A situation awareness large screen construction method, device and equipment and storage medium
By using digital twin technology to collect and render data from real physical and network environments, a 3D white film is generated and displayed, solving the problem that situational awareness screens cannot accurately simulate real physical environments, and realizing an intuitive display and efficient defense of network security situation.
Patent Information
- Application Number
- CN202211380645.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-04
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2042-11-04
AI Technical Summary
Traditional situational awareness screens cannot accurately simulate real physical environments, resulting in a weak presentation of network security situation and difficulty in achieving three-dimensional perception.
Digital twin technology is used to collect data from real physical and network environments, generate a 3D white film, and display it on a situational awareness screen through fine processing and scene rendering, integrating various layers of network situational data.
It provides an intuitive display of the network security situation, minimizes the losses caused by external attacks, and ensures the efficient and stable operation of business systems.
Smart Images

Figure CN116582508B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to a method, apparatus, device and storage medium for constructing a situational awareness large screen. Background Technology
[0002] Situational awareness (SA) is a dynamic and holistic capability that provides an understanding of security risks based on the environment. It leverages big data to enhance the ability to detect, identify, analyze, and respond to security threats from a global perspective, ultimately leading to decision-making and action—the practical application of security capabilities. The working principle of situational awareness involves acquiring and understanding information about security elements that cause changes in the network situation, assessing the overall network security status, predicting its development trends, and presenting this information to users in a visual manner. This helps users make appropriate security decisions and take corresponding actions, thereby achieving proactive and dynamic security defense. Situational awareness large screens are widely used due to their high-definition, large-screen interface and powerful data presentation capabilities. These large screens use visualization components such as maps, bar charts, and pie charts to present asset status, attack and defense status, and operational status, helping users quickly perceive security threats and providing strong data support for response and decision-making.
[0003] However, traditional situational awareness dashboards suffer from limited presentation and an inability to accurately simulate real physical environments, hindering a comprehensive and multi-dimensional understanding of network security. To address this weakness, the mainstream approach focuses on enriching the visual presentation by adding map-based displays. This involves using a two-dimensional geographic map overlaid with attack routes, but this only provides a macro-level view of network attacks. Another approach aims to present a realistic network structure using topology, but this only provides an abstract representation of the physical environment and cannot accurately depict the layout of data centers or the location and status of assets and equipment.
[0004] In summary, while using map-based attacks solves the problem of attack line restrictions, the granularity of the display is relatively coarse, at most down to the city or county level, making it impossible to accurately present the specific location of the attack, such as which building or server room. On the other hand, while topology-based presentation can show the network structure, the display effect is not realistic enough, and it has the disadvantage of not allowing users to experience the network operation status in an immersive way. Summary of the Invention
[0005] In view of this, the purpose of this application is to provide a method, apparatus, device, and storage medium for constructing a situational awareness dashboard, which enables network security services to be displayed more intuitively, restoring the real physical network environment, thereby minimizing network losses caused by external attacks, ensuring the efficient and stable operation of business systems, and overcoming the current problem of weak situational awareness dashboard presentation. The specific solution is as follows:
[0006] Firstly, this application discloses a method for constructing a situational awareness large screen, including:
[0007] Data on the real physical and network environments in fine-grained scenarios are collected to obtain network situational data;
[0008] The target object in the fine-grained scene is scanned to obtain scan data, and a 3D white film is generated by digital twin modeling of the scan data through a modeling engine.
[0009] The 3D white film is refined to trim out the details of the target object, resulting in a digital twin system, which is then presented on the target page through scene rendering.
[0010] Using the digital twin system on the target page as the base map, the various layers of the network situation data are fused to obtain the fused page, and the rendered fused page is displayed on the situation awareness screen.
[0011] Optionally, the process of collecting data on the real physical and network environments in fine-grained scenarios to obtain network situational data includes:
[0012] Feature data and image data of various objects in the real physical environment of fine-grained scenes, as well as data of the network environment, are collected to obtain network situation data.
[0013] Optionally, the step of scanning the target object in the fine-grained scene to obtain scan data includes:
[0014] The target objects in the fine-grained scene are quickly scanned by a drone to obtain scan data.
[0015] Optionally, presenting the digital twin system on the target page through scene rendering includes:
[0016] The digital twin system is presented on a web page that supports interactive interface operations through scene rendering.
[0017] Optionally, displaying the rendered and fused page on the situational awareness screen includes:
[0018] The attack routes in the rendered and fused page are displayed on the situational awareness screen using a variety of pre-provided display styles, and corresponding alarm information is generated.
[0019] Optionally, after generating the corresponding alarm information, the method further includes:
[0020] In the situational awareness screen, attackers in the selected single attack route are displayed, and the attacker's IP is sent to the security device through a linkage handling strategy so that the security device can block the attacker.
[0021] The alarm information on the situational awareness screen is deactivated, and a user-friendly pop-up reminder is generated on the situational awareness screen.
[0022] Optionally, the refinement of the 3D white film to trim out the details of the target object, thereby obtaining a digital twin system, includes:
[0023] The target objects in the fine-grained scene are hierarchically classified to obtain multiple classified hierarchical objects, and a hierarchical label is set for each classified hierarchical object so that the specific information of the corresponding level and the situational awareness data contained therein can be displayed by clicking the hierarchical label.
[0024] The 3D white film is refined to trim out the detailed parts of the classified hierarchical objects, thus obtaining a digital twin system.
[0025] Secondly, this application discloses a situational awareness large screen construction device, comprising:
[0026] The data acquisition module is used to collect data on the real physical environment and network environment in fine-grained scenarios to obtain network situation data;
[0027] The scanning module is used to scan the target objects in the fine-grained scene to obtain scan data;
[0028] The digital twin modeling module is used to generate a 3D white film by performing digital twin modeling on the scanned data through a modeling engine;
[0029] The fine processing module is used to perform fine processing on the 3D white film to trim out the detailed parts of the target object and obtain a digital twin system;
[0030] A digital twin system presentation module is used to present the digital twin system on a target page through scene rendering;
[0031] The fusion module is used to fuse the various layers of the network situation data using the digital twin system on the target page as the base map to obtain the fused page;
[0032] The page display module is used to display the rendered and merged page on the situational awareness screen.
[0033] Thirdly, this application discloses an electronic device, including a processor and a memory; wherein, when the processor executes a computer program stored in the memory, it implements the aforementioned situational awareness large screen construction method.
[0034] Fourthly, this application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned situational awareness large screen construction method.
[0035] As can be seen, this application first collects data on the real physical and network environments in fine-grained scenarios to obtain network situational data. Then, it scans the target objects in the fine-grained scenarios to obtain scan data. A modeling engine is then used to create a 3D white film using digital twin modeling. Next, the 3D white film is refined to trim out the details of the target objects, resulting in a digital twin system. This digital twin system is then presented on the target page through scene rendering. Using the digital twin system on the target page as a base image, the various layers of the network situational data are merged to obtain a merged page, which is then displayed on a situational awareness screen. This application integrates digital twin technology into traditional network security situational awareness screens, enabling a more intuitive display of network security services and restoring the real physical network environment. This minimizes losses to the network environment caused by external attacks, ensures the efficient and stable operation of business systems, and solves the problem of weak situational presentation in current situational awareness screens. Attached Figure Description
[0036] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0037] Figure 1 This is a flowchart of a situational awareness large screen construction method disclosed in this application;
[0038] Figure 2 This application discloses a flowchart of a specific method for constructing a situational awareness large screen.
[0039] Figure 3 This is a schematic diagram from the perspective of a computer room in a specific digital twin system disclosed in this application;
[0040] Figure 4 This is a schematic diagram from the perspective of a cabinet in a specific digital twin system disclosed in this application;
[0041] Figure 5 This is a schematic diagram of a specific urban-perspective attack route disclosed in this application;
[0042] Figure 6 This is a specific alarm linkage handling diagram disclosed in this application;
[0043] Figure 7 This is a schematic diagram of a situational awareness large screen construction device disclosed in this application;
[0044] Figure 8 This is a structural diagram of an electronic device disclosed in this application. Detailed Implementation
[0045] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0046] This application discloses a method for constructing a situational awareness large screen. See also Figure 1 As shown, the method includes:
[0047] Step S11: Collect data on the real physical environment and network environment in the fine-grained scene to obtain network situation data.
[0048] In this embodiment, data is first collected from fine-grained scenarios, specifically including two parts. The first part is data from the real physical environment, such as the shape, size, and color of objects in the real physical environment. The second part is data from the network environment, specifically data reported through various probes or terminal proxies. The reported data includes, but is not limited to, data on assets, logs, traffic, alarms, vulnerabilities, intelligence, and geographic databases. After being processed by a real-time stream computing engine and big data analysis, the data from both parts can be used as backup data for the situational awareness dashboard, i.e., network situational data. The fine-grained scenarios may include, but are not limited to, objects such as cities, streets, buildings, server rooms, server racks, devices, and ports.
[0049] In this embodiment, the collection of data on the real physical environment and network environment in a fine-grained scenario to obtain network situational data can specifically include: collecting feature data and image data of various objects in the real physical environment and network environment data to obtain network situational data. It should be noted that, in order to more realistically present various objects in the real physical environment on the situational awareness screen and improve user experience, in addition to collecting feature data (such as the shape, size, and color of server racks) and network environment data of various objects in the real physical environment, it is also possible to take pictures of the objects in the real physical environment and then collect the image information obtained from the pictures. Furthermore, through model construction, various objects can be displayed from different perspectives, such as cities, streets, buildings, server rooms, server racks, equipment, ports, etc., which can present scenarios of different granularities according to different business needs.
[0050] Step S12: Scan the target object in the fine-grained scene to obtain scan data, and use the modeling engine to perform digital twin modeling on the scan data to generate a 3D white film.
[0051] In this embodiment, after collecting network situational data from the real physical and network environments in a fine-grained scenario, the target objects in the fine-grained scenario are further scanned according to specific business requirements to obtain corresponding scan data. Then, a modeling engine quickly performs digital twin modeling on the scan data to generate a 3D white model. The target objects include, but are not limited to, cities, streets, buildings, computer rooms, and server racks.
[0052] Step S13: Refine the 3D white film to trim out the details of the target object, obtain a digital twin system, and present the digital twin system on the target page through scene rendering.
[0053] In this embodiment, after generating a 3D white film by digital twin modeling the scanned data using a modeling engine, the 3D white film can be further refined to trim out the details of the target object, such as architectural details. For complex details, the collected images can be directly pasted onto the model, thereby efficiently completing the construction of the digital twin system. Then, the digital twin system can be presented on the target page through scene rendering. The target page includes, but is not limited to, web pages.
[0054] Step S14: Using the digital twin system on the target page as the base map, fuse the various layers of the network situation data to obtain the fused page, and display the rendered fused page on the situation awareness screen.
[0055] In this embodiment, after the digital twin system is presented on the target page through scene rendering, the digital twin system on the target page can be used as the base map. Then, the various layers of the network situation data are fused together, that is, the network situation data is layered, such as the statistical results of asset and alarm data at the granularity of city, street or building, and then the fused page is obtained. Then, the fused page is rendered again, and finally the rendered fused page is displayed on the situation awareness screen.
[0056] As can be seen, this embodiment first collects data on the real physical and network environments in a fine-grained scene to obtain network situational data. Then, it scans the target objects in the fine-grained scene to obtain scan data. A modeling engine is then used to create a 3D white film using digital twin modeling. Next, the 3D white film is refined to trim out the details of the target objects, resulting in a digital twin system. This digital twin system is then rendered on the target page using scene rendering. Using the digital twin system on the target page as a base image, the various layers of the network situational data are merged to obtain a merged page, which is then displayed on a situational awareness screen. This embodiment integrates digital twin technology into a traditional network security situational awareness screen, enabling a more intuitive display of network security services and restoring the real physical network environment. This minimizes losses to the network environment caused by external attacks, ensures the efficient and stable operation of business systems, and solves the problem of weak situational presentation in current situational awareness screens.
[0057] This application discloses a specific method for constructing a situational awareness large screen. (See also...) Figure 2 As shown, the method includes:
[0058] Step S21: Collect feature data and image data of each object in the real physical environment of the fine-grained scene, as well as data of the network environment, to obtain network situation data.
[0059] Step S22: Use a drone to quickly scan the target object in the fine-grained scene to obtain scan data, and use a modeling engine to perform digital twin modeling on the scan data to generate a 3D white film.
[0060] In this embodiment, after collecting feature data and image data of each object in the real physical environment of the fine-grained scene, as well as network environment data, to obtain network situation data, the objects in the fine-grained scene can be scanned by a drone. For example, the city and streets can be quickly scanned by a drone to obtain the corresponding scan data. Then, the scan data is digitally twinned by the modeling engine to generate a 3D white film, that is, the scan data is modeled using digital twin technology.
[0061] Step S23: Perform hierarchical classification on the target objects in the fine-grained scene to obtain multiple classified hierarchical objects, and set a hierarchical label for each classified hierarchical object so that the specific information of the corresponding level and the situational awareness data contained therein can be displayed by clicking the hierarchical label.
[0062] In this embodiment, after generating a 3D white film by digital twin modeling of the scanned data using a modeling engine, the target objects in the fine-grained scene are further classified hierarchically. For example, objects in the fine-grained scene are classified according to the hierarchy of city, street, building, computer room, cabinet, and equipment, resulting in multiple classified hierarchical objects. Then, a hierarchical label is set for each of the above-mentioned classified hierarchical objects. In this way, users can easily view the specific information of the corresponding level and the situational awareness data contained in the level by clicking on the above-mentioned hierarchical labels. For example, a multi-level label display is composed of buildings, computer rooms, cabinets, and equipment. When the user clicks on the label corresponding to the computer room, the number, location, shape, and log information of the computer room will be displayed on the situational awareness screen.
[0063] Step S24: Refine the 3D white film to trim out the detailed parts of the classified hierarchical objects, and obtain a digital twin system.
[0064] In this embodiment, the generated 3D white film is further refined to trim the details of the classified hierarchical objects, thereby obtaining a digital twin system.
[0065] Step S25: Present the digital twin system on a web page that supports interactive interface operations through scene rendering.
[0066] In this embodiment, after trimming the detailed parts of the categorized hierarchical objects to obtain the digital twin system, scene rendering is performed on the digital twin system, and it is presented on a web page. It should be noted that the web page supports interactive interface operations, including but not limited to switching between zoomed-in and zoomed-out views, and page rotation.
[0067] In one specific implementation, the digital twin system allows users to view city and street models at a macro level, and building, floor, and server room displays at a micro level. Depending on the page's perspective, the digital twin system adaptively displays hierarchical labels, such as buildings, server rooms, server racks, and equipment, forming a multi-level label display. Users can click on labels to view specific information about the selected level and the situational awareness data contained within that level. For details, see [link to specific implementation details]. Figure 3 and Figure 4 As shown, Figure 3 This shows the interface of the digital twin system from the perspective of the computer room. Figure 4 The interface shown is a display of the cabinet view in the digital twin system.
[0068] Step S26: Using the digital twin system on the web page as the base map, merge the various layers of the network situation data to obtain the merged page, and display the attack routes in the rendered merged page on the situation awareness screen through a variety of pre-provided display styles, and generate corresponding alarm information.
[0069] In this embodiment, after presenting the digital twin system on a web page supporting interactive interface operations through scene rendering, the digital twin system on the web page is used as the base map, and various layers of the network situational data are integrated and displayed, such as statistical results of asset and alarm data at the granularity of city, street, or building, to obtain the integrated page. It should be noted that this embodiment provides multiple display styles for attack routes, such as a line shooting from a room in a building on the east side of the city to a room in a building on the west side of the city. Compared to the display method from city to city, the above style is more vivid. Of course, it can also be viewed from a micro perspective in a computer room, with lines flying from a device in one rack to a device in another rack, making the lateral attack within a small area fully demonstrated. Furthermore, the integrated page is rendered again, and then the rendered integrated page is displayed on the situational awareness screen. For details, see [link to relevant documentation]. Figure 5 As shown, Figure 5 This demonstrates a specific attack route from an urban perspective. Additionally, corresponding alerts can be generated for the attack route on a situational awareness dashboard.
[0070] Step S27: On the situational awareness screen, the attacker in the selected single attack route is displayed, and the attacker's IP is sent to the security device through the linkage handling strategy so that the security device can block the attacker.
[0071] In this embodiment, it can be understood that situational awareness is the process of discovering, identifying, understanding, analyzing, and responding to security alarms, completing a closed loop through coordinated alarm handling. In this embodiment, the attack routes in the rendered and merged page are displayed on the situational awareness screen using various pre-provided display styles. After generating corresponding alarm information, the user can select an attack route by clicking or hovering the mouse over a preset area containing the attack route. Then, the attacker in a single attack route is displayed on the situational awareness screen for the user to view. Next, the attacker's IP address (Internet Protocol) is sent to the security device through a coordinated handling strategy, and the security device blocks the attacker. The number of attackers can be one or multiple.
[0072] Step S28: Delete the alarm information in the situational awareness screen and generate a friendly pop-up reminder in the situational awareness screen.
[0073] In this embodiment, after the attacker is blocked by the security device, the alarm information displayed on the situational awareness screen can be accessed by the user through clicking or other means. (See also...) Figure 6 As shown, Figure 6 The diagram illustrates a specific alarm linkage handling method. The alarm information on the situational awareness screen can be cleared by clicking the "OK" button in the linkage handling pop-up window. A user-friendly pop-up reminder will also be provided after the alarm is cleared.
[0074] For a more detailed description of the process of step S21, please refer to the relevant content disclosed in the foregoing embodiments, which will not be repeated here.
[0075] As can be seen, this application's embodiment constructs a situational awareness screen based on digital twin technology. It models and simulates a digital twin world through digital means, overcoming the limitations of traditional situational awareness screens that offer only a single display and cannot accurately simulate the real physical environment, thus hindering a comprehensive and three-dimensional perception of network security situation. This makes the screen virtually indistinguishable from the real physical world, enabling more accurate situational awareness and prediction of the network environment. This minimizes losses caused by external attacks and ultimately ensures the efficient and stable operation of business systems. Furthermore, after the digital twin system is built, various layers of situational data are integrated into the system, and the integrated page provides a convenient interactive presentation of the situational awareness data, allowing for quick switching between different levels and perspectives.
[0076] Accordingly, this application also discloses a situational awareness large screen construction device, see [link to relevant documentation]. Figure 7 As shown, the device includes:
[0077] Data acquisition module 11 is used to collect data on the real physical environment and network environment in fine-grained scenarios to obtain network situation data;
[0078] Scanning module 12 is used to scan the target objects in the fine-grained scene to obtain scan data;
[0079] The digital twin modeling module 13 is used to generate a 3D white film by performing digital twin modeling on the scanned data through a modeling engine;
[0080] The fine processing module 14 is used to perform fine processing on the 3D white film to trim out the detailed parts of the target object and obtain a digital twin system;
[0081] The digital twin system presentation module 15 is used to present the digital twin system on the target page through scene rendering;
[0082] The fusion module 16 is used to fuse the various layers of the network situation data using the digital twin system on the target page as the base map to obtain the fused page;
[0083] Page display module 17 is used to display the rendered and merged page on the situational awareness screen.
[0084] The specific workflow of each of the above modules can be found in the relevant content disclosed in the foregoing embodiments, and will not be repeated here.
[0085] As can be seen, in this embodiment, data on the real physical and network environments in a fine-grained scene are first collected to obtain network situational data. Then, target objects in the fine-grained scene are scanned to obtain scan data. A modeling engine is used to perform digital twin modeling on the scan data to generate a 3D white film. Next, the 3D white film is refined to trim out the details of the target object, resulting in a digital twin system. The digital twin system is then presented on the target page through scene rendering. Using the digital twin system on the target page as a base map, the various layers of the network situational data are merged to obtain a merged page. The rendered merged page is then displayed on the situational awareness screen. This embodiment integrates digital twin technology into the traditional network security situational awareness screen, enabling a more intuitive display of network security services and restoring the real physical network environment. This minimizes losses to the network environment caused by external attacks, ensures the efficient and stable operation of business systems, and solves the problem of the current situational awareness screen's weak presentation of situational awareness.
[0086] Furthermore, in this embodiment, to address the user experience issue of weak interactivity in traditional situational awareness screens, an interaction module can be added between the refined processing module 14 and the digital twin system presentation module 15. This decouples the digital twin modeling process from the business display process, providing greater convenience for business matching and offering advantages for commercial replication. For example, when changing the application area of the digital twin screen, only the 3D model needs to be modeled; the upper-level digital twin system presentation module 15 requires no modification. The interaction module encapsulates various interaction interfaces to provide more flexible interaction methods, including but not limited to interfaces for level switching, perspective switching, attack wire switching, hacker profile switching, alarm handling and blocking, etc. It should be noted that the interaction module's support makes the previously weakly interactive situational awareness screen more suitable for frequently operated network security services, enabling network security services to complete the closed-loop handling process on the situational awareness screen, greatly increasing the efficiency of coordinated handling.
[0087] In some specific embodiments, the data acquisition module 11 may specifically include:
[0088] The network situation data acquisition unit is used to collect feature data and image data of various objects in the real physical environment in fine-grained scenarios, as well as network environment data, to obtain network situation data.
[0089] In some specific embodiments, the scanning module 12 may specifically include:
[0090] The city and street scanning unit is used to quickly scan target objects in the fine-grained scene using a drone to obtain scan data.
[0091] In some specific embodiments, the digital twin system presentation module 15 may specifically include:
[0092] The digital twin system presentation unit is used to present the digital twin system on a web page that supports interactive interface operations through scene rendering.
[0093] In some specific embodiments, the page display module 17 may specifically include:
[0094] The attack route display unit is used to display the attack routes in the rendered and fused page on the situational awareness screen using a variety of pre-provided display styles, and generate corresponding alarm information.
[0095] In some specific embodiments, after the page display module 17, the system may further include:
[0096] The attacker display unit is used to display the attacker in the selected single attack route on the situational awareness screen.
[0097] The attacker IP distribution unit is used to distribute the attacker's IP to the security device through a coordinated handling strategy;
[0098] The blocking unit is used to block the attacker through the security device;
[0099] An alarm information cancellation unit is used to cancel the alarm information in the situational awareness screen.
[0100] The pop-up reminder unit is used to generate user-friendly pop-up reminders on the situational awareness screen.
[0101] In some specific embodiments, the fine-tuning module 14 may specifically include:
[0102] A hierarchical classification unit is used to perform hierarchical classification on the target objects in the fine-grained scene to obtain multiple classified hierarchical objects.
[0103] The hierarchical label setting unit is used to set hierarchical labels for each hierarchical object after classification, so that the specific information of the corresponding hierarchical level and the situational awareness data contained therein can be displayed by clicking the hierarchical label.
[0104] The refinement processing unit is used to refine the 3D white film to trim out the detailed parts of the classified hierarchical objects, thereby obtaining a digital twin system.
[0105] Furthermore, embodiments of this application also disclose an electronic device, Figure 8 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application.
[0106] Figure 8 This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of this application. Specifically, the electronic device 20 may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the situational awareness large screen construction method disclosed in any of the foregoing embodiments. Alternatively, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0107] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.
[0108] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored thereon can include operating system 221, computer program 222, etc., and the storage method can be temporary storage or permanent storage.
[0109] The operating system 221 is used to manage and control the various hardware devices on the electronic device 20 and the computer program 222, which may be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of performing the situational awareness large screen construction method executed by the electronic device 20 as disclosed in any of the foregoing embodiments, the computer program 222 may further include a computer program capable of performing other specific tasks.
[0110] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned situational awareness large screen construction method. Specific steps of this method can be found in the corresponding content disclosed in the foregoing embodiments, and will not be repeated here.
[0111] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.
[0112] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0113] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.
[0114] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0115] The above provides a detailed description of the situational awareness large screen construction method, apparatus, device, and storage medium provided in this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. A method for constructing a situational awareness large screen, characterized in that, include: Data on the real physical and network environments in fine-grained scenarios are collected to obtain network situational data; The target object in the fine-grained scene is scanned to obtain scan data, and a 3D white film is generated by digital twin modeling of the scan data through a modeling engine. The 3D white film is refined to trim out the details of the target object, resulting in a digital twin system, which is then presented on the target page through scene rendering. Using the digital twin system on the target page as the base map, the various layers of the network situation data are fused to obtain the fused page, and the rendered fused page is displayed on the situation awareness screen. The refinement process of the 3D white film to trim out the details of the target object and obtain a digital twin system includes: hierarchically classifying the target object in the fine-grained scene to obtain multiple classified hierarchical objects, and setting a hierarchical label for each classified hierarchical object so that the specific information of the corresponding level and the situational awareness data contained therein can be displayed by clicking the hierarchical label; and refining the 3D white film to trim out the details of the classified hierarchical objects to obtain a digital twin system. The process of collecting data on the real physical and network environments in fine-grained scenarios to obtain network situational data includes: collecting data on the shape, size, and color of objects in the real physical environment of the fine-grained scenarios to obtain the first part of the data; the fine-grained scenarios include objects such as cities, streets, buildings, computer rooms, server racks, devices, and ports; collecting data on the network environment reported by various probes or terminal proxies in the fine-grained scenarios to obtain the second part of the data; the reported network environment data includes data on assets, logs, traffic, alarms, vulnerabilities, intelligence, and geographic databases; and processing the first part of the data and the second part of the data through a real-time stream computing engine and big data analysis to obtain network situational data.
2. The method for constructing a situational awareness large screen according to claim 1, characterized in that, The process of collecting data on the real physical and network environments in fine-grained scenarios to obtain network situational data includes: Feature data and image data of various objects in the real physical environment of fine-grained scenes, as well as data of the network environment, are collected to obtain network situation data.
3. The method for constructing a situational awareness large screen according to claim 1, characterized in that, The scanning of target objects in the fine-grained scene to obtain scan data includes: The target objects in the fine-grained scene are quickly scanned by a drone to obtain scan data.
4. The method for constructing a situational awareness large screen according to claim 1, characterized in that, The process of presenting the digital twin system on the target page through scene rendering includes: The digital twin system is presented on a web page that supports interactive interface operations through scene rendering.
5. The method for constructing a situational awareness large screen according to claim 1, characterized in that, The process of displaying the rendered and merged page on the situational awareness screen includes: The attack routes in the rendered and fused page are displayed on the situational awareness screen using a variety of pre-provided display styles, and corresponding alarm information is generated.
6. The method for constructing a situational awareness large screen according to claim 5, characterized in that, After generating the corresponding alarm information, the process also includes: In the situational awareness screen, attackers in the selected single attack route are displayed, and the attacker's IP is sent to the security device through a linkage handling strategy so that the security device can block the attacker. The alarm information on the situational awareness screen is deactivated, and a user-friendly pop-up reminder is generated on the situational awareness screen.
7. A situational awareness large screen construction device, characterized in that, include: The data acquisition module is used to collect data on the real physical environment and network environment in fine-grained scenarios to obtain network situation data; The scanning module is used to scan the target objects in the fine-grained scene to obtain scan data; The digital twin modeling module is used to generate a 3D white film by performing digital twin modeling on the scanned data through a modeling engine; The fine processing module is used to perform fine processing on the 3D white film to trim out the detailed parts of the target object and obtain a digital twin system; A digital twin system presentation module is used to present the digital twin system on a target page through scene rendering; The fusion module is used to fuse the various layers of the network situation data using the digital twin system on the target page as the base map to obtain the fused page; The page display module is used to display the rendered and fused page on the situational awareness screen; The fine-grained processing module is specifically used to perform hierarchical classification of the target objects in the fine-grained scene, obtain multiple classified hierarchical objects, and set a hierarchical label for each classified hierarchical object so that the specific information of the corresponding level and the situational awareness data contained therein can be displayed by clicking the hierarchical label; and to perform fine-grained processing on the 3D white film to trim out the detailed parts of the classified hierarchical objects to obtain a digital twin system. The data acquisition module is used to collect data on the shape, size, and color of objects in the real physical environment of a fine-grained scene to obtain the first part of the data. The fine-grained scene includes objects such as cities, streets, buildings, computer rooms, server racks, equipment, and ports. The module also collects data on the network environment reported by various probes or terminal agents in the fine-grained scene to obtain the second part of the data. The reported network environment data includes data on assets, logs, traffic, alarms, vulnerabilities, intelligence, and geographic databases. The first part of the data and the second part of the data are processed by a real-time stream computing engine and big data analysis to obtain network situation data.
8. An electronic device, characterized in that, It includes a processor and a memory; wherein, when the processor executes a computer program stored in the memory, it implements the situational awareness large screen construction method as described in any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that, Used to store computer programs; wherein, when the computer programs are executed by a processor, they implement the situational awareness large screen construction method as described in any one of claims 1 to 6.
Citation Information
Patent Citations
Situation awareness system and method based on digital twinning
CN114299045A