Emergency drill network topology processing method, device, computer equipment, storage medium and computer program product
By node division, update and disturbance processing of the network topology, a target emergency drill network topology diagram is generated, which solves the problem of low security in traditional emergency drill methods and improves the safety of drills.
Patent Information
- Application Number
- CN202411199443.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-29
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2044-08-29
AI Technical Summary
Traditional network topology emergency drills can easily lead to cyber attackers obtaining topology information and then launching precise attacks, resulting in lower security.
By obtaining the pending emergency drill network topology diagram, dividing nodes into two categories, updating the node set, determining the node selection probability and the number of nodes after disturbance, building an updated topology diagram, and disturbing the network segment and node information to generate a target emergency drill network topology diagram.
It improves the security of emergency drills for network topology and avoids the risks of information leakage and precise attacks under direct drill methods.
Smart Images

Figure CN119011411B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular, to a method, device, computer device, computer-readable storage medium, and computer program product for processing an emergency drill network topology. Background Art
[0002] Currently, for the emergency drill of the network topology, it is crucial to ensure the security of the network topology.
[0003] In the traditional technology, during the process of conducting an emergency drill on the network topology, a direct emergency drill method is generally adopted; however, this method is likely to cause network attackers to obtain relevant information of the network topology through the emergency drill and launch a precise attack on the network topology, thereby resulting in a low security level of the emergency drill of the network topology. Summary of the Invention
[0004] Based on this, in view of the above technical problems, it is necessary to provide an emergency drill network topology processing method, device, computer device, computer-readable storage medium, and computer program product that can improve the security of the emergency drill of the network topology.
[0005] In a first aspect, the present application provides an emergency drill network topology processing method, including:
[0006] Obtain an emergency drill network topology diagram to be processed;
[0007] Perform a partitioning process on the nodes in the emergency drill network topology diagram to be processed to obtain a first node set and a second node set; the first node set includes the first nodes in the nodes that are associated with a preset emergency drill script; the second node set includes second nodes, and the second nodes represent the nodes in the nodes except the first nodes;
[0008] Update the first node set and the second node set according to the target nodes in the second node set to obtain a first target node set and a second target node set;
[0009] Determine the number of perturbed nodes in each sub-emergency drill network topology diagram according to the number of nodes in each sub-emergency drill network topology diagram that belong to the second target node set;
[0010] Determine the selection probability of the nodes in each sub-emergency drill network topology diagram according to the number of nodes in each sub-emergency drill network topology diagram that belong to the second target node set and the set to which the nodes in each sub-emergency drill network topology diagram belong; the set to which the nodes belong is the first target node set or the second target node set;
[0011] Determine the super nodes in the to-be-processed emergency drill network topology diagram according to the selection probabilities of the nodes and the number of nodes after perturbation in each sub-emergency drill network topology diagram;
[0012] Construct an updated emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram according to the super nodes;
[0013] Perform perturbation processing on the network segments and node information in the updated emergency drill network topology diagram to obtain the target emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram.
[0014] In one embodiment, obtain the edges between every two nodes in the first node set, and the distances corresponding to the edges between every two nodes in the first node set;
[0015] For every two nodes in the first node set, screen out the edge with the smallest corresponding distance from the edges between every two nodes in the first node set as the target edge between every two nodes in the first node set;
[0016] Extract the nodes associated with the target edges from the second node set as the target nodes in the second node set.
[0017] In one embodiment, the step of determining the number of nodes after perturbation of each sub-emergency drill network topology diagram according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram of the to-be-processed emergency drill network topology diagram includes:
[0018] Determine the initial number of nodes of each sub-emergency drill network topology diagram according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram of the to-be-processed emergency drill network topology diagram;
[0019] Determine the number of nodes after perturbation of each sub-emergency drill network topology diagram according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram of the to-be-processed emergency drill network topology diagram and the initial number of nodes of each sub-emergency drill network topology diagram.
[0020] In one embodiment, the step of determining the selection probability of the nodes in each sub-emergency drill network topology diagram according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram and the set to which the nodes in each sub-emergency drill network topology diagram belong includes:
[0021] Determine the first privacy budget value of the nodes in each sub-emergency drill network topology diagram according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram;
[0022] Obtain the first global sensitivity of the nodes in each sub-emergency drill network topology diagram, and determine the selection probability of the nodes in each sub-emergency drill network topology diagram according to the first privacy budget value, the first global sensitivity and the set to which the nodes in each sub-emergency drill network topology diagram belong.
[0023] In one embodiment, the perturbing the network segment and node information in the updated emergency drill network topology diagram to obtain the target emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram includes:
[0024] Determine the second privacy budget value and the second global sensitivity corresponding to the network segments in the updated emergency drill network topology diagram, and determine the third privacy budget value and the third global sensitivity corresponding to the node information in the updated emergency drill network topology diagram;
[0025] Perturb the network segments in the updated emergency drill network topology diagram according to the second privacy budget value and the second global sensitivity to obtain processed network segments, and perturb the node information in the updated emergency drill network topology diagram according to the third privacy budget value and the third global sensitivity to obtain processed node information;
[0026] Construct the target emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram according to the processed network segments and the processed node information.
[0027] In one embodiment, before determining the number of perturbed nodes in each sub-emergency drill network topology diagram according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram of the to-be-processed emergency drill network topology diagram, it further includes:
[0028] Determine the network area to which each node in the to-be-processed emergency drill network topology diagram belongs;
[0029] Divide the to-be-processed emergency drill network topology diagram according to the network area to which each node belongs to obtain a plurality of the sub-emergency drill network topology diagrams.
[0030] In a second aspect, the present application further provides an emergency drill network topology processing device, including:
[0031] A network topology acquisition module, configured to acquire a to-be-processed emergency drill network topology diagram;
[0032] A node set partitioning module, configured to partition the nodes in the to-be-processed emergency drill network topology diagram to obtain a first node set and a second node set; the first node set includes first nodes in the nodes that are associated with a preset emergency drill script; the second node set includes second nodes, and the second nodes represent the nodes in the nodes except the first nodes;
[0033] A node set updating module, configured to update the first node set and the second node set according to the target nodes in the second node set to obtain a first target node set and a second target node set;
[0034] A node quantity determining module, configured to determine the quantity of nodes after perturbation of each sub-emergency drill network topology diagram in the to-be-processed emergency drill network topology diagram according to the quantity of nodes in each sub-emergency drill network topology diagram that belong to the second target node set;
[0035] A selection probability determining module, configured to determine the selection probability of the nodes in each sub-emergency drill network topology diagram according to the quantity of nodes in each sub-emergency drill network topology diagram that belong to the second target node set and the belonging sets of the nodes in each sub-emergency drill network topology diagram; the belonging set is the first target node set or the second target node set;
[0036] A super node determining module, configured to determine the super nodes in the to-be-processed emergency drill network topology diagram according to the selection probability and the quantity of nodes after perturbation of the nodes in each sub-emergency drill network topology diagram;
[0037] A network topology construction module, configured to construct an updated emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram according to the super nodes;
[0038] A network topology perturbation module, configured to perform perturbation processing on the network segments and node information in the updated emergency drill network topology diagram to obtain a target emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram.
[0039] In a third aspect, the present application further provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0040] Obtain a to-be-processed emergency drill network topology diagram;
[0041] Partition the nodes in the to-be-processed emergency drill network topology diagram to obtain a first node set and a second node set; the first node set includes the first nodes in the nodes that are associated with a preset emergency drill script; the second node set includes second nodes, where the second nodes represent the nodes in the nodes other than the first nodes.
[0042] Update the first node set and the second node set according to the target nodes in the second node set to obtain a first target node set and a second target node set.
[0043] Determine the number of perturbed nodes in each sub-emergency drill network topology diagram according to the number of nodes in each sub-emergency drill network topology diagram that belong to the second target node set.
[0044] Determine the selection probability of the nodes in each sub-emergency drill network topology diagram according to the number of nodes in each sub-emergency drill network topology diagram that belong to the second target node set and the set to which the nodes in each sub-emergency drill network topology diagram belong; the set is the first target node set or the second target node set.
[0045] Determine the super nodes in the to-be-processed emergency drill network topology diagram according to the selection probability and the number of perturbed nodes of the nodes in each sub-emergency drill network topology diagram.
[0046] Construct an updated emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram according to the super nodes.
[0047] Perform perturbation processing on the network segments and node information in the updated emergency drill network topology diagram to obtain the target emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram.
[0048] Fourthly, the present application also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:
[0049] Obtain a to-be-processed emergency drill network topology diagram.
[0050] Partition the nodes in the to-be-processed emergency drill network topology diagram to obtain a first node set and a second node set; the first node set includes the first nodes in the nodes that are associated with a preset emergency drill script; the second node set includes second nodes, where the second nodes represent the nodes in the nodes other than the first nodes.
[0051] Update the first node set and the second node set according to the target nodes in the second node set to obtain a first target node set and a second target node set;
[0052] Determine the number of nodes after perturbation of each sub-emergency drill network topology diagram according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram in the to-be-processed emergency drill network topology diagram;
[0053] Determine the selection probability of the nodes in each sub-emergency drill network topology diagram according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram and the set to which the nodes in each sub-emergency drill network topology diagram belong; the set is the first target node set or the second target node set;
[0054] Determine the super nodes in the to-be-processed emergency drill network topology diagram according to the selection probability and the number of nodes after perturbation of the nodes in each sub-emergency drill network topology diagram;
[0055] Construct an updated emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram according to the super nodes;
[0056] Perform perturbation processing on the network segments and node information in the updated emergency drill network topology diagram to obtain a target emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram.
[0057] In a fifth aspect, the present application also provides a computer program product, including a computer program, which when executed by a processor implements the following steps:
[0058] Obtain a to-be-processed emergency drill network topology diagram;
[0059] Perform partitioning processing on the nodes in the to-be-processed emergency drill network topology diagram to obtain a first node set and a second node set; the first node set includes the first nodes associated with a preset emergency drill script among the nodes; the second node set includes second nodes, and the second nodes represent the nodes other than the first nodes among the nodes;
[0060] Update the first node set and the second node set according to the target nodes in the second node set to obtain a first target node set and a second target node set;
[0061] Determine the number of nodes after perturbation of each sub-emergency drill network topology diagram according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram in the to-be-processed emergency drill network topology diagram;
[0062] Determine the selection probability of the nodes in each sub-emergency drill network topology diagram according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram and the set to which the nodes in each sub-emergency drill network topology diagram belong; the set is the first target node set or the second target node set;
[0063] Determine the super nodes in the to-be-processed emergency drill network topology diagram according to the selection probability of the nodes in each sub-emergency drill network topology diagram and the number of nodes after perturbation;
[0064] Construct an updated emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram according to the super nodes;
[0065] Perform perturbation processing on the network segments and node information in the updated emergency drill network topology diagram to obtain the target emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram.
[0066] The above-mentioned emergency drill network topology processing method, device, computer device, storage medium, and computer program product first obtain the emergency drill network topology diagram to be processed, and perform division processing on the nodes in the emergency drill network topology diagram to be processed to obtain a first node set corresponding to the first nodes associated with the preset emergency drill script, and a second node set corresponding to the nodes other than the first nodes in the nodes. Then, according to the target nodes in the second node set, the first node set and the second node set are updated to obtain a first target node set and a second target node set, and according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram in the emergency drill network topology diagram to be processed, the number of perturbed nodes in each sub-emergency drill network topology diagram is determined. Next, according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram, and the set to which the nodes in each sub-emergency drill network topology diagram belong, the selection probability of the nodes in each sub-emergency drill network topology diagram is determined, and according to the selection probability of the nodes in each sub-emergency drill network topology diagram and the number of perturbed nodes, the super nodes in the emergency drill network topology diagram to be processed are determined. Then, according to the super nodes, an updated emergency drill network topology diagram corresponding to the emergency drill network topology diagram to be processed is constructed. Finally, perturbation processing is performed on the network segments and node information in the updated emergency drill network topology diagram to obtain a target emergency drill network topology diagram corresponding to the emergency drill network topology diagram to be processed. In this way, during the process of performing an emergency drill on the network topology, through a series of processes such as dividing and updating the nodes in the emergency drill network topology diagram, and then constructing an updated emergency drill network topology diagram according to the obtained super nodes, and performing perturbation processing on the network segments and node information in the updated emergency drill network topology diagram, the entire process involves multiple updates of the emergency drill network topology diagram, so that a more complex target emergency drill network topology diagram can be obtained, which is beneficial to improving the security of the emergency drill of the network topology. Moreover, in the actual process of the emergency drill, this method does not adopt the method of directly performing the emergency drill, avoiding the defect that the method of directly performing the emergency drill is likely to cause network attackers to obtain relevant information of the network topology through the emergency drill and launch a precise attack on the network topology, resulting in a lower security of the emergency drill of the network topology, and further improving the security of the emergency drill of the network topology. Brief Description of the Drawings
[0067] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required to be used in the description of the embodiments of the present application or related technologies. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, other related drawings can be obtained without creative efforts based on these drawings.
[0068] Figure 1 It is a flowchart showing the process of an emergency drill network topology processing method in an embodiment;
[0069] Figure 2 It is a flowchart showing the steps of obtaining target nodes in the second node set in an embodiment;
[0070] Figure 3 It is a flowchart showing the steps of obtaining a target emergency drill network topology diagram corresponding to the emergency drill network topology diagram to be processed in an embodiment;
[0071] Figure 4 It is a flowchart showing the process of an emergency drill network topology processing method in another embodiment;
[0072] Figure 5 It is a structural block diagram of an emergency drill network topology processing device in an embodiment;
[0073] Figure 6 It is an internal structure diagram of a computer device in an embodiment. Detailed implementation manners
[0074] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0075] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data need to comply with relevant regulations.
[0076] In an exemplary embodiment, as Figure 1 shown, a method for processing an emergency drill network topology is provided. In this embodiment, the method is exemplified by being applied to a server; it can be understood that the method can also be applied to a terminal, and can also be applied to a system including a terminal and a server, and is implemented through the interaction between the terminal and the server. Among them, the terminal can be, but is not limited to, various personal computers, laptop computers, smart phones and tablet computers; the server can be implemented by an independent server or a server cluster composed of multiple servers. In this embodiment, the method includes the following steps:
[0077] Step S101, obtain an emergency drill network topology diagram to be processed.
[0078] Among them, the emergency drill network topology diagram to be processed refers to an emergency drill network topology diagram that needs to be processed.
[0079] Among them, the emergency drill network topology diagram refers to the network topology diagram associated with the emergency drill.
[0080] Among them, the network topology diagram includes multiple nodes and the edges between the nodes. In an actual scenario, a node refers to a network device node.
[0081] Exemplarily, the server obtains a preset emergency drill script and determines the network topology diagram associated with the preset emergency drill script as the to-be-processed emergency drill network topology diagram.
[0082] Step S102: Perform a partitioning process on the nodes in the to-be-processed emergency drill network topology diagram to obtain a first node set and a second node set; the first node set includes the first nodes in the nodes that are associated with the preset emergency drill script; the second node set includes second nodes, where the second nodes represent the nodes other than the first nodes in the nodes.
[0083] Among them, the first node set includes the nodes in the to-be-processed emergency drill network topology diagram that are associated with the preset emergency drill script.
[0084] Among them, the second node set includes the nodes in the to-be-processed emergency drill network topology diagram that are other than the first nodes.
[0085] Exemplarily, the server takes the nodes in all the nodes corresponding to the to-be-processed emergency drill network topology diagram that are associated with the preset emergency drill script as the first nodes, and constructs a first node set based on these first nodes; then, the server takes the nodes in all the nodes corresponding to the to-be-processed emergency drill network topology diagram that are other than the first nodes as the second nodes, and constructs a second node set based on these second nodes.
[0086] Step S103: Update the first node set and the second node set according to the target nodes in the second node set to obtain a first target node set and a second target node set.
[0087] Among them, the target node refers to the node in the second node set that has a preset connection relationship with the nodes in the first node set.
[0088] Among them, the first target node set refers to the updated first node set.
[0089] Among them, the second target node set refers to the updated second node set.
[0090] Exemplarily, the server updates the first node set and the second node set according to the target nodes in the second node set, and obtains the updated first node set and the updated second node set, which are used as the first target node set and the second target node set respectively; for example, the server merges the nodes in the first node set with the target nodes in the second node set to obtain the merged nodes, constructs the first target node set based on these merged nodes, and deletes all the target nodes in the second node set to obtain the processed second node set as the second target node set.
[0091] Step S104: Determine the number of nodes after perturbation for each sub-emergency drill network topology diagram in the to-be-processed emergency drill network topology diagram according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram.
[0092] Wherein, the sub-emergency drill network topology diagram is used to represent a subset corresponding to the to-be-processed emergency drill network topology diagram.
[0093] Wherein, the number of nodes refers to the size of the number of nodes corresponding to the second target node set in the sub-emergency drill network topology diagram.
[0094] Wherein, the number of nodes after perturbation refers to the number of nodes after perturbation processing.
[0095] Exemplarily, the server performs perturbation processing on the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram in the to-be-processed emergency drill network topology diagram, and obtains the number of nodes after perturbation for each sub-emergency drill network topology diagram in the to-be-processed emergency drill network topology diagram.
[0096] Step S105: Determine the selection probability of the nodes in each sub-emergency drill network topology diagram according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram and the set to which the nodes in each sub-emergency drill network topology diagram belong; the set to which the nodes belong is the first target node set or the second target node set.
[0097] Wherein, the set to which the nodes belong may refer to the first target node set or the second target node set.
[0098] Wherein, the selection probability is used to represent the screening possibility that the nodes in each sub-emergency drill network topology diagram are corresponding to super nodes.
[0099] Wherein, a super node refers to a node with a specific function.
[0100] Exemplarily, the server determines the scoring function values of the nodes in each sub-emergency drill network topology diagram according to the sets to which the nodes belong; then, the server determines the selection probabilities of the nodes in each sub-emergency drill network topology diagram according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram and the scoring function values of the nodes in each sub-emergency drill network topology diagram.
[0101] Step S106: Determine the super nodes in the to-be-processed emergency drill network topology diagram according to the selection probabilities of the nodes in each sub-emergency drill network topology diagram and the number of perturbed nodes.
[0102] Exemplarily, the server determines the nodes corresponding to the number of perturbed nodes in each sub-emergency drill network topology diagram according to the selection probabilities of the nodes in each sub-emergency drill network topology diagram and the number of perturbed nodes; then, the server takes the nodes corresponding to the number of perturbed nodes in each sub-emergency drill network topology diagram as the super nodes corresponding to each sub-emergency drill network topology diagram, and takes these super nodes as the super nodes in the to-be-processed emergency drill network topology diagram.
[0103] Step S107: Construct an updated emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram according to the super nodes.
[0104] Wherein, the updated emergency drill network topology diagram is used to represent the network topology diagram constructed according to the super nodes.
[0105] Exemplarily, the server deletes the edges between all the nodes in the super nodes from the to-be-processed emergency drill network topology diagram to obtain the processed to-be-processed emergency drill network topology diagram as the updated emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram.
[0106] Step S108: Perform perturbation processing on the network segments and node information in the updated emergency drill network topology diagram to obtain the target emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram.
[0107] Wherein, the network segment is used to represent the network segment information of each subnet in the updated emergency drill network topology diagram.
[0108] Wherein, the node information includes the IP (Internet Protocol) address, port, MAC (Media Access Control Address) address, etc. of the updated emergency drill network topology diagram.
[0109] Wherein, the perturbation processing may refer to noise addition processing.
[0110] Among them, the target emergency drill network topology diagram refers to the network topology diagram obtained by perturbing the network segment and node information in the updated emergency drill network topology diagram.
[0111] Exemplarily, the server perturbs the network segment and node information in the updated emergency drill network topology diagram to obtain the processed network segment and processed node information; then, the server constructs the target emergency drill network topology diagram corresponding to the emergency drill network topology diagram to be processed according to the processed network segment and processed node information.
[0112] In the above emergency drill network topology processing method, first obtain the emergency drill network topology diagram to be processed, and perform division processing on the nodes in the emergency drill network topology diagram to be processed to obtain the first node set corresponding to the first node associated with the preset emergency drill script, and the second node set corresponding to the nodes other than the first node in the nodes. Then, update the first node set and the second node set according to the target nodes in the second node set to obtain the first target node set and the second target node set, and determine the number of perturbed nodes in each sub-emergency drill network topology diagram according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram in the emergency drill network topology diagram to be processed. Then, according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram, and the set to which the nodes in each sub-emergency drill network topology diagram belong, determine the selection probability of the nodes in each sub-emergency drill network topology diagram, and determine the super nodes in the emergency drill network topology diagram to be processed according to the selection probability of the nodes in each sub-emergency drill network topology diagram and the number of perturbed nodes. Then, construct the updated emergency drill network topology diagram corresponding to the emergency drill network topology diagram to be processed according to the super nodes. Finally, perturb the network segment and node information in the updated emergency drill network topology diagram to obtain the target emergency drill network topology diagram corresponding to the emergency drill network topology diagram to be processed. In this way, during the process of emergency drill for the network topology, through a series of processes such as dividing and updating the nodes in the emergency drill network topology diagram, and then constructing the updated emergency drill network topology diagram according to the obtained super nodes, and perturbing the network segment and node information in the updated emergency drill network topology diagram, the whole process involves multiple updates of the emergency drill network topology diagram, so that a more complex target emergency drill network topology diagram can be obtained, which is beneficial to improving the security of the emergency drill of the network topology; moreover, in the actual process of emergency drill, this method does not adopt the method of directly conducting the emergency drill, avoiding the defect that the method of directly conducting the emergency drill is likely to cause network attackers to obtain relevant information of the network topology through the emergency drill and launch a precise attack on the network topology, resulting in a lower security of the emergency drill of the network topology, and further improving the security of the emergency drill of the network topology.
[0113] In an exemplary embodiment, before updating the first node set and the second node set according to the target nodes in the second node set to obtain the first target node set and the second target node set, step S103 specifically includes the following steps:
[0114] Step S201, obtain the edges between every two nodes in the first node set and the distances corresponding to the edges between every two nodes in the first node set.
[0115] Step S202, for every two nodes in the first node set, filter out the edge with the smallest corresponding distance from the edges between every two nodes in the first node set as the target edge between every two nodes in the first node set.
[0116] Step S203, extract the nodes associated with the target edge from the second node set as the target nodes in the second node set.
[0117] Wherein, the distance is used to represent the number of nodes passed by the edge between nodes, such as 3.
[0118] Wherein, the target edge refers to the edge with the smallest corresponding distance among the edges between every two nodes in the first node set.
[0119] Exemplarily, the server obtains the edges between every two nodes in the first node set and the distances corresponding to the edges between every two nodes in the first node set; then, the server determines the root node in the first node set or the node closest to the root node, and starts from this node to adopt the DFS (Depth-First Search) technology. For every two nodes in the first node set, filter out the edge with the smallest corresponding distance from the edges between every two nodes in the first node set as the target edge between every two nodes in the first node set, and continue to traverse the next two nodes in the first node set until the target edges corresponding to all nodes in the first node set are determined; then, the server extracts the nodes connected to the target edge from the second node set as the target nodes in the second node set.
[0120] Further, in the case where there are at least two edges with the smallest corresponding distance among the edges between every two nodes in the first node set, one of the edges will be randomly selected as the target edge.
[0121] In this embodiment, based on the edges between every two nodes in the first node set and the distances corresponding to the edges between every two nodes in the first node set, the target nodes in the second node set can be quickly obtained. The entire process does not require manual intervention, avoiding the defect that manual processing is prone to consuming a large amount of time, resulting in a low determination efficiency of the target nodes in the second node set.
[0122] In an exemplary embodiment, in step S104 above, according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram of the to-be-processed emergency drill network topology diagram, determine the number of nodes after perturbation of each sub-emergency drill network topology diagram, which specifically includes the following content: According to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram of the to-be-processed emergency drill network topology diagram, determine the initial number of nodes of each sub-emergency drill network topology diagram; According to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram of the to-be-processed emergency drill network topology diagram, and the initial number of nodes of each sub-emergency drill network topology diagram, determine the number of nodes after perturbation of each sub-emergency drill network topology diagram.
[0123] Among them, the initial number of nodes is used to represent the number of nodes expected to be screened out in each sub-emergency drill network topology diagram.
[0124] Exemplarily, the server queries the corresponding relationship between the number of nodes and the initial number of nodes according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram of the to-be-processed emergency drill network topology diagram, and obtains the initial number of nodes of each sub-emergency drill network topology diagram; Then, the server queries the corresponding relationship between the number of nodes, the initial number of nodes, and the number of nodes after perturbation according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram of the to-be-processed emergency drill network topology diagram, and the initial number of nodes of each sub-emergency drill network topology diagram, and obtains the number of nodes after perturbation of each sub-emergency drill network topology diagram.
[0125] Illustratively, the server can use the following formula to determine the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram of the to-be-processed emergency drill network topology diagram:
[0126] num( N i)=| Vi ∩ N |, Equation (1)
[0127] Among them, num( N i) refers to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram of the to-be-processed emergency drill network topology diagram, V i refers to the sub-emergency drill network topology diagram, and N refers to the second target node set.
[0128] For example, the server can determine the initial number of nodes in each sub-emergency drill network topology diagram through the following formula:
[0129]
[0130] where n i refers to the initial number of nodes in each sub-emergency drill network topology diagram.
[0131] For example, the server can determine the number of nodes after perturbation in each sub-emergency drill network topology diagram through the following formula:
[0132] n i ' = n i + Lap(n i / 2, num(N i ) - 1), Equation (3)
[0133] where n i ' refers to the number of nodes after perturbation in each sub-emergency drill network topology diagram, and Lap(n i / 2, num(N i ) - 1) represents a Laplace distribution centered on n i / 2 with a scale parameter of num(N i ) - 1. The lower bound of n i ' is 1 and the upper bound is num(N i ).
[0134] It should be noted that as shown in the following formula, the number of nodes n i ' after perturbation should be within a reasonable range:
[0135] n i ' = max(1, min(n i ', num(N i ))), Equation (4)
[0136] In this embodiment, by perturbing the determined initial number of nodes to obtain the number of nodes after perturbation, it is beneficial to increase the complexity corresponding to the number of nodes after perturbation and provide a data basis for the subsequent determination of super nodes.
[0137] In an exemplary embodiment, in step S105 above, according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram and the set to which the nodes in each sub-emergency drill network topology diagram belong, the selection probability of the nodes in each sub-emergency drill network topology diagram is determined, which specifically includes the following content: According to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram, the first privacy budget value of the nodes in each sub-emergency drill network topology diagram is determined; The first global sensitivity of the nodes in each sub-emergency drill network topology diagram is obtained, and according to the first privacy budget value, the first global sensitivity and the set to which the nodes in each sub-emergency drill network topology diagram belong, the selection probability of the nodes in each sub-emergency drill network topology diagram is determined.
[0138] Wherein, the first privacy budget value refers to the privacy budget value of the nodes in each sub-emergency drill network topology diagram.
[0139] Wherein, the privacy budget value is used to characterize the privacy protection degree corresponding to the emergency drill network topology diagram.
[0140] Wherein, the first global sensitivity refers to the global sensitivity of the nodes in each sub-emergency drill network topology diagram.
[0141] Wherein, the global sensitivity is used to characterize the sensitivity degree of data change in the emergency drill network topology diagram.
[0142] Exemplarily, the server queries the corresponding relationship between the number of nodes and the privacy budget value according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram, and obtains the first privacy budget value of the nodes in each sub-emergency drill network topology diagram; Then, the server determines the scoring function value of the nodes in each sub-emergency drill network topology diagram according to the set to which the nodes in each sub-emergency drill network topology diagram belong; Then, the server obtains the first global sensitivity of the nodes in each sub-emergency drill network topology diagram, and according to the first privacy budget value, the first global sensitivity and the scoring function value of the nodes in each sub-emergency drill network topology diagram, queries the corresponding relationship between the first privacy budget value, the first global sensitivity, the scoring function value and the selection probability, and obtains the selection probability of the nodes in each sub-emergency drill network topology diagram.
[0143] Illustratively, the server can determine the first privacy budget value of the nodes in each sub-emergency drill network topology diagram through the following formula:
[0144]
[0145] Wherein, ∈ refers to the first privacy budget value of the nodes in each sub-emergency drill network topology diagram.
[0146] For example, the server can determine the scoring function value of each node in the sub-emergency drill network topology diagram through the following formula:
[0147]
[0148] Among them, c(n) refers to the scoring function value of each node in the sub-emergency drill network topology diagram, K refers to the first set of target nodes, and N refers to the second set of target nodes.
[0149] For example, the server can determine the selection probability of each node in the sub-emergency drill network topology diagram through the following formula:
[0150]
[0151] Among them, P(n) refers to the selection probability of each node in the sub-emergency drill network topology diagram, gi refers to the sub-emergency drill network topology diagram, and Δ = 1.
[0152] In this embodiment, by comprehensively considering the first privacy budget value, the first global sensitivity, and the scoring function value of each node in the sub-emergency drill network topology diagram, the selection probability of each node in the sub-emergency drill network topology diagram is obtained, making the selection of nodes more scientific and reasonable, thereby protecting privacy and reducing risks.
[0153] In an exemplary embodiment, as Figure 3 shown, in step S108 above, the network segments and node information in the updated emergency drill network topology diagram are perturbed to obtain the target emergency drill network topology diagram corresponding to the emergency drill network topology diagram to be processed, which specifically includes the following contents:
[0154] Step S301: Determine the second privacy budget value and the second global sensitivity corresponding to the network segments in the updated emergency drill network topology diagram, and determine the third privacy budget value and the third global sensitivity corresponding to the node information in the updated emergency drill network topology diagram.
[0155] Step S302: Perturb the network segments in the updated emergency drill network topology diagram according to the second privacy budget value and the second global sensitivity to obtain the processed network segments, and perturb the node information in the updated emergency drill network topology diagram according to the third privacy budget value and the third global sensitivity to obtain the processed node information.
[0156] Step S303: Construct the target emergency drill network topology diagram corresponding to the emergency drill network topology diagram to be processed according to the processed network segments and the processed node information.
[0157] Among them, the second privacy budget value refers to the privacy budget value corresponding to the network segments in the updated emergency drill network topology diagram.
[0158] Among them, the second global sensitivity refers to the global sensitivity corresponding to the network segment in the updated emergency drill network topology diagram.
[0159] Among them, the third privacy budget value refers to the privacy budget value corresponding to the node information in the updated emergency drill network topology diagram.
[0160] Among them, the third global sensitivity refers to the global sensitivity corresponding to the node information in the updated emergency drill network topology diagram.
[0161] Among them, the processed network segment refers to the network segment in the updated emergency drill network topology diagram after perturbation processing.
[0162] Among them, the processed node information refers to the node information in the updated emergency drill network topology diagram after perturbation processing.
[0163] Exemplarily, the server determines the second global sensitivity corresponding to the network segment in the updated emergency drill network topology diagram according to the value range corresponding to the network segment in the updated emergency drill network topology diagram, and uses the preset privacy budget value as the second privacy budget value corresponding to the network segment in the updated emergency drill network topology diagram; then, the server determines the third global sensitivity corresponding to the node information in the updated emergency drill network topology diagram according to the value range corresponding to the node information in the updated emergency drill network topology diagram, and uses the preset privacy budget value as the third privacy budget value corresponding to the node information in the updated emergency drill network topology diagram; then, the server perturbs the network segment in the updated emergency drill network topology diagram according to the second privacy budget value and the second global sensitivity to obtain the processed network segment, and perturbs the IP address, port, and MAC address in the updated emergency drill network topology diagram according to the third privacy budget value and the third global sensitivity to obtain the processed IP address, processed port, and processed MAC address; finally, the server constructs the target emergency drill network topology diagram corresponding to the emergency drill network topology diagram to be processed according to the processed network segment, processed IP address, processed port, and processed MAC address.
[0164] For example, the server takes the privacy budget ∈ = 1 as both the second privacy budget value and the third privacy budget value.
[0165] For example, the server can obtain the processed network segment through the following formula:
[0166]
[0167] Among them, Subnet' refers to the processed network segment, Subne tIt refers to the network segment in the updated emergency drill network topology diagram, Δ refers to the second global sensitivity, and ∈ refers to the second privacy budget value.
[0168] For example, the server can obtain the processed IP address through the following formula:
[0169]
[0170] Wherein, IP′ refers to the processed IP address, IP refers to the IP address in the updated emergency drill network topology diagram, Δ refers to the third global sensitivity, and ∈ refers to the third privacy budget value.
[0171] For example, the server can obtain the processed port through the following formula:
[0172]
[0173] Wherein, Port' refers to the processed port, Port refers to the port in the updated emergency drill network topology diagram, Δ refers to the third global sensitivity, and ∈ refers to the third privacy budget value.
[0174] For example, the server can obtain the processed MAC address through the following formula:
[0175]
[0176] Wherein, MAC′ refers to the processed MAC address, MAC refers to the MAC address in the updated emergency drill network topology diagram, Δ refers to the third global sensitivity, and ∈ refers to the third privacy budget value.
[0177] In this embodiment, by determining the privacy budget value and global sensitivity of each of the network segment and node information, the privacy risk levels faced by different parts in the network topology can be accurately evaluated, which is beneficial to protecting sensitive information to the greatest extent, preventing attackers from obtaining key data by analyzing the network topology, and thus improving the security of the emergency drill network topology diagram to be processed.
[0178] In an exemplary embodiment, before determining the number of perturbed nodes of each sub-emergency drill network topology according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology in the emergency drill network topology diagram to be processed, the above step S104 specifically includes the following contents: determining the network area to which each node in the emergency drill network topology diagram to be processed belongs; dividing the emergency drill network topology diagram to be processed according to the network area to which each node belongs to obtain a plurality of sub-emergency drill network topologies.
[0179] Wherein, the network area includes DMZ (Demilitarized Zone e, isolation area), office area, etc.
[0180] Exemplarily, the server determines the network area to which each node in the to-be-processed emergency drill network topology diagram belongs according to the device type corresponding to each node in the to-be-processed emergency drill network topology diagram; then, the server performs a partitioning process on the to-be-processed emergency drill network topology diagram according to the network area to which each node belongs, and obtains a network topology diagram corresponding to the network area to which each node belongs, as each sub-emergency drill network topology diagram in the to-be-processed emergency drill network topology diagram.
[0181] In this embodiment, by performing a partitioning process on the to-be-processed emergency drill network topology diagram according to the network area to which each node belongs, it is beneficial to conduct targeted emergency drills for different regions, thereby improving the emergency drill effect of the to-be-processed emergency drill network.
[0182] In an exemplary embodiment, as Figure 4 shown, another method for processing the emergency drill network topology is provided. Taking the application of this method to a server as an example for illustration, it specifically includes the following steps:
[0183] Step S401, obtain the to-be-processed emergency drill network topology diagram.
[0184] Step S402, perform a partitioning process on the nodes in the to-be-processed emergency drill network topology diagram to obtain a first node set and a second node set; the first node set includes the first nodes in the nodes that are associated with a preset emergency drill script; the second node set includes second nodes, and the second nodes represent the nodes in the nodes other than the first nodes.
[0185] Step S403, obtain the edges between every two nodes in the first node set, and the distances corresponding to the edges between every two nodes in the first node set; for every two nodes in the first node set, select the edge with the smallest corresponding distance from the edges between every two nodes in the first node set as the target edge between every two nodes in the first node set; extract the nodes associated with the target edge from the second node set as the target nodes in the second node set.
[0186] Step S404, update the first node set and the second node set according to the target nodes in the second node set to obtain a first target node set and a second target node set.
[0187] Step S405, determine the network area to which each node in the to-be-processed emergency drill network topology diagram belongs; perform a partitioning process on the to-be-processed emergency drill network topology diagram according to the network area to which each node belongs to obtain multiple sub-emergency drill network topology diagrams.
[0188] Step S406: Determine the initial number of nodes for each sub-emergency drill network topology diagram based on the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram in the to-be-processed emergency drill network topology diagram.
[0189] Step S407: Determine the number of nodes after perturbation for each sub-emergency drill network topology diagram based on the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram in the to-be-processed emergency drill network topology diagram, and the initial number of nodes for each sub-emergency drill network topology diagram.
[0190] Step S408: Determine the first privacy budget value for the nodes in each sub-emergency drill network topology diagram based on the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram.
[0191] Step S409: Obtain the first global sensitivity of the nodes in each sub-emergency drill network topology diagram, and determine the selection probability of the nodes in each sub-emergency drill network topology diagram based on the first privacy budget value, the first global sensitivity, and the belonging set of the nodes in each sub-emergency drill network topology diagram; the belonging set is the first target node set or the second target node set.
[0192] Step S410: Determine the super nodes in the to-be-processed emergency drill network topology diagram based on the selection probability of the nodes in each sub-emergency drill network topology diagram and the number of nodes after perturbation.
[0193] Step S411: Construct the updated emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram based on the super nodes.
[0194] Step S412: Determine the second privacy budget value and the second global sensitivity corresponding to the network segments in the updated emergency drill network topology diagram, and determine the third privacy budget value and the third global sensitivity corresponding to the node information in the updated emergency drill network topology diagram.
[0195] Step S413: Perturb the network segments in the updated emergency drill network topology diagram based on the second privacy budget value and the second global sensitivity to obtain the processed network segments, and perturb the node information in the updated emergency drill network topology diagram based on the third privacy budget value and the third global sensitivity to obtain the processed node information.
[0196] Step S414: Construct the target emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram based on the processed network segments and the processed node information.
[0197] In the above emergency drill network topology processing method, during the process of conducting an emergency drill on the network topology, through a series of processes such as dividing and updating the nodes in the emergency drill network topology diagram, and then constructing an updated emergency drill network topology diagram based on the obtained super nodes, and disturbing the network segment and node information in the updated emergency drill network topology diagram. The entire process involves multiple updates of the emergency drill network topology diagram, so that a more complex target emergency drill network topology diagram can be obtained, which is beneficial to improving the security of the emergency drill of the network topology. Moreover, in the actual process of the emergency drill, this method does not adopt the method of directly conducting the emergency drill, avoiding the defect that the method of directly conducting the emergency drill is likely to cause network attackers to obtain relevant information of the network topology through the emergency drill and launch a precise attack on the network topology, resulting in a relatively low security of the emergency drill of the network topology, and further improving the security of the emergency drill of the network topology.
[0198] In an exemplary embodiment, in order to more clearly illustrate the emergency drill network topology processing method provided by the embodiments of the present application, the following uses a specific embodiment to specifically describe the emergency drill network topology processing method. In one embodiment, the present application also provides a method for implementing differential privacy protection for the network topology in an emergency drill. During the process of conducting an emergency drill on the network topology, first obtain the to-be-processed emergency drill network topology diagram, and perform a division process on the nodes in the to-be-processed emergency drill network topology diagram to obtain a first node set corresponding to the first node associated with the preset emergency drill script, and a second node set corresponding to the nodes other than the first node in the nodes. Then, update the first node set and the second node set according to the target nodes in the second node set to obtain a first target node set and a second target node set, and determine the number of disturbed nodes in each sub-emergency drill network topology diagram according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram in the to-be-processed emergency drill network topology diagram. Next, according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology diagram and the belonging set of the nodes in each sub-emergency drill network topology diagram, determine the selection probability of the nodes in each sub-emergency drill network topology diagram, and determine the super nodes in the to-be-processed emergency drill network topology diagram according to the selection probability of the nodes in each sub-emergency drill network topology diagram and the number of disturbed nodes. Then, construct an updated emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram according to the super nodes. Finally, disturb the network segment and node information in the updated emergency drill network topology diagram to obtain a target emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram. The specific content is as follows:
[0199] I. Network Topology Construction
[0200] Represent the obtained real user network as an undirected graph G=(V, E), where the node set V represents network devices, and the nodes V in the set V i have attributes such as network area, IP address, open port, MAC address, etc. according to different device types, and the edge set E represents network connection relationships. Each node and edge in the network corresponds to an actual network device and connection.
[0201] II. Network Topology Partitioning
[0202] Partition the network topology graph G into multiple subgraphs G={g1, g2,..., g i} according to network area partitioning such as DMZ area, office area, etc.; each subgraph g i =(V i , E i ) represents a sub-region of the network, where V i and E i are the sets of nodes and edges of this sub-region respectively.
[0203] III. Partitioning of Critical Node and Ordinary Node Sets
[0204] According to the network security emergency initial script L, form the initial set K with the nodes involved in the script L, and form the initial set N with the other nodes. Starting from the root node in K or the node k1 closest to the root node, use depth-first search DFS. If there are n connected paths between any two adjacent nodes ki, k i+1 , and the set of these n connected paths is p i ={p i1 , P i2 ····P in}, randomly select a path p i from the paths with the shortest distance in p ij and remove the nodes involved in it from the set N and add them to the set K. Repeat the above steps to obtain the final sets K and N.
[0205] IV. Node Screening
[0206] Calculate the number of nodes belonging to N in each subgraph gi:
[0207] num(N i ) = |V i ∩N|, Equation (1)
[0208] The number of nodes expected to be screened out from each subgraph gi is:
[0209]
[0210] To protect the information of the number of protected nodes, use the Laplace mechanism for nRandomly perturb the quantity of \(i\) to obtain the perturbed number of nodes \(n\). i ′:
[0211] n i ′ = n i + Lap(n i / 2, num(N i ) - 1), Equation (3)
[0212] where Lap(n i / 2, num(N i ) - 1) represents a Laplace distribution centered at n i / 2 with a scale parameter of num(Ni) - 1, and the lower bound of n i ′ is 1 and the upper bound is num(N i ).
[0213] The perturbed number of nodes n i ′ should be within a reasonable range:
[0214] n i ′ = max(1, min(n i ′, num(N i ))), Equation (4)
[0215] Privacy budget:
[0216]
[0217] When screening nodes, use the exponential mechanism, and the selected scoring function c(n) is defined as follows:
[0218]
[0219] The selection probability of the exponential mechanism is:
[0220]
[0221] where Δ = 1 is the global sensitivity.
[0222] The screening process follows the following rules:
[0223] If the screened nodes belong to K, terminate this screening.
[0224] If the screened nodes belong to N and the number of screened nodes is less than n i ′, then continue screening.
[0225] Repeat the above process until the screening ends.
[0226] V. Supernode construction
[0227] For the set of nodes D screened from each subgraphi = {d1, d2,..., d k}, which is regarded as a super node S i . Ignore the edges between the nodes in the set, and regard the non-repeated edges between the nodes in D i and the external nodes as the edges of the super node. Replace all the nodes and edges in the set D i in G with the super node S i and the edges. The modified topological graph is G′, where the connection between the super node and other nodes reflects the network connection in the emergency initial script L.
[0228] VI. Key Node Replacement
[0229] If the set D i contains a key node (i.e., ), then there is only one element in one case, that is, Num(D i ∩K) == 1; then in the emergency script L, replace the key node with the super node S i . This replacement process ensures that the process of the emergency script remains unchanged and does not affect the effectiveness of the emergency drill, and finally obtains the adjusted emergency script L′.
[0230] VII. Network Topology Perturbation
[0231] For the topological graph G′, regard each subgraph gi as a super node, and start traversing from the root node g1 using the breadth-first search algorithm BFS. During the traversal, randomly perturb the subnet / VLAN division of each subgraph. The specific operations of the perturbation include:
[0232] S11, if the root node uses a network segment for subnet division, the method for randomly perturbing the subnet configuration is as follows:
[0233] (1) Keep the subnet mask of the subnet unchanged, and for the IP address part of the subnet configuration, intercept the network part of the IP address according to the length of the non-host segment of the network mask;
[0234] (2) Divide the IP address into 4 groups every 8 bits. Pad with 0s at the end to make up 8 bits if less than 8 bits;
[0235] (3) Regard each group of 8-bit binary numbers as an integer A i , calculate the average value of the 4 integers The value range of this integer is 0 - 255. Use the Laplace mechanism to randomly perturb this integer, and take the privacy budget ∈ = 1, then the perturbed IP address for each grouped part is:
[0236]
[0237] (4) Truncate each perturbed integer to ensure that the truncated integer is within the range of 0 - 255;
[0238] (5) Combine the perturbed partial integers into a new IP address IP'. It is easy to know from the parallel combination type of differential privacy that the process of synthesizing the IP address still maintains differential privacy, with a privacy budget of ∈ = 1 and a global sensitivity of Δ = 255;
[0239] (6) Determine the gateway of the sub - graph according to the subnet configuration;
[0240] S12. If the root node uses VLAN for area division and the area division uses logical division instead of subnet division, the method for randomly perturbing the configuration is as follows:
[0241] For any node g 11 , g 12 ,....g 1i} in g1 = {g 1i , use the Laplace mechanism to perturb its IP address, port, and MAC address. The perturbation method is to regard attributes such as IP address, port, and MAC address as binary numbers with a certain number of bits. Divide every 8 bits into a group, regard the 8 - bit binary number in each group as an integer, with a range of 0 - 255, and calculate the mean of the corresponding integers of the corresponding groups of the mapping attributes of all nodes Take the privacy budget ∈ = 1, Use the Laplace mechanism to randomly perturb this integer, sequentially combine the perturbed integers into attributes such as IP address, port, and MAC address, and truncate the value of the integer to 0 - 255 as the perturbed attribute; replace the initial node with the node with perturbed attributes to form the VLAN logical area g1' = {g 11 ', g 12 ',....g 1i '}.
[0242] S13. Repeat the above steps. After the breadth - first search algorithm BFS traverses all nodes connected to the root node, synchronize the gateway information of all nodes to the root node and adjust the gateway information of the switch node of the root node.
[0243] S14. Repeat the above steps until all nodes are traversed.
[0244] VIII. Perturbation of Node Information in the Sub - graph
[0245] Traverse the nodes in the subnet starting from the nodes connected to the root node or the previous super - node using the breadth - first search algorithm BFS. During the traversal process, use the Laplace mechanism to perturb the IP address, port, and MAC address:
[0246] IP address perturbation:
[0247]
[0248] Port perturbation:
[0249]
[0250] MAC address perturbation:
[0251]
[0252] IX. Output the reconstructed topology graph
[0253] The finally output network topology graph G″ after differential privacy protection processing ensures the protection of the privacy of the network structure and nodes during the emergency drill; for the adjusted emergency script L′, since at most only one key node in each network area changes, and the connectivity of the new node after the change is consistent with the connectivity of the corresponding key node in the initial script L, it ensures that the connectivity of the script and the overall process remain unchanged.
[0254] In the above-mentioned embodiments, during the process of conducting an emergency drill on the network topology, through a series of processes such as partitioning and updating the nodes in the emergency drill network topology graph, then constructing the updated emergency drill network topology graph according to the obtained super nodes, and perturbing the network segment and node information in the updated emergency drill network topology graph, the whole process involves multiple updates of the emergency drill network topology graph, so that a more complex target emergency drill network topology graph can be obtained, which is beneficial to improving the security of the emergency drill of the network topology; moreover, in the actual process of the emergency drill, this method does not adopt the way of directly conducting the emergency drill, avoiding the defect that the direct emergency drill method is prone to cause network attackers to obtain relevant information of the network topology through the emergency drill and launch a precise attack on the network topology, thereby resulting in a relatively low security of the emergency drill of the network topology, and further improving the security of the emergency drill of the network topology.
[0255] It should be understood that although the steps in the flowcharts involved in the above-mentioned embodiments are sequentially shown according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or steps in other steps.
[0256] Based on the same inventive concept, an embodiment of the present application further provides an emergency drill network topology processing device for implementing the emergency drill network topology processing method involved above. The solution provided by this device for solving problems is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the emergency drill network topology processing device provided below can refer to the limitations on the emergency drill network topology processing method in the above text, and will not be elaborated here.
[0257] In an exemplary embodiment, as Figure 5 shown, an emergency drill network topology processing device is provided, including: a network topology acquisition module 501, a node set division module 502, a node set update module 503, a node quantity determination module 504, a selection probability determination module 505, a super node determination module 506, a network topology construction module 507, and a network topology perturbation module 508, where:
[0258] The network topology acquisition module 501 is configured to acquire an emergency drill network topology graph to be processed.
[0259] The node set division module 502 is configured to perform division processing on the nodes in the emergency drill network topology graph to be processed, obtaining a first node set and a second node set; the first node set includes first nodes in the nodes associated with a preset emergency drill script; the second node set includes second nodes, and the second nodes represent the nodes in the nodes except the first nodes.
[0260] The node set update module 503 is configured to update the first node set and the second node set according to the target nodes in the second node set, obtaining a first target node set and a second target node set.
[0261] The node quantity determination module 504 is configured to determine the number of perturbed nodes in each sub-emergency drill network topology graph according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology graph in the emergency drill network topology graph to be processed.
[0262] The selection probability determination module 505 is configured to determine the selection probability of the nodes in each sub-emergency drill network topology graph according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology graph and the belonging set of the nodes in each sub-emergency drill network topology graph; the belonging set is the first target node set or the second target node set.
[0263] The super node determination module 506 is configured to determine the super nodes in the emergency drill network topology graph to be processed according to the selection probability and the number of perturbed nodes of the nodes in each sub-emergency drill network topology graph.
[0264] A network topology construction module 507 is configured to construct an updated emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram based on super nodes.
[0265] A network topology perturbation module 508 is configured to perform perturbation processing on network segment and node information in the updated emergency drill network topology diagram to obtain a target emergency drill network topology diagram corresponding to the to-be-processed emergency drill network topology diagram.
[0266] In an exemplary embodiment, the emergency drill network topology processing device further includes a target node determination module, configured to obtain edges between every two nodes in a first node set, and distances corresponding to the edges between every two nodes in the first node set; for every two nodes in the first node set, filter out the edge with the smallest corresponding distance from the edges between every two nodes in the first node set as the target edge between every two nodes in the first node set; and extract nodes associated with the target edge from a second node set as target nodes in the second node set.
[0267] In an exemplary embodiment, the node quantity determination module 504 is further configured to determine an initial node quantity of each sub-emergency drill network topology diagram according to the quantity of nodes belonging to a second target node set in each sub-emergency drill network topology diagram in the to-be-processed emergency drill network topology diagram; and determine a perturbed node quantity of each sub-emergency drill network topology diagram according to the quantity of nodes belonging to the second target node set in each sub-emergency drill network topology diagram in the to-be-processed emergency drill network topology diagram and the initial node quantity of each sub-emergency drill network topology diagram.
[0268] In an exemplary embodiment, the selection probability determination module 505 is further configured to determine a first privacy budget value of nodes in each sub-emergency drill network topology diagram according to the quantity of nodes belonging to the second target node set in each sub-emergency drill network topology diagram; obtain a first global sensitivity of nodes in each sub-emergency drill network topology diagram, and determine a selection probability of nodes in each sub-emergency drill network topology diagram according to the first privacy budget value, the first global sensitivity and the belonging set of nodes in each sub-emergency drill network topology diagram.
[0269] In an exemplary embodiment, the network topology perturbation module 508 is further configured to determine a second privacy budget value and a second global sensitivity corresponding to a network segment in the updated emergency drill network topology diagram, and determine a third privacy budget value and a third global sensitivity corresponding to the node information in the updated emergency drill network topology diagram; perform perturbation processing on the network segments in the updated emergency drill network topology diagram according to the second privacy budget value and the second global sensitivity to obtain processed network segments, and perform perturbation processing on the node information in the updated emergency drill network topology diagram according to the third privacy budget value and the third global sensitivity to obtain processed node information; construct a target emergency drill network topology diagram corresponding to the emergency drill network topology diagram to be processed according to the processed network segments and the processed node information.
[0270] In an exemplary embodiment, the emergency drill network topology processing device further includes a network topology division module, configured to determine the network area to which each node in the emergency drill network topology diagram to be processed belongs; perform division processing on the emergency drill network topology diagram to be processed according to the network area to which each node belongs to obtain a plurality of sub-emergency drill network topology diagrams.
[0271] Each module in the above emergency drill network topology processing device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.
[0272] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as Figure 6 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data such as the number of perturbed nodes and selection probabilities. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements an emergency drill network topology processing method.
[0273] Those skilled in the art can understand,Figure 6 The structure shown is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0274] In an exemplary embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.
[0275] In an exemplary embodiment, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the steps in the above method embodiments are implemented.
[0276] In an exemplary embodiment, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the steps in the above method embodiments are implemented.
[0277] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., without limitation.
[0278] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0279] The above-described embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A method for processing network topology for emergency drills, characterized in that: The method comprises: Obtain the network topology diagram of the pending emergency drill; The nodes in the to-be-processed emergency drill network topology graph are divided and processed to obtain a first node set and a second node set; the first node set includes a first node among the nodes that is associated with a preset emergency drill script; the second node set includes a second node, and the second node represents a node among the nodes other than the first node; According to the target node in the second node set, the first node set and the second node set are updated to obtain a first target node set and a second target node set; the target node refers to a node in the second node set that has a preset connection relationship with a node in the first node set; According to the number of nodes belonging to the second target node set in each sub-emergency drill network topology graph in the to-be-processed emergency drill network topology graph, determining the number of nodes after disturbance in each sub-emergency drill network topology graph; Determine the selection probability of the nodes in each sub-emergency drill network topology graph according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology graph and the set to which the nodes in each sub-emergency drill network topology graph belong; the set to which the nodes belong is the first target node set or the second target node set; the selection probability is used to characterize the screening possibility corresponding to the nodes in each sub-emergency drill network topology graph being super nodes; Determine the super node in the to-be-processed emergency drill network topology graph according to the selection probability of the node in each sub-emergency drill network topology graph and the number of nodes after disturbance; According to the super node, construct an updated emergency drill network topology map corresponding to the emergency drill network topology map to be processed; The network segments and node information in the updated emergency drill network topology diagram are disturbed to obtain a target emergency drill network topology diagram corresponding to the emergency drill network topology diagram to be processed.
2. The method according to claim 1, characterized in that Before updating the first node set and the second node set according to the target nodes in the second node set to obtain the first target node set and the second target node set, the method further includes: Obtaining the edges between every two nodes in the first node set and the distances corresponding to the edges between every two nodes in the first node set; For every two nodes in the first node set, from the edges between every two nodes in the first node set, select the corresponding edge with the smallest distance as the target edge between every two nodes in the first node set; A node associated with the target edge is extracted from the second node set as a target node in the second node set.
3. The method according to claim 1, characterized in that The determining the number of nodes after disturbance in each sub-emergency drill network topology graph in the to-be-processed emergency drill network topology graph, according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology graph, comprises: Determine the initial number of nodes in each sub-emergency drill network topology graph in the to-be-processed emergency drill network topology graph according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology graph; According to the number of nodes belonging to the second target node set in each sub-emergency drill network topology graph in the emergency drill network topology graph to be processed, and the initial number of nodes in each sub-emergency drill network topology graph, the number of nodes after disturbance in each sub-emergency drill network topology graph is determined.
4. The method according to claim 1, characterized in that: The determining, according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology graph and the set to which the nodes in each sub-emergency drill network topology graph belong, the selection probability of the nodes in each sub-emergency drill network topology graph comprises: Determine a first privacy budget value of the nodes in each sub-emergency drill network topology graph according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology graph; Obtain a first global sensitivity of a node in each sub-emergency drill network topology graph, and determine a selection probability of a node in each sub-emergency drill network topology graph according to a first privacy budget value, a first global sensitivity, and a belonging set of the node in each sub-emergency drill network topology graph.
5. The method according to claim 1, characterized in that The perturbation process is performed on the network segments and node information in the updated emergency drill network topology map to obtain a target emergency drill network topology map corresponding to the emergency drill network topology map to be processed, including: Determine a second privacy budget value and a second global sensitivity corresponding to the network segment in the updated emergency drill network topology map, and determine a third privacy budget value and a third global sensitivity corresponding to the node information in the updated emergency drill network topology map; According to the second privacy budget value and the second global sensitivity, a network segment in the updated emergency drill network topology map is perturbed to obtain a processed network segment, and according to the third privacy budget value and the third global sensitivity, node information in the updated emergency drill network topology map is perturbed to obtain processed node information; According to the processed network segment and the processed node information, a target emergency drill network topology graph corresponding to the to-be-processed emergency drill network topology graph is constructed.
6. The method according to any one of claims 1 to 5, characterized in that Before determining the number of disturbed nodes in each sub-emergency drill network topology graph in the to-be-processed emergency drill network topology graph according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology graph, the method further includes: Determine the network area to which each node in the network topology diagram of the emergency drill to be processed belongs; According to the network area to which each node belongs, the to-be-processed emergency drill network topology graph is divided and processed to obtain a plurality of sub-emergency drill network topology graphs.
7. An emergency drill network topology processing device, characterized in that: The device comprises: A network topology acquisition module is used to obtain a network topology diagram for an emergency drill to be processed; A node set partitioning module is used to partition the nodes in the to-be-processed emergency drill network topology diagram to obtain a first node set and a second node set; the first node set includes a first node among the nodes associated with a preset emergency drill script; the second node set includes a second node, and the second node represents a node among the nodes other than the first node; a node set updating module, configured to update the first node set and the second node set according to a target node in the second node set, to obtain a first target node set and a second target node set; the target node refers to a node in the second node set that has a preset connection relationship with a node in the first node set; A node quantity determination module, used to determine the number of nodes after disturbance in each sub-emergency drill network topology graph in the emergency drill network topology graph to be processed according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology graph; A selection probability determination module is used to determine the selection probability of the nodes in each sub-emergency drill network topology map according to the number of nodes belonging to the second target node set in each sub-emergency drill network topology map and the set to which the nodes in each sub-emergency drill network topology map belong; the set to which the nodes belong is the first target node set or the second target node set; the selection probability is used to characterize the screening possibility corresponding to the node in each sub-emergency drill network topology map being a super node; A super node determination module, used to determine the super nodes in the to-be-processed emergency drill network topology diagram according to the selection probability of the nodes in each sub-emergency drill network topology diagram and the number of nodes after disturbance; A network topology construction module, used to construct an updated emergency drill network topology map corresponding to the to-be-processed emergency drill network topology map according to the super node; The network topology disturbance module is used to perform disturbance processing on the network segments and node information in the updated emergency drill network topology map to obtain a target emergency drill network topology map corresponding to the emergency drill network topology map to be processed.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Adaptive routing system and method for QOS packet networks
CA2299111A1
Emergency aid decision-making system based on intranet
CN115841221A