A network security monitoring system

By combining a network security monitoring system with low interactive honeypot and high interactive honeypot, using the attack information identification model for intelligent prediction and redirection, the existing honeypot system's insufficient monitoring capabilities and high cost are solved, and efficient network attack identification and defense are achieved.

CN117811802BActive Publication Date: 2025-07-04GUANGXI POWER GRID CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311845634.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-28
Publication Date
2025-07-04
Estimated Expiration
2043-12-28

AI Technical Summary

Technical Problem

The existing low-interaction honeypot system and high-interaction honeypot system have their own shortcomings. The low-interaction honeypot system is simple in design but has limited monitoring capabilities. The high-interaction honeypot system is costly and requires a lot of manpower and time to monitor and analyze, which cannot meet the security needs of modern network systems.

Method used

Combining the advantages of low-interaction honeypots and high-interaction honeypots, the information processing module, model training module, security monitoring module and model optimization module are adopted to intelligently predict and redirect network interaction information through attack information identification models, and use low-interaction honeypots and partially activated high-interaction honeypot systems to reduce deployment and maintenance costs and improve monitoring and defense capabilities.

Benefits of technology

It realizes intelligent identification and timely warning of network attacks, optimizes the model to improve the system's defense capabilities and processing efficiency, reduces deployment costs and improves the system's monitoring and defense capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117811802B_ABST
    Figure CN117811802B_ABST
Patent Text Reader

Abstract

The present invention is applied to the field of network security and provides a network security monitoring system. The system includes: an information processing module for collecting and processing determined or suspected attack information data; a model training module for training an attack information recognition model according to the attack information data; a security monitoring module for connecting network interaction information to a corresponding network system according to the prediction result of the attack information recognition model and initiating a warning of a corresponding level; a model optimization module for analyzing the attack information data and optimizing the system model. With the aid of the attack information recognition model, the present invention identifies and diverts network interaction information, and through an integrated honeypot system combining a low-interaction honeypot and a partially activated high-interaction honeypot, collects data and analyzes behaviors of attack information. Compared with the traditional honeypot system, the present invention saves human resources and computer resources while improving the efficiency of system monitoring and processing network attacks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and in particular to a network security monitoring system. Background Art

[0002] At present, with the rapid development of Internet technology, network attacks and defenses have been upgraded. Simply relying on simple defense technologies such as firewalls can no longer meet the security needs of many current network systems. In this context, the honeypot technology has emerged. The so-called honeypot technology is an active network defense technology that lures attackers through tools, enabling security personnel to observe the attack information and analyze their intentions, and making targeted improvements to the system based on the attack information to protect the real network system.

[0003] However, most current network systems use low-interaction honeypot systems, or simple combined honeypot systems of low-interaction honeypots and high-interaction honeypots. The low-interaction honeypot system has a simple design and structure, but can only provide interaction functions by simulating services. The high-interaction honeypot system can provide real system interaction responses, but has high construction costs, maintenance costs, and system risks, and requires a large amount of human and time costs to monitor and analyze attack behaviors. Summary of the Invention

[0004] In view of this, the present invention proposes a network security monitoring system, which is a honeypot system that combines low-interaction honeypots and high-interaction honeypots, taking advantage of both to reduce deployment and maintenance costs while improving the system's monitoring and defense capabilities against network attacks.

[0005] To achieve the above object, the present invention adopts the following technical solutions:

[0006] In a first aspect, the present invention provides a network security monitoring system, which includes:

[0007] An information processing module for collecting and processing determined or suspected attack information data;

[0008] A model training module for training an attack information recognition model based on the attack information data;

[0009] A security monitoring module for connecting network interaction information to the corresponding network system according to the prediction result of the attack information recognition model and initiating a warning of the corresponding level;

[0010] A model optimization module for analyzing attack information data and optimizing the system model;

[0011] Further, the information processing module includes:

[0012] An information collection unit for collecting determined or suspected attack information data;

[0013] An information processing unit for cleaning and preprocessing the attack information data;

[0014] An information uploading unit for uploading the processed attack information data to the system attack information database;

[0015] The specific functions of the information collection unit are as follows:

[0016] Analyze the system security log data and obtain the marked attack information data from the system security log;

[0017] Regularly start the network information acquisition function to obtain determined or suspected attack information data from the network;

[0018] The specific functions of the information processing unit are as follows:

[0019] Perform data conversion on the obtained attack information data, including:

[0020] Perform numerical conversion on the IP address;

[0021] Perform numerical processing on the browser fingerprint;

[0022] Optionally, the content of the attack information data includes IP address, browser fingerprint, network interaction degree, sensitive content involvement rate, and network access volume growth rate;

[0023] The browser fingerprint is a characteristic value obtained by combining recognizable information; the network interaction degree represents the interaction degree of network interaction information in the system; the sensitive content involvement rate represents the amount of system sensitive content involved in the interaction process of network interaction information with the system; the network access volume growth rate represents the growth rate of the system network access volume within a certain period.

[0024] Furthermore, the model training module includes:

[0025] A model construction unit for constructing the attack information recognition model;

[0026] A model training unit for training the attack information recognition model;

[0027] The specific functions of the model construction unit are as follows:

[0028] Determine the input layer, hidden layer, output layer, and transfer function of the model;

[0029] The input layer factor is X i, where \(i\in[1,5]\), \(X_1\) is the first preset factor, \(X_2\) is the second preset factor, \(X_3\) is the third preset factor, \(X_4\) is the fourth preset factor, and \(X_5\) is the fifth preset factor;

[0030] The number of hidden layer neurons \(N\) h The calculation formula is:

[0031]

[0032] where \(N\) i is the number of input layer neurons, \(N\) o is the number of output layer neurons, \(\beta\) is a specific constant, \(\beta\in(1,10)\);

[0033] The output layer factor is the attack information danger value, denoted by \(T\);

[0034] The attack information danger value represents the danger level of the attack information, and its value range is \([0,1]\). The higher the value, the higher the danger level of the information;

[0035] The transfer function \(F\) takes the sigmoid function;

[0036] Optionally, the first preset factor, the second preset factor, the third preset factor, the fourth preset factor, and the fifth preset factor are the IP address, browser fingerprint, network interaction degree, sensitive content involvement rate, and network access volume growth rate respectively.

[0037] The specific function of the model training unit is:

[0038] Obtain attack information data from the system attack information database as the input layer data;

[0039] Perform normalization processing on the input layer data;

[0040] Initialize each weight value in the model and assign a random number between \((-1,1)\);

[0041] Select a set of data pairs \((X\) k , \(T\) k ) from the training data group and add the input variable to the input layer;

[0042] The formula for adding the input variable to the input layer is:

[0043]

[0044] where \(Y\) i 0 represents the output value of the \(i\)-th node in the 0-th layer, that is represents the input value of the \(i\)-th node in the \(k\)-th layer;

[0045] The signal propagates forward through the neural network;

[0046] The formula for the forward propagation is:

[0047]

[0048] where F is the transfer function, is the weighted calculation value of the j-th node in the m-th layer, represents the continuous weighting from to and represents the threshold of the j-th node in the m-th layer, m≥1;

[0049] Calculate the error value of each node in the output layer

[0050] The error value The calculation formula is:

[0051]

[0052] where, represents the target requirement value of the j-th node in the k-th layer;

[0053] Calculate the error value of each node in the previous layers

[0054] The error value The calculation formula is:

[0055]

[0056] Reverse the weights and thresholds

[0057] The weight The calculation formula is:

[0058]

[0059] The threshold The calculation formula is:

[0060]

[0061] where t is the number of iterations, η is the learning rate, η∈(0,1), and α is the momentum factor, α∈(0,1);

[0062] Continue to select a set of data pairs (X k ,T k) Transfer to the next training phase and repeat all steps in this step until the global error E of the neural network reaches the preset accuracy E0;

[0063] The calculation formula for the global error E of the neural network is:

[0064]

[0065] Furthermore, the security monitoring module includes:

[0066] A honeypot deployment unit for deploying the honeypot system, where the honeypot system includes a first preset honeypot system and a second preset honeypot system;

[0067] A redirection control unit for redirecting network interaction flows to the corresponding network systems, where the network systems include a host system and a honeypot system;

[0068] An information recording unit for recording the basic data of attack information and the behavior data generated in the honeypot system, and uploading the logs to the system server;

[0069] An attack information updating unit for updating the system attack information database with the attack information data collected by the honeypot system;

[0070] A monitoring and warning unit for initiating warnings at corresponding levels according to the comprehensive situation of network attacks on the system;

[0071] The first preset honeypot system is a low-interaction honeypot system, which uses virtualization technology to deploy several honeypot nodes in a physical server and constructs a virtual system by imitating a real system;

[0072] The second preset honeypot system is a honeypot system combining a low-interaction honeypot and a partially activatable high-interaction honeypot, which is a partially real system constructed by combining virtualization technology and partial host system replicas;

[0073] The comprehensive situation of network attacks is represented by the network attack risk level NARL within a preset time period T0. The larger the NARL, the higher the risk level;

[0074] The specific functions of the honeypot deployment unit are:

[0075] According to the manually input honeypot deployment location information, install and configure the first preset honeypot system; use traffic simulation technology to construct simulated traffic; use network dynamic configuration technology to imitate normal network behaviors;

[0076] Based on a low-interaction honeypot system, combined with a high-interaction honeypot system that can activate corresponding system parts according to network attack information, deploy a second preset honeypot system; the second preset honeypot system can classify network attacks according to the network interaction degree and attack intention of network attack information, and activate the corresponding parts of the high-interaction honeypot system for different network attack categories;

[0077] Optionally, the network attack classification includes database attacks and cross-site scripting attacks;

[0078] The part that can activate corresponding system parts according to network attack information includes database services, database access monitoring functions, data analysis functions, form support services, input monitoring functions, and XSS attack analysis functions.

[0079] The specific function of the redirection unit is:

[0080] Use an attack information recognition model to predict the attack information risk value of network interaction information;

[0081] When the attack information risk value of network interaction information is higher than or equal to 0 and lower than the first preset threshold, redirect the network interaction information flow to the host system;

[0082] When the attack information risk value of network interaction information is higher than or equal to the first preset threshold and lower than the second preset threshold, redirect the network interaction information flow to the first preset honeypot system;

[0083] When the attack information risk value of network interaction information is higher than or equal to the second preset threshold and lower than the third preset threshold, redirect the network interaction information flow to the second preset honeypot system;

[0084] When the attack information risk value of network interaction information is higher than or equal to the third preset threshold and lower than or equal to 1, reject the connection of the network interaction information;

[0085] The specific function of the monitoring and warning unit is:

[0086] Every preset time period T0, calculate the network attack risk level NARL within this preset time period T0;

[0087] The calculation formula of the network attack risk level NARL is:

[0088]

[0089] Among them, the N i represents the number of network attacks at the i-th attack level, and w i represents the corresponding N iThe weights, w1, w2, and w3 are the first preset weight, the second preset weight, and the third preset weight respectively, and w1 < w2 < w3, n = 3;

[0090] The number of network attacks N i is:

[0091]

[0092] The attack level Attack i is:

[0093]

[0094] where Attack i represents the i-th type of attack level, NAI i represents the network attack information of Attack i num(NAI i ) represents the number of NAI i T(NAI i ) represents the attack information danger value of NAI i i ∈ [0, 4];

[0095] When the network attack danger level NARL is greater than or equal to 0 but less than the left endpoint of the first preset interval, no early warning is initiated;

[0096] When the network attack danger level NARL is within the first preset interval, a low-level early warning is initiated;

[0097] When the network attack danger level NARL is within the second preset interval, a medium-level early warning is initiated;

[0098] When the network attack danger level NARL is within the third preset interval, a high-level early warning is initiated;

[0099] Furthermore, the model optimization module includes:

[0100] A model optimization unit for regularly using the new attack information data in the system attack information database as a training set to train the model and update the model parameters;

[0101] The specific function of the model optimization unit is:

[0102] After an interval of a preset time period T1, using the method of random stratified sampling, select n pieces of attack information data updated in the system attack information database during the preset time period T1 and m pieces of attack information data during a preset time period T2 before the preset time period T1, randomly mix them as a new data set for the attack information recognition model, conduct model training, and update the model parameters.

[0103] In a second aspect, the present invention provides an electronic device, which is characterized by comprising: a processor, a memory, and a computer program stored on the memory and capable of running on the processor. When the computer program is executed by the processor, it implements each process of the above-mentioned embodiment of a network security monitoring system and can achieve the same technical effects.

[0104] In a third aspect, the present invention provides a computer-readable storage medium, which is characterized in that a computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, it implements each process of the above-mentioned embodiment of a network security monitoring system and can achieve the same technical effects.

[0105] The beneficial effects of the present invention are as follows:

[0106] The attack information recognition model realizes the intelligent prediction of the risk value of network attack information in network interaction information, realizes the timely identification and early warning of network attack information; and optimizes the current model according to the updated network attack information; the second preset honeypot system based on low-interaction honeypots and partial high-interaction honeypots improves the system defense ability and system processing efficiency while reducing the deployment cost. BRIEF DESCRIPTION OF THE DRAWINGS

[0107] Figure 1 It is a functional module diagram of a network security monitoring system;

[0108] Figure 2 It is a flowchart of a redirection unit of a network security monitoring system. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0109] The present invention will be further described below with reference to the drawings and embodiments.

[0110] Embodiment

[0111] The present invention provides a network security monitoring system. In this embodiment, it can be understood that the system can be applied to a server, can also be applied to a terminal, and can also be applied to include a terminal, a server and a system, and is realized through the interaction between the terminal and the server. The terminal and the server can be directly or indirectly connected through wired or wireless communication methods. The present application does not make any restrictions here. In addition, the types of terminals or servers to which the above methods are applied are not restricted here either.

[0112] As Figure 1 shown, a network security monitoring system provided by the present invention includes an information processing module, a model training module, a security monitoring module, and a model optimization module;

[0113] The information processing module includes an information collection unit, an information processing unit, and an information upload unit, and is used to collect and process definite or suspected attack information data;

[0114] The collection of the attack information data includes analyzing system security log data to obtain the marked attack information data from the system security logs; and using web crawler technology to obtain definite or suspected attack information data from the network once a month;

[0115] The content of the attack information data includes IP address, browser fingerprint, network interaction degree, sensitive content involvement rate, and network access volume growth rate;

[0116] The browser fingerprint is a characteristic value obtained by combining recognizable information such as device model and specifications, language and keyboard layout, location, time zone, installed hardware, software version, etc.; the network interaction degree represents the interaction degree of network interaction information in the system; the sensitive content involvement rate represents the amount of system sensitive content involved in the interaction process of network interaction information with the system; the network access volume growth rate represents the growth rate of the system network access volume within a certain period of time;

[0117] The processing of the attack information data includes cleaning and preprocessing the attack information data;

[0118] The specific functions of the information processing unit are:

[0119] Perform data conversion on the obtained attack information data, including:

[0120] Perform numerical conversion on the IP address;

[0121] Perform numerical processing on the browser fingerprint;

[0122] Let (a.b.c.d) be a section of IP address, and one formula for the numerical conversion is:

[0123] IP' = 256^3×a + 256^2×b + 256^1×c + 256^0×d

[0124] Taking the IP address (192.168.70.1) as an example, the value after numerical conversion is:

[0125] IP' = 256^3×192 + 256^2×168 + 256^1×70 + 256^0×1 = 3232253441

[0126] After the attack information data is processed, use the information upload unit to upload it to the attack information database of the system;

[0127] The model training module includes a model construction unit and a model training unit, and is used to train an attack information recognition model according to the attack information data;

[0128] The model construction unit is used to construct the attack information recognition model, including:

[0129] Determine the input layer, hidden layer, output layer and transfer function of the model;

[0130] The input layer factor is X i , i ∈ [1, 5], where X1 is the IP address, X2 is the browser fingerprint, X3 is the network interaction degree, X4 is the sensitive content involvement rate, and X5 is the network access volume growth rate;

[0131] The number of neurons in the hidden layer is N h The calculation formula is:

[0132]

[0133] where N i is the number of neurons in the input layer, N o is the number of neurons in the output layer, β is a specific constant, and β ∈ (1, 10);

[0134] The output layer is the attack information danger value, represented by T;

[0135] The attack information danger value represents the danger level of the attack information, and the value range is [0, 1]. The higher the value, the higher the danger level of the information;

[0136] The transfer function F takes the sigmoid function;

[0137] The model training unit is used to train the attack information recognition model, including:

[0138] Obtain attack information data from the system attack information database as the input layer data;

[0139] Perform standardization processing on the input layer data;

[0140] Initialize each weight value in the model and assign a random number between (-1, 1);

[0141] Select a set of data pairs (X k , T k ) from the training data group and add the input variable to the input layer;

[0142] The formula for adding the input variable to the input layer is:

[0143]

[0144] Among them, Y i 0 represents the output value of the i-th node in the 0-th layer, that is represents the input value of the i-th node in the k-th layer;

[0145] The signal propagates forward through the neural network;

[0146] The formula for the forward propagation is:

[0147]

[0148] Among them, F is the transfer function, is the weighted calculation value of the j-th node in the m-th layer, represents from to the continuous weighting in between, represents the threshold of the j-th node in the m-th layer, m≥1;

[0149] Calculate the error value of each node in the output layer

[0150] The error value The calculation formula is:

[0151]

[0152] Among them, represents the target requirement value of the j-th node in the k-th layer;

[0153] Calculate the error value of each node in the previous layers

[0154] The error value The calculation formula is:

[0155]

[0156] Revise the weights and thresholds

[0157] The weight The calculation formula is:

[0158]

[0159] The threshold The calculation formula is:

[0160]

[0161] Among them, t is the number of iterations, η is the learning rate, η∈(0,1), and α is the momentum factor, α∈(0,1);

[0162] Continue to select a set of data pairs (X k , T k ) from the training data set, transfer to the next training stage, and repeat all steps in this step until the global error E of the neural network reaches the preset accuracy E0;

[0163] The calculation formula for the global error E of the neural network is:

[0164]

[0165] The security monitoring module includes a honeypot deployment unit, a redirection control unit, an information recording unit, an attack information update unit, and a monitoring and warning unit, which is used to identify the prediction results of the attack information recognition model, connect network interaction information to the corresponding network system, and initiate warnings at corresponding levels;

[0166] The honeypot deployment unit is used to deploy the first preset honeypot system and the second preset honeypot system, including:

[0167] Install and configure the first preset honeypot system according to the manually input honeypot deployment location information; use traffic simulation technology to construct simulated traffic; use network dynamic configuration technology to imitate normal network behavior;

[0168] Based on the low-interaction honeypot system, combine the high-interaction honeypot system that can activate the corresponding system part according to network attack information to deploy the second preset honeypot system; the second preset honeypot system can classify network attacks according to the network interaction degree and attack intention of network attack information, and activate the corresponding part of the high-interaction honeypot system for different network attack categories.

[0169] The first preset honeypot system is a low-interaction honeypot system, which is a virtual system constructed by using virtualization technology to deploy several honeypot nodes in a physical server and imitating a real system;

[0170] The second preset honeypot system is a honeypot system combining a low-interaction honeypot and a partially activatable high-interaction honeypot, which is a real system constructed by combining virtualization technology and partial host system replicas;

[0171] The low-interaction honeypot generally only simulates the operating system and network services, with a low interaction degree, is relatively easy to be recognized, but has a simple deployment and low deployment cost, and is suitable for capturing attacks launched by automated attacks or network worms, etc.;

[0172] The high-interaction honeypot provides a complete and real operating system and network services, without any simulation, and is no different from the real environment, but has a higher deployment cost;

[0173] The network attack classification includes database attacks or cross-site scripting attacks;

[0174] If it is a database attack, when the attack occurs, the database-related part of the high-interaction honeypot system is started; the database attack can be an attack using SQL injection, SQL service vulnerabilities, or abuse of permissions;

[0175] The database-related part of the high-interaction honeypot system includes database services, database access monitoring functions, and data analysis functions;

[0176] The database service function of the high-interaction honeypot system is the same as the database service of the real system database to implement various functions of the database; the database access monitoring function of the high-interaction honeypot system is used to monitor network attack data, including login monitoring, access monitoring, and permission monitoring of the network attack data, etc.; the data analysis function of the high-interaction honeypot system is used to analyze the monitored data, including account permissions, database commands, and data access, etc.

[0177] Such as Figure 2 As shown, the redirection control unit is used to redirect network interaction flows to the corresponding network systems, where the network systems include a host system, a first preset honeypot system, and a second preset honeypot system, including:

[0178] Using an attack information recognition model, predict the attack information risk value of network interaction information;

[0179] When the attack information risk value of network interaction information is higher than or equal to 0 and lower than 0.6, redirect the network interaction information flow to the host system;

[0180] When the attack information risk value of network interaction information is higher than or equal to 0.6 and lower than 0.75, redirect the network interaction information flow to the first preset honeypot system;

[0181] When the attack information risk value of network interaction information is higher than or equal to 0.75 and lower than 0.9, redirect the network interaction information flow to the second preset honeypot system;

[0182] When the attack information risk value of network interaction information is higher than or equal to 0.9 and lower than or equal to 1, reject the connection of the network interaction information;

[0183] The input factors of the model are IP address, browser fingerprint, network interaction degree, sensitive content involvement rate, and network access volume growth rate respectively, and the prediction result is the attack information risk value;

[0184] Taking the following three groups of input data as examples, [3232256568, 16352745, 7, 0.8216, 0.4681], [3232253441, 12736652, 2, 0.2133, 0.7661], [3766534221, 14726292, 6, 0.4876, 0.3428], inputting into the attack information recognition model, the predicted attack information danger values are 0.8628, 0.2112, and 0.6237 respectively;

[0185] According to the prediction results, the first network interaction information will be redirected to the second preset honeypot system, the second network interaction information will be redirected to the host system, and the third network interaction information will be redirected to the first preset honeypot system;

[0186] The information recording unit is used to record the basic data of the attack information and the behavior data generated in the honeypot system, and upload the log to the system SIEM server;

[0187] The SIEM server is a security information and event management server;

[0188] The attack information update unit is used to update the system attack information database with the attack information data collected by the honeypot system;

[0189] The monitoring and early warning unit is used to initiate early warnings of corresponding levels according to the comprehensive situation of network attacks suffered by the system, including:

[0190] Every 10 minutes, calculate the network attack risk level NARL within these 10 minutes;

[0191] The comprehensive situation of network attacks is represented by the network attack risk level NARL within 10 minutes. The larger the NARL, the higher the risk level;

[0192] The calculation formula for the network attack risk level NARL is:

[0193]

[0194] Among them, the N i represents the number of network attacks at the i-th attack level, and w i represents the weight corresponding to N i . w1, w2, and w3 are 0.05, 0.35, and 0.6 respectively, and n is 3;

[0195] The number of network attacks N i is:

[0196]

[0197] The attack level Attack i is as follows:

[0198]

[0199] where Attack i represents the i-th type of attack level, NAI i represents the network attack information of Attack i , num(NAI i ) represents the quantity of NAI i , T(NAI i ) represents the attack information danger value of NAI i , and i ∈ [0, 4];

[0200] When the network attack danger level NARL ∈ [0, 10), no early warning is initiated;

[0201] When the network attack danger level NARL ∈ [10, 15), a low-level early warning is initiated;

[0202] When the network attack danger level NARL ∈ [15, 20), a medium-level early warning is initiated;

[0203] When the network attack danger level NARL ∈ [20, +∞), a high-level early warning is initiated;

[0204] Taking the network access information of the system within 10 minutes as an example, it is judged whether the system needs early warning;

[0205] Obtain the network interaction information within 10 minutes from the system and input it into the attack information recognition model;

[0206] The number of network attacks of 4 levels N0, N1, N2, and N3 are 353, 54, 17, and 2 respectively;

[0207] The currently calculated network attack danger level NARL is:

[0208] NARL = 0.05×54 + 0.35×17 + 0.6×2 = 9.85

[0209] The current network attack danger level NARL is within [0, 10), and no early warning is required.

[0210] The model optimization module includes a model optimization unit for analyzing attack information data and optimizing the system model;

[0211] The model optimization unit is used to regularly use the new attack information data in the system attack information database as a training set to train the model and update the model parameters, including:

[0212] After an interval of one month, using the method of random stratified sampling, 80% of the attack information data updated in the system attack information database last month and 80% of the attack information data in the system attack information database in the 11 months before the current month are selected, randomly mixed and used as the new data set of the attack information recognition model for model training and updating of model parameters.

[0213] The above-described embodiments only represent the preferred embodiments of the present invention, and the description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications, improvements and substitutions can be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention should be subject to the appended claims.

Claims

1. A network security monitoring system, characterized in that, including: An information processing module, configured to collect and process determined or suspected attack information data; A model training module, configured to train an attack information recognition model according to the attack information data; A security monitoring module, configured to connect network interaction information to a corresponding network system according to the prediction result of the attack information recognition model and initiate a warning of a corresponding level; A model optimization module, configured to analyze attack information data and optimize the system model; Further, the information processing module includes: An information collection unit, configured to collect determined or suspected attack information data; An information processing unit, configured to perform cleaning and preprocessing operations on the attack information data; An information uploading unit, configured to upload the processed attack information data to the system attack information database; The specific function of the information collection unit is: Analyze system security log data and obtain marked attack information data from the system security log; Regularly initiate the network information acquisition function to obtain determined or suspected attack information data from the network; The specific function of the information processing unit is: Perform data conversion on the obtained attack information data, including: Perform numerical conversion on the IP address; Perform numerical processing on the browser fingerprint; Further, the model training module includes: A model construction unit, configured to construct the attack information recognition model; A model training unit, configured to train the attack information recognition model; The specific function of the model construction unit is: Determine the input layer, hidden layer, output layer and transfer function of the model; The input layer factor is X i , i ∈ [1, 5], where X1 is the first preset factor, X2 is the second preset factor, X3 is the third preset factor, X4 is the fourth preset factor, and X5 is the fifth preset factor; The number of hidden layer neurons N h The calculation formula is as follows: Among them, N i is the number of neurons in the input layer, and N o is the number of neurons in the output layer. β is a specific constant, and β ∈ (1, 10); The output layer factor is the attack information danger value, denoted by T; The attack information danger value represents the danger level of the attack information, and the value range is [0,1]. The higher the value, the higher the danger level of this piece of information; The transfer function F takes the sigmoid function; The specific function of the model training unit is: Obtain attack information data from the system attack information database as the input layer data; Perform standardization processing on the input layer data; Initialize each weight value in the model and assign a random number between (-1, 1); Select a set of data pairs (X k , T k ) from the training data set, and add the input variables to the input layer; The formula for adding the input variable to the input layer is: Among them, Y i 0 represents the output value of the i-th node in the 0-th layer, that is represents the input value of the i-th node in the k-th layer; The signal propagates forward through the neural network; The formula for the forward propagation is: where F is the transfer function, is the weighted calculation value of the j-th node in the m-th layer, represents from to continuous weighting therebetween, represents the threshold of the j-th node in the m-th layer, m ≥ 1; Calculate the error value of each node in the output layer The error value is calculated by the following formula: Among them, represents the target requirement value of the j-th node in the k-th layer; Calculate the error value of each node in the previous layers The error value is calculated by the following formula: Reverse layer-by-layer weight correction and threshold The weight value has the following calculation formula: The threshold value has the following calculation formula: where t is the number of iterations, η is the learning rate, η ∈ (0,1), and α is the momentum factor, α ∈ (0,1); Continue to select a set of data pairs (X k , T k ) from the training data set, transfer to the next training phase, and repeat all steps in this step until the global error E of the neural network reaches the preset accuracy E0; The calculation formula for the global error E of the neural network is: Further, the security monitoring module includes: A honeypot deployment unit, configured to deploy a honeypot system, where the honeypot system includes a first preset honeypot system and a second preset honeypot system; A redirection control unit, configured to redirect the network interaction flow to a corresponding network system, where the network system includes a host system and a honeypot system; An information recording unit, configured to record the basic data of the attack information and the behavior data generated in the honeypot system and upload the log to the system server; An attack information update unit, configured to update the system attack information database with the attack information data collected by the honeypot system; A monitoring and warning unit, configured to initiate a warning of a corresponding level according to the comprehensive situation of network attacks received by the system; The first preset honeypot system is a low-interaction honeypot system, which uses virtualization technology to deploy several honeypot nodes in a physical server and constructs a virtual system by imitating a real system; The second preset honeypot system is a honeypot system that combines a low-interaction honeypot and a partially activatable high-interaction honeypot, and is a partially real system constructed by combining virtualization technology and partial host system replicas; The comprehensive network attack situation is represented by the network attack risk level NARL within a preset time period T0. The larger the NARL, the higher the risk level; The specific functions of the honeypot deployment unit are as follows: According to the manually input honeypot deployment location information, install and configure the first preset honeypot system; use traffic simulation technology to construct simulated traffic; use network dynamic configuration technology to imitate normal network behavior; Based on the low-interaction honeypot system, combine a high-interaction honeypot system that can activate corresponding system parts according to network attack information to deploy the second preset honeypot system; the second preset honeypot system can classify network attacks according to the network interaction degree and attack intention of network attack information, and activate the corresponding parts of the high-interaction honeypot system for different network attack categories; The specific functions of the redirection unit are as follows: Use the attack information recognition model to predict the attack information risk value of network interaction information; When the attack information risk value of network interaction information is higher than or equal to 0 and lower than the first preset threshold, redirect the network interaction information flow to the host system; When the attack information risk value of network interaction information is higher than or equal to the first preset threshold and lower than the second preset threshold, redirect the network interaction information flow to the first preset honeypot system; When the attack information risk value of network interaction information is higher than or equal to the second preset threshold and lower than the third preset threshold, redirect the network interaction information flow to the second preset honeypot system; When the attack information risk value of network interaction information is higher than or equal to the third preset threshold and lower than or equal to 1, reject the connection of this network interaction information; The specific functions of the monitoring and warning unit are as follows: Every preset time period T0, calculate the network attack risk level NARL within this preset time period T0; The calculation formula of the network attack risk level NARL is: Among them, the N i represents the number of cyberattacks at the i-th attack level, and w i represents the weight corresponding to N i The weights w1, w2, and w3 are the first preset weight, the second preset weight, and the third preset weight respectively, and w1 < w2 < w3, and n = 3; The number N of the network attacks i is as follows: The attack level Attack i is as follows: Among them, Attack i represents the i-th type of attack level, and NAI i represents the network attack information of Attack i , and num(NAI i ) represents the quantity of NAI i , and T(NAI i ) represents the attack information danger value of NAI i , where i ∈ [0, 4]; When the network attack risk level NARL is greater than or equal to 0 but less than the left endpoint of the first preset interval, no warning is initiated; When the network attack risk level NARL is within the first preset interval, initiate a low-level warning; When the network attack risk level NARL is within the second preset interval, initiate a medium-level warning; When the network attack risk level NARL is within the third preset interval, initiate a high-level warning; Furthermore, the model optimization module includes: The model optimization unit is used to regularly use the new attack information data in the system attack information database as a training set to train the model and update the model parameters; The specific functions of the model optimization unit are: After an interval of a preset time period T1, using the method of random stratified sampling, n pieces of updated attack information data in the system attack information database within the preset time period T1 and m pieces of attack information data within a preset time period T2 before the preset time period T1 are selected, randomly mixed and used as a new data set for the attack information recognition model for model training to update the model parameters.

2. The network security monitoring system according to claim 1, wherein The content of the attack information data includes IP address, browser fingerprint, network interaction degree, sensitive content involvement rate, and network access volume growth rate; the browser fingerprint is a characteristic value obtained by combining recognizable information. The network interaction degree represents the interaction degree of network interaction information in the system; the sensitive content involvement rate represents the amount of system sensitive content involved in the interaction process of network interaction information with the system; the network access volume growth rate represents the growth rate of the system network access volume within a certain time period.

3. A network security monitoring system according to claim 1, characterized in that, The first preset factor, the second preset factor, the third preset factor, the fourth preset factor, and the fifth preset factor are the IP address, browser fingerprint, network interaction degree, sensitive content involvement rate, and network access volume growth rate respectively.

4. A network security monitoring system according to claim 1, wherein The network attack classification includes database attack and cross-site scripting attack. The system parts that can be activated for network attack information include database service, database access monitoring function, data analysis function, form support service, input monitoring function, and XSS attack analysis function.

5. An electronic device, characterized in that, Include: A processor, a memory, and a computer program stored on the memory and capable of running on the processor. When the computer program is executed by the processor, it implements the steps of a network security monitoring system as described in any one of claims 1-4.

6. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium. When the computer program is executed by the processor, it implements the steps of a network security monitoring system as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Integrated industrial control honeypot identification system and method based on deep learning

    CN111126440A

  • Network asset risk control method and device

    CN111539644A