Network security asset three-dimensional visualization management method, system and device
By using digital twin technology and city information models, a three-dimensional model of cybersecurity assets is constructed, which solves the problems of single expression and poor real-time performance in traditional management methods. This enables real-time and comprehensive monitoring and management of cybersecurity assets, improving management efficiency and accuracy.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- CHINA UNITED NETWORK COMM GRP CO LTD
- Filing Date
- 2023-07-11
- Publication Date
- 2026-07-24
Smart Images

Figure CN116827811B_ABST
Abstract
Description
Technical Field
[0001] This application relates to communication technology, and in particular to a method, system and device for three-dimensional visualization management of network security assets. Background Technology
[0002] With the development of information technology, network information systems are playing an increasingly crucial role, and the software and hardware information related to network information is referred to as network security assets. Traditional methods of network security asset management involve collecting network security asset data and directly using it in network security management systems, or generating reports based on data analysis for managers to use.
[0003] However, most existing cybersecurity asset management methods use charts to display cybersecurity asset data, such as displaying fixed data content next to a cybersecurity asset diagram. This fails to show the location and status of cybersecurity assets in a 3D city scene. Furthermore, existing cybersecurity management methods lack effective interaction between cybersecurity assets and people, manual updates cannot be real-time and timely, and vulnerability detection programs are difficult to collect, making it difficult to fully grasp the cybersecurity status. Summary of the Invention
[0004] This application provides a method, system, and device for three-dimensional visualization management of network security assets, which solves the problems of traditional network security asset management methods being limited in expression, lacking real-time performance, having low management efficiency, and having a narrow perspective.
[0005] On the one hand, this application provides a method for three-dimensional visualization management of network security assets, including:
[0006] Cybersecurity asset data is obtained by collecting on-site data and equipment operation data;
[0007] The network security asset data is analyzed to obtain analytical data, which includes status data of various scenarios in the network security assets, and the scenarios include on-site and equipment.
[0008] Based on the scenarios in the network security assets, the network security asset 3D models corresponding to each scenario are retrieved from the preset network security asset 3D model library to construct the target 3D model. The network security asset 3D model library is used to store network security asset 3D models corresponding to different scenarios.
[0009] Based on the analysis data, the visualization parameters in the target 3D model are configured, and a visualization effect is generated on the target 3D model. Data windows are loaded and generated at the associated positions of each scene in the target 3D model, and the analysis data and original data corresponding to each scene are displayed in the data windows.
[0010] In one possible implementation, acquiring cybersecurity asset data through the collection of on-site data and equipment operation data includes:
[0011] Collect real-time data captured by the camera to obtain on-site data, and collect real-time operating data of the equipment to obtain equipment operating data;
[0012] The on-site data and the equipment operation data are aggregated as the raw data;
[0013] The raw data is preprocessed to generate data on acquiring network security assets.
[0014] In one possible implementation, the preprocessing of the raw data includes:
[0015] According to the preset data verification rules, the original data is divided into correct data, duplicate data, erroneous data, and incomplete data;
[0016] The function deletes duplicate data, keeping only one copy of the duplicate data as the correct data.
[0017] The correct data is retained, and a preprocessing report is generated based on the erroneous data and the incomplete data.
[0018] In one possible implementation, the analysis data includes geographic location data for each scenario within the cybersecurity assets. The step of retrieving the corresponding 3D models of the cybersecurity assets from a pre-defined 3D model library of cybersecurity assets to construct the target 3D model includes:
[0019] Obtain the corresponding 3D models of cybersecurity assets for each scenario from the pre-set 3D model library of cybersecurity assets;
[0020] Based on the geographic location data of each scenario, the 3D models of the cybersecurity assets corresponding to each scenario are combined to construct the target 3D model.
[0021] In one possible implementation, configuring visualization parameters in the target 3D model based on the analysis data and generating visualization effects based on the target 3D model includes:
[0022] Based on the state data of each scenario, the visualization parameters corresponding to each scenario are obtained from the preset state parameter library. The preset state parameter library is used to store the visualization parameters corresponding to each state data. The visualization parameters include color parameters, brightness parameters, flash frequency parameters, and transparency parameters.
[0023] Based on the visualization parameters corresponding to each scenario, the visualization parameters of the network security asset 3D model for each scenario in the target 3D model are configured to generate visualization effects.
[0024] In one possible implementation, the analysis of the network security asset data to obtain analysis data includes:
[0025] Based on the preset data security range for each scenario, determine whether the network security asset data in each scenario is abnormal data;
[0026] If so, the state data of the scenario is in an abnormal state;
[0027] If not, obtain the status data of the scenario based on the network security asset data of the scenario.
[0028] In one possible implementation, after determining whether the network security asset data in each scenario is abnormal data, the method further includes:
[0029] Scenarios with abnormal status data are identified as abnormal scenarios, and geographic information data of the abnormal scenarios are obtained from the network security asset data of the abnormal scenarios.
[0030] Based on the geographic information data of the abnormal scenario, an alarm is issued in the data window associated with the abnormal scenario.
[0031] On the other hand, this application provides a 3D visualization management device for network security assets, comprising:
[0032] The data acquisition module is used to acquire network security asset data by collecting on-site data and equipment operation data;
[0033] The data analysis module is used to analyze the network security asset data and obtain analysis data. The analysis data includes status data of various scenarios in the network security assets, and the scenarios include on-site and equipment.
[0034] The target 3D model construction module is used to retrieve the network security asset 3D model corresponding to each scenario from the preset network security asset 3D model library to construct the target 3D model based on the scenario in the network security asset. The network security asset 3D model library is used to store the network security asset 3D models corresponding to different scenarios.
[0035] The visualization module is used to configure the visualization parameters in the target 3D model according to the analysis data, generate visualization effects based on the target 3D model, load and generate data windows at the associated positions of each scene in the target 3D model, and display the analysis data and original data corresponding to each scene in the data windows.
[0036] Thirdly, this application provides an electronic device, including a memory, a processor, and computer-executable instructions stored in the memory and executable on the processor, wherein the processor executes the computer-executable instructions to implement the network security asset three-dimensional visualization management method described in any one of the first aspects above.
[0037] Fourthly, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the network security asset three-dimensional visualization management method described in any one of the first aspects.
[0038] This application provides a method, system, and device for 3D visualization management of cybersecurity assets. It acquires cybersecurity asset data by collecting on-site data and equipment operation data; analyzes the cybersecurity asset data to obtain analytical data, which includes status data for various scenarios within the cybersecurity assets, including on-site and equipment scenarios; constructs a target 3D model by retrieving corresponding 3D models of cybersecurity assets from a pre-set 3D model library for storing 3D models of cybersecurity assets corresponding to different scenarios; configures visualization parameters in the target 3D model based on the analytical data; generates visualization effects based on the target 3D model; loads and generates data windows at the associated locations of each scenario in the target 3D model; and displays the analytical data and original data corresponding to each scenario within the data windows. This method combines digital twin technology, urban information models, and cybersecurity asset monitoring to present cybersecurity asset information in real-time in the form of pre-stored animated 3D models of cybersecurity assets. Attached Figure Description
[0039] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this application and, together with the description, serve to explain the principles of this application.
[0040] Figure 1 This is a schematic diagram illustrating an application scenario of the network security asset 3D visualization management method provided in this application embodiment.
[0041] Figure 2 A flowchart illustrating the network security asset 3D visualization management method provided in this application embodiment.
[0042] Figure 3 This is a flowchart illustrating the method for generating visualization effects based on a target 3D model, as provided in this embodiment.
[0043] Figure 4 A schematic diagram of a network security asset 3D visualization management device provided in an embodiment of this application.
[0044] Figure 5 A schematic diagram of the structure of an electronic device based on a network security asset 3D visualization management device provided in this application embodiment.
[0045] The accompanying drawings illustrate specific embodiments of this application, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the concept in any way, but rather to illustrate the concept of this application to those skilled in the art through reference to particular embodiments. Detailed Implementation
[0046] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0047] First, let me explain the terms used in this application:
[0048] City Information Modeling (CIM) is an organic integration of three-dimensional urban spatial models and urban information, built upon urban information data. The CIM basic platform is a fundamental platform for expressing and managing the three-dimensional urban space, based on basic urban geographic information, to establish three-dimensional digital models of buildings, infrastructure, etc. It serves as the basic operational platform for urban planning, construction, management, and operation, and is the fundamental, crucial, and physical information infrastructure for smart cities.
[0049] Digital twins fully utilize data from physical models, sensor updates, and operational history to integrate multi-disciplinary, multi-physical, multi-scale, and multi-probabilistic simulation processes, completing a mapping in virtual space to reflect the entire lifecycle of the corresponding physical equipment. Digital twins are a concept that transcends reality, and can be viewed as a digital mapping system of one or more important, interdependent equipment systems.
[0050] In related technologies, traditional methods for managing cybersecurity assets have the following problems:
[0051] First, the presentation method is too simplistic. Most of the data on cybersecurity assets is presented in the form of charts and graphs. For example, fixed data content is displayed next to the schematic diagram of cybersecurity assets. It is impossible to show the location and status of cybersecurity assets in a 3D city scene, and it is difficult to view other content or view detailed information from other perspectives, which is not conducive to the monitoring of managers.
[0052] Secondly, there is a lack of real-time monitoring and feedback mechanisms. Traditional cybersecurity asset management typically requires manual collection and analysis of asset data, making real-time monitoring and feedback impossible. This makes it difficult for managers to understand the operational and security status of assets in a timely manner, hindering them from taking appropriate measures and increasing the risk of security vulnerabilities and malfunctions.
[0053] Third, it lacks comprehensiveness and holistic perspective. Traditional cybersecurity asset management typically focuses only on specific asset categories and security issues, lacking a comprehensive and holistic view. This makes it difficult for managers to fully understand and grasp the status of cybersecurity assets, easily leading to blind spots and vulnerabilities.
[0054] To address the aforementioned technical issues, this application aims to propose a method, system, and device for three-dimensional visualization management of network security assets. The core concept of this method is to combine virtual network security assets with real-world network security assets using digital twin technology. This allows network security managers to intuitively view network security assets and their operational status within a simulated three-dimensional scene displayed on a control terminal, without leaving their offices, and to grasp key network security information. This approach effectively compensates for the shortcomings of traditional network security management methods and improves the efficiency and accuracy of network security control.
[0055] To better understand the solutions of the embodiments of this application, an application scenario involved in the embodiments of this application will be introduced below.
[0056] Please see Figure 1 , Figure 1 This is a schematic diagram illustrating an application scenario of the 3D visualization management method for network security assets provided in this application embodiment, such as... Figure 1 As shown, it includes scene terminal 100, server 200, and display terminal 300.
[0057] The scenario terminal 100 includes a site and equipment. For example, the site can be a computer room with cameras, and the equipment can be sensors, etc. The scenario terminal 100 continuously generates real-time data related to network security assets and sends this data to the server 200.
[0058] Server 200 can receive relevant data sent by scene terminal 100 and process this data accordingly to form a visualized model and data that can be displayed on display terminal 300. Specifically, server 200 may include a data center, a data acquisition unit, a data analysis unit, and a 3D visualization unit. The data acquisition unit is used to receive relevant data sent by scene terminal 100 and store the data in the data center; the data analysis unit can be used to extract data from the data center, analyze the data, and obtain analyzed data; the 3D visualization unit includes a 3D model synthesis module, an analysis data matching module, and a 3D rendering and display module. The 3D model synthesis module is used to retrieve 3D models of network security assets from a city-level network security asset 3D model library; the analysis data matching module is used to configure visualization parameters of the 3D models of network security assets according to the analysis data; and the 3D rendering and display module is used to render the 3D models of network security assets.
[0059] The display terminal 300 can be used to display the rendered 3D model of the network security asset generated by the server 200. The display terminal 300 can refer to a terminal with a display screen or a terminal with a CIM 3D platform.
[0060] The technical solution of this application and how it solves the above-mentioned technical problems will be described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will be described below with reference to the accompanying drawings.
[0061] Figure 2 A flowchart illustrating the 3D visualization management method for network security assets provided in this application embodiment. Figure 2 As shown, the method in this embodiment includes:
[0062] S201: Obtain network security asset data by collecting on-site data and equipment operation data.
[0063] The execution entity of this application embodiment can be a server, or a network security asset 3D visualization management system in the server, wherein the network security asset 3D visualization management system can be implemented by software.
[0064] It is understood that the on-site data may include real-time video of the computer room captured by the camera, and the equipment operation data may include equipment data collected by sensors on the equipment, including network traffic, abnormal access, and other data.
[0065] S202: Analyze the network security asset data to obtain analysis data, which includes status data of various scenarios in the network security assets, including on-site and equipment scenarios.
[0066] In this step, the analysis of the network security asset data mainly includes statistical analysis of the data according to preset rules, and combining the raw data with the location of the network security assets, so as to obtain the status data of each scenario in the network security assets.
[0067] S203: Based on the scenarios in the network security assets, retrieve the network security asset 3D models corresponding to each scenario from the preset network security asset 3D model library to construct the target 3D model. The network security asset 3D model library is used to store the network security asset 3D models corresponding to different scenarios.
[0068] In this step, based on the real-world scenario, the corresponding 3D models of network security assets for each scenario are retrieved from a pre-set 3D model library of network security assets, thereby constructing a digital, virtual target 3D model. The target 3D model can reflect the state of the real scenario and realize digital twin.
[0069] Understandably, the CIM 3D scene contains various models that map real cybersecurity assets, such as devices and network connections, and a 3D model library of cybersecurity assets can be built based on the CIM 3D scene.
[0070] S204: Configure the visualization parameters in the target 3D model according to the analysis data, generate visualization effects based on the target 3D model, load and generate data windows at the associated positions of each scene in the target 3D model, and display the analysis data and original data corresponding to each scene in the data windows.
[0071] This step primarily involves transforming the state data corresponding to each scenario in the analyzed data and expressing it intuitively using specific visualization methods. Specifically, by acquiring and analyzing real-time data, the visualization parameters in the target 3D model are configured. For example, by changing the color, brightness, luminance, and transparency of the 3D model, the model corresponding to the scenario is categorized and displayed to represent different current working states. Thus, the state of a specific network security asset can be expressed through animation, essentially showing the real-time operational status of the network security asset. Furthermore, it allows for a clear understanding of whether a particular network security asset is functioning correctly when a scenario malfunctions.
[0072] The 3D visualization management method for cybersecurity assets provided in this embodiment acquires cybersecurity asset data by collecting on-site data and equipment operation data; analyzes the cybersecurity asset data to obtain analytical data, which includes status data of various scenarios within the cybersecurity assets, including on-site and equipment scenarios; constructs a target 3D model by retrieving corresponding cybersecurity asset 3D models from a pre-set cybersecurity asset 3D model library, which stores 3D models of cybersecurity assets corresponding to different scenarios; configures visualization parameters in the target 3D model based on the analytical data; generates visualization effects based on the target 3D model; loads and generates data windows at the associated locations of each scenario in the target 3D model; and displays the analytical data and original data corresponding to each scenario within the data windows. This method combines digital twin technology, urban information models, and cybersecurity asset monitoring to present cybersecurity asset information in real-time in the form of pre-stored cybersecurity asset 3D model animations.
[0073] The technical solution of the above-mentioned 3D visualization management method for network security assets will be described in detail below.
[0074] In one possible implementation, the network security asset 3D visualization management method provided in this embodiment summarizes the on-site data and the equipment operation data as raw data, and obtains network security asset data after preprocessing the raw data.
[0075] Specifically, the process of acquiring network security asset data by collecting on-site data and equipment operation data includes: collecting real-time shooting data from cameras to obtain on-site data; collecting real-time operation data from equipment to obtain equipment operation data; summarizing the on-site data and the equipment operation data as raw data; and preprocessing the raw data to generate network security asset data.
[0076] Understandably, data from the cybersecurity asset's location, including operational status data, can be collected via sensors, data acquisition devices, and monitoring programs deployed on the asset. This collected data is then converted to Transmission Control Protocol / Internet Protocol (TCP / IP), thus providing raw data that can be transmitted over the internet.
[0077] Specifically, the preprocessing of the raw data includes: classifying the raw data into correct data, duplicate data, erroneous data, and incomplete data according to preset data verification rules; deleting duplicate data and retaining only one copy of the duplicate data as correct data; retaining the correct data and generating a preprocessing report based on the erroneous data and the incomplete data.
[0078] In the preprocessing step of the raw data, the raw data is first classified according to preset data validation rules. These rules can be based on the content and generation time of the raw data to determine its category. Different processing is applied to raw data in different categories, thereby filtering the raw data. A preprocessing report is then generated based on the erroneous and incomplete data for maintenance personnel to review.
[0079] In this embodiment, by aggregating the field data and the equipment operation data as raw data, and preprocessing the raw data, network security asset data is obtained, which effectively ensures the comprehensiveness and accuracy of data collection and is beneficial to the accuracy of subsequent data analysis.
[0080] In one possible implementation, the analysis data includes geographic location data of various scenarios in the cybersecurity assets. The step of retrieving the cybersecurity asset 3D models corresponding to each scenario from a preset cybersecurity asset 3D model library to construct the target 3D model includes: obtaining the cybersecurity asset 3D models corresponding to each scenario from the preset cybersecurity asset 3D model library; and merging the cybersecurity asset 3D models corresponding to each scenario based on the geographic location data of each scenario to construct the target 3D model.
[0081] In this embodiment, the network security asset 3D model corresponding to each scenario can be called from the network security asset 3D model library, and the position parameter data can be matched to the network security asset 3D model. Thus, the network security asset 3D model can be generated at the corresponding position in the 3D scene, thereby constructing the target 3D model.
[0082] In this embodiment, by retrieving the corresponding 3D models of network security assets for each scenario from a preset 3D model library of network security assets, a digital and virtual target 3D model is constructed to achieve digital twin. This enables the digital twin to reflect the status of each actual scenario in real time within the CIM 3D scene in a digital form.
[0083] In one possible implementation, the network security asset 3D visualization management method provided in this embodiment obtains visualization parameters corresponding to each scenario from a preset state parameter library based on the state data of each scenario, and configures the visualization parameters in the target 3D model to generate visualization effects. Figure 3The flowchart of the method for generating visualization effects based on a target 3D model provided in this embodiment is as follows: Figure 3 As shown, the visualization parameters in the target 3D model are configured based on the analysis data, and a visualization effect is generated based on the target 3D model, including:
[0084] S301: Obtain the visualization parameters corresponding to each scenario from the preset state parameter library based on the state data of each scenario. The preset state parameter library is used to store the visualization parameters corresponding to each state data.
[0085] In this step, based on the current status data of each scenario in the city-level cybersecurity assets, visualization parameters that match the current status data are invoked from a preset status parameter library. As an example, and not a limitation, these visualization parameters include color parameters, brightness parameters, flash frequency parameters, and transparency parameters.
[0086] S302: Based on the visualization parameters corresponding to each scenario, configure the visualization parameters of the network security asset 3D model for each scenario in the target 3D model to generate visualization effects.
[0087] In this step, the model corresponding to the scene is displayed by changing the color, brightness, luminance, and transparency of the 3D model, so as to express the different current working states.
[0088] It is understandable that the process of configuring visualization parameters is also the process of driving state animation in the 3D model according to the state of the scene. The state animation is a pre-set state animation that matches the state of network security assets, and there is a corresponding matching relationship between the state animation and the state data.
[0089] Specifically, there are two ways to drive state animations: categorized data-driven state animations and numerical data-driven state animations. Categorized data-driven state animations work by pre-setting state animations in a preset state parameter library, categorizing state data of similar cybersecurity assets by different magnitudes or states. The corresponding state animation is then displayed based on the magnitude or state category of the current state data. This method utilizes a mapping relationship, directly calling the corresponding state animation from the preset animation library based on the state data. While the animation expression is discontinuous, it can be handled relatively simply, and the operation and setup are straightforward. Numerical data-driven state animations work by setting a corresponding state animation for a cybersecurity asset in a preset state parameter library. The display parameters of the state animation are changed based on the current data value, thus displaying the corresponding state animation. This method uses data values to change the parameter properties of the state animation itself, allowing the state animation to change continuously and express more detail. However, it requires more factors, making the calculation and processing more complex.
[0090] In this embodiment, visualization parameters corresponding to each scenario are obtained from a preset state parameter library based on the state data of each scenario. The visualization parameters in the target 3D model are then configured to generate a visualization effect. This method features high information integration and high information visualization, which can meet the needs of managers at all levels to quickly and efficiently grasp network security asset information, as well as the needs of managers to deeply view network security asset information.
[0091] In one possible implementation, the step of analyzing the network security asset data and obtaining analysis data includes: determining whether the network security asset data of each scenario is abnormal data based on the preset data security range of each scenario; if so, the status data of the scenario is abnormal; if not, obtaining the status data of the scenario based on the network security asset data of the scenario.
[0092] Understandably, when anomalies such as equipment failure or network intrusion occur in a scenario, the network security asset data will also exceed the preset data security range. Therefore, by detecting whether the network security asset data in a scenario exceeds the preset data security range, it can be determined whether the network security asset data is abnormal, and thus whether the scenario's state is abnormal, so as to facilitate display and issue alarms in the visualization interface.
[0093] In this embodiment, by detecting whether the network security asset data of the scene exceeds the preset data security range, it is determined whether the network security asset data is abnormal data. Status data corresponding to the actual state of the scene can be generated in the three-dimensional visualization model to quickly identify whether the scene is abnormal and thus issue an alarm in a timely manner.
[0094] In one possible implementation, considering that alarms can be issued for scenarios with abnormal data while also locating them, after determining whether the network security asset data for each scenario is abnormal data, the method further includes: designating scenarios with abnormal status data as abnormal scenarios, obtaining the geographic information data of the abnormal scenarios from the network security asset data of the abnormal scenarios; and issuing an alarm in the data window associated with the abnormal scenarios based on the geographic information data of the abnormal scenarios.
[0095] In this embodiment, after obtaining abnormal data, the system quickly locates the scene to which the abnormal data belongs and issues an alarm on the system's display interface.
[0096] In this embodiment, by acquiring the geographic information data of the abnormal scene, and issuing an alarm in the data window associated with the abnormal scene based on the geographic information data of the abnormal scene, the abnormal scene can be alarmed in a timely manner in the three-dimensional visualization model and associated with its geographic information data, which facilitates maintenance personnel to carry out maintenance work in a timely manner and improves the responsiveness of network security asset management.
[0097] Figure 4 This is a schematic diagram of a network security asset 3D visualization management device provided in an embodiment of this application. Figure 4 As shown, the 3D visualization management device for network security assets includes:
[0098] The data acquisition module 41 is used to acquire network security asset data by collecting on-site data and equipment operation data;
[0099] Data analysis module 42 is used to analyze the network security asset data and obtain analysis data. The analysis data includes status data of various scenarios in the network security assets. The scenarios include on-site and equipment.
[0100] The target 3D model construction module 43 is used to retrieve the network security asset 3D model corresponding to each scenario from the preset network security asset 3D model library to construct the target 3D model based on the scenario in the network security asset. The network security asset 3D model library is used to store the network security asset 3D models corresponding to different scenarios.
[0101] The visualization module 44 is used to configure the visualization parameters in the target 3D model according to the analysis data, generate visualization effects based on the target 3D model, load and generate data windows at the associated positions of each scene in the target 3D model, and display the analysis data and original data corresponding to each scene in the data windows.
[0102] In one possible design, the data acquisition module 41 is specifically used for:
[0103] Collect real-time data captured by the camera to obtain on-site data, and collect real-time operating data of the equipment to obtain equipment operating data;
[0104] The on-site data and the equipment operation data are aggregated as the raw data;
[0105] The raw data is preprocessed to generate data on acquiring network security assets.
[0106] In one possible design, the data acquisition module 41 is also specifically used for:
[0107] According to the preset data verification rules, the original data is divided into correct data, duplicate data, erroneous data, and incomplete data;
[0108] The function deletes duplicate data, keeping only one copy of the duplicate data as the correct data.
[0109] The correct data is retained, and a preprocessing report is generated based on the erroneous data and the incomplete data.
[0110] In one possible design, the analysis data includes geographic location data of various scenarios in the cybersecurity assets, and the target 3D model construction module 43 is specifically used to: obtain the cybersecurity asset 3D model corresponding to each scenario from the preset cybersecurity asset 3D model library;
[0111] Based on the geographic location data of each scenario, the 3D models of the cybersecurity assets corresponding to each scenario are combined to construct the target 3D model.
[0112] In one possible design, the visualization module 44 is specifically used for:
[0113] Based on the state data of each scenario, the visualization parameters corresponding to each scenario are obtained from the preset state parameter library. The preset state parameter library is used to store the visualization parameters corresponding to each state data. The visualization parameters include color parameters, brightness parameters, flash frequency parameters, and transparency parameters.
[0114] Based on the visualization parameters corresponding to each scenario, the visualization parameters of the network security asset 3D model for each scenario in the target 3D model are configured to generate visualization effects.
[0115] In one possible design, the data analysis module 42 is specifically used for:
[0116] Based on the preset data security range for each scenario, determine whether the network security asset data in each scenario is abnormal data;
[0117] If so, the state data of the scenario is in an abnormal state;
[0118] If not, obtain the status data of the scenario based on the network security asset data of the scenario.
[0119] In one possible design, the data analysis module 42 is also specifically used for:
[0120] Scenarios with abnormal status data are identified as abnormal scenarios, and geographic information data of the abnormal scenarios are obtained from the network security asset data of the abnormal scenarios.
[0121] Based on the geographic information data of the abnormal scenario, an alarm is issued in the data window associated with the abnormal scenario.
[0122] Figure 5 This is a schematic diagram of the structure of an electronic device based on a 3D visualization management device for network security assets, provided in an embodiment of this application. Figure 5 As shown, the electronic device of this embodiment includes: at least one processor 50 ( Figure 5 (Only one is shown) a processor, a memory 51, and a computer program stored in the memory 51 that can run on at least one processor 50, which executes the computer program to implement the steps in any of the above method embodiments.
[0123] The electronic device may include, but is not limited to, a processor 50 and a memory 51. Those skilled in the art will understand that... Figure 5 This is merely an example of an electronic device and does not constitute a limitation on electronic devices. It may include more or fewer components than shown in the illustration, or combinations of certain components, or different components. For example, it may also include input / output devices, network access devices, etc.
[0124] The processor 50 may be a Central Processing Unit (CPU), or it may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor.
[0125] The specific implementation process of processor 501 can be found in the above method embodiments, and its implementation principle and technical effect are similar. It will not be repeated here.
[0126] In some embodiments, memory 51 may be an internal storage unit of an electronic device, such as the memory of the electronic device. In other embodiments, memory 51 may be an external storage device of the electronic device, such as a plug-in hard drive, smart media card (SMC), secure digital (SD) card, flash card, etc. Furthermore, memory 51 may include both internal and external storage units of the electronic device. Memory 51 is used to store operating systems, applications, bootloaders, data, and other programs, such as program code for computer programs. Memory 51 can also be used to temporarily store data that has been output or will be output.
[0127] This application also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps described in the various method embodiments above.
[0128] The aforementioned computer-readable storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The readable storage medium can be any available medium accessible to a general-purpose or special-purpose computer.
[0129] An exemplary readable storage medium is coupled to a processor, enabling the processor to read information from and write information to the readable storage medium. Of course, the readable storage medium can also be a component of the processor. The processor and the readable storage medium can reside in an application-specific integrated circuit (ASIC). Alternatively, the processor and the readable storage medium can exist as discrete components in the aforementioned electronic device.
[0130] Those skilled in the art will understand that all or part of the steps of the above-described method embodiments can be implemented by hardware related to program instructions. The aforementioned program can be stored in a computer-readable storage medium. When executed, the program performs the steps of the above-described method embodiments; and the aforementioned storage medium includes various media capable of storing program code, such as ROM, RAM, magnetic disks, or optical disks.
[0131] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0132] In the embodiments provided in this application, it should be understood that the disclosed apparatus / network devices and methods can be implemented in other ways. For example, the apparatus / network device embodiments described above are merely illustrative. For instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.
[0133] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment, depending on actual needs. Other embodiments of this application will readily conceive of by those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this application that follow the general principles of this application and include common knowledge or customary techniques in the art not disclosed herein. The specification and embodiments are to be considered exemplary only, and the true scope and spirit of this application are indicated by the following claims.
[0134] It should be understood that this application is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this application is limited only by the appended claims.
Claims
1. A method for three-dimensional visualization management of network security assets, characterized in that, include: Collect real-time data captured by the camera to obtain on-site data, and collect real-time operating data of the equipment to obtain equipment operating data; The on-site data and the equipment operation data are aggregated as the raw data; The raw data is preprocessed to generate data on acquiring network security assets; The network security asset data is analyzed to obtain analytical data, which includes status data of various scenarios in the network security assets, including on-site and equipment scenarios; wherein, the analytical data includes geographical location data of various scenarios in the network security assets, and the status data is obtained by judging the network security asset data according to the preset data security range of each scenario; Based on the scene and geographic location data in the cybersecurity assets, the cybersecurity asset 3D model corresponding to each scene is obtained from the preset cybersecurity asset 3D model library. Based on the geographic location data of each scene, the cybersecurity asset 3D models corresponding to each scene are combined to construct the target 3D model. The cybersecurity asset 3D model library is used to store the cybersecurity asset 3D models corresponding to different scenes. Based on the state data of each scenario, the visualization parameters corresponding to each scenario are obtained from the preset state parameter library. Based on the visualization parameters corresponding to each scenario, the visualization parameters of the network security asset 3D model of each scenario in the target 3D model are configured to generate visualization effects. Data windows are loaded and generated at the associated positions of each scenario in the target 3D model, and the analysis data and raw data corresponding to each scenario are displayed in the data windows.
2. The method according to claim 1, characterized in that, The preprocessing of the raw data includes: According to the preset data verification rules, the original data is divided into correct data, duplicate data, erroneous data, and incomplete data; The function deletes duplicate data, keeping only one copy of the duplicate data as the correct data. The correct data is retained, and a preprocessing report is generated based on the erroneous data and the incomplete data.
3. The method according to claim 1, characterized in that, The preset state parameter library is used to store visualization parameters corresponding to each state data. The visualization parameters include color parameters, brightness parameters, flash frequency parameters, and transparency parameters.
4. The method according to claim 1, characterized in that, The analysis of the network security asset data to obtain analysis data includes: Based on the preset data security range for each scenario, determine whether the network security asset data in each scenario is abnormal data; If so, the state data of the scenario is in an abnormal state; If not, obtain the status data of the scenario based on the network security asset data of the scenario.
5. The method according to claim 4, characterized in that, After determining whether the network security asset data in each scenario is abnormal, the method further includes: Scenarios with abnormal status data are identified as abnormal scenarios, and geographic information data of the abnormal scenarios are obtained from the network security asset data of the abnormal scenarios. Based on the geographic information data of the abnormal scenario, an alarm is issued in the data window associated with the abnormal scenario.
6. A three-dimensional visualization management device for network security assets, comprising: The data acquisition module is used to collect real-time data captured by the camera to obtain on-site data, and to collect real-time operating data of the equipment to obtain equipment operating data. The on-site data and the equipment operation data are aggregated as the raw data; The raw data is preprocessed to generate data on acquiring network security assets; The data analysis module is used to analyze the network security asset data and obtain analysis data. The analysis data includes status data of various scenarios in the network security assets, and the scenarios include on-site and equipment. The analysis data includes geographical location data of various scenarios in the network security assets. The status data is obtained by judging the network security asset data according to the preset data security range of each scenario. The target 3D model construction module is used to obtain the network security asset 3D model corresponding to each scenario from a preset network security asset 3D model library based on the scenario and geographical location data in the network security asset, and to combine the network security asset 3D models corresponding to each scenario based on the geographical location data of each scenario to construct the target 3D model; wherein, the network security asset 3D model library is used to store the network security asset 3D models corresponding to different scenarios; The visualization module is used to obtain visualization parameters corresponding to each scenario from a preset state parameter library based on the state data of each scenario. Based on the visualization parameters corresponding to each scenario, the module configures the visualization parameters of the network security asset 3D model of each scenario in the target 3D model, generates visualization effects, loads and generates data windows at the associated positions of each scenario in the target 3D model, and displays the analysis data and raw data corresponding to each scenario in the data windows.
7. An electronic device, comprising: A processor, and a memory communicatively connected to the processor; The memory stores computer-executed instructions; The processor executes computer execution instructions stored in the memory to implement the method as described in any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the method as described in any one of claims 1 to 5.
Citation Information
Patent Citations
Virtual machine room visualization monitoring management system based on B / S architecture and realization method
CN106647586A
Automatic scene updating method and updating equipment for three-dimensional visual platform
CN111273977A