a graph neural network GAT to obtain a final network attack threat value, and perform network security situation awareness based on the network attack threat value, wherein the threat data includes a comprehensive hazard degree and an attack impact range.

[0052] It is worth noting that, although only some basic functional modules are disclosed in the embodiments of the present application, it does not mean that the composition of the system is limited to the above basic functional modules. On the contrary, the meaning expressed by the embodiments is that on the basis of the above basic functional modules, those skilled in the art can add one or more functional modules to form infinite embodiments or technical solutions in combination with the prior art. That is, the system is open rather than closed, and it cannot be considered that the protection scope of the present application is limited to the disclosed basic functional modules only because the embodiments only disclose individual basic functional modules. At the same time, for the convenience of description, the above device is described as various units and modules. Of course, when implementing the present application, the functions of the units and modules can be implemented in the same software and / or hardware.

[0053] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for part or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A cyber security situation awareness method, characterized by, The method comprises the following steps: obtaining log event data in response to collected multi-source heterogeneous logs and standardized analysis; based on the log event data, using a dynamic baseline correlation engine for real-time analysis to obtain log correlation alarm data, wherein the dynamic baseline correlation engine distinguishes abnormal events by obtaining the dynamic baseline of the event type in the log sample sequence, and quantifies the correlation of abnormal events, quantifies event correlation by fusing conditional probability and time decay correlation function, judges whether an event chain is formed, matches the formed event chain with an attack chain template to generate the log correlation alarm data, and the attack chain template is based on the MITRE ATT&CK framework and is obtained by combining the actual attack event chain combination in history; parsing triples from the log correlation alarm data, constructing a basic knowledge graph based on the triples and performing rule reasoning and embedding reasoning, and integrating the reasoning results to form a security situation knowledge graph with enhanced situation; extracting threat data from the security situation knowledge graph and optimizing the threat data by combining a graph neural network GAT to obtain a final network attack threat value, and performing network security situation awareness based on the network attack threat value, wherein the threat data includes comprehensive hazard degree and attack impact range.

2. The cyber security situation awareness method of claim 1, wherein, In response to the collected multi-source heterogeneous logs and standardized analysis, the log event data is obtained, further comprising: defining a unified log field, which includes log timestamp, event subject, event action and event object; mapping logs of different sources and formats to the unified log field using regular expressions to convert them into structured log events; performing timestamp normalization processing on all structured log events using NTP protocol, and transmitting through Kafka message queue to output standard events, forming a unified standardized log event data set.

3. The cyber security situation awareness method of claim 2, wherein, The dynamic baseline correlation engine distinguishes abnormal events by obtaining the dynamic baseline of the event type in the log sample sequence, further comprising: selecting log event data corresponding to normal sample data in historical data, and defining the event type of each log event data to form a log sample sequence; based on the log sample sequence, the probability density function of normal event frequency is calculated by using Gaussian kernel estimation method; based on the probability density function, set the significance level, and calculate the upper and lower limits of the confidence interval corresponding to the significance level, so that the integral value of the probability density function from negative infinity to the lower limit is equal to half of the significance level, and the integral value from the upper limit to positive infinity is also equal to half of the significance level; according to the upper and lower limits, the dynamic baseline of the event type at a specified time is obtained, wherein the dynamic baseline is an interval defined by the upper and lower limits.

4. The cyber security situation awareness method of claim 1, wherein, For abnormal events, the correlation quantification further comprises: defining a correlation function to measure the correlation between events, the correlation function fuses the conditional probability between event types and a factor that simulates the influence of event occurrence time interval in an exponential decay manner; the time window used to define the correlation relationship between events is preset to a fixed length.

5. The cyber security situation awareness method of claim 4, wherein, The event correlation is quantified by fusing the conditional probability and the correlation function with time decay, and it is determined whether an event chain is formed. The formed event chain is matched with an attack chain template to generate the log correlation alarm data, which further includes: From the historical attack logs, the number of times of the second event type occurring after the first event type occurs and within a preset time window, and the total number of times of the first event type occurring are counted. The conditional probability of the second event type after the first event type occurs is calculated. Based on the conditional probability and the actual time interval of the first event and the second event to be analyzed, the correlation degree between the first event and the second event is calculated. When the correlation degree reaches a preset correlation degree threshold, it is determined that the first event and the second event are correlated and an event chain is formed. The edit distance similarity between the event chain and the attack chain template is calculated. When the edit distance similarity reaches a preset similarity threshold, log correlation alarm data is generated, wherein the log correlation alarm data includes a set of correlated events, a correlation degree, and matched attack chain template identification information.

6. The cyber security situation awareness method of claim 1, wherein, From the log correlation alarm data, triples are parsed, a basic knowledge graph is constructed based on the triples, and rule reasoning and embedding reasoning are performed, and the reasoning results are integrated to form a security situation knowledge graph with enhanced situation, which further includes: Defining a knowledge graph, the entity types of the knowledge graph include network assets, users, and attack behaviors. From the log correlation alarm data, triples composed of head entities, relationships, and tail entities are extracted. All parsed triples are stored in a graph database, where the head entities and the tail entities are nodes, and the relationships are edges between the nodes, forming a basic knowledge graph. Hidden relationships are deduced through rule reasoning, and potential relationships are obtained through embedding reasoning. The hidden relationships and the potential relationships are integrated into the basic knowledge graph to obtain the security situation knowledge graph.

7. The cyber security situation awareness method of claim 6, wherein, Hidden relationships are deduced through rule reasoning, and potential relationships are obtained through embedding reasoning, which further includes: In rule reasoning, hidden relationships are inferred from the basic knowledge graph according to predefined event chain formation rules. In embedding reasoning, TransE model is used to map entities and relationships in the basic knowledge graph to low-dimensional vector space, and vector representations of entities and relationships are trained through vector operations. For real-time triples, if the distance between the sum of the head entity vector and the relationship vector and the tail entity vector is less than a preset distance threshold, it is determined that there is a potential relationship between the head entity and the tail entity.

8. The cyber security situation awareness method of claim 7, wherein, According to the security situation knowledge graph, threat data is extracted and combined with graph neural network GAT to optimize the threat data to obtain the final network attack threat value, which further includes: The comprehensive harm degree and the attack influence range are obtained from the security situation knowledge graph. The vector representations of entities and relationships in the security situation knowledge graph are input into the graph attention network. For the attack behavior in the security situation knowledge graph and the associated network assets, the attention weight of the attack behavior on the network assets is calculated, wherein the attention weight is calculated via an attention mechanism including vector splicing, linear transformation and activation function, and is normalized for all network asset nodes; The information of the network asset nodes associated with the attack behavior is aggregated by the graph attention network to obtain an enhanced feature vector of the attack behavior; In combination with the comprehensive harm degree, the attack influence range and the enhanced feature vector, a final network attack threat value is obtained through an activation function mapping.

9. The cyber security situation awareness method of claim 8, wherein, The comprehensive harm degree and the attack influence range are obtained, further comprising: For the attack behavior in the security situation knowledge graph, if it is a vulnerability exploitation type attack, the Common Vulnerability Scoring System (CVSS) is used to score and obtain the harm degree through normalization processing; If it is a non-vulnerability exploitation type attack, the harm degree is predefined according to the historical attack harm degree; the comprehensive harm degree is composed of the harm degree obtained by processing and the predefined harm degree; The sum of the number of network assets directly affected by the attack behavior and the number of network assets indirectly affected is counted, and then compared with the total number of network assets to obtain the attack influence range.

10. A cyber security situation awareness system characterized by, It comprises: A log acquisition module configured to respond to collected multi-source heterogeneous logs and perform standardized analysis to obtain log event data; A data analysis module configured to use a dynamic baseline correlation engine to perform real-time analysis based on the log event data to obtain log correlation alarm data, wherein the dynamic baseline correlation engine distinguishes abnormal events by obtaining the dynamic baseline of event types in the log sample sequence, and quantifies the correlation of abnormal events, quantifies event correlation by fusing conditional probability and time decay correlation function, judges whether an event chain is formed, matches the formed event chain with an attack chain template to generate the log correlation alarm data, and the attack chain template is based on the MITRE ATT&CK framework and is obtained by combining actual attack event chains in history; A rule reasoning module configured to parse triples from the log correlation alarm data, build a basic knowledge graph based on the triples and perform rule reasoning and embedding reasoning, and integrate the reasoning results to form a situation-enhanced security situation knowledge graph; A situation awareness module configured to extract threat data from the security situation knowledge graph and optimize the threat data to obtain a final network attack threat value by combining a graph neural network (GAT), and perform network security situation awareness based on the network attack threat value, wherein the threat data includes a comprehensive harm degree and an attack influence range.

Citation Information

Patent Citations

  • Network security comprehensive analysis and situation awareness platform

    CN115941317A

  • Internet situation assessment method based on knowledge graph

    CN117692198A

  • Network attack link tracking and threat situation reasoning method based on knowledge graph

    CN119544327A

  • Network security big data state evaluation method based on pattern recognition

    CN120301637A

  • Risk monitoring method based on intelligent association and global situation of multi-source data

    CN120675823A

Cited By

  • Network security situation awareness method and system based on deep learning

    CN121356921A

  • Intelligent unknown threat determination method and system based on multi-modal knowledge graph

    CN121547292A