A network information security analysis method and system based on big data

By collecting real-time and historical data at key network nodes, training network traffic prediction models, and analyzing network information abnormalities in combination with weather data, the problem that the existing technology cannot comprehensively analyze the impact of network traffic and user behavior on network information security is solved, and a more accurate and comprehensive big data network information security analysis is achieved.

CN118748600BActive Publication Date: 2025-06-27BEIJING MASHANG TRY TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410773620.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-17
Publication Date
2025-06-27
Estimated Expiration
2044-06-17

AI Technical Summary

Technical Problem

The prior art cannot conduct a comprehensive analysis of network information security based on network traffic and user behavior.

Method used

By setting up a data collector at key network nodes, real-time and historical data can be collected, including network traffic, configuration information, user behavior data and weather data. Use this data to train the network traffic prediction model, and determine the abnormal coefficient of the network information based on the model and weather data. If the abnormal coefficient is less than the threshold, an alarm information is generated.

Benefits of technology

It improves the accuracy and adaptability of network traffic prediction, enhances the comprehensiveness and objectivity of network information security analysis, and can promptly detect network information abnormalities and generate alarms.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118748600B_ABST
    Figure CN118748600B_ABST
Patent Text Reader

Abstract

The present invention provides a network information security analysis method and system based on big data, which relates to the technical field of network information security. The method includes: collecting real-time data and historical data in the network through data collectors set at key network nodes; obtaining real-time weather data in the area where network devices are located; training a network traffic prediction model using historical data to obtain a trained network traffic prediction model; obtaining predicted network traffic data according to the trained network traffic prediction model; determining a network information anomaly coefficient according to the real-time data, the predicted network traffic data and the real-time weather data; and generating an alarm message if the network information anomaly coefficient is less than a set anomaly coefficient threshold. According to the present invention, network information security can be analyzed based on both network traffic and user behavior, improving the comprehensiveness and objectivity of network information security analysis.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network information security, and in particular, to a network information security analysis method and system based on big data. Background Art

[0002] In the related art, CN117478349A discloses a network information security maintenance system based on big data, which relates to the field of big data technology; an information collection module is used to obtain the information source of network information; an information processing module obtains an information source index according to the level of the information source and the account credit score; obtains an information quality index according to the level of information quality; obtains a security index according to the information source index and the information quality index; the information processing module sets a security index range; when the security index belongs to the security index range, the corresponding network information is marked as secure information; when the security index belongs to the suspected security index range, the corresponding network information is marked as suspected information; when the security index belongs to the error security index range, the corresponding network information is marked as dangerous information; a security alarm module deletes the network information marked as dangerous information and reduces the account credit score of the corresponding uploading user; improving the security and greenness of the network environment.

[0003] CN115396167A discloses a network information security protection method based on big data, belonging to the field of network information security, which solves the problem of how to monitor network attack data to ensure network information security; an abnormal data detection unit detects abnormal data in the cloud server and sends it to the network range module; the attacker in the network range module sends the network attack data in the abnormal data to the cloud server virtual machine through network routing, the defense unit intercepts the network attack data, and the attack and defense detection unit monitors and records and analyzes the attack behavior characteristics of the attacker and the defense behavior characteristics of the defense unit in real time, and is cracked by professional technicians and the cloud server is fortified; the local server or local computer filters network data, sets pseudo-system vulnerabilities, professional technicians analyze the network attack data, fortify the real local server or local computer, and the security steward module comprehensively monitors the local computer.

[0004] Based on the above related technologies, the problem of difficult to monitor network attack data to ensure network information security is solved. However, the related technologies do not consider the impact of network traffic monitoring and user behavior monitoring on network information security, that is, it is impossible to comprehensively analyze network information security according to network traffic and user behavior.

[0005] The information disclosed in the background art section of the present application is only intended to deepen the understanding of the general background art of the present application, and should not be regarded as an admission or any form of suggestion that this information constitutes the prior art known to those skilled in the art. Summary of the Invention

[0006] The present invention provides a method and system for network information security analysis based on big data, which can solve the technical problem that the related technology cannot comprehensively analyze network information security according to network traffic and user behavior.

[0007] According to the first aspect of the embodiments of the present invention, a method for network information security analysis based on big data is provided, including:

[0008] At multiple moments in the current time period, collect real-time data and historical data in the network through data collectors set at key network nodes, where the real-time data includes: network traffic, configuration information, and user behavior data, and the historical data includes: historical configuration information and historical user behavior data;

[0009] At multiple moments in the current time period, obtain real-time weather data in the area where the network device is located, where the real-time weather data includes: humidity data and wind force data;

[0010] Use the historical data to train a network traffic prediction model to obtain a trained network traffic prediction model;

[0011] According to the trained network traffic prediction model, process the configuration information and the user behavior data to obtain predicted network traffic data at multiple moments in the current time period;

[0012] Determine a network information anomaly coefficient according to the real-time data, the predicted network traffic data, the real-time weather data, the user behavior data, and the historical user behavior data at multiple moments in the current time period;

[0013] If the network information anomaly coefficient is less than a set anomaly coefficient threshold, generate an alarm message.

[0014] According to the second aspect of the present invention, a system for network information security analysis based on big data is provided, including:

[0015] A network data collection module, at multiple moments in the current time period, collect real-time data and historical data in the network through data collectors set at key network nodes, where the real-time data includes: network traffic, configuration information, and user behavior data, and the historical data includes: historical configuration information and historical user behavior data;

[0016] A weather data collection module, at multiple moments in the current time period, obtain real-time weather data in the area where the network device is located, where the real-time weather data includes: humidity data and wind force data;

[0017] A model training module that uses the historical data to train a network traffic prediction model to obtain a trained network traffic prediction model;

[0018] A traffic prediction module that processes the configuration information and the user behavior data according to the trained network traffic prediction model to obtain predicted network traffic data at multiple moments in the current time period;

[0019] An anomaly coefficient module that determines a network information anomaly coefficient based on the real-time data at multiple moments in the current time period, the predicted network traffic data, the real-time weather data, the user behavior data, and the historical user behavior data;

[0020] An alarm module that generates an alarm message if the network information anomaly coefficient is less than a set anomaly coefficient threshold.

[0021] Technical effects: According to the present invention, network traffic can be predicted. When predicting network traffic data, a network traffic prediction model is trained based on the influence of configuration information and user behavior data on network traffic, enhancing the adaptability of the network traffic prediction model to the current network configuration environment and user behavior, improving the accuracy of network traffic prediction results. Further, based on both network traffic and user behavior, network information security is analyzed, improving the comprehensiveness and objectivity of network information security analysis. When determining the user behavior influence coefficient, the user behavior influence coefficient is determined according to historical user behavior data. During the operation process, the influence of user behavior on network traffic can be evaluated from three aspects: file transfer size status, page access status, and application usage status, improving the comprehensiveness and accuracy of the calculation of the user behavior influence coefficient. When determining the training loss function of the network traffic prediction model, the influence of network traffic shaping configuration information, interface configuration information, routing configuration information, and security configuration information on network traffic can be used to determine the influence of the above data on the error of predicting network data. Then, based on this influence, as well as the relative error of predicting network traffic data and the user behavior influence coefficient, the training loss function is set, enabling the network traffic prediction model to reduce the training loss function during the training process and making the trained network traffic prediction model more suitable for predicting network traffic under the user behavior and configuration information of the current date, more specifically improving the accuracy of the network traffic prediction model. When determining the user behavior anomaly coefficient, the user behavior anomaly coefficient is determined according to user behavior data and historical user behavior data. During the operation process, the user behavior anomaly coefficient is determined from two aspects: the user's login status and the security event trigger status. When determining the user's login status, the cosine similarity operation is performed between the user login vector of the current time period and the historical user login vectors of multiple historical time periods, and the maximum value of the cosine similarity is taken to determine the user's login status, improving the comprehensiveness, accuracy, and objectivity of the user behavior anomaly coefficient.

[0022] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and do not limit the present invention. Other features and aspects of the present invention will become clearer based on the following detailed description of exemplary embodiments with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other embodiments can be obtained based on these drawings.

[0024] Figure 1Schematic diagram of the process of a big data-based network information security analysis method according to an embodiment of the present invention is exemplarily shown;

[0025] Figure 2 Block diagram of a big data-based network information security analysis system according to an embodiment of the present invention is exemplarily shown. Detailed implementation manners

[0026] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are only a part rather than all of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0027] The technical solutions of the present invention will be described in detail below with specific embodiments. These specific embodiments may be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.

[0028] Figure 1 Schematic diagram of the process of a big data-based network information security analysis method according to an embodiment of the present invention is exemplarily shown. The method includes:

[0029] Step S101, at multiple moments in the current time period, collect real-time data and historical data in the network through data collectors set at key network nodes, where the real-time data includes: network traffic, configuration information, and user behavior data, and the historical data includes: historical configuration information and historical user behavior data;

[0030] Step S102, at multiple moments in the current time period, obtain real-time weather data in the area where the network device is located, where the real-time weather data includes: humidity data and wind force data;

[0031] Step S103, use the historical data to train a network traffic prediction model to obtain a trained network traffic prediction model;

[0032] Step S104, according to the trained network traffic prediction model, process the configuration information and the user behavior data to obtain predicted network traffic data at multiple moments in the current time period;

[0033] Step S105, determine a network information anomaly coefficient according to the real-time data, the predicted network traffic data, the real-time weather data, the user behavior data, and the historical user behavior data at multiple moments in the current time period;

[0034] Step S106, if the network information anomaly coefficient is less than a set anomaly coefficient threshold, generate an alarm message.

[0035] According to the big data-based network information security analysis method of an embodiment of the present invention, network traffic can be predicted. When predicting network traffic data, based on the influence of configuration information and user behavior data on network traffic, a network traffic prediction model is trained to improve the adaptability of the network traffic prediction model to the current network configuration environment and user behavior, and improve the accuracy of the network traffic prediction result. Further, based on both network traffic and user behavior, network information security is analyzed, improving the comprehensiveness and objectivity of network information security analysis.

[0036] According to an embodiment of the present invention, in step S101, at multiple moments in the current time period, real-time data and historical data in the network are collected through data collectors set at network key nodes, where the real-time data includes: network traffic, configuration information, and user behavior data, and the historical data includes: historical configuration information and historical user behavior data.

[0037] For example, at multiple moments in the current time period, through data collectors (such as traffic monitoring devices, security audit devices, etc.) set at network key nodes, network traffic, configuration information, and user behavior data in the network are collected. By analyzing network traffic, abnormal network activities (such as DDoS attacks, malicious traffic, etc.) can be identified. By analyzing configuration information, the network status can be identified. By analyzing user behavior data, abnormal user activities (such as illegal logins, unauthorized access, etc.) can be identified, and the obtained historical configuration information and historical user behavior data are stored.

[0038] According to an embodiment of the present invention, in step S102, at multiple moments in the current time period, real-time weather data in the area where the network device is located is obtained, where the real-time weather data includes: humidity data and wind force data.

[0039] For example, at multiple moments in the current time period, humidity data and wind force data in the area where the network device is located are collected through a humidity sensor and a wind force sensor.

[0040] According to an embodiment of the present invention, in step S103, the historical data is used to train a network traffic prediction model to obtain a trained network traffic prediction model.

[0041] According to an embodiment of the present invention, step S103 includes:

[0042] Determine a user behavior impact coefficient according to the historical user behavior data, where the historical user behavior data includes: page view volume, number of application programs, file transfer volume, and file size;

[0043] Process the historical configuration information and historical user behavior data for multiple time periods in the previous historical date of the current date through a network traffic prediction model to obtain predicted network traffic data for multiple moments in multiple time periods in the previous historical date of the current date;

[0044] Obtain historical network traffic data for multiple moments in multiple time periods in the previous historical date of the current date;

[0045] Determine a training loss function according to the historical configuration information, the user behavior impact coefficient, the predicted network traffic data, and the historical network traffic data, where the historical configuration information includes: routing configuration information, interface bandwidth configuration information, network traffic shaping configuration information, and security configuration information;

[0046] Train the network traffic prediction model according to the training loss function to obtain a trained network traffic prediction model.

[0047] For example, determine the impact of user operations on network traffic according to the page view volume accessed by the user, the number of application programs used, the file transfer volume and file size transferred, and obtain a user behavior impact coefficient; the network traffic prediction model is a deep learning neural network model, which can be processed based on historical configuration information and historical user behavior data to obtain predicted network traffic data for multiple moments in multiple time periods in the previous historical date of the current date; obtain the historical network traffic data of the previous historical date of the current date. Determine a training loss function according to the predicted network traffic data, the historical network traffic data, the historical configuration information, and the user behavior impact coefficient; train the network traffic prediction model according to the training loss function.

[0048] According to an embodiment of the present invention, determining a user behavior impact coefficient according to the historical user behavior data includes: determining the user behavior impact coefficient U at the jth moment of the kth time period in the previous historical date of the current date according to formula (1) k,j ,

[0049]

[0050] where θ1, θ2, and θ3 are preset weights, FS k,i,j is the file size of the ith file transmitted at the jth moment of the kth time period in the previous historical date of the current date, F T is a preset file traffic threshold, Pk,j The page view volume at the j-th moment of the k-th time period in the previous historical date of the current date, P T The preset page traffic threshold, A k,j The number of application programs at the j-th moment of the k-th time period in the previous historical date of the current date, A T The preset application traffic threshold, n is the number of downloaded files, i ≤ n, and both i and n are positive integers.

[0051] According to an embodiment of the present invention, It is the ratio of the total network traffic consumed by all files transmitted at the j-th moment of the k-th time period in the previous historical date of the current date to the preset file traffic threshold. The closer this ratio is to 1, the smaller the impact of the user's file transmission behavior on the network traffic. Thus, the change in the file transmission size has a smaller impact on the error of predicting network traffic data. It is the ratio of the network traffic consumed by the accessed page at the j-th moment of the k-th time period in the previous historical date of the current date to the preset page traffic threshold. The closer this ratio is to 1, the smaller the impact of the user's page view volume on the network traffic. Thus, the change in the page view volume has a smaller impact on the error of predicting network traffic data. It is the ratio of the network traffic consumed by the application programs used by the user at the j-th moment of the k-th time period in the previous historical date of the current date to the preset application traffic threshold. The closer this ratio is to 1, the smaller the impact of the number of application programs used by the user on the network traffic. Thus, the change in the number of application programs has a smaller impact on the error of predicting network traffic data.

[0052] In this way, according to the historical user behavior data, the user behavior influence coefficient is determined. During the operation process, the impact of user behavior on network traffic can be evaluated from three aspects: the file transmission size status, the page access status, and the application program usage status, improving the comprehensiveness and accuracy of the calculation of the user behavior influence coefficient.

[0053] According to an embodiment of the present invention, a training loss function is determined based on the historical configuration information, the user behavior influence coefficient, the predicted network traffic data, and the historical network traffic data, including:

[0054] Determine the network configuration state vector according to the routing configuration information and the security configuration information;

[0055] Determine the training loss function Loss of the network traffic prediction model according to formula (2) T ,

[0056]

[0057] Among them, NF k,j is the network traffic at the j-th moment of the k-th time period in the previous historical date of the current date, NF k,j,p is the predicted network traffic data at the j-th moment of the k-th time period in the previous historical date of the current date, N k,j is the network traffic shaping configuration information at the j-th moment of the k-th time period in the previous historical date of the current date, I k,j is the interface bandwidth configuration information at the j-th moment of the k-th time period in the previous historical date of the current date, R k,j is the routing configuration information at the j-th moment of the k-th time period in the previous historical date of the current date, S k,j is the security configuration information at the j-th moment of the k-th time period in the previous historical date of the current date, N k,j,T is the standard network traffic shaping configuration information, I k,j,T is the standard interface bandwidth configuration information, R k,j,T is the standard routing configuration information, S k,j,T is the standard security configuration information, is the network configuration status vector, is the standard network configuration status vector, U k,j is the user behavior influence coefficient at the j-th moment of the k-th time period in the previous historical date of the current date, K is the number of time periods in the previous historical date, m is the number of moments in the time period, j ≤ m, k ≤ K, and k, j, m, and K are all positive integers.

[0058] According to an embodiment of the present invention, is the ratio of the interface bandwidth configuration information at the j-th moment of the k-th time period in the previous historical date of the current date to the standard interface bandwidth configuration information. The closer this ratio is to 1, the smaller the impact of the change in the interface bandwidth configuration information on the error of the predicted network traffic data. is the cosine similarity between the network configuration status vector and the standard network configuration status vector. The closer this cosine similarity is to 1, the smaller the impact of the changes in the routing configuration information and the security configuration information on the error of the predicted network traffic data. is the cosine similarity between the vector determined by the network traffic shaping configuration information and the vector determined by the standard network traffic shaping configuration information. The closer this cosine similarity is to 1, the smaller the impact of the change in the network traffic shaping configuration information on the error of the predicted network traffic data. It is shown that the similarity between the interface bandwidth configuration information, the network configuration status vector and the standard network configuration status vector is positively correlated with the network traffic, and the similarity between the network traffic shaping configuration information and the standard network traffic shaping configuration information is negatively correlated with the network traffic. For example, the larger the bandwidth of the interface, the faster the transmission speed of the network traffic. The load balancing function in the routing configuration information can disperse the network traffic to multiple paths or devices to ensure the efficient transmission of the network traffic. The smaller the difference between the routing configuration information and the standard routing configuration information, the larger the network traffic. The security configuration can prevent the policy from not matching the actual network topology and ensure the smooth transmission and security of the network traffic. The smaller the difference between the security configuration information and the standard security configuration information, the larger the network traffic. Network traffic shaping is mainly used for traffic control and preventing network abuse. The smaller the difference between the network traffic shaping configuration information and the standard network traffic shaping configuration information, the better the traffic control effect and the smaller the network traffic. Therefore, the items related to the interface bandwidth configuration information, the routing configuration information and the security configuration information are placed in the numerator, indicating that the larger the interface bandwidth configuration information is relative to the standard network bandwidth configuration information, the more similar the network configuration status vector is to the standard network configuration status vector, that is, the larger the value of, the larger the network traffic and the greater the impact on the error of the predicted network traffic data. The items related to the network traffic shaping configuration information are placed in the denominator, indicating that the greater the difference between the network traffic shaping configuration information and the standard network traffic shaping configuration information, that is, the smaller the value of, the larger the network traffic and the greater the impact on the error of the predicted network traffic data. is the ratio of the difference between the network traffic data and the predicted network traffic data at the jth moment of the kth time period of the previous historical date of the current date to the network traffic data at the jth moment of the kth time period of the previous historical date of the current date, that is, the relative error of the predicted network traffic data. U k,j is the user behavior influence coefficient at the jth moment of the kth time period in the previous historical date of the current date. The larger the user behavior influence coefficient, the larger the network traffic and the greater the impact on the error of the predicted network traffic data.

[0059] In this way, the influence of the network traffic shaping configuration information, the interface configuration information, the routing configuration information and the security configuration information on the network traffic can be used to determine the influence of the above data on the error of the predicted network data. Based on this influence, as well as the relative error of the predicted network traffic data and the user behavior influence coefficient, the training loss function can be set, so that during the training process of the network traffic prediction model, the training loss function is reduced, and the trained network traffic prediction model is more applicable to the prediction of network traffic under the user behavior and configuration information of the current date, and more targeted to improve the accuracy of the network traffic prediction model.

[0060] According to an embodiment of the present invention, in step S104, based on the trained network traffic prediction model, the configuration information and the user behavior data are processed to obtain predicted network traffic data at multiple moments in the current time period.

[0061] For example, the configuration information of the current time period and the user behavior data of the current time period are input into the trained network traffic prediction model to obtain predicted network traffic data at multiple moments in the current period.

[0062] According to an embodiment of the present invention, in step S105, based on the real-time data at multiple moments in the current time period, the predicted network traffic data, the real-time weather data, the user behavior data, and the historical user behavior data, a network information anomaly coefficient is determined.

[0063] According to an embodiment of the present invention, step S105 includes:

[0064] Based on the network traffic, the predicted network traffic data, and the real-time weather data, a network traffic anomaly coefficient is determined;

[0065] Based on the user behavior data and the historical user behavior data, a user behavior anomaly coefficient is determined, where the user behavior data includes: user login time, login IP address, login method, and user-triggered security event data, and the historical user behavior data further includes: historical user login time, historical login IP address, and historical login method;

[0066] Based on the network traffic anomaly coefficient and the user behavior anomaly coefficient, a network information anomaly coefficient is determined.

[0067] For example, when extreme weather conditions occur, such as storms, heavy rains, etc., the network condition will be affected to a certain extent. Based on the network traffic, the predicted network traffic data, and the real-time weather data, the abnormal condition of the network traffic is determined to obtain a network traffic anomaly coefficient; by analyzing the user login time, login IP address, login method, and user-triggered security event data, the abnormal condition of the user behavior is determined to obtain a user behavior anomaly coefficient; based on the network traffic anomaly coefficient and the user behavior anomaly coefficient, a weighted sum is performed to determine the network information anomaly coefficient.

[0068] According to an embodiment of the present invention, determining the network traffic anomaly coefficient based on the network traffic, the predicted network traffic data, and the real-time weather data includes: determining the network traffic anomaly coefficient Ab of the current time period according to formula (3) NF ,

[0069]

[0070] Among them, α1 is a preset weight, and NF j is the network traffic at the j-th moment of the current time period, and NF j,p is the predicted network traffic data at the j-th moment of the current time period, and H j is the humidity data at the j-th moment of the current time period, and F j is the wind force data at the j-th moment of the current time period.

[0071] According to an embodiment of the present invention, is a function to be fitted in the form of a sine function, representing a fitting term with a certain periodicity. For example, when the current weather condition is rainy, and half an hour later, the weather condition becomes sunny. During a change cycle, the humidity data and the wind force data will have a transient impact on the network traffic. In , under normal circumstances, the humidity data, the wind force data and the network traffic have a negative correlation. For example, when the humidity data and the wind force data are large, the weather condition may be heavy rain, and extreme weather will affect the network traffic and network transmission equipment. The larger the humidity data and the wind force data, the smaller the network traffic. With the periodic changes of the humidity data and the wind force data within a short time period, the network traffic within a short time can be affected periodically. Therefore, the humidity data and the wind force data at the j-th moment of the current time period can be periodically fitted with the preset weight to express the part of the network traffic change in the current time period that conforms to the transient change. represents the predicted network traffic data considering the influence of weather factors at the j-th moment of the current time period, represents the relative difference between the network traffic at the j-th moment of the current time period and the predicted network traffic data considering the influence of weather factors. The smaller this ratio, the smaller the possibility of network traffic anomalies.

[0072] In this way, the network traffic anomaly coefficient can be determined based on the network traffic, the predicted network traffic data and the real-time weather. During the operation process, the periodic influence of the weather condition on the network traffic within a short time is fully considered, which improves the accuracy, comprehensiveness and objectivity of the calculation of the network traffic anomaly coefficient.

[0073] According to an embodiment of the present invention, according to the user behavior data and the historical user behavior data, the user behavior anomaly coefficient is determined, including:

[0074] Determine the user login vector according to the user behavior data;

[0075] Determine the historical user login vector according to the historical user behavior data;

[0076] Determine the user behavior anomaly coefficient Ab for the current time period according to formula (4). UA ,

[0077]

[0078] where max is the maximum value function, if is the conditional function, LaT is the login time of the user in the current time period, LaI is the login IP address of the user in the current time period, LaM is the login method of the user in the current time period, LaT c is the login time of the user in the c-th historical time period that is the same as the start time of the current time period, LaI c is the login IP address of the user in the c-th historical time period that is the same as the start time of the current time period, LaM c is the login method of the user in the c-th historical time period that is the same as the start time of the current time period, is the user login vector for the current time period, is the historical user login vector for the c-th historical time period that is the same as the start time of the current time period, US o is the number of security events triggered by the user in the current time period, US T is the preset threshold for the number of security event triggers, S is the number of historical time periods, c ≤ S, and both c and S are positive integers.

[0079] According to an embodiment of the present invention, is the cosine similarity between the user login vector for the current time period and the historical user login vector for the c-th historical time period that is the same as the start time of the current time period. The closer this cosine similarity is to 1, the more similar the login time, login IP address, and login method in the current time period are to those in the c-th historical time period that is the same as the start time of the current time period, and the smaller the possibility that the user's login status is abnormal. is the maximum value of the cosine similarities between the user login vector for the current time period and the historical user login vectors for S historical time periods. The above processing of taking the maximum value can be used to determine the maximum security level of the current login status. Based on this, the user behavior anomaly coefficient is determined, enabling the user behavior anomaly coefficient to reflect whether the user's login status is abnormal.

[0080] According to an embodiment of the present invention, the following two situations are represented in the form of a conditional function in formula (4). When US o ≥ US T is satisfied, the number of security events triggered by the user in the current time period is greater than or equal to the preset threshold for the number of security event triggers, indicating that the user's behavior may be abnormal. At this time, the value of the conditional function is 0. When USo <US T When the condition is that the number of security events triggered by the user within the current time period is less than the preset threshold of the number of security event triggers, the value of the conditional function is It represents the difference between the number of security events triggered by the user within the current time period and the preset threshold of the number of security event triggers. The larger this ratio, the smaller the possibility that the user's behavior is abnormal.

[0081] In this way, according to the user behavior data and historical user behavior data, the user behavior anomaly coefficient can be determined. During the operation process, the user behavior anomaly coefficient is determined based on two aspects: the user's login status and the security event trigger status. When determining the user's login status, the cosine similarity operation is performed between the user login vector in the current time period and the historical user login vectors in multiple historical time periods, and the maximum value of the cosine similarity is taken to determine the user's login status, which improves the comprehensiveness, accuracy, and objectivity of the user behavior anomaly coefficient.

[0082] According to an embodiment of the present invention, in step S106, if the network information anomaly coefficient is less than the set anomaly coefficient threshold, an alarm message is generated.

[0083] For example, when the network information anomaly coefficient is less than the anomaly coefficient threshold, it indicates that there are abnormalities in network traffic and user behavior, and an alarm message is generated to remind the user to perform network security maintenance.

[0084] The network information security analysis method based on big data according to an embodiment of the present invention can predict network traffic. When predicting network traffic data, based on the influence of configuration information and user behavior data on network traffic, a network traffic prediction model is trained to improve the adaptability of the network traffic prediction model to the current network configuration environment and user behavior, and improve the accuracy of the network traffic prediction result. Further, based on both network traffic and user behavior, network information security is analyzed, improving the comprehensiveness and objectivity of network information security analysis. When determining the user behavior influence coefficient, the user behavior influence coefficient is determined according to historical user behavior data. During the operation process, the influence of user behavior on network traffic can be judged from three aspects: file transfer size status, page access status, and application program usage status, improving the comprehensiveness and accuracy of the calculation of the user behavior influence coefficient. When determining the training loss function of the network traffic prediction model, the influence of network traffic shaping configuration information, interface configuration information, routing configuration information, and security configuration information on network traffic can be used to determine the influence of the above data on the error of predicting network data. Then, based on this influence, as well as the relative error of predicting network traffic data and the user behavior influence coefficient, the training loss function is set, so that during the training process of the network traffic prediction model, the training loss function is reduced, and the trained network traffic prediction model is more suitable for predicting network traffic under the user behavior and configuration information of the current date, and more specifically improves the accuracy of the network traffic prediction model. When determining the user behavior anomaly coefficient, the user behavior anomaly coefficient can be determined according to user behavior data and historical user behavior data. During the operation process, the user behavior anomaly coefficient is determined from two aspects: the user's login status and the security event trigger status. When determining the user's login status, the cosine similarity operation is performed between the user login vector of the current time period and the historical user login vectors of multiple historical time periods, and the maximum value of the cosine similarity is taken to determine the user's login status, improving the comprehensiveness, accuracy, and objectivity of the user behavior anomaly coefficient.

[0085] Figure 2 Exemplarily, a block diagram of a network information security analysis system based on big data according to an embodiment of the present invention is shown. The system includes:

[0086] A network data collection module, at multiple moments in the current time period, collects real-time data and historical data in the network through data collectors set at key network nodes. Among them, the real-time data includes: network traffic, configuration information, and user behavior data, and the historical data includes: historical configuration information and historical user behavior data;

[0087] A weather data acquisition module obtains real-time weather data of the area where the network device is located at multiple moments in the current time period. The real-time weather data includes humidity data and wind force data.

[0088] A model training module trains a network traffic prediction model using the historical data to obtain a trained network traffic prediction model.

[0089] A traffic prediction module processes the configuration information and the user behavior data according to the trained network traffic prediction model to obtain predicted network traffic data at multiple moments in the current time period.

[0090] An anomaly coefficient module determines a network information anomaly coefficient according to the real-time data at multiple moments in the current time period, the predicted network traffic data, the real-time weather data, the user behavior data, and the historical user behavior data.

[0091] An alarm module generates an alarm message if the network information anomaly coefficient is less than a set anomaly coefficient threshold.

[0092] According to an embodiment of the present invention, there is provided a network information security analysis device based on big data, including: a processor; a memory for storing processor-executable instructions; wherein the processor is configured to call the instructions stored in the memory to execute the network information security analysis method based on big data.

[0093] According to an embodiment of the present invention, there is provided a computer-readable storage medium having computer program instructions stored thereon, and when the computer program instructions are executed by a processor, the network information security analysis method based on big data is implemented.

[0094] The present invention may be a method, an apparatus, a system, and / or a computer program product. The computer program product may include a computer-readable storage medium having computer-readable program instructions for performing various aspects of the present invention loaded thereon.

[0095] Those skilled in the art should understand that the embodiments of the present invention described above and shown in the drawings are only examples and do not limit the present invention. The object of the present invention has been fully and effectively achieved. The function and structural principle of the present invention have been shown and described in the embodiments, and without departing from the principle, the embodiments of the present invention may have any deformation or modification.

Claims

1. A network information security analysis method based on big data, characterized in that: include: At multiple moments in the current time period, real-time data and historical data in the network are collected through data collectors set at key nodes of the network, wherein the real-time data includes: network traffic, configuration information and user behavior data, and the historical data includes: historical configuration information and historical user behavior data; At multiple moments in the current time period, obtaining real-time weather data of the area where the network device is located, wherein the real-time weather data includes: humidity data and wind data; Using the historical data to train a network traffic prediction model to obtain a trained network traffic prediction model; According to the trained network traffic prediction model, the configuration information and the user behavior data are processed to obtain predicted network traffic data at multiple moments in the current time period; Determine a network information anomaly coefficient based on the real-time data at multiple moments in the current time period, the predicted network traffic data, the real-time weather data, and the historical user behavior data; If the network information abnormality coefficient is less than a set abnormality coefficient threshold, generating an alarm message; Determining a network information anomaly coefficient according to the real-time data at multiple moments in the current time period, the predicted network traffic data, the real-time weather data, and the historical user behavior data includes: Determining a network traffic anomaly coefficient according to the network traffic, the predicted network traffic data and the real-time weather data; Determine the user behavior abnormality coefficient according to the user behavior data and historical user behavior data, wherein the user behavior data includes: user login time, login IP address, login method and user-triggered security event data, and the historical user behavior data also includes: historical user login time, historical login IP address and historical login method; Determining a network information abnormality coefficient according to the network traffic abnormality coefficient and the user behavior abnormality coefficient; Determining a network traffic anomaly coefficient according to the network traffic, the predicted network traffic data and the real-time weather data includes: According to the formula Determine the network traffic anomaly coefficient Ab for the current time period NF , where α1 is the preset weight, NF j is the network traffic at the jth moment in the current time period, NF j,p is the predicted network traffic data at the jth moment in the current time period, H j is the humidity data at the jth moment of the current time period, F j is the wind force data at the jth moment of the current time period; Determine the user behavior abnormality coefficient based on the user behavior data and historical user behavior data, including: Determining a user login vector according to the user behavior data; Determining a historical user login vector according to the historical user behavior data; According to the formula Determine the user behavior abnormality coefficient Ab for the current time period UA , where max is the maximum value function, if is the conditional function, LaT is the login time of the user in the current time period, LaI is the login IP address of the user in the current time period, LaM is the login method of the user in the current time period, LaT c is the user's login time in the cth historical time period that is the same as the start time of the current time period, LaI c is the user's login IP address in the cth historical time period that is the same as the start time of the current time period, LaM c is the user's login method in the cth historical time period that is the same as the start time of the current time period, is the user login vector for the current time period, is the historical user login vector of the cth historical time period that is the same as the start time of the current time period, US o The number of security events triggered by the user in the current time period, US T is the preset security event triggering number threshold, S is the number of historical time periods, c≤S, and both c and S are positive integers.

2. The network information security analysis method based on big data according to claim 1 is characterized in that: Using the historical data to train the network traffic prediction model to obtain a trained network traffic prediction model includes: Determining a user behavior influence coefficient according to the historical user behavior data, wherein the historical user behavior data includes: page visits, number of applications, file transfer volume, and file size; Through the network traffic prediction model, the historical configuration information and historical user behavior data of multiple time periods in the previous historical date of the current date are processed to obtain the predicted network traffic data of multiple moments in the multiple time periods in the previous historical date of the current date; Get the historical network traffic data at multiple times in multiple time periods on the previous historical date; Determine a training loss function according to the historical configuration information, the user behavior influence coefficient, the predicted network traffic data and the historical network traffic data, wherein the historical configuration information includes: routing configuration information, interface bandwidth configuration information, network traffic shaping configuration information and security configuration information; The network traffic prediction model is trained according to the training loss function to obtain a trained network traffic prediction model.

3. According to the network information security analysis method based on big data in claim 2, determining the user behavior influence coefficient according to the historical user behavior data comprises: According to the formula Determine the user behavior influence coefficient U at the jth moment in the kth time period of the previous historical date k,j , where θ1, θ2 and θ3 are preset weights, FS k,i,j is the file size of the i-th file transferred at the j-th moment in the k-th time period of the previous historical date, F T is the preset file flow threshold, P k,j is the page views at the jth moment in the kth time period of the previous historical date, P T is the preset page traffic threshold, A k,j A is the number of applications at the jth moment in the kth time period of the previous historical date. T is the preset application traffic threshold, n is the number of downloaded files, i≤n, and both i and n are positive integers.

4. According to the network information security analysis method based on big data in claim 3, determining a training loss function according to the historical configuration information, the user behavior influence coefficient, the predicted network traffic data and the historical network traffic data comprises: Determining a network configuration state vector according to the routing configuration information and the security configuration information; According to the formula Determine the training loss function Loss of the network traffic prediction model T , where NF k,j is the network traffic at the jth moment in the kth time period of the previous historical date, NF k,j,p is the predicted network traffic data at the jth moment in the kth time period of the previous historical date, N k,j is the network traffic shaping configuration information at the jth moment in the kth time period of the previous historical date, I k,j is the interface bandwidth configuration information at the jth moment in the kth time period of the previous historical date. k,j is the routing configuration information at the jth moment in the kth time period of the previous historical date, S k,j is the security configuration information at the jth moment in the kth time period of the previous historical date, N k,j,T For standard network traffic shaping configuration information, I k,j,T is the standard interface bandwidth configuration information, R k,j,T For standard routing configuration information, S k,j,T For standard security configuration information, Configure the state vector for the network, The state vector for the standard network configuration, U k,j is the user behavior influence coefficient at the jth moment in the kth time period in the previous historical date, K is the number of time periods in the previous historical date, m is the number of moments in the time period, j≤m, k≤K, and k, j, m and K are all positive integers.

5. A network information security analysis system based on big data for executing the method according to any one of claims 1 to 4, characterized in that: include: The network data collection module collects real-time data and historical data in the network at multiple moments in the current time period through data collectors set at key network nodes, wherein the real-time data includes: network traffic, configuration information and user behavior data, and the historical data includes: historical configuration information and historical user behavior data; A weather data collection module, which obtains real-time weather data of the area where the network device is located at multiple moments in the current time period, wherein the real-time weather data includes: humidity data and wind data; A model training module, using the historical data to train a network traffic prediction model to obtain a trained network traffic prediction model; A traffic prediction model, processing the configuration information and the user behavior data according to a trained network traffic prediction model, to obtain predicted network traffic data at multiple moments in a current time period; An abnormality coefficient module, determining a network information abnormality coefficient according to the real-time data at multiple moments in the current time period, the predicted network traffic data, the real-time weather data, the user behavior data and the historical user behavior data; The alarm module generates an alarm message if the network information abnormality coefficient is less than a set abnormality coefficient threshold.

6. A network information security analysis device based on big data, comprising: processor; A memory for storing processor-executable instructions; wherein the processor is configured to call the instructions stored in the memory to execute the method according to any one of claims 1 to 4.

7. A computer-readable storage medium, characterized in that: Computer program instructions are stored thereon, and when the computer program instructions are executed by a processor, the method according to any one of claims 1 to 4 is implemented.

Citation Information

Patent Citations

  • Model training method, traffic prediction method, traffic load balancing method and device, and storage medium

    CN115622895A

  • Intelligent data monitoring system and method for Internet information security

    CN116723034A