A network security situation prediction method and system
By preprocessing and analyzing the data of multiple network operation periods during the network equipment operation, network security index is generated, and the problem of lack of real-time monitoring and comprehensive impact in the existing technology is solved, more accurate network security situation assessment and early warning are achieved, and defense capabilities for network attacks are improved.
Patent Information
- Application Number
- CN202411687533.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-25
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2044-11-25
AI Technical Summary
The existing network security situation prediction methods mainly rely on the log data analysis of network security events. They lack dynamic monitoring of the real-time operating status of network equipment, making it difficult to deal with sudden network attacks, and fail to fully consider the comprehensive impact of network internal stability and external threats, resulting in insufficient accuracy of network security situation evaluation.
By continuously obtaining data of multiple network operation periods during network equipment operation, preprocessing and analysis, calculating the internal stability index and external threat index, and conducting comprehensive analysis to generate a network security index. Then, the rate of change of the network security index is analyzed, the security index for the next period is predicted, and compared with the set security threshold range to conduct security situation prediction evaluation and early warning measures.
It improves the accuracy of network security situation monitoring, promptly detects potential network risks, significantly improves the defense ability of complex and changeable network attacks, perceives potential network security threats in advance, reduces the time for passive response, and improves the initiative in network security protection.
Smart Images

Figure CN119210896B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security situation assessment, and in particular to a network security situation prediction method and system. Background Art
[0002] In today's rapid development of digital transformation, cybersecurity has become a global focus. With the widespread application of technologies such as the Internet, big data, the Internet of Things, and cloud computing, the scale and complexity of cyber attacks are increasing, causing traditional security protection methods to gradually become ineffective. Attackers continue to use new technologies and strategies to implement complex attacks such as advanced persistent threats (APTs), distributed denial of service attacks (DDoS), and ransomware, bringing huge challenges to various information systems and network infrastructure.
[0003] Existing network security defense systems mainly detect and defend based on static rules and known threat features, but their effectiveness is often limited when facing complex and ever-changing network attacks. This defense model mainly relies on the analysis of historical data, but it is difficult to cope with the ever-changing attack behaviors and unknown threats. At the same time, as attackers become increasingly intelligent, attack behaviors become more difficult to predict and prevent. Therefore, how to effectively predict network security situations, identify potential threats, and take corresponding defense measures in advance has become a key issue that needs to be solved in the field of network security.
[0004] Prior art, such as the invention patent application with announcement number: CN109302407A, discloses a network security situation prediction method, device, equipment and storage medium, the method includes obtaining log data of network security events; obtaining a strong rule set according to the log data of the network security events; and predicting network attacks according to the strong rule set. The network security situation prediction method provided by the present application can predict network attacks and improve network security by establishing a strong rule set.
[0005] Based on the above scheme, it is found that the limitations of the existing technology include at least the following problems. First, the existing network security situation prediction method mainly relies on the log data analysis of network security events, lacks dynamic monitoring of the real-time operating status of network equipment, which makes it difficult to respond in time and make accurate predictions when facing sudden network attacks, thereby increasing the risk of network equipment being attacked. Secondly, the existing method fails to fully consider the combined impact of the internal stability of the network and the external threats, and it is difficult to comprehensively evaluate the security status of the network. It is easy to ignore potential security risks and reduce the overall network protection capabilities. At the same time, when predicting changes in the network security index, the existing technology fails to combine dynamic data analysis of multiple time periods, which makes the network security situation assessment insufficiently accurate, which makes it difficult to take effective early warning and response measures before a network security incident occurs, thereby affecting the continuous and stable operation of the network. Summary of the invention
[0006] In view of the deficiencies in the prior art, the present invention provides a network security situation prediction method and system, which solves the problem that the prior network security situation prediction method mainly relies on log data analysis of network security events, lacks dynamic monitoring of the real-time operating status of network equipment, resulting in difficulty in timely response and accurate prediction when facing sudden network attacks, thereby increasing the risk of network equipment being attacked. Secondly, the prior method fails to fully consider the combined impact of internal network stability and external threats, and it is difficult to comprehensively evaluate the security status of the network. It is easy to ignore potential security risks and reduce the overall network protection capabilities. At the same time, when predicting changes in the network security index, the prior art fails to combine dynamic data analysis of multiple time periods, resulting in insufficient accuracy in network security situation assessment, which in turn makes it difficult to take effective early warning and response measures before a network security incident occurs, thereby affecting the problem of continued stable operation of the network.
[0007] To achieve the above objectives, the present invention is implemented through the following technical solutions: a network security situation prediction method, comprising the following steps: continuously acquiring network device operation data of several network operation time periods when the network device is running, and performing preprocessing; performing data analysis on the preprocessed network device operation data of each network operation time period when the network device is running, obtaining the network internal stability index and the network external threat index of each network operation time period when the network device is running, and performing comprehensive analysis to obtain the network security index of each network operation time period when the network device is running; analyzing the obtained network security indexes of several network operation time periods, obtaining several groups of network security index change rates, and predicting the network predicted security index of the next network operation time period; judging and analyzing the predicted network predicted security index of the next network operation time period and the set network security index threshold range, performing security situation prediction and evaluation based on the analysis results, and taking corresponding early warning measures.
[0008] Furthermore, the network device operation data specifically includes CPU utilization value, memory utilization value, network delay time value, network throughput value, response time value of each internal connection and connection duration value, connection establishment time of each external connection of each network external attack event, external attack duration value, network data transmission value, IP address, network bandwidth value, and response code.
[0009] Furthermore, the specific formula for calculating the network security index of each network operation period when the network device is running is as follows: ;in, For the The network security index of the network operation period, For the The network internal stability index for the network operation period, is the reliability coefficient stored in the database, For the The network external threat index for each network operation period, is the threat factor stored in the database, , , is the number of network operation time periods, is a natural constant.
[0010] Furthermore, the specific steps for obtaining the network internal stability index of each network operation time period when the network device is running are as follows: comprehensively analyze the CPU usage value, memory usage value, network delay time value, and network throughput value of each network operation time period when the network device is running, and obtain the network response degree index of each network operation time period when the network device is running; comprehensively analyze the response time value and connection duration value of each internal connection of each network operation time period when the network device is running, and obtain the connection quality index of each network operation time period when the network device is running; weighted analysis is performed on the network response degree index and connection quality index of each network operation time period when the network device is running, and obtain the network internal stability index of each network operation time period when the network device is running.
[0011] Furthermore, the specific formulas for calculating the network response index, connection quality index, and network internal stability index for each network operation period when the network device is running are as follows: ;in, When the network device is running The network responsiveness index for the network operation period, When the network device is running The CPU usage value of the network operation period, When the network device is running The memory usage value of the network running period, When the network device is running The network throughput value for the network operation period, When the network device is running The network delay time value during the network operation period, When the network device is running The connection quality index for the network operation period, When the network device is running The first The duration value of the inner connection. When the network device is running The first The response time value of the internal connection. When the network device is running The network internal stability index for the network operation period, is the response coefficient stored in the database, is the connection coefficient stored in the database, , , is the number of network operation time periods, , is the number of internal connections, is a natural constant.
[0012] Furthermore, the specific steps for obtaining the network external threat index of each network operation time period when the network device is running are as follows: combining the statistical method to identify and analyze the IP address and response code of each external connection of each network external attack event in each network operation time period when the network device is running, and obtain the number of IP address types and the number of successful attack external connections of each network external attack event in each network operation time period when the network device is running; performing mean analysis on the number of IP address types of each external connection of each network external attack event in each network operation time period when the network device is running, and obtain the network attack distribution index of each network operation time period when the network device is running; performing a comprehensive analysis on the connection establishment time and external attack duration value of each successful attack external connection of each network external attack event in each network operation time period when the network device is running, and obtain the network attack success index of each network operation time period when the network device is running; performing a comprehensive analysis on the network data transmission volume value and network bandwidth value of each external connection of each network external attack event in each network operation time period when the network device is running, and obtain the network attack intensity index of each network operation time period when the network device is running; performing a comprehensive analysis on the network attack distribution index, network attack success index and network attack intensity index of each network operation time period when the network device is running, and obtain the network external threat index of each network operation time period when the network device is running.
[0013] Furthermore, the specific formulas for calculating the network attack distribution index, network attack success index, network attack intensity index, and network external threat index for each network operation period when the network device is running are as follows: ;in, When the network device is running The network attack distribution index for each network operation period, When the network device is running The first The first type of external network attack incident The number of IP address types of external connections, When the network device is running The network attack success index for each network operation period, When the network device is running The first The first type of external network attack incident The connection establishment time of the successful external connection of the attack, When the network device is running The first The first type of external network attack incident The duration value of the external attack of the successful external connection, When the network device is running The network attack intensity index for each network operation period, When the network device is running The first The first type of external network attack incident The value of network data transmission volume for each external connection. When the network device is running The first The first type of external network attack incident The network bandwidth value of the external connection, When the network device is running The network external threat index for each network operation period, is the distribution coefficient stored in the database, is the attack efficiency coefficient stored in the database, is the intensity coefficient stored in the database, and , , is the number of network operation time periods, , is the number of types of network external attack events, , is the number of external connections outside the network, , The number of successful external connections from external attacks on the network. is a natural constant.
[0014] Furthermore, the specific steps for predicting the network prediction security index for the next network operation period are as follows: combining the weighted average method to perform mean analysis on the change rate of each group of network security indexes when the network equipment is running, and obtain the mean value of the network security index change when the network equipment is running; based on the moving exponential average method, the network security index of the last two consecutive network operation periods obtained when the network equipment is running and the mean value of the network security index change are predicted and analyzed to obtain the network security prediction index of the next network operation period when the network equipment is running; wherein, the specific formula for calculating the mean value of the network security index change and the network security prediction index when the network equipment is running is as follows: ;in, is the average value of the network security index change when the network equipment is running. When the network device is running Group network security index change rate, The first time the network device is running stored in the database The weighted coefficient of the group network security index change rate, For the Group network security index change rate, The first time the network device is running stored in the database The weighted coefficient of the rate of change of the group's network security index, and , , is the number of groups of network security index change rate, It is the network security prediction index for the next network operation period when the network equipment is running. When the network device is running The network security index of the network operation period, When the network device is running The network security index of the network operation period, , The number of network operation time periods.
[0015] Furthermore, the specific measures for predicting and evaluating the security situation based on the analysis results and taking corresponding early warning measures are as follows: if the network prediction security index of the next network operation time period when the network device is running is within the set network security index threshold range, then the network security situation of the next network operation time period is safe; if the network prediction security index of the next network operation time period when the network device is running is outside the set network security index threshold range, then the network security situation of the next network operation time period is risky, and a risk warning is issued, and relevant staff are notified at the same time.
[0016] A network security situation prediction system comprises: a data acquisition module, a data analysis module, a prediction analysis module, and an evaluation and early warning module; the data acquisition module is used to continuously acquire network device operation data of several network operation time periods when the network device is operating, and perform preprocessing; the data analysis module is used to perform data analysis on the preprocessed network device operation data of each network operation time period when the network device is operating, obtain the network internal stability index and network external threat index of each network operation time period when the network device is operating, and perform comprehensive analysis to obtain the network security index of each network operation time period when the network device is operating; the prediction analysis module is used to analyze the network security index of several network operation time periods obtained, obtain several groups of network security index change rates, and predict the network prediction security index of the next network operation time period; the evaluation and early warning module is used to judge and analyze the predicted network prediction security index of the next network operation time period with the set network security index threshold range, perform security situation prediction and evaluation based on the analysis results, and take corresponding early warning measures.
[0017] The present invention has the following beneficial effects:
[0018] (1) The network security situation prediction method pre-processes and analyzes the data of multiple network operation time periods when the network equipment is running, comprehensively evaluates the stability of the network and external threat factors, and thus generates a network security index. The network security index of each network operation time period can accurately reflect the current network security status, and predict the security index of the next time period by analyzing the change rate of the network security index. Through this prediction method, the monitoring accuracy of the network security situation can be effectively improved, potential network risks can be discovered in time and corresponding protective measures can be taken, which significantly improves the defense capability against complex and changeable network attacks.
[0019] (2) This network security situation prediction method can perceive potential network security threats in advance by combining the predicted network security index with the set network security threshold for judgment and analysis. When the network predicted security index exceeds the preset threshold range, an early warning will be automatically issued to remind managers to take necessary defensive actions. Through this active early warning mechanism, risks can be perceived in advance before an attack occurs, reducing the time of passive response and improving the initiative of network security protection, thereby ensuring the stable operation of the network.
[0020] (3) This network security situation prediction method generates a more comprehensive network internal stability index and external threat index through the analysis and processing of multi-dimensional data, ensuring a more comprehensive and objective assessment of the network status. Compared with traditional data analysis methods that rely on a small number of parameters, it provides a more accurate and reliable basis for the assessment of network security situation through the fusion of multi-source data, thereby improving the comprehensiveness and accuracy of risk identification.
[0021] (4) The network security situation prediction system realizes all-round monitoring and management of the network environment by integrating data acquisition, analysis, prediction and evaluation and early warning modules. The data acquisition module can capture the operation data of network equipment in real time to ensure the timeliness and accuracy of information. Secondly, through the data analysis module, the data can be deeply analyzed to identify the stability of the network and external threats, thereby generating a network security index, which reflects the current network security status and provides a solid foundation for subsequent predictive analysis. In addition, the predictive analysis module can predict potential security risks in advance by calculating the rate of change, so that the organization can take effective measures before the problem occurs. Finally, the threshold setting mechanism of the evaluation and early warning module ensures that when the security index exceeds the safety range, the system will automatically trigger an alarm, thereby achieving timely intervention.
[0022] Of course, any product implementing the present invention does not necessarily need to achieve all of the advantages described above at the same time. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1The present invention is a flow chart of a network security situation prediction method.
[0024] Figure 2 The present invention is a flowchart of the specific steps of obtaining the network internal stability index of each network operation period when the network equipment is running in a network security situation prediction method of the present invention.
[0025] Figure 3 This is a block diagram of a network security situation prediction system of the present invention. DETAILED DESCRIPTION
[0026] The embodiment of the present application solves the problem that the existing network security situation prediction method mainly relies on the log data analysis of network security events, lacks dynamic monitoring of the real-time operating status of network equipment, and thus makes it difficult to respond in time and make accurate predictions when facing sudden network attacks, thereby increasing the risk of network equipment being attacked. Secondly, the existing method fails to fully consider the combined impact of the internal stability of the network and the external threats, and it is difficult to comprehensively evaluate the security status of the network. It is easy to ignore potential security risks and reduce the overall network protection capabilities. At the same time, the existing technology fails to combine dynamic data analysis of multiple time periods when predicting changes in the network security index, which makes the network security situation assessment insufficiently accurate, and thus makes it difficult to take effective early warning and response measures before a network security incident occurs, thereby affecting the continuous and stable operation of the network.
[0027] The overall idea of the problem in the embodiment of this application is as follows:
[0028] First, the operation data of network devices in a specific time period is continuously obtained. These data include parameters such as CPU usage, memory usage, network delay time value, network throughput value, etc. The obtained data is preprocessed to ensure the accuracy and availability of the data. The preprocessed data is deeply analyzed to calculate the network internal stability index and external threat index of each operation period, and then the network security index is comprehensively obtained. This process helps to quantify the security status of the network, analyze the change rate of the network security index in multiple time periods, predict the network security index in the next time period, compare the prediction results with the set security threshold, conduct security situation assessment based on the analysis results, and take corresponding early warning measures to improve network security.
[0029] See also Figure 1The embodiment of the present invention provides a technical solution: a network security situation prediction method, comprising the following steps: continuously obtaining network device operation data of several network operation time periods (for example, 30 minutes) when a network device (such as a content distribution network (CDN) device) is running, and preprocessing the network device operation data of each network operation time period when the preprocessed network device is running, to obtain the network internal stability index and the network external threat index of each network operation time period when the network device is running, and to perform a comprehensive analysis to obtain the network security index of each network operation time period when the network device is running; analyzing the network security index of the obtained several network operation time periods to obtain several groups of network security index change rates (specifically, the difference between the network security index of the latter time period and the previous time period, divided by the time period), and predicting the network predicted security index of the next network operation time period; judging and analyzing the predicted network predicted security index of the next network operation time period and the set network security index threshold range, performing security situation prediction and evaluation based on the analysis results, and taking corresponding early warning measures.
[0030] The network equipment operation data specifically includes CPU utilization value, memory utilization value, network delay time value, network throughput value, response time value and connection duration value of each internal connection, connection establishment time of each external connection of each network external attack event, external attack duration value, network data transmission value, IP address, network bandwidth value and response code.
[0031] The network throughput value refers to the data transmitted between devices in the same network during the network operation period, which is obtained by using professional network monitoring software (such as Wireshark, NetFlow Analyzer).
[0032] The response time value of each internal connection is the time taken for the connection between devices or applications, such as the connection time between a server and a client, which is obtained by monitoring using network monitoring software (such as Wireshark, Nagios, PRTG, etc.).
[0033] The connection duration value of each internal connection is the length of time that the connection between devices or applications is maintained, for example, the length of time that the connection between a server and a client is maintained, which is obtained by monitoring using network monitoring software (such as Wireshark, Nagios, PRTG, etc.).
[0034] External network attack events are malicious behaviors from outside the network, which are intended to damage, interfere with or gain illegal access to systems, networks or data, and are captured by intrusion detection systems (IDS).
[0035] The connection establishment time is the time required for an external attack source to establish a connection with the network.
[0036] The external attack duration value is the time from the start of the attack to the end of the attack by the external attack source of the network. The start and end time of the attack event can be queried through the log of the security system (such as firewall, intrusion detection system), and the external attack duration value = the end time of the attack event - the start and end time of the attack event.
[0037] The response code is a numeric code indicating the server's response status to a request, and is obtained by querying the access log of the Web server.
[0038] Specifically, the specific formula for calculating the network security index of each network operation period when the network device is running is as follows: ;in, When the network device is running The network security index of the network operation period, When the network device is running The network internal stability index for the network operation period, is the reliability coefficient stored in the database, For the The network external threat index for each network operation period, is the threat factor stored in the database, , , is the number of network operation time periods, It is a natural constant, usually taken as 2.71.
[0039] It needs to be explained that , The specific acquisition process is as follows: read the network internal stability index and network external threat index of each network operation period when the network device is running, and perform mean analysis respectively to obtain the network internal reliability benchmark index and network external threat benchmark index when the network device is running, sum and analyze the network internal reliability benchmark index and network external threat benchmark index when the network device is running to obtain the network security sum value, and perform proportion analysis on the network internal reliability benchmark index and network external threat benchmark index with the network security sum value respectively, and the proportion analysis result is the corresponding coefficient.
[0040] Among them, The following table shows an example of the network security index calculation data for each network operation period:
[0041] Table 1 Example of network security index calculation data for network operation periods
[0042]
[0043] In the table, When the network device is running The network internal stability index for the network operation period, When the network device is running The network external threat index for each network operation period, is the reliability coefficient stored in the database, is the threat factor stored in the database, For the The network security index of the network operation period.
[0044] The first set of data: the network internal stability index of the first network operation period when the network equipment is running is about 0.89; the network external threat index of the first network operation period when the network equipment is running is about 0.67; the reliability coefficient stored in the database is about 0.56; the threat coefficient stored in the database is about 0.44; The network security index during the network operation period is approximately: 0.46.
[0045] The second set of data: The network internal stability index of the first network operation period when the network equipment is running is about 0.92; the network external threat index of the first network operation period when the network equipment is running is about 0.62; the reliability coefficient stored in the database is about 0.56; the threat coefficient stored in the database is about 0.44; The network security index during the network operation period is approximately: 0.42.
[0046] The third set of data: The network internal stability index of the first network operation period when the network equipment is running is about: 0.84; the network external threat index of the first network operation period when the network equipment is running is about: 0.75; the reliability coefficient stored in the database is about: 0.56; the threat coefficient stored in the database is about: 0.44; The network security index during the network operation period is approximately: 0.40.
[0047] The fourth set of data: The network internal stability index of the first network operation period when the network equipment is running is about: 0.78; the network external threat index of the first network operation period when the network equipment is running is about: 0.74; the reliability coefficient stored in the database is about: 0.56; the threat coefficient stored in the database is about: 0.44; The network security index during the network operation period is approximately: 0.38.
[0048] The fifth set of data: The network internal stability index of the first network operation period when the network equipment is running is about: 0.95; the network external threat index of the first network operation period when the network equipment is running is about: 0.65; the reliability coefficient stored in the database is about: 0.56; the threat coefficient stored in the database is about: 0.44; The network security index during the network operation period is approximately: 0.43.
[0049] In this implementation scheme, by calculating the benchmark index of internal network stability and external threats, a unified evaluation standard can be provided for different network operation periods, so that the security index of each period is comparable, which is convenient for horizontal analysis. The calculation of the network security index is combined with the actual data of internal network stability and external threats, which can more accurately reflect the true security status of the network and help decision makers identify potential risks. Secondly, through the analysis of the benchmark index and coefficient, the security strategy can be dynamically adjusted according to the real-time status of the network to cope with the rapidly changing network environment. At the same time, in the analysis process, the main factors affecting network security can be identified, thereby providing targeted improvement suggestions and measures for network security management. Finally, through clear calculation formulas and steps, the transparency of the network security assessment process is improved, which helps stakeholders understand and trust the assessment results. The establishment of the benchmark index provides a basis for subsequent network security situation monitoring and improvement, and promotes the continuous improvement of network security management.
[0050] Specifically, Figure 2 As shown, the specific steps of obtaining the network internal stability index of each network operation time period when the network device is running are as follows: comprehensively analyze the CPU usage value, memory usage value, network delay time value, and network throughput value of each network operation time period when the network device is running, and obtain the network response degree index of each network operation time period when the network device is running (i.e., measure the efficiency of the network in processing requests and transmitting data); comprehensively analyze the response time value and connection duration value of each internal connection of each network operation time period when the network device is running, and obtain the connection quality index of each network operation time period when the network device is running (i.e., the reliability of the network in processing requests); perform weighted analysis on the network response degree index and connection quality index of each network operation time period when the network device is running, and obtain the network internal stability index of each network operation time period when the network device is running.
[0051] In this implementation scheme, by analyzing the network response index, the network bottlenecks in data transmission and request processing can be identified, thereby helping network managers to optimize configuration and resource allocation, thereby improving the overall efficiency of the network so that it can meet user needs more quickly. Secondly, the evaluation of the connection quality index enables managers to promptly discover potential connection problems, such as high response time or short connections, and then help the team take measures in advance to reduce the risk of connection interruption or failure, and ensure the continuity and stability of network services. Finally, a comprehensive analysis of the network response index and the connection quality index can provide a strong basis for troubleshooting. For example, if the network response index is low and the connection quality index is high, it may be a network congestion problem, which enables managers to quickly locate the source of the fault, reduce troubleshooting time, and increase response speed, thereby improving user experience.
[0052] Specifically, the specific formulas for calculating the network response index, connection quality index, and network internal stability index for each network operation period when the network device is running are as follows: ;in, When the network device is running The network responsiveness index for the network operation period, When the network device is running The CPU usage value of the network operation period, When the network device is running The memory usage value of the network running period, When the network device is running The network throughput value for the network operation period, When the network device is running The network delay time value during the network operation period, When the network device is running The connection quality index for the network operation period, When the network device is running The first The duration value of the inner connection. When the network device is running The first The response time value of the internal connection. When the network device is running The network internal stability index for the network operation period, is the response coefficient stored in the database, is the connection coefficient stored in the database, , , is the number of network operation time periods, , is the number of internal connections, It is a natural constant, usually taken as 2.71.
[0053] It needs to be explained that , The specific acquisition process is as follows: read the network response index and connection quality index of each network operation period when the network device is running, and perform mean analysis respectively to obtain the mean value of the network response index and the mean value of the connection quality index when the network device is running, sum the mean value of the network response index and the mean value of the connection quality index when the network device is running, and perform proportion analysis on the mean value of the network response index and the mean value of the connection quality index with the network reliability sum, and the proportion analysis result is the corresponding coefficient.
[0054] In this implementation scheme, by performing mean analysis on the network response index and the connection quality index, the performance of network equipment in different operating periods can be fully understood, thereby helping network managers to identify performance bottlenecks in a timely manner and then optimize them in a targeted manner. The mean and proportion analysis results provide important data support for network management, allowing managers to make scientific decisions based on actual data. For example, by analyzing resource usage during peak hours, bandwidth allocation and device configuration can be effectively adjusted to meet user needs. Secondly, by analyzing the relationship between CPU and memory usage and network throughput and latency, managers can identify resource bottlenecks, perform reasonable resource allocation and scheduling, thereby improving network operation efficiency and helping to avoid resource waste and ensure network stability under high load. At the same time, calculating network reliability and performing proportion analysis can help network managers identify key factors affecting network stability. By performing proportion analysis regularly, network management can establish a long-term performance monitoring mechanism, which can then help to timely discover and adjust network configuration to adapt to changing user needs and network environment, and ensure efficient operation of the network. Finally, when evaluating network performance, mean and proportion analysis can reveal potential risk points, allowing managers to take measures in advance to reduce the probability of failures and reduce the risk of network interruption.
[0055] Specifically, the specific steps for obtaining the network external threat index for each network operation time period when the network device is running are as follows: combine the statistical method to identify and analyze the IP address and response code of each external connection of each network external attack event in each network operation time period when the network device is running, and obtain the number of IP address types and the number of successful external connections for each network external attack event in each network operation time period when the network device is running; perform mean analysis on the number of IP address types for each external connection of each network external attack event in each network operation time period when the network device is running, and obtain the network attack distribution index for each network operation time period when the network device is running; A comprehensive analysis is conducted on the connection establishment time and external attack duration values of each successful external connection of the external attack event to obtain the network attack success index (i.e., a measure of the efficiency of attack success) for each network operation time period when the network device is running; a comprehensive analysis is conducted on the network data transmission volume and network bandwidth values of each external connection of each network external attack event in each network operation time period when the network device is running to obtain the network attack intensity index for each network operation time period when the network device is running; a comprehensive analysis is conducted on the network attack distribution index, network attack success index, and network attack intensity index for each network operation time period when the network device is running to obtain the network external threat index for each network operation time period when the network device is running.
[0056] Among them, the specific process of identifying and analyzing the IP address of each external connection of each network external attack event in each network operation period when the network device is running in combination with the statistical method is: reading the IP address of each external connection of each network external attack event in each network operation period when the network device is running, classifying the same IP addresses into one type, and using the statistical method to count the number of IP address types.
[0057] The specific process of identifying and analyzing the response code of each external connection of each network external attack event in each network operation period when the network device is running in combination with the statistical method is: read the response code of each external connection of each network external attack event in each network operation period when the network device is running, and identify the series of each response code. For example, if the response code is a 2xx series or a 3xx series, the number of external connections is regarded as a successful attack, and the number of successful external connections is obtained in combination with the statistical method.
[0058] In this implementation scheme, by carefully analyzing the external connection data in each network operation period, it is possible to comprehensively identify and evaluate the external attack threats faced by network devices, thereby helping to timely discover potential security vulnerabilities and abnormal activities, and by combining the statistical method to identify and analyze IP addresses and response codes, it is possible to quantify the impact of external attack events, thereby providing data support for network security management, making decisions more scientific and targeted. Secondly, by analyzing the number of different IP addresses and the number of successful attack connections, common attack patterns and sources can be identified, which is crucial for formulating targeted defense strategies and improving network security. At the same time, weighted analysis of network attack distribution index, success index and intensity index can provide dynamic threat assessment. Network managers can adjust security strategies in a timely manner according to changes in these indexes and enhance the network's defense capabilities. Finally, by identifying the efficiency of successful attacks, network managers can evaluate the effectiveness of defense measures, which in turn helps to optimize security strategies and improve the speed and efficiency of response to external threats, thereby better protecting the network environment. By continuously monitoring the external threat index, network managers can identify long-term trends, understand the cyclical changes of attacks, and provide a reference for future security strategies.
[0059] Specifically, the specific formulas for calculating the network attack distribution index, network attack success index, network attack intensity index, and network external threat index for each network operation period when the network device is running are as follows: ;in, When the network device is running The network attack distribution index for each network operation period, When the network device is running The first The first type of external network attack incident The number of IP address types of external connections, When the network device is running The network attack success index for each network operation period, When the network device is running The first The first type of external network attack incident The connection establishment time of the successful external connection of the attack, When the network device is running The first The first type of external network attack incident The duration value of the external attack of the successful external connection, When the network device is running The network attack intensity index for each network operation period, When the network device is running The first The first type of external network attack incident The value of network data transmission volume for each external connection. When the network device is running The first The first type of external network attack incident The network bandwidth value of the external connection, When the network device is running The network external threat index for each network operation period, is the distribution coefficient stored in the database, is the attack efficiency coefficient stored in the database, is the intensity coefficient stored in the database, and , , is the number of network operation time periods, , is the number of types of network external attack events, , is the number of external connections outside the network, , The number of successful external connections from external attacks on the network. It is a natural constant, usually taken as 2.71.
[0060] It needs to be explained that , , The specific acquisition process is as follows: obtain the network attack distribution index, network attack success index, and network attack intensity index of each network operation period when the network equipment is running, and perform mean analysis on them respectively to obtain the mean of the network attack distribution index, the mean of the network attack success index, and the mean of the network attack intensity index; sum and analyze the mean of the network attack distribution index, the mean of the network attack efficiency, and the mean of the network attack intensity to obtain the network external threat and value; and perform proportion analysis on the mean of the network attack distribution index, the mean of the network attack success index, and the mean of the network attack intensity index with the network external threat and value, respectively, and the proportion analysis results are the corresponding coefficients.
[0061] In this implementation scheme, by calculating the network attack distribution index, attack success index and attack intensity index, the attack risk faced by network equipment can be fully quantified, thereby providing a solid data foundation for network security management, allowing managers to clearly understand the security situation, and the calculation of the network attack success index and attack intensity index can evaluate the actual impact of the attack on the network, helping managers to identify the effectiveness of the attack and its consumption of network resources, which is crucial for optimizing defense measures. Secondly, mean analysis and proportion analysis provide data-driven decision support for network security management. By analyzing different indexes, managers can formulate more reasonable security strategies based on actual data, thereby effectively improving the network's defense capabilities and Real-time calculation of the network external threat index can help network managers discover security risks in a timely manner and dynamically adjust defense strategies. At the same time, through the analysis of various network attack incidents, common attack patterns and sources can be identified, which provides an important basis for subsequent security defense measures and helps to formulate more effective defense strategies. In addition, by evaluating the intensity and success rate of network attacks, managers can optimize the configuration of network resources to ensure sufficient defense capabilities during high-risk periods and avoid unnecessary waste of resources. Finally, through continuous monitoring and analysis of external threats, a long-term protection mechanism can be built for the security line of network equipment, which in turn helps enterprises maintain stability and security in the face of various security challenges that may arise in the future.
[0062] Specifically, the specific steps for predicting the network prediction security index for the next network operation period are as follows: perform mean analysis on the change rate of each group of network security indexes when the network equipment is running by combining the weighted average method to obtain the mean value of the network security index change when the network equipment is running; perform prediction analysis on the network security index of the last two consecutive network operation periods obtained when the network equipment is running and the mean value of the network security index change based on the moving exponential average method to obtain the network security prediction index of the next network operation period when the network equipment is running; wherein, the specific formula for calculating the mean value of the network security index change and the network security prediction index when the network equipment is running is as follows: ;in, is the average value of the network security index change when the network equipment is running. When the network device is running Group network security index change rate, The first time the network device is running stored in the database The weighted coefficient of the group network security index change rate, For the Group network security index change rate, The first time the network device is running stored in the database The weighted coefficient of the rate of change of the group's network security index, and , , is the number of groups of network security index change rate, It is the network security prediction index for the next network operation period when the network equipment is running. When the network device is running The network security index of the network operation period, When the network device is running The network security index of the network operation period, , The number of network operation time periods.
[0063] It needs to be explained that , The specific calculation process is: , The change rate of the network security index of each group is summed and analyzed to obtain the The network security index change rate and value are then , The change rates of the network security index of the first The change rate and value of the group network security index are analyzed by proportion, and the result of the proportion analysis is the corresponding weighted coefficient.
[0064] In this implementation scheme, by performing mean analysis on the rate of change of the network security index, the security situation of network equipment can be grasped more accurately, so that managers can identify potential risks in advance and enhance the effectiveness of defense strategies. In combination with the analysis process of the weighted average method and the moving exponential average method, data-based decision support is provided for network security management, so that managers can make scientific and reasonable security management decisions based on historical data and change trends. Secondly, by calculating the mean value of the network security index change in real time, network managers can dynamically adjust defense measures to cope with the ever-changing network threats, and predictive analysis can help managers reasonably allocate security resources to ensure sufficient security protection capabilities during high-risk periods, avoid resource waste and improve network operation efficiency. In addition, by analyzing the network security index in different time periods, managers can identify attack patterns and trends, thereby optimizing security strategies and response mechanisms and enhancing network security defense lines. At the same time, by continuously monitoring and analyzing the network security index, managers can evaluate the effectiveness of current security measures and make corresponding adjustments to adapt to new security challenges. Finally, through regular predictive analysis, long-term plans can be made for future security strategies to ensure flexibility and adaptability in the face of future risks.
[0065] Specifically, the specific measures for predicting and evaluating the security situation based on the analysis results and taking corresponding early warning measures are as follows: if the network prediction security index of the next network operation period when the network device is running is within the set network security index threshold range, the network security situation of the next network operation period will be safe, and regular monitoring will continue to maintain normal network operation. At the same time, the network will continue to collect data and analyze it in real time, and perform periodic inspections to ensure that potential threats will not appear in the future; if the network prediction security index of the next network operation period when the network device is running is outside the set network security index threshold range, the network security situation of the next network operation period will be risky, and a risk warning will be issued, and relevant staff will be notified. The specific measures are: improve network protection strategies, increase the sensitivity of firewall rules, network intrusion detection systems (IDS) or intrusion prevention systems (IPS), or temporarily restrict external access. In addition, notify the security team and initiate emergency response, further check potential threat sources (such as malicious attacks, network vulnerabilities), isolate and process them, and implement more stringent network monitoring, enable more real-time monitoring tools, analyze abnormal traffic or abnormal behavior, and ensure that the threat will not expand further.
[0066] In this implementation scheme, by setting the network prediction security index threshold, potential security risks can be identified in time, so as to respond quickly, thereby effectively reducing the incidence of network security incidents and protecting the integrity of data. Secondly, according to the changes in the network security index, managers can flexibly adjust security policies, such as enhancing the sensitivity of firewall rules or intrusion detection systems, thereby ensuring that network protection measures always match the current risk level. In addition, in a risky state, immediately notifying the security team and initiating an emergency response can quickly identify and isolate the source of the threat, thereby preventing the potential attack from spreading, which is crucial to maintaining the stability of the network environment. Continuous data collection and real-time analysis provide a basis for the assessment of the security situation, enabling managers to make more scientific decisions based on the latest data and reduce the risks caused by information lags. Finally, notifying the security team and responding in a coordinated manner when risks are discovered will help to enhance security awareness within the organization, promote cooperation between teams, and improve overall security protection capabilities.
[0067] See also Figure 3The embodiment of the present invention provides a technical solution: a network security situation prediction system, comprising: a data acquisition module, a data analysis module, a prediction analysis module, and an evaluation and early warning module; the data acquisition module is used to continuously acquire network device operation data of several network operation time periods when the network device is running, and perform preprocessing; the data analysis module is used to perform data analysis on the network device operation data of each network operation time period when the network device is running after preprocessing, obtain the network internal stability index and network external threat index of each network operation time period when the network device is running, and perform comprehensive analysis to obtain the network security index of each network operation time period when the network device is running; the prediction analysis module is used to analyze the network security index of several network operation time periods obtained, obtain several groups of network security index change rates, and predict the network prediction security index of the next network operation time period; the evaluation and early warning module is used to judge and analyze the predicted network prediction security index of the next network operation time period with the set network security index threshold range, perform security situation prediction evaluation based on the analysis results, and take corresponding early warning measures.
[0068] In summary, this application has at least the following effects:
[0069] By preprocessing and analyzing data from multiple network operation time periods when network equipment is running, and comprehensively evaluating the stability of the network's internal stability and external threat factors, a network security index is generated. The network security index of each network operation time period can accurately reflect the current network's security status, and by analyzing the rate of change of the network security index, the security index of the next time period is predicted. This prediction method can effectively improve the monitoring accuracy of the network security situation, timely discover potential network risks and take corresponding protective measures, significantly improving the defense capabilities against complex and changeable network attacks.
[0070] By combining the predicted network security index with the set network security threshold for judgment and analysis, potential network security threats can be perceived in advance. When the network predicted security index exceeds the preset threshold range, an early warning will be automatically issued to remind managers to take necessary defensive actions. Through this active early warning mechanism, risks can be perceived in advance before an attack occurs, reducing the time for passive response, and improving the initiative of network security protection, thereby ensuring the stable operation of the network.
[0071] By analyzing and processing multi-dimensional data, a more comprehensive network internal stability index and external threat index are generated to ensure a more comprehensive and objective assessment of the network status. Compared with traditional data analysis methods that rely on a small number of parameters, multi-source data fusion provides a more accurate and reliable basis for the assessment of network security situation, thereby improving the comprehensiveness and accuracy of risk identification.
[0072] By integrating data acquisition, analysis, prediction and evaluation and early warning modules, all-round monitoring and management of the network environment is achieved. The data acquisition module can capture the operating data of network equipment in real time to ensure the timeliness and accuracy of information. Secondly, through the data analysis module, in-depth analysis of these data can identify the stability of the internal network and external threats, thereby generating a network security index, which reflects the current network security status and provides a solid foundation for subsequent predictive analysis. In addition, the predictive analysis module can predict potential security risks in advance by calculating the rate of change, allowing organizations to take effective measures before problems occur. Finally, the threshold setting mechanism of the evaluation and early warning module ensures that when the security index exceeds the safety range, the system will automatically trigger an alarm, thereby achieving timely intervention.
[0073] Although the preferred embodiments of the present invention have been described, those skilled in the art may make other changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.
[0074] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.
Claims
1. A network security situation prediction method, characterized in that: The following steps are involved: Continuously obtain network device operation data of several network operation time periods when the network device is running, wherein the network device operation data specifically includes a CPU usage value, a memory usage value, a network delay time value, a network throughput value, a response time value and a connection duration value of each internal connection, a connection establishment time of each external connection of each network external attack event, an external attack duration value, a network data transmission volume value, an IP address, a network bandwidth value, and a response code, and perform preprocessing; The network equipment operation data of each network operation period when the preprocessed network equipment is running are analyzed respectively to obtain the network internal stability index and network external threat index of each network operation period when the network equipment is running. A comprehensive analysis is performed to obtain the network security index of each network operation period when the network equipment is running. The calculation formula is as follows: ; in, , , The network equipment is running. The network security index, network internal stability index, and network external threat index of each network operation period. , They are the reliability coefficient and threat coefficient stored in the database, , , is the number of network operation time periods, is a natural constant; The specific steps for obtaining the network internal stability index for each network operation period when the network device is running are as follows: Comprehensively analyze the CPU usage value, memory usage value, network delay time value, and network throughput value of each network operation period when the network device is running, and obtain the network response degree index of each network operation period when the network device is running; Comprehensively analyzing the response time value and the connection duration value of each internal connection in each network operation period when the network device is running, and obtaining the connection quality index of each network operation period when the network device is running; Performing weighted analysis on the network response index and the connection quality index of each network operation period when the network device is operating, and obtaining the network internal stability index of each network operation period when the network device is operating; The specific steps to obtain the network external threat index for each network operation period when the network device is running are as follows: Combined with the statistical method, the IP address and response code of each external connection of each network external attack event in each network operation period when the network device is running are identified and analyzed, and the number of IP address types and the number of successful external connections of each network external attack event in each network operation period when the network device is running are obtained; The specific process of identifying and analyzing the IP address of each external connection of each network external attack event in each network operation period when the network device is running in combination with the statistical method is as follows: reading the IP address of each external connection of each network external attack event in each network operation period when the network device is running, classifying the same IP addresses into one type, and counting the number of IP address types in combination with the statistical method; Performing mean analysis on the number of types of IP addresses of each external connection for each network external attack event in each network operation period when the network device is running, and obtaining a network attack distribution index for each network operation period when the network device is running; Comprehensively analyze the connection establishment time and external attack duration value of each successful external connection of each network external attack event in each network operation period when the network device is running, and obtain the network attack success index in each network operation period when the network device is running; Comprehensively analyze the network data transmission volume value and network bandwidth value of each external connection of each network external attack event in each network operation period when the network device is running, and obtain the network attack intensity index of each network operation period when the network device is running; Comprehensively analyze the network attack distribution index, network attack success index, and network attack intensity index of each network operation period when the network device is running, and obtain the network external threat index of each network operation period when the network device is running Comprehensively analyze the network security indexes of several network operation periods, obtain several groups of network security index change rates, and predict the network security index of the next network operation period. The specific steps are as follows: Combined with the weighted average method, the change rate of each group of network security index when the network equipment is running is analyzed, and the mean value of the network security index change when the network equipment is running is obtained; Based on the moving exponential average method, the network security index of the last two consecutive network operation periods when the network device is running and the average value of the network security index change are predicted and analyzed to obtain the network security prediction index of the next network operation period when the network device is running; The specific formulas for calculating the mean change of the network security index and the network security prediction index during the operation of network equipment are as follows: ; in, is the average value of the network security index change when the network equipment is running. When the network device is running Group network security index change rate, The first time the network device is running stored in the database The weighted coefficient of the group network security index change rate, For the Group network security index change rate, The first time the network device is running stored in the database The weighted coefficient of the rate of change of the group's network security index, and , , is the number of groups of network security index change rate, It is the network security prediction index for the next network operation period when the network equipment is running. When the network device is running The network security index of the network operation period, When the network device is running The network security index of the network operation period, , is the number of network operation time periods; The predicted network security index for the next network operation period is compared with the set network security index threshold range, and a security situation prediction assessment is performed based on the analysis results, and corresponding early warning measures are taken.
2. The network security situation prediction method according to claim 1, characterized in that: The specific formulas for calculating the network response index, connection quality index, and network internal stability index for each network operation period when the network equipment is running are as follows: ; in, When the network device is running The network responsiveness index for the network operation period, When the network device is running The CPU usage value of the network operation period, When the network device is running The memory usage value of the network running period, When the network device is running The network throughput value for the network operation period, When the network device is running The network delay time value during the network operation period, When the network device is running The connection quality index for the network operation period, When the network device is running The first The duration value of the inner connection. When the network device is running The first The response time value of the internal connection. When the network device is running The network internal stability index for the network operation period, is the response coefficient stored in the database, is the connection coefficient stored in the database, , , is the number of network operation time periods, , is the number of internal connections, is a natural constant.
3. The network security situation prediction method according to claim 1, characterized in that: The specific formulas for calculating the network attack distribution index, network attack success index, network attack intensity index, and network external threat index for each network operation period when the network equipment is running are as follows: ; in, When the network device is running The network attack distribution index for each network operation period, When the network device is running The first The first type of external network attack incident The number of IP address types of external connections, When the network device is running The network attack success index for each network operation period, When the network device is running The first The first type of external network attack incident The connection establishment time of the successful external connection of the attack, When the network device is running The first The first type of external network attack incident The duration value of the external attack of the successful external connection, When the network device is running The network attack intensity index for each network operation period, When the network device is running The first The first type of external network attack incident The value of network data transmission volume for each external connection. When the network device is running The first The first type of external network attack incident The network bandwidth value of the external connection, When the network device is running The network external threat index for each network operation period, is the distribution coefficient stored in the database, is the attack efficiency coefficient stored in the database, is the intensity coefficient stored in the database, and , , is the number of network operation time periods, , is the number of types of network external attack events, , is the number of external connections outside the network, , The number of successful external connections from external attacks on the network. is a natural constant.
4. The network security situation prediction method according to claim 1, characterized in that: The specific measures for conducting security situation prediction and assessment based on the analysis results and taking corresponding early warning measures are as follows: If the predicted network security index of the next network operation period when the network device is running is within the set network security index threshold range, the network security situation of the next network operation period is in a safe state; If the predicted network security index of the next network operation period when the network equipment is running is outside the set network security index threshold range, the network security situation of the next network operation period will be at risk, and a risk warning will be issued, and relevant personnel will be notified.
5. A network security situation prediction system, using the network security situation prediction method according to any one of claims 1 to 4, characterized in that: include: Data acquisition module, data analysis module, prediction analysis module, and evaluation and early warning module; The data acquisition module is used to continuously acquire network device operation data of several network operation time periods when the network device is running, and perform preprocessing; The data analysis module is used to perform data analysis on the preprocessed network device operation data of each network operation period when the network device is running, obtain the network internal stability index and network external threat index of each network operation period when the network device is running, and perform comprehensive analysis to obtain the network security index of each network operation period when the network device is running; The prediction and analysis module is used to analyze the network security indexes of the obtained network operation periods, obtain several groups of network security index change rates, and predict the network prediction security index of the next network operation period; The evaluation and early warning module is used to judge and analyze the predicted network security index of the next network operation period and the set network security index threshold range, perform security situation prediction and evaluation based on the analysis results, and take corresponding early warning measures.
Citation Information
Patent Citations
Network security situation prediction method, device, equipment and storage medium
CN109302407A
Network security situation analysis method, device and equipment, and computer storage medium
CN108092985A
Network security situation prediction system based on artificial intelligence
CN108429767A