A data analysis method and system based on active and passive detection

Through active passive detection combined with BP neural network data analysis method, the problem of inaccurate positioning of attack sources in the existing technology is solved, and accurate detection and positioning of attack sources is achieved.

CN116232722BActive Publication Date: 2025-07-25BEIJING CYBERYEON TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310192866.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-03
Publication Date
2025-07-25
Estimated Expiration
2043-03-03

AI Technical Summary

Technical Problem

The poor detection of attack sources in the prior art makes the ultimate positioning of attack sources inaccurate.

Method used

The data analysis method based on active passive detection is adopted. By obtaining network signals, data transmission and data storage information, setting a preset detection cycle for regular detection, combining active and passive detection methods, a BP neural network is used to build a network protection model, output protection result information, and actively patrol when receiving warning information to trace the source of attack.

Benefits of technology

Active passive and accurate detection of attack sources is achieved, and the accuracy of attack source positioning is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116232722B_ABST
    Figure CN116232722B_ABST
Patent Text Reader

Abstract

The present invention provides a data analysis method and system based on active and passive detection, which relates to the field of intelligent identification technology. The method includes: setting a preset detection period for regular detection based on network signal information, network data transmission information, and network data storage information, respectively analyzing network data through active and passive detection, covering and traversing network signals, network data transmission, and network data storage, inputting multiple regular inspection information, multiple analysis results, and the input network protection model, and outputting protection result information. When receiving a protection warning information, an active inspection task is added to obtain inspection data, and tracing is carried out in combination with the protection result information to locate the attack source, solving the technical problem in the prior art that the detection of the attack source is poor, resulting in inaccurate final positioning of the attack source, realizing the active and passive accurate detection of the attack source, and improving the accuracy of positioning the attack source.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of intelligent recognition, and specifically relates to a data analysis system based on active and passive detection. Background Art

[0002] In recent years, cyber security threats such as ransomware and supply chain attacks have become increasingly rampant. Cyber attack means are more diverse, methods are more flexible, frequencies are faster, and depths are greater. The risk exposure faced by network systems is extremely alarming. However, the cyber security protection measures taken are often limited to static defense, passive defense, and rigid defense, and there are problems such as a relatively low level of attack defense, long average detection and response time, etc.

[0003] In the prior art, the detection of the attack source is poor, which ultimately leads to the problem of inaccurate positioning of the attack source. Summary of the Invention

[0004] This application provides a data analysis method based on active and passive detection, which is used to solve the technical problem in the prior art that the detection of the attack source is poor, resulting in inaccurate positioning of the attack source.

[0005] In view of the above problems, this application provides a data analysis method and system based on active and passive detection.

[0006] In a first aspect, this application provides a data analysis method based on active and passive detection. The method includes: obtaining network information, where the network information includes network signal information, network data transmission information, and network data storage information; setting a preset detection period for regular detection based on the network signal information, the network data transmission information, and the network data storage information to obtain a plurality of regular detection information; respectively analyzing network data through active and passive detection to obtain a plurality of analysis results; performing coverage traversal on the network signal, the network data transmission, and the network data storage to obtain a plurality of coverage traversal results; inputting the plurality of regular detection information, the plurality of analysis results, and the plurality of coverage traversal results into a network protection model to output protection result information, where the protection result information includes protection warning information; when receiving the protection warning information, adding an active patrol task, obtaining patrol data, tracing the source in combination with the protection result information, and positioning the attack source.

[0007] Second aspect, the present application provides a data analysis system based on active and passive detection, the system comprising: an information acquisition module for acquiring network information, wherein the network information includes network signal information, network data transmission information, and network data storage information; a detection module for setting a preset detection period based on the network signal information, the network data transmission information, and the network data storage information for regular detection to obtain a plurality of regular detection information; an analysis module for analyzing network data through active and passive detection respectively to obtain a plurality of analysis results; a coverage traversal module for performing coverage traversal on the network signal, the network data transmission, and the network data storage to obtain a plurality of coverage traversal results; an input module for inputting the plurality of regular detection information, the plurality of analysis results, and the plurality of coverage traversal results into a network protection model to output protection result information, wherein the protection result information includes protection warning information; a positioning module for adding an active inspection task when receiving the protection warning information, acquiring inspection data, and performing traceability in combination with the protection result information to locate the attack source.

[0008] One or more technical solutions provided in the present application have at least the following technical effects or advantages:

[0009] A data analysis method based on active and passive detection provided in the present application relates to the technical field of intelligent identification, solves the technical problem in the prior art that the detection of the attack source is poor, resulting in inaccurate positioning of the attack source finally, realizes the active and passive accurate detection of the network attack source, and further improves the accuracy of positioning the attack source. Description of the Drawings

[0010] Figure 1 is a schematic flowchart of a data analysis method based on active and passive detection provided in the present application;

[0011] Figure 2 is a schematic structural diagram of a data analysis system based on active and passive detection provided in the present application.

[0012] Description of the reference numerals: information acquisition module 1, detection module 2, analysis module 3, coverage traversal module 4, input module 5, positioning module 6. Detailed Embodiments

[0013] The present application provides a data analysis method based on active and passive detection to solve the technical problem in the prior art that the detection of the attack source is poor, resulting in inaccurate positioning of the attack source finally.

[0014] Embodiment 1

[0015] Such asFigure 1 As shown in Figure 1 , an embodiment of the present application provides a data analysis method based on active and passive detection. The method includes:

[0016] Step S100: Obtain network information, where the network information includes network signal information, network data transmission information, and network data storage information;

[0017] Specifically, a data analysis method based on active and passive detection provided by an embodiment of the present application is applied to a data analysis system based on active and passive detection. Before a network attack occurs, it is necessary to collect the network information of the target host in real time. The network information may include the network signal information of the target host, the network data transmission information of the target host, and the network data storage information of the target host. The network signal information of the target host includes wired signals, wireless signals, signal stability, signal input and output frequency bands, etc. The network data transmission information of the target host includes baseband transmission, band transmission, broadband transmission, etc. The network data storage information includes direct-attached storage, network-attached storage, storage area network, etc. Furthermore, the network information of the target host is improved through the collected network signal information, network data transmission information, and network data storage information, providing an important reference basis for later positioning the attack source.

[0018] Step S200: Based on the network signal information, the network data transmission information, and the network data storage information, set a preset detection period for regular detection to obtain multiple regular detection information;

[0019] Specifically, based on the collected network signal information, network data transmission information, and network data storage information, a corresponding preset detection period is set for each of the above three. That is, the preset detection period for network signal information can be set to 24 hours, the preset detection period for network data transmission information can be set to 1 hour, and the preset detection period for network data storage information can be set to 6 hours. Therefore, the network signal information, network data transmission information, and network data storage information are regularly monitored according to the set preset detection periods, respectively, so as to obtain multiple regular detection information correspondingly, and further guarantee the positioning of the attack source.

[0020] Step S300: Analyze the network data through active and passive detection respectively to obtain multiple analysis results;

[0021] Specifically, since the active detection and passive detection have different detection methods for the target host, it is necessary to set weights for the active detection and passive detection respectively according to the situation of the target host. Further, based on the weight ratios assigned to the active detection and passive detection, the network data of the target host is detected respectively. On this basis, the detected network data is analyzed for network attacks to determine whether the current target host is under a network attack. Further, according to the obtained judgment and analysis results, the network attack information in the target host under a network attack is compared with the historical attack information to determine the system attack points, and the judgment and analysis results and the determined system attack points are integrated and output as multiple analysis results, laying a solid foundation for subsequent positioning of the attack source.

[0022] Step S400: Perform a coverage traversal on the network signal, the network data transmission, and the network data storage to obtain multiple coverage traversal results.

[0023] Specifically, perform a coverage traversal on the network signal information, network data transmission information, and network data storage information included in the network information. The coverage traversal means that, on the premise of meeting the optimal or near-optimal performance evaluation indicators of the network signal information, network data transmission information, and network data storage information, find a path starting from the starting point, visit each network information node in the target host once in sequence, and further obtain the coverage traversal results. At the same time, if the obtained coverage traversal results contain abnormal traversal data, further, the obtained multiple regular inspection information is covered corresponding to the obtained multiple analysis results, that is, the range of the corresponding multiple analysis results covered by the information detected in the multiple regular inspection information, so as to obtain abnormal traversal data. Among them, the obtained abnormal traversal data is the data that does not match the obtained multiple analysis results in the obtained multiple regular inspection information. Based on the obtained abnormal traversal data, obtain the coverage traversal results corresponding to the abnormal traversal data, which has a restrictive effect on realizing the positioning of the attack source.

[0024] Step S500: Input the multiple regular inspection information, the multiple analysis results, and the multiple coverage traversal results into the network protection model to output protection result information, where the protection result information includes protection warning information.

[0025] Specifically, based on the BP neural network, a network protection model is constructed, and multiple regular inspection information, multiple analysis results, and multiple coverage traversal results are data-labeled and partitioned to obtain multiple training sets, multiple validation sets, and multiple test sets. Further, the network protection model is supervised, trained, validated, and tested using the multiple training sets, multiple validation sets, and multiple test sets respectively to obtain a network protection model with an accuracy rate meeting the preset requirements. Then, the multiple regular inspection information, multiple analysis results, and multiple coverage traversal results are input into the network protection model, and a preliminary protection result information is obtained correspondingly. Next, the protection result information with the highest frequency of protection warning information in the preliminarily obtained protection result information is used as the final protection result information for output. At the same time, the protection result contains protection warning information, which has a profound impact on the subsequent positioning of the attack source.

[0026] Step S600: When receiving the protection warning information, add an active inspection task, obtain inspection data, trace back in combination with the protection result information, and locate the attack source.

[0027] Specifically, based on the protection result information output above, when the system receives the protection result information containing protection warning information, an active inspection task is added to the target host, that is, multiple regular inspection information, multiple analysis results, and multiple coverage traversal results in the target host are automatically inspected regularly or randomly during the use of the target host, so as to summarize and integrate the inspection results, and the inspection data is obtained correspondingly. Further, the inspection data is combined with the obtained anti-slip result information, and on this basis, the attack source of the network attack on the target host is located, realizing the active and passive accurate detection of the attack source and improving the accuracy rate of locating the attack source.

[0028] Furthermore, step S200 of the present application further includes:

[0029] Step S210: Detect the network signal information in terms of network signal security dimension to obtain a first security dimension detection result;

[0030] Step S220: Detect the network data transmission information in terms of network data transmission security dimension to obtain a second security dimension detection result;

[0031] Step S230: Detect the network data storage information in terms of network data storage security dimension to obtain a third security dimension detection result;

[0032] Step S240: Based on the security factor set, correlate the first security dimension detection result, the second security dimension detection result, and the third security dimension detection result to obtain multiple regular inspection information.

[0033] Specifically, based on the network signal information, network data transmission information, and network data storage information in the obtained network information, the network signal information is respectively detected in terms of the security dimension of network signal information, that is, the security level of the current network signal in the target host, which is denoted as the first security dimension detection result. The network data transmission information is detected in terms of the security dimension of network data transmission, that is, when the target host needs to perform network data transmission, the security level of its transmission process, which is denoted as the second security dimension detection result. The network data storage information is detected in terms of the security dimension of network data storage, that is, when the target host needs to store network data, the security level of the stored data, which is denoted as the third security dimension detection result.

[0034] After the network status, security device logs, and system operation data are collected in real time and then subjected to correlation analysis to generate a set of security factors. On this basis, the above-obtained first security dimension detection result, second security dimension detection result, and third security dimension detection result are correlated, that is, among the obtained first security dimension detection result, second security dimension detection result, and third security dimension detection result, frequent patterns, associations, correlations, or causal structures existing among them are searched, and finally multiple regular inspection information is generated, achieving the technical effect of providing an important basis for later positioning the attack source.

[0035] Furthermore, step S240 of this application includes:

[0036] Step S241: Collect the network status in real time to obtain network security factors;

[0037] Step S242: Collect the security device logs in real time to obtain log security factors;

[0038] Step S243: Collect the system operation data in real time to obtain operation security factors;

[0039] Step S244: Based on the correlation function, perform correlation analysis on the network security factors, the log security factors, and the operation security factors to obtain a set of security factors.

[0040] Specifically, in the target host network, real-time collection is performed on its network status, security device logs, and system operation data. Its network status refers to the complete equivalent decoupling process in which, under the condition of strict equivalent transformation, the service provided by a certain common transmission path between different hosts is changed to the service provided by each independent transmission path. Its security device logs refer to the security logs of probe-type security devices such as IDS, IPS, and WAF. Its system operation data refers to the data for maintaining and managing the system during operation. Further, based on the fitting function, the network security factor, log security factor, and operation security factor are fitted. Among them, fitting the network security factor, log security factor, and operation security factor means that the discrete function values of the network security factor, log security factor, and operation security factor are known as {f1, f2,..., f n}, by adjusting the undetermined coefficients of the network security factor, log security factor, and operation security factor in the function to f(λ1, λ2,..., λ n ), making the difference between the function and the known point set small, so as to obtain the security factor set to ensure the efficiency when locating the attack source.

[0041] Furthermore, step S300 of this application further includes:

[0042] Step S310: Set the first weight for the active detection;

[0043] Step S320: Set the second weight for the passive detection;

[0044] Step S330: Perform active and passive detection on the target host based on the first weight and the second weight to obtain the active and passive detection results;

[0045] Step S340: Perform historical attack analysis of the target host on the active and passive detection results to determine the system attack point;

[0046] Step S350: Add the system attack point to multiple analysis results.

[0047] Specifically, the methods for detecting network data are divided into active detection and passive detection. First, the corresponding weights are set for active detection as the first weight and for passive detection as the second weight. Although the accuracy of active detection is high, it is not as good as the secrecy of passive detection. Exemplarily, the weight ratio of active detection to passive detection can be the first influence coefficient: the second influence coefficient is 4:6. Further, active detection and passive detection are respectively performed on the target host, so as to obtain the active detection result and the passive detection result correspondingly, and then determine whether to trigger the alarm of the target host security system. If the alarm of the target host security system is triggered, the weights of active and passive detections are adjusted, that is, the weight of active detection is reduced and the weight of passive detection is increased, so as to obtain the active and passive detection results. Then, historical attack analysis of the target host is performed on the active and passive detection results, that is, the network attack information in the target host under network attack is compared with the historical attack information, so as to determine the system attack points. Finally, the determined system attack points are added to the obtained multiple analysis results, achieving the technical effect of providing a reference for locating the attack source.

[0048] Furthermore, step S330 of the present application includes:

[0049] Step S331: Perform active detection on the target host to obtain a first detection result;

[0050] Step S332: Perform passive detection on the target host to obtain a second detection result;

[0051] Step S333: Based on the first detection result and the second detection result, determine whether to trigger the alarm of the target host security system;

[0052] Step S334: If triggered, adjust the weights of active and passive detections and update the active and passive detection results.

[0053] Specifically, performing active detection on the target host means sending a specific data packet to the target host and analyzing the response of the target host to the data packet, so as to judge the possible operating system type in the target host. Compared with passive detection, the result obtained by active detection is more accurate, but it is also easy to trigger the alarm of the target security system. The active detection result is recorded as the first detection result. Further, performing passive detection on the target host means sniffing, recording, and analyzing the data packet stream through tools and analyzing the operating system of the target host according to the data packet information. Compared with active detection, although the result of passive detection is not as accurate as that of active detection, it is not easily detected by the target host security system. The passive detection result is recorded as the second detection result.

[0054] Based on the obtained first detection result and second detection result, determine whether to trigger the alarm of the target host security system, that is, find the critical value between active detection and passive detection to ensure that the security system of the target host is not triggered under the condition of the highest accuracy rate. After multiple iterations of active detection and passive detection, if the alarm of the target host security system is triggered, the weights of active detection and passive detection are adjusted accordingly, and then the real-time update of the obtained active and passive detection results is completed, and finally the technical effect of locating the attack source is achieved.

[0055] Furthermore, step S500 of this application further includes:

[0056] Step S510: Based on the BP neural network, construct the network protection model;

[0057] Step S520: Perform data annotation and division on the multiple regular inspection information, the multiple analysis results, and the multiple coverage traversal results to obtain multiple training sets, multiple validation sets, and multiple test sets;

[0058] Step S530: Use the multiple training sets, multiple validation sets, and multiple test sets to perform supervised training, validation, and testing on the network protection model respectively to obtain the network protection model with the accuracy rate meeting the preset requirements;

[0059] Step S540: Input the multiple regular inspection information, the multiple analysis results, and the multiple coverage traversal results into the network protection model to obtain the first protection result information;

[0060] Step S550: Output the first protection result information with the highest frequency of protection warning information in the first protection result information as the protection result information.

[0061] Specifically, based on the BP neural network, construct the network protection model, and improve the accuracy of the obtained protection result by obtaining the first protection result information with the highest frequency of protection warning information in the first protection result information.

[0062] Further, data annotation and partitioning are performed on multiple regular inspection information, the multiple analysis results, and multiple coverage traversal results, so as to correspondingly obtain multiple training sets, multiple validation sets, and multiple test sets, and construct and train a network protection model based on the multiple training sets, multiple validation sets, and multiple test sets. The network protection model is a BP neural network model in machine learning that can continuously perform self-iterative optimization. The network protection model is obtained by training with multiple training data sets and multiple validation data sets. Among them, each set of training data in the multiple training data sets includes multiple regular inspection information, multiple analysis results, and the multiple coverage traversal results; the multiple validation data sets are validation data corresponding one-to-one to the training data sets.

[0063] Further, the process of constructing the network protection model is as follows: Input each set of training data in the multiple training data sets into the network protection model, and perform output verification and adjustment of the network protection model through the verification data corresponding to this set of training data. When the output result of the network protection model is consistent with the verification data, the current set of training ends. When all the training data in the multiple training data sets have been trained, the training of the network protection model is completed.

[0064] To ensure the accuracy of the network protection model, the output result of the network protection model can be evaluated for accuracy using multiple test data sets. For example, the test accuracy can be set to 80%. When the test accuracy meets 80%, the network protection model is obtained. Input multiple regular inspection information, the multiple analysis results, and multiple coverage traversal results into the network protection model, and output the first protection result information. Finally, select the first protection result information with the highest frequency of protection warning information in the first protection result information and output it as the protection result information. Further, determine the attack source through the network attack points extracted from the obtained protection information.

[0065] Embodiment 2

[0066] Based on the same inventive concept as a data analysis method based on active and passive detection in the foregoing embodiment, as Figure 2 shown, the present application provides a data analysis system based on active and passive detection. The system includes:

[0067] An information collection module 1, which is used to obtain network information. Among them, the network information includes network signal information, network data transmission information, and network data storage information;

[0068] A detection module 2, which is used to perform regular detection at a preset detection period based on the network signal information, the network data transmission information, and the network data storage information, and obtain multiple regular inspection information;

[0069] Analysis module 3, which is used to analyze network data through active and passive detection respectively to obtain multiple analysis results;

[0070] Coverage traversal module 4, which is used to perform coverage traversal on the network signal, network data transmission, and network data storage to obtain multiple coverage traversal results;

[0071] Input module 5, which is used to input the multiple regular inspection information, the multiple analysis results, and the multiple coverage traversal results into the network protection model to output protection result information, where the protection result information includes protection warning information;

[0072] Location module 6, which is used to add an active inspection task when receiving the protection warning information, obtain inspection data, trace the source in combination with the protection result information, and locate the attack source.

[0073] Furthermore, the system further includes:

[0074] The first security dimension detection module, which is used to perform network signal security dimension detection on the network signal information to obtain the first security dimension detection result;

[0075] The second security dimension detection module, which is used to perform network data transmission security dimension detection on the network data transmission information to obtain the second security dimension detection result;

[0076] The third security dimension detection module, which is used to perform network data storage security dimension detection on the network data storage information to obtain the third security dimension detection result;

[0077] The association module, which is used to associate the first security dimension detection result, the second security dimension detection result, and the third security dimension detection result based on the security factor set to obtain multiple regular inspection information.

[0078] Furthermore, the system further includes:

[0079] The first factor module, which is used to collect network status in real time to obtain network security factors;

[0080] The second factor module, which is used to collect security device logs in real time to obtain log security factors;

[0081] The third factor module, which is used to collect system operation data in real time to obtain operation security factors;

[0082] The association analysis module is used to perform association analysis on the network security factor, the log security factor, and the operation security factor based on an association function to obtain a set of security factors.

[0083] Furthermore, the system further includes:

[0084] The first weight setting module is used to set a first weight for the active detection.

[0085] The second weight setting module is used to set a second weight for the passive detection.

[0086] The first detection module is used to perform active and passive detections on a target host based on the first weight and the second weight to obtain an active and passive detection result.

[0087] The historical attack analysis module is used to perform historical attack analysis on the target host for the active and passive detection result to determine system attack points.

[0088] The addition module is used to add the system attack points to multiple analysis results.

[0089] Furthermore, the system further includes:

[0090] The second detection module is used to perform active detection on the target host to obtain a first detection result.

[0091] The third detection module is used to perform passive detection on the target host to obtain a second detection result.

[0092] The judgment module is used to judge whether to trigger an alarm of the target host security system based on the first detection result and the second detection result.

[0093] The update module is used to adjust the active and passive detection weights and update the active and passive detection result if triggered.

[0094] Furthermore, the system further includes:

[0095] The model construction module is used to construct the network protection model based on a BP neural network.

[0096] The annotation and division module is used to perform data annotation and division on the multiple regular inspection information, the multiple analysis results, and the multiple coverage traversal results to obtain multiple training sets, multiple verification sets, and multiple test sets.

[0097] A model acquisition module, which is used to separately perform supervised training, verification, and testing on the network protection model by using the multiple training sets, multiple validation sets, and multiple test sets, so as to obtain the network protection model with an accuracy rate meeting the preset requirements;

[0098] A first input module, which is used to input the multiple regular inspection information, the multiple analysis results, and the multiple coverage traversal results into the network protection model to obtain first protection result information;

[0099] An output module, which is used to output the first protection result information with the highest frequency of protection warning information in the first protection result information as the protection result information.

[0100] Through the foregoing detailed description of a data analysis method based on active and passive detection in this specification, those skilled in the art can clearly know a data analysis method and system based on active and passive detection in this embodiment. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method part.

[0101] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to these embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A data analysis method based on active and passive detection, characterized in that, The method includes: Obtain network information, where the network information includes network signal information, network data transmission information, and network data storage information; Based on the network signal information, the network data transmission information, and the network data storage information, set a preset detection period for regular detection to obtain multiple regular detection information; Analyze network data through active and passive detection respectively to obtain multiple analysis results; Perform coverage traversal on the network signal, the network data transmission, and the network data storage to obtain multiple coverage traversal results; Input the multiple regular detection information, the multiple analysis results, and the multiple coverage traversal results into a network protection model to output protection result information, where the protection result information includes protection warning information; When receiving the protection warning information, add an active inspection task, obtain inspection data, trace back in combination with the protection result information, and locate the attack source.

2. The method according to claim 1, characterized in that Obtain multiple regular detection information, the method includes: Perform network signal security dimension detection on the network signal information to obtain a first security dimension detection result; Perform network data transmission security dimension detection on the network data transmission information to obtain a second security dimension detection result; Perform network data storage security dimension detection on the network data storage information to obtain a third security dimension detection result; Based on a security factor set, associate the first security dimension detection result, the second security dimension detection result, and the third security dimension detection result to obtain multiple regular detection information.

3. The method according to claim 2, wherein Based on a security factor set, the method includes: Collect network status in real time to obtain network security factors; Collect security device logs in real time to obtain log security factors; Collect system operation data in real time to obtain operation security factors; Based on a correlation function, perform correlation analysis on the network security factors, the log security factors, and the operation security factors to obtain a security factor set.

4. The method according to claim 1, characterized in that, Obtain multiple analysis results, the method includes: Set a first weight for the active detection; Set a second weight for the passive detection; Based on the first weight and the second weight, perform active and passive detection on the target host to obtain an active and passive detection result; Perform historical attack analysis of the target host on the active and passive detection result to determine system attack points; Add the system attack points to the multiple analysis results.

5. The method according to claim 4, characterized in that Obtain an active and passive detection result, the method includes: Perform active detection on the target host to obtain a first detection result; Perform passive detection on the target host to obtain a second detection result; Based on the first detection result and the second detection result, determine whether to trigger the alarm of the target host security system; If triggered, adjust the active and passive detection weights and update the active and passive detection result.

6. The method according to claim 1, wherein Output protection result information, the method includes: Based on a BP neural network, construct the network protection model; Perform data annotation and division on the multiple regular detection information, the multiple analysis results, and the multiple coverage traversal results to obtain multiple training sets, multiple validation sets, and multiple test sets; Supervise and train, validate, and test the network protection model respectively using the multiple training sets, multiple validation sets, and multiple test sets to obtain the network protection model with an accuracy meeting the preset requirements; Input the multiple regular inspection information, the multiple analysis results, and the multiple coverage traversal results into the network protection model to obtain the first protection result information; Output the first protection result information with the highest frequency of protection warning information in the first protection result information as the protection result information.

7. A data analysis system based on active and passive detection, characterized in that The system includes: An information collection module for obtaining network information, where the network information includes network signal information, network data transmission information, and network data storage information; A detection module for setting a preset detection period for regular detection based on the network signal information, the network data transmission information, and the network data storage information to obtain multiple regular inspection information; An analysis module for analyzing network data through active and passive detection respectively to obtain multiple analysis results; A coverage traversal module for performing coverage traversal on the network signal, the network data transmission, and the network data storage to obtain multiple coverage traversal results; An input module for inputting the multiple regular inspection information, the multiple analysis results, and the multiple coverage traversal results into a network protection model and outputting protection result information, where the protection result information includes protection warning information; A positioning module for adding an active inspection task when receiving the protection warning information, obtaining inspection data, tracing back in combination with the protection result information, and positioning the attack source.

Citation Information

Patent Citations

  • Holographic evaluation system based on power data network and fault positioning method thereof

    CN108306756A

  • Network attack behavior real-time capturing and monitoring system of distributed architecture

    CN111885020A