A big data driven cyber security posture monitoring and visualization method

By constructing a big data-driven cybersecurity situation monitoring model and utilizing feedforward neural networks and distributed big data network elements, we have achieved predictive monitoring and visualization of cybersecurity situation over future time intervals. This solves the problem that existing technologies cannot respond to cybersecurity crises in advance and improves the security of server clusters.

CN119496642BActive Publication Date: 2025-10-21GUIZHOU WUJIANG HYDROPOWER DEV
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411578045.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-06
Publication Date
2025-10-21
Estimated Expiration
2044-11-06

AI Technical Summary

Technical Problem

Existing technologies cannot predictively monitor and visualize the cybersecurity situation in future timeframes, making it impossible to respond to potential cybersecurity crises in advance and increasing the probability of successful attacks.

Method used

By employing distributed big data network element resources, a network security situation monitoring model is constructed. This model is trained using a feedforward neural network and combined with server cluster configuration data and historical attack virus information to intelligently determine the types of attack viruses in future time intervals. The model is then visualized and virus defense programs are configured in advance.

Benefits of technology

It enables predictive monitoring and visualization of the network security situation in future time intervals, reducing the likelihood of network crises and improving the overall network security performance of the server cluster.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119496642B_ABST
    Figure CN119496642B_ABST
Patent Text Reader

Abstract

The application relates to a big data driven network security situation monitoring and visualization method, and relates to the field of network security.The method comprises the following steps: using a big data network element to perform each training operation on a feedforward neural network to obtain a network security situation monitoring model; using the network security situation monitoring model to intelligently judge the attack virus number of a set server group in a target time interval based on the duration of each time interval, the configuration data of the set server group and the past attack virus number of the set server group. Through the application, the network security situation of a server group composed of multiple servers in a future time interval can be predictively predicted, monitored and responded to by using the network security situation monitoring model after corresponding training, so that the probability of successful virus attack is reduced, and the network crisis of data leakage or system paralysis is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security, and in particular to a big data-driven network security situation monitoring and visualization method. Background Art

[0002] Network security has different interpretations in different application environments. For a system operating on a network, network security refers to the security of information processing and transmission. This includes the safe and reliable operation of hardware systems, the security of operating systems and application software, the security of database systems, and protection against electromagnetic information leakage. In a narrow sense, network security focuses on the security of network transmission. This security is closely related to the content of the information being transmitted. The security of information content is information security, encompassing the confidentiality, authenticity, and integrity of information. In a broad sense, network security refers to the protection of the hardware, software, and information within a network system. This includes the continuous, reliable, and normal operation of the system, uninterrupted network services, and the protection of information within the system from damage, alteration, or leakage due to accidental or malicious behavior.

[0003] For example, Chinese invention patent publication CN 116032650A proposes a real-time network security situation monitoring method, which includes: 1) extracting basic network security data of different dimensions; 2) using Storm and Hadoop to store and process the basic network security data, where Hadoop is used to process historical data and Storm is used to process real-time data; 3) Hadoop uses big data processing methods to extract key security features from the historical data and establish a database table structure to form a network security feature knowledge base; 4) Storm extracts relevant security features from the real-time data, performs feature matching with the network security feature knowledge base, and determines the network security situation; 5) dynamically visualizes the network security situation determined by Storm. This invention can effectively monitor the network security situation and present a comprehensive visualization of the network security situation.

[0004] For example, the Chinese invention patent publication CN116231633A proposes a big data-driven network security situation monitoring and visualization method, which includes: at the big data processing network element end, based on the various network configuration information of the source network device corresponding to each IP address and the multiple bandwidth values ​​corresponding to the set number of network data packets sent, an artificial intelligence model is used to intelligently identify whether the source network device is a malicious attack network device; the IP address and geographical location of the intelligently identified malicious attack network device are associated and visualized. Through the present invention, in the face of the technical problem of the lack of targeted and intelligent solutions for the evaluation of malicious network attack devices, it is possible to use an artificial intelligence model built for the destination network device to perform intelligent identification and visualization of whether each IP address accessing the destination network device is a malicious attack network device, thereby solving the above technical problems.

[0005] It can be seen from this that the network security situation monitoring in the above-mentioned existing technologies is real-time monitoring of the network security situation performed on real-time network data, and the network security situation obtained by real-time monitoring is visualized. It is impossible to predict and monitor the network security situation in the future time period in a predictive manner, and thus it is impossible to visualize the predictive monitoring results. As a result, when a network security crisis occurs in the future time period, such as when it is frequently attacked by a virus with a greater threat, due to the lack of advance response measures, even if a real-time response is carried out on the spot, there is still a probability of a successful attack, which makes it easy to fall into a network crisis of data leakage or system paralysis. Summary of the Invention

[0006] In order to solve the technical defects in the existing technology, the present invention provides a big data-driven network security situation monitoring and visualization method, which relies on distributed big data network element resources. For a server group composed of multiple servers, according to the specific number of servers, a network security situation monitoring model that has undergone corresponding training scale is designed, and basic data of the corresponding data scale is used to predict and monitor the network security situation of the server group in the future time period, and then the predictive monitoring results are visualized and predictive crisis network security events are responded to in advance, thereby reducing the possibility of network crises and improving the overall network security performance of the server group.

[0007] According to the present invention, a big data-driven network security situation monitoring and visualization method is provided, the method comprising:

[0008] Using a first data network element to collect various configuration data for a set server group, the configuration data for the set server group includes the number of servers in the set server group, network transmission bandwidth, region number, and number of applications with network data interaction, wherein each server in the set server group has the same structure and the same maximum computing speed and content capacity;

[0009] Using a second data network element to capture the attack virus IDs of the set server group corresponding to each of the past time intervals before the target time interval, and simultaneously capturing the single attack virus ID corresponding to the time interval of the set server group at the same time axis position as the target time interval on the day before the current day;

[0010] performing training operations on the feedforward neural network using a third data network element to obtain a feedforward neural network after each training operation, and outputting the feedforward neural network after each training operation as a network security situation monitoring model, wherein the number of training operations performed by the feedforward neural network is proportional to the number of applications interacting with network data in the set server cluster;

[0011] The network security situation monitoring model is used to intelligently determine the single attack virus number corresponding to the set server group in the target time interval based on the duration of each time interval, various configuration data of the set server group, the attack virus numbers corresponding to each past time interval of the set server group before the target time interval, and the single attack virus number corresponding to the time interval of the set server group at the same time axis position as the target time interval on the day before the current day;

[0012] Visualizing the single attack virus number corresponding to the set server group in the target time interval obtained by intelligent judgment, and simultaneously configuring a virus defense program matching the single attack virus number corresponding to the set server group in the target time interval for the set server group in advance;

[0013] The first data network element, the second data network element and the third data network element are distributedly arranged on the network;

[0014] Among them, the single attack virus number corresponding to the set server group in the target time interval obtained by intelligent judgment is visualized, and at the same time, a virus defense program matching the single attack virus number corresponding to the set server group in the target time interval is pre-configured for the set server group in the target time interval, including: using a giant screen monitoring device configured in a monitoring room remote from the set server group to display on-site the single attack virus number corresponding to the set server group in the target time interval obtained by intelligent judgment, and the pre-configured virus defense program matching the single attack virus number corresponding to the set server group in the target time interval is used to defend against and clear the virus type associated with the single attack virus number corresponding to the set server group in the target time interval.

[0015] It can be seen that the present invention has at least the following key inventive concepts:

[0016] First, in order to intelligently determine the most frequent virus types that attack a set server cluster within a future timeframe, a customized artificial intelligence model, namely a network security situation monitoring model, is designed. The customized structure of the network security situation monitoring model is manifested in the following aspects: training operations are performed on a feedforward neural network to obtain a feedforward neural network after each training operation, and the feedforward neural network after each training operation is used as the output of the network security situation monitoring model. The number of training operations performed by the feedforward neural network is proportional to the number of applications interacting with network data in the set server cluster, thereby ensuring the effectiveness and stability of the intelligent judgment results;

[0017] Second, in order to intelligently determine the most frequent virus types that attack a set server cluster within a future time interval, multiple basic data sets are specifically selected, including the duration of each time interval, various configuration data for the set server cluster, the attack virus IDs corresponding to each time interval before the target time interval, and the single attack virus ID corresponding to the time interval when the server cluster was at the same time axis position as the target time interval the day before the current day. This comprehensive and targeted selection of multiple basic data sets further ensures the effectiveness and stability of the intelligent judgment results.

[0018] Third, in each training operation performed on the feedforward neural network, the known single attack virus ID corresponding to the set server group in a certain historical time interval is used as the output content of the feedforward neural network, and the duration of each time interval, the various configuration data of the set server group, the attack virus IDs corresponding to each past time interval before the certain historical time interval, and the single attack virus ID corresponding to the time interval when the set server group is at the same time axis position as the day before the date of the certain historical time interval are used as the input content of the feedforward neural network to complete this training operation, thereby ensuring the training effect of each training operation of the feedforward neural network;

[0019] Fourthly, when capturing the attack virus IDs corresponding to each past time interval of the set server group before the target time interval, the number of selected past time intervals is monotonically positively correlated with the number of servers in the set server group, thereby matching the amount of basic data with the set server groups of different sizes;

[0020] Fifth: Visualize the single attack virus number corresponding to the set server group in the target time interval obtained by intelligent judgment. At the same time, pre-configure a virus defense program that matches the single attack virus number corresponding to the set server group in the target time interval for the set server group, thereby improving the network security situation of the set server group and reducing the probability of the set server group being successfully attacked by different viruses. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] The embodiments of the present invention will be described below with reference to the accompanying drawings, in which:

[0022] Figure 1 The technical flow chart of a big data-driven network security situation monitoring and visualization method according to the present invention.

[0023] Figure 2 The present invention is a flowchart illustrating the steps of a big data-driven network security situation monitoring and visualization method according to the first embodiment of the present invention.

[0024] Figure 3 The present invention is a flowchart showing the steps of a big data-driven network security situation monitoring and visualization method according to the second embodiment of the present invention.

[0025] Figure 4 The present invention is a flowchart showing the steps of a big data-driven network security situation monitoring and visualization method according to the third embodiment of the present invention.

[0026] Figure 5The present invention is a flowchart showing the steps of a big data-driven network security situation monitoring and visualization method according to the fourth embodiment of the present invention.

[0027] Figure 6 The present invention is a flowchart showing the steps of a big data-driven network security situation monitoring and visualization method according to the fifth embodiment of the present invention. DETAILED DESCRIPTION

[0028] like Figure 1 As shown, a technical flow chart of a big data driven network security situation monitoring and visualization method according to the present invention is given.

[0029] like Figure 1 As shown, the giant screen monitoring device in the same monitoring room is responsible for monitoring the network security status of multiple server clusters and performing corresponding visualization processing based on the monitoring results;

[0030] exist Figure 1 In the present invention, a big data-driven network security situation monitoring and visualization method is specifically described by taking the first server group as a setting server group in an illustrative manner.

[0031] like Figure 1 As shown, the specific technical process of the present invention is as follows:

[0032] Technical Process A: Build a network security situation monitoring model whose structure matches the server size of the designated server cluster, and intelligently determine the most frequent virus types that will attack the designated server cluster in the future.

[0033] Specifically, the structure of the network security situation monitoring model matches the server size of the set server cluster. The network security situation monitoring model is a feedforward neural network that executes each training operation. The key point is that the number of training operations executed by the feedforward neural network is proportional to the number of applications that interact with network data in the set server cluster. This allows network security situation monitoring models with different structures to be constructed for set server clusters of different server sizes, ensuring the effectiveness and stability of the intelligent judgment results.

[0034] In addition, in each training operation performed on the feedforward neural network, the known single attack virus number corresponding to the set server group in a certain historical time interval is used as the output content of the feedforward neural network, and the duration of each time interval, the various configuration data of the set server group, the attack virus numbers corresponding to each past time interval before the certain historical time interval, and the single attack virus number corresponding to the time interval when the set server group is at the same time axis position as the certain historical time interval on the day before the date of the certain historical time interval are used as the input content of the feedforward neural network to complete this training operation, thereby ensuring the training effect of each training operation of the feedforward neural network;

[0035] Technical Process B: Introducing basic data that matches the size of the server cluster to intelligently determine the most frequent virus types that attack the cluster in the future.

[0036] For example, the basic data includes the duration of each time interval, various configuration data of the server group, the attack virus IDs corresponding to each previous time interval before the target time interval, and the single attack virus ID corresponding to the time interval of the server group at the same time axis position as the target time interval on the previous day. The comprehensive and targeted selection of the above multiple basic data further ensures the effectiveness and stability of the intelligent judgment results.

[0037] Crucially, when capturing the attack virus IDs corresponding to each past time interval of the set server cluster before the target time interval, the number of selected past time intervals is monotonically positively correlated with the number of servers in the set server cluster, thereby matching the amount of basic data with the set server clusters of different sizes.

[0038] Technical Process C: The network security situation monitoring model designed in Technical Process A uses the multiple basic data selected in Technical Process B to intelligently determine the most frequent virus types that attack the specified server cluster within the future time period.

[0039] Technical Process D: Visualize the single attack virus ID corresponding to the target time interval of the set server group obtained by intelligent judgment. At the same time, pre-configure a virus defense program for the set server group in the target time interval that matches the single attack virus ID corresponding to the set server group in the target time interval.

[0040] The execution of technical process A and technical process B depends on various big data network elements distributed on the network. For example, technical process B depends on the first big data network element and the second big data network element, and technical process A depends on the third big data network element.

[0041] In this way, through the design of the above-mentioned multiple technical processes, the network security situation of the set server group is improved, the probability of successful attacks by different viruses on the set server group is reduced, and the effectiveness and efficiency of network security situation monitoring is ensured.

[0042] The key points of the present invention are: the structural construction of a network security situation monitoring model that matches the server quantity scale of the set server group, the selection of the data scale of basic data that matches the server quantity scale of the set server group, the intelligent judgment of the virus type that attacks the set server group most frequently in the future time period, and the visualization processing and targeted advance response based on the intelligent judgment results.

[0043] Below, a big data driven network security situation monitoring and visualization method of the present invention will be specifically described in the form of an embodiment.

[0044] First embodiment

[0045] Figure 2 The present invention is a flowchart illustrating the steps of a big data-driven network security situation monitoring and visualization method according to the first embodiment of the present invention.

[0046] like Figure 2 As shown, the big data-driven network security situation monitoring and visualization method includes the following steps:

[0047] Step S201: Using a first data network element, various configuration data for a set server group are collected. The configuration data for the set server group includes the number of servers in the set server group, network transmission bandwidth, region number, and number of applications interacting with network data. Each server in the set server group has the same structure and the same maximum computing speed and content capacity.

[0048] For example, for a server cluster with a scale of 100 servers, each server has the same structure and performance. The number of applications that interact with network data in the overall configuration of the server cluster is 20. These applications serve as channels for external virus attacks, posing a network security risk to the entire server cluster.

[0049] Step S202: Using a second data network element, the second data network element captures the attack virus IDs corresponding to each of the time intervals before the target time interval for the server group, and also captures the single attack virus ID corresponding to the time interval on the same time axis as the target time interval for the server group on the day before the current day.

[0050] Specifically, different virus types correspond to different attack virus numbers. Usually, these different attack virus numbers are represented by binary values.

[0051] Step S203: Using a third data network element to perform each training operation on the feedforward neural network to obtain a feedforward neural network after each training operation, and outputting the feedforward neural network after each training operation as a network security situation monitoring model, wherein the number of training operations performed by the feedforward neural network is proportional to the number of applications interacting with network data in the set server group;

[0052] For example, the number of training operations performed by the feedforward neural network is proportional to the number of applications with network data interaction in the set server group, including: when the number of applications with network data interaction in the set server group is 15, the number of training operations performed by the feedforward neural network is 150; when the number of applications with network data interaction in the set server group is 20, the number of training operations performed by the feedforward neural network is 200; when the number of applications with network data interaction in the set server group is 30, the number of training operations performed by the feedforward neural network is 300, and so on;

[0053] Step S204: Using the network security situation monitoring model, intelligently determining the single attack virus number corresponding to the target time interval of the set server group based on the duration of each time interval, various configuration data of the set server group, the attack virus numbers corresponding to each past time interval of the set server group before the target time interval, and the single attack virus number corresponding to the time interval of the set server group at the same time axis position as the target time interval on the previous day;

[0054] Specifically, a numerical simulation mode can be selected to implement testing and simulation using the network security situation monitoring model to intelligently determine the single attack virus number corresponding to the target time interval of the set server group based on the duration of each time interval, various configuration data of the set server group, the attack virus numbers corresponding to each past time interval of the set server group before the target time interval, and the single attack virus number corresponding to the time interval of the set server group at the same time axis position as the target time interval on the previous day;

[0055] Step S205: Visualizing the single attack virus ID corresponding to the set server group in the target time interval obtained by intelligent judgment, and pre-configuring a virus defense program for the set server group in the target time interval that matches the single attack virus ID corresponding to the set server group in the target time interval;

[0056] For example, pre-configuring a virus defense program that matches a single attack virus ID corresponding to the set server group in the target time interval for the set server group in the target time interval includes: upon obtaining the single attack virus ID corresponding to the set server group in the target time interval, immediately calling the matching virus defense program from a local application database or downloading the matching virus defense program from a remote virus data storage network element to complete on-site virus defense and removal;

[0057] The first data network element, the second data network element and the third data network element are distributedly arranged on the network;

[0058] For example, the first big data network element, the second big data network element, and the third big data network element are distributedly arranged on the network, including: the physical devices corresponding to the first big data network element, the second big data network element, and the third big data network element can be arranged in different regions;

[0059] The method further comprises: visualizing the single attack virus number corresponding to the set server group in the target time interval obtained by intelligent judgment, and pre-configuring a virus defense program for the set server group in the target time interval that matches the single attack virus number corresponding to the set server group in the target time interval, including: using a giant screen monitoring device configured in a monitoring room remote from the set server group to display the single attack virus number corresponding to the set server group in the target time interval obtained by intelligent judgment, and using the pre-configured virus defense program that matches the single attack virus number corresponding to the set server group in the target time interval to defend against and clear the virus type associated with the single attack virus number corresponding to the set server group in the target time interval;

[0060] The method further includes: using a second data network element to capture the numbers of attack viruses corresponding to respective past time intervals of the set server group before the target time interval, and capturing the numbers of single attack viruses corresponding to the same time interval as the target time interval on the day before the current day; wherein the number of each past time interval is monotonically positively correlated with the number of servers in the set server group;

[0061] For example, the number of each past time interval is monotonically positively correlated with the number of servers in the set server group, including: when the set server group has 80 servers, the number of each past time interval is selected as 5; when the set server group has 100 servers, the number of each past time interval is selected as 8; when the set server group has 150 servers, the number of each past time interval is selected as 10, and so on;

[0062] wherein, a third data network element is used to perform each training operation on the feedforward neural network to obtain a feedforward neural network after each training operation is performed, and the feedforward neural network after each training operation is output as a network security situation monitoring model, wherein the number of training operations performed by the feedforward neural network is proportional to the number of applications with network data interaction in the set server group, including: in each training operation performed on the feedforward neural network using the third data network element, a single attack virus number corresponding to a certain historical time interval of the known set server group is used as the output content of the feedforward neural network, and the duration of each time interval, various configuration data of the set server group, the attack virus numbers corresponding to each past time interval of the set server group before the certain historical time interval, and the single attack virus number corresponding to the time interval when the set server group is at the same time axis position as the certain historical time interval on the day before the date of the certain historical time interval are used as the input content of the feedforward neural network to complete this training operation;

[0063] For example, the duration of each time interval is a fixed value each time the network security situation monitoring model is constructed, for example, 20 minutes;

[0064] Among them, using a second large data network element to capture each attack virus number corresponding to each past time interval before the target time interval of the set server group, and simultaneously capturing a single attack virus number corresponding to a simultaneous time interval of the set server group that is at the same time axis position as the target time interval on the day before the current day includes: the target time interval belongs to a future time interval starting at the current moment, and the target time interval and each past time interval before the target time interval form a complete time segment on the time axis, and the position of the simultaneous time interval on the time axis of the day before the current day is the same as the position of the target time interval on the time axis of the current day;

[0065] And wherein, a second large data network element is used to capture each attack virus number corresponding to each past time interval before the target time interval of the set server group, and at the same time, captures the single attack virus number corresponding to the time interval when the set server group is at the same time axis position as the target time interval the day before the current day, and also includes: the duration of each time interval is equal and is a fixed time length, and the single attack virus number corresponding to each time interval is the number corresponding to the virus type that attacks the set server group the most times within the time interval.

[0066] Second embodiment

[0067] Figure 3 The present invention is a flowchart showing the steps of a big data-driven network security situation monitoring and visualization method according to the second embodiment of the present invention.

[0068] like Figure 3 As shown, compared with Figure 2 After step S203, the method further includes:

[0069] Step S301: using a big data storage network element to receive the network security situation monitoring model, and completing the model storage of the network security situation monitoring model by storing various model parameters of the network security situation monitoring model;

[0070] Specifically, using a big data storage network element to receive the network security situation monitoring model, and completing the model storage of the network security situation monitoring model by storing various model parameters of the network security situation monitoring model includes: optionally using a local data storage chip to replace the big data storage network element, for receiving the network security situation monitoring model, and completing the model storage of the network security situation monitoring model by storing various model parameters of the network security situation monitoring model.

[0071] Third embodiment

[0072] Figure 4 The present invention is a flowchart showing the steps of a big data-driven network security situation monitoring and visualization method according to the third embodiment of the present invention.

[0073] like Figure 4 As shown, compared with Figure 2 After step S204, the method further includes:

[0074] Step S401: When there is no virus defense program matching the single attack virus number corresponding to the set server group in the target time interval, downloading the virus defense program matching the single attack virus number corresponding to the set server group in the target time interval from a remote virus data storage network element;

[0075] For example, when there is a lack of a virus defense program that matches the single attack virus number corresponding to the set server group in the target time interval, downloading the virus defense program that matches the single attack virus number corresponding to the set server group in the target time interval from a remote virus data storage network element includes: optionally downloading the virus defense program that matches the single attack virus number corresponding to the set server group in the target time interval from a remote virus data storage network element via a time division duplex communication link or a frequency division duplex communication link.

[0076] Fourth embodiment

[0077] Figure 5 The present invention is a flowchart showing the steps of a big data-driven network security situation monitoring and visualization method according to the fourth embodiment of the present invention.

[0078] like Figure 5 As shown, compared with Figure 2 After step S204, the method further includes:

[0079] Step S501: using a virus warning component configured in a monitoring room remote from the set server group to execute an on-site warning action corresponding to the absence of viruses and the need for timely virus protection procedures;

[0080] For example, using a virus warning component configured in a monitoring room remote from the set server group to execute on-site warning actions corresponding to the lack of viruses and the need for timely virus defense programs includes: the monitoring room is generally responsible for monitoring and managing the network security situation of multiple server groups.

[0081] Fifth embodiment

[0082] Figure 6 The present invention is a flowchart showing the steps of a big data-driven network security situation monitoring and visualization method according to the fifth embodiment of the present invention.

[0083] like Figure 6 As shown, compared with Figure 2 After step S205, the method further includes:

[0084] Step S601: After pre-configuration of a virus defense program that matches the single attack virus ID corresponding to the target time interval of the set server cluster, a large screen monitoring device located in a monitoring room remote from the set server cluster is used to display a notification signal corresponding to successful configuration of the virus defense program for the target time interval in real time;

[0085] Specifically, after completing the advance configuration of the virus defense program that matches the single attack virus number corresponding to the set server group in the target time interval, a giant screen monitoring device configured in a monitoring room remote from the set server group is used to perform real-time display of a notification signal corresponding to the successful configuration of the virus defense program in the target time interval, including: an LCD display array or an LED display array can be selected to replace the giant screen monitoring device to perform real-time display of a notification signal corresponding to the successful configuration of the virus defense program in the target time interval.

[0086] Next, various embodiments of the present invention will be further described.

[0087] In each of the above embodiments, optionally, in the big data-driven network security situation monitoring and visualization method:

[0088] The method further includes: using a second data network element to capture the attack virus numbers corresponding to each of the past time intervals of the set server group before the target time interval, and capturing the single attack virus number corresponding to the time interval of the set server group at the same time axis position as the target time interval on the previous day, further comprising: using a numerical mapping formula to represent a numerical mapping relationship in which the number of the past time intervals is monotonically positively correlated with the number of servers in the set server group;

[0089] For example, a MATLAB toolbox may be selected to complete the simulation and testing of a data processing process for using a numerical mapping formula to represent a numerical mapping relationship in which the number of each past time interval is monotonically positively correlated with the number of servers in the set server group.

[0090] The method further includes: using a second data network element to capture the attack virus IDs of the set server group corresponding to respective time intervals before the target time interval, and capturing the single attack virus ID of the set server group corresponding to the same time interval as the target time interval on the previous day. The method further includes: in the numerical mapping formula, the number of servers of the set server group is used as an input parameter of the numerical mapping formula;

[0091] Among them, using a second large data network element to capture each attack virus number corresponding to each past time interval before the target time interval of the set server group, and at the same time capturing a single attack virus number corresponding to the same time interval when the set server group is at the same time axis position as the target time interval on the day before the current day also includes: in the numerical mapping formula, the number of the each past time interval corresponding to the number of servers of the set server group is the output parameter of the numerical mapping formula.

[0092] In each of the above embodiments, optionally, in the big data-driven network security situation monitoring and visualization method:

[0093] Using the network security situation monitoring model to intelligently determine the single attack virus number corresponding to the set server group in the target time interval based on the duration of each time interval, the various configuration data of the set server group, the attack virus numbers corresponding to the various past time intervals of the set server group before the target time interval, and the single attack virus number corresponding to the time interval when the set server group was at the same time axis position as the target time interval on the day before the current day, the network security situation monitoring model includes: inputting the duration of each time interval, the various configuration data of the set server group, the attack virus numbers corresponding to the various past time intervals of the set server group before the target time interval, and the single attack virus number corresponding to the time interval when the set server group was at the same time axis position as the target time interval on the day before the current day into the network security situation monitoring model in parallel;

[0094] Wherein, the duration of each time interval, the various configuration data of the set server group, the attack virus numbers corresponding to the various past time intervals of the set server group before the target time interval, and the single attack virus numbers corresponding to the time intervals when the set server group was at the same time axis position as the target time interval on the day before the current day are inputted in parallel into the network security situation monitoring model, including: performing numerical normalization processing on the duration of each time interval, the various configuration data of the set server group, the attack virus numbers corresponding to the various past time intervals of the set server group before the target time interval, and the single attack virus numbers corresponding to the time intervals when the set server group was at the same time axis position as the target time interval on the day before the current day, and then inputting them in parallel into the network security situation monitoring model;

[0095] Among them, the duration of each time interval, the various configuration data of the set server group, the attack virus numbers corresponding to the various past time intervals of the set server group before the target time interval, and the single attack virus numbers corresponding to the time intervals when the set server group was at the same time axis position as the target time interval on the day before the current day are respectively subjected to numerical normalization processing and then input in parallel into the network security situation monitoring model. It also includes: the duration of each time interval, the various configuration data of the set server group, the attack virus numbers corresponding to the various past time intervals of the set server group before the target time interval, and the single attack virus numbers corresponding to the time intervals when the set server group was at the same time axis position as the target time interval on the day before the current day are respectively subjected to binary numerical conversion processing and then input in parallel into the network security situation monitoring model.

[0096] In each of the above embodiments, optionally, in the big data-driven network security situation monitoring and visualization method:

[0097] Intelligently determining the single attack virus number corresponding to the set server group in the target time interval using the network security situation monitoring model based on the duration of each time interval, various configuration data of the set server group, the attack virus numbers corresponding to various past time intervals of the set server group before the target time interval, and the single attack virus number corresponding to the time interval of the set server group at the same time axis position as the target time interval on the day before the current day, includes: executing the network security situation monitoring model to obtain the single attack virus number corresponding to the set server group in the target time interval output by the network security situation monitoring model;

[0098] Among them, executing the network security situation monitoring model to obtain the single attack virus number corresponding to the set server group in the target time interval output by the network security situation monitoring model includes: the single attack virus number corresponding to the set server group in the target time interval output by the network security situation monitoring model is represented in the form of a binary value.

[0099] In addition, in a big data driven network security situation monitoring and visualization method according to the present invention:

[0100] The method includes: using a parallel drive interface to perform binary value conversion on the duration of each time interval, the various configuration data of the set server group, the attack virus numbers corresponding to the various past time intervals of the set server group before the target time interval, and the single attack virus number corresponding to the time interval of the set server group at the same time axis position as the target time interval on the previous day, and then inputting the binary value conversion to the network security situation monitoring model in parallel;

[0101] For example, the parallel input of the network security situation monitoring model to the duration of each time interval after binary value conversion processing is performed using a parallel drive interface, various configuration data of the set server group, the attack virus numbers corresponding to each past time interval of the set server group before the target time interval, and the single attack virus number corresponding to the time interval of the set server group at the same time axis position as the target time interval on the previous day includes: the parallel drive interface is a CPLD device designed in VHDL language;

[0102] And wherein, the duration of each time interval, the various configuration data of the set server group, the attack virus numbers corresponding to the various past time intervals of the set server group before the target time interval, and the single attack virus numbers corresponding to the time interval when the set server group was at the same time axis position as the target time interval on the day before the current day are respectively subjected to binary numerical conversion processing and then input into the network security situation monitoring model in parallel, which also includes: using a numerical conversion component to perform binary numerical conversion processing on the duration of each time interval, the various configuration data of the set server group, the attack virus numbers corresponding to the various past time intervals of the set server group before the target time interval, and the single attack virus numbers corresponding to the time interval when the set server group was at the same time axis position as the target time interval on the day before the current day.

[0103] In addition, the terms "first" and "second" are used for descriptive purposes only and are not to be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Thus, features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of the embodiments of the present application, "multiple" means two or more, unless otherwise clearly and specifically defined. In the description of this specification, the description with reference to the terms "one embodiment", "certain embodiments", "illustrative embodiments", "example", "specific example" or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiments or examples are included in at least one embodiment or example of the present application. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in an appropriate manner in any one or more embodiments or examples.

[0104] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limitations on the present application. Ordinary technicians in this field can change, modify, replace and modify the above embodiments within the scope of the present application.

Claims

1. A big data driven network security situation monitoring and visualization method, characterized in that: The method comprises: Using a first data network element to collect various configuration data for a set server group, the configuration data for the set server group includes the number of servers in the set server group, network transmission bandwidth, region number, and number of applications with network data interaction, wherein each server in the set server group has the same structure and the same maximum computing speed and content capacity; Using a second data network element to capture the attack virus IDs of the set server group corresponding to each of the past time intervals before the target time interval, and simultaneously capturing the single attack virus ID corresponding to the time interval of the set server group at the same time axis position as the target time interval on the day before the current day; performing training operations on the feedforward neural network using a third data network element to obtain a feedforward neural network after each training operation, and outputting the feedforward neural network after each training operation as a network security situation monitoring model, wherein the number of training operations performed by the feedforward neural network is proportional to the number of applications interacting with network data in the set server cluster; The network security situation monitoring model is used to intelligently determine the single attack virus number corresponding to the set server group in the target time interval based on the duration of each time interval, various configuration data of the set server group, the attack virus numbers corresponding to each past time interval of the set server group before the target time interval, and the single attack virus number corresponding to the time interval of the set server group at the same time axis position as the target time interval on the day before the current day; Visualizing the single attack virus number corresponding to the set server group in the target time interval obtained by intelligent judgment, and simultaneously configuring a virus defense program matching the single attack virus number corresponding to the set server group in the target time interval for the set server group in advance; The first data network element, the second data network element and the third data network element are distributedly arranged on the network; Among them, the single attack virus number corresponding to the set server group in the target time interval obtained by intelligent judgment is visualized, and at the same time, a virus defense program matching the single attack virus number corresponding to the set server group in the target time interval is pre-configured for the set server group in the target time interval, including: using a giant screen monitoring device configured in a monitoring room remote from the set server group to display on-site the single attack virus number corresponding to the set server group in the target time interval obtained by intelligent judgment, and the pre-configured virus defense program matching the single attack virus number corresponding to the set server group in the target time interval is used to defend against and clear the virus type associated with the single attack virus number corresponding to the set server group in the target time interval.

2. The big data-driven network security situation monitoring and visualization method according to claim 1, characterized in that: The method further includes: using a second data network element to capture the numbers of attack viruses corresponding to respective past time intervals of the set server group before the target time interval, and capturing the numbers of single attack viruses corresponding to the same time interval as the target time interval on the day before the current day; wherein the number of each past time interval is monotonically positively correlated with the number of servers in the set server group; Among them, a third data network element is used to perform each training operation on the feedforward neural network to obtain a feedforward neural network after each training operation is performed, and the feedforward neural network after each training operation is performed is output as a network security situation monitoring model. The number of training operations performed by the feedforward neural network is proportional to the number of applications that have network data interaction in the set server group. It includes: in each training operation performed on the feedforward neural network using the third data network element, the single attack virus number corresponding to the set server group in a certain historical time interval is used as the output content of the feedforward neural network, the duration of each time interval, the various configuration data of the set server group, the attack virus numbers corresponding to each past time interval of the set server group before the certain historical time interval, and the single attack virus number corresponding to the time interval when the set server group is at the same time axis position as the certain historical time interval on the day before the date of the certain historical time interval are used as the input content of the feedforward neural network to complete this training operation.

3. The big data-driven network security situation monitoring and visualization method according to claim 2, characterized in that: Using a second data network element to capture the attack virus numbers corresponding to each of the past time intervals before the target time interval for the set server group, and simultaneously capturing the single attack virus number corresponding to a simultaneous time interval of the set server group that is at the same time axis position as the target time interval on the day before the current day, including: the target time interval belongs to a future time interval starting at the current time, the target time interval and each of the past time intervals before the target time interval form a complete time segment on the time axis, and the position of the simultaneous time interval on the time axis on the day before the current day is the same as the position of the target time interval on the time axis on the current day; Among them, a second large data network element is used to capture the attack virus numbers corresponding to each past time interval of the set server group before the target time interval, and at the same time, capture the single attack virus number corresponding to the time interval when the set server group is at the same time axis position as the target time interval on the day before the current day. It also includes: the duration of each time interval is equal and is a fixed time length, and the single attack virus number corresponding to each time interval is the number corresponding to the virus type that attacks the set server group the most times within the time interval.

4. The big data driven network security situation monitoring and visualization method according to claim 3, characterized in that: After performing each training operation on the feedforward neural network using the third data network element to obtain the feedforward neural network after each training operation, and outputting the feedforward neural network after each training operation as a network security situation monitoring model, wherein the number of training operations performed by the feedforward neural network is proportional to the number of applications interacting with network data in the set server group, the method further includes: The network security situation monitoring model is received by using a big data storage network element, and the model storage of the network security situation monitoring model is completed by storing various model parameters of the network security situation monitoring model.

5. The big data driven network security situation monitoring and visualization method according to claim 3, characterized in that: After intelligently determining the single attack virus number corresponding to the target time interval of the set server group using the network security situation monitoring model based on the duration of each time interval, various configuration data of the set server group, the attack virus numbers corresponding to each past time interval of the set server group before the target time interval, and the single attack virus number corresponding to the time interval of the set server group at the same time axis position as the target time interval on the previous day, the method further includes: When there is no virus defense program that matches the single attack virus number corresponding to the set server group in the target time interval, the virus defense program that matches the single attack virus number corresponding to the set server group in the target time interval is downloaded from a remote virus data storage network element.

6. The big data driven network security situation monitoring and visualization method according to claim 3, characterized in that: After intelligently determining the single attack virus number corresponding to the target time interval of the set server group using the network security situation monitoring model based on the duration of each time interval, various configuration data of the set server group, the attack virus numbers corresponding to each past time interval of the set server group before the target time interval, and the single attack virus number corresponding to the time interval of the set server group at the same time axis position as the target time interval on the previous day, the method further includes: The virus early warning component configured in the monitoring room at the remote end of the set server group is used to execute on-site early warning actions corresponding to the lack of viruses and the need for timely virus defense programs.

7. The big data driven network security situation monitoring and visualization method according to claim 3, characterized in that: After visualizing the single attack virus number corresponding to the set server group in the target time interval obtained by intelligent judgment, and pre-configuring a virus defense program matching the single attack virus number corresponding to the set server group in the target time interval for the set server group in the target time interval, the method further includes: After completing the advance configuration of the virus defense program that matches the single attack virus number corresponding to the set server group in the target time interval, a giant screen monitoring device configured in a monitoring room remote from the set server group is used to perform real-time display of the notification signal corresponding to the successful configuration of the virus defense program in the target time interval.

8. The big data-driven network security situation monitoring and visualization method according to any one of claims 3 to 7, characterized in that: The method further includes: using a second data network element to capture the attack virus numbers corresponding to each of the past time intervals of the set server group before the target time interval, and capturing the single attack virus number corresponding to the time interval of the set server group at the same time axis position as the target time interval on the previous day, further comprising: using a numerical mapping formula to represent a numerical mapping relationship in which the number of the past time intervals is monotonically positively correlated with the number of servers in the set server group; The method further includes: using a second data network element to capture the attack virus IDs of the set server group corresponding to respective time intervals before the target time interval, and capturing the single attack virus ID of the set server group corresponding to the same time interval as the target time interval on the previous day. The method further includes: in the numerical mapping formula, the number of servers of the set server group is used as an input parameter of the numerical mapping formula; Among them, using a second large data network element to capture each attack virus number corresponding to each past time interval before the target time interval of the set server group, and at the same time capturing a single attack virus number corresponding to the same time interval when the set server group is at the same time axis position as the target time interval on the day before the current day also includes: in the numerical mapping formula, the number of the each past time interval corresponding to the number of servers of the set server group is the output parameter of the numerical mapping formula.

9. The big data-driven network security situation monitoring and visualization method according to any one of claims 3 to 7, characterized in that: Using the network security situation monitoring model to intelligently determine the single attack virus number corresponding to the set server group in the target time interval based on the duration of each time interval, the various configuration data of the set server group, the attack virus numbers corresponding to the various past time intervals of the set server group before the target time interval, and the single attack virus number corresponding to the time interval when the set server group was at the same time axis position as the target time interval on the day before the current day, the network security situation monitoring model includes: inputting the duration of each time interval, the various configuration data of the set server group, the attack virus numbers corresponding to the various past time intervals of the set server group before the target time interval, and the single attack virus number corresponding to the time interval when the set server group was at the same time axis position as the target time interval on the day before the current day into the network security situation monitoring model in parallel; Wherein, the duration of each time interval, the various configuration data of the set server group, the attack virus numbers corresponding to the various past time intervals of the set server group before the target time interval, and the single attack virus numbers corresponding to the time intervals when the set server group was at the same time axis position as the target time interval on the day before the current day are inputted in parallel into the network security situation monitoring model, including: performing numerical normalization processing on the duration of each time interval, the various configuration data of the set server group, the attack virus numbers corresponding to the various past time intervals of the set server group before the target time interval, and the single attack virus numbers corresponding to the time intervals when the set server group was at the same time axis position as the target time interval on the day before the current day, and then inputting them in parallel into the network security situation monitoring model; Among them, the duration of each time interval, the various configuration data of the set server group, the attack virus numbers corresponding to the various past time intervals of the set server group before the target time interval, and the single attack virus numbers corresponding to the time intervals when the set server group was at the same time axis position as the target time interval on the day before the current day are respectively subjected to numerical normalization processing and then input in parallel into the network security situation monitoring model. It also includes: the duration of each time interval, the various configuration data of the set server group, the attack virus numbers corresponding to the various past time intervals of the set server group before the target time interval, and the single attack virus numbers corresponding to the time intervals when the set server group was at the same time axis position as the target time interval on the day before the current day are respectively subjected to binary numerical conversion processing and then input in parallel into the network security situation monitoring model.

10. The big data driven network security situation monitoring and visualization method according to any one of claims 3 to 7, characterized in that: Intelligently determining the single attack virus number corresponding to the set server group in the target time interval using the network security situation monitoring model based on the duration of each time interval, various configuration data of the set server group, the attack virus numbers corresponding to various past time intervals of the set server group before the target time interval, and the single attack virus number corresponding to the time interval of the set server group at the same time axis position as the target time interval on the day before the current day, includes: executing the network security situation monitoring model to obtain the single attack virus number corresponding to the set server group in the target time interval output by the network security situation monitoring model; Among them, executing the network security situation monitoring model to obtain the single attack virus number corresponding to the set server group in the target time interval output by the network security situation monitoring model includes: the single attack virus number corresponding to the set server group in the target time interval output by the network security situation monitoring model is represented in the form of a binary value.

Citation Information

Patent Citations

  • Network security situation real-time monitoring method

    CN116032650A

  • Method, device and equipment for monitoring carbon emission of power distribution network and storage medium

    CN116231633A

  • Virus processing method and device, equipment and storage medium

    CN110826069A

  • System and method for extracting and combining electronic risk information for business continuity management with actionable feedback methodologies

    US20200322370A1