Network Security Awareness Method, System, Device and Medium Based on Big Data Analysis
By acquiring and analyzing network nodes and terminal data, calculating the fluctuation amount and slope, combined with periodic analysis, the problems of low efficiency and insufficient coverage in the existing technology are solved, and efficient and accurate monitoring of network terminals and nodes are achieved.
Patent Information
- Application Number
- CN202411560550.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-04
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2044-11-04
AI Technical Summary
When performing data security monitoring of information systems, the prior art has low efficiency and insufficient coverage capabilities, making it difficult to achieve efficient monitoring of network terminals and network nodes.
By obtaining network node data, network terminal data and network communication data, calculate data fluctuation, node slope and terminal slope, combine period length and peak and trough analysis to determine whether the network information data is abnormal, and achieve simultaneous monitoring of network terminals and network nodes.
It improves monitoring efficiency and coverage capabilities, ensures the accuracy and comprehensiveness of the analysis, and can detect abnormal situations in a timely manner.
Smart Images

Figure CN119420553B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and particularly relates to a network security perception method, system, device and medium based on big data analysis. Background Art
[0002] With the continuous improvement of the requirements for the informatization level of all walks of life, the in-depth development of informatization construction work, and the successive online operation of various industry core business systems, information technology is playing an increasingly important role in supporting the operation of each business, transforming the traditional industrial operation and management mode, and promoting enterprise management innovation. At the same time, the technical complexity, business relevance and data security difficulty of information systems are also continuously increasing, and the requirements for the security, stability and reliability of information systems are getting higher and higher.
[0003] In the prior art, when monitoring the data security of a system, it is usually to monitor the information content, which not only has low efficiency but also insufficient monitoring coverage. Summary of the Invention
[0004] The purpose of the present invention is to provide a network security perception method, system, device and medium based on big data analysis, which can realize the simultaneous monitoring of network terminals and network nodes, with high efficiency, sufficient coverage and high accuracy.
[0005] The first aspect of the present invention provides a network security perception method based on big data analysis, including:
[0006] Obtain network information data, where the network information data includes: network node data, network terminal data and network communication data;
[0007] Calculate the data fluctuation amount of the network communication data according to the peaks and valleys of the network communication data;
[0008] Determine the detection time period according to the cycle length, peaks and valleys of the network communication data;
[0009] Calculate the node slope of the network node data within the detection time period;
[0010] Calculate the terminal slope of the network terminal data within the detection time period;
[0011] Judge whether the network information data is abnormal according to the node slope, terminal slope and data fluctuation amount.
[0012] In some embodiments, the determining the detection time period according to the cycle length, peaks and valleys of the network communication data includes:
[0013] Compare the cycle length of the network communication data with a preset cycle threshold. If the cycle length of the network communication data is less than the cycle threshold, generate a low-cycle signal; if the cycle length of the network communication data is greater than or equal to the cycle threshold, generate a high-cycle signal;
[0014] Obtain the target time period between the peak and trough of the network communication data;
[0015] If the low-cycle signal appears, multiply the target time period by a first preset coefficient to obtain a detection time period; if the high-cycle signal appears, multiply the target time period by a second preset coefficient to obtain a detection time period.
[0016] In some embodiments, determining whether the network information data is abnormal according to the node slope, terminal slope, and data fluctuation amount includes:
[0017] Compare the node slope with a preset node change slope threshold. If the node slope is greater than or equal to the node change slope threshold, generate a multi-node signal; if the node slope is less than the node change slope threshold, generate a low-node signal;
[0018] Compare the terminal slope with a preset terminal change slope threshold. If the terminal slope is greater than or equal to the terminal change slope threshold, generate a multi-device signal; if the terminal slope is less than the terminal change slope threshold, generate a low-device signal;
[0019] Compare the data fluctuation amount with a preset data fluctuation amount threshold. If the data fluctuation amount is less than the data fluctuation amount threshold, generate a data stability signal; if the data fluctuation amount is greater than or equal to the data fluctuation amount threshold, generate a data fluctuation signal;
[0020] If the data fluctuation signal, multi-node signal, and low-device signal appear, output a data impact anomaly signal; if the data fluctuation signal, low-node signal, and low-device signal appear, output a data transmission anomaly signal.
[0021] In some embodiments, after outputting the data impact anomaly signal, it includes:
[0022] Obtain the terminal device with the largest received data volume in the network communication data to obtain a marked device;
[0023] Use the IP address corresponding to the marked device and the IP address sending data to the marked device as impact anomaly data, and record the impact anomaly data.
[0024] In some embodiments, after outputting the data transmission anomaly signal, it includes:
[0025] Obtain the terminal device with the largest amount of received data in the network communication data to obtain a marked device;
[0026] Obtain the network node with the largest amount of received data in the network communication data to obtain a marked node;
[0027] Take the IP address corresponding to the marked device and the IP address corresponding to the marked node as transmitted abnormal data, and record the transmitted abnormal data.
[0028] In some embodiments, calculating the data fluctuation amount of the network communication data according to the peaks and valleys of the network communication data includes:
[0029] Obtain the first data amount of the network communication data at the peak;
[0030] Obtain the second data amount of the network communication data at the valley;
[0031] Calculate the difference between the first data amount and the second data amount to obtain the data fluctuation amount.
[0032] In some embodiments, calculating the node slope of the network node data within a detection time period includes:
[0033] Obtain the first data point of the network node data at the starting point of the detection time period;
[0034] Obtain the second data point of the network node data at the ending point of the detection time period;
[0035] Calculate the slope between the first data point and the second data point to obtain the node slope;
[0036] Calculating the terminal slope of the network terminal data within a detection time period includes:
[0037] Obtain the third data point of the network terminal data at the starting point of the detection time period;
[0038] Obtain the fourth data point of the network terminal data at the ending point of the detection time period;
[0039] Calculate the slope between the third data point and the fourth data point to obtain the terminal slope.
[0040] The second aspect of the present invention provides a network security perception system based on big data analysis, including:
[0041] A data acquisition module for acquiring network information data, where the network information data includes: network node data, network terminal data, and network communication data;
[0042] A fluctuation quantity calculation module, configured to calculate the data fluctuation quantity of the network communication data according to the wave peaks and wave valleys of the network communication data;
[0043] A time period determination module, configured to determine a detection time period according to the cycle length, wave peaks, and wave valleys of the network communication data;
[0044] A first calculation module, configured to calculate the node slope of the network node data within the detection time period;
[0045] A second calculation module, configured to calculate the terminal slope of the network terminal data within the detection time period;
[0046] An abnormality determination module, configured to determine whether the network information data is abnormal according to the node slope, terminal slope, and data fluctuation quantity.
[0047] A third aspect of the present invention provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the steps of the above method are implemented.
[0048] A fourth aspect of the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above method are implemented.
[0049] The technical solution provided by the present invention has the following advantages and effects: By analyzing the network node data, network communication data, and network terminal data respectively, three analysis results, namely the corresponding node slope, data fluctuation quantity, and terminal slope, are obtained. Corresponding combined analysis is performed according to the changes in the data volumes of the three. Whether the network information data is abnormal is judged according to the analysis results, thereby realizing the simultaneous monitoring of network terminals and network nodes, with high efficiency and sufficient coverage ability. Moreover, through the mutual assistance of the three analysis results, the accuracy of the analysis is further improved. Description of the Drawings
[0050] Figure 1 is a flowchart of a network security perception method based on big data analysis provided by the present invention;
[0051] Figure 2 is a structural block diagram of a network security perception system based on big data analysis provided by the present invention;
[0052] Figure 3 is an internal structure diagram of a computer device provided by an embodiment of the present invention. Detailed Embodiments
[0053] To facilitate the understanding of the present invention, the specific embodiments of the present invention will be described in more detail below with reference to the accompanying drawings of the specification.
[0054] Unless otherwise specified or defined, the "first, second, ..." used in this article is only for differentiating names and does not represent a specific quantity or order.
[0055] Unless otherwise specified or defined, the term "and / or" used in this article includes any and all combinations of one or more of the related listed items.
[0056] It should be noted that in this article, "fixed to" and "connected to" can be directly fixed or connected to an element, or indirectly fixed or connected to an element.
[0057] As Figure 1 shown, in this embodiment, a network security awareness method based on big data analysis is provided, including the following steps S1 to S6:
[0058] Step S1, obtain network information data, where the network information data includes: network node data, network terminal data, and network communication data.
[0059] In practical applications, network nodes are servers or information relay devices, etc., network terminals are clients, and each network node and each network terminal have a unique IP address. Network nodes and network terminals communicate with each other, and network nodes also communicate with each other. Network communication data is the sum of the communication data volume between network nodes and network terminals and the communication data volume between network nodes. Network node data is the number of network nodes connected to the network, and network terminal data is the number of network terminals connected to the network.
[0060] Step S2, calculate the data fluctuation amount of the network communication data according to the peaks and valleys of the network communication data.
[0061] Specifically, calculating the data fluctuation amount of the network communication data according to the peaks and valleys of the network communication data includes the following sub-steps:
[0062] Step S21, obtain the first data volume of the network communication data at the peak;
[0063] Step S22, obtain the second data volume of the network communication data at the valley;
[0064] Step S23, calculate the difference between the first data volume and the second data volume to obtain the data fluctuation amount.
[0065] In practical applications, after real-time acquisition of network node data, network terminal data, and network communication data, a coordinate system is established with time as the horizontal axis and the data volume as the vertical axis, and data volume change curves of the network node data, network terminal data, and network communication data are plotted. According to the data volume change curve of the network communication data, the first data volume at the peak and the second data volume at the trough can be obtained, and the data fluctuation volume of the network communication data is obtained by subtracting the second data volume from the first data volume. By establishing a coordinate system and plotting data volume change curves of various types of data in the coordinate system, the abstraction of data is made concrete and visualized, which can effectively reflect the changes in various types of data volumes, thereby facilitating security analysis based on historical data to improve system security.
[0066] Further, in the case of real-time acquisition of network communication data, the method for determining whether a data point on the network communication data is a peak or a trough includes:
[0067] Obtain the data volumes to be compared of all data points within a preset time period on both sides of the target data point;
[0068] Compare the data volume of the target data point with all the data volumes to be compared. If the data volume of the target data point is greater than all the data volumes to be compared, the target data point is a peak; if the data volume of the target data point is less than all the data volumes to be compared, the target data point is a trough.
[0069] Specifically, obtaining the data volumes to be compared of all data points within a preset time period on both sides of the target data point means obtaining the data volumes to be compared of all data points within the preset time period before the target data point and within the preset time period after the target data point. For example, if the time point corresponding to the target data point is 9:10 and the preset time period is 10 minutes, then obtain the data volumes of all data points between 9:00 and 9:10 and between 9:10 and 9:20. The obtained time points do not include the target data point corresponding to 9:10, and then compare the data volume of the target data point with the data volumes of all data points between 9:00 and 9:10 and between 9:10 and 9:20 to determine whether the data point is a peak or a trough.
[0070] Step S3: Determine the detection time period according to the cycle length, peak, and trough of the network communication data.
[0071] Specifically, the determination of the detection time period according to the cycle length, peak, and trough of the network communication data includes the following steps:
[0072] Step S31: Compare the cycle length of the network communication data with a preset cycle threshold. If the cycle length of the network communication data is less than the cycle threshold, generate a low-cycle signal; if the cycle length of the network communication data is greater than or equal to the cycle threshold, generate a high-cycle signal.
[0073] In practical applications, network communication data is periodic. By plotting the curve of the change in the amount of network communication data on a coordinate system, the period length of the network communication data can be obtained. For example, after obtaining the peaks and valleys of the network communication data, the time period between adjacent peaks is used as the period length of the network communication data. This period length is compared with a period threshold. When the period length is less than the period threshold, a low-period signal is generated, that is, the network communication data is used as the low-period signal. When the period length is greater than or equal to the period threshold, a high-period signal is generated, that is, the network communication data is used as the high-period signal.
[0074] Step S32: Obtain the target time period between the peak and valley of the network communication data.
[0075] In practical applications, the time period between the peak and valley of the network communication data is used as the target time period. For example, if the time at the peak is 10 o'clock and the time at the valley is 11 o'clock, then the target time period is from 10 o'clock to 11 o'clock.
[0076] Step S33: If the low-period signal appears, multiply the target time period by a first preset coefficient to obtain a detection time period. If the high-period signal appears, multiply the target time period by a second preset coefficient to obtain a detection time period.
[0077] In practical applications, the first preset coefficient is less than the second preset coefficient. When the network communication data is used as the low-period signal, it means that the period of the network communication data is short and the frequency of the network communication data is high. By expanding the target time period with the first preset coefficient, both the number of samples can be increased and the amount of data outside the peaks and valleys can be prevented from being collected. When the network communication data is used as the high-period signal, it means that the period of the network communication data is long and the frequency of the network communication data is low. By expanding the target time period with the second preset coefficient, compared with the expansion in the case of the low-period signal, the expanded time period is increased.
[0078] Specifically, the expanded time period can be expanded before and / or after the target time period. If it is expanded before and after the target time period, after dividing the expanded time period equally, it is respectively added before and after the target time period. For example, if the target time is from 10 o'clock to 11 o'clock and the expanded time period is 10 minutes, then the detection time period is from 9:55 to 11:05, which is used for subsequent calculation of the node slope and the terminal slope.
[0079] Step S4: Calculate the node slope of the network node data within the detection time period.
[0080] Specifically, calculating the node slope of the network node data within the detection time period includes the following steps:
[0081] Step S41: Obtain the first data point at the starting point of the detection time period of the network node data;
[0082] Step S42: Obtain the second data point at the ending point of the detection time period of the network node data;
[0083] Step S43: Calculate the slope between the first data point and the second data point to obtain the node slope.
[0084] In practical applications, after plotting the data volume change curve of the network node data in the coordinate system, the first data point at the starting point of the detection time period of the network node data and the second data point at the ending point of the detection time period can be obtained. Then, divide the difference between the data volume of the first data point and the data volume of the second data point by the detection time period to obtain the node slope of the network node data, so as to facilitate subsequent judgment of the network node status based on the node slope. If the difference between the data volume of the first data point and the data volume of the second data point is 8, and the detection time period is from 9:55 to 11:05, a total of 70 minutes, then the node slope is 0.11.
[0085] Step S5: Calculate the terminal slope of the network terminal data within the detection time period.
[0086] Specifically, the calculation of the terminal slope of the network terminal data within the detection time period includes the following steps:
[0087] Step S51: Obtain the third data point at the starting point of the detection time period of the network terminal data;
[0088] Step S52: Obtain the fourth data point at the ending point of the detection time period of the network terminal data;
[0089] Step S53: Calculate the slope between the third data point and the fourth data point to obtain the terminal slope.
[0090] In practical applications, after plotting the data volume change curve of the network terminal data in the coordinate system, the third data point at the starting point of the detection time period of the network terminal data and the fourth data point at the ending point of the detection time period can be obtained. Then, divide the difference between the data volume of the third data point and the data volume of the fourth data point by the detection time period to obtain the terminal slope of the network terminal data, so as to facilitate subsequent judgment of the network terminal status based on the terminal slope. If the difference between the data volume of the third data point and the data volume of the fourth data point is 10, and the detection time period is from 9:55 to 11:05, a total of 70 minutes, then the node slope is 0.14.
[0091] Step S6: Judge whether the network information data is abnormal according to the node slope, terminal slope, and data fluctuation amount.
[0092] Specifically, determining whether the network information data is abnormal according to the node slope, terminal slope, and data fluctuation amount includes the following steps:
[0093] Step S61: Compare the node slope with a preset node change slope threshold. If the node slope is greater than or equal to the node change slope threshold, generate a multi-node signal; if the node slope is less than the node change slope threshold, generate a low-node signal.
[0094] Specifically, if the node slope is greater than or equal to the node change slope threshold, it means that the number of network nodes added is greater than or equal to the preset increase number, and a multi-node signal is generated; if the node slope is less than the node change slope threshold, it means that the number of network nodes added is less than the preset increase number, and a low-node signal is generated.
[0095] Step S62: Compare the terminal slope with a preset terminal change slope threshold. If the terminal slope is greater than or equal to the terminal change slope threshold, generate a multi-device signal; if the terminal slope is less than the terminal change slope threshold, generate a low-device signal.
[0096] Specifically, if the terminal slope is greater than or equal to the terminal change slope threshold, it means that the number of network terminals added is greater than or equal to the preset increase number, and a multi-device signal is generated; if the terminal slope is less than the terminal change slope threshold, it means that the number of network terminals added is less than the preset increase number, and a low-device signal is generated.
[0097] Step S63: Compare the data fluctuation amount with a preset data fluctuation amount threshold. If the data fluctuation amount is less than the data fluctuation amount threshold, generate a data stability signal; if the data fluctuation amount is greater than or equal to the data fluctuation amount threshold, generate a data fluctuation signal.
[0098] Specifically, if the data fluctuation amount is greater than or equal to the data fluctuation amount threshold, it means that the increased value of the data volume is greater than or equal to the preset increased value, and a data fluctuation signal is generated; if the data fluctuation amount is less than the data fluctuation amount threshold, it means that the increased value of the data volume is less than the preset increased value, and a data stability signal is generated.
[0099] Step S64: If the data fluctuation signal, multi-node signal, and low-device signal appear, output a data impact anomaly signal; if the data fluctuation signal, low-node signal, and low-device signal appear, output a data transmission anomaly signal.
[0100] In practical applications, when data fluctuation signals, multi-node signals, and multi-device signals occur, no response is made. By analyzing network node data, network communication data, and network terminal data respectively, three analysis results, namely the corresponding node slope, data fluctuation amount, and terminal slope, are obtained. According to the changes in the data volumes of the three, corresponding combined analysis is carried out, and different abnormal signals are generated based on different analysis results, thereby realizing the simultaneous monitoring of network terminals and network nodes, with high efficiency and sufficient coverage ability. Moreover, through the mutual assistance of the three analysis results, the accuracy of the analysis is further improved.
[0101] Further, after the abnormal data impact signal is output, the following steps are included:
[0102] Step S641: Obtain the terminal device with the largest received data volume in the network communication data to obtain a marked device;
[0103] Step S642: Use the IP address of the marked device and the IP address sending data to the marked device as abnormal impact data, and record the abnormal impact data.
[0104] In practical applications, in the case of low-device signals and multi-node signals, when a data fluctuation signal appears, it indicates that a device has received an abnormal data volume. Then, the terminal device with the largest data volume is selected from the network communication data for marking to obtain a marked device. Usually, a large number of IP addresses send data to the marked device, so all the IP addresses sending data to the marked device and the IP address of the marked device are used as abnormal impact data for recording.
[0105] Further, after the abnormal data transfer signal is output, the following steps are included:
[0106] Step S643: Obtain the terminal device with the largest received data volume in the network communication data to obtain a marked device;
[0107] Step S644: Obtain the network node with the largest received data volume in the network communication data to obtain a marked node;
[0108] Step S645: Use the IP address of the marked device and the IP address of the marked node as abnormal transfer data, and record the abnormal transfer data.
[0109] In practical applications, when low device signals and low node signals occur and data fluctuation signals appear, it indicates that a device has received an abnormal amount of data. Then, the terminal device with the largest data volume is selected from the network communication data for marking to obtain a marked device, and the network node with the largest transmitted data volume is selected from the network communication data for marking to obtain a marked node. Then, the IP address corresponding to the marked device and the IP address corresponding to the marked node are both recorded as the transmitted abnormal data.
[0110] Furthermore, after obtaining the impact abnormal data, a data attack abnormal reminder is output. After obtaining the transmitted abnormal data, a data transmission abnormal reminder is output. After obtaining the impact abnormal data or the transmitted abnormal data, the impact abnormal data or the transmitted abnormal data can also be stored, thus avoiding the difficulty in finding or loss of the impact abnormal data or the transmitted abnormal data during recheck. At the same time, corresponding labels are established for the abnormal data and the corresponding abnormal reminders, which is convenient for management personnel to retrieve and view the abnormal data.
[0111] As Figure 2 shown, an embodiment of the present invention also provides a network security awareness system based on big data analysis, including:
[0112] A data acquisition module 10, configured to acquire network information data, where the network information data includes: network node data, network terminal data, and network communication data;
[0113] A fluctuation amount calculation module 20, configured to calculate the data fluctuation amount of the network communication data according to the wave peaks and wave valleys of the network communication data;
[0114] A time period determination module 30, configured to determine a detection time period according to the cycle length, wave peaks, and wave valleys of the network communication data;
[0115] A first calculation module 40, configured to calculate the node slope of the network node data within the detection time period;
[0116] A second calculation module 50, configured to calculate the terminal slope of the network terminal data within the detection time period;
[0117] An abnormality determination module 60, configured to determine whether the network information data is abnormal according to the node slope, terminal slope, and data fluctuation amount.
[0118] As an optional implementation manner, the time period determination module includes the following units not shown in the figure:
[0119] A comparison unit for comparing the cycle length of the network communication data with a preset cycle threshold. If the cycle length of the network communication data is less than the cycle threshold, a low-cycle signal is generated; if the cycle length of the network communication data is greater than or equal to the cycle threshold, a high-cycle signal is generated;
[0120] A time period acquisition unit for acquiring the target time period between the peak and trough of the network communication data;
[0121] A time period calculation unit for multiplying the target time period by a first preset coefficient to obtain a detection time period if the low-cycle signal appears, and multiplying the target time period by a second preset coefficient to obtain a detection time period if the high-cycle signal appears.
[0122] As an optional implementation manner, the anomaly judgment module includes the following units not shown in the figure:
[0123] A first comparison unit for comparing the node slope with a preset node change slope threshold. If the node slope is greater than or equal to the node change slope threshold, a multi-node signal is generated; if the node slope is less than the node change slope threshold, a low-node signal is generated;
[0124] A second comparison unit for comparing the terminal slope with a preset terminal change slope threshold. If the terminal slope is greater than or equal to the terminal change slope threshold, a multi-device signal is generated; if the terminal slope is less than the terminal change slope threshold, a low-device signal is generated;
[0125] A third comparison unit for comparing the data fluctuation amount with a preset data fluctuation amount threshold. If the data fluctuation amount is less than the data fluctuation amount threshold, a data stability signal is generated; if the data fluctuation amount is greater than or equal to the data fluctuation amount threshold, a data fluctuation signal is generated;
[0126] An output unit for outputting a data impact anomaly signal if the data fluctuation signal, multi-node signal, and low-device signal appear, and outputting a data transmission anomaly signal if the data fluctuation signal, low-node signal, and low-device signal appear.
[0127] In some embodiments, the output unit includes the following units not shown in the figure:
[0128] A first marking unit for obtaining the terminal device with the largest received data volume in the network communication data after outputting the data impact anomaly signal to obtain a marked device;
[0129] A first recording unit for recording the IP address corresponding to the marked device and the IP address sending data to the marked device as impact anomaly data.
[0130] In some embodiments, the output unit further includes the following units not shown in the figure:
[0131] A second marking unit, configured to, after the output data transfer anomaly signal is sent, obtain the terminal device with the largest received data volume in the network communication data to obtain a marked device;
[0132] A third marking unit, configured to obtain the network node with the largest received data volume in the network communication data to obtain a marked node;
[0133] A second recording unit, configured to use the IP address corresponding to the marked device and the IP address corresponding to the marked node as transfer anomaly data, and record the transfer anomaly data.
[0134] In some embodiments, the fluctuation amount calculation module includes the following units not shown in the figure:
[0135] A first acquisition unit, configured to acquire a first data volume of the network communication data at the wave crest;
[0136] A second acquisition unit, configured to acquire a second data volume of the network communication data at the wave trough;
[0137] A data volume calculation unit, configured to calculate the difference between the first data volume and the second data volume to obtain a data fluctuation amount.
[0138] In some embodiments, the first calculation module includes the following units not shown in the figure:
[0139] A third acquisition unit, configured to acquire a first data point of the network node data at the start point of the detection time period;
[0140] A fourth acquisition unit, configured to acquire a second data point of the network node data at the end point of the detection time period;
[0141] A node slope calculation unit, configured to calculate the slope between the first data point and the second data point to obtain a node slope.
[0142] In some embodiments, the second calculation module includes the following units not shown in the figure:
[0143] A fifth acquisition unit, configured to acquire a third data point of the network terminal data at the start point of the detection time period;
[0144] A sixth acquisition unit, configured to acquire a fourth data point of the network terminal data at the end point of the detection time period;
[0145] A terminal slope calculation unit, configured to calculate the slope between the third data point and the fourth data point to obtain a terminal slope.
[0146] Each module of the above network security awareness system based on big data analysis can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above modules and units can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so as to facilitate the processor to call and execute the operations corresponding to each of the above modules.
[0147] As Figure 3 shown, an embodiment of the present invention discloses a computer device, including a memory and a processor, where the memory stores a computer program;
[0148] Among them, the computer device can be a server, and its internal structure diagram can be as Figure 3 shown. The computer device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it realizes the network security awareness method based on big data analysis described in the above embodiments.
[0149] Those skilled in the art can understand that Figure 3 the structure shown in
[0150] is only a block diagram of a part of the structure related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0151] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0152] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
Claims
1. A network security awareness method based on big data analysis, characterized in that, Including: Obtain network information data, where the network information data includes: network node data, network terminal data, and network communication data; Calculate the data fluctuation amount of the network communication data according to the peaks and valleys of the network communication data; Determine the detection time period according to the cycle length, peak, and valley of the network communication data; Calculate the node slope of the network node data within the detection time period, where the node slope represents the slope of the number of network nodes within the detection time period; Calculate the terminal slope of the network terminal data within the detection time period, where the terminal slope represents the slope of the number of network terminals within the detection time period; Judge whether the network information data is abnormal according to the node slope, terminal slope, and data fluctuation amount; The judging whether the network information data is abnormal according to the node slope, terminal slope, and data fluctuation amount includes: Compare the node slope with a preset node change slope threshold. If the node slope is greater than or equal to the node change slope threshold, generate a multi-node signal. If the node slope is less than the node change slope threshold, generate a low-node signal; Compare the terminal slope with a preset terminal change slope threshold. If the terminal slope is greater than or equal to the terminal change slope threshold, generate a multi-device signal. If the terminal slope is less than the terminal change slope threshold, generate a low-device signal; Compare the data fluctuation amount with a preset data fluctuation amount threshold. If the data fluctuation amount is less than the data fluctuation amount threshold, generate a data stability signal. If the data fluctuation amount is greater than or equal to the data fluctuation amount threshold, generate a data fluctuation signal; If the data fluctuation signal, multi-node signal, and low-device signal appear, output a data impact abnormal signal. If the data fluctuation signal, low-node signal, and low-device signal appear, output a data transmission abnormal signal.
2. The network security awareness method based on big data analysis according to claim 1, wherein, The determining the detection time period according to the cycle length, peak, and valley of the network communication data includes: Compare the cycle length of the network communication data with a preset cycle threshold. If the cycle length of the network communication data is less than the cycle threshold, generate a low-cycle signal. If the cycle length of the network communication data is greater than or equal to the cycle threshold, generate a high-cycle signal; Obtain the target time period between the peak and valley of the network communication data; If the low-cycle signal appears, multiply the target time period by a first preset coefficient to obtain the detection time period. If the high-cycle signal appears, multiply the target time period by a second preset coefficient to obtain the detection time period.
3. The network security awareness method based on big data analysis according to claim 1, characterized in that, After the output of the data impact abnormal signal, it includes: Obtain the terminal device with the largest received data volume in the network communication data to obtain a marked device; Use the IP address corresponding to the marked device and the IP address sending data to the marked device as impact abnormal data, and record the impact abnormal data.
4. The network security awareness method based on big data analysis according to claim 1, wherein After the output of the data transmission abnormal signal, it includes: Obtain the terminal device with the largest received data volume in the network communication data to obtain a marked device; Obtain the network node with the largest received data volume in the network communication data to obtain a marked node; Take the IP address corresponding to the marking device and the IP address corresponding to the marking node as the transmitted abnormal data, and record the transmitted abnormal data.
5. The network security awareness method based on big data analysis according to any one of claims 1-4, characterized in that, The calculating the data fluctuation amount of the network communication data according to the peaks and valleys of the network communication data includes: Obtain the first data amount of the network communication data at the peak; Obtain the second data amount of the network communication data at the valley; Calculate the difference between the first data amount and the second data amount to obtain the data fluctuation amount.
6. The network security awareness method based on big data analysis according to any one of claims 1-4, characterized in that, The calculating the node slope of the network node data within the detection time period includes: Obtain the first data point of the network node data at the starting point of the detection time period; Obtain the second data point of the network node data at the ending point of the detection time period; Calculate the slope between the first data point and the second data point to obtain the node slope; The calculating the terminal slope of the network terminal data within the detection time period includes: Obtain the third data point of the network terminal data at the starting point of the detection time period; Obtain the fourth data point of the network terminal data at the ending point of the detection time period; Calculate the slope between the third data point and the fourth data point to obtain the terminal slope.
7. A network security perception system based on big data analysis, characterized in that a data acquisition module, configured to acquire network information data, where the network information data includes: network node data, network terminal data, and network communication data; a fluctuation amount calculation module, configured to calculate the data fluctuation amount of the network communication data according to the peaks and valleys of the network communication data; a time period determination module, configured to determine a detection time period according to the cycle length, peaks, and valleys of the network communication data; a first calculation module, configured to calculate the node slope of the network node data within the detection time period, where the network node data represents the number of network nodes; a second calculation module, configured to calculate the terminal slope of the network terminal data within the detection time period, where the network terminal data represents the number of network terminals; an abnormality determination module, configured to determine whether the network information data is abnormal according to the node slope, terminal slope, and data fluctuation amount; The determining whether the network information data is abnormal according to the node slope, terminal slope, and data fluctuation amount includes: Compare the node slope with a preset node change slope threshold. If the node slope is greater than or equal to the node change slope threshold, generate a multi-node signal. If the node slope is less than the node change slope threshold, generate a low-node signal; Compare the terminal slope with a preset terminal change slope threshold. If the terminal slope is greater than or equal to the terminal change slope threshold, generate a multi-device signal. If the terminal slope is less than the terminal change slope threshold, generate a low-device signal; Compare the data fluctuation amount with a preset data fluctuation amount threshold. If the data fluctuation amount is less than the data fluctuation amount threshold, generate a data stability signal. If the data fluctuation amount is greater than or equal to the data fluctuation amount threshold, generate a data fluctuation signal; If the data fluctuation signal, multi-node signal, and low device signal appear, a data impact anomaly signal is output. If the data fluctuation signal, low node signal, and low device signal appear, a data transmission anomaly signal is output.
8. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1-6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1-6 are implemented.
Citation Information
Patent Citations
Network traffic monitoring method and system
CN107579981A
Network attack detection method, device and equipment and storage medium
CN109951491A