A network information security analysis method and system based on big data
Through a network information security analysis method based on big data and machine learning, combined with AI intelligent firewall, the problems of inefficient network information security analysis in the existing technology are solved, and efficient and intelligent network security protection is achieved.
Patent Information
- Application Number
- CN202410545845.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-06
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-05-06
AI Technical Summary
The existing network information security analysis methods rely on manual experience and rule bases, and are inefficient in processing, difficult to effectively deal with complex and diverse cyber threats, and lack comprehensive coverage for large-scale data and complex attacks.
The network information security analysis method based on big data is adopted to obtain basic network information data through Internet big data, conduct network traffic analysis and abnormal behavior detection, and use machine learning methods to establish a network security model, combine AI intelligent firewall to conduct attack type analysis and firewall reinforcement processing to achieve intelligent identification and real-time prediction of network abnormal behavior.
It improves network information security processing efficiency and adaptability, can effectively respond to complex and changeable network security challenges, provide comprehensive security guarantees, and has high intelligence level, automation level and real-time monitoring capabilities.
Smart Images

Figure CN118677641B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security protection technology, and in particular to a network information security analysis method and system based on big data. Background Art
[0002] Existing network security defense methods have gradually become inadequate. In the face of increasingly complex and diverse network threats, a more efficient and comprehensive security analysis method is urgently needed. Against this background, network information security analysis methods based on big data technology have emerged. Big data technology, with its characteristics of massive data processing, real-time analysis, and intelligent prediction, provides unprecedented advantages in the field of network security. Through in-depth mining and analysis of large-scale network data, timely discovery and early warning of network security threats can be achieved, and effective security defense measures can be taken. In addition, the continuous development of cutting-edge technologies such as machine learning and artificial intelligence has also provided new solutions for network security. By combining big data technology and machine learning algorithms, automatic identification and analysis of abnormal network behaviors can be achieved, improving the efficiency and accuracy of security defense. The application of encryption technology, cloud computing, distributed computing and other technologies provides a more comprehensive and reliable guarantee for network information security. However, existing network information security analysis methods often rely on manual experience and rule bases, with low processing efficiency and are easily restricted by new threats. They lack comprehensive coverage of large-scale data and complex attacks, and are difficult to timely discover and respond to potential security risks. Summary of the invention
[0003] Based on this, it is necessary to provide a network information security analysis method and system based on big data to solve at least one of the above technical problems.
[0004] To achieve the above purpose, a network information security analysis method based on big data is provided, the method comprising the following steps:
[0005] Step S1: using the Internet big data to obtain network basic information data; performing network traffic analysis on the network basic information data to generate network basic traffic information data;
[0006] Step S2: preprocessing the network basic traffic information data to obtain standard network basic information data; performing abnormal behavior detection on the standard network basic information data to obtain network information abnormal behavior data; using machine learning methods to perform model training on the standard abnormal behavior data to generate a network security model;
[0007] Step S3: Use the network security model to perform security prediction on the standard abnormal behavior data to obtain a security prediction value; execute the security detection strategy based on the security prediction value to generate a security analysis result; compare the security analysis result with the preset security threshold to generate the first type of feedback data and the second type of feedback data; merge the first type of feedback data and the second type of feedback data to generate a feedback data set;
[0008] Step S4: Based on the preset firewall, perform AAC technical security identification on the returned data set to generate an AI firewall protection strategy; perform attack type analysis on the network basic traffic information data according to the AI firewall protection strategy to obtain attack type analysis data; use the attack type analysis data to perform firewall reinforcement processing on the preset firewall to generate an AI intelligent firewall; perform abnormal intrusion behavior analysis based on the AI firewall to obtain abnormal intrusion behavior monitoring data; open up storage space based on the abnormal intrusion data to obtain abnormal data storage space; perform IP identification processing on the abnormal intrusion data based on the abnormal data storage space to generate an abnormal data IP identification; perform attack range analysis on the abnormal data IP identification to obtain attack range data; construct a disaster area strategy based on the attack range data to generate a hierarchical processing strategy.
[0009] The present invention summarizes the integration of big data technology and machine learning algorithms, and uses Internet big data to obtain network basic information data. The system can establish a complete network data foundation, providing necessary information support for subsequent security analysis. Then, based on the preprocessing of the basic network traffic information data and abnormal behavior detection, abnormal activities in the network can be discovered in time, including potential security threats and attack behaviors, so as to give early warnings and take necessary defense measures. Model training is performed on abnormal behavior data through machine learning methods to generate network security models, which further improves the perception and response capabilities of network security issues. Using AI intelligent firewalls to perform security identification and attack type analysis on network data, real-time monitoring and intelligent defense of network traffic can be achieved to ensure the security and stability of the network. Finally, in the abnormal intrusion behavior analysis and attack range analysis stages, the system can conduct in-depth analysis of the network disaster situation, and take corresponding strategies and measures to respond to ensure the security and stability of the network. The comprehensive protection of network security is improved by using intelligent methods. Therefore, the present invention improves the network information security processing efficiency and adaptive capabilities by integrating technologies such as big data, machine learning and artificial intelligence.
[0010] In this specification, a network information security analysis system based on big data is provided, which is used to execute the above-mentioned network information security analysis method based on big data. The network information security analysis system based on big data includes:
[0011] The traffic analysis module is used to obtain basic network information data by using Internet big data; perform network traffic analysis on the basic network information data to generate basic network traffic information data;
[0012] The network security model training module is used to perform data preprocessing on the network basic traffic information data to obtain standard network basic information data; perform abnormal behavior detection on the standard network basic information data to obtain network information abnormal behavior data; use machine learning methods to perform model training on the standard abnormal behavior data to generate a network security model;
[0013] The security prediction module is used to use the network security model to perform security prediction on the standard abnormal behavior data to obtain the security prediction value; execute the security detection strategy based on the security prediction value to generate the security analysis result; compare the security analysis result with the preset security threshold to generate the first type of feedback data and the second type of feedback data; merge the first type of feedback data and the second type of feedback data to generate a feedback data set;
[0014] The security enhancement module is used to perform AAC technical security identification on the returned data set based on the preset firewall and generate an AI firewall protection strategy; perform attack type analysis on the network basic traffic information data according to the AI firewall protection strategy to obtain attack type analysis data; use the attack type analysis data to perform firewall reinforcement processing on the preset firewall to generate an AI intelligent firewall; perform abnormal intrusion behavior analysis based on the AI firewall to obtain abnormal intrusion behavior monitoring data; open up storage space based on abnormal intrusion data to obtain abnormal data storage space; perform IP identification processing on abnormal intrusion data based on the abnormal data storage space to generate abnormal data IP identification; obtain attack range data by performing attack range analysis on the abnormal data IP identification; construct a disaster area strategy based on the attack range data to generate a hierarchical processing strategy.
[0015] The beneficial effect of the present invention is that through multiple modules such as traffic analysis, security model training, security prediction and security enhancement, it is possible to realize intelligent identification and real-time prediction of abnormal network behavior. In particular, based on the intrusion behavior analysis and dynamic protection strategy generation of AI intelligent firewall, the system has the ability to flexibly adjust the protection strategy, and can effectively respond to the ever-changing network security threats. By analyzing the IP identification and attack range of abnormal data, the system can quickly locate the affected area and generate corresponding disaster recovery processing strategies, providing comprehensive protection for network security. Compared with the existing network security analysis system, the system has a higher level of intelligence, automation and real-time monitoring capabilities, and can more effectively respond to complex and changing network security challenges. Therefore, the present invention improves the efficiency and adaptability of network information security processing by integrating technologies such as big data, machine learning and artificial intelligence. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 It is a schematic diagram of the steps of a network information security analysis method based on big data;
[0017] Figure 2 for Figure 1 Detailed implementation steps of step S3 in FIG.
[0018] Figure 3 for Figure 2 Detailed implementation steps of step S32;
[0019] Figure 4 for Figure 1 Detailed implementation steps of step S4 in FIG.
[0020] Figure 5 It is a schematic diagram of the detailed implementation steps of step S46. DETAILED DESCRIPTION
[0021] The following is a clear and complete description of the technical method of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by technicians in this field without creative work are within the scope of protection of the present invention.
[0022] In addition, the accompanying drawings are only schematic illustrations of the present invention and are not necessarily drawn to scale. The same reference numerals in the figures represent the same or similar parts, and their repeated description will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities and do not necessarily correspond to physically or logically independent entities. The functional entities can be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor methods and / or microcontroller methods.
[0023] It should be understood that, although the terms "first", "second", etc. may be used herein to describe various units, these units should not be limited by these terms. These terms are used only to distinguish one unit from another unit. For example, without departing from the scope of the exemplary embodiments, the first unit may be referred to as the second unit, and similarly the second unit may be referred to as the first unit. The term "and / or" used herein includes any and all combinations of one or more of the listed associated items.
[0024] To achieve this, please refer to Figures 1 to 5 , a network information security analysis method based on big data, the method comprising the following steps:
[0025] Step S1: using the Internet big data to obtain network basic information data; performing network traffic analysis on the network basic information data to generate network basic traffic information data;
[0026] Step S2: preprocessing the network basic traffic information data to obtain standard network basic information data; performing abnormal behavior detection on the standard network basic information data to obtain network information abnormal behavior data; using machine learning methods to perform model training on the standard abnormal behavior data to generate a network security model;
[0027] Step S3: Use the network security model to perform security prediction on the standard abnormal behavior data to obtain a security prediction value; execute the security detection strategy based on the security prediction value to generate a security analysis result; compare the security analysis result with the preset security threshold to generate the first type of feedback data and the second type of feedback data; merge the first type of feedback data and the second type of feedback data to generate a feedback data set;
[0028] Step S4: Based on the preset firewall, perform AAC technical security identification on the returned data set to generate an AI firewall protection strategy; perform attack type analysis on the network basic traffic information data according to the AI firewall protection strategy to obtain attack type analysis data; use the attack type analysis data to perform firewall reinforcement processing on the preset firewall to generate an AI intelligent firewall; perform abnormal intrusion behavior analysis based on the AI firewall to obtain abnormal intrusion behavior monitoring data; open up storage space based on the abnormal intrusion data to obtain abnormal data storage space; perform IP identification processing on the abnormal intrusion data based on the abnormal data storage space to generate an abnormal data IP identification; perform attack range analysis on the abnormal data IP identification to obtain attack range data; construct a disaster area strategy based on the attack range data to generate a hierarchical processing strategy.
[0029] The present invention summarizes the integration of big data technology and machine learning algorithms, and uses Internet big data to obtain network basic information data. The system can establish a complete network data foundation, providing necessary information support for subsequent security analysis. Then, based on the preprocessing of the basic network traffic information data and abnormal behavior detection, abnormal activities in the network can be discovered in time, including potential security threats and attack behaviors, so as to give early warnings and take necessary defense measures. Model training is performed on abnormal behavior data through machine learning methods to generate network security models, which further improves the perception and response capabilities of network security issues. Using AI intelligent firewalls to perform security identification and attack type analysis on network data, real-time monitoring and intelligent defense of network traffic can be achieved to ensure the security and stability of the network. Finally, in the abnormal intrusion behavior analysis and attack range analysis stages, the system can conduct in-depth analysis of the network disaster situation, and take corresponding strategies and measures to respond to ensure the security and stability of the network. The comprehensive protection of network security is improved by using intelligent methods. Therefore, the present invention improves the network information security processing efficiency and adaptive capabilities by integrating technologies such as big data, machine learning and artificial intelligence.
[0030] In the embodiment of the present invention, reference Figure 1 The above is a schematic diagram of the steps of a network information security analysis method based on big data of the present invention. In this example, the network information security analysis method based on big data includes the following steps:
[0031] Step S1: using the Internet big data to obtain network basic information data; performing network traffic analysis on the network basic information data to generate network basic traffic information data;
[0032] In the embodiment of the present invention, basic network information data, including network traffic, device logs, etc., are obtained from the Internet through tools such as data capture tools or API interfaces. Then, network traffic analysis software (Wireshark, tcpdump) and network traffic analysis framework (Bro / Zeek) are used to analyze the collected data, identify the pattern, behavior and characteristics of network traffic, extract key information, and generate basic network traffic information data;
[0033] Step S2: preprocessing the network basic traffic information data to obtain standard network basic information data; performing abnormal behavior detection on the standard network basic information data to obtain network information abnormal behavior data; using machine learning methods to perform model training on the standard abnormal behavior data to generate a network security model;
[0034] In the embodiment of the present invention, preprocessing the network basic traffic information data may involve steps such as data cleaning, missing value processing, feature selection and conversion, and the tools used include Pandas, NumPy and Scikit-learn libraries in Python. Next, abnormal behavior detection is performed on the preprocessed data, and the methods used include statistical methods, machine learning algorithms and deep learning models, and the tools used are Scikit-learn, TensorFlow, and PyTorch. Finally, the standard abnormal behavior data is trained by machine learning methods, and various machine learning algorithms can be used to implement it using support vector machines (SVM), random forests, and deep neural networks.
[0035] Step S3: Use the network security model to perform security prediction on the standard abnormal behavior data to obtain a security prediction value; execute the security detection strategy based on the security prediction value to generate a security analysis result; compare the security analysis result with the preset security threshold to generate the first type of feedback data and the second type of feedback data; merge the first type of feedback data and the second type of feedback data to generate a feedback data set;
[0036] In an embodiment of the present invention, a trained deep learning model is used to perform security prediction on standard abnormal behavior data, and the tools used include TensorFlow and PyTorch deep learning frameworks. The security detection strategy is executed based on the security prediction value, and the security detection strategy is executed using a rule engine, logical judgment, and machine learning algorithms. Next, the security analysis results are compared with the preset security threshold, and the first type of feedback data and the second type of feedback data are generated, and a custom script is written to complete this step. Finally, the Pandas library tool in Python is used to merge the first type of feedback data and the second type of feedback data to generate a feedback data set to complete the data merging operation.
[0037] Step S4: Based on the preset firewall, perform AAC technical security identification on the returned data set to generate an AI firewall protection strategy; perform attack type analysis on the network basic traffic information data according to the AI firewall protection strategy to obtain attack type analysis data; use the attack type analysis data to perform firewall reinforcement processing on the preset firewall to generate an AI intelligent firewall; perform abnormal intrusion behavior analysis based on the AI firewall to obtain abnormal intrusion behavior monitoring data; open up storage space based on the abnormal intrusion data to obtain abnormal data storage space; perform IP identification processing on the abnormal intrusion data based on the abnormal data storage space to generate an abnormal data IP identification; perform attack range analysis on the abnormal data IP identification to obtain attack range data; construct a disaster area strategy based on the attack range data to generate a hierarchical processing strategy.
[0038] In the embodiment of the present invention, when using the AI intelligent firewall to perform AAC technology security identification, the AAC technology security identification tool is used; then, the network basic traffic information data is analyzed for attack types according to the AI firewall protection strategy, and the attack type analysis tool is used; then, the preset firewall is reinforced using the attack type analysis data, and the firewall reinforcement processing tool is used to generate the AI intelligent firewall; next, when performing abnormal intrusion behavior analysis based on the AI intelligent firewall, the abnormal intrusion behavior analysis tool is used; then, when opening up storage space according to the abnormal intrusion data, the storage space opening tool is used; then, when performing IP identification processing on the abnormal intrusion data based on the abnormal data storage space, the IP identification processing tool is used; finally, when performing attack range analysis on the IP identification of the abnormal data, the attack range analysis tool is used.
[0039] Preferably, step S1 comprises the following steps:
[0040] Step S11: using a data acquisition tool to obtain a network basic information data packet;
[0041] Step S12: Decomposing the network basic information data packet to generate network basic information data;
[0042] Step S13: Perform traffic analysis on the network basic information data to generate network basic traffic information data.
[0043] The present invention can monitor the network interface in real time by using the tcpdump data acquisition tool, obtain network basic information data packets, capture all data packets transmitted through the interface, and save them as raw data. Subsequently, the Wireshark network protocol analysis tool is used to parse these obtained network basic information data packets according to the format of each network protocol, and extract various parts of the data packet, including the data packet header and the payload part. It can display the content of the data packet in a human-readable form, which is convenient for subsequent analysis. Finally, the tshark professional network traffic analysis tool is used to conduct an in-depth analysis of the disassembled data packets, extract key information in the network traffic, such as source address, destination address, transmission protocol, port number, etc., so as to generate network basic traffic information data;
[0044] In the embodiment of the present invention, by using TCPDump, a professional data acquisition tool, real-time and efficient monitoring of the network interface is achieved. Through this tool, all data packets passing through the interface are captured. In order to further analyze these data packets, Wireshark, an industry-leading network protocol analysis tool, is selected. Through this tool, not only the header information of the data packet is deeply analyzed, but also the payload content of the data packet is interpreted in detail, so as to fully grasp the key information of each data packet. On this basis, tshark, a powerful network traffic analysis tool, is also used to conduct a more in-depth and detailed analysis of the data packet. Tshark successfully extracts key information such as the source address, destination address, transmission protocol and port number in the data packet, and builds a complete network basic traffic information data. These data provide an in-depth understanding of network traffic distribution, traffic mode and traffic trend, and provide strong data support for network security and performance optimization. By comprehensively using professional tools such as TCPDump, Wireshark and tshark, comprehensive and efficient monitoring and analysis of network traffic is achieved. This rigorous and steady analysis process not only ensures the accuracy of the data, but also provides an important decision-making basis for network security and performance optimization.
[0045] Preferably, step S2 comprises the following steps:
[0046] Step S21: Clean the network basic traffic information data to generate network basic information cleansing data;
[0047] Step S22: integrating the network basic information cleansing data to generate network basic information integrated data;
[0048] Step S23: standardizing the network basic information integration data to obtain standard network basic information data;
[0049] Step S24: performing abnormal behavior detection on the standard network basic information data to obtain network information abnormal behavior data;
[0050] Step S25: Import the network information abnormal behavior data into the convolutional neural network and the recursive neural network for model fusion to generate a network security model.
[0051] The present invention helps to remove noise and redundant information from the data by performing fine data cleaning and integration on the network basic traffic information data, thereby improving data quality and accuracy. The cleaned data is rigorously standardized to ensure the consistency of the data in scale and mean, which is conducive to subsequent analysis and modeling. Abnormal behavior detection is performed on standard network basic information data to discover and locate potential abnormal situations and threats in the network. The obtained abnormal behavior data is imported into advanced convolutional neural networks and recursive neural networks for deep model fusion, thereby improving the accuracy and robustness of the network security model.
[0052] In the examples of the present invention, data cleaning techniques such as data deduplication, missing value processing, and outlier detection are used to remove noise from the network basic traffic information data, and also to further refine the invalid information of duplicate data, erroneous data, and incomplete data. The cleaned network basic information data is integrated by data merging, data conversion, and data format standardization to establish a unified data format and structure for subsequent processing and analysis. The integrated network basic information data is subjected to Z-scor standardization to eliminate the dimensional influence between different attributes so that the data has a unified scale and mean. The standardized network basic information data is subjected to abnormal behavior detection to identify and locate abnormal situations and potential threats in the network. The detected network information abnormal behavior data is imported into deep learning models such as convolutional neural networks (CNNs) and recursive neural networks (RNNs) for model fusion, and abnormal behavior is analyzed and identified more accurately and comprehensively.
[0053] Preferably, step S24 includes the following steps:
[0054] Step S241: extracting access timestamps from standard network basic information data to generate network information access timestamps; performing time series conversion on standard network basic information data according to the network information access timestamps to generate time series conversion data;
[0055] Step S242: performing time domain data analysis on the time series conversion data to generate a time domain signal; performing Fourier transformation on the time series conversion data to generate a frequency domain signal; constructing a spectrum diagram based on the time domain signal and the frequency domain signal to generate a network access spectrum diagram;
[0056] Step S243: performing abnormal frequency peak analysis on the network access spectrum diagram to obtain abnormal network information behavior data.
[0057] By extracting access timestamps, the system can track the access of basic network information in real time, which helps to timely discover abnormal network access. After converting standard basic network information data into time series data, it is more convenient to observe and analyze the mode, trend and periodic changes of network access. Time series analysis plays an important role in predicting future network access and optimizing network resource configuration. Time domain analysis can reveal the law of network access signal changes over time, while frequency domain analysis can show the distribution characteristics of signals in frequency. The combination of the two can provide a more comprehensive understanding of the characteristics of network access and help discover potential abnormal behaviors. The complex network access data of the spectrum graph is displayed in a graphical manner, so that analysts can intuitively observe the frequency distribution and changes of network access. This helps to quickly locate the abnormal frequency peak, so as to discover abnormal network information behavior. By performing abnormal frequency peak analysis on the network access spectrum graph, abnormal behavior data in network information can be accurately identified. This helps to timely discover security threats such as network attacks and data leakage, and ensure the safe and stable operation of the network.
[0058] In the embodiment of the present invention, accurate timestamp technology is used to extract the precise time point of each access operation from the massive standard network basic information data to ensure the real-time and accuracy of the data. Then, the standard network basic information data is normalized and differentially converted to a time series according to the network information access timestamp to eliminate noise and non-stationarity in the data, extract useful information, and generate time series conversion data. By performing time domain data analysis on the time series conversion data, a time domain signal is generated. Time domain analysis describes this law by finding the statistical law of the correlation between sequence values and fitting an appropriate mathematical model, and then using the model to predict the future value of the sequence. Fourier transform is performed on the time series conversion data to generate a frequency domain signal. Fourier transform is a linear integral transform that can convert time series data from the time domain to the frequency domain, thereby analyzing its frequency components and periodicity. A spectrum diagram is constructed based on the time domain signal and the frequency domain signal, and a network access spectrum diagram is generated by Fourier transform (FFT). By analyzing the abnormal frequency peak, abnormal behavior data in the network information can be quickly located and extracted to provide support for network security management.
[0059] Preferably, step S25 includes the following steps:
[0060] Step S251: dividing the network information abnormal behavior data into data sets to generate training data and iteration data; importing the training data into the convolutional neural network and the recursive neural network for model output to obtain convolutional neural network output data and recursive neural network output data; fusing the convolutional neural network output data and the recursive neural network output data in series to obtain fused data;
[0061] Step S252: performing one-dimensional vector arrangement on the fused data based on the stack function to generate one-dimensional vector arrangement data;
[0062] Step S253: performing a two-dimensional matrix stacking operation on the fused data to generate two-dimensional matrix stacking data;
[0063] Step S254: performing model optimization on the one-dimensional vector arrangement data and the two-dimensional matrix stacking data through a loss function to generate a network security training model;
[0064] Step S255: Iteratively adjust the network security training model according to the iteration data to generate a network security model.
[0065] The present invention can make full use of the network information abnormal behavior data to train and optimize the network security model by dividing it into training data and iterative data. The training data is output by a convolutional neural network and a recursive neural network, which can capture the deep-level features of the data, and the output data of the two are integrated by data fusion technology to improve the accuracy and generalization ability of the model. A variety of data processing methods are adopted, including one-dimensional vector arrangement and two-dimensional matrix stacking, which helps to extract feature information of the data from multiple angles and levels. This flexibility enables the model to better adapt to data of different types and dimensions, and improves the adaptability and robustness of the model. By iteratively adjusting the network security training model through iterative data, the parameters and structure of the model can be gradually optimized to make it more in line with the needs of the actual network environment. This iterative adjustment process can continuously improve the performance and accuracy of the model, thereby generating an efficient and reliable network security model. The generated network security model can effectively detect and identify abnormal behavior data in the network and discover potential security threats in a timely manner. This helps to take measures to prevent and respond in a timely manner to ensure the safe and stable operation of the network. At the same time, by continuously optimizing the model, its ability to identify and defend against new attacks and threats can be further improved.
[0066] In an embodiment of the present invention, CNN is particularly good at processing data with spatial correlation such as images and videos, while RNN has excellent processing capabilities for sequence data (such as time series or text). CNN and RNN are used to extract features from training data and generate corresponding output data. The output data of CNN and RNN are fused in series to obtain fused data, which helps to combine the advantages of both and improve the performance of the model. The Stack function is used to arrange the data into one-dimensional vectors, and the stacking operation is used to stack the data into two-dimensional matrices. It helps to convert the fused data into a format suitable for model training and optimization. The loss function is defined to optimize the model for one-dimensional vector arrangement data and two-dimensional matrix stacking data, and the loss is minimized by adjusting the parameters of the model, thereby improving the accuracy of the model. Iterative adjustment of the network security training model according to the iterative data helps the model adapt to new environments and attack modes and maintain its effectiveness and accuracy.
[0067] Preferably, step S3 comprises the following steps:
[0068] Step S31: Use the network security model to perform security prediction on the standard abnormal behavior data to obtain a security prediction value;
[0069] Step S32: Execute the security detection strategy based on the security prediction value to generate a security analysis execution result, wherein the security detection strategy includes a system security strategy, a data security strategy and a user security strategy, and the security analysis execution result includes a system security analysis execution result, a data security analysis execution result and a user security analysis execution result;
[0070] Step S33: Perform security performance evaluation on the security analysis execution result to generate security performance evaluation data; compare the security performance evaluation data with the preset security threshold, and when the security performance evaluation data is greater than or equal to the preset security threshold, perform content blocking processing on the corresponding network basic information data to generate the first type of return data;
[0071] Step S34: when the security performance evaluation data is less than the preset security threshold, the corresponding network basic information data is continuously detected and processed to generate the second type of return data;
[0072] Step S35: Merge the first type of feedback data and the second type of feedback data to generate a feedback data set.
[0073] The present invention uses a network security model to perform real-time security prediction c on standard abnormal behavior data to ensure that an early warning can be obtained before a threat occurs. It is based on model learning and training, so it has high accuracy. Security strategies based on the three levels of system, data and user ensure that there are no blind spots in network security protection. Through security performance evaluation data, the effectiveness of current network security measures can be objectively evaluated to avoid subjective assumptions. The preset security threshold can be adjusted according to actual needs to adapt to different security needs and environments. Steps S34 and S35: Take different processing measures based on the security performance evaluation results, and merge the feedback data. Depending on the evaluation results, content bans or continuous detection processing measures are taken to ensure accurate response to potential threats. The feedback data generated by different processing measures are merged to form a unified feedback data set, which is convenient for subsequent data analysis and processing.
[0074] As an example of the present invention, refer to Figure 2 As shown, in this example, step S3 includes.
[0075] Step S31: Use the network security model to perform security prediction on the standard abnormal behavior data to obtain a security prediction value;
[0076] In the embodiment of the present invention, the safety prediction of standard abnormal behavior data is performed by using a trained model. A safety prediction value is generated according to the prediction result of the model to indicate the safety level or abnormality degree of the data;
[0077] Step S32: Execute the security detection strategy based on the security prediction value to generate a security analysis execution result, wherein the security detection strategy includes a system security strategy, a data security strategy and a user security strategy, and the security analysis execution result includes a system security analysis execution result, a data security analysis execution result and a user security analysis execution result;
[0078] In the embodiment of the present invention, through the prepared security detection strategy, including system security strategy, data security strategy and user security strategy, these strategies are then executed, and various security detection technologies and tools such as network security tools, data encryption algorithms and access control mechanisms are used to perform security detection on the system, data and users. According to the execution result, a security analysis execution result is generated, covering the security assessment of the system, the security assessment of the data and the security assessment of the user, and it is output for further analysis and decision-making by the system administrator or security expert, and presented in the form of a report, log or visual chart for easy understanding and use.
[0079] Step S33: Perform security performance evaluation on the security analysis execution result to generate security performance evaluation data; compare the security performance evaluation data with the preset security threshold, and when the security performance evaluation data is greater than or equal to the preset security threshold, perform content blocking processing on the corresponding network basic information data to generate the first type of return data;
[0080] In the embodiment of the present invention, security performance evaluation data is generated by analyzing the security evaluation data of the system, data and users. Subsequently, the security performance evaluation data is compared with a preset security threshold. If the security performance evaluation data is greater than or equal to the preset security threshold, the corresponding content blocking process is performed, the network basic information data is blocked, and the first type of return data is generated.
[0081] Step S34: when the security performance evaluation data is less than the preset security threshold, the corresponding network basic information data is continuously detected and processed to generate the second type of return data;
[0082] In the embodiment of the present invention, the security performance evaluation data is monitored and analyzed in real time to ensure the continuity and accuracy of the data. When the security performance evaluation data is lower than the preset security threshold, the system will trigger the continuous detection and processing mechanism. Then, the system will perform security detection including abnormal behavior detection and attack type analysis on the corresponding network basic information data. For the detected security issues, the system will generate the second type of feedback data to provide subsequent security analysis and processing.
[0083] Step S35: Merge the first type of feedback data and the second type of feedback data to generate a feedback data set.
[0084] In the embodiment of the present invention, the consistency of data format and structure is ensured by collecting and organizing the first type of feedback data and the second type of feedback data. Then the two types of feedback data are merged by matching and fusing based on common data fields or identifiers. The merged data is deduplicated and filtered to ensure the uniqueness and accuracy of the data set. Finally, a feedback data set is generated, which contains complete information of the first type and the second type of feedback data for further analysis and processing.
[0085] Preferably, step S32 includes the following steps:
[0086] Step S321: Execute the security detection strategy based on the security prediction value to generate a security analysis execution result. The security detection strategy is divided into system security strategy, data security strategy and user security strategy;
[0087] Step S322: Performing policy execution judgment on the security analysis execution result, and when confirming that the security analysis execution result is to execute the system security policy, performing a network hierarchy and system component security review according to the system security policy to obtain review result data; performing network topology redeployment based on the review result data to obtain network topology deployment result data; performing software and hardware update through the network topology deployment result data to obtain software and hardware update result data; and combining the review result data, network topology deployment result data, and software and hardware update result data to obtain the system security analysis execution result;
[0088] Step S323: When the security analysis execution result is confirmed to be the execution of the data security policy, sensitive data analysis is performed on the network information abnormal behavior data according to the data security policy to obtain sensitive data; the sensitive data is encrypted to obtain encrypted data; authorization restrictions are performed based on the encrypted data to obtain an authority control user; authorization restrictions are performed on the encrypted data according to the authority control user to obtain authorization restriction data; network basic traffic information data is backed up to obtain network basic backup data; the encrypted data, authorization restriction data and network basic backup data are aggregated to obtain the data security analysis execution result;
[0089] Step S324: When it is confirmed that the security analysis execution result is to execute the user security policy, the user identity biometric factor verification is performed according to the user security policy to obtain user identity authentication result data; user behavior monitoring is performed based on the user identity authentication result data to obtain user behavior monitoring result data; the user identity authentication result data and the user behavior monitoring result data are combined to obtain the user security analysis execution result.
[0090] The present invention can ensure that the security requirements of each level are fully considered and met by distinguishing the security policies of the three different levels of system, data and user. This layered policy execution method helps to improve the pertinence and efficiency of security management. When reviewing the network hierarchy and system components, potential security vulnerabilities can be discovered and repaired; network topology redeployment can optimize the network structure and improve the robustness and security of the network; software and hardware updates can ensure that the system always runs in the latest and safest state. Through the analysis and encryption of sensitive data, data can be prevented from being illegally obtained or tampered with; authorization restrictions can ensure that only authorized users can access and use sensitive data; the existence of network basic backup data can provide timely recovery measures when problems occur with the data. The authenticity of the user's identity can be ensured by verifying the biometric factors to prevent identity fraud; user behavior monitoring can track user behavior in real time, and issue warnings or take blocking measures in a timely manner after abnormal behavior is discovered; these measures together enhance the security of the network.
[0091] As an example of the present invention, refer to Figure 3 As shown, in this example, step S32 includes:
[0092] Step S321: Execute the security detection strategy based on the security prediction value to generate a security analysis execution result. The security detection strategy is divided into system security strategy, data security strategy and user security strategy;
[0093] In the embodiment of the present invention, the security detection strategy is executed through the security prediction value, and these strategies include system security, data security and user security strategy. Then, according to the execution result, the security analysis execution result including the system, data and user is generated.
[0094] Step S322: Performing policy execution judgment on the security analysis execution result, and when confirming that the security analysis execution result is to execute the system security policy, performing a network hierarchy and system component security review according to the system security policy to obtain review result data; performing network topology redeployment based on the review result data to obtain network topology deployment result data; performing software and hardware update through the network topology deployment result data to obtain software and hardware update result data; and combining the review result data, network topology deployment result data, and software and hardware update result data to obtain the system security analysis execution result;
[0095] In the embodiment of the present invention, by performing policy execution judgment on the security analysis execution result, the execution of the system security policy is confirmed. According to the system security policy, a security review of the network hierarchy and system components is performed to obtain review result data. Based on the review result data, the network topology is redeployed to obtain network topology deployment result data. Software and hardware are updated through the network topology deployment result data to generate software and hardware update result data. The review result data, the network topology deployment result data, and the software and hardware update result data are aggregated to obtain the system security analysis execution result.
[0096] Step S323: When the security analysis execution result is confirmed to be the execution of the data security policy, sensitive data analysis is performed on the network information abnormal behavior data according to the data security policy to obtain sensitive data; the sensitive data is encrypted to obtain encrypted data; authorization restrictions are performed based on the encrypted data to obtain an authority control user; authorization restrictions are performed on the encrypted data according to the authority control user to obtain authorization restriction data; network basic traffic information data is backed up to obtain network basic backup data; the encrypted data, authorization restriction data and network basic backup data are aggregated to obtain the data security analysis execution result;
[0097] In the embodiment of the present invention, the security analysis execution result is to execute the data security policy. According to the data security policy, the network information abnormal behavior data is subjected to sensitive data analysis to obtain sensitive data. The sensitive data is encrypted to generate encrypted data. Authorization restrictions are performed based on the encrypted data to obtain the authority control user. Authorization restriction processing is performed on the encrypted data according to the authority control user to obtain authorization restriction data. The network basic traffic information data is backed up to obtain network basic backup data. The encrypted data, the authorization restriction data and the network basic backup data are combined to obtain the data security analysis execution result.
[0098] Step S324: When it is confirmed that the security analysis execution result is to execute the user security policy, the user identity biometric factor verification is performed according to the user security policy to obtain user identity authentication result data; user behavior monitoring is performed based on the user identity authentication result data to obtain user behavior monitoring result data; the user identity authentication result data and the user behavior monitoring result data are combined to obtain the user security analysis execution result.
[0099] In the embodiment of the present invention, the user security policy is executed by confirming the security analysis execution result. The user identity biometric factor verification is performed according to the user security policy to obtain user identity verification result data. User behavior monitoring is performed based on the user identity verification result data to obtain user behavior monitoring result data. The user identity verification result data and the user behavior monitoring result data are combined to obtain the user security analysis execution result.
[0100] Preferably, step S4 comprises the following steps:
[0101] Step S41: passing the returned data set to the preset firewall, and using the AAC technology to adaptively adjust the preset firewall to generate an AI firewall protection strategy;
[0102] Step S42: Perform intelligent intrusion detection on the network basic traffic information data according to the AI firewall protection strategy to obtain firewall intrusion interception data; perform attack type analysis on the firewall intrusion interception data to generate attack type analysis data;
[0103] Step S43: Using the attack type analysis data, the preset firewall is reinforced to generate an AI intelligent firewall;
[0104] Step S44: Use the AI intelligent firewall to perform abnormal behavior monitoring to obtain abnormal intrusion behavior monitoring data, wherein the abnormal behavior monitoring includes abnormal traffic monitoring, abnormal request frequency monitoring, and abnormal intrusion behavior feature monitoring;
[0105] Step S45: using the intrusion detection system technology to open up storage space for abnormal intrusion behavior monitoring data to obtain abnormal data storage space; based on the abnormal data storage space, IP identification is performed on the abnormal intrusion behavior monitoring data to generate abnormal data IP identification; attack range monitoring is performed through the abnormal data IP identification to generate attack range data;
[0106] Step S46: Divide the network system into disaster-affected areas according to the attack range data to generate disaster-affected areas, wherein the disaster-affected areas include high-level disaster-affected areas, medium-level disaster-affected areas and low-level disaster-affected areas; perform regional disaster grade processing based on the disaster-affected areas to generate a graded processing strategy, wherein the graded processing strategy includes high-level processing strategy, medium-level processing strategy and low-level processing strategy.
[0107] The present invention uses AAC technology to adaptively adjust the preset firewall and generate an AI firewall protection strategy. The firewall settings can be dynamically adjusted according to the real-time changes in the network environment to improve the protection capability of network security. This adaptability and intelligence are important advantages of network security protection, and can cope with various complex and changeable network attacks. According to the AI firewall protection strategy, intelligent intrusion detection is performed on the basic network traffic information data, and potential network attacks can be accurately identified and intercepted. This helps to prevent the invasion of threats such as malicious code, viruses, and Trojans, and protect the security of the network system. By using the attack type analysis data to reinforce the preset firewall, the protection capability of the firewall can be further improved. The reinforcement process may include enhancing the filtering rules of the firewall, optimizing the performance of the firewall, etc., so that it can better resist network attacks. By monitoring abnormal behavior, including abnormal traffic monitoring, abnormal request frequency monitoring, and abnormal intrusion behavior feature monitoring, abnormal behavior in the network can be fully captured. This helps to timely discover and respond to potential security threats and prevent attackers from exploiting vulnerabilities to carry out malicious activities. By opening up abnormal data storage space and IP-marking the abnormal intrusion behavior monitoring data, abnormal data can be efficiently stored and managed, and the IP mark is used to monitor the attack range and accurately locate the source and range of the attack. This helps to quickly respond to and deal with network attacks and reduce losses. According to the classification and level processing strategy of the affected areas, network system managers can formulate corresponding processing strategies according to the disaster situation in different areas. High-level disaster areas can be treated first to ensure the security of key businesses and data; low-level disaster areas can take more relaxed processing measures to avoid waste of resources. This hierarchical processing strategy helps to improve the efficiency and effectiveness of network security management.
[0108] As an example of the present invention, refer to Figure 4 As shown, in this example, step S4 includes:
[0109] Step S41: passing the returned data set to the preset firewall, using the AAC technology to adaptively adjust the preset firewall, and generating an AI firewall protection strategy;
[0110] In the embodiment of the present invention, the returned data set is transmitted to the preset firewall. Then, the preset firewall is adjusted using adaptive access control (AAC) technology to adapt to the current network environment and threat situation, thereby generating an AI firewall protection strategy.
[0111] Step S42: Perform intelligent intrusion detection on the network basic traffic information data according to the AI firewall protection strategy to obtain firewall intrusion interception data; perform attack type analysis on the firewall intrusion interception data to generate attack type analysis data;
[0112] In the embodiment of the present invention, the network basic traffic information data is intelligently intruded through the AI firewall protection strategy to identify potential intrusion behaviors and generate firewall intrusion interception data. The firewall intrusion interception data is further analyzed to identify the attack type and generate corresponding attack type analysis data.
[0113] Step S43: Using the attack type analysis data, the preset firewall is reinforced to generate an AI intelligent firewall;
[0114] In the embodiment of the present invention, the preset firewall is analyzed through the attack type analysis data to identify potential attack types and vulnerabilities, and the firewall is reinforced according to these findings to enhance the security performance of the firewall. A reinforced AI intelligent firewall is generated to improve the network security protection capability.
[0115] Step S44: Use the AI intelligent firewall to perform abnormal behavior monitoring to obtain abnormal intrusion behavior monitoring data, wherein the abnormal behavior monitoring includes abnormal traffic monitoring, abnormal request frequency monitoring, and abnormal intrusion behavior feature monitoring;
[0116] In an embodiment of the present invention, the network traffic is monitored in real time through an AI intelligent firewall, including the monitoring of abnormal traffic, request frequency and intrusion behavior; the monitored abnormal behavior data is recorded, including the characteristics of abnormal traffic, abnormal request frequency and characteristics of intrusion behavior; abnormal intrusion behavior monitoring data is generated, including detailed records and characteristic information of various abnormal behaviors, for subsequent analysis and processing.
[0117] Step S45: using the intrusion detection system technology to open up storage space for abnormal intrusion behavior monitoring data to obtain abnormal data storage space; based on the abnormal data storage space, IP identification is performed on the abnormal intrusion behavior monitoring data to generate abnormal data IP identification; attack range monitoring is performed through the abnormal data IP identification to generate attack range data;
[0118] In the embodiment of the present invention, the storage space of abnormal intrusion behavior monitoring data is allocated and managed through the intrusion detection system technology to ensure that there is sufficient storage space for storing abnormal data; based on the abnormal data storage space, the abnormal intrusion behavior monitoring data is IP-identified, that is, a unique IP identifier is assigned to each abnormal data record for subsequent identification and analysis; by analyzing the abnormal data IP identifier, the attack range is monitored and analyzed, and the attack range data is generated to determine the impact range and attack target of the abnormal intrusion behavior.
[0119] Step S46: Divide the network system into disaster-affected areas according to the attack range data to generate disaster-affected areas, wherein the disaster-affected areas include high-level disaster-affected areas, medium-level disaster-affected areas and low-level disaster-affected areas; perform regional disaster grade processing based on the disaster-affected areas to generate a graded processing strategy, wherein the graded processing strategy includes high-level processing strategy, medium-level processing strategy and low-level processing strategy.
[0120] In an embodiment of the present invention, the network system is divided into disaster-affected areas through attack range data, and the disaster situation is divided into high-level, medium-level and low-level disaster-affected areas; based on the disaster-affected divided areas, the regional disaster levels are graded and corresponding graded processing strategies are generated, including high-level, medium-level and low-level processing strategies, so that corresponding processing measures can be taken according to different degrees of disaster.
[0121] Preferably, step S46 includes the following steps:
[0122] Step S461: dividing the network system into affected areas according to the attack range data, wherein the affected areas include high-level affected areas, medium-level affected areas, and low-level affected areas;
[0123] Step S462: Perform intrusion impact analysis on the high-level disaster-affected area to generate intrusion impact analysis data; perform security isolation on the high-level disaster-affected area based on the intrusion impact analysis data to generate a high-level processing strategy;
[0124] Step S463: Perform vulnerability analysis on the medium-level disaster-affected area to generate vulnerability analysis data; perform vulnerability repair on the medium-level disaster-affected area according to the vulnerability analysis data to generate a medium-level processing strategy;
[0125] Step S464: Monitor the threat situation of the low-level disaster-stricken areas and generate threat monitoring data; issue security warnings to the low-level disaster-stricken areas based on the threat monitoring data and generate low-level processing strategies;
[0126] Step S465: merge the high-level processing strategy, the middle-level processing strategy and the low-level processing strategy to generate a hierarchical processing strategy.
[0127] The present invention divides the affected areas of the network system by attack range data, including high-level, medium-level and low-level affected areas. This division helps to prioritize the affected areas, so that security managers can more clearly understand the affected situation of the network system, and provide a basis for the subsequent processing strategy formulation. By performing intrusion impact analysis on high-level affected areas and generating corresponding processing strategies. Since high-level affected areas may have suffered serious attacks, it is very important to conduct in-depth analysis and security isolation on them. This can prevent the spread of attacks, protect key data and services, and reduce losses. By performing vulnerability analysis on medium-level affected areas and repairing vulnerabilities accordingly. This helps to eliminate potential security risks in a timely manner and prevent attackers from using these vulnerabilities to carry out further attacks. Vulnerability repair is an important link in improving the security of the network system and can enhance the protection capability of the system. By monitoring the threat situation of low-level affected areas and issuing security warnings based on the monitoring data. This helps to discover and respond to potential security threats in a timely manner and prevent them from escalating into more serious attacks. Through real-time warnings, security managers can prepare in advance and take corresponding preventive measures. Processing strategies at different levels are merged to generate hierarchical processing strategies. This helps to achieve unified management and coordinated execution of network security policies, and improve the efficiency and effectiveness of network security management. By merging policies, conflicts and duplications between policies can be avoided, ensuring the coherence and consistency of network security management.
[0128] As an example of the present invention, refer to Figure 5 As shown, in this example, step S46 includes:
[0129] Step S461: dividing the network system into affected areas according to the attack range data, wherein the affected areas include high-level affected areas, medium-level affected areas, and low-level affected areas;
[0130] In an embodiment of the present invention, the network system is divided into disaster-affected areas through attack range data, and the disaster situation is divided into high-level, medium-level and low-level disaster-affected areas according to the degree of impact of the attack; then the disaster-affected areas in the network system are carefully determined to ensure accurate division of disaster-affected areas of various levels.
[0131] Step S462: Perform intrusion impact analysis on the high-level disaster-affected area to generate intrusion impact analysis data; perform security isolation on the high-level disaster-affected area based on the intrusion impact analysis data to generate a high-level processing strategy;
[0132] In an embodiment of the present invention, a detailed analysis of the impact of intrusion is performed on high-level disaster-stricken areas to generate intrusion impact analysis data to accurately understand the extent of the impact of the attack; then, based on the intrusion impact analysis data, security isolation measures are taken to isolate and protect the high-level disaster-stricken areas to reduce further security threats and generate a high-level processing strategy.
[0133] Step S463: Perform vulnerability analysis on the medium-level disaster-affected area to generate vulnerability analysis data; perform vulnerability repair on the medium-level disaster-affected area according to the vulnerability analysis data to generate a medium-level processing strategy;
[0134] In an embodiment of the present invention, a detailed vulnerability analysis is performed on the medium-level disaster-stricken area to generate vulnerability analysis data, and the security vulnerabilities and weaknesses therein are accurately identified; then, based on the vulnerability analysis data, corresponding vulnerability repair measures are taken to repair the medium-level disaster-stricken area to eliminate potential security threats and generate a medium-level processing strategy.
[0135] Step S464: Monitor the threat situation of the low-level disaster-stricken areas and generate threat monitoring data; issue security warnings to the low-level disaster-stricken areas based on the threat monitoring data and generate low-level processing strategies;
[0136] In an embodiment of the present invention, by conducting detailed threat situation monitoring of low-level disaster-stricken areas, possible threats and security risks are collected and analyzed to generate threat monitoring data; then, based on the threat monitoring data, corresponding security warning measures are implemented to warn and prevent low-level disaster-stricken areas, so as to respond to potential security threats and generate low-level processing strategies.
[0137] Step S465: merge the high-level processing strategy, the middle-level processing strategy and the low-level processing strategy to generate a hierarchical processing strategy.
[0138] In an embodiment of the present invention, the processing strategies for high-level, medium-level and low-level disaster-stricken areas are summarized and integrated, including the policy contents of various aspects such as intrusion impact analysis, vulnerability repair, and threat monitoring; the processing strategies at each level are comprehensively compared and weighed to determine the processing priorities and response measures of each level under different circumstances; the high-, medium- and low-level processing strategies are integrated and merged to form a comprehensive hierarchical processing strategy to provide the system with comprehensive response and management of various security threats and risks.
[0139] In this specification, a network information security analysis system based on big data is provided, which is used to execute the above-mentioned network information security analysis method based on big data. The network information security analysis system based on big data includes:
[0140] The traffic analysis module is used to obtain basic network information data by using Internet big data; perform network traffic analysis on the basic network information data to generate basic network traffic information data;
[0141] The network security model training module is used to perform data preprocessing on the network basic traffic information data to obtain standard network basic information data; perform abnormal behavior detection on the standard network basic information data to obtain network information abnormal behavior data; use machine learning methods to perform model training on the standard abnormal behavior data to generate a network security model;
[0142] The security prediction module is used to use the network security model to perform security prediction on the standard abnormal behavior data to obtain the security prediction value; execute the security detection strategy based on the security prediction value to generate the security analysis result; compare the security analysis result with the preset security threshold to generate the first type of feedback data and the second type of feedback data; merge the first type of feedback data and the second type of feedback data to generate a feedback data set;
[0143] The security enhancement module is used to perform AAC technical security identification on the returned data set based on the preset firewall and generate an AI firewall protection strategy; perform attack type analysis on the network basic traffic information data according to the AI firewall protection strategy to obtain attack type analysis data; use the attack type analysis data to perform firewall reinforcement processing on the preset firewall to generate an AI intelligent firewall; perform abnormal intrusion behavior analysis based on the AI firewall to obtain abnormal intrusion behavior monitoring data; open up storage space based on abnormal intrusion data to obtain abnormal data storage space; perform IP identification processing on abnormal intrusion data based on the abnormal data storage space to generate abnormal data IP identification; obtain attack range data by performing attack range analysis on the abnormal data IP identification; construct a disaster area strategy based on the attack range data to generate a hierarchical processing strategy.
[0144] The beneficial effect of the present invention is that through multiple modules such as traffic analysis, security model training, security prediction and security enhancement, it is possible to realize intelligent identification and real-time prediction of abnormal network behavior. In particular, based on the intrusion behavior analysis and dynamic protection strategy generation of AI intelligent firewall, the system has the ability to flexibly adjust the protection strategy, and can effectively respond to the ever-changing network security threats. By analyzing the IP identification and attack range of abnormal data, the system can quickly locate the affected area and generate corresponding disaster recovery processing strategies, providing comprehensive protection for network security. Compared with the existing network security analysis system, the system has a higher level of intelligence, automation and real-time monitoring capabilities, and can more effectively respond to complex and changing network security challenges. Therefore, the present invention improves the efficiency and adaptability of network information security processing by integrating technologies such as big data, machine learning and artificial intelligence.
[0145] The above description is only a specific embodiment of the present invention, so that those skilled in the art can understand or implement the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but should conform to the widest scope consistent with the principles and novel features invented herein.
Claims
1. A network information security analysis method based on big data, characterized in that: The following steps are involved: Step S1: using Internet big data to obtain network basic information data; Perform network traffic analysis on network basic information data to generate network basic traffic information data; Step S2: preprocessing the network basic traffic information data to obtain standard network basic information data; Perform abnormal behavior detection on standard network basic information data to obtain network information abnormal behavior data; use machine learning methods to train models on standard abnormal behavior data to generate network security models; Step S3: Use the network security model to perform security prediction on the standard abnormal behavior data to obtain a security prediction value; Execute the security detection strategy based on the security prediction value to generate a security analysis result; compare the security analysis result with the preset security threshold to generate the first type of feedback data and the second type of feedback data; merge the first type of feedback data and the second type of feedback data to generate a feedback data set; wherein step S3 is specifically as follows: Step S31: Use the network security model to perform security prediction on the standard abnormal behavior data to obtain a security prediction value; Step S32: Execute the security detection strategy based on the security prediction value to generate a security analysis execution result, wherein the security detection strategy includes a system security strategy, a data security strategy and a user security strategy, and the security analysis execution result includes a system security analysis execution result, a data security analysis execution result and a user security analysis execution result; wherein step S32 is specifically as follows: Step S321: Execute the security detection strategy based on the security prediction value to generate a security analysis execution result. The security detection strategy is divided into system security strategy, data security strategy and user security strategy; Step S322: Performing policy execution judgment on the security analysis execution result, and when confirming that the security analysis execution result is to execute the system security policy, performing a network hierarchy and system component security review according to the system security policy to obtain review result data; performing network topology redeployment based on the review result data to obtain network topology deployment result data; performing software and hardware update through the network topology deployment result data to obtain software and hardware update result data; and combining the review result data, network topology deployment result data, and software and hardware update result data to obtain the system security analysis execution result; Step S323: When the security analysis execution result is confirmed to be the execution of the data security policy, sensitive data analysis is performed on the network information abnormal behavior data according to the data security policy to obtain sensitive data; the sensitive data is encrypted to obtain encrypted data; authorization restrictions are performed based on the encrypted data to obtain an authority control user; authorization restrictions are performed on the encrypted data according to the authority control user to obtain authorization restriction data; network basic traffic information data is backed up to obtain network basic backup data; the encrypted data, authorization restriction data and network basic backup data are aggregated to obtain the data security analysis execution result; Step S324: when it is confirmed that the security analysis execution result is to execute the user security policy, the user identity biometric factor verification is performed according to the user security policy to obtain user identity verification result data; user behavior monitoring is performed based on the user identity verification result data to obtain user behavior monitoring result data; the user identity verification result data and the user behavior monitoring result data are combined to obtain the user security analysis execution result; Step S33: Perform security performance evaluation on the security analysis execution result to generate security performance evaluation data; compare the security performance evaluation data with the preset security threshold, and when the security performance evaluation data is greater than or equal to the preset security threshold, perform content blocking processing on the corresponding network basic information data to generate the first type of return data; Step S34: when the security performance evaluation data is less than the preset security threshold, the corresponding network basic information data is continuously detected and processed to generate the second type of return data; Step S35: merging the first type of returned data and the second type of returned data to generate a returned data set; Step S4: Based on the preset firewall, perform AAC technology security identification on the returned data set to generate an AI firewall protection strategy; perform attack type analysis on the network basic traffic information data according to the AI firewall protection strategy to obtain attack type analysis data; use the attack type analysis data to perform firewall reinforcement processing on the preset firewall to generate an AI intelligent firewall; perform abnormal intrusion behavior analysis based on the AI firewall to obtain abnormal intrusion behavior monitoring data; open up storage space according to the abnormal intrusion data to obtain abnormal data storage space; perform IP identification processing on the abnormal intrusion data based on the abnormal data storage space to generate an abnormal data IP identification; perform attack range analysis on the abnormal data IP identification to obtain attack range data; construct a disaster area strategy based on the attack range data to generate a hierarchical processing strategy, wherein step S4 is specifically as follows: Step S41: Pass the returned data set to the preset firewall, and use the AAC technology to adaptively adjust the preset firewall to generate an AI firewall protection strategy; Step S42: Perform intelligent intrusion detection on the network basic traffic information data according to the AI firewall protection strategy to obtain firewall intrusion interception data; perform attack type analysis on the firewall intrusion interception data to generate attack type analysis data; Step S43: Using the attack type analysis data, the preset firewall is reinforced to generate an AI intelligent firewall; Step S44: Use the AI intelligent firewall to perform abnormal behavior monitoring to obtain abnormal intrusion behavior monitoring data, wherein the abnormal behavior monitoring includes abnormal traffic monitoring, abnormal request frequency monitoring, and abnormal intrusion behavior feature monitoring; Step S45: using the intrusion detection system technology to open up storage space for abnormal intrusion behavior monitoring data to obtain abnormal data storage space; based on the abnormal data storage space, IP identification is performed on the abnormal intrusion behavior monitoring data to generate abnormal data IP identification; attack range monitoring is performed through the abnormal data IP identification to generate attack range data; Step S46: divide the network system into affected areas according to the attack range data, and generate affected areas, wherein the affected areas include high-level affected areas, medium-level affected areas, and low-level affected areas; perform regional disaster grade classification based on the affected areas, and generate grade classification processing strategies, wherein the grade classification processing strategies include high-level processing strategies, medium-level processing strategies, and low-level processing strategies; wherein step S4 is specifically as follows: Step S461: dividing the network system into affected areas according to the attack range data, wherein the affected areas include high-level affected areas, medium-level affected areas, and low-level affected areas; Step S462: Perform intrusion impact analysis on the high-level disaster-affected area to generate intrusion impact analysis data; perform security isolation on the high-level disaster-affected area based on the intrusion impact analysis data to generate a high-level processing strategy; Step S463: Perform vulnerability analysis on the medium-level disaster-affected area to generate vulnerability analysis data; perform vulnerability repair on the medium-level disaster-affected area according to the vulnerability analysis data to generate a medium-level processing strategy; Step S464: Monitor the threat situation of the low-level disaster-stricken areas and generate threat monitoring data; issue security warnings to the low-level disaster-stricken areas based on the threat monitoring data and generate low-level processing strategies; Step S465: merge the high-level processing strategy, the middle-level processing strategy and the low-level processing strategy to generate a hierarchical processing strategy.
2. The network information security analysis method based on big data according to claim 1, characterized in that: Step S1 includes the following steps: Step S11: using a data acquisition tool to obtain a network basic information data packet; Step S12: Decomposing the network basic information data packet to generate network basic information data; Step S13: Perform traffic analysis on the network basic information data to generate network basic traffic information data.
3. The network information security analysis method based on big data according to claim 1, characterized in that: Step S2 includes the following steps: Step S21: Clean the network basic traffic information data to generate network basic information cleansing data; Step S22: integrating the network basic information cleansing data to generate network basic information integrated data; Step S23: standardizing the network basic information integration data to obtain standard network basic information data; Step S24: performing abnormal behavior detection on the standard network basic information data to obtain network information abnormal behavior data; Step S25: Import the network information abnormal behavior data into the convolutional neural network and the recursive neural network for model fusion to generate a network security model.
4. The network information security analysis method based on big data according to claim 3, characterized in that: Step S24 includes the following steps: Step S241: extracting access timestamps from standard network basic information data to generate network information access timestamps; performing time series conversion on standard network basic information data according to the network information access timestamps to generate time series conversion data; Step S242: performing time domain data analysis on the time series conversion data to generate a time domain signal; performing Fourier transformation on the time series conversion data to generate a frequency domain signal; constructing a spectrum diagram based on the time domain signal and the frequency domain signal to generate a network access spectrum diagram; Step S243: performing abnormal frequency peak analysis on the network access spectrum diagram to obtain abnormal network information behavior data.
5. The network information security analysis method based on big data according to claim 3, characterized in that: Step S25 includes the following steps: Step S251: dividing the network information abnormal behavior data into data sets to generate training data and iteration data; importing the training data into the convolutional neural network and the recursive neural network for model output to obtain convolutional neural network output data and recursive neural network output data; fusing the convolutional neural network output data and the recursive neural network output data in series to obtain fused data; Step S252: performing one-dimensional vector arrangement on the fused data based on the stack function to generate one-dimensional vector arrangement data; Step S253: performing a two-dimensional matrix stacking operation on the fused data to generate two-dimensional matrix stacking data; Step S254: performing model optimization on the one-dimensional vector arrangement data and the two-dimensional matrix stacking data through a loss function to generate a network security training model; Step S255: Iteratively adjust the network security training model according to the iteration data to generate a network security model.
6. A network information security analysis system based on big data, characterized in that: Used to execute the network information security analysis method based on big data as claimed in claim 1, the network information security analysis system based on big data includes: The traffic analysis module is used to obtain basic network information data by using Internet big data; perform network traffic analysis on the basic network information data to generate basic network traffic information data; The network security model training module is used to perform data preprocessing on the network basic traffic information data to obtain standard network basic information data; perform abnormal behavior detection on the standard network basic information data to obtain network information abnormal behavior data; use machine learning methods to perform model training on the standard abnormal behavior data to generate a network security model; The security prediction module is used to use the network security model to perform security prediction on the standard abnormal behavior data to obtain the security prediction value; execute the security detection strategy based on the security prediction value to generate the security analysis result; compare the security analysis result with the preset security threshold to generate the first type of feedback data and the second type of feedback data; merge the first type of feedback data and the second type of feedback data to generate a feedback data set; The security enhancement module is used to perform AAC technical security identification on the returned data set based on the preset firewall and generate an AI firewall protection strategy; perform attack type analysis on the network basic traffic information data according to the AI firewall protection strategy to obtain attack type analysis data; use the attack type analysis data to perform firewall reinforcement processing on the preset firewall to generate an AI intelligent firewall; perform abnormal intrusion behavior analysis based on the AI firewall to obtain abnormal intrusion behavior monitoring data; open up storage space based on abnormal intrusion data to obtain abnormal data storage space; perform IP identification processing on abnormal intrusion data based on the abnormal data storage space to generate abnormal data IP identification; obtain attack range data by performing attack range analysis on the abnormal data IP identification; construct a disaster area strategy based on the attack range data to generate a hierarchical processing strategy.
Citation Information
Patent Citations
Data anti-intrusion method based on big data and artificial intelligence and big data server
CN112615865A
Ai cybersecurity system monitoring wireless data transmissions
US20220225101A1