A Visualization Display Method and Device in Network Security Attack and Defense

By adaptively allocating the display area and distribution of network terminals, the problem of inability to intuitively display the offensive and defense situation in network security offensive and defense drills is solved, and visual display and information dissemination of the network offensive and defense process are realized.

CN115150127BActive Publication Date: 2025-07-25QI AN XIN TECHNOLOGY GROUP INC +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210567732.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-05-23
Publication Date
2025-07-25
Estimated Expiration
2042-05-23

AI Technical Summary

Technical Problem

In existing cybersecurity offensive and defense drills, users cannot intuitively display the offensive and defense process and situation, and participants cannot submit reports based on the attack results.

Method used

By determining the number of network terminals, adaptively allocate the display area and distribution, using preset display styles and content filling, a visual network offensive and defense scenario is constructed to show the distribution and offensive and defense situation of network terminals.

Benefits of technology

It realizes intuitive display of the network offensive and defense process, facilitates real-time monitoring and publicity of network security technology, and improves user experience and information visualization effects.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115150127B_ABST
    Figure CN115150127B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention provides a method and device for visual display in network security attack and defense. Among them, the method includes: determining the number of each network terminal participating in network attack and defense; determining the area for displaying network terminals and the distribution of each network terminal in the area according to the number of the network terminals. By judging the number of network terminals and setting the display area of the network terminals, it is beneficial to adaptively allocate the area for displaying network terminals and their distribution in each area according to the scale of attack and defense, so as to intuitively and vividly display the attack and defense situation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security, and in particular, to a method and device for visual display in network security attack and defense. Background Art

[0002] With the development of the network, network security has gradually attracted people's attention, and the learning and research of network attack and defense technologies have become increasingly urgent. At present, network security attack and defense deduction mainly builds a simulation environment based on known vulnerabilities and preset attacks. Users analyze and defend against attacks in this simulation environment.

[0003] However, the rules of attack and defense drills generally stipulate that the attacker can penetrate the intranet of the target or take control of the target by any feasible means, and then the target will withdraw from the public target, and other attackers will no longer be able to submit reports on the target. In this way, what is obtained is often the final attack result, and the users participating in the network security attack and defense deduction and their attack and defense processes cannot be intuitively presented. Summary of the Invention

[0004] In view of the problems in the prior art, embodiments of the present invention provide a method and device for visual display in network security attack and defense.

[0005] Specifically, the embodiments of the present invention provide the following technical solutions:

[0006] In a first aspect, an embodiment of the present invention provides a method for visual display in network security attack and defense, including: determining the number of each network terminal participating in network attack and defense; determining the area for displaying network terminals according to the number of the network terminals and the distribution of each network terminal in the area.

[0007] Further, the area includes a main area. Determining the area for displaying network terminals according to the number of the network terminals and the distribution of each network terminal in the area includes: judging whether the number of the network terminals is less than or equal to a second threshold. If so, determining the main area as the area for displaying network terminals, and distributing and displaying each network terminal in the main area in a preset display style.

[0008] Further, the main area includes a first main area and other main areas. Among them, the first main area has the highest priority. Determining the area for displaying network terminals according to the number of network terminals includes: judging whether the number of network terminals is less than or equal to a first threshold, where the first threshold is less than a second threshold. If so, distribute and display each network terminal in the first main area in a preset display style, and fill the other main areas with preset content; if the number of network terminals is greater than the first threshold and less than or equal to the second threshold, distribute and display each network terminal in the first main area and other main areas in a preset display style.

[0009] Further, the area is a pre-constructed area within the scene.

[0010] Further, the area further includes a slave area, and the slave area is hidden by default. Determining the area for displaying network terminals according to the number of network terminals, and the distribution of each network terminal in the area includes: if the number of network terminals is greater than the second threshold and less than or equal to the third threshold, trigger the display of at least one slave area, and determine the main area and the at least one slave area as the areas for displaying network terminals, and distribute and display each network terminal in the main area and the at least one slave area in a preset display style.

[0011] Further, determining the area for displaying network terminals according to the number of network terminals, and the distribution of each network terminal in the area includes: if the number of network terminals is greater than the third threshold, trigger the addition of at least one area as a slave area, and determine the main area and the slave area as the areas for displaying network terminals, and distribute and display each network terminal in the main area and the slave area in a preset display style.

[0012] Further, the method further includes: triggering the slave area according to the attack and defense records of each network terminal, and transferring and distributing the network terminals that meet the predetermined conditions to the slave area in a preset display style.

[0013] Further, triggering the slave area according to the attack and defense records of each network terminal, and transferring and distributing the network terminals that meet the predetermined conditions to the slave area in a preset display style includes: determining the heat value of each network terminal according to the attack and defense records of each network terminal, triggering the slave area according to the heat value, and the heat value is determined based on at least one of the number of attack times, the number of defense times, the attack success rate, and the defense success rate in the attack and defense records.

[0014] Further, determining the area for displaying network terminals and the distribution of each network terminal in the area according to the number of the network terminals includes: determining the ranking of each network terminal participating in network attack and defense according to attack and defense records, and displaying the network terminals within a preset ranking range.

[0015] Further, determining the area for displaying network terminals and the distribution of each network terminal in the area according to the number of the network terminals includes: distributing each network terminal visualized in each area based on a preset density and a preset overall aesthetic coefficient of the area, where the density is used to represent the density degree of network terminals, and the preset overall aesthetic coefficient of the area is used to represent the distribution pattern of network terminals in the area.

[0016] Further, the method further includes: filling each area with preset content according to the distribution positions of network terminals in the first main area and / or other main areas and / or at least one additional area.

[0017] In a second aspect, an embodiment of the present invention further provides a visualization display device in network security attack and defense, including: a first processing module, configured to determine the number of each network terminal participating in network attack and defense; a second processing module, configured to determine the area for displaying network terminals and the distribution of each network terminal in the area according to the number of the network terminals.

[0018] In a third aspect, an embodiment of the present invention further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, where when the processor executes the program, the steps of the visualization display method in network security attack and defense as described in the first aspect are implemented.

[0019] In a fourth aspect, an embodiment of the present invention further provides a non-transitory computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the visualization display in network security attack and defense as described in the first aspect are implemented.

[0020] In a fifth aspect, an embodiment of the present invention further provides a computer program product, on which executable instructions are stored, and when the instructions are executed by a processor, the processor implements the steps of the visualization display method in network security attack and defense as described in the first aspect.

[0021] The visualization display method and device in network security attack and defense provided by the embodiments of the present invention determine the number of each network terminal participating in network attack and defense; determine the area for displaying network terminals and the distribution of each network terminal in the area according to the number of the network terminals. By judging the number of network terminals, it is beneficial to adaptively allocate the area for displaying network terminals and their distribution in each area according to the scale of attack and defense, so as to intuitively and vividly display the attack and defense situation. Description of the Drawings

[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the accompanying drawings required in the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.

[0023] Figure 1 It is a flowchart of an embodiment of a visualization display method in network security attack and defense of the present invention;

[0024] Figure 2 It is a schematic diagram of the distribution display of each network terminal in the first main area;

[0025] Figure 3 It is a schematic diagram of the distribution display of each network terminal in the first main area and other main areas;

[0026] Figure 4 It is a schematic structural diagram of an embodiment of a visualization display device in network security attack and defense of the present invention;

[0027] Figure 5 It is a schematic structural diagram of an embodiment of an electronic device entity of the present invention. Specific embodiments

[0028] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts belong to the scope of protection of the present invention.

[0029] Figure 1 It is a flowchart of an embodiment of a visualization display method in network security attack and defense of the present invention. As Figure 1 shown, the method of the embodiment of the present invention includes:

[0030] S101, determining the number of each network terminal participating in network attack and defense.

[0031] It should be noted that the visualization display method in network security attack and defense in the embodiments of the present invention can be used in real network attack and defense scenarios such as network attack and defense exercises and network attack and defense competitions, so that the process and situation of network attack and defense can be seen more intuitively.

[0032] In network attack and defense, as an implementation method, network terminals are embodied in the form of teams. A team is both the attacked and the attacker. Teams defend and attack each other. Since the number of teams may not be fixed each time, the displayed area and position of the teams will be adjusted according to the number of teams.

[0033] S102. Determine the area for displaying network terminals and the distribution of each network terminal in the area according to the number of network terminals.

[0034] A visualization display method in network security attack and defense provided by an embodiment of the present invention includes determining the number of each network terminal participating in network attack and defense; determining the area for displaying network terminals and the distribution of each network terminal in the area according to the number of network terminals. By judging the number of network terminals and setting the display area of the network terminals, it is beneficial to adaptively allocate the area for displaying network terminals and their distribution in each area according to the scale of attack and defense, so as to visually display the attack and defense situation and facilitate the real-time display of each network terminal.

[0035] In one implementation, the area includes a main area. Judge whether the number of network terminals is less than or equal to a second threshold. If so, determine the main area as the area for displaying network terminals, and display each network terminal in the main area in a preset display style. In this implementation, if the number of network terminals does not exceed the second threshold, all network terminals will be displayed in one area, that is, the main area.

[0036] As an example, the number of network terminals is 30 and the second threshold is 50. When it is judged that the number of network terminals 30 is less than the second threshold 50, the main area is determined as the area for displaying network terminals.

[0037] In another implementation, the main area includes a first main area and other main areas. Among them, the first main area has the highest priority. In this implementation, the first main area is the area with the best visual position among all main areas, or the area of the first main area is larger compared with that of other main areas. Determining the area for displaying network terminals according to the number of network terminals includes: judging whether the number of network terminals is less than or equal to a first threshold, where the first threshold is less than the second threshold. If so, display each network terminal in the first main area in a preset display style, and fill other main areas with preset content; if the number of network terminals is greater than the first threshold and less than or equal to the second threshold, display each network terminal in the first main area and other main areas in a preset display style.

[0038] As an example, the first threshold is 25 and the second threshold is 50.

[0039] For example, assume that the number of network terminals participating in network attack and defense is 10. If it is determined that the number of network terminals is less than the first threshold of 25, then these 10 network terminals are distributed and displayed in the first main area in a preset display style (such as Figure 2 the main area shown), and other main areas will automatically generate decorations to fill in.

[0040] For example, assume that the number of network terminals participating in network attack and defense is 30. If it is determined that the number of network terminals is greater than the first threshold of 25 and less than the second threshold of 50. Then these 30 network terminals are distributed and displayed in the first main area and other main areas, as Figure 3 shown.

[0041] As a specific implementation, in a preset network attack and defense scenario, the area is an area pre-constructed within the scenario. Each area is generated by pre-dotting, and the area size and outer contour shape of each area can be different. Through this implementation, when determining the area for displaying network terminals according to the number of network terminals, the area can be determined very quickly, which is beneficial to efficiently and conveniently constructing a network attack and defense scenario.

[0042] According to the scope of each area, each network terminal is distributed and displayed according to a preset layout algorithm. When the area is relatively empty, decorations such as flowers, plants and trees will be automatically calculated and filled in. The purpose is to be able to display each network terminal reasonably, dispersedly and clearly, and the constructed network attack and defense scenario is also observable.

[0043] As a specific implementation, the preset display style of the network terminal can be in the shape of a chariot, a building or other custom styles. The building shape includes a castle, a building, etc. The display style of the network terminal can be adjusted or custom-set according to the form of network attack and defense. If the network terminals attack each other in network attack and defense, then the display style of the network terminal is preferably in the shape of a chariot. If the network terminals launch attacks on a predetermined network target in network attack and defense, then the attacking network terminals are preferably in the shape of a chariot, and the predetermined network target being attacked is preferably a castle or a building. Through this implementation, each network terminal participating in network attack and defense can be visualized, making the attack and defense situation observable, which is beneficial to the publicity and promotion of network security technology.

[0044] As an example, the pre-constructed scenario can be an island in the shape of a tiger and / or some small islands around it, and the shape of the scenario can play a role in identification.

[0045] In some embodiments, the first main area and other main areas can be pre-displayed within the pre-constructed scenario. When a network attack and defense situation is detected, the network terminals participating in the attack and defense are distributed and displayed in the first main area and / or other main areas.

[0046] The present invention does not limit the display style, the pre-constructed scene, the shape, area size, etc. of the first main area and other main areas, which can be adjusted according to specific needs. The first main area and other main areas can be pre-generated or constructed in real time.

[0047] In some alternative implementation manners, the area further includes a slave area. The slave area is pre-generated and is hidden by default. The area for displaying network terminals is determined according to the number of network terminals and the distribution of each network terminal in the area, including: if the number of network terminals is greater than a second threshold and less than or equal to a third threshold, at least one slave area is triggered to be displayed, and the main area and at least one slave area are determined as the areas for displaying network terminals, and each network terminal is distributed and displayed in the main area and at least one slave area in a preset display style.

[0048] As a specific embodiment, if the number of network terminals is 60, the second threshold is 50, and the third threshold is 100. It is judged that the number of network terminals is greater than the second threshold and less than or equal to the third threshold, then at least one slave area is triggered to be displayed (at least one slave area is a pre-set area that is hidden, and the slave area is as Figure 3 shown). The slave area can be presented in the form of an island, and there is an area for displaying network terminals on the island. After determining the area for displaying network terminals, 50 network terminals are distributed and displayed in the main area in a preset display style, and the remaining 10 network terminals are distributed and displayed in at least one slave area in a preset display style, or according to the total range of the determined area, 60 network terminals are evenly distributed in the main area and at least one slave area.

[0049] In some alternative implementation manners, if the number of network terminals participating in network attack and defense exceeds the third threshold set usually, and the pre-generated area is not sufficient to distribute and display the network terminals, then areas need to be added in real time to accommodate the excess network terminals. Therefore, determining the area for displaying network terminals according to the number of network terminals and the distribution of each network terminal in the area may further include: if the number of network terminals is greater than the third threshold, at least one area is triggered to be added as a slave area, and the main area and the slave area are determined as the areas for displaying network terminals, and each network terminal is distributed and displayed in the main area and the slave area in a preset display style.

[0050] In some popular network attack and defense competitions and network attack and defense drills, it is possible that the main area and the hidden and displayed secondary areas are insufficient. When the number of teams (network terminals) is greater than the third threshold, since it exceeds the limit of the number of teams that can be displayed in the main area and the hidden and displayed secondary areas, additional areas can be triggered and used as new secondary areas. For example, if the number of teams is 200, which is greater than the third threshold of 100, additional areas are triggered. 100 teams are displayed in the main area and the hidden and displayed secondary areas, and the remaining 100 teams are displayed in at least one of the triggered additional secondary areas.

[0051] In some alternative implementation manners, the method further includes: triggering a secondary area according to the attack and defense records of each network terminal, and transferring and distributing the network terminals that meet a predetermined condition to the secondary area according to a preset display style.

[0052] The attack and defense records include the team ID, team name, number of times the team is liked, attack means, number of attack times and number of times being attacked, attack result, etc.

[0053] In some embodiments, all information or some information of the attack and defense records is monitored in real time, and according to this information, the network terminals are transferred and distributed to the secondary area. In a scenario of an attack and defense drill, the number of times each team is attacked is monitored. If the number of times being attacked is greater than a preset number of times, the corresponding team is transferred and distributed to the secondary area for special display of the team.

[0054] It can be seen from the above description that the secondary area triggered according to the attack and defense records of each network terminal can be a pre-set, hidden and displayed secondary area, or a newly triggered additional secondary area.

[0055] In some alternative implementation manners, the method further includes: triggering a secondary area according to the attack and defense records of each network terminal, and transferring and distributing the network terminals that meet a predetermined condition to the secondary area according to a preset display style, including: determining the heat value of each network terminal according to the attack and defense records of each network terminal, triggering the secondary area according to the heat value, and the heat value is determined based on at least one of the number of attack times, number of defense times, attack success rate and defense success rate in the attack and defense records.

[0056] The heat value can represent the activity of the team in the attack and defense deduction, the intensity of the battle, or the attention of the audience.

[0057] In a scenario of an attack and defense drill: monitoring the attack and defense records of each team, including attack means, number of times being attacked and number of attack times, taking the weighted sum value of the attack means, number of times being attacked and number of attack times as the heat value, and determining whether the heat value meets a preset range. If it meets, the corresponding team is transferred and distributed to the corresponding secondary area for special display.

[0058] In some alternative implementations, determining the area for displaying network terminals and the distribution of each network terminal in the area according to the number of network terminals includes: determining the rankings of each network terminal participating in network attack and defense based on attack and defense records, and displaying the network terminals within a preset ranking range.

[0059] As an example, in a scenario of attack and defense application, each network terminal participating in network attack and defense attacks a specific target. The area for displaying teams only supports 50 teams (the preset ranking range is 50), while there are approximately 200 participating teams. Therefore, it is necessary to settle the team scores in real time according to the attack and defense records, calculate the top 50 teams, and only display the top 50 teams and the corresponding information of the teams in the area. The information includes question information, attack ability, defense ability, score, ranking, etc.

[0060] In some alternative implementations, determining the area for displaying network terminals and the distribution of each network terminal in the area according to the number of network terminals includes: distributing each network terminal visualized in each area based on a preset density and a preset overall aesthetic coefficient of the area. The density is used to represent the degree of density of the distribution of network terminals, and the preset overall aesthetic coefficient of the area is used to represent the distribution pattern of network terminals in the area.

[0061] Setting and adjusting the density and the overall aesthetic coefficient of the area are for better visual effects. The preset density and the preset overall aesthetic coefficient of the area can be defined according to specific needs. As an example, after determining the number of teams and the display area, calculate the area of each area, and automatically distribute the teams in each area according to the area of each area and the preset density.

[0062] By setting and adjusting the density, the distance between each team is made greater than the preset value, so as to ensure that each team has a necessary display space. As a specific implementation, each area can be divided into multiple small areas of a certain area according to a preset rule. The small areas can be hexagons, circles or squares, and the teams are distributed at the centers of these small areas, so that the teams can be distributed at a certain density.

[0063] In some alternative implementations, the method further includes: filling each area with preset content according to the distribution positions of network terminals in the first main area and / or other main areas and / or at least one additional area, to achieve an aesthetic visual effect.

[0064] In some embodiments, after the team distribution is completed, the blank areas between teams or other areas without distributed teams can be adaptively filled with custom fillers to achieve the expected aesthetic effect. The preset content can be items such as flowers, plants and trees, which have decorative or concealment effects, or specific scene pictures such as jungles, deserts, and wildernesses.

[0065] Figure 4 This is a schematic structural diagram of an embodiment of a visualization display device in network security attack and defense according to the present invention. As Figure 4 shown, the device based on this includes:

[0066] A first processing module 401, configured to determine the number of each network terminal participating in network attack and defense;

[0067] A second processing module 402, configured to determine the area for displaying network terminals and the distribution of each network terminal in the area according to the number of network terminals.

[0068] Optionally, the second processing module 402 is further configured to: determine whether the number of network terminals is less than or equal to a second threshold. If so, determine the main area as the area for displaying network terminals, and display each network terminal in the main area in a preset display style.

[0069] Optionally, the main area includes a first main area and other main areas. Among them, the first main area has the highest priority. The second processing module 402 is further configured to: determine whether the number of network terminals is less than or equal to a first threshold, where the first threshold is less than the second threshold. If so, display each network terminal in the first main area in a preset display style, and fill other main areas with preset content; if the number of network terminals is greater than the first threshold and less than or equal to the second threshold, display each network terminal in the first main area and other main areas in a preset display style.

[0070] Optionally, the area is an area pre-constructed in the scene.

[0071] Optionally, the area further includes a slave area, and the slave area is default hidden. The second processing module 402 is further configured to: if the number of network terminals is greater than the second threshold and less than or equal to a third threshold, trigger the display of at least one slave area, and determine the main area and at least one slave area as the areas for displaying network terminals, and display each network terminal in the main area and at least one slave area in a preset display style.

[0072] Optionally, the second processing module 402 is further configured to: if the number of network terminals is greater than the third threshold, trigger the addition of at least one area as a slave area, and determine the main area and the slave area as the areas for displaying network terminals, and display each network terminal in the main area and the slave area in a preset display style.

[0073] Optionally, the device further includes a third processing module, configured to: trigger the slave area according to the attack and defense records of each network terminal, and transfer and distribute the network terminals that meet the predetermined conditions to the slave area in a preset display style.

[0074] Optionally, the device further includes a third processing module, which is further configured to: determine the heat value of each network terminal according to the attack and defense records of each network terminal, trigger a slave area according to the heat value, and the heat value is determined based on at least one of the number of attacks, the number of defenses, the attack success rate, and the defense success rate in the attack and defense records.

[0075] Optionally, the second processing module 402 is further configured to: determine the ranking of each network terminal participating in the network attack and defense according to the attack and defense records, and display the network terminals within a preset ranking range.

[0076] Optionally, the second processing module 402 is further configured to: distribute the visual network terminals in each area based on a preset density and a preset overall aesthetic coefficient of the area, where the density is used to represent the density degree of the network terminals, and the preset overall aesthetic coefficient of the area is used to represent the distribution pattern of the network terminals in the area.

[0077] Optionally, the device further includes a fourth processing module, which is further configured to: fill each area with preset content according to the distribution positions of the network terminals in the first main area and / or other main areas and / or at least one additional area.

[0078] For example, as follows:

[0079] Figure 5 The schematic diagram of the physical structure of an electronic device is illustrated, as Figure 5 shown, the electronic device may include: a processor 510, a communications interface 520, a memory 530, and a communication bus 540. Among them, the processor 510, the communications interface 520, and the memory 530 communicate with each other through the communication bus 540. The processor 510 may call the logical instructions in the memory 530 to execute the following methods: determine the number of each network terminal participating in the network attack and defense; determine the area for displaying the network terminals and the distribution of each network terminal in the area according to the number of network terminals.

[0080] In addition, when the logical instructions in the above-mentioned memory 530 can be implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.

[0081] On the other hand, an embodiment of the present invention also provides a computer program product. The computer program product includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute a method for visual display in network security attack and defense provided in the above-mentioned various embodiments. For example, it includes: determining the number of each network terminal participating in the network attack and defense; determining the area for displaying network terminals and the distribution of each network terminal in the area according to the number of network terminals.

[0082] On another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is configured to execute a method for visual display in network security attack and defense provided in the above-mentioned various embodiments. For example, it includes: determining the number of each network terminal participating in the network attack and defense; determining the area for displaying network terminals and the distribution of each network terminal in the area according to the number of network terminals.

[0083] The device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative labor.

[0084] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods of each embodiment or some parts of the embodiments.

[0085] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. And these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A visualization display method in network security attack and defense, characterized in that Including: Determine the number of each network terminal participating in network attack and defense; Determine the area for displaying network terminals and the distribution of each network terminal in the area according to the number of the network terminals; The area is a pre-constructed area within the scene, and each area is generated by pre-dotting, and the area size and outer contour shape of each area are different from each other; The area includes a main area, and determining the area for displaying network terminals and the distribution of each network terminal in the area according to the number of the network terminals includes: Judge whether the number of the network terminals is less than or equal to a second threshold. If so, determine the main area as the area for displaying network terminals, and display each network terminal in the main area in a preset display style; The area further includes a secondary area, and the secondary area is hidden by default; the method further includes: triggering the secondary area according to the attack and defense records of each network terminal, and transferring and distributing the network terminals meeting the predetermined conditions to the secondary area in a preset display style; Triggering the secondary area according to the attack and defense records of each network terminal, and transferring and distributing the network terminals meeting the predetermined conditions to the secondary area in a preset display style includes: determining the heat value of each network terminal according to the attack and defense records of each network terminal, and triggering the secondary area according to the heat value, where the heat value is determined based on at least one of the number of attack times, the number of defense times, the attack success rate, and the defense success rate in the attack and defense records.

2. The visualization display method in network security attack and defense according to claim 1, wherein, The main area includes a first main area and other main areas. Among them, the first main area has the highest priority, and determining the area for displaying network terminals according to the number of the network terminals includes: Judge whether the number of the network terminals is less than or equal to a first threshold, where the first threshold is less than the second threshold. If so, display each network terminal in the first main area in a preset display style, and fill the other main areas with preset content; if the number of the network terminals is greater than the first threshold and less than or equal to the second threshold, display each network terminal in the first main area and other main areas in a preset display style.

3. The visualization display method in network security attack and defense according to claim 1, wherein Determining the area for displaying network terminals and the distribution of each network terminal in the area according to the number of the network terminals includes: If the number of the network terminals is greater than the second threshold and less than or equal to a third threshold, trigger the display of at least one secondary area, and determine the main area and the at least one secondary area as the areas for displaying network terminals, and display each network terminal in the main area and the at least one secondary area in a preset display style.

4. The visualization display method in network security attack and defense according to claim 1, wherein Determining the area for displaying network terminals and the distribution of each network terminal in the area according to the number of the network terminals includes: If the number of the network terminals is greater than the third threshold, trigger the addition of at least one area as a secondary area, and determine the main area and the secondary area as the areas for displaying network terminals, and display each network terminal in the main area and the secondary area in a preset display style.

5. The visualization display method in network security attack and defense according to claim 1, wherein Determine the area for displaying network terminals and the distribution of each network terminal in the area according to the number of the network terminals, including: Determine the rankings of the network terminals participating in network attack and defense according to the attack and defense records, and display the network terminals within a preset ranking range.

6. The visualization display method in network security attack and defense according to claim 1, characterized in that Determine the area for displaying network terminals and the distribution of each network terminal in the area according to the number of the network terminals, including: Distribute the visualized network terminals in each area based on a preset density and a preset overall aesthetic coefficient of the area. The density is used to represent the density degree of the network terminals, and the preset overall aesthetic coefficient of the area is used to represent the distribution pattern of the network terminals in the area.

7. A visualization display device in network security attack and defense, characterized in that, Including: A first processing module, configured to determine the number of network terminals participating in network attack and defense; A second processing module, configured to determine the area for displaying network terminals and the distribution of each network terminal in the area according to the number of the network terminals; The area is a pre-constructed area in the scene, and each area is generated by pre-dotting. The area size and outer contour shape of each area are different from each other; The area includes a main area. The second processing module is configured to: determine whether the number of the network terminals is less than or equal to a second threshold. If so, determine the main area as the area for displaying network terminals, and distribute and display each network terminal in the main area in a preset display style; The area further includes a secondary area, and the secondary area is hidden by default. The apparatus further includes a third processing module, configured to: trigger the secondary area according to the attack and defense records of the network terminals, and transfer and distribute the network terminals meeting a predetermined condition to the secondary area in a preset display style; The third processing module is further configured to: determine the heat value of each network terminal according to the attack and defense records of the network terminals, and trigger the secondary area according to the heat value. The heat value is determined based on at least one of the number of attack times, the number of defense times, the attack success rate, and the defense success rate in the attack and defense records.

8. An electronic device, characterized in that, Including: A processor, a memory, and a bus, where The processor and the memory communicate with each other through the bus; The memory stores program instructions executable by the processor, and the processor can execute the steps of the method for visual display in network security attack and defense according to any one of claims 1 to 6 by calling the program instructions.

9. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores computer instructions, and the computer instructions cause the computer to execute the steps of the method for visual display in network security attack and defense according to any one of claims 1 to 6.

10. A computer program product, the computer program product comprising computer-executable instructions, characterized in that, When the instructions are executed, they are used to execute the steps of the method for visual display in network security attack and defense according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • A method for displaying icons and terminal

    CN109542324A

  • Network security information display method and device

    CN112446955A