A computer network security analysis system and method based on big data
By designing a computer network security analysis system based on big data, using machine learning and deep learning technologies for feature extraction and risk assessment, combining generative adversarial network technology and intelligent early warning strategies, the problem that traditional security analysis methods are difficult to deal with large-scale data and identify complex attacks is solved, and efficient and accurate security analysis and protection strategy generation are achieved.
Patent Information
- Application Number
- CN202411319203.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-21
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2044-09-21
AI Technical Summary
Traditional computer network security analysis methods are difficult to handle large-scale data, cannot effectively identify complex and hidden network attacks, and are difficult to adapt to dynamically changing network environments, and lack the ability to fusion and correlation analysis of multi-source data.
A computer network security analysis system based on big data is designed, including data acquisition module, data preprocessing module, feature extraction module, risk assessment module, security early warning module, protection strategy generation module and intelligent collaboration module. Machine learning and deep learning technology are used for feature extraction and risk assessment, combined with generative adversarial network technology for feature enhancement, and dynamic adjustment and optimization are achieved through intelligent early warning strategies and case reasoning-based protection strategy generation algorithm.
It realizes comprehensive collection and comprehensive analysis of network traffic, system logs and user behavior data, improves the accuracy and comprehensiveness of security analysis, can timely identify and respond to complex network attacks, adapt to dynamically changing network environments, and reduces security risks.
Smart Images

Figure CN119094225B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer network security technology, and more specifically, to a computer network security analysis system and method based on big data. Background Art
[0002] With the rapid development of information technology, computer networks have penetrated into all areas of society, including business, finance, medical care, education, etc. The openness and interconnectivity of the network make it face increasingly severe security challenges.
[0003] Traditional computer network security protection methods mainly rely on rule-based and feature-based security devices such as firewalls and intrusion detection systems. However, these devices have gradually exposed many limitations in the face of increasingly complex and diverse network attacks.
[0004] On the one hand, traditional security devices are unable to cope with large-scale data processing needs. In today's network environment, the amount of data is growing explosively, and massive amounts of information such as network traffic, system logs, and user behavior data are constantly generated. Traditional security analysis methods are often unable to process such a large amount of data within a reasonable time, resulting in security risks being hidden in the ocean of data and unable to be discovered in time. For example, in large enterprise networks or data centers, the network traffic data generated every day can reach hundreds of TB or even more. Traditional security analysis tools are inefficient in processing this data and are prone to omissions or false positives.
[0005] On the other hand, traditional security protection methods are difficult to adapt to the characteristics of new network attacks. Modern network attack methods are becoming more and more complex and covert. For example, in advanced persistent threat (APT) attacks, attackers usually use long-term latent, multi-stage attack methods, constantly changing attack methods and paths to evade detection by traditional security devices. Traditional rule- and feature-based detection methods can only identify known attack patterns, and are often powerless against new, unknown attack behaviors. For example, some malware will constantly mutate its own code to avoid detection by antivirus software. Traditional security devices are difficult to effectively respond to such dynamically changing attack threats.
[0006] In addition, the dynamic changes in the network security environment have also brought great challenges to traditional security protection. The constant changes in network topology, the continuous emergence of new applications and services, and the diversity of user behavior have made the network security boundary increasingly blurred. Traditional security protection systems are usually built based on fixed network boundaries and preset security policies, which are difficult to adapt to this dynamically changing environment. For example, with the popularization of mobile office and cloud computing, the boundaries of enterprise networks have expanded to various mobile devices and cloud service platforms. Traditional security protection methods are difficult to fully cover these new network access points and application scenarios.
[0007] At the same time, existing network security analysis methods are insufficient in terms of multi-source data fusion and correlation analysis. Network security incidents often involve data from multiple aspects, such as network traffic data that can reflect the situation of network communication, system log data that can reveal the internal operating status of the system, and user behavior data that can reflect the user's operating habits. However, traditional security analysis methods can usually only analyze these data in isolation, lacking effective data fusion and correlation analysis capabilities, and it is difficult to discover clues to security threats hidden behind multi-source data. For example, a seemingly normal user behavior may be judged as a potential attack behavior after combining specific network traffic patterns and system log abnormal records, but traditional methods often cannot achieve such in-depth correlation analysis.
[0008] In summary, traditional computer network security analysis methods and technologies can no longer meet the security needs in the current complex network environment. There is an urgent need for an innovative computer network security analysis system and method based on big data to meet these challenges. Summary of the invention
[0009] The present invention proposes an enterprise management system and method based on big data analysis to solve the problems mentioned in the above-mentioned prior art.
[0010] In order to achieve the above-mentioned purpose, the present invention adopts the following technical scheme: a computer network security analysis system based on big data, including a data acquisition module, a data preprocessing module, a feature extraction module, a risk assessment module, a security warning module, a protection strategy generation module and an intelligent collaboration module;
[0011] The data collection module is used to collect network traffic data, system log data and user behavior data. The data collection module has the function of collecting external threat intelligence data, and obtains the latest threat intelligence data from public security information sources by using web crawler technology;
[0012] The data preprocessing module uses a data cleaning algorithm to remove conventional noise data and erroneous data, and detects and repairs abnormal data based on the time series characteristics of the data and the relevance of network business logic. The data cleaning effect evaluation formula is: Where C represents the evaluation value of data cleaning effect, N clean Represents the number of correct data after cleaning, N total represents the total amount of original data, α is the adjustment coefficient, T consistency Indicator representing the temporal consistency of data;
[0013] The feature extraction module uses machine learning algorithms and deep learning models to extract key feature information from preprocessed data, introduces feature enhancement technology based on generative adversarial networks (GANs), and generates representative and robust feature representations through adversarial training of generators and discriminators.
[0014] The risk assessment module conducts quantitative assessment of network security risks based on the extracted feature information and an innovative risk assessment model. The risk assessment model includes a network infrastructure risk assessment sub-model, an application security risk assessment sub-model, and a user behavior risk assessment sub-model. The comprehensive risk assessment formula is: Where R represents the comprehensive risk assessment value, R infrastructure represents the risk assessment value of network infrastructure, R application represents the application security risk assessment value, R behavior represents the user behavior risk assessment value, β is the threat intelligence impact coefficient, and I threat Indicates the external threat intelligence risk indicator value;
[0015] When the risk assessment result exceeds the preset threshold, the security warning module will issue a warning message, including a sound alarm, email notification or mobile phone text message push. The warning module automatically adjusts the frequency and method of warning according to the severity and urgency of the risk. For high-risk emergencies, continuous high-frequency sound alarms and instant text message push are used, and for low-risk events, regular email notifications are used;
[0016] The protection strategy generation module automatically generates corresponding protection strategies based on risk assessment results and system security requirements. The protection strategies include network access control strategy adjustment, system vulnerability repair suggestions, user behavior monitoring rule optimization, and emergency response plan generation. The accuracy and effectiveness evaluation formula of the protection strategy generation is: Where P represents the evaluation value of the protection strategy, N effective Represents the number of effective protection strategies, N generated represents the total amount of protection strategies generated, γ is the response time adjustment coefficient, T response Indicates the response time of the protection strategy;
[0017] The intelligent collaboration module is used to promote information exchange and collaborative work among the systems. When the data acquisition module finds abnormal data, it notifies the feature extraction module to extract key features and notifies the security warning module to prepare for warnings.
[0018] Furthermore, the network traffic data collection in the data collection module adopts a distributed data collection architecture, and automatically adjusts the collection frequency according to the dynamic changes of network traffic. The collection frequency adjustment formula is: Where F represents the acquisition frequency, ω is the basic acquisition frequency value, is the adjustment coefficient, T traffic Indicates the network traffic change index value.
[0019] Furthermore, the data format standardization in the data preprocessing module adopts an adaptive data format conversion algorithm, which can automatically perform format conversion according to the data format characteristics of different data sources.
[0020] Furthermore, the feature extraction module is based on the feature enhancement technology of the generative adversarial network, and the training process of the generator and the discriminator adopts an improved adversarial training algorithm, and the training loss function is:
[0021]
[0022] Where L represents the training loss function value, n represents the number of training samples, and y i represents the real data label, x i represents the real data sample, D represents the discriminator network, G represents the generator network, z i represents the random noise vector, λ and μ are regularization coefficients, θ G and θ D Represent the network parameters of the generator and the discriminator respectively.
[0023] Furthermore, the network infrastructure risk assessment sub-model in the risk assessment module adopts a hierarchical risk assessment method, which divides the network infrastructure into the physical layer, the network layer and the application layer, conducts risk assessment on each layer respectively, and conducts a comprehensive assessment based on the dependency relationship between the layers. The comprehensive assessment formula is: Where R infrastructure represents the risk assessment value of the network infrastructure, m represents the number of layers, and W j Represents the weight coefficient of the jth level, R layer,j Represents the risk assessment value of the jth level.
[0024] Furthermore, the frequency and method of warning in the safety warning module are adjusted using an intelligent warning strategy algorithm, which learns and optimizes according to risk assessment results and historical warning data, and automatically adjusts the frequency and method of warning. Its optimization objective function is: Where O represents the optimization objective function value, n represents the number of warning events, T i represents the response time of the ith warning event, F i represents the frequency adjustment coefficient of the i-th warning event, η is the false alarm penalty coefficient, E false Represents the number of false alarms. By minimizing the weighted sum of response time and number of false alarms, the optimal warning frequency and method adjustment can be achieved.
[0025] Furthermore, a computer network security analysis method based on big data includes the following steps:
[0026] S1. Use the data acquisition module to comprehensively collect network-related data;
[0027] S2, processing the collected data through the data preprocessing module, including data cleaning, denoising and format standardization;
[0028] S3. Use the feature extraction module to extract data features, use machine learning algorithms and deep learning models for feature extraction, and combine generative adversarial network technology for feature enhancement;
[0029] S4. Use the risk assessment module to conduct risk assessment, and use a multi-level and multi-dimensional risk assessment model combined with external threat intelligence to conduct a comprehensive risk assessment;
[0030] S5. Take appropriate measures based on the risk assessment results.
[0031] Furthermore, after the risk assessment step, it is determined whether to trigger the security warning module for warning based on the assessment results. If the risk assessment value exceeds the preset warning threshold, the security warning module is started, and the warning frequency and method are adjusted according to the intelligent warning strategy algorithm to issue a warning message.
[0032] Furthermore, after the risk assessment is completed, if there is a risk, the protection strategy generation module is used to automatically generate the corresponding protection strategy. The protection strategy generation process is optimized based on historical protection strategy data and current risk assessment results, and a protection strategy generation algorithm based on case reasoning is used to improve the accuracy and effectiveness of the protection strategy.
[0033] Furthermore, the protection strategy generated by the protection strategy generation module includes network access control strategy adjustment, system vulnerability repair suggestions, and user behavior monitoring rule optimization. After the protection strategy is implemented, the protection effect is monitored and evaluated in real time, and the protection strategy is dynamically adjusted and optimized according to the evaluation results. The optimization formula is: Where S represents the protection effect evaluation value, N secure Indicates the amount of data or number of network nodes in a safe state, N total represents the total amount of data or the total number of network nodes, ξ is the adjustment time coefficient, T adjust Indicates the protection policy adjustment interval.
[0034] Compared with the prior art, the present invention has the following beneficial effects:
[0035] More comprehensive data collection and integration:
[0036] By introducing the external threat intelligence data collection function, it is possible to combine external security information with internal network data to provide a broader perspective for network security analysis. This allows the system to not only pay attention to the status of the internal network, but also to understand potential external threats in a timely manner and make preparations in advance.
[0037] It realizes the comprehensive collection and comprehensive analysis of multi-source data such as network traffic data, system log data, and user behavior data, breaking the data isolation situation in traditional security analysis. Through the fusion of multi-source data, we can have a more comprehensive understanding of the overall operation status and security situation of the network, and improve the accuracy and comprehensiveness of security analysis.
[0038] Efficient and accurate data preprocessing:
[0039] The use of intelligent data cleaning algorithms can not only effectively remove noise and erroneous data, but also conduct in-depth detection and repair based on the time series characteristics of the data and the relevance of network business logic. This greatly improves the quality of the data, provides a reliable data foundation for subsequent analysis work, and reduces misjudgments and missed judgments caused by data quality issues.
[0040] The adaptive data format standardization algorithm ensures that data from different sources can be processed compatibly and consistently in the system, improves the efficiency and accuracy of data processing, and avoids processing difficulties caused by differences in data formats.
[0041] Advanced feature extraction and risk assessment:
[0042] Using a variety of machine learning algorithms and deep learning models for feature extraction, combined with generative adversarial network technology for feature enhancement, can mine more representative and robust features in the data. This helps to discover potential security threat patterns and abnormal behaviors hidden in the data, and improves the depth and accuracy of security analysis.
[0043] The multi-level and multi-dimensional risk assessment model combines external threat intelligence for comprehensive risk assessment, which can more comprehensively and accurately assess network security risks. It not only considers internal factors such as network infrastructure, applications, and user behavior, but also incorporates the impact of external threat intelligence, making the risk assessment results closer to the actual situation and providing enterprises with more valuable risk information.
[0044] 1. Intelligent security warning and protection strategy generation:
[0045] The intelligent early warning strategy algorithm can automatically adjust the frequency and method of early warning according to the risk assessment results and historical early warning data, ensuring that timely and effective warnings can be issued to relevant personnel when security incidents occur. At the same time, differentiated early warnings are carried out according to the severity and urgency of the risk, which improves the pertinence and effectiveness of early warnings.
[0046] The protection strategy generation module can automatically generate corresponding protection strategies based on risk assessment results, including network access control strategy adjustments, system vulnerability repair suggestions, and user behavior monitoring rule optimization, etc. This greatly improves the response speed and pertinence of security protection, and can take effective protection measures in the shortest time to reduce security risks.
[0047] 2. System coordination and optimization capabilities:
[0048] The intelligent collaboration module promotes information exchange and collaborative work between modules of the system, and realizes real-time data sharing and task collaboration between modules. This improves the overall operating efficiency and response speed of the system, allowing each module to work closely together to jointly respond to network security challenges.
[0049] The protection strategy generation algorithm based on case reasoning and the real-time monitoring and evaluation mechanism of protection effect can continuously optimize the protection strategy and ensure the continuous effectiveness of protection measures. At the same time, the protection effect is quantitatively evaluated through the optimization formula, which provides a scientific basis for further improving and perfecting the security protection system.
[0050] 3. Adapt to complex and changing network environment:
[0051] The system and method of the present invention can adapt to the needs of large-scale data processing, and can efficiently perform security analysis and protection in both large enterprise networks and complex network environments. This provides enterprises with a reliable network security solution, enabling them to cope with the growing network security challenges in the big data era.
[0052] It can adapt to the dynamic changes in the network security environment, including changes in network topology, the emergence of new applications and services, and the diversity of user behavior. Through continuous learning and optimization, the system can timely adjust security strategies and analysis methods to maintain effective protection of network security. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] Figure 1 This is a schematic block diagram of the enterprise management system based on big data analysis proposed by the present invention. DETAILED DESCRIPTION
[0054] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0055] In the description of the present invention, it should be understood that the terms "center", "longitudinal", "lateral", "length", "width", "thickness", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", "clockwise", "counterclockwise" and the like indicate orientations or positional relationships based on the orientations or positional relationships shown in the accompanying drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the referred device or element must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be understood as limiting the present invention.
[0056] In addition, the terms "first" and "second" are used for descriptive purposes only and cannot be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Therefore, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of the present invention, the meaning of "multiple" is two or more, unless otherwise clearly and specifically defined. In addition, the terms "installed", "connected" and "connected" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection, or it can be indirectly connected through an intermediate medium, and it can be the internal connection of two elements. For ordinary technicians in this field, the specific meanings of the above terms in the present invention can be understood according to specific circumstances. The present invention will be further described in detail below in conjunction with the accompanying drawings.
[0057] Reference Figure 1 : A computer network security analysis system based on big data, including a data acquisition module, a data preprocessing module, a feature extraction module, a risk assessment module, a security warning module, a protection strategy generation module and an intelligent collaboration module;
[0058] The data collection module is used to collect network traffic data, system log data and user behavior data. The data collection module has the function of collecting external threat intelligence data, and obtains the latest threat intelligence data from public security information sources by using web crawler technology;
[0059] The data preprocessing module uses a data cleaning algorithm to remove conventional noise data and erroneous data, and detects and repairs abnormal data based on the time series characteristics of the data and the relevance of network business logic. The data cleaning effect evaluation formula is: Where C represents the evaluation value of data cleaning effect, N clean Represents the number of correct data after cleaning, N total represents the total amount of original data, α is the adjustment coefficient, T consistency Indicator representing the temporal consistency of data;
[0060] The feature extraction module uses machine learning algorithms and deep learning models to extract key feature information from preprocessed data, introduces feature enhancement technology based on generative adversarial networks (GANs), and generates representative and robust feature representations through adversarial training of generators and discriminators.
[0061] The risk assessment module conducts quantitative assessment of network security risks based on the extracted feature information and an innovative risk assessment model. The risk assessment model includes a network infrastructure risk assessment sub-model, an application security risk assessment sub-model, and a user behavior risk assessment sub-model. The comprehensive risk assessment formula is: Where R represents the comprehensive risk assessment value, R infrastructure represents the risk assessment value of network infrastructure, R application represents the application security risk assessment value, R behavior represents the user behavior risk assessment value, β is the threat intelligence impact coefficient, and I threat Indicates the external threat intelligence risk indicator value;
[0062] When the risk assessment result exceeds the preset threshold, the security warning module will issue a warning message, including a sound alarm, email notification or mobile phone text message push. The warning module automatically adjusts the frequency and method of warning according to the severity and urgency of the risk. For high-risk emergencies, continuous high-frequency sound alarms and instant text message push are used, and for low-risk events, regular email notifications are used;
[0063] The protection strategy generation module automatically generates corresponding protection strategies based on risk assessment results and system security requirements. The protection strategies include network access control strategy adjustment, system vulnerability repair suggestions, user behavior monitoring rule optimization, and emergency response plan generation. The accuracy and effectiveness evaluation formula of the protection strategy generation is: Where P represents the evaluation value of the protection strategy, N effective Represents the number of effective protection strategies, N generated represents the total amount of protection strategies generated, γ is the response time adjustment coefficient, T response Indicates the response time of the protection strategy;
[0064] The intelligent collaboration module is used to promote information exchange and collaborative work among the systems. When the data acquisition module finds abnormal data, it notifies the feature extraction module to extract key features and notifies the security warning module to prepare for warnings.
[0065] Furthermore, the network traffic data collection in the data collection module adopts a distributed data collection architecture, and automatically adjusts the collection frequency according to the dynamic changes of network traffic. The collection frequency adjustment formula is: Where F represents the acquisition frequency, w is the basic acquisition frequency value, is the adjustment coefficient, T traffic Indicates the network traffic change index value.
[0066] Furthermore, the data format standardization in the data preprocessing module adopts an adaptive data format conversion algorithm, which can automatically perform format conversion according to the data format characteristics of different data sources.
[0067] Furthermore, the feature extraction module is based on the feature enhancement technology of the generative adversarial network, and the training process of the generator and the discriminator adopts an improved adversarial training algorithm, and the training loss function is:
[0068]
[0069] Where L represents the training loss function value, n represents the number of training samples, and y i represents the real data label, x i represents the real data sample, D represents the discriminator network, G represents the generator network, z i represents the random noise vector, λ and μ are regularization coefficients, θ G and θ D Represent the network parameters of the generator and the discriminator respectively.
[0070] Furthermore, the network infrastructure risk assessment sub-model in the risk assessment module adopts a hierarchical risk assessment method, which divides the network infrastructure into the physical layer, the network layer and the application layer, conducts risk assessment on each layer respectively, and conducts a comprehensive assessment based on the dependency relationship between the layers. The comprehensive assessment formula is: Where R infrastructure represents the risk assessment value of the network infrastructure, m represents the number of layers, and W j Represents the weight coefficient of the jth level, R layer,j Represents the risk assessment value of the jth level.
[0071] Furthermore, the frequency and method of warning in the safety warning module are adjusted using an intelligent warning strategy algorithm, which learns and optimizes according to risk assessment results and historical warning data, and automatically adjusts the frequency and method of warning. Its optimization objective function is: Where O represents the optimization objective function value, n represents the number of warning events, T i represents the response time of the ith warning event, F i represents the frequency adjustment coefficient of the i-th warning event, η is the false alarm penalty coefficient, E false Represents the number of false alarms. By minimizing the weighted sum of response time and number of false alarms, the optimal warning frequency and method adjustment can be achieved.
[0072] The present invention also discloses a computer network security analysis method based on big data, comprising the following steps:
[0073] S1. Use the data acquisition module to comprehensively collect network-related data;
[0074] S2, processing the collected data through the data preprocessing module, including data cleaning, denoising and format standardization;
[0075] S3. Use the feature extraction module to extract data features, use machine learning algorithms and deep learning models for feature extraction, and combine generative adversarial network technology for feature enhancement;
[0076] S4. Use the risk assessment module to conduct risk assessment, and use a multi-level and multi-dimensional risk assessment model combined with external threat intelligence to conduct a comprehensive risk assessment;
[0077] S5. Take appropriate measures based on the risk assessment results.
[0078] In the present invention, after completing the key risk assessment step, the system immediately enters a crucial decision-making link, that is, accurately judging whether it is necessary to trigger the safety warning module to take further action based on the assessment results.
[0079] First, the system will conduct a detailed analysis and interpretation of the various data and indicators obtained from the risk assessment. These assessment results include the quantitative value of network security risks, as well as the classification and detailed description of different types of risks, such as the stability assessment value of network infrastructure risks, the risk level of potential security vulnerabilities in applications, and the risk probability that may be caused by abnormal user behavior.
[0080] On this basis, the system compares these assessment results with the preset warning thresholds one by one. This warning threshold is a key parameter that has been carefully set and continuously optimized based on the system's strict requirements for network security and past experience data. If the risk assessment value is within the normal range, that is, lower than the preset warning threshold, it indicates that the current network security situation is relatively stable. The system will continue to closely monitor the network status, but will not start the security warning module.
[0081] However, once the risk assessment value exceeds the preset warning threshold, it means that the network may face a more serious security threat, and the system will immediately activate the security warning module. After being activated, the security warning module will not use the traditional single fixed warning method, but will dynamically adjust the warning frequency and method based on the advanced intelligent warning strategy algorithm.
[0082] The intelligent early warning strategy algorithm will comprehensively consider many factors to determine the best early warning plan. For example, the frequency of early warnings will be adjusted according to the severity of the risk. For high-risk emergencies, the system will significantly increase the frequency of early warnings to ensure that relevant personnel can receive multiple alarm messages in the shortest time and respond quickly. At the same time, the most appropriate early warning method will be selected based on the object receiving the early warning information and the environment in which it is located. If the network security manager is at work, the system may use more direct and eye-catching methods such as pop-up prompts and sound alarms to issue early warnings; for managers who are on business trips, the system will automatically send mobile text messages or push notifications from special security management applications to ensure that they can understand the network security status anytime and anywhere.
[0083] In addition, the intelligent early warning strategy algorithm will also refer to historical early warning data and response effects, and continuously learn and optimize its own early warning strategy. For example, if it is found that a certain type of risk has a poor effect in the past early warning of a certain type of risk, the system will automatically adjust to a more effective early warning method in subsequent similar situations. In this way, the system can issue accurate and effective early warning information in a timely manner, buy precious time to respond to network security risks, and minimize potential losses.
[0084] In the present invention, once the risk assessment module completes the comprehensive assessment of network security risks, the system will immediately conduct in-depth analysis and judgment on the assessment results. If potential security risks are detected, the protection strategy generation module will be quickly activated and play a key role.
[0085] The protection strategy generation module fully integrates multiple key information and advanced technologies in the process of generating protection strategies. First, it will deeply mine and analyze historical protection strategy data, which contains detailed records of strategies adopted in the past to deal with various network security risks and their implementation effects. By learning and summarizing these historical data, we can learn from successful experiences, avoid repeating past mistakes, and provide important reference for the current protection strategy generation.
[0086] At the same time, combined with the current accurate risk assessment results, the key elements such as risk type, source, potential impact scope and possible development trend are carefully analyzed. For example, if the risk assessment results show that there are abnormal network traffic, which may be a precursor to a distributed denial of service attack (DDoS), then the protection strategy generation module will formulate a corresponding response strategy for this specific type of risk.
[0087] In terms of the core technology of generating protection strategies, a protection strategy generation algorithm based on case reasoning is adopted. The working principle of this algorithm is similar to the human thinking mode. When faced with a new risk situation, it will search for similar historical cases in a huge case database and learn from the successful protection strategy solutions in these cases. Then, adaptive adjustments and optimizations are made according to the specific characteristics of the current risk. For example, if a historical case is found that the protection strategy for dealing with similar network attacks is to add specific firewall rules and adjust network bandwidth allocation, then in the current situation, the protection strategy generation module will make appropriate modifications and improvements to these strategies based on the actual situation of the current network architecture, application environment, and resource configuration.
[0088] In this way, the accuracy and effectiveness of the protection strategy can be greatly improved. It ensures that the generated protection strategy can not only accurately respond to current security risks, but also play a practical role in practical applications, effectively reduce the potential damage caused by risks to network systems, and ensure the safe and stable operation of computer networks. In addition, as the system continues to operate and new risk cases accumulate, the protection strategy generation module can continue to learn and evolve, and continuously improve its ability to generate high-quality protection strategies.
[0089] In the present invention, the protection strategy generation module has a high degree of flexibility and adaptability, and can generate a series of comprehensive and accurate protection strategies. In terms of network access control policy adjustment, the network access permission settings can be intelligently adjusted according to the network access anomalies involved in the risk assessment results, such as abnormal high-traffic access sources, IP addresses that frequently attempt to access sensitive areas, etc. For example, for IP addresses that are judged to have potential security threats, the system can automatically add them to the access blacklist and restrict their access to key network resources; or for user accounts that have abnormal access patterns within a specific time period, temporarily reduce their access permission levels, and decide whether to restore normal permissions after further verifying the safety of their behavior.
[0090] In terms of system vulnerability repair suggestions, when analysis finds that there are vulnerabilities in the system that may be exploited by attackers, the protection strategy generation module can not only accurately locate the location of these vulnerabilities, but also provide detailed repair suggestion steps based on the repair cases and best practices of similar vulnerabilities in big data. For example, for security vulnerabilities at the operating system level, corresponding patch installation instructions and post-installation verification methods are provided; for vulnerabilities in applications, reference examples of code repairs and security configuration adjustment suggestions are given to ensure that vulnerabilities can be repaired in a timely and effective manner to reduce the risk of being attacked.
[0091] For optimization of user behavior monitoring rules, based on in-depth analysis of user behavior data, after discovering abnormal operation patterns or behavior habits that may pose risks, user behavior monitoring rules are automatically adjusted. For example, if a user is detected to frequently attempt to access a high-authority business system during non-working hours, or continues to attempt to log in after entering an incorrect password multiple times, the system can strengthen monitoring of the user's behavior, add additional identity verification links, or send alarm information to security managers in real time so that further investigation and preventive measures can be taken in a timely manner.
[0092] After implementing these protection strategies, the system will immediately start a real-time monitoring and evaluation mechanism for the protection effect. By deploying monitoring probes at key nodes of the network, key indicator data such as data flow, system response time, and user access success rate are collected in real time to judge the implementation effect of the protection strategy. The protection strategy is dynamically adjusted and optimized based on the evaluation results. The optimization formula is: Where S represents the protection effect evaluation value, N secure Indicates the amount of data or number of network nodes in a safe state, N total represents the total amount of data or the total number of network nodes, ξ is the adjustment time coefficient, T adjust Indicates the time interval for adjusting the protection strategy; if the value of S shows that the protection effect is not ideal, the system will quickly trigger the optimization process of the protection strategy, re-analyze the current network security status and risk factors, and dynamically adjust and optimize the protection strategy in combination with historical experience and the latest security intelligence in big data. For example, increase the strictness of network access control, further refine the plan for repairing system vulnerabilities, or adjust the rule parameters of user behavior monitoring to ensure that the protection strategy can always adapt to the ever-changing network security environment, maintain continuous effectiveness, and provide a solid guarantee for the safe and stable operation of computer networks.
[0093] The above are only preferred specific implementation modes of the present invention, but the protection scope of the present invention is not limited thereto. Any technician familiar with the technical field can make equivalent replacements or changes according to the technical solutions and inventive concepts of the present invention within the technical scope disclosed by the present invention, which should be covered by the protection scope of the present invention.
Claims
1. A computer network security analysis system based on big data, characterized in that: It includes data acquisition module, data preprocessing module, feature extraction module, risk assessment module, security warning module, protection strategy generation module and intelligent collaboration module; The data collection module is used to collect network traffic data, system log data and user behavior data. The data collection module has the function of collecting external threat intelligence data, and obtains the latest threat intelligence data from public security information sources by using web crawler technology; The data preprocessing module uses a data cleaning algorithm to remove conventional noise data and erroneous data, and detects and repairs abnormal data based on the time series characteristics of the data and the relevance of network business logic. The data cleaning effect evaluation formula is: Where C represents the evaluation value of data cleaning effect, N clean Represents the number of correct data after cleaning, N total represents the total amount of original data, α is the adjustment coefficient, T consistency Indicator representing the temporal consistency of data; The feature extraction module uses machine learning algorithms and deep learning models to extract key feature information from preprocessed data, introduces feature enhancement technology based on generative adversarial networks (GANs), and generates representative and robust feature representations through adversarial training of generators and discriminators. The risk assessment module conducts quantitative assessment of network security risks based on the extracted feature information and an innovative risk assessment model. The risk assessment model includes a network infrastructure risk assessment sub-model, an application security risk assessment sub-model, and a user behavior risk assessment sub-model. The comprehensive risk assessment formula is: Where R represents the comprehensive risk assessment value, R infrastructure represents the risk assessment value of network infrastructure, R application represents the application security risk assessment value, R behavior represents the user behavior risk assessment value, β is the threat intelligence impact coefficient, and I threat Indicates the external threat intelligence risk indicator value; When the risk assessment result exceeds the preset threshold, the security warning module will issue a warning message, including a sound alarm, email notification or mobile phone text message push. The warning module automatically adjusts the frequency and method of warning according to the severity and urgency of the risk. For high-risk emergencies, continuous high-frequency sound alarms and instant text message push are used, and for low-risk events, regular email notifications are used; The protection strategy generation module automatically generates corresponding protection strategies based on risk assessment results and system security requirements. The protection strategies include network access control strategy adjustment, system vulnerability repair suggestions, user behavior monitoring rule optimization, and emergency response plan generation. The accuracy and effectiveness evaluation formula of the protection strategy generation is: Where P represents the evaluation value of the protection strategy, N effective Represents the number of effective protection strategies, N generated represents the total amount of protection strategies generated, γ is the response time adjustment coefficient, T response Indicates the response time of the protection strategy; The intelligent collaboration module is used to promote information exchange and collaborative work among the systems. When the data acquisition module finds abnormal data, it notifies the feature extraction module to extract key features and notifies the security warning module to prepare for warnings.
2. The computer network security analysis system based on big data according to claim 1 is characterized in that: The network traffic data collection in the data collection module adopts a distributed data collection architecture, and automatically adjusts the collection frequency according to the dynamic changes of network traffic. The collection frequency adjustment formula is: Where F represents the acquisition frequency, ω is the basic acquisition frequency value, is the adjustment coefficient, T traffic Indicates the network traffic change index value.
3. The computer network security analysis system based on big data according to claim 1 is characterized in that: The data format standardization in the data preprocessing module adopts an adaptive data format conversion algorithm, which can automatically perform format conversion according to the data format characteristics of different data sources.
4. The computer network security analysis system based on big data according to claim 1 is characterized in that: The feature extraction module is based on the feature enhancement technology of the generative adversarial network. The training process of its generator and discriminator adopts an improved adversarial training algorithm, and the training loss function is: Where L represents the training loss function value, n represents the number of training samples, yi represents the real data label, and x i represents the real data sample, D represents the discriminator network, G represents the generator network, z i represents the random noise vector, λ and μ are regularization coefficients, θ G and θ D Represent the network parameters of the generator and the discriminator respectively.
5. The computer network security analysis system based on big data according to claim 1 is characterized in that: The network infrastructure risk assessment sub-model in the risk assessment module adopts a hierarchical risk assessment method, which divides the network infrastructure into the physical layer, the network layer and the application layer, conducts risk assessment on each layer respectively, and conducts a comprehensive assessment based on the dependency relationship between the layers. The comprehensive assessment formula is: Where R infrastructure represents the risk assessment value of the network infrastructure, m represents the number of layers, and W j Represents the weight coefficient of the jth level, R layer,j Represents the risk assessment value of the jth level.
6. The computer network security analysis system based on big data according to claim 1 is characterized in that: The frequency and method of warning in the safety warning module are adjusted by using an intelligent warning strategy algorithm. The algorithm learns and optimizes according to the risk assessment results and historical warning data, and automatically adjusts the frequency and method of warning. The optimization objective function is: Where O represents the optimization objective function value, n represents the number of warning events, T i represents the response time of the ith warning event, F i represents the frequency adjustment coefficient of the i-th warning event, η is the false alarm penalty coefficient, E false Represents the number of false alarms. By minimizing the weighted sum of response time and number of false alarms, the optimal warning frequency and method adjustment can be achieved.
7. A method for applying the computer network security analysis system based on big data according to any one of claims 1 to 6, characterized in that: The following steps are involved: S1. Use the data acquisition module to comprehensively collect network-related data; S2, processing the collected data through the data preprocessing module, including data cleaning, denoising and format standardization; S3. Use the feature extraction module to extract data features, use machine learning algorithms and deep learning models for feature extraction, and combine generative adversarial network technology for feature enhancement; S4. Use the risk assessment module to conduct risk assessment, and use a multi-level and multi-dimensional risk assessment model combined with external threat intelligence to conduct a comprehensive risk assessment; S5. Take appropriate measures based on the risk assessment results.
8. The computer network security analysis method based on big data according to claim 7 is characterized in that: After the risk assessment step, the assessment results determine whether to trigger the security warning module for warning. If the risk assessment value exceeds the preset warning threshold, the security warning module is started, the warning frequency and method are adjusted according to the intelligent warning strategy algorithm, and a warning message is issued.
9. The computer network security analysis method based on big data according to claim 7 is characterized in that: When the risk assessment is completed, if there is a risk, the protection strategy generation module is used to automatically generate the corresponding protection strategy. The protection strategy generation process is optimized based on historical protection strategy data and current risk assessment results, and a protection strategy generation algorithm based on case reasoning is used to improve the accuracy and effectiveness of the protection strategy.
10. The computer network security analysis method based on big data according to claim 9 is characterized in that: The protection strategy generated by the protection strategy generation module includes network access control strategy adjustment, system vulnerability repair suggestions, and user behavior monitoring rule optimization. After the protection strategy is implemented, the protection effect is monitored and evaluated in real time, and the protection strategy is dynamically adjusted and optimized based on the evaluation results. The optimization formula is: Where S represents the protection effect evaluation value, N secure Indicates the amount of data or number of network nodes in a safe state, N total represents the total amount of data or the total number of network nodes, ξ is the adjustment time coefficient, T adjust Indicates the protection policy adjustment interval.
Citation Information
Patent Citations
Big data information network self-adaptive security protection system based on trusted computing
CN108200067A
Computer network security intelligent analysis system and method based on big data
CN117896137A