A method and system for constructing a network security system

The network security system uses big data to predict and coordinate defenses across layers, effectively mitigating attacks through coordinated security measures and real-time monitoring, enhancing overall network resilience.

CN118890208BActive Publication Date: 2025-07-15ANYU (GUANGZHOU) INFORMATION TECHNOLOGY CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411176604.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-26
Publication Date
2025-07-15
Estimated Expiration
2044-08-26

AI Technical Summary

Technical Problem

The existing single network security defense measures cannot effectively deal with malicious attacks under the rapid rise of current network technology, and network security is insufficient.

Method used

Build a multi-layer security defense system, determine the predictions of each network level to be attacked through big data analysis, set security protection measures at the network layer, host layer and application layer respectively, and monitor and prevent and intercept in the multi-layer defense system to achieve the coordinated work of multi-layer defense measures.

Benefits of technology

Significantly improve the security of network systems, reduce the risk of being attacked, and realize intelligent defense and real-time monitoring of network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118890208B_ABST
    Figure CN118890208B_ABST
Patent Text Reader

Abstract

The present invention provides a method and system for constructing a network security system. The method includes: determining, based on big data, the predicted attacks corresponding to each network layer of the current network; respectively setting corresponding security protection measures at the network layer, host layer, and application layer according to the predicted attacks to construct a multi-layer security defense system; monitoring the current network based on the multi-layer defense system, and when the current network is attacked, controlling the multi-layer defense system to perform protection interception and attack traceability. The present invention constructs and generates a multi-layer security defense system with collaborative defense among multiple network layers, which can significantly improve the security of the network system and reduce the risk of being attacked.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly relates to a method and system for constructing a network security system. Background Art

[0002] With the rapid development of global informatization, the whole world is rapidly integrating, and a large number of constructed information systems have become critical infrastructures. Many enterprises, organizations, government departments and institutions are building and developing their own networks and connecting them to fully share and utilize the information and resources of the network. The network has become a powerful driving force for social and economic development and its status is becoming increasingly important. With the continuous development and progress of computer technology and network information technology in practical applications, the requirements for computer network security have also increased accordingly. A single network security defense can no longer cope with the malicious attacks under the rapid rise of current network technology. Therefore, the present invention proposes a method and system for constructing a network security system. Summary of the Invention

[0003] The present invention provides a method and system for constructing a network security system, which is used to construct and generate a multi-layer security defense system for collaborative defense between multiple network levels, realize the collaborative work of various defense measures at multiple network levels, can significantly improve the security of the network system, and reduce the risk of being attacked.

[0004] The present invention provides a method for constructing a network security system, including:

[0005] Based on big data, determine the predicted attacks corresponding to each network level of the current network;

[0006] According to the predicted attacks, set corresponding security protection measures in the network layer, host layer and application layer respectively to construct a multi-layer security defense system;

[0007] Monitor the current network based on the multi-layer defense system. When the current network is attacked, control the multi-layer defense system to perform protection interception and attack traceability.

[0008] Preferably, in a method for constructing a network security system, it is characterized in that, based on big data, determining the predicted attacks corresponding to each network level of the current network includes:

[0009] Based on big data, obtain a large amount of malicious attack records, extract malicious attack data features from each malicious attack record to obtain attack data features;

[0010] Classify based on the malicious attack location to obtain the attack data feature sets corresponding to each network level, and perform feature clustering on each attacked data feature set respectively;

[0011] Based on the clustering results, determine the attack data characteristics corresponding to each network layer. Based on the characteristics of the attack data sources and in combination with the preset characteristics corresponding to various attack means, determine the predicted attacks corresponding to different network layers.

[0012] Preferably, in a method for constructing a network security system, according to the predicted attacks, set corresponding security protection measures at the network layer, host layer, and application layer respectively, and construct a multi-layer security defense system, including:

[0013] Match security protection measures based on the predicted attacks corresponding to each network layer, and determine the matching security protection measures corresponding to each network layer;

[0014] Based on the matching security protection measures, deploy security protection measures at each network layer respectively to obtain a multi-layer security defense system.

[0015] Preferably, in a method for constructing a network security system, match security protection measures based on the predicted attacks corresponding to each network layer, and determine the matching security protection measures corresponding to each network layer, including:

[0016] Obtain the attacked data corresponding to the attack means that can be used for each network layer, and based on the first association relationship between various attacked data, determine the second association relationship between each predicted attack;

[0017] And synchronously obtain the attack frequencies of each predicted attack in networks with different network characteristics, and calculate the attack probabilities of each predicted attack in different local area networks;

[0018] Among them, the network characteristics include the topological structure of the attack network and the application field of the attack network;

[0019] Based on the network characteristics of the current network and in combination with the attack probability, determine the highly probable attacks and low-probability attacks corresponding to each network layer of the current network;

[0020] Based on the first association relationship, the second association relationship, and the attack probability, determine the first main attacked data and secondary attacked data of the highly probable attacks;

[0021] Screen in the preset defense library according to the first main attacked data and secondary attacked data, and respectively obtain the first candidate security protection measures corresponding to the first main attacked data and the second candidate security protection measures corresponding to the secondary attacked data;

[0022] According to the mutual exclusion relationship in operation between the first candidate security protection measures and the second candidate security protection measures, perform paired screening to obtain the best combined security protection measures corresponding to the highly probable attacks of each network layer of the current network;

[0023] Based on the first association relationship and the second association relationship, determine the second main attacked data of the low-probability attack, screen in the preset defense library according to the second main attacked data, and obtain multiple third candidate security protection measures respectively. Based on the optimal combined security protection measures and combining the mutual exclusion relationship of the operations between different protection measures, obtain the optimal third candidate security protection measure corresponding to the current network layer;

[0024] Based on the optimal third candidate security protection measure and the optimal first candidate security protection measure and the optimal second candidate security protection measure included in the optimal combined security protection measures, respectively obtain the matching security protection measures corresponding to the current network level.

[0025] Preferably, in a method for constructing a network security system, based on the matching security protection measures, deploy security protection measures at each network level respectively, specifically including:

[0026] Deploy illegal intrusion recognition and interception devices at the network layer;

[0027] Deploy security protection devices at the host layer;

[0028] Defensively reinforce application programs and data at the application layer.

[0029] Preferably, in a method for constructing a network security system, before deploying security protection measures at each network level respectively based on the matching security protection measures, it further includes:

[0030] Obtain the application field of the current network, and based on the application field of the current network, determine the transmission data characteristics of the current network;

[0031] Based on the transmission data characteristics, adjust the attack data capture characters of the matching security protection measures to obtain optimized matching security protection measures.

[0032] Preferably, in a method for constructing a network security system, after deploying security protection measures at each network level respectively based on the matching security protection measures, it further includes:

[0033] Based on the first association relationship, combine the attacked data corresponding to each predicted attack at each network level to obtain multiple multi-level attack data combinations;

[0034] And according to the correlation degree of the attack data between each multi-level attack data combination, respectively determine the attack correlation probability corresponding to each multi-level attack data combination;

[0035] Based on the attack correlation probability, determine the defense correlation relationships between different network attacks at different network levels. According to the defense correlation relationships, establish defense correlation strengthening links between the various network levels of the multi-layer security defense system.

[0036] Preferably, in a method for constructing a network security system, monitor the current network based on a multi-layer defense system. When the current network is attacked, control the multi-layer defense system to perform protection interception and attack traceability, including:

[0037] Perform real-time monitoring on each network level respectively based on the security defense measures corresponding to the respective network levels of the multi-layer defense system;

[0038] When it is detected that any network level is attacked, automatically activate the multi-layer defense system, mark the attack data with a message, and perform traceability tracking on the attack data based on the message mark to obtain a traceability result;

[0039] Generate a defense log for display and storage based on the real-time defense interception result and the traceability result of the multi-layer security defense system.

[0040] Preferably, in a method for constructing a network security system, when it is detected that any network level is attacked, it further includes:

[0041] When any network level is attacked, trigger a deployment based on the security defense of the current level, identify the current attack type, and based on the identification result, combine the first correlation relationship and the second correlation relationship to predict the attacked location of the associated network level and its corresponding defense correlation strengthening link after the defense of the current network level fails;

[0042] Generate a defense enhancement patch based on the data characteristics of the predicted attacked data of each network level corresponding to the defense correlation strengthening link, perform defense enhancement on the associated network level based on the defense enhancement patch, and automatically eliminate invalid defense enhancement patches and retain valid defense enhancement patches after the current attack is successfully intercepted.

[0043] The present invention provides a network security system construction system for implementing any one of the methods for constructing a network security system, including:

[0044] An intelligent speculation module for determining the predicted attacks suffered by the respective network levels of the current network based on big data;

[0045] A security system construction module for setting corresponding security protection measures at the network layer, host layer, and application layer respectively according to the predicted attacks suffered, and constructing a multi-layer security defense system;

[0046] A defense traceability module is used to monitor the current network based on a multi-layer defense system. When the current network is attacked, it controls the multi-layer defense system to perform protection interception and attack traceability.

[0047] Compared with the prior art, the present invention has at least the following beneficial effects:

[0048] First, based on big data, the present invention determines the predicted attacks corresponding to each network layer of the current network. Then, according to the predicted attacks, corresponding security protection measures are respectively set at the network layer, host layer, and application layer. At the network layer, by deploying devices such as firewalls and intrusion detection systems, network attacks can be effectively intercepted and identified. At the host layer, by strengthening system security configurations, installing antivirus software, etc., the security protection ability of the host can be improved; at the application layer, by implementing technologies such as access control and data encryption, the security of application programs and data can be protected. A multi-layer security defense system for collaborative defense between multiple network layers is constructed and generated, enabling the collaborative work of various defense measures at multiple network layers, which can significantly improve the security of the network system, reduce the risk of being attacked, and monitor the current network based on the multi-layer defense system. When the current network is attacked, it controls the multi-layer defense system to perform protection interception and attack traceability, realizing the intelligent defense of network security and ensuring the security of the operating network.

[0049] Other features and advantages of the present invention will be described in the following specification, and some of them will become obvious from the specification or be understood by implementing the present invention. The objectives and other advantages of the present invention can be achieved and obtained through the structures specifically pointed out in this application document.

[0050] The technical solutions of the present invention will be further described in detail below through the accompanying drawings and embodiments. Description of the Drawings

[0051] The drawings are used to provide a further understanding of the present invention, and constitute a part of the specification. They are used together with the embodiments of the present invention to explain the present invention, and do not constitute a limitation to the present invention. In the drawings:

[0052] Figure 1 It is a flowchart of a method for constructing a network security system in an embodiment of the present invention;

[0053] Figure 2 It is a flowchart of step 1 of a method for constructing a network security system in an embodiment of the present invention;

[0054] Figure 3 It is a flowchart of step 2 of a method for constructing a network security system in an embodiment of the present invention;

[0055] Figure 4It is a flowchart of step 3 of a method for constructing a network security system in an embodiment of the present invention;

[0056] Figure 5 It is a structural diagram of a network security system construction system in an embodiment of the present invention. Specific embodiments

[0057] The following describes the preferred embodiments of the present invention with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.

[0058] Embodiment 1:

[0059] The present invention provides a method for constructing a network security system, as Figure 1 shown, including:

[0060] Step 1: Based on big data, determine the predicted attacks corresponding to each network layer of the current network;

[0061] Step 2: According to the predicted attacks, set corresponding security protection measures in the network layer, host layer, and application layer respectively to construct a multi-layer security defense system;

[0062] Step 3: Monitor the current network based on the multi-layer defense system. When the current network is attacked, control the multi-layer defense system to perform protection interception and attack traceability.

[0063] In this embodiment, the network layers include the network layer, host layer, and application layer.

[0064] In this embodiment, the predicted attacks refer to the types of network attack viruses or malicious intrusions that each network layer may be subject to.

[0065] The beneficial effects of the above technical solutions: The present invention first determines the predicted attacks corresponding to each network layer of the current network based on big data, and then sets corresponding security protection measures in the network layer, host layer, and application layer respectively according to the predicted attacks. In the network layer, by deploying devices such as firewalls and intrusion detection systems, network attacks can be effectively intercepted and identified. In the host layer, by strengthening system security configurations and installing anti-virus software, etc., the security protection ability of the host can be improved; in the application layer, by implementing technologies such as access control and data encryption, the security of application programs and data can be protected, and a multi-layer security defense system for collaborative defense between multiple network layers is constructed and generated, realizing the collaborative work of multiple defense measures of multiple network layers, which can significantly improve the security of the network system, reduce the risk of being attacked, and monitor the current network based on the multi-layer defense system. When the current network is attacked, control the multi-layer defense system to perform protection interception and attack traceability, realizing the intelligent defense of network security and ensuring the security of the running network.

[0066] Example 2:

[0067] Based on Example 1, Step 1: Based on big data, determine the predicted attacks corresponding to each network layer of the current network, as Figure 2 shown, including:

[0068] Step 101: Based on big data, obtain a large number of malicious attack records, extract malicious attack data features from each malicious attack record, and obtain attack data features;

[0069] Step 102: Classify based on the malicious attack location to obtain the attack data feature sets corresponding to each network layer, and perform feature clustering on each attacked data feature set respectively;

[0070] Step 103: Based on the clustering results, determine the attack data features corresponding to each network layer, and based on the attack data source features, combine the preset features corresponding to various attack means to determine the predicted attacks corresponding to different network layers.

[0071] In this embodiment, the attack data feature refers to the data feature of the data that attacks the network.

[0072] In this embodiment, the preset feature refers to the data features corresponding to various viruses or intrusion means that are pre-stored in the database.

[0073] Beneficial effects of the above technical solution: Based on big data, the present invention obtains a large number of malicious attack records, extracts malicious attack data features from each malicious attack record, and obtains attack data features; classifies based on the malicious attack location to obtain the attack data feature sets corresponding to each network layer, and performs feature clustering on each attacked data feature set respectively; based on the clustering results, determines the attack data features corresponding to each network layer, and based on the attack data source features, combines the preset features corresponding to various attack means to determine the predicted attacks corresponding to different network layers, and respectively determines the attack means corresponding to each network layer, providing a basis for determining the defense measures for each network layer, which is beneficial to improving the accuracy of the selection of security defense measures corresponding to each network layer and the defense ability of the finally constructed multi-layer security defense system.

[0074] Example 3:

[0075] Based on Example 1, Step 2: According to the predicted attacks, set corresponding security protection measures in the network layer, host layer, and application layer respectively to construct a multi-layer security defense system, as Figure 3 shown, including:

[0076] Step 201: Based on the predicted attacks corresponding to each network layer, match security protection measures, and determine the corresponding matched security protection measures for each network layer;

[0077] Step 202: Based on the matched security protection measures, deploy security protection measures at each network layer respectively to obtain a multi-layer security defense system;

[0078] Among them, based on the matched security protection measures, deploying security protection measures at each network layer respectively specifically includes:

[0079] Deploy illegal intrusion recognition and interception devices at the network layer;

[0080] Deploy security protection devices at the host layer;

[0081] Defensively reinforce applications and data at the application layer.

[0082] Beneficial effects of the above technical solution: Different network defense measures are respectively deployed at different network layers, constructing and generating a multi-layer security defense system with collaborative defense among multiple network layers, realizing the collaborative work of various defense measures at multiple network layers, which can significantly improve the security of the network system and reduce the risk of being attacked.

[0083] Example 4:

[0084] Based on the predicted attacks corresponding to each network layer in Example 3, match security protection measures, and determine the corresponding matched security protection measures for each network layer, including:

[0085] Obtain the attacked data corresponding to the attack means corresponding to each network layer, and based on the first association relationship between various attacked data, determine the second association relationship between each predicted attack;

[0086] And synchronously obtain the attack frequencies of each predicted attack in networks with different network characteristics, and calculate the attack probabilities of each predicted attack in different local area networks;

[0087] Among them, network characteristics include the topological structure of the attack network and the application field of the attack network;

[0088] Based on the network characteristics of the current network, combined with the attack probability, determine the highly probable attacks and low-probability attacks corresponding to each network layer of the current network;

[0089] Based on the first association relationship, the second association relationship, and the attack probability, determine the first main attacked data and secondary attacked data of the highly probable attacks;

[0090] Filter according to the first main attacked data and the secondary attacked data in the preset defense library, and respectively obtain the first candidate security protection measures corresponding to the first main attacked data and the second candidate security protection measures corresponding to the secondary attacked data;

[0091] Perform paired screening according to the running mutual exclusion relationship between the first candidate security protection measures and the second candidate security protection measures, and obtain the optimal combined security protection measures corresponding to the probable attacks at each network layer of the current network;

[0092] Based on the first correlation relationship and the second correlation relationship, determine the second main attacked data of the low-probability attack, filter in the preset defense library according to the second main attacked data, and respectively obtain multiple third candidate security protection measures. Based on the optimal combined security protection measures and in combination with the running mutual exclusion relationship between different protection measures, obtain the optimal third candidate security protection measures corresponding to the current network layer;

[0093] Based on the optimal third candidate security protection measures and the optimal first candidate security protection measures and the optimal second candidate security protection measures included in the optimal combined security protection measures, respectively obtain the matching security protection measures corresponding to the current network layer.

[0094] In this embodiment, the first candidate security protection measures, the second candidate security protection measures, and the third candidate security protection measures may be the same or different.

[0095] In this embodiment, the first correlation relationship refers to the correlation relationship between the attacked data of different network layers. The second correlation relationship refers to both the correlation relationship between each predicted attack of different network layers and the correlation relationship between each predicted attack of the same network layer.

[0096] In this embodiment, based on the network characteristics of the current network and in combination with the attack probability, determine the probable attacks and low-probability attacks corresponding to each network layer of the current network, specifically including:

[0097] According to the network characteristics of the current network, determine the local area network type corresponding to the current network, and filter based on the attack probability of each predicted attack corresponding to the high local area network type. The predicted attack with an attack probability greater than the preset value is a probable attack;

[0098] Otherwise, it is a low-probability attack.

[0099] In this embodiment, the first main attacked data refers to a certain data or a certain segment of data that is easily attacked (the attack probability is greater than or equal to 50%) in the probable attack. The secondary attacked data refers to other predicted attacked data except the first main attacked data in the probable attack.

[0100] In this embodiment, the running mutex relationship means that when the same type of security defense program operates, it cannot be compatible and cannot be installed or work simultaneously, which will result in software mutual detection and killing or program chaos. For example, two anti-virus software cannot run simultaneously.

[0101] In this embodiment, the second main attacked data refers to a certain data or a certain section of data that is easily attacked (the attack probability is greater than or equal to 50%) in a low-probability attack.

[0102] In this embodiment, the preset defense library refers to a database that stores various security defense measures applicable to different network levels.

[0103] The beneficial effects of the above technical solutions: The present invention first classifies multiple predicted attacks that may be suffered at each network level of the network to obtain high-probability attacks and low-probability attacks, then screens in the preset defense library according to the first main attacked data and the secondary attacked data of the high-probability attacks respectively, and then performs paired screening according to the screening results in combination with the running mutex relationship to obtain the best combined security protection measures corresponding to the high-probability attacks at each network level of the current network. Then, it screens in the preset defense library according to the second main attacked data corresponding to the low-probability attacks, and based on the best combined security protection measures, combines the running mutex relationship between different protection measures to obtain the best third candidate security protection measures corresponding to the current network layer. Finally, based on the best third candidate security protection measures and the best first candidate security protection measures and the best second candidate security protection measures included in the best combined security protection measures, the matching security protection measures corresponding to the current network layer are respectively obtained, realizing the defense against most of the attacks that the current network may suffer.

[0104] Embodiment 5:

[0105] On the basis of Embodiment 4, before deploying the security protection measures at each network level respectively based on the matching security protection measures, it further includes:

[0106] Obtain the application field of the current network, and based on the application field of the current network, determine the transmission data characteristics of the current network;

[0107] Based on the transmission data characteristics, adjust the attack data capture characters of the matching security protection measures to obtain optimized matching security protection measures.

[0108] Advantages of the above technical solution: Before deploying security protection measures at each network layer based on matching security protection measures, the present invention obtains the application field of the current network, determines the transmission data characteristics of the current network based on the application field of the current network; based on the transmission data characteristics, adjusts the attack data capture characters of the matching security protection measures to obtain an optimized matching security protection measure, and associates the security protection measures required with the data transmission characteristics of the current network, realizing the adaptive optimization in the process of deploying security defense measures, making the adaptability of the constructed and generated security protection system to the current network conducive to improving the security defense effect of the multi-layer security protection network.

[0109] Embodiment 6:

[0110] On the basis of Embodiment 4, after deploying security protection measures at each network layer based on matching security protection measures, it further includes:

[0111] Based on the first association relationship, combine the attacked data corresponding to each predicted attack at each network layer to obtain multiple multi-level attack data combinations;

[0112] And determine the attack association probability corresponding to each multi-level attack data combination according to the association degree of the attack data between each multi-level attack data combination;

[0113] Based on the attack association probability, determine the defense association relationship between different network attacks at different network layers, and establish a defense association strengthening link between each network layer of the multi-layer security defense system according to the defense association relationship.

[0114] In this embodiment, the attacked data refers to the data attacked inside the network.

[0115] In this embodiment, the attack association probability refers to the association degree of being attacked between the data of each network layer, that is, when a certain piece or section of data in any one network layer is attacked, the probability that a certain piece or section of data in the data of other network layers is used as the attack target corresponding to the network layer.

[0116] In this embodiment, the multi-level attack data combination refers to the combination of the attacked data at each layer during the process of network intrusion layer by layer. Due to the difference in the attacked data of the previous network layer, the attacked data of the next network layer of the current network layer may be different.

[0117] In this embodiment, the defense association strengthening link means that when the data at a certain network level is attacked, the data at other network levels that have a defense association with the current data needs to be key-defended to avoid data loss or data tampering caused by the failure of the current network defense. A defense link is formed between the attacked data and the data at other network levels that have a defense association with it. If the data at any network level is attacked, the data at other network levels will also strengthen their defenses.

[0118] Advantages of the above technical solution: Based on the first association relationship, the present invention combines the attacked data corresponding to each predicted attack at each network level to obtain multiple multi-level attack data combinations; and determines the attack association probability corresponding to each multi-level attack data combination according to the correlation degree of the attack data between each multi-level attack data combination; based on the attack association probability, determines the defense association relationship between different network attacks at different network levels, and according to the defense association relationship, establishes a defense association strengthening link between each network level of the multi-level security defense system, realizes the association of each network defense layer while forming each independent network defense layer, and at the same time provides a basis for the prediction of attack defense, effectively improving the intelligence and defense ability of the security defense of the multi-level security defense system.

[0119] Embodiment 7:

[0120] Based on Embodiment 1, Step 3: Monitor the current network based on the multi-level defense system. When the current network is attacked, control the multi-level defense system to perform protection interception and attack traceability, as Figure 4 shown, including:

[0121] Step 301: Real-time monitor each network level based on the security defense measures corresponding to each network level of the multi-level defense system;

[0122] Step 302: When it is detected that any network level is attacked, automatically activate the multi-level defense system, mark the attack data with a message, and trace and track the attack data based on the message mark to obtain a traceability result;

[0123] Step 303: Generate a defense log based on the real-time defense interception result and the traceability result of the multi-level security defense system for display and storage.

[0124] Advantages of the above technical solution: Based on the security defense measures corresponding to each network layer of the multi-layer defense system, the present invention monitors each network layer in real time, achieving independent defense and attack monitoring for each network layer; when it is detected that any network layer is under attack, the multi-layer defense system is automatically activated, and the attack data is marked with a message. Based on the message mark, the attack data is traced and the tracing result is obtained; based on the real-time defense interception result and the tracing result of the multi-layer security defense system, a defense log is generated for display and storage, realizing the function of automatically chasing hackers, realizing intelligent defense of network security and ensuring the security of the operating network.

[0125] Embodiment 8:

[0126] Based on Embodiment 7, when it is detected that any network layer is under attack, it further includes:

[0127] When any network layer is under attack, based on the security defense trigger deployment of the current layer, the current attack type is identified. Based on the identification result, combined with the first association relationship and the second association relationship, after predicting the failure of the current network layer defense, the attacked positions of the associated network layers and their corresponding defense association strengthening links are predicted;

[0128] Based on the data characteristics of the predicted attacked data of each network layer corresponding to the defense association strengthening link, a defense strengthening patch is generated. Based on the defense strengthening patch, the associated network layers are strengthened in defense, and after the current attack is successfully intercepted, the invalid defense strengthening patches are automatically eliminated and the valid defense strengthening patches are retained.

[0129] In this embodiment, the associated network layer refers to other network layers except the current network layer.

[0130] In this embodiment, an invalid defense strengthening patch refers to a defense strengthening patch that does not run or fails to successfully intercept an attack after running during the actual attack defense process, and a valid defense strengthening patch refers to a defense strengthening patch that runs and successfully intercepts an attack after running during the actual attack defense process.

[0131] Beneficial effects of the above technical solution: When it is detected that the current network is under attack, a deployment is triggered based on the security defense at the current level to identify the current attack type. Based on the identification result, in combination with the first association relationship and the second association relationship, after predicting the failure of the defense at the current network level, the attacked locations of the associated network levels and their corresponding defense association strengthening links are predicted. Then, based on the data characteristics of the predicted attacked data of each network level corresponding to the defense association strengthening link, a defense enhancement patch is generated. Based on the defense enhancement patch, the associated network levels are enhanced in defense, realizing multi-level prediction of network attacks, automatically controlling other network levels to enhance their defenses according to the defense association strengthening link, specifically enhancing the attack defense capabilities of the data of other network levels, and completing the automatic repair of the deployment vulnerabilities of the security defense measures of the associated network levels to avoid data loss or data tampering caused by the failure of the current network defense, effectively improving network security.

[0132] Embodiment 9:

[0133] The present invention provides a network security system construction system for any one of the described network security system construction methods, as Figure 5 shown, including:

[0134] An intelligent speculation module for determining the predicted attacks corresponding to each network level of the current network based on big data;

[0135] A security system construction module for setting corresponding security protection measures in the network layer, host layer, and application layer respectively according to the predicted attacks, and constructing a multi-layer security defense system;

[0136] A defense traceability module for monitoring the current network based on the multi-layer defense system, and when the current network is attacked, controlling the multi-layer defense system to perform protection interception and attack traceability.

[0137] Advantages of the above technical solution: First, based on big data, the present invention determines that each network layer of the current network is predicted to be attacked. Then, according to the predicted attacks, corresponding security protection measures are respectively set at the network layer, host layer, and application layer. At the network layer, by deploying devices such as firewalls and intrusion detection systems, network attacks can be effectively intercepted and identified. At the host layer, by strengthening system security configurations, installing antivirus software, etc., the security protection ability of the host can be improved. At the application layer, by implementing technologies such as access control and data encryption, the security of application programs and data can be protected. A multi-layer security defense system for collaborative defense between multiple network layers is constructed and generated, enabling the collaborative work of various defense measures at multiple network layers, which can significantly improve the security of the network system, reduce the risk of being attacked, and monitor the current network based on the multi-layer defense system. When the current network is attacked, the multi-layer defense system is controlled to perform protection interception and attack traceability, realizing intelligent defense of network security and ensuring the security of the operating network.

[0138] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these changes and modifications.

Claims

1. A method for constructing a network security system, characterized in that, Including: Based on big data, determine the predicted attacks corresponding to each network layer of the current network; According to the predicted attacks, set corresponding security protection measures at the network layer, host layer, and application layer respectively to build a multi-layer security defense system; Monitor the current network based on the multi-layer defense system. When the current network is attacked, control the multi-layer defense system to perform protection interception and attack traceability; Among them, according to the predicted attacks, setting corresponding security protection measures at the network layer, host layer, and application layer respectively includes: Obtain the attacked data corresponding to the attack means that can be used for each network layer. Based on the first correlation relationship between various attacked data, determine the second correlation relationship between each predicted attack; And synchronously obtain the attack frequencies of each predicted attack in networks with different network characteristics, and calculate the attack probabilities of each predicted attack in different local area networks Among them, network characteristics include the topological structure of the attacking network and the application field of the attacking network; Based on the network characteristics of the current network and in combination with the attack probability, determine the high-probability attacks and low-probability attacks corresponding to each network layer of the current network; Based on the first correlation relationship, the second correlation relationship, and the attack probability, determine the first main attacked data and secondary attacked data of the high-probability attacks; Screen in the preset defense library according to the first main attacked data and secondary attacked data to obtain the first candidate security protection measures corresponding to the first main attacked data and the second candidate security protection measures corresponding to the secondary attacked data respectively; Perform paired screening according to the running mutual exclusion relationship between the first candidate security protection measures and the second candidate security protection measures to obtain the optimal combined security protection measures corresponding to the high-probability attacks of each network layer of the current network; Based on the first correlation relationship and the second correlation relationship, determine the second main attacked data of the low-probability attacks. Screen in the preset defense library according to the second main attacked data to obtain multiple third candidate security protection measures respectively. Based on the optimal combined security protection measures and in combination with the running mutual exclusion relationship between different protection measures, obtain the optimal third candidate security protection measures corresponding to the current network layer; Based on the optimal third candidate security protection measures and the optimal first candidate security protection measures and optimal second candidate security protection measures included in the optimal combined security protection measures, obtain the matching security protection measures corresponding to the current network layer respectively.

2. The method for constructing a network security system according to claim 1, characterized in that, Based on big data, determining the predicted attacks corresponding to each network layer of the current network includes: Based on big data, obtain a large number of malicious attack records, extract malicious attack data features for each malicious attack record to obtain attack data features; Classify based on the malicious attack location to obtain the attack data feature sets corresponding to each network layer, and perform feature clustering on each attacked data feature set respectively; Based on the clustering results, determine the attack data features corresponding to each network layer. Based on the attack data source features and in combination with the preset features corresponding to various attack means, determine the predicted attacks corresponding to different network layers.

3. A method for constructing a network security system according to claim 1, characterized in that, In the event of a predicted attack, corresponding security protection measures are set at the network layer, host layer, and application layer respectively to build a multi-layer security defense system, including: Based on the predicted attacks corresponding to each network level, match the security protection measures to determine the corresponding matching security protection measures for each network level; Based on the matching security protection measures, deploy the security protection measures at each network level respectively to obtain a multi-layer security defense system.

4. A method for constructing a network security system according to claim 3, characterized in that, Based on the matching security protection measures, deploy the security protection measures at each network level respectively, specifically including: Deploy illegal intrusion identification and interception devices at the network layer; Deploy security protection devices at the host layer; Defensively reinforce the application programs and data at the application layer.

5. A method for constructing a network security system according to claim 1, characterized in that, Before deploying the security protection measures at each network level respectively based on the matching security protection measures, it also includes: Obtain the application field of the current network, and based on the application field of the current network, determine the transmission data characteristics of the current network; Based on the transmission data characteristics, adjust the attack data capture characters of the matching security protection measures to obtain optimized matching security protection measures.

6. A method for constructing a network security system according to claim 1, characterized in that, After deploying the security protection measures at each network level respectively based on the matching security protection measures, it also includes: Based on the first association relationship, combine the attacked data corresponding to each predicted attack at each network level to obtain multiple multi-level attack data combinations; And based on the correlation degree of the attack data between each multi-level attack data combination, determine the corresponding attack correlation probability for each multi-level attack data combination; Based on the attack correlation probability, determine the defense association relationship between different network attacks at different network levels, and according to the defense association relationship, establish a defense association strengthening link between each network level of the multi-layer security defense system.

7. A method for constructing a network security system according to claim 1, characterized in that Monitor the current network based on the multi-layer defense system. When the current network is attacked, control the multi-layer defense system to perform protection interception and attack traceability, including: Perform real-time monitoring on each network level respectively based on the security protection measures corresponding to each network level of the multi-layer defense system; When it is detected that any network level is attacked, automatically activate the multi-layer defense system, mark the attack data with a message, and trace and track the attack data based on the message mark to obtain a traceability result; Generate a defense log based on the real-time defense interception result and traceability result of the multi-layer security defense system for display and storage.

8. A method for constructing a network security system according to claim 7, characterized in that, When it is detected that any network level is attacked, it also includes: When any network level is attacked, trigger a deployment based on the security defense of the current level, identify the current attack type, and based on the identification result, combine the first association relationship and the second association relationship to predict the attacked location of the associated network level and its corresponding defense association strengthening link after the defense of the current network level fails; Generate a defense enhancement patch based on the data characteristics of the predicted attacked data of each network level corresponding to the defense association strengthening link, enhance the defense of the associated network level based on the defense enhancement patch, and automatically eliminate the invalid defense enhancement patches and retain the valid defense enhancement patches after the current attack is successfully intercepted.

9. A network security system construction system for implementing a network security system construction method according to any one of claims 1-8, characterized in that, Including: An intelligent speculation module, used to determine the predicted attacks corresponding to each network layer of the current network based on big data; A security system construction module, used to set corresponding security protection measures in the network layer, host layer, and application layer respectively according to the predicted attacks, and construct a multi-layer security defense system; A defense traceability module, used to monitor the current network based on the multi-layer defense system. When the current network is attacked, it controls the multi-layer defense system to perform protection interception and attack traceability.

Citation Information

Patent Citations

  • Power Internet of Things security defense method and system, storage medium and server

    CN114143348A