System for Detecting Cybersecurity Threats Using Static and Runtime Data
By collecting and processing static and operating data of the network system, generating real-time network characterization data, and performing network security threat detection and intelligent control, the problem of difficulty in timely discovering network security threats in the existing technology is solved, and the effectiveness of network security control is improved.
Patent Information
- Application Number
- CN202410322924.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-21
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2044-03-21
AI Technical Summary
The existing technology is difficult to detect threats from network security in a timely manner, resulting in poor network security control effectiveness.
By collecting static data and operation data of the network system in static and operating states, combining the comprehensive processing of data retrieval, grouping, sorting, feature extraction and calculation, real-time network characterization data is generated, and network security threat detection and intelligent control are carried out.
It realizes timely discovery and handling of network security threats, and improves the effectiveness of network security control.
Smart Images

Figure CN118233173B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and specifically to a system for detecting network security threats using static and runtime data. Background Art
[0002] Network security means that the hardware, software, and data in a network system are protected and not damaged, altered, or leaked due to accidental or malicious reasons, and the system runs continuously, reliably, and normally, and network services are not interrupted.
[0003] A computer communication network interconnects several computers with independent functions through communication devices and transmission media, and under the support of communication software, realizes the information transmission and exchange between computers. A computer network refers to a system that connects several relatively geographically dispersed independent computer systems, terminal devices, and data devices for the purpose of sharing resources and exchanges data under the control of a protocol; the fundamental purpose of a computer network is resource sharing, and a communication network is the way to achieve network resource sharing. Therefore, a computer network is secure, and correspondingly, a computer communication network must also be secure and should be able to realize information exchange and resource sharing for network users.
[0004] Chinese Patent No. CN116961987A discloses a network security index evaluation method, belonging to the field of network security technology. The method includes obtaining network security indicators and constructing a network security indicator dataset; constructing and training a random forest model; inputting the network security indicator dataset into the trained random forest model to obtain the objective weights of each network security indicator; using the objective weights of each network security indicator to obtain the network security index evaluation result; using the random forest model to obtain the objective weights of the network security index and then evaluating the network security index, making the network security index evaluation result more objective; however, the above patent has the following defects:
[0005] The prior art cannot timely detect the threats existing in network security, resulting in poor network security control effect. Summary of the Invention
[0006] The purpose of the present invention is to provide a system for detecting network security threats using static and runtime data, which can timely detect the threats existing in network security, improve the network security control effect, and solve the problems raised in the above background art.
[0007] To achieve the above purpose, the present invention provides the following technical solutions:
[0008] A system for detecting network security threats using static and runtime data, comprising:
[0009] A data acquisition module, which is used to acquire static data and operation data of a network system in static and operation states, and determine real-time network data based on the acquired static data and operation data;
[0010] A data processing module, which is used to perform comprehensive processing on the acquired real-time network data based on retrieval, grouping, sorting, feature extraction and calculation, and determine real-time network characterization data;
[0011] A threat detection module, which is used to perform network security threat detection on the real-time network characterization data and determine network security threat detection results;
[0012] An intelligent control module, which is used to mine and analyze the network security threat detection results, determine network security intelligent control methods, and intelligently control network security based on the network security intelligent control methods.
[0013] Preferably, the data acquisition module includes:
[0014] A static acquisition unit, which is used to acquire static data of the network system in static state;
[0015] A dynamic acquisition unit, which is used to acquire operation data of the network system in operation state;
[0016] Determine real-time network data based on the acquired static data and operation data;
[0017] Wherein, data acquisition ports are arranged on both the static acquisition unit and the dynamic acquisition unit, and both the static acquisition unit and the dynamic acquisition unit are connected to the network system through the data acquisition ports.
[0018] Preferably, the dynamic acquisition unit includes:
[0019] A trial retrieval module, which is used to retrieve network traffic feature data from the dynamic data in real time; wherein, the network traffic feature data includes traffic rate, traffic direction and data packet quantity information; and the traffic direction refers to the downstream traffic direction from the server to the client in the network to generate network traffic;
[0020] A reference coefficient acquisition module, which is used to obtain a traffic reference coefficient by using the traffic rate and the traffic direction, and the traffic reference coefficient is obtained through the following formula:
[0021]
[0022] Wherein, f represents the traffic reference coefficient; f0 represents a preset initial coefficient; v d represents the traffic rate of the current network; v e represents the traffic rate saturation value of the preset network; m represents the number of servers in the network; N irepresents the cumulative number of changes in the address of the client corresponding to the i-th server at the current moment compared to the address of the initial client; N e represents the number of clients initially corresponding to the server; n represents the number of unit time periods experienced by the network operation;
[0023] A comparison module for comparing the traffic reference coefficient with a preset coefficient threshold to obtain a comparison result;
[0024] A data packet quantity information retrieval module for retrieving data packet quantity information when the traffic reference coefficient exceeds a preset parameter threshold;
[0025] A first traffic evaluation parameter acquisition module for obtaining a first traffic evaluation parameter by using the traffic reference coefficient and the data packet quantity information; wherein, the first traffic evaluation parameter is obtained through the following formula:
[0026]
[0027] wherein, R 01 represents the first traffic evaluation parameter; h i represents the total quantity of data packets generated by the i-th server at the moment corresponding to when the traffic reference coefficient exceeds the preset parameter threshold; h p represents the average quantity of data packets at a historical moment; C j represents the data volume of the j-th data packet; C0 represents the reference data volume of the preset data packet;
[0028] A second traffic evaluation parameter acquisition module for obtaining a second traffic evaluation parameter through the data packet quantity information when the traffic reference coefficient does not exceed the preset parameter threshold;
[0029] A traffic anomaly alarm module for performing a traffic anomaly alarm when the first traffic evaluation parameter is lower than a preset first evaluation parameter threshold or the second traffic evaluation parameter is lower than a preset second evaluation parameter threshold.
[0030] Preferably, the second traffic evaluation parameter acquisition module includes:
[0031] A difference acquisition module for obtaining the difference between the traffic reference coefficient and the preset parameter threshold when the traffic reference coefficient does not exceed the preset parameter threshold;
[0032] An information retrieval module for retrieving the traffic rate and traffic direction in the historical network traffic feature data;
[0033] A compensation coefficient acquisition module, configured to obtain an evaluation parameter compensation coefficient by using the traffic rate and traffic direction in the historical network traffic feature data; wherein, the evaluation parameter compensation coefficient is obtained through the following formula:
[0034]
[0035] wherein, f b represents the evaluation parameter compensation coefficient;
[0036] A data packet quantity information retrieval module, configured to retrieve the data packet quantity information;
[0037] A second traffic evaluation parameter calculation and acquisition module, configured to obtain the second traffic evaluation parameter by combining the difference between the traffic reference coefficient and the preset parameter threshold, the evaluation parameter compensation coefficient, and the data packet quantity information, wherein, the second traffic evaluation parameter is obtained through the following formula:
[0038]
[0039] wherein, R 02 represents the second traffic evaluation parameter; g i represents the total quantity of data packets generated by the i-th server at the corresponding moment when the traffic reference coefficient does not exceed the preset parameter threshold.
[0040] Preferably, the data processing module includes:
[0041] A data retrieval unit, configured to retrieve the collected real-time network data;
[0042] Obtain the collected real-time network data, and based on the sequential retrieval method, retrieve the collected real-time network data one by one, filter out the duplicate and missing relevant real-time network data in the real-time network data, and determine the relevant real-time network data valuable for network security threat detection in the real-time network data;
[0043] A data grouping unit, configured to group the retrieved relevant real-time network data;
[0044] Obtain the relevant real-time network data valuable for network security threat detection in the real-time network data, and based on the mutual exclusion principle, group the relevant real-time network data valuable for network security threat detection in the real-time network data to determine different real-time network data groups;
[0045] A data sorting unit, configured to sort the grouped real-time network data groups;
[0046] Obtain different groups of real-time network data, and based on the internal sorting method, sort the real-time network data placed in different groups of real-time network data one by one to determine the group of real-time network data with an arrangement order.
[0047] Preferably, the data processing module further includes:
[0048] A feature extraction unit, configured to extract features from the group of real-time network data with an arrangement order;
[0049] Obtain the group of real-time network data with an arrangement order, extract features from the real-time network data placed in the group of real-time network data with an arrangement order, and determine the real-time network feature data;
[0050] A data calculation unit, configured to calculate the real-time network feature data;
[0051] Obtain the real-time network feature data, and calculate the real-time network feature data to determine the real-time network representation data.
[0052] Preferably, the threat detection module includes:
[0053] A data storage unit, configured to store the pre-set real-time network standard data for threat detection of network security;
[0054] Based on the network security threat detection requirements, pre-set the real-time network standard data of the network system in the static and running states, provide a reference standard for network security threat detection, and facilitate subsequent threat detection of network security;
[0055] A data indexing unit, configured to index the pre-set real-time network standard data for threat detection of network security;
[0056] Based on the network security threat detection requirements, index the pre-set real-time network standard data for threat detection of network security from the data storage unit;
[0057] A data retrieval unit, configured to retrieve the pre-set real-time network standard data for threat detection of network security;
[0058] Obtain the indexed pre-set real-time network standard data for threat detection of network security, and retrieve the indexed pre-set real-time network standard data for threat detection of network security, facilitating subsequent threat detection of network security.
[0059] Preferably, the threat detection module further includes:
[0060] A threat detection unit, configured to perform network security threat detection on the real-time network representation data;
[0061] Obtain real-time network representation data and real-time network standard data, and based on the real-time network standard data, perform network security threat detection on the real-time network representation data;
[0062] For the situation where the real-time network representation data is within the range of the real-time network standard data, the network security threat detection result is that the network system is normal and there is no network security threat;
[0063] For the situation where the real-time network representation data is not within the range of the real-time network standard data, the network security threat detection result is that the network system is abnormal and there is a network security threat.
[0064] Preferably, the intelligent control module includes:
[0065] A mining and analysis unit for mining and analyzing the network security threat detection result;
[0066] Obtain the network security threat detection result, perform in-depth mining and correlation analysis on the network security threat detection result, and determine the reasons for the existence of the network security threat detection result;
[0067] A control method formulation unit for formulating a network security intelligent control method;
[0068] Obtain the reasons for the existence of the network security threat detection result, and based on the reasons for the existence of the network security threat detection result, determine the network security intelligent control method;
[0069] An intelligent control unit for intelligently controlling network security;
[0070] Obtain the network security intelligent control method, and based on the network security intelligent control method, perform intelligent control on network security.
[0071] Preferably, for intelligent control of network security, the following operations are performed:
[0072] For the situation where the network system is normal and there is no network security threat, continuously perform real-time threat detection on the network security of the network system and intelligently control the network security of the network system;
[0073] For the situation where the network system is abnormal and there is a network security threat, give a timely warning to the network system, and send a real-time warning message to the network security maintenance personnel to guide the network security maintenance personnel to perform remote intelligent control on the network system in a timely manner.
[0074] Compared with the prior art, the beneficial effects of the present invention are:
[0075] The present invention collects static data and running data of a network system in static and running states, determines real-time network data based on the collected static data and running data, performs comprehensive processing on the collected real-time network data based on retrieval, grouping, sorting, feature extraction, and calculation to determine real-time network characterization data, performs network security threat detection on the real-time network characterization data to determine a network security threat detection result, performs mining analysis on the network security threat detection result to determine a network security intelligent control method, and intelligently controls network security based on the network security intelligent control method, which can timely discover threats existing in network security and improve the network security control effect. BRIEF DESCRIPTION OF THE DRAWINGS
[0076] Figure 1 It is a principle module diagram of the system for network security threat detection using static and running data of the present invention;
[0077] Figure 2 It is an algorithm flowchart of the system for network security threat detection using static and running data of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0078] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0079] To solve the problem that the prior art cannot timely discover threats existing in network security, resulting in poor network security control effect, please refer to Figure 1 - Figure 2 , the following technical solutions are provided in this embodiment:
[0080] A system for network security threat detection using static and running data includes a data collection module, a data processing module, a threat detection module, and an intelligent control module, wherein the data collection module, the data processing module, the threat detection module, and the intelligent control module communicate with each other.
[0081] It should be noted that the data collection module can collect static data and running data of the network system in static and running states, and determine real-time network data based on the collected static data and running data;
[0082] In this embodiment, as a preferred technical solution of the present invention, the data collection module includes:
[0083] A static collection unit for collecting static data of the network system in a static state;
[0084] A dynamic acquisition unit for acquiring the operation data of a network system in an operating state;
[0085] Based on the acquired static data and operation data, determine the real-time network data;
[0086] It should be noted that data acquisition ports are provided on both the static acquisition unit and the dynamic acquisition unit, and both the static acquisition unit and the dynamic acquisition unit are connected to the network system through the data acquisition ports.
[0087] Specifically, after the static acquisition unit and the dynamic acquisition unit are connected to the network system through the data acquisition ports, a network connection between the static acquisition unit and the dynamic acquisition unit and the network system is established, and the static data of the network system in a static state and the operation data of the network system in an operating state can be acquired through the static acquisition unit and the dynamic acquisition unit.
[0088] It should be noted that the data processing module can perform comprehensive processing on the acquired real-time network data based on retrieval, grouping, sorting, feature extraction, and calculation to determine the real-time network characterization data;
[0089] Specifically, the dynamic acquisition unit includes:
[0090] A data retrieval module for retrieving network traffic feature data from the dynamic data in real time; wherein, the network traffic feature data includes traffic rate, traffic direction, and data packet quantity information; and the traffic direction refers to the downstream traffic direction from the server to the client within the network to generate network traffic;
[0091] A reference coefficient acquisition module for obtaining a traffic reference coefficient by using the traffic rate and the traffic direction, wherein the traffic reference coefficient is obtained through the following formula:
[0092]
[0093] Wherein, f represents the traffic reference coefficient; f0 represents a preset initial coefficient; v d represents the traffic rate of the current network; v e represents the traffic rate saturation value of the preset network; m represents the number of servers in the network; N i represents the cumulative number of changes in the address of the client corresponding to the i-th server at the current moment compared to the address of the initial client; N e represents the number of clients initially corresponding to the server; n represents the number of unit time periods experienced by the network operation;
[0094] A comparison module for comparing the traffic reference coefficient with a preset coefficient threshold to obtain a comparison result;
[0095] The data packet quantity information retrieval module is used to retrieve the data packet quantity information when the traffic reference coefficient exceeds a preset parameter threshold;
[0096] The first traffic evaluation parameter acquisition module is used to acquire a first traffic evaluation parameter by using the traffic reference coefficient and the data packet quantity information; wherein, the first traffic evaluation parameter is obtained through the following formula:
[0097]
[0098] wherein, R 01 represents the first traffic evaluation parameter; h i represents the total quantity of data packets generated by the i-th server at the corresponding moment when the traffic reference coefficient exceeds the preset parameter threshold; h p represents the average quantity of data packets at historical moments; C j represents the data volume of the j-th data packet; C0 represents the reference data volume of the preset data packet;
[0099] The second traffic evaluation parameter acquisition module is used to acquire a second traffic evaluation parameter through the data packet quantity information when the traffic reference coefficient does not exceed the preset parameter threshold;
[0100] The traffic anomaly alarm module is used to perform a traffic anomaly alarm when the first traffic evaluation parameter is lower than a preset first evaluation parameter threshold or the second traffic evaluation parameter is lower than a preset second evaluation parameter threshold.
[0101] The technical effects of the above technical solution are as follows: The dynamic acquisition unit can retrieve and analyze network traffic characteristic data in real time, including traffic rate, traffic direction, and packet quantity information, etc., thus ensuring the instant perception and response to the network state. By introducing a traffic reference coefficient, this solution can comprehensively consider factors such as traffic rate, the number of servers, and changes in client addresses, etc., to provide a more accurate assessment of the state of network traffic. This assessment method is more comprehensive and refined than simply relying on a single indicator (such as traffic rate). The comparison module in the solution can dynamically select different traffic evaluation parameter acquisition modules according to the comparison result between the traffic reference coefficient and the preset coefficient threshold. This flexible processing method enables the system to adaptively adjust according to different network states, improving the adaptability and robustness of the system. At the same time, by setting a first evaluation parameter threshold and a second evaluation parameter threshold, the above technical solution can issue a warning before the traffic anomaly reaches a serious level. This helps network administrators discover and handle potential network problems in a timely manner, avoiding serious consequences such as network congestion and service interruption. The above technical solution not only considers traffic rate and direction, but also combines packet quantity information to comprehensively evaluate network traffic from multiple dimensions. This comprehensive evaluation method can more comprehensively reflect the state and characteristics of network traffic, improving the accuracy and reliability of the assessment.
[0102] In summary, through real-time acquisition and analysis of network traffic characteristic data, combined with traffic reference coefficients and traffic evaluation parameters, this technical solution realizes the precise assessment and early warning of network traffic. This helps to improve the efficiency and security of network management, reduce the occurrence of network failures, and ensure the smooth operation of network services.
[0103] Specifically, the second traffic evaluation parameter acquisition module includes:
[0104] The difference acquisition module is used to obtain the difference between the traffic reference coefficient and the preset parameter threshold when the traffic reference coefficient does not exceed the preset parameter threshold;
[0105] The information retrieval module is used to retrieve the traffic rate and traffic direction in the historical network traffic characteristic data;
[0106] The compensation coefficient acquisition module is used to obtain an evaluation parameter compensation coefficient by using the traffic rate and traffic direction in the historical network traffic characteristic data; wherein, the evaluation parameter compensation coefficient is obtained through the following formula:
[0107]
[0108] where f b represents the evaluation parameter compensation coefficient;
[0109] The packet quantity information retrieval module is used to retrieve the packet quantity information;
[0110] The second traffic evaluation parameter calculation and acquisition module is used to obtain the second traffic evaluation parameter by combining the difference between the traffic reference coefficient and the preset parameter threshold and the evaluation parameter compensation coefficient with the packet quantity information, where the second traffic evaluation parameter is obtained through the following formula:
[0111]
[0112] where R 02 represents the second traffic evaluation parameter; g i represents the total quantity of packets generated by the i-th server at the corresponding moment when the traffic reference coefficient does not exceed the preset parameter threshold.
[0113] The technical effects of the above technical solution are as follows: When the traffic reference coefficient does not exceed the preset parameter threshold, the system calculates the difference between the traffic reference coefficient and the preset threshold through the difference acquisition module, which reflects the proximity of the traffic state to the abnormal state. This refined evaluation method helps to better understand the current network traffic state and predict its possible change trend. The information retrieval module obtains the traffic rate and traffic direction from the historical network traffic feature data, and these historical data provide a long-term view of the network traffic for the system. By analyzing and utilizing these historical data, the system can more comprehensively understand the normal patterns and rules of the network traffic, providing more accurate background information for the evaluation of the current traffic state. The compensation coefficient acquisition module calculates the evaluation parameter compensation coefficient using the historical network traffic feature data. This compensation coefficient takes into account the influence of historical traffic features on the current traffic evaluation, helping to adjust and optimize the accuracy of the traffic evaluation parameters. The second traffic evaluation parameter calculation and acquisition module combines the packet quantity information, as well as the difference between the traffic reference coefficient and the preset threshold and the evaluation parameter compensation coefficient, to calculate the second traffic evaluation parameter. This method of integrating multiple factors can more comprehensively evaluate the network traffic state, improving the accuracy and reliability of the evaluation. When the second traffic evaluation parameter is lower than the preset second evaluation parameter threshold, the traffic anomaly alarm module will issue a warning. Since the calculation method of the second traffic evaluation parameter takes into account multiple factors, including historical data and the current traffic state, this warning mechanism has higher flexibility and accuracy.
[0114] In summary, the above technical solution improves the refinement and accuracy of traffic state evaluation by introducing multiple factors such as difference, historical data, compensation coefficient, and packet quantity information. At the same time, by combining real-time data and historical data, the system can more comprehensively understand the state and rules of network traffic, providing more reliable support for network management and anomaly warning.
[0115] In this embodiment, as a preferred technical solution of the present invention, the data processing module includes:
[0116] A data retrieval unit for retrieving the collected real-time network data;
[0117] Obtain the collected real-time network data, and based on the sequential retrieval method, retrieve the collected real-time network data one by one, filter out the duplicate and missing relevant real-time network data in the real-time network data, and determine the relevant real-time network data valuable for network security threat detection in the real-time network data;
[0118] It should be noted that through the data retrieval unit, the collected real-time network data can be retrieved, and the duplicate and missing relevant real-time network data in the real-time network data can be filtered out, which can improve the accuracy of subsequent processing of the real-time network data;
[0119] Specifically, if the collected real-time network data includes A1, A2, A3, A4, B1, B2, B3, and B4, where A4 is incomplete missing data, and B3 and B4 are duplicate data;
[0120] Therefore, when the data retrieval unit retrieves A1, A2, A3, A4, B1, B2, B3, and B4, A4 and B4 can be filtered out, and A1, A2, A3, B1, B2, and B3 valuable for network security threat detection can be determined.
[0121] A data grouping unit for grouping the retrieved relevant real-time network data;
[0122] Obtain the relevant real-time network data valuable for network security threat detection in the real-time network data, and based on the mutual exclusion principle, group the relevant real-time network data valuable for network security threat detection in the real-time network data to determine different real-time network data groups;
[0123] It should be noted that through the data grouping unit, the retrieved relevant real-time network data can be grouped to determine different real-time network data groups, which is convenient for subsequent network security threat detection;
[0124] Specifically, if the retrieved relevant real-time network data is A1, A2, A3, B1, B2, and B3;
[0125] Through the data grouping unit, A1, A2, A3, B1, B2, and B3 can be grouped to determine different real-time network data groups, namely the A1, A2, A3 group and the B1, B2, B3 group;
[0126] A data sorting unit for sorting the grouped real-time network data groups;
[0127] Obtain different groups of real-time network data, and based on an internal sorting method, sort the real-time network data placed in different groups of real-time network data one by one to determine a group of real-time network data with an arrangement order;
[0128] It should be noted that the data sorting unit can sort the grouped real-time network data groups to determine a group of real-time network data with an arrangement order, which is convenient for subsequent network security threat detection;
[0129] Specifically, if the grouped real-time network data groups are groups A1, A2, A3 and groups B1, B2, B3;
[0130] The data sorting unit can sort A1, A2, A3 within groups A1, A2, A3 and B1, B2, B3 within groups B1, B2, B3 to determine a group of real-time network data with an arrangement order;
[0131] A feature extraction unit, configured to extract features from the group of real-time network data with an arrangement order;
[0132] Obtain a group of real-time network data with an arrangement order, extract features from the real-time network data placed in the group of real-time network data with an arrangement order, and determine real-time network feature data;
[0133] A data calculation unit, configured to calculate the real-time network feature data;
[0134] Obtain the real-time network feature data, and calculate the real-time network feature data to determine real-time network representation data.
[0135] It should be noted that the threat detection module can perform network security threat detection on the real-time network representation data to determine a network security threat detection result;
[0136] In this embodiment, as a preferred technical solution of the present invention, the threat detection module includes:
[0137] A data storage unit, configured to store pre-set real-time network standard data for threat detection of network security;
[0138] Based on the network security threat detection requirements, pre-set the real-time network standard data of the network system in the static and running states to provide a reference standard for network security threat detection, which is convenient for subsequent threat detection of network security;
[0139] A data indexing unit, configured to index the pre-set real-time network standard data for threat detection of network security;
[0140] Based on the requirements of network security threat detection, retrieve the preset real-time network standard data for network security threat detection from the data storage unit;
[0141] A data retrieval unit for retrieving the preset real-time network standard data for network security threat detection;
[0142] Obtain the retrieved preset real-time network standard data for network security threat detection, and retrieve the retrieved preset real-time network standard data for network security threat detection, facilitating subsequent network security threat detection;
[0143] It should be noted that the real-time network standard data of the network system in the static and operating states are preset to provide a reference standard for network security threat detection, facilitating subsequent network security threat detection. Moreover, by indexing the preset real-time network standard data for network security threat detection through the data indexing unit and retrieving the preset real-time network standard data for network security threat detection through the data retrieval unit, it is convenient to perform network security threat detection on the real-time network characterization data;
[0144] A threat detection unit for performing network security threat detection on the real-time network characterization data;
[0145] Obtain the real-time network characterization data and the real-time network standard data, and perform network security threat detection on the real-time network characterization data based on the real-time network standard data;
[0146] For the situation where the real-time network characterization data is within the range of the real-time network standard data, the network security threat detection result is that the network system is normal and there is no network security threat;
[0147] For the situation where the real-time network characterization data is not within the range of the real-time network standard data, the network security threat detection result is that the network system is abnormal and there is a network security threat.
[0148] It should be noted that by performing network security threat detection, the network security situation of the network system can be understood in real time, facilitating timely control of the network system.
[0149] It should be noted that the intelligent control module can mine and analyze the network security threat detection results, determine the network security intelligent control method, and intelligently control network security based on the network security intelligent control method.
[0150] In this embodiment, as a preferred technical solution of the present invention, the intelligent control module includes:
[0151] A mining and analysis unit for mining and analyzing the results of network security threat detection;
[0152] Obtain the results of network security threat detection, conduct in-depth mining and correlation analysis on the results of network security threat detection, and determine the reasons for the existence of the results of network security threat detection;
[0153] A control method formulation unit for formulating network security intelligent control methods;
[0154] Obtain the reasons for the existence of the results of network security threat detection, and based on the reasons for the existence of the results of network security threat detection, determine network security intelligent control methods;
[0155] An intelligent control unit for intelligently controlling network security;
[0156] Obtain network security intelligent control methods, and based on the network security intelligent control methods, intelligently control network security.
[0157] In this embodiment, as a preferred technical solution of the present invention, for intelligent control of network security, the following operations are performed:
[0158] In the case where the network system is normal and there is no network security threat, continuously conduct real-time threat detection on the network security of the network system and intelligently control the network security of the network system;
[0159] In the case where the network system is abnormal and there is a network security threat, give a timely warning to the network system, and send a real-time warning message to the network security maintenance personnel to guide the network security maintenance personnel to remotely and intelligently control the network system in a timely manner.
[0160] It should be noted that when using a system that uses static and runtime data for network security threat detection to detect network security threats, the network security threat detection situation is shown in Table 1:
[0161] Table 1: Network security threat detection situation
[0162]
[0163] Therefore, by collecting the static data and running data of the network system in the static and running states, based on the collected static data and running data, real-time network data is determined. Through comprehensive processing of the collected real-time network data, including retrieval, grouping, sorting, feature extraction, and calculation, real-time network characterization data is determined. By performing network security threat detection on the real-time network characterization data, the network security threat detection results are determined. Through mining and analysis of the network security threat detection results, a network security intelligent control method is determined. Based on the network security intelligent control method, network security is intelligently controlled, which can timely detect the threats existing in network security and improve the network security control effect.
[0164] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device.
[0165] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A system for network security threat detection using static and runtime data, characterized in that: include: The data collection module is used to collect static data and running data of the network system in static and running states, and determine real-time network data based on the collected static data and running data; The data processing module is used to perform comprehensive processing on the collected real-time network data based on retrieval, grouping, sorting, feature extraction and calculation to determine the real-time network representation data; A threat detection module is used to perform network security threat detection on real-time network characterization data and determine network security threat detection results; The intelligent management and control module is used to mine and analyze the network security threat detection results, determine the network security intelligent management and control method, and intelligently manage network security based on the network security intelligent management and control method; The data acquisition module includes a dynamic acquisition unit; Dynamic acquisition unit, including: A real-time retrieval module, used to retrieve network traffic characteristic data from the operation data in real time; wherein the network traffic characteristic data includes traffic rate, traffic direction and data packet quantity information; and the traffic direction refers to the downlink traffic direction of the network traffic generated from the server to the client in the network; The reference coefficient acquisition module is used to obtain a flow reference coefficient using the flow rate and flow direction, wherein the flow reference coefficient is obtained by the following formula: ; Where, f represents the flow reference coefficient; f0 represents the preset initial coefficient; v d Indicates the current network traffic rate; v e Indicates the preset network traffic rate saturation value; m indicates the number of servers in the network; N i N represents the cumulative number of changes in the address of the client corresponding to the i-th server at the current moment compared with the initial client address; e Indicates the number of clients initially corresponding to the server; n indicates the number of unit time experienced by the network operation; A comparison module, used for comparing the flow reference coefficient with a preset coefficient threshold to obtain a comparison result; A data packet quantity information retrieving module, used for retrieving data packet quantity information when the flow reference coefficient exceeds a preset parameter threshold; The first flow evaluation parameter acquisition module is used to obtain the first flow evaluation parameter by using the flow reference coefficient and the data packet quantity information; wherein the first flow evaluation parameter is obtained by the following formula: ; Among them, R 01 represents the first flow evaluation parameter; h i represents the total number of data packets generated by the ith server at the corresponding time when the traffic reference coefficient exceeds the preset parameter threshold; h p Indicates the average number of packets at a historical moment; C j represents the data volume of the jth data packet; C0 represents the reference data volume of the preset data packet; A second flow evaluation parameter acquisition module, used for acquiring a second flow evaluation parameter through data packet quantity information when the flow reference coefficient does not exceed a preset parameter threshold; The flow abnormality alarm module is used to issue a flow abnormality alarm when the first flow evaluation parameter is lower than a preset first evaluation parameter threshold or the second flow evaluation parameter is lower than a preset second evaluation parameter threshold.
2. The system for network security threat detection using static and runtime data according to claim 1, characterized in that: The data acquisition module comprises: Static data collection unit, used to collect static data of the network system in a static state; A dynamic collection unit is used to collect the operation data of the network system in operation; Determine real-time network data based on collected static data and operational data; Wherein, both the static collection unit and the dynamic collection unit are provided with data collection ports, and both the static collection unit and the dynamic collection unit are connected to the network system through the data collection ports.
3. The system for network security threat detection using static and runtime data according to claim 1, characterized in that: The second flow evaluation parameter acquisition module includes: A difference acquisition module, used for acquiring the difference between the flow reference coefficient and the preset parameter threshold when the flow reference coefficient does not exceed the preset parameter threshold; An information retrieval module is used to retrieve the flow rate and flow direction in the historical network flow characteristic data; The compensation coefficient acquisition module is used to obtain the evaluation parameter compensation coefficient by using the flow rate and flow direction in the historical network flow characteristic data; wherein the evaluation parameter compensation coefficient is obtained by the following formula: ; Among them, f b represents the evaluation parameter compensation coefficient; A data packet quantity information retrieving module, used to retrieve the data packet quantity information; The second traffic evaluation parameter calculation and acquisition module is used to obtain the second traffic evaluation parameter by using the difference between the traffic reference coefficient and the preset parameter threshold and the evaluation parameter compensation coefficient in combination with the data packet quantity information, wherein the second traffic evaluation parameter is obtained by the following formula: ; Among them, R 02 represents the second flow evaluation parameter; g i It indicates the total number of data packets generated by the ith server at the corresponding time when the traffic reference coefficient does not exceed the preset parameter threshold.
4. The system for network security threat detection using static and runtime data according to claim 2, characterized in that: The data processing module comprises: A data retrieval unit, used for retrieving the collected real-time network data; Acquire the collected real-time network data, search the collected real-time network data one by one based on the sequential search method, filter out the duplicate and missing related real-time network data contained in the real-time network data, and determine the relevant real-time network data in the real-time network data that is valuable for network security threat detection; A data grouping unit, used for grouping the retrieved relevant real-time network data; Acquire relevant real-time network data valuable for network security threat detection in the real-time network data, group the relevant real-time network data valuable for network security threat detection in the real-time network data based on the mutual exclusion principle, and determine different real-time network data groups; A data sorting unit, used for sorting the grouped real-time network data groups; Different real-time network data groups are obtained, and based on an internal sorting method, the real-time network data placed in the different real-time network data groups are sorted one by one to determine a real-time network data group with an arrangement order.
5. The system for network security threat detection using static and runtime data according to claim 4, characterized in that: The data processing module also includes: A feature extraction unit, used for extracting features from the real-time network data group having an arrangement order; Acquire a real-time network data group with an arrangement order, extract features of the real-time network data placed in the real-time network data group with an arrangement order, and determine the real-time network feature data; A data calculation unit, used for calculating real-time network characteristic data; Real-time network characteristic data is acquired, and the real-time network characteristic data is calculated to determine the real-time network characterization data.
6. The system for network security threat detection using static and runtime data according to claim 5, characterized in that: The threat detection module comprises: A data storage unit, used to store pre-set real-time network standard data for threat detection on network security; Based on the needs of network security threat detection, the real-time network standard data of the network system in static and running states is pre-set to provide a reference standard for network security threat detection, which is convenient for subsequent threat detection of network security; A data indexing unit, used to index pre-set real-time network standard data for threat detection on network security; Based on the network security threat detection requirements, pre-set real-time network standard data for network security threat detection is indexed from the data storage unit; A data retrieval unit, used to retrieve pre-set real-time network standard data for threat detection on network security; The indexed pre-set real-time network standard data for threat detection on network security is obtained, and the indexed pre-set real-time network standard data for threat detection on network security is retrieved to facilitate subsequent threat detection on network security.
7. The system for network security threat detection using static and runtime data according to claim 6, characterized in that: The threat detection module also includes: A threat detection unit, used for performing network security threat detection on real-time network characterization data; Acquire real-time network characterization data and real-time network standard data, and perform network security threat detection on the real-time network characterization data based on the real-time network standard data; If the real-time network characterization data is within the range of the real-time network standard data, the network security threat detection result is that the network system is normal and there is no network security threat; In the case where the real-time network characterization data is not within the range of the real-time network standard data, the network security threat detection result is that the network system is abnormal and there is a network security threat.
8. The system for network security threat detection using static and runtime data according to claim 7, characterized in that: The intelligent management and control module includes: A mining and analysis unit, used for mining and analyzing network security threat detection results; Obtain network security threat detection results, conduct in-depth mining and correlation analysis on the network security threat detection results, and determine the reasons for the existence of network security threat detection results; A control formulation unit, which is used to formulate intelligent network security control methods; Obtain the reasons for the existence of network security threat detection results, and determine the network security intelligent management and control method based on the reasons for the existence of network security threat detection results; Intelligent management and control unit, used for intelligent management and control of network security; Obtain intelligent network security management and control methods, and perform intelligent network security management and control based on the intelligent network security management and control methods.
9. The system for network security threat detection using static and runtime data according to claim 8, characterized in that: To intelligently manage network security, perform the following operations: If the network system is normal and there is no network security threat, the network system's network security will continue to be detected in real time, and the network security of the network system will be managed and controlled intelligently; In case of network system anomalies and network security threats, the network system will be promptly warned, and real-time warning information will be sent to network security maintenance personnel to guide them to conduct remote intelligent management and control of the network system in a timely manner.
Citation Information
Patent Citations
Network security index assessment method
CN116961987A
Network security analysis method and system based on digital twinning
CN117478394A