Network security situation awareness method, device, equipment, storage medium and product

By dynamically adjusting the weights of network status anomalies and vulnerabilities based on network service types, the problem of low efficiency in passive firewall defense in existing technologies is solved, enabling proactive defense of network security posture and improving network security defense efficiency.

CN118827121BActive Publication Date: 2025-11-21CHINA MOBILE GROUP SHAIHAI +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410194858.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-02-21
Publication Date
2025-11-21
Estimated Expiration
2044-02-21

AI Technical Summary

Technical Problem

Existing technologies rely on firewalls to passively defend against external network intrusions, resulting in low network security defense efficiency and an inability to accurately predict future network security risks.

Method used

By determining the weights of network status anomalies and vulnerabilities based on the service type of the network to be perceived, and combining this with network perception data, the network security situational awareness results are dynamically adjusted to achieve proactive defense.

Benefits of technology

By anticipating the evolving cybersecurity landscape, we can shift from passive to proactive cybersecurity defense, thereby improving the efficiency of cybersecurity defense.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118827121B_ABST
    Figure CN118827121B_ABST
Patent Text Reader

Abstract

The application belongs to the computer field and discloses a network security situation awareness method, device, equipment, storage medium and computer program product. The method comprises the following steps: determining the service type of a network to be sensed according to the network sensing data of each node in the network to be sensed; determining the network state abnormal value weight and the fragile value weight according to the service type and the network sensing data; determining the network state abnormal value and the fragile value based on the network sensing data, and determining the network security situation awareness result of the network to be sensed according to the network state abnormal value, the fragile value, the network state abnormal value weight and the fragile value weight. According to the application, the network state abnormal value weight and the fragile value weight are determined according to the service type of the network to be sensed, and then the network security situation awareness result of the network to be sensed is determined in combination with the network state abnormal value and the fragile value. Compared with the existing network security defense mode of passively defending external network intrusion through a firewall, the application can sense the network security situation in advance.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer, and particularly relates to a network security situation awareness method, device, equipment, storage medium and computer program product. BACKGROUND

[0002] Traditional network security defense mainly passively defends external network intrusion through a firewall, antivirus software and the like, and cannot accurately predict the future trend; network security situation prediction can analyze network status and predict future conditions, and can formulate security prevention measures before the network is in danger. Therefore, how to analyze network status, understand the network security risk to be occurred in advance, and thus realize the transition of network security defense from passive defense to active defense is a problem to be solved urgently at present. SUMMARY

[0003] The main purpose of the present application is to provide a network security situation awareness method, device, equipment, storage medium and computer program product, and aims to solve the technical problem of low network security defense efficiency caused by passive defense of external network intrusion through a firewall in the prior art.

[0004] To achieve the above purpose, the present application provides a network security situation awareness method, which comprises the following steps:

[0005] determining a service type of the network to be sensed according to network sensing data of each node in the network to be sensed;

[0006] determining a network status abnormal value weight and a vulnerability value weight according to the service type and the network sensing data;

[0007] determining a network status abnormal value and a vulnerability value based on the network sensing data, and determining a network security situation awareness result of the network to be sensed according to the network status abnormal value, the vulnerability value, the network status abnormal value weight and the vulnerability value weight.

[0008] Optionally, the step of determining a network status abnormal value and a vulnerability value based on the network sensing data comprises:

[0009] grouping the network sensing data to obtain a grouping result;

[0010] determining data packet data of each target group in the grouping result, and determining a network status abnormal value according to the data packet data;

[0011] determining attack data of each target group in the grouping result, determining a grouping vulnerability value of the target group according to the attack data, and determining a vulnerability value according to the grouping vulnerability value.

[0012] Optionally, the step of grouping the network perception data to obtain a grouping result comprises:

[0013] grouping the network perception data according to a preset IP address coding rule to obtain a preliminary grouping result;

[0014] determining a data packet quantity of each grouping in the preliminary grouping result;

[0015] determining a reference grouping according to the data packet quantity;

[0016] splitting a to-be-split grouping that meets a preset grouping condition based on the data packet quantity and the reference grouping to obtain a grouping result.

[0017] Optionally, the step of determining network state abnormal values according to data packet data of each target grouping in the grouping result comprises:

[0018] determining data packet data of each target grouping in the grouping result;

[0019] determining data packet quantity information and device connection duration information according to the data packet data;

[0020] obtaining bandwidth information of a target node corresponding to the grouping result;

[0021] determining network state abnormal values according to the bandwidth information, the data packet quantity information, the device connection duration information, and a grouping quantity in the grouping result.

[0022] Optionally, the step of determining attack data of each target grouping in the grouping result, determining a grouping vulnerability value of the target grouping according to the attack data, and determining a vulnerability value according to the grouping vulnerability value comprises:

[0023] determining attack data of each target grouping in the grouping result;

[0024] clustering the attack data according to attack features to obtain a clustering result;

[0025] determining a grouping vulnerability value of the target grouping based on the clustering result and the attack data;

[0026] determining a vulnerability value according to the grouping vulnerability value.

[0027] Optionally, the step of determining a service type of the to-be-perceived network according to network perception data of each node in the to-be-perceived network comprises:

[0028] determine a security data average value, a security data median value and a security data standard deviation of the network to be perceived according to network perception data of each node in the network to be perceived;

[0029] determine whether a service type of the network to be perceived is a data type according to the security data average value, the security data median value and the security data standard deviation;

[0030] determine the service type of the network to be perceived according to attack data, vulnerability data and bandwidth data in the network perception data when the service type of the network to be perceived is not the data type.

[0031] Optionally, the step of determining the network state abnormal value weight and the vulnerability value weight according to the service type and the network perception data comprises:

[0032] determine target data packet information according to the network perception data when the service type is a flow type;

[0033] determine data packet variance according to the target data packet information;

[0034] determine the network state abnormal value weight and the vulnerability value weight according to the data packet variance;

[0035] determine target attack data according to the network perception data when the service type is a comprehensive type;

[0036] determine the network state abnormal value weight and the vulnerability value weight according to the target attack data.

[0037] In addition, to achieve the above object, the application further provides a network security situation awareness device, which comprises:

[0038] a service type determination module configured to determine a service type of a network to be perceived according to network perception data of each node in the network to be perceived;

[0039] a weight determination module configured to determine a network state abnormal value weight and a vulnerability value weight according to the service type and the network perception data;

[0040] a network security situation awareness module configured to determine a network state abnormal value and a vulnerability value based on the network perception data, and determine a network security situation awareness result of the network to be perceived according to the network state abnormal value, the vulnerability value, the network state abnormal value weight and the vulnerability value weight.

[0041] In addition, to achieve the above object, the present application further provides a network security situation awareness device, which comprises a memory, a processor, and a network security situation awareness program stored in the memory and executable on the processor, and the network security situation awareness program is configured to implement the steps of the network security situation awareness method as described above.

[0042] In addition, to achieve the above object, the present application further provides a storage medium, which stores a network security situation awareness program, and the network security situation awareness program is executable on a processor to implement the steps of the network security situation awareness method as described above.

[0043] In addition, to achieve the above object, the present application further provides a computer program product, which comprises a network security situation awareness program, and the network security situation awareness program is executable on a processor to implement the steps of the network security situation awareness method as described above.

[0044] The present application determines the service type of the network to be perceived according to the network perception data of each node in the network to be perceived, determines the network state abnormal value weight and the vulnerable value weight according to the service type and the network perception data, determines the network state abnormal value and the vulnerable value based on the network perception data, and determines the network security situation awareness result of the network to be perceived according to the network state abnormal value, the vulnerable value, the network state abnormal value weight, and the vulnerable value weight. Since the present application determines the network state abnormal value weight and the vulnerable value weight according to the service type of the network to be perceived, and then determines the network security situation awareness result of the network to be perceived in combination with the network state abnormal value and the vulnerable value, compared with the existing network security defense mode of passively defending against external network intrusion through a firewall, the above mode of the present application can perceive the network security situation trend in advance, so as to realize the conversion of the network security defense from passive defense to active defense. BRIEF DESCRIPTION OF DRAWINGS

[0045] Figure 1 is a structural schematic diagram of a network security situation awareness device of a hardware running environment related to the embodiment scheme of the present application;

[0046] Figure 2 is a flowchart of a first embodiment of the network security situation awareness method of the present application;

[0047] Figure 3 is a flowchart of a second embodiment of the network security situation awareness method of the present application;

[0048] Figure 4 is a flowchart of a third embodiment of the network security situation awareness method of the present application;

[0049] Figure 5The structural block diagram of the first embodiment of the network security situation awareness device of the present application.

[0050] The implementation, functional features and advantages of the present application will be further illustrated with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION

[0051] It should be understood that the specific embodiments described herein are merely illustrative of the present application and are not intended to limit the present application.

[0052] Referring to Figure 1 , Figure 1 The structural schematic diagram of the network security situation awareness device of the hardware running environment involved in the embodiment scheme of the present application.

[0053] As Figure 1 shown, the network security situation awareness device can include a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. The communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 can include a display, an input unit such as a keyboard, and can also include a standard wired interface, a wireless interface. The network interface 1004 can optionally include a standard wired interface, a wireless interface (such as a wireless fidelity (WI-FI) interface). The memory 1005 can be a high-speed random access memory (RAM), and can also be a stable non-volatile memory (NVM), such as a disk memory. The memory 1005 can also be a storage device independent of the aforementioned processor 1001.

[0054] Those skilled in the art can understand that Figure 1 the structure shown in the foregoing embodiments does not constitute a limitation on the network security situation awareness device, and can include more or fewer components than the illustrated components, or combine certain components, or different component arrangements.

[0055] As Figure 1 shown, the memory 1005 as a storage medium can include an operating system, a network communication module, a user interface module, and a network security situation awareness program.

[0056] In Figure 1The network interface 1004 is mainly used for data communication with a network server; the user interface 1003 is mainly used for data interaction with a user; the processor 1001 and the memory 1005 in the network security situation awareness device can be arranged in the network security situation awareness device, the network security situation awareness device calls the network security situation awareness program stored in the memory 1005 through the processor 1001, and executes the network security situation awareness method provided in the embodiment of the application.

[0057] Based on the network security situation awareness device, the embodiment of the application provides a network security situation awareness method, which refers to Figure 2 , Figure 2 The flowchart of the network security situation awareness method in the first embodiment of the application is shown in the figure.

[0058] In the embodiment, the network security situation awareness method comprises the following steps:

[0059] Step S10: determining the service type of the network to be sensed according to the network sensing data of each node in the network to be sensed.

[0060] It should be noted that the execution subject of the embodiment can be a computing service device with data processing, network communication and program running functions, such as a mobile phone, a tablet computer, a personal computer, etc., or an electronic device or a network security situation awareness device capable of realizing the above functions. The network security situation awareness device is taken as an example to describe the embodiment and the following embodiments.

[0061] It should be noted that the network to be perceived can be a network that needs to perform network security situation awareness, for example, a local area network of a certain cell or family. The network perception data of each node can include bandwidth, data packet, vulnerability, attack, security and the like of each network node in the network to be perceived. For any node in the network to be perceived, the network perception data thereof includes: bandwidth data: since the bandwidth data is real-time changing, the bandwidth data can include the maximum bandwidth, the minimum bandwidth and the average bandwidth in a preset security situation awareness period (i.e., a network perception time period set in advance); data packet data: all data packets in the network perception time period are obtained from a traffic log to form four-tuple of data including: for uplink data, the four-tuple is: [destination IP, destination port, packet size, sending time], and for downlink data, the four-tuple is: [source IP, source port, packet size, receiving time]; vulnerability data: the vulnerability condition of the node is obtained, and the CVSS (Common Vulnerability Scoring System) value of each vulnerability is obtained. The vulnerability condition of the device operating system or other software can be obtained by crawling. The CVSS is an industry public standard designed to evaluate the severity of vulnerabilities and help determine the urgency and importance of the required response. Its main purpose is to help people establish a standard for measuring the severity of vulnerabilities so that people can compare the severity of vulnerabilities to determine their priority. The CVSS score is based on measurements in a series of dimensions, which are called metrics. The final score of the vulnerability is 10 at most and 0 at least. Vulnerabilities with scores of 7-10 are generally considered serious, those with scores of 4-6.9 are intermediate vulnerabilities, and those with scores of 0-3.9 are low-level vulnerabilities; security data: the security data is derived from the score of the security program (such as firewall) of the node on the node. At least one score can be obtained in the network perception time period, and the minimum score obtained is taken as the security data of the network node; attack data: the attack log of the network node is obtained, and the four-tuple [attack feature, attack start time, attack duration, involved vulnerability] of each attack is determined based on the attack log, wherein, for any attack, the time when the attack is received is taken as the attack start time, and the time when the attack is first detected is taken as the end time of the attack, and the end time-initial time=attack duration. The business type of the network to be perceived can include data type, traffic type and comprehensive type.

[0062] Further, in order to avoid wasting resources caused by network security situation awareness when data is abnormal, the obtained data packet data is preprocessed in the embodiment to determine whether the current network awareness data is abnormal, and if it is abnormal, the network security situation awareness in the embodiment is not performed. Specifically, the IP address mentioned in the embodiment is the destination IP (for uplink data) and the source IP address (for downlink data). The port mentioned is the destination port (for uplink data) and the source port (for downlink data). The steps of preprocessing the obtained data packet data include: determining the number of destination IPs and the number of source IPs. The same destination IP address can send multiple data packets, and the embodiment determines the number of different destination IP addresses involved in all uplink data In all downlink data, the number of different source IP addresses involved is determined Although the ports are the same, the IP addresses are different, so the data is sent or received from different devices, and therefore, the IP address is considered when determining the number of ports. That is, in all uplink data, the destination IP and the destination port are combined into one data to determine the number of destination ports Similarly, in all downlink data, the source IP and the source port are combined into one data to determine the number of source ports Determine the change value of the IP address Determine the change value of the port If one of the change values of the IP address and the port is 0, it means that the data is abnormal, and a direct warning is given, and the network security situation awareness in the embodiment is not performed.

[0063] It should be noted that the determination of the service type of the network to be perceived according to the network awareness data of each node in the network to be perceived can be the determination of the service type of the network to be perceived according to the bandwidth data, vulnerability data, attack data and security data in the network awareness data of each node in the network to be perceived.

[0064] Further, different business type networks have different possibilities of being attacked, and then the weight of each perception parameter in the subsequent network security perception process is different. In order to make the perception result more consistent with the current network business, the embodiment will determine the current business type of the network, and then perform perception based on the business type in the subsequent network security situation perception process, thereby ensuring the accuracy of the network security situation perception result and the fitting degree with the network business. The network business type represents the current business scenario of the network, that is, the characteristics of the actual business carried in the network. The network business type is divided into traffic type, data type and comprehensive type. The traffic type network means that a large amount of data flows on the network, but the data value is not high. For example, for the network between the Internet of Things terminal and the server in the Internet of Things, a large amount of real-time data uploaded by the Internet of Things terminal will be carried on the network. Most of the large amount of data is worthless data. For the traffic type network, the possibility of being attacked is small. Only when the network is paralyzed, the network will be attacked. Because after a large amount of data is stolen by attacking the network, the stolen data may have no value. The data type network means that the data flowing on the network has high value. For example, the internal network with high security level (such as a network containing user feature data), once the data on the network is leaked, the loss is large. The possibility of attacking the network is large. The comprehensive type network means that the amount of data flowing on the network is not large, and the data value is general. For example, the network used by the user. The possibility of attacking the network is general. Therefore, the step is realized based on bandwidth data, vulnerability data, security data and attack data. The vulnerability data indicates the risk of a node, and the security data indicates the current situation of a node. When a node device is configured, the purpose of the device and the security level of the data involved by the device are evaluated. At the same time, the vulnerability situation of the device is known. Then, the corresponding security strategy is taken based on the business situation and the vulnerability situation of the device to ensure that the device meets the data security requirement. The matching degree can be known through the security data. If the matching degree is low, it is determined whether the data security requirement is not high or the node security has hidden dangers based on the bandwidth data and the attack data, and then the network type is obtained. Therefore, the step S10 can include: determining the average value, the median and the standard deviation of the security data of the network to be perceived according to the network perception data of each node in the network to be perceived.

[0065] determining whether the business type of the network to be perceived is the data type according to the average value, the median and the standard deviation of the security data.

[0066] when the business type of the network to be perceived is not the data type, determining the business type of the network to be perceived according to the attack data, the vulnerability data and the bandwidth data in the network perception data.

[0067] It should be noted that the determination of the security data average value, the security data median value and the security data standard deviation corresponding to the network to be perceived can be to calculate the security data average value and the standard deviation of all nodes in the network to be perceived, arrange all the security data of the nodes in descending order, and if the median value of the security data in the sequence is not less than the average value of the security data*(1+security data standard deviation), it is determined that the service type of the network to be perceived is data type. Otherwise, the maximum value of the CVSS value of each node, the total number of attacks in the attack data and the maximum bandwidth in the traffic data are determined. If the maximum value of the CVSS value does not exceed 6 (other values can be defined according to the actual scene), the total number of attacks is less than the attack threshold (defined according to the experience value and the actual scene), and the maximum bandwidth is greater than the bandwidth threshold (defined according to the experience value and the actual scene) of more than half of the total nodes in the network, it is indicated that the network itself is not very risky, but the data volume is large, and it is determined that the service type of the network to be perceived is traffic type. Otherwise, it is determined that the service type of the network to be perceived is comprehensive type. The attack threshold and the bandwidth threshold can be experience values, which can be dynamically set by the user according to the current security policy. If the network security policy is relatively loose, the attack threshold is larger and the bandwidth threshold is smaller, and at this time it is more likely to be a traffic type network.

[0068] Step S20: determining network state abnormal value weight and vulnerability value weight according to the service type and the network perception data.

[0069] It should be noted that the determination of the network state abnormal value weight and the vulnerability value weight according to the service type and the network perception data can be that when the service type of the network to be perceived is traffic type, the network to be perceived itself does not pay much attention to the network vulnerability, and therefore the network state abnormal value weight at this time can be set to be greater than the vulnerability value weight, for example, the network state abnormal value weight is set to 0.7, and the vulnerability value weight is 1-0.7=0.3. The application scene of the network to be perceived can be defined and set according to the application scene of the network to be perceived. If the service type of the network to be perceived is data type, it indicates that the network to be perceived pays attention to both the network state and the vulnerability, and therefore the network state abnormal value weight wight AW of the network state abnormal value AW can be set to 0.5, and the vulnerability value weight wight SK of the vulnerability value SK can be set to 1-wight AW =0.5. If the service type of the network to be perceived is comprehensive type, the network to be perceived pays attention to both the network state and the vulnerability, but pays more attention to the vulnerability value, and therefore the network state abnormal value weight at this time can be set to be less than the vulnerability value weight, for example, the network state abnormal value weight is set to 0.4, and the vulnerability value weight is 1-0.4=0.6. The application scene of the network to be perceived can be defined and set according to the application scene of the network to be perceived.

[0070] Step S30: determining a network state anomaly value and a vulnerability value based on the network perception data, and determining a network security situation awareness result of the network to be perceived according to the network state anomaly value, the vulnerability value, a network state anomaly value weight and a vulnerability value weight.

[0071] It should be noted that the network state anomaly value can be determined according to the network perception data, the data amount of the data packets received or sent at each time in the network perception time period, the maximum amount of the data packets received or sent at a single time, the minimum amount of the data packets, the average amount of the data packets, and the variance of the data packets, which represents the change of the data amount in the node. The network state anomaly value can be determined according to the maximum amount of the data packets, the minimum amount of the data packets, the average amount of the data packets, and the variance of the data packets, and specifically, the network state anomaly value = (average amount of data packets - minimum amount of data packets) / (maximum amount of data packets - minimum amount of data packets) + variance of data packets. The vulnerability value can be determined based on the network perception data, the attack times of each attack received by the node, the attack duration, and the CVSS value of the vulnerability involved in the attack, and the vulnerability value can be determined according to the attack times of each attack received by the node, the attack duration, and the CVSS value of the vulnerability involved in the attack, and specifically:

[0072]

[0073] Wherein, a represents an attack identifier, and n represents the number of attack types.

[0074] It should be noted that the network security situation awareness result of the network to be perceived can be determined according to the following formula to determine the node network security situation awareness value of each node:

[0075]

[0076] Wherein, S represents the node network security situation awareness value of the network node, wight SK represents the vulnerability value weight of the network node, SK represents the vulnerability value of the network node, wight AW represents the network state anomaly value weight of the network node, AW represents the network state anomaly value of the network node, and the security data is the score of the network node given by the security program (such as a firewall) of the network node.

[0077] It should be noted that the network security situation awareness result of the network to be perceived can be the average value of the node network security situation awareness values of each network node in the network to be perceived.

[0078] In a specific implementation, a network security threshold value can be preset, which can be an empirical value or obtained through big data analysis. When the network security value in the network security situation awareness result of the network to be sensed is greater than the network security threshold value, it is determined that the network to be sensed has a greater risk and needs network security situation early warning.

[0079] The embodiment determines the service type of the network to be sensed according to the network sensing data of each node in the network to be sensed, determines the network state abnormal value weight and the vulnerability value weight according to the service type and the network sensing data, determines the network state abnormal value and the vulnerability value based on the network sensing data, and determines the network security situation awareness result of the network to be sensed according to the network state abnormal value, the vulnerability value, the network state abnormal value weight and the vulnerability value weight. Compared with the existing network security defense mode of passively defending against external network intrusion through a firewall, the above mode of the embodiment can perceive the network security situation in advance, so as to realize the conversion of network security defense from passive defense to active defense.

[0080] The embodiment determines the current service type of the network to be sensed based on the bandwidth data, the vulnerability data, the security data and the attack data, and then determines the weights of the network state abnormal value and the vulnerability value based on the current service type of the network to be sensed, so that the network security situation is perceived based on the weights of the network state abnormal value and the vulnerability value and the network state abnormal value and the vulnerability value. Since the possibility of network attack is different for different service types, the weights of the sensing parameters are also different in the subsequent network security sensing process. In order to make the sensing result more consistent with the current network service, the embodiment determines the current service type of the network to be sensed, and then performs sensing based on the service type in the subsequent network security situation awareness process, thereby ensuring the accuracy of the network security situation awareness result of the embodiment and the fitting degree with the network service.

[0081] Reference Figure 3 , Figure 3 FIG. 2 is a flowchart of a second embodiment of the network security situation awareness method of the present application.

[0082] Based on the above first embodiment, in the present embodiment, the step S30 comprises:

[0083] Step S301: Grouping the network sensing data to obtain a grouping result.

[0084] It should be noted that the grouping of the network perception data to obtain the grouping result can be grouping the data packets in the network perception data according to the IP addresses corresponding to the data packets sent or received, to obtain the grouping result. Specifically, in order to facilitate the management of IP addresses, IP addresses are basically divided into 5 categories, namely A, B, C, D and E. The first digit of the IP address of A must be 0, the first byte is the network bit, and the other 3 bytes are the host bit. The binary range of the network bit is: 00000001~01111111, converted to the decimal range: 1~127, the IP address range divided is: 1.0.0.0~126.255.255.254. The first digit of the IP address of B must be 10, the first and second bytes are network bits, and the other 2 bytes are host bits. The binary range of the network bit is: 10000000~10111111, converted to the decimal range: 128~191, the IP address range divided is: 128.0.0.1~191.255.255.254. The first digit of the IP address of C must be 110, the first, second and third bytes are network bits, and the other 1 byte is the host bit. The binary range of the network bit is: 11000000~11011111, converted to the decimal range: 192~223, the IP address range divided is: 192.0.0.1~223.255.255.254. The first digit of the IP address of D must be 111 (multicast), and there is no network address and host address. The address range is: 224.0.0.1-239.255.255.254. The first digit of the IP address of E must be 1111 (scientific research reserved), and there is no network address and host address. The address range is: 240.0.0.1-255.255.255.254. In IP address allocation, A class address is allocated to government agencies, B class address is allocated to medium-sized enterprises, C class address is allocated to anyone who needs it, D class address is used for multicast, and E class address is used for experiments. In actual application, the possibility of receiving D class address and E class address is low, and the influence of receiving A class address on network security is small. Therefore, the data packets are divided into 3 groups according to the IP address, that is, the first group composed of A class address, D class address and E class address, the second group composed of B class address, and the third group composed of C class address. The above grouping result is obtained.

[0085] Further, in order to ensure that the number of data packets in each group in the final grouping result is approximate, the step S301 can include: grouping the network perception data according to a preset IP address coding rule to obtain a preliminary grouping result.

[0086] Determine the number of data packets in each group in the preliminary grouping result.

[0087] Determine the reference grouping according to the number of data packets.

[0088] Split the to-be-split group meeting the preset group condition based on the data packet quantity and the reference group to obtain a group result.

[0089] It should be noted that the preliminary grouping of the network awareness data according to the preset IP address coding rule to obtain a preliminary group result can be grouping the network awareness data according to the above-mentioned five types of IP address coding rules A, B, C, D and E to obtain five groups of grouping, and then grouping the A-class address, the D-class address and the E-class address into a first group, grouping the B-class address into a second group, and grouping the C-class address into a third group to obtain the preliminary group result.

[0090] In actual application, the IP addresses involved by the nodes are not quite in the three groups, for example, the IP addresses in the second group are very few, and the IP addresses in the third group are very many, and the embodiment will split in each group to make the number of each group obtained finally more balanced, so as to facilitate subsequent analysis and processing. The data packet quantity of each group in the three groups determined can be that the IP addresses involved by each group are respectively Determining the reference group according to the data packet quantity can be taking the group with the least data packet quantity as the reference group. In order to facilitate the introduction of the implementation mode of the embodiment, the following will take the minimum value as an example to illustrate. The data packet quantity of each group in the three groups determined can be that the IP addresses involved by each group are respectively

[0091] If , the second group is not split, otherwise the second group is split. If , the third group is not split, otherwise the third group is split. If the conditions are met, the second group and the third group can be split at the same time or not split.

[0092] The following will take the splitting of the second group as an example to introduce the splitting process:

[0093] The IP address is a 32-bit address, which is divided into four 8-bit segments, such as A1.A2.A3.A4.

[0094] A. The second group data is sorted according to A1 from small to large, if A1 is the same, then A2 is sorted, if A1 and A2 are the same, then A3 is sorted, if A1, A2 and A3 are the same, then A4 is sorted.

[0095] B. Determine the splitting point , wherein is a rounding up function. The S2 splitting points will divide the second group IP addresses into S2+1 groups.

[0096] ​​C. Determine the data volume threshold of each group after splitting

[0097] D. From the IP addresses in the second group after sorting, select multiple IP addresses in turn, so that the number of data packets of the selected IP addresses is closest to a0.

[0098] This step can be realized by using the existing optimal solution algorithm. Taking the splitting into two groups as an example, S2=1. Let the number of data packets of each group after splitting be and Then solve the optimal solution that satisfies the following relationship:

[0099]

[0100]

[0101] The number of IP addresses in each group is an integer. The groups after splitting are taken as the final groups, that is, the grouping result, and the number of groups in the grouping result is greater than or equal to three groups in the preliminary grouping result. Through the above grouping process, it can be ensured that the number of data packets in each group is approximate, and the IP addresses located in the same network segment are located in the same group, thereby increasing the comparability.

[0102] Step S302: Determine the data packet data of each target group in the grouping result, and determine the network state abnormal value according to the data packet data.

[0103] It should be noted that the target group can be each group in the grouping result, and the data packet data can include the data volume of the data packets received or sent by the target group at each time in the network perception time period. The network state abnormal value can be determined according to the maximum value, the minimum value, and the average value of the data volume of the data packets received or sent at each time in the network perception time period.

[0104] Further, in order to accurately perceive the network state of the network to be perceived, the step S302 can include: determining the data packet data of each target group in the grouping result;

[0105] determining data packet quantity information and device connection duration information according to the data packet data;

[0106] obtaining bandwidth information of a target node corresponding to the grouping result;

[0107] determining a network state abnormal value according to the bandwidth information, the data packet quantity information, the device connection duration information, and the number of groups in the grouping result.

[0108] It should be noted that the data packet quantity information can include the maximum amount DB of data volume of data packets received or sent at a single time max , the minimum amount DB min , the average amount DB avg , and the variance σ of the total amount of data packets at each time DB . σ DB is the variance of the data packet quantity at each time, representing the change of the data volume in the group, and can also include the normalized data packet volume of the target group, and the variance of the normalized data packet volume of each group. Specifically, the total amount of data packets sent or received at any time is determined according to the data packet data. And determine the maximum amount DB max , the minimum amount DB min , the average amount DB avg of data volume of data packets received or sent at a single time, determine the variance σ DB of the data packet according to the total amount of data packets sent or received at any time, determine the normalized data packet volume of each target group determine the variance of the normalized data packet volume DB0 of each group according to the normalized data packet volume of each target group The device connection duration information can include the maximum duration IP of data packets sent by the same IP address max , which is the duration from the establishment of the connection of the IP address to the disconnection of the connection. The bandwidth information of the target node corresponding to the grouping result can be the maximum bandwidth BW max , the minimum bandwidth BW min and the average bandwidth BW avg of the network node corresponding to the grouping result in the network perception time period. The network state abnormal value determined according to the bandwidth information, the data packet quantity information, the device connection duration information, and the number of groups in the grouping result can be determined by the following formula:

[0109]

[0110] Wherein, AW is used to represent the network state abnormal value, BW max is used to represent the maximum bandwidth, BW min is used to represent the minimum bandwidth, g is used to represent the group identifier, is used to represent the variance σ of the data packet of the gth group DB , is used to represent the maximum duration IP max of the gth group, G is used to represent the total number of groups of the target node, BW avg is used to represent the average bandwidth, is used to represent the variance of the normalized data packet volume DB0 of each group.

[0111] Step S203: determining attack data of each target group in the grouping result, determining a group vulnerability value of the target group according to the attack data, and determining a vulnerability value according to the group vulnerability value.

[0112] It should be noted that the attack data can include attack features, attack start time, attack duration, and information about involved vulnerabilities. The group vulnerability value of the target group can be determined according to the attack data by calculating an attack score corresponding to each attack, selecting the highest score as the group vulnerability value, and selecting the group vulnerability value with the highest score in the group as the vulnerability value of the target node. The attack score can be the product of the attack duration and the CVSS value of the involved vulnerability.

[0113] Further, to improve the efficiency of network perception, the step S203 can include: determining attack data of each target group in the grouping result;

[0114] clustering the attack data according to attack features to obtain a clustering result;

[0115] determining a group vulnerability value of the target group based on the clustering result and the attack data;

[0116] determining a vulnerability value according to the group vulnerability value.

[0117] It should be noted that the attack data can include attack features, attack start time, attack duration, and information about involved vulnerabilities. The group vulnerability value of the target group can be determined according to the attack data by calculating an attack score corresponding to each attack, selecting the highest score as the group vulnerability value, and selecting the group vulnerability value with the highest score in the group as the vulnerability value of the target node. The attack score can be the product of the attack duration and the CVSS value of the involved vulnerability.

[0118]

[0119] wherein a represents an attack identifier, Da represents an attack vulnerability value of attack a, N A represents the total number of attacks in the attack data, n a represents the total number of attacks in the class to which attack a belongs, t is the current time, t a is the start time of the attack with the same feature as attack a that occurred most recently, is the average time difference between two adjacent attacks with the same feature as attack a, Δt a is the average attack duration of attacks with the same feature as attack a, CVSS a is the CVSS value of the vulnerability involved in attack a.

[0120] The attack vulnerability value with the highest score is selected from the attack vulnerability values ​​as the group vulnerability value of the target group. The group vulnerability value of each target group is determined, and the group vulnerability value with the highest score in the group is used as the vulnerability value of the target node.

[0121] This embodiment groups the network sensing data to obtain grouping results; it determines the data packet data of each target group in the grouping results, and determines network state anomaly values ​​based on the data packet data; it also determines the attack data of each target group in the grouping results, determines the group vulnerability value of the target group based on the attack data, and determines the vulnerability value based on the group vulnerability value. This embodiment determines network state anomaly values ​​and vulnerability values ​​based on network sensing data, and then performs network security situation awareness of the network to be sensed, ensuring the accuracy of the network security situation awareness results and their relevance to network services.

[0122] refer to Figure 4 , Figure 4 This is a flowchart illustrating the third embodiment of the network security situation awareness method of the present invention.

[0123] Based on the above embodiments, in this embodiment, step S20 includes:

[0124] Step S201: When the service type is traffic-based, determine the target data packet information based on the network sensing data.

[0125] It should be noted that the target data packet information may include the data volume of data packets received or sent by each group in the network node at each time during the network sensing time period.

[0126] Step S202: Determine the data packet variance based on the target data packet information.

[0127] It should be noted that determining the data packet variance based on the target data packet information can be the variance of the data volume of each packet received or sent by each group in the network node at each moment within the network sensing time period, i.e., σ. DB Refer to σ in each group in the above embodiments. DB The calculation method.

[0128] Step S203: Determine the weights of network state outliers and vulnerabilities based on the data packet variance.

[0129] It should be noted that the determination of network state outlier weights and vulnerability weights based on the packet variance can be the network state outlier weights (wight) of the network state outlier (AW). AE =min{1-α,max{0.75,avg(σ DB Vulnerability value SK's vulnerability weight (wight)SK = 1 - wight AW wherein a is a very small number, preset, in order to prevent the weight wight SK of the fragile value SK from being 0, avg (σ DB ) is the average of the packet variance of all groups in the network node.

[0130] Step S204: When the service type is comprehensive, determining target attack data according to the network awareness data.

[0131] It should be noted that the target attack data can include the attack start time and attack duration of each attack suffered by the network node.

[0132] Step S205: Determining network state anomaly value weight and fragile value weight according to the target attack data.

[0133] It should be noted that the determining network state anomaly value weight and fragile value weight according to the target attack data can be that the network state anomaly value weight of the network state anomaly value AW is the fragile value weight wight SK of the fragile value SK is AW .

[0134] wherein β is a very small number, preset, in order to prevent the weight wight SK of the fragile value SK from being 0.5, so that wight AW and wight SK are both 0.5. is the average of the ratio of the current distance to the last attack to the average duration of all attacks. Wherein t is the current time, t a is the start time of the last attack with the same characteristics as attack a, is the average time difference between adjacent two attacks with the same characteristics as attack a.

[0135] The embodiment determines target packet information according to the network awareness data when the service type is traffic type; determines packet variance according to the target packet information; determines network state anomaly value weight and fragile value weight according to the packet variance; determines target attack data according to the network awareness data when the service type is comprehensive; and determines network state anomaly value weight and fragile value weight according to the target attack data. When the network situation awareness is performed, the embodiment also considers the current service type of the network, adjusts the weight of the network state anomaly value and the fragile value according to the service type, ensures the fitting of the network situation awareness result to the current network, and further ensures the accuracy of the network situation awareness.

[0136] In addition, the embodiment of the present application further provides a storage medium, wherein the storage medium stores a network security situation awareness program, and the network security situation awareness program is executed by a processor to realize the steps of the network security situation awareness method.

[0137] In addition, the embodiment of the present application further provides a computer program product, comprising a network security situation awareness program, and the network security situation awareness program is executed by a processor to realize the steps of the network security situation awareness method.

[0138] The computer program product of the present application has the same implementation as the network security situation awareness method, and thus will not be repeated here.

[0139] Reference Figure 5 , Figure 5 is a structural block diagram of the first embodiment of the network security situation awareness device of the present application.

[0140] As shown in Figure 5 , the network security situation awareness device provided by the embodiment of the present application comprises:

[0141] a service type determination module 10, configured to determine a service type of a network to be sensed according to network sensing data of each node in the network to be sensed;

[0142] a weight determination module 20, configured to determine a network state abnormal value weight and a vulnerability value weight according to the service type and the network sensing data;

[0143] a network security situation awareness module 30, configured to determine a network state abnormal value and a vulnerability value based on the network sensing data, and determine a network security situation awareness result of the network to be sensed according to the network state abnormal value, the vulnerability value, the network state abnormal value weight and the vulnerability value weight.

[0144] The embodiment determines a service type of the network to be perceived according to network perception data of each node in the network to be perceived, determines a network state abnormal value weight and a vulnerability value weight according to the service type and the network perception data, determines a network state abnormal value and a vulnerability value based on the network perception data, and determines a network security situation awareness result of the network to be perceived according to the network state abnormal value, the vulnerability value, the network state abnormal value weight and the vulnerability value weight. Since the embodiment determines the network state abnormal value weight and the vulnerability value weight according to the service type of the network to be perceived, and then determines the network security situation awareness result of the network to be perceived in combination with the network state abnormal value and the vulnerability value, compared with the existing network security defense mode of passively defending against external network intrusion through a firewall, the above mode of the embodiment can perceive the network security situation trend in advance, so that the network security defense is changed from passive defense to active defense.

[0145] It should be noted that the above-described workflow is only illustrative and does not limit the protection scope of the present application. In actual application, a person skilled in the art can select part or all of the above-described workflow to achieve the purpose of the embodiment according to actual needs, which is not limited herein.

[0146] In addition, technical details not described in detail in the embodiment can be referred to the network security situation awareness method provided by any embodiment of the present application, which will not be described herein.

[0147] Based on the first embodiment of the network security situation awareness device, the second embodiment of the network security situation awareness device is provided.

[0148] In the embodiment, the network security situation awareness module 30 is further configured to group the network perception data to obtain a grouping result.

[0149] The network security situation awareness module 30 is further configured to determine data packet data of each target group in the grouping result, and determine a network state abnormal value according to the data packet data.

[0150] The network security situation awareness module 30 is further configured to determine attack data of each target group in the grouping result, determine a grouping vulnerability value of the target group according to the attack data, and determine a vulnerability value according to the grouping vulnerability value.

[0151] Further, the network security situation awareness module 30 is further configured to preliminarily group the network perception data according to a preset IP address coding rule to obtain a preliminary grouping result.

[0152] The network security situation awareness module 30 is further configured to determine a data packet number of each group in the preliminary grouping result.

[0153] The network security situation awareness module 30 is further configured to determine a reference group according to the data packet number.

[0154] split the to-be-split packets that meet the preset packet condition based on the packet quantity and the reference packet, to obtain a packet result.

[0155] Further, the network security situation awareness module 30 is further configured to determine packet data of each target packet in the packet result.

[0156] determine packet quantity information and device connection duration information according to the packet data;

[0157] obtain bandwidth information of a target node corresponding to the packet result;

[0158] determine a network state abnormal value according to the bandwidth information, the packet quantity information, the device connection duration information, and a packet quantity in the packet result.

[0159] Further, the network security situation awareness module 30 is further configured to determine attack data of each target packet in the packet result.

[0160] cluster the attack data according to attack features, to obtain a clustering result;

[0161] determine a packet vulnerability value of the target packet based on the clustering result and the attack data;

[0162] determine a vulnerability value according to the packet vulnerability value.

[0163] Further, the business type determination module 10 is further configured to determine a security data average value, a security data median, and a security data standard deviation of a to-be-aware network according to network awareness data of each node in the to-be-aware network.

[0164] determine whether a business type of the to-be-aware network is a data type according to the security data average value, the security data median, and the security data standard deviation.

[0165] when the business type of the to-be-aware network is not the data type, determine the business type of the to-be-aware network according to attack data, vulnerability data, and bandwidth data in the network awareness data.

[0166] Further, the weight determination module 20 is further configured to, when the business type is a traffic type, determine target packet information according to the network awareness data.

[0167] determine a packet variance according to the target packet information;

[0168] determine a network state abnormal value weight and a vulnerability value weight according to the packet variance;

[0169] When the service type is comprehensive, target attack data is determined according to the network awareness data;

[0170] A network state abnormal value weight and a vulnerability value weight are determined according to the target attack data.

[0171] Other embodiments or specific implementations of the network security situation awareness device of the present application can refer to the above-mentioned method embodiments, which will not be described here.

[0172] It should be noted that in this paper, the term "includes", "contains" or any other variant thereof is intended to cover non-exclusive inclusion, so that the process, method, article or system including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or includes elements inherent to such process, method, article or system. Without more limitations, the element defined by the statement "includes a" does not exclude the presence of another identical element in the process, method, article or system including the element.

[0173] The above-mentioned embodiment number of the present application is only for description, not representing the pros and cons of the embodiments.

[0174] Through the above description of the embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment method can be realized by means of software and necessary general hardware platform, of course, it can also be realized by hardware, but in many cases, the former is a better implementation. Based on such understanding, the technical solutions of the present application or the part that contributes to the prior art can be embodied in the form of software product, which is stored in a storage medium (such as read-only memory / random access memory, magnetic disk, optical disk), including a number of instructions to make a terminal device (which can be a mobile phone, computer, server, air conditioner or network device, etc.) execute the method described in each embodiment of the present application.

[0175] The above is only the preferred embodiment of the present application, and does not limit the patent scope of the present application, and any equivalent structure or equivalent process transformation, or direct or indirect application in other related technical fields, is also included in the patent protection scope of the present application.

Claims

1. A cyber security situation awareness method, characterized by, The network security situation awareness method comprises the following steps: determining the business type of the network to be perceived according to the network perception data of each node in the network to be perceived; determining the network state abnormal value weight and the vulnerability value weight according to the business type and the network perception data; determining the network security situation awareness result of the network to be perceived according to the network state abnormal value, the vulnerability value, the network state abnormal value weight and the vulnerability value weight based on the network perception data.

2. The cyber security situation awareness method of claim 1, wherein, The step of determining the network state abnormal value and the vulnerability value based on the network perception data comprises: grouping the network perception data to obtain a grouping result; determining the data packet data of each target group in the grouping result, and determining the network state abnormal value according to the data packet data; determining the attack data of each target group in the grouping result, determining the grouping vulnerability value of the target group according to the attack data, and determining the vulnerability value according to the grouping vulnerability value.

3. The cyber security situation awareness method of claim 2, wherein, The step of grouping the network perception data to obtain a grouping result comprises: preliminarily grouping the network perception data according to a preset IP address coding rule to obtain a preliminary grouping result; determining the number of data packets of each group in the preliminary grouping result; determining a reference group according to the number of data packets; splitting the to-be-split group meeting the preset grouping condition based on the number of data packets and the reference group to obtain a grouping result.

4. The cyber security situation awareness method of claim 2, wherein, The step of determining the data packet data of each target group in the grouping result, and determining the network state abnormal value according to the data packet data comprises: determining the data packet data of each target group in the grouping result; determining the data packet quantity information and the device connection time length information according to the data packet data; obtaining the bandwidth information of the target node corresponding to the grouping result; determining the network state abnormal value according to the bandwidth information, the data packet quantity information, the device connection time length information and the number of groups in the grouping result.

5. The cyber security situation awareness method of claim 2, wherein, The step of determining the attack data of each target group in the grouping result, determining the grouping vulnerability value of the target group according to the attack data, and determining the vulnerability value according to the grouping vulnerability value comprises: determining the attack data of each target group in the grouping result; clustering the attack data according to attack characteristics to obtain a clustering result; determining the grouping vulnerability value of the target group based on the clustering result and the attack data; determining the vulnerability value according to the grouping vulnerability value.

6. The cyber security situation awareness method of any one of claims 1-5, wherein, The step of determining the business type of the network to be perceived according to the network perception data of each node in the network to be perceived comprises: determining the security data average value, the security data median and the security data standard deviation corresponding to the network to be perceived according to the network perception data of each node in the network to be perceived; judging whether the business type of the network to be perceived is data type according to the security data average value, the security data median and the security data standard deviation. When the service type of the network to be perceived is not the data type, the service type of the network to be perceived is determined according to attack data, vulnerability data and bandwidth data in the network perception data.

7. A cyber-security situation awareness apparatus, characterized by, The network security situation perception device comprises: a service type determination module configured to determine the service type of the network to be perceived according to network perception data of each node in the network to be perceived; a weight determination module configured to determine a network state abnormal value weight and a vulnerability value weight according to the service type and the network perception data; a network security situation perception module configured to determine a network state abnormal value and a vulnerability value based on the network perception data, and determine a network security situation perception result of the network to be perceived according to the network state abnormal value, the vulnerability value, the network state abnormal value weight and the vulnerability value weight.

8. A cyber-security situation awareness device, characterized by, The device comprises a memory, a processor and a network security situation perception program stored on the memory and executable on the processor, and the network security situation perception program is configured to implement the steps of the network security situation perception method according to any one of claims 1 to 6.

9. A storage medium, characterized by The storage medium stores a network security situation perception program, and the network security situation perception program is executed by the processor to implement the steps of the network security situation perception method according to any one of claims 1 to 6.

10. A computer program product, characterised in that, The computer program product comprises a network security situation perception program, and the network security situation perception program is executed by the processor to implement the steps of the network security situation perception method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Power grid security situation awareness platform architecture

    CN112651006A

  • Situation awareness network vulnerability defense method, device and system

    CN114189360A