A method, apparatus, electronic device, and storage medium for predicting network attacks.

By acquiring network security log data, identifying attack types, and generating scoring values, the problem of chaotic network attack data is solved, enabling effective prediction of network attacks.

CN116232636BActive Publication Date: 2025-11-14CHINA TELECOM CORP LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211555233.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-06
Publication Date
2025-11-14
Estimated Expiration
2042-12-06

Smart Images

  • Figure CN116232636B_ABST
    Figure CN116232636B_ABST
Patent Text Reader

Abstract

This invention provides a method, apparatus, electronic device, and storage medium for predicting network attacks. The method includes: acquiring network security log data; determining the attack type corresponding to each network security log data; determining a target data set based on the attack type corresponding to each network security log data; the log data in the target data set being log data corresponding to at least two attack types; and generating a target data set score based on server information and business type information of the log data in the target data set. In this invention, by determining the target data set of log data generated by at least two attack types through the attack types of the log data, the problem of data confusion caused by obfuscation attacks is solved. Furthermore, by generating evaluation data for network obfuscation attacks based on the server information and business type information of the target data set, the problem of being unable to predict network attacks due to missing required data is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a network attack prediction method, a network attack prediction device, an electronic device, and a storage medium. Background Technology

[0002] With the development of network technology, network security has become particularly important. Using scientific theories, methods, and existing experience to judge and predict the development trend and harm of major security incidents discovered in network systems is an important stage of network security situation awareness. The main goal of network security situation awareness is to predict network security incidents. However, because attackers can launch attacks through obfuscation, the resulting data becomes chaotic, leading to a lack of data needed to evaluate network attack prediction methods and making it impossible to predict network attacks. Summary of the Invention

[0003] In view of the above problems, embodiments of the present invention are proposed to provide a network attack prediction method, a network attack prediction device, an electronic device, and a storage medium that overcome or at least partially solve the above problems.

[0004] To address the aforementioned problems, this invention discloses a network attack prediction method applied to a server, the method comprising:

[0005] Obtain network security log data; the network security log data includes server information and service type information;

[0006] Determine the attack type corresponding to each network security log data;

[0007] Based on the attack types corresponding to each network security log data, a target data set is determined; the log data in the target data set consists of log data corresponding to at least two attack types.

[0008] Based on the server information and business type information of the log data of the target data set, a score value for the target data set is generated; the score value is used to characterize the probability that the server is attacked by at least two types of attacks.

[0009] Optionally, generating a score value for the target data set based on the server information and the business type information of the log data of the target data set includes:

[0010] Based on the server information of the log data of the target data set, determine the first score of the target data set;

[0011] Based on the business type information of the log data of the target data set, determine the second score of the target data set;

[0012] A score is generated based on the first score and the second score.

[0013] Optionally, the server information includes the usage duration of the server recording the network security log data; determining the first score of the target data set based on the server information of the log data of the target data set includes:

[0014] Based on the usage duration of the servers corresponding to each network security log data in the target dataset, determine the duration data subsets belonging to different usage duration intervals;

[0015] Based on the duration data subsets of each usage duration interval, determine the usage duration interval with the largest data volume in the duration data subset;

[0016] Obtain a first mapping relationship between usage duration intervals and preset scores, and set a first score for the target data set based on the first mapping relationship and the usage duration interval with the largest data volume.

[0017] Optionally, determining the second score of the target data set based on the business type information of the log data of the target data set includes:

[0018] Based on the business type information corresponding to each network security log data in the target data set, determine the type data subsets belonging to different business type information;

[0019] Based on the type data subsets of each business type information, determine the business type information with the largest data volume in the type data subset;

[0020] Obtain the second mapping relationship between the business type information and the preset score, and set the second score for the target data set based on the second mapping relationship and the business type information with the largest data volume.

[0021] Optionally, determining the attack type corresponding to each network security log data includes:

[0022] The network security log data is imported into the attack classification model to obtain the attack type corresponding to each network security log data.

[0023] Optionally, determining the target data set based on the attack type corresponding to each network security log data includes:

[0024] The network security log data is imported into a classification prediction model to obtain a target data set of log data corresponding to at least two attack types.

[0025] Accordingly, embodiments of the present invention also disclose a network attack prediction device applied to a server, the device comprising:

[0026] The data acquisition module is used to acquire network security log data; the network security log data includes server information and business type information.

[0027] The type determination module is used to determine the attack type corresponding to each network security log data.

[0028] The set determination module is used to determine the target data set based on the attack types corresponding to each network security log data; the log data in the target data set is log data corresponding to at least two attack types;

[0029] The scoring value generation module is used to generate a scoring value for the target data set based on the server information and the business type information of the log data of the target data set; the scoring value is used to characterize the probability that the server is attacked by at least two types of attacks.

[0030] Optionally, the score generation module includes:

[0031] The first score determination submodule is used to determine the first score of the target data set based on the server information of the log data of the target data set;

[0032] The second score determination submodule is used to determine the second score of the target data set based on the business type information of the log data of the target data set;

[0033] The rating value generation submodule is used to generate a rating value based on the first score and the second score.

[0034] Optionally, the first score determination submodule includes:

[0035] The duration data subset determination unit is used to determine duration data subsets belonging to different usage duration intervals based on the usage duration of the servers corresponding to each network security log data in the target data set.

[0036] The interval determination unit is used to determine the usage time interval with the largest data volume in each usage time interval based on the duration data subset of each usage time interval;

[0037] The first score setting unit is used to obtain a first mapping relationship between the usage time interval and the preset score, and to set a first score for the target data set according to the first mapping relationship and the usage time interval with the largest data volume.

[0038] Optionally, the second score determination submodule includes:

[0039] The type data subset determination unit is used to determine the type data subset belonging to different business type information based on the business type information corresponding to each network security log data in the target data set;

[0040] The business type determination unit is used to determine the business type information with the largest data volume in the type data subset based on the type data subset of each business type information.

[0041] The second score setting unit is used to obtain a second mapping relationship between the business type information and the preset score, and to set a second score for the target data set according to the second mapping relationship and the business type information with the largest data volume.

[0042] Optionally, the type determination module includes:

[0043] The type determination submodule is used to import the network security log data into the attack classification model to obtain the attack type corresponding to each network security log data.

[0044] Optionally, the set determination module includes:

[0045] The set determination submodule is used to import the network security log data into the classification prediction model to obtain a target data set of log data corresponding to at least two attack types.

[0046] Accordingly, this invention discloses an electronic device, including: a processor, a memory, and a computer program stored in the memory and capable of running on the processor. When the computer program is executed by the processor, it implements the various steps of the above-described network attack prediction method embodiments.

[0047] Accordingly, embodiments of the present invention disclose a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the various steps of the above-described network attack prediction method embodiments.

[0048] The embodiments of this invention include the following advantages: acquiring network security log data; the network security log data includes server information and business type information; determining the attack type corresponding to each network security log data; determining a target data set based on the attack types corresponding to each network security log data; the log data in the target data set is log data corresponding to at least two attack types; generating a target data set score value based on the server information and business type information of the log data in the target data set; the score value is used to characterize the probability that the server is attacked by at least two attack types. In these embodiments, the target data set of log data generated by at least two attack types can be determined through the attack types of the log data, thus solving the problem of data chaos caused by obfuscation attacks. Furthermore, evaluation data for network obfuscation attacks can be generated based on the server information and business type information of the target data set, thus solving the problem of being unable to predict network attacks due to missing required data. Attached Figure Description

[0049] Figure 1 This is a flowchart illustrating the steps of a network attack prediction method provided in an embodiment of the present invention;

[0050] Figure 2 This is a flowchart of another network attack prediction method provided in an embodiment of the present invention;

[0051] Figure 3 This is a target data set determination diagram provided in the embodiments of the present invention;

[0052] Figure 4 This is a structural block diagram of a network attack prediction device provided in an embodiment of the present invention. Detailed Implementation

[0053] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0054] During the pre-planning process of network security incidents, attackers may use various attack methods to attack servers, causing server log data to become chaotic. This results in a lack of data needed to evaluate network attack prediction methods, making it impossible to predict network attacks.

[0055] One of the core concepts of this invention is to propose a network attack prediction method. By identifying the attack type, the method determines the data set generated by multiple attack methods attacking the server. Then, based on the server information and business type information of the log data in the data set, it generates evaluation data on the server being attacked by multiple attack methods. This solves the problem of missing data required for the evaluation of network attack prediction methods, which makes it impossible to predict network attacks.

[0056] Reference Figure 1 The diagram illustrates a flowchart of a network attack prediction method provided by an embodiment of the present invention. The method may specifically include the following steps:

[0057] Step 101: Obtain network security log data; the network security log data includes server information and business type information.

[0058] With the development of network technology, people's lives have become inseparable from the internet. Hackers, seeking profit, launch cyberattacks, which are attacks initiated from one or more computers against another, multiple computers, or a network. Cyberattacks can be divided into two main categories: attacks that aim to disable or take offline a target computer, and attacks that aim to access data on a target computer and potentially gain administrator privileges. To maintain network security, enterprises use scientific theories, methods, and existing experience to assess and predict the development trends and potential harm of major security incidents discovered in their network systems.

[0059] When a server is attacked by a network, corresponding log data will be generated in the network security log data. The network security log data can be obtained from the server and may include server information and business type information.

[0060] Step 102: Determine the attack type corresponding to each network security log data.

[0061] After a hacker attacks a server using a certain attack method, the server will generate log data corresponding to the attack type in the network security log data. The attack type corresponding to each network security log data can be determined by using the network security log data in the server.

[0062] Step 103: Determine the target data set based on the attack types corresponding to each network security log data; the log data in the target data set is log data corresponding to at least two attack types.

[0063] Hackers can attack servers using various attack methods. The server's network security logs will generate log data for various attack methods. After determining the attack type corresponding to each network security log data, log data corresponding to at least two attack types can be assigned to a target data set to obtain the log data of the target data set. For example, if there are 100 log data in the network security logs, among which 5 log data belong to both attack type A and attack type B, 10 log data belong to both attack type A and attack type C, 5 log data belong to both attack type B and attack type C, and 10 log data belong to all three types of attack types, then the target data set can include these 30 log data. These 30 log data can be called obfuscated attack data.

[0064] Step 104: Generate a target data set score based on the server information and the business type information of the log data of the target data set; the score is used to characterize the probability that the server is attacked by at least two types of attacks.

[0065] After determining the target dataset, a score can be generated using server information and business type information from the log data of the target dataset. For example, the score can be generated using server usage data from the server information and business failure information from the business type information. The score can be generated using formulas or models. The specific method for generating the target dataset score can be set according to actual circumstances, and this embodiment of the invention does not impose any limitations. The score can be used to represent the probability that a server is attacked by at least two types of attacks. Based on the score, staff can predict the probability of the server being subjected to obfuscation attacks.

[0066] The process involves acquiring network security log data, including server information and business type information; determining the attack type corresponding to each network security log data; identifying a target data set based on the attack types corresponding to each network security log data; the target data set consisting of log data corresponding to at least two attack types; and generating a target data set score based on the server information and business type information of the log data in the target data set. The score is used to characterize the probability that a server is attacked by at least two attack types. In this embodiment of the invention, the target data set of log data generated by at least two attack types can be determined through the attack types of the log data, thus solving the problem of data confusion caused by obfuscation attacks. Furthermore, evaluation data for network obfuscation attacks can be generated based on the server information and business type information of the target data set, thus solving the problem of being unable to predict network attacks due to missing required data.

[0067] Reference Figure 2 This illustrates another network attack prediction method provided by an embodiment of the present invention, applied to a server, the method comprising:

[0068] Step 201: Obtain network security log data; the network security log data includes server information and business type information.

[0069] Step 202: Determine the attack type corresponding to each network security log data.

[0070] In this embodiment of the invention, determining the attack type corresponding to each network security log data includes:

[0071] The network security log data is imported into the attack classification model to obtain the attack type corresponding to each network security log data.

[0072] An attack classification model can be constructed, which can deduce the attack type received by the server based on the data. Network security log data can be imported into the attack classification model to obtain the attack type corresponding to each network security log data. The attack classification model can be constructed using the Pareto method. The specific method for constructing the attack classification model can be set according to the actual situation, and the embodiments of the present invention are not limited here.

[0073] Step 203: Determine the target data set based on the attack types corresponding to each network security log data; the log data in the target data set is log data corresponding to at least two attack types.

[0074] In this embodiment of the invention, determining the target data set based on the attack type corresponding to each network security log data includes:

[0075] The network security log data is imported into a classification prediction model to obtain a target data set of log data corresponding to at least two attack types.

[0076] A classification prediction model can be built. This model can classify network security log data based on the attack types of each log. It can also classify network security log data that includes at least two attack types. By importing network security log data into the classification prediction model, a target data set corresponding to at least two attack types can be obtained. This log data corresponding to at least two attack types can be called obfuscated data generated by an obfuscation attack. Therefore, a target data set for obfuscation attacks can be obtained. For example, attack types can include noise injection, trajectory erasure, and alarm tampering. (See reference...) Figure 3 The three circles represent log data from noise injection, trajectory erasure, and alarm tampering, respectively. The log data in regions a, b, c, and d represent obfuscated data generated by obfuscation attacks, which are the target data sets of log data corresponding to at least two attack types.

[0077] Step 204: Determine the first score of the target data set based on the server information of the log data of the target data set.

[0078] Network security log data can include server information and business type information. After obtaining the target data set, the first score of the target data set can be determined based on the server information of the log data in the target data set.

[0079] In this embodiment of the invention, the server information includes the usage duration of the server that records the network security log data; determining the first score of the target data set based on the server information of the log data of the target data set includes:

[0080] Based on the usage duration of the servers corresponding to each network security log data in the target dataset, determine the duration data subsets belonging to different usage duration intervals;

[0081] Based on the duration data subsets of each usage duration interval, determine the usage duration interval with the largest data volume in the duration data subset;

[0082] Obtain a first mapping relationship between usage duration intervals and preset scores, and set a first score for the target data set based on the first mapping relationship and the usage duration interval with the largest data volume.

[0083] Server information can include the usage duration of the server that records network security log data. The usage duration can be obtained based on the server's production date and current date. Different usage duration intervals can also be determined based on the usage duration, such as 1 year, 2 years, and 3 years. Based on the usage duration of the server corresponding to each network security log data in the target dataset, each network security log data corresponding to the usage duration can be assigned to the corresponding usage duration interval, thus obtaining a subset of duration data belonging to different usage duration intervals. For example, the 1-year duration data subset can include all log data with a server usage duration of 1 year, the 2-year duration data subset can include all log data with a server usage duration of 2 years, and the 3-year duration data subset can include all log data with a server usage duration of 3 years.

[0084] Step 205: Determine the second score of the target data set based on the business type information of the log data of the target data set;

[0085] Different business type information in log data corresponds to different preset scores. The second score of the target data set can be determined based on the business type information of the log data in the target data set.

[0086] In this embodiment of the invention, determining the second score of the target data set based on the business type information of the log data of the target data set includes:

[0087] Based on the business type information corresponding to each network security log data in the target data set, determine the type data subsets belonging to different business type information;

[0088] Based on the type data subsets of each business type information, determine the business type information with the largest data volume in the type data subset;

[0089] Obtain the second mapping relationship between the business type information and the preset score, and set the second score for the target data set based on the second mapping relationship and the business type information with the largest data volume.

[0090] Based on the business type information corresponding to each network security log data in the target dataset, each network security log data can be assigned to a subset of type data belonging to different business type information. For example, the subset of type data for business type information A can include all network security log data belonging to business type information A, and the subset of type data for business type information B can include all network security log data belonging to business type information B. The data volume of each subset of type data for each business type information can also be compared to identify the business type information with the largest data volume. For example, the data volume of the subset of type data for business type information A is greater than that of the subset of type data for business type information B. Furthermore, a second mapping relationship between business type information and preset scores can be obtained. This second mapping relationship can be set according to weight levels. For example, business type information A has a weight level of level one and a corresponding preset score of 3 points, while business type information B has a weight level of level two and a corresponding preset score of 2 points, thus obtaining the second mapping relationship between business type information and preset scores. Furthermore, based on the second mapping relationship and the business type information with the largest data volume, the preset score of the business type information with the largest data volume can be set as the second score. For example, if the business type information with the largest data volume is business type information A, and the preset score corresponding to business type information A is 3 points, then the second score is 3 points.

[0091] Step 206: Generate a score value based on the first score and the second score; the score value is used to characterize the probability that the server is attacked by at least two types of attacks.

[0092] After obtaining the first score and the second score, the first score and the second score can be calculated to obtain the score value of the target data set. The score value can be used to characterize the probability that the server is attacked by at least two types of attacks. Staff can judge the probability that the server is obfuscated based on the score value. The calculation method of the first score and the second score can be set according to the actual situation. This embodiment of the invention does not limit it here.

[0093] The process involves acquiring network security log data, including server information and business type information; determining the attack type corresponding to each network security log data; determining a target data set based on the attack type corresponding to each network security log data; the target data set consists of log data corresponding to at least two attack types; determining a first score for the target data set based on the server information of the log data; determining a second score for the target data set based on the business type information of the log data; generating a rating value based on the first and second scores; and the rating value characterizing the probability that the server is attacked by at least two attack types. In this embodiment of the invention, the target data set of log data generated by at least two attack types can be determined through the attack types of the log data, thus solving the problem of data confusion caused by obfuscation attacks. Furthermore, a first score can be obtained based on the server information of the target data set, and a second score can be obtained based on the business type information. Based on the first and second scores, evaluation data for network obfuscation attacks can be generated, thus solving the problem of being unable to predict network attacks due to missing required data.

[0094] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of the present invention are not limited to the described order of actions, because according to the embodiments of the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.

[0095] Reference Figure 4 The diagram illustrates a structural block diagram of a network attack prediction device provided by an embodiment of the present invention, which is applied to a server and may specifically include the following modules:

[0096] Data acquisition module 301 is used to acquire network security log data; the network security log data includes server information and business type information;

[0097] The type determination module 302 is used to determine the attack type corresponding to each network security log data.

[0098] The set determination module 303 is used to determine the target data set based on the attack types corresponding to each network security log data; the log data in the target data set is log data corresponding to at least two attack types;

[0099] The scoring value generation module 304 is used to generate a scoring value for the target data set based on the server information and the business type information of the log data of the target data set; the scoring value is used to characterize the probability that the server is attacked by at least two types of attacks.

[0100] Optionally, the score generation module includes:

[0101] The first score determination submodule is used to determine the first score of the target data set based on the server information of the log data of the target data set;

[0102] The second score determination submodule is used to determine the second score of the target data set based on the business type information of the log data of the target data set;

[0103] The rating value generation submodule is used to generate a rating value based on the first score and the second score.

[0104] Optionally, the first score determination submodule includes:

[0105] The duration data subset determination unit is used to determine duration data subsets belonging to different usage duration intervals based on the usage duration of the servers corresponding to each network security log data in the target data set.

[0106] The interval determination unit is used to determine the usage time interval with the largest data volume in each usage time interval based on the duration data subset of each usage time interval;

[0107] The first score setting unit is used to obtain a first mapping relationship between the usage time interval and the preset score, and to set a first score for the target data set according to the first mapping relationship and the usage time interval with the largest data volume.

[0108] Optionally, the second score determination submodule includes:

[0109] The type data subset determination unit is used to determine the type data subset belonging to different business type information based on the business type information corresponding to each network security log data in the target data set;

[0110] The business type determination unit is used to determine the business type information with the largest data volume in the type data subset based on the type data subset of each business type information.

[0111] The second score setting unit is used to obtain a second mapping relationship between the business type information and the preset score, and to set a second score for the target data set according to the second mapping relationship and the business type information with the largest data volume.

[0112] Optionally, the type determination module includes:

[0113] The type determination submodule is used to import the network security log data into the attack classification model to obtain the attack type corresponding to each network security log data.

[0114] Optionally, the set determination module includes:

[0115] The set determination submodule is used to import the network security log data into the classification prediction model to obtain a target data set of log data corresponding to at least two attack types.

[0116] As the device embodiment is basically similar to the method embodiment, the description is relatively simple, and relevant parts can be found in the description of the method embodiment.

[0117] This invention also provides an electronic device, comprising:

[0118] It includes a processor, a memory, and a computer program stored in the memory and capable of running on the processor. When the computer program is executed by the processor, it implements the various processes of the above-described network attack prediction method embodiments and achieves the same technical effect. To avoid repetition, it will not be described again here.

[0119] This invention also provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the various processes of the above-described network attack prediction method embodiments and achieves the same technical effect. To avoid repetition, it will not be described again here.

[0120] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0121] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, apparatus, or computer program products. Therefore, embodiments of the present invention can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of the present invention can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0122] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0123] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0124] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0125] Although preferred embodiments of the present invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present invention.

[0126] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.

[0127] The present invention has provided a detailed description of a network attack prediction method, a network attack prediction device, an electronic device, and a storage medium. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, those skilled in the art will recognize that there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A method for predicting network attacks, characterized in that, Applied to a server, the method includes: Obtain network security log data; the network security log data includes server information and service type information; Determine the attack type corresponding to each network security log data; Based on the attack types corresponding to each network security log data, a target data set is determined; the log data in the target data set consists of log data corresponding to at least two attack types. Based on the server information and business type information of the log data of the target data set, a score value for the target data set is generated; the score value is used to characterize the probability that the server is attacked by at least two types of attacks. The step of generating a score value for the target data set based on the server information and the business type information of the log data of the target data set includes: Based on the server information of the log data of the target data set, determine the first score of the target data set; Based on the business type information of the log data of the target data set, determine the second score of the target data set; A score is generated based on the first score and the second score; Determining the second score of the target data set based on the business type information of the log data of the target data set includes: Based on the business type information corresponding to each network security log data in the target data set, determine the type data subsets belonging to different business type information; Based on the type data subsets of each business type information, determine the business type information with the largest data volume in the type data subset; Obtain the second mapping relationship between the business type information and the preset score, and set the second score for the target data set based on the second mapping relationship and the business type information with the largest data volume.

2. The method according to claim 1, characterized in that, The server information includes the usage duration of the server that records the network security log data; determining the first score of the target data set based on the server information of the log data of the target data set includes: Based on the usage duration of the servers corresponding to each network security log data in the target dataset, determine the duration data subsets belonging to different usage duration intervals; Based on the duration data subsets of each usage duration interval, determine the usage duration interval with the largest data volume in the duration data subset; Obtain a first mapping relationship between usage duration intervals and preset scores, and set a first score for the target data set based on the first mapping relationship and the usage duration interval with the largest data volume.

3. The method according to claim 1, characterized in that, The process of determining the attack type corresponding to each network security log data includes: The network security log data is imported into the attack classification model to obtain the attack type corresponding to each network security log data.

4. The method according to claim 1, characterized in that, The step of determining the target data set based on the attack type corresponding to each network security log data includes: The network security log data is imported into a classification prediction model to obtain a target data set of log data corresponding to at least two attack types.

5. A network attack prediction device, characterized in that, Applied to a server, the device includes: The data acquisition module is used to acquire network security log data; the network security log data includes server information and business type information. The type determination module is used to determine the attack type corresponding to each network security log data. The set determination module is used to determine the target data set based on the attack types corresponding to each network security log data; the log data in the target data set is log data corresponding to at least two attack types; The scoring value generation module is used to generate a scoring value for the target data set based on the server information and the business type information of the log data of the target data set; the scoring value is used to characterize the probability that the server is attacked by at least two attack types; The score generation module includes: The first score determination submodule is used to determine the first score of the target data set based on the server information of the log data of the target data set; The second score determination submodule is used to determine the second score of the target data set based on the business type information of the log data of the target data set; The scoring value generation submodule is used to generate a scoring value based on the first score and the second score; The first score determination submodule includes: The duration data subset determination unit is used to determine duration data subsets belonging to different usage duration intervals based on the usage duration of the servers corresponding to each network security log data in the target data set. The interval determination unit is used to determine the usage time interval with the largest data volume in each usage time interval based on the duration data subset of each usage time interval; The first score setting unit is used to obtain a first mapping relationship between the usage time interval and the preset score, and to set a first score for the target data set according to the first mapping relationship and the usage time interval with the largest data volume.

6. An electronic device, characterized in that, include: A processor, a memory, and a computer program stored in the memory and capable of running on the processor, wherein the computer program, when executed by the processor, implements the steps of the network attack prediction method as described in any one of claims 1-4.

7. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, which, when executed by a processor, implements the steps of the network attack prediction method as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Threat detection and response method and system based on security cloud platform

    CN113709176A