Network security situation early warning method, device, equipment, storage medium and product

By comprehensively considering the security status of devices in the network, the data flow between devices, and the vulnerability situation, the problem of incomplete assessment dimensions in existing technologies has been solved, enabling more accurate early warning of network security situation and improving network security and risk response efficiency.

CN118802313BActive Publication Date: 2026-04-24CHINA MOBILE GROUP DESIGN INST +1
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA MOBILE GROUP DESIGN INST
Filing Date
2024-05-21
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

Existing cybersecurity situational awareness early warning schemes focus on a single node, neglecting the connections between nodes, resulting in incomplete assessment dimensions and affecting the effectiveness of early warnings.

Method used

By determining quantitative indicators of the security status of devices in the network, quantitative indicators of data interaction between devices, quantitative indicators of device vulnerabilities, and the probability of network attacks recurring, a network security situation assessment is conducted to determine network security situation early warning indicators, and an early warning is issued when the early warning indicators exceed the threshold.

Benefits of technology

It has improved the effectiveness of early warning, enhanced network security, reduced potential security threats, and improved the efficiency of network risk response.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118802313B_ABST
    Figure CN118802313B_ABST
Patent Text Reader

Abstract

The application provides a network security situation early warning method, device, equipment, storage medium and product, the method comprises the following steps: determining the security situation quantitative index of the equipment in the network, the data interaction situation quantitative index between the equipment, the vulnerability situation quantitative index of the equipment and the network attack recurrence probability; based on the security situation quantitative index of the equipment, the data interaction situation quantitative index between the equipment, the vulnerability situation quantitative index of the equipment and the network attack recurrence probability, network security situation assessment is carried out, and the network security situation early warning index is determined; if the early warning index is greater than the early warning threshold, network security situation early warning is carried out. The application not only considers the security situation of the equipment itself and the situation of the network itself, but also considers the data flow situation between the equipment in the network to carry out network security situation early warning, which is beneficial to improve the early warning effect, improve the security of the network, reduce potential security threats and improve the network risk response efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a network security situation early warning method, apparatus, device, storage medium, and product. Background Technology

[0002] With the rapid development of computer and communication technologies, the types and severity of cybersecurity threats are constantly increasing. Cyberattacks are becoming more distributed, large-scale, and complex, making single protective measures such as firewalls, intrusion detection, antivirus, and access control insufficient for current needs. Currently, cybersecurity situational awareness technologies and related application platforms have emerged to address this need. These technologies enable real-time and comprehensive monitoring of network security, timely detection and even early prediction of network attacks, proactive implementation of cybersecurity protection measures, improved network security capabilities, and reduced cybersecurity risks.

[0003] The cybersecurity situational awareness early warning solution is based on security big data. Through continuous network data monitoring, it can detect various attack threats and abnormal traffic, and has the capabilities of threat investigation and analysis, threat level assessment, and visualization of overall protection level.

[0004] Existing early warning schemes are based on abnormal network traffic. However, these schemes start from a single node and evaluate the traffic of each node, resulting in an incomplete evaluation scope and affecting the effectiveness of the early warning. Summary of the Invention

[0005] To address the above problems, this invention provides a network security situation early warning method, the method comprising:

[0006] Determine quantitative indicators of the security status of devices in the network, quantitative indicators of data interaction between devices, quantitative indicators of device vulnerabilities, and the probability of network attacks recurring.

[0007] A network security situation assessment is conducted based on quantitative indicators of the security status of the devices, quantitative indicators of data interaction between the devices, quantitative indicators of the vulnerabilities of the devices, and the probability of the network attack recurring, and network security situation warning indicators are determined.

[0008] If the warning indicator is greater than the warning threshold, a network security situation warning will be issued.

[0009] According to a network security situation early warning method provided by the present invention, the probability of the network attack recurring is determined by the following method:

[0010] Based on the network's attack logs, determine the attack time and number of attacks for each type of attack;

[0011] Based on the attack time and number of attacks for each type of attack, determine the probability of each type of attack occurring again;

[0012] The maximum probability of a network attack recurring is determined by the highest probability among all types of attacks.

[0013] According to a network security situation early warning method provided by the present invention, determining the probability of each type of attack recurring based on the attack time and number of attacks includes:

[0014] Calculate the attack frequency of each type of attack based on the total number of attacks and the number of attacks of each type.

[0015] The probability of each type of attack occurring again is determined based on the average attack time difference between two adjacent attacks of each type, the time difference between the current time and the previous attack, and the attack frequency of each type of attack.

[0016] According to a network security situation early warning method provided by the present invention, the quantitative indicators of the security status of the device are determined in the following manner:

[0017] Obtain the network topology diagram;

[0018] Determine the device type and security value of the devices corresponding to the nodes in the network topology diagram;

[0019] The vulnerability level of the device is determined based on the relationship between the device type and the vulnerability level.

[0020] Based on the vulnerability and security value of the device, quantitative indicators of the device's security status are determined.

[0021] According to a network security situation early warning method provided by the present invention, the quantitative indicators of data interaction between the devices are determined in the following manner:

[0022] Obtain a network topology graph and determine the first and second nodes connected by edges in the network topology graph; the first node corresponds to a first device and the second node corresponds to a second device.

[0023] Based on the data traffic logs of the first node and the second node, determine the first proportion of the total amount of data with the target IP of the second node in the total amount of uplink data of the first node, the second proportion of the total amount of data with the source IP of the first node in the total amount of downlink data of the second node, the third proportion of the total amount of data with the source IP of the second node in the total amount of downlink data of the first node, and the fourth proportion of the total amount of data with the target IP of the first node in the total amount of uplink data of the second node.

[0024] A quantitative indicator of data interaction between devices is determined based on the maximum value of the first proportion and the second proportion, and the maximum value of the third proportion and the fourth proportion.

[0025] According to a network security situation early warning method provided by the present invention, the quantitative indicators of the vulnerability status of the device are determined in the following manner:

[0026] Obtain the severity score of each vulnerability in the device;

[0027] The maximum value among the severity scores of each vulnerability is determined as the quantitative indicator of the vulnerability status of the device.

[0028] According to a network security situation early warning method provided by the present invention, the method involves assessing the network security situation based on quantitative indicators of the security status of the device, quantitative indicators of data interaction between the devices, quantitative indicators of the vulnerability status of the device, and the probability of recurrence of the network attack, and determining network security situation early warning indicators, including:

[0029] Based on the quantitative indicators of security status of each device, the quantitative indicators of data interaction between each device and all connected devices, the degree of each device, and the quantitative indicators of vulnerability status of each device, the device security status early warning indicators are determined for each device.

[0030] Based on the device security status warning indicators of each device and the probability of the network attack recurring, a network security status warning indicator is determined.

[0031] The present invention also provides a network security situation early warning device, comprising:

[0032] The determination module is used to determine quantitative indicators of the security status of devices in the network, quantitative indicators of data interaction between devices, quantitative indicators of device vulnerabilities, and the probability of network attacks recurring.

[0033] The assessment module is used to conduct a network security situation assessment based on the security status quantification indicators of the device, the data interaction status quantification indicators between the devices, the vulnerability status quantification indicators of the device, and the probability of the network attack recurring, and to determine network security situation early warning indicators.

[0034] The early warning module is used to issue a network security situation warning if the early warning indicator is greater than the early warning threshold.

[0035] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps of the network security situation early warning method as described in any of the preceding claims.

[0036] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the network security situation early warning method as described in any of the preceding claims.

[0037] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of any of the network security situation early warning methods described above.

[0038] The network security situation early warning method, device, equipment, storage medium, and product provided by this invention determine network security situation early warning indicators by identifying quantitative indicators of the security status of devices in the network, quantitative indicators of data interaction between devices, quantitative indicators of device vulnerabilities, and the probability of network attacks recurring. A network security situation early warning is issued when the early warning indicators exceed the early warning threshold. This approach considers not only the security status of the devices themselves and the network itself, but also the data flow between devices in the network, thus improving the early warning effect, enhancing network security, reducing potential security threats, and improving network risk response efficiency. Attached Figure Description

[0039] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0040] Figure 1 This is a flowchart illustrating the network security situation early warning method provided in an embodiment of the present invention;

[0041] Figure 2 This is a schematic diagram of the network topology structure provided in an embodiment of the present invention;

[0042] Figure 3 This is a schematic diagram of the network security situation early warning device provided in an embodiment of the present invention;

[0043] Figure 4 This is a schematic diagram of the structure of the electronic device provided in an embodiment of the present invention. Detailed Implementation

[0044] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0045] Existing solutions are based on abnormal network traffic. However, nodes in a network are not isolated entities but interconnected. Existing solutions, focusing on individual nodes and evaluating traffic based on each node's traffic, neglect the connections between nodes, thus affecting the effectiveness of early warning. This invention, however, considers not only the security of the devices themselves and the network itself, but also the data flow between devices in the network for network security situational awareness warnings, thereby improving the effectiveness of early warnings.

[0046] Figure 1 This is a flowchart illustrating the network security situation early warning method provided in an embodiment of the present invention. (Refer to...) Figure 1 This invention provides a network security situation early warning method, which may specifically include the following steps:

[0047] Step 101: Determine the quantitative indicators of the security status of devices in the network, the quantitative indicators of data interaction between devices, the quantitative indicators of device vulnerabilities, and the probability of network attacks recurring.

[0048] It should be noted that the execution subject of the network security situation early warning method provided in this embodiment of the invention can be an electronic device, a component in the electronic device, an integrated circuit, or a chip. The electronic device can be a mobile electronic device or a non-mobile electronic device. For example, a mobile electronic device can be a mobile phone, tablet computer, laptop computer, PDA, wearable device, ultra-mobile personal computer (UMPC), netbook, or personal digital assistant (PDA), etc., while a non-mobile electronic device can be a server, network attached storage (NAS), personal computer (PC), television (TV), ATM, or self-service machine, etc. This embodiment of the invention does not specifically limit the specific implementation of these devices. The following embodiments of the invention describe the execution subject using a server as the execution subject.

[0049] Figure 2 This is a schematic diagram of the network topology structure provided in an embodiment of the present invention. (Refer to...) Figure 2A network topology graph consists of nodes and edges, representing the structural relationships between nodes in the network. Nodes in a network topology graph can represent devices in the network; if two devices can communicate, then a line (i.e., an edge) can connect the nodes corresponding to the two devices in the network topology graph.

[0050] Nodes in a network topology graph can have vertex weights, and edges can have edge weights. Vertex weights can represent the physical security status of devices, while edge weights can represent the data interaction between devices. In this embodiment of the invention, the server can obtain the vertex weights (i.e., quantitative indicators of device security status), edge weights (i.e., quantitative indicators of data interaction between devices), quantitative indicators of vulnerability status of devices corresponding to each node, and the probability of network attacks recurring from each node in the network topology graph to conduct network security situation warnings. Thus, when conducting network security situation warnings, not only the security status of the devices themselves and the network itself are considered, but also the data flow between devices in the network, which is beneficial to improving the warning effect.

[0051] Step 102: Based on the security status quantification indicators of the device, the data interaction status quantification indicators between the devices, the vulnerability status quantification indicators of the device, and the probability of the network attack recurring, determine the network security situation warning indicators.

[0052] Specifically, network security posture assessments can be conducted based on quantifiable indicators of the security status of individual devices in the network, quantifiable indicators of data interaction between devices, quantifiable indicators of vulnerabilities in individual devices, and the recurrence rate of network attacks, thereby determining network security posture warning indicators. These indicators can then be used to determine whether to issue a network security posture warning.

[0053] Step 103: If the warning indicator is greater than the warning threshold, then a network security situation warning is issued.

[0054] Specifically, if the cybersecurity situation warning indicator is greater than the warning threshold, it can be confirmed that the cybersecurity risk is relatively high, and a cybersecurity situation warning will be issued. If the cybersecurity situation warning indicator is less than or equal to the warning threshold, it can be confirmed that the cybersecurity risk is relatively low, and no cybersecurity situation warning will be issued.

[0055] The warning threshold can be set according to actual needs, determined based on experience, or obtained through big data analysis. This invention does not impose any restrictions on this.

[0056] This invention determines network security situation warning indicators by identifying quantitative indicators of the security status of devices in the network, quantitative indicators of data interaction between devices, quantitative indicators of device vulnerabilities, and the probability of network attacks recurring. When the warning indicators exceed the warning threshold, a network security situation warning is issued. This approach considers not only the security status of the devices themselves and the network itself, but also the data flow between devices in the network, which helps improve the warning effect, enhance network security, reduce potential security threats, and improve network risk response efficiency.

[0057] In one optional embodiment, the probability of the network attack recurring is determined by: determining the attack time and number of attacks for each type of attack based on the network's attack logs; determining the probability of each type of attack recurring based on the attack time and number of attacks for each type of attack; and determining the maximum value among the probabilities of each type of attack recurring as the probability of the network attack recurring.

[0058] Similar attacks can share the same attack characteristics. In this embodiment of the invention, network attack logs can be obtained, and the attack characteristics and time of each attack can be determined based on the attack logs. The number of attacks with the same characteristics can be determined, thus obtaining the attack count for each type of attack. The probability of each type of attack recurring can be determined based on the attack count for each type of attack and the attack time of each attack for that type of attack.

[0059] The probability of a network attack recurring can be determined by the maximum probability among all types of attacks. For example, suppose the probability of attack type A recurring is P. A The probability of a type B attack recurring is P. B The probability of a type C attack recurring is P. C P A >P B >P C The probability P of a type A attack recurring can be calculated. A The probability P of a network attack recurring is determined.

[0060] This invention determines the probability of various attacks recurring and identifies the maximum probability among these probabilities as the network attack recurrence probability. This allows for accurate quantification of the network's condition for network security situation early warning, thus improving the effectiveness of early warning.

[0061] In one optional embodiment, determining the probability of each type of attack recurring based on the attack time and number of attacks of each type of attack includes: calculating the attack frequency of each type of attack based on the total number of attacks and the number of attacks of each type of attack; and determining the probability of each type of attack recurring based on the average attack time difference between two adjacent attacks of each type of attack, the time difference between the current time and the previous attack, and the attack frequency of each type of attack.

[0062] Specifically, this can be based on the total number of attacks N and the number of attacks n for each type of attack. x Calculate the attack frequency of each type of attack. The probability of each type of attack recurring can be calculated using the following formula (1):

[0063]

[0064] Where, n x Let t be the number of attacks of type x with attack characteristic x, N be the total number of attacks, and t be the number of attacks of type x. x (1) is the time of the last attack of attack type x (i.e., the time of the most recent attack), t x For the current time, Let be the average attack time difference between two consecutive attacks of attack type x.

[0065] This invention determines the probability of each type of attack recurring by considering the average attack time difference between two adjacent attacks, the time difference between the current time and the previous attack, and the attack frequency of each type of attack. The maximum value among the probabilities of each type of attack recurring is then determined as the probability of network attack recurring. This allows for accurate quantification of the network's situation for network security situation early warning, which is beneficial for improving the early warning effect.

[0066] In one optional embodiment, the security status quantification index of the device is determined by: obtaining a network topology map; determining the device type and security value of the devices corresponding to the nodes in the network topology map; determining the vulnerability level of the device based on the relationship between the device type and the vulnerability level; and determining the security status quantification index of the device based on the vulnerability level and the security value.

[0067] Specifically, the network topology map can be obtained, and the device type corresponding to the nodes in the topology map can be determined, such as terminal, server, switch, etc. The device type can be predetermined during device deployment.

[0068] When deploying a device, its security value (A) can be determined based on its environment, such as whether it is located on an intranet or an extranet, and the nature of the data it stores, such as whether it is only used to store encrypted data. i (2).

[0069] Different types of devices have varying degrees of vulnerability to attack. For example, if the device is a server storing a large amount of useful information, then the server is more vulnerable to attack. The vulnerability level for each device type can be determined based on empirical values ​​or by analyzing a large number of historical attack cases using big data analytics, and the relationship between device type and vulnerability level can be stored. In this embodiment of the invention, the vulnerability level A of a device can be determined based on the relationship between its device type and its vulnerability level. i (1). Where i can be the identifier of the node corresponding to the device.

[0070] Point weights can be used as a quantitative indicator of safety status to characterize the physical safety of equipment. A larger point weight indicates a less safe equipment. Specifically, point weights can be determined using the following formula (2):

[0071]

[0072] Among them, A i (1) The vulnerability level of the device, A i (2) is the safety value of the equipment.

[0073] This invention determines the device type and security value of the device corresponding to the node in the topology graph, determines the vulnerability of the device based on the relationship between the device type and the vulnerability level, and determines the quantitative indicators of the device's security status based on the vulnerability level and security value. This allows for accurate quantification of the device's status for network security situation early warning, which is beneficial for improving the early warning effect.

[0074] In an optional embodiment, the quantitative index of data interaction between the devices is determined by the following method: obtaining a network topology map, and determining a first node and a second node connected by edges in the network topology map; the first node corresponds to a first device, and the second node corresponds to a second device; based on the data traffic logs of the first node and the second node, determining a first percentage of the total amount of data with the target IP of the second node in the total amount of uplink data of the first node, a second percentage of the total amount of data with the source IP of the first node in the total amount of downlink data of the second node, a third percentage of the total amount of data with the source IP of the second node in the total amount of downlink data of the first node, and a fourth percentage of the total amount of data with the target IP of the first node in the total amount of uplink data of the second node; and determining the quantitative index of data interaction between the devices based on the maximum value of the first percentage and the second percentage, and the maximum value of the third percentage and the fourth percentage.

[0075] Specifically, we can obtain the constructed network topology graph, identify the two nodes connected by the edges in the topology graph (i.e., the first node i and the second node j), and obtain the data traffic logs of nodes i and j over a period of time. The first node can correspond to the first device, and the second node can correspond to the second device.

[0076] The total amount of uplink data N at point i can be determined based on the data flow logs at point i. i (1) The total amount of downlink data at point i is N i (2); Based on the data flow log at point j, determine the total uplink data volume N at point j. j (1) The total amount of downlink data at point j is N j (2). Uplink data is data sent from the node, and downlink data is data received by the node.

[0077] From all uplink data at point i, we can identify data destined for IP address j, along with the transmission time of each data segment, and calculate the total number of data segments destined for IP address j. From all downlink data at point i, we can identify data with a source IP at point j, along with the transmission time of each data point, and then calculate the total amount of data with a source IP at point j. From all uplink data at point j, we can identify data whose destination IP is point i, along with the transmission time of each data point, and then calculate the total number of data whose destination IP is point i. From all downlink data at point j, we can identify data with source IP at point i, along with the transmission time of each data point, and calculate the total amount of data with source IP at point i. This allows us to determine the first proportion. Second percentage Third percentage Fourth percentage

[0078] Edge weights can serve as a quantitative indicator of data interaction between devices, representing the interaction between the two devices corresponding to that edge in the data flow. A larger edge weight indicates a less secure device. Specifically, edge weights can be determined using the following formula (3):

[0079]

[0080] in, It refers to the edge weight of the edge connecting point i and point j.

[0081] This invention determines the quantitative indicators of device security status based on the total uplink and downlink data of each of the two nodes connected by the edge, as well as the total uplink and downlink data between the two nodes. This allows for accurate quantification of data flow between devices in the network for network security situation early warning, which is beneficial for improving the early warning effect.

[0082] In one optional embodiment, the vulnerability status quantification index of the device is determined by: obtaining the severity scores of each vulnerability of the device; and determining the maximum value among the severity scores of each vulnerability as the vulnerability status quantification index of the device.

[0083] Specifically, it can obtain vulnerability information for each node's corresponding device and the CVSS (Common Vulnerability Scoring System) value for each vulnerability on that device. The vulnerability information for the device can be obtained through web scraping and may include vulnerabilities in the device's operating system and other software.

[0084] CVSS (Virtual Criteria for Severity Assessment) can be used to assess the severity of vulnerabilities and help determine the urgency and importance of the required responses. It helps establish standards for measuring vulnerability severity, allowing for comparison of vulnerability severity and thus prioritizing their handling. CVSS scores are based on measurements across a series of dimensions called metrics. Vulnerability severity scores range from 0 to 10. Vulnerabilities scoring 7-10 are considered relatively severe, those scoring 4-6.9 are considered medium-severity, and those scoring 0-3.9 are considered low-severity.

[0085] A device can have multiple vulnerabilities, and the maximum value of the severity scores of each vulnerability can be used as a quantitative indicator of the device's vulnerability status.

[0086] This invention uses the maximum value among the severity scores of various vulnerabilities of a device as a quantitative indicator of the device's vulnerability status. This allows for accurate quantification of the device's security status for network security situation early warning, which is beneficial for improving the early warning effect.

[0087] In one optional embodiment, the step of conducting a network security situation assessment based on the security status quantification indicators of the devices, the data interaction quantification indicators between the devices, the vulnerability quantification indicators of the devices, and the probability of the network attack recurring, and determining network security situation warning indicators, includes: conducting a device security situation assessment based on the security status quantification indicators of each device, the data interaction quantification indicators between each device and all connected devices, the degree of each device, and the vulnerability quantification indicators of each device, and determining a device security situation warning indicator for each device; and conducting a network security situation assessment based on the device security situation warning indicators of each device and the probability of the network attack recurring, and determining a network security situation warning indicator.

[0088] In this embodiment of the invention, device security posture assessment can be performed based on quantitative indicators of the security status of each device in the network, quantitative indicators of data interaction between devices, and quantitative indicators of vulnerabilities of each device, thereby determining device security posture warning indicators for each device. Network security posture assessment can be performed based on the device security posture warning indicators for each device and the probability of network attacks recurring, thereby determining network security posture warning indicators.

[0089] Specifically, the network security situation early warning indicator can be calculated using the following formula (4):

[0090]

[0091] Where P represents the probability of a network attack recurring. Quantify the safety indicators of the equipment. CVSS is a quantitative indicator for the data interaction between the device corresponding to point i and the connected devices. max D quantifies the vulnerability status of devices. i Let i be the degree of point i.

[0092] This invention assesses device security status by quantifying the security status of each device, the data interaction between each device and all connected devices, the degree of security of each device, and the vulnerability status of each device. It then determines device security status early warning indicators for each device and, based on these indicators and the probability of recurrence of network attacks, assesses network security status and determines network security status early warning indicators. This approach considers not only the security of the devices themselves and the network itself, but also the data flow between devices within the network, thus improving early warning effectiveness, enhancing network security, reducing potential security threats, and increasing network risk response efficiency. It can be widely applied in network security-related businesses and has broad application prospects.

[0093] The network security situation early warning device provided by the present invention is described below. The network security situation early warning device described below can be referred to in correspondence with the network security situation early warning method described above.

[0094] Figure 3 This is a schematic diagram of the network security situation early warning device provided in an embodiment of the present invention. (Refer to...) Figure 3 This invention provides a network security situation early warning device, which may specifically include the following modules:

[0095] The determination module 301 is used to determine quantitative indicators of the security status of devices in the network, quantitative indicators of data interaction between devices, quantitative indicators of device vulnerabilities, and the probability of network attacks recurring.

[0096] The evaluation module 302 is used to conduct a network security situation assessment based on the security status quantification indicators of the device, the data interaction status quantification indicators between the devices, the vulnerability status quantification indicators of the device, and the probability of the network attack recurring, and to determine network security situation warning indicators.

[0097] The early warning module 303 is used to issue a network security situation warning if the early warning indicator is greater than the early warning threshold.

[0098] This invention determines network security situation warning indicators by identifying quantitative indicators of the security status of devices in the network, quantitative indicators of data interaction between devices, quantitative indicators of device vulnerabilities, and the probability of network attacks recurring. When the warning indicators exceed the warning threshold, a network security situation warning is issued. This approach considers not only the security status of the devices themselves and the network itself, but also the data flow between devices in the network, which helps improve the warning effect, enhance network security, reduce potential security threats, and improve network risk response efficiency.

[0099] Figure 4 An example is a schematic diagram of the physical structure of an electronic device, such as... Figure 4 As shown, the electronic device may include: a processor 410, a communications interface 420, a memory 430, and a communication bus 440, wherein the processor 410, the communications interface 420, and the memory 430 communicate with each other via the communication bus 440. The processor 410 can call logical instructions in the memory 430 to execute a network security situation early warning method, the method including:

[0100] Determine quantitative indicators of the security status of devices in the network, quantitative indicators of data interaction between devices, quantitative indicators of device vulnerabilities, and the probability of network attacks recurring.

[0101] A network security situation assessment is conducted based on quantitative indicators of the security status of the devices, quantitative indicators of data interaction between the devices, quantitative indicators of the vulnerabilities of the devices, and the probability of the network attack recurring, and network security situation warning indicators are determined.

[0102] If the warning indicator is greater than the warning threshold, a network security situation warning will be issued.

[0103] Furthermore, the logical instructions in the aforementioned memory 430 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0104] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to perform the network security situation early warning method provided by the above methods, the method comprising:

[0105] Determine quantitative indicators of the security status of devices in the network, quantitative indicators of data interaction between devices, quantitative indicators of device vulnerabilities, and the probability of network attacks recurring.

[0106] A network security situation assessment is conducted based on quantitative indicators of the security status of the devices, quantitative indicators of data interaction between the devices, quantitative indicators of the vulnerabilities of the devices, and the probability of the network attack recurring, and network security situation warning indicators are determined.

[0107] If the warning indicator is greater than the warning threshold, a network security situation warning will be issued.

[0108] On the other hand, the present invention also provides a computer program product, the computer program product comprising a computer program, the computer program being able to be stored on a non-transitory computer-readable storage medium, and when the computer program is executed by a processor, the computer being able to execute the network security situation early warning method provided by the above methods, the method comprising:

[0109] Determine quantitative indicators of the security status of devices in the network, quantitative indicators of data interaction between devices, quantitative indicators of device vulnerabilities, and the probability of network attacks recurring.

[0110] A network security situation assessment is conducted based on quantitative indicators of the security status of the devices, quantitative indicators of data interaction between the devices, quantitative indicators of the vulnerabilities of the devices, and the probability of the network attack recurring, and network security situation warning indicators are determined.

[0111] If the warning indicator is greater than the warning threshold, a network security situation warning will be issued.

[0112] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0113] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0114] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for early warning of network security situation, characterized in that, The method includes: The system determines quantitative indicators of the security status of devices in the network, quantitative indicators of data interaction between devices, quantitative indicators of device vulnerabilities, and the probability of network attacks recurring; the probability of network attacks recurring is the maximum value among the probabilities of various types of attacks recurring. A network security situation assessment is conducted based on quantitative indicators of the security status of the devices, quantitative indicators of data interaction between the devices, quantitative indicators of the vulnerabilities of the devices, and the probability of the network attack recurring, and network security situation early warning indicators are determined. If the warning indicator is greater than the warning threshold, a network security situation warning will be issued. In this context, the edge weights between the nodes corresponding to two devices in the network topology graph are used to represent the data interaction between devices; the quantitative indicators of the data interaction between devices are determined in the following way: Obtain a network topology graph and determine the first and second nodes connected by edges in the network topology graph; the first node corresponds to a first device and the second node corresponds to a second device. Based on the data traffic logs of the first node and the second node, determine the first proportion of the total amount of data with the target IP of the second node in the total amount of uplink data of the first node, the second proportion of the total amount of data with the source IP of the first node in the total amount of downlink data of the second node, the third proportion of the total amount of data with the source IP of the second node in the total amount of downlink data of the first node, and the fourth proportion of the total amount of data with the target IP of the first node in the total amount of uplink data of the second node. A quantitative indicator of data interaction between devices is determined based on the maximum value of the first proportion and the second proportion, and the maximum value of the third proportion and the fourth proportion.

2. The method according to claim 1, characterized in that, The probability of the network attack recurring is determined in the following way: Based on the network's attack logs, determine the attack time and number of attacks for each type of attack; Based on the attack time and number of attacks for each type of attack, determine the probability of each type of attack occurring again; The maximum probability of a network attack recurring is determined by the highest probability among all types of attacks.

3. The method according to claim 2, characterized in that, The determination of the probability of each type of attack recurring based on the attack time and number of attacks includes: Calculate the attack frequency of each type of attack based on the total number of attacks and the number of attacks of each type. The probability of each type of attack occurring again is determined based on the average attack time difference between two adjacent attacks of each type, the time difference between the current time and the previous attack, and the attack frequency of each type of attack.

4. The method according to claim 1, characterized in that, The quantitative indicators of the equipment's safety status are determined in the following ways: Obtain the network topology diagram; Determine the device type and security value of the devices corresponding to the nodes in the network topology diagram; The vulnerability level of the device is determined based on the relationship between the device type and the vulnerability level. Based on the vulnerability and security value of the device, quantitative indicators of the device's security status are determined.

5. The method according to claim 1, characterized in that, The quantitative indicators of the device's vulnerability status are determined in the following ways: Obtain the severity score of each vulnerability in the device; The maximum value among the severity scores of each vulnerability is determined as the quantitative indicator of the vulnerability status of the device.

6. The method according to claim 1, characterized in that, The network security situation assessment is conducted based on the security status quantification indicators of the devices, the data interaction quantification indicators between the devices, the vulnerability status quantification indicators of the devices, and the probability of the network attack recurring, to determine network security situation early warning indicators, including: Based on the quantitative indicators of security status of each device, the quantitative indicators of data interaction between each device and all connected devices, the degree of each device, and the quantitative indicators of vulnerability status of each device, the device security status early warning indicators are determined for each device. Based on the device security status warning indicators of each device and the probability of the network attack recurring, a network security status warning indicator is determined.

7. A network security situation early warning device, characterized in that, include: The determination module is used to determine quantitative indicators of the security status of devices in the network, quantitative indicators of data interaction between devices, quantitative indicators of device vulnerabilities, and the probability of network attacks recurring. The probability of a network attack recurring is the maximum value among the probabilities of various types of attacks recurring. The assessment module is used to conduct a network security situation assessment based on the security status quantification indicators of the device, the data interaction status quantification indicators between the devices, the vulnerability status quantification indicators of the device, and the probability of the network attack recurring, and to determine network security situation early warning indicators. The early warning module is used to issue a network security situation warning if the early warning indicator is greater than the early warning threshold. In this context, the edge weights between the nodes corresponding to two devices in the network topology graph are used to represent the data interaction between devices; the quantitative indicators of the data interaction between devices are determined in the following way: Obtain a network topology graph and determine the first and second nodes connected by edges in the network topology graph; the first node corresponds to a first device and the second node corresponds to a second device. Based on the data traffic logs of the first node and the second node, determine the first proportion of the total amount of data with the target IP of the second node in the total amount of uplink data of the first node, the second proportion of the total amount of data with the source IP of the first node in the total amount of downlink data of the second node, the third proportion of the total amount of data with the source IP of the second node in the total amount of downlink data of the first node, and the fourth proportion of the total amount of data with the target IP of the first node in the total amount of uplink data of the second node. A quantitative indicator of data interaction between devices is determined based on the maximum value of the first proportion and the second proportion, and the maximum value of the third proportion and the fourth proportion.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the network security situation early warning method as described in any one of claims 1 to 6.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the network security situation early warning method as described in any one of claims 1 to 6.

10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the network security situation early warning method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Network security situation assessment method and device, equipment and storage medium

    CN118802195A