A network space confrontation knowledge graph construction method based on operatorization framework
By constructing a cyberspace adversarial knowledge graph based on an operator-based framework, the problem of poor adversarial effectiveness at key nodes in the cyber adversarial process is solved, and continuous network adversarial and precise protection at critical time nodes are achieved.
Patent Information
- Application Number
- CN202310196919.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-03
- Publication Date
- 2026-01-02
- Estimated Expiration
- 2043-03-03
AI Technical Summary
In the process of network confrontation, the effectiveness of confrontation at key nodes is not good, especially in the rapidly changing battlefield of offense and defense, the response speed is slowed down, resulting in poor results.
Based on the operatorization framework, a cyberspace adversarial knowledge graph is constructed. By mining the set of operators in cyberspace, a target operator value framework is built, network attack and defense data is obtained, mapping and preprocessing are performed, a dataset is generated, a network adversarial knowledge graph is constructed, and information adversarial control is carried out.
It enables convenient aggregation of various fields and systems for continuous network confrontation at critical time points in cyberspace warfare, improves network protection efficiency, and can accurately protect against and prevent potential threats in advance, thereby reducing losses.
Smart Images

Figure CN116244449B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the technical field of network confrontation, and particularly relates to a network space confrontation knowledge graph construction method based on an operator framework. BACKGROUND
[0002] Network confrontation includes network attack and network protection. The network attack refers to attacking the hardware and software of a target network system and data in the system by comprehensively utilizing vulnerabilities and security defects existing in the target network. The network protection refers to protecting the network and equipment of a home party by comprehensively utilizing the functions and technical means of the network system of the home party, so that information data is not intercepted, tampered with or eliminated in the storage and transmission process, and the network security of the home party is protected.
[0003] In real life, from resisting hacker intrusion to protecting data security, cleaning harmful data, to dangerous defense in new technologies and new scenes, under the background of digital economy, the boundary of network security also begins to gradually expand, and in the rapidly changing attack and defense field, the protection of network security also faces multiple challenges, especially at the key time node of confrontation. Due to the increase of harmful information, the phenomenon of slow response speed often occurs, resulting in poor confrontation effect.
[0004] In summary, the prior art has the technical problem of poor confrontation effect at the key node in the network confrontation process. SUMMARY
[0005] Therefore, it is necessary to provide a network space confrontation knowledge graph construction method based on an operator framework in view of the above technical problems.
[0006] A network space confrontation knowledge graph construction method based on an operator framework, the method is applied to a network space confrontation knowledge graph construction system, and the method comprises the following steps: mining an operator set in a network space, wherein the operator set comprises a first operator, a second operator and a third operator; the first operator is an identity operator, the second operator is a strong operator, and the third operator is a bounded linear operator; performing convergence judgment on the second operator, combining the first operator and the third operator to form a target operator value framework; performing attack and defense in the network space based on the operator value framework to obtain network attack and defense data, wherein the network attack and defense data comprises network attack data and network defense data, and the network attack and defense data is provided with a time identifier; performing mapping corresponding on the network attack data and the network defense data, performing preprocessing based on a mapping result to obtain a construction data set; constructing a network confrontation knowledge graph based on the construction data set; and performing information confrontation control in the network space based on the network confrontation knowledge graph.
[0007] In one embodiment, further comprising: constructing a plurality of operator value frameworks based on the framework operator, wherein the plurality of operator value frameworks are primary frameworks; obtaining cyberspace confrontation demand, generating a framework fusion condition; based on the framework fusion condition, performing fusion conversion on the plurality of operator value frameworks to generate a target framework operator; and based on the target framework operator, generating the target operator value framework.
[0008] In one embodiment, further comprising: performing big data investigation and statistics to determine a plurality of network attack and defense types; mapping and corresponding the network attack data and the network defense data to obtain a mapping result; according to the plurality of network attack and defense types, traversing the mapping result to perform data division and attribution to determine a plurality of type data groups; and performing cleaning and screening on the plurality of type data groups to generate the constructed data set.
[0009] In one embodiment, further comprising: performing abnormal data elimination and missing data processing on the plurality of type data groups to generate a target data group; based on the target data group, respectively performing attack level and defense level configuration to determine data identification level; based on the target data group, extracting a defense system and a defense attribute for each group of target data, wherein the defense system in any group of data can be one or more; and according to the data identification level, the defense system and the defense attribute, generating the constructed data set.
[0010] In one embodiment, further comprising: based on the constructed data set, generating a plurality of attack and defense systems, wherein the plurality of attack and defense systems correspond one-to-one to the plurality of network attack and defense types; performing mutual influence analysis on the plurality of attack and defense systems, correlating the plurality of attack and defense systems based on system influence to generate the network confrontation knowledge graph.
[0011] In one embodiment, further comprising: obtaining real-time information confrontation data in cyberspace; traversing the network confrontation knowledge graph, performing node matching on the real-time information confrontation data to generate an associated sub-graph; performing structure analysis on the associated sub-graph to generate a defense management sequence; and based on the defense management sequence, performing information confrontation control in cyberspace.
[0012] In one embodiment, further comprising: performing structure analysis on the associated sub-graph to determine a target defense part and a derived defense part; configuring a defense priority for the target defense part and the derived defense part, wherein the priority of the target defense part is higher than that of the derived defense part; configuring a defense enablement time based on the defense priority; generating a plurality of defense management sequences based on the target defense part, the derived defense part, the defense priority and the defense enablement time; and constructing a defense management list based on the plurality of defense management sequences.
[0013] A network space confrontation knowledge graph construction system based on an operatorized framework comprises:
[0014] An operator set mining module is configured to mine an operator set in a network space, wherein the operator set comprises a first operator, a second operator and a third operator.
[0015] An operator set interpretation module is configured such that the first operator is an identity operator, the second operator is a strong operator, and the third operator is a set of bounded linear operators.
[0016] An operator value framework construction module is configured to judge the convergence of the second operator, and construct a target operator value framework in combination with the first operator and the third operator.
[0017] A network attack and defense data acquisition module is configured to perform attack and defense in the network space based on the operator value framework, and acquire network attack and defense data, wherein the network attack and defense data comprises network attack data and network defense data, and is provided with a time identifier.
[0018] A construction data set acquisition module is configured to map and correspond the network attack data and the network defense data, pre-process a mapping result, and acquire a construction data set.
[0019] A network confrontation knowledge graph construction module is configured to construct a network confrontation knowledge graph based on the construction data set.
[0020] An information confrontation control module is configured to perform information confrontation control in the network space based on the network confrontation knowledge graph.
[0021] The above network space confrontation knowledge graph construction method based on an operatorized framework can solve the technical problem of poor key node confrontation effect in a network confrontation process. The operator set in the network space is acquired through data mining, and the first operator, the second operator and the third operator in the acquired operator set are extracted. The network attack and defense data is obtained by constructing a target operator value framework, the network confrontation knowledge graph is further constructed, and finally the information confrontation control is performed in the network space based on the network confrontation knowledge graph, so as to achieve the effect of conveniently gathering various fields and systems for network continuous confrontation at key time nodes in the network space confrontation.
[0022] The above description is only a summary of the technical scheme of the present application. In order to more clearly understand the technical means of the present application, the specific embodiments of the present application can be implemented in accordance with the content of the description, and in order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the following specific embodiments of the present application are described. Attached Figure Description
[0023] Figure 1 This application provides a flowchart illustrating a method for constructing a cyberspace adversarial knowledge graph based on an operatorization framework;
[0024] Figure 2 This application provides a flowchart illustrating the process of constructing the target operator value framework in a network space adversarial knowledge graph construction method based on an operatorization framework;
[0025] Figure 3 This application provides a flowchart illustrating the process of obtaining the construction dataset in a network space adversarial knowledge graph construction method based on an operatorization framework;
[0026] Figure 4 This application provides a schematic diagram of the structure of a network space adversarial knowledge graph construction system based on an operatorization framework.
[0027] Figure labeling: 1. Operator set mining module; 2. Operator set interpretation module; 3. Operator value framework construction module; 4. Network attack and defense data acquisition module; 5. Data set acquisition module; 6. Network adversarial knowledge graph construction module; 7. Information adversarial control module. Detailed Implementation
[0028] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0029] like Figure 1 As shown, this application provides a method for constructing a cyberspace adversarial knowledge graph based on an operatorization framework. The method is applied to a cyberspace adversarial knowledge graph construction system and includes:
[0030] Step S100: Mining the set of operators in the network space, wherein the set of operators includes a first operator, a second operator, and a third operator;
[0031] Step S200: Wherein, the first operator is an identity operator, the second operator is a strong operator, and the third operator is all bounded linear operators;
[0032] Specifically, data mining is performed on operators in cyberspace to obtain an operator set. An operator refers to a mapping from one space to another in the network. The operator set includes a first operator, a second operator, and a third operator. The first operator is an identity operator, which includes a strong operator and multiple subsets in the strong operator mapping space. The second operator is a strong operator, meaning it can map to multiple subsets, which may include multiple weak operators. The set of all bounded linear operators is used to describe the range of the operators. By mining the operator set in cyberspace, raw data is provided for constructing a cyberspace adversarial knowledge graph.
[0033] Step S300: Perform a convergence judgment on the second operator, and combine the first operator and the third operator to form a target operator value framework;
[0034] like Figure 2 As shown, in one embodiment, step S300 of this application further includes:
[0035] Step S310: Based on the framework operator, construct multiple operator value frameworks, wherein the multiple operator value frameworks are primary frameworks;
[0036] Step S320: Obtain cyberspace adversarial requirements and generate framework fusion conditions;
[0037] Step S330: Based on the frame fusion conditions, the multiple operator value frames are fused and transformed to generate the target frame operator;
[0038] Step S340: Generate the target operator value framework based on the target framework operator.
[0039] Specifically, convergence is assessed for strong operators. When a strong operator is uniformly convergent, multiple operator value frames are constructed based on the basic framework architecture of the operators, combining the identity operator and all bounded linear operators. These multiple operator value frames are primary frames, including multiple strong operators and a subset of their mappings. Adversarial requirements in the cyberspace are obtained, including adversarial types, characteristics, and situations. Framework fusion conditions are generated based on these requirements. Then, based on these conditions, the multiple operator value frames are fused to generate a target frame operator, which includes multiple operator value frames. Finally, a target operator value frame is generated based on the target frame operator. Generating the target operator value frame provides support for obtaining network attack and defense data in the next step.
[0040] Step S400: Based on the operator value framework, perform attack and defense in cyberspace to obtain network attack and defense data, wherein the network attack and defense data includes network attack data and network defense data, and is marked with a time stamp;
[0041] Step S500: mapping the network attack data and the network defense data, preprocessing based on the mapping result, and obtaining a construction dataset;
[0042] As shown in Figure 3 the step S500 of the present application further includes, in an embodiment:
[0043] Step S510: conducting big data research and statistics to determine multiple network attack and defense types;
[0044] Step S520: mapping the network attack data and the network defense data to obtain a mapping result;
[0045] Step S530: according to the multiple network attack and defense types, traversing the mapping result to divide and attribute data, and determining multiple type data groups;
[0046] Step S540: cleaning and screening the multiple type data groups to generate the construction dataset.
[0047] In an embodiment, the step S540 of the present application further includes:
[0048] Step S541: removing abnormal data and processing missing data from the multiple type data groups to generate a target data group;
[0049] Step S542: respectively configuring attack levels and defense levels based on the target data group to determine data identification levels;
[0050] Step S543: based on the target data group, extracting a defense system and defense attributes for each group of target data, wherein the defense system in any group of data can be one or more;
[0051] Step S544: generating the construction dataset according to the data identification levels, the defense system, and the defense attributes.
[0052] Specifically, according to the operator value framework, network attack and defense tasks are performed in cyberspace to obtain network attack and defense data, which includes network attack data and network defense data with time identifiers. Based on big data technology, data query and statistics are performed to obtain various network attack and defense types, such as DOS attacks, phishing attacks, password attacks, etc. The network attack data and the network defense data are mapped, which means that multiple sets of network defense data are obtained from the network attack data, and a mapping result is obtained. According to the various network attack and defense types, the mapping result is sequentially divided into data to obtain multiple type data sets, which contain various network attack and defense types and corresponding network attack and defense data. First, the abnormal data in the multiple type data sets are removed, and the missing data are filled to generate a target data set. The attack and defense levels and the attack and defense level data range are set, the data in the target data set are identified according to the attack and defense level data range, and the data identification level is determined. The protection systems and protection attributes in the target data set are extracted, the protection attributes include active protection and passive protection, and any data set contains one or more protection systems. The data in the target data set are identified according to the protection systems and the protection attributes to generate the constructed data set, and the data in the constructed data set include data identification level, protection system and protection attribute. By generating the constructed data set, data support is provided for the next step of constructing the network confrontation knowledge graph.
[0053] Step S600: based on the constructed data set, a network confrontation knowledge graph is constructed;
[0054] In one embodiment, the step S600 of the present application further comprises:
[0055] Step S610: based on the constructed data set, multiple attack and defense systems are generated, wherein the multiple attack and defense systems correspond one-to-one to the various network attack and defense types;
[0056] Step S620: mutual influence analysis is performed on the multiple attack and defense systems, the multiple attack and defense systems are associated based on system influence, and the network confrontation knowledge graph is generated.
[0057] Specifically, the constructed data set is divided into data according to the various network attack and defense types to generate multiple attack and defense systems, wherein the multiple attack and defense systems correspond one-to-one to the various network attack and defense types. Then, mutual influence analysis is performed on the multiple attack and defense systems, the mutual influence analysis means that the relationship between the multiple attack and defense systems is judged, multiple systems with mutual relationship are associated with each other, and the network confrontation knowledge graph is generated. By generating the network confrontation knowledge graph, the attack in cyberspace can be accurately protected, and the efficiency of network protection is improved.
[0058] Step S700: Based on the network confrontation knowledge graph, information confrontation control is performed in cyberspace.
[0059] In one embodiment, the step S700 of the present application further comprises:
[0060] Step S710: Real-time information confrontation data in cyberspace is obtained;
[0061] Step S720: The network confrontation knowledge graph is traversed, the real-time information confrontation data is node-matched, and an associated sub-graph is generated;
[0062] Step S730: The associated sub-graph is structurally analyzed, and a protection management sequence is generated;
[0063] In one embodiment, the step S730 of the present application further comprises:
[0064] Step S731: The associated sub-graph is structurally analyzed, and a target protection part and a derived protection part are determined;
[0065] Step S732: A protection priority is configured for the target protection part and the derived protection part, wherein the priority of the target protection part is higher than that of the derived protection part;
[0066] Step S733: A protection enablement time is configured based on the protection priority;
[0067] Step S734: A plurality of protection management sequences are generated based on the target protection part, the derived protection part, the protection priority, and the protection enablement time;
[0068] Step S735: A protection management list is constructed based on the plurality of protection management sequences.
[0069] Step S740: Information confrontation control is performed in cyberspace based on the protection management sequence.
[0070] Specifically, the method involves obtaining real-time information warfare data in cyberspace, sequentially matching nodes in the real-time information warfare data according to the network warfare knowledge graph, and generating a related sub-graph based on multiple matched sub-nodes. Then, the related sub-graph is structurally analyzed to determine the target protection part and the derivative protection part. The target protection part is the main protection part, and the derivative protection part is the secondary protection part. The target protection part has a higher protection priority than the derivative protection part, meaning the target protection part is protected first. Protection activation time is configured according to the protection priority; the higher the protection priority, the shorter the activation time. Finally, multiple protection management sequences are generated based on the target protection part, the derivative protection part, the protection priority, and the protection activation time. A protection management list is further generated based on these sequences, with the protection parts arranged in ascending order of activation time. Finally, information warfare control is performed in cyberspace according to the protection management sequences, i.e., data in the protection management list is processed sequentially. This method solves the technical problem of poor combat effectiveness at key nodes in network warfare, achieving the effect of conveniently aggregating various fields and systems for continuous network warfare at key time nodes in cyberspace.
[0071] In one embodiment, such as Figure 4 The system provided is a network space adversarial knowledge graph construction system based on an operatorization framework, comprising: an operator set mining module 1, an operator set interpretation module 2, an operator value framework construction module 3, a network attack and defense data acquisition module 4, a dataset acquisition module 5, a network adversarial knowledge graph construction module 6, and an information adversarial control module 7. wherein:
[0072] Operator set mining module 1, the operator set mining module 1 is used to mine operator sets in network space, wherein the operator set includes a first operator, a second operator and a third operator;
[0073] Operator set interpretation module 2, wherein the first operator is an identity operator, the second operator is a strong operator, and the third operator is all bounded linear operators;
[0074] Operator value framework construction module 3 is used to perform convergence judgment on the second operator, and combine the first operator and the third operator to form a target operator value framework.
[0075] Network attack and defense data acquisition module 4 is used to perform attack and defense in cyberspace based on the operator value framework and acquire network attack and defense data, wherein the network attack and defense data includes network attack data and network defense data, and is marked with a time stamp;
[0076] A construction data set acquisition module 5 is configured to map and correspond the network attack data and the network defense data, preprocess based on a mapping result, and acquire a construction data set;
[0077] A network confrontation knowledge graph construction module 6 is configured to construct a network confrontation knowledge graph based on the construction data set;
[0078] An information confrontation control module 7 is configured to perform information confrontation control in cyberspace based on the network confrontation knowledge graph.
[0079] In one embodiment, the system further comprises:
[0080] An operator value framework construction module is configured to construct a plurality of operator value frameworks based on the framework operator, wherein the plurality of operator value frameworks are primary frameworks;
[0081] A framework fusion condition generation module is configured to acquire cyberspace confrontation requirements and generate a framework fusion condition;
[0082] A target framework operator generation module is configured to fuse and convert the plurality of operator value frameworks based on the framework fusion condition to generate a target framework operator;
[0083] A target operator value framework generation module is configured to generate the target operator value framework based on the target framework operator.
[0084] In one embodiment, the system further comprises:
[0085] A network attack and defense type determination module is configured to perform big data research and statistics to determine a plurality of network attack and defense types;
[0086] A data mapping module is configured to map and correspond the network attack data and the network defense data to acquire a mapping result;
[0087] A multi-type data group determination module is configured to perform data division and attribution on the mapping result according to the plurality of network attack and defense types to determine a multi-type data group;
[0088] A construction data set generation module is configured to clean and filter the multi-type data group to generate the construction data set.
[0089] In one embodiment, the system further comprises:
[0090] a target data set generation module configured to perform abnormal data elimination and missing data processing on the multi-type data sets to generate a target data set;
[0091] a data identification level determination module configured to respectively configure an attack level and a defense level based on the target data set to determine a data identification level;
[0092] a target data extraction module configured to extract a defense system and a defense attribute for each group of target data based on the target data set, wherein the defense system in any group of data can be one or more;
[0093] a construction data set generation module configured to generate the construction data set according to the data identification level, the defense system, and the defense attribute.
[0094] In one embodiment, the system further comprises:
[0095] a multi-group attack and defense system generation module configured to generate a multi-group attack and defense system based on the construction data set, wherein the multi-group attack and defense system corresponds to the multi-type network attack and defense type one-to-one;
[0096] a network confrontation knowledge graph generation module configured to perform mutual influence analysis on the multi-group attack and defense system, associate the multi-group attack and defense system based on system influence, and generate the network confrontation knowledge graph.
[0097] In one embodiment, the system further comprises:
[0098] a confrontation data acquisition module configured to acquire real-time information confrontation data in cyberspace;
[0099] an associated sub-graph generation module configured to traverse the network confrontation knowledge graph, perform node matching on the real-time information confrontation data, and generate an associated sub-graph;
[0100] a defense management sequence generation module configured to perform structural analysis on the associated sub-graph to generate a defense management sequence;
[0101] an information confrontation control module configured to perform information confrontation control in cyberspace based on the defense management sequence.
[0102] In one embodiment, the system further comprises:
[0103] a structure parsing module, configured to perform structure parsing on the associated sub-graph, and determine a target protection part and a derived protection part;
[0104] a protection priority configuration module, configured to configure protection priorities for the target protection part and the derived protection part, wherein the target protection part has a higher priority than the derived protection part;
[0105] a protection enablement time configuration module, configured to configure protection enablement times based on the protection priorities;
[0106] a protection management sequence generation module, configured to generate a plurality of protection management sequences based on the target protection part, the derived protection part, the protection priorities, and the protection enablement times;
[0107] a protection management list construction module, configured to construct a protection management list based on the plurality of protection management sequences.
[0108] In summary, the network space confrontation knowledge graph construction method based on the operatorized framework provided in the present application has the following technical effects:
[0109] 1. The technical problem of poor key node confrontation effect in network confrontation is solved, the target operator value framework is constructed to obtain network attack and defense data, the network confrontation knowledge graph is further constructed, and finally, information confrontation control is performed in the network space based on the network confrontation knowledge graph, so that the effect of gathering various fields and systems for network continuous confrontation at key time nodes in the network space confrontation is achieved.
[0110] 2. By performing structure parsing on the associated sub-graph, the protection management sequence is generated, the attack information in the network space can be accurately protected, the efficiency of network protection is improved, and potential threats existing in the network space can be prevented and handled in advance, so that the loss is reduced.
[0111] The technical features of the above embodiments can be combined arbitrarily, and to make the description concise, all possible combinations of the technical features in the above embodiments are not described, however, as long as the combinations of the technical features do not exist contradictory, they should be considered as the scope of the present disclosure.
[0112] The above-described embodiments are merely illustrative of several embodiments of the present application, which are described in more detail and in a specific and detailed manner, but should not be construed as limiting the scope of the patent. It should be noted that for those skilled in the art, several modifications and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.
Claims
1. A cyber space confrontation knowledge graph construction method based on operatorized framework, characterized in that, The method is applied to a network space confrontation knowledge graph construction system, and the method comprises the following steps: Mining an operator set in a network space, wherein the operator set comprises a first operator, a second operator and a third operator; The first operator is an identity operator, the second operator is a strong operator, and the third operator is a set of bounded linear operators; Convergence of the second operator is judged, and a target operator value framework is formed in combination with the first operator and the third operator; Based on the operator value framework, network attack and defense are performed in the network space to obtain network attack and defense data, wherein the network attack and defense data comprises network attack data and network defense data, and is provided with a time identifier; The network attack data and the network defense data are mapped and corresponded, and a construction data set is obtained based on the mapping result after preprocessing; Based on the construction data set, a network confrontation knowledge graph is constructed; Based on the network confrontation knowledge graph, information confrontation control is performed in the network space; The information confrontation control in the network space based on the network confrontation knowledge graph comprises the following steps: Real-time information confrontation data in the network space is obtained; The network confrontation knowledge graph is traversed, the real-time information confrontation data is node-matched to generate an associated sub-graph; The associated sub-graph is structurally analyzed to generate a protection management sequence; Based on the protection management sequence, information confrontation control is performed in the network space; The network attack data and the network defense data are mapped and corresponded, and a construction data set is obtained based on the mapping result after preprocessing, which comprises the following steps: Big data research and statistics are performed to determine multiple network attack and defense types; The network attack data and the network defense data are mapped and corresponded to obtain a mapping result; According to the multiple network attack and defense types, the mapping result is traversed for data division and attribution to determine multiple type data groups; The multiple type data groups are cleaned and screened to generate the construction data set; Based on the construction data set, a network confrontation knowledge graph is constructed, which comprises the following steps: Based on the construction data set, multiple attack and defense systems are generated, wherein the multiple attack and defense systems correspond to the multiple network attack and defense types one by one; The multiple attack and defense systems are analyzed for mutual influence, the multiple attack and defense systems are associated based on system influence, and the network confrontation knowledge graph is generated; The associated sub-graph is structurally analyzed to generate a protection management list, which comprises the following steps: The associated sub-graph is structurally analyzed to determine a target protection part and a derived protection part; For the target protection part and the derived protection part, a protection priority is configured, wherein the priority of the target protection part is higher than that of the derived protection part; Based on the protection priority, a protection enablement time is configured; Based on the target protection part, the derived protection part, the protection priority and the protection enablement time, multiple protection management sequences are generated; Based on the multiple protection management sequences, a protection management list is constructed.
2. The method of claim 1, wherein, The target operator value framework is formed, which comprises the following steps: Based on the framework operator integrated by the first operator, the second operator and the third operator in the operator set, a plurality of operator value frameworks are constructed, wherein the plurality of operator value frameworks are primary frameworks; Cyberspace confrontation requirements are obtained, and a framework fusion condition is generated; Based on the framework fusion condition, the plurality of operator value frameworks are fused and converted to generate a target framework operator; Based on the target framework operator, the target operator value framework is generated.
3. The method of claim 1, wherein, The cleaning and screening of the plurality of types of data groups to generate the construction data set includes: The plurality of types of data groups are subjected to abnormal data elimination and missing data processing to generate a target data group; Based on the target data group, attack levels and defense levels are configured respectively to determine data identification levels; Based on the target data group, protection systems and protection attributes are extracted for each group of target data, wherein the protection system in any group of data can be one or more; According to the data identification levels, the protection systems and the protection attributes, the construction data set is generated.
4. An operatorized framework-based cyber space adversarial knowledge graph construction system, characterized in that, The system is used to implement the cyberspace confrontation knowledge graph construction method based on the operator framework according to any one of claims 1-3, and the system includes: An operator set mining module, which is used to mine an operator set in cyberspace, wherein the operator set includes a first operator, a second operator and a third operator; An operator set interpretation module, wherein the first operator is an identity operator, the second operator is a strong operator, and the third operator is a total bounded linear operator; An operator value framework construction module, which is used to judge the convergence of the second operator and construct a target operator value framework in combination with the first operator and the third operator; A network attack and defense data acquisition module, which is used to execute attack and defense in cyberspace based on the operator value framework to acquire network attack and defense data, wherein the network attack and defense data includes network attack data and network defense data with time identifiers; A construction data set acquisition module, which is used to map and correspond the network attack data and the network defense data, pre-process based on the mapping result, and acquire a construction data set; A network confrontation knowledge graph construction module, which is used to construct a network confrontation knowledge graph based on the construction data set; An information confrontation control module, which is used to perform information confrontation control in cyberspace based on the network confrontation knowledge graph.
Citation Information
Patent Citations
Hacker attack scene construction method and equipment based on knowledge graph
CN114726634A
Prioritizing security controls using a cyber digital twin simulator
US20230067128A1