A Visual Data Security Analysis Method and System Based on Big Data

The method and system enhance data security analysis by employing big data visualization and multi-dimensional risk assessment to accurately detect anomalies and classify risks, addressing the inefficiencies of existing systems and enhancing network security.

CN119484131BActive Publication Date: 2025-07-15NANJING KUNJIN NETWORK TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411676465.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-22
Publication Date
2025-07-15
Estimated Expiration
2044-11-22

AI Technical Summary

Technical Problem

When facing large-scale network link traffic data, it is difficult to quickly and accurately determine whether traffic changes are abnormal and the real reasons behind the abnormality. It lacks an efficient identification and analysis mechanism and cannot provide a decision-making basis for network security protection in a timely and effective manner, resulting in network systems being vulnerable to security attacks and data leakage risks.

Method used

By collecting and preprocessing the visual data, real-time traffic changes of the network link are monitored, change monitoring results are generated, and data types and risks are identified in combination with historical data analysis, operating frequency, system log and other factors are used to evaluate risks, and multi-level and multi-dimensional risk analysis results are generated.

Benefits of technology

It improves the accuracy and flexibility of abnormal traffic detection, can accurately locate the sources and properties of security risks, provide detailed security policy basis, timely discover potential unstable changes, and enhance the integrity and foresight of network security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119484131B_ABST
    Figure CN119484131B_ABST
Patent Text Reader

Abstract

The present invention discloses a visualization data security analysis method and system based on big data. The present invention relates to the technical field of data security, and solves the technical problems that it is difficult to determine the reasons for abnormal visualization data, lacks an efficient identification and analysis mechanism, and cannot provide good decision-making for network security protection. The present invention performs real-time traffic monitoring on the network link at a time period set by the operator, and accurately judges whether the traffic change is abnormal by comparing with a preset value obtained based on historical data analysis. This method can adapt to different network environments and business requirements, improve the accuracy and flexibility of abnormal traffic detection, overcome the problems of lack of pertinence and dynamic adaptability in traditional traffic monitoring methods, and the multi-level and multi-dimensional analysis method can more accurately locate the source and nature of security risks, providing more detailed basis for formulating effective security strategies.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security technology, and specifically to a visual data security analysis method and system based on big data. Background Art

[0002] With the rapid development of information technology, the amount of data has grown explosively, and the network environments of enterprises and various organizations have become increasingly complex. In this context, data security faces unprecedented challenges. A large number of security devices such as firewalls, intrusion detection systems, and antivirus software continuously generate massive amounts of log data. At the same time, audit data of systems and applications is also continuously accumulating. In addition, external threat intelligence data is also pouring in continuously.

[0003] According to the publication number CN116707940A, a data security visualization analysis method and system based on big data is disclosed, including constructing a security evaluation strategy, obtaining the real-time security coefficient of a terminal device at any time after accessing the internal network through the security evaluation strategy, presetting a corresponding minimum passing coefficient for each page of the internal network, and comparing the real-time security coefficient with the preset minimum passing coefficient before the terminal device accesses each web page.

[0004] However, when some existing technologies analyze visual data, it is difficult to quickly and accurately determine whether the traffic change is abnormal and the real reason behind the abnormality when facing large-scale network link traffic data. There is also a lack of an efficient identification and analysis mechanism for security risks caused by user operations and system operations themselves, and it is unable to provide decision-making basis for network security protection in a timely and effective manner, resulting in the network system being vulnerable to various security attacks and data leakage risks, seriously affecting the normal operation of enterprises and organizations and the security of information assets. Summary of the Invention

[0005] Aiming at the deficiencies of the existing technology, the present invention provides a visual data security analysis method and system based on big data, which solves the problems of difficult to determine the reason for visual data abnormality, lack of an efficient identification and analysis mechanism, and inability to provide good decision-making for network security protection.

[0006] To achieve the above objectives, the present invention is realized through the following technical solutions: A visual data security analysis method based on big data, the method specifically includes the following steps:

[0007] Step 1, collect visual data, and at the same time preprocess the collected visual data to obtain preprocessed data;

[0008] Step 2: Monitor the network links based on the obtained preprocessed data, and at the same time monitor the real-time traffic changes of different network links within a time period, and generate a change monitoring result. The specific change monitoring results include normal traffic change results and abnormal traffic change results;

[0009] Step 3: Analyze the obtained abnormal traffic change results, and generate regular change results and irregular change results by analyzing the traffic change situations corresponding to the same time periods in the historical data;

[0010] Step 4: Analyze the obtained regular change results, identify the data types of the real-time changing traffic, and perform risk analysis on the real-time traffic of different data types to obtain risk analysis results. Analyze the obtained irregular change results, collect the traffic packet information, perform periodic monitoring, and at the same time combine the corresponding traffic protocol distribution to perform risk analysis to generate risk analysis results;

[0011] Step 5: Analyze the obtained normal traffic change results, monitor the periodic traffic change values, and generate monitoring results according to the adjacent periodic traffic change values.

[0012] As a further solution of the present invention, the specific method for generating the change monitoring result in Step 2 is as follows:

[0013] Obtain all network links and label them as i, where i = 1, 2,..., j, and j represents the number label of the network links. Then, take time t as the period to obtain the real-time traffic change situation of the preprocessed data in network link i, obtain the real-time traffic change value, and at the same time compare the real-time traffic change value with a preset value;

[0014] If the real-time traffic change value is greater than the preset value, generate an abnormal traffic change result; otherwise, generate a normal traffic change result.

[0015] As a further solution of the present invention, the specific method for analyzing the abnormal traffic change results in Step 3 is as follows:

[0016] Obtain the network link corresponding to the abnormal traffic change result and denote it as the abnormal link. At the same time, obtain the historical data corresponding to the abnormal link and the abnormal time period corresponding to the abnormal link. Then, take the abnormal time period as the standard to obtain the data in the same time period in the historical data as the comparison data, and at the same time analyze the real-time traffic change situation corresponding to the comparison data;

[0017] If the real-time traffic change situations are the same, generate regular change results; otherwise, if the real-time traffic change situations are different, generate irregular change results.

[0018] As a further solution of the present invention, the specific method for analyzing the regularly changing result in step four is as follows:

[0019] Obtain the preprocessed data corresponding to the regularly changing result, classify the data types of the preprocessed data to obtain operation data and system data, and then analyze the classified operation data and system data respectively;

[0020] Analyze the classified operation data to obtain user operation information, and the user operation information includes operation frequency and operation volume. Then substitute the operation frequency and operation volume into the formula , where P represents the operation frequency, L represents the operation volume, a1 and a2 represent the corresponding weight coefficients. Calculate the operation value Q of the user according to the formula. Then compare the operation value Q with the threshold Qy to generate normal information and risk information;

[0021] The specific method for analyzing the classified system data is as follows: Obtain the system log, and analyze whether there is a non-system operation according to the system log. If there is, generate risk information. On the contrary, if there is no such operation, generate normal information.

[0022] As a further solution of the present invention, the specific method for comparing the operation value Q with the threshold Qy to generate normal information and risk information in step four is as follows:

[0023] If the operation value Q is greater than the threshold Qy, it means that there is a risk in the real-time traffic change situation, and risk information is generated. On the contrary, if the operation value Q is less than the threshold Qy, it means that the real-time traffic change situation is normal, and normal information is generated.

[0024] As a further solution of the present invention, the specific method for analyzing the irregularly changing result in step four is as follows:

[0025] Obtain the traffic packet information corresponding to the abnormal link, and at the same time obtain the corresponding traffic protocol distribution. Analyze and judge the two comprehensively. If the traffic protocol distribution is unstable and the corresponding traffic packet transmission is large traffic packet transmission, high-risk information is comprehensively generated. If the traffic protocol distribution is unstable and the corresponding traffic packet transmission is traffic packet transmission, medium-risk information is comprehensively generated. If the traffic protocol distribution is stable and the corresponding traffic packet transmission is small traffic packet transmission, low-risk information is generated.

[0026] As a further solution of the present invention, the specific method for analyzing the normal traffic change result in step five is as follows:

[0027] Obtain the traffic change value. At the same time, obtain the traffic change values corresponding to adjacent time periods, and compare the two traffic change values. If the difference between the two traffic changes is a stable change, generate a stable change signal and perform normal monitoring. On the contrary, if the difference between the two traffic changes is an unstable change, generate an unstable change signal and perform a secondary analysis;

[0028] Obtain the unstable change signal, and judge the numerical magnitude of the difference between the two traffic changes. If the traffic change difference in the adjacent period is greater than the traffic change difference in the current period, generate a risk information. On the contrary, if the traffic change difference in the adjacent period is less than the traffic change difference in the current period, mark the current period, and at the same time obtain the user operations corresponding to the current period, and perform an analysis to generate a risk analysis result.

[0029] A visualization data security analysis system based on big data, including: a visualization data acquisition unit, a link identification and analysis unit, a normal monitoring unit, a risk analysis unit, and an analysis result output unit;

[0030] The visualization data acquisition unit is used to collect visualization data, process the visualization data to obtain preprocessed data, and at the same time transmit the obtained preprocessed data to the link identification and analysis unit;

[0031] The link identification and analysis unit is used to analyze the obtained preprocessed data, monitor the network link according to the obtained preprocessed data, and at the same time monitor the real-time traffic changes of different network links within a time period, and generate a change monitoring result. The specific change monitoring results include normal traffic change results and abnormal traffic change results. At the same time, transmit the normal traffic change results to the normal monitoring unit, and transmit the abnormal traffic change results to the risk analysis unit;

[0032] The normal monitoring unit is used to analyze the obtained normal traffic change results, monitor the periodic traffic change values, and generate a monitoring result according to the adjacent period traffic change values, and transmit the obtained monitoring result to the analysis result output unit;

[0033] The risk analysis unit is used to analyze the obtained abnormal traffic change results. By analyzing the traffic change situations corresponding to the same time period in the historical data, generate regular change results and irregular change results. Analyze the obtained regular change results, identify the data types of the real-time changing traffic, and perform risk analysis on the real-time traffic of different data types to obtain a risk analysis result. Analyze the obtained irregular change results, collect the traffic packet information, perform periodic monitoring, and at the same time combine the corresponding traffic protocol distribution to perform risk analysis to generate a risk analysis result, and transmit the obtained risk analysis result to the analysis result output unit;

[0034] An analysis result output unit, which is used to display the obtained analysis results and monitoring results to the corresponding operators.

[0035] The present invention provides a visualization data security analysis method and system based on big data. Compared with the prior art, it has the following beneficial effects:

[0036] The present invention proposes to perform real-time traffic monitoring on the network link at a time period settable by the operator, and by comparing with the preset value obtained through historical data analysis, accurately judge whether the traffic change is abnormal. This method can adapt to different network environments and business requirements, improve the accuracy and flexibility of abnormal traffic detection, and overcome the problems of lack of pertinence and dynamic adaptability in traditional traffic monitoring methods;

[0037] For the abnormal traffic change results, not only can it distinguish regular changes and irregular changes, but also further in-depth analysis can be carried out. For the regular change results, through the classified analysis of operation data and system data, comprehensively considering factors such as operation frequency, operation volume, and non-system operations in the system log, the risk is comprehensively evaluated; for the irregular change results, the risk level is divided according to the traffic packet information and traffic protocol distribution. This multi-level and multi-dimensional analysis method can more accurately locate the source and nature of security risks and provide more detailed basis for formulating effective security strategies;

[0038] When dealing with the normal traffic change results, by monitoring the stability of the traffic change values in adjacent periods, potential unstable change situations can be discovered in time, and when the unstable change occurs, further analysis and judgment of the risk source and degree can be carried out. This helps to discover potential security hazards that may exist under seemingly normal traffic conditions, makes up for the deficiency of traditional technologies in the sensitivity to potential risks in normal traffic monitoring, and improves the integrity and forward-looking of the entire network security protection system. Brief Description of the Drawings

[0039] Figure 1 It is a flowchart of the method steps of the present invention;

[0040] Figure 2 It is a block diagram of the system principle of the present invention. Detailed Embodiments

[0041] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0042] Example 1, please refer to Figure 1 , this application provides a visualization data security analysis method based on big data, and the method specifically includes the following steps:

[0043] Step 1, collect the visualization data, and at the same time preprocess the collected visualization data to obtain preprocessed data.

[0044] Collect log data from various security devices (such as firewalls, intrusion detection systems, antivirus software, etc.). These logs contain key security information such as network connection attempts, malware detection records, user authentication information, etc.

[0045] Collect audit data of systems and applications, including database access records, file access and modification records, etc., to understand the activities of internal systems.

[0046] External threat intelligence data is also an important source, such as a list of known malicious IP addresses, the latest vulnerability information, etc., which can help identify potential threats from outside.

[0047] Remove duplicate data records, because duplicate data may interfere with the analysis results and occupy unnecessary storage space. For example, in firewall logs, there may be a large number of duplicate port scan attempt records that need to be de-duplicated.

[0048] Handle missing values. For the missing values of some key data fields (such as user account information, IP address, etc.), they need to be filled or marked according to the specific situation. If there are too many missing values, the reliability of the data may need to be considered.

[0049] Standardize the data, and convert data in different formats into a unified format. For example, unify the timestamp into a specific date and time format for subsequent time series analysis.

[0050] After the above processing, preprocessed data is obtained.

[0051] Step 2, monitor the network link according to the obtained preprocessed data, and at the same time monitor the real-time traffic changes of different network links within a time period, and generate a change monitoring result. The specific change monitoring results include normal traffic change results and abnormal traffic change results.

[0052] Obtain all network links and label them as i, where i = 1, 2, …, j, and j represents the number label of the network links. Then, take time t as the period to obtain the real-time traffic change of the preprocessed data in network link i. The specific value of time t is set by the operator. For example, the time period t can be set to 5 minutes, which means that every 5 minutes the system will collect the change information of the data upload and download amounts in each network link to understand the dynamic change of the traffic and obtain the real-time traffic change value. At the same time, compare the real-time traffic change value with the preset value, and the specific value of the preset value is set by the operator and is specifically obtained by analyzing the historical data of the corresponding network link. Calculate the average value of the traffic change corresponding to the network link under normal circumstances as the preset value;

[0053] If the real-time traffic change value is greater than the preset value, it indicates that there is an abnormality in the corresponding network link i, and at the same time, a traffic change abnormality result is generated. On the contrary, if the real-time traffic change value is less than the preset value, it indicates that the corresponding network link i is normal, and at the same time, a traffic change normal result is generated.

[0054] Step three, analyze the obtained traffic change abnormality result. Generate a regular change result and an irregular change result by analyzing the traffic change situation corresponding to the same time period in the historical data.

[0055] Obtain the network link corresponding to the traffic change abnormality result and denote it as the abnormal link. At the same time, obtain the historical data corresponding to the abnormal link and the abnormal time period corresponding to the abnormal link. Then, take the abnormal time period as the standard to obtain the data in the same time period in the historical data and denote it as the comparison data. For example, extract the traffic data of the link connecting the Marketing Department from the stored historical data for every day from 10:00 - 10:30 am within the past month (such as from October 15, 2024 to November 14, 2024). At the same time, analyze the real-time traffic change situation corresponding to the comparison data, and here it is judged according to the real-time traffic change value. If the real-time traffic change situations are the same, a regular change result is generated. On the contrary, if the real-time traffic change situations are different, an irregular change result is generated. Specifically, if the comparison data in the same time period in the historical data are all in the same change situation, it means it is regular in this time period. If the change situations are different, it means it is irregular in this time period.

[0056] Step four, analyze the obtained regular change result, identify the data types of the real-time changing traffic, and perform risk analysis on the real-time traffic of different data types to obtain the risk analysis result.

[0057] Obtain the preprocessed data corresponding to the regularly changing results, classify the data types of the preprocessed data to obtain operation data and system data. Here, the operation data refers to the data generated by user operations, while the system data is the data generated by the system itself, such as system updates or data backups. Then, analyze the classified operation data and system data respectively;

[0058] The specific method for analyzing the classified operation data is as follows: Obtain user operation information, and the user operation information includes operation frequency and operation volume. The operation frequency is obtained by analyzing the number of operations within a predetermined time. The specific formula is operation frequency = number of operations ÷ predetermined time, and the value of the predetermined time is set by the operator. The operation volume represents the corresponding data volume. Then, substitute the operation frequency and operation volume into the formula where P represents the operation frequency, L represents the operation volume, and a1 and a2 represent the corresponding weight coefficients. Calculate the user's operation value Q according to the formula. Then, compare the operation value Q with the threshold Qy, and the value of the threshold is set by the operator;

[0059] If the operation value Q is greater than the threshold Qy, it indicates that there is a risk in the real-time traffic change situation and generate a risk message. On the contrary, if the operation value Q is less than the threshold Qy, it indicates that the real-time traffic change situation is normal and generate a normal message;

[0060] The specific method for analyzing the classified system data is as follows: Obtain the system log and analyze whether there are non-system operations according to the system log. Here, the non-system operation refers to the record that is contrary to the normal system operation mode. If it exists, generate a risk message. On the contrary, if it does not exist, generate a normal message.

[0061] For example, in network security monitoring, it is found that there are a large number of data reading requests from an external strange IP address in the system log, and these requests are targeted at the enterprise's core sensitive data files, and there will be no such operations from this external IP in the normal business logic and operation process of the system. This can determine that there are non-system operations, further indicating that there will be risks.

[0062] Step Five, analyze the obtained non-regular change results. Collect the traffic packet information, conduct periodic monitoring, and at the same time combine the corresponding traffic protocol distribution to conduct risk analysis to generate a risk analysis result.

[0063] Obtain the traffic packet information corresponding to the abnormal link, and the traffic packet information here includes the size and frequency of the traffic packet. At the same time, obtain the corresponding traffic protocol distribution, and analyze and judge the combination of the two. If the traffic protocol distribution is unstable and the corresponding traffic packet transmission is large traffic packet transmission, then comprehensively generate high-risk information. If the traffic protocol distribution is unstable and the corresponding traffic packet transmission is traffic packet transmission, then comprehensively generate medium-risk information. If the traffic protocol distribution is stable and the corresponding traffic packet transmission is small traffic packet transmission, then generate low-risk information.

[0064] Embodiment 2. As Embodiment 2 of the present invention, this embodiment is implemented on the basis of Embodiment 1, and the difference from Embodiment 1 is as follows:

[0065] This embodiment analyzes the obtained normal traffic change result by monitoring the periodic traffic change value and generating a monitoring result according to the adjacent periodic traffic change value.

[0066] Obtain the traffic change value, and at the same time obtain the traffic change value corresponding to the adjacent time period. Here, the adjacent time period can be expressed as the previous adjacent time period or the next adjacent time period, and compare the two traffic change values. Here, the two traffic change values respectively represent the change values of the current time period and the adjacent time period. If the difference between the two traffic changes is a stable change, then generate a stable change signal and perform normal monitoring. On the contrary, if the difference between the two traffic changes is an unstable change, then generate an unstable change signal and perform secondary analysis;

[0067] Obtain the unstable change signal and judge the numerical size of the difference between the two traffic changes. If the traffic change difference in the adjacent period is greater than the traffic change difference in the current period, then generate risk information. On the contrary, if the traffic change difference in the adjacent period is less than the traffic change difference in the current period, then mark the current period, and at the same time obtain the user operation corresponding to the current period and perform analysis to generate a risk analysis result. Here, the specific method of analysis is the same as the processing process in Step 4 of Embodiment 1.

[0068] Embodiment 3. As Embodiment 3 of the present invention, the key lies in combining the implementation processes of Embodiment 1 and Embodiment 2.

[0069] Embodiment 4. Please refer to Figure 2 , this application provides a visualization data security analysis system based on big data, including: a visualization data acquisition unit, a link identification and analysis unit, a normal monitoring unit, a risk analysis unit, and an analysis result output unit. At the same time, the above functional units are unidirectionally electrically connected.

[0070] Visual data acquisition unit, which is used to acquire visual data, process the visual data to obtain preprocessed data, and transmit the obtained preprocessed data to the link identification and analysis unit;

[0071] Link identification and analysis unit, which is used to analyze the obtained preprocessed data, monitor the network link according to the obtained preprocessed data, monitor the real-time traffic changes of different network links within a time period, and generate a change monitoring result. The specific change monitoring results include normal traffic change results and abnormal traffic change results. The processing method here is the same as that in step 2 of Embodiment 1. At the same time, the normal traffic change result is transmitted to the normal monitoring unit, and the abnormal traffic change result is transmitted to the risk analysis unit;

[0072] Normal monitoring unit, which is used to analyze the obtained normal traffic change result, monitor the periodic traffic change value, and generate a monitoring result according to the adjacent periodic traffic change value. The processing method here is the same as that in Embodiment 2, and the obtained monitoring result is transmitted to the analysis result output unit;

[0073] Risk analysis unit, which is used to analyze the obtained abnormal traffic change result. By analyzing the traffic change situation corresponding to the same time period in the historical data, a regular change result and an irregular change result are generated. The processing method here is the same as that in step 3 of Embodiment 1. Analyze the obtained regular change result, identify the data type of the real-time changing traffic, and perform risk analysis on the real-time traffic of different data types to obtain a risk analysis result. The processing method here is the same as that in step 4 of Embodiment 1. Analyze the obtained irregular change result, collect the traffic packet information, perform periodic monitoring, and combine the corresponding traffic protocol distribution to perform risk analysis to generate a risk analysis result. The processing method here is the same as that in step 5 of Embodiment 1, and the obtained risk analysis result is transmitted to the analysis result output unit;

[0074] Analysis result output unit, which is used to display the obtained analysis result and monitoring result to the corresponding operator.

[0075] Some data in the above formula are all numerically calculated after removing their dimensions, and the content not described in detail in this specification belongs to the prior art well known to those skilled in the art.

[0076] The above embodiments are only used to illustrate the technical method of the present invention and not to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical method of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical method of the present invention.

Claims

1. A visualization data security analysis method based on big data, characterized in that The method specifically includes the following steps: Step 1: Collect the visualization data, and simultaneously preprocess the collected visualization data to obtain preprocessed data; Step 2: Monitor the network link according to the obtained preprocessed data, and simultaneously monitor the real-time traffic changes of different network links within a time period. Obtain all network links and label them as i, where i = 1, 2,..., j, and j represents the number label of the network link. Then, obtain the real-time traffic change situation of the preprocessed data in network link i with time t as the period, and obtain the real-time traffic change value. At the same time, compare the real-time traffic change value with a preset value; If the real-time traffic change value is greater than the preset value, generate a traffic change abnormal result; otherwise, generate a traffic change normal result; Step 3: Analyze the obtained traffic change abnormal result, and generate a regular change result and an irregular change result by performing a regular analysis on the traffic change situation corresponding to the same time period in the historical data; Step 4: Analyze the obtained regular change result, identify the data types of the real-time changing traffic, and perform a risk analysis on the real-time traffic of different data types to obtain a risk analysis result. Analyze the obtained irregular change result by collecting the traffic packet information, performing a periodic monitoring, and simultaneously combining the corresponding traffic protocol distribution to perform a risk analysis to generate a risk analysis result; Step 5: Analyze the obtained traffic change normal result by monitoring the periodic traffic change value and generating a monitoring result according to the adjacent periodic traffic change value.

2. The visualization data security analysis method based on big data according to claim 1, characterized in that The specific method for analyzing the traffic change abnormal result in Step 3 is as follows: Obtain the network link corresponding to the traffic change abnormal result and label it as the abnormal link. At the same time, obtain the historical data corresponding to the abnormal link and the abnormal time period corresponding to the abnormal link. Then, obtain the data in the same time period in the historical data as the comparison data with the abnormal time period as the standard, and simultaneously analyze the real-time traffic change situation corresponding to the comparison data; If the real-time traffic change situations are the same, generate a regular change result; otherwise, if the real-time traffic change situations are different, generate an irregular change result.

3. A visualization data security analysis method based on big data according to claim 1, characterized in that, The specific method for analyzing the regular change result in Step 4 is as follows: Obtain the preprocessed data corresponding to the regular change result, and classify the data types of the preprocessed data to obtain operation data and system data. Then, analyze the classified operation data and system data respectively; Analyze the classified operation data to obtain user operation information, and the user operation information includes the operation frequency and the operation volume. Then substitute the operation frequency and the operation volume into the formula , where P represents the operation frequency, L represents the operation volume, a1 and a2 represent the corresponding weight coefficients. Calculate the operation value Q of the user according to the formula. Then compare the operation value Q with the threshold Qy to generate normal information and risk information; The specific method for analyzing the classified system data is as follows: Obtain the system log, and analyze whether there is a non-system operation according to the system log. If there is, generate a risk message; otherwise, if there is no such operation, generate a normal message.

4. A visualization data security analysis method based on big data according to claim 3, characterized in that, The specific method for comparing the operation value Q with the threshold Qy to generate a normal message and a risk message in Step 4 is as follows: If the operation value Q is greater than the threshold Qy, it indicates that there is a risk in the real-time traffic change situation, and a risk message is generated; otherwise, if the operation value Q is less than the threshold Qy, it indicates that the real-time traffic change situation is normal, and a normal message is generated.

5. A visualization data security analysis method based on big data according to claim 1, characterized in that, The specific method for analyzing the irregular change result in Step 4 is as follows: Obtain the traffic packet information corresponding to the abnormal link, and at the same time obtain the corresponding traffic protocol distribution. Analyze and judge by combining the two. If the traffic protocol distribution is unstable and the corresponding traffic packet transmission is large traffic packet transmission, then comprehensively generate high-risk information. If the traffic protocol distribution is unstable and the corresponding traffic packet transmission is traffic packet transmission, then comprehensively generate medium-risk information. If the traffic protocol distribution is stable and the corresponding traffic packet transmission is small traffic packet transmission, then generate low-risk information.

6. A visualization data security analysis method based on big data according to claim 1, characterized in that The specific method for analyzing the normal result of traffic change in step five is as follows: Obtain the traffic change value, and at the same time obtain the traffic change value corresponding to the adjacent time period, and compare the two traffic change values. If the difference between the two traffic changes is a stable change, then generate a stable change signal and conduct normal monitoring. On the contrary, if the difference between the two traffic changes is an unstable change, then generate an unstable change signal and conduct secondary analysis; Obtain the unstable change signal and judge the numerical size of the difference between the two traffic changes. If the traffic change difference in the adjacent period is greater than the traffic change difference in the current period, then generate risk information. On the contrary, if the traffic change difference in the adjacent period is less than the traffic change difference in the current period, then mark the current period, and at the same time obtain the user operation corresponding to the current period and conduct analysis to generate a risk analysis result.

7. A visualization data security analysis system based on big data, which is used to execute a visualization data security analysis method according to any one of claims 1-6, characterized in that, It includes: Visual data acquisition unit, link identification and analysis unit, normal monitoring unit, risk analysis unit and analysis result output unit; Visual data acquisition unit, which is used to collect visual data, process the visual data to obtain preprocessed data, and at the same time transmit the obtained preprocessed data to the link identification and analysis unit; Link identification and analysis unit, which is used to analyze the obtained preprocessed data, monitor the network link according to the obtained preprocessed data, and at the same time monitor the real-time traffic change of different network links within the time period and generate a change monitoring result. The specific change monitoring result includes a normal traffic change result and an abnormal traffic change result. At the same time, transmit the normal traffic change result to the normal monitoring unit and transmit the abnormal traffic change result to the risk analysis unit; Normal monitoring unit, which is used to analyze the obtained normal traffic change result, monitor the periodic traffic change value, and generate a monitoring result according to the traffic change value in the adjacent period, and transmit the obtained monitoring result to the analysis result output unit; Risk analysis unit, which is used to analyze the obtained abnormal results of traffic changes. By conducting a regular analysis of the traffic change situations corresponding to the same time periods in historical data, regular change results and irregular change results are generated. The obtained regular change results are analyzed, the data types of real-time changing traffic are identified, and risk analysis is performed on the real-time traffic of different data types to obtain risk analysis results. The obtained irregular change results are analyzed. By collecting traffic packet information and conducting periodic monitoring, and at the same time combining the corresponding traffic protocol distribution for risk analysis to generate risk analysis results, and the obtained risk analysis results are transmitted to the analysis result output unit; Analysis result output unit, which is used to display the obtained analysis results and monitoring results to the corresponding operators.

Citation Information

Patent Citations

  • Data security visual analysis method and system based on big data

    CN116707940A

  • Network path analysis method and system based on network security anomaly detection

    CN117319047A

  • Data security dynamic protection method and system based on artificial intelligence

    CN118381672A