A method for constructing a knowledge base for network security
By building a network security knowledge base and using network device system log files and attack behavior sequence analysis, the problem that traditional methods cannot quickly update network security knowledge is solved, and efficient network security information management and decision support are achieved.
Patent Information
- Application Number
- CN202410820937.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-24
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2044-06-24
AI Technical Summary
Traditional network security knowledge base construction methods rely on manual sorting and fixed data sources, and cannot meet the rapid update of network security knowledge.
By obtaining network equipment system log files, network security data collection and processing and attack behavior sequence mining analysis, network security ontology is extracted, and entity matching link processing is carried out to build a network security knowledge base, and through instance extraction, attribute deduction and knowledge relationship optimization analysis, a network security knowledge update base is generated.
It has achieved rapid updates and improvements to the network security knowledge base, provided more comprehensive and accurate network security information, and supported network security decisions and practices.
Smart Images

Figure CN118585656B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security processing, and particularly to a method for constructing a knowledge base for network security. Background Art
[0002] Network security is one of the important challenges faced in the current Internet era. Threats such as malware, cyber attacks, and data breaches are increasing continuously. At the same time, with the increasing complexity and severity of cyber attacks, building and managing a comprehensive and accurate network security knowledge base is crucial for network security protection. However, traditional methods for constructing network security knowledge bases often rely on manual collation and fixed data sources, and cannot meet the rapid update of network security knowledge. Summary of the Invention
[0003] Based on this, it is necessary for the present invention to provide a method for constructing a knowledge base for network security to solve at least one of the above technical problems.
[0004] To achieve the above object, a method for constructing a knowledge base for network security includes the following steps:
[0005] Step S1: Obtain the system log files of network devices, and perform network security data collection and processing on the system log files of network devices to obtain network security information data of the network device system; perform mining and analysis on the attack behavior sequence of the network security information data of the network device system to obtain the sequence data of the system network attacked behavior events;
[0006] Step S2: Perform network security ontology extraction processing on the network security information data of the network device system to obtain the system network security ontology; perform entity matching and linking processing on the network security information data of the network device system based on the sequence data of the system network attacked behavior events and the system network security ontology to obtain the network security linked entities of each system network security ontology;
[0007] Step S3: Perform knowledge base connection construction according to the system network security ontology and the network security linked entities of each system network security ontology to obtain a network security knowledge base; perform network security instance extraction processing on the network security knowledge base to obtain a network security instance set;
[0008] Step S4: Perform attribute pair value deduction processing on the network security instance set to obtain network security instance attribute pair values; perform knowledge relationship optimization analysis on the network security instance set based on the network security instance attribute pair values to obtain the optimized connection relationship of network security instance knowledge; perform knowledge relationship update processing on the network security knowledge base according to the optimized connection relationship of network security instance knowledge to generate a network security knowledge update base.
[0009] The present invention first obtains the system log file of a network device. This log file contains relevant information recording the operation and operation of the network device system, such as user login information, network security connection records, malicious code attack exception logs, etc. By obtaining this log file, the network security operation status and network attack situation of the network device system can be deeply understood. Such a collection process is very important in network security management and can provide a data basis for subsequent analysis and evaluation. The network security data collection and processing of the network device system log file is to further deeply analyze the possible security problems in the network device system, so as to identify corresponding network security events and extract malicious code samples, which can discover potential network attack and threat behaviors in the network device system. These data and information are very important for taking timely measures to protect the security of the system and network, thus providing basic data guarantee for the subsequent processing process. At the same time, by mining and analyzing the attack behavior sequence of the network security information data of the network device system, the attack behavior patterns and attack event processes of the attacker in the network device system can be identified, and their attack target subjects and entity situations can be further understood, so as to provide a data basis for the subsequent network security entity identification and analysis process. Secondly, through the network security ontology extraction and processing of the network security information data of the network device system, the purpose of this step is to extract and extract the ontology information of the system network security from the original data, making the subsequent analysis and understanding more accurate and effective. By combining the system network security ontology and the system network attack behavior event sequence data to perform entity matching and linking processing on the network security information data of the network device system, the entities corresponding in the network security information data can be matched, screened and linked with the entities of each system network security ontology, so as to identify and match the entities in the network security information data with the suspected entities in the system network security ontology, and the actual matching and linking relationship between the ontology and the corresponding entities during the attack behavior process can be established. This entity matching and linking processing helps to integrate and associate the network security information in different data sources, provides more comprehensive and accurate network security linked entities, and provides richer information support for comprehensive analysis and decision-making. Then, by combining the system network security ontology and the network security linked entities of each system network security ontology to construct a knowledge base connection, the network security ontology and the linked entities can be organically organized together by establishing a connection relationship, thus forming a complete network security knowledge base. This knowledge base can be a graph database or a semantic network, used to store, manage and query knowledge and information related to network security, and provide comprehensive and fine-grained network security knowledge representation and access.By performing network security instance extraction processing on the network security knowledge base, the key to this step lies in extracting specific instances from the network security knowledge base by applying natural language processing and information extraction technologies. These instances can be specific network attack cases, security vulnerability information, defense strategies, or other practical examples related to network security. The obtained network security instance set helps to provide practical cases and examples for learning, training, and analysis, thereby assisting network security personnel in better understanding and coping with real network security threats and challenges. Finally, by performing attribute-value deduction processing on the network security instance set, an inference model between network security instance attributes can be established to infer missing or newly optimized attribute-value pairs of network security instances, thus filling the gaps in the attribute set. This helps to improve the attribute set and enhance the accuracy and comprehensiveness of subsequent analysis. In addition, knowledge relationship optimization analysis is also performed on the network security instance set by combining network security instance attribute-value pairs. By analyzing the relationships and patterns between attribute values, dependencies, similarities, or other correlations between attributes can be discovered, and these relationships are optimized into more accurate and useful knowledge associations. This helps to better understand the knowledge in the network security instance set and improve the understandability and applicability of the knowledge. By performing knowledge relationship update processing on the network security knowledge base according to the optimized connection relationship of network security instance knowledge, a network security knowledge update library is generated. By applying the optimized knowledge relationship to the knowledge base, the knowledge associations in the knowledge base can be updated and improved, and the accuracy and practicality of the knowledge base can be enhanced. In this way, a more comprehensive and accurate network security knowledge update library can be generated to provide better support for network security decision-making and practice, thereby meeting the rapid update of network security knowledge. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] Other features, objects, and advantages of the present invention will become more apparent from the following detailed description of non-limiting embodiments read in conjunction with the accompanying drawings:
[0011] Figure 1 It is a schematic flowchart of the steps of the method for constructing a network security-oriented knowledge base of the present invention;
[0012] Figure 2 is Figure 1 a detailed schematic flowchart of step S1 in
[0013] Figure 3 is Figure 2 a detailed schematic flowchart of step S14 in DETAILED DESCRIPTION OF THE EMBODIMENTS
[0014] The technical method of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of them. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative work belong to the scope of protection of the present invention.
[0015] In addition, the accompanying drawings are only schematic diagrams of the present invention and are not necessarily drawn to scale. The same reference numerals in the drawings represent the same or similar parts, and thus repeated descriptions thereof will be omitted. Some of the block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. The functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor methods and / or microcontroller methods.
[0016] It should be understood that although terms such as "first" and "second" may be used here to describe various units, these units should not be limited by these terms. These terms are only used to distinguish one unit from another. For example, without departing from the scope of the exemplary embodiments, the first unit can be called the second unit, and similarly the second unit can be called the first unit. The term "and / or" used here includes any and all combinations of one or more of the listed associated items.
[0017] To achieve the above object, please refer to Figures 1 to 3 , the present invention provides a method for constructing a knowledge base for network security. The method includes the following steps:
[0018] Step S1: Obtain the system log file of the network device, and perform network security data collection and processing on the system log file of the network device to obtain the network security information data of the network device system; perform mining and analysis on the attack behavior sequence of the network security information data of the network device system to obtain the system network attack behavior event sequence data;
[0019] Step S2: Perform network security ontology extraction processing on the network security information data of the network device system to obtain the system network security ontology; perform entity matching and linking processing on the network security information data of the network device system based on the system network attack behavior event sequence data and the system network security ontology to obtain the network security linked entities of each system network security ontology;
[0020] Step S3: Perform knowledge base connection construction according to the system network security ontology and the network security linked entities of each system network security ontology to obtain a network security knowledge base; perform network security instance extraction processing on the network security knowledge base to obtain a network security instance set;
[0021] Step S4: Perform attribute-value deduction processing on the network security instance set to obtain network security instance attribute-value pairs; perform knowledge relationship optimization analysis on the network security instance set based on the network security instance attribute-value pairs to obtain an optimized connection relationship of network security instance knowledge; perform knowledge relationship update processing on the network security knowledge base according to the optimized connection relationship of network security instance knowledge to generate a network security knowledge update library.
[0022] In the embodiment of the present invention, please refer to Figure 1 as shown, which is a schematic flow chart of the steps of the knowledge base construction method for network security of the present invention. In this example, the steps of the knowledge base construction method for network security include:
[0023] Step S1: Obtain the network device system log file, and perform network security data collection processing on the network device system log file to obtain network device system network security information data; perform attack behavior sequence mining analysis on the network device system network security information data to obtain system network attacked behavior event sequence data.
[0024] In an embodiment of the present invention, relevant log files are obtained from the log storage system of the network device system to obtain information related to the operation and operation of the network device system, such as user login information, network security connection records, malicious code attack exception logs, etc., and to deeply understand the network security operation status and network attack situation of the network device system from them, so as to obtain the log files of the network device system. At the same time, the log files of the network device system are detected by using a log analysis tool or a custom script to detect abnormal behaviors in the log files of the network device system, and abnormal events inconsistent with normal behaviors are identified from them, such as abnormal login attempts, unauthorized access, etc. At the same time, the log files where the abnormal events are located are screened out to screen out log abnormal files that do not conform to the normal operation of the system network security or have potential security vulnerability risks, and the log abnormal files of the network device system are identified by using methods such as log analysis tools and intrusion event detection to identify possible network security events contained therein, such as attack behaviors, abnormal traffic and other event information. Secondly, the malicious code detection tool or custom script is used to extract and process the malicious code samples from the network security event information data to extract potential malicious code samples from them, and to discover potential network attack and threat behaviors in the network device system, and to analyze the attack behaviors and impacts of the malicious code in the network device system, so as to evaluate and determine the threat information data of the network security vulnerability to the network device system. The previously obtained network security event information data and threat information data are merged to ensure that the data formats and fields of the two are consistent, and the security events and vulnerabilities existing in the network device system are comprehensively analyzed to form a more comprehensive and integrated network security information data, so as to obtain the network security information data of the network device system. Then, by using technologies such as behavior rules and machine learning to perform behavior recognition and analysis on the network security information data of the network device system, the relevant data of network traffic, network security events and network security vulnerability threats in the network security information data of the network device system are analyzed, and various possible attack behavior situations in the network device system are identified from them, such as malicious software, intrusion attempts, denial-of-service attacks and other behavior information, and relevant data mining and feature extraction methods are used for analysis and mining to extract the key features of the attacked behaviors of the network device system. According to the analyzed feature data, corresponding sequence mining methods (such as frequent pattern mining, sequence clustering, etc.) are used for analysis to analyze the sequence patterns and rules of the attacked behaviors, and to reveal the timing patterns, attack links and attack stages of the network attack behavior events on the network device system, and finally the sequence data of the system network attacked behavior events is obtained.
[0025] Step S2: Perform network security ontology extraction processing on the network security information data of the network device system to obtain the system network security ontology; perform entity matching and linking processing on the network security information data of the network device system based on the system network attack behavior event sequence data and the system network security ontology to obtain the network security linked entities of each system network security ontology;
[0026] In the embodiments of the present invention, natural language processing technology and ontology concept analysis method are used to analyze the text data in the network security information data of the network device system, so as to identify the ontology concept information therein, such as network devices, network traffic, attack behaviors, etc., and the network security ontology information in the network security information data of the network device system is extracted and processed by combining the analyzed ontology concept information, so as to extract and extract the ontology information of the system network security from the original data according to the ontology concept information, thereby obtaining the system network security ontology. Secondly, the system network attack behavior event sequence data is processed based on the system network security ontology, so as to filter and screen the network security event sequence of the entire system according to the ontology-related rules and screening conditions, extract the network security attack behavior event sequence situation related to the network security ontology from the system network attack behavior event sequence data, and simulate and analyze the network security attack process of the network attack behavior event sequence of each system network security ontology obtained by screening, so as to analyze the characteristics such as attack patterns, attack time intervals, and attack behavior association relationships in the corresponding event sequence, and understand the evolution process of the attack behavior and possible attack paths. Then, data mining and machine learning technologies are used to analyze and mine the network attack behavior process information data of each system network security ontology, so as to identify the network security suspected entities corresponding to each system network security ontology during the network attack behavior process, including attackers, attacked systems, or other entities related to network security, and analyze the network security suspected entities of each system network security ontology by using natural language processing technology, text mining, feature extraction and other technologies, so as to extract the semantic features of the suspected entities, including entity attributes, relationships, and context information. Next, entity recognition methods are used to analyze the network security information data of the network device system, so as to identify the entities of the entire system network security, including devices, users, application programs, and other entities related to network security, and analyze the identified system network security entities to extract their semantic features, including device types, IP addresses, geographical locations, etc. Finally, appropriate similarity calculation methods (such as cosine similarity, Euclidean distance, etc.) are used to perform matching calculations on the semantic features of the network security suspected entities and the semantic features of the system network security entities of each system network security ontology, so as to calculate and determine the similarity or association degree between the network security suspected entities and the system network security entities, and at the same time determine the matching relationship and connection between the network security suspected entities and the system network security entities according to the calculated similarity degree, and establish the actual matching link relationship between the ontology and the corresponding entities during the attack behavior process, so as to determine the actual entity situation associated with the system network security ontology, and finally obtain the network security linked entities of each system network security ontology.
[0027] Step S3: Construct a knowledge base connection based on the system network security ontology and the network security link entities of each system network security ontology to obtain a network security knowledge base; perform network security instance extraction processing on the network security knowledge base to obtain a network security instance set;
[0028] In the embodiment of the present invention, the association rule mining algorithm is used to analyze the system network security ontology and the network security link entities of each system network security ontology, so as to analyze the relevance and interaction between the system network security ontology and the link entities, and infer their connection relationship to reveal the hidden association and dependency relationship between the network security ontology and the link entities. And by combining the potential association connection relationship obtained from the analysis, the knowledge graph connection technology is used to construct the connection of the system network security ontology and the network security link entities of each system network security ontology, so as to organically organize the network security ontology and the link entities together to form a knowledge graph or knowledge map of a complete network security knowledge base, thereby obtaining a network security knowledge base. Then, by applying natural language processing and information extraction technology to process the network security knowledge base, instances that meet the conditions are extracted from the network security knowledge base, including specific network attack cases, security vulnerability information, defense strategies, or other practical examples related to network security, and finally a network security instance set is obtained.
[0029] Step S4: Perform attribute-value deduction processing on the network security instance set to obtain network security instance attribute values; perform knowledge relationship optimization analysis on the network security instance set based on the network security instance attribute values to obtain a network security instance knowledge optimization connection relationship; perform knowledge relationship update processing on the network security knowledge base according to the network security instance knowledge optimization connection relationship to generate a network security knowledge update base.
[0030] In the embodiments of the present invention, first, data cleaning and preprocessing are performed on the network security instance set to remove missing values, handle outliers, etc. Then, through attribute extraction processing on the processed network security instance set, relevant attribute information is extracted from each network security instance, including but not limited to attack types, affected systems, attacker behavior patterns, etc. At the same time, by using corresponding association mining algorithms (such as the Apriori algorithm, FP-growth algorithm, etc.) to analyze each network security instance attribute in the network security instance attribute set, screening is performed according to the support and confidence of association rules, and the relevance between various network security instance attributes is analyzed. By using corresponding potential relationship pattern recognition algorithms (such as latent semantic analysis (LSA), topic models (such as LDA), etc.) to analyze the network security instance attribute set, potential relationship patterns between various network security instance attributes are identified, that is, the semantic, topic, or pattern information hidden in the attribute set, and the mutual dependence and influence between different network security instance attributes are understood. Through combining the obtained attribute potential relationship patterns, target variable requirement prediction analysis is performed on the network security instance attribute set to predict the target variable requirements of network security instances, such as predicting future attack trends or potential vulnerability requirements. By using mathematical statistical methods to perform statistical analysis on each existing attribute pair value in the network security instance attribute set, the value range, distribution, and common attribute combination of each known attribute pair value are analyzed, that is, each network security instance attribute and its corresponding value. Secondly, by combining the association relationships between various network security instance attributes and the obtained attribute target variable requirement data, a suitable attribute deduction algorithm (such as decision trees, neural networks, etc.) is used to construct an attribute deduction mathematical model, and the known attribute pair values of network security instances are speculated and predicted through the attribute deduction mathematical model to speculate the missing or newly optimized attribute pair values in the network security instances, thereby obtaining the network security instance attribute pair values. Then, by using the knowledge relationship analysis method to analyze the network security instance set, the attributes and other association information between network security instances (including specific network attack cases, security vulnerability information, and defense strategies, etc.) are analyzed, and the knowledge connection relationships between them are predicted. At the same time, by using knowledge graph algorithms or path reasoning algorithms to analyze the analyzed knowledge connection relationships, reachable paths between network security instances are searched and discovered, and the length values of each reachable path are judged and analyzed to determine which reachable path corresponding to the network security instance knowledge prediction connection relationship is shorter and reliable, and which reachable paths are longer or unreliable. According to the analysis results, the knowledge connection relationships are optimized, including deleting redundant paths, adding missing paths, etc., to screen out more reliable and effective connection relationships, thereby obtaining the optimized knowledge connection relationships of network security instances.Finally, by optimizing the connection relationship according to the updated and optimized network security instance knowledge, the corresponding knowledge relationship in the network security knowledge base is updated, so as to apply the optimized knowledge relationship to the network security knowledge base, in order to better reflect the attribute-value pairs of the network security instance and the knowledge optimization connection relationship, and provide the latest network security knowledge and related information of the attribute-value pairs, and finally generate a network security knowledge update library.
[0031] The present invention first obtains the system log file of the network device. This log file contains relevant information recording the operation and operation of the network device system, such as user login information, network security connection records, malicious code attack exception logs, etc. By obtaining this log file, the network security operation status and network attack situation of the network device system can be deeply understood. Such a collection process is very important in network security management and can provide a data basis for subsequent analysis and evaluation. The network security data collection and processing of the network device system log file is to further deeply analyze the possible security problems in the network device system to identify corresponding network security events and extract malicious code samples, so as to discover potential network attacks and threat behaviors in the network device system. These data and information are very important for taking timely measures to protect the security of the system and network, thus providing basic data guarantee for the subsequent processing process. At the same time, by mining and analyzing the attack behavior sequence of the network security information data of the network device system, the attack behavior pattern and attack event process of the attacker in the network device system can be identified, and their attack target subjects and entity situations can be further understood, so as to provide a data basis for the subsequent network security entity identification and analysis process. Secondly, through the network security ontology extraction and processing of the network security information data of the network device system, the purpose of this step is to extract and extract the ontology information of the system network security from the original data, making the subsequent analysis and understanding more accurate and effective. By combining the system network security ontology and the system network attack behavior event sequence data to perform entity matching and linking processing on the network security information data of the network device system, the entities corresponding in the network security information data can be matched, screened and linked with the entities of each system network security ontology to identify and match the entities in the network security information data with the suspected entities in the system network security ontology, and the actual matching and linking relationship between the ontology and the corresponding entities in the attack behavior process can be established. This entity matching and linking processing helps to integrate and associate the network security information in different data sources, provides a more comprehensive and accurate network security linked entity, and provides richer information support for comprehensive analysis and decision-making. Then, by combining the system network security ontology and the network security linked entities of each system network security ontology to construct a knowledge base connection, the network security ontology and the linked entities can be organically organized together by establishing a connection relationship, thus forming a complete network security knowledge base. This knowledge base can be a graph database or a semantic network, used to store, manage and query knowledge and information related to network security, and provide comprehensive and fine-grained network security knowledge representation and access.By performing network security instance extraction processing on the network security knowledge base, the key to this step lies in extracting specific instances from the network security knowledge base by applying natural language processing and information extraction technologies. These instances can be specific network attack cases, security vulnerability information, defense strategies, or other practical examples related to network security. The obtained network security instance set helps to provide practical cases and examples for learning, training, and analysis, thus assisting network security personnel in better understanding and coping with real network security threats and challenges. Finally, by performing attribute-to-value deduction processing on the network security instance set, an inference model between network security instance attributes can be established to infer missing or newly optimized attribute-to-value pairs of network security instances, thereby filling the gaps in the attribute set. This helps to improve the attribute set and enhance the accuracy and comprehensiveness of subsequent analysis. In addition, knowledge relationship optimization analysis is also performed on the network security instance set by combining network security instance attribute-to-value pairs. By analyzing the relationships and patterns between attribute values, dependencies, similarities, or other correlations between attributes can be discovered, and these relationships can be optimized into more accurate and useful knowledge associations. This helps to better understand the knowledge in the network security instance set and improve the understandability and applicability of the knowledge. By performing knowledge relationship update processing on the network security knowledge base according to the optimized connection relationship of network security instance knowledge, a network security knowledge update library is generated. By applying the optimized knowledge relationship to the knowledge base, the knowledge associations in the knowledge base can be updated and improved, and the accuracy and practicality of the knowledge base can be enhanced. In this way, a more comprehensive and accurate network security knowledge update library can be generated to provide better support for network security decision-making and practice, thus meeting the rapid update of network security knowledge.
[0032] Preferably, step S1 includes the following steps:
[0033] Step S11: Obtain the network device system log file;
[0034] Step S12: Perform file anomaly screening processing on the network device system log file to obtain the network device system log anomaly file;
[0035] Step S13: Perform network security event recognition and analysis on the network device system log anomaly file to obtain network security event information data; perform malicious code sample extraction processing on the network device system log anomaly file to obtain network device system malicious code sample information data;
[0036] Step S14: Perform network vulnerability threat assessment and analysis on the network device system log anomaly file based on the network device system malicious code sample information data to obtain network security vulnerability threat information data;
[0037] Step S15: Merge the network security event information data and the network security vulnerability threat information data to obtain the network security information data of the network device system;
[0038] Step S16: Mine and analyze the attack behavior sequence of the network security information data of the network device system to obtain the system network attacked behavior event sequence data.
[0039] As an embodiment of the present invention, refer to Figure 2 shown in Figure 1 the detailed step flow schematic diagram of step S1 in
[0040] Step S11: Obtain the network device system log file;
[0041] In the embodiment of the present invention, the corresponding log file is obtained from the log storage system of the network device system to obtain the relevant information recording the operation and operation of the network device system, such as user login information, network security connection records, malicious code attack exception logs, etc., and deeply understand the network security operation status and network attacked situation of the network device system from it. At the same time, ensure that the obtained log file includes various network security event records and information during the operation of the network device system, and finally obtain the network device system log file.
[0042] Step S12: Perform file exception screening processing on the network device system log file to obtain the network device system log exception file;
[0043] In the embodiment of the present invention, the network device system log file is detected by using a log analysis tool or a custom script to detect the abnormal behavior in the network device system log file, and identify the abnormal events that do not conform to the normal behavior, such as abnormal login attempts, unauthorized access, etc. At the same time, screen out the log file where the abnormal event is located to screen out the log exception file that does not conform to the normal operation of the system network security or has potential security vulnerability risks, and finally obtain the network device system log exception file.
[0044] Step S13: Perform network security event identification and analysis on the network device system log exception file to obtain the network security event information data; perform malicious code sample extraction processing on the network device system log exception file to obtain the network device system malicious code sample information data;
[0045] In the embodiments of the present invention, methods such as using log analysis tools and intrusion event detection are employed to identify events in the abnormal files of the network device system logs, so as to identify possible network security events contained therein, such as attack behaviors, abnormal traffic and other event information, thereby obtaining network security event information data. Then, by using malicious code detection tools or custom scripts, the network security event information data is processed to extract potential malicious code samples, and potential network attacks and threat behaviors in the network device system are discovered, and finally, malicious code sample information data of the network device system is obtained.
[0046] Step S14: Based on the malicious code sample information data of the network device system, conduct a network vulnerability threat assessment and analysis on the abnormal files of the network device system logs to obtain network security vulnerability threat information data;
[0047] In the embodiments of the present invention, through behavioral analysis of the malicious code sample information data of the network device system, the attack behaviors and impacts of the malicious code in the network device system are analyzed and understood, its purpose and function are determined, as well as its specific attack behaviors in the network device system. And through the use of feature extraction methods (such as static code analysis, dynamic behavior monitoring and other technologies) for feature analysis, the behavioral characteristics of the malicious code are extracted, including malicious code sample attack behavior operations, attack behavior patterns, abnormal operations, etc. Secondly, by combining the extracted behavioral characteristics and using appropriate prediction models and algorithms, such as machine learning, data mining and other methods, the abnormal files of the network device system logs are analyzed to analyze and predict possible network security vulnerabilities in the network device system, and the potential security vulnerability status existing in the network device system is discovered early. Then, through the use of corresponding vulnerability threat assessment methods for analysis, indicators such as the threat level, impact scope, vulnerability to attack of the network security vulnerability are analyzed, and the threat level of the network security vulnerability to the network device system is evaluated and determined, and finally, network security vulnerability threat information data is obtained.
[0048] Step S15: Merge the network security event information data and the network security vulnerability threat information data to obtain network security information data of the network device system;
[0049] In the embodiments of the present invention, by merging the network security event information data and the network security vulnerability threat information data, the data formats and fields of the two are ensured to be consistent, and the security events and vulnerabilities existing in the network device system are comprehensively analyzed, thereby forming a more comprehensive and integrated network security information data, and finally obtaining network security information data of the network device system.
[0050] Step S16: Conduct mining analysis on the attack behavior sequence of the network security information data of the network device system to obtain the data of the system network attacked behavior event sequence.
[0051] In the embodiments of the present invention, by using technologies such as behavior rules and machine learning to perform behavior recognition and analysis on the network security information data of the network device system, relevant data on network traffic, network security events, and network security vulnerability threats in the network security information data of the network device system are analyzed, and various possible attack behavior situations in the network device system are identified therefrom, such as behavior information of malware, intrusion attempts, denial-of-service attacks, etc. Then, through the use of relevant data mining and feature extraction methods for analysis and mining, key features of the attacked behavior of the network device system are extracted, such as attack type, attack source, attack time, etc. At the same time, by using corresponding sequence mining methods (such as frequent pattern mining, sequence clustering, etc.) according to the analyzed feature data to analyze the information data of the attacked behavior of the system network security, the sequence patterns and rules of the attacked behavior are analyzed, and the temporal patterns, attack links, and attack phases of the network attack behavior events on the network device system are revealed, and finally the sequence data of the attacked behavior events of the system network is obtained.
[0052] First, the present invention obtains the system log file of the network device. This log file contains relevant information recording the operation and operation of the network device system, such as user login information, network security connection records, malicious code attack exception logs, etc. By obtaining this log file, the network security operation status and network attack situation of the network device system can be deeply understood. Such a collection process is very important in network security management and can provide a data basis for subsequent analysis and evaluation. At the same time, by performing file anomaly screening processing on the system log file of the network device, it means that log anomaly files that do not conform to the normal operation of the system network security or have potential security vulnerability risks can be screened out. By screening out these abnormal files, it can help to pay attention to possible network security problems and abnormal situations in the network device system and further strengthen the security of the network device system. Secondly, by performing network security event identification analysis and malicious code sample extraction processing on the abnormal system log file of the network device, it is to further deeply analyze possible security problems in the network device system. By identifying network security events and extracting malicious code samples, potential network attacks and threat behaviors in the network device system can be discovered. This information is very important for taking timely measures to protect the security of the system and network, thus providing basic data guarantee for the subsequent processing process. Then, by performing network vulnerability threat assessment analysis on the log anomaly file of the network device system based on the malicious code sample information data of the network device system, it means that various network vulnerabilities existing in the network device system can be evaluated and their potential threats to the system network security can be analyzed. This assessment and analysis process helps to understand the weaknesses and vulnerabilities in the network device system, thus providing data support for the subsequent processing process. Next, by merging the network security event information data and the network security vulnerability threat information data, the purpose of this is to comprehensively analyze the security events and vulnerabilities existing in the network device system, so as to form a more comprehensive and integrated security information data of the network device system. In this way, the overall security status of the network device system can be better understood, providing data support for the subsequent attack behavior sequence processing process. Finally, by performing attack behavior sequence mining analysis on the network security information data of the network device system, the attack behavior patterns and attack event processes of the attacker in the network device system can be identified, and their attack target subjects and entity situations can be further understood, thus providing a data basis for the subsequent network security entity identification analysis process.
[0053] Preferably, step S14 includes the following steps:
[0054] Step S141: Perform code behavior parsing and analysis on the malicious code sample information data of the network device system to obtain the malicious code behavior information data of the network device system;
[0055] Step S142: Perform behavior feature extraction processing on the malicious code behavior information data of the network device system to obtain the malicious code behavior feature data of the network device system;
[0056] Step S143: Based on the malicious code behavior feature data of the network device system, perform network security vulnerability prediction analysis on the network device system log exception file to obtain the network security vulnerability status data of the network device system;
[0057] Step S144: Perform network vulnerability threat assessment analysis on the network security vulnerability status data of the network device system to obtain the network security vulnerability threat information data.
[0058] As an embodiment of the present invention, referring to Figure 3 shown, for Figure 2 the detailed step flow diagram of step S14 in
[0059] Step S141: Perform code behavior parsing analysis on the malicious code sample information data of the network device system to obtain the malicious code behavior information data of the network device system;
[0060] In the embodiment of the present invention, by performing behavior parsing analysis on the malicious code sample information data of the network device system, the attack behavior and impact of the malicious code in the network device system are analyzed and understood, its purpose and function are determined, as well as its specific attack behavior in the network device system, and finally the malicious code behavior information data of the network device system is obtained.
[0061] Step S142: Perform behavior feature extraction processing on the malicious code behavior information data of the network device system to obtain the malicious code behavior feature data of the network device system;
[0062] In the embodiment of the present invention, by using feature extraction methods (such as static code analysis, dynamic behavior monitoring and other technologies) to perform feature analysis on the malicious code behavior information data of the network device system, the behavior features of the malicious code are extracted, including malicious code sample attack behavior operations, attack behavior patterns, abnormal operations, etc., and finally the malicious code behavior feature data of the network device system is obtained.
[0063] Step S143: Based on the malicious code behavior feature data of the network device system, perform network security vulnerability prediction analysis on the network device system log exception file to obtain the network security vulnerability status data of the network device system;
[0064] In an embodiment of the present invention, by combining the malicious code behavior characteristic data of the network device system and using appropriate prediction models and algorithms, such as machine learning, data mining and other methods, the abnormal files in the network device system logs are analyzed to analyze and predict the possible network security vulnerabilities in the network device system, and the potential security vulnerability status existing in the network device system is detected early, and finally the network security vulnerability status data of the network device system is obtained.
[0065] Step S144: Perform a network vulnerability threat assessment and analysis on the network security vulnerability status data of the network device system to obtain network security vulnerability threat information data.
[0066] In an embodiment of the present invention, by using the corresponding vulnerability threat assessment method to analyze the network security vulnerability status data of the network device system, indicators such as the threat level, the scope of influence, and the vulnerability to attack of the network security vulnerability are analyzed, and the threat level of the network security vulnerability to the network device system is evaluated and determined, and finally the network security vulnerability threat information data is obtained.
[0067] The present invention first analyzes the code behavior of the malicious code sample information data of the network device system, which can deeply study the behavior of the malicious code. By analyzing the code logic and execution path of the malicious code, its purpose and function, as well as its specific attack behavior in the network device system can be understood. This code behavior analysis process can reveal the hidden attack behavior characteristics of the malicious code, thus providing an important reference for the subsequent security vulnerability analysis process. Secondly, by performing behavior characteristic extraction processing on the malicious code behavior information data of the network device system, the behavior characteristic data of the malicious code can be obtained. By extracting the behavior patterns, key behavior characteristics, and abnormal behavior characteristics of the malicious code, it helps to achieve automated network security vulnerability detection, thereby improving the recognition accuracy and response speed of network security vulnerabilities. Then, by combining the malicious code behavior characteristic data of the network device system to perform network security vulnerability prediction analysis on the abnormal files in the network device system logs, it means that the possible network security vulnerabilities in the network device system can be predicted through the abnormal log information and malicious code behavior characteristic data of the network device system. Through this prediction analysis, the potential security vulnerability status existing in the network device system can be detected early, thus providing data support for the subsequent vulnerability threat assessment and analysis process. Finally, by performing a network vulnerability threat assessment and analysis on the network security vulnerability status data of the network device system, network security vulnerability threat information data can be obtained. By evaluating the severity, scope of influence, and potential threat of the network vulnerability, the threat level of the network security vulnerability to the network device system can be determined. This assessment and analysis process helps to understand the weaknesses and vulnerabilities in the network device system, thus providing data support for the subsequent processing process.
[0068] Preferably, step S16 includes the following steps:
[0069] Step S161: Identify and analyze network attack behaviors on the network security information data of the network device system to obtain the information data on the network security attack behaviors of the system;
[0070] In the embodiment of the present invention, by using technologies such as behavior rules and machine learning to perform behavior identification and analysis on the network security information data of the network device system, relevant data on network traffic, network security events, and network security vulnerability threats in the network security information data of the network device system are analyzed, and various possible attack behavior situations in the network device system are identified from them, such as behavior information data of malware, intrusion attempts, denial-of-service attacks, etc., and finally the information data on the network security attack behaviors of the system is obtained.
[0071] Step S162: Analyze the characteristics of the attacked behaviors on the information data of the network security attack behaviors of the system to obtain the characteristic data of the network security attack behaviors of the system;
[0072] In the embodiment of the present invention, by using relevant data mining and feature extraction methods to analyze and mine the information data of the network security attack behaviors of the system, the key characteristics of the attacked behaviors of the network device system are extracted, such as attack type, attack source, attack time, etc., and finally the characteristic data of the network security attack behaviors of the system is obtained.
[0073] Step S163: Statistically analyze the rules of the attacked behaviors on the characteristic data of the network security attack behaviors of the system to obtain the rule data of the network security attack behaviors of the system;
[0074] In the embodiment of the present invention, by using corresponding mathematical statistical analysis methods to statistically analyze the characteristic data of the network security attack behaviors of the system, the rules of the attacked behaviors are explored, including the distribution of attack types, the distribution of attack sources, the distribution of attack times, etc., and the frequencies, time periods, and targets of different types of attacks are identified from them, and finally the rule data of the network security attack behaviors of the system is obtained.
[0075] Step S164: Based on the rule data of the network security attack behaviors of the system, perform mining and analysis on the attack behavior sequence of the information data of the network security attack behaviors of the system to obtain the event sequence data of the network attacks on the system.
[0076] In the embodiment of the present invention, the method of sequence mining (such as frequent pattern mining, sequence clustering, etc.) is combined with the rule data of the network security attack behaviors of the system to analyze the information data of the network security attack behaviors of the system, so as to analyze the sequence patterns and rules of the attacked behaviors, and reveal the temporal patterns, attack links, and attack stages of the network attack behavior events on the network device system, and finally obtain the event sequence data of the network attacks on the system.
[0077] First, the present invention identifies and analyzes network attack behaviors on the network security information data of the network device system, aiming to identify the network security attack behavior situations in the system. By analyzing relevant data such as network traffic, network security events, and network security vulnerability threats, various possible attack behavior situations in the network device system can be detected, such as malware, intrusion attempts, denial-of-service attacks, etc. This identification and analysis of attack behaviors helps to timely discover potential security threats, so as to take corresponding security measures and countermeasures to ensure the stability and security of the system. Secondly, by analyzing the attack behavior information data of the system network security, the key features of the attack behaviors on the network device system are extracted. By analyzing the feature patterns, behavior rules, and abnormal features in the attack behavior data, these attack behavior feature data can help to automatically detect and identify newly emerging attack types in real-time monitoring and log analysis, thereby improving the network device system's ability to identify and respond to various network security attacks. Then, by statistically analyzing the attack behavior feature data of the system network security, the aim is to understand the rules and trends of the system's attack behaviors from a global perspective. By statistically analyzing the attack behavior feature data, the frequencies, time periods, and targets of different types of attacks can be identified, and the correlations and patterns between attack events can be discovered. This statistical analysis of rules can provide important reference information for subsequent processing processes and help to mine and analyze the event sequence situations of corresponding attack behaviors. Finally, by combining the attack behavior rule data of the system network security with the attack behavior information data of the system network security, the attack behavior sequence mining analysis is carried out. By mining the temporal relationships and interaction patterns in the attack behavior data, the event sequence of the system's network attack behaviors can be constructed. This serialized analysis can reveal the temporal patterns, attack links, and attack stages of the network device system being subjected to network attack behaviors, providing a deeper understanding and insight for subsequent processing processes. These attack behavior event sequence data can be used to further understand their attack target subjects and entity situations, thereby providing a data basis for the subsequent network security entity identification and analysis process.
[0078] Preferably, step S2 includes the following steps:
[0079] Step S21: Identify and analyze the ontology concepts of the network security information data of the network device system to obtain the system network security ontology concept information data;
[0080] In the embodiment of the present invention, natural language processing technology and ontology concept analysis method are used to analyze the text data in the network security information data of the network device system to identify the ontology concept information therein, such as network devices, network traffic, attack behaviors, etc., and finally obtain the system network security ontology concept information data.
[0081] Step S22: Perform network security ontology extraction processing on the network device system network security information data based on the system network security ontology concept information data to obtain the system network security ontology;
[0082] In the embodiment of the present invention, by combining the system network security ontology concept information data, the network security ontology information in the network device system network security information data is extracted and processed, so as to extract and extract the ontology information of the system network security from the original data, and finally obtain the system network security ontology.
[0083] Step S23: Perform ontology attack screening processing on the system network attacked behavior event sequence data based on the system network security ontology to obtain the network attacked behavior event sequence data of each system network security ontology;
[0084] In the embodiment of the present invention, by processing the system network attacked behavior event sequence data based on the system network security ontology, the network security event sequence of the entire system is filtered and screened according to the ontology-related rules and screening conditions, and the network security attacked behavior event sequence situation related to the network security ontology is extracted from the system network attacked behavior event sequence data. Finally, the network attacked behavior event sequence data of each system network security ontology is obtained, including the network security events corresponding to each system network security ontology in the system.
[0085] Step S24: Perform simulation analysis on the attacked process of the network attacked behavior event sequence data of each system network security ontology to obtain the network attacked behavior process information data of each system network security ontology;
[0086] In the embodiment of the present invention, by simulating and analyzing the network security attacked process of the network attacked behavior event sequence of each system network security ontology obtained by screening, the characteristics such as the attack mode, attack time interval, and attack behavior association relationship in the corresponding event sequence are analyzed, and the evolution process and possible attack paths of the attack behavior are understood. Finally, the network attacked behavior process information data of each system network security ontology is obtained.
[0087] Step S25: Perform entity matching and linking processing on the network device system network security information data based on the network attacked behavior process information data of each system network security ontology to obtain the network security linked entities of each system network security ontology.
[0088] In the embodiments of the present invention, data mining and machine learning technologies are used to analyze and mine the information data of the network attack behavior process of each system network security ontology, so as to identify the network security suspected entities corresponding to each system network security ontology during the network attack behavior process, including attackers, attacked systems or other entities related to network security. Then, natural language processing technologies, text mining, feature extraction and other technologies are used to analyze the network security suspected entities of each system network security ontology to extract the semantic features of the suspected entities, including the attributes, relationships and context information of the entities. Secondly, entity recognition methods are used to analyze the network security information data of the network device system to identify the entities of the entire system network security, including devices, users, application programs and other entities related to network security, and the identified system network security entities are analyzed to extract their semantic features, including device types, IP addresses, geographical locations, etc. Then, appropriate similarity calculation methods (such as cosine similarity, Euclidean distance, etc.) are used to perform matching calculations on the semantic features of the network security suspected entities and the semantic features of the system network security entities of each system network security ontology, so as to calculate and determine the similarity or correlation degree between the network security suspected entities and the system network security entities. At the same time, according to the calculated similarity degree, the matching relationship and connection between the network security suspected entities and the system network security entities are determined, and the actual matching link relationship between the ontology and the corresponding entities during the attack behavior process is established, so as to determine the actual entity situation associated with the system network security ontology, and finally obtain the network security link entities of each system network security ontology.
[0089] First, the present invention identifies and analyzes the ontology concept information of the network device system network security information data to identify the ontology concept information of the system network security. By performing semantic understanding and annotation on the text data of the network device system network security based on natural language processing technology, the network security-related concepts involved are identified and classified. Through this analysis process, an ontology concept library of the network device system network security can be established, clarifying the meanings and relationships of various network security concepts in the network device system. This helps to unify the understanding of concepts, improve the accuracy and consistency of network security information, and provide a basis for subsequent analysis and processing. Secondly, through the network security ontology extraction process of the network device system network security information data in combination with the system network security ontology concept information data, the purpose of this step is to extract and extract the ontology information of the system network security from the original data, making subsequent analysis and understanding more accurate and effective. Then, through the ontology attack screening process of the system network attacked behavior event sequence data in combination with the system network security ontology, the network security event sequence can be filtered and screened through ontology-related rules and screening conditions, and the network security attacked behavior events related to the network security ontology can be extracted from the system network attacked behavior event sequence data, so as to obtain the network attacked behavior event sequence data of each system network security ontology. This screening process helps to more accurately depict the network security events corresponding to each network security ontology in the system and filter out the attack behavior event data irrelevant to the network security of the corresponding network security ontology. Next, through the simulation analysis of the network attacked behavior event sequence data of each system network security ontology for the attacked process, by analyzing the characteristics such as patterns, time intervals, and correlation relationships in the corresponding event sequence, the evolution process and possible attack paths of the attack behavior can be understood. This attacked process simulation analysis helps to reveal the behavior patterns and strategies of the attackers of the corresponding network security ontology and provides the basic data guarantee for the subsequent entity recognition analysis process. Finally, through the entity matching and linking process of the network device system network security information data based on the network attacked behavior process information data of each system network security ontology, the entities corresponding in the network security information data can be matched, screened, and linked with the entities of each system network security ontology. By identifying and matching the entities in the network security information data with the suspected entities in the system network security ontology, the actual matching and linking relationship between the ontology and the corresponding entities during the attacked behavior process can be established. This entity matching and linking process helps to integrate and correlate the network security information in different data sources, provide more comprehensive and accurate network security linked entities, and provide richer information support for comprehensive analysis and decision-making.
[0090] Preferably, step S25 includes the following steps:
[0091] Step S251: Perform suspected entity recognition and analysis on the network attack behavior process information data of each system network security ontology to obtain the network security suspected entities of each system network security ontology;
[0092] In the embodiment of the present invention, data mining and machine learning techniques are used to analyze and mine the network attack behavior process information data of each system network security ontology, so as to identify the network security suspected entities corresponding to each system network security ontology during the network attack behavior process, including attackers, attacked systems, or other entities related to network security, and finally obtain the network security suspected entities of each system network security ontology.
[0093] Step S252: Perform semantic feature analysis on the network security suspected entities of each system network security ontology to obtain the network security suspected entity semantic feature data of each system network security ontology;
[0094] In the embodiment of the present invention, natural language processing techniques, text mining, feature extraction and other techniques are used to analyze the network security suspected entities of each system network security ontology, so as to extract the semantic features of the suspected entities, including the attributes, relationships and context information of the entities, and finally obtain the network security suspected entity semantic feature data of each system network security ontology.
[0095] Step S253: Perform network security entity recognition and analysis on the network device system network security information data to obtain system network security entities; perform semantic feature analysis on the system network security entities to obtain system network security entity semantic feature data;
[0096] In the embodiment of the present invention, entity recognition methods are used to analyze the network device system network security information data to identify the entities of the entire system network security, including devices, users, application programs and other entities related to network security, so as to obtain system network security entities. Then, natural language processing techniques, text mining, feature extraction and other techniques are used to analyze the system network security entities to extract their semantic features, including device types, IP addresses, geographical locations, etc., and finally obtain system network security entity semantic feature data.
[0097] Step S254: Perform entity semantic matching calculation on the network security suspected entity semantic feature data of each system network security ontology and the system network security entity semantic feature data to obtain the network security entity semantic matching index;
[0098] In an embodiment of the present invention, by using a suitable similarity calculation method (such as cosine similarity, Euclidean distance, etc.), the network security suspected entity semantic feature data and the system network security entity semantic feature data of each system network security ontology are matched and calculated to calculate and determine the similarity or correlation degree between the network security suspected entity and the system network security entity, and finally the network security entity semantic matching index is obtained.
[0099] Step S255: Based on the network security entity semantic matching index, entity matching link processing is performed on the network security suspected entities of each system network security ontology to obtain the network security linked entities of each system network security ontology.
[0100] In an embodiment of the present invention, the network security suspected entities of each system network security ontology are processed by using the calculated network security entity semantic matching index to determine the matching relationship and connection between the network security suspected entity and the system network security entity according to the size of the network security entity semantic matching index, and establish the actual matching link relationship between the ontology and the corresponding entity during the attack behavior process, so as to determine the actual entity situation associated with the system network security ontology, and finally obtain the network security linked entities of each system network security ontology.
[0101] The present invention first performs suspected entity recognition and analysis on the information data of the network attack behavior process of each system network security ontology to identify the network security suspected entities corresponding to each system network security ontology during the network attack behavior process. The key to this step is to be able to analyze and mine the information data of the network attack behavior process by using data mining and machine learning techniques to determine the corresponding potential suspected entities. These suspected entities may be attackers, attacked systems, or other entities related to network security. This analysis process helps to discover potential suspected entities related to system network security, thereby enhancing the understanding and perception ability of network attack behavior. Secondly, semantic feature analysis is performed on the network security suspected entities of each system network security ontology to further analyze the identified suspected entities, thereby extracting their semantic feature data. By using natural language processing and feature extraction techniques, the text descriptions and associated information of the suspected entities are analyzed to obtain the semantic features of the entities, such as the attributes, relationships, and context information of the entities. This semantic feature analysis helps to accurately describe the attributes and features of network security suspected entities and provides a basis for subsequent entity matching and linking. Then, network security entity recognition analysis is performed on the network security information data of the network device system to identify the entities of the entire system network security. By using data mining and pattern recognition techniques to analyze and process the network security information data of the system, the entities therein are determined. These entities can be devices, users, applications, and other entities related to network security. Through this analysis, the network security entities in the network device system can be accurately identified and characterized, and comprehensive and rich entity information can be provided. Next, entity semantic matching calculation is performed on the semantic feature data of the network security suspected entities and the semantic feature data of the system network security entities of each system network security ontology. The key to this step is to calculate the semantic similarity between entities by using a semantic matching algorithm, which can compare the semantic features of network security suspected entities and system network security entities, helping to determine the similarity and correlation degree between network security suspected entities and system network security entities, and providing a basis for weighing in subsequent entity matching and linking. Finally, entity matching and linking processing is performed on the network security suspected entities of each system network security ontology by combining the calculated network security entity semantic matching index. According to the size of the network security entity semantic matching index, the matching relationship and connection between network security suspected entities and system network security entities can be determined. This entity matching and linking processing helps to establish the association relationship between entities of each system network security ontology and provide accurate and complete network security linked entities.
[0102] Preferably, step S3 includes the following steps:
[0103] Step S31: Perform potential association inference analysis based on the system network security ontology and the network security link entities of each system network security ontology to obtain the potential association connection relationship between the system network security ontology and the link entities;
[0104] In the embodiment of the present invention, the association rule mining algorithm is used to analyze the system network security ontology and the network security link entities of each system network security ontology, so as to analyze the relevance and interaction between the system network security ontology and the link entities, and infer the connection relationship between them to reveal the hidden association and dependence relationship between the network security ontology and the link entities, and finally obtain the potential association connection relationship between the system network security ontology and the link entities.
[0105] Step S32: Perform knowledge base connection construction on the system network security ontology and the network security link entities of each system network security ontology according to the potential association connection relationship between the system network security ontology and the link entities to obtain a network security knowledge base;
[0106] In the embodiment of the present invention, the knowledge graph connection technology is used to perform connection construction on the system network security ontology and the network security link entities of each system network security ontology by combining the obtained potential association connection relationship between the system network security ontology and the link entities, so as to organically organize the network security ontology and the link entities together, thereby forming a knowledge graph or knowledge map of a complete network security knowledge base, and finally obtaining a network security knowledge base.
[0107] Step S33: Perform network security instance extraction processing on the network security knowledge base to obtain a network security instance set.
[0108] In the embodiment of the present invention, natural language processing and information extraction technologies are used to process the network security knowledge base to extract qualified instances from the network security knowledge base, including specific network attack cases, security vulnerability information, defense strategies or other practical examples related to network security, and finally obtain a network security instance set.
[0109] The present invention first performs potential association inference analysis by combining the system network security ontology and the network security link entities of each system network security ontology, which can analyze the relevance and interaction between the system network security ontology and the link entities, thereby inferring the potential association connection relationship between them. This inference analysis helps to reveal the hidden associations and dependencies between the network security ontology and the link entities, providing key clues for subsequent knowledge base construction and network security instance extraction. Then, according to the potential association connection relationship between the system network security ontology and the link entities, the knowledge base connection construction is carried out for the system network security ontology and the network security link entities of each system network security ontology. By establishing the connection relationship, the network security ontology and the link entities can be organically organized together to form a complete network security knowledge base. This knowledge base can be a graph database or a semantic network, used to store, manage, and query knowledge and information related to network security, providing comprehensive and fine-grained network security knowledge representation and access. Finally, through the network security instance extraction process on the network security knowledge base, the key to this step is to extract specific instances from the network security knowledge base by applying natural language processing and information extraction techniques. These instances can be specific network attack cases, security vulnerability information, defense strategies, or other practical examples related to network security. The obtained network security instance set helps to provide practical cases and examples for learning, training, and analysis, thus helping network security personnel better understand and respond to real network security threats and challenges.
[0110] Preferably, step S4 includes the following steps:
[0111] Step S41: Perform attribute extraction processing on the network security instance set to obtain a network security instance attribute set;
[0112] In the embodiment of the present invention, first, data cleaning and preprocessing are performed on the network security instance set to remove missing values, process outliers, etc. Then, through attribute extraction processing on the processed network security instance set, relevant attribute information is extracted from each network security instance, including but not limited to attack type, affected system, attacker's behavior pattern, etc., and finally a network security instance attribute set is obtained.
[0113] Step S42: Perform association mining analysis on the network security instance attribute set to obtain network security instance attribute association relationship data;
[0114] In the embodiments of the present invention, each network security instance attribute in the network security instance attribute set is analyzed by using corresponding association mining algorithms (such as Apriori algorithm, FP-growth algorithm, etc.), screened according to the support degree and confidence degree of association rules, and the relevance between each network security instance attribute is analyzed to determine the dependency relationship and correlation between each network security instance attribute, and finally the network security instance attribute association relationship data is obtained.
[0115] Step S43: Perform potential relationship pattern recognition analysis on the network security instance attribute set to obtain network security instance attribute potential relationship pattern data; perform target variable requirement prediction analysis on the network security instance attribute set based on the network security instance attribute potential relationship pattern data to obtain network security instance attribute target variable requirement data;
[0116] In the embodiments of the present invention, the network security instance attribute set is analyzed by using corresponding potential relationship pattern recognition algorithms (such as latent semantic analysis (LSA), topic model (such as LDA), etc.) to identify the potential relationship patterns between each network security instance attribute, that is, the semantic, topic or pattern information hidden in the attribute set, and understand the mutual dependence and influence between different network security instance attributes, so as to obtain the network security instance attribute potential relationship pattern data. Then, the target variable requirement prediction analysis is performed on the network security instance attribute set by combining the obtained network security instance attribute potential relationship pattern data to predict the target variable requirements of the network security instance, such as predicting future attack trends or potential vulnerability and other requirement information, and finally the network security instance attribute target variable requirement data is obtained.
[0117] Step S44: Perform attribute pair value deduction processing on the network security instance attribute set by using the attribute deduction algorithm based on the network security instance attribute association relationship data and the network security instance attribute target variable requirement data to obtain the network security instance attribute pair value;
[0118] In the embodiments of the present invention, first, each existing attribute pair value in the network security instance attribute set is statistically analyzed by using mathematical statistical methods to analyze the value range, distribution, and common attribute combination of each known attribute pair value, that is, each network security instance attribute and its corresponding value, and by combining the association relationship between each network security instance attribute in the network security instance attribute association relationship data and the network security instance attribute target variable requirement data, an appropriate attribute deduction algorithm (such as decision tree, neural network, etc.) is applied to construct an attribute deduction mathematical model, and the known attribute pair values of the network security instance are speculated and predicted by the attribute deduction mathematical model to speculate the missing or newly optimized attribute pair values in the network security instance, and finally the network security instance attribute pair value is obtained.
[0119] Step S45: Based on the network security instance attribute pairs, perform knowledge relationship optimization analysis on the network security instance set to obtain the optimized connection relationship of network security instance knowledge;
[0120] In the embodiment of the present invention, first, the network security instance set is analyzed by using the knowledge relationship analysis method to analyze the attributes and other associated information among network security instances (including specific network attack cases, security vulnerability information, defense strategies, etc.), and predict the knowledge connection relationship among them. At the same time, the predicted connection relationship of network security instance knowledge analyzed is analyzed by using the knowledge graph algorithm or path reasoning algorithm to find and discover the reachable paths among network security instances. Secondly, by combining the network security instance attribute pairs, the path metric statistical method is used to statistically calculate the length of the reachable paths analyzed to quantitatively analyze the length values of the reachable paths. Then, by judging and analyzing the length values of each reachable path, it is determined which reachable paths corresponding to the predicted connection relationship of network security instance knowledge are shorter and reliable, and which reachable paths are longer or unreliable. And the predicted connection relationship of network security instance knowledge is optimized according to the analysis results, including deleting redundant paths, adding missing paths, etc., to screen out more reliable and effective connection relationships, and finally obtain the optimized connection relationship of network security instance knowledge.
[0121] Step S46: According to the optimized connection relationship of network security instance knowledge, perform knowledge relationship update processing on the network security knowledge base to generate a network security knowledge update library.
[0122] In the embodiment of the present invention, according to the updated and optimized connection relationship of network security instance knowledge, the corresponding knowledge relationship in the network security knowledge base is updated to apply the optimized knowledge relationship to the network security knowledge base, so as to better reflect the attribute pairs and knowledge optimized connection relationship of network security instances, and provide the latest network security knowledge and relevant information of attribute pairs, and finally generate a network security knowledge update library.
[0123] First, the present invention processes the attribute extraction of the network security instance set, aiming to extract relevant attribute information from each network security instance, including but not limited to attack types, affected systems, attacker behavior patterns, etc. Such a processing process can transform network security instances into structured attribute sets, facilitating subsequent analysis and mining. At the same time, through the association mining analysis of the network security instance attribute set, it aims to discover the association relationships between the attributes of each network security instance. By applying association analysis algorithms, it is possible to find the attribute combinations that appear simultaneously in network security instances, revealing the potential association relationships between different attributes. This helps to understand the mutual dependence and influence between different attributes and provides a basis for subsequent analysis. Secondly, through the potential relationship pattern recognition analysis of the network security instance attribute set, it aims to identify the potential relationship patterns existing in the attribute set. Through clustering, classification, or other machine learning methods, similar attributes can be grouped to identify the patterns and rules between attributes. And by combining the data of the potential relationship patterns of network security instance attributes, a target variable demand prediction analysis is carried out on the network security instance attribute set to predict the target variable demands of network security instances, such as predicting future attack trends or potential vulnerabilities. Then, through the attribute pair value deduction process of the network security instance attribute set using the attribute deduction algorithm based on the network security instance attribute association relationship data and the network security instance attribute target variable demand data, an inference model between network security instance attributes can be established to infer the missing or newly optimized attribute pair values of network security instance attributes, thus filling the gaps in the attribute set. This helps to improve the attribute set and enhance the accuracy and comprehensiveness of subsequent analysis. Next, through the knowledge relationship optimization analysis of the network security instance set by combining the network security instance attribute pair values, by analyzing the relationships and patterns between attribute values, it is possible to discover the dependencies, similarities, or other associations between attributes and optimize these relationships into more accurate and useful knowledge associations. This helps to better understand the knowledge in the network security instance set and improve the understandability and applicability of knowledge. Finally, through the knowledge relationship update process of the network security knowledge base according to the optimized connection relationship of network security instance knowledge, a network security knowledge update library is generated. By applying the optimized knowledge relationships to the knowledge base, the knowledge associations in the knowledge base can be updated and improved, enhancing the accuracy and practicality of the knowledge base. In this way, a more comprehensive and accurate network security knowledge update library can be generated, providing better support for network security decision-making and practice, and thus meeting the rapid update of network security knowledge.
[0124] Preferably, step S44 includes the following steps:
[0125] Step S441: Perform a statistical calculation on the existing attribute pair values of the network security instance attribute set to obtain the existing attribute pair values of the network security instance;
[0126] In the embodiment of the present invention, statistical analysis is performed on each existing attribute pair value in the network security instance attribute set by using mathematical statistical methods to analyze the value range, distribution, and common attribute combination situations of each known attribute pair value, that is, each network security instance attribute and its corresponding value situation, and finally the existing attribute pair values of the network security instance are obtained.
[0127] Step S442: Perform statistical analysis on the attribute pair value deduction rules of the network security instance attribute set based on the network security instance attribute association relationship data to obtain the network security instance attribute pair value deduction rule data;
[0128] In the embodiment of the present invention, the association relationship between each network security instance attribute in the network security instance attribute association relationship data is combined to analyze the corresponding existing attribute pair values in the network security instance attribute set to reveal the deduction rules and correlations between each network security instance attribute. For example, it is observed that the change of certain attribute pair values will follow the change rules of other attribute pair values, and finally the network security instance attribute pair value deduction rule data is obtained.
[0129] Step S443: Perform feature engineering processing on the network security instance attribute target variable requirement data to obtain the network security instance attribute target pair value deduction feature data;
[0130] In the embodiment of the present invention, the network security instance attribute target variable requirement data is processed by using feature engineering methods (including processing steps such as feature extraction, dimensionality reduction, and construction of new features) to extract features that can better describe the target pair value features and patterns, and extract the corresponding feature vectors to describe the deduction relationship and rules between the network security instance attribute target pair values and other information, and finally the network security instance attribute target pair value deduction feature data is obtained.
[0131] Step S444: Perform attribute pair value deduction processing on the existing attribute pair values of the network security instance by using the attribute deduction algorithm based on the network security instance attribute pair value deduction rule data and the network security instance attribute target pair value deduction feature data to obtain the network security instance attribute pair values.
[0132] In the embodiment of the present invention, an attribute deduction mathematical model is constructed by using the attribute deduction algorithm in combination with the network security instance attribute pair value deduction rule data and the network security instance attribute target pair value deduction feature data, and according to the deduction rules of the known attribute pair values and the deduction requirement feature data of the target pair values through the attribute deduction mathematical model, the missing or newly optimized attribute pair values in the network security instance are inferred, and finally the network security instance attribute pair values are obtained.
[0133] First, by statistically analyzing the existing attribute-value pairs of the network security instance attribute set, the present invention can understand the value ranges, distributions, and common attribute combinations of each known attribute-value pair. This helps to deeply understand the existing attributes of the network security instance and provides a basis for subsequent attribute deduction and analysis. Second, by statistically analyzing the deduction rules of attribute-value pairs of the network security instance attribute set based on the network security instance attribute correlation relationship data, this step can reveal the deduction rules and correlations between attributes by using statistical analysis methods. For example, it can be observed that the change of certain attribute values is accompanied by the change of other attribute values, so as to discover potential attribute deduction rules and provide guidance and basis for subsequent attribute deduction algorithms. Then, by performing feature engineering on the network security instance attribute target variable requirement data to obtain the feature data for the deduction of the network security instance attribute target-value pair, feature engineering is to transform and integrate the original data to extract features that can better describe the characteristics and patterns of the target-value pair. By performing feature engineering on the target variable requirement data, feature vectors can be extracted to describe information such as the relationships between attributes and the combined characteristics of attributes, thereby providing more expressive feature data for the deduction of attribute-value pairs. Finally, by using the attribute deduction algorithm based on the network security instance attribute-value pair deduction rule data and the network security instance attribute target-value pair deduction feature data to perform deduction processing on the existing attribute-value pairs of the network security instance, this attribute deduction algorithm can infer the missing or newly optimized attribute-value pairs in the network security instance according to the known attribute values and deduction rule data. This deduction processing process can be analyzed and predicted based on the existing attribute correlation relationships and feature data, combined with statistical models or machine learning methods, so as to provide more complete and accurate attribute-value pairs for the network security instance.
[0134] Preferably, step S45 includes the following steps:
[0135] Step S451: Perform knowledge relationship prediction analysis on the network security instance set to obtain the network security instance knowledge prediction connection relationship;
[0136] In the embodiment of the present invention, the network security instance set is analyzed by using the knowledge relationship analysis method to analyze the attributes and other correlation information between network security instances (including specific network attack cases, security vulnerability information, and defense strategies, etc.), and predict the knowledge connection relationship between them, and finally obtain the network security instance knowledge prediction connection relationship.
[0137] Step S452: Perform path reasoning analysis on the network security instance knowledge prediction connection relationship to obtain the network security instance knowledge prediction relationship reachable path;
[0138] In the embodiments of the present invention, the predicted connection relationships of network security instance knowledge analyzed are analyzed by using a knowledge graph algorithm or a path reasoning algorithm to find and discover the reachable paths between network security instances, so as to represent the possible knowledge transfer relationships between network security instances, and to help reveal the knowledge flow and transformation process between network security instances, and finally obtain the reachable paths of the predicted relationships of network security instance knowledge.
[0139] Step S453: Based on the network security instance attributes, perform path length statistical calculation on the reachable paths of the predicted relationships of network security instance knowledge to obtain the reachable path length value of the predicted relationships of instance knowledge.
[0140] In the embodiments of the present invention, by combining the network security instance attributes, the path metric statistical method is used to perform statistical calculation on the lengths of the reachable paths of the predicted relationships of network security instance knowledge, so as to analyze the reachable path length values of the predicted relationships of network security instances, and finally obtain the reachable path length value of the predicted relationships of instance knowledge.
[0141] Step S454: Based on the reachable path length value of the predicted relationships of instance knowledge, perform knowledge relationship optimization analysis on the predicted connection relationships of network security instance knowledge to obtain the optimized connection relationships of network security instance knowledge.
[0142] In the embodiments of the present invention, by judging and analyzing the reachable path length values of the predicted relationships of instance knowledge for each reachable path, it is determined which reachable paths corresponding to the predicted connection relationships of network security instance knowledge are shorter and reliable, and which reachable paths are longer or unreliable, and the predicted connection relationships of network security instance knowledge are optimized according to the analysis results, including deleting redundant paths, adding missing paths, etc., so as to screen out more reliable and effective connection relationships, and finally obtain the optimized connection relationships of network security instance knowledge.
[0143] First, through the knowledge relationship prediction and analysis of the network security instance set, the present invention can analyze the attributes and other associated information among network security instances (including specific network attack cases, security vulnerability information, and defense strategies, etc.), thereby predicting the knowledge connection relationships among them. In this way, the potential associations and similarities among instances can be discovered, providing a basis for subsequent path reasoning and knowledge optimization. Secondly, through the path reasoning analysis of the knowledge prediction connection relationships of network security instances, the reachable paths of the knowledge prediction relationships among network security instances can be discovered by applying path reasoning algorithms. These reachable paths represent the possible knowledge transfer relationships among network security instances, which can help reveal the knowledge flow and transformation process among network security instances, providing a basis for subsequent path length statistics and knowledge optimization. Then, by combining the network security instance attribute value pairs, the path length statistics calculation of the reachable paths of the network security instance knowledge prediction relationships is performed. In this way, the length values of the reachable paths of the knowledge prediction relationships among network security instances can be analyzed, and the complexity and distance of different paths can also be understood. This helps to evaluate the reliability and prediction performance of the paths, providing a basis for subsequent knowledge optimization analysis. Finally, through the knowledge relationship optimization analysis of the network security instance knowledge prediction connection relationships by combining the reachable path length values of the instance knowledge prediction relationships, the key to this step is to be able to judge which paths are shorter and reliable and which paths are longer or unreliable according to the path length values. In this way, the knowledge connection relationships can be optimized, so as to screen out more reliable and effective connection relationships and improve the accuracy and efficiency of knowledge transfer.
[0144] Therefore, from any perspective, the embodiments should be regarded as exemplary and non-limiting. The scope of the present invention is defined by the appended claims rather than the above description. Therefore, it is intended to embrace all changes within the meaning and scope of the equivalent elements of the application documents in the present invention.
[0145] The above are only the specific embodiments of the present invention, enabling those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be obvious to those skilled in the art. The general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but rather to the broadest scope consistent with the principles and novel features invented herein.
Claims
1. A method for constructing a knowledge base for network security, characterized in that: The following steps are involved: Step S1: obtaining a network device system log file, and performing network security data collection and processing on the network device system log file to obtain network device system network security information data; Perform attack behavior sequence mining and analysis on network equipment system network security information data to obtain system network attack behavior event sequence data; step S1 includes the following steps: Step S11: Obtaining a network device system log file; Step S12: Perform file abnormality screening on the network device system log file to obtain a network device system log abnormality file; Step S13: Perform network security event identification and analysis on the abnormal log file of the network device system to obtain network security event information data; perform malicious code sample extraction processing on the abnormal log file of the network device system to obtain network device system malicious code sample information data; Step S14: Based on the network device system malicious code sample information data, a network vulnerability threat assessment analysis is performed on the network device system log abnormal file to obtain network security vulnerability threat information data; Step S14 includes the following steps: Step S141: performing code behavior analysis on the network device system malicious code sample information data to obtain the network device system malicious code behavior information data; Step S142: extracting behavior characteristics from the network device system malicious code behavior information data to obtain network device system malicious code behavior characteristic data; Step S143: performing network security vulnerability prediction analysis on abnormal log files of the network device system based on the network device system malicious code behavior feature data to obtain network security vulnerability status data of the network device system; Step S144: Performing a network vulnerability threat assessment analysis on the network security vulnerability status data of the network device system to obtain network security vulnerability threat information data; Step S15: merging the network security event information data and the network security vulnerability threat information data to obtain network device system network security information data; Step S16: performing attack behavior sequence mining analysis on the network device system network security information data to obtain system network attack behavior event sequence data; Step S16 includes the following steps: Step S161: Perform network attack behavior identification analysis on the network device system network security information data to obtain system network security attack behavior information data; Step S162: Analyze the attack behavior characteristics of the system network security attack behavior information data to obtain the system network security attack behavior characteristic data; Step S163: Performing statistical analysis on the attack behavior pattern of the system network security attack behavior feature data to obtain the system network security attack behavior pattern data; Step S164: performing attack behavior sequence mining analysis on the system network security attack behavior information data based on the system network security attack behavior law data to obtain the system network attack behavior event sequence data; Step S2: Perform network security ontology extraction processing on the network device system network security information data to obtain the system network security ontology; perform entity matching and link processing on the network device system network security information data based on the system network attack behavior event sequence data and the system network security ontology to obtain the network security link entity of each system network security ontology; Step S3: construct a knowledge base connection based on the system network security ontology and the network security link entities of each system network security ontology to obtain a network security knowledge base; extract network security instances from the network security knowledge base to obtain a network security instance set; Step S4: perform attribute pair value deduction processing on the network security instance set to obtain network security instance attribute pair values; perform knowledge relationship optimization analysis on the network security instance set based on the network security instance attribute pair values to obtain network security instance knowledge optimization connection relationship; perform knowledge relationship update processing on the network security knowledge base according to the network security instance knowledge optimization connection relationship to generate a network security knowledge update library.
2. The method for constructing a network security-oriented knowledge base according to claim 1, characterized in that: Step S2 includes the following steps: Step S21: Performing ontology concept recognition analysis on the network device system network security information data to obtain system network security ontology concept information data; Step S22: performing network security ontology extraction processing on the network device system network security information data based on the system network security ontology concept information data to obtain the system network security ontology; Step S23: Based on the system network security ontology, the system network attack behavior event sequence data is subjected to ontology attack screening processing to obtain the network attack behavior event sequence data of each system network security ontology; Step S24: performing attack process simulation analysis on the network attack behavior event sequence data of each system network security entity to obtain network attack behavior process information data of each system network security entity; Step S25: Based on the network attack behavior process information data of each system network security ontology, the network device system network security information data is subjected to entity matching and linking processing to obtain the network security link entity of each system network security ontology.
3. The method for constructing a network security-oriented knowledge base according to claim 2, characterized in that: Step S25 includes the following steps: Step S251: performing suspected entity recognition analysis on the network attack behavior process information data of each system network security entity to obtain the network security suspected entity of each system network security entity; Step S252: Perform semantic feature analysis on the suspected network security entities of each system network security ontology to obtain semantic feature data of the suspected network security entities of each system network security ontology; Step S253: Perform network security entity recognition analysis on the network device system network security information data to obtain a system network security entity; perform semantic feature analysis on the system network security entity to obtain system network security entity semantic feature data; Step S254: performing entity semantic matching calculation on the network security suspected entity semantic feature data of each system network security ontology and the system network security entity semantic feature data to obtain a network security entity semantic matching index; Step S255: Perform entity matching and linking processing on the network security suspected entities of each system network security ontology based on the network security entity semantic matching index to obtain the network security link entities of each system network security ontology.
4. The method for constructing a network security-oriented knowledge base according to claim 1, characterized in that: Step S3 includes the following steps: Step S31: Perform potential association inference analysis based on the system network security ontology and the network security link entities of each system network security ontology to obtain a potential association connection relationship between the system network security ontology and the link entity; Step S32: constructing a knowledge base connection for the system network security ontology and the network security link entities of each system network security ontology according to the potential association connection relationship between the system network security ontology and the link entity, to obtain a network security knowledge base; Step S33: extract network security instances from the network security knowledge base to obtain a network security instance set.
5. The method for constructing a network security-oriented knowledge base according to claim 1, characterized in that: Step S4 includes the following steps: Step S41: extracting attributes from the network security instance set to obtain a network security instance attribute set; Step S42: performing association mining analysis on the network security instance attribute set to obtain network security instance attribute association relationship data; Step S43: performing potential relationship pattern recognition analysis on the network security instance attribute set to obtain network security instance attribute potential relationship pattern data; performing target variable demand forecasting analysis on the network security instance attribute set based on the network security instance attribute potential relationship pattern data to obtain network security instance attribute target variable demand data; Step S44: performing attribute pair value deduction processing on the network security instance attribute set using an attribute deduction algorithm based on the network security instance attribute association relationship data and the network security instance attribute target variable requirement data to obtain the network security instance attribute pair value; Step S45: performing knowledge relationship optimization analysis on the network security instance set based on the network security instance attribute pair values to obtain the network security instance knowledge optimization connection relationship; Step S46: performing knowledge relationship update processing on the network security knowledge base according to the network security instance knowledge optimization connection relationship to generate a network security knowledge update base.
6. The method for constructing a network security-oriented knowledge base according to claim 5, characterized in that: Step S44 includes the following steps: Step S441: performing statistical calculation on existing attribute pairs of the network security instance attribute set to obtain existing attribute pairs of the network security instance; Step S442: performing attribute pair value deduction law statistical analysis on the network security instance attribute set based on the network security instance attribute association relationship data to obtain network security instance attribute pair value deduction law data; Step S443: performing feature engineering processing on the network security instance attribute target variable demand data to obtain network security instance attribute target pair value deduction feature data; Step S444: Based on the network security instance attribute pair value deduction rule data and the network security instance attribute target pair value deduction feature data, an attribute deduction algorithm is used to perform attribute pair value deduction processing on the existing attribute pair values of the network security instance to obtain the network security instance attribute pair values.
7. The method for constructing a network security-oriented knowledge base according to claim 6, characterized in that: Step S45 includes the following steps: Step S451: performing knowledge relationship prediction analysis on the network security instance set to obtain network security instance knowledge prediction connection relationship; Step S452: Perform path reasoning analysis on the network security instance knowledge prediction connection relationship to obtain a reachable path of the network security instance knowledge prediction relationship; Step S453: performing path length statistics calculation on the reachable path of the network security instance knowledge prediction relationship based on the network security instance attribute pair value, and obtaining the reachable path length value of the instance knowledge prediction relationship; Step S454: Based on the reachable path length value of the instance knowledge prediction relationship, a knowledge relationship optimization analysis is performed on the network security instance knowledge prediction connection relationship to obtain the network security instance knowledge optimization connection relationship.
Citation Information
Cited By
Intelligent seaport-oriented AI knowledge base construction method and system
CN120973959A
An AI knowledge base construction method and system for a smart seaport
CN120973959B