A network data risk assessment system for a computer

By designing a network data risk assessment system for computers, using machine learning algorithms to identify abnormal patterns and evaluate the degree of threat, the problem of response lag in the prior art is solved, and the effect of rapid response and improving network security is achieved.

CN119449432BActive Publication Date: 2025-06-20XIAMEN DUODUO CLOUD TECHNOLOGY INNOVATION RESEARCH INSTITUTE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411598002.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-11
Publication Date
2025-06-20
Estimated Expiration
2044-11-11

AI Technical Summary

Technical Problem

The existing technology is difficult to identify and evaluate new security threats in the network environment in real time, resulting in the system's response lagging in the face of emergencies of security incidents and unable to take effective protective measures in a timely manner.

Method used

A network data risk assessment system for computers is designed, including a data monitoring platform, data acquisition module, data preprocessing module, abnormality detection module, threat assessment module, automatic alarm module, response policy generation module and report generation module. The system uses machine learning algorithm to identify abnormal patterns, evaluate the degree of threat, and automatically trigger protection measures to achieve rapid response.

Benefits of technology

The system can quickly and accurately identify abnormal behaviors in the network, improve the accuracy of identification of threats, and automatically trigger protection measures, reduce the damage to the system by security incidents, and significantly improve the overall security and resilience of the network system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119449432B_ABST
    Figure CN119449432B_ABST
Patent Text Reader

Abstract

The present invention discloses a network data risk assessment system for a computer. The present invention relates to the technical field of data security monitoring, and includes a data monitoring platform. The data monitoring platform is communicatively connected to a data acquisition module, a data preprocessing module, an anomaly detection module, a threat assessment module, an automatic alarm module, a response strategy generation module, and a report generation module. Among them, the modules are electrically connected to each other. The network data risk assessment system for a computer realizes the rapid detection and response to network threats by integrating functions such as anomaly detection, threat assessment, response strategy generation, and automatic alarm. It uses machine learning technology to identify abnormal patterns, discovers potential security threats, and improves the accuracy of identifying abnormal behaviors. In addition, it automatically triggers preset protection measures, so as to quickly respond when detecting high-risk threats and reduce the damage of security incidents to the system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security monitoring, and particularly to a network data risk assessment system for a computer. Background Art

[0002] With the rapid development of information technology and the popularization of the Internet, computer networks have become an indispensable infrastructure in modern society. However, this also makes the cyberspace face increasingly complex threats, such as hacker attacks, data leaks, malware, etc. These threats may not only lead to the loss or leakage of important information, but also affect the normal operation of enterprises, and even bring significant economic losses and reputation risks. Therefore, risk assessment of network data has become an important measure to ensure network security.

[0003] In the prior art, the network environment changes rapidly and there is interference from multi-dimensional data, making it difficult to identify and evaluate new security threats in real time, resulting in a lag in the system's response to sudden security incidents and the inability to take effective protection measures in a timely manner. Therefore, how to improve the recognition efficiency of abnormal patterns to quickly respond to protection measures is the problem we need to solve. For this reason, a network data risk assessment system for a computer is proposed. Summary of the Invention

[0004] To achieve the above objectives, the present invention is realized through the following technical solutions: A network data risk assessment system for a computer, including a data monitoring platform, which is communicatively connected to a data collection module, a data preprocessing module, an anomaly detection module, a threat assessment module, an automatic alarm module, a response strategy generation module, and a report generation module. Among them, the modules are electrically connected to each other;

[0005] The data collection module collects various raw data from various network devices and systems, including traffic data, log files, and system status information, ensuring the comprehensiveness and real-time nature of the data and providing basic data support for risk assessment;

[0006] The data preprocessing module is used to perform preprocessing on the collected raw data, including cleaning, formatting, and normalizing, removing noise and redundant information, and extracting abnormal features for risk assessment from the preprocessed data to obtain an abnormal network traffic feature set and an abnormal system status feature set, improving the data processing efficiency, providing a high-quality data set for subsequent analysis, and converting a large amount of data into key features to facilitate the model to more efficiently perform risk assessment;

[0007] The anomaly detection module uses machine learning algorithms combined with abnormal features to identify abnormal patterns in the preprocessed data, discovers potential security threats, and quickly and accurately identifies abnormal behaviors in the network, providing clues for timely response;

[0008] The threat assessment module is used to deeply analyze the detected abnormal behaviors, evaluate their potential threat levels, including threat types and influence scopes, determine their potential risk levels to the system, provide accurate threat intelligence for formulating protection measures, and ensure the effective allocation of resources;

[0009] The automatic alarm module continuously monitors the network status and conducts real-time monitoring and alarming for abnormal situations;

[0010] The response strategy generation module is used to automatically generate and recommend protection strategies of corresponding levels according to the threat assessment results;

[0011] The report generation module is used to record all key events and operations during the system operation, and generate detailed audit logs and risk assessment reports.

[0012] Preferably, in the data collection module, the process of collecting raw data includes:

[0013] Identify the network devices and systems for which data needs to be collected, including servers, routers, firewalls, intrusion detection systems, and applications, clarify the data sources, and ensure the comprehensiveness of data collection;

[0014] According to the network devices and systems for which data needs to be collected, determine the data types, collection frequencies, and storage formats and locations of the data. The data types include network traffic data, system status information, and log files, and configure data collection methods according to different data types;

[0015] According to the data collection objectives and methods, deploy data collection agents on each data source, configure corresponding data collectors, set collection parameters and rules, ensure the stable operation of the data collectors, and establish reliable connections with the target network devices and systems;

[0016] The data collector captures the raw data of network traffic data and system status information from the target network devices and systems, converts it into a unified data format, and transmits it to the central data warehouse through the network.

[0017] Preferably, in the data preprocessing module, the process of obtaining the abnormal network traffic feature set and the abnormal system status feature set includes:

[0018] Perform preprocessing operations on the raw data of the collected network traffic data, system status information, and log files. The preprocessing operations include steps of cleaning, formatting, and normalizing;

[0019] Using the correlation coefficient to combine the preprocessed network traffic data and system status information data, identify the features associated with risk assessment, and perform feature extraction to obtain abnormal features for risk assessment. Extract the associated data of abnormal network traffic and abnormal system status information to form an abnormal network traffic feature set and an abnormal system status feature set. Among them, the abnormal features of network traffic data include sudden increase in traffic, sudden decrease in traffic, abnormal traffic patterns, abnormal packet sizes, and frequent connection failures. The abnormal features of system status information include sudden increase in CPU usage rate, sudden increase in memory usage rate, sudden increase in disk usage rate, abnormal network connection, and system configuration changes;

[0020] Perform encoding processing on the abnormal features in the abnormal network traffic feature set and the abnormal system status feature set, convert non-numerical data into numerical data, and make the data suitable for numerical calculations.

[0021] Preferably, in the abnormal detection module, the process of identifying abnormal patterns includes:

[0022] Respectively extract the associated data of abnormal network traffic data and abnormal system status information applied to risk assessment from the abnormal network traffic feature set and the abnormal system status feature set. Among them, for abnormal network traffic data, extract the network traffic value, total network traffic, and total abnormal network traffic within the observation time range, and determine the baseline value of network traffic based on the average value of normal network traffic. For abnormal system status information, extract the system status value, number of configuration changes, and average system status value of each system status indicator within the observation time range, and determine the baseline value of system status based on the average value of normal system status;

[0023] According to the time series characteristics of network traffic data, combine the time series analysis algorithm and abnormal network traffic data to train a network traffic analysis model, and conduct verification and evaluation on the constructed network traffic analysis model, and make necessary adjustments to improve performance to analyze the abnormal degree of network traffic;

[0024] According to the static and dynamic characteristics of system status information, use the clustering algorithm to identify abnormal system configurations and behaviors, combine abnormal system status information to train a system status analysis model, and conduct verification and evaluation on the constructed system status analysis model, and adjust parameters to identify abnormal system configurations and behaviors;

[0025] Combine the output of the network traffic analysis model and abnormal network traffic data to obtain a traffic assessment index, analyze the abnormal degree of network traffic, combine the output of the system status analysis model and abnormal system status information to obtain a status assessment index, and measure the health status and abnormal trend of the system.

[0026] Preferably, the calculation expression of the traffic assessment index is:

[0027] ;

[0028] Among them, is the traffic evaluation index, is the network traffic value at the th time point, is the baseline value of the network traffic, is the number of observed time points, is the total abnormal network traffic during the observation period, is the total network traffic during the observation period, The lower the value, the more normal the network traffic is, The higher the value, the greater the degree of abnormality of the network traffic;

[0029] The calculation expression of the state evaluation index is:

[0030] ;

[0031] Among them, is the state evaluation index, is the system state value of the th index, is the baseline value of the system state, is the number of observed indexes, is the number of configuration changes during the observation period, is the average system state value during the observation period, The lower the value, the healthier the system state is, The higher the value, the greater the abnormal trend of the system state.

[0032] Preferably, in the threat evaluation module, the process of evaluating the potential threat degree of abnormal behavior includes:

[0033] Traverse the historical abnormal behavior data in the log file, combine the traffic evaluation index and the state evaluation index with the historical abnormal behavior data, analyze the correlation between the abnormal behavior and the traffic evaluation index and the state evaluation index, and perform weighted calculation on the traffic evaluation index and the state evaluation index to obtain the abnormal threat evaluation coefficient;

[0034] According to the historical abnormal behavior data in the log file, the threat type and the influence range of the abnormal behavior, evaluate the potential threat degree of the abnormal behavior to determine different risk levels, namely the first-level risk level, the second-level risk level, the third-level risk level, and the fourth-level risk level. Among them, the potential threat degree of the abnormal behavior of the risk level increases gradually from the first-level risk level to the fourth-level risk level;

[0035] Match the calculated result of the set risk level and the abnormal threat evaluation coefficient, and preset corresponding risk thresholds for different risk levels;

[0036] Calculate the calculation results of the abnormal threat assessment coefficient and the matching relationship of different risk levels, obtain the abnormal threat sequence, and clarify the correlation between each risk level and the potential threat degree of abnormal behavior;

[0037] Input the real-time data of the collected network traffic data and system status information, calculate the results of the abnormal threat assessment coefficient, and match the corresponding risk levels in combination with the preset risk thresholds to evaluate the potential threat degree of abnormal behavior.

[0038] Preferably, the calculation expression of the abnormal threat assessment coefficient is:

[0039] ;

[0040] Among them, is the abnormal threat assessment coefficient, is the traffic assessment index at the th time point, is the baseline value of the traffic assessment index, is the weight at the th time point, is the number of observed time points, is the status assessment index of the rd index, is the baseline value of the status assessment index, is the number of observed indexes, and are the weight coefficients affecting the adjustment of and , is the coefficient for adjusting the exponential decay rate. A low value indicates that the network traffic and system status are close to the baseline value, and the abnormal behavior is not significant. A high value indicates a significant deviation from the baseline behavior, indicating a serious threat.

[0041] Preferably, multiple risk levels correspond to multiple risk thresholds, where the risk thresholds include an upper threshold and a lower threshold;

[0042] The multiple risk levels and the multiple risk thresholds satisfy the following relationship:

[0043] First-level risk level ; Low potential threat degree, requiring the least attention and resources;

[0044] Second-level risk level ; Medium potential threat degree, requiring moderate attention and resources;

[0045] Third-level risk level ; High potential threat level, requiring significant attention and resources;

[0046] Level 4 risk rating ; Severe potential threat level, requiring immediate and concentrated response;

[0047] Among them, is the abnormal threat assessment coefficient, is the lower threshold corresponding to the second-level risk rating and the upper threshold corresponding to the first-level risk rating, is the lower threshold corresponding to the third-level risk rating and the upper threshold corresponding to the second-level risk rating, is the lower threshold corresponding to the fourth-level risk rating and the upper threshold corresponding to the third-level risk rating, , , .

[0048] Preferably, in the automatic alarm module and the response strategy generation module, the process of alarm and generating protection strategies includes:

[0049] Continuously monitor the network status, collect key data of network traffic, system status information, and log files, and perform real-time analysis and processing on the collected data to identify abnormal behaviors and abnormal situations;

[0050] Combine the abnormal behavior assessment results of the threat assessment module with the identified abnormal behaviors and abnormal situations, output the risk rating of the abnormal behavior, check whether the abnormal behavior violates the security policy, and identify the potential security threats of the abnormal behavior;

[0051] Once an abnormal situation is detected, immediately trigger the alarm mechanism, and send alarm information to the administrator through multiple methods such as email, SMS, and instant messaging. The alarm information includes details such as the abnormal type, occurrence time, affected range, severity, and handling suggestions;

[0052] At the same time as triggering the alarm, the automatic alarm module conducts a risk assessment on the abnormal situation to determine whether it constitutes a high-risk threat. Combining the threat assessment results, select the corresponding protection measures from the preset protection measure library. For high-risk threats, more stringent measures may be selected, such as blocking the attack source, isolating the infected device, etc. Without manual intervention, the automatic alarm module directly calls the execution system to execute the selected protection measures. By automatically triggering the protection measures, instant protection is achieved, effectively curbing the spread and damage of threats. After the protection measures are executed, the automatic alarm module conducts a damage assessment to check whether the system has returned to normal operation and whether there are other potential impacts;

[0053] The response strategy generation module receives the evaluation results of abnormal behaviors from the threat assessment module and the alarm results of abnormal situations from the automatic alarm module, deeply analyzes the received evaluation results and alarm results, and clarifies the current potential risk levels and corresponding alarm mechanisms;

[0054] Monitor the execution results, synchronously record all generated protection strategies and execution results, and retain change logs and event response records for subsequent auditing and analysis;

[0055] Evaluate the implementation effects of the protection strategies according to the monitoring results, including whether the threats are effectively contained and whether the system resumes normal operation, and optimize and adjust the protection strategies according to the evaluation results, including improving the effectiveness of the strategies, reducing the false alarm rate, and increasing the response speed, etc.

[0056] Preferably, in the report generation module, the generation processes of the audit log and the risk assessment report include:

[0057] Capture all key events during the system operation, including login attempts, configuration changes, anomaly detections, and alarm triggers, record all security-related operations, organize the captured data, extract key information, including user IDs, operation types, and result statuses, and format the data for easy report generation;

[0058] Generate a detailed audit log based on the captured and organized data. The audit log includes timestamps, event types, operators, and impact scope information, summarize the results of the risk assessment, including the detection, evaluation, and response of abnormal behaviors, and generate a risk assessment report, including risk levels, threat types, and impact scopes;

[0059] Distribute the generated reports to designated users and departments via email, message notifications, or file sharing, and update the reports regularly to reflect the latest system operation and security status, and archive the reports in a secure system for future reference.

[0060] The present invention provides a network data risk assessment system for a computer. It has the following beneficial effects:

[0061] First, the network data risk assessment system for a computer integrates anomaly detection, threat assessment, response strategy generation, and automatic alarm functions, realizes the rapid detection and response to network threats, uses machine learning technology for anomaly pattern recognition, discovers potential security threats, improves the recognition accuracy of abnormal behaviors, and in addition, automatically triggers preset protection measures, so as to quickly respond when detecting high-risk threats and reduce the damage of security incidents to the system.

[0062] II. The network data risk assessment system for computers integrates efficient monitoring and alerting modules to achieve real-time monitoring of network status and data streams. It can quickly identify potential threats such as abnormal traffic and unauthorized access attempts, and automatically trigger preset protection measures when detecting high-risk threats. The instant threat detection and response mechanism greatly shortens the time window from threat discovery to response, effectively curbs the spread and damage of security incidents, and significantly improves the overall security and resilience of the network system. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] Figure 1 It is a block diagram of the module composition of a network data risk assessment system for computers according to the present invention;

[0064] Figure 2 It is a flowchart for the present invention to identify abnormal patterns;

[0065] Figure 3 It is a flowchart for the present invention to evaluate the potential threat level of abnormal behaviors. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0066] The present invention will be further described in detail below in conjunction with the drawings and specific embodiments. The embodiments of the present invention are given for the purpose of illustration and description, and are not exhaustive or limit the present invention to the disclosed form. Many modifications and variations are obvious to those of ordinary skill in the art. The embodiments are selected and described to better illustrate the principles and practical applications of the present invention, and enable those of ordinary skill in the art to understand the present invention and design various embodiments with various modifications suitable for specific purposes.

[0067] The first embodiment, as Figure 1 、 Figure 2 shown, the present invention provides a technical solution: a network data risk assessment system for computers, including a data monitoring platform, which is communicatively connected to a data acquisition module, a data preprocessing module, an anomaly detection module, a threat assessment module, an automatic alert module, a response strategy generation module, and a report generation module. Among them, the modules are electrically connected to each other;

[0068] The data collection module collects various raw data from various network devices and systems, including traffic data, log files, and system status information, ensuring the comprehensiveness and real-time nature of the data, providing basic data support for risk assessment. Identify the network devices and systems from which data needs to be collected, including servers, routers, firewalls, intrusion detection systems, and applications. Clearly define the data sources to ensure the comprehensiveness of data collection. Based on the network devices and systems from which data needs to be collected, determine the data types, collection frequencies, and storage formats and locations of the data. The data types include network traffic data, system status information, and log files, and configure data collection methods according to different data types. For the collection of network traffic data, use network packet capture tools (such as Wireshark, tcpdump) to capture network traffic data, obtain real-time network traffic information through network monitoring devices (such as traffic analyzers, intrusion detection systems), and use network traffic mirroring technology to copy a copy of the network traffic to the data collection system for analysis. For the collection of system status information, use system monitoring tools (such as Zabbix, Prometheus) to obtain real-time system performance metrics (such as CPU usage, memory occupancy, disk I / O, etc.), obtain system status information by calling system services through API interfaces (such as Windows Management Instrumentation, WMI; Systemd in Linux), and write scripts to periodically query system commands or configuration files to obtain system configuration and status data. According to the data collection objectives and methods, deploy data collection agents on each data source, configure the corresponding data collectors, and set collection parameters and rules to ensure that the data collectors can run stably and establish reliable connections with the target network devices and systems. The data collectors capture the raw data of network traffic data and system status information from the target network devices and systems, convert it into a unified data format, and transmit it through the network to the central data warehouse;

[0069] The data preprocessing module is used to perform preprocessing on the collected raw data, including cleaning, formatting, and normalizing, removing noise and redundant information, and extracting abnormal features for risk assessment from the preprocessed data to obtain an abnormal network traffic feature set and an abnormal system status feature set, improving data processing efficiency, providing a high-quality data set for subsequent analysis, converting a large amount of data into key features, facilitating the model to perform risk assessment more efficiently, and performing preprocessing operations on the collected raw data of network traffic data, system status information, and log files. The preprocessing operations include the steps of cleaning, formatting, and normalizing. Among them, data cleaning identifies and processes missing values, outliers, duplicate records, etc., ensuring the integrity and accuracy of the data. Data formatting converts the data into a unified format, such as date and time format, numerical format, etc., standardizing the data for easy processing and analysis. Data normalization scales the data to a specific range, such as 0 to 1, or makes the data have the same dimension, eliminating the influence brought by different magnitudes and dimensions, and improving the convergence speed and accuracy of the algorithm. Using the correlation coefficient, combined with the preprocessed network traffic data and system status information data, identify the features associated with risk assessment, and perform feature extraction to obtain abnormal features for risk assessment, extract the associated data of abnormal network traffic and abnormal system status information, and form an abnormal network traffic feature set and an abnormal system status feature set. Among them, the abnormal features of network traffic data include sudden increase in traffic, sudden decrease in traffic, abnormal traffic pattern, abnormal packet size, and frequent connection failures. A sudden increase in traffic means that the network traffic increases sharply in a short period of time, which may indicate a DDoS attack or other types of traffic anomalies. A sudden decrease in traffic means that the network traffic suddenly decreases, which may indicate network connection problems or service interruptions. An abnormal traffic pattern means that the traffic increases abnormally during non-peak hours, or the traffic pattern does not match the normal pattern. An abnormal packet size means that the packet size is much larger or smaller than the normal value, which may indicate an attack or abnormal transmission. Frequent connection failures mean a large number of connection failure attempts in a short period of time, which may indicate scanning or attacks. The abnormal features of system status information include sudden increase in CPU usage, sudden increase in memory usage, sudden increase in disk usage, network connection anomalies, and system configuration changes. A sudden increase in CPU usage means that the CPU usage suddenly rises significantly, which may indicate malware or system resources being occupied. A sudden increase in memory usage means that the memory usage suddenly rises significantly, which may indicate memory leaks or malware activities. A sudden increase in disk usage means that the disk usage suddenly rises significantly, which may indicate data leakage or malware activities. A network connection anomaly means that the system establishes a large number of connections with unusual IP addresses or ports. A system configuration change means that there are unauthorized changes in the system configuration file. Perform encoding processing on the abnormal features in the abnormal network traffic feature set and the abnormal system status feature set, convert non-numerical data into numerical data, and make the data suitable for numerical calculations;

[0070] Anomaly detection module, which uses machine learning algorithms combined with anomaly features to identify anomaly patterns in the preprocessed data, discovers potential security threats, quickly and accurately identifies abnormal behaviors in the network, provides clues for timely response, extracts associated data of abnormal network traffic data and abnormal system state information applied to risk assessment from the abnormal network traffic feature set and the abnormal system state feature set respectively. Among them, for abnormal network traffic data, the network traffic value, total network traffic and total abnormal network traffic within the observed time range are extracted, and the baseline value of network traffic is determined based on the average value of normal network traffic. For abnormal system state information, the system state value, number of configuration changes and average system state value of each system state indicator within the observed time range are extracted, and the baseline value of system state is determined based on the average value of normal system state. According to the time series characteristics of network traffic data, combined with time series analysis algorithms and abnormal network traffic data, a network traffic analysis model is trained, and the constructed network traffic analysis model is verified and evaluated, and necessary adjustments are made to improve performance to analyze the degree of network traffic anomaly. According to the static and dynamic characteristics of system state information, clustering algorithms are used to identify abnormal system configurations and behaviors, combined with abnormal system state information to train a system state analysis model, and the constructed system state analysis model is verified and evaluated, and parameter adjustments are made to identify abnormal system configurations and behaviors. Combining the output of the network traffic analysis model and abnormal network traffic data, a traffic evaluation index is obtained to analyze the degree of network traffic anomaly. Combining the output of the system state analysis model and abnormal system state information, a state evaluation index is obtained to measure the health status and abnormal trend of the system;

[0071] Further, the calculation expression of the traffic evaluation index is:

[0072] ;

[0073] Wherein, is the traffic evaluation index, is the network traffic value at the th time point, is the baseline value of network traffic, is the number of observed time points, is the total abnormal network traffic during the observation period, is the total network traffic during the observation period, The lower the value, the more normal the network traffic. The higher the value, the greater the degree of network traffic anomaly. Calculate the square of the difference between the network traffic at each time point and the baseline network traffic, sum them up and divide by the number of time points , to obtain the average value of the sum of squares of network traffic deviation, and use the exponential function to adjust the average value of the sum of squares of network traffic deviation, where Indicates the proportion of abnormal network traffic in the total network traffic, and the finally obtained value comprehensively considers the network traffic deviation and the proportion of abnormal network traffic;

[0074] The calculation expression of the status evaluation index is:

[0075] ;

[0076] Among them, is the status evaluation index, is the system status value of the th index, is the baseline value of the system status, is the number of observed indicators, is the number of configuration changes during the observation period, is the average system status value during the observation period, The lower the value, the healthier the system status. The higher the value, the greater the abnormal trend of the system status. Calculate the square of the difference between each system status indicator and the baseline status, sum them up and divide by the number of indicators , to obtain the average value of the sum of squares of the status deviation. Use the radical to adjust the average value of the sum of squares of the status deviation, where represents the number of configuration changes, represents the average system status value. The finally obtained

[0077] The threat assessment module is used to deeply analyze the detected abnormal behaviors, evaluate their potential threat levels, including threat types and influence scopes, determine their potential risk levels to the system, and provide accurate threat intelligence for formulating protection measures to ensure the effective allocation of resources;

[0078] The automatic alarm module continuously monitors the network status, conducts real-time monitoring and alarming of abnormal situations, and when detecting high-risk threats, automatically triggers preset protection measures, such as blocking the attack source, isolating the infected device, etc., to achieve instant protection, reduce the damage of security incidents to the system, enhance the transparency and controllability of the system, and facilitate the administrator to conduct emergency handling and subsequent analysis;

[0079] The response strategy generation module is used to automatically generate and recommend corresponding levels of protection strategies according to the threat assessment results, including blocking rules and alarm settings, improve the pertinence and effectiveness of protection measures, reduce human intervention, and speed up the response speed;

[0080] The report generation module is used to record all key events and operations during the system operation, generate detailed audit logs and risk assessment reports, provide a basis for post - event analysis, help optimize system configuration and improve protection measures, and at the same time meet compliance requirements.

[0081] The second embodiment, based on the first embodiment, please refer to Figure 3 As shown, in the threat assessment module, the process of evaluating the potential threat level of abnormal behavior includes:

[0082] Traverse the historical abnormal behavior data in the log file, combine the traffic evaluation index and the status evaluation index with the historical abnormal behavior data, analyze the correlation between the abnormal behavior and the traffic evaluation index as well as the status evaluation index, and perform weighted calculation on the traffic evaluation index and the status evaluation index to obtain the abnormal threat assessment coefficient. According to the historical abnormal behavior data in the log file, the threat type and the impact scope of the abnormal behavior, evaluate the potential threat level of the abnormal behavior to determine different risk levels, namely the first - level risk level, the second - level risk level, the third - level risk level, and the fourth - level risk level. Among them, the potential threat level of abnormal behavior of the risk level increases gradually from the first - level risk level to the fourth - level risk level. Match the calculated result of the set risk level and the abnormal threat assessment coefficient, preset corresponding risk thresholds for different risk levels, output the calculated result of the abnormal threat assessment coefficient and the matching relationship of different risk levels to obtain the abnormal threat sequence, clarify the correlation between each risk level and the potential threat level of abnormal behavior, input the real - time data of the collected network traffic data and system status information, calculate the result of the abnormal threat assessment coefficient, combine it with the preset risk threshold, and match the corresponding risk level to evaluate the potential threat level of the abnormal behavior;

[0083] Furthermore, the calculation expression of the abnormal threat assessment coefficient is:

[0084] ;

[0085] Where is the abnormal threat assessment coefficient, is the traffic evaluation index at the th time point, is the baseline value of the traffic evaluation index, is the weight at the th time point, is the number of observed time points, is the status evaluation index of the th index, is the baseline value of the status evaluation index, is the number of observed indexes, and are for adjusting and The weight coefficient of the impact, is the coefficient for adjusting the exponential decay rate. A low value indicates that the network traffic and system status are close to the baseline value, and abnormal behaviors are not significant. A high value indicates significant deviation from the baseline behavior, indicating a serious threat. For the traffic assessment part, calculate the difference from the baseline value at each time point, and perform a weighted calculation of the sum of squares of the differences to emphasize the behavior deviating from the baseline. Use the logarithmic function to transform the calculation result of the sum of squared differences, so that even in the case of multiple deviations from the baseline, the sensitivity to the threat level can be maintained. The weight is used to adjust the importance of traffic assessment in the total assessment coefficient. For the status assessment part, calculate the difference from the baseline value for each indicator, and square it. Use the exponential function to transform the calculation result of the sum of squared differences, where controls the impact of the deviation degree on the final index. Emphasize larger deviations in the form of , that is, larger deviations lead to an increase in . The weight is used to adjust the importance of status assessment in the total assessment coefficient;

[0086] Furthermore, multiple risk levels correspond to multiple risk thresholds. Among them, the risk thresholds include an upper threshold and a lower threshold;

[0087] The multiple risk levels and multiple risk thresholds satisfy the following relationship:

[0088] The first - level risk level ; Low potential threat level, requiring the least attention and resources;

[0089] The second - level risk level ; Medium potential threat level, requiring moderate attention and resources;

[0090] The third - level risk level ; High potential threat level, requiring significant attention and resources;

[0091] The fourth - level risk level ; Severe potential threat level, requiring immediate and concentrated response;

[0092] Among them, is the abnormal threat assessment coefficient, is the lower threshold corresponding to the second - level risk level and the upper threshold corresponding to the first - level risk level, is the lower threshold corresponding to the third - level risk level and the upper threshold corresponding to the second - level risk level, is the lower threshold value corresponding to the fourth - level risk level and the upper threshold value corresponding to the third - level risk level, , , ;

[0093] In the automatic alarm module and response strategy generation module, the process of alarm and generating protection strategies includes:

[0094] Continuously monitor the network status, collect key data of network traffic, system status information, and log files, and perform real - time analysis and processing on the collected data to identify abnormal behaviors and abnormal situations. Combine the abnormal behavior assessment results of the threat assessment module with the identified abnormal behaviors and abnormal situations, output the risk level of the abnormal behavior, check whether the abnormal behavior violates the security policy, identify the potential security threats of the abnormal behavior. Once an abnormal situation is detected, immediately trigger the alarm mechanism and send alarm information to the administrator through multiple methods such as email, SMS, and instant messaging. The alarm information includes details such as the type of abnormality, occurrence time, scope of influence, severity, and handling suggestions. At the same time as triggering the alarm, the automatic alarm module conducts a risk assessment of the abnormal situation to determine whether it constitutes a high - risk threat. Combine the threat assessment results and select the corresponding protection measures from the preset protection measure library. For high - risk threats, more stringent measures may be selected, such as blocking the attack source, isolating the infected device, etc. Without manual intervention, the automatic alarm module directly calls the execution system to execute the selected protection measures. By automatically triggering the protection measures, immediate protection is achieved, effectively containing the spread and damage of the threat. After the protection measures are executed, the automatic alarm module conducts a damage assessment to check whether the system has returned to normal operation and whether there are other potential impacts. The response strategy generation module receives the assessment results of abnormal behaviors from the threat assessment module and the alarm results of abnormal situations from the automatic alarm module, conducts in - depth analysis on the received assessment results and alarm results, clarifies the current potential risk level and the corresponding alarm mechanism, monitors the execution results, synchronously records all generated protection strategies and execution results, retains the change log and event response records for subsequent auditing and analysis, evaluates the implementation effect of the protection strategy according to the monitoring results, including whether the threat is effectively contained and whether the system has returned to normal operation, and optimizes and adjusts the protection strategy according to the evaluation results, including improving the effectiveness of the strategy, reducing the false alarm rate, and increasing the response speed, etc.;

[0095] In the report generation module, the process of generating the audit log and risk assessment report includes:

[0096] Capture all key events during the operation of the capture system, including login attempts, configuration changes, anomaly detection, and alert triggering, and record all security-related operations. Organize the captured data, extract key information, including user ID, operation type, and result status, and format the data for report generation. Generate a detailed audit log based on the captured and organized data. The audit log includes a timestamp, event type, operator, and impact scope information. Summarize the results of risk assessment, including the detection, assessment, and response to abnormal behaviors, and generate a risk assessment report, including risk level, threat type, and impact scope. Distribute the generated report to the designated users and departments via email, message notification, or file sharing, and update the report regularly to reflect the latest system operation and security status. Archive the report in a secure system for future reference.

[0097] Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art and related fields based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention. The structures, devices, and operation methods not specifically described and explained in the present invention shall be implemented by conventional means in the art unless otherwise specified and limited.

Claims

1. A network data risk assessment system for a computer, comprising a data monitoring platform, characterized in that: The data monitoring platform is connected to the following modules: Data collection module, which collects various raw data from various network devices and systems, including traffic data, log files, and system status information; The data preprocessing module is used to preprocess the collected raw data and extract abnormal features for risk assessment from the preprocessed data to obtain an abnormal network traffic feature set and an abnormal system status feature set; The anomaly detection module uses machine learning algorithms combined with abnormal features to identify abnormal patterns in preprocessed data and discover potential security threats. Based on the time series characteristics of network traffic data, it combines time series analysis algorithms and abnormal network traffic data to train network traffic analysis models to analyze the degree of abnormality of network traffic. According to the static and dynamic characteristics of system status information, combined with abnormal system status information, the system status analysis model is trained, and the clustering algorithm is used to identify abnormal system configuration and behavior; Combining the output of the network traffic analysis model with abnormal network traffic data, we get the traffic evaluation index to analyze the abnormal degree of network traffic. Combining the output of the system status analysis model with abnormal system status information, we get the status evaluation index to measure the health status and abnormal trend of the system. Threat assessment module, used to assess its potential threat level, including: Traverse the historical abnormal behavior data in the log file, combine the traffic assessment index and the state assessment index with the historical abnormal behavior data, analyze the correlation between the abnormal behavior and the traffic assessment index and the state assessment index, and perform weighted calculation on the traffic assessment index and the state assessment index to obtain the abnormal threat assessment coefficient; Match the set risk level with the calculation result of the abnormal threat assessment coefficient, and preset corresponding risk thresholds for different risk levels; Output the calculation results of the abnormal threat assessment coefficient and the matching relationship between different risk levels to obtain the abnormal threat sequence; Input the collected network traffic data and real-time data of system status information, calculate the result of abnormal threat assessment coefficient, combine it with the preset risk threshold, match the corresponding risk level, and evaluate the potential threat level of abnormal behavior; Automatic alarm module, which continuously monitors the network status and provides real-time monitoring and alarm for abnormal situations; The response strategy generation module is used to automatically generate and recommend protection strategies of corresponding levels based on threat assessment results.

2. A network data risk assessment system for computers according to claim 1, characterized in that: In the data acquisition module, the process of collecting raw data includes: Identify the network devices and systems that need to collect data, including servers, routers, firewalls, intrusion detection systems, and applications; Determine the data type, collection frequency, and data storage format and location based on the network devices and systems that need to collect data. The data types include network traffic data, system status information, and log files. Configure data collection methods based on different data types. According to the data collection objectives and methods, deploy data collection agents on various data sources, configure corresponding data collectors, set collection parameters and rules, and connect with target network devices and systems; The data collector captures the raw data of network traffic data and system status information from the target network devices and systems, converts them into a unified data format, and transmits them to the central data warehouse through the network.

3. A network data risk assessment system for computers according to claim 2, characterized in that: In the data preprocessing module, the process of acquiring the abnormal network traffic feature set and the abnormal system status feature set includes: Perform preprocessing operations on the collected network traffic data, system status information, and raw data of log files, including cleaning, formatting, and normalization steps; Use correlation coefficients in combination with preprocessed network traffic data and system status information data to identify features associated with risk assessment, perform feature extraction, obtain abnormal features for risk assessment, extract associated data of abnormal network traffic and abnormal system status information, and form an abnormal network traffic feature set and an abnormal system status feature set, wherein the abnormal features of network traffic data include sudden increase in traffic, sudden decrease in traffic, abnormal traffic pattern, abnormal data packet size, and frequent connection failures, and the abnormal features of system status information include sudden increase in CPU usage, sudden increase in memory usage, sudden increase in disk usage, abnormal network connection, and system configuration changes; The abnormal features in the abnormal network traffic feature set and the abnormal system status feature set are encoded and processed to convert non-numeric data into numerical data.

4. A network data risk assessment system for computers according to claim 3, characterized in that: In the anomaly detection module, the process of identifying anomaly patterns includes: Abnormal network traffic data and associated data of abnormal system status information used for risk assessment are extracted from the abnormal network traffic feature set and the abnormal system status feature set respectively. For the abnormal network traffic data, the network traffic value, total network traffic and total abnormal network traffic within the observation time range are extracted, and the baseline value of the network traffic is determined based on the average value of the normal network traffic. For the abnormal system status information, the system status value, the number of configuration changes and the average system status value of each system status indicator within the observation time range are extracted, and the baseline value of the system status is determined based on the average value of the normal system status.

5. A network data risk assessment system for computers according to claim 4, characterized in that: The calculation expression of the flow evaluation index is: ; in, is the flow evaluation index, For the The network traffic value at a time point, is the baseline value of network traffic, is the number of observed time points, is the total abnormal network traffic during the observation period, is the total network traffic during the observation period, The lower the value, the more normal the network traffic. The higher the value, the greater the abnormality of network traffic; The calculation expression of the state evaluation index is: ; in, is the status assessment index, For the The system status value of each indicator, is the baseline value of the system status, is the number of observed indicators, is the number of configuration changes during the observation period, is the average system state value during the observation period, The lower the value, the healthier the system status. The higher the value, the more abnormal the system status is.

6. A network data risk assessment system for computers according to claim 5, characterized in that: The calculation expression of the abnormal threat assessment coefficient is: ; in, is the abnormal threat assessment coefficient, For the The flow evaluation index at a time point, is the baseline value of the flow assessment index, For the The weight of each time point, is the number of observed time points, For the The status assessment index of the indicator, is the baseline value of the status assessment index, is the number of observed indicators, and To adjust and The weight coefficient of influence, A factor that adjusts the exponential decay rate.

7. A network data risk assessment system for computers according to claim 6, characterized in that: The plurality of risk levels correspond to the plurality of risk thresholds, wherein the risk thresholds include an upper threshold and a lower threshold; The multiple risk levels and the multiple risk thresholds satisfy the following relationship: Level 1 risk ; Secondary risk level ; Level 3 risk ; Four risk levels ; in, is the abnormal threat assessment coefficient, is the lower threshold corresponding to the second-level risk level and the upper threshold corresponding to the first-level risk level, is the lower threshold corresponding to the third-level risk level and the upper threshold corresponding to the second-level risk level. It is the lower threshold corresponding to the fourth risk level and the upper threshold corresponding to the third risk level.

8. A network data risk assessment system for computers according to claim 7, characterized in that: In the automatic alarm module and the response strategy generation module, the process of alarming and generating protection strategies includes: Continuously monitor network status, collect key data such as network traffic, system status information, and log files, and analyze and process the collected data in real time to identify abnormal behaviors and situations; Combine the abnormal behavior assessment results of the threat assessment module with the identified abnormal behaviors and abnormal situations, output the risk level of the abnormal behavior, check whether the abnormal behavior violates the security policy, and identify the potential security threats of the abnormal behavior; Once an abnormal situation is detected, the alarm mechanism is triggered immediately, and alarm information is sent to the administrator via email, SMS, and instant messaging. When the alarm is triggered, the automatic alarm module conducts a risk assessment on the abnormal situation to determine whether it constitutes a high-risk threat. Based on the threat assessment results, the module selects the corresponding protection measures from the preset protection measures library. The automatic alarm module directly calls the execution system to execute the selected protection measures. By automatically triggering the protection measures, immediate protection is achieved. After the protection measures are executed, the automatic alarm module conducts a damage assessment to check whether the system has resumed normal operation and whether there are other potential impacts. The response strategy generation module receives the evaluation results of abnormal behaviors from the threat assessment module and the alarm results of abnormal situations from the automatic alarm module. It conducts in-depth analysis on the received evaluation results and alarm results to clarify the current potential risk level and the corresponding alarm mechanism. Monitor execution results, synchronously record all generated protection strategies and execution results, and keep change logs and incident response records; Evaluate the effectiveness of the protection strategy based on the monitoring results, including whether the threat has been effectively contained and whether the system has resumed normal operation, and optimize and adjust the protection strategy based on the evaluation results.

9. A network data risk assessment system for computers according to claim 8, characterized in that: The system also includes a report generation module, which is used to record all key events and operations during the operation of the system and generate audit logs and risk assessment reports. In the report generation module, the generation process of the audit log and risk assessment report includes: Capture all key events during system operation, including login attempts, configuration changes, anomaly detection, and alarm triggering, and record all security-related operations. Organize the captured data and extract key information, including user ID, operation type, and result status. Generate detailed audit logs based on captured and collated data. The audit logs include timestamps, event types, operators, and impact scope information, summarize risk assessment results, and generate risk assessment reports; The generated reports are distributed to designated users and departments through email, message notification or file sharing, and the reports are updated regularly to reflect the latest system operation and security status, and the reports are archived in a secure system.

Citation Information

Patent Citations

  • Network information security analysis method and system based on data analysis

    CN118784348A