Data analysis method, medium and device for cyber space network security situation awareness

By constructing a situational analysis model library with multiple driving methods, and dynamically calling suitable models for cybersecurity analysis, the problems of timeliness and accuracy of analysis results in existing technologies are solved, and flexible and accurate data analysis and spiral growth of the knowledge base are realized.

CN116527351BActive Publication Date: 2026-01-06ZHENGZHOU XINDA ADVANCED TECH RES INST
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310441177.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-23
Publication Date
2026-01-06
Estimated Expiration
2043-04-23

AI Technical Summary

Technical Problem

Existing technologies are insufficient for quickly and accurately analyzing diverse cybersecurity issues in cyberspace, resulting in inadequate timeliness and accuracy of data analysis results.

Method used

By pre-setting the mapping relationship between cybersecurity issues and type identifiers, and between type identifiers and situation analysis models, a situation analysis model library is constructed, which includes knowledge-driven, data-driven, and hybrid-driven approaches, and the appropriate model is dynamically called for analysis.

Benefits of technology

It improves the flexibility and adaptability of the data analysis process for cybersecurity situational awareness in cyberspace, ensures the accuracy and timeliness of analysis results, and enhances analytical capabilities through closed-loop updates of the knowledge base.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116527351B_ABST
    Figure CN116527351B_ABST
Patent Text Reader

Abstract

The application provides a kind of cyberspace network security situation awareness data analysis method, medium and equipment, the method comprises the following steps: obtaining problem to be analyzed, and extracting type identifier from the problem to be analyzed;According to the type identifier, select the situation analysis model matched with the problem to be analyzed;Read the network security situation data corresponding to the problem to be analyzed, input the network security situation data corresponding to the problem to be analyzed into the selected situation analysis model, to obtain the analysis result corresponding to the problem to be analyzed.The application pre-constructs a variety of driving mode situation analysis models for different problems in advance, and when analyzing network security problems, different situation analysis models are dynamically called based on different problems to be analyzed for situation assessment and prediction, so as to ensure the timeliness of cyberspace network security situation awareness while improving the accuracy of analysis results.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of cyberspace security, in particular to a cyberspace network security situation awareness data analysis method, medium and equipment. BACKGROUND

[0002] With the continuous development of information technology and network technology, cyberspace emerges as the times require and becomes the fifth territory after land, sea, air and space; "cyberspace" refers to a digital virtual space composed of data, computing and network, which is not only a network space, but also an extremely dispersed area, characterized by increasing global connectivity, ubiquity and mobility.

[0003] Cyberspace network refers to a multi-hop three-dimensional network formed by mobile nodes and fixed nodes through wireless links; cyberspace network security problem refers to attacking the potential problems of communication network technology or engineering application by using the defects of communication network technology system, so as to make the communication network work abnormally.

[0004] Communication network is an important part of cyberspace, and its own security will directly affect the security of the whole cyberspace, so it is urgent to conduct in-depth research and design on cyberspace network security situation awareness to meet the security needs of future cyberspace development.

[0005] Therefore, for the diversified cyberspace network security problems, how to quickly and accurately analyze has become a technical problem to be solved.

[0006] In order to solve the above problems, people have been seeking an ideal technical solution. SUMMARY

[0007] The present application provides a cyberspace network security situation awareness data analysis method, medium and equipment, which can enhance the relevance between the problem to be analyzed and the situation analysis model, make the data analysis process of cyberspace network security situation awareness more flexible, and effectively improve the accuracy of data analysis results and the timeliness of analysis results.

[0008] In order to achieve the above purpose, the first aspect of the present application provides a cyberspace network security situation awareness data analysis method, which comprises the following steps:

[0009] Obtain the problem to be analyzed, and extract the type identifier from the problem to be analyzed; wherein the type identifier and the pre-set situation analysis model have a mapping relationship;

[0010] Based on the type identifier, select a situation analysis model that matches the problem to be analyzed:

[0011] If the type identifier is a first identifier, then a knowledge-driven situation analysis model is selected as the situation analysis model that matches the problem to be analyzed; if the type identifier is a second identifier, then a data-driven situation analysis model is selected as the situation analysis model that matches the problem to be analyzed; if the type identifier is a third identifier, then a situation analysis model based on both knowledge-driven and data-driven approaches is selected as the situation analysis model that matches the problem to be analyzed.

[0012] Read the network security situation data corresponding to the problem to be analyzed;

[0013] The read network security situation data is input into the selected situation analysis model to obtain the analysis results corresponding to the problem to be analyzed.

[0014] To achieve the above objectives, a second aspect of the present invention provides a computer-readable storage medium storing computer-readable instructions that cause at least one processor to execute the data analysis method for cyberspace network security situational awareness as described above.

[0015] To achieve the above objectives, a third aspect of the present invention provides a data analysis device, which includes a memory and a processor. The memory stores computer-readable instructions, and when the computer-readable instructions are executed by the processor, they implement the data analysis method for cyberspace network security situation awareness as described above.

[0016] The beneficial effects of this invention are as follows:

[0017] 1) This invention enhances the correlation between the problem to be analyzed and the situation analysis model by pre-setting the mapping relationship between the cybersecurity problem and the type identifier, the type identifier and the situation analysis model, and pre-constructing a situation analysis model library that includes knowledge-driven situation analysis models, data-driven situation analysis models and situation analysis models based on both knowledge-driven and data-driven approaches. When analyzing diverse cybersecurity problems, this invention can quickly and accurately select the matching situation analysis model based on the obtained problem to be analyzed and the type identifier, thereby improving the matching degree between the problem to be analyzed and the situation analysis model.

[0018] 2) Compared to a single model that analyzes a single problem, the data analysis process for cybersecurity situational awareness in this invention is more flexible and adaptable.

[0019] 3) This invention pre-constructs situation analysis models with multiple driving modes for different problems, and dynamically calls different situation analysis models to perform situation assessment and prediction based on different problems to be analyzed when analyzing network security issues, thereby ensuring the timeliness of cyberspace network security situation awareness while improving the accuracy of analysis results;

[0020] 4) This invention also extracts and refines the analysis results after prediction and evaluation, thereby enriching the cybersecurity knowledge base, forming a closed loop of knowledge and data, and spiraling upward to improve the cybersecurity situation data analysis and processing capabilities of cyberspace. Attached Figure Description

[0021] Figure 1 This is a flowchart illustrating the data analysis process for cybersecurity situational awareness in cyberspace according to the present invention. Figure One ;

[0022] Figure 2 This is a flowchart illustrating the data analysis process for cybersecurity situational awareness in cyberspace according to the present invention. Figure Two ;

[0023] Figure 3 This is a schematic diagram of the knowledge-driven data analysis process of the present invention;

[0024] Figure 4 This is a schematic diagram of the data-driven data analysis process of the present invention;

[0025] Figure 5 A schematic diagram of the knowledge-data hybrid-driven data analysis process of the present invention;

[0026] Figure 6 This is a schematic diagram of the cyberspace network security situation awareness data analysis framework of the present invention. Detailed Implementation

[0027] The technical solution of the present invention will be further described in detail below through specific embodiments.

[0028] Example 1

[0029] As attached Figure 1 and attached Figure 2 As shown, a data analysis method for cybersecurity situational awareness in cyberspace includes the following steps:

[0030] Step 1: Obtain the problem to be analyzed and extract the type identifier from the problem to be analyzed; wherein, there is a mapping relationship between the type identifier and the preset situation analysis model;

[0031] The problem to be analyzed is pre-configured to include key problem information, type identifier, and knowledge-driven / data-driven / hybrid-driven tags. The key problem information is used to identify the problem to be analyzed and can be pre-agreed English abbreviations, numerical serial numbers, etc.

[0032] The problems to be analyzed mentioned above are either manually entered or selected by the user, or are pre-configured in the system and analyzed at fixed time intervals.

[0033] The problems to be analyzed are one or more of the preset cyberspace network security problems. When the number of problems to be analyzed is greater than 1, each problem to be analyzed is pre-configured to be processed in parallel to improve analysis efficiency.

[0034] The presupposed cybersecurity issues in cyberspace include both simple and complex cybersecurity incident analysis.

[0035] The mapping relationship between the aforementioned type identifiers and the preset situation analysis models is a pre-configured and pre-stored mapping relationship, which prepares for selecting a situation analysis model based on the type identifiers. One type identifier corresponds to one type of situation analysis model. For example, there is a mapping relationship between the type identifier KD and the knowledge-driven situation analysis model, a mapping relationship between the type identifier DD and the data-driven situation analysis model, and a mapping relationship between the type identifier HD and the situation analysis models based on both knowledge-driven and data-driven approaches.

[0036] Step 2: Select a situation analysis model that matches the problem to be analyzed based on the type identifier;

[0037] If the type identifier is the first identifier, then the knowledge-driven situation analysis model is selected as the situation analysis model that matches the problem to be analyzed.

[0038] If the type identifier is the second identifier, then the data-driven situation analysis model is selected as the situation analysis model that matches the problem to be analyzed.

[0039] If the type identifier is a third identifier, then a situation analysis model based on knowledge-driven and data-driven approaches is selected as the situation analysis model that matches the problem to be analyzed.

[0040] Step 3: Read the network security situation data corresponding to the problem to be analyzed;

[0041] It is understandable that different cybersecurity situation data correspond to different problems to be analyzed;

[0042] The aforementioned cybersecurity situation data refers to information on elements that can affect cybersecurity, collected through various detection tools, including intrusion detection systems, Wireshark, etc.

[0043] It is understandable that, depending on the data source, cybersecurity situational elements in cyberspace can be categorized into: network environment data, network vulnerability data, network attack data, and cybersecurity incidents, etc.

[0044] The network environment data refers to multiple data related to network security status, such as network topology, network processes, and application configurations.

[0045] The network vulnerability data refers to the vulnerability attributes, vulnerability objects, and exploitation methods collected by attackers when they scan various network systems for defects in software and hardware such as code, protocol design, and security policies, and use these defects to achieve unauthorized access or privilege escalation to launch attacks on the system.

[0046] The network attack data refers to the attack attributes, attack tools, security status, attackers, and attack results collected when attackers use various attack methods to illegally intrude into, eavesdrop on, deceive, or even destroy security targets. Network attacks cause serious damage to the hardware and software facilities and system data in network systems and are a major threat to network security.

[0047] The network security incidents refer to the raw events and log events collected when a series of abnormal activities occur that threaten the operation of the network and application systems; each log file records a separate network security incident.

[0048] Step 4: Input the read network security situation data into the selected situation analysis model to obtain the analysis results corresponding to the problem to be analyzed.

[0049] It is understandable that the question to be analyzed containing the first identifier is pre-configured as a simple network security incident analysis. This type of question usually targets a small number of network security data types and can be described with specific rules and knowledge; for example, simple user behavior analysis and simple network threat analysis (is the likelihood of device intrusion high, or will the likelihood of device intrusion increase?).

[0050] The problem to be analyzed containing the second identifier is pre-configured as the first type of complex network security incident analysis. This type of problem usually involves a large amount of data, which is difficult to describe with knowledge patterns and requires data mining and analysis. Generally, it requires the use of machine learning, deep learning and other methods, such as network security situation assessment, abnormal behavior detection, vulnerability detection and other problems.

[0051] The problem to be analyzed containing a third identifier is pre-configured as the second type of complex network security incident analysis. This type of problem usually involves a large amount of data and requires analysis and mining from the data. It generally uses methods such as machine learning and deep learning. However, the influence of domain knowledge needs to be considered in the decision-making process and model building process, such as network security situation prediction and software security vulnerability analysis.

[0052] It should be noted that this embodiment enhances the correlation between the problem to be analyzed and the situation analysis model by pre-setting the mapping relationship between the cybersecurity issues and type identifiers, the type identifiers and the situation analysis model, and pre-constructing a situation analysis model library that includes knowledge-driven situation analysis models, data-driven situation analysis models and situation analysis models based on both knowledge-driven and data-driven approaches.

[0053] When analyzing diverse cybersecurity issues in cyberspace, this embodiment can quickly and accurately select a situational analysis model that matches the problem to be analyzed based on the acquired problem and type identifier.

[0054] It should be noted that since the situation analysis model in this embodiment is generated for different problems, the application of this embodiment is very wide.

[0055] Example 2

[0056] Based on Example 1, this example provides a specific implementation method for data analysis of cyberspace network security situation awareness when the type identifier is the first identifier.

[0057] Specifically, the knowledge-driven situational analysis model refers to a rule-based knowledge base generated based on a cybersecurity knowledge base, which includes at least one IF condition THEN event.

[0058] The aforementioned cybersecurity knowledge base stores expert knowledge, historical experience, and domain knowledge.

[0059] It is understandable that when building a knowledge-driven situational analysis model, the following steps are taken: based on a cybersecurity knowledge base established by expert knowledge, domain knowledge, and rule knowledge, the existing knowledge and experience of experts, domain knowledge, etc., are transformed into rule-based knowledge such as IF conditions and THEN events through certain methods.

[0060] As attached Figure 3As shown, if the type identifier in the problem to be analyzed is the first identifier, then a knowledge-driven tag is extracted from the problem to be analyzed, and there is a preset mapping relationship between the knowledge-driven tag and the IF condition THEN event;

[0061] The aforementioned knowledge-driven tags are used to mark IF condition THEN events in the rule-based knowledge base, and a mapping relationship is pre-established between a knowledge-driven tag and an IF condition THEN event;

[0062] Based on the extracted knowledge-driven tags, the IF condition THEN event corresponding to the knowledge-driven tags is searched from the rule-based knowledge base as the target event;

[0063] Obtain the network security situation data corresponding to the problem to be analyzed, as the data to be analyzed;

[0064] The data to be analyzed is extracted to form regularized data;

[0065] The rule-based data is analyzed to obtain conditional data related to the target event;

[0066] Based on the target event, knowledge reasoning is performed on the conditional data, and the result of the knowledge reasoning is used as the analysis result corresponding to the problem to be analyzed.

[0067] The above-mentioned extraction of the data to be analyzed to form regularized data refers to the reduction processing of the data to be analyzed to form a data format that conforms to a preset standard.

[0068] Data reduction includes outlier removal, redundancy removal, and data standardization. Outlier removal refers to eliminating data with significant deviations. Redundancy removal refers to removing similar data with the same attributes to reduce the amount of data to be analyzed. Data standardization aims to eliminate the influence of dimensions between indicators to ensure comparability and facilitate subsequent analysis. Element data standardization is not applied to all element data. Data standardization methods include min-max standardization, Z-score standardization, simplified Z-scores, logarithmic transformation, decimal scaling, and the sigmoid function.

[0069] In one specific implementation, the problem to be analyzed is whether a device in a cyberspace network is likely to be compromised.

[0070] The type identifier in the problem to be analyzed is the first identifier. At this time, it is necessary to extract the knowledge-driven tag from the problem to be analyzed. For example, the knowledge-driven tag is kd00000001. There is a mapping relationship between kd000000001 and the event "IF Firewall is closed and the frequency of browsing high-risk web pages is greater than the browsing threshold THEN indicates that the device is likely to be intruded".

[0071] Based on the extracted knowledge-driven tag kd00000001, the event "IF firewall is off and browsing high-risk web pages more frequently than the browsing threshold THEN indicates that the device is likely to be compromised" is searched from the rule-based knowledge base and used as the target event.

[0072] Obtain the network security situation data corresponding to the problem to be analyzed, as the data to be analyzed; extract the data to be analyzed to form rule-based data, and obtain user behavior data {A1, A2, ..., A...}. m}, m refers to the number of users, and the i-th user behavior data A i This includes user device identifier, operating system identifier, user IP, whether security software is installed, firewall status identifier, and browsing page identifier;

[0073] The rule-based data is analyzed to obtain conditional data related to the target event, such as whether the frequency of browsing high-risk web pages is greater than the browsing threshold, and whether the firewall is turned off.

[0074] Based on the target event, knowledge reasoning is performed on the conditional data. Since the conditional data is consistent with the conditions of the target event, the analysis result is that the device is likely to have been compromised.

[0075] In another specific implementation, the problem to be analyzed is whether the possibility of a device in the cyberspace network being compromised has increased.

[0076] The type identifier in the problem to be analyzed is the first identifier. At this time, it is necessary to extract the knowledge-driven tag from the problem to be analyzed. For example, the knowledge-driven tag is kd00000002. There is a mapping relationship between kd00000002 and the event "IF Firewall is closed and security software is not installed THEN prompts that the possibility of the device being compromised is increased".

[0077] Based on the extracted knowledge-driven tag kd00000002, the event "IF firewall is off and security software is not installed THEN indicates that the device is more likely to be compromised" is searched from the rule-based knowledge base and selected as the target event.

[0078] Obtain network security situation data corresponding to the problem to be analyzed, as the data to be analyzed; extract the data to be analyzed to form rule-based data; wherein, the rule-based data is user behavior data {A1, A2, ..., A...} m}, m refers to the number of users, and the i-th user behavior data A i This includes user device identifier, operating system identifier, user IP, whether security software is installed, firewall status identifier, and browsing page identifier;

[0079] The rule-based data is analyzed to obtain conditional data related to the target event, such as whether the firewall is turned off and whether the security software is installed; knowledge reasoning is performed on the conditional data based on the target event, such as the conditional data including that the firewall is turned off and the security software is not installed;

[0080] Based on the target event, knowledge reasoning is performed on the conditional data. Since the conditional data is consistent with the conditions of the target time, the analysis result indicates that the possibility of the device being hacked has increased.

[0081] In other specific implementations, after obtaining user behavior data, the following is also performed:

[0082] The system collects data on user behavior such as disabling firewalls, browsing high-risk websites, and not installing security software, as well as the data from these overlapping data points. The system then visualizes this data and outputs the intrusion threat level of m users based on knowledge from the knowledge base.

[0083] It should be noted that the knowledge-driven situational analysis model's knowledge reasoning process for the problem to be analyzed mainly includes: acquiring network security situational data corresponding to the problem to be analyzed; then extracting the network security situational data to make it rule-based data; then analyzing and summarizing the rule-based data; performing knowledge reasoning based on the IF condition THEN event that matches the problem to be analyzed; and finally visualizing the results to obtain the analysis results corresponding to the problem to be analyzed.

[0084] Example 3

[0085] Based on Example 1, this example provides a specific implementation method for data analysis of cyberspace network security situation awareness when the type identifier is a second identifier.

[0086] Specifically, the data-driven situation analysis model refers to training a pre-set model using a dataset related to a pre-set problem to obtain a set of situation analysis models for the pre-set problem; specifically, it includes classification models and prediction models.

[0087] Among them, the datasets related to the preset questions include network environment datasets, network vulnerability datasets, network attack datasets, and network security incident datasets, etc.

[0088] The pre-built models include one or more of the following: situation analysis models based on support vector machines, KNN, random forest, RNN, ResNet, and CNN.

[0089] It is understandable that when building a data-driven situation analysis model, a dataset related to a pre-defined problem is constructed by labeling, and a pre-built machine learning / deep learning model is trained to finally obtain a situation analysis model for a certain pre-defined problem.

[0090] As attached Figure 4 As shown, if the type identifier in the problem to be analyzed is the second identifier, then a data-driven label is extracted from the problem to be analyzed, and there is a preset mapping relationship between the data-driven label and the preset situation analysis model for the preset problem.

[0091] The aforementioned data-driven tags are used to label classification or prediction models in a set of situation analysis models for a predefined problem. A mapping relationship is pre-established between a data-driven tag and a classification or prediction model.

[0092] Based on the data-driven tags, a corresponding classification model or prediction model is obtained from the set of situation analysis models for the preset problem, and used as the first target model;

[0093] Obtain the network security situation data corresponding to the problem to be analyzed, as the data to be analyzed;

[0094] The data to be analyzed is identified based on the first target model, and the identification result is used as the analysis result corresponding to the problem to be analyzed.

[0095] In one specific implementation, the problem to be analyzed is whether intrusion detection exists in the cyberspace network;

[0096] The type identifier in the problem to be analyzed is the second identifier. At this time, it is necessary to extract the data-driven label from the problem to be analyzed. For example, the data-driven label is dd00000001. There is a mapping relationship between dd00000001 and the classification model for intrusion detection.

[0097] It should be noted that when constructing a classification model for intrusion detection: first, the KDD dataset is processed (dataset processing includes downsampling, normalization, and removal), and then the KDD dataset is input into a pre-built model to train the situation analysis model, generating a classification model for intrusion detection;

[0098] The KDD dataset contains over 5 million training data points and 2 million test data points. It includes 41 feature attributes, categorized into basic features, traffic features, and content features. The dataset can be divided into four main categories based on attack type: Probe monitoring / probing dataset, Denial-of-Service (DoS) dataset, Unauthorized U2R (Unauthorized Access to Superuser Privileges) dataset, and Unauthorized R2L (Unauthorized Access to Remote Hosts) dataset.

[0099] Based on the data-driven tag dd00000001, a classification model for intrusion detection is obtained from the set of situation analysis models for a preset problem, and used as the first target model;

[0100] The network security situation data corresponding to the problem to be analyzed is input into the first target model, and the attack type (the above 4 categories) is output as the analysis result corresponding to the problem to be analyzed.

[0101] Example 4

[0102] Based on Example 1, this example provides a specific implementation method for data analysis of cyberspace network security situation awareness when the type identifier is a third identifier.

[0103] Specifically, the knowledge-driven and data-driven situational analysis model refers to a set of hybrid driven models generated based on the cybersecurity knowledge base, datasets related to preset issues, and pre-set models.

[0104] The datasets related to the preset questions include network environment datasets, network vulnerability datasets, network attack datasets, and network security incident datasets. The network security situation data includes knowledge from the network security knowledge base.

[0105] The pre-built models include one or more of the following: situation analysis models based on support vector machines, KNN, random forest, RNN, ResNet, and CNN.

[0106] It should be noted that while knowledge-driven situation analysis models are efficient, they suffer from a simple structure and can only use existing knowledge; while data-driven situation analysis models improve accuracy, they still suffer from poor interpretability and poor generalization ability.

[0107] Therefore, this embodiment proposes a situation analysis model based on knowledge-driven and data-driven approaches. This situation analysis model is a hybrid knowledge- and data-driven approach, a new model proposed to address the shortcomings of each individual knowledge-driven and data-driven approach. Its core is to combine the advantages of knowledge-driven and data-driven approaches. This process has two aspects: first, during the construction of the data-driven model, the model is improved using rule knowledge related to the preset problem, enhancing the interpretability of the situation analysis model and its ability to analyze the preset problem; second, (after the model is trained) during data analysis, rule knowledge related to the preset problem is used to assist decision-making after the model makes predictions, avoiding obvious errors in the model's prediction results and enhancing the credibility of hybrid decision-making.

[0108] As attached Figure 5 As shown, if the type identifier in the problem to be analyzed contains a third identifier, then a hybrid driving label is extracted from the problem to be analyzed, and there is a preset mapping relationship between the hybrid driving label and the preset hybrid driving classification model;

[0109] The aforementioned hybrid driving labels are used to mark classification models or prediction models in the hybrid driving model set. There is a pre-established mapping relationship between a hybrid driving label and a classification model or a prediction model in the driving model set.

[0110] Based on the hybrid driving label, the corresponding hybrid driving model is obtained from the hybrid driving model set and used as the second target model;

[0111] Obtain the network security situation data corresponding to the problem to be analyzed, as the data to be analyzed;

[0112] The data to be analyzed is identified based on the second target model, and the identification results are analyzed using the rule knowledge in the network security knowledge base to obtain the analysis results corresponding to the problem to be analyzed.

[0113] In one specific implementation, the problem to be analyzed is whether there are software security vulnerabilities in cyberspace network security;

[0114] The type identifier in the problem to be analyzed is a third identifier, and the hybrid driver label extracted from the problem to be analyzed is hd00000001. There is a mapping relationship between hd00000001 and the prediction model for software security vulnerability detection.

[0115] It should be noted that when constructing a predictive model for software security vulnerability detection: The NVD software security vulnerability dataset is obtained, and the dataset is preprocessed (preprocessing typically involves combining rule knowledge to remove redundant and non-compliant data, thereby enhancing data quality); then, the data is input into a pre-built model for training to obtain the predictive model for software security vulnerability detection; the NVD software security vulnerability dataset contains vulnerability information such as CVE-ID, CVSS_score, CVSS_Accuracyess, CVSS_vector, vuln-source, CWE-ID, and vuln-summary.

[0116] In the process of building a predictive model for software security vulnerability detection, the model can be improved by combining domain knowledge related to software security vulnerability detection (such as relevant intrusion detection indicators), which can make the model more specialized.

[0117] Based on the hybrid driver tag hd00000001, a prediction model for software security vulnerability detection is obtained from the hybrid driver model set and used as the second target model.

[0118] The network security situation data corresponding to the problem to be analyzed is obtained as the data to be analyzed; the data to be analyzed is identified or predicted based on the second target model to obtain the prediction result; then, domain knowledge related to software security vulnerability detection is used to guide and suggest the prediction result; for example, if the prediction result is of type CVSS_score, but its related indicators are obviously of type CVE-ID according to rule knowledge, then rule knowledge can be used to guide the prediction result and the CVE-ID type can be used as the final analysis result.

[0119] It should be noted that this embodiment dynamically calls the corresponding situation analysis model based on the received problem to be analyzed, and evaluates the current cyberspace network situation security, which not only has high analysis efficiency but also high accuracy of analysis results.

[0120] In other specific implementations, after obtaining the analysis results, the specific degree of danger is also analyzed, and early warning levels and decision-making suggestions for the network security situation are given (the decision-making suggestions are different for different assessment problems), and the danger level is visualized and described in a graded manner; for example, it can be divided into three levels: Level 1 is low danger level, no action is required; Level 2 is medium danger level, attention is required, and the behavior should be stopped at any time; Level 3 is high danger level, and the behavior should be stopped immediately.

[0121] Example 5

[0122] Based on the above embodiments, this embodiment provides a specific implementation method for another data analysis method for cyberspace network security situation awareness.

[0123] As attached Figure 6 As shown, the data analysis method for cybersecurity situational awareness in cyberspace also performs the following: updating the pre-built cybersecurity knowledge base based on the analysis results.

[0124] It should be noted that this embodiment extracts cybersecurity knowledge in cyberspace. Specifically, it extracts the relevant results output by the situation analysis model to form rule-based cybersecurity knowledge, and inputs the obtained knowledge into the cybersecurity knowledge base to enrich the cybersecurity knowledge base, form a knowledge closed loop, and spirally improve the capabilities of the knowledge base and the situation analysis model.

[0125] Example 6

[0126] Based on the above embodiments, this embodiment provides a specific implementation of a computer-readable storage medium that stores computer-readable instructions to cause at least one processor to execute a data analysis method for cyberspace network security situation awareness as described in Embodiment 1, 2, 3, 4, or 5.

[0127] Based on the above embodiments, this embodiment also provides a specific implementation of a data analysis device, which includes a memory and a processor. The memory stores computer-readable instructions. When the computer-readable instructions are executed by the processor, they implement the data analysis method for cyberspace network security situation awareness as in Embodiment 1, 2, 3, 4, or 5.

[0128] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0129] Those skilled in the art will recognize that the algorithmic steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0130] If the above algorithm steps are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms.

[0131] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them; although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications can still be made to the specific implementation of the present invention or equivalent substitutions can be made to some technical features without departing from the spirit of the technical solutions of the present invention, and all such modifications and substitutions should be covered within the scope of the technical solutions claimed in the present invention.

Claims

1. A data analysis method for cyber space network security situation awareness, characterized in that, The method comprises the following steps: acquiring a problem to be analyzed and extracting a type identifier from the problem to be analyzed; the type identifier has a mapping relationship with a preset situation analysis model; the problem to be analyzed is preconfigured to include problem key information, a type identifier, and a knowledge-driven label / data-driven label / hybrid-driven label; selecting a situation analysis model matched with the problem to be analyzed according to the type identifier: if the type identifier is a first identifier, selecting a knowledge-driven situation analysis model as the situation analysis model matched with the problem to be analyzed; if the type identifier is a second identifier, selecting a data-driven situation analysis model as the situation analysis model matched with the problem to be analyzed; if the type identifier is a third identifier, selecting a situation analysis model based on knowledge driving and data driving as the situation analysis model matched with the problem to be analyzed; wherein the situation analysis model based on knowledge driving and data driving improves a data-driven model by using rule knowledge related to a preset problem in a training stage, and analyzes an identification result of the data-driven model by using rule knowledge related to the preset problem in a decision-making stage; wherein the knowledge-driven situation analysis model refers to a rule-based knowledge base generated based on a network security knowledge base; the data-driven situation analysis model refers to a preset model trained by using a data set related to a preset problem to obtain a situation analysis model set for the preset problem; the situation analysis model based on knowledge driving and data driving refers to a hybrid-driven model set generated based on the network security knowledge base, a data set related to a preset problem, and a preset model; reading network security situation data corresponding to the problem to be analyzed; wherein the network security situation data includes cyber space network security situation elements composed of multiple types of network environment data, network vulnerability data, network attack data, and network security event data; inputting the read network security situation data into the selected situation analysis model to obtain an analysis result corresponding to the problem to be analyzed.

2. The cyber space network security situation awareness data analysis method of claim 1, wherein: The rule-based knowledge base includes at least one IF condition THEN event.

3. The data analysis method for cyber space network security situation awareness according to claim 2, characterized in that: if the type identifier in the problem to be analyzed is a first identifier, extracting a knowledge-driven label from the problem to be analyzed; the knowledge-driven label has a preset mapping relationship with the IF condition THEN event; based on the extracted knowledge-driven label, searching for an IF condition THEN event corresponding to the knowledge-driven label from the rule-based knowledge base as a target event; acquiring network security situation data corresponding to the problem to be analyzed as analysis data; extracting the analysis data to form regularized data; analyzing the regularized data to obtain condition data related to the target event; Based on the target event, knowledge reasoning is performed on the conditional data, and a result of the knowledge reasoning is taken as an analysis result corresponding to the problem to be analyzed.

4. The cyber space network security situation awareness data analytics method of claim 1, wherein: The preset model is trained by using a data set related to the preset problem, to obtain a set of situation analysis models facing the preset problem, and the preset model includes one or more of a support vector machine-based situation analysis model, a KNN-based situation analysis model, a random forest-based situation analysis model, an RNN-based situation analysis model, a ResNet-based situation analysis model, and a CNN-based situation analysis model.

5. The data analysis method for cyber space network security situation awareness according to claim 4, wherein, if the type identifier in the problem to be analyzed is the second identifier, a data-driven label is extracted from the problem to be analyzed, and a preset mapping relationship exists between the data-driven label and the preset situation analysis model facing the preset problem; a corresponding classification model or prediction model is obtained from the set of situation analysis models facing the preset problem based on the data-driven label, as a first target model; network security situation data corresponding to the problem to be analyzed is obtained as analyzed data; the analyzed data is identified based on the first target model, and an identification result is taken as an analysis result corresponding to the problem to be analyzed.

6. The cyber space network security situation awareness data analytics method of claim 1, wherein: The set of hybrid-driven models is generated based on the network security knowledge base, the data set related to the preset problem, and the preset model, and the preset model includes one or more of a support vector machine-based situation analysis model, a KNN-based situation analysis model, a random forest-based situation analysis model, an RNN-based situation analysis model, a ResNet-based situation analysis model, and a CNN-based situation analysis model.

7. The data analysis method for cyber space network security situation awareness according to claim 6, wherein: if the type identifier in the problem to be analyzed contains a third identifier, a hybrid-driven label is extracted from the problem to be analyzed, and a preset mapping relationship exists between the hybrid-driven label and a preset hybrid-driven classification model; a corresponding hybrid-driven model is obtained from the set of hybrid-driven models based on the hybrid-driven label, as a second target model; network security situation data corresponding to the problem to be analyzed is obtained as analyzed data; the analyzed data is identified based on the second target model, and rule knowledge in the network security knowledge base is used to assist in analyzing the identification result, to obtain an analysis result corresponding to the problem to be analyzed.

8. The cyber space network security situation awareness data analytics method of claim 1, wherein, Further performed are: the network security knowledge base constructed in advance is updated based on the analysis result.

9. A computer-readable storage medium, characterized in that, The computer readable instructions are stored, so that at least one processor executes the data analysis method for cyber space network security situation awareness according to any one of claims 1 to 8.

10. A data analysis device, characterized by, The computer readable instructions are stored in the memory, and the computer readable instructions are executed by the processor, so that the data analysis method for cyber space network security situation awareness according to any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • Security event analysis method and system in cloud computing network

    CN103746991A