Network situation awareness method and device, computer device and storage medium

By acquiring situational awareness data of network nodes, determining the network assessment impact coefficient, threat perception value, and value perception value of nodes, and generating network situational awareness results, the problem of difficulty in comprehensively assessing network security in existing technologies is solved, and effective assessment of network security is achieved.

CN118802344BActive Publication Date: 2026-01-20CHINA MOBILE GRP FUJIAN CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410934331.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-12
Publication Date
2026-01-20
Estimated Expiration
2044-07-12

AI Technical Summary

Technical Problem

Existing network security technologies are insufficient to effectively assess the security of the entire network and cannot fully consider the impact of node risks on the network.

Method used

By acquiring raw situational awareness data of the nodes to be analyzed in the network, the network assessment impact coefficient, threat perception value, risk perception value, and value perception value of the nodes are determined, and network situational awareness results are generated. The network assessment impact coefficient is then added to reflect the relationship between node security and network security.

Benefits of technology

It enables an effective assessment of overall network security, taking into account the impact of node risks on the network, and improving the accuracy and comprehensiveness of security assessments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118802344B_ABST
    Figure CN118802344B_ABST
Patent Text Reader

Abstract

The present disclosure provides a network situation awareness method, device, computer equipment and storage medium, the method comprises: obtaining the situation awareness original data of a node to be analyzed in a network; determining the network evaluation influence coefficient, threat awareness value, risk awareness value and value awareness value of the node to be analyzed for the network according to the situation awareness original data, wherein the network evaluation influence coefficient is used to indicate the influence degree of the node to be analyzed on network security; generating a network situation awareness result according to the network evaluation influence coefficient, threat awareness value, risk awareness value and value awareness value corresponding to each node in the network. By implementing the method of the present disclosure, the network evaluation influence coefficient can be added to the awareness value, which reflects the relationship between node security and network security, so that when the network situation is evaluated through the risk of the node, the influence of the node risk on the network is considered, ensuring effective evaluation of the security of the entire network.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present disclosure relates to the technical field of network security, in particular to a network situation awareness method and device, computer equipment and storage medium. BACKGROUND

[0002] Network security refers to a comprehensive system of technologies, policies, laws and practices that protect computer systems, network devices, data and network users from unauthorized access, damage, tampering or leakage in a network environment. With the development of networks, network security has become one of the core issues of the whole society.

[0003] Currently, network security is usually protected by security protection programs such as firewalls. For example, a firewall is running on a network node device, which checks and filters network traffic. Through deep packet inspection, it decides whether to allow or block the transmission of data packets according to a predefined rule set (such as an access control list), thereby preventing malicious traffic from entering the network.

[0004] In this way, it is difficult to effectively evaluate the security of the entire network. SUMMARY

[0005] The present disclosure aims to at least partially solve one of the technical problems in the related art.

[0006] To this end, the purpose of the present disclosure is to propose a network situation awareness method, device, computer equipment and storage medium, which can add a network evaluation influence coefficient to the perception value, and the network evaluation influence coefficient reflects the relationship between node security and network security, so that the influence of the node risk on the network is considered when the network situation is evaluated through the risk of the node, and the security of the entire network is effectively evaluated.

[0007] To achieve the above purpose, the network situation awareness method according to the first aspect of the present disclosure comprises:

[0008] Obtain the situation awareness original data of a node to be analyzed in a network;

[0009] According to the situation awareness original data, determine a network evaluation influence coefficient of the node to be analyzed on the network, a threat perception value, a risk perception value and a value perception value, wherein the network evaluation influence coefficient is used to indicate the influence degree of the node to be analyzed on network security, the threat perception value is used to indicate the threat situation of the node to be analyzed, the risk perception value is used to indicate the traffic risk of the node to be analyzed, and the value perception value is used to indicate the value information of the node to be analyzed;

[0010] According to the network evaluation influence coefficient, the threat awareness value, the risk awareness value and the value awareness value corresponding to each node in the network, a network situation awareness result is generated.

[0011] To achieve the above object, the second aspect of the present disclosure proposes a network situation awareness device, which comprises:

[0012] An acquisition module is configured to acquire situation awareness original data of a node to be analyzed in a network.

[0013] A determination module is configured to determine, according to the situation awareness original data, a network evaluation influence coefficient, a threat awareness value, a risk awareness value and a value awareness value of the node to be analyzed for the network, wherein the network evaluation influence coefficient is used to indicate the influence degree of the node to be analyzed on network security, the threat awareness value is used to indicate the threat situation of the node to be analyzed itself, the risk awareness value is used to indicate the traffic risk of the node to be analyzed, and the value awareness value is used to indicate the value information of the node to be analyzed.

[0014] A generation module is configured to generate, according to the network evaluation influence coefficient, the threat awareness value, the risk awareness value and the value awareness value corresponding to each node in the network, a network situation awareness result.

[0015] The third aspect of the present disclosure proposes a computer device, which comprises a memory, a processor and a computer program stored in the memory and executable on the processor, and the processor executes the program to realize the network situation awareness method proposed in the first aspect of the present disclosure.

[0016] The fourth aspect of the present disclosure proposes a non-transitory computer readable storage medium, which stores a computer program, and the program is executed by a processor to realize the network situation awareness method proposed in the first aspect of the present disclosure.

[0017] The fifth aspect of the present disclosure proposes a computer program product, and when the instructions in the computer program product are executed by a processor, the network situation awareness method proposed in the first aspect of the present disclosure is executed.

[0018] The network situation awareness method, device, computer device and storage medium provided by the present disclosure can obtain situation awareness original data of a node to be analyzed in a network, determine a network evaluation influence coefficient, a threat awareness value, a risk awareness value and a value awareness value of the node to be analyzed in the network according to the situation awareness original data, wherein the network evaluation influence coefficient is used to indicate the influence degree of the node to be analyzed on network security, the threat awareness value is used to indicate the threat situation of the node to be analyzed, the risk awareness value is used to indicate the traffic risk of the node to be analyzed, and the value awareness value is used to indicate the value information of the node to be analyzed, and generate a network situation awareness result according to the network evaluation influence coefficient, the threat awareness value, the risk awareness value and the value awareness value corresponding to each node in the network. Thus, the network evaluation influence coefficient can be added to the awareness value, and the network evaluation influence coefficient reflects the relationship between the node security and the network security, so that the influence of the node risk on the network is considered when the network situation is evaluated through the node risk, and the security of the entire network is effectively evaluated.

[0019] Additional aspects and advantages of the present disclosure will be made apparent from the following description, which, taken together with the accompanying drawings, describes or illustrates such aspects and advantages by way of example as described below. BRIEF DESCRIPTION OF DRAWINGS

[0020] The above and / or additional aspects and advantages of the present disclosure will become apparent and be readily appreciated from the following description, taken in conjunction with the accompanying drawings, in which:

[0021] Figure 1 is a flowchart of a network situation awareness method according to an embodiment of the present disclosure;

[0022] Figure 2 is a flowchart of a network situation awareness method according to another embodiment of the present disclosure;

[0023] Figure 3 is a structural diagram of a network situation awareness device according to an embodiment of the present disclosure;

[0024] Figure 4 shows a block diagram of an exemplary computer device suitable for implementing embodiments of the present disclosure. DETAILED DESCRIPTION

[0025] Embodiments of the present disclosure are described in detail below with reference to the accompanying drawings, examples of which are shown in the drawings, wherein the same or similar notations represent the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present disclosure, and cannot be understood as limiting the present disclosure. On the contrary, the embodiments of the present disclosure include all changes, modifications and equivalents falling within the spirit and scope of the appended claims.

[0026] Figure 1 is a flow diagram of a network situation awareness method according to an embodiment of the present disclosure.

[0027] It should be noted that the execution subject of the network situation awareness method in this embodiment is a network situation awareness device, which can be implemented by software and / or hardware. The device can be configured in a computer device, which can include but is not limited to a terminal, a server, etc. For example, the terminal can be a mobile phone, a palm computer, etc.

[0028] As shown in Figure 1 , the network situation awareness method comprises the following steps.

[0029] S101: Obtain situation awareness original data of a node to be analyzed in a network.

[0030] The node to be analyzed can be any node in the network.

[0031] The situation awareness original data refers to any data related to situation awareness of the node to be analyzed.

[0032] That is, in the embodiment of the present disclosure, when performing network situation awareness, the situation awareness original data of the node to be analyzed in the network can be obtained first, thereby providing reliable data support for the subsequent network situation awareness process.

[0033] S102: Determine a network evaluation influence coefficient, a threat awareness value, a risk awareness value, and a value awareness value of the node to be analyzed on the network according to the situation awareness original data, wherein the network evaluation influence coefficient is used to indicate the influence degree of the node to be analyzed on network security, the threat awareness value is used to indicate the threat situation of the node to be analyzed, the risk awareness value is used to indicate the traffic risk of the node to be analyzed, and the value awareness value is used to indicate the value information of the node to be analyzed.

[0034] For example, the risk awareness value may be obtained by evaluating the traffic data in the period from T i to T i-3 , such as evaluating the traffic change, the packet loss rate change, the throughput change, etc. between the periods. Based on the traffic change, the traffic risk of the node is evaluated to obtain The greater the value is, the higher the security risk is. The value awareness value may be obtained by comprehensively considering the access frequency of the node j and the sensitivity of the stored data. For example, the average access frequency of all nodes of the same type as the node j is determined,

[0035] In the embodiments of the present disclosure, when the network evaluation influence coefficient, the threat perception value, the risk perception value and the value perception value of the to-be-analyzed node on the network are determined according to the situational awareness original data, reliable reference information can be provided for subsequent network situational awareness.

[0036] S103: generating a network situational awareness result according to the network evaluation influence coefficient, the threat perception value, the risk perception value and the value perception value corresponding to each node in the network.

[0037] The network situational awareness result refers to a result obtained by perceiving the network situation of the entire network.

[0038] In the embodiments of the present disclosure, when the network situational awareness result is generated according to the network evaluation influence coefficient, the threat perception value, the risk perception value and the value perception value corresponding to each node in the network, the network evaluation influence coefficient, the threat perception value, the risk perception value and the value perception value corresponding to each node can be input into a pre-trained machine learning model to obtain the corresponding network situational awareness result, or the network situational awareness result can also be generated based on a number-shape combination method according to the network evaluation influence coefficient, the threat perception value, the risk perception value and the value perception value corresponding to each node in the network, and no limitation is made in this regard.

[0039] In the embodiments, by obtaining the situational awareness original data of the to-be-analyzed node in the network, the network evaluation influence coefficient, the threat perception value, the risk perception value and the value perception value of the to-be-analyzed node on the network are determined according to the situational awareness original data, wherein the network evaluation influence coefficient is used to indicate the influence degree of the to-be-analyzed node on the network security, the threat perception value is used to indicate the threat situation of the to-be-analyzed node itself, the risk perception value is used to indicate the traffic risk of the to-be-analyzed node, and the value perception value is used to indicate the value information of the to-be-analyzed node. The network situational awareness result is generated according to the network evaluation influence coefficient, the threat perception value, the risk perception value and the value perception value corresponding to each node in the network. Thus, the network evaluation influence coefficient can be added to the perception value, and the network evaluation influence coefficient reflects the relationship between the node security and the network security, so that when the network situation is evaluated through the risk of the node, the influence of the node risk on the network is considered, and the security of the entire network is effectively evaluated.

[0040] Figure 2 is a flow diagram of a network situational awareness method according to another embodiment of the present disclosure.

[0041] As shown in Figure 2 , the network situational awareness method comprises:

[0042] S201: Obtain monitoring data corresponding to the to-be-analyzed node in continuous multiple execution periods as situational awareness original data corresponding to a target period, where the target period is the latest period in the continuous multiple execution periods, and the monitoring data includes traffic data, vulnerability data, attack data, and node basic data, and the node basic data includes a target node type and a target security value of the to-be-analyzed node.

[0043] The execution period can refer to a period in which the network situational awareness method is executed in the embodiments of the present disclosure, for example, can be 1 month, 1 year, etc., and no limitation is made to this. The continuous multiple execution periods can be 4 continuous execution periods (the T i th period, the T i-1 th period, the T i-2 th period, and the T i-3 th period), and the target period refers to the latest period (the T i th period) in the continuous multiple execution periods.

[0044] The monitoring data refers to data monitored and obtained by the to-be-analyzed node corresponding to the to-be-analyzed node in the execution period.

[0045] The traffic data can be used to describe the traffic situation of the to-be-analyzed node in the execution period. The traffic data can be obtained based on a traffic log.

[0046] The vulnerability data can be used to describe the vulnerability situation of the to-be-analyzed node in the execution period. The vulnerability data can be obtained based on a vulnerability scanning report.

[0047] The attack data can be used to describe the network attack situation of the to-be-analyzed node in the execution period. The attack data can be obtained based on an attack log.

[0048] The target node type can be set by relevant personnel when the node is configured, such as a data collection node, a data processing node, a data forwarding node, etc.

[0049] The target security value can be obtained by evaluating the current security situation of the to-be-analyzed node based on a firewall or other program running on the node.

[0050] That is, in the embodiments of the present disclosure, the monitoring data corresponding to the to-be-analyzed node in the continuous multiple execution periods can be obtained as the situational awareness original data corresponding to the target period, where the target period is the latest period in the continuous multiple execution periods, and the monitoring data includes the traffic data, the vulnerability data, the attack data, and the node basic data. Therefore, the obtained situational awareness original data can effectively improve the indication comprehensiveness of the recent related information of the to-be-analyzed node, thereby improving the practicability of the situational awareness original data in the subsequent situational awareness process.

[0051] S202: determining, according to the situational awareness raw data, a threat awareness value, a risk awareness value and a value awareness value of the to-be-analyzed node for the network, wherein the threat awareness value is used to indicate a threat condition of the to-be-analyzed node itself, the risk awareness value is used to indicate a traffic risk of the to-be-analyzed node, and the value awareness value is used to indicate value information of the to-be-analyzed node.

[0052] The description of S202 can be specifically referred to the above-mentioned embodiments, and will not be repeated here.

[0053] S203: determining, according to the target node type and the traffic data, a node influence coefficient.

[0054] The node influence coefficient can be used to indicate an influence degree of the corresponding node on the network situation.

[0055] Optionally, in some embodiments, when the node influence coefficient is determined according to the target node type and the traffic data, the preset influence coefficient of the corresponding to-be-analyzed node can be determined according to the target node type, the first node that exists data communication with the to-be-analyzed node in a plurality of continuous execution cycles is determined according to the traffic data, and the first node quantity of the first node is determined. The maximum node quantity and the minimum node quantity of the first node quantity corresponding to different nodes in the network are determined. The preset influence coefficient, the first node quantity, the maximum node quantity and the minimum node quantity are used to calculate and determine the node influence coefficient. In this way, the traffic condition and the node type corresponding to different nodes in the network can be comprehensively considered, so as to ensure the indication accuracy of the obtained node influence coefficient.

[0056] The preset influence coefficient refers to a coefficient configured by a user in advance for the type of node.

[0057] The first node can be any node in the network other than the to-be-analyzed node that exists data communication with the to-be-analyzed node in a plurality of continuous execution cycles. The first node can exist data communication with the to-be-analyzed node in one execution cycle, or can exist data communication with the to-be-analyzed node in a plurality of execution cycles, which is not limited.

[0058] In the embodiments of the present disclosure, each node in the network can be sequentially taken as the to-be-analyzed node, and then the first node quantity corresponding to each node is determined, so as to determine the maximum node quantity and the minimum node quantity in the first node quantity corresponding to different nodes.

[0059] S204: determining, according to the traffic data, a first influence degree value of the to-be-analyzed node for the network traffic.

[0060] The first influence degree value can be used to describe the influence of the to-be-analyzed node on the network traffic.

[0061] Optionally, in some embodiments, when determining the first influence degree value of the node to be analyzed on network traffic according to the traffic data, the period traffic average of the node to be analyzed in each execution cycle can be determined according to the traffic data; the overall traffic average, the overall traffic change rate and the traffic fluctuation value of the node to be analyzed can be determined according to the period traffic average; the maximum value and the minimum value of the overall traffic average corresponding to different nodes in the network can be determined; the maximum value and the minimum value of the traffic fluctuation value corresponding to different nodes in the network can be determined; and the first influence degree value can be determined according to the traffic fluctuation value, the maximum value and the minimum value of the traffic fluctuation value, the overall traffic change rate, the overall traffic average, the maximum value and the minimum value of the overall traffic average. Thus, the reliability and accuracy of the first influence degree value calculation process can be effectively improved.

[0062] S205: determining the second influence degree value of the node to be analyzed on network stability according to the target security value and the traffic data.

[0063] The second influence degree value can be used to describe the influence of the node to be analyzed on network stability.

[0064] Optionally, in some embodiments, when determining the second influence degree value of the node to be analyzed on network stability according to the target security value and the traffic data, the first node having data communication with the node to be analyzed in a plurality of consecutive execution cycles can be determined according to the traffic data, and the first node quantity of the first node and the first security value corresponding to each first node can be determined; the second node quantity of the first node having the first security value greater than or equal to the target security value can be determined, and the maximum value of the plurality of first security values can be determined; the overall traffic average of the node to be analyzed, and the maximum value and the minimum value of the overall traffic average corresponding to different nodes in the network can be determined; the maximum value and the minimum value of the node quantity corresponding to different nodes in the network can be determined; and the second influence degree value can be determined according to the overall traffic average, the maximum value and the minimum value of the overall traffic average, the first node quantity, the second node quantity, the maximum value and the minimum value of the node quantity, the target security value and the maximum value of the security value. Thus, the reliability of the obtained second influence degree value can be effectively guaranteed by combining the relevant data of multiple dimensions.

[0065] S206: calculating the arithmetic square root of the first influence degree value and the second influence degree value, and calculating the product value of the node influence coefficient and the arithmetic square root as the network evaluation influence coefficient.

[0066] That is to say, in the node basic data in the embodiments of the present disclosure, the target node type and the target security value of the node to be analyzed are included, after the situational awareness original data is obtained, the node influence coefficient can be determined according to the target node type and the traffic data; the first influence degree value of the node to be analyzed on the network traffic is determined according to the traffic data; the second influence degree value of the node to be analyzed on the network stability is determined according to the target security value and the traffic data; the arithmetic square root of the first influence degree value and the second influence degree value is calculated, and the product value of the node influence coefficient and the arithmetic square root is calculated as the network evaluation influence coefficient. Therefore, the comprehensive consideration of different dimension related information can be realized in the process of determining the network evaluation influence coefficient, so as to ensure the indication accuracy of the obtained network evaluation influence coefficient.

[0067] S207: The threat perception value, the risk perception value and the value perception value of the node are weighted and summed according to the pre-configured threat perception weight, risk perception weight and value perception weight to obtain a node perception value.

[0068] The threat perception weight, the risk perception weight and the value perception weight can be weight values pre-configured for the threat perception value, the risk perception value and the value perception value. The sum of the threat perception weight, the risk perception weight and the value perception weight can be 1.

[0069] The node perception value can be used to describe the situational awareness of the corresponding node.

[0070] In the embodiments of the present disclosure, when the threat perception value, the risk perception value and the value perception value of the node are weighted and summed according to the pre-configured threat perception weight, risk perception weight and value perception weight to obtain the node perception value, the obtained node perception value can accurately indicate the situational awareness of the corresponding node, thereby providing reliable reference information for subsequent situational awareness of the network as a whole.

[0071] S208: The network situational awareness result is obtained by weighting and summing the network evaluation influence coefficient and the node perception value corresponding to each node and then dividing by the total number of nodes in the network.

[0072] That is to say, after determining the network evaluation influence coefficient, the threat awareness value, the risk awareness value and the value awareness value of the node to be analyzed in the embodiments of the present disclosure, the threat awareness value, the risk awareness value and the value awareness value of the node are weighted and summed according to the pre-configured threat awareness weight, risk awareness weight and value awareness weight to obtain a node awareness value, and the network evaluation influence coefficient corresponding to each node and the node awareness value are weighted and summed and then divided by the total number of nodes in the network to obtain a network situation awareness result. Thus, the effective fusion processing of the awareness values of different nodes can be realized based on the network evaluation influence coefficient in the network situation awareness process, thereby ensuring the indication accuracy of the obtained network situation awareness result.

[0073] Optionally, the embodiments of the present disclosure also propose a network situation awareness method, wherein the threat awareness value is determined based on the following manner: determining the vulnerability identifier involved in the attack data of the node to be analyzed in the target period; classifying the network attack information of the node to be analyzed in the target period according to the vulnerability identifier to obtain an attack information set corresponding to each vulnerability identifier, wherein the network attack information in the attack information set is sorted from far to near according to the attack time; performing threat evaluation based on the attack data in the target period to obtain a threat value; and determining the threat awareness value according to the attack information set and the threat value. Thus, the threat situation of the node itself can be accurately analyzed based on the attack data, thereby ensuring the accuracy of the obtained threat awareness value.

[0074] Optionally, when determining the threat awareness value according to the attack information set and the threat value in the embodiments of the present disclosure, the first number of attack information sets in the target period and the first vulnerability awareness value corresponding to each attack information set can be determined; the second number of vulnerabilities that do not appear in the target period but appear in other periods in the continuous multiple execution periods and the second vulnerability awareness value of each vulnerability in the other periods can be determined; and the threat awareness value is calculated and determined according to the threat value, the first number, the first vulnerability awareness value, the second number and the second vulnerability awareness value. Thus, the reliability of the obtained threat awareness value can be ensured.

[0075] The first number can refer to the number of attack information sets generated in the target period. The second number refers to the total number of vulnerabilities that do not appear in the T i th period but appear in one or more of the T i-1 th period, the T i-2 th period and the T i-3 th period.

[0076] The first vulnerability awareness value and the second vulnerability awareness value can be used to describe the threat situation of the corresponding vulnerability.

[0077] In summary, this disclosure provides a network situational awareness method. First, it comprehensively determines the network assessment impact coefficient of each node based on its type, traffic, and security status. Then, based on this network assessment impact coefficient, it performs network situational awareness from three aspects: threat perception, risk perception, and value perception. Because the network assessment impact coefficient is incorporated into the perceived value, and this coefficient reflects the relationship between node security and network security, the impact of a node's risk on the network is considered when assessing network situational awareness through node risk assessment, ensuring an effective assessment of the overall network security.

[0078] The technical solution disclosed herein can be executed periodically to periodically assess network situation and evaluate network security based on the assessment results. For example, it can be executed monthly, using data from that month to assess network situation and evaluate the current network security based on the assessment results. The implementation process for each execution of the proposed method is as follows:

[0079] For example, if this is the i-th execution of the method provided in this embodiment, then:

[0080] Step 1: Obtain raw situational awareness data from each node in the network:

[0081] Including the Tth node in the network i Monitoring data within each cycle, Tth i-1 One cycle, T i-2 Each cycle and T i-3 Monitoring data within a certain period.

[0082] 1. The Tth i Monitoring data within a certain period (i.e., the target period mentioned above).

[0083] The monitoring data here includes traffic data (which can be obtained from traffic logs), vulnerability data (which can be obtained from vulnerability scan reports), attack data (which can be obtained from attack logs), and basic node data.

[0084] Basic data includes: security value (which can be obtained by assessing the current security status of the node based on programs such as firewalls running on the node) and node type (which is set by relevant personnel when the node is configured, such as data acquisition node, data processing node, data forwarding node, etc.).

[0085] In addition, the data will be stored after it is retrieved so that it can be read directly when the method of this proposal is executed again, thus avoiding repeated retrieval.

[0086] 2. The Tth i-1 One cycle, T i-2 Each cycle and T i-3 Data within a period.

[0087] Since i-1 times of the method provided by the present disclosure have been performed before the present execution, the step 1 of each execution will obtain the monitoring data of each node in the network in the T i-1 th period, the T i-2 th period and the T i-3 th period.

[0088] The data here is the same as the data in 1, which has been obtained in the previous execution, and the obtained data has been stored at that time, so the data can be directly read from the storage location at this time.

[0089] In addition, it is possible that the present execution is the first execution of the method provided by the present disclosure, or the number of executions is less than 4 times, and there may be no data of the T i-1 th period, the T i-2 th period and the T i-3 th period. If there is no data, the value of the data can be set to null, that is, there will still be traffic data, vulnerability data, attack data and node basic data of the period, but the data values of each item are null.

[0090] Therefore, no matter which execution of the method provided by the present disclosure, a data vector in the T i th period and data vectors of the T i-1 th period, the T i-2 th period and the T i-3 th period can be obtained, and each period of the data vector includes the same dimension.

[0091] Step 2, obtaining the network evaluation influence coefficient, threat perception value, risk perception value and value perception value of each node according to the situation awareness original data:

[0092] The network evaluation influence coefficient is a value reflecting the relationship between the node and the network. The network evaluation influence coefficient represents the influence degree of the node on the network security. The addition of this coefficient makes the method of the present disclosure consider the influence degree of the node on the network security when performing network security evaluation, thereby improving the evaluation effectiveness of the security of the entire network.

[0093] The threat perception value, risk perception value and value perception value are values reflecting the security of the node itself, which are values evaluating the security of the node itself from the perspective of the node itself.

[0094] The following takes any node j (i.e. the above-mentioned node to be analyzed) as an example, and the determination method of the network evaluation influence coefficient, the threat perception value, the risk perception value and the value perception value is as follows:

[0095] 1. Network evaluation influence coefficient

[0096] The coefficient is the core innovation point of the present disclosure, which reflects the relationship between node security and network security, and the mapping between node perception value and network situation perception value can be realized through the coefficient.

[0097] Network evaluation influence coefficient

[0098] wherein,

[0099] 1) KC j is the influence coefficient of the node, which is obtained based on the node type of node j. KC j The greater the value, the greater the influence on the network situation.

[0100]

[0101] wherein, a j is the influence coefficient corresponding to the node type of node j, which is pre-set, such as pre-setting and storing a coefficient table containing the influence coefficient corresponding to each node type, and the final value of the influence coefficient is determined by relevant personnel based on the possibility of the attack on the node of this type, the influence on the network after the attack, etc. For example, the data processing node is more likely to be favored by the attacker because it not only stores all the analysis of raw data, but also stores the analysis result data, and once the attack is successful, the data loss is very large, so the influence coefficient value corresponding to the data processing node is larger.

[0102] d j is the number of other nodes having data communication with the jth node in T i-3 to T i , i.e. the first node number, which can be obtained based on the flow data statistics, for example, clustering all the flow data from T i-3 to T i by IP address, and each category of data with the same IP address is classified. Since the flow data includes uplink flow and downlink flow, for the uplink flow, the IP address is the destination IP address, and for the downlink flow, the IP address is the source IP address, so each category is one other node having data communication with node j, and the total number of categories is d j .

[0103] d max is the maximum value of the number of other nodes having data communication with each node in T i-3 to T i , i.e. the maximum value of the node number, and d min is the minimum value of the number of other nodes having data communication with each node in T i-3 to T i , i.e. the minimum value of the node number.

[0104] 2) The first influence degree value (i.e. the above-mentioned first influence degree value) is the influence degree of node j on the network traffic. The greater the value, the greater the influence of node j on the change of the network traffic.

[0105] (1) Obtain all the traffic data of node j in T i-3 to T i , calculate the average of the traffic data of each period, and obtain the average traffic of T i-3 The average traffic of T i-2 The average traffic of T i-1 The average traffic of T i

[0106] (2) Calculate the overall average traffic of node j and the overall traffic change rate

[0107] (3) Calculate the traffic fluctuation value of node j

[0108] (4) Calculate

[0109] f max is the maximum value of the traffic fluctuation value of each node, and f min is the minimum value of the traffic fluctuation value of each node. is the maximum value of the overall average traffic of each node, is the minimum value of the overall average traffic of each node.

[0110] 3) The second influence degree value (i.e. the above-mentioned second influence degree value) is the influence degree of node j on the network stability. The greater the value, the greater the influence of node j on the network stability.

[0111]

[0112] wherein A j is the security value of node j, nA j is the number of nodes having a security value not less than A i-3 in T i to T j , and A max is the maximum security value of the nodes having data communication with the jth node.

[0113] 2, threat perception value

[0114] ​​​​The threat perception value is the threat situation of the node j itself, and the value is obtained based on the attack data.

[0115] 1) Based on the attack data of T i , the vulnerability identifier involved in each attack is obtained.

[0116] 2) According to the vulnerability identifier, each attack in T i is classified to obtain an attack information set corresponding to each vulnerability, and the attacks in the set are sorted from far to near according to the attack time.

[0117] 3) For each attack information set, the following processing is performed:

[0118] For example, for the attack information set , wherein, is the earliest attack attribute of the vulnerability corresponding to the attack information set in T i , and the attribute includes attack time, attack type, risk level, etc.

[0119] (1) Determine the attack time difference set corresponding to wherein, is the end time of T i period;

[0120] (2) Calculate the mean value and the standard deviation of each element value in

[0121] (3) Determine the time length when the vulnerability corresponding to is discovered and the total number of attack types involved the maximum risk level

[0122] This time length can first determine the resource involved in the vulnerability (such as an operating system vulnerability, then the resource involved in the operating system), and then determine the time when the resource appears in the node (such as the time when the node installs the operating system), and finally

[0123] 4) Determine

[0124] wherein, U is the total number of attack information sets in T i (i.e., the first number described above), is the perception value of the vulnerability corresponding to the attack information set in T i (i.e., the first vulnerability perception value described above), and if The corresponding vulnerability is at point T. i-1 One cycle, T i-2 Each cycle and T i-3 If it has appeared in one or more of the cycles, then

[0125] β is the value at time T i-1 One cycle, T i-2 Each cycle and T i-3 In each cycle, it appears The quotient of the mean and standard deviation of the attack times of all related attacks in each period of the corresponding vulnerability. j The total deployment time for node j is - The time when node j was first deployed. u For the Tth i-1 One cycle, T i-2 Each cycle and T i-3 In each cycle, it appears The maximum total number of attack types involved in each period of the corresponding vulnerability. u (max) is the maximum value at time T. i-1 One cycle, T i-2 Each cycle and T i-3 In each cycle, it appears The maximum value of the maximum risk level involved in each period of the corresponding vulnerability.

[0126] if The corresponding vulnerability is at point T. i-1 One cycle, T i-2 Each cycle and T i-3 If it has not appeared in any of the cycles, then CVSS (Common Vulnerability Scoring System) is an industry-standard open standard designed to assess the severity of vulnerabilities and help determine the urgency and importance of the required responses. Its main purpose is to help establish standards for measuring vulnerability severity, allowing for comparison of vulnerability severity and thus prioritizing their handling. CVSS scores are based on measurements across a series of dimensions called metrics. The final score for a vulnerability ranges from a maximum of 10 to a minimum of 0.

[0127] V is not present in T. i In the middle, but appearing at the Tth i-1 One cycle, T i-2 Each cycle and T i-3 The total number of vulnerabilities in one or more cycles within a given cycle (i.e., the second number mentioned above), where v represents the number of vulnerabilities not appearing in T. iThe vulnerability identification appears in one or more of the T i-1 periods, T i-2 periods and T i-3 periods. j (v) the second vulnerability awareness value mentioned above, wherein at v is the length of time when the vulnerability is found.

[0128] The threat value is a value obtained by evaluating the attack data in T i , the greater the value, the higher the threat level.

[0129] 3. Risk awareness value is obtained by evaluating the traffic data in T i to T i-3 periods, such as evaluating the traffic change between periods, packet loss rate change, throughput change, etc. Based on the traffic change, the traffic risk of the node is evaluated to obtain The greater the value, the higher the security risk.

[0130] 4. Value awareness value is obtained by combining the number of accesses in node j and the sensitivity of the stored data, for example, determining the average access times of all nodes of the same type as node j,

[0131] Step 3: Network situation awareness is performed to obtain a network situation awareness result

[0132] J is the total number of nodes in the network, w1 is the threat awareness weight, w2 is the risk awareness weight, and w3 is the value awareness weight. The value is set in advance according to the specific situation of network situation awareness. If more emphasis is placed on threat factors, w1 will be relatively large, as long as w1+w2+w3=1.

[0133] Since the network evaluation influence coefficient is added to the awareness value, the network evaluation influence coefficient reflects the relationship between node security and network security, so that when the network situation is evaluated through the risk of the node, the influence of the node risk on the network is considered, ensuring effective evaluation of the security of the entire network.

[0134] In addition, after obtaining the awareness value, it can be compared with the preset threshold value. If the awareness value is higher than the threshold value, it means that the network is abnormal. Even if a single node in the network is normal, as long as the awareness value is abnormal, the network is still considered abnormal and a warning is given.

[0135] Figure 3is a structural schematic diagram of a network situation awareness device according to an embodiment of the present disclosure.

[0136] As shown in the figure, the network situation awareness device 30 comprises: Figure 3

[0137] The acquisition module 301 is configured to acquire situation awareness original data of a node to be analyzed in a network.

[0138] The determination module 302 is configured to determine, according to the situation awareness original data, a network evaluation influence coefficient of the node to be analyzed on the network, a threat awareness value, a risk awareness value and a value awareness value, wherein the network evaluation influence coefficient is used to indicate an influence degree of the node to be analyzed on network security, the threat awareness value is used to indicate a threat situation of the node to be analyzed, the risk awareness value is used to indicate a traffic risk of the node to be analyzed, and the value awareness value is used to indicate value information of the node to be analyzed.

[0139] The generation module 303 is configured to generate a network situation awareness result according to the network evaluation influence coefficient, the threat awareness value, the risk awareness value and the value awareness value corresponding to each node in the network.

[0140] It should be noted that the foregoing explanation and description of the network situation awareness method also apply to the network situation awareness device of this embodiment, which will not be described here again.

[0141] In this embodiment, by acquiring situation awareness original data of a node to be analyzed in a network, according to the situation awareness original data, a network evaluation influence coefficient of the node to be analyzed on the network, a threat awareness value, a risk awareness value and a value awareness value are determined, wherein the network evaluation influence coefficient is used to indicate an influence degree of the node to be analyzed on network security, the threat awareness value is used to indicate a threat situation of the node to be analyzed, the risk awareness value is used to indicate a traffic risk of the node to be analyzed, and the value awareness value is used to indicate value information of the node to be analyzed, and a network situation awareness result is generated according to the network evaluation influence coefficient, the threat awareness value, the risk awareness value and the value awareness value corresponding to each node in the network. Thus, the network evaluation influence coefficient can be added to the awareness value, and the network evaluation influence coefficient reflects the relationship between node security and network security, so that when the network situation is evaluated through the risk of the node, the influence of the risk of the node on the network is considered, and the security of the entire network is effectively evaluated.

[0142] Figure 4 A block diagram of an exemplary computer device suitable for implementing embodiments of the present disclosure is shown. Figure 4 The computer device 12 shown is merely an example and should not impose any limitations on the functions and use range of the embodiments of the present disclosure.

[0143] As shown in the figure, the network situation awareness device 30 comprises: Figure 4 ​As shown, the computer device 12 is in the form of a general-purpose computing device. The components of the computer device 12 can include, but are not limited to, one or more processors or processing units 16, a system memory 28, and a bus 18 that couples various system components including the system memory 28 to the processing unit 16.

[0144] The bus 18 represents one or more of any of several types of bus structures, including a memory bus or memory controller, a peripheral bus, a graphics acceleration bus (e.g., an Accelerated Graphics Port, or AGP bus) and a local bus using any of a variety of bus architectures (e.g., Industrial Standard Architecture (ISA), Micro Channel Architecture (MCA), Enhanced ISA (EISA), Video Electronics Standards Association (VESA) local bus, and Peripheral Component Interconnect (PCI) bus).

[0145] The computer device 12 typically includes a variety of computer system readable media. Such media can be any available media that is accessible by the computer device 12 and includes both volatile and non- volatile media, removable and non-removable media.

[0146] The memory 28 can include computer system readable media in the form of volatile memory, such as random access memory (RAM) 30 and / or cache memory 32. The computer device 12 can further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, a storage system 34 can be provided for reading from and writing to non-removable, non-volatile magnetic media (e.g., a "hard drive"). Figure 4 A removable / non-removable volatile, non-volatile computer system storage medium (e.g., a floppy disk, a magnetic floppy disk, a tape, an optical disk, a flash memory card, or the like) can also be used as the storage system 34.

[0147] Although Figure 4A disk drive, a floppy disk drive, a CD-ROM drive, a DVD-ROM drive, or other removable media drive, can be provided, as shown in FIG. 1, for reading from and writing to a removable n on-volatile magnetic media (e.g., a "floppy disk"), and to a removable non-volatile optical disk (e.g., a CD-ROM, a DVD-ROM, or other optical media). In such cases, each will include a drive mechanism and optical or other storage media interface for accessing data media with the bus 18. The storage 28 can include at least one program product having a set (e.g., at least one) of program modules that are configured to carry out the functions of embodiments of the disclosure.

[0148] The program / utility 40, having a set (at least one) of program modules 42, can be stored in memory 28 by way of example, and not limitation, as well as an operating system, one or more application programs, other program modules, and program data, each or some combination thereof, can include implementation of a network environment. The program modules 42 generally carry out the functions and / or methodologies of embodiments of the disclosure as described herein.

[0149] The computer device 12 can also communicate with one or more external devices 14 such as a keyboard, a pointing device, a display 24, etc.; one or more devices that enable a human user to interact with the computer device 12; and / or one or more devices that enable the computer device 12 to communicate with one or more other computer devices. Such communication can be via the input / output (I / O) interface(s) 22. Furthermore, the computer device 12 can communicate with one or more networks (such as a Local Area Network (LAN), a Wide Area Network (WAN), and / or the public networks, such as the Internet) through a network adapter 20. As shown, the network adapter 20 communicates with the other components of the computer device 12 through the bus 18. It should be appreciated that, although not shown, other hardware and / or software modules could be used in connection with the computer device 12. These include, but are not limited to, microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data archival storage systems, etc.

[0150] The processing unit(s) 16 performs functions and data processing by executing programs stored in the system memory 28, such as implementing the network situation awareness methods mentioned in the foregoing embodiments.

[0151] To achieve the above-mentioned embodiments, the present disclosure further provides a non-transitory computer-readable storage medium having stored thereon a computer program, which, when executed by a processor, implements the network situation awareness method as proposed in the foregoing embodiments of the present disclosure.

[0152] To achieve the above-mentioned embodiments, the present disclosure further provides a computer program product, which, when executed by a processor, performs the network situation awareness method as proposed in the foregoing embodiments of the present disclosure.

[0153] Other embodiments of the present disclosure will be apparent to those skilled in the art from consideration of the specification and practice of the features disclosed herein. The present disclosure is intended to cover any variations, uses or adaptations of the present disclosure following, in general, the principles of the present disclosure and including such features that are evident to those skilled in the art to which the present disclosure pertains. The specification and examples are to be considered exemplary only, with the true scope and spirit of the present disclosure being indicated by the following claims.

[0154] It should be understood that the present disclosure is not limited to the precise structures as herein described and illustrated in the drawings, and that various modifications and changes can be made without departing from the scope thereof. The scope of the present disclosure is limited only by the claims that follow.

[0155] It should be noted that in the description of the present disclosure, the terms "first", "second", etc. are used only for descriptive purposes and cannot be understood as indicating or implying relative importance. In addition, in the description of the present disclosure, the meaning of "a plurality of" is two or more, unless otherwise specified.

[0156] Any process or method descriptions or descriptions of the flow diagrams in the present disclosure can be understood as representing modules, segments, or portions of code that include one or more executable instructions for implementing specific logical functions or steps in the process, and that the scope of the preferred embodiments of the present disclosure includes additional implementation in which the functions are carried out in different orders, in substantially simultaneous fashion, or in reverse order, depending on the functionality involved, as will be understood by those skilled in the art of the embodiments of the present disclosure.

[0157] It should be understood that portions of the present disclosure can be realized with a hardware, software, firmware or a combination thereof. In the above-described embodiments, a plurality of steps or methods can be realized with software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if realized with hardware, and as in another embodiment, any one or a combination of the following technologies known in the art can be used: discrete logic circuit having logic gates for implementing logic functions on data signals, application specific integrated circuits having appropriate combinational logic gates, programmable gate arrays (PGA), field programmable gate arrays (FPGA), etc.

[0158] Those skilled in the art of the present technology can understand that all or part of the steps carried out by the above-mentioned embodiment methods can be completed by a program instructing the relevant hardware, and the program can be stored in a computer readable storage medium. When the program is executed, it includes one of the steps of the method embodiment or a combination thereof.

[0159] In addition, each functional unit in each embodiment of the present disclosure can be integrated into one processing module, or each unit can exist physically independently, or two or more units can be integrated into one module. The above-mentioned integrated module can be realized in the form of hardware or in the form of a software functional module. When the integrated module is realized in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer readable storage medium.

[0160] The storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disk, etc.

[0161] In the description of the present specification, the description of the terms "one embodiment", "some embodiments", "an example", "a specific example" or "some examples" means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present disclosure. In the present specification, the illustrative description of the above terms does not necessarily mean the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.

[0162] Although the embodiments of the present disclosure have been shown and described above, it should be understood that the above-described embodiments are exemplary and cannot be understood as limiting the present disclosure, and those skilled in the art can make changes, modifications, replacements and variations to the above-described embodiments within the scope of the present disclosure.

Claims

1. A cyber situation awareness method, characterized by, The method comprises: obtaining situational awareness original data of a node to be analyzed in a network; determining a network evaluation influence coefficient, a threat awareness value, a risk awareness value and a value awareness value of the node to be analyzed for the network according to the situational awareness original data, wherein the network evaluation influence coefficient is used to indicate the influence degree of the node to be analyzed on network security, the threat awareness value is used to indicate the threat situation of the node to be analyzed itself, the risk awareness value is used to indicate the traffic risk of the node to be analyzed, and the value awareness value is used to indicate the value information of the node to be analyzed; generating a network situational awareness result according to the network evaluation influence coefficient, the threat awareness value, the risk awareness value and the value awareness value corresponding to each node in the network; The method comprises: obtaining monitoring data corresponding to the node to be analyzed in a plurality of continuous execution cycles as the situational awareness original data corresponding to a target cycle, wherein the target cycle is the latest cycle in the plurality of continuous execution cycles, and the monitoring data comprises traffic data, vulnerability data, attack data and node basic data; The node basic data comprises a target node type and a target security value of the node to be analyzed; The method comprises: determining a node influence coefficient according to the target node type and the traffic data; determining a first influence degree value of the node to be analyzed on network traffic according to the traffic data; determining a second influence degree value of the node to be analyzed on network stability according to the target security value and the traffic data; calculating the arithmetic square root of the first influence degree value and the second influence degree value, and calculating the product value of the node influence coefficient and the arithmetic square root as the network evaluation influence coefficient.

2. The method of claim 1, wherein, The method comprises: determining a preset influence coefficient corresponding to the node to be analyzed according to the target node type; determining a first node which has data communication with the node to be analyzed in the plurality of continuous execution cycles according to the traffic data, and determining a first node number of the first node; determining a maximum node number and a minimum node number of the first node number corresponding to different nodes in the network; calculating the node influence coefficient according to the preset influence coefficient, the first node number, the maximum node number and the minimum node number.

3. The method of claim 1, wherein, The method comprises: determining a cycle traffic mean value of the node to be analyzed in each execution cycle according to the traffic data; calculating an overall traffic mean value, an overall traffic change rate and a traffic fluctuation value of the node to be analyzed according to the cycle traffic mean value; determining a maximum value and a minimum value of the overall traffic average corresponding to different nodes in the network; determining a maximum value and a minimum value of the traffic fluctuation value corresponding to different nodes in the network; calculating the first influence degree value according to the traffic fluctuation value, the maximum value of the traffic fluctuation value, the minimum value of the traffic fluctuation value, the overall traffic change rate, the overall traffic average, the maximum value of the overall traffic average, and the minimum value of the overall traffic average.

4. The method of claim 1, wherein, The second influence degree value of the to-be-analyzed node on network stability is determined according to the target security value and the traffic data, including: determining a first node that has data communication with the to-be-analyzed node in the continuous multiple execution cycles according to the traffic data, and determining a first node quantity of the first node and a first security value corresponding to each of the first node; determining a second node quantity of the first node whose first security value is greater than or equal to the target security value, and determining a maximum value of the security value in the plurality of first security values; determining an overall traffic average of the to-be-analyzed node, and a maximum value and a minimum value of the overall traffic average corresponding to different nodes in the network; determining a maximum value and a minimum value of the node quantity corresponding to different nodes in the network; calculating the second influence degree value according to the overall traffic average, the maximum value of the overall traffic average, the minimum value of the overall traffic average, the first node quantity, the second node quantity, the maximum value of the node quantity, the minimum value of the node quantity, the target security value, and the maximum value of the security value.

5. The method of claim 1, wherein, The threat awareness value is determined based on the following manner: determining a vulnerability identifier involved in the attack data of the to-be-analyzed node in the target cycle; classifying network attack information of the to-be-analyzed node in the target cycle according to the vulnerability identifier to obtain an attack information set corresponding to each of the vulnerability identifiers, wherein the network attack information in the attack information set is sorted from far to near according to attack time; performing threat evaluation based on the attack data in the target cycle to obtain a threat value; determining the threat awareness value according to the attack information set and the threat value. The threat awareness value is determined according to the attack information set and the threat value, including:

6. The method of claim 5, wherein, determining a first quantity of the attack information set in the target cycle, and a first vulnerability awareness value corresponding to each of the attack information set; determining a second quantity of vulnerabilities that do not appear in the target cycle but appear in other cycles in the continuous multiple execution cycles, and a second vulnerability awareness value of the vulnerabilities in each of the other cycles; calculating the threat awareness value according to the threat value, the first quantity, the first vulnerability awareness value, the second quantity, and the second vulnerability awareness value. ​ 7. The method of claim 1, wherein, The network situation awareness result is generated according to the network evaluation influence coefficient, the threat perception value, the risk perception value and the value perception value corresponding to each node in the network, and the network situation awareness result comprises: The threat perception value, the risk perception value and the value perception value of the node are weighted and summed according to the pre-configured threat perception weight, risk perception weight and value perception weight to obtain a node perception value; The network situation awareness result is obtained by weighting and summing the network evaluation influence coefficient corresponding to each node and the node perception value and then dividing the total number of nodes in the network.

8. A cyber situation awareness apparatus, characterized by, Comprise: An acquisition module is configured to acquire situation awareness original data of a node to be analyzed in a network; A determination module is configured to determine, according to the situation awareness original data, a network evaluation influence coefficient, a threat perception value, a risk perception value and a value perception value of the node to be analyzed with respect to the network, wherein the network evaluation influence coefficient is used to indicate the influence degree of the node to be analyzed on network security, the threat perception value is used to indicate the threat situation of the node to be analyzed, the risk perception value is used to indicate the traffic risk of the node to be analyzed, and the value perception value is used to indicate the value information of the node to be analyzed; A generation module is configured to generate a network situation awareness result according to the network evaluation influence coefficient, the threat perception value, the risk perception value and the value perception value corresponding to each node in the network; The acquisition module is specifically configured to acquire monitoring data corresponding to the node to be analyzed in a plurality of continuous execution cycles as the situation awareness original data corresponding to a target cycle, wherein the target cycle is the latest cycle in the plurality of continuous execution cycles, and the monitoring data comprises traffic data, vulnerability data, attack data and node basic data; The node basic data comprises a target node type and a target security value of the node to be analyzed, and the determination module is specifically configured to determine a node influence coefficient according to the target node type and the traffic data; Determine a first influence degree value of the node to be analyzed on network traffic according to the traffic data; Determine a second influence degree value of the node to be analyzed on network stability according to the target security value and the traffic data; Calculate the arithmetic square root of the first influence degree value and the second influence degree value, and calculate the product value of the node influence coefficient and the arithmetic square root as the network evaluation influence coefficient.

9. A computer device, comprising: Comprise: At least one processor; And The memory is in communication connection with the at least one processor; wherein The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method of any one of claims 1-7.

10. A non-transitory computer-readable storage medium having stored thereon computer instructions, wherein, Wherein, The computer instructions are used to enable the computer to execute the method of any one of claims 1-7.

11. A computer program product, characterised in that, Comprise a computer program, the computer program is executed by the processor to realize the steps of the method according to any one of claims 1-7.

Citation Information

Patent Citations

  • Network safety risk assessment system

    CN108881325A

  • Enterprise network security assessment method and device, mobile terminal and storage medium

    CN114615016A