Network security situation awareness method, device and electronic equipment
By clustering the uplink and downlink traffic data of network nodes to calculate the network situation awareness value, the problem of high network security situation awareness dimension is solved, and more efficient security situation awareness is achieved.
Patent Information
- Application Number
- CN202111177095.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-10-09
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2041-10-09
AI Technical Summary
The high dimension of network security situation awareness leads to low efficiency and it is difficult to quickly handle network security incidents.
By obtaining the uplink and downlink traffic data of each node in the network, performing clustering analysis, computing the network situation awareness value, and performing security alarms when the threshold is reached, reducing dimension analysis.
There is no need to comprehensively analyze multiple network security elements, which improves the efficiency of network security situation awareness.
Smart Images

Figure CN115955323B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network security situation awareness method, device and electronic equipment. Background Art
[0002] Network security situation awareness is a technology used by network administrators to monitor network security status. It is used to comprehensively analyze network security factors, evaluate network security conditions, and predict network development trends.
[0003] As networks continue to expand, cybersecurity incidents are characterized by massive volume, diverse types, low value density, and rapid processing. These characteristics of cybersecurity incidents require comprehensive analysis of multiple cybersecurity factors, such as system flows and intrusion attacks. This increases the dimensionality of cybersecurity situational awareness, further leading to lower efficiency. Summary of the Invention
[0004] The purpose of the embodiments of the present application is to provide a network security situation awareness method, device and electronic equipment to reduce the dimension of network security situation awareness and further improve the efficiency of network situation awareness.
[0005] In order to solve the above technical problems, the embodiments of the present application are implemented as follows:
[0006] In a first aspect, an embodiment of the present application provides a network security situation awareness method, comprising:
[0007] Obtain the uplink traffic data and downlink traffic data of each node in the network; cluster the uplink traffic data and downlink traffic data for each node to obtain the clustering results corresponding to each node; calculate the network situation awareness value of the network based on the clustering results, uplink traffic data and downlink traffic data; when the network situation awareness value is greater than the threshold, issue a security alarm.
[0008] In a second aspect, an embodiment of the present application provides a network security situation awareness device, the device comprising:
[0009] The acquisition module is used to obtain the uplink traffic data and downlink traffic data of each node in the network; the clustering module is used to cluster the uplink traffic data and downlink traffic data for each node respectively to obtain the clustering results corresponding to each node; the calculation module is used to calculate the network situation awareness value of the network based on the clustering results, uplink traffic data and downlink traffic data; the alarm module is used to issue a security alarm when the network situation awareness value is greater than the threshold.
[0010] In a third aspect, an embodiment of the present application provides an electronic device comprising a processor, a communication interface, a memory and a communication bus; wherein the processor, the communication interface and the memory communicate with each other through the bus; the memory is used to store computer programs; and the processor is used to execute the programs stored in the memory to implement the steps of the network security situation awareness method as in the first aspect.
[0011] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the network security situation awareness method as in the first aspect are implemented.
[0012] The technical solution provided by the embodiment of the present application includes: obtaining uplink traffic data and downlink traffic data of each node in the network; clustering the uplink traffic data and downlink traffic data for each node to obtain clustering results corresponding to each node; calculating the network situation awareness value of the network based on the clustering results, the uplink traffic data, and the downlink traffic data; and issuing a security alarm when the network situation awareness value is greater than a threshold. Therefore, the embodiment of the present application calculates the network situation awareness value based on the uplink traffic data and downlink traffic data of each node, eliminating the need for comprehensive analysis of multiple network security factors, reducing the dimensionality of network security situation awareness, and improving the efficiency of network security situation awareness. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments recorded in the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0014] Figure 1 A diagram showing a network topology structure provided by an embodiment of the present application;
[0015] Figure 2 A first flow chart of a network security situation awareness method provided by an embodiment of the present application is shown;
[0016] Figure 3 A second flow chart of a network security situation awareness method provided by an embodiment of the present application is shown;
[0017] Figure 4 A schematic diagram showing the module composition of a network security situation awareness device provided by an embodiment of the present application is shown;
[0018] Figure 5 A schematic structural diagram of an electronic device provided in an embodiment of the present application is shown; DETAILED DESCRIPTION
[0019] The embodiments of the present application provide a network security situation awareness method, device, and electronic device to reduce the dimension of network security situation awareness and further improve the efficiency of network situation awareness.
[0020] In order to enable those skilled in the art to better understand the technical solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0021] In some application scenarios, such as Figure 1 As shown, the network topology diagram in the network may include gateway A, gateway B, gateway C, local server A, local server B, local server C, cloud server A, etc. Among them, network management A, gateway B, gateway C, local server A, local server B, local server C, cloud server A can be used as nodes in the network, and each node represents a stage on the transmission network. If a connection is established between two stages, there will be an edge between the corresponding two nodes in the network topology diagram. It is worth noting that the network topology diagram is not limited to Figure 1 The structure shown is as follows; the network topology diagram may also be of other types depending on the actual situation of the network.
[0022] like Figure 1 The network traffic data for each node shown in the network topology diagram includes upstream traffic data and downstream traffic data. Upstream traffic data includes, but is not limited to, packet identification, packet size, packet arrival time, source address, and destination address. Downstream traffic data includes, but is not limited to, packet identification, packet size, packet sending time, source address, and destination address.
[0023] Below is Figure 1 Taking the illustrated network topology structure as an example, the network security situation awareness method provided in the embodiment of the present application is explained.
[0024] like Figure 2 As shown, an embodiment of the present application provides a network security situation awareness method, the execution subject of the method can be a server, wherein the server can be an independent server or a server cluster composed of multiple servers, and the server can be a server capable of network security situation awareness. The network security situation awareness method can specifically include the following steps:
[0025] In S201, uplink traffic data and downlink traffic data of each node in the network are obtained.
[0026] Specifically, for uplink traffic data, it includes but is not limited to the packet identifier, packet size, packet arrival time, source address, and destination address. For downlink traffic data, it includes but is not limited to the packet identifier, packet size, packet sending time, source address, and destination address. The packet identifiers in the uplink and downlink traffic data can be the same.
[0027] Each node has a corresponding security weight. The security weight of each node can be the product of the node's degree in the network topology and the node's level. The node's level can be a user-defined security level, such as a server's security level of 3, a gateway's security level of 2, etc.
[0028] In S202, the uplink traffic data and the downlink traffic data are clustered respectively to obtain clustering results.
[0029] Specifically, when clustering uplink traffic data and downlink traffic data, you can first select any data element from the uplink traffic data or the downlink traffic data as the central data element, and classify the data elements with a high correlation with the central data element into one category, thereby dividing the uplink traffic data or the downlink traffic data into multiple categories.
[0030] In S203, a network situation awareness value is calculated based on the clustering result, the uplink traffic data, and the downlink traffic data. If the network situation awareness value is greater than a threshold, a security alarm is issued.
[0031] Specifically, the threshold value can be customized by the user according to the actual situation of the network, and the embodiment of the present application does not limit this.
[0032] In one possible implementation, calculating the network situational awareness value specifically includes:
[0033] For each node, calculate the first product of the number of data elements in each data class and the security weight of the corresponding node, and the second product of the average correlation of each data class and the contribution of the corresponding node; sum the first product and the second product to obtain a first sum; calculate the variance of the time parameters of the uplink data and the downlink data with the same data packet identifier; calculate the ratio of the first sum and the variance, and superimpose the ratios to obtain the network situation awareness value of each node; superimpose the network situation awareness value of each node to obtain the network situation awareness value of the network.
[0034] Specifically, the network situational awareness value can be calculated using the following formula:
[0035] Network situational awareness value = ΣΣ(the number of elements in each category of any node + the security weight of any node + the average relevance of each category of any node * the contribution of any node) / the variance of the time parameters of the uplink data and downlink data with the same data packet identifier included in any node.
[0036] The first summation "Σ" on the left is the superposition of the network status values of each node, and the second summation "Σ" is the superposition of the ratios in a single node.
[0037] The contribution of each node is calculated as follows: the correlation between each node and the central node of its class / the average correlation between each node and the central node in each class. The central node is the central node in each node class and can be customized by the user. The nodes belonging to the class of the central node can also be customized by the user, but this is not limited in this embodiment.
[0038] It can be seen from the technical solutions provided in the above embodiments of the present application that the network situation awareness value is calculated by the uplink traffic data and downlink traffic data of each node, without the need for comprehensive analysis of multiple network security factors, thereby reducing the dimension of network security situation awareness and improving the efficiency of network security situation awareness.
[0039] like Figure 3 As shown, an embodiment of the present application provides a network security situation awareness method, the execution subject of the method can be a server, wherein the server can be an independent server or a server cluster composed of multiple servers, and the server can be a server capable of network security situation awareness. The network security situation awareness method can specifically include the following steps:
[0040] S301, obtaining uplink traffic data and downlink traffic data of each node in the network;
[0041] S302: Execute a loop process until all data elements in the uplink traffic data or the downlink traffic data are classified.
[0042] The cycle process includes:
[0043] A central data element is selected from unclassified data elements of the upstream traffic data or the downstream traffic data, and the central data element is used as the center of a data class; a target data element is selected from unclassified data elements of the upstream traffic data or the downstream traffic data; the correlation between the target data element and the central data element is calculated; the maximum and minimum values are determined from each correlation; the target data element corresponding to the maximum value is classified into the data class where the central data element is located, and the target data element corresponding to the minimum value is used as a new unclassified central data element.
[0044] The following describes the data clustering process in detail, taking uplink traffic data as an example:
[0045] For any node, the set of uplink traffic data is denoted as S 上 , optional S 上 In the uplink data sequence, select S from the earliest to the latest data element. 上 For any unclassified data element (target data element), calculate the correlation between the target data element and the central data element (data element j). For example, for data element i (target data element), calculate the correlation S between data element i and data element j. ij .
[0046] In one possible implementation, Figure 3 As shown, calculating the relevance between the target data element and the central data element includes:
[0047] Determine the security weight of the node where the central data element is located; calculate a first probability related to the central data element and the target data element; calculate a second probability related to the central data element and the target data element; calculate the similarity of the source addresses between the central data element and the target data element; calculate the product of the security weight, the first probability, the second probability and the similarity to obtain the correlation.
[0048] Specifically, the correlation S ij It can be calculated using the following formula:
[0049] S ij =W*Pt(i|j)*Pp(i|j)*Aip(i,j)
[0050] Wherein, W is the security weight of the node. Determining the security weight of the node where the central data element is located includes: determining the network topology of the network; determining the degree of the node where the central data element is located based on the network topology; calculating the product of the predefined security level of the node where the central data element is located and the degree of the node to obtain the security weight.
[0051] The calculation formula of the security weight W is as follows:
[0052] W = degree of the node in the network topology * level of the node.
[0053] The level of the node may be a security level predefined by the user, such as a security level of 3 for the server and a security level of 2 for the gateway.
[0054] In one possible implementation, calculating a first probability that the central data element and the target data element are associated includes:
[0055] Sort the uplink traffic data or the downlink traffic data from early to late according to the arrival time to obtain an uplink data sequence or a downlink data sequence; calculate a first arrival time difference between the arrival time of a central data element and the arrival time of a data element that is one position before the central data element, and use the first arrival time difference as the first value of the time interval attribute of the central data element; calculate a second arrival time difference between the arrival time of a target data element and the arrival time of a data element that is one position before the target data element, and use the second arrival time difference as the second value of the time interval attribute of the target data element; calculate a first probability based on the first value, the second value, and the average value of the time interval attribute of all data elements in the uplink traffic data; or calculate the first probability based on the first value, the second value, and the average value of the time interval attribute of all data elements in the downlink traffic data.
[0056] Specifically, let Pt(i|j) be the first probability that data element i is associated with data element j. The calculation formula for Pt(i|j) is as follows:
[0057] Pt(i|j)=(1-|the value of the time interval attribute of data element i-the value of the time interval attribute of data element j / the average value of the time interval attribute of all uplink data)*(the value of the time interval attribute of data element i / the value of the time interval attribute of data element j).
[0058] The time interval attribute value is calculated as follows: sort the uplink traffic data by arrival time from earliest to latest to obtain an uplink data sequence. Calculate the arrival time difference between each uplink data point in the uplink data sequence and the arrival time of the previous uplink data point. Use this arrival time difference as the time interval attribute value for that uplink data point. For the first uplink data point to arrive, use 0 as its time interval attribute value.
[0059] Sort the downlink traffic data by send time from earliest to latest to obtain a downlink data sequence. Calculate the arrival time difference between each downlink data packet and the previous downlink data packet in the sequence, and use this time difference as the value of the interval attribute for that downlink data packet. For the first downlink data packet sent, use 0 as the value of its interval attribute.
[0060] The data packets in the uplink traffic data are classified according to the data packet identifiers. For the uplink data and downlink data with the same data packet identifier, the time difference between the uplink data arrival time and the downlink data sending time is calculated, and the time difference is used as the time parameter of the data packet identifier.
[0061] Calculating a second probability associated with the center data element and the target data element includes:
[0062] Calculate the difference between the data volume of the central data element and the data volume of the target data element and a first ratio; select the one with smaller data volume from the central data element and the target data element as the target data volume; calculate the product of the second ratio of the difference to the target data volume and the first ratio as the second probability.
[0063] Specifically, Pp(i|j) is the second probability that data element i is associated with data element j, which can be calculated using the following formula:
[0064] Pp(i|j) = (|packet size of element i - packet size of element j| / min{packet size of element i, packet size of element j}) * (packet size of element i / packet size of element j)
[0065] The packet size of element i is the data size of the target data element, and the packet size of element j is the data size of the central data element. min{packet size of element i,packet size of element j} indicates that the smaller data size of the central data element or the target data element is selected as the target data size.
[0066] In one possible implementation, calculating the similarity of the source addresses between the central data element and the target data element includes:
[0067] Starting from the leftmost decimal number of the source address, the values of the central data element and the target data element at the corresponding positions are compared in sequence to find the position of the first different decimal number; the similarity of the source address between the central data element and the target data element is calculated based on the value of the position of the first different decimal number.
[0068] Specifically, Aip(i, j) is used as the similarity of the source addresses between data element i and data element j, where the source address (source IP address) is divided into 4 decimal numbers. The similarity of the source addresses is calculated as follows:
[0069] For example, if the source address of data element i is 120.244.110.131 and the source address of data element j is 120.244.110.100, then the first decimal digit that differs between data element i and data element j is on the far right, i.e., the position of "131" in data element i and the position of "100" in data element j.
[0070] Furthermore, take the source address AAA.BBB.CCC.DDD as an example.
[0071] If the first different decimal number is on the rightmost side (the fourth from the left), that is, (the position of DDD), then the similarity of the source address between data element i and data element j = the absolute value of the difference between the two different numbers / 255.
[0072] If the first different decimal number is second from the right (third from the left to the right), (i.e., the position of CCC), then the similarity of the source address between data element i and data element j = (1-absolute value of the difference between the two different numbers / 255) / 2.
[0073] If the first different decimal number is the second from the left (the second from the left to the right), (i.e., the position of BBB), then the similarity of the source address between data element i and data element j = (1-the absolute value of the difference between the two different numbers / 255) / 4.
[0074] If the first different decimal number is first from the left (the first from left to right), (i.e., the position of AAA), then the similarity of the source address between data element i and data element j = (1-the absolute value of the difference between the two different numbers / 255) / 8.
[0075] In S 上 Among all the unclassified data elements in , the data element with the greatest correlation is classified into the class where data element j is located, and the data element with the least correlation is used as a new class center.
[0076] From S 上 Select the unclassified data elements in turn and repeat the above method until all data elements are classified.
[0077] For the downlink traffic data set S 下 , according to S 上 The classification of data elements in S 下 The data elements in are classified, and the embodiments of the present application will not be repeated here.
[0078] S303: Calculate a network situation awareness value based on the clustering results, the uplink traffic data, and the downlink traffic data; and issue a security alarm when the network situation awareness value is greater than a threshold.
[0079] It is worth noting that S301 and S303 have the same or similar implementation methods as the above-mentioned embodiments S201 and S203, which can be referenced to each other, and the embodiments of this application are not described in detail here.
[0080] Through the technical solution disclosed in the embodiments of the present application, the network situation awareness value is calculated by the uplink traffic data and downlink traffic data of each node, without the need for comprehensive analysis of multiple network security elements, which reduces the dimension of network security situation awareness and improves the efficiency of network security situation awareness.
[0081] Corresponding to the network security situation awareness method provided in the above embodiment, based on the same technical concept, the embodiment of the present application also provides a network security situation awareness device, Figure 4This is a schematic diagram of the module composition of the network security situation awareness device provided in the embodiment of the present application, which is used to perform Figures 2 to 3 The cybersecurity situational awareness methods described, such as Figure 4 As shown, the network security situation awareness device includes:
[0082] The acquisition module 401 is used to obtain the uplink traffic data and downlink traffic data of each node in the network; the clustering module 402 is used to cluster the uplink traffic data and downlink traffic data for each node respectively to obtain the clustering results corresponding to each node; the calculation module 403 is used to calculate the network situation awareness value of the network based on the clustering results, the uplink traffic data and the downlink traffic data; the alarm module 404 is used to issue a security alarm when the network situation awareness value is greater than a threshold.
[0083] It can be seen from the technical solutions provided in the above embodiments of the present application that the network situation awareness value is calculated by the uplink traffic data and downlink traffic data of each node, without the need for comprehensive analysis of multiple network security factors, thereby reducing the dimension of network security situation awareness and improving the efficiency of network security situation awareness.
[0084] In one possible implementation, the clustering module 402 is further configured to execute a loop process until all data elements in the upstream traffic data or the downstream traffic data are classified; the loop process includes: selecting a central data element from the unclassified data elements in the upstream traffic data or the downstream traffic data, and using the central data element as the center of a data cluster; selecting a target data element from the unclassified data elements in the upstream traffic data or the downstream traffic data; calculating a correlation between the target data element and the central data element; and determining a maximum value and a minimum value from each correlation;
[0085] The target data element corresponding to the maximum value is classified into the data class where the central data element is located, and the target data element corresponding to the minimum value is used as a new unclassified central data element.
[0086] In one possible implementation, the clustering module 402 is further used to determine the security weight of the node where the central data element is located; calculate the first probability related to the central data element and the target data element; calculate the second probability related to the central data element and the target data element; calculate the similarity of the source address between the central data element and the target data element; and calculate the product of the security weight, the first probability, the second probability and the similarity to obtain the correlation.
[0087] In one possible implementation, the clustering module 402 is further used to determine the network topology of the network; determine the degree of the node where the central data element is located based on the network topology; and calculate the product of the predefined security level of the node where the central data element is located and the degree of the node to obtain a security weight.
[0088] In one possible implementation, the clustering module 402 is further used to sort the uplink traffic data or the downlink traffic data from early to late according to the arrival time to obtain an uplink data sequence or a downlink data sequence; calculate a first arrival time difference between the arrival time of the central data element and the arrival time of the data element that is ranked before the central data element, and use the first arrival time difference as the first value of the time interval attribute of the central data element; calculate a second arrival time difference between the arrival time of the target data element and the arrival time of the data element that is ranked before the target data element, and use the second arrival time difference as the second value of the time interval attribute of the target data element; calculate a first probability based on the first value, the second value and the average value of the time interval attribute of all data elements in the uplink traffic data; or calculate based on the first value, the second value and the average value of the time interval attribute of all data elements in the downlink traffic data.
[0089] In one possible implementation, the clustering module 402 is further used to calculate the difference between the data volume of the central data element and the data volume of the target data element and a first ratio; select the one with the smaller data volume from the central data element and the target data element as the target data volume; and calculate the product of the second ratio of the difference to the target data volume and the first ratio as the second probability.
[0090] In one possible implementation, the clustering module 402 is further used to compare the values of the central data element and the target data element at corresponding positions starting from the leftmost decimal number of the source address, and find the position of the first different decimal number; and calculate the similarity of the source address between the central data element and the target data element based on the value of the position of the first different decimal number.
[0091] In one possible implementation, the calculation module 403 is also used to calculate, for each node, a first product of the number of data elements in each data class and the security weight of the corresponding node, and a second product of the average correlation of each data class and the contribution of the corresponding node; summing the first product and the second product to obtain a first sum; calculating the variance of the time parameters of the uplink data and the downlink data with the same data packet identifier; calculating the ratio of the first sum and the variance, and superimposing the ratios to obtain the network situation awareness value of each node; and superimposing the network situation awareness value of each node to obtain the network situation awareness value of the network.
[0092] The network security situation awareness device provided in the embodiment of the present application can implement each process in the embodiment corresponding to the above-mentioned network security situation awareness method. To avoid repetition, it will not be described here.
[0093] It should be noted that the network security situation awareness device provided in the embodiment of the present application and the network security situation awareness method provided in the embodiment of the present application are based on the same inventive concept. Therefore, the specific implementation of this embodiment can refer to the implementation of the aforementioned network security situation awareness method, and the repeated parts will not be repeated.
[0094] Corresponding to the network security situation awareness method provided in the above embodiment, based on the same technical concept, the embodiment of the present application also provides an electronic device, which is used to execute the above network security situation awareness method. Figure 5 A schematic diagram of the structure of an electronic device for implementing various embodiments of the present invention is shown in FIG. Figure 5 As shown. Electronic devices may have relatively large differences due to different configurations or performances, and may include one or more processors 501 and memory 502, and the memory 502 may store one or more storage applications or data. Among them, the memory 502 may be a temporary storage or a persistent storage. The application stored in the memory 502 may include one or more modules (not shown in the figure), each module may include a series of computer executable instructions in the electronic device. Furthermore, the processor 501 may be configured to communicate with the memory 502 to execute a series of computer executable instructions in the memory 502 on the electronic device. The electronic device may also include one or more power supplies 503, one or more wired or wireless network interfaces 504, one or more input and output interfaces 505, and one or more keyboards 506.
[0095] Specifically in this embodiment, the electronic device includes a processor, a communication interface, a memory, and a communication bus; wherein the processor, the communication interface, and the memory communicate with each other via the bus; the memory is used to store computer programs; and the processor is used to execute the programs stored in the memory to implement the following method steps:
[0096] Obtain the uplink traffic data and downlink traffic data of each node in the network; cluster the uplink traffic data and downlink traffic data for each node to obtain the clustering results corresponding to each node; calculate the network situation awareness value of the network based on the clustering results, uplink traffic data and downlink traffic data; when the network situation awareness value is greater than the threshold, issue a security alarm.
[0097] The present application also provides a computer-readable storage medium, wherein the storage medium stores a computer program. When the computer program is executed by a processor, the following method steps are implemented:
[0098] Obtain the uplink traffic data and downlink traffic data of each node in the network; cluster the uplink traffic data and downlink traffic data for each node to obtain the clustering results corresponding to each node; calculate the network situation awareness value of the network based on the clustering results, uplink traffic data and downlink traffic data; when the network situation awareness value is greater than the threshold, issue a security alarm.
[0099] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, apparatus, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0100] The present invention is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0101] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0102] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0103] In a typical configuration, an electronic device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0104] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0105] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0106] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0107] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, devices, or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0108] The above are merely embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.
Claims
1. A network security situation awareness method, characterized in that: The method comprises: Obtain uplink and downlink traffic data of each node in the network; For each of the nodes, clustering the uplink traffic data and the downlink traffic data respectively to obtain a clustering result corresponding to each of the nodes; Calculating a network situation awareness value of the network according to the clustering result, the uplink traffic data, and the downlink traffic data; When the network situation awareness value is greater than a threshold, a security alarm is issued; Calculating the network situation awareness value of the network according to the clustering result, the uplink traffic data, and the downlink traffic data includes: For each of the nodes, calculating a first product of the number of data elements in each data class and the security weight of the corresponding node, and a second product of the average relevance of each data class and the contribution of the corresponding node; summing the first product and the second product to obtain a first sum value; Calculating the variance of the time parameters of the uplink data and the downlink data having the same data packet identifier; Calculating a ratio of the first sum value to the variance, and superimposing the ratios to obtain a network situation awareness value of each node; The network situation awareness value of each node is superimposed to obtain the network situation awareness value of the network.
2. The method according to claim 1, characterized in that The clustering of the uplink traffic data and the downlink traffic data respectively includes: Executing a loop process until all data elements in the uplink traffic data or the downlink traffic data are classified; The cycle process includes: Selecting a central data element from unclassified data elements of the uplink traffic data or the downlink traffic data, and using the central data element as the center of a data class; Selecting a target data element from unclassified data elements of the uplink traffic data or the downlink traffic data; Calculating the correlation between the target data element and the central data element; determining a maximum value and a minimum value from among said correlations; The target data element corresponding to the maximum value is classified into the data class where the central data element is located, and the target data element corresponding to the minimum value is used as a new unclassified central data element.
3. The method according to claim 2, characterized in that Calculating the relevance between the target data element and the central data element includes: Determining the security weight of the node where the central data element is located; Calculating a first probability that a central data element is associated with the target data element; calculating a second probability that a central data element is associated with the target data element; Calculating the similarity of the source addresses between the central data element and the target data element; Calculating the product of the security weight, the first probability, the second probability, and the similarity to obtain the correlation; The calculating a first probability associated with the central data element and the target data element comprises: Sorting the uplink traffic data or the downlink traffic data from early to late according to arrival time to obtain an uplink data sequence or a downlink data sequence; Calculating a first arrival time difference between the arrival time of the central data element and the arrival time of the data element that precedes the central data element in sorting order, and using the first arrival time difference as a first value of the time interval attribute of the central data element; Calculating a second arrival time difference between the arrival time of the target data element and the arrival time of the data element that precedes the target data element in sorting order, and using the second arrival time difference as a second value of the time interval attribute of the target data element; Calculating the first probability according to the first value, the second value, and an average of the values of the time interval attributes of all data elements in the uplink traffic data; or according to the first value, the second value and the average value of the time interval attributes of all data elements in the downstream traffic data; Calculating a second probability associated with the central data element and the target data element includes: Calculating a difference between the data amount of the central data element and the data amount of the target data element and a first ratio; Selecting the one with smaller data volume from the central data element and the target data element as the target data volume; A product of a second ratio of the difference to the target data amount and the first ratio is calculated as the second probability.
4. The method according to claim 3, characterized in that Determining the security weight of the node where the central data element is located includes: determining a network topology of the network; Determining the degree of the node where the central data element is located based on the network topology; The security weight is obtained by calculating the product of a predefined security level of the node where the central data element is located and the degree of the node.
5. The method according to claim 3, characterized in that The calculating the similarity of the source addresses between the central data element and the target data element includes: Starting from the leftmost decimal number of the source address, compare the values of the central data element and the target data element at the corresponding position in sequence to find the position of the first different decimal number; The similarity of the source address between the central data element and the target data element is calculated based on the value of the position where the first different decimal number is located.
6. A network security situation awareness device, characterized in that: The device comprises: An acquisition module is used to obtain uplink and downlink traffic data of each node in the network; A clustering module, configured to cluster the uplink traffic data and the downlink traffic data for each of the nodes, respectively, to obtain a clustering result corresponding to each of the nodes; A calculation module, configured to calculate a network situation awareness value of the network based on the clustering result, the uplink traffic data, and the downlink traffic data; An alarm module is used to issue a security alarm when the network situation awareness value is greater than a threshold; In the calculation module, calculating the network situation awareness value of the network according to the clustering result, the uplink traffic data, and the downlink traffic data includes: For each of the nodes, calculating a first product of the number of data elements in each data class and the security weight of the corresponding node, and a second product of the average relevance of each data class and the contribution of the corresponding node; summing the first product and the second product to obtain a first sum value; Calculating the variance of the time parameters of the uplink data and the downlink data having the same data packet identifier; Calculating a ratio of the first sum value to the variance, and superimposing the ratios to obtain a network situation awareness value of each node; The network situation awareness value of each node is superimposed to obtain the network situation awareness value of the network.
7. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus; wherein the processor, the communication interface and the memory communicate with each other through the bus; the memory is used to store computer programs; the processor is used to execute the programs stored in the memory to implement the steps of the network security situation awareness method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Network security early warning method and device based on situation awareness
CN111342988A