Network Security Risk Control Method, Device and Electronic Device Based on Cloud Computing

Through deep learning technology, feature extraction and correlation analysis of network attack alarm information, system log data and user login behavior data collected by cloud computing platforms, and network security risk level tags are generated, solving the problem of a large number of low-risk alarms and false alarms in the industrial Internet, and achieving efficient alarm processing and real-time security threat identification.

CN119276577BActive Publication Date: 2025-06-20HUNAN QINGMU INTELLIGENT TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411412733.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-11
Publication Date
2025-06-20
Estimated Expiration
2044-10-11

AI Technical Summary

Technical Problem

In the industrial Internet, network security equipment often generates a large number of low-risk alarms and false alarms during the detection process, resulting in delayed response to potential threats.

Method used

By obtaining historical cyber attack alarm information, system log data and user login behavior data collected by the cloud computing platform, deep learning technology is used to perform feature extraction and correlation analysis, and network security risk level tags are generated to identify potential security threats.

Benefits of technology

It reduces low-risk alarms and false alarms, optimizes alarm processing efficiency, enhances the interpretability and transparency of the system, and improves the real-time and scalability of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119276577B_ABST
    Figure CN119276577B_ABST
Patent Text Reader

Abstract

This application relates to the field of network security. Specifically, it discloses a network security risk control method, device, and electronic device based on cloud computing. First, it obtains historical network attack warning information, system log data, and user login behavior data collected by the cloud computing platform. Then, using deep learning technology, it performs feature extraction and correlation analysis on the three. Finally, through a classifier, it obtains a classification result to obtain a network security risk level label, thereby identifying potential security threats, reducing low-risk warnings and false alarms, and further optimizing the warning processing efficiency, enhancing the interpretability and transparency of the system, and improving the real-time performance and scalability of the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security, and more specifically, to a network security risk control method, apparatus, and electronic device based on cloud computing. Background Art

[0002] Traditionally, industrial control systems are relatively isolated from external networks, which provides basic security protection for the systems. However, with the popularization of the industrial Internet, the openness of the network environment exposes these systems to potential network attacks, posing significant security risks.

[0003] To address the increasingly serious network security threats, intrusion detection systems (IDS), web application firewalls (WAF), and other network security devices are usually deployed in the industrial Internet. These devices are designed to monitor network traffic, detect abnormal activities, and prevent potential attacks. In addition, network security analysts are responsible for monitoring, analyzing, and processing the massive alarms generated by the systems and devices. However, network security devices often generate a large number of low-risk alarms and false alarms during the detection process. Moreover, due to the large number of alarms, it is difficult for analysts to process each alarm one by one, resulting in a response delay for potential threats.

[0004] Therefore, there is a need for a network security risk control method, apparatus, and electronic device based on cloud computing. Summary of the Invention

[0005] To solve the above technical problems, the present application is proposed. Embodiments of the present application provide a network security risk control method, apparatus, and electronic device based on cloud computing. First, historical network attack alarm information, system log data, and user login behavior data collected by a cloud computing platform are obtained. Then, deep learning technology is used to perform feature extraction and correlation analysis on the three. Finally, a classification result is obtained through a classifier to obtain a network security risk level label, so as to identify potential security threats, reduce low-risk alarms and false alarms, and further optimize the alarm processing efficiency, enhance the interpretability and transparency of the system, and improve the real-time performance and scalability of the system.

[0006] According to one aspect of the present application, there is provided a network security risk control method based on cloud computing, which includes:

[0007] Obtain historical network attack alarm information, system log data, and user login behavior data collected by a cloud computing platform;

[0008] Extract an attack pattern recognition correlation feature vector and a user login behavior data correlation feature vector from the historical network attack alarm information, the system log data, and the user login behavior data collected by the cloud computing platform;

[0009] Based on the associated feature vector of the attack pattern recognition and the associated feature vector of the user login behavior data, a network security risk level label is obtained.

[0010] According to another aspect of the present application, there is provided a network security risk control device based on cloud computing, which includes:

[0011] A network security risk data acquisition module, configured to acquire historical network attack warning information, system log data, and user login behavior data collected by a cloud computing platform;

[0012] A network security risk data processing module, configured to extract an attack pattern recognition associated feature vector and a user login behavior data associated feature vector from the historical network attack warning information, the system log data, and the user login behavior data collected by the cloud computing platform;

[0013] A network security risk level label classification module, configured to obtain a network security risk level label based on the attack pattern recognition associated feature vector and the user login behavior data associated feature vector.

[0014] According to still another aspect of the present application, there is provided an electronic device, including: a processor; and a memory, in which computer program instructions are stored, and when the computer program instructions are run by the processor, the processor is caused to execute the above-mentioned network security risk control device based on cloud computing.

[0015] Compared with the prior art, a network security risk control method, device, and electronic device based on cloud computing provided by the present application first acquire historical network attack warning information, system log data, and user login behavior data collected by a cloud computing platform, then use deep learning technology to perform feature extraction and correlation analysis on the three, and finally obtain a classification result through a classifier to obtain a network security risk level label, so as to identify potential security threats, reduce low-risk warnings and false alarms, and further optimize the alarm processing efficiency, enhance the interpretability and transparency of the system, and improve the real-time performance and scalability of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] By describing the embodiments of the present application in more detail in conjunction with the drawings, the above and other objects, features, and advantages of the present application will become more obvious. The drawings are used to provide a further understanding of the embodiments of the present application, and constitute a part of the specification, and are used to explain the present application together with the embodiments of the present application, and do not constitute a limitation to the present application. In the drawings, the same reference numerals generally represent the same components or steps.

[0017] Figure 1 It is a flowchart of a network security risk control method based on cloud computing according to an embodiment of the present application.

[0018] Figure 2 It is a flowchart for extracting features from the historical network attack warning information to obtain the semantic association feature vector of the historical network attack warning information text in the network security risk control method based on cloud computing according to an embodiment of the present application.

[0019] Figure 3 It is a flowchart for extracting features from the system log data to obtain the semantic understanding feature vector of the system log data segment information in the network security risk control method based on cloud computing according to an embodiment of the present application.

[0020] Figure 4 It is a flowchart for extracting features from the user login behavior data to obtain the associated feature vector of the user login behavior data in the network security risk control method based on cloud computing according to an embodiment of the present application.

[0021] Figure 5 It is a block diagram schematic of a network security risk control device based on cloud computing according to an embodiment of the present application.

[0022] Figure 6 It is a structural diagram of an exemplary hardware architecture of a computing device for a network security risk control method and device based on cloud computing according to an embodiment of the present application. Detailed implementation manners

[0023] Various exemplary embodiments, features, and aspects of the present application will be described in detail below with reference to the accompanying drawings. The same reference numerals in the drawings denote elements having the same or similar functions. Although various aspects of the embodiments are shown in the drawings, the drawings do not have to be drawn to scale unless otherwise specified.

[0024] The special term "exemplary" here means "serving as an example, embodiment, or illustration". Any embodiment described as "exemplary" here does not have to be construed as superior to or better than other embodiments.

[0025] In addition, for a better description of the present application, numerous specific details are given in the following detailed implementation manners. Those skilled in the art should understand that the present application can also be implemented without some of these specific details. In some instances, methods, means, elements, and circuits well known to those skilled in the art are not described in detail so as to highlight the gist of the present application.

[0026] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of this application, "a plurality of" means two or more unless otherwise specifically defined.

[0027] Figure 1 FIG. is a flowchart of a network security risk control method based on cloud computing according to an embodiment of this application. As Figure 1 shown, the network security risk control method based on cloud computing according to an embodiment of this application includes: S110, obtaining historical network attack alarm information, system log data, and user login behavior data collected by a cloud computing platform; S120, extracting an attack pattern recognition correlation feature vector and a user login behavior data correlation feature vector from the historical network attack alarm information, the system log data, and the user login behavior data collected by the cloud computing platform; S130, obtaining a network security risk level label based on the attack pattern recognition correlation feature vector and the user login behavior data correlation feature vector.

[0028] In the above network security risk control method based on cloud computing, in step S110, historical network attack alarm information, system log data, and user login behavior data collected by a cloud computing platform are obtained. It should be understood that traditionally, there is a strong isolation between industrial control systems and external networks, which provides basic security protection for the systems. However, with the rapid development of the industrial Internet, this isolation state has been broken, and the network environment has become more open, resulting in these systems facing potential network attack risks and bringing serious security hazards. To cope with the increasing network security threats, network security devices such as intrusion detection systems (IDSs) and web application firewalls (WAFs) are usually deployed in the industrial Internet. The main functions of these devices are to monitor network traffic, identify abnormal behaviors, and prevent potential attacks. At the same time, network security analysts are responsible for monitoring and processing a large number of alarms generated by the systems and devices. However, network security devices often generate a large number of low-risk alarms and false alarms during the detection process. Due to the large number of alarms, it is difficult for analysts to process them one by one, which leads to a response delay for potential threats. Therefore, in the technical solution of this application, historical network attack alarm information, system log data, and user login behavior data collected by a cloud computing platform are obtained, and combined with deep learning technology, by generating a network security risk level label, potential security threats can be effectively identified, low-risk alarms and false alarms can be reduced. This will optimize the efficiency of alarm processing, improve the interpretability and transparency of the system, and at the same time enhance the real-time response ability and scalability of the system.

[0029] Specifically, historical network attack alert information can reveal the frequency, type, and source of attacks, thereby identifying attack patterns and trends. System log data provides a detailed record of the system's operating status and events. These logs include information such as user operations, system errors, and application exceptions, which can help the security team track system activities and identify abnormal behaviors. User login behavior data is an important basis for understanding user access patterns and behaviors. By monitoring the user's login time, location, and device information, the security team can identify abnormal login behaviors, such as access from unusual locations or logins during non-working hours. Such behaviors may indicate account theft or internal threats. Combining these data for comprehensive analysis can improve the response speed and effectiveness of security incidents and enable timely measures to be taken.

[0030] In the above-mentioned network security risk control method based on cloud computing, in step S120, extract the attack pattern recognition correlation feature vector and the user login behavior data correlation feature vector from the historical network attack alert information, the system log data, and the user login behavior data collected by the cloud computing platform. In this way, by extracting the correlation feature vectors of attack pattern recognition and user login behavior from the data collected by the cloud computing platform to construct a feature vector model, machine learning algorithms can be used for real-time anomaly detection and attack prediction. This intelligent analysis not only improves the efficiency of security monitoring but also reduces the need for human intervention, thus accelerating the response speed.

[0031] In a specific embodiment of the present application, step S120 includes: extracting features from the historical network attack alert information to obtain the historical network attack alert information text semantic correlation feature vector; extracting features from the system log data to obtain the system log data segment information semantic understanding feature vector; correlating the historical network attack alert information text semantic correlation feature vector and the system log data segment information semantic understanding feature vector to obtain the attack pattern recognition correlation feature vector; extracting features from the user login behavior data to obtain the user login behavior data correlation feature vector.

[0032] It should be understood that historical network attack alert information usually contains a large amount of text data, involving multi-dimensional information such as attack type, time, source IP, and target system. Through feature extraction, this information can be transformed into structured feature vectors. Among them, the structured representation of feature vectors helps to improve data processing efficiency, reduce the time and resources required for manual analysis, and ensure a quick response to potential threats. Considering that different network attack alerts may use different description methods, by extracting semantic correlation feature vectors, the similarities and correlations between these alerts can be identified.

[0033] Furthermore, the log data generated by modern systems is huge and complex, covering various events, operations, and exception information. These logs usually exist in text form and contain multi-dimensional information such as timestamps, event types, source addresses, and target addresses. That is, system logs often contain highly technical terms and descriptions, and ordinary text analysis may not be able to capture their deep meanings. By extracting semantic feature vectors, the key events in the logs and their context relationships can be better identified. For example, when dealing with security events, the feature vectors can help identify the relationships between a specific event and other related events. For instance, the operations performed by a certain user at a specific time may be directly related to subsequent system exceptions. This in-depth understanding helps quickly locate problems and perform effective troubleshooting.

[0034] Even further, the network security environment is complex and ever-changing, and a single data source often cannot comprehensively reflect the security situation. Historical network attack alert information provides specific descriptions of attack events, while system log data records the internal operation behaviors and exception situations of the system. By correlating the feature vectors of these two types of data, a richer and more multi-dimensional security situation model can be constructed. This comprehensive analysis helps more clearly identify potential attack patterns and vulnerabilities, and improves the ability to identify network threats.

[0035] In particular, by analyzing the user's login history, features such as login time, login location, device type, and login frequency can be extracted. These features can help the security team discover situations that do not conform to the normal behavior patterns of users. For example, a user logs in from a strange location late at night, or the same account is logged in multiple times by different devices within a very short period. This anomaly detection ability is the key to preventing account theft and other malicious activities. By correlating the feature vectors, the model can learn the differences between normal login behaviors and abnormal behaviors, and thus improve the prediction accuracy of future login behaviors.

[0036] Figure 2 It is a flowchart for extracting features from the historical network attack alert information to obtain the text semantic association feature vector of the historical network attack alert information in the network security risk control method based on cloud computing according to the embodiments of the present application. As Figure 2As shown, in a specific embodiment of the present application, feature extraction is performed on the historical network attack warning information to obtain a text semantic association feature vector of the historical network attack warning information, including: S210, passing the historical network attack warning information through a historical network attack warning information text word embedding model to obtain a plurality of historical network attack warning information text word vectors; S220, passing the plurality of historical network attack warning information text word vectors through a historical network attack warning information text word bidirectional long short-term memory model to obtain a plurality of historical network attack warning information text feature vectors; S230, concatenating the plurality of historical network attack warning information text feature vectors into the plurality of historical network attack warning information text feature vectors.

[0037] It should be understood that historical network attack warning information usually exists in the form of natural language, which makes it difficult for machines to directly understand its content. The word embedding model can transform each word or phrase in the text into a vector representation in a high-dimensional space. This transformation not only preserves the semantic information of the text but also captures the relationships between different words. For example, in a vector space, words with similar semantics will be mapped to similar positions, enabling the computer to better understand and process text information. By generating word vectors, the semantic analysis ability of the warning information can be enhanced. Specifically, word segmentation is performed on the historical network attack warning information to obtain a historical network attack word sequence; the embedding layer of the historical network attack warning information text word embedding model is used to map each historical network attack word in the historical network attack word sequence into a word embedding vector to obtain a plurality of historical network attack warning information text word vectors.

[0038] Furthermore, network attack alert messages are usually generated in chronological order, and attack behaviors often exhibit temporal continuity. When traditional neural network models process time series data, they may not be able to effectively capture long-distance dependencies. However, LSTM can maintain the effectiveness of information when processing longer sequences through its unique gating mechanism. Inputting the word vectors of historical network attack alert messages into a bidirectional LSTM can help the model learn long-term dependencies in time, thus more accurately capturing the evolution process of attack behaviors. Among them, an important advantage of the bidirectional long short-term memory model is that it can consider the forward and backward contexts of the text sequence simultaneously. When processing historical network attack alert messages, the information in the alert text often depends on the context. For example, the meaning of a certain attack description may be related to the keywords before and after. Through the bidirectional LSTM, the model can more comprehensively capture these context relationships, thereby improving the accuracy of understanding alert messages. This deep understanding of the context enables the model to identify potential patterns and similar features of attacks, thus enhancing the detection effect. The feature vectors processed by the bidirectional LSTM can significantly improve the detection and classification capabilities of the network security system for different attack types, helping to timely discover and respond to potential security threats. Specifically, the historical network attack alert message text word bidirectional long short-term memory model is used to perform global context semantic encoding on the multiple historical network attack alert message text word vectors to obtain multiple historical network attack alert message text feature vectors.

[0039] Furthermore, in network attack detection, faced with diverse and complex attack types, a single feature vector may not be sufficient to fully describe the characteristics of a specific alert. By concatenating multiple feature vectors, more information can be provided to the model, enabling it to better distinguish different types of attacks.

[0040] Figure 3 It is a flowchart for extracting features from the system log data to obtain the semantic understanding feature vector of the system log data segment information in the network security risk control method based on cloud computing according to an embodiment of the present application. As Figure 3 shown, in a specific embodiment of the present application, extracting features from the system log data to obtain the semantic understanding feature vector of the system log data segment information includes: S310, passing the system log data through a system log data semantic understanding model based on a transformer to obtain a system log data segment information sequence; S320, passing the system log data segment information sequence through system log data segment information context encoding to obtain the semantic understanding feature vector of the system log data segment information.

[0041] It should be understood that system log data is usually a large and diverse collection of information, containing a large amount of text information. Transformer-based models, such as BERT and GPT, utilize self-attention mechanisms and can maintain high efficiency when processing large-scale text. This mechanism allows the model to consider all the words in the log during processing and assign corresponding weights to them in context. This approach avoids the limitations of traditional sequence models when dealing with long texts, making the extraction of information more comprehensive and accurate. Compared with traditional convolutional neural network models, Transformer-based models are good at capturing complex semantic relationships and can handle issues such as synonyms, antonyms, and context changes. Specifically, the system log data is segmented to obtain a system log segment sequence; the embedding layer of the Transformer-based system log data semantic understanding model is used to map each system log segment in the system log segment sequence into a segment embedding vector to obtain a system log data segment information sequence.

[0042] Furthermore, log information is often chronological, and the meaning of each record may be affected by the preceding and succeeding log entries. Through context encoding, corresponding context information can be assigned to each log segment, so that the feature vector not only contains the direct content of the log entry but also the relevant context before and after it. In this way, the context relationship of each log data segment can be integrated into the feature vector. This method enables the model to capture complex semantic relationships and thus understand the meaning of the log more accurately. Specifically, the Transformer-based Bert model with context encoding of the system log data segment information is used to perform global context semantic encoding on the system log data segment information sequence to obtain multiple system log feature vectors; and, the multiple system log feature vectors are concatenated to obtain the system log data segment information semantic understanding feature vector.

[0043] In a specific embodiment of the present application, associating the semantic association feature vector of the historical network attack alert information and the semantic understanding feature vector of the system log data segment information to obtain the attack pattern recognition association feature vector includes: establishing a connection with the database through the DriverManager.getConnection method; preparing an SQL query statement and using PreparedStatement to create a query statement for the semantic association feature vector of the historical network attack alert information and the semantic understanding feature vector of the system log data segment information; executing the query through the executeQuery method of the PreparedStatement object and storing the result set in ResultSet; extracting the semantic association feature vector of the historical network attack alert information text and the semantic understanding feature vector of the system log data segment information from the ResultSet; performing an element-wise multiplication operation on the semantic association feature vector of the historical network attack alert information text and the semantic understanding feature vector of the system log data segment information by calling the multiplyVectors method to generate the attack pattern recognition association feature vector; outputting or storing the obtained attack pattern recognition association feature vector to the database, and the storage step is implemented by calling the storeResult method.

[0044] Among them, part of the deployment code is as follows.

[0045]

[0046]

[0047]

[0048]

[0049] Specifically, first, establish a connection to the database through the DriverManager.getConnection method. This process ensures that the program can effectively access the database storing network attack-related data. After successfully establishing the connection, the program prepares an SQL query statement and constructs a query for historical network attack alerts and system logs using PreparedStatement. This structured query method not only improves the security of the code, preventing SQL injection attacks, but also flexibly handles input parameters. After executing the query, the program obtains a ResultSet through the executeQuery method, which is where the query results are stored. After obtaining the result set, the program extracts the semantic association feature vector (attackInfoVector) of the historical network attack alert information text and the semantic understanding feature vector (logDataVector) of the system log data segment. These two feature vectors are crucial for attack pattern recognition because they contain rich information about past network attacks. Next, the program uses the custom multiplyVectors method to perform an element-wise multiplication operation on these two feature vectors to generate an attack pattern recognition association feature vector. The significance of this step is that it combines data from two different sources to form a comprehensive view for subsequent analysis and processing. Finally, the program outputs or stores the calculated result through the storeResult method. This storage step ensures that the result can be used by subsequent data processing or analysis modules, providing valuable insights for network security experts.

[0050] In this way, it can help the network security team quickly identify potential attack patterns, thereby enhancing the network protection ability. By this means, enterprises can timely respond to and prevent potential security threats in a dynamically changing network environment, ensuring information security.

[0051] It should be understood that PreparedStatement is an important interface in the JDBC API of Java for executing pre-compiled SQL statements. Different from the regular Statement, PreparedStatement allows developers to pre-define the structure of the SQL query and dynamically bind parameters at runtime, thus improving security and performance. By using pre-compiled statements, PreparedStatement can effectively prevent SQL injection attacks because the input parameters from users will be automatically escaped. In addition, since the SQL statement is compiled once and can be executed multiple times, it reduces the parsing and compilation overhead of the database, thereby enhancing the execution efficiency. PreparedStatement provides a secure and efficient way to interact with the database.

[0052] Figure 4It is a flowchart for extracting features from the user login behavior data to obtain the user login behavior data associated feature vector in the network security risk control method based on cloud computing according to an embodiment of the present application. As Figure 4 shown, in a specific embodiment of the present application, extracting features from the user login behavior data to obtain the user login behavior data associated feature vector includes: S410, passing the user login behavior data through a user login behavior data semantic understanding model to obtain multiple user login behavior data text feature vectors; S420, arranging the multiple user login behavior data text feature vectors and passing them through a user login behavior data feature encoder based on a dilated convolutional neural network to obtain the user login behavior data associated feature vector.

[0053] It should be understood that by converting the login behavior data into a feature vector, unusual login activities can be quickly identified. For example, when a user logs in at an unusual time or location, the feature vector can provide instant feedback to the system. This real-time nature can help the security team respond promptly to potential security threats and reduce risks. Specifically, the embedding layer of the user login behavior data semantic understanding model is used to convert the user login behavior data into a login behavior embedding vector to obtain a sequence of login behavior embedding vectors; the Transformer-based Bert model of the user login behavior data semantic understanding model is used to perform global context semantic encoding on the sequence of login behavior embedding vectors to obtain multiple user login behavior data text feature vectors.

[0054] Furthermore, user login behavior data usually exhibits temporal characteristics, with strong correlations and long-term dependencies. When traditional convolutional neural networks process time series data, they may be unable to effectively capture long-distance context information due to the limitations of the convolutional kernel size. Dilated convolution, by increasing the spacing between convolutional kernels, enables the model to capture a wider range of context information without increasing the number of parameters, thus more accurately understanding the evolution of user behavior. Among them, arranging the feature vectors of multiple user login behaviors to form a continuous input sequence provides rich context information for the dilated convolutional neural network. This arrangement allows the network to capture the relationships between features during the learning process, thereby enhancing the feature extraction ability. Among them, the structure of dilated convolution can flexibly adjust the receptive field according to needs, enabling the model to adaptively adjust its learning ability when processing input data of different scales. This flexibility not only improves the performance of the model but also adapts to the diverse behavior characteristics of different user groups, ensuring good results when facing various complex user behaviors. Specifically, arrange the text feature vectors of the multiple user login behavior data into a login behavior input vector; use each layer of the first convolutional neural network model of the user login behavior data feature encoder based on the dilated convolutional neural network to perform dilated convolution processing based on the first convolutional kernel, pooling processing along the channel dimension, and non-linear activation processing on the input data respectively during the forward pass of the layer to output a first feature vector by the last layer of the first convolutional neural network model; use each layer of the second convolutional neural network model of the user login behavior data feature encoder based on the dilated convolutional neural network to perform dilated convolution processing based on the second convolutional kernel, pooling processing along the channel dimension, and non-linear activation processing on the input data respectively during the forward pass of the layer to output a second feature vector by the last layer of the second convolutional neural network model; fuse the first feature vector and the second feature vector to obtain the associated feature vector of the user login behavior data.

[0055] In the above network security risk control method based on cloud computing, in step S130, based on the attack pattern recognition associated feature vector and the user login behavior data associated feature vector, a network security risk level label is obtained. It should be understood that the assessment of network security risks often requires considering multiple factors. The attack pattern recognition feature vector provides detailed information about potential attacks, including the type, frequency, means, and target characteristics of the attacks. The feature vector of user login behavior data, on the other hand, reflects the normal behavior patterns, login habits, and usage environments of users. By combining these two types of feature vectors, the security risks in the network environment can be comprehensively evaluated, and potential threats can be identified. Further, by combining the feature vectors of attack patterns and user login behavior data and analyzing them using machine learning or deep learning models, risk level labels can be quickly generated. This efficient processing ability can significantly improve the response speed of the security team and timely respond to potential security incidents.

[0056] In a specific embodiment of the present application, obtaining a network security risk level label based on the attack pattern recognition associated feature vector and the user login behavior data associated feature vector includes: fusing the attack pattern recognition associated feature vector and the user login behavior data associated feature vector to obtain a risk level judgment classification feature vector; performing model overfitting adjustment on the risk level judgment classification feature vector based on the distance topological walk map to obtain a sparse optimized risk level judgment classification feature vector; passing the sparse optimized risk level judgment classification feature vector through a classifier to obtain a classification result, and the classification result is used to represent the network security risk level label.

[0057] It should be understood that the network environment is dynamically changing, and threats are also constantly evolving. By fusing attack patterns and user behavior data, a real-time monitoring system can be established to dynamically evaluate the risk level according to the current feature vectors. This dynamic risk assessment mechanism can ensure that security policies are updated in a timely manner and quickly respond to newly emerging threats.

[0058] In particular, in the technical solution of this application, the risk level judgment classification feature vector is formed by fusing data from multiple sources, including the feature vectors of historical network attack warning information, system log data, and user login behavior data. They have different dimensions and distribution characteristics, and there are significant differences in their numerical ranges, feature spaces, and correlations. During the fusion process, different features may introduce different noises and irrelevant information, and these noises may generate interaction effects in the risk level judgment classification feature vector, interfering with the classifier's recognition of important features. If the design of the learning parameter matrix fails to effectively distinguish this information, the classifier will be affected by the noise during the training process, resulting in an enhanced adaptability of the classifier to the training data but a reduced generalization ability to unknown data, that is, the model is overfitted, causing useful information to be submerged by the redundant structure of the learning parameter matrix, ultimately affecting the classification accuracy of the network security risk level label. Therefore, in the technical solution of this application, the model overfitting adjustment based on the distance topology walk map is performed on the risk level judgment classification feature vector to obtain the sparse optimized risk level judgment classification feature vector.

[0059] Among them, performing the model overfitting adjustment based on the distance topology walk map on the risk level judgment classification feature vector to obtain the sparse optimized risk level judgment classification feature vector includes: extracting each row vector of the learning parameter matrix in the classifier as a set of attack risk learning parameter row vectors; calculating the maximum simulation value of the attack risk entropy degradation between the risk level judgment classification feature vector and each attack risk learning parameter row vector in the set of attack risk learning parameter row vectors to obtain a set of maximum simulation values of the attack risk entropy degradation; based on the comparison between each maximum simulation value of the attack risk entropy degradation in the set of maximum simulation values of the attack risk entropy degradation and a preset threshold, performing gating pruning processing on the learning parameter matrix to obtain the attack risk learning parameter entropy degradation optimized matrix; multiplying the risk level judgment classification feature vector by the attack risk learning parameter entropy degradation optimized matrix to obtain the sparse optimized risk level judgment classification feature vector.

[0060] Among them, the optimization steps are specifically expressed as:

[0061] P = {p1, p2,..., p i ,..., p n}

[0062]

[0063] w i = mask(D i )

[0064]

[0065] Ps = {w1·p1, w2·p2,..., w i ·p i ,..., w n ·p n}

[0066]

[0067] Where P is a set of row vectors of attack risk learning parameters, {...} is a set operation, p1, p2, p i , p n are the eigenvalues of the first, second, ith, and nth attack risk learning parameter row vectors in the set of attack risk learning parameter row vectors respectively, D i is the ith attack risk entropy degradation maximization simulation value in the set of attack risk entropy degradation maximization simulation values, max is the maximum value function, D(v1, p i ) represents calculating the Euclidean distance between vector v1 and p i , v1 is a risk level judgment classification feature vector, p i T is the transposed vector of the ith attack risk learning parameter row vector, L is the length of the feature vector, is matrix multiplication, w1, w2, w i , w n are the first, second, ith, and nth learning parameter mask values respectively, mask is a masking operation, θ represents a preset threshold, P s is an attack risk learning parameter entropy degradation optimization matrix, and v1' is a sparse optimization risk level judgment classification feature vector.

[0068] In the technical solution of this application, considering that in the process of inputting the risk level judgment classification feature vector into the learning parameter matrix of the classifier to obtain the classification result of the network security risk level label, due to the mismatch between the structure of the learning parameter matrix itself and the risk level judgment classification feature vector, that is, there is structural redundancy and information confusion in the learning parameter matrix relative to the risk level judgment classification feature vector, it may cause feature redundancy or noise in the classification result of the network security risk level label, resulting in model overfitting.

[0069] Based on this, in the technical solution of this application, model overfitting adjustment is performed on the risk level judgment classification feature vector based on the distance topology random walk map. The risk level judgment classification feature vector is used as the random walk node, and the feature distribution between the risk level judgment classification feature vector and each row vector in the learning parameter matrix is used to simulate the random walk pattern. The distance topology between the risk level judgment classification feature vector and each row vector in the learning parameter matrix is used as the random walk map. In this way, the maximum simulation value of the attack risk entropy degradation is obtained through the random walk result of the random walk node in a specific random walk pattern on the random walk map. Furthermore, based on the comparison between each maximum simulation value of the attack risk entropy degradation in the set of the maximum simulation values of the attack risk entropy degradation and a preset threshold, the part of the learning parameter matrix that makes no significant contribution to the representation of the input data and may even introduce noise or redundant information is screened out. Specifically, the learning parameter matrix is subjected to gated pruning processing based on the comparison result to obtain an optimized matrix of the attack risk learning parameter entropy degradation. Finally, the structurally optimized learning parameter matrix is used as a feature modulation unit to linearly modulate the risk level judgment classification feature vector to obtain the sparse optimized risk level judgment classification feature vector.

[0070] Furthermore, by processing the sparse optimized risk level judgment classification feature vector through a classifier, network security risk level labels can be generated in real time. The classifier determines the current risk status based on combinations of different features, enabling the system to dynamically adjust security policies. Different risk level labels can correspond to different response measures. For example, high-risk events are handled urgently, while low-risk events can be monitored or recorded. This flexible risk classification and processing mechanism helps improve the overall response ability of the network security protection system. This not only improves the efficiency of the network security system but also reduces human judgment errors and enhances the reliability of overall security protection.

[0071] In summary, the embodiments of this application first obtain historical network attack warning information, system log data, and user login behavior data collected by a cloud computing platform, then use deep learning technology to perform feature extraction and correlation analysis on the three, and finally obtain a classification result through a classifier to obtain network security risk level labels, thereby identifying potential security threats, reducing low-risk warnings and false alarms, further optimizing the warning processing efficiency, enhancing the interpretability and transparency of the system, and improving the real-time performance and scalability of the system.

[0072] Figure 5 FIG. is a block diagram schematic of a network security risk control device based on cloud computing according to an embodiment of this application. As Figure 5As shown, the network security risk control device 100 based on cloud computing according to an embodiment of the present application includes: a network security risk data acquisition module 110, configured to acquire historical network attack warning information, system log data, and user login behavior data collected by a cloud computing platform; a network security risk data processing module 120, configured to extract an attack pattern recognition associated feature vector and a user login behavior data associated feature vector from the historical network attack warning information, the system log data, and the user login behavior data collected by the cloud computing platform; and a network security risk level label classification module 130, configured to obtain a network security risk level label based on the attack pattern recognition associated feature vector and the user login behavior data associated feature vector.

[0073] Here, those skilled in the art can understand that the specific operations of each step in the above network security risk control device based on cloud computing have been described in detail in the description of the network security risk control method based on cloud computing above with reference to Figures 1 to 4 and thus, the repeated description thereof will be omitted.

[0074] As described above, the network security risk control device 100 based on cloud computing according to an embodiment of the present application can be implemented in various terminal devices. In one example, the network security risk control device 100 based on cloud computing can be integrated into a terminal device as a software module and / or a hardware module. For example, the network security risk control device 100 based on cloud computing can be a software module in the operating system of the terminal device, or can be an application program developed for the terminal device; of course, the network security risk control device 100 based on cloud computing can also be one of many hardware modules of the terminal device.

[0075] Alternatively, in another example, the network security risk control device 100 based on cloud computing and the terminal device can also be separate devices, and the network security risk control device 100 based on cloud computing can be connected to the terminal device through a wired and / or wireless network and transmit interaction information in accordance with a predefined data format.

[0076] Figure 6 It is a structural diagram of an exemplary hardware architecture of a computing device for a network security risk control method and device based on cloud computing according to an embodiment of the present application.

[0077] As Figure 6As shown, the electronic device 10 includes an input device 11, an input interface 12, a central processing unit 13, a memory 14, an output interface 15, an output device 16, and a bus 17. Among them, the input interface 12, the central processing unit 13, the memory 14, and the output interface 15 are interconnected through the bus 17. The input device 11 and the output device 16 are respectively connected to the bus 17 through the input interface 12 and the output interface 15, and then connected to other components of the electronic device 10.

[0078] Specifically, the input device 11 receives input information from the outside and transmits the input information to the central processing unit 13 through the input interface 12; the central processing unit 13 processes the input information based on computer-executable instructions stored in the memory 14 to generate output information, temporarily or permanently stores the output information in the memory 14, and then transmits the output information to the output device 16 through the output interface 15; the output device 16 outputs the output information to the outside of the electronic device 10 for the user to use.

[0079] In one embodiment, Figure 6 The illustrated electronic device 10 can be implemented as a network device, which can include: a memory configured to store a program; a processor configured to run the program stored in the memory to execute any one of the network security risk control methods based on cloud computing described in the above embodiments.

[0080] According to the embodiments of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments of the present application include a computer program product, which includes a computer program tangibly contained on a machine-readable medium, and the computer program includes program codes for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network and / or installed from a removable storage medium.

[0081] Those of ordinary skill in the art can understand that all or some of the steps in the methods disclosed above, and the functional modules / units in systems and devices, can be implemented as software, firmware, hardware, and their appropriate combinations. In the hardware implementation, the division between the functional modules / units mentioned above does not necessarily correspond to the division of physical components; for example, one physical component can have multiple functions, or one function or step can be executed by several physical components in cooperation. Some or all physical components can be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or be implemented as hardware, or be implemented as an integrated circuit, such as an application-specific integrated circuit. Such software can be distributed on a computer-readable medium, which can include a computer storage medium (or non-transitory medium) and a communication medium (or transitory medium). As is well known to those of ordinary skill in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information, such as computer-readable instructions, data structures, program modules, or other data. Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disk (DVD) or other optical disk storage, magnetic cassette, tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, as is well known to those of ordinary skill in the art, a communication medium typically contains computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transmission mechanism, and can include any information delivery medium.

[0082] It can be understood that the above embodiments are merely exemplary embodiments adopted to illustrate the principles of the present application, but the present application is not limited thereto. For those of ordinary skill in the art, various modifications and improvements can be made without departing from the spirit and essence of the present application, and these modifications and improvements are also regarded as the protection scope of the present application.

Claims

1. A network security risk control method based on cloud computing, characterized in that: include: Obtain historical network attack warning information, system log data, and user login behavior data collected by the cloud computing platform; Extracting attack pattern recognition associated feature vectors and user login behavior data associated feature vectors from the historical network attack alarm information collected by the cloud computing platform, the system log data, and the user login behavior data; Obtaining a network security risk level label based on the attack pattern recognition associated feature vector and the user login behavior data associated feature vector; Wherein, based on the attack pattern recognition associated feature vector and the user login behavior data associated feature vector, a network security risk level label is obtained, including: Fusion of the attack pattern recognition associated feature vector and the user login behavior data associated feature vector to obtain a risk level judgment classification feature vector; Extracting each row vector of the learning parameter matrix in the classifier as a set of attack risk learning parameter row vectors; Calculating attack risk entropy degradation maximization simulation values ​​between the risk level judgment classification feature vector and each attack risk learning parameter row vector in the set of attack risk learning parameter row vectors to obtain a set of attack risk entropy degradation maximization simulation values; Based on the comparison between each attack risk entropy degradation maximization simulation value and a preset threshold, the learning parameter matrix is ​​gated and pruned to obtain an attack risk learning parameter entropy degradation optimization matrix; Perform matrix multiplication of the risk level judgment classification feature vector and the attack risk learning parameter entropy degradation optimization matrix to obtain a sparse optimized risk level judgment classification feature vector; The sparse optimized risk level judgment classification feature vector is passed through a classifier to obtain a classification result, and the classification result is used to represent a network security risk level label.

2. The network security risk control method based on cloud computing according to claim 1 is characterized in that: Extracting attack pattern recognition associated feature vectors and user login behavior data associated feature vectors from the historical network attack alarm information collected by the cloud computing platform, the system log data, and the user login behavior data, including: Performing feature extraction on the historical network attack warning information to obtain a text semantic association feature vector of the historical network attack warning information; Performing feature extraction on the system log data to obtain a semantic understanding feature vector of the system log data segment information; Associating the historical network attack warning information text semantic association feature vector with the system log data segment information semantic understanding feature vector to obtain the attack pattern recognition association feature vector; Feature extraction is performed on the user login behavior data to obtain a feature vector associated with the user login behavior data.

3. The network security risk control method based on cloud computing according to claim 2 is characterized in that: Performing feature extraction on the historical network attack warning information to obtain a text semantic association feature vector of the historical network attack warning information includes: The historical network attack warning information is embedded into a historical network attack warning information text word model to obtain multiple historical network attack warning information text word vectors; Passing the multiple historical network attack warning information text word vectors through a historical network attack warning information text word bidirectional long short-term memory model to obtain multiple historical network attack warning information text feature vectors; The multiple historical network attack warning information text feature vectors are cascaded into the multiple historical network attack warning information text feature vectors.

4. The network security risk control method based on cloud computing according to claim 3 is characterized in that: Feature extraction is performed on the system log data to obtain a semantic understanding feature vector of the system log data segment information, including: The system log data is passed through a converter-based system log data semantic understanding model to obtain a system log data segment information sequence; The system log data segment information sequence is encoded through the system log data segment information context to obtain the system log data segment information semantic understanding feature vector.

5. The network security risk control method based on cloud computing according to claim 4 is characterized in that: Associating the historical network attack warning information text semantic association feature vector with the system log data segment information semantic understanding feature vector to obtain the attack pattern recognition association feature vector, including: Establish a connection with the database through the DriverManager.getConnection method; Prepare SQL query statements and use PreparedStatement to create query statements for the semantic association feature vectors of historical network attack alarm information text and the semantic understanding feature vectors of system log data segment information; Execute the query through the executeQuery method of the PreparedStatement object and store the result set in ResultSet; Extracting the semantic association feature vector of the historical network attack warning information text and the semantic understanding feature vector of the system log data segment information from the ResultSet; By calling the multiplyVectors method, the semantic association feature vector of the historical network attack alarm information text and the semantic understanding feature vector of the system log data segment information are multiplied element by element to generate an attack pattern recognition association feature vector; The obtained attack pattern recognition associated feature vector is output or stored in a database, and the storage step is implemented by calling the storeResult method.

6. The network security risk control method based on cloud computing according to claim 5 is characterized in that: Extracting features from the user login behavior data to obtain a feature vector associated with the user login behavior data includes: The user login behavior data is passed through a user login behavior data semantic understanding model to obtain a plurality of user login behavior data text feature vectors; The multiple user login behavior data text feature vectors are arranged and passed through a user login behavior data feature encoder based on a dilated convolutional neural network to obtain the user login behavior data associated feature vector.

7. A network security risk control device based on cloud computing, characterized in that: include: The network security risk data acquisition module is used to obtain historical network attack warning information, system log data and user login behavior data collected by the cloud computing platform; A network security risk data processing module, used to extract attack pattern recognition associated feature vectors and user login behavior data associated feature vectors from the historical network attack warning information collected by the cloud computing platform, the system log data and the user login behavior data; A network security risk level label classification module, used to obtain a network security risk level label based on the attack pattern recognition associated feature vector and the user login behavior data associated feature vector; Wherein, based on the attack pattern recognition associated feature vector and the user login behavior data associated feature vector, a network security risk level label is obtained, including: Fusion of the attack pattern recognition associated feature vector and the user login behavior data associated feature vector to obtain a risk level judgment classification feature vector; Extracting each row vector of the learning parameter matrix in the classifier as a set of attack risk learning parameter row vectors; Calculating attack risk entropy degradation maximization simulation values ​​between the risk level judgment classification feature vector and each attack risk learning parameter row vector in the set of attack risk learning parameter row vectors to obtain a set of attack risk entropy degradation maximization simulation values; Based on the comparison between each attack risk entropy degradation maximization simulation value and a preset threshold, the learning parameter matrix is ​​gated and pruned to obtain an attack risk learning parameter entropy degradation optimization matrix; Perform matrix multiplication of the risk level judgment classification feature vector and the attack risk learning parameter entropy degradation optimization matrix to obtain a sparse optimized risk level judgment classification feature vector; The sparse optimized risk level judgment classification feature vector is passed through a classifier to obtain a classification result, and the classification result is used to represent a network security risk level label.

8. An electronic device, characterized in that: include: at least one processor; And, a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the cloud computing-based network security risk control method as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Transverse threat sensing method, device, equipment, medium and product

    CN118250093A

  • Network behavior anomaly detection method and system based on data mining and electronic equipment

    CN118713918A