A network security situation awareness method, system, storage medium and electronic device
By generating the target matrix and analyzing network security data using the network security situation awareness model, combining sentiment analysis and log file analysis, data omission and subjectivity problems in network security situation awareness in the prior art are solved, and the accuracy of the analysis is improved.
Patent Information
- Application Number
- CN202210266764.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-17
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2042-03-17
AI Technical Summary
The prior art is prone to missing security data in network security situation awareness, reducing the accuracy of analysis, and affecting the accuracy of analysis due to the subjectivity of manual analysis.
By generating the target matrix, using the trained network security situation awareness model, the network security situation data of each preset node of the evaluation network is analyzed, the network security situation awareness results are obtained, and the results are further corrected through sentiment analysis and log file analysis.
It improves the accuracy of network security situation awareness results, avoids data omissions and subjectivity of manual analysis, and ensures a more complete and accurate analysis of network security situations.
Smart Images

Figure CN114710327B_ABST
Abstract
Description
Background Art
[0002] With the development of technology, the number of various devices in the network has increased sharply, and various security threats and attacks from both external and internal sources have also increased significantly, seriously threatening network security. The current methods for perceiving network security situation are as follows:
[0003] First, a large amount of security data is collected, and then, through the experience of engineers, the large amount of security data is analyzed, that is, the traditional manual analysis method is still used. However, using this manual analysis method often misses some security data, reduces the accuracy of the analysis of the security situation, and because manual analysis is subjective, to a certain extent, it also affects the accuracy of the analysis of the security situation. Summary of the Invention
[0004] The technical problem to be solved by the present invention is to provide a network security situation perception method, system, storage medium and electronic device in view of the deficiencies of the prior art.
[0005] The technical solution of a network security situation perception method of the present invention is as follows:
[0006] Generate a target matrix according to the network security situation data of each preset node of the network to be evaluated;
[0007] Input the target matrix into the trained network security situation perception model to obtain the network security situation perception result of the network to be evaluated.
[0008] The beneficial effects of a network security situation perception method of the present invention are as follows:
[0009] On the one hand, network security situation data will not be missed, the analysis of the security situation is more complete, and the accuracy of the network security situation perception result is improved. On the other hand, the subjectivity brought by manual analysis is avoided, and the accuracy of the network security situation perception result is further improved.
[0010] On the basis of the above solution, a network security situation perception method of the present invention can also be improved as follows.
[0011] Further, it further includes:
[0012] Collect and perform sentiment analysis on each evaluation statement of the network to be evaluated to determine the security sentiment tendency of each evaluation statement towards the network to be evaluated;
[0013] Correct the network security situation perception result according to all security sentiment tendencies.
[0014] The beneficial effects of adopting the above further solution are as follows: Through sentiment analysis, the results of network security situation awareness are corrected, further improving the accuracy of the results of network security situation awareness.
[0015] Further, it further includes:
[0016] According to the log files of each preset node, all associated clients of the abnormal client are determined. According to the data interaction frequency between every two associated clients, target clients are screened out from all associated clients, and the abnormal client and the clients corresponding to each layer of the abnormal client are determined as a risk gang.
[0017] The beneficial effects of adopting the above further solution are as follows: The risk gang can be determined through the log files, facilitating subsequent processing.
[0018] Further, the process of generating the target matrix includes:
[0019] According to the network security situation data of each preset node of the network to be evaluated, an initial matrix corresponding to each preset node is generated, and the target matrix is generated based on all the initial matrices.
[0020] Further, the network security situation data includes: abnormal event situation data, security vulnerability situation data, data inflow volume, and anti-attack ability level.
[0021] The technical solution of a network security situation awareness system of the present invention is as follows:
[0022] It includes a generation module and a determination module;
[0023] The generation module is used for: generating a target matrix according to the network security situation data of each preset node of the network to be evaluated;
[0024] The determination module is used for: inputting the target matrix into a trained network security situation awareness model to obtain the network security situation awareness result of the network to be evaluated.
[0025] The beneficial effects of a network security situation awareness system of the present invention are as follows:
[0026] On the one hand, the network security situation data will not be missed, the analysis of the security situation is more complete, improving the accuracy of the results of network security situation awareness. On the other hand, the subjectivity brought by manual analysis is avoided, further improving the accuracy of the results of network security situation awareness.
[0027] On the basis of the above solution, a network security situation awareness system of the present invention can also be improved as follows.
[0028] Further, it further includes a correction module, and the correction module is used for:
[0029] Collect and perform sentiment analysis on each evaluation statement of the network to be evaluated, and determine the security sentiment tendency of each evaluation statement towards the network to be evaluated;
[0030] Modify the network security situation awareness result according to all security sentiment tendencies.
[0031] The beneficial effect of adopting the above further solution is that through sentiment analysis, the network security situation awareness result is modified, and the accuracy of the network security situation awareness result is further improved.
[0032] Furthermore, it further includes a risk group determination module, and the risk group determination module is used for:
[0033] According to the log files of each preset node, determine all associated clients of the abnormal client, and screen out target clients from all associated clients according to the data interaction frequency between every two associated clients, and determine the abnormal client and all target clients as a risk group.
[0034] The beneficial effect of adopting the above further solution is that the risk group can be determined through the log files, which is convenient for subsequent processing.
[0035] Furthermore, the generation module is specifically used for:
[0036] Generate an initial matrix corresponding to each preset node according to the network security situation data of each preset node of the network to be evaluated, and generate the target matrix according to all the initial matrices.
[0037] Furthermore, the network security situation data includes: abnormal event situation data, security vulnerability situation data, data inflow volume, and anti-attack ability level.
[0038] A storage medium of the present invention stores instructions, and when a computer reads the instructions, the computer executes a network security situation awareness method as described in any one of the above.
[0039] An electronic device of the present invention includes a processor and a storage medium, and the processor executes the instructions in the storage medium. Description of the Drawings
[0040] Figure 1 It is a flowchart of a network security situation awareness method according to an embodiment of the present invention;
[0041] Figure 2 It is a structural diagram of a network security situation awareness method according to an embodiment of the present invention. Detailed Embodiments
[0042] As Figure 1 shown, a network security situation awareness method according to an embodiment of the present invention includes the following steps:
[0043] S1. Generate a target matrix according to the network security situation data of each preset node of the network to be evaluated;
[0044] Among them, a node refers to an entity component or a virtual component applied to the network to be evaluated. The entity component may specifically be: a server, a computer, a switch, a gateway, a memory, a router, etc., and the virtual component may specifically be: a database, a cloud platform, a cloud memory, etc.
[0045] Among them, the network security situation data includes: abnormal event situation data, security vulnerability situation data, data inflow volume, and anti-attack ability level.
[0046] Among them, the process of generating the target matrix includes:
[0047] Generate an initial matrix corresponding to each preset node according to the network security situation data of each preset node of the network to be evaluated, and generate the target matrix according to all the initial matrices. Specifically:
[0048] 1) The specific form of the initial matrix can be set according to the actual situation. For example, the initial matrix is a matrix with 1 row and multiple columns. Since the network security situation data includes: abnormal event situation data, security vulnerability situation data, data inflow volume per unit time, and anti-attack ability level, at this time, the initial matrix is specifically a matrix with 1 row and 4 columns, or the initial matrix can also be set as a matrix with 2 rows and 2 columns, etc.;
[0049] 2) The abnormal event situation data includes the abnormal event type and the abnormal event occurrence frequency; the security vulnerability situation data includes: the vulnerability type, the vulnerability level, the vulnerability impact range, and the vulnerability occurrence frequency; the evaluation criterion for the data inflow volume per unit time is: as the data inflow volume per unit time increases, the security evaluation level decreases. The anti-attack ability level can be determined by a multi-agent system network anti-attack ability evaluation method based on representation learning, a network behavior attack method based on FPGA, or a scale-free network attack method based on random neighbor nodes, or the anti-attack ability level of each preset node can also be determined by other existing technologies;
[0050] The standard can be set manually to quantify each abnormal event situation data, security vulnerability situation data, data inflow volume per unit time, and anti-attack ability level to obtain the initial matrix, and then arrange all the initial matrices in a preset order, such as the order of the preset nodes, to generate the target matrix.
[0051] Collect in advance multiple groups of network security data of each preset node, namely, abnormal event data, security vulnerability data, data inflow per unit time and anti-attack capability level; quantify the network security data of each preset node in each group, namely, abnormal event data, security vulnerability data, data inflow per unit time and anti-attack capability level according to the same artificially set standards mentioned above; generate a matrix corresponding to each preset node in the specific form of the initial matrix mentioned above; then arrange the matrices corresponding to each preset node in the preset order mentioned above to generate a standard matrix corresponding to the group of data; and have multiple experts verify the comprehensive weight value corresponding to the standard matrix and the network security situation awareness result corresponding to the comprehensive weight value until multiple standard matrices, a comprehensive weight value corresponding to each standard matrix and a network security situation awareness result corresponding to each comprehensive weight value are obtained.
[0052] The standard matrix is used as the input of the neural network, and the comprehensive weight value is used as the output of the neural network. The model is trained based on the neural network to obtain a trained network security situation awareness model. It can also be trained based on other learning models to obtain a trained network security situation awareness model.
[0053] S2. Input the target matrix into the trained network security situation awareness model to obtain the network security situation awareness result of the network to be evaluated.
[0054] Among them, the network security situation awareness results are: level 1 security level, level 2 security level, level 3 security level and other levels of security level, among which level 1 security level is the highest security level, and other security levels are analogous. For example, the network security situation awareness result corresponding to the comprehensive weight value of 10 is level 1 security level, the network security situation awareness result corresponding to the comprehensive weight value of 9 to 10 is level 2 security level, the network security situation awareness result corresponding to the comprehensive weight value of 8 to 9 is level 2 security level, etc., then:
[0055] For example, when the target matrix is input into the trained network security situation awareness model, the calculated comprehensive weight value is 8.5, and the network security situation awareness result is the second-level security level. For example, when the target matrix is input into the trained network security situation awareness model, the calculated comprehensive weight value is 7.5, and the network security situation awareness result is the third-level security level.
[0056] On the one hand, network security data will not be missed, the analysis of the security situation will be more complete, and the accuracy of the network security situation awareness results will be improved. On the other hand, the subjectivity brought by manual analysis will be avoided, further improving the accuracy of the network security situation awareness results.
[0057] Optionally, in the above technical solution, it also includes:
[0058] Collect and perform sentiment analysis on each evaluation statement of the network to be evaluated, and determine the security sentiment tendency of each evaluation statement towards the network to be evaluated;
[0059] Modify the network security situation awareness result according to all the security sentiment tendencies. Specifically:
[0060] First, process each evaluation statement collected for the network to be evaluated using a security thesaurus to confirm whether each evaluation statement contains words in the security thesaurus. The security thesaurus is a collection of words about network security collected manually, such as words like "network security", "vulnerability", "network attack", etc. Then, select all the evaluation statements that contain at least one word in the security thesaurus. Then, through semantic analysis, determine the security sentiment tendency of each selected evaluation statement towards the network to be evaluated. The security sentiment tendency is divided into five levels: considering the security situation of the network to be evaluated as excellent, good, medium, passing, and failing. Then:
[0061] 1) For example, if more than 60% of the security sentiment tendencies of all the selected evaluation statements are failing, then downgrade the network security situation awareness result by one level. For example, if the network security situation awareness result of the network to be evaluated obtained from the target matrix is at the first-level security level, then downgrade the network security situation awareness result by one level, that is, the network security situation awareness result of the network to be evaluated is at the second-level security level.
[0062] 2) For example, if more than 80% of the security sentiment tendencies of all the selected evaluation statements are excellent, then upgrade the network security situation awareness result by one level. For example, if the network security situation awareness result of the network to be evaluated obtained from the target matrix is at the third-level security level, then upgrade the network security situation awareness result by one level, that is, the network security situation awareness result of the network to be evaluated is at the second-level security level.
[0063] Alternatively, different judgment criteria can also be set according to the actual situation, which will not be elaborated here. By performing sentiment analysis to modify the network security situation awareness result, the accuracy of the network security situation awareness result can be further improved.
[0064] Optionally, in the above technical solution, it further includes:
[0065] Determine all associated clients of the abnormal client according to the log files of each preset node, where any log file is a record file or a set of files recording the operation events of the preset node, and through the record file, it is possible to determine whether there is data interaction between each client. Among them, the client with bad behaviors such as fraud records or unreturned resources is determined as an abnormal client. Specifically, it is possible to identify whether there is a fraud record or an unreturned fund record through the historical data of the client. If so, it is regarded as an abnormal client.
[0066] Among them, the process of determining all associated clients of the abnormal client includes:
[0067] If there is at least one data interaction between the abnormal client and the first client, then the first client is an associated client of the abnormal client. Thus, all associated clients of the abnormal client are selected from all the clients involved in the log files of each preset node. The client can be a mobile phone number, a telephone number, a QQ number, a WeChat number, an email address, etc.
[0068] After all associated clients of the abnormal client are selected, according to the data interaction frequency between every two associated clients, target clients are screened out from all the associated clients. The data interaction frequency between every two target clients among all the selected target clients is greater than a preset data interaction frequency threshold. The preset data interaction frequency threshold can be 100 times per day, etc., and can be adjusted according to the actual situation. Since there is a lot of data interaction between the abnormal client and every two clients among all the target clients, it means that the relationship between the abnormal client and every two clients among all the target clients is close, and the risk of gang crime is relatively high. Therefore, the abnormal client and all the target clients are determined as a risk gang for subsequent processing.
[0069] In the above embodiments, although the steps are numbered S1, S2, etc., they are only specific embodiments given in this application. Those skilled in the art can adjust the execution order of S1, S2, etc. according to the actual situation, and this is also within the protection scope of the present invention. It can be understood that in some embodiments, it may include some or all of the above embodiments.
[0070] As Figure 2 shown, a network security situation awareness system 200 according to an embodiment of the present invention includes a generation module 210 and a determination module 220;
[0071] The generation module 210 is used for: generating a target matrix according to the network security situation data of each preset node of the network to be evaluated;
[0072] The determining module 220 is configured to: input the target matrix into a trained network security situation awareness model to obtain the network security situation awareness result of the network to be evaluated.
[0073] On the one hand, it will not miss network security situation data, and the analysis of the security situation is more complete, improving the accuracy of the network security situation awareness result. On the other hand, it avoids the subjectivity brought by manual analysis and further improves the accuracy of the network security situation awareness result.
[0074] Optionally, in the above technical solution, it further includes a correction module, and the correction module is configured to:
[0075] Collect and perform sentiment analysis on each evaluation statement of the network to be evaluated to determine the security sentiment tendency of each evaluation statement towards the network to be evaluated;
[0076] Correct the network security situation awareness result according to all security sentiment tendencies.
[0077] By performing sentiment analysis to correct the network security situation awareness result, the accuracy of the network security situation awareness result is further improved.
[0078] Optionally, in the above technical solution, it further includes a risk gang determination module, and the risk gang determination module is configured to:
[0079] According to the log files of each preset node, determine all associated clients of the abnormal client, screen out the target clients from all associated clients according to the data interaction frequency between every two associated clients, and determine the abnormal client and all target clients as a risk gang.
[0080] Optionally, in the above technical solution, the generating module 210 is specifically configured to:
[0081] Generate an initial matrix corresponding to each preset node according to the network security situation data of each preset node of the network to be evaluated, and generate the target matrix according to all the initial matrices.
[0082] Optionally, in the above technical solution, the network security situation data includes: abnormal event situation data, security vulnerability situation data, data inflow volume, and anti-attack ability level.
[0083] For the parameters and the steps for each unit module in the above-mentioned network security situation awareness system 200 of the present invention to implement corresponding functions, reference can be made to the parameters and steps in the embodiments of the above-mentioned network security situation awareness method, which will not be elaborated here.
[0084] A storage medium according to an embodiment of the present invention stores instructions that, when read by a computer, cause the computer to execute a network security situation awareness method as described in any one of the above.
[0085] An electronic device according to an embodiment of the present invention includes a processor and the above storage medium, and the processor executes the instructions in the storage medium. Among them, the electronic device can be a computer, a mobile phone, etc.
[0086] Those skilled in the art of the present technology know that the present invention can be implemented as a system, a method, or a computer program product.
[0087] Therefore, the present disclosure can be specifically implemented in the following forms: it can be completely hardware, can also be completely software (including firmware, resident software, microcode, etc.), or can also be a combination of hardware and software, generally referred to as "circuit", "module" or "system" in this article. In addition, in some embodiments, the present invention can also be implemented in the form of a computer program product in one or more computer-readable media, and the computer-readable media contains computer-readable program code.
[0088] Any combination of one or more computer-readable media can be adopted. The computer-readable media can be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0089] Although the embodiments of the present invention have been shown and described above, it can be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those of ordinary skill in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention.
Claims
1. A network security situation awareness method, characterized in that, it includes: generating a target matrix according to the network security situation data of each preset node of the network to be evaluated; inputting the target matrix into a trained network security situation awareness model to obtain the network security situation awareness result of the network to be evaluated; the network security situation data includes: abnormal event situation data, security vulnerability situation data, data inflow volume, and anti-attack ability level; artificially setting criteria to quantify each abnormal event situation data, security vulnerability situation data, data inflow volume per unit time, and anti-attack ability level to obtain an initial matrix, and then arranging all the initial matrices in a preset order to generate the target matrix; collecting and performing sentiment analysis on each evaluation statement of the network to be evaluated to determine the security sentiment tendency of each evaluation statement towards the network to be evaluated; correcting the network security situation awareness result according to all the security sentiment tendencies.
2. The network security situation awareness method according to claim 1, characterized in that, it further includes: determining all associated clients of the abnormal client according to the log file of each preset node, screening out target clients from all the associated clients according to the data interaction frequency between every two associated clients, and determining the abnormal client and all the target clients as a risk gang.
3. The network security situation awareness method according to claim 1, characterized in that, the network security situation data includes: abnormal event situation data, security vulnerability situation data, data inflow volume, and anti-attack ability level.
4. A network security situation awareness system, characterized in that, it includes a generation module and a determination module; the generation module is used for: generating a target matrix according to the network security situation data of each preset node of the network to be evaluated; the determination module is used for: inputting the target matrix into a trained network security situation awareness model to obtain the network security situation awareness result of the network to be evaluated; the network security situation data includes: abnormal event situation data, security vulnerability situation data, data inflow volume, and anti-attack ability level; artificially setting criteria to quantify each abnormal event situation data, security vulnerability situation data, data inflow volume per unit time, and anti-attack ability level to obtain an initial matrix, and then arranging all the initial matrices in a preset order to generate the target matrix; it further includes a correction module, and the correction module is used for: collecting and performing sentiment analysis on each evaluation statement of the network to be evaluated to determine the security sentiment tendency of each evaluation statement towards the network to be evaluated; correcting the network security situation awareness result according to all the security sentiment tendencies.
5. The network security situation awareness system according to claim 4, characterized in that, it further includes a risk gang determination module, and the risk gang determination module is used for: Determine all associated clients of the abnormal client according to the log files of each preset node, screen out the target clients from all the associated clients according to the data interaction frequency between every two associated clients, and determine the abnormal client and all the target clients as a risk group.
6. A storage medium, characterized in that, instructions are stored in the storage medium, and when a computer reads the instructions, the computer is caused to execute a network security situation awareness method according to any one of claims 1 to 3.
7. An electronic device, characterized in that, it includes a processor and the storage medium according to claim 6, and the processor executes the instructions in the storage medium.
Citation Information
Patent Citations
Network security situation awareness model and method based on CE-RBF
CN110392048A
Network security situation self-adaptive active defense system and method
CN113965404A