Data security early warning method, device and electronic equipment

By using a security value calculation and early warning mechanism based on historical data, the problem of the inability to proactively defend against network attacks in existing technologies has been solved. This enables proactive security assessment and early warning of network nodes, thereby improving the network security defense capabilities.

CN118802289BActive Publication Date: 2026-01-23CHINA MOBILE GROUP ZHEJIANG +3
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410352985.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-03-26
Publication Date
2026-01-23
Estimated Expiration
2044-03-26

AI Technical Summary

Technical Problem

Existing technologies cannot proactively defend against cyberattacks; they can only provide passive defense after an attack occurs, lacking proactive assessment and early warning of security risks.

Method used

By determining the target sampling period based on historical data of the target node, target information is obtained, a safety value is calculated, and an early warning is issued when the safety value exceeds the threshold, thus achieving proactive defense.

Benefits of technology

It enables proactive security risk assessment and early warning for network nodes, avoiding the shortcomings of passive defense and improving the proactive defense capability of network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118802289B_ABST
    Figure CN118802289B_ABST
Patent Text Reader

Abstract

The application discloses a data security early warning method and device and electronic equipment, and belongs to the computer field. The method comprises the following steps: determining a target sampling period of a target node based on historical data of the target node in a historical time period; obtaining target information obtained by sampling data of the target node in the target sampling period; calculating a security value of the target node based on the target information; the security value is used for evaluating the security risk of the target node; and in the case that the security value is greater than a preset threshold, a security early warning is performed on the target node.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of computer science, and specifically relates to a data security early warning method, device, and electronic device. Background Technology

[0002] With the advent of the big data era, massive amounts of data converge at network nodes. These nodes are vulnerable to cyberattacks, posing security risks to the data. Furthermore, with the development of big data technology, the forms and methods of cyberattacks have become increasingly diverse. Therefore, node network security has received widespread attention.

[0003] Related technologies typically use firewalls and other techniques to prevent nodes from being attacked by networks. However, this approach can only provide passive defense after an attack has occurred, and it cannot proactively defend against security risks. Summary of the Invention

[0004] This application provides a data security early warning method, device, and electronic device, which can solve the problem that related technologies cannot proactively defend against security risks.

[0005] In a first aspect, embodiments of this application provide a data security early warning method, including:

[0006] The target sampling period of the target node is determined based on the historical data of the target node within the historical time period.

[0007] Obtain target information obtained by sampling data from the target node within the target sampling period;

[0008] Based on the target information, the security value of the target node is calculated; the security value is used to assess the security risk of the target node.

[0009] If the security value exceeds a preset threshold, a security warning is issued to the target node.

[0010] Secondly, embodiments of this application provide a data security early warning device, comprising:

[0011] The determination module is used to determine the data sampling period of the target node based on the historical data of the target node within a historical time period;

[0012] The acquisition module is used to acquire target information obtained by sampling data from the target node within the target sampling period;

[0013] A calculation module is used to calculate the security value of the target node based on the target information; the security value is used to assess the security risk of the target node.

[0014] The early warning module is used to issue a security warning to the target node when the security value is greater than a preset threshold.

[0015] Thirdly, embodiments of this application provide an electronic device including a processor and a memory, wherein the memory stores programs or instructions executable on the processor, and the programs or instructions, when executed by the processor, implement the steps of the method described in the first aspect.

[0016] Fourthly, embodiments of this application provide a computer-readable storage medium on which a program or instructions are stored, which, when executed, implement the steps of the method described in the first aspect.

[0017] Fifthly, embodiments of this application provide a computer program product comprising a computer program that, when executed by a processor, implements the steps of the method described in the first aspect.

[0018] The at least one technical solution provided in the embodiments of this application can achieve the following technical effects:

[0019] In this embodiment, a target sampling period for the target node is determined based on historical data of the target node within a historical time period; target information is obtained by sampling data from the target node within the target sampling period; a security value for the target node is calculated based on the target information; the security value is used to assess the security risk of the target node; and a security warning is issued to the target node if the security value exceeds a preset threshold. Thus, by using historical data of the target node to determine its target sampling period, calculating its security value based on the information obtained from that target sampling period, assessing its security risk using the security value, and issuing a security warning if the security value exceeds a preset threshold, this method eliminates the need for passive defense when a security vulnerability appears on the target node. It allows for proactive defense by assessing security risks using security values, solving the problem of related technologies being unable to proactively defend against security risks. Attached Figure Description

[0020] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present invention and should not be regarded as a limitation on the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0021] Figure 1This is a flowchart of a data security early warning method provided in an embodiment of this application;

[0022] Figure 2 This is a flowchart of a data security early warning method provided in an embodiment of this application;

[0023] Figure 3 This is a flowchart of a data security early warning method provided in an embodiment of this application;

[0024] Figure 4 This is a complete flowchart of a data security early warning method provided in an embodiment of this application;

[0025] Figure 5 This is a structural block diagram of a data security early warning device provided in an embodiment of this application;

[0026] Figure 6 This is a structural block diagram of an electronic device provided in an embodiment of this application. Detailed Implementation

[0027] The technical solutions of the embodiments of this application will be clearly described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this application. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0028] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0029] Therefore, the following detailed description of the embodiments of the invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely to illustrate selected embodiments of the invention. All other embodiments obtained by those skilled in the art based on the embodiments of the invention without inventive effort are within the scope of protection of the invention.

[0030] The data security early warning method provided in this application is applied to network security detection, and in particular, to data security early warning of network nodes. Specifically, it can determine the security value of a target node in real time, and then issue a security warning to the target node when the security value exceeds a preset threshold.

[0031] The data security early warning method provided in this application can be executed by a target device, which can be a single electronic device or multiple electronic devices. That is, the data security early warning method provided in this application can be executed by a single electronic device, which can be a security device (e.g., a security intrusion detection device), a terminal device such as a desktop computer, laptop, mobile phone, or tablet, or a server, such as a standalone physical server, a server cluster composed of multiple servers, or a cloud server capable of cloud computing. When the data security early warning method provided in this application is executed by multiple electronic devices, these multiple electronic devices can form a service cluster, and they cooperate to complete each step.

[0032] The data security early warning method provided in this application will be described in detail below with reference to the accompanying drawings, through specific embodiments and application scenarios.

[0033] Please see Figure 1 , Figure 1 This is a flowchart illustrating a data security early warning method provided in an embodiment of this application. Figure 1 As shown, the method includes the following steps:

[0034] Step 110: Determine the target sampling period of the target node based on the historical data of the target node within the historical time period;

[0035] In this embodiment, the target node can be a single network device or a network of multiple network devices (e.g., a small device network). The historical time period can be a continuous historical period, which can be manually set, such as 20 minutes. The historical data can include the network traffic data of the target node within the historical time period. The fluctuation of the network traffic data can reflect the attack status of the target node to a certain extent. For example, if there is a point in time where the network traffic data suddenly decreases, the sudden decrease in network traffic data at that point in time may be because the target node was attacked near that point in time.

[0036] In this embodiment, the target sampling period can be a time period following the historical time period, such as the current time period. Furthermore, the target sampling period for the target node can be determined based on the fluctuations in the historical data. Specifically, if the frequency of fluctuations in the historical data is high, a smaller target sampling period can be determined; if the frequency of fluctuations in the historical data is low, a larger target sampling period can be determined.

[0037] In one embodiment of this application, the historical data includes attacked data of the target node and network traffic data other than the attacked data. Determining the data sampling period of the target node based on its historical data within a historical time period includes: determining a first average time difference based on the network traffic data, wherein the first average time difference is the average of at least one first time difference, the at least one first time difference being obtained based on the time points when multiple maxima of the network traffic data occur; determining a second average time difference based on the attacked data and the network traffic data, wherein the second average time difference is the average of at least one second time difference, the at least one second time difference being obtained based on the time points when multiple maxima of the network traffic data occur and the attack time point of the attacked data; determining an average attack value based on the attacked data; and determining the data sampling period of the target node based on the first average time difference, the second average time difference, and the average attack value.

[0038] Step 120: Obtain target information obtained by sampling data from the target node within the target sampling period;

[0039] In this embodiment, the target sampling period allows for real-time sampling of the target node's data. Furthermore, since the target sampling period is determined based on the target node's historical data, the sampled data within the target sampling period reflects the data characteristics of the target node itself. The target information may include attack data on the target node within the target sampling period. This attack data allows for further analysis to determine the actual security risks of the target node being attacked.

[0040] In one embodiment of this application, the target information may include vulnerability information of the target node and vulnerability information of the target node's neighboring nodes. The stability of the target node can be analyzed using the vulnerability information of the target node and its neighboring nodes. Furthermore, the stability of the target node can, to some extent, reflect the actual security risk of the target node being attacked.

[0041] Step 130: Based on the target information, calculate the security value of the target node; the security value is used to assess the security risk of the target node;

[0042] In this embodiment, to further quantify the security risk of the target node, the security value of the target node can be calculated based on the data in the target information. Simultaneously, the security value of the target node can be evaluated every target sampling period, allowing for real-time determination of the target node's security value and timely security warnings.

[0043] In this embodiment, the target sampling period can be dynamically determined based on the characteristics of data within a dynamically changing historical time period. Specifically, when the real-time sampled data changes dynamically, the historical time period also changes, and consequently, the data within that historical time period also changes. Based on the dynamically changing characteristics of the data within the historical time period, the target sampling period can be dynamically determined. Data sampling can be performed in real time based on the latest target sampling period, and the safety value of the current target node can be determined.

[0044] In one embodiment of this application, the target information includes vulnerability information of the target node, attack data of the target node, vulnerability information of the target node's neighboring nodes, and attack data of the target node's neighboring nodes; a connection relationship exists between the target node and its neighboring nodes. Calculating the security value of the target node based on the target information includes: calculating the stability of the target node based on the vulnerability information of the target node and the vulnerability information of the target node's neighboring nodes; calculating the target impact value of the target node and the target impact value of the target node's neighboring nodes based on the attack data of the target node and the attack data of the target node's neighboring nodes; and calculating the security value of the target node based on the stability, the target impact value of the target node, and the target impact value of the target node's neighboring nodes.

[0045] Step 140: If the security value is greater than the preset threshold, issue a security warning to the target node.

[0046] In this embodiment, after determining the security value of the target node, since the security value is used to assess the security risk of the target node, when the security value is greater than a preset threshold, the target node can be considered to have a high security risk, and a security warning needs to be issued for the target node. The preset threshold can be a threshold value for the security risk of the node, and can be set manually based on experience; no restriction is imposed here.

[0047] In this embodiment, the data sampling period of the target node is determined based on historical data of the target node within a historical time period; target information obtained by sampling the target node within the target sampling period is acquired; a security value of the target node is calculated based on the target information; the security value is used to assess the security risk of the target node; and a security warning is issued to the target node if the security value is greater than a preset threshold. Thus, the target sampling period of the target node can be determined through its historical data, and the security value of the target node can be calculated based on the information obtained from the target sampling period. The security risk of the target node is then assessed using the security value, and a security warning is issued to the target node if the security value is greater than a preset threshold. This method eliminates the need for passive defense when a security vulnerability appears on the target node; it allows for proactive defense by assessing security risks through security values, thus solving the problem of related technologies being unable to proactively defend against security risks.

[0048] Please see Figure 2 , Figure 2 A flowchart of a data security early warning method provided in this application embodiment is shown below. Figure 2 As shown, the method includes the following steps:

[0049] Step 210: Based on the network traffic data of the target node within a historical time period, determine a first average time difference, wherein the first average time difference is the average of at least one first time difference, and the at least one first time difference is obtained based on the time points when multiple maximum values ​​of the network traffic data occur;

[0050] In this embodiment, the time point at which the maximum value of the network traffic data of the target node occurs within a historical time period can be determined. The maximum value refers to an extremely short period within the historical time period during which, except for the time point of the maximum value, the network traffic data at other time points is lower than the network traffic data at the time point of the maximum value. The fluctuation of the target node's network traffic data can be determined through the maximum value point. Simultaneously, the first average time difference can be used to estimate the fluctuation period of the target node's network traffic data.

[0051] For example, in one embodiment of this application, the step 410 of determining the first average time difference based on the network traffic data of the target node within a historical time period includes: obtaining M maximum values ​​of the network traffic data, where M is an integer greater than 1; obtaining the time point at which each of the M maximum values ​​occurs, resulting in M ​​time points; calculating the first time difference between two time points corresponding to two adjacent maximum values ​​in the M time points according to the time order; and determining the first average time difference based on the first time difference between the two time points corresponding to the two adjacent maximum values.

[0052] In this embodiment, network traffic data of the target node within a historical time period can be obtained, the maximum values ​​in the network traffic data can be determined, and the M maximum values ​​can be sorted from oldest to youngest according to their chronological order to obtain a set of maximum values ​​including M maximum value time points. For each maximum value time point in the set of maximum values, a first time difference between that maximum value time point and the previous maximum value time point can be determined, and M-1 first time differences can be determined. A first average time difference can be determined by calculating the average of the M-1 first time differences.

[0053] In one embodiment of this application, a first time difference can be preset for the first maximum time point in the set of maximum values. Accordingly, M time differences can be determined, and the average of the M time differences can be determined as the first average time difference.

[0054] Step 220: Based on the attacked data and the network traffic data, determine a second average time difference, wherein the second average time difference is the average of at least one second time difference, and the at least one second time difference is obtained based on the time points when multiple maximum values ​​of the network traffic data occur and the attack time point of the attacked data;

[0055] In this embodiment, the attacked data can be data describing the attack on the target node, which can be obtained from the logs of security software such as firewalls on the target node. Both the attacked data and the network traffic data are data from a historical time period. The attacked data may include the attack type, attack time, and vulnerabilities involved in the attack. The relationship between the maximum value time point in the maximum value set and the attack time point can be determined by the time difference between them. However, since the attack data is obtained from security software such as firewalls, there may be a time offset, such as a time lag, meaning the attack may occur later than the maximum value time point of the network traffic data. This time offset can be corrected by setting a threshold value, which can be manually preset based on the relationship between the attack and the traffic.

[0056] In this embodiment of the application, it can be further determined whether the maximum value time point is caused by an attack by checking whether the time difference between the maximum value time point and the attack time point is less than the critical value, and the time point where the time difference is less than the critical value can be identified as the time point of concern.

[0057] For example, in one embodiment of this application, the step 420 of determining the second average time difference based on the attacked data and the network traffic data includes: obtaining N attack time points based on the attacked data; for each maximum value obtained based on the network traffic data, performing the following operations: determining the target time point where the maximum value occurs; obtaining the attack time point that is closest in time to the target time point from the N attack time points as a designated time point; if the difference between the target time point and the designated time point is less than a critical value, determining the target time point where the maximum value occurs as a time point of concern; obtaining K time points of concern arranged in chronological order based on the M maximum values, where K is less than or equal to M and K is an integer greater than 2; calculating the second time difference between every two adjacent time points of concern among the K time points of concern in chronological order; and determining the second average time difference based on the second time difference between every two adjacent time points of concern among the K time points of concern.

[0058] In this embodiment of the application, after obtaining K attention time points, the second time difference between each of the K attention time points and the previous attention time point can be calculated in chronological order, and K-1 second time differences can be determined. The average value of the K-1 time differences can be determined as the second average time difference.

[0059] Step 230: Determine the average attack value based on the attacked data;

[0060] In this embodiment, the attacked data includes at least one of the following: attack type corresponding to N attacks, vulnerabilities involved in the attacks, and the actual impact value caused by the attacks, where N is a positive integer. Specifically, the attacked data may include the attack type of the N attacks, and a standard impact value corresponding to the attack type can be determined based on the attack type. The standard impact value is the impact value obtained by analyzing the attack behavior of that attack type. Network security personnel can pre-estimate the impact if such an attack type occurs based on the attack behavior of different attack types and the configuration of the network devices corresponding to the target node. Simultaneously, the matching rules for the standard impact value can be stored during the configuration process of the target node and can be obtained by matching attack types. The average attack value can be determined using the standard impact values ​​corresponding to the N attacks.

[0061] In this embodiment, the attacked data may include the actual impact value of each of the N attacks. This actual impact value is determined by cybersecurity personnel after the attack occurred. The average attack value can be determined using the actual impact values ​​corresponding to the N attacks.

[0062] In this embodiment, the attacked data may include vulnerability information involved in each of the N attacks. The N attacks can be scored using a Common Vulnerability Scoring System (CVSS) to obtain a common vulnerability score corresponding to each of the N attacks. The common vulnerability score can reflect the severity of the vulnerability and help determine the urgency and importance of the required response. The CVSS score is based on measurements across a series of dimensions, also known as metrics. The CVSS helps establish standards for measuring vulnerability severity, and the CVSS score can be used to determine the priority of vulnerability handling. Specifically, the common vulnerability score can be a maximum of 10 and a minimum of 0. Vulnerabilities with a common vulnerability score between 7 and 10 are considered relatively severe, those between 4 and 6.9 are considered medium-level vulnerabilities, and those between 0 and 3.9 are considered low-level vulnerabilities. The average attack value can be determined using the common vulnerability scores corresponding to the N attacks.

[0063] In one embodiment of this application, the attacked data includes the attack types corresponding to N attacks, the vulnerabilities involved in the attacks, and the actual impact values ​​caused by the attacks; based on the attack type of the j-th attack among the N attacks, the standard impact value of the j-th attack is determined; based on the standard impact value, the actual impact value, and the general vulnerability score of the j-th attack, the target impact value of the j-th attack can be determined by the following formula:

[0064]

[0065] Among them, A j Let X be the target impact value of the j-th attack. j Y represents the actual impact value of the j-th attack. j Let CVSS be the standard impact value of the j-th attack. j The general vulnerability score for the j-th attack.

[0066] In this embodiment, the general vulnerability score is obtained by scoring the vulnerabilities involved in the attack. Using the above formula, the target impact value corresponding to each of the N attacks can be determined. Next, for the N attacks, the time difference between each attack and the previous attack is determined according to the attack time sequence, and a time difference is pre-set for the first attack in the N attacks, thus determining N time differences.

[0067] In this embodiment of the application, after determining N time differences, the average attack value of the attacked data can be calculated based on the target impact values ​​of the N attacks using the following formula:

[0068]

[0069] Where L is the average attack value, Δt j Let A be the time difference between the j-th attack and the previous attack. j Let be the target impact value of the j-th attack.

[0070] In this embodiment, based on the attack type of the j-th attack among the N attacks, the standard impact value of the j-th attack is determined; based on the standard impact value, actual impact value, and general vulnerability score of the j-th attack, the target impact value of the j-th attack is determined by a formula; the general vulnerability score is obtained by scoring the vulnerabilities involved in the attack; based on the target impact values ​​of the M attacks, the average attack value of the attacked data is calculated. Thus, the target impact value in the attacked data of the target node can be comprehensively evaluated through multiple indicators, thereby determining the average attack value of the attacked data, which allows for a more objective determination of the average attack value.

[0071] Step 240: Determine the target sampling period of the target node based on the first average time difference, the second average time difference, and the average attack value;

[0072] In this embodiment, if the first average time difference is less than the second average time difference, it can be determined whether the average attack value is less than a preset attack threshold. If the average attack value is not less than the preset attack threshold, the first average time difference can be determined as the target sampling period of the target node. If the average attack value is less than the preset attack threshold, the product of the first average time difference and the second average time difference can be determined as the target sampling period of the target node.

[0073] In this embodiment of the application, based on the determination of the time point of interest, it is known that the second average time difference must not be less than the first average time difference. The second average time difference can be verified first to ensure it is not less than the first average time difference. If the verification passes, subsequent operations can be performed. If the verification fails, the first and second average time differences can be re-determined.

[0074] In this embodiment of the application, if the second average time difference is not less than the first average time difference, it is further determined whether the average attack value is less than a preset attack threshold. Specifically, if the average attack value is not less than the preset attack threshold, it can be considered that the target node has been subjected to a large attack during the historical time period, and a shorter time period can be used as the target sampling period. At this time, the first average time difference can be directly determined as the target sampling period, that is, the target sampling period is determined by the following formula:

[0075] Δ T =Δt1;

[0076] If the average attack value is less than a preset attack threshold, the target node can be considered to have experienced relatively small attacks during the historical time period, and a longer time period can be used as the target sampling period. In this case, the product of the first average time difference and the second average time difference can be determined as the target sampling period, i.e., the target sampling period can be determined using the following formula:

[0077] Δ T =Δt2×Δt1;

[0078] Where, Δ T Let Δt1 be the target sampling period, Δt2 be the first average time difference, and Δt2 be the second average time difference.

[0079] Step 250: Obtain target information obtained by sampling data from the target node within the target sampling period;

[0080] Step 260: Based on the target information, calculate the security value of the target node; the security value is used to assess the security risk of the target node;

[0081] Step 270: If the security value is greater than the preset threshold, issue a security warning to the target node.

[0082] In this embodiment, the maximum time point in the network traffic data of the target node within a historical time period is determined, and this maximum time point is correlated with the attacked data to analyze whether the occurrence of the maximum point is related to the attacked data. Simultaneously, the average attack value within the historical time period is determined to further determine the data sampling period of the target node. In this process, the data characteristics of the target node within the historical time period can be fully analyzed, and the data sampling period of the target node is determined based on these data characteristics.

[0083] Please see Figure 3 , Figure 3 A flowchart of a data security early warning method provided in this application embodiment is shown below. Figure 3 As shown, the method includes the following steps:

[0084] Step 310: Determine the target sampling period of the target node based on the historical data of the target node within the historical time period;

[0085] Step 320: Obtain target information obtained by sampling data from the target node within the target sampling period; the target information includes vulnerability information of the target node, attacked data of the target node, vulnerability information of the target node's neighboring nodes, and attacked data of the target node's neighboring nodes.

[0086] In this embodiment, the target node can be a single network device or a network of multiple network devices (e.g., a small device network). If the target node is a single network device, the vulnerability information of that network device can be determined as the vulnerability information of the target node. If the target node is a network of multiple network devices, the vulnerability information of each network device in the target node can be determined first, and then the vulnerability information of the target node can be determined through the vulnerability information of each network device. The vulnerability information of the devices can all be obtained through web crawling.

[0087] In this embodiment of the application, in order to more comprehensively evaluate the stability of the target node, vulnerability information of neighboring nodes that are connected to the target node can be obtained. The stability of the target node can be comprehensively evaluated by combining the vulnerability information of the target node and the vulnerability information of the neighboring nodes of the target node.

[0088] In this embodiment of the application, the vulnerability information of the target node, the attack data of the target node, the vulnerability information of the target node's neighboring nodes, and the attack data of the target node's neighboring nodes are all information obtained within the target sampling period.

[0089] Step 330: Calculate the stability of the target node based on the vulnerability information of the target node and the vulnerability information of the target node's neighboring nodes;

[0090] In this embodiment, the stability is used to reflect the vulnerability status of the target node and its neighboring nodes. The stability of the target node can be further determined by the vulnerability information of the target node and the vulnerability information of its neighboring nodes. Vulnerabilities can be evaluated using the CVSS standard.

[0091] For example, in one embodiment of this application, the neighboring nodes include Q nodes, where Q is a positive integer. Step 530, calculating the stability of the target node based on the vulnerability information of the target node and the vulnerability information of its neighboring nodes, includes: obtaining vulnerability parameters of the target node and Q vulnerability parameters corresponding to the Q nodes based on the vulnerability information of the target node and the vulnerability information of its neighboring nodes.

[0092] In this embodiment, if the target node is a single network device, its CVSS value can be determined through the vulnerability information of that network device, and this CVSS value can be used as the vulnerability parameter of the target node. If the target node is a small network of devices, the CVSS value of each network device can be determined through the vulnerability information of each network device in the target node, and the maximum value among the CVSS values ​​of each network device can be used as the vulnerability parameter of the target node; alternatively, the average value of the CVSS values ​​of each network device can also be used as the vulnerability parameter of the target node.

[0093] In this embodiment of the application, the Q vulnerability parameters of the Q neighboring nodes of the target node can be determined using the above method. After obtaining the vulnerability parameters of the target node and the Q vulnerability parameters of the Q neighboring nodes of the target node, the stability can be further determined using the following method.

[0094] If all Q vulnerability parameters are less than the vulnerability parameter of the target node, the stability of the target node is calculated using the following formula:

[0095]

[0096] If R out of the Q vulnerability parameters are greater than the vulnerability parameters of the target node, where R is a positive integer, the stability of the target node can be calculated using the following formula:

[0097]

[0098] Where S is the stability of the target node, and B v Let Q be the vulnerability parameter of the v-th neighboring node, Q be the number of neighboring nodes of the target node, and R be the number of neighboring nodes whose vulnerability parameter is greater than that of the target node.

[0099] In this embodiment, the stability of the target node is determined not only by the vulnerability information of the target node, but also by the vulnerability information of the neighboring nodes adjacent to the target node. A specific method for determining the stability is also proposed, which makes the determination of the stability more objective and reliable.

[0100] Step 340: Based on the attack data of the target node and the attack data of the neighboring nodes of the target node, calculate the target impact value of the target node and the target impact value of the neighboring nodes of the target node;

[0101] In this embodiment, the target impact value of the target node and the target impact value of its neighboring nodes can be calculated by acquiring the attack data of the target node and the attack data of its neighboring nodes within the target sampling period. If both the target impact value of the target node and the target impact value of its neighboring nodes are large, the target node is considered to have a high security risk.

[0102] In this embodiment, attacks in the attacked data are not necessarily attacks that pose a security risk; for example, a large number of devices on the target node at a given time may be considered an attack. Therefore, to more comprehensively assess the security risk of the target node, not only the attacked data of the target node but also the attacked data of its neighboring nodes are included. If the target node and its neighboring nodes both have relatively large impact values, the target node can be considered to have a high security risk.

[0103] In this embodiment of the application, the calculation of the target influence value of the target node and the target influence value of the adjacent nodes of the target node can refer to the calculation method of the target influence value in step 230 above, and will not be repeated here.

[0104] Step 350: Calculate the safety value of the target node based on the stability, the target influence value of the target node, and the target influence values ​​of the neighboring nodes of the target node;

[0105] In this embodiment of the application, in order to more comprehensively assess the security risk of the target node, the security value of the target node can be calculated by the target influence value of the target node, the target influence values ​​of the neighboring nodes of the target node, and the stability of the target node. If the target influence value of the target node is large, the target influence values ​​of the neighboring nodes are also large, and the stability of the target node is low, the security value of the target node can be considered large, that is, the security risk of the target node is large.

[0106] For example, in one embodiment of this application, the security value of the target node can be calculated using the following formula:

[0107]

[0108] Wherein, B is the security value of the target node, and A v Let A be the target influence value of the vth adjacent node, and S be the stability of the target node.

[0109] In this embodiment of the application, the determination of the security value is quantified by a specific formula. The security risk of the target node can be objectively assessed by scoring the security value, and the security warning of the target node can be further provided, so that the accuracy of the security risk assessment of the target node is higher.

[0110] Step 360: If the security value is greater than the preset threshold, issue a security warning to the target node.

[0111] In this embodiment, the security value of the target node is determined by the stability of the target node, the target influence value of the target node, and the target influence values ​​of the neighboring nodes of the target node. The security risk of the target node can be assessed from multiple dimensions, which is more accurate and has higher credibility than assessment from a single dimension.

[0112] Please see Figure 4 , Figure 4 This is a complete flowchart of a data security early warning method provided in an embodiment of this application. Figure 4 As shown in the figure, a data security early warning method provided in this application includes the following steps:

[0113] Step 410: Based on the network traffic data of the target node within a historical time period, determine the first average time difference, wherein the first average time difference is the average of at least one first time difference, and the at least one first time difference is obtained based on the time points when multiple maximum values ​​of the network traffic data occur;

[0114] In this embodiment of the application, M maximum values ​​of the network traffic data can be obtained, where M is an integer greater than 1. The time point of occurrence of each of the M maximum values ​​is obtained, resulting in M ​​time points. Then, the first time difference between the two time points corresponding to two adjacent maximum values ​​can be calculated in chronological order. Based on the first time difference between the two time points corresponding to the two adjacent maximum values, a first average time difference is determined.

[0115] Step 420: Based on the attacked data and the network traffic data, determine a second average time difference, wherein the second average time difference is the average of at least one second time difference, and the at least one second time difference is obtained based on the time points when multiple maximum values ​​of the network traffic data occur and the attack time point of the attacked data;

[0116] In this embodiment, M maximum values ​​of the network traffic data are obtained, where M is an integer greater than 1. Based on the attacked data, N attack time points are obtained. For each of the M maximum values, the following operations are performed: The target time point where the maximum value occurs is determined; the attack time point closest in time to the target time point is selected from the N attack time points and designated as the specified time point; if the difference between the target time point and the specified time point is less than a critical value, the target time point where the maximum value occurs is determined as the time point of interest. Based on the M maximum values, K time points of interest are obtained in chronological order, where K is less than or equal to M and K is an integer greater than 2. The second time difference between every two adjacent time points of interest among the K time points of interest is calculated in chronological order. Based on the second time difference between every two adjacent time points of interest among the K time points of interest, a second average time difference is determined.

[0117] Step 430: Determine the average attack value based on the attacked data;

[0118] In this embodiment of the application, the attacked data includes the attack types corresponding to N attacks, the vulnerabilities involved in the attacks, and the actual impact values ​​caused by the attacks. Based on the attack type of the j-th attack among the N attacks, the standard impact value of the j-th attack is determined; based on the standard impact value, actual impact value, and general vulnerability score of the j-th attack, a formula is used to... Determine the target impact value of the j-th attack; the general vulnerability score is obtained based on the scoring of the vulnerabilities involved in the attack; based on the target impact values ​​of M attacks, calculate the average attack value of the attacked data; where A j Let X be the target impact value of the j-th attack. j Y represents the actual impact value of the j-th attack. j Let CVSS be the standard impact value of the j-th attack. j The general vulnerability score for the j-th attack.

[0119] Step 440: Determine the data sampling period of the target node based on the first average time difference, the second average time difference, and the average attack value;

[0120] Step 450: Obtain target information obtained by sampling data from the target node within the target sampling period; the target information includes vulnerability information of the target node, attacked data of the target node, vulnerability information of the target node's neighboring nodes, and attacked data of the target node's neighboring nodes.

[0121] Step 460: Calculate the stability of the target node based on the vulnerability information of the target node and the vulnerability information of the target node's neighboring nodes;

[0122] In this embodiment, the adjacent nodes include Q nodes, where Q is a positive integer. Based on the vulnerability information of the target node and the vulnerability information of its adjacent nodes, the vulnerability parameters of the target node and the Q vulnerability parameters corresponding to the Q nodes can be obtained. If all Q vulnerability parameters are less than the vulnerability parameter of the target node, the stability of the target node can be calculated using the following formula:

[0123]

[0124] If R out of the Q vulnerability parameters are greater than the vulnerability parameters of the target node, where R is a positive integer, the stability of the target node can be calculated using the following formula:

[0125]

[0126] Where S is the stability of the target node, and B v The vulnerability parameter is the v-th adjacent node.

[0127] Step 470: Based on the attack data of the target node and the attack data of the neighboring nodes of the target node, calculate the target impact value of the target node and the target impact value of the neighboring nodes of the target node;

[0128] Step 480: Calculate the safety value of the target node based on the stability, the target influence value of the target node, and the target influence values ​​of the neighboring nodes of the target node;

[0129] In this embodiment, the security value of the target node can be calculated using the following formula:

[0130]

[0131] Wherein, B is the security value of the target node, and A v Let A be the target influence value of the vth adjacent node, and S be the stability of the target node.

[0132] Step 490: If the security value is greater than the preset threshold, issue a security warning to the target node.

[0133] In this embodiment, the data sampling period of the target node is determined based on historical data of the target node within a historical time period; target information obtained by sampling the target node within the target sampling period is acquired; a security value of the target node is calculated based on the target information; the security value is used to assess the security risk of the target node; and a security warning is issued to the target node if the security value is greater than a preset threshold. Thus, the target sampling period of the target node can be determined through its historical data, and the security value of the target node can be calculated based on the information obtained from the target sampling period. The security risk of the target node is then assessed using the security value, and a security warning is issued to the target node if the security value is greater than a preset threshold. This method eliminates the need for passive defense when a security vulnerability appears on the target node; it allows for proactive defense by assessing security risks through security values, thus solving the problem of related technologies being unable to proactively defend against security risks.

[0134] It is important to understand that Figures 1 to 4 The explanations of the same or corresponding steps can be cross-referenced. For example, Figure 1 The explanations of steps 130 and 140 are applicable to Figure 2 Steps 260 and 270 in the process.

[0135] Meanwhile, it should be understood that the data security early warning method provided in this application embodiment can have the following beneficial effects: First, this application embodiment provides a security detection method for target nodes based on dynamic sampling. It can dynamically determine the target sampling period of a node based on its data characteristics, and perform security detection on the target node based on the data obtained from the target sampling period. Second, since the target sampling period is determined based on the characteristics of the target node, it can ensure that the sampled data reflects the data situation of the target node itself, thereby ensuring the accuracy of security detection. This allows for early understanding of the security risks of the target node and enables proactive defense of network security.

[0136] Figure 5 This is a structural block diagram of a data security early warning device provided in an embodiment of this application. (Refer to...) Figure 5 The data security early warning device 500 provided in this application embodiment includes:

[0137] The determining module 510 is used to determine the data sampling period of the target node based on the historical data of the target node within a historical time period;

[0138] The acquisition module 520 is used to acquire target information obtained by sampling data from the target node within the target sampling period;

[0139] The calculation module 530 is used to calculate the security value of the target node based on the target information; the security value is used to assess the security risk of the target node.

[0140] The early warning module 540 is used to provide a safety warning to the target node when the safety value is greater than a preset threshold.

[0141] In this embodiment, the data sampling period of the target node is determined based on historical data of the target node within a historical time period; target information obtained by sampling the target node within the target sampling period is acquired; a security value of the target node is calculated based on the target information; the security value is used to assess the security risk of the target node; and a security warning is issued to the target node if the security value is greater than a preset threshold. Thus, the target sampling period of the target node can be determined through its historical data, and the security value of the target node can be calculated based on the information obtained from the target sampling period. The security risk of the target node is then assessed using the security value, and a security warning is issued to the target node if the security value is greater than a preset threshold. This method eliminates the need for passive defense when a security vulnerability appears on the target node; it allows for proactive defense by assessing security risks through security values, thus solving the problem of related technologies being unable to proactively defend against security risks.

[0142] The data security early warning device provided in this application embodiment can achieve... Figure 4 The various processes implemented in the method implementation examples will not be described again here to avoid repetition.

[0143] like Figure 6As shown, this application embodiment also provides an electronic device 600, which can be an adapter or various types of computers, etc. The electronic device 600 includes a processor 610 and a memory 620. The memory 620 stores programs or instructions, which, when executed by the processor 610, implement the steps of any of the methods described above. For example, when the program is executed by the processor 610, it implements the following process: determining the data sampling period of the target node based on historical data of the target node within a historical time period; acquiring target information obtained by sampling data from the target node within the target sampling period; calculating the security value of the target node based on the target information; using the security value to assess the security risk of the target node; and issuing a security warning to the target node if the security value is greater than a preset threshold. In this way, the target sampling period of the target node can be determined by using the historical data of the target node. Based on the information obtained from the target sampling period, the security value of the target node can be calculated, and the security risk of the target node can be assessed by using the security value. If the security value is greater than a preset threshold, a security warning is issued to the target node. This method does not require passive defense when the target node has security risks. Instead, it can actively defend by assessing security risks through the security value, thus solving the problem that related technologies cannot actively defend against security risks.

[0144] This application also provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the steps of various embodiments of the data security early warning method and achieve the same technical effect. To avoid repetition, they will not be described again here.

[0145] The processor is the processor in the electronic device described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.

[0146] This application embodiment also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above method embodiments and achieve the same technical effect. To avoid repetition, it will not be described again here.

[0147] This application provides a computer program product, which is stored in a storage medium and executed by at least one processor to implement the various processes of the above method embodiments and achieve the same technical effects. To avoid repetition, it will not be described again here.

[0148] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.

[0149] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a computer software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0150] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.

Claims

1. A data security early warning method, characterized in that, include: The target sampling period of the target node is determined based on the historical data of the target node within the historical time period. Obtain target information obtained by sampling data from the target node within the target sampling period; The target information includes vulnerability information of the target node, attack data of the target node, vulnerability information of the target node's neighboring nodes, and attack data of the target node's neighboring nodes. There is a connection relationship between the target node and its adjacent nodes; Based on the vulnerability information of the target node and the vulnerability information of the target node's neighboring nodes, the stability of the target node is calculated. The stability level is used to reflect the vulnerability situation; Based on the attack data of the target node and the attack data of the neighboring nodes of the target node, calculate the target impact value of the target node and the target impact value of the neighboring nodes of the target node. Based on the stability, the target influence value of the target node, and the target influence values ​​of the neighboring nodes of the target node, the safety value of the target node is calculated. The security value is used to assess the security risk of the target node; If the security value exceeds a preset threshold, a security warning is issued to the target node. The historical data includes attack data of the target node and network traffic data other than the attack data. Determining the target sampling period of the target node based on its historical data within a historical time period includes: determining a first average time difference based on the network traffic data, wherein the first average time difference is the average of at least one first time difference, which is obtained based on the time points when multiple maxima of the network traffic data occur; determining a second average time difference based on the attack data and the network traffic data, wherein the second average time difference is the average of at least one second time difference, which is obtained based on the time points when multiple maxima of the network traffic data occur and the attack time point of the attack data; determining an average attack value based on the attack data; and determining the target sampling period of the target node based on the first average time difference, the second average time difference, and the average attack value.

2. The method according to claim 1, characterized in that, Based on the network traffic data, the first average time difference is determined, including: Obtain the M maximum values ​​of the network traffic data, where M is an integer greater than 1; Obtain the time point at which each of the M maxima occurs, thus obtaining M time points; Calculate the first time difference between two time points corresponding to two adjacent maximum values ​​among the M time points in chronological order; The first average time difference is determined based on the first time difference between the two time points corresponding to the two adjacent maxima; Accordingly, based on the attacked data and the network traffic data, a second average time difference is determined, including: Based on the attacked data, obtain N attack time points; For each maximum value obtained based on the network traffic data, the following operations are performed: determine the target time point when the maximum value occurs; select the attack time point that is closest to the target time point in time from the N attack time points and use it as the designated time point; if the difference between the target time point and the designated time point is less than a critical value, determine the target time point when the maximum value occurs as the time point of concern. Based on the M maxima, obtain K attention time points arranged in chronological order, where K is less than or equal to M and K is an integer greater than 2; Calculate the second time difference between every two adjacent attention time points in the K attention time points in chronological order; The second average time difference is determined based on the second time difference between every two adjacent attention time points among the K attention time points.

3. The method according to claim 1, characterized in that, The attacked data includes the attack type corresponding to N attacks, the vulnerabilities involved in the attacks, and the actual impact of the attacks, where N is a positive integer; The step of determining the average attack value based on the attacked data includes: Based on the attack type of the j-th attack among the N attacks, determine the standard impact value of the j-th attack; Based on the standard impact value, actual impact value, and general vulnerability score of the j-th attack, using the formula... The target impact value of the j-th attack is determined; the general vulnerability score is obtained by scoring the vulnerabilities involved in the attack. Based on the target impact values ​​of N attacks, calculate the average attack value of the attacked data. Among them, A j Let X be the target impact value of the j-th attack. j Y represents the actual impact value of the j-th attack. j Let CVSS be the standard impact value of the j-th attack. j The general vulnerability score for the j-th attack.

4. The method according to claim 1, characterized in that, The step of determining the target sampling period of the target node based on the first average time difference, the second average time difference, and the average attack value includes: If the first average time difference is less than the second average time difference, determine whether the average attack value is less than a preset attack threshold; If the average attack value is not less than the preset attack threshold, the first average time difference is determined as the target sampling period of the target node. If the average attack value is less than the preset attack threshold, the product of the first average time difference and the second average time difference is determined as the target sampling period of the target node.

5. The method according to claim 1, characterized in that, The adjacent nodes include Q nodes, where Q is a positive integer; the calculation of the stability of the target node based on the vulnerability information of the target node and the vulnerability information of the target node's adjacent nodes includes: Based on the vulnerability information of the target node and the vulnerability information of the neighboring nodes of the target node, obtain the vulnerability parameters of the target node and the Q vulnerability parameters corresponding to the Q nodes; If all Q vulnerability parameters are less than the vulnerability parameter of the target node, then by formula Calculate the stability of the target node; If among the Q vulnerability parameters, R vulnerability parameters are greater than the vulnerability parameter of the target node, where R is a positive integer, then the formula is used to determine the vulnerability parameters. Calculate the stability of the target node; Where S is the stability of the target node, and B v The vulnerability parameter is the v-th adjacent node.

6. The method according to claim 1, characterized in that, Based on the stability, the target influence value of the target node, and the target influence values ​​of the neighboring nodes of the target node, the safety value of the target node is calculated, including: Through formula Calculate the security value of the target node; Wherein, B is the security value of the target node, and A v Let A be the target influence value of the vth adjacent node, and S be the stability of the target node.

7. A data security early warning device, characterized in that, include: The determination module is used to determine the target sampling period of the target node based on the historical data of the target node within a historical time period; The acquisition module is used to acquire target information obtained by sampling data from the target node within the target sampling period; The target information includes vulnerability information of the target node, attack data of the target node, vulnerability information of the target node's neighboring nodes, and attack data of the target node's neighboring nodes. There is a connection relationship between the target node and its adjacent nodes; The calculation module is used to calculate the stability of the target node based on the vulnerability information of the target node and the vulnerability information of the neighboring nodes of the target node; The stability level is used to reflect the vulnerability situation; Based on the attack data of the target node and the attack data of the neighboring nodes of the target node, calculate the target impact value of the target node and the target impact value of the neighboring nodes of the target node. Based on the stability, the target influence value of the target node, and the target influence values ​​of the neighboring nodes of the target node, the safety value of the target node is calculated. The security value is used to assess the security risk of the target node; The early warning module is used to provide a security warning to the target node when the security value is greater than a preset threshold. The historical data includes attack data of the target node and network traffic data other than the attack data. The determining module is specifically configured to: determine a first average time difference based on the network traffic data, wherein the first average time difference is the average of at least one first time difference, which is obtained based on the time points when multiple maxima of the network traffic data occur; determine a second average time difference based on the attack data and the network traffic data, wherein the second average time difference is the average of at least one second time difference, which is obtained based on the time points when multiple maxima of the network traffic data occur and the attack time point of the attack data; determine an average attack value based on the attack data; and determine the target sampling period of the target node based on the first average time difference, the second average time difference, and the average attack value.

8. An electronic device, characterized in that, It includes a processor and a memory, the memory storing a program or instructions that run on the processor, the program or instructions which, when executed by the processor, implement the steps of the method as described in any one of claims 1-6.

9. A computer-readable storage medium, characterized in that, The medium stores a program or instructions that, when executed, implement the steps of the method as described in any one of claims 1-6.

10. A computer program product, characterized in that, Includes a computer program that, when executed by a processor, implements the method described in any one of claims 1-6.

Citation Information

Patent Citations

  • Internet of Things security risk early warning management and control method and system based on big data

    CN114978770A