A computer network information security monitoring method
By combining peak and average traffic assessment methods with weights and attenuation factors for dynamic risk assessment, this approach addresses the issues of incomplete assessments and reliance on manual adjustments in existing technologies. It enables rapid response and automated adjustments for cybersecurity, improving assessment accuracy and system stability.
Patent Information
- Application Number
- CN202411961149.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-30
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2044-12-30
AI Technical Summary
Existing technologies rely on a single traffic rate assessment metric, ignoring peak traffic information, resulting in incomplete assessment results and a lack of dynamic adjustment mechanisms. This makes it difficult to detect cybersecurity threats in a timely and accurate manner, and security policy adjustments depend on human experience, leading to slow response times and low efficiency.
The monitoring and acquisition module monitors network traffic in real time, and the comprehensive assessment and adjustment module judges the degree of anomaly and risk level to generate a policy adjustment report. The security execution module automatically executes the policy and adopts an assessment method that combines peak and average traffic. It introduces weighting factors and attenuation factors to conduct dynamic risk assessment and realize automated security policy adjustment.
It improves the accuracy and sensitivity of cybersecurity assessments, enabling timely detection of potential threats, rapid response, and automated policy adjustments, thereby enhancing the stability and response speed of cybersecurity.
Smart Images

Figure CN119603069B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network information security monitoring technology, specifically a method for monitoring computer network information security. Background Technology
[0002] With the widespread application and popularization of computer networks, cybersecurity threats are becoming increasingly severe. Frequent security incidents such as hacker attacks, virus propagation, and phishing attacks pose enormous challenges to the information security of individuals, enterprises, and nations. These security threats may not only lead to data leaks and property losses but also affect social stability and national security. Therefore, developing effective computer network information security monitoring methods has become an urgent task. Moreover, in the field of cybersecurity, adjusting security strategies is an important means of dealing with security threats.
[0003] Existing technologies often rely on a single traffic rate as an evaluation metric, ignoring crucial information about traffic peaks. This results in incomplete evaluations. Furthermore, risk assessments and security policy adjustments are often based on static thresholds and fixed rules, failing to dynamically adapt to real-time changes in the network environment. When facing complex and ever-changing network attacks, existing technologies lack sensitivity, making it difficult to detect potential security threats in a timely and accurate manner. In addition, security policy adjustments often depend on manual judgment and experience, lacking automated adjustment mechanisms, leading to slow response times and low efficiency. Summary of the Invention
[0004] The purpose of this invention is to provide a computer network information security monitoring method that solves the problems mentioned in the background art.
[0005] To achieve the above objectives, the present invention provides the following technical solution, and the specific implementation steps are as follows:
[0006] Step 1: Use the monitoring and acquisition module to monitor and collect network traffic data in real time, and extract and record historical network traffic data;
[0007] Step 2: Using the comprehensive assessment and adjustment module, determine the degree of anomaly in the current traffic, assess the overall risk level of network security, adjust network security strategies, and generate a strategy adjustment report;
[0008] Step 3: Based on the policy adjustment report, and using the security execution module, execute the adjusted network security policy;
[0009] Step 4: Continuously monitor network traffic using the monitoring and data acquisition module;
[0010] The comprehensive assessment and adjustment module includes a unit for monitoring and assessing the degree of traffic anomalies, a unit for comprehensively assessing current network security risks, and a security policy adjustment unit.
[0011] The monitoring and acquisition module uses network traffic monitoring devices, such as network traffic analyzers and network probes, to collect network traffic data in real time.
[0012] The comprehensive assessment and adjustment module uses equipment including servers, which are used to store historical traffic data, run monitoring software and algorithms, and perform security policy adjustments.
[0013] The secure execution module uses devices including security devices such as firewalls, intrusion detection systems, and intrusion prevention systems, providing hardware support for implementing network security policies.
[0014] Optionally, the calculation formula for the monitoring and assessment unit of the degree of traffic anomaly is as follows:
[0015] ;
[0016] in:
[0017] XL represents the abnormal traffic assessment value;
[0018] DL represents the current flow rate;
[0019] PL is the average flow threshold, which is used to determine the flow level that generates flow.
[0020] DF represents the current peak flow rate, reflecting the instantaneous change in flow rate.
[0021] LF is the average peak flow threshold, which is used to determine the degree of abnormality of peak flow.
[0022] ((DF-LF) / LF) 2 Magnify the difference between the current peak flow rate (DF) and the average peak flow rate threshold (LF) to highlight abnormal changes in the peak flow rate.
[0023] Optionally, based on the abnormal traffic assessment value XL, the monitoring and acquisition module is used to extract abnormal traffic assessment values XL reflecting network security and stability for the previous n time periods. The specific calculation formula is as follows:
[0024] XL avg =(XL1+XL2+XL3+……+XL3) / n;
[0025] XL avg The average of n abnormal traffic assessments;
[0026] n is the total number of items extracted;
[0027] XL1+XL2+XL3+......+XL3 calculates the sum of the abnormal traffic assessment values XL reflecting network security stability over n time periods.
[0028] Optionally, the calculation formula for the comprehensive assessment of the current network security risk unit is as follows:
[0029] FX=FX prev × (1-S) + (XL / 100) a ×S;
[0030] in:
[0031] FX represents the risk assessment value;
[0032] FX prev This is the risk assessment value from the previous period;
[0033] 'a' is a weighting factor. 'a' is used to adjust the degree of influence of the abnormal flow assessment value XL in the risk assessment. The larger 'a' is, the greater the influence of the abnormal flow assessment value XL on the risk assessment value FX.
[0034] S is the attenuation factor, which reflects the degree of influence of historical risk assessment values on current assessment values.
[0035] Optionally, based on the abnormal traffic assessment value XL and the average value XL of the n abnormal traffic assessments. avg The current network state is determined, and the attenuation factor S is adjusted accordingly as follows:
[0036] S1, if the abnormal flow assessment value XL and the average value of n abnormal flow assessments XL avg If the difference between them is small, it indicates that the network condition is relatively stable and historical data has high reference value for the current assessment. When the attenuation factor S is increased;
[0037] S2, if the abnormal flow assessment value XL and the average value of n abnormal flow assessments XL avg A large difference between the values indicates that the network conditions are changing rapidly, and historical data has low reference value for the current assessment. Therefore, the attenuation factor S should be reduced.
[0038] Optionally, the calculation formula for the security policy adjustment unit is as follows:
[0039] ;
[0040] in:
[0041] AC is the security policy adjustment factor;
[0042] AC prev This is the adjustment factor for the security strategy in the previous period;
[0043] AQ is a preset safety threshold;
[0044] T represents the sensitivity adjustment, indicating the sensitivity to changes in the security policy adjustment factor AC.
[0045] Optionally, based on the security policy adjustment factor AC and the security policy adjustment factor AC of the previous time period. prev The adjustment steps are as follows:
[0046] S1, if AC <AC prev This indicates that a strict security strategy is needed, including limiting traffic, increasing encryption strength, and enabling higher-level firewall rules;
[0047] S2, If AC > AC prev This indicates that the current network security situation is good, and security policies should be maintained and relaxed.
[0048] Optionally, if the security policy adjustment factor AC indicates that the current network security status is good, then the abnormal traffic assessment value XL of this algorithm will be incorporated into the average value XL of n abnormal traffic assessments in the next time period. avg Calculation;
[0049] If the security policy adjustment factor AC indicates that a strict security policy is required, the input value of the current traffic rate DL in the next round will be reduced.
[0050] Compared with the prior art, the present invention has the following beneficial effects:
[0051] I. This invention introduces the current peak flow rate (DF) and the average peak flow rate threshold (LF), and combines them with the current flow rate (DL) and the average flow rate threshold (PL), enabling the monitoring and evaluation unit for assessing the degree of flow anomalies to more comprehensively evaluate the anomalies in the flow. This comprehensive evaluation not only considers the average level of the flow but also the instantaneous changes in the flow, thus improving the accuracy and reliability of the evaluation.
[0052] II. This invention comprehensively assesses the current network security risk unit by combining the risk assessment value FX from the previous period. prev By combining the current abnormal traffic assessment value XL with the introduction of attenuation factor S and weighting factor a, the risk assessment is dynamically adjusted. This dynamic adjustment mechanism can flexibly adjust the risk assessment value according to the real-time changes in the network environment, thereby more accurately reflecting the actual situation of network security.
[0053] Third, the security policy adjustment unit of this invention introduces the security policy adjustment factor AC from the previous time period. prev By combining the current risk assessment value FX, the preset security threshold AQ, and the sensitivity adjustment T, the security policy can be automatically adjusted. This flexible policy adjustment mechanism can quickly respond to changes in network security, thereby improving network security and stability.
[0054] Fourth, by adjusting the weighting factor a and the sensitivity T, this invention can more flexibly control the influence of the abnormal flow assessment value XL and the risk assessment value FX during the monitoring process, thereby improving the sensitivity of the monitoring system. This enables the monitoring system to detect potential security threats more promptly and accurately, and take corresponding countermeasures. Attached Figure Description
[0055] Figure 1 This is a flowchart of the computer network information security monitoring method.
[0056] Figure 2 This is a schematic diagram of the structure of the comprehensive evaluation and adjustment module of the present invention;
[0057] Figure 3 This is a schematic diagram of the overall feedback loop of this computer network information security monitoring method. Detailed Implementation
[0058] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0059] This computer network information security monitoring method differs from traditional monitoring methods. Traditional methods often rely on a single traffic rate threshold to determine whether the network is under attack by abnormal traffic. However, with the continuous evolution and increasing complexity of network attack methods, relying solely on traffic rate is no longer sufficient to comprehensively and accurately assess the anomalies and risks of network security. This algorithm unit achieves the beneficial effects and optimizations of comprehensive assessment, dynamic risk assessment, flexible strategy adjustment, and improved sensitivity. These optimizations and innovations not only solve the problems and shortcomings of existing technologies but also improve the accuracy and reliability of the monitoring system, providing a more comprehensive and effective guarantee for computer network information security.
[0060] For examples, please refer to Figures 1 to 3 This implementation provides a computer network information security monitoring method, and the specific implementation steps are as follows:
[0061] Step 1: Use the monitoring and acquisition module to monitor and collect network traffic data in real time, and extract and record historical network traffic data;
[0062] Step 2: Using the comprehensive assessment and adjustment module, determine the degree of anomaly in the current traffic, assess the overall risk level of network security, adjust network security strategies, and generate a strategy adjustment report;
[0063] Step 3: Based on the policy adjustment report, and using the security execution module, execute the adjusted network security policy;
[0064] Step 4: Continuously monitor network traffic using the monitoring and data acquisition module;
[0065] The comprehensive assessment and adjustment module includes a unit for monitoring and assessing the degree of traffic anomalies, a unit for comprehensively assessing current network security risks, and a security policy adjustment unit.
[0066] The monitoring and acquisition module uses network traffic monitoring devices, such as network traffic analyzers and network probes, to collect network traffic data in real time.
[0067] The comprehensive assessment and adjustment module uses equipment including servers, which are used to store historical traffic data, run monitoring software and algorithms, and perform security policy adjustments.
[0068] The secure execution module uses devices including security devices such as firewalls, intrusion detection systems, and intrusion prevention systems, providing hardware support for implementing network security policies.
[0069] In this embodiment, the system utilizes the cooperation of three algorithm units, combining the results of XL, FX, and AC calculations. Each unit performs its specific function within the network information security monitoring system, jointly achieving a comprehensive assessment, risk quantification, and policy adjustment of network security. XL represents the abnormal traffic assessment value, which considers not only the average traffic level but also instantaneous changes in traffic, thus providing a more comprehensive assessment of traffic anomalies. FX represents the risk assessment value, which can flexibly adjust the contribution of the abnormal traffic assessment value XL to the risk assessment, making the risk assessment results more consistent with reality. AC represents the security policy adjustment factor, reflecting the degree of deviation between the current network security status and the security threshold, as well as the impact of this deviation on security policy adjustments. This enables the monitoring system to automatically adjust security policies to cope with constantly changing network security threats. Furthermore, the calculation results of AC can also influence the calculations of XL and FX, resulting in a high degree of correlation and interdependence among the three algorithms in this system. The three algorithm units are interconnected and mutually supportive, jointly forming an efficient and flexible network security monitoring and response mechanism.
[0070] Please see Figures 1 to 3 The calculation formula for the unit monitoring and assessing the degree of traffic anomalies is as follows:
[0071] ;
[0072] in:
[0073] XL represents the abnormal traffic assessment value;
[0074] DL represents the current flow rate;
[0075] PL is the average flow threshold, which is used to determine the flow level that generates flow.
[0076] DF represents the current peak flow rate, reflecting the instantaneous change in flow rate.
[0077] LF is the average peak flow threshold, which is used to determine the degree of abnormality of peak flow.
[0078] ((DF-LF) / LF) 2 Magnify the difference between the current peak flow rate (DF) and the average peak flow rate threshold (LF) to highlight abnormal changes in the peak flow rate.
[0079] In this embodiment: First, in this algorithm unit, " "This part calculates the square of the difference between the current flow rate DL and the average flow threshold PL, and normalizes it by dividing by the square of the average flow threshold PL. The purpose is to quantify the degree to which the current flow rate DL deviates from the average flow threshold PL, that is, the degree of flow abnormality. The squaring operation amplifies the deviation value, making the abnormal value more significant."
[0080] This algorithm unit not only focuses on the average level of traffic, i.e., the comparison between the current traffic rate DL and the average traffic threshold PL, but also introduces the concepts of the current traffic peak DF and the average traffic peak threshold LF. This enables a multi-dimensional consideration of traffic characteristics. This approach allows the monitoring system to more comprehensively capture abnormal characteristics of network traffic, including sudden high-traffic attacks that may be hidden below the average level. By comparing the current traffic rate DL and the average traffic threshold PL, as well as the current traffic peak DF and the average traffic peak threshold LF, the monitoring system can accurately identify abnormal traffic patterns in the network. Whether it is continuous high traffic or sudden traffic peaks, they can be effectively captured and analyzed.
[0081] Because this algorithm unit considers both the average level and instantaneous changes in traffic, the unit that monitors and assesses the degree of traffic anomalies can capture minute abnormal changes in traffic. This high sensitivity enables the monitoring system to issue early warnings in the early stages of an attack, buying valuable time for subsequent defense measures. By providing early warnings of potential security threats, the monitoring system can help network administrators take timely measures to prevent the attack from spreading and worsening further.
[0082] The calculated abnormal traffic assessment value XL enables the monitoring system to quantify the degree of traffic abnormality, providing an objective basis for subsequent risk assessment and security policy adjustments. This quantification method makes the decision-making process more scientific and reasonable. Furthermore, as the abnormal traffic assessment value XL changes, the monitoring system can dynamically adjust its monitoring and security policies to adapt to the ever-changing network security environment.
[0083] Please see Figures 1 to 3 The calculation formula for comprehensively assessing the current network security risk units is as follows:
[0084] FX=FX prev × (1-S) + (XL / 100) a ×S;
[0085] in:
[0086] FX represents the risk assessment value;
[0087] FX prev This is the risk assessment value from the previous period;
[0088] 'a' is a weighting factor. 'a' is used to adjust the degree of influence of the abnormal flow assessment value XL in the risk assessment. The larger 'a' is, the greater the influence of the abnormal flow assessment value XL on the risk assessment value FX.
[0089] S is the attenuation factor, which reflects the degree of influence of historical risk assessment values on current assessment values.
[0090] In this embodiment, firstly, the calculation of "(1-S)" is the complement of the attenuation factor S, used to calculate the risk assessment value FX of the previous period. prev In the risk assessment value FX, when the attenuation factor S increases, “(1-S)” decreases, indicating that the influence of historical values on the current value decreases; conversely, when the attenuation factor S decreases, “(1-S)” increases, indicating that the influence of historical values on the current value increases.
[0091] This algorithm unit combines the risk assessment value FX from the previous period. prev The current abnormal traffic assessment value XL is dynamically calculated to obtain the current risk assessment value FX. This calculation method enables the risk assessment results to reflect the actual situation of network security in real time. By introducing the attenuation factor S and the weighting factor a, the current network security risk unit can be comprehensively evaluated to more accurately assess the risk level of network security. The introduction of the attenuation factor S gradually weakens the influence of historical information on the current assessment value, while the adjustment of the weighting factor a can flexibly control the contribution of the abnormal traffic assessment value XL in the risk assessment according to the actual situation.
[0092] By adjusting the weighting factor 'a', the monitoring system can assess the risk level of network security in a customized manner according to different network environments and security needs. This customized assessment method makes the monitoring system more flexible and adaptable. Based on the risk assessment results, the monitoring system can optimize its monitoring and security strategies to better cope with network security threats.
[0093] The introduction of the attenuation factor D enables the monitoring system to comprehensively consider historical and current information when assessing cybersecurity risks. This comprehensive approach makes the assessment results more comprehensive and accurate.
[0094] By balancing the influence of historical and current information, monitoring systems can avoid biases and misjudgments caused by over-reliance on either historical or current information.
[0095] Please see Figures 1 to 3 Based on the abnormal traffic assessment value XL, the monitoring and acquisition module extracts the abnormal traffic assessment values XL reflecting network security and stability for the previous n time periods. The specific calculation formula is as follows:
[0096] XL avg =(XL1+XL2+XL3+……+XL3) / n;
[0097] XL avg The average of n abnormal traffic assessments;
[0098] n is the total number of items extracted;
[0099] XL1+XL2+XL3+......+XL3 calculates the sum of the abnormal traffic assessment values XL reflecting network security stability over n time periods;
[0100] Based on the abnormal traffic assessment value XL and the average value of the n abnormal traffic assessments XL avg The current network state is determined, and the attenuation factor S is adjusted accordingly as follows:
[0101] S1, if the abnormal flow assessment value XL and the average value of n abnormal flow assessments XL avg If the difference between them is small, it indicates that the network condition is relatively stable and historical data has high reference value for the current assessment. When the attenuation factor S is increased;
[0102] S2, if the abnormal flow assessment value XL and the average value of n abnormal flow assessments XL avg A large difference between the values indicates that the network conditions are changing rapidly, and historical data has low reference value for the current assessment. Therefore, the attenuation factor S should be reduced.
[0103] In this embodiment, by comprehensively considering the average of the abnormal traffic assessment values XL over n time periods that reflect network security stability, a more comprehensive assessment of the network's security status can be achieved. This method reduces the potential for misjudgment due to a single indicator, improves the accuracy and reliability of the assessment, and because the average of the n abnormal traffic assessment values XL... avg It is calculated based on the current good network security situation, therefore it has a certain degree of dynamic adaptability. As the network environment and business needs change, the average value XL of n abnormal traffic assessments will change. avg The criteria will be adjusted accordingly to ensure that the judgment standards remain consistent with the actual situation.
[0104] When the average value of n abnormal traffic assessments is XL avg When the deviation from the average value reaches a certain level, an early warning mechanism can be triggered, due to the average value XL of n abnormal traffic assessments. avg It is calculated based on data under good conditions, so this early warning mechanism is more sensitive and accurate, and can detect potential security threats in a timely manner;
[0105] Based on the abnormal traffic assessment value XL and the average of n abnormal traffic assessments XL avg The degree of deviation between these parameters allows for more precise adjustments to network security strategies, and by reasonably setting the average value XL of n abnormal traffic assessments... avg The established criteria enable more effective use of network security resources. When network security is in good condition, the investment in security resources can be appropriately reduced, while when network security deteriorates, the investment in security resources can be rapidly increased to cope with the risks. In addition, through timely early warning and fine-grained policy adjustments, it can ensure that the network maintains a good operating status in most cases. This not only reduces service interruptions and performance degradation caused by network security issues, but also improves the overall user experience.
[0106] Please see Figures 1 to 3 The calculation formula for the security policy adjustment unit is as follows:
[0107] ;
[0108] in:
[0109] AC is the security policy adjustment factor;
[0110] AC prev This is the adjustment factor for the security strategy in the previous period;
[0111] AQ is a preset safety threshold;
[0112] T represents the sensitivity adjustment, indicating the sensitivity to changes in the security policy adjustment factor AC.
[0113] In this embodiment, the value of the security policy adjustment factor AC in this algorithm unit directly reflects the deviation between the current network security status and the security threshold, as well as the degree of influence of this deviation on the security policy adjustment. By using the value of the security policy adjustment factor AC, the monitoring system can clearly know whether the security policy needs to be adjusted, as well as the direction and intensity of the adjustment. Furthermore, based on the value of the security policy adjustment factor AC, the monitoring system can automatically adjust the security policy, achieving rapid response and effective defense with minimal or no manual intervention.
[0114] The denominator FX+AQ+T design in the security policy adjustment unit makes the change of the security policy adjustment factor AC more stable when the risk assessment value FX is close to the preset security threshold AQ. This design avoids the problem of frequent security policy adjustments caused by small changes in the risk assessment value FX, thereby improving the stability and reliability of the system. The smooth adjustment process reduces the inconvenience and trouble caused to users by frequent adjustments, improving user experience and satisfaction.
[0115] When a deterioration in network security is detected, i.e., an increase in the risk assessment value FX, the security policy adjustment factor AC will decrease rapidly, thereby triggering a more stringent security policy adjustment. This rapid response mechanism enables the monitoring system to react to security threats and take effective measures to defend against them in the shortest possible time. Through rapid response and effective defense, the monitoring system can minimize the losses and impacts of network security incidents on the network and users.
[0116] Please see Figures 1 to 3 Based on the security policy adjustment factor AC and the security policy adjustment factor AC of the previous time period prev The adjustment steps are as follows:
[0117] S1, if AC <AC prev This indicates that a strict security strategy is needed, including limiting traffic, increasing encryption strength, and enabling higher-level firewall rules;
[0118] S2, If AC > AC prev This indicates that the current network security situation is good, and security policies should be maintained and relaxed.
[0119] If the security policy adjustment factor AC indicates that the current network security status is good, then the abnormal traffic assessment value XL of this algorithm will be carried over to the average value XL of n abnormal traffic assessments in the next time period. avg Calculation;
[0120] If the security policy adjustment factor AC indicates that a strict security policy is required, the input value of the current traffic rate DL in the next round will be reduced.
[0121] In this embodiment, the algorithm unit is based on the security policy adjustment unit and guides the adjustment of the security policy through the security policy adjustment factor AC. These adjustment measures will directly affect the traffic patterns and abnormal traffic in the network. Therefore, when the security policy is adjusted, the current traffic rate DL in the network will change, which will affect the calculation of the abnormal traffic evaluation value XL in the monitoring and evaluation of the degree of traffic abnormality. This dynamic adjustment process forms a closed-loop feedback mechanism that enables the monitoring system to continuously optimize its monitoring effect. Through the closed-loop feedback mechanism, the monitoring system can continuously adjust its monitoring policy and security policy according to the changes in the network security situation, thereby achieving continuous improvement and optimization.
[0122] The closed-loop feedback mechanism enables the monitoring system to more accurately monitor abnormal traffic patterns in the network and promptly detect potential security threats. This precise monitoring capability improves the effectiveness and reliability of the monitoring system. After detecting potential security threats, the monitoring system can quickly adjust its security strategy and take effective measures to defend against them, thereby ensuring the security and stability of the network.
[0123] Because the network environment is constantly changing and new security threats and attack methods are emerging one after another, the monitoring system, through the cyclical impact of the security policy adjustment unit on the monitoring and assessment unit of traffic anomalies, can flexibly respond to these changes and adjust its monitoring and security policies according to the actual situation to ensure the continuity and effectiveness of network security. By continuously adapting to changes in the network environment, the monitoring system can enhance its resilience and anti-attack capabilities, thereby better protecting the network and users from security threats.
[0124] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A method for monitoring computer network information security, characterized in that, The specific implementation steps are as follows: Step 1: Use the monitoring and acquisition module to monitor and collect network traffic data in real time, and extract and record historical network traffic data; Step 2: Using the comprehensive assessment and adjustment module, determine the degree of anomaly in the current traffic, assess the overall risk level of network security, adjust network security strategies, and generate a strategy adjustment report; Step 3: Based on the policy adjustment report, and using the security execution module, execute the adjusted network security policy; Step 4: Continuously monitor network traffic using the monitoring and data acquisition module; The comprehensive assessment and adjustment module includes a unit for monitoring and assessing the degree of traffic anomalies, a unit for comprehensively assessing current network security risks, and a security policy adjustment unit. The calculation formula for the monitoring and assessment unit of the degree of traffic anomaly is as follows: ; in: XL represents the abnormal traffic assessment value; DL represents the current flow rate; PL is the average flow threshold, which is used to determine the flow level that generates flow. DF represents the current peak flow rate, reflecting the instantaneous change in flow rate. LF is the average peak flow threshold, which is used to determine the degree of abnormality of peak flow. Magnify the difference between the current peak flow rate (DF) and the average peak flow rate threshold (LF) to highlight abnormal changes in the peak flow rate; Based on the abnormal traffic assessment value XL, the monitoring and acquisition module is used to extract the abnormal traffic assessment values XL reflecting network security and stability for the previous n time periods. The specific calculation formula is as follows: XL avg =(XL1+XL2+XL3+......+XL3) / n; XL avg The average of n abnormal traffic assessments; n is the total number of items extracted; XL1+XL2+XL3+......+XL3 calculates the sum of the abnormal traffic assessment values XL reflecting network security stability over n time periods; The calculation formula for comprehensively assessing the current network security risk units is as follows: FX=FX prev ×(1-S)+(XL / 100) a ×S; in: FX represents the risk assessment value; FX prev This is the risk assessment value from the previous period; 'a' is a weighting factor. 'a' is used to adjust the degree of influence of the abnormal flow assessment value XL in the risk assessment. The larger 'a' is, the greater the influence of the abnormal flow assessment value XL on the risk assessment value FX. S is the attenuation factor, which reflects the degree of influence of historical risk assessment values on current assessment values. Based on the abnormal traffic assessment value XL and the average value of the n abnormal traffic assessments XL avg The current network state is determined, and the attenuation factor S is adjusted accordingly as follows: If the abnormal traffic assessment value XL and the average of n abnormal traffic assessments XL avg A small difference between the values indicates that the network condition is relatively stable and historical data has high reference value for the current assessment, when the attenuation factor S is increased; If the abnormal traffic assessment value XL and the average of n abnormal traffic assessments XL avg A large difference between the values indicates that when network conditions change rapidly, historical data has low reference value for the current assessment, and the attenuation factor S should be reduced.
2. The computer network information security monitoring method according to claim 1, characterized in that, The calculation formula for the security policy adjustment unit is as follows: ; in: AC is the security policy adjustment factor; AC prev This is the adjustment factor for the security strategy in the previous period; AQ is a preset safety threshold; T represents the sensitivity adjustment, indicating the sensitivity to changes in the security policy adjustment factor AC.
3. The computer network information security monitoring method according to claim 2, characterized in that, The monitoring and acquisition module uses network traffic monitoring equipment, including network traffic analyzers and network probes, to collect network traffic data in real time. The comprehensive assessment and adjustment module uses equipment including servers, which are used to store historical traffic data, run monitoring software and algorithms, and perform security policy adjustments. The secure execution module uses devices including security devices such as firewalls, intrusion detection systems, and intrusion prevention systems, providing hardware support for implementing network security policies.
4. The computer network information security monitoring method according to claim 3, characterized in that: Based on the security policy adjustment factor AC and the security policy adjustment factor AC of the previous period prev The adjustment steps are as follows: If AC <AC prev This indicates that a strict security strategy is needed, including limiting traffic, increasing encryption strength, and enabling higher-level firewall rules; If AC>AC prev This indicates that the current network security situation is good, and security policies should be maintained and relaxed.
5. A computer network information security monitoring method according to claim 4, characterized in that: If the security policy adjustment factor AC indicates that the current network security status is good, then the abnormal traffic assessment value XL will be carried over to the average value XL of n abnormal traffic assessments in the next time period. avg Calculation; If the security policy adjustment factor AC indicates that a strict security policy is required, the input value of the current traffic rate DL in the next round will be reduced.
Citation Information
Patent Citations
Network security intelligent protection method and system based on endogenous security mechanism
CN118972157A