A network security situation awareness method and system
By monitoring network data in real time and building a network situation awareness model based on neural networks, combined with parameter optimization of risk assessment model, it solves the problem that traditional network security management methods are difficult to cope with unknown attacks and cannot fully perceive the network security status, real-time perception and risk assessment of network security situation are achieved.
Patent Information
- Application Number
- CN202411555135.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-04
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2044-11-04
AI Technical Summary
Traditional network security management methods are difficult to effectively deal with unknown new and variant attacks, and network situation awareness methods cannot comprehensively and accurately reflect the security status of the network.
By monitoring network data in real time, the characteristics of network topology, node attributes and interaction relationships are extracted, encoded and integrated into the feature matrix. A network situational awareness model is constructed based on neural networks, and the feature matrix is used as input to generate network situational awareness vectors through nonlinear mapping. The risk assessment model is optimized parameterly, and the optimized model uses the network situation awareness vector as input to conduct risk assessment.
It realizes real-time and comprehensive perception of the network security situation, can promptly discover and respond to potential threats and risks in the network, and provides an important decision-making basis.
Smart Images

Figure CN119420547B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network security situation awareness method and system. Background Art
[0002] In traditional network security management, rule-based detection and protection methods are usually used. These methods filter and intercept network data through preset rules and policies to prevent malicious behavior. At the same time, some simple statistical and analytical methods are also used to roughly perceive and evaluate the network situation. However, these traditional methods have obvious limitations.
[0003] First, rule-based detection and protection methods can only defend against known attacks and threats, but are ineffective against unknown new attacks and variant attacks, because new attacks and variant attacks can usually bypass preset rules and policies, thus evading detection and protection.
[0004] Secondly, traditional network situational awareness methods can usually only provide simple statistical and analytical results, which cannot fully and accurately reflect the security status of the network. These results often lack depth and breadth and cannot provide sufficient decision support for network security managers. Summary of the invention
[0005] Based on this, the purpose of the present invention is to propose a network security situation awareness method and system to solve the above-mentioned problems.
[0006] A network security situation awareness method proposed in the present invention includes:
[0007] Monitor network data in real time, extract network topology features, node attribute features, and interaction relationship features from the network data, encode them, and integrate them into a unified feature matrix;
[0008] A network situation awareness model is constructed based on a neural network, the feature matrix is used as an input of the network situation awareness model, and the input data is converted into an output reflecting the network security situation through the nonlinear mapping capability of the neural network, the output is a network situation awareness vector used to represent the security status of the current network;
[0009] The risk assessment model is parameter optimized, and the network situation awareness vector is used as the input of the optimized risk assessment model to perform risk assessment and output a risk assessment value for evaluating the size or severity of the current network security risk.
[0010] Furthermore, the step of constructing a network situation awareness model based on a neural network includes:
[0011] For each layer of the neural network, initialize the weight matrix and bias vector;
[0012] Take the feature matrix a0 as input data and calculate the output z of each layer i And the output after activation a i , the calculation formula is: i =W i a i-1 +b i , a i =σ(z i ), where σ is a nonlinear activation function, W i is the weight of each layer, b i is the bias of each layer;
[0013] For the output layer L, the output network situation awareness vector a L ;
[0014] Calculate the loss function based on the actual situation and the model's predicted output;
[0015] The gradient of the loss function with respect to the weights and bias terms is calculated through back propagation and updated;
[0016] Repeat the iteration, and terminate the iteration after the iteration termination condition is met to obtain the trained network situation awareness model.
[0017] Furthermore, the step of optimizing the parameters of the risk assessment model includes:
[0018] The parameters of the risk assessment model are optimized using the GWO algorithm.
[0019] Furthermore, the step of optimizing the parameters of the risk assessment model by using the GWO algorithm includes:
[0020] Define an objective function to evaluate the performance of the risk assessment model under a given set of parameters;
[0021] A set of individuals is randomly generated, where each individual represents a set of parameters of the risk assessment model, including weights, bias terms, and learning rates in the model;
[0022] Calculate the fitness value of each individual through the objective function;
[0023] Update the position of each individual to be close to individuals a, β, and δ, where individuals a, β, and δ represent the optimal solution, suboptimal solution, and third optimal solution in the current population, respectively;
[0024] In each iteration, the a, β, and δ individuals are updated according to the fitness values;
[0025] After the iteration stop condition is met, the current position of individual a is output and set as the parameter of the optimized risk assessment model.
[0026] Furthermore, the step of updating the position of each individual to be closer to individuals a, β and δ includes:
[0027] For each dimension j, update according to the following formula: α =|C1X α -X i |, D β =|C2X β -X i |, D δ =|C3X δ -X i |, where X i is the current position of the individual, C1, C2, C3 are random coefficients, C1 = 2r1-1, C2 = 2r2-1, C3 = 2r3-1, r1, r2, r3 are random numbers between [0, 1];
[0028] Update the position of each individual, X i,new =X α -A1D α +A2D β -A3D δ , where X i,new is the position of the updated individual, A1, A2, A3 are random coefficients, A1 = 2ar4-a, A2 = 2ar5-a, A3 = 2ar6-a, r4, r5, r6 are random numbers between [0, 1], a is a parameter that decreases linearly with the number of iterations, a = 2-2t / T, t is the current number of iterations, and T is the maximum number of iterations;
[0029] Determine whether the updated individual's position is within the search space;
[0030] If it is in the search space, it is updated according to the position of the individual;
[0031] The iteration is repeated until the maximum number of iterations T is reached.
[0032] Furthermore, after the step of determining whether the updated position of the individual is within the search space, the step further includes:
[0033] If it is not in the search space, the boundary value is taken.
[0034] Furthermore, the step of updating the a, β and δ individuals according to the fitness values includes:
[0035] Determine whether there is an individual among the current individuals whose fitness value is better than the current individual a;
[0036] If it exists, update individual a to the corresponding individual, and determine whether there is an individual with a better fitness value than the current β individual among the current individuals other than individual a;
[0037] If it exists, update the β individual to the corresponding individual, and check whether there is an individual with a better fitness value than the current δ individual among the current individuals other than a and β individuals;
[0038] If it exists, update the δ individuals to the corresponding individuals.
[0039] Furthermore, the step of using the network situation awareness vector as an input of the optimized risk assessment model to perform risk assessment and output a risk assessment value for assessing the size or severity of the current network security risk includes:
[0040] Inputting the situation awareness feature vector at the current moment into the optimized risk assessment model, wherein the risk assessment model is constructed based on a support vector machine;
[0041] In the inference prediction process of the risk assessment model, for each support vector, the similarity between the network situation awareness vector and the support vector is calculated to obtain a kernel function value;
[0042] Calculate the decision function value according to the kernel function value and the Lagrange multiplier;
[0043] According to the calculated decision function value, a risk assessment value is output, where the risk assessment value is a continuous numerical value used to represent the size or severity of the current network security risk.
[0044] The present invention also provides a network security situation awareness system, the system comprising:
[0045] Network data monitoring module: used to monitor network data in real time, extract network topology features, node attribute features and interaction relationship features from the network data, encode them, and integrate them into a unified feature matrix;
[0046] Network situation awareness module: used to build a network situation awareness model based on a neural network, taking the feature matrix as the input of the network situation awareness model, and converting the input data into an output reflecting the network security situation through the nonlinear mapping capability of the neural network. The output is a network situation awareness vector, which is used to represent the security status of the current network;
[0047] Network risk assessment module: used to optimize the parameters of the risk assessment model, and use the network situation awareness vector as the input of the optimized risk assessment model to perform risk assessment and output a risk assessment value for assessing the size or severity of the current network security risk.
[0048] In summary, according to the above-mentioned network security situation awareness method, by real-time monitoring of network data, the dynamic changes in the network are captured instantly, and the characteristics of network topology, node attributes and interactive relationships are extracted from the network data. These characteristics can fully and multi-levelly reflect the security status of the network, and the extracted characteristics are encoded and integrated into a unified feature matrix; then a network situation awareness model is constructed based on a neural network, and through its powerful nonlinear mapping ability, the input feature matrix is converted into an output reflecting the network security situation, that is, a network situation awareness vector, to achieve real-time and comprehensive perception of the network security situation; then the risk assessment model is parameter optimized to improve the accuracy and reliability of risk assessment, and the optimized risk assessment model takes the network situation awareness vector as input, and outputs a risk assessment value through the analysis of the model, which is used to reflect the size or severity of the current network security risk, and provides an important decision-making basis for network security management. The present invention realizes comprehensive perception of network security situation and accurate assessment of network security risks through the combination of fine feature extraction, neural network situation awareness and risk assessment, and can timely discover and respond to potential threats and risks in the network.
[0049] Additional aspects and advantages of the present invention will be given in part in the following description and in part will be obvious from the following description or will be learned through embodiments of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] The above and / or additional aspects and advantages of the present invention will become apparent and easily understood from the description of the embodiments in conjunction with the following drawings, in which:
[0051] Figure 1 This is a flow chart of a network security situation awareness method according to the first embodiment of the present invention;
[0052] Figure 2 This is a system block diagram of a network security situation awareness system according to Embodiment 2 of the present invention. DETAILED DESCRIPTION
[0053] In order to facilitate the understanding of the present invention, the present invention will be described more fully below with reference to the relevant drawings. Several embodiments of the present invention are given in the drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. On the contrary, the purpose of providing these embodiments is to make the disclosure of the present invention more thorough and comprehensive.
[0054] It should be noted that when an element is referred to as being "fixed to" another element, it may be directly on the other element or there may be a central element. When an element is considered to be "connected to" another element, it may be directly connected to the other element or there may be a central element at the same time. The terms "vertical", "horizontal", "left", "right" and similar expressions used herein are for illustrative purposes only.
[0055] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art of the present invention. The terms used herein in the specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The term "and / or" used herein includes any and all combinations of one or more related listed items.
[0056] Embodiment 1
[0057] See also Figure 1 The present invention proposes a network security situation awareness method, which includes steps S101 to S103:
[0058] S101, real-time monitoring of network data, real-time monitoring of network data, extracting network topology features, node attribute features and interaction relationship features from the network data, encoding them, and integrating them into a unified feature matrix.
[0059] Understandably, network data monitoring equipment is deployed at each key node of the network to monitor the network data of each node in real time. According to the needs and goals of network situation awareness, features are extracted from the network data. These features may include network topology features (such as node degree, path length, clustering coefficient, etc.), node attribute features (such as node type, configuration, operating status, etc.) and interactive relationship features (such as communication traffic, data packet type, source and destination addresses, etc.). The extracted features are then encoded.
[0060] For network topology, the adjacency matrix method can be used for encoding. The adjacency matrix is a two-dimensional array that represents the connection relationship between nodes in the network. For node attributes, the attribute information of each node can be encoded into a feature vector. For example, the type, configuration, operating status and other attributes of the node can be converted into numerical or categorical labels, and these labels can be combined into a feature vector. For interaction relationships, time series data can be used for encoding, which can present interaction relationships that change over time.
[0061] The encoded network topology, node attributes, and interaction relationship features are integrated into a unified feature matrix, where each row represents a sample (such as the network state within a time window) and each column represents a feature.
[0062] S102, constructing a network situation awareness model based on a neural network, taking the feature matrix as the input of the network situation awareness model, and converting the input data into an output reflecting the network security situation through the nonlinear mapping capability of the neural network, wherein the output is a network situation awareness vector for indicating the security status of the current network.
[0063] It can be understood that the network situation awareness model based on neural network utilizes the powerful nonlinear mapping ability and self-learning ability of neural network, so that it can process complex network data and mine potential security threats. The extracted and integrated feature matrix is used as the input of the neural network, and the neural network is used to perceive the network security situation, and the dynamic risk assessment is performed based on the perception results to obtain the specific risk assessment value.
[0064] Through layer-by-layer calculation and transformation of the neural network, the input feature matrix is converted into a network situation awareness vector. This vector not only integrates multi-dimensional information of network topology, node attributes and interaction relationships, but also perceives the network security situation through the nonlinear mapping of the neural network to accurately reflect the current network security status, so as to quickly grasp the overall situation of network security and make timely decisions and responses.
[0065] S103, optimizing the parameters of the risk assessment model, and using the network situation awareness vector as the input of the optimized risk assessment model to perform risk assessment, and output a risk assessment value for assessing the size or severity of the current network security risk.
[0066] It is understandable that by optimizing and adjusting the risk assessment model parameters, it can better adapt to the dynamic changes of the network environment and more accurately capture potential security threats, thereby outputting accurate risk assessment results.
[0067] Although both the network situation awareness model and the risk assessment model need to be trained and verified to ensure their performance, their requirements for parameter optimization are different. The network situation awareness model does not require frequent parameter adjustments after training, because the key to the model is to extract useful information from the input feature matrix and convert it into an output vector that can reflect the network security situation. Once the model is trained and performs well, it can learn the effective features in the data and can be used in actual network situation awareness tasks. The risk assessment model, on the other hand, needs to continuously optimize its parameters according to changes in the network security environment to ensure that it can accurately reflect the current network security situation, because its goal is to further evaluate the size or severity of network security risks based on the output vector provided by the network situation awareness model. Since the network security environment is dynamically changing, new threats and vulnerabilities may appear at any time, so the risk assessment model needs to constantly adapt to these changes. Parameter optimization can enable the risk assessment model to maintain its accuracy and effectiveness, and can ensure that the risk assessment model accurately reflects the current network security situation.
[0068] After completing the parameter optimization of the risk assessment model, the network situation awareness vector is used as input and fed into the optimized risk assessment model for risk assessment. The risk assessment model outputs a clear risk assessment value through in-depth analysis of the network situation awareness vector to quantify the size or severity of the current network security risk. Such output provides network security managers with specific risk indicators, enabling them to more clearly understand the security status of the network and formulate targeted defense strategies accordingly.
[0069] Based on step S101 to step S103, by real-time monitoring of network data, dynamic changes in the network are captured instantly, and the characteristics of network topology, node attributes and interactive relationships are extracted from the network data. These characteristics can reflect the security status of the network in an all-round and multi-level manner, and the extracted characteristics are encoded and integrated into a unified feature matrix; then a network situation awareness model is constructed based on a neural network, and through its powerful nonlinear mapping ability, the input feature matrix is converted into an output reflecting the network security situation, that is, a network situation awareness vector, thereby realizing real-time and comprehensive perception of the network security situation; then the risk assessment model is parameter optimized to improve the accuracy and reliability of risk assessment, and the optimized risk assessment model takes the network situation awareness vector as input, and outputs a risk assessment value through the analysis of the model, which is used to reflect the size or severity of the current network security risk, and provides an important decision-making basis for network security management. The present invention realizes comprehensive perception of network security situation and accurate assessment of network security risks through the combination of fine feature extraction, neural network situation awareness and risk assessment, and can timely discover and respond to potential threats and risks in the network.
[0070] The following is a further detailed introduction to a network security situation awareness method according to an embodiment of the present invention:
[0071] Further optionally, in step S102, the step of constructing a network situation awareness model based on the neural network includes:
[0072] For each layer of the neural network, initialize the weight matrix and bias vector;
[0073] Take the feature matrix a0 as input data and calculate the output z of each layer i And the output after activation a i , the calculation formula is: i =W i a i-1 +b i , a i =σ(z i ), where σ is a nonlinear activation function, W i is the weight of each layer, b i is the bias of each layer;
[0074] For the output layer L, the output network situation awareness vector a L ;
[0075] Calculate the loss function based on the actual situation and the model's predicted output;
[0076] The gradient of the loss function with respect to the weights and bias terms is calculated through back propagation and updated;
[0077] Repeat the iteration, and terminate the iteration after the iteration termination condition is met to obtain the trained network situation awareness model.
[0078] It is understandable that the neural network extracts useful features from the input network data through layer-by-layer calculations and represents them as network situation awareness vectors. It also captures the complex relationships and patterns in the data through nonlinear activation functions, thereby more accurately reflecting the network security situation. This nonlinear mapping capability is unmatched by traditional linear models. The gradient of the loss function relative to the weight and bias terms is calculated through the back-propagation algorithm, and it is iteratively updated, so that the model can continuously learn new features in the data and optimize its performance. The neural network can adaptively adjust its parameters during the training process to adapt to changes in different network environments and security threats.
[0079] Further optionally, in step S103, the step of optimizing the parameters of the risk assessment model includes:
[0080] The parameters of the risk assessment model are optimized using the GWO algorithm.
[0081] Understandably, the GWO (Grey Wolf Optimization) algorithm has powerful global search capabilities and fast convergence characteristics. The global search capabilities of the GWO algorithm are used to adjust and improve the internal parameter settings of the risk assessment model to ensure that the model can more accurately quantify the size or severity of the current network security risks. Through the optimization of the GWO algorithm, the risk assessment model can better adapt to the dynamic changes in the network security environment, providing network security managers with more accurate and timely risk assessment results, so as to make more effective security decisions.
[0082] Further optionally, the step of optimizing the parameters of the risk assessment model by using the GWO algorithm includes:
[0083] Define an objective function to evaluate the performance of the risk assessment model under a given set of parameters;
[0084] A set of individuals is randomly generated, where each individual represents a set of parameters of the risk assessment model, including weights, bias terms, and learning rates in the model;
[0085] Calculate the fitness value of each individual through the objective function;
[0086] Update the position of each individual to be close to individuals a, β, and δ, where individuals a, β, and δ represent the optimal solution, suboptimal solution, and third optimal solution in the current population, respectively;
[0087] In each iteration, the a, β, and δ individuals are updated according to the fitness values;
[0088] After the iteration stop condition is met, the current position of individual a is output and set as the parameter of the optimized risk assessment model.
[0089] It can be understood that the GWO algorithm is used to optimize the parameters of the risk assessment model, and a set of optimal parameters is efficiently and accurately found to maximize the performance of the risk assessment model. In this process, the fitness of each individual, that is, the corresponding model performance, is evaluated through the objective function, and the individual position is iteratively updated according to the fitness value, so that they gradually approach the optimal solution (a individual), the second-best solution (β individual) and the third-best solution (δ individual) in the current population. Finally, after the iteration stop condition is met, the output optimal solution (i.e., the position of individual a) is set as the optimization parameter of the risk assessment model, thereby significantly improving the accuracy and reliability of the model's assessment of network security risks.
[0090] Further optionally, the step of updating the position of each individual to be closer to individuals a, β and δ includes:
[0091] For each dimension j (j=1, 2, ..., d), update according to the following formula: D α =|C1X α -Xi |, D β =|C2X β -X i |, D δ =|C3X δ -X i |, where X i is the current position of the individual, C1, C2, C3 are random coefficients, C1 = 2r1-1, C2 = 2r2-1, C3 = 2r3-1, r1, r2, r3 are random numbers between [0, 1];
[0092] Update the position of each individual, X i,new =X α -A1D α +A2D β -A3D δ , where X i,new is the position of the updated individual, A1, A2, A3 are random coefficients, A1 = 2ar4-a, A2 = 2ar5-a, A3 = 2ar6-a, r4, r5, r6 are random numbers between [0, 1], a is a parameter that decreases linearly with the number of iterations, a = 2-2t / T, t is the current number of iterations, and T is the maximum number of iterations;
[0093] Determine whether the updated individual's position is within the search space;
[0094] If it is in the search space, it is updated according to the position of the individual;
[0095] The iteration is repeated until the maximum number of iterations T is reached.
[0096] Understandably, the above formula is used, combined with the information of the current optimal solution (a individual), the second-best solution (β individual) and the third-best solution (δ individual), as well as the random coefficient and the linear decreasing parameter, to dynamically adjust the position of each individual in each dimension. Through continuous iteration, and judging whether the updated individual position is within the preset search space, the effectiveness and legitimacy of the search process are ensured. This process is used to efficiently explore the parameter space and quickly converge to the parameter combination that optimizes the performance of the risk assessment model, thereby improving the model's assessment accuracy and efficiency for network security risks.
[0097] Further optionally, after the step of determining whether the updated position of the individual is within the search space, the step further includes:
[0098] If it is not in the search space, the boundary value is taken.
[0099] Further optionally, the step of updating the a, β and δ individuals according to the fitness values includes:
[0100] Determine whether there is an individual among the current individuals whose fitness value is better than the current individual a;
[0101] If it exists, update individual a to the corresponding individual, and determine whether there is an individual with a better fitness value than the current β individual among the current individuals other than individual a;
[0102] If it exists, update the β individual to the corresponding individual, and check whether there is an individual with a better fitness value than the current δ individual among the current individuals other than a and β individuals;
[0103] If it exists, update the δ individuals to the corresponding individuals.
[0104] Understandably, the a, β, and δ individuals are updated according to the fitness values, thereby dynamically tracking and recording the optimal solution, suboptimal solution, and third-optimal solution in the current population. By comparing the fitness value of the current individual with the fitness values of the existing a, β, and δ individuals, the algorithm can promptly discover and update a better solution, thereby ensuring that the search process always proceeds in the direction of performance improvement. This update mechanism not only helps to speed up the convergence speed, but also effectively avoids the search from falling into the local optimum, thereby improving the globality and accuracy of the risk assessment model parameter optimization.
[0105] Further optionally, the step of using the network situation awareness vector as an input of the optimized risk assessment model to perform risk assessment and output a risk assessment value for assessing the size or severity of the current network security risk includes:
[0106] Inputting the situation awareness feature vector at the current moment into the optimized risk assessment model, wherein the risk assessment model is constructed based on a support vector machine;
[0107] In the inference prediction process of the risk assessment model, for each support vector, the similarity between the network situation awareness vector and the support vector is calculated to obtain a kernel function value;
[0108] Calculate the decision function value according to the kernel function value and the Lagrange multiplier;
[0109] According to the calculated decision function value, a risk assessment value is output, where the risk assessment value is a continuous numerical value used to represent the size or severity of the current network security risk.
[0110] It is understandable that the current situation awareness feature vector is input into the risk assessment model based on the support vector machine, and the powerful classification and regression capabilities of SVM are used to conduct in-depth analysis and interpretation of the network situation. In the inference and prediction process of the risk assessment model, the kernel function value is obtained by calculating the similarity between the network situation awareness vector and the support vector, and the decision function value is calculated in combination with the Lagrange multiplier, and finally a continuous value is output as the risk assessment value. This risk assessment value can intuitively reflect the size or severity of the current network security risk, provide accurate decision-making basis for network security managers, and help to timely discover and respond to potential security threats.
[0111] Embodiment 2
[0112] See also Figure 2 The present invention provides a network security situation awareness system, which includes:
[0113] Network data monitoring module: used to monitor network data in real time and perform preprocessing;
[0114] Network situation awareness module: used to build a network situation awareness model based on a neural network, taking the feature matrix as the input of the network situation awareness model, and converting the input data into an output reflecting the network security situation through the nonlinear mapping capability of the neural network. The output is a network situation awareness vector, which is used to represent the security status of the current network;
[0115] Network risk assessment module: used to optimize the parameters of the risk assessment model, and use the network situation awareness vector as the input of the optimized risk assessment model to perform risk assessment and output a risk assessment value for assessing the size or severity of the current network security risk.
[0116] Further optionally, the network situation awareness module is also used for:
[0117] For each layer of the neural network, initialize the weight matrix and bias vector;
[0118] Take the feature matrix a0 as input data and calculate the output z of each layer i And the output after activation a i , the calculation formula is: i =W i a i-1 +b i , a i =σ(z i ), where σ is a nonlinear activation function, W i is the weight of each layer, b i is the bias of each layer;
[0119] For the output layer L, the output network situation awareness vector a L ;
[0120] Calculate the loss function based on the actual situation and the model's predicted output;
[0121] The gradient of the loss function with respect to the weights and bias terms is calculated through back propagation and updated;
[0122] Repeat the iteration, and terminate the iteration after the iteration termination condition is met to obtain the trained network situation awareness model.
[0123] Further optionally, the network risk assessment module is also used to:
[0124] The parameters of the risk assessment model are optimized using the GWO algorithm.
[0125] Further optionally, the network risk assessment module is also used to:
[0126] Define an objective function to evaluate the performance of the risk assessment model under a given set of parameters;
[0127] A set of individuals is randomly generated, where each individual represents a set of parameters of the risk assessment model, including weights, bias terms, and learning rates in the model;
[0128] Calculate the fitness value of each individual through the objective function;
[0129] Update the position of each individual to be close to individuals a, β, and δ, where individuals a, β, and δ represent the optimal solution, suboptimal solution, and third optimal solution in the current population, respectively;
[0130] In each iteration, the a, β, and δ individuals are updated according to the fitness values;
[0131] After the iteration stop condition is met, the current position of individual a is output and set as the parameter of the optimized risk assessment model.
[0132] Further optionally, the network risk assessment module is also used to:
[0133] For each dimension j, update according to the following formula: α =|C1X α -X i |, D β =|C2X β -X i |, D δ =|C3X δ -X i |, where X iis the current position of the individual, C1, C2, C3 are random coefficients, C1 = 2r1-1, C2 = 2r2-1, C3 = 2r3-1, r1, r2, r3 are random numbers between [0, 1];
[0134] Update the position of each individual, X i,new =X α -A1D α +A2D β -A3D δ , where X i,new is the position of the updated individual, A1, A2, A3 are random coefficients, A1 = 2ar4-a, A2 = 2ar5-a, A3 = 2ar6-a, r4, r5, r6 are random numbers between [0, 1], a is a parameter that decreases linearly with the number of iterations, a = 2-2t / T, t is the current number of iterations, and T is the maximum number of iterations;
[0135] Determine whether the updated individual's position is within the search space;
[0136] If it is in the search space, it is updated according to the position of the individual;
[0137] The iteration is repeated until the maximum number of iterations T is reached.
[0138] Further optionally, the network risk assessment module is also used to:
[0139] If it is not in the search space, the boundary value is taken.
[0140] Further optionally, the network risk assessment module is also used to:
[0141] Determine whether there is an individual among the current individuals whose fitness value is better than the current individual a;
[0142] If it exists, update individual a to the corresponding individual, and determine whether there is an individual with a better fitness value than the current β individual among the current individuals other than individual a;
[0143] If it exists, update the β individual to the corresponding individual, and check whether there is an individual with a better fitness value than the current δ individual among the current individuals other than a and β individuals;
[0144] If it exists, update the δ individuals to the corresponding individuals.
[0145] Further optionally, the network risk assessment module is also used to:
[0146] Inputting the situation awareness feature vector at the current moment into the optimized risk assessment model, wherein the risk assessment model is constructed based on a support vector machine;
[0147] In the inference prediction process of the risk assessment model, for each support vector, the similarity between the network situation awareness vector and the support vector is calculated to obtain a kernel function value;
[0148] Calculate the decision function value according to the kernel function value and the Lagrange multiplier;
[0149] According to the calculated decision function value, a risk assessment value is output, where the risk assessment value is a continuous numerical value used to represent the size or severity of the current network security risk.
[0150] The above-mentioned embodiments only express several implementation methods of the present invention, and the description thereof is relatively specific and detailed, but it cannot be understood as limiting the scope of the patent of the present invention. It should be pointed out that, for ordinary technicians in this field, several variations and improvements can be made without departing from the concept of the present invention, which all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be subject to the attached claims.
Claims
1. A network security situation awareness method, characterized in that: The method comprises: Monitor network data in real time, extract network topology features, node attribute features, and interaction relationship features from the network data, encode them, and integrate them into a unified feature matrix; A network situation awareness model is constructed based on a neural network, the feature matrix is used as an input of the network situation awareness model, and the input data is converted into an output reflecting the network security situation through the nonlinear mapping capability of the neural network, the output is a network situation awareness vector used to represent the security status of the current network; Optimizing the parameters of the risk assessment model, and using the network situation awareness vector as the input of the optimized risk assessment model to perform risk assessment, and outputting a risk assessment value for assessing the size or severity of the current network security risk; The step of optimizing the parameters of the risk assessment model includes: The GWO algorithm is used to optimize the parameters of the risk assessment model, including: Define an objective function to evaluate the performance of the risk assessment model under a given set of parameters; A set of individuals is randomly generated, where each individual represents a set of parameters of a risk assessment model; Calculate the fitness value of each individual through the objective function; Update the position of each individual to be close to individuals α, β, and δ, where individuals α, β, and δ represent the optimal solution, suboptimal solution, and third optimal solution in the current population, respectively; In each iteration, the α, β, and δ individuals are updated according to their fitness values; After the iteration stop condition is met, the position of the current α individual is output and set as the parameter of the optimized risk assessment model; The step of updating the position of each individual to be closer to individuals α, β and δ comprises: For each dimension j, the update is performed according to the following formula: , , ,in, is the current location of the individual, is the random coefficient, , , , is a random number between [0, 1]; Update the position of each individual, ,in, is the updated position of the individual, is the random coefficient, , , , is a random number between [0, 1], a is a parameter that decreases linearly with the number of iterations, , t is the current iteration number, T is the maximum iteration number; Determine whether the updated individual's position is within the search space; If it is within the search space, the position of the individual is updated; Repeat the iteration until the maximum number of iterations T is reached.
2. The network security situation awareness method according to claim 1 is characterized in that: The step of constructing a network situation awareness model based on a neural network comprises: For each layer of the neural network, initialize the weight matrix and bias vector; The feature matrix As input data, calculate the output of each layer And the output after activation , the calculation formula is: , ,in, is a nonlinear activation function, is the weight of each layer, is the bias of each layer; For the output layer L, the output network situation awareness vector ; Calculate the loss function based on the actual situation and the model's predicted output; The gradient of the loss function with respect to the weights and bias terms is calculated through back propagation and updated; Repeat the iteration, and terminate the iteration after the iteration termination condition is met to obtain the trained network situation awareness model.
3. The network security situation awareness method according to claim 1 is characterized in that: After the step of determining whether the updated position of the individual is within the search space, the following step is further included: If it is not in the search space, the boundary value is taken.
4. The network security situation awareness method according to claim 1 is characterized in that: The step of updating the α, β and δ individuals according to the fitness values comprises: Determine whether there is an individual among the current individuals whose fitness value is better than the current α individuals; If it exists, update the α individual to the corresponding individual, and determine whether there is an individual with a better fitness value than the current β individual among the current individuals other than the α individual; If it exists, update the β individual to the corresponding individual, and check whether there is an individual with a better fitness value than the current δ individual among the current individuals other than the α and β individuals; If it exists, update the δ individuals to the corresponding individuals.
5. The network security situation awareness method according to claim 1 is characterized in that: The step of using the network situation awareness vector as the input of the optimized risk assessment model to perform risk assessment and output a risk assessment value for assessing the size or severity of the current network security risk includes: Inputting the situation awareness feature vector at the current moment into the optimized risk assessment model, wherein the risk assessment model is constructed based on a support vector machine; In the inference prediction process of the risk assessment model, for each support vector, the similarity between the network situation awareness vector and the support vector is calculated to obtain a kernel function value; Calculate the decision function value according to the kernel function value and the Lagrange multiplier; According to the calculated decision function value, a risk assessment value is output, where the risk assessment value is a continuous numerical value used to represent the size or severity of the current network security risk.
6. A network security situation awareness system, characterized in that: The system comprises: Network data monitoring module: used to monitor network data in real time, extract network topology features, node attribute features and interaction relationship features from the network data, encode them, and integrate them into a unified feature matrix; Network situation awareness module: used to build a network situation awareness model based on a neural network, use the feature matrix as the input of the network situation awareness model, and convert the input data into an output reflecting the network security situation through the nonlinear mapping ability of the neural network. The output is a network situation awareness vector, which is used to represent the security status of the current network; Network risk assessment module: used to optimize the parameters of the risk assessment model, and use the network situation awareness vector as the input of the optimized risk assessment model to perform risk assessment and output a risk assessment value for assessing the size or severity of the current network security risk; Wherein, the network risk assessment module is also used for: The GWO algorithm is used to optimize the parameters of the risk assessment model, including: Define an objective function to evaluate the performance of the risk assessment model under a given set of parameters; A set of individuals is randomly generated, where each individual represents a set of parameters of a risk assessment model; Calculate the fitness value of each individual through the objective function; Update the position of each individual to be close to individuals α, β, and δ, where individuals α, β, and δ represent the optimal solution, suboptimal solution, and third optimal solution in the current population, respectively; In each iteration, the α, β, and δ individuals are updated according to their fitness values; After the iteration stop condition is met, the position of the current α individual is output and set as the parameter of the optimized risk assessment model; The network risk assessment module is also used to: For each dimension j, the update is performed according to the following formula: , , ,in, is the current location of the individual, is the random coefficient, , , , is a random number between [0, 1]; Update the position of each individual, ,in, is the updated position of the individual, is the random coefficient, , , , is a random number between [0, 1], a is a parameter that decreases linearly with the number of iterations, , t is the current iteration number, T is the maximum iteration number; Determine whether the updated individual's position is within the search space; If it is within the search space, the position of the individual is updated; Repeat the iteration until the maximum number of iterations T is reached.
Citation Information
Patent Citations
Reactive power optimization and loss reduction method and system for power distribution area
CN115714397A
SAA-SSA-BPNN-based network security situation assessment method
CN116846565A
Low-conductivity working solution for optimizing neural network based on genetic algorithm and design method
CN117252084A
Network security data analysis system based on big data
CN118250102A