Video recognition-based network situation assessment method and device, equipment and storage medium

By performing feature recognition and security situation assessment on network video data, and utilizing kernel functions, density functions, and gradient calculations, the shortcomings of network security situation assessment in video tracking and recognition tasks are addressed, enabling real-time assessment and stable assurance of the overall network security situation.

CN116192422BActive Publication Date: 2026-04-14CHINA TELECOM CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-29
Publication Date
2026-04-14

AI Technical Summary

Technical Problem

In existing technologies, video tracking and recognition tasks cannot effectively assess the overall security posture of the network during operation, resulting in a lack of security guarantees.

Method used

By inputting network video data into a video recognition network for feature recognition, the video recognition result data is obtained. This data is then input into a network security situation assessment network for risk identification and security situation assessment. Kernel functions and density functions are used to calculate object contours and trajectories. Combined with gradient calculation and feature extraction, the indicators of network security situation assessment elements are determined and quantitatively analyzed to obtain a network security index.

Benefits of technology

It enables real-time assessment and protection of the overall network security situation in video tracking and recognition tasks, ensuring the stability and accuracy of video tracking and recognition tasks and improving network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116192422B_ABST
    Figure CN116192422B_ABST
Patent Text Reader

Abstract

The embodiment of the application relates to the technical field of network security, in particular to a network situation assessment method and device based on video recognition, equipment and storage medium, and aims to realize overall network security situation assessment when a video tracking and recognition task is executed. The method comprises the following steps: inputting network video data into a video recognition network; performing feature recognition on the network video data through the video recognition network to obtain video recognition result data; inputting the video recognition result data into a network security situation assessment network to obtain a network security situation assessment result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and more specifically, to a network situation assessment method, apparatus, device, and storage medium based on video recognition. Background Technology

[0002] Video tracking and recognition is a popular field today, playing a role in various business scenarios such as surveillance video recognition and animation recognition. In current technologies, video for video tracking and recognition is often acquired via the network. The security of network video needs to be guaranteed, and video tracking and recognition technology is frequently used in network services. Network video originates from multiple locations in cyberspace and is applied to various network services. Therefore, when performing network video tracking and recognition, an effective assessment and understanding of the overall network security situation is necessary. Current technologies typically assess network security only when the network is under attack, analyzing the attack to evaluate the network security situation. However, when performing video tracking and recognition tasks, the overall security of the network in which the task is performed is not considered.

[0003] Current technologies are relatively passive in assessing network security posture and cannot guarantee the overall network security while video tracking and identification tasks are being performed. Summary of the Invention

[0004] This application provides a network situation assessment method, apparatus, device, and storage medium based on video recognition, aiming to achieve overall network security situation assessment during the execution of video tracking and recognition tasks.

[0005] A first aspect of this application provides a network situation assessment method based on video recognition, the method comprising:

[0006] Input the online video data into the video recognition network;

[0007] The video recognition network is used to perform feature recognition on the network video data to obtain video recognition result data;

[0008] The video recognition result data is input into the network security situation assessment network to obtain the network security situation assessment result.

[0009] Optionally, before inputting the network video data into the video recognition network, the method further includes:

[0010] The network video data is input into the network security situation assessment network;

[0011] The network security situation assessment network is used to identify risks in the network video data, resulting in network video data with identified risks.

[0012] Optionally, the step of performing feature recognition on the network video data through the video recognition network to obtain video recognition result data includes:

[0013] Kernel function and density function calculations are performed on the network video data to determine the recognition windows of multiple objects in the network video data, and the network video data after kernel density calculation is obtained.

[0014] Gradient calculation is performed on the network video data after kernel density calculation to determine the window trajectory of the recognition window;

[0015] Based on multiple recognition windows in the network video data and the window trajectories of the recognition windows, feature recognition is performed on objects in the network video to obtain video recognition result data.

[0016] Optionally, inputting the video recognition result data into the network security situation assessment network to obtain the network security situation assessment result includes:

[0017] The relevant business networks for the video recognition result data are determined through the network security situation assessment network.

[0018] Based on the network characteristics of the relevant business networks, determine the relevant indicators of the network security situation assessment elements of the relevant business networks;

[0019] The network security situation assessment elements are analyzed to obtain the network security situation assessment results.

[0020] Optionally, the network security situation assessment elements include: vulnerability assessment, attack risk assessment, and asset and task assessment.

[0021] Optionally, the analysis of the network security situation assessment elements to obtain the network security situation assessment result includes:

[0022] The network security situation assessment elements are quantitatively calculated using an index quantification algorithm to obtain the index quantification values ​​of the network security situation assessment elements.

[0023] The weight of each indicator in the network security situation assessment elements is determined by the analytic hierarchy process.

[0024] Based on the quantitative values ​​of the indicators of the network security situation assessment elements and the weights of the indicators, the overall network security index is determined.

[0025] The cybersecurity situation assessment result is determined based on the cybersecurity index.

[0026] Optionally, the method further includes:

[0027] The network security situation assessment network is used to determine the extent to which the video recognition result data improves the relevant services related to the video recognition result data.

[0028] When the improvement level of the relevant business is negative, determine the video webpage corresponding to the video recognition result data;

[0029] Data interception is performed on the video webpage.

[0030] A second aspect of this application provides a network situation assessment device based on video recognition, the device comprising:

[0031] The video data input module is used to input network video data into the video recognition network;

[0032] The video recognition module is used to perform feature recognition on the network video data through the video recognition network to obtain video recognition result data;

[0033] The network security situation assessment module is used to input the video recognition result data into the network security situation assessment network to obtain the network security situation assessment result.

[0034] Optionally, before inputting the network video data into the video recognition network, the method further includes:

[0035] The network video data is input into the network security situation assessment network;

[0036] The network security situation assessment network is used to identify risks in the network video data, resulting in network video data with identified risks.

[0037] Optionally, the video recognition module includes:

[0038] The kernel density calculation submodule is used to calculate the kernel function and density function on the network video data, determine the recognition window of multiple objects in the network video data, and obtain the network video data after kernel density calculation.

[0039] The gradient calculation submodule is used to perform gradient calculation on the network video data after kernel density calculation to determine the window trajectory of the recognition window;

[0040] The recognition result acquisition submodule is used to perform feature recognition on objects in the network video based on multiple recognition windows in the network video data and the window trajectory of the recognition windows, and obtain video recognition result data.

[0041] Optionally, the network security situation assessment module includes:

[0042] The relevant business network determination submodule is used to determine the relevant business networks of the video recognition result data through the network security situation assessment network;

[0043] The relevant indicator determination submodule is used to determine the relevant indicators of the network security situation assessment elements of the relevant business network based on the network characteristics of the relevant business network.

[0044] The evaluation result acquisition submodule is used to analyze the network security situation assessment elements and obtain the network security situation assessment results.

[0045] Optionally, the network security situation assessment elements include: vulnerability assessment, attack risk assessment, and asset and task assessment.

[0046] Optionally, the submodule for obtaining the evaluation results includes:

[0047] The index quantification submodule is used to perform quantitative calculations on the network security situation assessment elements through index quantification algorithms to obtain the index quantification values ​​of the network security situation assessment elements.

[0048] The hierarchical analysis submodule is used to determine the index weight of each assessment element in the network security situation assessment elements through the hierarchical analysis method.

[0049] The network security index determination submodule is used to determine the overall network security index based on the quantitative values ​​of the indicators of the network security situation assessment elements and the indicator weights.

[0050] The security situation assessment result acquisition submodule is used to determine the security situation assessment result based on the cybersecurity index.

[0051] Optionally, the device further includes:

[0052] The business improvement determination submodule is used to determine, through the network security situation assessment network, the degree of improvement that the video recognition result data brings to the relevant businesses related to the video recognition result data;

[0053] The video webpage determination submodule is used to determine the video webpage corresponding to the video recognition result data when the improvement level of the related service is negative.

[0054] The data interception submodule is used to intercept data from the video webpage.

[0055] A third aspect of this application provides a readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps described in the first aspect of this application.

[0056] A fourth aspect of this application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the steps of the method described in the first aspect of this application.

[0057] The network situation assessment method based on video recognition provided in this application involves inputting network video data into a video recognition network; performing feature recognition on the network video data through the video recognition network to obtain video recognition result data; and inputting the video recognition result data into a network security situation assessment network to obtain a network security situation assessment result. In this method, executing the network video tracking and recognition task through the video recognition network effectively ensures the accuracy of the video tracking and recognition task. Receiving the video recognition result data through the network security situation assessment network, and combining the video recognition result data, performs a network security situation assessment of the overall network environment in which the video tracking and recognition task takes place, obtaining a network security situation assessment result. This allows for an effective grasp of the overall network security situation during the network video tracking and recognition task, ensuring the stable execution of the video tracking and recognition task from a network security perspective. Attached Figure Description

[0058] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments of this application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0059] Figure 1 This is a flowchart of a network situation assessment method based on video recognition proposed in an embodiment of this application;

[0060] Figure 2 This is a schematic diagram of a network situation assessment device based on video recognition proposed in an embodiment of this application. Detailed Implementation

[0061] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0062] refer to Figure 1 , Figure 1 This is a flowchart of a network situation assessment method based on video recognition proposed in an embodiment of this application. Figure 1 As shown, the method includes the following steps:

[0063] S11: Input the network video data into the video recognition network.

[0064] In this embodiment, the network video data is video downloaded from various links on the Internet, and the video recognition network is a neural network specifically designed to identify objects within the network video. The video recognition network includes: a kernel function and density function calculation module for identifying the contours of objects in the video and adding recognition windows to each object; a density gradient estimation module for determining the movement trajectory of the recognition windows for each object; and a feature extraction module for extracting features from the objects within each window.

[0065] In this embodiment, the network video file is downloaded to the local machine via the Internet, and the collected network video file, i.e., network video data, is input into the video recognition network.

[0066] For example, online videos can be news videos, movie or TV show clips, etc. Video recognition networks can be image feature extraction networks such as CNN networks; there are no restrictions here.

[0067] S12: Through the video recognition network, feature recognition is performed on the network video data to obtain video recognition result data.

[0068] In this embodiment, the video recognition result data is the data obtained by identifying and tagging various objects in the video through a video network. The video recognition result data indicates the movement trajectory of each object in the video, the name of the object, and the relevant network information of the object.

[0069] In this embodiment, after receiving network video data, the video recognition network performs kernel function and density function calculations on the network video data to obtain the approximate outline of the objects in the network video and the window area of ​​the objects. Then, through density gradient calculation, the movement trajectory of the objects in the network video is obtained. Then, through the feature extraction module, the features of the objects in the video are extracted. Based on the features of the objects, the objects are classified and identified to obtain the specific types of the objects. Each object in the video is identified and labeled.

[0070] For example, the network video is a surveillance video of a parking lot. The video recognition network performs kernel function and density function calculations on the video data, adds windows to people and cars in the video, and then calculates the density gradient to obtain the movement trajectory of objects (people, cars, and other objects) in the video. Each object in the video is then labeled accordingly. The final video recognition result data is marked with the name of each object in the video, and you can also view relevant information about the object, such as: vehicle (XX brand, XX model car).

[0071] S13: Input the video recognition result data into the network security situation assessment network to obtain the network security situation assessment result.

[0072] In this embodiment, the network security situation assessment network is used to assess the overall network environment for video tracking and recognition tasks. This network can identify the relevant services and networks associated with the video recognition result data, and these networks are also part of the overall network. The network security situation assessment results demonstrate the current security status of the overall network, indicating whether it is in a secure or dangerous state.

[0073] In this embodiment, after obtaining the video recognition result data, the video recognition result data is input from the video recognition network into the network security situation assessment network. The network security situation assessment network determines the relevant service network of the video result data, and then determines the service for which the video result data is used. Based on different services, the network security situation assessment elements can be determined, and then the overall network security situation can be quantitatively assessed. Based on the results of the quantitative assessment, the current overall network security situation is determined.

[0074] For example, the video recognition results of parking lot surveillance videos are input into the network security situation assessment network. The network security situation assessment network determines that the relevant business of the video recognition results data is parking lot charging, parking management, personnel trajectory tracking, etc., and then determines the relevant business networks as parking lot charging network, personnel trajectory tracking network, parking management network, etc. Based on the nature of the network, the elements of network security situation assessment are determined, and the index values ​​of each element are calculated to obtain the overall network security situation assessment result.

[0075] In this embodiment, while performing the video tracking and recognition task, the network security situation of the network where the task is located and the related business network is assessed, ensuring that the overall network where the video tracking and recognition task is located is safe and reliable. From the perspective of network security, this ensures the stable operation of the video tracking and recognition task and related services. The real-time and accurate assessment of the overall network security situation helps relevant personnel to have a comprehensive understanding of the network security situation.

[0076] In another embodiment of this application, the method further includes, before inputting video collected via a network into a video recognition network:

[0077] S21: Input the network video into the network security situation assessment network.

[0078] S22: Through the network security situation assessment network, the video files of the network video are risk-identified to obtain the network video after risk identification.

[0079] In this embodiment, the security situation assessment network can also perform risk identification on network videos downloaded from the network. By scanning the network video data and performing risk identification on the network video data, abnormal data in the network video data can be identified, and abnormal data can be deleted to obtain the network video after risk identification.

[0080] For example, the security posture assessment network receives multiple network video data, scans these multiple network video data, and finds abnormal data in one of the network video data. This data may be virus data or garbled data. The abnormal data is then deleted, and the remaining video data is sent to the video recognition network.

[0081] In this embodiment, the video data was risk-identified through a network security situation assessment network, ensuring that the video recognition network would not receive abnormal data, thereby guaranteeing the security of the entire business system.

[0082] In another embodiment of this application, the step of performing feature recognition on the network video data through the video recognition network to obtain video recognition result data includes:

[0083] S31: Perform kernel function and density function calculations on the network video data to determine the recognition windows of multiple objects in the network video data, and obtain the network video data after kernel density calculation.

[0084] In this embodiment, the calculation of the kernel function and density function, also known as kernel density estimation (Parzen window technique), can determine the contours of objects in an image during a network video task, and then add recognition windows to the objects in the image. The recognition window is a bounding box that can select objects in the video, and the objects will not exceed the bounding box of the recognition window. The network video data after kernel density calculation contains the contour windows of each object.

[0085] In this embodiment, after the video recognition network receives the network video data, it determines the recognition window of all objects in the network video by calculating the kernel function and kernel density, and obtains the video recognition result data.

[0086] For example, the zero-point drift algorithm can be used to calculate the kernel function and density function of network video data. Let R... d There are n sampling data points x in the 4-dimensional space R4. i Let i = 1, 2, ..., n. The multivariate kernel function estimate for point x is given by the kernel function K(x) and the symmetric positive definite bandwidth matrix H of d×d.

[0087]

[0088] K H =||H||K(H 0,5 x) (2)

[0089] The kernel function K(x) is a bounded function with compact support that satisfies the following equation:

[0090]

[0091]

[0092] In the formula, δ K It is a constant. A multivariate kernel function can be synthesized from a symmetric univariate kernel function K1(x) using the following two methods:

[0093]

[0094] or

[0095]

[0096] K S (x) is obtained through the product of radial basis functions; K s (x) through space R d In the rotational composition, K1(x) is radially symmetric. Coefficients The integral of K(x) is guaranteed to be 1.

[0097] We are more interested in kernel functions that satisfy the following radial symmetry property:

[0098] K(x)=c k,d k(||x|| 2 (7)

[0099] Here, k(x) is called the contour function of the kernel function, and K(x) can be completely determined as long as the case of X≥0 is defined. k,d k is a strictly normal quantity that satisfies the integral normalization of K(x).

[0100] Using a fully parameterized variable H increases the complexity of the estimation. In practice, the bandwidth matrix H is chosen as a diagonal matrix. Or proportional to the identity matrix H = h 2 I. The most obvious advantage of the latter case is that it only requires a bandwidth parameter greater than 0. When the bandwidth matrix is ​​defined using only one bandwidth parameter, the density estimate based on the kernel function becomes the well-known formula below.

[0101]

[0102] The performance of kernel density estimation is measured by the mean squared error between the true density value and its estimate, with the integration range covering the entire domain. However, in practice, only the asymptotic estimate of the mean squared error (AMISE) can be calculated. Under the asymptotic condition, the bandwidth approaches zero at a much slower rate as the number of data samples approaches infinity. The Epanechnikov kernel function is defined as follows.

[0103]

[0104] Where c is the volume of the d-dimensional spherical unit. The contour function of KE(x) is

[0105] other

[0106]

[0107] Regardless of whether additive or multiplicative multivariate kernel function construction methods are used, the AMISE measure tends to converge with respect to the Epanechnikov kernel function. It is important to note that the Epanechnikov contour function is not differentiable at its boundaries. The following contour function is an example:

[0108] The normal kernel function is defined as follows:

[0109]

[0110] In practical applications, the normal kernel function is often symmetrically truncated to obtain a finite defined interval.

[0111] These two kernel functions can meet most needs. The kernel density estimation is expressed using the contour function method.

[0112] The formula is rewritten in the following form:

[0113]

[0114] Many applications that require analysis of the feature space of a specific density f(x) essentially seek patterns in the kernel density. These patterns reside within the gradient. Of all the zero points.

[0115] The mean-shift algorithm in the above formula is used to calculate the kernel function and density. Compared with the traditional kernel density calculation method, it can more accurately determine the outline of objects in the video and add accurate recognition boxes to the objects in the video.

[0116] S32: Perform gradient calculation on the network video data after kernel density calculation to determine the window trajectory of the recognition window.

[0117] In this embodiment, the trajectory of objects in the video can be obtained through gradient calculation, thereby determining the window trajectory of the recognition window. The window trajectory is the movement trajectory of the window of an object in the network video.

[0118] In this embodiment, the video recognition network performs gradient calculation on the network video data after kernel density calculation, thereby determining the window trajectory of the recognition window in the network video data.

[0119] For example, the zero-point drift algorithm can be used to calculate the gradient of video data. Based on the linearization characteristics of the kernel density, the gradient estimator of the density function can be represented by the gradient of the density estimator.

[0120]

[0121] Define the following function:

[0122] g(x)=-k′(x) (15)

[0123] Assume that the derivative of the contour function exists for all x∈(0,∞). Now, using g(x) as the contour function, the kernel function G(x) can be defined as follows.

[0124] G(x) = c g,d g(||x|| 2 (16)

[0125] c g,d This is the corresponding normalization constant. The kernel function K(x) is also called the shadow function of G(x). Note that the Epanechnikov kernel function is the shadow of the uniform kernel function, which is a D-dimensional unit space. The normal kernel function and its shadow function have the same form.

[0126] Substituting g(x) into the gradient expression for the kernel density, we get

[0127]

[0128] In the formula, The condition that the value is positive satisfies all practically usable contour functions. The two product terms in the above equation are quite special. The first term is proportional to the density estimate at point x expressed by the kernel function G(x).

[0129]

[0130] The second term is the mean shift vector:

[0131]

[0132] It is the distance difference between the weighted mean of G(x) positions and the center x of the kernel window. Based on the definitions of these two terms, the gradient of the kernel density can be simplified to...

[0133]

[0134] The mean shift vector can be expressed as:

[0135]

[0136] The expression for the mean drift vector shows that at position x, the mean drift vector calculated by the kernel function G(x) is directly proportional to the normalized density gradient estimate obtained by the kernel function K(x), and inversely proportional to the density estimate at x calculated by the kernel function G(x). The mean drift vector always points in the direction of the maximum increase in density.

[0137] The above explanation of the mean-shift vector relies on intuition; the local mean vector points to the region where most points reside. Since the mean-shift vector is related to the local gradient estimate, it defines a path for estimating density values, eventually converging to a resting point according to a predetermined density function. The mean-shift algorithm continuously calculates the mean-shift vector *m*, shifting the window position of the kernel function G(x) by the mean-shift vector to ensure that G(x) converges to points where the gradient is 0. Normalizing the mean-shift vector according to the density estimate is a desirable feature. For low-density value regions of little interest in the feature space, the mean-shift algorithm uses a larger step size. Conversely, near local maxima, the step size is smaller, resulting in a more refined analysis. Therefore, the mean-shift algorithm is an adaptive gradient descent algorithm. It can be proven that when the contour function of the kernel function is a monotonically decreasing convex function, the mean-shift algorithm converges to the extreme point of the pattern after multiple iterations.

[0138] S33: Based on the multiple recognition windows in the network video and the window trajectory of the recognition windows, perform feature recognition on the objects in the network video to obtain video recognition result data.

[0139] In this embodiment, after determining the recognition windows and window trajectories of multiple objects in the network video, the feature extraction network is used to extract features of the objects in the recognition windows to obtain the features of each object in the recognition windows. Then, the objects are classified according to the features of each object to obtain video recognition result data.

[0140] For example, the feature extraction network can be an image extraction network such as a CNN network.

[0141] In this embodiment, the kernel density function and density gradient in the video data are calculated using the zero-point drift algorithm. The mean-shift algorithm is a pattern recognition algorithm, typically used in image segmentation. A local pattern is established for each image pixel, and then their convergent extrema are calculated using the mean-shift algorithm. The convergence points of the entire image are summarized and used as representative points of the image region, forming different segmentation regions. By controlling the width of the window function and the minimum number of pixels in the region, different segmentation results can be obtained. This determines the window position and size of objects in the network video data, as well as the trajectory of window movement, enabling the feature extraction network to more easily identify object features and increasing the accuracy of object recognition.

[0142] In another embodiment of this application, the step of inputting the video recognition result data into the network security situation assessment network to obtain the network security situation assessment result includes:

[0143] S41: Through the network security situation assessment network, determine the relevant business network of the video recognition result data.

[0144] In this embodiment, the network security situation assessment network is the network that performs an overall network security situation assessment of the network where the video tracking and recognition task is located and related networks. The related service networks for the video recognition result data refer to the network systems where the services related to the video recognition data reside.

[0145] In this embodiment, after obtaining the video recognition result data, the network security situation assessment network will query the relevant business information of the video result data in the system. The business information includes the type of business being executed, the network node executing the business, the execution efficiency of the business, and other relevant business information. Then, based on the relevant business information, the network structure, network nodes, network IP addresses, and other information of the network related to the video recognition result data will be determined.

[0146] For example, the video recognition result data of the parking lot monitoring video is input into the network security situation assessment network. The network security situation assessment network determines that the relevant business of the video recognition result data is parking lot charging, parking management, personnel trajectory tracking, etc., and then determines that the relevant business networks are parking lot charging network, personnel trajectory tracking network, parking management network, etc. Based on the network information of the business networks, it is determined that the parking lot charging network has 3 network nodes, the 3 network nodes are connected through a local area network, and one of the network nodes is connected to an external network, etc., and other relevant information of the parking lot charging network.

[0147] S42: Based on the network characteristics of the relevant business network, determine the relevant indicators of the network security situation assessment elements of the business-related network.

[0148] In this embodiment, the network characteristics of the relevant business network include its network structure, network function, and connection methods. Network security situation assessment elements include vulnerability assessment elements, attack risk assessment elements, and asset and task assessment elements.

[0149] In this embodiment, relevant indicators for network security situation assessment elements can be determined based on the specific needs of the business network. Vulnerability assessment elements mainly consider the vulnerability status of assets (software and hardware) in the business network, that is, the vulnerability of the network itself in the absence of attacks, including the scale of attacks the network can withstand, the number of attacks, and the extent of harm and loss that attacks would cause to the network. Attack risk assessment elements can be generated by viewing network alarm data and analyzing the correlation between attack event data collected by multiple security devices. Asset and task element assessment mainly selects from the perspectives of the business network's hardware capabilities, security protection capabilities, and actual load. It is necessary to consider whether the servers carried by the network can operate healthily, and whether the various node devices that make up the network can work normally and provide services to users in a timely manner, that is, the disaster recovery and stability of assets and tasks.

[0150] For example, relevant indicators for cybersecurity situation assessment elements could be vulnerability index, attack risk index, asset and workload index, etc.

[0151] S43: Analyze the network security situation assessment elements to obtain the network security situation assessment results.

[0152] In this embodiment, the network security situation assessment results reflect the overall security situation of the network where the video tracking and recognition task is located, that is, the level of network security.

[0153] In this embodiment, the steps for analyzing the network security situation assessment elements to obtain the network security situation assessment result include:

[0154] S43-1: The network security situation assessment elements are quantitatively calculated using an index quantification algorithm to obtain the index quantification values ​​of the network security situation assessment elements.

[0155] In this embodiment, after determining the assessment elements of network security situation, it is necessary to quantify the indicators of each assessment element to obtain the quantitative values ​​of the network security situation assessment elements.

[0156] For example, the algorithm for quantifying indicators can be selected according to the needs of the assessment and the specific assessment target. Taking the calculation of the cyber deception threat index as an example, in the indicator system, cyber deception practices have four indicators: target assets, harm, number of incidents, and erasure. Assume that within a set unit assessment time, the original vectors of the three indicators—target assets, harm, and erasure—are A(t) = {A1, A2, ..., A...} n} (twenty two)

[0157] B(t) = {B1, B1…B1} n} (twenty three)

[0158] C(t) = {C1, C2, ..., C} n} (twenty four)

[0159] Here, n represents the number of events. The target asset, hazard level, and number of events can be obtained by querying the alarm event database, while the removability is a static attribute.

[0160] The values ​​of the four key indicators during this period are:

[0161] Number of events: n;

[0162] Target asset:

[0163] Harmfulness:

[0164] Cleanability:

[0165] You can also quantify attribute values. For the number of events, use a threshold method; for other attributes, use maximum or minimum value methods.

[0166] S43-2: Determine the index weight of each assessment element in the network security situation assessment elements by using the hierarchical analysis method.

[0167] S43-3: Determine the overall network security index based on the quantitative values ​​of the network security situation assessment elements and the weights of the indicators.

[0168] In this embodiment, the hierarchical analysis method analyzes the indicators of each network security situation assessment element based on the network hierarchy.

[0169] In this embodiment, the weight of each evaluation element in the network security situation assessment is determined by the analytic hierarchy process (AHP). Then, based on the quantitative value of each evaluation element and its weight, the overall network security index is obtained.

[0170] As can be seen from the construction process of the cybersecurity indicator system, the overall cybersecurity is the result of the combined effect of various security indicators, and the weight of each indicator and sub-indicator on system security varies. Based on the principle of the Analytic Hierarchy Process (AHP), the cybersecurity indicator system includes a total cybersecurity index, cybersecurity indices for each dimension (vulnerability dimension index, attack threat dimension index, asset and task index), and influencing elements for each dimension (secondary and tertiary indicators). The influence weight of each target element at each level relative to a certain element at the next higher level is obtained using expert evaluation. Then, a weighted summation method is used to merge the final weights of each sub-target on the overall target. The total cybersecurity index is obtained by weighted summation of the various indicators of the cybersecurity elements.

[0171] For example, the Overall Cybersecurity Index (IC) is calculated from the Vulnerability Index (IF), Attack Risk Index (IV), and Assets and Tasks Index (IR), using the following formula:

[0172] IC = W F *IF+WV*I V +W R *IR (28)

[0173] Where W represents the weight of each index in the overall evaluation, satisfying ∑W1=1.

[0174] S43-4: Determine the network security situation assessment result based on the network security index.

[0175] In this embodiment, after obtaining the network security index, the network security situation assessment result can be determined based on the magnitude of the network security index.

[0176] For example, when the network security index is 1, the overall network is determined to be in a secure state; when the network security index is less than 1, the overall network is determined to be in a dangerous state.

[0177] In another scenario, based on the threat indices of various network threat events, the overall network threat index T is obtained using a predefined aggregation function within the indicator system.

[0178]

[0179] Where T(t) is the overall network threat index at the current moment. This indicates a weighted calculation of the threat index for various types of network threats at the current time.

[0180] Similarly, when the overall network threat index is 0, the overall network is in a safe state; when the overall network threat index is greater than 0, the overall network is in a dangerous state.

[0181] In this embodiment, the relevant business networks of the video recognition result data were identified, and the network security assessment elements were quantitatively calculated to obtain the overall network security index and network threat index, thereby making an accurate network security situation assessment.

[0182] In another embodiment of this application, the method further includes:

[0183] S51: Through the network security situation assessment network, determine the degree to which the video recognition result data improves the relevant services related to the video recognition result data.

[0184] In this embodiment, the network security situation assessment network determines the relevant services based on the video recognition result data, and obtains the degree of improvement of the relevant services, i.e., the execution speed of the relevant services, based on the execution speed of the relevant services after obtaining the video result data.

[0185] For example, if the network video data is a parking lot surveillance video, and the video recognition results accurately identify the information of each vehicle, then when the system calculates parking fees, the execution speed of the parking fee collection process will remain normal or unchanged. However, if the video recognition results do not accurately identify the information of each vehicle, the parking fee collection process will be slower or may result in errors, leading to a slower execution speed and a negative impact on the service.

[0186] S52: When the improvement level of the related service is negative, determine the video webpage corresponding to the video recognition result data.

[0187] S53: Intercept the video webpage.

[0188] In this embodiment, when the improvement of services related to video recognition result data is negative, the network security situation assessment network will search for the webpage corresponding to the video in the download records and intercept the video webpage data.

[0189] In this embodiment, when the video recognition result data leads to a negative improvement in related services, it may be that there is a problem with the source of the video, so the video of that webpage will no longer be acquired.

[0190] Furthermore, if the training results are unsatisfactory during the training of the video recognition model, it may lead to a negative impact on related businesses. In this case, the training result data of the video model, i.e., the webpage corresponding to the video recognition result data obtained during training, is identified. The webpage containing the video is then marked and its data is blocked. The training video is no longer obtained from that webpage. This ensures that the materials used to train the video recognition model are all high-quality videos, thus guaranteeing the training effect of the video recognition model from a network security perspective.

[0191] In this embodiment, when the video recognition result data has an adverse impact on related services, the source of video acquisition is detected and intercepted through the network security situational awareness network. This ensures that the entire network no longer acquires low-quality videos, thus guaranteeing the accuracy of video recognition and the security of the overall network from a network security perspective.

[0192] Based on the same inventive concept, one embodiment of this application provides a network situation assessment device based on video recognition. (Reference) Figure 2 , Figure 2 This is a schematic diagram of a network situation assessment device 200 based on video recognition according to an embodiment of this application. Figure 2 As shown, the device includes:

[0193] The video data input module 201 is used to input network video data into the video recognition network;

[0194] The video recognition module 202 is used to perform feature recognition on the network video data through the video recognition network to obtain video recognition result data;

[0195] The network security situation assessment module 203 is used to input the video recognition result data into the network security situation assessment network to obtain the network security situation assessment result.

[0196] Optionally, before inputting the network video data into the video recognition network, the method further includes:

[0197] The network video data is input into the network security situation assessment network;

[0198] The network security situation assessment network is used to identify risks in the network video data, resulting in network video data with identified risks.

[0199] Optionally, the video recognition module includes:

[0200] The kernel density calculation submodule is used to calculate the kernel function and density function on the network video data, determine the recognition window of multiple objects in the network video data, and obtain the network video data after kernel density calculation.

[0201] The gradient calculation submodule is used to perform gradient calculation on the network video data after kernel density calculation to determine the window trajectory of the recognition window;

[0202] The recognition result acquisition submodule is used to perform feature recognition on objects in the network video based on multiple recognition windows in the network video data and the window trajectory of the recognition windows, and obtain video recognition result data.

[0203] Optionally, the network security situation assessment module includes:

[0204] The relevant business network determination submodule is used to determine the relevant business networks of the video recognition result data through the network security situation assessment network;

[0205] The relevant indicator determination submodule is used to determine the relevant indicators of the network security situation assessment elements of the relevant business network based on the network characteristics of the relevant business network.

[0206] The evaluation result acquisition submodule is used to analyze the network security situation assessment elements and obtain the network security situation assessment results.

[0207] Optionally, the network security situation assessment elements include: vulnerability assessment, attack risk assessment, and asset and task assessment.

[0208] Optionally, the submodule for obtaining the evaluation results includes:

[0209] The index quantification submodule is used to perform quantitative calculations on the network security situation assessment elements through index quantification algorithms to obtain the index quantification values ​​of the network security situation assessment elements.

[0210] The hierarchical analysis submodule is used to determine the index weight of each assessment element in the network security situation assessment elements through the hierarchical analysis method.

[0211] The network security index determination submodule is used to determine the overall network security index based on the quantitative values ​​of the indicators of the network security situation assessment elements and the indicator weights.

[0212] The security situation assessment result acquisition submodule is used to determine the security situation assessment result based on the cybersecurity index.

[0213] Optionally, the device further includes:

[0214] The business improvement determination submodule is used to determine, through the network security situation assessment network, the degree of improvement that the video recognition result data brings to the relevant businesses related to the video recognition result data;

[0215] The video webpage determination submodule is used to determine the video webpage corresponding to the video recognition result data when the improvement level of the related service is negative.

[0216] The data interception submodule is used to intercept data from the video webpage.

[0217] Based on the same inventive concept, another embodiment of this application provides a readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps in the network situation assessment method based on video recognition as described in any of the above embodiments of this application.

[0218] Based on the same inventive concept, another embodiment of this application provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the steps of the network situation assessment method based on video recognition described in any of the above embodiments of this application.

[0219] As the device embodiment is basically similar to the method embodiment, the description is relatively simple, and relevant parts can be found in the description of the method embodiment.

[0220] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0221] Those skilled in the art will understand that embodiments of this application can be provided as methods, apparatus, or computer program products. Therefore, embodiments of this application can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of this application can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0222] This application describes embodiments with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0223] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0224] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0225] Although preferred embodiments of the present application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present application.

[0226] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.

[0227] The network situation assessment method, apparatus, device, and storage medium based on video recognition provided in this application have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the method and its core ideas. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A network situation assessment method based on video recognition, characterized in that, The method includes: Input the online video data into the video recognition network; The video recognition network is used to perform feature recognition on the network video data to obtain video recognition result data; The video recognition result data is input into the network security situation assessment network to obtain the network security situation assessment result; The step of inputting the video recognition result data into the network security situation assessment network to obtain the network security situation assessment result includes: The relevant business networks for the video recognition result data are determined through the network security situation assessment network. Based on the network characteristics of the relevant business networks, determine the relevant indicators of the network security situation assessment elements of the relevant business networks; The network security situation assessment elements are analyzed to obtain the network security situation assessment results.

2. The method according to claim 1, characterized in that, Before inputting the network video data into the video recognition network, the method further includes: The network video data is input into the network security situation assessment network; The network security situation assessment network is used to identify risks in the network video data, resulting in network video data with identified risks.

3. The method according to claim 1, characterized in that, The step of performing feature recognition on the network video data through the video recognition network to obtain video recognition result data includes: Kernel function and density function calculations are performed on the network video data to determine the recognition windows of multiple objects in the network video data, and the network video data after kernel density calculation is obtained. Gradient calculation is performed on the network video data after kernel density calculation to determine the window trajectory of the recognition window; Based on multiple recognition windows in the network video data and the window trajectories of the recognition windows, feature recognition is performed on objects in the network video to obtain video recognition result data.

4. The method according to claim 1, characterized in that, The network security situation assessment elements include: vulnerability assessment elements, attack risk assessment elements, and asset and task assessment elements.

5. The method according to claim 1, characterized in that, The analysis of the network security situation assessment elements to obtain the network security situation assessment result includes: The network security situation assessment elements are quantitatively calculated using an index quantification algorithm to obtain the index quantification values ​​of the network security situation assessment elements. The weight of each indicator in the network security situation assessment elements is determined by the analytic hierarchy process. Based on the quantitative values ​​of the indicators of the network security situation assessment elements and the weights of the indicators, the overall network security index is determined. The cybersecurity situation assessment result is determined based on the cybersecurity index.

6. The method according to claim 1, characterized in that, The method further includes: The network security situation assessment network is used to determine the extent to which the video recognition result data improves the relevant services related to the video recognition result data. When the improvement level of the relevant business is negative, determine the video webpage corresponding to the video recognition result data; Data interception is performed on the video webpage.

7. A network situation assessment device based on video recognition, characterized in that, The device includes: The video data input module is used to input network video data into the video recognition network; The video recognition module is used to perform feature recognition on the network video data through the video recognition network to obtain video recognition result data; The network security situation assessment module is used to input the video recognition result data into the network security situation assessment network to obtain the network security situation assessment result. The network security situation assessment module includes: The relevant business network determination submodule is used to determine the relevant business networks of the video recognition result data through the network security situation assessment network; The relevant indicator determination submodule is used to determine the relevant indicators of the network security situation assessment elements of the relevant business network based on the network characteristics of the relevant business network. The evaluation result acquisition submodule is used to analyze the network security situation assessment elements and obtain the network security situation assessment results.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method as described in any one of claims 1 to 6.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Attack occurrence confidence-based network security situation assessment method and system

    CN108306894A

  • Network video recommendation system with high security

    CN108712680A