Methods, devices, and electronic equipment for building a data security situation awareness platform
By constructing a data security situation awareness platform and utilizing anomaly analysis and detection technologies, the problem of poor adaptability of traditional data security protection methods in dynamic network environments has been solved, enabling real-time anomaly detection and protection, and improving the security and stability of data transmission.
Patent Information
- Application Number
- CN202411728828.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-28
- Publication Date
- 2025-10-31
- Estimated Expiration
- 2044-11-28
AI Technical Summary
Traditional data security protection methods rely on static rules and signature-based detection systems, which are difficult to adapt to dynamically changing network environments and attack patterns, leading to false positives or missed detections, thus affecting the accuracy and efficiency of security protection.
A data security situation awareness platform is constructed to acquire network communication data, perform anomaly analysis and detection, identify abnormal nodes and links, construct blocking strategies, form a secure information transmission link structure model, and achieve real-time anomaly detection and protection.
It improves the security and real-time performance of data transmission, enables timely identification and response to network security threats, reduces false alarms and missed alarms, and enhances the stability and security of the network environment.
Smart Images

Figure CN119544335B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to a method, apparatus, and electronic device for constructing a data security situation awareness platform. Background Technology
[0002] With the rapid development of information technology and the widespread application of the Internet, data security has become a primary concern for all types of organizations and enterprises. In a digital and networked environment, the transmission, storage, and processing of data are becoming increasingly complex, and data security threats are becoming increasingly serious. From early virus attacks and network intrusions to modern advanced persistent threats (APTs), data breaches, and ransomware, the types and complexity of data security threats are constantly increasing.
[0003] Traditional data security protection methods mainly rely on static rules and signature-based detection systems. These methods depend primarily on known attack signature databases and may fail when faced with unknown or variant attack techniques. Traditional static rules, based on fixed security policies, struggle to adapt to dynamically changing network environments and attack patterns, easily leading to false positives or missed detections, thus affecting the accuracy and efficiency of security protection. Summary of the Invention
[0004] This application provides a method, apparatus, and electronic device for building a data security situation awareness platform, so as to improve the real-time performance and adaptability of push notifications for transaction risks and marketing content.
[0005] In a first aspect, embodiments of this application provide a method for constructing a data security situation awareness platform, the method comprising:
[0006] Obtain the network communication data of the entity to be constructed, and determine the information transmission data and information transmission topology model of the entity to be constructed based on the network communication data;
[0007] Anomaly analysis is performed on the information transmission data to obtain abnormal information transmission data. Based on the network communication data, abnormal network communication correction is performed on the abnormal information transmission data to obtain insecure information transmission data.
[0008] An abnormal information transmission detection model is constructed based on insecure information transmission data, and the abnormal information transmission data is detected by the abnormal information transmission detection model to obtain real-time abnormal information transmission data.
[0009] Based on the real-time abnormal information transmission data, the information transmission topology model is divided into abnormal information transmission nodes to obtain abnormal information transmission node data. Then, based on the abnormal information transmission node data, the abnormal node links are integrated to obtain abnormal node link data.
[0010] Based on the abnormal node link data and information transmission data, the abnormal transmission node blocking strategy is analyzed to obtain the abnormal transmission node blocking strategy. Based on the abnormal transmission node blocking strategy and the information transmission topology model, a secure information transmission link structure model is constructed.
[0011] A security situation awareness platform is constructed based on a secure information transmission link structure model and an abnormal information transmission detection model, resulting in the information transmission security situation awareness platform for the entity to be built.
[0012] Secondly, embodiments of this application provide an apparatus for constructing a data security situation awareness platform, the apparatus comprising:
[0013] The information transmission topology module is used to acquire the network communication data of the entity to be constructed, and to determine the information transmission data and information transmission topology model of the entity to be constructed based on the network communication data.
[0014] The abnormal information transmission analysis module is used to perform abnormal analysis on the information transmission data, obtain abnormal information transmission data, and perform abnormal network communication correction on the abnormal information transmission data based on network communication data to obtain insecure information transmission data.
[0015] The abnormal information transmission detection model construction module is used to construct an abnormal information transmission detection model based on insecure information transmission data, and to perform abnormal information transmission detection on the information transmission data through the abnormal information transmission detection model to obtain real-time abnormal information transmission data.
[0016] The abnormal node link integration module is used to divide the information transmission topology model into abnormal information transmission nodes based on real-time abnormal information transmission data, obtain abnormal information transmission node data, and integrate abnormal node links based on the abnormal information transmission node data to obtain abnormal node link data.
[0017] The blocking strategy analysis module is used to analyze the blocking strategy of abnormal transmission nodes based on the abnormal node link data and information transmission data, obtain the blocking strategy of abnormal transmission nodes, and construct a secure information transmission link structure model based on the abnormal transmission node blocking strategy and the information transmission topology model.
[0018] The security situation awareness platform construction module is used to construct a security situation awareness platform based on a security information transmission link structure model and an abnormal information transmission detection model, thereby obtaining the information transmission security situation awareness platform for the entity to be constructed.
[0019] Thirdly, embodiments of this application also provide an electronic device, which includes:
[0020] One or more processors;
[0021] Storage device for storing one or more programs.
[0022] When one or more programs are executed by one or more processors, the one or more processors implement the method for building a data security situation awareness platform as provided in any embodiment of this application.
[0023] The technical solution of this application embodiment acquires and extracts network communication data of the entity to be constructed to obtain information transmission data of the entity to be constructed; analyzes the information transmission data of the entity to be constructed to obtain an information transmission topology model; analyzes the information transmission data of the entity to be constructed to obtain insecure information transmission data; constructs an abnormal information transmission detection model based on the insecure information transmission data and performs detection to obtain real-time abnormal information transmission data; integrates the information transmission topology model to obtain abnormal node link data; analyzes the abnormal node link data and the information transmission data of the entity to be constructed to obtain a secure information transmission link structure model; and establishes an information transmission security situation awareness platform. This invention can prevent data security or network security incidents from occurring and provide a better network environment. Attached Figure Description
[0024] Figure 1 A flowchart illustrating the method for constructing a data security situation awareness platform as provided in Embodiment 1 of this application;
[0025] Figure 2 A schematic diagram of the structure of an apparatus for constructing a data security situation awareness platform, provided in Embodiment 2 of this application;
[0026] Figure 3 This is a schematic diagram of the structure of an electronic device provided in Embodiment 3 of this application. Detailed Implementation
[0027] The present application will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the application and not intended to limit it. Furthermore, it should be noted that, for ease of description, the accompanying drawings show only the parts relevant to the present application, not the entire structure.
[0028] Example 1
[0029] Figure 1 A flowchart illustrating the method for constructing a data security situation awareness platform as provided in Embodiment 1 of this application is shown below. Figure 1 As shown, the method for constructing a data security situation awareness platform provided in this embodiment can be applied to a data security situation awareness platform built on devices with data processing capabilities, such as computers. It can be used in conjunction with some application software to achieve a better user experience. Specifically, it can include the following steps:
[0030] Step 101: Obtain the network communication data of the entity to be constructed, and determine the information transmission data and information transmission topology model of the entity to be constructed based on the network communication data.
[0031] In this step, the entity to be constructed can be an organization, enterprise, or other entity that needs to build a data security situation awareness platform.
[0032] In this embodiment, network traffic monitoring tools (such as Wireshark or NetFlow) are used to collect traffic data from the internal and external networks of the entity to be constructed. This data should include information such as IP packets, transport layer protocols (such as TCP and UDP), source / destination IP addresses and port numbers, and transmission time. Data analysis tools (such as Python's pandas library or R language) are used to extract features from the raw traffic data, including packet size, transmission rate, connection duration, and transmission protocol type, generating a feature dataset. For example, the features of each connection (number of packets, total data volume, average latency) will be used as the information transmission data for the entity to be constructed. Network topology analysis tools (such as Graphviz or Gephi) are used to perform topology analysis on the extracted feature data, constructing a network model of the information transmission for the entity to be constructed, including nodes (such as servers and terminals) and edges (such as communication paths), generating an information transmission topology model, such as a graph structure file (.dot) or a graph database (such as Neo4j).
[0033] Specifically, this involves: acquiring network communication data of the entity to be developed, extracting enterprise information transmission characteristics from this data, and obtaining information transmission data containing the entity's information transmission information. Traffic capture devices, such as network analyzers or proxy servers, can be deployed within the entity's internal network. These devices will collect network traffic data in real time, including the source IP address, destination IP address, protocol type, packet size, and transmission time of data packets. Then, specific algorithms (e.g., feature extraction algorithms based on traffic pattern analysis) are used to analyze the captured data and extract characteristics related to the entity's information transmission. These characteristics include network bandwidth usage, data transmission frequency, and common communication paths. This provides preliminary information transmission data for the entity, laying the foundation for subsequent analysis.
[0034] When dividing information transmission data into information storage node data and information relay node data, after data extraction, network topology analysis tools are used to process the data and identify each information transmission node in the network. Information transmission nodes include information storage nodes (e.g., servers, databases) and information relay nodes (e.g., routers, switches). By analyzing IP addresses and port numbers in network traffic data, data can be classified into different nodes. For example, nodes with high-volume storage access requests are marked as information storage nodes, while nodes handling a large number of forwarding operations are marked as information relay nodes. This node data is recorded in a database for further analysis.
[0035] Information relay node connection analysis is performed on the data. When obtaining the information transmission node connection data, a detailed connection analysis is conducted on the data of the information relay nodes, and network graph analysis tools are used to construct the connection graph between nodes. By analyzing the data flow and communication paths between information relay nodes, the connection relationships between each node can be determined. Graph theory connection degree calculation methods are applied, such as calculating the degree of each relay node (i.e., the number of directly connected nodes), and key relay nodes are identified, as these nodes play an important role in network data transmission. This connection information is saved as node connection data for subsequent analysis.
[0036] Specifically, based on the information transmission data, node transmission frequency statistics can be performed to obtain high-frequency transmission node data and low-frequency transmission node data; node intersection calculations can be performed on the high-frequency transmission node data and information relay node data to obtain core relay node data; node intersection calculations can be performed on the low-frequency transmission node data and information relay node data to obtain edge relay node data; node connection relationships can be integrated on the core relay node data and edge relay node data based on the information transmission data to obtain core relay node connection data and edge relay node connection data; node connection similarity calculations can be performed on the core relay node connection data and edge relay node connection data to obtain relay node connection similarity data; and node connection network clustering can be performed on the core relay node connection data and edge relay node connection data based on the relay node connection similarity data to obtain information transmission node connection data.
[0037] In obtaining high-frequency and low-frequency transmission node data, the information system of the entity to be constructed first collects transmission data from all nodes. This includes the number and frequency of data packets sent and received by each node. Data sources can include network logs, traffic monitoring systems, and network analysis tools. Data processing scripts written in Python are used to analyze this data and statistically analyze the transmission frequency of each node. Assume node A's transmission frequency is 1000 times / minute, node B's is 500 times / minute, and node C's is 50 times / minute. Based on the statistical results, nodes A and B are marked as high-frequency transmission nodes, and node C is marked as a low-frequency transmission node.
[0038] After acquiring the high-frequency and low-frequency transmission node data, set operations are used to calculate the intersection. Assume the high-frequency transmission node set is {A, B, D} and the low-frequency transmission node set is {C, D, E}. Through intersection calculation, the core relay node set is obtained as {D} and the edge relay node set is {C, E}. This intersection calculation can be implemented using Python set operations: `core_relay_nodes = high_freq_nodes.intersection(mid_relay_nodes)` and `edge_relay_nodes = low_freq_nodes.intersection(mid_relay_nodes)`.
[0039] In the process of obtaining connection data for core relay nodes and edge relay nodes, the connection relationships of core relay nodes (e.g., D) and edge relay nodes (e.g., C, E) are integrated. Assume that in the network, node D is connected to nodes A and B, node C is connected to nodes F and G, and node E is connected to nodes H and I. By constructing a network topology graph, the connection relationships of core relay node D are integrated as {A, B}, the connection relationships of edge relay node C are {F, G}, and the connection relationships of edge relay node E are {H, I}. This integration of nodes and connection relationships can be achieved using graph theory libraries such as NetworkX.
[0040] When calculating similarity, the connection similarity between core relay nodes and edge relay nodes is calculated. Cosine similarity or Jaccard similarity is used as the metric. Assume that the connected nodes of core relay node D are {A, B}, and the connected nodes of edge relay node C are {F, G}. The similarity can be calculated as 0 because the connected nodes have no intersection. If Jaccard similarity is used, the formula is J(A, B) = \frac{|A\cap B|}{|A\cup B|}, and in this case, the result is 0.
[0041] When clustering node connection networks, clustering analysis can be performed on the connection data of core relay nodes and edge relay nodes based on the calculated relay node connection similarity data. The K-means clustering algorithm is used to divide the node connection data into multiple clusters. Assume the node connection data is divided into two classes: one containing highly similar nodes and the other containing low-similar nodes. Clustering is performed using the KMeans class from Python's Scikit-learn library to obtain the final node connection network clusters. The result might be that nodes D, A, and B are grouped into one cluster, and nodes C, F, and G into another cluster.
[0042] The process involves associating data from information storage nodes and information transmission nodes with interconnected nodes to obtain information transmission node connection data. Based on this data, topology analysis is performed to determine the information transmission topology. This involves combining the data from information storage nodes and information relay nodes to establish a complete network topology. Topology analysis tools are used to construct a network graph model based on the node connection data for topology analysis. The analysis includes node connectivity, network path efficiency, and potential bottlenecks. For example, Kruskal's algorithm or Prim's algorithm is used to calculate the minimum spanning tree of the network, thereby identifying the main data flow paths and the connections between nodes. Through these analyses, the overall information transmission topology can be obtained.
[0043] Based on data from information storage nodes and information relay nodes, node security protocols are selected to derive the information transmission topology model. After topology analysis, a suitable security protocol is selected based on the type and function of each node. For example, for information storage nodes, a strong encryption protocol (such as AES encryption) is selected to ensure data storage security; for information relay nodes, a network layer security protocol (such as IPsec) is selected to protect data transmission security. Security protocol selection tools can be used to automatically recommend the most suitable protocol based on node characteristics (such as data sensitivity and communication frequency). Applying the selected security protocols to the network topology forms a security protocol model, which effectively protects the security of the entire information transmission system to be built.
[0044] The process of obtaining the information transmission topology model can be specifically as follows: calculate the access volume of the information storage node data to obtain the access volume data of the storage node, and select the data encryption protocol for the information storage node data based on the access volume data of the storage node to obtain the information storage security protocol.
[0045] In this embodiment, within a large-scale distributed storage system to be constructed, the access volume of each storage node is first monitored, including the number of read and write operations. To accurately calculate the access volume, statistical software can be used to summarize and analyze the operation logs of the storage nodes. Assume that storage node A has 10,000 accesses and storage node B has 5,000 accesses. Based on the access volume data, an appropriate data encryption protocol is selected. For example, for node A with high access volume, the AES-256 encryption protocol can be selected to ensure the security of data transmission, while for node B with low access volume, a lighter encryption protocol such as AES-128 can be selected to reduce resource consumption. These selections are then applied to nodes A and B to protect their data.
[0046] Based on the information transmission data of the entity to be constructed, the relay node performance is evaluated to obtain the relay node performance data.
[0047] In this embodiment, the performance of information relay nodes is evaluated. Assume there are three relay nodes X, Y, and Z. The performance evaluation includes measurements of bandwidth, latency, and throughput. A network performance monitoring tool (such as iperf) is used to test the bandwidth and latency of each relay node. For example, node X has a bandwidth of 1Gbps and a latency of 5ms; node Y has a bandwidth of 500Mbps and a latency of 10ms; and node Z has a bandwidth of 750Mbps and a latency of 8ms. Based on this performance data, an appropriate secure communication protocol is selected. For example, a more complex security protocol (such as TLS 1.3) is chosen for node X with higher bandwidth, while a simpler protocol (such as TLS 1.2) is chosen for node Y with lower bandwidth to balance performance and security.
[0048] Based on the relay node performance data, a secure communication protocol is selected for the information relay node data, thereby obtaining the information relay security protocol;
[0049] In this embodiment, a secure communication protocol is selected based on the relay node's performance data. For example, if node X has good bandwidth and latency, a protocol with strong security (such as IPsec or VPN) can be selected to ensure data confidentiality and integrity. For node Y, a more basic protocol (such as standard HTTPS) is selected to reduce system load and ensure basic communication security. The selection process is based on each node's performance requirements and network security requirements.
[0050] Terminal node features are extracted from the information transmission topology to obtain terminal node data, and communication network layer statistics are performed on the terminal node data to obtain terminal node communication network layer data.
[0051] In this embodiment, within a multi-layered communication network, the characteristics of each terminal node, such as IP address, device type, and connection frequency, are extracted. Statistical analysis of the terminal node's communication data is performed, for example using network traffic analysis tools (such as Wireshark), to obtain the communication data of each terminal node at different network layers (such as the physical layer, data link layer, and network layer). A terminal node with a high-frequency connection is classified as a high-level node, while nodes with a low-frequency connection are classified as low-level nodes. This data is used to optimize network configuration and resource allocation.
[0052] Based on the terminal node connection volume data, the data encryption protocol is selected for the terminal node data to obtain the terminal transmission security protocol;
[0053] In this embodiment, an appropriate data encryption protocol is selected based on the connection volume of the terminal nodes. For example, if terminal node C has a very high connection volume, a more complex encryption protocol (such as TLS 1.3) will be selected to ensure the security of data transmission. For terminal node D with a lower connection volume, a lighter encryption protocol (such as TLS 1.2) will be selected to balance security and performance requirements. The finally selected encryption protocol will be applied to the data transmission process of these terminal nodes to ensure the confidentiality and integrity of the data.
[0054] A network public key encryption architecture is constructed based on information storage security protocols, information relay security protocols, and terminal transmission security protocols, thereby obtaining an information transmission public key encryption architecture. Node architecture mapping is then performed on the information transmission public key encryption architecture and the information transmission topology to obtain an information transmission topology model.
[0055] In this embodiment, the network public-key encryption architecture integrates information storage security protocols, information relay security protocols, and terminal transmission security protocols. For example, the RSA 2048-bit public-key encryption algorithm is selected as the public-key encryption standard for the entire network. These protocols are applied to each node in the network topology, and the node architecture is mapped according to the connection relationships between nodes in the topology (such as star, ring, or mesh structures). Assuming the network topology is a star structure, the central node uses RSA 2048-bit encryption, and the surrounding nodes use the public key provided by the central node for encryption. Finally, a complete public-key encryption architecture model is generated to ensure the security and confidentiality of data transmission throughout the network.
[0056] Step 102: Perform anomaly analysis on the information transmission data to obtain abnormal information transmission data, and perform abnormal network communication correction on the abnormal information transmission data based on network communication data to obtain insecure information transmission data.
[0057] In this embodiment, anomaly detection algorithms (such as Isolation Forest or statistical methods) are applied to analyze abnormal patterns in the information transmission data of the entity to be constructed, such as abnormal traffic, frequent connections, and abnormal packet sizes, generating abnormal information transmission data and marking abnormal transmission events. Based on known normal traffic patterns and anomaly detection results, the data is corrected to eliminate false alarms. For example, by comparing with historical data, normal high-traffic events are excluded, insecure information transmission data is generated, and those traffic events that still exhibit abnormalities after correction are marked. This step may specifically include:
[0058] The transmission frequency features and data packet transmission features of the information transmission data of the entity to be constructed are extracted to obtain the information transmission frequency data and data packet transmission data of the entity to be constructed.
[0059] In this embodiment, when analyzing the network information transmission data of the entity to be constructed, the transmission frequency feature is first extracted. It is assumed that 1000 data packets are transmitted per second in the network of the entity to be constructed. Using a time window method, the data stream is divided into multiple time windows, each with a length of 1 minute. The number of data packets within each window is counted to calculate the data packet transmission frequency. Furthermore, the data packet transmission time intervals within each time window are statistically analyzed, and the mean and standard deviation of the time intervals are extracted as data packet transmission features. Finally, these frequency and time interval features will be used as input data for subsequent analysis and processing.
[0060] The frequency domain is converted based on the information transmission frequency data of the entity to be constructed, thereby obtaining the information transmission spectrum of the entity to be constructed. Periodic information transmission statistics are then performed on the information transmission spectrum of the entity to be constructed, thereby obtaining information transmission periodic data.
[0061] In this embodiment, after obtaining the information transmission frequency data of the entity to be constructed, the time-domain data is converted into frequency-domain data using a Fast Fourier Transform (FFT). This helps identify periodic patterns in information transmission. For example, assuming the frequency-domain converted data exhibits obvious periodic peaks, it indicates that a periodic pattern exists in the information transmission. Periodic statistics are performed on the spectrum data to calculate the main periodic components in the spectrum. For example, if there is a periodic peak every 5 minutes in the spectrum, the information transmission period is 5 minutes. Periodic statistics may include calculating the period length, peak intensity, etc., thereby obtaining periodic information transmission data.
[0062] The packet loss rate is calculated based on the data packet transmission data to obtain the packet loss rate data. High packet loss rate transmission data is then clustered based on the packet loss rate data to obtain high packet loss rate information transmission data.
[0063] In this embodiment, when calculating the packet loss rate of transmitted data packets, the number of packet losses within a specific time window is first counted. For example, if 1000 data packets are expected to be received within a 10-minute time window, but only 900 data packets are actually received, the packet loss rate is 10%. After calculating the packet loss rate for each time window, high packet loss rate transmissions are clustered based on these packet loss rate data. For example, the K-means clustering algorithm can be used to classify data with a packet loss rate higher than 15% as high packet loss rate transmission data. This data will be used to identify time periods where network problems may exist, thereby obtaining high packet loss rate information transmission data.
[0064] Based on the information transmission cycle data, non-periodic transmission clustering is performed on the information transmission data of the entity to be constructed to obtain non-periodic information transmission data.
[0065] In this embodiment, based on the obtained information transmission cycle data, aperiodic transmission clustering is performed on the information transmission data of the entity to be constructed. First, a time model is created based on the periodic statistical results, for example, setting 5 minutes as a periodic time period. If the actual transmitted data does not show a clear periodic pattern within this periodic time period, then this data is classified as aperiodic data. For example, the DBSCAN clustering algorithm is used to perform cluster analysis on data outside the periodic pattern, and transmission data that does not conform to the periodic model is marked as aperiodic information transmission data.
[0066] Perform information transmission intersection operation on high packet loss rate information transmission data and non-periodic information transmission data to obtain abnormal information transmission data;
[0067] In this embodiment, the obtained high packet loss rate information transmission data and the obtained aperiodic information transmission data are subjected to an intersection operation. For example, using set operations, the intersection of these two types of data is identified as abnormal information transmission data. If there are intersection data points in the high packet loss rate and aperiodic data, these data are considered abnormal information transmissions. This method can effectively filter out abnormal data that appears under high packet loss rate and aperiodic patterns.
[0068] Based on the network communication data of the entity to be constructed, abnormal network communication correction is performed on the abnormal information transmission data to obtain insecure information transmission data.
[0069] In this embodiment, abnormal network communication correction is performed on the identified abnormal information transmission data. First, the network communication pattern of the abnormal data is analyzed; for example, abnormal data may manifest as an abnormally high packet loss rate or abnormal transmission delay. Then, a correction algorithm (e.g., an adaptive filter or machine learning algorithm) is used to adjust the network configuration or optimize the data transmission path. If the abnormal data is found to be related to a high packet loss rate of a certain network node, network performance optimization can be performed on that node to reduce the packet loss rate, thereby obtaining the insecure information transmission data for subsequent processing.
[0070] Based on the network communication data of the entity to be constructed, communication delay features are extracted to obtain the network communication delay data of the entity to be constructed.
[0071] In this embodiment, the network communication latency feature extraction step for the entity to be constructed includes collecting communication data between internal nodes of the entity, for example, using network monitoring tools such as Wireshark or NetFlow to collect the transmission time of data packets. The timestamps of these data packets are analyzed to calculate the latency between each pair of nodes. Latency feature extraction includes calculating the RTT (Round-Trip Time) from the transmission and reception times of each data packet, and then statistically analyzing characteristic indicators such as average latency, maximum latency, minimum latency, and standard deviation of latency over different time periods. These indicators help to understand the network performance at different time periods and serve as the data basis for subsequent steps.
[0072] A sliding window method is used to statistically analyze the network communication delay data of the entity to be constructed, thereby obtaining the network congestion time data of the entity to be constructed.
[0073] In this embodiment, a sliding window method is used to analyze the extracted communication latency data. Assuming a window size of 5 minutes, the data is divided into multiple windows based on time periods, and network congestion performance is statistically analyzed within each window. The latency distribution within each window can be calculated, such as the maximum latency, the average latency, and the number of delays exceeding a threshold. These statistics can indicate whether network congestion exists within that time window. For example, if the latency within a window exceeds a set threshold (e.g., 200ms), that time period is marked as a network congestion period.
[0074] The network congestion time data and abnormal information transmission data of the construction entity are correlated in time series to obtain network congestion transmission data;
[0075] In this embodiment, time-series correlation is performed between network congestion time data and abnormal transmission data. First, criteria for abnormal transmission data are defined, such as a packet loss rate exceeding 5% or an error rate exceeding a certain threshold during transmission. Next, the network congestion time data and abnormal transmission data are aligned by timestamps. Time-series analysis techniques, such as cross-correlation analysis or dynamic time warping (DTW), are applied to evaluate the relationship between network congestion and abnormal transmission events. If it is found that frequent congestion within certain time periods is accompanied by a significant increase in abnormal transmission events, this indicates that network congestion is one of the factors contributing to abnormal transmission.
[0076] By correcting abnormal network communication in abnormal information transmission data based on network congestion transmission data, insecure information transmission data can be obtained.
[0077] In this embodiment, abnormal information transmissions are corrected based on the network congestion transmission data obtained in the preceding steps. For example, a model is built using a machine learning algorithm (such as random forest or support vector machine), which is trained with network congestion data as input features and abnormal information transmission data as labels. Then, the trained model is used to correct newly received abnormal information transmission data. The correction process includes identifying anomalies caused by network congestion and adjusting these abnormal data. For example, if the model detects transmission errors due to network congestion, these errors can be retransmitted or the data can be corrected to obtain more accurate insecure information transmission data.
[0078] By extracting transmission frequency and packet transmission characteristics, the entity undertaking network construction can gain a deeper understanding of its network communication behavior patterns. For example, it can determine common data transmission time intervals and basic packet characteristics, which are crucial for subsequent analysis. This provides foundational data support for subsequent data analysis and anomaly detection steps, making the analysis process more accurate and effective. Frequency domain transformation can reveal periodic patterns in information transmission data. This helps identify normal periodic communication behaviors, such as regular data backups or service updates. By understanding the information transmission cycle, the entity undertaking network construction can optimize its network resource allocation and scheduling strategies, reducing latency and improving efficiency. Calculating packet loss rates and clustering them can help identify high-packet-loss problem areas in the network, which are often indicators of network performance issues or potential faults. By identifying and clustering high-packet-loss data transmissions, the entity undertaking network construction can perform targeted network optimization and troubleshooting, thereby improving overall network performance and stability. Analyzing information transmission cycle data can identify non-periodic data transmission behaviors, which indicate abnormal or unplanned activity in the network. Identifying non-periodic transmissions helps discover potential security threats, such as unauthorized access or data breaches, and thus allows for the implementation of appropriate security measures. By combining intersection operations with high packet loss rate and aperiodic information transmission data, abnormal information transmissions can be identified more accurately. These anomalies typically indicate network security issues or system failures. Using multiple anomaly indicators in combination helps reduce false positives and false negatives, improving the accuracy and reliability of anomaly detection. Correcting abnormal information transmission data can rectify detected network communication anomalies, thereby accurately identifying genuine security threats. The resulting insecure information transmission data can help the entity undertaking the project take measures to strengthen network security protection, such as updating firewall rules or adjusting network monitoring strategies, thereby effectively reducing security risks.
[0079] By extracting communication delay features, we can gain a deeper understanding of the specific causes of network latency. This helps identify bottlenecks or instability factors in the network. After analyzing latency features, network configuration can be optimized to improve network performance and increase data transmission efficiency. The extracted latency features can help predict potential network problems and take early measures to prevent network latency issues from occurring. The sliding window statistical method allows for dynamic monitoring of network congestion time, reflecting changes in network congestion trends in a timely manner. By statistically analyzing network congestion time, we can more accurately assess the actual network usage and understand network load and its fluctuations. Through congestion time data, we can optimize the allocation of network resources, adjust network configuration, and reduce the impact of congestion on network performance. Time series correlation can reveal the relationship between network congestion and abnormal information transmission, helping to identify the specific network conditions causing anomalies. By correlating congestion time with abnormal information transmission data, we can more effectively detect and diagnose abnormal events, improving the efficiency of network fault diagnosis. The correlation analysis results provide network administrators with data-driven decision-making support, helping to develop more effective network management strategies. By correcting abnormal information transmission data, transmission errors caused by network congestion can be corrected, ensuring the correctness and integrity of data transmission. Correcting abnormal network communications helps eliminate potential security risks and ensures the security of transmitted data. By correcting abnormal data, the overall reliability and stability of the network are improved, reducing service interruptions caused by network problems.
[0080] Step 103: Construct an abnormal information transmission detection model based on the insecure information transmission data, and use the abnormal information transmission detection model to detect abnormal information transmission data to obtain real-time abnormal information transmission data.
[0081] In this embodiment, an abnormal information transmission detection model is constructed by training a machine learning model (such as a support vector machine (SVM), neural network, or ensemble method) using insecure information transmission data. The trained model is then used to detect anomalies in the real-time transmission data of the entity to be constructed. If the real-time transmission data is detected as abnormal, it is marked as real-time abnormal information transmission data. If the real-time transmission data is not detected as abnormal, it is uploaded to the information transmission management system of the entity to be constructed, and the information transmission task continues.
[0082] Step 104: Divide the information transmission topology model into abnormal information transmission nodes based on the real-time abnormal information transmission data to obtain abnormal information transmission node data, and integrate the abnormal node links based on the abnormal information transmission node data to obtain abnormal node link data.
[0083] In this step, based on real-time abnormal information transmission data, the information transmission topology model is analyzed to identify abnormal nodes (such as servers or network devices) and classify them (e.g., high risk, medium risk, low risk), generating abnormal information transmission node data. The abnormal node data is then combined with the topology model to identify the connection links between abnormal nodes (such as the paths of abnormal data flows), generating abnormal node link data and indicating abnormal transmission paths and potential attack paths.
[0084] This step may specifically include: extracting the characteristics of the transmission terminal nodes from the real-time abnormal information transmission data, thereby obtaining abnormal transmission terminal node data;
[0085] In this embodiment, terminal node features are extracted from real-time abnormal information transmission data. It is assumed that abnormal information in the network of the entity to be constructed includes high latency, packet loss, or erroneous data. Network monitoring tools (such as SolarWinds) can be used to capture data packets in real time and extract the IP address, port number, and performance metrics (such as packet loss rate) of each terminal node from them. This feature data forms abnormal transmission terminal node data, recording all affected terminal nodes and their performance. For example, if a terminal's packet loss rate reaches 10% in the past hour, then the terminal's IP address and port number will be marked as abnormal.
[0086] The information transmission topology model is divided into terminal connection nodes based on the abnormal transmission terminal node data, thereby obtaining the abnormal terminal connection node data.
[0087] In this embodiment, terminal connection nodes in the information transmission topology are divided based on abnormal transmission terminal node data. Using a network topology mapping tool (such as Cisco Network Assistant), abnormal terminal nodes are associated with other directly connected nodes to form a connection node list. The system analyzes the connection relationships of abnormal terminals to identify affected switches, routers, and other network devices. For example, if an abnormal terminal is directly connected to a specific switch, that switch will also be marked as an abnormal terminal connection node.
[0088] Extract the public key features of the information transmission encryption from the abnormal transmission terminal node data to obtain the abnormal terminal transmission encryption public key data;
[0089] In this embodiment, the public key features of abnormal transmission terminal nodes are extracted. By analyzing the encrypted information of the transmitted data, the public key features used by each terminal are extracted. The transmitted data is decrypted using an encryption analysis tool (such as Cryptool in Kali Linux), and the public key information of each terminal is extracted. Abnormal terminal transmission encryption public key data is generated, recording the public key used by each abnormal terminal and its associated encryption algorithm. For example, if an abnormal terminal uses the RSA-2048 encryption algorithm, its public key will be extracted and recorded.
[0090] Based on the public key encryption architecture for information transmission, the encrypted public key data transmitted by abnormal terminals is divided into encrypted public key associated nodes, thereby obtaining the key associated node data of abnormal terminals;
[0091] In this embodiment, based on the extracted encryption public key information, abnormal terminals are categorized into encryption public key associated nodes. The system uses Public Key Infrastructure (PKI) tools to map the relationship between public keys and nodes. Terminals using the same public key are grouped together, forming abnormal terminal key associated node data. For example, if multiple abnormal terminals use the same public key for data encryption, these terminals will be classified into the same key associated node group.
[0092] Perform node intersection operation on the abnormal terminal connection node data and the abnormal terminal key associated node data to obtain the abnormal information transmission node data;
[0093] In this embodiment, a node intersection operation is performed on the abnormal terminal connection node data and the abnormal terminal key association node data. The intersection of the two datasets is calculated using set operation tools (such as Python's `set` library). The intersection operation will identify nodes that exist in both datasets simultaneously, i.e., those terminals that are both connection nodes and key association nodes. For example, if a node exists in both the abnormal connection node data and the abnormal key association node data, it will be marked as an abnormal information transmission node.
[0094] By integrating the abnormal transmission terminal node data and the abnormal information transmission node data, the abnormal node link data can be obtained.
[0095] In this embodiment, abnormal transmission terminal node data and abnormal information transmission node data are integrated into node links. A network link analysis tool (such as Grapher) is used to integrate all abnormal terminal nodes and their associated links, forming abnormal node link data. A network graph containing all abnormal terminal nodes and their connected links can be drawn to help identify abnormal propagation paths. For example, if an abnormal terminal node is connected to other nodes through multiple links, these links will be integrated into a link set for further analysis of abnormal propagation patterns.
[0096] Extracting terminal node features clarifies the source and target nodes of abnormal information transmission, providing accurate data for subsequent analysis. Real-time feature extraction enables rapid response and handling of network anomalies, minimizing impact on business operations. Detailed terminal node data helps pinpoint specific anomalies in the network, improving troubleshooting efficiency. Topology segmentation provides a better understanding of the connection methods of abnormal terminals, allowing for network layout optimization. Identifying the connection nodes of abnormal terminals helps identify potential security vulnerabilities and strengthens network protection. Segmenting terminal connection nodes helps accurately identify the propagation path of anomalies and quickly locate the problem. Extracting public key features helps identify abnormal encryption behavior, protecting the security of data transmission. It can detect problems with the public keys used by abnormal terminals, allowing for early protective measures. Providing public key data facilitates security auditing, ensuring data transmission in the network complies with security standards. Associating nodes allows for more effective management and allocation of encryption keys, enhancing network security. Identifying key association nodes helps in-depth analysis of the relationship between abnormal terminals and other nodes, identifying potential security risks. Strengthening monitoring of abnormal terminal keys enhances network protection capabilities and data security. By performing node intersection operations and comprehensively considering anomalies in terminal connections and key associations, it is helpful to fully identify and understand the transmission paths of abnormal information. This provides more accurate anomaly node data, offering network administrators a complete picture of the anomaly situation and improving data analysis and decision-making. Ensuring the accuracy of anomaly node data helps in timely response to and handling of security incidents, minimizing impact. Integrating node link data provides a complete link view of abnormal transmissions, helping to analyze the propagation path and scope of impact. A comprehensive understanding of abnormal links enables timely network repair and optimization, reducing the impact of link anomalies on services.
[0097] Step 105: Analyze the blocking strategy for abnormal transmission nodes based on the abnormal node link data and information transmission data, obtain the blocking strategy for abnormal transmission nodes, and construct a secure information transmission link structure model based on the blocking strategy for abnormal transmission nodes and the information transmission topology model.
[0098] In this embodiment, the link data of abnormal nodes and the information transmission data of the entity to be constructed are analyzed to formulate blocking strategies (such as disconnecting the connection of abnormal nodes and adding access control). Policy analysis tools (such as Palo Alto Networks' Threat Intelligence or Cisco's AMP) can be used to evaluate the effectiveness of different blocking strategies and generate blocking strategies for abnormal transmission nodes. Based on the blocking strategies, the information transmission topology model is adjusted to optimize the network security link, such as reconfiguring network paths and adding firewall rules, generating a secure information transmission link structure model, including updated network topology and security policies.
[0099] This step specifically includes: integrating abnormal patterns based on abnormal node link data to obtain abnormal transmission pattern data. In this embodiment, data analysis of abnormal node links reveals frequent data transmission anomalies in these links. These abnormal links are then integrated to identify common abnormal transmission patterns, such as specific bandwidth fluctuations, increased latency, or packet loss patterns, thereby obtaining abnormal transmission pattern data. For example, if multiple nodes are found to experience packet loss within a specific time period, these patterns are integrated to form a common abnormal pattern.
[0100] An impact assessment of abnormal transmission patterns is conducted based on the information transmission data of the entity to be constructed, thereby obtaining an impact assessment data. In this embodiment, the impact of discovered abnormal transmission patterns on the information transmission of the entity to be constructed is analyzed. For example, by simulating the actual impact of abnormal patterns, the impact of these anomalies on the data transmission speed and reliability of the critical applications of the entity to be constructed can be determined. The integrated abnormal transmission patterns can be combined with the information transmission data of the entity to be constructed, and regression analysis can be used to assess the impact of each pattern on the overall network performance. For example, the impact of high latency patterns on the response time of business systems can be analyzed to obtain impact assessment data for that pattern, such as the risk probability of response time delay exceeding 10%. Assume that the connection interruption between nodes C and D in the network of the entity to be constructed severely affects the online transaction system. The assessment process includes analyzing the degree of impact of abnormal patterns on business processes, such as the latency and data loss caused by the connection interruption between nodes C and D. By modeling and simulating the latency and data loss caused by different abnormal patterns, a comprehensive assessment is conducted to generate an abnormal pattern impact assessment data, showing which abnormal patterns have the most significant impact on the entity to be constructed, and providing detailed assessment results.
[0101] Anomaly node priority data is obtained by prioritizing anomaly node link data based on anomaly pattern impact assessment data. In this embodiment, priorities are assigned to anomaly node links based on the anomaly pattern impact assessment data. For example, anomalous patterns with a significant impact may lead to higher priorities for certain node links, so that these high-priority anomaly nodes are processed first in subsequent steps to minimize the impact on the business of the entity being built. A weighted sorting algorithm can be used to determine priorities by combining the degree of impact and the frequency of occurrence. For example, nodes that occur frequently and have a significant impact are assigned high priority for priority processing. Suppose that the anomaly patterns of nodes E and F have the greatest impact on the core business system, then these nodes need to be processed first. A priority algorithm (e.g., a weighted scoring system based on impact assessment results) is used to assign a priority to each anomaly node. For example, the priorities of nodes E and F are set to the highest, and the priorities of other nodes are assigned in turn, so that these key nodes are given priority in resource allocation and strategy formulation.
[0102] To obtain transmission node resource allocation data, the information transmission data of the entity to be constructed is analyzed by extracting transmission node resource allocation features. In this embodiment, features such as bandwidth utilization and node load are extracted from the information transmission data of the entity to be constructed. Feature selection techniques (such as Principal Component Analysis, PCA) are used to extract the most representative features, thereby obtaining resource allocation data and ensuring the effective utilization of transmission nodes under limited resources. Assume that node G's CPU utilization frequently reaches 90%, while node H's network bandwidth utilization is close to 100%. Through monitoring tools and data analysis techniques, the resource usage of each transmission node is extracted, and this data is compiled into transmission node resource allocation data. For example, node G may require more computing resources, while node H may require bandwidth expansion to maintain network performance during abnormal modes.
[0103] Node blocking strategies are analyzed based on transmission node resource allocation data and abnormal node priority data to obtain abnormal transmission node blocking strategies. In this embodiment, resource allocation data and node priority data are used to analyze node blocking strategies. For example, if some nodes frequently experience abnormalities due to high load, a strategy can be formulated to prioritize blocking the traffic of these high-priority nodes when resources are scarce, thereby reducing the overall network load. Assume that node I needs to be temporarily blocked due to resource scarcity to prevent it from affecting the overall network performance. By analyzing the resource status and priority of different nodes, corresponding blocking strategies are formulated. For example, for the highest priority nodes E and F, if anomalies occur, automatic traffic redirection or resource limiting strategies can be adopted, while for lower priority nodes, more lenient measures such as reducing network load can be adopted.
[0104] A secure information transmission link structure model is constructed based on the abnormal transmission node blocking strategy and the information transmission topology model. In this embodiment, a secure information transmission link structure model is constructed based on the established node blocking strategy and the information transmission topology model of the entity to be constructed. It is assumed that the connection path between nodes J and K is marked as a high-risk area in the original network topology. Through simulation and modeling techniques, a new topology model is constructed, taking into account the improved paths after the abnormal node blocking strategy. For example, the high-risk path between nodes J and K is replaced with a backup path to ensure the security and reliability of data transmission. Finally, the generated secure information transmission link structure model will demonstrate the improved network structure, ensuring the stability and security of information transmission.
[0105] Specifically, the process of obtaining the priority data of abnormal nodes can include:
[0106] The impact features of anomalous pattern nodes are extracted from the anomalous pattern impact assessment data to obtain anomalous pattern node impact data. In this embodiment, an impact feature for each anomalous pattern is extracted from the anomalous pattern impact assessment data using algorithms such as feature selection. These features can be indicators such as the severity of the node's impact or the frequency of anomalies. Each node is then scored based on the weights of different features. The weights can be determined based on the importance of the features or expert knowledge. Features of different dimensions are standardized to allow comparison on the same scale. For example, the node's impact score is normalized to between 0 and 1. A comprehensive impact score is calculated by combining multiple features. A weighted average method or a comprehensive model can be used to derive the final score. Ultimately, the generated anomalous pattern node impact data provides a crucial information foundation for subsequent steps.
[0107] The impact priority of abnormal nodes is evaluated based on the impact data of abnormal node links to obtain abnormal node impact priority data. In this embodiment, the priority of each abnormal node in the network is calculated using the obtained abnormal node impact data. Assume that in a network with multiple nodes, both nodes B and C exhibit abnormal patterns. The priority of each node is evaluated based on its impact characteristic data, which includes a comprehensive assessment of the node's impact, the severity of the abnormal pattern, and the node's importance to quantify the node's priority. For example, the impact of node B's abnormal pattern on network performance is 0.8, while that of node C is 0.6. Therefore, node B's abnormal node priority is higher than that of node C.
[0108] The connection priority of abnormal nodes is evaluated by using an information transmission topology model to obtain connection priority data. In this embodiment, to further analyze the impact of abnormal nodes, the connection priority of abnormal nodes is calculated using an information transmission topology model. For example, assume that node B is connected to nodes D and E in the network topology. Based on the connection quality and abnormal mode impact data in the topology model, the connection priority of node B is calculated. Assuming that the connection stability between node B and node D is poor and the impact of node D is also high, the connection priority between node B and node D will be higher.
[0109] The abnormal node priority data is obtained by performing a weighted average of the abnormal node impact priority data and the abnormal node connection priority data. In this embodiment, a weighted average is performed on the obtained abnormal node impact priority data and abnormal node connection priority data. This involves setting different weight coefficients and then weighting these two types of priority data according to the weight coefficients to obtain the final abnormal node priority data. The purpose is to comprehensively consider the impact degree and connection priority of nodes in order to more accurately assess the overall priority of each abnormal node. Assume that in a network monitoring system, there are multiple abnormal patterns such as traffic surges or node failures. First, the impact characteristics (such as impact degree and frequency) of each pattern on different nodes are extracted. Then, the impact priority of these abnormal patterns on links is evaluated. The connection priority of nodes is calculated using a graph model. Finally, the two types of priority data are weighted and averaged to generate the final priority of each node for subsequent processing and decision-making.
[0110] By integrating abnormal node link data, it is possible to comprehensively identify abnormal patterns in the network. This helps to understand the scope and nature of the anomalies. The integrated data provides a clearer picture of abnormal transmission patterns, helping to accurately locate problems in the network and reduce the possibility of false alarms and missed alarms. The obtained abnormal transmission pattern data will serve as the basis for subsequent analysis and decision-making, improving the overall system's anomaly handling capabilities. By assessing the impact of abnormal patterns, it is possible to understand the specific impact of abnormal transmission patterns on the information transmission of the entity being built, thus providing a basis for formulating corresponding countermeasures. Assessment data can help the entity being built determine which transmission patterns have the greatest impact on the system, thereby optimizing resource allocation and prioritizing the resolution of critical issues. By assessing the impact of abnormal patterns, the entity being built can take measures to reduce the negative impact on system stability and improve the overall system reliability and performance. By assigning priorities to abnormal nodes, it is possible to clarify which nodes and links need to be addressed first, ensuring the rapid repair or maintenance of critical nodes. Priority data helps network administrators respond quickly to problems with high-impact nodes, improving problem-solving efficiency and reducing system downtime. Through priority allocation, more precise maintenance strategies can be formulated, reducing interference with normal operations and ensuring the normal operation of the system. Extracting resource allocation characteristics from transmission nodes helps understand the resource usage of each node, thereby optimizing resource allocation and improving transmission efficiency. Resource allocation data provides administrators with detailed information on resource usage, aiding in more rational resource allocation decisions. Reasonable resource allocation can improve overall system performance, reduce transmission bottlenecks, and enhance the stability and speed of information transmission. By analyzing transmission node resource allocation and abnormal node priorities, more effective node blocking strategies can be developed, thereby improving the effectiveness of anomaly handling. Node blocking strategies help isolate and handle abnormal nodes, prevent the spread of anomalies, and protect the overall security of the network. Appropriate blocking strategies can reduce the interference of anomalies on normal services, ensuring the normal operation of the system. The constructed secure information transmission link structure model provides a reliable framework for ensuring the security of information transmission. By combining blocking strategies and topology, network link design can be optimized, improving transmission stability and security. This model helps improve the system's ability to respond to anomalies, enhances system resilience and robustness, and reduces potential security threats.
[0111] By extracting the impact characteristics of anomalous nodes, we can gain a deeper understanding of their influence scope and nature, thus more accurately identifying critical nodes. Calculating the impact priority of anomalous nodes helps focus attention on the nodes with the most severe impact on the system, thereby optimizing resource allocation and response measures. Prioritizing anomalous nodes using an information transmission topology model helps identify nodes with critical connections, enhancing the efficiency of network outage recovery. By using a weighted average of anomalous node priority data, we can comprehensively consider the impact and connectivity of nodes, providing a comprehensive priority ranking and optimizing anomaly handling decisions.
[0112] Step 106: Construct a security situation awareness platform based on the secure information transmission link structure model and the abnormal information transmission detection model to obtain the information transmission security situation awareness platform for the entity to be constructed.
[0113] In this embodiment, a secure information transmission link structure model and an anomaly information transmission detection model are integrated to construct a security situation awareness platform for the entity to be built. Integration can be achieved using platforms such as Splunk or ELK Stack, enabling real-time monitoring, alarms, and data visualization to display network security status and anomaly detection results. The data and reports from the security situation awareness platform are uploaded to the entity's information transmission management system, ensuring that the security team can promptly obtain the latest security information, configure automated alarm and reporting systems, execute security situation awareness tasks, and respond to potential threats.
[0114] Example 2
[0115] Figure 2 This is a schematic diagram of the structure of an apparatus for constructing a data security situation awareness platform, provided in Embodiment 2 of this application. Figure 2 As shown, the device for constructing a data security situation awareness platform specifically includes: an information transmission topology module 201, an abnormal information transmission analysis module 202, an abnormal information transmission detection model construction module 203, an abnormal node link integration module 204, a blocking strategy analysis module 205, and a security situation awareness platform construction module 206.
[0116] Among them, the information transmission topology module is used to acquire the network communication data of the entity to be constructed, and to determine the information transmission data and information transmission topology model of the entity to be constructed based on the network communication data.
[0117] The abnormal information transmission analysis module is used to perform abnormal analysis on the information transmission data, obtain abnormal information transmission data, and perform abnormal network communication correction on the abnormal information transmission data based on network communication data to obtain insecure information transmission data.
[0118] The abnormal information transmission detection model construction module is used to construct an abnormal information transmission detection model based on insecure information transmission data, and to perform abnormal information transmission detection on the information transmission data through the abnormal information transmission detection model to obtain real-time abnormal information transmission data.
[0119] The abnormal node link integration module is used to divide the information transmission topology model into abnormal information transmission nodes based on real-time abnormal information transmission data, obtain abnormal information transmission node data, and integrate abnormal node links based on the abnormal information transmission node data to obtain abnormal node link data.
[0120] The blocking strategy analysis module is used to analyze the blocking strategy of abnormal transmission nodes based on the abnormal node link data and information transmission data, obtain the blocking strategy of abnormal transmission nodes, and construct a secure information transmission link structure model based on the abnormal transmission node blocking strategy and the information transmission topology model.
[0121] The security situation awareness platform construction module is used to construct a security situation awareness platform based on a security information transmission link structure model and an abnormal information transmission detection model, thereby obtaining the information transmission security situation awareness platform for the entity to be constructed.
[0122] Example 3
[0123] Figure 3 This is a schematic diagram of the structure of an electronic device provided in Embodiment 3 of this application, as shown below. Figure 3 As shown, the electronic device includes a processor 310, a memory 320, an input device 330, and an output device 340; the number of processors 310 in the electronic device can be one or more. Figure 3 Taking a processor 310 as an example; the processor 310, memory 320, input device 330, and output device 340 in the electronic device can be connected via a bus or other means. Figure 3 Taking the example of a connection between China and Israel via a bus.
[0124] The memory 320, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the method for constructing a data security situation awareness platform in this embodiment of the invention. The processor 310 executes various functional applications and data processing of the electronic device by running the software programs, instructions, and modules stored in the memory 320, thereby realizing the aforementioned method for constructing a data security situation awareness platform. The memory 320 may mainly include a program storage area and a data storage area.
Claims
1. A method for constructing a data security situation awareness platform, characterized in that, The method includes: Obtain the network communication data of the entity to be constructed, and determine the information transmission data and information transmission topology model of the entity to be constructed based on the network communication data; Anomaly analysis is performed on the information transmission data to obtain abnormal information transmission data, and abnormal network communication correction is performed on the abnormal information transmission data based on the network communication data to obtain insecure information transmission data. An abnormal information transmission detection model is constructed based on the non-secure information transmission data, and the abnormal information transmission detection model is used to detect abnormal information transmission in the information transmission data to obtain real-time abnormal information transmission data. Based on the real-time abnormal information transmission data, the information transmission topology model is divided into abnormal information transmission nodes to obtain abnormal information transmission node data, and abnormal node links are integrated based on the abnormal information transmission node data to obtain abnormal node link data. Based on the abnormal node link data and the information transmission data, an abnormal transmission node blocking strategy is analyzed to obtain the abnormal transmission node blocking strategy. Based on the abnormal transmission node blocking strategy and the information transmission topology model, a secure information transmission link structure model is constructed. Based on the secure information transmission link structure model and the abnormal information transmission detection model, a security situation awareness platform is constructed to obtain the information transmission security situation awareness platform for the entity to be constructed.
2. The method according to claim 1, characterized in that, The step of acquiring the network communication data of the entity to be constructed, and determining the information transmission data and information transmission topology model of the entity to be constructed based on the network communication data, includes: Obtain the network communication data of the entity to be constructed, and extract enterprise information transmission features from the network communication data to obtain the information transmission data of the entity to be constructed; The information transmission data is divided into information transmission nodes to obtain information storage node data and information relay node data; The information relay node data is analyzed to obtain information transmission node connection data. The information storage node data and the information transmission node connection data are associated with nodes to obtain information transmission node connection data. Based on the information transmission node connection data, a topology analysis is performed to obtain the information transmission topology. Based on the information storage node data and the information relay node data, node security protocols are selected for the information transmission topology to obtain an information transmission topology model.
3. The method according to claim 2, characterized in that, The step of performing information transmission node connection analysis on the information relay node data to obtain information transmission node connection data includes: Based on the information transmission data, the node transmission frequency is statistically analyzed to obtain high-frequency transmission node data and low-frequency transmission node data. The intersection of high-frequency transmission node data and information relay node data is calculated to obtain core relay node data; the intersection of low-frequency transmission node data and information relay node data is calculated to obtain edge relay node data. Based on the information transmission data, the node connection relationships of the core relay node data and the edge relay node data are integrated to obtain the core relay node connection data and the edge relay node connection data. Node connection similarity is calculated on the core relay node connection data and the edge relay node connection data to obtain relay node connection similarity data; Based on the relay node connection similarity data, the core relay node connection data and the edge relay node connection data are clustered into node connection network clusters to obtain information transmission node connection data.
4. The method according to claim 1, characterized in that, The step of performing anomaly analysis on the information transmission data to obtain abnormal information transmission data includes: The information transmission data is subjected to transmission frequency feature extraction and data packet transmission feature extraction to obtain information transmission frequency data and data packet transmission data; The information transmission frequency data is converted into a frequency domain to obtain the information transmission spectrum, and the information transmission spectrum is statistically analyzed periodically to obtain information transmission period data. The packet loss rate is calculated based on the data packet transmission data to obtain data packet transmission packet loss rate data. High packet loss rate transmission clustering is then performed on the data packet transmission packet loss rate data to obtain high packet loss rate information transmission data. Based on the information transmission cycle data, the information transmission data is clustered for aperiodic transmission to obtain aperiodic information transmission data. An abnormal information transmission data is obtained by performing an information transmission intersection operation on the high packet loss rate information transmission data and the aperiodic information transmission data.
5. The method according to claim 1, characterized in that, The step of correcting abnormal network communication in the abnormal information transmission data based on the network communication data to obtain insecure information transmission data includes: Based on the network communication data, communication delay features are extracted to obtain network communication delay data; The network communication delay data is statistically analyzed using a sliding window method to obtain network congestion time data. By performing time-series correlation on the network congestion time data and the abnormal information transmission data, network congestion transmission data is obtained; Based on the network congestion transmission data, abnormal network communication correction is performed on the abnormal information transmission data to obtain insecure information transmission data.
6. The method according to claim 1, characterized in that, The step of dividing the information transmission topology model into abnormal information transmission nodes based on the real-time abnormal information transmission data to obtain abnormal information transmission node data, and then integrating the abnormal node links based on the abnormal information transmission node data to obtain abnormal node link data, includes: The characteristics of the transmission terminal nodes are extracted from the real-time abnormal information transmission data to obtain abnormal transmission terminal node data. Based on the abnormal transmission terminal node data, the information transmission topology model is divided into terminal connection nodes to obtain the normal terminal connection node data. Extract the public key features of the information transmission encryption public key from the abnormal transmission terminal node data to obtain the abnormal terminal transmission encryption public key data. Based on the public key encryption architecture for information transmission, the encrypted public key data transmitted by abnormal terminals is divided into encrypted public key associated nodes to obtain the abnormal terminal key associated node data. Perform node intersection operation on the abnormal terminal connection node data and the abnormal terminal key associated node data to obtain the abnormal information transmission node data; The abnormal transmission terminal node data and the abnormal information transmission node data are integrated into the node link to obtain the abnormal node link data.
7. The method according to claim 1, characterized in that, The step of analyzing abnormal transmission node blocking strategies based on the abnormal node link data and the information transmission data to obtain abnormal transmission node blocking strategies, and constructing a secure information transmission link structure model based on the abnormal transmission node blocking strategies and the information transmission topology model, includes: Abnormal transmission pattern data is obtained by integrating abnormal node link data and abnormal patterns. An impact assessment of abnormal transmission patterns is conducted on enterprise information transmission data to obtain abnormal pattern impact assessment data. Based on the impact assessment data of abnormal patterns, abnormal node link data is prioritized to obtain abnormal node priority data. Extract the resource allocation features of the transmission nodes from the information transmission data to obtain the resource allocation data of the transmission nodes; Based on the resource allocation data of transmission nodes and the priority data of abnormal nodes, the node blocking strategy is analyzed to obtain the blocking strategy for abnormal transmission nodes. A secure information transmission link structure model is constructed based on the abnormal transmission node blocking strategy and the information transmission topology model.
8. The method according to claim 7, characterized in that, The step of prioritizing abnormal nodes based on the abnormal mode impact assessment data to obtain abnormal node priority data includes: Based on the impact assessment data of abnormal patterns, the impact degree features of abnormal pattern nodes are extracted to obtain the impact degree data of abnormal pattern nodes; Based on the impact data of abnormal pattern nodes, the impact priority of abnormal node link data is evaluated to obtain the impact priority data of abnormal nodes. The connection priority of abnormal nodes is evaluated by using the information transmission topology model to obtain connection priority data of abnormal nodes. The abnormal node priority data is obtained by performing a node priority weighted average on the abnormal node impact priority data and the abnormal node connection priority data.
9. An apparatus for constructing a data security situation awareness platform, characterized in that, The device includes: The information transmission topology module is used to acquire the network communication data of the entity to be constructed, and to determine the information transmission data and information transmission topology model of the entity to be constructed based on the network communication data. An abnormal information transmission analysis module is used to perform abnormal analysis on the information transmission data to obtain abnormal information transmission data, and to perform abnormal network communication correction on the abnormal information transmission data based on the network communication data to obtain insecure information transmission data. An abnormal information transmission detection model construction module is used to construct an abnormal information transmission detection model based on the insecure information transmission data, and to perform information transmission anomaly detection on the information transmission data through the abnormal information transmission detection model to obtain real-time abnormal information transmission data. An abnormal node link integration module is used to divide the information transmission topology model into abnormal information transmission nodes according to the real-time abnormal information transmission data to obtain abnormal information transmission node data, and to integrate abnormal node links according to the abnormal information transmission node data to obtain abnormal node link data. The blocking strategy analysis module is used to analyze the blocking strategy of abnormal transmission nodes based on the abnormal node link data and the information transmission data, obtain the abnormal transmission node blocking strategy, and construct a secure information transmission link structure model based on the abnormal transmission node blocking strategy and the information transmission topology model. The security situation awareness platform construction module is used to construct a security situation awareness platform based on the security information transmission link structure model and the abnormal information transmission detection model, thereby obtaining the information transmission security situation awareness platform of the entity to be constructed.
10. An electronic device, characterized in that, include: One or more processors; Storage device for storing one or more programs. When the one or more programs are executed by the one or more processors, the one or more processors implement the method for building a data security situation awareness platform as described in any one of claims 1-8.
Citation Information
Patent Citations
Method and system architecture for enterprise network security operation management
CN110708316A
Power grid security situation awareness platform architecture
CN112651006A