Network security situation scoring method, device, electronic device and storage medium
By using the first network security situation rating model to extract part of the data for analysis in network security situation awareness, and using the second network security situation rating model to evaluate the results, the problem of slow prediction of network security situation cognition in the prior art is solved, and a fast and accurate network security situation rating is achieved.
Patent Information
- Application Number
- CN202211539022.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-02
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2042-12-02
AI Technical Summary
In the prior art, the large amount of data for network security situation awareness and prediction has led to slow calculation speed of prediction models, and the prediction results cannot be obtained in time, and there is a lack of fast and accurate network security situation scoring methods.
By collecting current network data and inputting the pre-trained first network security situation scoring model, extracting some data for analysis, and obtaining the network security situation scoring. In addition, the second network security situation scoring model is used to evaluate the scoring results of the first model to ensure the accuracy of the scoring results.
It realizes the rapid and accurate completion of network security situation scores, reduces the amount of computing, improves the computing speed, improves the efficiency of network security situation scores, and ensures the accuracy of the scoring results.
Smart Images

Figure CN116015728B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to the field of information processing technology, and in particular to a network security situation scoring method, device, electronic device, and storage medium. Background Art
[0002] Cybersecurity situational awareness and prediction is an environment-based, dynamic, and holistic ability to understand security risks. It is based on security big data and is a way to improve the ability to discover, identify, understand, analyze, and respond to security threats from a global perspective. It aims to obtain, understand, display, and predict the continuation of recent development trends of security factors that can cause changes in network situations in large-scale network environments, and then make security-related decisions and actions. To achieve cybersecurity situational awareness and prediction, it is necessary to use existing real-time or quasi-real-time detection technologies, and at the same time, to discover abnormal behaviors through longer data analysis.
[0003] In related technologies, neural network models are usually used for network security situation awareness and prediction. However, due to the large amount of data faced by network security situation awareness and prediction, the prediction models in related technologies still have problems such as local minimization and slow convergence speed, which ultimately leads to slow calculation speed and inability to obtain prediction results in a timely manner.
[0004] It can be seen that there is an urgent need for a network security situation scoring method to quickly and accurately complete the network security situation scoring. Summary of the invention
[0005] The embodiments of the present invention provide a network security situation scoring method, device, electronic device and storage medium to solve the problems existing in the related technologies and quickly and accurately complete the network security situation scoring.
[0006] A first aspect of an embodiment of the present invention provides a network security situation scoring method, the method comprising:
[0007] Collect current network data;
[0008] Inputting the current network data into a pre-trained first network security situation scoring model;
[0009] Extracting a portion of the current network data from the current network data by using the first network security situation scoring model, and analyzing the extracted portion of the current network data to obtain a network security situation score corresponding to the current network data;
[0010] The first network security situation scoring model learns the correspondence between a portion of network data and a network security situation score. During the training process of the first network security situation scoring model, its scoring result is evaluated by a pre-trained second network security situation scoring model. The second network security situation scoring model learns the correspondence between the complete network data and the network security situation score, and the portion of network data is extracted from the complete network data.
[0011] Optionally, the training step of the first network security situation scoring model includes:
[0012] Inputting the training data into the preset model and the second network security situation scoring model respectively;
[0013] Extracting a portion of training data from the training data using the preset model, and analyzing the extracted portion of training data to obtain a first network security situation score corresponding to the training data;
[0014] Analyzing the training data using the second network security situation scoring model to obtain a second network security situation score;
[0015] Using the second network security situation score and the first network security situation score, evaluating the preset model;
[0016] If the assessment is qualified, the preset model is used as the first network security situation scoring model.
[0017] Optionally, it also includes:
[0018] If the assessment is unqualified, adjusting the model parameters of the preset model, inputting the training data into the adjusted preset model, and obtaining a third network security situation score corresponding to the training data;
[0019] The adjusted preset model is evaluated using the second network security situation score and the third network security situation score.
[0020] Optionally, extracting a portion of training data from the training data by using the preset model includes:
[0021] Sampling the training data through the preset model;
[0022] The adjusting of the model parameters of the preset model includes:
[0023] The sampling parameters of the preset model are adjusted, and the sampling parameters at least include: sampling frequency and sampling amount.
[0024] Optionally, the adjusting the model parameters of the preset model includes:
[0025] The data analysis dimension of the preset model is adjusted, and the data analysis dimension at least includes: analysis according to network equipment and analysis according to time.
[0026] Optionally, extracting a portion of training data from the training data by using the preset model includes:
[0027] Eliminating redundant data according to the redundancy rule and extracting the remaining data as part of the training data; said adjusting the model parameters of the preset model includes:
[0028] The redundancy rule is adjusted.
[0029] Optionally, the method further includes: when the network security situation score corresponding to the current network data obtained by the first network security situation scoring model exceeds a preset range, using the second network security situation scoring model to analyze the current network data to obtain a network security situation score corresponding to the current network data.
[0030] A second aspect of an embodiment of the present invention provides a network security situation scoring device, the device comprising:
[0031] The device comprises:
[0032] Collection module, used to collect current network data;
[0033] An input module, used for inputting the current network data into a pre-trained first network security situation scoring model;
[0034] A first scoring module, configured to extract a portion of the current network data from the current network data by using the first network security situation scoring model, and analyze the extracted portion of the current network data to obtain a network security situation score corresponding to the current network data;
[0035] The first network security situation scoring model learns the correspondence between a portion of network data and a network security situation score. During the training process of the first network security situation scoring model, its scoring result is evaluated by a pre-trained second network security situation scoring model. The second network security situation scoring model learns the correspondence between the complete network data and the network security situation score, and the portion of network data is extracted from the complete network data.
[0036] Optionally, the training step of the first network security situation scoring model includes:
[0037] Inputting the training data into the preset model and the second network security situation scoring model respectively;
[0038] Extracting a portion of training data from the training data using the preset model, and analyzing the extracted portion of training data to obtain a first network security situation score corresponding to the training data;
[0039] Analyzing the training data using the second network security situation scoring model to obtain a second network security situation score;
[0040] Using the second network security situation score and the first network security situation score, evaluating the preset model;
[0041] If the assessment is qualified, the preset model is used as the first network security situation scoring model.
[0042] Optionally, also include:
[0043] If the assessment is unqualified, adjusting the model parameters of the preset model, inputting the training data into the adjusted preset model, and obtaining a third network security situation score corresponding to the training data;
[0044] The adjusted preset model is evaluated using the second network security situation score and the third network security situation score.
[0045] Optionally, extracting a portion of training data from the training data by using the preset model includes:
[0046] Sampling the training data through the preset model;
[0047] The adjusting of the model parameters of the preset model includes:
[0048] The sampling parameters of the preset model are adjusted, and the sampling parameters at least include: sampling frequency and sampling amount.
[0049] Optionally, the adjusting the model parameters of the preset model includes:
[0050] The data analysis dimension of the preset model is adjusted, and the data analysis dimension at least includes: analysis according to network equipment and analysis according to time.
[0051] Optionally, extracting a portion of training data from the training data by using the preset model includes:
[0052] Eliminating redundant data according to the redundancy rule and extracting the remaining data as part of the training data; said adjusting the model parameters of the preset model includes:
[0053] The redundancy rule is adjusted.
[0054] Optionally, the device further comprises:
[0055] The second scoring module is used to use the second network security situation scoring model to analyze the current network data to obtain the network security situation score corresponding to the current network data when the network security situation score corresponding to the current network data obtained by the first network security situation scoring model exceeds a preset range.
[0056] A third aspect of an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps in the method described in the first aspect of the present invention.
[0057] A fourth aspect of an embodiment of the present invention provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executed, implements the steps in the method described in the first aspect of the present invention.
[0058] In an embodiment of the present invention, a portion of the current network data is extracted from the current network data through a first network security situation scoring model, and the extracted portion of the current network data is analyzed to obtain a network security situation score corresponding to the current network data. Therefore, there is no need to analyze the current network data in full, only extract part of the current network data for analysis, and obtain the corresponding network security situation score, thereby reducing the budget, improving the computing speed, and improving the efficiency of network security situation scoring. In addition, the first network security situation scoring model provided in an embodiment of the present invention evaluates its scoring results through a second network security situation scoring model during the training process, and the second network security situation scoring model learns the corresponding relationship between the complete network data and the network security situation score. Therefore, after the evaluation of the second network security situation scoring model, the first network security situation scoring model finally trained can accurately obtain the network security situation score. Furthermore, in an embodiment of the present invention, through the first network security situation scoring model, the network security situation score corresponding to the current network data can be quickly and accurately analyzed. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative labor.
[0060] Figure 1 is a flow chart of a network security situation scoring method according to an embodiment of the present invention;
[0061] Figure 2 It is a flow chart of the training steps of a first network security situation scoring model in a network security situation scoring method according to an embodiment of the present invention;
[0062] Figure 3 It is a flow chart of the training steps of a first network security situation scoring model in another network security situation scoring method according to an embodiment of the present invention;
[0063] Figure 4 It is a flow chart of the training steps of a first network security situation scoring model in a network security situation scoring method according to an embodiment of the present invention;
[0064] Figure 5 is a flow chart of another network security situation scoring method according to an embodiment of the present invention;
[0065] Figure 6 It is a structural block diagram of a network security situation scoring device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0066] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the present invention is further described in detail below with reference to the accompanying drawings and specific embodiments.
[0067] In an embodiment of the present invention, in order to improve the efficiency of network security situation scoring, it is proposed to extract current network data through a first network security situation scoring model, analyze a part of the extracted current network data, and obtain a network security situation score, thereby reducing the amount of calculation and improving the calculation speed. In addition, in order to ensure the accuracy of the network security situation score, an embodiment of the present invention proposes to use a trusted network (a second network security situation scoring model that has learned the correspondence between the complete network data and the network security situation score) to evaluate the first network security situation scoring model during its training process to ensure the accuracy of its scoring result.
[0068] Specifically, refer to Figure 1 , shows a flow chart of a network security situation scoring method according to an embodiment of the present invention. The network security situation scoring method provided by the embodiment of the present invention may include the following steps:
[0069] S101, collecting current network data.
[0070] In the embodiment of the present invention, the current network data may include: information data such as node information, protection information, topology information, flow information, alarm information, configuration information, etc. in the network.
[0071] S102: Input the current network data into a pre-trained first network security situation scoring model.
[0072] Specifically, in an embodiment of the present invention, the first network security situation scoring model may be an Elman neural network model.
[0073] The Elman neural network is divided into four layers, including: input layer, hidden layer, output layer and receiving layer; wherein the nodes of the input layer play a role in signal transmission, the nodes of the output layer play a role in linear weighting, the activation function of the hidden layer selects a linear or nonlinear function, and the receiving layer plays a role in a delay operator, which is used to memorize the output value of the hidden layer at the previous moment and return it to the input layer.
[0074] S103: extracting a portion of current network data from the current network data by using the first network security situation scoring model, and analyzing the extracted portion of current network data to obtain a network security situation score corresponding to the current network data.
[0075] In the embodiment of the present invention, the collected network data can be cleaned preprocessed, cleaned and analyzed at the input layer of the first network security situation scoring model, and the obtained preliminary situation prediction results can be output to the hidden layer of the first network security situation scoring model. Specifically, cleaning mainly includes data dimensionality reduction and cluster analysis; situation analysis mainly includes association rule mining and preliminary situation prediction based on the time dimension.
[0076] In an embodiment of the present invention, the first network security situation scoring model learns the correspondence between a portion of network data and a network security situation score. During the training process of the first network security situation scoring model, its scoring result is evaluated by a pre-trained second network security situation scoring model. The second network security situation scoring model learns the correspondence between the complete network data and the network security situation score, and the portion of network data is extracted from the complete network data.
[0077] In the embodiment of the present invention, since the second network security situation scoring model has learned the corresponding relationship between the complete network data and the network security situation score, the scoring result output by the second network security situation scoring model can be regarded as a credible result. During the training process of the model, the second network security situation scoring model and the first network security situation scoring model are used to analyze the same set of training data, and the first network security situation scoring model is evaluated according to the degree of difference between the scoring results output by the two until the degree of difference between the scoring result output by the first network security situation scoring model and that of the second network security situation scoring model meets expectations.
[0078] In the embodiment of the present invention, in order to facilitate the first network security situation scoring model to perform network security situation scoring, numerical values are used to quantitatively describe the four levels of network security status levels. The scoring value corresponding to level 1 can be set to 0-0.2, the scoring value corresponding to level 2 can be set to 0.2-0.5, the scoring value corresponding to level 3 can be set to 0.5-0.8, and the scoring value corresponding to level 4 can be set to 0.8-1.
[0079] Therefore, the first network security situation scoring model can analyze the current network data and output a network security situation score between 0 and 1.
[0080] In the embodiment of the present invention, level 1 represents the security level, specifically referring to the fact that the entire network is not subject to or is subject to slight network security threats, and the operation of the entire network is normal; level 2 represents a mild danger level, specifically referring to the fact that network threats such as viruses and attacks are active to a certain extent, the possibility of network failure is high, and the operation of the entire network is affected; level 3 represents moderate danger, specifically referring to the fact that network attacks, viruses and other activities are constantly increasing, and even cause network service interruptions or endanger key network infrastructure, and the operation of the entire network is seriously damaged; level 4 indicates that large-scale viruses or attacks occur in the network, specifically referring to the fact that the activity of malicious codes reaches the highest level, a large number of high-level network security incidents occur, the network operation is more seriously damaged, and the entire network is paralyzed.
[0081] Reference Figure 2 , shows a flow chart of the training steps of a first network security situation scoring model in a network security situation scoring method according to an embodiment of the present invention. The training steps of the first network security situation scoring model in the network security situation scoring method provided by the embodiment of the present invention include:
[0082] S201, inputting training data into a preset model and the second network security situation scoring model respectively.
[0083] In the embodiment of the present invention, the training data is historical network data that has been manually scored or graded.
[0084] In the embodiment of the present invention, the preset model may be an Elman neural network model.
[0085] In an embodiment of the present invention, the second network security situation scoring model can be a BP neural network model. Specifically, the second network security situation scoring model is composed of an input layer, a plurality of hidden layers and an output layer. The neurons between the layers form a fully interconnected connection, and there is no connection between the neurons in each layer. When a group of learning samples is supplied to the network, the activation value of the neuron is propagated from the input layer through the hidden layers to the output layer, and the neurons in the output layer obtain the output. Then, with the error between the expected output and the actual output as the reverse direction, the network connection weights are adjusted and corrected from the output layer through the hidden layers to the input layer. With the continuous correction of the weights according to the reverse propagation of the error, the adaptability of the network to the input mode continues to increase.
[0086] Therefore, after the second network security situation scoring model is pre-trained with a large amount of training data, the corresponding relationship between the complete network data and the network security situation scoring is learned, so that a reliable scoring result can be obtained based on the input network data through analysis.
[0087] S202: extract a portion of training data from the training data using the preset model, and analyze the extracted portion of training data to obtain a first network security situation score corresponding to the training data.
[0088] In an embodiment of the present invention, in order to reduce the amount of calculation and improve the calculation speed, the preset model can extract a part of the training data from the training data, and analyze the extracted part of the training data to obtain a first network security situation score corresponding to the training data.
[0089] In an embodiment of the present invention, the preset model can extract a part of the training data from the training data by a random sampling method, or extract a part of the main training data from the training data by principal component analysis, or eliminate redundant data from the training data by redundancy analysis to propose the remaining part of the training data.
[0090] S203: Analyze the training data using the second network security situation scoring model to obtain a second network security situation score.
[0091] In an embodiment of the present invention, during the training process of the model, the second network security situation scoring model and the first network security situation scoring model are used to analyze the same set of training data, and the first network security situation scoring model is evaluated according to the degree of difference in the scoring results output by the two, until the degree of difference between the scoring results output by the first network security situation scoring model and the second network security situation scoring model meets expectations.
[0092] S204: Evaluate the preset model using the second network security situation score and the first network security situation score.
[0093] Specifically, in the embodiment of the present invention, the difference calculation can be performed on the scoring results output by the second network security situation scoring model and the preset model. If the difference is less than the preset value, it means that the results output by the two models are not very different, and the evaluation result of the preset model is qualified. Otherwise, it means that the scoring result output by the preset model is wrong, and the evaluation result of the preset model is unqualified.
[0094] Specifically, the preset value may be a value preset in advance by a technician based on experience, for example, 10%.
[0095] S205: If the evaluation is qualified, use the preset model as the first network security situation scoring model.
[0096] In an optional implementation manner, the training step of the first network security situation scoring model in the network security situation scoring method provided in the embodiment of the present invention further includes:
[0097] S206, when the evaluation is unqualified, adjusting the model parameters of the preset model, inputting the training data into the adjusted preset model, and obtaining a third network security situation score corresponding to the training data.
[0098] Specifically, the model parameters may include: the number of nodes in the neural network input layer, the number of nodes in the hidden layer, the number of nodes in the output layer, the number of nodes in the receiving layer, etc.
[0099] S207: Evaluate the adjusted preset model using the second network security situation score and the third network security situation score.
[0100] In the embodiment of the present invention, the training data can be re-input into the adjusted preset model, re-trained, and the difference between the scoring results output by the adjusted preset model is continuously calculated until the difference between the scoring results output by the adjusted preset model and the scoring results output by the second network security situation scoring model is less than the preset value.
[0101] Reference Figure 3 , shows a flow chart of the training steps of a first network security situation scoring model in a network security situation scoring method according to an embodiment of the present invention. The training steps of the first network security situation scoring model in the network security situation scoring method provided by the embodiment of the present invention include:
[0102] S301, inputting training data into a preset model and the second network security situation scoring model respectively.
[0103] The step S301 is similar to the above step S201 and will not be described again.
[0104] S302: Sample the training data using the preset model, and analyze a portion of the sampled training data to obtain a first network security situation score corresponding to the training data.
[0105] In an embodiment of the present invention, the preset model can sample training data according to preset sampling parameters, and analyze a portion of the sampled training data to obtain a first network security situation score corresponding to the training data.
[0106] S303: Analyze the training data using the second network security situation scoring model to obtain a second network security situation score.
[0107] S304: Evaluate the preset model using the second network security situation score and the first network security situation score.
[0108] The steps S303-S304 are similar to the above steps S203-S204 and will not be described again.
[0109] S305, when the evaluation is unqualified, adjusting the sampling parameters of the preset model, inputting the training data into the adjusted preset model, and obtaining a third network security situation score corresponding to the training data.
[0110] The sampling parameters include at least: sampling frequency and sampling amount.
[0111] In an optional implementation, the step S305 further includes: adjusting the data analysis dimension of the preset model.
[0112] The data analysis dimensions include at least: analysis according to network devices and analysis according to time.
[0113] In an embodiment of the present invention, in the event of an unqualified evaluation, model-related parameters (including model parameters, sampling parameters, data analysis dimensions, etc.) may be adjusted to obtain an adjusted preset model, and the adjusted preset model may be retrained.
[0114] S306: Evaluate the adjusted preset model using the second network security situation score and the third network security situation score.
[0115] Reference Figure 4 , shows a flow chart of the training steps of a first network security situation scoring model in a network security situation scoring method according to an embodiment of the present invention. The training steps of the first network security situation scoring model in the network security situation scoring method provided by the embodiment of the present invention include:
[0116] S401, inputting training data into a preset model and the second network security situation scoring model respectively.
[0117] The step S401 is similar to the above step S201 and will not be described again.
[0118] S402, eliminating redundant data according to a redundancy rule, extracting remaining data as a portion of training data, and analyzing the extracted portion of current network data to obtain a first network security situation score corresponding to the training data.
[0119] In the embodiment of the present invention, redundant analysis is performed on the input data through redundant rules, redundant data is eliminated from the training data, a portion of the remaining training data is extracted and analyzed, and a first network security situation score corresponding to the training data is obtained. Therefore, when the preset model is adjusted later, the redundant rules can also be adjusted.
[0120] S403: Analyze the training data using the second network security situation scoring model to obtain a second network security situation score.
[0121] S404: Evaluate the preset model using the second network security situation score and the first network security situation score.
[0122] The steps S403-S404 are similar to the above steps S203-S204 and will not be described again.
[0123] S405, when the evaluation is unqualified, adjusting the redundant rules, inputting the training data into the adjusted preset model, and obtaining a third network security situation score corresponding to the training data.
[0124] S406: Evaluate the adjusted preset model using the second network security situation score and the third network security situation score.
[0125] Reference Figure 5 , shows a flow chart of a network security situation scoring method according to an embodiment of the present invention. The network security situation scoring method provided by the embodiment of the present invention may include the following steps:
[0126] S501, collecting current network data.
[0127] S502: Input the current network data into a pre-trained first network security situation scoring model.
[0128] S503: extract a portion of the current network data from the current network data by using the first network security situation scoring model, and analyze the extracted portion of the current network data to obtain a network security situation score corresponding to the current network data.
[0129] Among them, the first network security situation scoring model learns the correspondence between a part of network data and the network security situation score. During the training process of the first network security situation scoring model, its scoring result is evaluated by a pre-trained second network security situation scoring model. The second network security situation scoring model learns the correspondence between the complete network data and the network security situation score, and the part of network data is extracted from the complete network data.
[0130] The steps S501-S503 are similar to the above steps S101-S103 and will not be described again.
[0131] S504: When the network security situation score corresponding to the current network data obtained by the first network security situation scoring model exceeds a preset range, the second network security situation scoring model is used to analyze the current network data to obtain a network security situation score corresponding to the current network data.
[0132] In the embodiment of the present invention, since the first network security situation scoring model only learns the correspondence between a part of the network data and the network security situation score, its prediction result may be biased. Therefore, when its output result has obvious deviation (for example, the network security situation score exceeds the preset range), the output result of the first network security situation scoring model is regarded as an unreliable result, and the second network security situation scoring model can be used to analyze the current network data to obtain the network security situation score corresponding to the current network data.
[0133] The network security situation score exceeding the preset range may be: the network security situation score is less than 0.2 or the network security situation score is greater than 0.8.
[0134] Therefore, the network security situation scoring method provided in the embodiment of the present invention can quickly and accurately obtain the network security situation score corresponding to the current network data through the first network security situation scoring model, and can also use the second network security situation scoring model to obtain the accurate network security situation score corresponding to the current network data when there is an obvious deviation in the first network security situation scoring model.
[0135] Based on the same inventive concept, the embodiment of the present invention provides a network security situation scoring device, referring to Figure 6 , Figure 6Schematic diagram of a network security situation scoring device provided by an embodiment of the present invention. Figure 6 As shown, the device comprises:
[0136] The collection module 601 is used to collect current network data;
[0137] An input module 602 is used to input the current network data into a pre-trained first network security situation scoring model;
[0138] A first scoring module 603 is used to extract a portion of the current network data from the current network data by using the first network security situation scoring model, and analyze the extracted portion of the current network data to obtain a network security situation score corresponding to the current network data;
[0139] The first network security situation scoring model learns the correspondence between a portion of network data and a network security situation score. During the training process of the first network security situation scoring model, its scoring result is evaluated by a pre-trained second network security situation scoring model. The second network security situation scoring model learns the correspondence between the complete network data and the network security situation score, and the portion of network data is extracted from the complete network data.
[0140] Optionally, the training step of the first network security situation scoring model includes:
[0141] Inputting the training data into the preset model and the second network security situation scoring model respectively;
[0142] Extracting a portion of training data from the training data using the preset model, and analyzing the extracted portion of training data to obtain a first network security situation score corresponding to the training data;
[0143] Analyzing the training data using the second network security situation scoring model to obtain a second network security situation score;
[0144] Using the second network security situation score and the first network security situation score, evaluating the preset model;
[0145] If the assessment is qualified, the preset model is used as the first network security situation scoring model.
[0146] Optionally, also include:
[0147] If the assessment is unqualified, adjusting the model parameters of the preset model, inputting the training data into the adjusted preset model, and obtaining a third network security situation score corresponding to the training data;
[0148] The adjusted preset model is evaluated using the second network security situation score and the third network security situation score.
[0149] Optionally, extracting a portion of training data from the training data by using the preset model includes:
[0150] Sampling the training data through the preset model;
[0151] The adjusting of the model parameters of the preset model includes:
[0152] The sampling parameters of the preset model are adjusted, and the sampling parameters at least include: sampling frequency and sampling amount.
[0153] Optionally, the adjusting the model parameters of the preset model includes:
[0154] The data analysis dimension of the preset model is adjusted, and the data analysis dimension at least includes: analysis according to network equipment and analysis according to time.
[0155] Optionally, extracting a portion of training data from the training data by using the preset model includes:
[0156] Eliminating redundant data according to the redundancy rule and extracting the remaining data as part of the training data; said adjusting the model parameters of the preset model includes:
[0157] The redundancy rule is adjusted.
[0158] Optionally, the device further comprises:
[0159] The second scoring module is used to use the second network security situation scoring model to analyze the current network data to obtain the network security situation score corresponding to the current network data when the network security situation score corresponding to the current network data obtained by the first network security situation scoring model exceeds a preset range.
[0160] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0161] Based on the same inventive concept, an embodiment of the present invention provides a computer-readable storage medium on which a computer program is stored. When the program is executed by a processor, the steps in the network security situation scoring method described in any of the above embodiments are implemented.
[0162] Based on the same inventive concept, an embodiment of the present invention provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executed, implements the steps in the network security situation scoring method described in any of the above embodiments.
[0163] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0164] It will be appreciated by those skilled in the art that the embodiments of the present invention may be provided as methods, devices, or computer program products. Therefore, the embodiments of the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the embodiments of the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.
[0165] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0166] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing terminal device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0167] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device so that a series of operating steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable terminal device to implement the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0168] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present invention.
[0169] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or terminal device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or terminal device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or terminal device including the elements.
[0170] The network security situation scoring method, device, electronic device and storage medium provided by the present invention are introduced in detail above. The principle and implementation mode of the present invention are explained by using specific examples in this article. The description of the above embodiments is only used to help understand the method and core idea of the present invention. At the same time, for those skilled in the art, according to the idea of the present invention, there will be changes in the specific implementation mode and application scope. In summary, the content of this specification should not be understood as limiting the present invention.
Claims
1. A network security situation scoring method, characterized in that: The method comprises: Collect current network data; Inputting the current network data into a pre-trained first network security situation scoring model; Extracting a portion of the current network data from the current network data by using the first network security situation scoring model, and analyzing the extracted portion of the current network data to obtain a network security situation score corresponding to the current network data, including: Implementing cleaning preprocessing, cleaning and situation analysis on the collected network data at the input layer of the first network security situation scoring model, and outputting the obtained preliminary situation prediction results to the hidden layer of the first network security situation scoring model; The first network security situation scoring model learns the correspondence between a portion of network data and a network security situation score. During the training process of the first network security situation scoring model, its scoring result is evaluated by a pre-trained second network security situation scoring model. The second network security situation scoring model learns the correspondence between the complete network data and the network security situation score, and the portion of network data is extracted from the complete network data.
2. The method according to claim 1, characterized in that The training steps of the first network security situation scoring model include: Inputting the training data into the preset model and the second network security situation scoring model respectively; Extracting a portion of training data from the training data using the preset model, and analyzing the extracted portion of training data to obtain a first network security situation score corresponding to the training data; Analyzing the training data using the second network security situation scoring model to obtain a second network security situation score; Using the second network security situation score and the first network security situation score, evaluating the preset model; If the assessment is qualified, the preset model is used as the first network security situation scoring model.
3. The method according to claim 2, characterized in that Also includes: If the assessment is unqualified, adjusting the model parameters of the preset model, inputting the training data into the adjusted preset model, and obtaining a third network security situation score corresponding to the training data; The adjusted preset model is evaluated using the second network security situation score and the third network security situation score.
4. The method according to claim 3, characterized in that Extracting a portion of training data from the training data by using the preset model includes: Sampling the training data through the preset model; The adjusting of the model parameters of the preset model includes: The sampling parameters of the preset model are adjusted, and the sampling parameters at least include: sampling frequency and sampling amount.
5. The method according to claim 3, characterized in that: The adjusting of the model parameters of the preset model includes: The data analysis dimension of the preset model is adjusted, and the data analysis dimension at least includes: analysis according to network equipment and analysis according to time.
6. The method according to claim 3, characterized in that: Extracting a portion of training data from the training data by using the preset model includes: Eliminating redundant data according to the redundancy rule and extracting the remaining data as part of the training data; said adjusting the model parameters of the preset model includes: The redundancy rule is adjusted.
7. The method according to any one of claims 1 to 6, characterized in that: The method also includes: when the network security situation score corresponding to the current network data obtained by the first network security situation scoring model exceeds a preset range, using the second network security situation scoring model to analyze the current network data to obtain a network security situation score corresponding to the current network data.
8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the steps of the network security situation scoring method described in any one of claims 1 to 7 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the network security situation scoring method described in any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Scoring model training method and electronic book scoring method and device
CN111737554A
Network security assessment method and system based on machine learning
CN114422269A