Situational awareness method, device, equipment and storage medium based on Bayesian network
By dividing the system into multiple microservices, grouping the historical data and attribute fields of each microservice, forming a target Bayesian network model, solving the problem of zero-trust situational awareness of large resource consumption in the existing technology, and real-time adaptive assessment and situational awareness of user risks under smaller resource consumption.
Patent Information
- Application Number
- CN202111400851.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-24
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2041-11-24
AI Technical Summary
The existing Bayesian network model is difficult to achieve real-time adaptive assessment of user risks under the premise of small resource consumption in zero-trust situation awareness. If all the user's attribute values are used as nodes, the model is too complex, and if the microservices are used as nodes, the model is too simple and cannot meet the real-time adaptive assessment requirements.
The system is divided into multiple microservices, and data performance analysis is performed for each microservice's preset historical data and related attribute fields, the target group attribute fields and their intervals are determined, and the historical Bayesian network model is updated with these intervals as nodes to form a target Bayesian network model for zero trust situation awareness.
With smaller resource consumption, the adaptation of the number of Bayesian network model nodes is achieved, which meets the real-time adaptive assessment of user risks in zero trust, and improves the efficiency and accuracy of network security situation awareness.
Smart Images

Figure CN114117447B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present invention relate to the field of computer technology, and in particular to a situational awareness method, apparatus, device, and storage medium based on a Bayesian network. Background Art
[0002] Zero trust represents a new generation of network security protection concept. It can be understood as a method of risk assessment in network security that uses dynamic risk determination methods instead of machine topology relationships (such as firewall software).
[0003] When using the situation awareness method to implement the zero trust standard, it is sometimes necessary to use a Bayesian network model. When using the Bayesian network model, it is necessary to determine the nodes of the network. On the one hand, if all the attribute values of the user are used as the nodes of the Bayesian network, the Bayesian network model is too complex. If it is necessary to meet the real-time adaptive assessment of all user risks in zero trust, it will consume a lot of resources; on the other hand, if microservices are used as nodes of the Bayesian network, the Bayesian network model is too simple and usually cannot meet the requirements of real-time adaptive assessment of all user risks in zero trust. Therefore, it is currently difficult to reasonably determine the nodes in the Bayesian network model so that the constructed Bayesian network model can be better applied to situation awareness under the zero trust standard. Summary of the Invention
[0004] The embodiments of the present invention provide a situation awareness method, apparatus, device and storage medium based on a Bayesian network, which can optimize the existing situation awareness solution based on a Bayesian network.
[0005] In a first aspect, an embodiment of the present invention provides a situation awareness method based on a Bayesian network, comprising:
[0006] For each microservice in the system, determine a target grouping attribute field based on preset historical data corresponding to the current microservice and data representation of related attribute fields, and determine at least two target grouping intervals corresponding to the target grouping attribute field;
[0007] Taking the target grouping intervals corresponding to all microservices in the system as target nodes, the historical Bayesian network model is updated to obtain a target Bayesian network model;
[0008] Zero-trust situational awareness is performed based on the target Bayesian network model.
[0009] In a second aspect, an embodiment of the present invention provides a situation awareness device based on a Bayesian network, comprising:
[0010] A grouping interval determination module is used to determine, for each microservice in the system, a target grouping attribute field based on preset historical data corresponding to the current microservice and data representations of related attribute fields, and to determine at least two target grouping intervals corresponding to the target grouping attribute field;
[0011] A historical model updating module is used to update the historical Bayesian network model with the target grouping intervals corresponding to all microservices in the system as target nodes to obtain a target Bayesian network model;
[0012] The target model application module is used to perform zero-trust situational awareness based on the target Bayesian network model.
[0013] In a third aspect, an embodiment of the present invention provides a computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, a situational awareness method based on a Bayesian network as provided in an embodiment of the present invention is implemented.
[0014] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a situational awareness method based on a Bayesian network as provided in an embodiment of the present invention.
[0015] The embodiment of the present invention provides a situational awareness solution based on a Bayesian network. First, for each microservice in the system, a target group attribute field is determined based on the preset historical data corresponding to the current microservice and the data performance of the relevant attribute field, and at least two target group intervals corresponding to the target group attribute field are determined; then, the target group intervals corresponding to all microservices in the system are used as target nodes to update the historical Bayesian network model to obtain a target Bayesian network model; finally, zero-trust situational awareness is performed based on the target Bayesian network model. The embodiment of the present invention adopts the above technical solution to divide the system into multiple microservices, and determines at least two corresponding target group intervals for the preset historical data and the data performance of the relevant attribute field in each microservice. By inputting the target group interval corresponding to each microservice as a target node into the historical Bayesian network model for updating, compared to inputting all the data generated by the system as the input node of the Bayesian network model, the number of Bayesian network model nodes can be adaptively adjusted to meet the real-time adaptive assessment of user risks in zero trust under the premise of relatively small resource consumption, thereby achieving the technical effect of achieving zero trust using a situational awareness method based on a Bayesian network. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 A schematic diagram of a process flow of a situation awareness method based on a Bayesian network provided by an embodiment of the present invention;
[0017] Figure 2 A schematic flow chart of another situation awareness method based on a Bayesian network provided in an embodiment of the present invention;
[0018] Figure 3 A structural block diagram of a situation awareness device based on a Bayesian network provided by an embodiment of the present invention;
[0019] Figure 4 This is a structural block diagram of a computer device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0020] The technical solution of the present invention will be further described below with reference to the accompanying drawings and through specific embodiments. It will be understood that the specific embodiments described herein are intended only to illustrate the present invention and are not intended to limit the present invention. It should also be noted that, for ease of description, the accompanying drawings only illustrate portions relevant to the present invention, not all of the structures.
[0021] Before discussing the exemplary embodiments in more detail, it should be mentioned that some exemplary embodiments are described as processes or methods depicted as flow charts. Although the flow charts describe the steps as sequential processes, many of the steps can be implemented in parallel, concurrently, or simultaneously. In addition, the order of the steps can be rearranged. The process can be terminated when its operation is completed, but can also have additional steps not included in the accompanying drawings. The process can correspond to a method, function, procedure, subroutine, subprogram, etc.
[0022] Example 1
[0023] Figure 1 The present invention provides a flow chart of a situational awareness method based on a Bayesian network. The method can be performed by a situational awareness device based on a Bayesian network, wherein the device can be implemented by software and / or hardware and can generally be integrated into a computer device such as a server. Figure 1 As shown, the method includes:
[0024] S101. For each microservice in the system, determine a target grouping attribute field according to preset historical data corresponding to the current microservice and data representations of related attribute fields, and determine at least two target grouping intervals corresponding to the target grouping attribute field.
[0025] The system can represent the architecture system of each enterprise, such as a bank risk control system, an enterprise employee login system, and a product sales system. In each system, each system can be divided into corresponding microservices based on its usage function or different user login nodes.
[0026] For example, a bank risk control system can be divided into a first microservice for management, a second microservice for risk assessment, and a third microservice for statistics, based on different functionalities. For example, a company employee login system can be divided into a first microservice for management, a second microservice for technology, and a third microservice for planning, based on each employee's department or position.
[0027] Correspondingly, a large amount of historical data about user access or user login can be generated in each microservice. If all the historical data contained in each microservice within a preset time period (for example, one day, one week, or one month) is analyzed to implement the zero trust standard based on the Bayesian network model using the situational awareness method, and all the user's attribute values are used as nodes of the Bayesian network, there will be too many nodes in the Bayesian network model, resulting in a complex model. When meeting the real-time adaptive assessment of all user risks in zero trust, a large amount of resources will be consumed. On the other hand, if each microservice itself is used as a Bayesian network node, the Bayesian network model will have fewer nodes and a larger data granularity, which is less able to meet the requirements of real-time adaptive assessment of all user risks in zero trust.
[0028] In order to solve the above problems, an embodiment of the present invention provides a situational awareness method based on a Bayesian network, which determines the target group attribute field by presetting historical data and the data performance of related attribute fields, so that data with the same or similar characteristics are merged, and the data in each microservice is classified. Therefore, under the premise of relatively small resource consumption, the number of nodes in the Bayesian network model is adaptively satisfied to meet the requirements of real-time adaptive assessment of all relevant risks in zero trust.
[0029] Specifically, the preset historical data may be data generated by accessing or logging into each microservice in the current system within a preset time period.
[0030] Among them, the relevant attribute field can be understood as a field corresponding to an attribute related to the microservice, which can be a field determined based on a keyword of preset historical data, or a storage field that has been divided in a database for storing preset historical data. It can include relevant user attributes or other attributes, for example, the user's Internet Protocol (IP) address, the type of data requested for access, the number of logins or accesses within a preset period, the number of preset requests initiated within a preset period, gender, age, hobbies, occupation, position, user level, and user rating, etc. It can also be the access time of the microservice, the access web page address (uniform resource locator, referred to as URL), access context, and other access parameters, etc., without limitation. Further, the relevant attribute field can be obtained by performing statistical analysis on the historical data. Generally, the determined relevant attribute field is the attribute field that has a greater impact on the current system.
[0031] For example, during the training phase or historical usage, a statistical analysis can be performed on the selection of relevant attribute fields, and the target grouping attribute fields can be determined based on the statistical analysis results. It should be noted that the target grouping attribute fields can be determined by selecting relevant attribute fields with a statistical quantity greater than a certain value among the relevant attribute fields as the target grouping attribute fields, or by selecting relevant attribute fields that rank in the top few in the statistical quantity order as the target grouping attribute fields, etc., without limitation herein.
[0032] Accordingly, determining at least two target grouping intervals corresponding to the target grouping attribute field based on the preset historical data corresponding to the current microservice and the data representation of the relevant attribute field can be understood as filtering the historical data corresponding to the relevant attribute field from the preset historical data, dividing the historical data into multiple target grouping intervals, and thus determining at least two target grouping intervals corresponding to the target grouping attribute field. When performing the division, for example, the division can be performed by grouping.
[0033] For example, taking the first microservice with management functions in the bank risk control system as an example, assuming that the data representation of the relevant attribute field is the number of logins within a preset time period, by grouping the number of logins, three grouping intervals can be obtained: (0, 1], (1, 4], and (5 or more).
[0034] It should be noted that the relevant attribute fields corresponding to each microservice may be different, and the data representation of its relevant attribute fields may also be different, so the at least two target grouping intervals determined are not necessarily the same. Therefore, after traversing all the microservices included in the system, multiple target grouping intervals corresponding to each microservice can be obtained in the entire system.
[0035] S102: Taking the target grouping intervals corresponding to all microservices in the system as target nodes, the historical Bayesian network model is updated to obtain a target Bayesian network model.
[0036] After step S101, the at least two target grouping intervals determined by each microservice are recorded as m. There may be a situation where the target grouping interval m of each microservice is different. When the target grouping intervals corresponding to all microservices in the system are used as target nodes, the total number of target nodes generated by the k microservices in the current system can be expressed as m1+m2+…+m k .
[0037] Each target node is input into the historical Bayesian network model and updated to obtain the target Bayesian model. Optionally, the historical Bayesian network model includes: the Bayesian network model obtained by the last update, or the Bayesian network model in the training phase.
[0038] S103. Zero-trust situational awareness based on the target Bayesian network model.
[0039] For example, the data generated by the current system in real time can be input into the target Bayesian network model, and zero-trust situational awareness can be performed based on the output results of the model. For example, it can be determined whether there are nodes or connections in the target Bayesian network model that trigger risks. If so, targeted processing can be carried out, such as risk warnings or alerts. If not, the Bayesian network model can be updated at an appropriate time.
[0040] Furthermore, the data generated in real time by the current system can be used as new historical data, and steps S101 and S102 can be repeated again to obtain the latest target Bayesian network model, thereby performing zero-trust situational awareness based on the latest target Bayesian network model.
[0041] By conducting zero-trust situational awareness based on the target Bayesian network model, the security level of the system network can be obtained for each day or each time period. By analyzing the trend of the network security situation, possible network security threats can be discovered in advance, thereby providing early warnings for network system managers, preventing the occurrence of network security incidents, and avoiding asset losses.
[0042] The situational awareness method based on Bayesian network provided in the embodiment of the present invention first determines the target group attribute field for each microservice in the system according to the preset historical data corresponding to the current microservice and the data performance of the relevant attribute field, and determines at least two target group intervals corresponding to the target group attribute field; then updates the historical Bayesian network model with the target group intervals corresponding to all microservices in the system as the target nodes to obtain the target Bayesian network model; finally, performs zero-trust situational awareness based on the target Bayesian network model. The embodiment of the present invention divides the system into multiple microservices by adopting the above technical solution, determines at least two corresponding target group intervals for the historical data and the data performance of the relevant attribute field in each microservice, and inputs the target group interval corresponding to each microservice as the target node into the historical Bayesian network model for updating. Compared with using all the data generated by the system as the input node of the Bayesian network model, the number of Bayesian network model nodes can be adaptively adjusted to meet the real-time adaptive assessment of user risk in zero trust under the premise of relatively small resource consumption, thereby achieving the technical effect of achieving zero trust using the situational awareness method based on Bayesian network.
[0043] Example 2
[0044] The present application is further optimized on the basis of the above-mentioned embodiment, and optimizes the steps of determining the target grouping attribute field according to the preset historical data corresponding to the current microservice and the data performance of the relevant attribute field, and determining at least two target grouping intervals corresponding to the target attribute field, including: obtaining the first historical data within the most recent preset time period corresponding to the current microservice; obtaining the sorting of the relevant attribute fields corresponding to the current microservice; grouping the first historical data according to the corresponding preset grouping method based on the current attribute field in turn according to the sorting of the relevant attribute fields, and obtaining at least two grouping intervals corresponding to the current attribute field. If the number of grouping intervals is within the preset number range, the corresponding current attribute field is determined as the target grouping attribute field, wherein the preset grouping method is determined according to the data performance of the corresponding historical data during the training phase; and the grouping interval corresponding to the target attribute field is determined as the target grouping interval. The advantage of such a setting is that by grouping historical data using a preset grouping method, data with the same or similar characteristics can be merged, reducing data input and simplifying model calculation.
[0045] Figure 2 A flow chart of another situation awareness method based on a Bayesian network provided in an embodiment of the present invention is provided. Specifically, the method includes the following steps:
[0046] S210: Obtain first historical data within a recent preset time period corresponding to the current microservice.
[0047] Since the data generated by the system will be updated in real time, the current data will also become historical data within the preset time period. Therefore, when using data within the preset time period to analyze the current microservice, the data generated by the system within the most recent time period (for example, 10 seconds) can be preferred as the first historical data for analysis.
[0048] S220. Obtain the order of related attribute fields corresponding to the current microservice.
[0049] According to the first historical data within the latest preset time period corresponding to the current microservice in S210, relevant attribute fields corresponding to the current microservice are obtained, and the obtained relevant attribute fields are sorted from large to small according to the cumulative number of times.
[0050] Optionally, the method for obtaining the order of the relevant attribute fields corresponding to the current microservice may be: obtaining the order of the relevant attribute fields corresponding to the current microservice obtained in the last update, or obtaining the order of the relevant attribute fields corresponding to the current microservice in the training phase.
[0051] Among them, obtaining the sorting of relevant attribute fields obtained from the last update corresponding to the current microservice can be understood as the data generated by the system will be updated in real time. Based on the relevant attribute fields obtained from the last update, the data generated from the latest update to the current time period can be statistically sorted.
[0052] Obtaining the sorting of relevant attribute fields in the training phase corresponding to the current microservice can be understood as requiring the model to be trained before different grouping intervals of relevant attribute fields are input as nodes into the model. Therefore, relevant attribute fields can be sorted in the training phase.
[0053] Specifically, the order of relevant attribute fields in the training phase is obtained in the following way:
[0054] a) Obtain the second historical data within a plurality of consecutive preset time periods corresponding to the current microservice.
[0055] The method for obtaining the second historical data within multiple consecutive preset time periods corresponding to the current microservice can be to obtain the historical data corresponding to the current microservice, and divide it based on the preset time period (such as t), so that the historical data corresponding to each microservice can be divided into multiple segments (slots), that is, the second historical data within multiple consecutive preset time periods is obtained.
[0056] It should be noted that when the current microservice is divided according to time t and the second historical data within multiple consecutive preset time periods is obtained, the time t can be 10 seconds or 30 seconds, and the selection of the specific time t is not limited here.
[0057] Exemplarily, the second historical data within a plurality of consecutive preset time periods may be divided into slot 1, slot 2, slot 3, ..., slot q for each microservice.
[0058] b) For each preset duration, the second historical data corresponding to the current preset duration is grouped in a preset grouping manner based on each attribute field, and the number of grouping intervals corresponding to each attribute field is obtained. The attribute field with the number of grouping intervals closest to the preset number is determined as the target field, and the cumulative number of times corresponding to the target field is increased by 1.
[0059] For each second historical data corresponding to a preset time length, the values of attribute fields with the same or similar characteristics are grouped according to a preset grouping method. That is, in each slot, the attribute fields corresponding to the historical data that are meaningful after investigation are grouped separately. The meaningful ones are the attribute fields corresponding to the data that have a greater impact on the system. First, a slot divided according to time t is selected. For the second historical data corresponding to the current slot, the relevant attribute fields can be determined based on the keywords of the second historical data, such as age, occupation, and position, and the corresponding number of grouping intervals can be obtained by grouping the values of the current relevant attribute fields.
[0060] Among them, the preset grouping method is determined according to the data performance of the second historical data. The grouping principles corresponding to the preset grouping method include the minimum number of members in each group and / or grouping error grouping. The preset grouping method includes supervised or unsupervised, and the grouping methods of different attribute fields can be different, which is not limited here.
[0061] In the embodiments of the present invention, the grouping method used is not limited. Each cluster obtained after grouping can correspond to a grouping interval. The grouping interval may be a numerical interval, such as a numerical interval of age or number of logins, or a specific attribute name, such as a specific name corresponding to a position, etc., without limitation. For example, for age, grouping intervals such as (0-18), (18-45), (45-60), and (above 60) may be obtained; for position, grouping intervals such as ordinary employee, team leader, manager, and director may be obtained.
[0062] When determining the number of grouping intervals corresponding to each relevant attribute field for each preset duration, the relevant attribute fields determined for each preset duration may be the same or different. Based on different relevant attribute fields, the number of grouping intervals determined is also different.
[0063] Furthermore, a preset number can be set in advance, and the preset number is used to represent the expected number of nodes corresponding to the current microservice. The specific value of the preset number is not limited, for example, it can be 5. The determination of the relevant attribute field whose grouping interval number is closest to the preset number as the target field can be understood as follows: for each preset time length, that is, each slot, before grouping, it can be planned to divide each slot into a preset number recorded as n, but in the actual division process, the number of grouping intervals corresponding to the actual relevant attribute field is recorded as m. In each slot, m and n may be the same or different. If m=n, the relevant attribute field corresponding to the grouping interval number n is determined as the target field; if m≠n, the relevant attribute field whose grouping interval number m is closest to the preset number n is determined as the target field.
[0064] A preferred method determines the relevant attribute field whose number of grouping intervals is closest to the preset number as the target field, including: if there are multiple candidate relevant attribute fields whose number of grouping intervals is closest to the preset number, randomly sampling is used to select a candidate relevant attribute field from the multiple candidate relevant attribute fields as the target field.
[0065] It can be understood that when the preset number is 5, and the number of grouping intervals corresponding to the first candidate related attribute field is 4, and the number of grouping intervals corresponding to the second candidate related attribute field is 4 or 6, then the first candidate related attribute field and the second candidate related attribute field are both close to the preset number of candidate related attribute fields. Therefore, any candidate related attribute field can be selected as the target field by random sampling.
[0066] The specific random sampling method is not limited here. The candidate related attribute field with a larger value can be selected as the target field, or the candidate related attribute field with a smaller value can be selected as the target field, or any one of them can be randomly selected.
[0067] Furthermore, in order to count the cumulative number of occurrences of the target field, the cumulative number of occurrences corresponding to the target field is counted and added by 1.
[0068] c) Determine the order of the relevant attribute fields in the training phase according to the final cumulative number of times each attribute field corresponds to.
[0069] The final cumulative number of times each attribute field corresponds to is the cumulative number of times the target field is obtained by statistics, so the target field is sorted according to the cumulative number of times it corresponds to determine the order of the relevant attribute fields in the training phase.
[0070] S230. Group the first historical data in a corresponding preset grouping method based on the current attribute field according to the sorting of related attribute fields to obtain at least two grouping intervals corresponding to the current attribute field. If the number of grouping intervals is within a preset number range, determine the corresponding current attribute field as the target grouping attribute field.
[0071] The preset grouping method is determined during the training phase based on the data performance of the corresponding historical data.
[0072] When grouping the first historical data according to the preset grouping method based on the current attribute field according to the order of the relevant attribute fields, the relevant attribute fields arranged in a preset order can be selected to group the first historical data, or a certain number of attribute fields can be selected according to the order of the relevant attribute fields to group the first historical data. The specific method is not limited here. Generally, the current attribute field is determined to meet the requirements in order from the highest cumulative number to the lowest cumulative number according to the order of the relevant attribute fields.
[0073] The process of grouping the first historical data according to the current attribute field is the same as the process of grouping the second historical data according to each attribute field. The process of determining the relevant attribute field is the same as the process of determining the target field, which will not be repeated here.
[0074] Optionally, the attribute field corresponding to the target field may be determined as the relevant attribute field.
[0075] The preset quantity range includes a preset quantity. For example, the lower limit of the preset quantity range may be the difference between the preset quantity and the preset value, and the upper limit of the preset quantity range may be the sum of the preset quantity and the preset value. For example, if the preset quantity is 5 and the preset value is 1, then the preset quantity range may be 4 to 6.
[0076] The purpose of determining whether the number of grouping intervals is within a preset range is to convert the large amount of uncontrollable data generated by the system into a manageable number of grouping intervals by analyzing the data of each microservice. The grouping intervals can then be used as input nodes for the Bayesian network model, reducing the number of model node inputs and simplifying calculations. For example, if the current system contains 1,000 pieces of data, analyzing all 1,000 pieces of data as nodes would result in a cumbersome model input data. Therefore, the current system can be divided into four microservices, each of which is planned to generate 25 grouping intervals. This reduces the 1,000 data inputs to inputs for nodes corresponding to 100 grouping intervals.
[0077] After determining the corresponding current attribute field as the target group attribute field, the method further includes: adding 1 to the cumulative number of times the target group attribute field appears in the related attribute field sorting, and updating the related attribute field sorting.
[0078] The number of times the relevant attribute field appears is counted, and after the cumulative number is increased by 1, if the original value of the relevant attribute field changes, the relevant attribute field sorting is updated. The purpose of this is to directly use the currently updated relevant attribute field sorting when the Bayesian network model is updated next time.
[0079] S240: Determine the grouping interval corresponding to the target grouping attribute field as the target grouping interval.
[0080] S250: Determine whether all microservices have determined the target grouping interval. If so, execute S260; if not, execute S210.
[0081] S260: Taking the target grouping intervals corresponding to all microservices in the system as target nodes, the historical Bayesian network model is updated to obtain a target Bayesian network model.
[0082] Through the above analysis, we can use the target grouping intervals corresponding to all microservices in the system as target nodes, and input the target nodes into the historical Bayesian network model for update, thereby obtaining the target Bayesian network model. The historical Bayesian network model includes: the Bayesian network model obtained in the last update, or the Bayesian network model in the training phase.
[0083] The Bayesian network model in the embodiments of the present invention can be updated based on a certain time period (e.g., every hour, half a day, or a day). For example, the target grouping interval of the Bayesian network model obtained from the last update of the system data generated within a day can be analyzed, and the historical Bayesian network model can be updated to obtain the target Bayesian network model. Alternatively, the Bayesian network model in the training phase can be directly applied to obtain the target Bayesian network model.
[0084] In a preferred embodiment, the Bayesian network model in the training phase is obtained in the following manner: for each microservice, the relevant attribute field ranked first in the sorting of relevant attribute fields corresponding to the current microservice is determined as the target grouping field, and all second historical data within multiple consecutive preset time lengths corresponding to the current microservice are grouped in a preset grouping manner based on the target grouping field to obtain the grouping interval corresponding to the target grouping field; with the grouping intervals corresponding to all microservices in the system as nodes, all second historical data are modeled using the Bayesian network to obtain the Bayesian network model in the training phase.
[0085] S270. Zero-trust situational awareness based on target Bayesian network model.
[0086] The situational awareness method based on the Bayesian network provided by the embodiment of the present invention determines the current attribute field as the target group attribute field by using a preset grouping method, and determines the group interval corresponding to the target group attribute field as the target group interval, thereby updating the historical Bayesian network model with the target group interval corresponding to all microservices in the system as the target node, so that under the premise of relatively small resource consumption, the number of nodes in the Bayesian network model adaptively meets the requirements of real-time adaptive assessment of all user risks in zero trust.
[0087] Example 3
[0088] Figure 3 This is a block diagram of a Bayesian network-based situational awareness device provided by an embodiment of the present invention. The device can be implemented by software and / or hardware and can generally be integrated into a computer device such as a server. It can perform situational awareness based on a Bayesian network by executing a situational awareness method based on a Bayesian network. Figure 3 As shown, the device includes: a grouping interval determination module 31, a historical model updating module 32 and a target model application module 33, wherein:
[0089] The grouping interval determination module 31 is used to determine, for each microservice in the system, a target grouping attribute field based on preset historical data corresponding to the current microservice and data representations of related attribute fields, and to determine at least two target grouping intervals corresponding to the target grouping attribute field;
[0090] A historical model updating module 32 is configured to update the historical Bayesian network model using the target grouping intervals corresponding to all microservices in the system as target nodes to obtain a target Bayesian network model;
[0091] The target model application module 33 is used to perform zero-trust situational awareness based on the target Bayesian network model.
[0092] The embodiment of the present invention provides a situational awareness device based on a Bayesian network. First, for each microservice in the system, a target group attribute field is determined based on the preset historical data corresponding to the current microservice and the data performance of the relevant attribute field, and at least two target group intervals corresponding to the target group attribute field are determined; then, the target group intervals corresponding to all microservices in the system are used as target nodes to update the historical Bayesian network model to obtain a target Bayesian network model; finally, zero-trust situational awareness is performed based on the target Bayesian network model. The embodiment of the present invention adopts the above technical solution to divide the system into multiple microservices, and determines at least two corresponding target group intervals for the preset historical data and the data performance of the relevant attribute field in each microservice. By inputting the target group interval corresponding to each microservice as a target node into the historical Bayesian network model for updating, compared to inputting all the data generated by the system as the input node of the Bayesian network model, the number of Bayesian network model nodes can be adaptively satisfied with the real-time adaptive assessment of user risk in zero trust under the premise of relatively small resource consumption, thereby achieving the technical effect of using the situational awareness method based on the Bayesian network to achieve zero trust.
[0093] Optionally, the grouping interval determination module 31 includes: a first historical data acquisition unit, an attribute field acquisition unit, a target attribute field determination unit, and a target grouping interval determination unit.
[0094] A first historical data acquisition unit is used to acquire first historical data within a recent preset time period corresponding to the current microservice;
[0095] An attribute field acquisition unit, configured to acquire the order of related attribute fields corresponding to the current microservice;
[0096] a target grouping attribute field determining unit, configured to group the first historical data using a preset grouping method based on the current attribute field in sequence according to the order of the relevant attribute fields, to obtain at least two grouping intervals corresponding to the current attribute field, and if the number of grouping intervals is within a preset number range, determine the corresponding current attribute field as the target grouping attribute field, wherein the preset grouping method is determined in a training phase based on data performance of the corresponding historical data;
[0097] The target grouping interval determining unit is configured to determine the grouping interval corresponding to the target grouping attribute field as the target grouping interval.
[0098] Optionally, the attribute fields in the related attribute field sorting are sorted from largest to smallest according to the cumulative number of times.
[0099] The grouping interval determination module 31 further includes: an attribute field updating unit;
[0100] an attribute field updating unit, configured to add 1 to the cumulative number of occurrences of the target group attribute field in the related attribute field sorting, and update the related attribute field sorting;
[0101] The attribute field acquisition unit is further used to obtain the order of relevant attribute fields obtained in the last update corresponding to the current microservice, or to obtain the order of relevant attribute fields in the training phase corresponding to the current microservice.
[0102] The historical Bayesian network model includes: the Bayesian network model obtained in the last update, or the Bayesian network model in the training phase.
[0103] Optionally, the grouping interval determination module 31 further includes: a second data acquisition unit, a target field determination unit and an attribute field determination unit, wherein;
[0104] A second data acquisition unit is used to acquire second historical data within a plurality of consecutive preset time periods corresponding to the current microservice;
[0105] a target field determination unit, configured to, for each preset duration, sequentially group the second historical data corresponding to the current preset duration using a preset grouping method based on each attribute field, obtain the number of grouping intervals corresponding to each attribute field, determine the attribute field having the number of grouping intervals closest to the preset number as the target field, and increment the cumulative number of times corresponding to the target field by 1, wherein the preset grouping method is determined based on data representation of the second historical data, the grouping principles corresponding to the preset grouping method include a minimum number of members per group and / or grouping error, and the preset grouping method includes supervised or unsupervised;
[0106] The attribute field determination unit is used to determine the order of the relevant attribute fields in the training phase according to the final cumulative number of times corresponding to each attribute field.
[0107] Optionally, the target field determination unit is further configured to select a candidate attribute field as the target field from the multiple candidate attribute fields by random sampling if there are multiple candidate attribute fields whose number of grouping intervals is closest to the preset number.
[0108] Optionally, the target grouping interval determination unit is further used to determine, for each microservice, the relevant attribute field that ranks first in the sorting of relevant attribute fields corresponding to the current microservice as the target grouping field, and group all the second historical data within the multiple consecutive preset time lengths corresponding to the current microservice in a preset grouping manner based on the target grouping field to obtain the grouping interval corresponding to the target grouping field; using the grouping intervals corresponding to all microservices in the system as nodes, use the Bayesian network to model all the second historical data to obtain the Bayesian network model in the training stage.
[0109] Optionally, the preset quantity range includes the preset quantity.
[0110] Example 4
[0111] An embodiment of the present invention provides a computer device, into which the situation awareness device based on the Bayesian network provided by the embodiment of the present invention can be integrated. Figure 4 This is a block diagram of a computer device according to an embodiment of the present invention. The computer device 400 may include a memory 401, a processor 402, and a computer program stored in the memory 401 and executable by the processor. When the processor 402 executes the computer program, it implements the Bayesian network-based situational awareness method according to an embodiment of the present invention.
[0112] The computer device provided by the embodiment of the present invention can execute the situation awareness method based on the Bayesian network provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.
[0113] Example 5
[0114] An embodiment of the present invention further provides a storage medium containing computer-executable instructions, wherein the computer-executable instructions, when executed by a computer processor, are used to perform a situational awareness method based on a Bayesian network, the method comprising:
[0115] For each microservice in the system, determine a target grouping attribute field based on preset historical data corresponding to the current microservice and data representation of related attribute fields, and determine at least two target grouping intervals corresponding to the target grouping attribute field;
[0116] Taking the target grouping intervals corresponding to all microservices in the system as target nodes, the historical Bayesian network model is updated to obtain a target Bayesian network model;
[0117] Zero-trust situational awareness is performed based on the target Bayesian network model.
[0118] Storage medium - any of various types of memory devices or storage devices. The term "storage medium" is intended to include: installation media, such as CD-ROMs, floppy disks, or tape drives; computer system memory or random access memory, such as DRAM, DDRRAM, SRAM, EDORAM, Rambus RAM, etc.; non-volatile memory, such as flash memory, magnetic media (such as hard disks or optical storage); registers or other similar types of memory elements, etc. Storage media may also include other types of memory or combinations thereof. In addition, the storage medium may be located in the first computer system in which the program is executed, or may be located in a different second computer system that is connected to the first computer system via a network (such as the Internet). The second computer system can provide program instructions to the first computer for execution. The term "storage medium" may include two or more storage media that can reside in different locations (e.g., in different computer systems connected via a network). The storage medium can store program instructions (e.g., embodied as a computer program) that can be executed by one or more processors.
[0119] Of course, the storage medium containing computer-executable instructions provided in an embodiment of the present invention is not limited to the situational awareness operations based on the Bayesian network as described above, and can also execute related operations in the situational awareness method based on the Bayesian network provided in any embodiment of the present invention.
[0120] The Bayesian network-based situational awareness apparatus, device, and storage medium provided in the above embodiments can execute the Bayesian network-based situational awareness method provided in any embodiment of the present invention, and have the corresponding functional modules and beneficial effects of executing the method. For technical details not fully described in the above embodiments, please refer to the Bayesian network-based situational awareness method provided in any embodiment of the present invention.
[0121] Note that the above are only preferred embodiments of the present invention and the technical principles employed. Those skilled in the art will understand that the present invention is not limited to the specific embodiments described herein, and that various obvious changes, readjustments, and substitutions can be made by those skilled in the art without departing from the scope of protection of the present invention. Therefore, although the present invention has been described in detail through the above embodiments, the present invention is not limited to the above embodiments and may include many other equivalent embodiments without departing from the concept of the present invention. The scope of the present invention is determined by the scope of the appended claims.
Claims
1. A situation awareness method based on Bayesian network, characterized in that: include: For each microservice in the system, determine a target grouping attribute field based on preset historical data corresponding to the current microservice and data representation of related attribute fields, and determine at least two target grouping intervals corresponding to the target grouping attribute field; Taking the target grouping intervals corresponding to all microservices in the system as target nodes, the historical Bayesian network model is updated to obtain a target Bayesian network model; Perform zero-trust situational awareness based on the target Bayesian network model; The step of determining the target group attribute field based on the preset historical data corresponding to the current microservice and the data representation of the relevant attribute field, and determining at least two target group intervals corresponding to the target group attribute field, includes: Get the first historical data within the most recent preset time period corresponding to the current microservice; Obtaining a ranking of related attribute fields corresponding to the current microservice; wherein each attribute field in the ranking of related attribute fields is sorted from largest to smallest according to the cumulative number of occurrences; Grouping the first historical data according to a preset grouping method based on the current attribute field in sequence according to the order of the relevant attribute fields to obtain at least two grouping intervals corresponding to the current attribute field; if the number of grouping intervals is within a preset number range, determining the corresponding current attribute field as a target grouping attribute field, wherein the preset grouping method is determined according to data performance of the corresponding historical data during the training phase; The grouping interval corresponding to the target grouping attribute field is determined as the target grouping interval.
2. The method according to claim 1, characterized in that After determining the corresponding current attribute field as the target group attribute field, the method further includes: Add 1 to the cumulative number of times the target group attribute field is ranked in the relevant attribute field ranking, and update the relevant attribute field ranking; The step of obtaining the order of the relevant attribute fields corresponding to the current microservice includes: Obtain the order of the relevant attribute fields obtained in the last update corresponding to the current microservice, or obtain the order of the relevant attribute fields in the training phase corresponding to the current microservice; Wherein, the historical Bayesian network model includes: The Bayesian network model obtained in the last update, or the Bayesian network model in the training phase.
3. The method according to claim 2, characterized in that The ordering of the relevant attribute fields in the training phase is obtained in the following way: Obtain the second historical data within a plurality of consecutive preset time periods corresponding to the current microservice; For each preset duration, the second historical data corresponding to the current preset duration is grouped using a preset grouping method based on each attribute field, and the number of grouping intervals corresponding to each attribute field is obtained. The attribute field with the number of grouping intervals closest to the preset number is determined as the target field, and the cumulative number of times corresponding to the target field is increased by 1. The preset grouping method is determined based on the data performance of the second historical data, and the grouping principles corresponding to the preset grouping method include a minimum number of members per group and / or grouping error grouping. The preset grouping method includes supervised or unsupervised. The order of the relevant attribute fields in the training phase is determined according to the final cumulative number of times each attribute field corresponds to.
4. The method according to claim 3, characterized in that The step of determining the attribute field whose number of grouping intervals is closest to the preset number as the target field includes: If there are multiple candidate attribute fields whose number of grouping intervals is closest to the preset number, a candidate attribute field is selected from the multiple candidate attribute fields as the target field by random sampling.
5. The method according to claim 3, characterized in that The Bayesian network model in the training phase is obtained by: For each microservice, the related attribute field ranked first in the sorting of related attribute fields corresponding to the current microservice is determined as the target grouping field, and all second historical data within the plurality of consecutive preset time periods corresponding to the current microservice are grouped in a preset grouping manner based on the target grouping field to obtain a grouping interval corresponding to the target grouping field; Taking the grouping intervals corresponding to all microservices in the system as nodes, all the second historical data are modeled using a Bayesian network to obtain a Bayesian network model in the training phase.
6. The method according to claim 3, characterized in that The preset quantity range includes the preset quantity.
7. A situation awareness device based on Bayesian network, characterized in that: include: A grouping interval determination module is used to determine, for each microservice in the system, a target grouping attribute field based on preset historical data corresponding to the current microservice and data representations of related attribute fields, and to determine at least two target grouping intervals corresponding to the target grouping attribute field; A historical model updating module is used to update the historical Bayesian network model with the target grouping intervals corresponding to all microservices in the system as target nodes to obtain a target Bayesian network model; A target model application module, configured to perform zero-trust situational awareness based on the target Bayesian network model; The grouping interval determination module includes: a first historical data acquisition unit, an attribute field acquisition unit, a target attribute field determination unit, and a target grouping interval determination unit, wherein: A first historical data acquisition unit is used to acquire first historical data within a recent preset time period corresponding to the current microservice; An attribute field acquisition unit is used to acquire a related attribute field ranking corresponding to the current microservice; wherein each attribute field in the related attribute field ranking is sorted from largest to smallest according to the cumulative number of times; a target grouping attribute field determining unit, configured to group the first historical data using a preset grouping method based on the current attribute field in sequence according to the order of the relevant attribute fields, to obtain at least two grouping intervals corresponding to the current attribute field, and if the number of grouping intervals is within a preset number range, determine the corresponding current attribute field as the target grouping attribute field, wherein the preset grouping method is determined in a training phase based on data performance of the corresponding historical data; The target grouping interval determining unit is configured to determine the grouping interval corresponding to the target grouping attribute field as the target grouping interval.
8. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 6 is implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Service fault high-response matching method based on MIDS-Tree
CN112488181A