A multi-dimensional integrated early warning method and system for network security

By constructing a multi-dimensional network security comprehensive early warning method, using random forest algorithms, knowledge graphs and LSTM neural networks and other technologies, the shortcomings of multi-dimensional analysis in network security early warning are solved, and accurate early warning and effective decision-making support for network security status are achieved.

CN116668045BActive Publication Date: 2025-07-29INST OF SOFTWARE - CHINESE ACAD OF SCI
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210145279.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-02-17
Publication Date
2025-07-29
Estimated Expiration
2042-02-17

AI Technical Summary

Technical Problem

In the network security warning, it is difficult to analyze network assets, threat attack impact surfaces and comprehensive network security status based on multi-dimensionality in the existing technology, resulting in the early warning work being insufficiently accurate and comprehensive enough to effectively support decision-making and judgment.

Method used

Build a multi-dimensional network security comprehensive early warning method, including data preprocessing, construction of multi-dimensional network security early warning model and comprehensive alarm model, and combine random forest algorithms, knowledge graphs, LSTM neural networks and other technologies to carry out multi-dimensional characterization and early warning of network security status.

Benefits of technology

It has achieved a comprehensive description and accurate warning of the network security situation, helping network security managers to control the network security situation from a macro perspective and make effective warning responses.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116668045B_ABST
    Figure CN116668045B_ABST
Patent Text Reader

Abstract

The present invention proposes a multi-dimensional network security comprehensive early warning method and system. The method includes: first, collecting multi-source heterogeneous network security big data, and performing pre-processing operations on the data to make it meet the needs of subsequent model analysis; second, constructing a multi-dimensional network security early warning model to characterize the current network security status in multiple dimensions; then, based on the multi-dimensional network security early warning model, constructing a comprehensive warning model to comprehensively warn the current network security status; finally, combining specific business needs, carrying out the business process of warning information release, tracking, upgrading, disposing, and lifting warnings. The present invention constructs a network security early warning model based on network security spatiotemporal big data, conducts in-depth profiling, indicator extraction and calculation from the perspectives of network asset susceptibility, threat attack impact, and comprehensive network security status, and conducts comprehensive early warning of the network environment security status, which can effectively help network security early warning related personnel make decisions and judgments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention proposes a multi-dimensional network security comprehensive early warning method and system, belonging to the technical field of network security. Background Art

[0002] With the rapid development of network information technology, network security vulnerabilities and hidden dangers are being reported, and the frequency and intensity of cyberattacks are increasing. When external threats reach a certain level of severity or when a cybersecurity incident occurs, the decision to issue cybersecurity warnings within a certain range and for a specific target audience based on massive amounts of network security logs requires comprehensive and informed decision-making. However, while network security early warning work continues to evolve and change, the emphasis in technical research on replacing early warnings with alerts has left network security early warning practitioners feeling overwhelmed. Therefore, it is necessary to conduct a multi-dimensional analysis and calculation of the threats facing network assets and protection targets, the impact of cybersecurity incidents on network security at specific stages, and the overall network security status over a specific period. This requires developing an indicator system based on national standards, researching network security monitoring and early warning models, and employing a combination of qualitative and quantitative methods to calculate early warning indices and determine warning levels. This will provide a basis for decision-making and support for issuing network security warnings.

[0003] Current cybersecurity early warning systems focus on alerts generated by cybersecurity threat attack detection. This information is far from practical cybersecurity early warning, requiring model calculations to advance to the early warning assessment stage. Cybersecurity attack predictions often rely on historical attack information, employing techniques such as cluster analysis, relationship mining, and feature analysis to predict the next steps of a cyberattack. While this approach provides some useful information, it still falls short of the scope of cybersecurity early warning assessment. Research on cybersecurity early warning models based on spatiotemporal cybersecurity big data is necessary. This requires in-depth profiling, indicator extraction, and calculation of network asset susceptibility, threat attack impact, and overall cybersecurity status. This will effectively assist cybersecurity early warning personnel in issuing alerts, assessing alert levels, and tracking the entire process from issuance to release. Summary of the invention

[0004] The present invention proposes a multi-dimensional comprehensive network security early warning method, which organically combines information such as network security events, multi-dimensional asset portraits, and threat intelligence, and constructs a network security early warning model from multiple dimensions such as security event early warning, asset susceptibility early warning, and attack impact early warning to provide a comprehensive early warning of the network environment security status.

[0005] To achieve the above objectives, the present invention proposes a multi-dimensional network security comprehensive early warning method, comprising the following steps:

[0006] Collect multi-source heterogeneous network security big data and perform data preprocessing operations on the collected data to make it meet the needs of subsequent model analysis;

[0007] Utilize the collected multi-source heterogeneous network security big data to build a multi-dimensional network security early warning model to characterize the current network security situation in multiple dimensions;

[0008] Based on the constructed multi-dimensional network security early warning model, a comprehensive warning model is constructed to provide a comprehensive early warning of the current network security situation;

[0009] Based on the constructed comprehensive police situation warning model and combined with specific business needs, the business processes of warning information release, tracking, upgrading, handling and lifting of warnings are carried out.

[0010] Furthermore, the data preprocessing operation includes operations such as completion, deduplication, correction, and normalization of the data.

[0011] Furthermore, the construction of a multi-dimensional network security early warning model includes the following steps:

[0012] Construct a security incident level warning model based on a random forest algorithm: Based on multi-dimensional information such as attack vulnerabilities, attack targets, and damage levels of security incidents, a network security incident level warning indicator system is constructed, and weights are set for the indicators using an expert system. Based on historical experience and the indicator system, the warning levels of historical security incidents are manually annotated to form model training samples. Some samples are randomly extracted with replacement from these as the sample sets for each decision tree, and these sample sets are used as the basis for training the random forest classifier to construct a security incident level warning model.

[0013] Construct asset susceptibility level warning model: According to the basic information of network assets, vulnerability information, asset threat list and other information, extract asset features and form feature vectors, which can be expressed as A i ={a i1 ,a i2 ,...,a in}, where a i1 to a in Represents the first to nth attributes of the asset numbered i, realizing multi-dimensional profiling of network assets; constructs a rule base for determining asset susceptibility levels, and constructs an asset susceptibility level warning model based on the rule base;

[0014] Build an attack impact surface warning model based on a knowledge graph: clarify the dimensions affecting the warning, mainly including aspects such as the affected industries, regions, operating systems, services and ports, asset types, etc.; build a knowledge graph of impact surface information; build an inference model for the degree of influence of each dimension based on the knowledge graph; and infer the warning impact surface information such as the affected regions, industries, systems, and trends of the event according to this inference model.

[0015] Further, the construction of the comprehensive police situation warning model includes the following steps:

[0016] Build an asset comprehensive susceptibility warning model based on graph algorithms: Based on the susceptibility data of assets in the network environment of the asset susceptibility level warning model, combined with graph algorithms such as PageRank, assign weights to the importance of each asset node in the network topology, and infer and calculate the comprehensive susceptibility warning level of all assets in the current network environment, and output the warning information on the current network comprehensive susceptibility status;

[0017] Build a comprehensive police situation warning model based on the threshold dynamic adaptive algorithm: Based on the security event level warning data, asset susceptibility level warning data, and attack impact surface warning data, build a comprehensive warning index system, determine the index weights, and assign values to the warning indicators; Based on the threshold dynamic adaptive algorithm, calculate the network security comprehensive police situation index, and issue comprehensive warning information on the frequency and severity of the current system being attacked;

[0018] Build a network security police situation trend warning model based on the LSTM neural network: Use daily attack events, asset susceptibility status, etc. as feature inputs, and use the daily comprehensive police situation index score as the annotation result to form a training data set, build and train the LSTM neural network, and warn about the future development trend of the network security state.

[0019] Based on the same inventive concept, the present invention also provides a multi-dimensional network security comprehensive warning system using the above method, which includes:

[0020] A data collection and preprocessing module for collecting multi-source heterogeneous network security big data and performing data preprocessing operations on the collected data to make it meet the requirements of subsequent model analysis;

[0021] A multi-dimensional network security warning model construction module for building a multi-dimensional network security warning model to depict the current network security situation in multiple dimensions;

[0022] A comprehensive police situation warning model construction module for building a comprehensive police situation warning model based on the constructed multi-dimensional network security warning model to comprehensively warn about the current network security situation;

[0023] The early warning business process execution module is used to execute the entire business process of early warning information release, tracking, upgrading, disposing and lifting the early warning based on the constructed comprehensive alarm warning model and combined with specific business needs.

[0024] This invention targets the multi-dimensional and multi-angle characteristics of network security data, combines existing network security standards and specifications, and constructs a multi-dimensional network security early warning model and a comprehensive early warning index model to describe the current network security status in detail. This can effectively help network security managers control the network security status from a macro perspective and make relevant early warning responses. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] Figure 1 It is a flow chart of a multi-dimensional network security comprehensive early warning method of the present invention.

[0026] Figure 2 It is a flowchart for building a multi-dimensional network security early warning model.

[0027] Figure 3 It is a flow chart for constructing a comprehensive police warning model. DETAILED DESCRIPTION

[0028] In order to make the technical solution of the present invention more clear and easy to understand, embodiments are given and described in detail with reference to the accompanying drawings as follows.

[0029] Step 1: Data collection and preprocessing

[0030] Network security data includes security incident data, multi-dimensional asset portraits, and threat intelligence data. The preprocessing process removes noise and irrelevant data from multi-source data sets, addresses possible omissions and dirty data in the data sets, and specifically addresses incomplete and abnormal data, smooths out noisy data, identifies and deletes isolated points, and resolves data inconsistencies to improve the quality of collected data and ensure its integrity and accuracy. Data cleaning includes, but is not limited to, the following:

[0031] 1) It should support the processing of missing values in the collected data, such as missing collected data due to equipment failure, or some data not being entered because they were not given enough attention during input;

[0032] 2) Support for abnormal data processing of collected data. Abnormal data includes duplicate data and erroneous data. Duplicate data may appear when merging multiple data sources. Erroneous data may be directly written to the backend database without judgment after receiving the input due to an incomplete business system, which may introduce random errors or deviations in a measurement variable, such as inaccurate date format.

[0033] 3) It should support the cleaning of the format content of the collected data. Data from multiple data sources may have differences in the data table structure definition or field types. When integrating multi-source data, it is necessary to process it into a consistent format;

[0034] 4) It should support the cleaning of non-required data in the collected data. In order to avoid data redundancy, after a reasonable assessment of the platform business, it is necessary to delete the non-required data in the collected data.

[0035] Step 2: Build a multi-dimensional network security early warning model

[0036] This embodiment is based on relevant standards and specifications in the field of network security, such as the ISO / IEC 27000 information security management system standard family, the network security threat information format specification GB / T36643-2018, the information security technology terminology GB / T25069-2019, the information security technology network attack definition and description specification GB / T37027-2018, and some public security industry standards, etc., so as to determine the core ontology, concepts and terms in the field of network security, establish a network security knowledge ontology model, and clarify the attribute set.

[0037] For example:

[0038] (1) Network assets: including various hardware devices, software devices, network environments, virtual personnel, etc. in the cyberspace.

[0039] (2) Vulnerabilities: including vulnerability vulnerabilities and weakness vulnerabilities, such as vulnerabilities, system configurations, protection software, etc.

[0040] (3) Network attacks: including attackers, attack methods, exploitation tools, attack events, attack consequences, etc. Among them, attackers include individuals, groups or hacker organizations; attack methods include the means used in the attack, such as denial-of-service attacks, backdoor attacks, vulnerability attacks, network scanning and eavesdropping, phishing, interference events, advanced threat events, and other network attack events; exploitation tools include normal software and malicious software.

[0041] The specific model construction method includes:

[0042] 1) Build a security event level early warning model based on the random forest algorithm

[0043] The present invention classifies the early warning levels of cybersecurity incidents with reference to the "GB / T 32924-2016 Information Security Technology - Cybersecurity Early Warning Guide": red early warning (Level I early warning), orange early warning (Level II early warning), yellow early warning (Level III early warning), and blue early warning (Level IV early warning). To construct a security incident level early warning model based on the random forest algorithm, first, on the basis of the judgment criteria for the importance degree of cybersecurity protection objects and the judgment criteria for the possible damage degree of cybersecurity protection objects in the "GB / T 32924-2016 Information Security Technology - Cybersecurity Early Warning Guide", combined with the actual business requirements and characteristics, a preliminary cybersecurity incident level early warning index system is constructed, and the weights of each index are determined according to the expert system here. Then, based on the index system, data annotation is performed on the historical security incident dataset, and the importance degree of the assets affected by each security incident is matched. Each asset affected by each security incident is stored in the training sample database as a binary tuple (C i ,A j ), where C i represents the damage degree of security incident i, and A j represents the importance degree of asset j. Furthermore, according to the judgment criteria of the "GB / T 32924-2016 Information Security Technology - Cybersecurity Early Warning Guide", the cybersecurity incident early warning level is calculated based on the importance degree of the cybersecurity protection object and the possible damage degree of the cybersecurity protection object.

[0044] Based on the dataset with annotation completed, a security incident level early warning model based on the random forest algorithm is constructed. Each time, a part of the samples is randomly and with replacement selected as the training set of a decision tree in the random forest. The input of the decision tree is the attributes of the security incident and asset binary tuple, such as feature information like exploited vulnerabilities, attack paths, port and service information, etc. At the same time, in order to ensure that the random forest has better noise resistance (i.e., is insensitive to default values), the size of the feature subset selected for each decision tree should be much smaller than the total feature dimension of the samples. Finally, all the trained decision trees form a random forest. For each subsequent input security incident, all the decision trees vote to determine its early warning level classification. Voting method: Each decision tree returns the probability evaluation of all the results. Finally, the average value of the probability evaluations of each result by all the decision trees is statistically calculated, and the result with the highest probability is selected as the output of the random forest.

[0045] 2) Construct an asset susceptibility level early warning model

[0046] First, count the security attributes of all assets and convert them into the feature vectors of the assets. Specifically expressed as A i ={a i1 ,a i2 ,...,a in}, where a i1 to ain The first to the nth attributes representing the asset numbered i, such as permission level, number of vulnerabilities, number of devices that can be affected, etc. In this embodiment, {R i , D i , V i , P i , T i} is selected as the feature vector of the asset, where R i represents the risk faced by the network system where asset i is located, D i represents the severity of the result after asset i is attacked, V i represents the vulnerability probability of the system where asset i is located, P i represents the relative probability of asset i being attacked, and T i represents the importance level of asset i. Among them, the relative attack probability P i can be expressed as And the risk can be expressed as the product of system vulnerability, result severity, and attack probability, that is, R i =V i D i P i . From this, taking the partial derivative, it can be known that Thus, it can be seen that R i has a linear relationship with V i , D i , P i . According to the above feature vector structure, network security portraits are created for all assets.

[0047] Then, organize experts to build a determination rule library for the susceptibility level of assets based on feature extraction, and on this basis, build a susceptibility level warning model for assets based on the rule library and the intelligence library to determine the susceptibility level of network assets.

[0048] Among them, building a determination rule library for the susceptibility level of assets means manually configuring index weights for the above asset attributes and designing a calculation formula for the susceptibility warning level of assets in combination with actual needs.

[0049] Among them, building a susceptibility level warning model for assets based on the rule library and the intelligence library means using the pre-built asset and security event intelligence library to calculate the various security attributes of assets, and calculating and outputting the susceptibility warning level of assets based on the index weights and calculation formula in the built determination rule library for the susceptibility level of assets.

[0050] 3) Build an attack impact surface warning model based on a knowledge graph

[0051] The attack impact surface includes aspects such as the affected industries, regions, operating systems, services and ports, asset types, etc. This patent uses a knowledge graph to store and reason about the possible scope of attack events, and builds an attack impact surface model based on this.

[0052] A knowledge graph is composed of structured knowledge, and knowledge can be expressed as a triple consisting of a subject, a predicate, and an object. The knowledge graph of this embodiment constructs triples such as vulnerability information utilized by security events (security event ID, "utilizes", vulnerability ID), the operating system to which the vulnerability belongs (vulnerability ID, "belongs to", operating system), the service and port to which the vulnerability belongs (vulnerability ID, "belongs to", service name or port number), and the operating systems commonly used in the industry (industry name, "uses", operating system), thereby constructing an inference path for the impact surface of an attack event, where the inference logic uses first-order predicate logic. Then, based on this knowledge graph, an inference model for the impact degree of each dimension is constructed to infer the possible impact range of the security event and evaluate the impact degree of each dimension, and the warning result of the impact surface is output, including warning impact surface information such as the affected region, affected industry, affected system, and impact trend.

[0053] Step 3: Construct a comprehensive police situation warning model

[0054] The specific model construction method is as follows:

[0055] 1) Construct an asset comprehensive susceptibility warning model based on graph algorithms

[0056] Assets are usually interconnected through a network, and all assets form an overall local area network. In this embodiment, the PageRank algorithm is used to calculate the importance weight of assets in the topological structure of the current network system, where the importance weight of each node (asset) can be expressed as the weighted average of the importance weights of the nodes it can directly affect. Specifically expressed as where PR(A) represents the importance weight of node A, and A i represents all the nodes that node A can directly affect, and L(A i ) represents the number of nodes that can affect node A i . In this process, the importance weight of any one node needs to be set to non-zero first, and then iterated continuously until the importance weights of all nodes converge.

[0057] After obtaining the importance weight of the asset, combined with the single-asset susceptibility level calculated above, the asset comprehensive susceptibility warning level is calculated by weighted average as the output of the model.

[0058] 2) Construct a comprehensive police situation warning model based on the threshold dynamic adaptive algorithm

[0059] The comprehensive police situation warning model takes the single-asset susceptibility level, the single security event warning level, and the impact surface of the attack event as the model input. Since security events often show a periodic and intensive distribution, the output of the comprehensive police situation warning model may fluctuate greatly. Therefore, a dynamic adaptive threshold needs to be introduced to limit the output of the warning model.

[0060] Define the recent network security vulnerability factor in this embodiment As a dynamic adaptive threshold, this factor represents the comprehensive risk level within the recent i security events, where E i represents the early warning index of security event i, and C i represents the weighted average of the asset susceptibility early warning index affected by it. Based on this, define the network security comprehensive alarm index where m is the pre-set number of target security events (such as 5), and KR is the output of the comprehensive alarm early warning model.

[0061] 3) Construct a network security alarm trend early warning model based on the LSTM neural network

[0062] The time-series future impact trend model is established based on the LSTM neural network. This model takes daily attack events, asset susceptibility status, etc. as inputs and outputs the prediction of the alarm level at the next or several future time nodes. The basic principle of the LSTM neural network is to use the information learned at the previous moment for learning at the current moment. In this embodiment, the recent comprehensive alarm index KR of the past n time nodes is expressed as {k1, k2, k3,..., k n}, and the expected output of the model is k n+1 , then the long-term memory C t = f t * C t-1 + i t * C t , where f t represents the forgetting gate coefficient, and i t = σ(W i · [h t-1 , k t + b i ) represents the current input gate; the short-term memory h t = o t * tanh(C t ), where o t = σ(W o · [h t-1 , k t + b o ) represents the output gate. Among them, C t-1 represents the long-term memory at time t - 1, h t-1 represents the short-term memory at time t - 1, W i , b i represent the weight matrix and bias term of the input gate, σ represents the Sigmoid function, W o , b o represent the weight matrix and bias term of the output gate. By looping and iterating in this way, the prediction k t+1 at time t + 1 is obtained as the model output.

[0063] Step 4: Execute the early warning business process

[0064] In combination with specific business needs, based on the output of multiple early warning models, the entire business process of early warning information release, tracking, upgrading, disposing and lifting of warnings is executed.

[0065] Based on the same inventive concept, another embodiment of the present invention provides a multi-dimensional network security comprehensive early warning system using the above method, which includes:

[0066] The data collection and preprocessing module is used to collect multi-source heterogeneous network security big data and perform data preprocessing operations on the collected data to make it meet the needs of subsequent model analysis;

[0067] A multi-dimensional network security early warning model construction module is used to build a multi-dimensional network security early warning model to characterize the current network security status in multiple dimensions;

[0068] A comprehensive warning model construction module is used to build a comprehensive warning model based on the multi-dimensional network security warning model to provide comprehensive warning of the current network security situation;

[0069] The early warning business process execution module is used to execute the entire business process of early warning information release, tracking, upgrading, disposing and lifting the early warning based on the constructed comprehensive alarm warning model and combined with specific business needs.

[0070] Based on the same inventive concept, another embodiment of the present invention provides an electronic device (computer, server, smart phone, etc.), which includes a memory and a processor, the memory stores a computer program, the computer program is configured to be executed by the processor, and the computer program includes instructions for executing each step in the method of the present invention.

[0071] Based on the same inventive concept, another embodiment of the present invention provides a computer-readable storage medium (such as ROM / RAM, disk, CD), which stores a computer program. When the computer program is executed by a computer, it implements the various steps of the method of the present invention.

[0072] The specific embodiments of the present invention disclosed above are intended to help understand the content of the present invention and implement it accordingly. It can be understood by those skilled in the art that various replacements, changes and modifications are possible without departing from the spirit and scope of the present invention. The present invention should not be limited to the contents disclosed in the embodiments of this specification, and the scope of protection of the present invention shall be subject to the scope defined in the claims.

Claims

1. A multi-dimensional comprehensive network security early warning method, characterized in that It includes the following steps: Collect multi-source heterogeneous cybersecurity big data, and perform data preprocessing operations on the collected data to make it meet the requirements of subsequent model analysis; Construct a multi-dimensional cybersecurity early warning model to depict the current cybersecurity situation in multiple dimensions; Based on the constructed multi-dimensional cybersecurity early warning model, construct a comprehensive police situation early warning model to conduct comprehensive early warning of the current cybersecurity situation; Based on the constructed comprehensive police situation early warning model, combined with specific business requirements, execute the entire process business process of early warning information release, tracking, upgrade / downgrade, disposal, and early warning cancellation; The steps of constructing the multi-dimensional cybersecurity early warning model include: Construct a security event level early warning model based on the random forest algorithm; Construct an asset susceptibility level early warning model; Construct an attack impact surface early warning model based on the knowledge graph; The construction of the security event level early warning model based on the random forest algorithm includes: based on the multi-dimensional information of security events including attack vulnerabilities, attack targets, and damage degrees, construct a cybersecurity event level early warning index system, and set weights for the indicators based on the expert system; based on historical experience and the index system, manually label the early warning levels of historical security events to form model training samples; randomly and with replacement, extract some samples as the sample sets for each decision tree, and based on these sample sets, train a random forest classifier to construct a security event level early warning model; The construction of the asset susceptibility level warning model includes: extracting asset features based on network asset basic information, vulnerability information, and asset threat lists to form a feature vector, which is represented as A i ={a i1 ,a i2 ,...,a in}, where a i1 to a in represent the first to the nth attributes of the asset numbered i, realizing multi-dimensional profiling of network assets; constructing an asset susceptibility level determination rule base, and constructing an asset susceptibility level warning model according to the asset susceptibility level determination rule base; The construction of the attack impact surface early warning model based on the knowledge graph includes: clarify the dimensions affecting early warning, mainly including the affected industry, region, operating system, services and ports, and asset types; construct an impact surface information knowledge graph; construct an inference model for the impact degree of each dimension based on the knowledge graph; according to this inference model, infer the early warning impact surface information of the event, including the affected area, affected industry, affected system, and impact trend; The steps of constructing the comprehensive police situation early warning model include: Construct an asset comprehensive susceptibility early warning model based on the graph algorithm; Construct a police situation early warning model based on the threshold dynamic adaptive algorithm; Construct a cybersecurity police situation trend early warning model based on the LSTM neural network; The construction of the asset comprehensive susceptibility early warning model based on the graph algorithm includes: based on the susceptibility data of assets in the network environment of the asset susceptibility level early warning model, combined with the PageRank graph algorithm, assign weights to the importance of each asset node in the network topology, and infer and calculate the comprehensive susceptibility early warning level of all assets in the current network environment, and output the early warning information of the current network comprehensive susceptibility situation; The construction of the police situation early warning model based on the threshold dynamic adaptive algorithm includes: based on the security event level early warning data, asset susceptibility level early warning data, and attack impact surface early warning data, construct a comprehensive early warning index system, determine the index weights, and assign values to the early warning indicators; based on the threshold dynamic adaptive algorithm, calculate the network security comprehensive police situation index, and issue comprehensive early warning information about the frequency and severity of attacks on the current system; The construction of a network security alert trend warning model based on an LSTM neural network includes: using daily attack events and asset susceptibility status as feature inputs, and taking the daily comprehensive alert index score as the annotation result to form a training dataset, constructing and training an LSTM neural network to warn of the development trend of the future network security state.

2. The method according to claim 1, characterized in that, The multi-source heterogeneous network security big data includes security event data, multi-dimensional portraits of assets, and threat intelligence data. The data preprocessing removes noise data and irrelevant data in the multi-source dataset, processes possible omission problems and dirty data in the dataset, including the processing of incomplete data and abnormal data, smoothing noise data, identifying and deleting outliers, and solving data inconsistency problems to improve the quality of the collected data and ensure the integrity and accuracy of the collected data.

3. The method according to claim 1, wherein Combined with specific business requirements, based on the outputs of multiple warning models in the comprehensive alert warning model, the whole process business processes of warning information release, tracking, upgrade / downgrade, disposal, and warning cancellation are executed.

4. A multi-dimensional network security comprehensive early warning system adopting the method described in any one of claims 1 to 3, characterized in that, It includes: A data collection and preprocessing module, which is used to collect multi-source heterogeneous network security big data and perform data preprocessing operations on the collected data to make it meet the requirements of subsequent model analysis; A multi-dimensional network security warning model construction module, which is used to construct a multi-dimensional network security warning model to depict the current network security status in multiple dimensions; A comprehensive alert warning model construction module, which is used to construct a comprehensive alert warning model based on the constructed multi-dimensional network security warning model to give a comprehensive warning of the current network security status; An alert business process execution module, which is used to execute the whole process business processes of warning information release, tracking, upgrade / downgrade, disposal, and warning cancellation based on the constructed comprehensive alert warning model and combined with specific business requirements.

5. An electronic device, characterized in that, It includes a memory and a processor. The memory stores a computer program, and the computer program is configured to be executed by the processor. The computer program includes instructions for executing the method described in any one of claims 1 to 3.

6. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and when the computer program is executed by a computer, the method described in any one of claims 1 to 3 is implemented.

Citation Information

Patent Citations

  • Network safety situation awareness early-warning method and system based big data

    CN105553957A

  • Knowledge graph construction method and device based on bank-to-public data

    CN113065657A