A monitoring system for information network engineering supervision
By collecting and calculating network data, generating network information security index and performing real-time comparison, the problem of inability to detect network information security index in the prior art is solved, and the security and privacy of the information network engineering monitoring system is improved.
Patent Information
- Application Number
- CN202410888536.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-04
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2044-07-04
AI Technical Summary
The existing information network engineering monitoring system cannot detect network information security index in real time, resulting in information leakage and system security reduction.
The data acquisition module collects network traffic, device status, performance and security event data. The information processing module calculates data transmission rate changes, device load, failure rate, bandwidth utilization rate and intrusion frequency, generates network information security index, and compares it with the internal standard index, generates risk reports and transmits them to the remote monitoring module for real-time early warning.
Real-time detection and early warning of network intrusion risks is realized, the security of the system and the privacy of information are improved, and the security of information network engineering is ensured.
Smart Images

Figure CN118611979B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of information network management, and particularly to a monitoring system for information network project supervision. Background Art
[0002] A monitoring system for information network project supervision is a system used to monitor, manage, and control the construction and operation status of information network projects. Such a monitoring system usually includes various sensors, monitoring devices, data acquisition and processing devices, and related software systems. The system can monitor the construction of the project and the operation of equipment in real time, discover problems in a timely manner and issue alarms, which helps to avoid potential risks and respond quickly to abnormal situations. At the same time, the monitoring system can monitor resource conditions such as energy consumption and equipment utilization rate, help achieve effective management of resources, energy conservation and emission reduction, and improve the sustainability of the project.
[0003] At present, most monitoring systems for information network project supervision do not detect the network information security index in real time. Therefore, when a network intrusion occurs in the monitoring system, there is no way to detect it, resulting in information leakage and a reduction in the security of the monitoring system. Summary of the Invention
[0004] (1) Technical Problems to be Solved
[0005] In view of the deficiencies of the prior art, the present invention provides a monitoring system for information network project supervision, which has the advantages of collecting network traffic data Wlsj, network device status data Wlsb, network performance data Wlxn, security event data Aqsj, and application layer data Ycsj through a data acquisition module. The information processing module calculates the change index Cszs of the data transmission rate, the network device load Wbfz, the equipment failure rate Gzsb, the bandwidth utilization rate Dkly, and the network intrusion frequency Wlrq according to the above data through a formula, and calculates the network information security index Wazs according to the obtained values above and transmits it to the information warning module. The information warning module compares the network information security index Wazs with the network security standard index Wlbz set internally, analyzes the network intrusion risk, and generates a risk information report and transmits it to the remote monitoring module. The remote monitoring module displays the received risk information report on the monitoring interface. By calculating the network information security index and making a risk comparison, anomalies are discovered and warnings are issued in a timely manner, and maintenance measures are taken to ensure the privacy of information and improve the security of the system, etc., and solves the above problems.
[0006] (2) Technical Solutions
[0007] To achieve the above object, the present invention provides the following technical solution: A monitoring system for information network project supervision, including a data acquisition module, an information processing module, an information warning module, and a remote monitoring module;
[0008] The data acquisition module is used to collect network traffic data Wlsj, network device status data Wlsb, network performance data Wlxn, security event data Aqsj, and application layer data Ycsj, and transmit the above collected data to the information processing module through the network;
[0009] The information processing module calculates the change index Cszs of the data transmission rate, the network device load Wbfz, the device failure rate Gzsb, the bandwidth utilization rate Dkly, and the network intrusion frequency Wlrq according to the data transmitted by the data acquisition module, and calculates the network information security index Wazs based on the above calculated values and transmits it to the information warning module;
[0010] The information warning module internally sets the network security standard index Wlbz, and analyzes the network intrusion risk by comparing it with the network information security index Wazs and generates a risk information report and transmits it to the remote monitoring module;
[0011] The remote monitoring module displays the received risk information report on the monitoring interface.
[0012] Preferably, the data acquisition module incorporates the collected network traffic data into a data set, and this data set is {Wlsj n-9 , Wlsj n-8 , Wlsj n-7 , Wlsj n-6 ,..., Wlsj n}, and the data acquisition module incorporates the collected network device status data into a data set, and this data set is {Wlsb n-9 , Wlsb n-8 , Wlsb n-7 , Wlsb n-6 ,..., Wlsb n}.
[0013] Preferably, the data acquisition module incorporates the collected network performance data into a data set, and this data set is {Wlxn n-9 , Wlxn n-8 , Wlxn n-7 , Wlxn n-6 ,..., Wlxn n}, and the data acquisition module incorporates the collected security event data into a data set, and this data set is {Aqsj n-9 , Aqsj n-8 , Aqsj n-7 , Aqsj n-6 ,..., Aqsj n}, the data acquisition module incorporates the collected application layer data into a data set, and this data set is {Ycsj n-9 , Ycsj n-8 , Ycsj n-7 , Ycsj n-6 ,..., Ycsj n}.
[0014] Preferably, based on the data transmitted by the data acquisition module, the information processing module calculates the change index Cszs of the data transmission rate through a formula, and the calculation formula is as follows:
[0015]
[0016] In the formula, Cszs represents the change index of the data transmission rate, n represents the number of time points, and v i represents the corresponding data transmission rate at time point t i , and t i represents the i-th time point.
[0017] Preferably, based on the data transmitted by the data acquisition module, the information processing module calculates the network device load Wbfz through a formula, and the calculation formula is as follows:
[0018]
[0019] In the formula, Wbfz represents the network device load, Sjcl represents the actual data processing capacity, Pbdx represents the average packet size, Zddk represents the maximum supported bandwidth, and the above values can be obtained through system background detection. Cszs represents the change index of the data transmission rate.
[0020] Preferably, based on the data transmitted by the data acquisition module, the information processing module calculates the device failure rate Gzsb through a formula, and the calculation formula is as follows:
[0021] Gzsb = 1 - e -λt
[0022] In the formula, Gzsb represents the device failure rate, λ represents the parameter of the device failure rate, t is the specified time length, indicating whether an event occurs during this period, e is the base of the natural logarithm, with a value of 2.71828, and e -λt represents the probability that the event does not occur within the time period t, that is, the expression of the exponential distribution function of the event not occurring. Therefore, 1 - e -λt represents the probability that the event occurs within the time period t, that is, the probability that the event occurs at least once during this period.
[0023] Preferably, the information processing module calculates the bandwidth utilization rate Dkly according to the data transmitted by the data acquisition module through the following formula:
[0024]
[0025] In the formula, Dkly represents the bandwidth utilization rate, Pb represents the packet arrival rate, C represents the server item of the system, MQ represents the processing rate of the system, C! represents the factorial of C, represents the C-th power of the packet arrival rate PB divided by the factorial of C, represents the ratio of the difference between the processing rate MQ of the system and the arrival rate PB to the processing rate.
[0026] Preferably, for a monitoring system for information network engineering supervision according to claim 7, wherein: the information processing module calculates the network intrusion frequency Wlrq according to the data transmitted by the data acquisition module through the following formula:
[0027] Wlrq = P(adex) * P(bpre) * P(cmos)
[0028] In the formula, Wlrq represents the network intrusion frequency, P(adex) represents the probability of an attack event occurring, P(bpre) represents the probability of vulnerabilities existing in the system, P(cmos) represents the probability that the attack is not detected, and the above probabilities are obtained through penetration testing and vulnerability scanning.
[0029] Preferably, the information processing module calculates the network information security index Wazs according to the change index Cszs of the data transmission rate, the network device load Wbfz, the device failure rate Gzsb, the bandwidth utilization rate Dkly, and the network intrusion frequency Wlrq, and the calculation formula is as follows:
[0030] Wazs = (1 - Cszs) * (1 - Wbfz) * (1 - Gzsb) * (1 - Dkly) * (1 - Wlrq)
[0031] In the formula, Wazs represents the network information security index, Cszs represents the change index of the data transmission rate, Wbfz represents the network device load, Gzsb represents the device failure rate, Dkly represents the bandwidth utilization rate, and Wlrq represents the network intrusion frequency. In this formula, the value range of each factor is between 0 and 1, indicating the quality of the future network security state. A high value indicates strong security, while a low value indicates potential security risks.
[0032] Preferably, the network security standard index Wlbz is set inside the information warning module, and the comparison is made with the network information security index Wazs as follows:
[0033] When the network information security index Wazs is less than the network security standard index Wlbz, it indicates that there is an information security risk at this time;
[0034] When the network information security index Wazs is greater than or equal to the network security standard index Wlbz, it indicates that the system security level is high and there is no information security risk at this time.
[0035] Compared with the prior art, the present invention provides a monitoring system for information network engineering supervision, which has the following beneficial effects:
[0036] The present invention collects network traffic data Wlsj, network device status data Wlsb, network performance data Wlxn, security event data Aqsj, and application layer data Ycsj through a data collection module. The information processing module calculates the change index Cszs of the data transmission rate, the network device load Wbfz, the device failure rate Gzsb, the bandwidth utilization rate Dkly, and the network intrusion frequency Wlrq according to the above data through a formula, and calculates the network information security index Wazs based on the obtained values above and transmits it to the information warning module. The information warning module compares the network information security index Wazs with the network security standard index Wlbz set internally, analyzes the network intrusion risk and generates a risk information report and transmits it to the remote monitoring module. The remote monitoring module displays the received risk information report on the monitoring interface. By calculating the network information security index and conducting risk comparison, anomalies are discovered and early warnings are issued in a timely manner, and maintenance measures are taken to ensure the privacy of information and improve the security of the system. Brief Description of the Drawings
[0037] Figure 1 It is a schematic diagram of the system flow of the present invention. Detailed Embodiments
[0038] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0039] In view of the problem that most current monitoring systems do not detect the network information security index, there will be a risk of information leakage, resulting in a reduction in the security of the system. For this reason, a monitoring system for information network engineering supervision is proposed. Please refer to Figure 1 This system includes a data collection module, an information processing module, an information warning module, and a remote monitoring module, where:
[0040] The data acquisition module incorporates the collected network traffic data into a data set, which is {Wlsj n-9 ,Wlsj n-8 ,Wlsj n-7 ,Wlsj n-6 ,...,Wlsj n}, incorporates the collected network device status data into a data set, which is {Wlsb n-9 ,Wlsb n-8 ,Wlsb n-7 ,Wlsb n-6 ,...,Wlsb n}, incorporates the collected network performance data into a data set, which is {Wlxn n-9 ,Wlxn n-8 ,Wlxn n-7 ,Wlxn n-6 ,...,Wlxn n}, incorporates the collected security event data into a data set, which is {Aqsj n-9 ,Aqsj n-8 ,Aqsj n-7 ,Aqsj n-6 ,...,Aqsj n}, incorporates the collected application layer data into a data set, which is {Ycsj n-9 ,Ycsj n-8 ,Ycsj n-7 ,Ycsj n-6 ,...,Ycsj n}. Each data set contains ten data, and these collected data are the reference basis for the data analysis module to calculate;
[0041] The data analysis module calculates the change index Cszs of the data transmission rate, the network device load Wbfz, the device failure rate Gzsb, the bandwidth utilization rate Dkly, and the network intrusion frequency Wlrq according to the relevant data in the above data sets, where:
[0042] Calculation formula for the change index of the data transmission rate:
[0043]
[0044] By calculating the change index of the data transmission rate, the trend change of the data transmission rate can be analyzed to understand whether the rate is increasing, decreasing, or remaining stable, helping the supervision personnel understand the operating status of the system. In the formula, Cszs represents the change index of the data transmission rate, n represents the number of time points, and v i represents at time point t iThe corresponding data transfer rate, t i Represents the i-th time point. This formula evaluates the overall rate change by calculating the sum of the logarithms of the rate changes between each data point, t i -t i-1 Represents the time interval between the i-th data point and the previous data point, that is, the time difference between two data points, and represents the logarithm of the ratio between the rate of the previous data point and the rate of the current data point The rate ratio here represents the relative change in rate. The role of the logarithmic function is to unify changes of different magnitudes into exponents for easy comparison. The summation symbol in the formula indicates the accumulation of the logarithms of the rate changes between all data points, resulting in a comprehensive evaluation index used to measure the change in the overall data transfer rate. This index can help monitoring personnel more comprehensively understand the fluctuations in the data transfer rate and provide a reference for evaluating and optimizing system performance
[0045] Calculation formula for network device load:
[0046]
[0047] By monitoring and calculating the load of network devices, the current working condition of the devices can be understood, and situations of too high or too low load can be discovered in a timely manner, so as to adjust the device configuration in a timely manner and optimize the performance. In the formula, Wbfz represents the network device load, Sjcl represents the actual data processing capacity, Pbdx represents the average packet size, Zddk represents the maximum supported bandwidth, and the above values can be obtained through system background detection. Cszs represents the change index of the data transfer rate. By calculating and optimizing the network device load, the stability and performance of the network can be improved, the user experience in the network can be enhanced, and the situations of latency and data loss can be reduced
[0048] Calculation formula for device failure rate:
[0049] Gzsb = 1 - e -λt
[0050] By monitoring and calculating the failure rate of devices, the failure modes and failure frequencies of the devices can be discovered, which helps to improve the device design and manufacturing process and enhance the reliability and stability of the devices. In the formula, Gzsb represents the device failure rate, λ represents the parameter of the device failure rate, t is the specified time length, indicating whether an event occurs during this period, and e is the base of the natural logarithm, with a value of 2.71828, e -λt Represents the probability that the event does not occur within the time period t, that is, the expression of the exponential distribution function of the non-occurrence of the event. Therefore, 1 - e -λt Represents the probability that the event occurs within the time period t, that is, the probability that the event occurs at least once during this period
[0051] Calculation formula for bandwidth utilization rate:
[0052]
[0053] Calculating the bandwidth utilization rate can help identify performance issues and bottlenecks in the network, quickly locate the cause of faults, take timely measures for repair, and reduce the impact of network faults on the business. In the formula, Dkly represents the bandwidth utilization rate, Pb represents the packet arrival rate, C represents the server item of the system, MQ represents the processing rate of the system, C! represents the factorial of C, represents the Cth power of the packet arrival rate PB divided by the factorial of C, represents the ratio of the difference between the processing rate MQ of the system and the arrival rate PB to the processing rate;
[0054] Calculation formula for network intrusion frequency:
[0055] Wlrq = P(adex) * P(bpre) * P(cmos)
[0056] By monitoring and calculating the network intrusion frequency, network attack behaviors can be detected in a timely manner, countermeasures can be taken, network security protection can be strengthened, the security level of the network can be improved, and the possibility of being invaded can be reduced. In the formula, Wlrq represents the network intrusion frequency, P(adex) represents the probability of attack events occurring, P(bpre) represents the probability of vulnerabilities existing in the system, P(cmos) represents the probability that the attack is not detected, and the above probabilities are obtained through penetration testing and vulnerability scanning;
[0057] The information processing module calculates the network information security index Wazs based on the change index Cszs of the data transmission rate, the network device load Wbfz, the device failure rate Gzsb, the bandwidth utilization rate Dkly, and the network intrusion frequency Wlrq. The calculation formula is as follows:
[0058] Wazs = (1 - Cszs) * (1 - Wbfz) * (1 - Gzsb) * (1 - Dkly) * (1 - Wlrq)
[0059] The network information security index can quantify the security status and reflect the security level of the network in digital form, facilitating the supervision to monitor and evaluate the security status, promptly discover existing problems and take corresponding measures for improvement. In the formula, Wazs represents the network information security index, Cszs represents the change index of the data transmission rate, Wbfz represents the network device load, Gzsb represents the device failure rate, Dkly represents the bandwidth utilization rate, and Wlrq represents the network intrusion frequency. In this formula, the value range of each factor is between 0 and 1, indicating the quality of the future network security status. A high value represents strong security, while a low value represents potential security risks;
[0060] The information warning module internally sets the network security standard index Wlbz, and analyzes the network intrusion risk and generates a risk information report for transmission to the remote monitoring module by comparing it with the network information security index Wazs. The comparison method is as follows:
[0061] When the network information security index Wazs is less than the network security standard index Wlbz, it indicates that there is an information security risk at this time, and the information warning module will promptly issue an alarm signal;
[0062] When the network information security index Wazs is greater than or equal to the network security standard index Wlbz, it indicates that the system security level is high and there is no information security risk;
[0063] The remote monitoring module displays the received risk information report on the monitoring interface. The monitoring and maintenance personnel can promptly discover the security problems existing in the monitoring system at this time, and give corresponding solutions according to the risk information report. This system calculates the network information security index and conducts risk comparison, discovers anomalies and gives early warnings in a timely manner, and takes maintenance measures, which ensures the privacy of information and improves the security of the system.
[0064] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A monitoring system for information network engineering supervision, characterized in that: It includes data acquisition module, information processing module, information alarm module and remote monitoring module; The data acquisition module is used to collect network traffic data Wlsj, network device status data Wlsb, network performance data Wlxn, security event data Aqsj and application layer data Ycsj, and transmit the collected data to the information processing module through the network; The information processing module calculates the data transmission rate change index Cszs, network equipment load Wbfz, equipment failure rate Gzsb, bandwidth utilization rate Dkly and network intrusion frequency Wlrq through a formula according to the data transmitted by the data acquisition module, and calculates the network information security index Wazs according to the above calculated values and transmits it to the information alarm module; The information processing module calculates the change index Cszs of the data transmission rate according to the data transmitted by the data acquisition module through the formula, and the calculation formula is as follows: In the formula, Cszs represents the change index of data transmission rate, n represents the number of time points, and v i Indicates that at time point t i The corresponding data transmission rate, t i represents the i-th time point; The information processing module calculates the network device load Wbfz according to the data transmitted by the data acquisition module through the formula, and the calculation formula is as follows: In the formula, Wbfz represents the network device load, Sjcl represents the actual data processing capacity, Pbdx represents the average packet size, and Zddk represents the maximum supported bandwidth. The above values can be obtained through system background detection. Cszs represents the change index of data transmission rate. The information processing module calculates the equipment failure rate Gzsb according to the data transmitted by the data acquisition module through the formula, and the calculation formula is as follows: Gzsb=1-e -λt In the formula, Gzsb represents the equipment failure rate, λ represents the parameter of the equipment failure rate, t represents the specified time length, indicating whether the event occurs during this period of time, e represents the base of the natural logarithm, and the value is 2.71828, e -λt represents the probability that an event does not occur within time period t, that is, the exponential distribution function expression of the event not occurring. Therefore, 1-e -λt It represents the probability of an event occurring within time period t, that is, the probability that the event occurs at least once within this period of time; The information processing module calculates the bandwidth utilization rate Dkly according to the data transmitted by the data acquisition module through the formula, and the calculation formula is as follows: In the formula, Dkly represents bandwidth utilization, Pb represents packet arrival rate, C represents the server project of the system, MQ represents the processing rate of the system, and C! represents the factorial of C. represents the C-th power of the packet arrival rate PB divided by the factorial of C, It represents the ratio of the difference between the system's processing rate MQ and the arrival rate PB to the processing rate; The information processing module calculates the network intrusion frequency Wlrq according to the data transmitted by the data acquisition module through the formula, and the calculation formula is as follows: Wlrq=P(adex)*P(bpre)*P(cmos) In the formula, Wlrq represents the frequency of network intrusion, P(adex) represents the probability of an attack event, P(bpre) represents the probability that a vulnerability exists in the system, and P(cmos) represents the probability that an attack is not detected. The above probabilities are obtained through penetration testing and vulnerability scanning. The information processing module calculates the network information security index Wazs according to the data transmission rate change index Cszs, network equipment load Wbfz, equipment failure rate Gzsb, bandwidth utilization rate Dkly and network intrusion frequency Wlrq. The calculation formula is as follows: Waza=(1-Cszs)*(1-Wbfz)*(1-Gzsb)*(1-Dkly)*(1-Wlrq In the formula, Wazs represents the network information security index, Cszs represents the change index of data transmission rate, Wbfz represents the network equipment load, Gzsb represents the equipment failure rate, Dkly represents the bandwidth utilization rate, and Wlrq represents the network intrusion frequency. In this formula, the value range of each factor is between 0 and 1, indicating the degree of future network security status. A high value indicates strong security, while a low value indicates potential security risks. The information alarm module sets a network security standard index Wlbz inside, and analyzes the network intrusion risk by comparing it with the network information security index Wazs, and generates a risk information report to transmit to the remote monitoring module; The remote monitoring module displays the received risk information report on the monitoring interface.
2. A monitoring system for information network engineering supervision according to claim 1, characterized in that: The data collection module compiles the collected network traffic data into a data set, and the data set is {Wlsj n-9 ,Wlsj n-8 ,Wlsj n-7 ,Wlsj n-6 ,...,Wlsj n }, the data collection module compiles the collected network device status data into a data set, and the data set is {Wlsb n-9 ,Wlsb n-8 ,Wlsb n-7 ,Wlsb n-6 ,...,Wlsb n }.
3. A monitoring system for information network engineering supervision according to claim 1, characterized in that: The data collection module compiles the collected network performance data into a data set, and the data set is {Wlxn n-9 ,Wlxn n-8 ,Wlxn n-7 ,Wlxn n-6 ,...,Wlxn n }, the data collection module compiles the collected security event data into a data set, and the data set is {Aqsj n-9 ,Aqsj n-8 ,Aqsj n-7 ,Aqsj n-6 ,...,Aqsj n }, the data collection module compiles the collected application layer data into a data set, and the data set is {Ycsj n-9 ,Ycsj n-8 ,Ycsj n-7 ,Ycsj n-6 ,...,Ycsj n }.
4. A monitoring system for information network engineering supervision according to claim 1, characterized in that: The information alarm module sets a network security standard index Wlbz internally and compares it with the network information security index Wazs in the following way: When the network information security index Wazs is less than the network security standard index Wlbz, it means that there is an information security risk at this time; When the network information security index Wazs is greater than or equal to the network security standard index Wlbz, it means that the system security level is high and there is no information security risk.
Citation Information
Patent Citations
Method and system for monitoring network security of power grid industrial control system
CN114172702A
Computer network monitoring system
CN117155625A