Network topology annotation methods, devices and equipment for addressing cybersecurity threats
By acquiring a set of network threat intelligence, determining the weight and threat level of network nodes, the problem of insufficient efficiency and accuracy of traditional network security protection methods is solved, and network threat intelligence is displayed intuitively in the network topology, improving management efficiency.
Patent Information
- Application Number
- CN202411470558.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-21
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2044-10-21
AI Technical Summary
Traditional network security protection methods rely on static rules and attack signature databases, which are insufficient to cope with the rapid changes in information systems and the complexity of network attacks, resulting in inefficiency and inaccuracy.
By acquiring a set of network threat intelligence, determining the weight and threat level of network nodes, and using network topology annotation methods, a direct association is established between network threat intelligence and network nodes, intuitively reflecting the impact and scope of network threats.
It has improved the efficiency and accuracy of network security management and enhanced the effectiveness of network security protection.
Smart Images

Figure CN119299199B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to a method, apparatus and device for annotating network topology structures in response to network security threats. Background Technology
[0002] With the rapid development of information technology and the widespread use of the Internet, cybersecurity issues have become increasingly serious, leading to the emergence of cybersecurity protection methods.
[0003] Traditional network security protection methods mainly rely on static rules and attack signature databases for detection and protection.
[0004] However, with the rapid changes in information systems and the increasing complexity and diversity of cyberattacks, traditional methods have gradually shown their shortcomings in terms of efficiency and accuracy, and the effectiveness of cybersecurity protection needs to be improved. Summary of the Invention
[0005] Therefore, it is necessary to provide a network topology annotation method, apparatus, and device that can improve the effectiveness of network security protection and address the aforementioned technical problems.
[0006] On one hand, this application provides a network topology annotation method, comprising: acquiring a network threat intelligence set; determining the severity characterization value of each network threat intelligence in the network threat intelligence set; determining the weight of each network node in the network topology to be annotated; for a network node in the network topology, determining at least one associated network threat intelligence related to the network node from the network threat intelligence set, and determining the threat level of the network node according to the weight of the network node and the severity characterization value of the at least one associated network threat intelligence; and annotating the threat level and weight of the network node in the network topology.
[0007] On the other hand, this application also provides a network topology annotation device, comprising: an intelligence acquisition module, configured to acquire a set of network threat intelligence and determine the severity characterization value of each network threat intelligence in the set of network threat intelligence; a weight determination module, configured to determine the weight of each network node in the network topology to be annotated; a level determination module, configured to, for a network node in the network topology, determine at least one associated network threat intelligence related to the network node from the set of network threat intelligence, and determine the threat level of the network node according to the weight of the network node and the severity characterization value of the at least one associated network threat intelligence; and a node annotation module, configured to annotate the threat level and weight of the network node in the network topology.
[0008] In some embodiments, the weight determination module is further configured to, for each network node in the network topology, determine the number of network nodes directly connected to the network node in the network topology, and obtain the number of connected nodes corresponding to the network node; obtain a first evaluation value of the network node based on the number of connected nodes; and determine the weight of the network node based on the first evaluation value.
[0009] In some embodiments, the weight determination module is further configured to: determine each pair of network nodes from the network topology, wherein each pair of network nodes includes two distinct network nodes; for each pair of network nodes, determine at least one shortest path between the two network nodes in the pair, forming a set of shortest paths corresponding to the pair of network nodes; for each network node, count the number of target shortest paths passing through the network node in the set of shortest paths corresponding to each pair of network nodes excluding the network node, obtain the number of shortest paths corresponding to the network node, and determine a second evaluation value for the network node based on the number of shortest paths; and determine the weight of the network node based on the first evaluation value and the second evaluation value.
[0010] In some embodiments, the weight determination module is further configured to, for each network node in the network topology, determine the shortest path length between the network node and each of the remaining network nodes in the network topology, and obtain a third evaluation value corresponding to the network node by combining the determined shortest path lengths; and determine the weight of the network node based on the first evaluation value, the second evaluation value and the third evaluation value.
[0011] In some embodiments, the level determination module is further configured to comprehensively calculate the severity characterization values of each of the at least one associated network threat intelligence to obtain a total severity characterization value; and determine the threat level of the network node based on the weight of the network node and the total severity characterization value.
[0012] In some embodiments, the intelligence acquisition module is further configured to determine the threat level of each network threat intelligence in the network threat intelligence set; and to determine the severity characterization value of the threat intelligence based on the threat level of the threat intelligence.
[0013] On the other hand, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above-described network topology annotation method.
[0014] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps in the above-described video file compression method.
[0015] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps in the above-described network topology annotation method.
[0016] The aforementioned network topology annotation method, apparatus, computer equipment, computer-readable storage medium, and computer program product acquire a set of network threat intelligence, determine the severity characterization value of each network threat intelligence in the set, determine the weight of each network node in the network topology to be annotated, and for each network node in the network topology, identify at least one associated network threat intelligence related to the network node from the set. Based on the weight of the network node and the severity characterization value of the at least one associated network threat intelligence, the threat level of the network node is determined, and the threat level and weight of the network node are annotated in the network topology. This establishes a direct correlation between network threat intelligence and the network topology, effectively applying network threat intelligence to the network topology. It can intuitively reflect the various threats faced by the network topology, and allow for direct observation of the impact and scope of network threats on the network topology, improving the efficiency and accuracy of network security management, thereby enhancing the effectiveness of network security protection. Attached Figure Description
[0017] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 This is an application environment diagram of the network topology annotation method in one embodiment;
[0019] Figure 2 This is a flowchart illustrating a network topology annotation method in one embodiment;
[0020] Figure 3 This is a schematic diagram of the network topology annotation method in another embodiment;
[0021] Figure 4 This is a structural block diagram of a network topology annotation device in one embodiment;
[0022] Figure 5This is an internal structural diagram of a computer device in one embodiment;
[0023] Figure 6 This is a diagram of the internal structure of a computer device in another embodiment. Detailed Implementation
[0024] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0025] The network topology annotation method provided in this application can be applied to, for example... Figure 1 The application environment shown includes a network topology with multiple network nodes, such as network nodes 1 to 6, and also includes computer equipment. Connections between network nodes represent communication between them. A data storage system stores the data that the computer equipment needs to process. This data storage system can be integrated into the computer equipment or located in the cloud or on other network servers. Although the computer equipment is shown outside the network in the diagram, this solution does not limit its location; the computer equipment can also be located within the network, meaning it can be a network node. The computer equipment can acquire a set of network threat intelligence, determine the severity value of each network threat intelligence in the set, determine the weight of each network node in the network topology, and for each network node in the network topology, identify at least one associated network threat intelligence related to the node from the set. Based on the node's weight and the severity value of the associated network threat intelligence, the threat level of the network node is determined, and the threat level and weight of the network node are marked in the network topology.
[0026] In this context, network nodes can be terminals or servers. Computer equipment can be terminals or servers; terminals can be, but are not limited to, various desktop computers, laptops, smartphones, tablets, etc. Servers can be independent physical servers, server clusters or distributed systems composed of multiple physical servers, or cloud servers providing cloud computing services.
[0027] In some embodiments, such as Figure 2 As shown, a network topology annotation method is provided. This method can be applied to terminals or servers. Figure 1 The following steps are used as an example of computer equipment, including steps 202 to 208. Wherein:
[0028] Step 202: Obtain the network threat intelligence set and determine the severity characterization value of each network threat intelligence in the network threat intelligence set.
[0029] Specifically, a computer device can construct a network threat intelligence set from some or all of the threat intelligence in a threat intelligence database. The threat intelligence in the database can be collected by the computer device itself or by other devices. The sources of network threat intelligence include, but are not limited to, open-source or closed-source threat intelligence. The data interface definition for threat intelligence can be pre-defined. The threat intelligence in the database can be collected based on the data interface defined in the data interface definition. The threat intelligence database can be stored in a database.
[0030] Cyber threat intelligence can be categorized into several types, including but not limited to malware intelligence, vulnerability intelligence, attack behavior intelligence, and malicious domain and IP (Internet Protocol Address) intelligence. Malware intelligence includes, but is not limited to, basic information, analysis, and detection methods for computer viruses, worms, Trojans, spyware, and other malware. Vulnerability intelligence includes, but is not limited to, information on vulnerabilities existing in various software, systems, and devices. Attack behavior intelligence includes, but is not limited to, information on attack methods, targets, and attack tools. Malicious domain and IP address intelligence includes, but is not limited to, information on malicious domains and IP addresses.
[0031] Specifically, computer equipment or other devices can clean, deduplicate, verify, and classify the collected network threat intelligence to build a threat intelligence database.
[0032] Step 204: Determine the weight of each network node in the network topology to be labeled.
[0033] The network topology includes multiple network nodes and edges, which represent connections between two network nodes, allowing them to communicate.
[0034] Specifically, computer devices can determine the weight of a network node based on its connections to other network nodes within the network topology. For example, for a given network node, the computer device can determine the number of network nodes connected to that node from the network topology, and then determine the weight of that network node based on that number. The weight can be positively correlated with that number.
[0035] In some embodiments, for each network node, the computer device can obtain functional description information of that network node. This functional description information describes the role of the network node, and the weight of the network node is determined based on this information. Network nodes with different roles can have different weights, and weights corresponding to different roles can be preset.
[0036] Step 206: For network nodes in the network topology, identify at least one associated network threat intelligence related to the network node from the network threat intelligence set, and determine the threat level of the network node based on the weight of the network node and the severity characterization value of each of the at least one associated network threat intelligence.
[0037] Specifically, for each network node, at least one associated network threat intelligence related to the network node is searched from the network threat intelligence set. If no such threat intelligence is found, the threat level of the network node can be determined as the lowest level. If a threat intelligence is found, the threat level of the network node can be determined based on the weight of the network node and the severity characterization value of each of the at least one associated network threat intelligence related to the network node.
[0038] In some embodiments, the computer device can determine the severity characterization value of network threat intelligence based on the mapping relationship between network threat intelligence and severity characterization values. For example, if Y represents network threat intelligence, M represents the severity characterization value of network threat intelligence, and s represents the mapping relationship between network threat intelligence and severity characterization values, then M = s(Y).
[0039] In some embodiments, when the at least one associated network threat intelligence is only one associated network threat intelligence, the computer device can determine the threat level of a network node based on a severity characterization value and the weight of the network node. The computer device can multiply the severity characterization value and the weight of the network node, using the result as the severity characterization value corresponding to the network node, and determine the threat level of the network node based on the severity characterization value. The severity characterization value of a network node is positively correlated with its threat level.
[0040] In some embodiments, when the at least one associated network threat intelligence is at least two associated network threat intelligences, the computer device can perform a comprehensive calculation on the severity characterization values of each of the at least one associated network threat intelligences to obtain a total severity characterization value, and determine the threat level of the network node based on the weight of the network node and the total severity characterization value.
[0041] In some embodiments, the computer device determines network threat intelligence related to network nodes in the following ways, including but not limited to: (1) IP address and domain name matching: matching the IP address and domain name in the network threat intelligence with the network nodes in the network topology. If the IP address or domain name in the network threat intelligence directly corresponds to a certain network node in the network topology, then it can be determined that the network threat intelligence is directly related to that network node. (2) Attack methods and target system analysis: analyzing the attack methods and target systems described in the network threat intelligence. If the attack methods may affect a certain network node in the network topology, or the target system is part of the network topology, then it can be considered that the network threat intelligence has a potential association with the relevant network nodes in the network topology. (3) Utilizing tools and platforms: using network security analysis tools and platforms, such as SIEM (Security Information and Event Management) and SOC (Security Operations Center), to further analyze and correlate the network threat intelligence. These tools usually have powerful data processing and correlation analysis capabilities, which can help security personnel quickly identify the correlation between network threat intelligence and network nodes in the network topology.
[0042] Step 208: Mark the threat level and weight of network nodes in the network topology.
[0043] Specifically, computer devices can directly or indirectly display the network topology and, for each network node in the topology, display and label its corresponding weight. For network nodes with a threat level, the device displays and labels the corresponding threat level. From the labeled network topology, the effect and impact of threat intelligence on the network topology can be visually observed.
[0044] In some embodiments, when the computer device is a server, the computer device can send the network topology and the threat levels and weights of the network nodes in the network topology to the terminal, and the terminal can display the network topology and the threat levels and weights of the network nodes on the network topology.
[0045] In some embodiments, when the computer device is a terminal, the terminal can display the network topology and show the threat level and weight of network nodes on the network topology.
[0046] The aforementioned network topology annotation method involves acquiring a set of network threat intelligence, determining the severity value of each network threat intelligence in the set, determining the weight of each network node in the network topology to be annotated, and for each network node in the network topology, identifying at least one associated network threat intelligence related to the node from the set. Based on the node's weight and the severity value of the associated network threat intelligence, the threat level of the network node is determined, and the threat level and weight of the network node are annotated in the network topology. This establishes a direct correlation between network threat intelligence and the network topology, effectively applying network threat intelligence to the network topology. This allows for a direct visualization of the various threats faced by the network topology, enabling a direct observation of the impact and scope of network threats on the network topology, improving the efficiency and accuracy of network security management, and ultimately enhancing the effectiveness of network security protection.
[0047] In some embodiments, such as Figure 3 As shown, determining the weight of each network node in the network topology to be labeled includes: step 302, for each network node in the network topology, determining the number of network nodes directly connected to the network node in the network topology, and obtaining the number of connected nodes corresponding to the network node; step 304, obtaining the first evaluation value of the network node based on the number of connected nodes; and determining the weight of the network node based on the first evaluation value.
[0048] In the network topology, an edge is a line connecting two nodes. The first evaluation value is positively correlated with the number of connected nodes.
[0049] Specifically, the computer device can use the number of connected nodes as the first evaluation value. Alternatively, the computer device can normalize the number of connected nodes to obtain the first evaluation value.
[0050] In some embodiments, the computer device can determine the number of network nodes included in the network topology to obtain the total number of network nodes. The computer device can calculate the ratio of the number of connected nodes to the total number of network nodes to obtain a first evaluation value. Alternatively, the computer device can calculate the ratio of the number of connected nodes to the total number of network nodes minus 1 to obtain the first evaluation value, for example, the first evaluation value = number of connected nodes / (total number of network nodes - 1).
[0051] In some embodiments, the weight of a network node is positively correlated with a first evaluation value. For example, a computer device may use the first evaluation value as the weight of a network node.
[0052] In this embodiment, the weight of a network node is determined based on the number of connected node data, which improves the accuracy of the weight.
[0053] In some embodiments, the method further includes: determining network node pairs from the network topology, each network node pair comprising two distinct network nodes; for each network node pair, determining at least one shortest path between the two network nodes in the network node pair, forming a set of shortest paths corresponding to the network node pair; for each network node, counting the number of target shortest paths passing through the network node in the set of shortest paths corresponding to each network node pair excluding the network node, obtaining the number of shortest paths corresponding to the network node, and determining a second evaluation value of the network node based on the number of shortest paths; and determining the weight of the network node based on the first evaluation value, including: determining the weight of the network node based on the first evaluation value and the second evaluation value.
[0054] The weights of network nodes are positively correlated with the second evaluation value. Figure 1 Taking a network topology as an example, the process of obtaining the shortest path set is illustrated. The network node pairs are: (network node 1, network node 2), (network node 1, network node 3), (network node 1, network node 4), (network node 1, network node 5), (network node 1, network node 6), (network node 2, network node 3), (network node 2, network node 4), (network node 2, network node 5), (network node 2, network node 6), (network node 3, network node 4), (network node 3, network node 5), (network node 4, network node 6), (network node 5, network node 6).
[0055] Taking (network node 1, network node 6) as an example, the paths from network node 1 to network node 6 are: Path 1: Network node 1 → Network node 3 → Network node 5 → Network node 6; Path 2: Network node 1 → Network node 3 → Network node 4 → Network node 6; Path 3: Network node 1 → Network node 2 → Network node 3 → Network node 4 → Network node 6; Path 4: Network node 1 → Network node 2 → Network node 3 → Network node 4 → Network node 6. Since the lengths (number of edges) of paths 1 through 4 are 3, 3, 4, and 4 respectively, it can be seen that paths 1 and 2 are both shortest paths between network node 1 and network node 6. Therefore, paths 1 and 2 constitute the set of shortest paths corresponding to the network node pair (network node 1, network node 6). Similarly, the set of shortest paths corresponding to the remaining network node pairs can be obtained.
[0056] When calculating the second evaluation value of any network node, such as network node 3, among network nodes 1 to 6, we can first determine the network node pairs excluding network node 3, namely (network node 1, network node 2), (network node 1, network node 4), (network node 1, network node 5), (network node 1, network node 6), (network node 2, network node 4), (network node 2, network node 5), (network node 2, network node 6), (network node 4, network node 6), and (network node 5, network node 6). Then, from the shortest path set corresponding to each network node excluding network node 3, we determine the target shortest paths passing through network node 3. In this example, the target shortest path refers to the shortest path passing through network node 3, and the number of target shortest paths is taken as the number of shortest paths corresponding to network node 3.
[0057] Specifically, for each network node, the computer device can count the number of shortest paths in the shortest path sets corresponding to each network node excluding that node, thus obtaining the total number of paths corresponding to that network node. For example, for network node 3, the shortest path sets corresponding to network nodes excluding 3 are sets A and B. The sum of the number of shortest paths included in set A and set B yields the total number of paths corresponding to network node 3. The computer device can determine a second evaluation value for the network node based on the number of shortest paths and the total number of paths corresponding to that network node. The second evaluation value is negatively correlated with the total number of paths. The second evaluation value is positively correlated with the number of shortest paths.
[0058] In some embodiments, for each network node i, the computer device can determine the network node pair that does not include network node i as the target network node pair corresponding to network node i, determine the number of each shortest path in the shortest path set corresponding to the target network node pair that does not pass through network node i, obtain the first quantity corresponding to the target network node pair, determine the total number of all shortest paths included in the shortest path set corresponding to the target network node pair, obtain the second quantity corresponding to the target network node pair, calculate the ratio of the first quantity to the second quantity, obtain the quantity ratio corresponding to the target network node, and sum the quantity ratios corresponding to each target network node corresponding to network node i to obtain the second evaluation value of network node i.
[0059] In this embodiment, the second evaluation value is determined by combining the shortest path, and the weight of the network node is determined by combining the first evaluation value and the second evaluation value, thereby improving the accuracy of the weight.
[0060] In some embodiments, the method further includes: for each network node in the network topology, determining the shortest path length between the network node and each of the remaining network nodes in the network topology, and combining the determined shortest path lengths to obtain a third evaluation value corresponding to the network node; and determining the weight of the network node based on the first evaluation value and the second evaluation value, including: determining the weight of the network node based on the first evaluation value, the second evaluation value and the third evaluation value.
[0061] The weights of network nodes are positively correlated with the third evaluation value. The shortest path length between two network nodes refers to the length of the shortest path between these two network nodes (i.e., the number of edges included in the shortest path).
[0062] Specifically, for network node i, the computer device can determine the shortest path length between network node i and network node j, where network node j is any network node identical to network node i (i.e., i ≠ j). If there are multiple network nodes different from network node i (i.e., the remaining network nodes), the shortest path lengths between network node i and each of the remaining network nodes are summed to obtain the total length. The computer device can then determine a third evaluation value for the network node based on the total length, and this third evaluation value is negatively correlated with the total length. The computer device can determine the third evaluation value for a network node based on the total number of network nodes in the network topology and the total length. For example, if the total number of network nodes is N, the ratio of N to the total length can be used as the third evaluation value for the network node, or the ratio of N-1 to the total length can be used as the third evaluation value for the network node. In some embodiments, the first evaluation value is the value of the network node on the degree centrality (DC) metric, the second evaluation value is the value of the network node on the betweenness centrality (BC) metric, and the third evaluation value is the value of the network node on the closeness centrality (CC) metric. The computer device can use a weight calculation function to calculate the weights, where X represents the weight and w represents the weight calculation function, then X = w(first evaluation value, second evaluation value, third evaluation value). The weight calculation function can be, but is not limited to, a function that calculates the mean or summation.
[0063] In some embodiments, the computer device may determine a fourth evaluation value for a network node based on its role, with a higher fourth evaluation value indicating a more important role. The computer device may determine the weight of a network device based on at least one of a first evaluation value, a second evaluation value, a third evaluation value, or a fourth evaluation value.
[0064] In this embodiment, the third evaluation value corresponding to the network node is obtained by comprehensively determining the shortest path lengths. Based on the first evaluation value, the second evaluation value, and the third evaluation value, the weight of the network node is determined, which improves the accuracy of the weight.
[0065] In some embodiments, determining the threat level of a network node based on the weight of the network node and the severity characterization value of each of at least one associated network threat intelligence includes: comprehensively calculating the severity characterization values of each of the at least one associated network threat intelligence to obtain a total severity characterization value; and determining the threat level of the network node based on the weight of the network node and the total severity characterization value.
[0066] Specifically, the comprehensive calculation can be a summation calculation, in which the computer device can sum the severity characterization values of each of the at least one related network threat intelligence to obtain a total severity characterization value.
[0067] In some embodiments, the computer device may employ a function to determine the threat level of a network node. For example, if Z represents the threat level of a network node, then Z = f(X,M). f may be, but is not limited to, a function for calculating a product.
[0068] In this embodiment, the threat level of a network node is determined based on its weight and total severity characterization value, thus improving the accuracy of the threat level assessment.
[0069] In some embodiments, determining the severity characterization value of each network threat intelligence in the network threat intelligence set includes: determining the threat level of each network threat intelligence in the network threat intelligence set; and determining the severity characterization value of the threat intelligence based on the threat level of the threat intelligence.
[0070] Threat levels can be categorized into high, medium, and low. Different threat levels correspond to different severity ratings.
[0071] Specifically, computer devices can determine the severity characterization value corresponding to the threat level of threat intelligence, and use it as the severity characterization value of threat intelligence.
[0072] In this embodiment, the severity characterization value of the threat intelligence is determined based on the threat level of the threat intelligence, thereby improving the accuracy of the severity characterization value.
[0073] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0074] Based on the same inventive concept, this application also provides a network topology annotation apparatus for implementing the network topology annotation method described above. The solution provided by this apparatus is similar to the implementation described in the above method; therefore, the specific limitations in one or more network topology annotation apparatus embodiments provided below can be found in the limitations of the network topology annotation method described above, and will not be repeated here.
[0075] In some embodiments, such as Figure 4 As shown, a network topology annotation device is provided, comprising: an information acquisition module 402, a weight determination module 404, a level determination module 406, and a node annotation module 408, wherein:
[0076] The intelligence acquisition module 402 is used to acquire a set of network threat intelligence and determine the severity characterization value of each network threat intelligence in the set of network threat intelligence.
[0077] The weight determination module 404 is used to determine the weight of each network node in the network topology to be labeled.
[0078] The level determination module 406 is used to determine, for network nodes in the network topology, at least one associated network threat intelligence related to the network node from the network threat intelligence set, and determine the threat level of the network node based on the weight of the network node and the severity characterization value of each of the at least one associated network threat intelligence.
[0079] The node labeling module 408 is used to label the threat level and weight of network nodes in the network topology.
[0080] In some embodiments, the weight determination module 404 is further configured to, for each network node in the network topology, determine the number of network nodes directly connected to the network node in the network topology, obtain the number of connected nodes corresponding to the network node; obtain a first evaluation value of the network node based on the number of connected nodes; and determine the weight of the network node based on the first evaluation value.
[0081] In some embodiments, the weight determination module 404 is further configured to determine each pair of network nodes from the network topology, wherein each pair of network nodes includes two distinct network nodes; for each pair of network nodes, determine at least one shortest path between the two network nodes in the pair, forming a set of shortest paths corresponding to the pair of network nodes; for each network node, count the number of target shortest paths passing through the network node in the set of shortest paths corresponding to each pair of network nodes (excluding the network node), obtain the number of shortest paths corresponding to the network node, and determine a second evaluation value for the network node based on the number of shortest paths; and determine the weight of the network node based on the first evaluation value and the second evaluation value.
[0082] In some embodiments, the weight determination module 404 is further configured to determine the shortest path length between each network node and each other network node in the network topology, and to obtain a third evaluation value corresponding to the network node by combining the determined shortest path lengths; and to determine the weight of the network node based on the first evaluation value, the second evaluation value and the third evaluation value.
[0083] In some embodiments, the level determination module 406 is further configured to perform a comprehensive calculation on the severity characterization values of each of at least one associated network threat intelligence to obtain a total severity characterization value; and determine the threat level of the network node based on the weight of the network node and the total severity characterization value.
[0084] In some embodiments, the intelligence acquisition module 402 is further configured to determine the threat level of each network threat intelligence in the network threat intelligence set; and determine the severity characterization value of the threat intelligence based on the threat level of the threat intelligence.
[0085] Each module in the aforementioned network topology annotation device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the operations corresponding to each module.
[0086] In some embodiments, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 5As shown, the computer device includes a processor, memory, input / output interfaces (I / O), and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computational and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides the environment for the operating system and computer programs stored in the non-volatile storage media. The database stores data related to the network topology annotation method. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communicating with external terminals via a network connection. When the computer program is executed by the processor, it implements a network topology annotation method.
[0087] In some embodiments, a computer device is provided, which may be a terminal, and its internal structure diagram may be as follows: Figure 6 As shown, the computer device includes a processor, memory, input / output interfaces, a communication interface, a display unit, and an input device. The processor, memory, and input / output interfaces are connected via a system bus, and the communication interface, display unit, and input device are also connected to the system bus via the input / output interfaces. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The input / output interfaces are used for exchanging information between the processor and external devices. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, mobile cellular networks, Near Field Communication (NFC), or other technologies. When executed by the processor, the computer program implements a network topology annotation method. The display unit is used to form a visually visible image and can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be an LCD screen or an e-ink screen. The input device of the computer device can be a touch layer covering the display screen, or buttons, trackballs, or touchpads set on the casing of the computer device, or external keyboards, touchpads, or mice, etc.
[0088] Those skilled in the art will understand that Figure 5 and Figure 6The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0089] In some embodiments, a computer device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above-described method embodiments.
[0090] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps in the above embodiments.
[0091] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above embodiments.
[0092] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.
[0093] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.
[0094] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0095] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A method for annotating network topology, characterized in that, The method includes: Obtain a set of network threat intelligence and determine the severity characterization value of each network threat intelligence in the set; For each network node in the network topology to be labeled, determine the number of network nodes directly connected to the network node from the network topology to obtain the number of connected nodes corresponding to the network node, and obtain the first evaluation value of the network node based on the number of connected nodes. Each network node pair is determined from the network topology, and each network node pair includes two different network nodes. For each network node pair, at least one shortest path between the two network nodes in the network node pair is determined to form the shortest path set corresponding to the network node pair. For each network node, the number of target shortest paths passing through the network node in the shortest path set corresponding to each network node pair excluding the network node is counted to obtain the number of shortest paths corresponding to the network node. A second evaluation value of the network node is determined based on the number of shortest paths. The shortest path length between the network node and each of the other network nodes in the network topology is determined, and the third evaluation value corresponding to the network node is obtained by combining the determined shortest path lengths. The weights of the network nodes are determined based on the first evaluation value, the second evaluation value, and the third evaluation value. For a network node in the network topology, at least one associated network threat intelligence related to the network node is determined from the network threat intelligence set, and the threat level of the network node is determined according to the weight of the network node and the severity characterization value of each of the at least one associated network threat intelligence. The threat level and weight of the network nodes are marked in the network topology.
2. The method according to claim 1, characterized in that, Determining the threat level of a network node based on its weight and the severity characterization value of each of the at least one associated network threat intelligence includes: When the at least one associated network threat intelligence is at least two associated network threat intelligences, the severity characterization values of each of the at least one associated network threat intelligences are comprehensively calculated to obtain the total severity characterization value. The threat level of the network node is determined based on the weight of the network node and the total severity characterization value.
3. The method according to claim 2, characterized in that, The method further includes: In the case where the at least one associated network threat intelligence is only one associated network threat intelligence, the threat level of the network node is determined based on the severity characterization value of the associated network threat intelligence and the weight of the network node.
4. The method according to any one of claims 1 to 3, characterized in that, Determining the severity characterization value of each network threat intelligence in the network threat intelligence set includes: For each network threat intelligence in the network threat intelligence set, determine the threat level of the threat intelligence; Based on the threat level of the threat intelligence, a severity characterization value for the threat intelligence is determined.
5. A network topology annotation device, characterized in that, The device includes: The intelligence acquisition module is used to acquire a set of network threat intelligence and determine the severity characterization value of each network threat intelligence in the set of network threat intelligence. The weight determination module is used to: determine the number of network nodes directly connected to each network node in the network topology to be labeled, obtaining the number of connected nodes corresponding to the network node; obtain a first evaluation value for the network node based on the number of connected nodes; determine each pair of network nodes in the network topology, each pair including two distinct network nodes; for each pair of network nodes, determine at least one shortest path between the two network nodes in the pair, forming a set of shortest paths corresponding to the pair; for each network node, count the number of target shortest paths passing through the network node in the shortest path sets corresponding to each pair of network nodes (excluding the network node itself), obtaining the number of shortest paths corresponding to the network node, and determine a second evaluation value for the network node based on the number of shortest paths; determine the shortest path length between the network node and each of the remaining network nodes in the network topology, and obtain a third evaluation value for the network node by combining the determined shortest path lengths; and determine the weight of the network node based on the first evaluation value, the second evaluation value, and the third evaluation value. The threat level determination module is used to determine, for network nodes in the network topology, at least one associated network threat intelligence related to the network node from the network threat intelligence set, and determine the threat level of the network node based on the weight of the network node and the severity characterization value of each of the at least one associated network threat intelligence. The node labeling module is used to label the threat level and weight of the network nodes in the network topology.
6. The apparatus according to claim 5, characterized in that, The level determination module is also used for: The severity characterization values of each of the at least one associated network threat intelligence are comprehensively calculated to obtain the total severity characterization value; The threat level of the network node is determined based on the weight of the network node and the total severity characterization value.
7. The apparatus according to claim 5 or 6, characterized in that, The intelligence acquisition module is also used for: For each network threat intelligence in the network threat intelligence set, determine the threat level of the threat intelligence; Based on the threat level of the threat intelligence, a severity characterization value for the threat intelligence is determined.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 4.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Network topology safety testing method and device of power data network
CN103441891A
Electric power communication network key node identification method
CN110474806A