Network security early warning method and system based on big data

By collecting multiple types of network data, calculating risk indicators and comprehensively evaluating network security risks, the limitations of relying on a single data source in the existing technology are solved, a comprehensive understanding of the network environment and accurate risk assessment are achieved, and the effectiveness of network security protection is improved.

CN119603076BActive Publication Date: 2025-05-02SICHUAN WATER CONSERVANCY VOCATIONAL & TECH COLLEGE
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510134793.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-07
Publication Date
2025-05-02
Estimated Expiration
2045-02-07

AI Technical Summary

Technical Problem

The existing network security early warning methods rely on a single data source and cannot fully cover all potential threats in the network environment. The data processing capacity is limited, the risk assessment is not meticulous enough, and misreporting false alarms often occur, resulting in timely elimination of security risks.

Method used

By collecting multiple types of data, including network traffic, user behavior, system logs and hardware status data, the corresponding risk indicators are calculated, and the comprehensive network security risk indicators are comprehensively calculated, the network security warning threshold is preset, and the warning mechanism is determined whether to trigger the warning mechanism, and corresponding warning information is generated.

Benefits of technology

It realizes all-round insight into the network environment and multi-dimensional data collection, avoids the one-sidedness brought by a single data source, ensures a comprehensive understanding of the network system, lays the foundation for accurate risk assessment, and improves the effectiveness and timeliness of network security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119603076B_ABST
    Figure CN119603076B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for network security early warning based on big data, which relates to the technical field of network security. The main scheme is: by collecting multiple types of data, including network traffic, user behavior, system logs and hardware status data, and then calculating indicators based on these data, network attack risk indicators, user data abnormality risk indicators, system security risk indicators and hardware failure risk indicators, and further comprehensively calculating a comprehensive network security risk indicator, and finally presetting a network security early warning threshold, comparing the comprehensive indicator with it, judging whether to trigger the early warning mechanism according to the comparison result, and generating corresponding early warning information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method and system for network security early warning based on big data. Background Art

[0002] With the rapid development of information technology, the Internet has been deeply integrated into all aspects of social life. Whether it is corporate operations, government management or personal daily affairs processing, it is highly dependent on network infrastructure. But at the same time, network security threats are becoming increasingly severe and complex, showing characteristics such as diversity, high frequency and high concealment, posing huge challenges to the stability and security of cyberspace.

[0003] Traditional network security early warning methods usually rely on firewall log data to issue early warnings, which cannot fully cover all potential threats in the network environment. The data processing capabilities are limited, the risk assessment is not sophisticated enough, and it has certain limitations. Missed reports and false alarms often occur, making it difficult to eliminate security risks in a timely manner. Summary of the invention

[0004] 1. Technical issues to be resolved

[0005] In view of the shortcomings of the prior art, the present invention provides a method and system for network security early warning based on big data, which collects multiple types of data, including network traffic, user behavior, system logs and hardware status data, and then calculates network attack risk indicators, user data anomaly risk indicators, system security risk indicators and application system health indicators based on these data, and further comprehensively calculates the network security comprehensive risk index. Finally, a network security early warning threshold is preset, and the comprehensive risk indicator is compared with it. According to the comparison result, it is determined whether to trigger the early warning mechanism, and corresponding early warning information is generated, which solves the problems of relying on only one data source, failing to fully cover all potential threats in the network environment, limited data processing capabilities, and insufficiently refined risk assessment.

[0006] (II) Technical solution

[0007] To achieve the above objectives, the present invention is implemented through the following technical solutions: A method for network security early warning based on big data comprises the following steps:

[0008] Step 1: Collect network traffic data, user behavior data, system log data and hardware status data of network devices;

[0009] Step 2: Calculate the network attack risk index QCH based on network traffic data;

[0010] Calculate the account abnormal login index MHW and access frequency deviation index VFD based on user behavior data; calculate the user data abnormal risk index DGU based on the account abnormal login index MHW and access frequency deviation index VFD;

[0011] Calculate the system health index NDK and attack threat index AMI based on system log data, and further calculate the system security risk index JKH;

[0012] Calculate the hardware network communication quality index HNQ, hardware abnormality change rate IUY and hardware performance health index HPI based on the hardware status data; calculate the hardware failure risk index SMU based on the hardware network communication quality index HNQ, hardware abnormality change rate IUY and hardware performance health index HPI;

[0013] Calculate the network security comprehensive risk index CFR based on the network attack risk index QCH, user data abnormality risk index DGU, system security risk index JKH and hardware failure risk index SMU;

[0014] Step 3: Preset a set of network security warning thresholds, compare the network security comprehensive risk index CFR with the network security warning threshold set, determine whether to trigger the warning mechanism based on the comparison results, and generate corresponding warning information.

[0015] In the preferred embodiment of the above-mentioned method for network security early warning based on big data: the method for calculating the network attack risk index QCH is:

[0016] Network traffic data including packet loss rate , jitter rate SWV, broadband utilization NGU, average network connection time MNG and number of successful connections NTQ;

[0017] According to the data packet loss rate , jitter rate SWV, broadband utilization NGU, average network connection time MNG and number of successful connections NTQ are used to calculate the network attack risk index QCH. The formula is as follows:

[0018] .

[0019] In the preferred embodiment of the method for network security early warning based on big data, the method for calculating the account abnormal login index MHW and the access frequency deviation index VFD is:

[0020] User behavior data includes the number of off-site logins HYI, the number of non-working hours logins RGK, and the total number of logins KHY;

[0021] The account abnormal login index MHW is calculated based on the number of off-site logins HYI, the number of non-working hours logins RGK and the total number of logins KHY. The formula is as follows:

[0022] ;

[0023] Among them, ω1 is The weight coefficient is 0.1~0.3; ω2 is The weight coefficient is 0.7~0.9; and ω1+ω2=1;

[0024] User behavior data also includes current access frequency TRW and historical access frequency XBN;

[0025] The access frequency deviation index VFD is calculated based on the current access frequency TRW and the historical access frequency XBN, and the formula is as follows:

[0026] ;

[0027] Among them, γ1 is The weight coefficient is 0.2~0.4; γ2 is The weight coefficient is between 0.6 and 0.8, and γ1+γ2=1.

[0028] In the preferred embodiment of the above-mentioned method for network security early warning based on big data: the method for calculating the user data abnormal risk index DGU is:

[0029] The user data abnormality risk index DGU is calculated based on the account abnormal login index MHW and the access frequency deviation index VFD. The formula is as follows:

[0030] ;

[0031] Among them, µ1 is The weight coefficient is 0.1~0.4, and µ2 is The weight coefficient is 0.2~0.4; µ3 is The weight coefficient is between 0.4 and 0.5, and µ1+µ2+µ3=1.

[0032] In the preferred embodiment of the above-mentioned method for network security early warning based on big data: the method for calculating the system security risk index JKH is:

[0033] System log data includes the normal state duration TNS, the number of normal operations YSM, the number of failures NSQ, the total operation time of all states EME and the total number of all operations CZX recorded in the system log;

[0034] The system health index NDK is calculated based on the normal state duration TNS, the number of normal operations YSM, the number of failures NSQ, the total operation time of all states EME and the total number of all operations CZX. The formula is as follows:

[0035] ;

[0036] System log data also includes the attack frequency UPQ recorded in the system log i , Attack duration value SGL i and the total number of events YXZ;

[0037] UPQ based on attack frequency i , Attack duration value SGL i The attack threat index AMI is calculated based on the total number of events YXZ, and the formula is as follows:

[0038] ;

[0039] Among them, UPQ i is the occurrence frequency of the i-th attack type, SGL i is the duration of the attack of the i-th attack type, i is the serial number corresponding to different attack types, and its value is [1, n]; n is the number of attack types, and its value is a positive integer;

[0040] The system security risk index JKH is calculated based on the system health index NDK and the attack threat index AMI. The formula is as follows:

[0041] ;

[0042] Among them, α1 is α1 is the weight coefficient of attack threat index AMI, which is between 0.1 and 0.4; α2 is the weight coefficient of attack threat index AMI, which is between 0.6 and 0.9; and α1+α2=1.

[0043] In the preferred embodiment of the above-mentioned method for network security early warning based on big data: the method for calculating the hardware network communication quality index HNQ, the hardware abnormal change rate IUY and the hardware performance health index HPI is:

[0044] The hardware status data includes the received normal communication data packets NTY, the total data packets sent MEB and the lost data packets MRE;

[0045] The hardware network communication quality index HNQ is calculated based on the received normal communication data packets NTY, the total sent data packets MEB and the lost data packets MRE, and the formula is as follows:

[0046] ;

[0047] The hardware status data also includes the current actual measured temperature value TUA, the reference temperature value NSE, the electromagnetic interference intensity value CSW and the vibration intensity value EBW;

[0048] The hardware abnormality change rate IUY is calculated based on the current actual measured temperature value TUA, the reference temperature value NSE, the electromagnetic interference intensity value CSW and the vibration intensity value EBW, and the formula is as follows:

[0049] ;

[0050] The hardware performance health index HPI is calculated based on the hardware abnormal change rate IUY, and the formula is as follows:

[0051] .

[0052] In the preferred embodiment of the above-mentioned method for network security early warning based on big data: the method for calculating the hardware failure risk index SMU is:

[0053] The hardware network communication quality index HNQ, the hardware abnormal change rate IUY and the hardware performance health index HPI are used to calculate the hardware failure risk index SMU. The formula is as follows:

[0054] ;

[0055] Among them, β1 is the weight coefficient of the hardware network communication quality index HNQ, which ranges from 0.1 to 0.3; β2 is the weight coefficient of the hardware abnormal change rate IUY, which ranges from 0.3 to 0.4; β3 is The weight coefficient is between 0.4 and 0.5, and β1+β2+β3=1.

[0056] In the preferred embodiment of the above-mentioned method for network security early warning based on big data: the method for calculating the network security comprehensive risk index CFR is:

[0057] The network security comprehensive risk index CFR is calculated based on the network attack risk index QCH, the user data abnormality risk index DGU, the system security risk index JKH and the hardware failure risk index SMU. The formula is as follows:

[0058] .

[0059] In the preferred embodiment of the above-mentioned method for network security early warning based on big data: the method for determining whether to trigger the early warning mechanism is:

[0060] The network security warning threshold set includes a mild warning threshold HJ and a severe warning threshold HN; where HN>HJ;

[0061] Compare the network security comprehensive risk index CFR with the network security warning threshold set, and determine whether to trigger the warning mechanism based on the comparison results. The standards are as follows:

[0062] ;

[0063] Among them, corresponding warning information is generated according to the warning results.

[0064] The present invention also discloses a network security early warning system based on big data, including:

[0065] Data collection module, used to collect network traffic data, user behavior data, system log data and hardware status data of network devices;

[0066] A data calculation module is used to calculate the network attack risk index QCH based on network traffic data;

[0067] Calculate the account abnormal login index MHW and access frequency deviation index VFD based on user behavior data; calculate the user data abnormal risk index DGU based on the account abnormal login index MHW and access frequency deviation index VFD;

[0068] Calculate the system health index NDK and attack threat index AMI based on system log data, and further calculate the system security risk index JKH;

[0069] Calculate the hardware network communication quality index HNQ, hardware abnormality change rate IUY and hardware performance health index HPI based on the hardware status data; calculate the hardware failure risk index SMU based on the hardware network communication quality index HNQ, hardware abnormality change rate IUY and hardware performance health index HPI;

[0070] Calculate the network security comprehensive risk index CFR based on the network attack risk index QCH, user data abnormality risk index DGU, system security risk index JKH and hardware failure risk index SMU;

[0071] The judgment module is used to preset a set of network security warning thresholds, compare the network security comprehensive risk index CFR with the network security warning threshold set, determine whether to trigger the warning mechanism based on the comparison result, and generate corresponding warning information.

[0072] (III) Beneficial effects

[0073] The present invention provides a method and system for network security early warning based on big data, which has the following beneficial effects:

[0074] (1) By collecting network traffic data, user behavior data, system log data, and hardware status data from network devices, we can gain a comprehensive insight into the network environment, achieve multi-dimensional data collection, avoid the one-sidedness brought by a single data source, ensure a comprehensive understanding of the network system, and lay a solid foundation for subsequent accurate risk assessment.

[0075] (2) By processing network traffic data to obtain relevant indexes, the risk of network attacks can be detected in advance, account anomalies and access anomalies can be quickly discovered, user data security can be guaranteed, system vulnerabilities and threats can be detected, and system stability can be ensured. This enables quantitative assessment of network security from multiple dimensions, providing strong support for accurate judgment of network security situation.

[0076] (3) By presetting a set of network security warning thresholds and comparing the comprehensive network security risk indicators with them to determine whether to trigger the warning mechanism, it is possible to quickly and accurately determine whether the network security situation is in a dangerous range and trigger the warning mechanism in a timely manner, effectively avoiding the expansion of security incidents caused by human judgment errors or delays. The network security maintenance team can quickly take targeted measures based on the warning information, greatly improving the effectiveness of network security protection, ensuring that the network system can receive a quick response and proper handling when facing potential threats, and ensuring the stability and security of network operations. BRIEF DESCRIPTION OF THE DRAWINGS

[0077] Figure 1 It is a schematic diagram of the working steps of the method for network security early warning based on big data of the present invention. DETAILED DESCRIPTION

[0078] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0079] See also Figure 1 The present invention provides a method for network security early warning based on big data, comprising the following steps:

[0080] Step 1: Collect network traffic data, user behavior data, system log data, and hardware status data of network devices.

[0081] When using, combine the content of step 1:

[0082] By collecting network traffic data, user behavior data, system log data and hardware status data of network devices, we can gain comprehensive insight into the network environment, realize multi-dimensional data collection, avoid the one-sidedness brought by a single data source, ensure a comprehensive understanding of the network system, and lay a solid foundation for subsequent accurate risk assessment.

[0083] Step 2: Calculate the network attack risk index QCH based on the network traffic data.

[0084] The account abnormal login index MHW and the access frequency deviation index VFD are calculated based on user behavior data; the user data abnormal risk index DGU is calculated based on the account abnormal login index MHW and the access frequency deviation index VFD.

[0085] The system health index NDK and attack threat index AMI are calculated based on the system log data, and the system security risk index JKH is further calculated.

[0086] The hardware network communication quality index HNQ, the hardware abnormality change rate IUY and the hardware performance health index HPI are calculated based on the hardware status data; the hardware failure risk index SMU is calculated based on the hardware network communication quality index HNQ, the hardware abnormality change rate IUY and the hardware performance health index HPI.

[0087] The comprehensive network security risk index CFR is calculated based on the network attack risk index QCH, the user data abnormality risk index DGU, the system security risk index JKH and the hardware failure risk index SMU.

[0088] Step 201: The method for calculating the network attack risk index QCH is:

[0089] Network traffic data including packet loss rate , jitter rate SWV, bandwidth utilization NGU, average network connection time MNG and number of successful connections NTQ.

[0090] It should be noted that the data packet loss rate It indicates the ratio of data packets lost during network transmission to the total data packets. The packet loss rate is calculated by counting the number of data packets sent and not received during the network connection process through the network monitoring tool. The jitter rate SWV indicates the degree of jitter in network connection performance. It is calculated by the built-in algorithm of the PingPlotter network performance monitoring tool. The broadband utilization rate NGU indicates the ratio of the actual bandwidth used by the network to the total bandwidth. The bandwidth utilization rate is calculated by obtaining the currently used bandwidth and the total bandwidth of the device through the network device. The average network connection time MNG indicates the average duration of the network connection. It is calculated by recording the start time and end time of the network connection through the network management system and taking the average value. The number of successful connections NTQ indicates the total number of successful network connections. It is obtained through the network application.

[0091] According to the data packet loss rate , jitter rate SWV, broadband utilization NGU, average network connection time MNG and number of successful connections NTQ are used to calculate the network attack risk index QCH. The formula is as follows:

[0092] ;

[0093] It should be noted that in this formula: the data packet loss rate, jitter rate, bandwidth utilization, average network connection time and number of successful connections are comprehensively considered to evaluate the risk of network attacks. Used to measure the impact of data packet loss on network attack risks, Used to assess the impact of jitter on network attack risks, It reflects the efficiency of network connection. If this ratio is large, it means that there are more successful connections within a relatively short average connection time, which usually indicates that the network connection is efficient and stable, and the risk of network attack is low. On the contrary, if this ratio is small, it means that the network connection is at a high risk. The three are multiplied by the broadband utilization rate NGU to obtain the network attack risk index QCH. The higher the value of QCH, the higher the risk of network attack; the lower the value of QCH, the more secure the network is and the lower the risk of attack.

[0094] Step 202: The method for calculating the account abnormal login index MHW and the access frequency deviation index VFD is:

[0095] User behavior data includes the number of off-site logins HYI, the number of logins during non-working hours RGK and the total number of logins KHY.

[0096] It should be noted that the number of off-site logins HYI indicates the number of times a user logs into an account in a non-local network environment. It is determined by recording the IP address information of each login through the account login system and comparing it with the account's commonly used IP address range; the number of non-working hours logins RGK indicates the number of times a user logs into an account during non-working hours. It is determined by recording the time of each login through the login system and comparing it with the preset working hours range; the total number of logins KHY indicates the total number of times a user logs into an account within a certain time range, including off-site logins, non-working hours logins and normal logins. It is obtained by directly counting the total number of user logins to their account within a specific time period through the login system.

[0097] The account abnormal login index MHW is calculated based on the number of off-site logins HYI, the number of non-working hours logins RGK and the total number of logins KHY. The formula is as follows:

[0098] ;

[0099] Among them, ω1 is The weight coefficient is determined according to the influence of the remote login frequency on the account abnormal login index MHW, and the value is 0.1~0.3; ω2 is The weight coefficient is determined according to the impact of the non-working hours login frequency on the account abnormal login index MHW, and the value is 0.7~0.9; and ω1+ω2=1.

[0100] It should be noted that in this formula: Indicates the frequency of remote logins; Exponential function. When the frequency of remote login increases, the value of this part will increase rapidly, emphasizing the impact of remote login on account abnormality. Indicates the frequency of non-working hours logins; It is a logarithmic function. When the frequency of non-working hours login increases, the value of this part will gradually increase, but the growth rate is slower than the exponential function, reflecting the impact of non-working hours login on account abnormalities. The abnormality of account login is evaluated by comprehensively considering the number of off-site logins and the number of non-working hours logins.

[0101] User behavior data also includes current access frequency TRW and historical access frequency XBN.

[0102] It should be noted that the current access frequency TRW indicates the number of times a user accesses a resource in the current time period, which is obtained through the system's access records; the historical access frequency XBN indicates the average access frequency of a user to a resource over a long period of time in the past, which is calculated by analyzing the system's access records in the past quarter.

[0103] The access frequency deviation index VFD is calculated based on the current access frequency TRW and the historical access frequency XBN, and the formula is as follows:

[0104] ;

[0105] Among them, γ1 is The weight coefficient is based on the absolute deviation ratio of the access frequency The influence degree of the access frequency deviation index VFD is determined, and the value is 0.2~0.4; γ2 is The weight coefficient is determined according to the influence of the square of the relative deviation of the access frequency on the access frequency deviation index VFD, and its value is 0.6~0.8; and γ1+γ2=1.

[0106] It should be noted that in this formula: Indicates the degree of deviation between the current access frequency and the historical access frequency. The larger the difference, the larger the value of this part; Through the square operation, the impact of the deviation degree is made more significant. The current access frequency is compared with the historical access frequency, and the absolute value ratio of the difference between the two and the square of the difference ratio are considered, and multiplied by the corresponding weight coefficient to comprehensively obtain a deviation index.

[0107] Step 203: The method for calculating the user data abnormality risk index DGU is:

[0108] The user data abnormality risk index DGU is calculated based on the account abnormal login index MHW and the access frequency deviation index VFD. The formula is as follows:

[0109] ;

[0110] Among them, µ1 is The weight coefficient is determined according to the influence of the account abnormal login index MHW on the user data abnormal risk index DGU, and the value is 0.1~0.4; µ2 is The weight coefficient is determined according to the influence of the access frequency deviation index VFD on the user data abnormal risk index DGU, and the value is 0.2~0.4; µ3 is The weight coefficient is determined according to the influence of the cross term of MHW and VFD on the user data abnormal risk index DGU, and its value is 0.4~0.5; and µ1+µ2+µ3=1.

[0111] It should be noted that in this formula: It is an exponential function. As MHW increases, the value of this part will increase rapidly, emphasizing the impact of the account abnormal login index on the risk index; It is a logarithmic function. As VFD increases, the value of this part will gradually increase, but the growth rate is slower than that of the exponential function, which reflects the impact of the access frequency deviation index on the risk index; It determines the degree of influence of the interaction between MHW and VFD on DGU, comprehensively considers the abnormal situation of account login and the deviation of access frequency to evaluate the abnormal risk of user data, and more accurately reflects the influence of different factors on risk indicators by introducing weight coefficients and nonlinear functions, so as to more effectively monitor and warn of abnormal risks of user data.

[0112] Step 204: The method for calculating the system security risk index JKH is:

[0113] The system log data includes the normal state duration TNS, the number of normal operations YSM, the number of failures NSQ, the total operation time of all states EME and the total number of all operations CZX recorded in the system log.

[0114] It should be noted that the normal state duration TNS indicates the cumulative time that the system is in normal operating state, which is obtained through the system's operation monitoring software; the number of normal operations YSM indicates the cumulative number of operations performed by the system in normal operating state, which is obtained through the system's operation log records; the number of faults NSQ indicates the cumulative number of faults that occur during the operation of the system, which is obtained through the system's fault alarm records; the total operating time of all states EME indicates the cumulative time that the system is in all operating states, including normal and fault states, which is obtained by recording the time of each system start and stop operation through the system's operation monitoring software, and cumulatively calculating; the total number of all operations CZX indicates the cumulative number of operations performed by the system in all operating states, which is obtained by comprehensively recording all operations in the system's operation log.

[0115] The system health index NDK is calculated based on the normal state duration TNS, the number of normal operations YSM, the number of failures NSQ, the total operation time of all states EME and the total number of all operations CZX. The formula is as follows:

[0116] ;

[0117] It should be noted that in this formula: Indicates the ratio of normal state duration to total operation duration. The higher this ratio is, the longer the system is in normal state, and the greater its contribution to the system health index. Indicates the ratio of normal operation times to total operation times. The higher this ratio is, the better the system performs in normal operation and the greater its contribution to the system health index. It indicates that the number of failures has a negative impact on the system health index. The more failures there are, the smaller this value is, which lowers the system health index. The health status of the system is evaluated by comprehensively considering the length of time the system is in normal state, the number of normal operations and the number of failures. These three factors are combined by taking the fourth root to obtain an index that reflects the overall health of the system. The higher the index, the healthier the system; the lower the index, the more problems there are in the system.

[0118] System log data also includes the attack frequency UPQ recorded in the system log i , Attack duration value SGL i And the total number of events is YXZ.

[0119] It should be noted that the attack frequency UPQ i Indicates the frequency of the i-th attack type, obtained through the network security monitoring system. Taking the distributed denial of service attack as an example, assuming that an online shopping website has suffered 6 attacks in the past 30 days, then 6 / 30 is the frequency of this attack type; the attack duration value SGL i It represents the duration of the i-th attack from the beginning to the end. Through the network monitoring system, the start time and end time of the attack are recorded, and the difference between the two is calculated to obtain the duration of the attack. The total number of events YXZ represents all network security events, including the total number of various attack events, which is obtained through the network security monitoring system.

[0120] UPQ based on attack frequency i , Attack duration value SGL i The attack threat index AMI is calculated based on the total number of events YXZ, and the formula is as follows:

[0121] ;

[0122] Among them, UPQ i is the occurrence frequency of the i-th attack type, SGL i is the duration of the attack of the i-th attack type, i is the serial number corresponding to different attack types, and its value is [1, n]; n is the number of attack types, and its value is a positive integer.

[0123] It should be noted that in this formula: the sum of the product of the frequency of occurrence of each attack type and the duration of the attack is divided by the total number of events YXZ to obtain the attack threat index AMI. The higher the index, the greater the attack threat faced by the network; the lower the index, the smaller the attack threat.

[0124] The system security risk index JKH is calculated based on the system health index NDK and the attack threat index AMI. The formula is as follows:

[0125] ;

[0126] Among them, α1 is The weight coefficient is based on The degree of influence on the system security risk index JKH is determined, and the value is 0.1~0.4; α2 is the weight coefficient of the attack threat index AMI, which is determined according to the degree of influence of the attack threat index AMI on the system security risk index JKH, and the value is 0.6~0.9; and α1+α2=1.

[0127] It should be noted that in this formula: 1-NDK represents the degree of system unhealthiness, which is then multiplied by the weight coefficient to obtain the impact value of the system health status on the system security risk. AMI is multiplied by its weight coefficient to obtain the impact value of the attack threat on the system security risk. The two are added together to obtain the system security risk index JKH. The higher the index value, the greater the security risk faced by the system, and the lower the index value, the relatively safer the system.

[0128] Step 205: The method for calculating the hardware network communication quality index HNQ, the hardware abnormal change rate IUY and the hardware performance health index HPI is:

[0129] The hardware status data includes the received normal communication data packets NTY, the sent total data packets MEB and the lost data packets MRE.

[0130] It should be noted that normal communication data packets NTY indicates the number of data packets normally received by the hardware during network communication, which is obtained through the network statistics function of the hardware device itself; total data packets sent MEB indicates the total number of data packets sent by the hardware during network communication, including data packets that arrive at the destination normally and data packets lost on the way, which is obtained through the network statistics function of the hardware device itself; lost data packets MRE indicates the number of data packets sent by the hardware during network communication but not correctly received, which is calculated by comparing the total number of data packets sent and the number of normal data packets received.

[0131] The hardware network communication quality index HNQ is calculated based on the received normal communication data packets NTY, the total sent data packets MEB and the lost data packets MRE, and the formula is as follows:

[0132] ;

[0133] It should be noted that in this formula: Indicates the ratio of received data packets, the numerator The contribution of the number of effectively received packets to the hardware network communication quality index after comprehensively considering the packet loss; It is an exponential function. When the number of lost packets increases, the value of this part will increase rapidly, reflecting the negative impact of lost packets on network communication quality. The denominator The influence of the total number of data packets sent and the number of lost data packets on the network communication quality is comprehensively considered; the hardware network communication quality index HNQ is obtained by dividing the numerator and the denominator by the square root, wherein the square root is to make the value of HNQ within a reasonable range. By taking the square root, the HNQ value can be prevented from being too large or too small, so that it can more smoothly reflect the changes in network communication quality; the whole formula comprehensively considers the number of normal communication data packets received, the total number of data packets sent, and the number of lost data packets to obtain an index reflecting the network communication quality. The higher the value of this index, the better the network communication quality; the lower the index, the worse the network communication quality.

[0134] The hardware status data also includes the current actual measured temperature value TUA, the reference temperature value NSE, the electromagnetic interference intensity value CSW and the vibration intensity value EBW.

[0135] It should be noted that the current actual measured temperature value TUA represents the temperature value actually measured by the hardware at the current moment, which is obtained through the built-in temperature sensor of the hardware; the reference temperature value NSE represents the reference temperature value when the hardware is working normally, which is obtained through the technical manual of the hardware device; the electromagnetic interference intensity value CSW represents the electromagnetic interference intensity in the environment where the hardware is located, which is measured around the hardware device by an electromagnetic interference test instrument; the vibration intensity value EBW represents the vibration intensity to which the hardware is subjected, which is obtained by measuring the vibration intensity to which the hardware is subjected through a vibration sensor.

[0136] The hardware abnormality change rate IUY is calculated based on the current actual measured temperature value TUA, the reference temperature value NSE, the electromagnetic interference intensity value CSW and the vibration intensity value EBW, and the formula is as follows:

[0137] ;

[0138] It should be noted that in this formula: It is the ratio of the absolute value of the difference between the current actual measured temperature value and the reference temperature value to the reference temperature value. It is the ratio of the electromagnetic interference intensity value to the vibration intensity value. The product of the two and then multiplying by 100% is the hardware abnormal change rate IUY. The higher the IUY value, the more the hardware is affected by abnormal factors and may face a higher risk of failure; the lower the IUY value, the more the hardware is in a relatively stable working state.

[0139] The hardware performance health index HPI is calculated based on the hardware abnormal change rate IUY, and the formula is as follows:

[0140] .

[0141] It should be noted that in this formula: Divide the square of the hardware abnormality change rate by 2 and take the negative square root. This value is used as the exponent for the power operation of e. Overall, when the hardware abnormality change rate is low, the HPI value will be close to 0, indicating that the hardware performance health is good; when the hardware abnormality change rate is high, the HPI value will be close to 1, indicating that the hardware performance health is poor. Through the above complex functional relationship, the hardware abnormality change rate is converted into an intuitive health index between 0 and 1, which is convenient for evaluating the performance health status of the hardware.

[0142] Step 206: The method for calculating the hardware failure risk indicator SMU is:

[0143] The hardware network communication quality index HNQ, the hardware abnormal change rate IUY and the hardware performance health index HPI are used to calculate the hardware failure risk index SMU. The formula is as follows:

[0144] ;

[0145] Among them, β1 is the weight coefficient of the hardware network communication quality index HNQ, which is determined according to the influence of the hardware network communication quality index HNQ on the hardware failure risk index SMU, and its value is 0.1~0.3; β2 is the weight coefficient of the hardware abnormal change rate IUY, which is determined according to the influence of the hardware abnormal change rate IUY on the hardware failure risk index SMU, and its value is 0.3~0.4; β3 is The weight coefficient is determined according to the impact of the unhealthy hardware performance on the hardware failure risk indicator SMU, and its value is 0.4~0.5; and β1+β2+β3=1.

[0146] It should be noted that in this formula: the hardware network communication quality index HNQ, the hardware abnormal change rate IUY and the hardware performance health index HPI are comprehensively considered to evaluate the risk of hardware failure. The higher the SMU value, the lower the risk of hardware failure. Conversely, the lower the SMU value, the greater the risk of hardware failure.

[0147] Step 207: The method for calculating the cybersecurity comprehensive risk index CFR is:

[0148] The network security comprehensive risk index CFR is calculated based on the network attack risk index QCH, the user data abnormality risk index DGU, the system security risk index JKH and the hardware failure risk index SMU. The formula is as follows:

[0149] .

[0150] It should be noted that in this formula: the indicators of network attack risk, user data abnormality risk, system security risk and application system health status are comprehensively considered. By adding these four risks and health indicators, a comprehensive score CFR is obtained. The higher the CFR, the higher the overall network security risk and the lower the security of the system and user data; the lower the CFR, the better the network security and the lower the risk to the system and user data.

[0151] When used, combine the contents of step 201 to step 207:

[0152] By processing network traffic data to obtain relevant indexes, we can detect network attack risks in advance, quickly discover account anomalies and access anomalies, ensure user data security, detect system vulnerabilities and threats, ensure system stability, and realize quantitative assessment of network security from multiple dimensions, providing strong support for accurately judging the network security situation.

[0153] Step 3: Preset a set of network security warning thresholds, compare the network security comprehensive risk index CFR with the network security warning threshold set, determine whether to trigger the warning mechanism based on the comparison results, and generate corresponding warning information.

[0154] Step 301: Preset a network security warning threshold set, the standards are as follows:

[0155] The network security warning threshold set collects historical network security data from the past period, calculates the network security comprehensive risk index CFR for the past period, screens out the lower 50% network security comprehensive risk index CFR and calculates its average and standard deviation. The average plus 2 times the standard deviation is used as the severe warning threshold HN; the average minus 2 times the standard deviation is used as the mild warning threshold HJ; among which the severe warning threshold HN>the mild warning threshold HJ.

[0156] Step 302: The method for determining whether the early warning mechanism is triggered is:

[0157] The network security warning threshold set includes a mild warning threshold HJ and a severe warning threshold HN; where HN>HJ;

[0158] Compare the network security comprehensive risk index CFR with the network security warning threshold set, and determine whether to trigger the warning mechanism based on the comparison results. The standards are as follows:

[0159] ;

[0160] Among them, corresponding warning information is generated according to the warning results.

[0161] It should be noted that in the normal level state, the warning information is: the network security is good, no obvious security threats are currently detected, the system is running stably, and network devices and applications are working normally within the security parameter range. It is recommended to continue to maintain regular network security monitoring and maintenance operations without taking additional protective measures;

[0162] In the case of a minor warning, the warning information is: there are certain security risks in the network, which need to be paid attention to. There may be a small amount of abnormal traffic, slight deviations in the operation behavior of individual users, or small fluctuations in the performance of some network devices. It is recommended that relevant network security personnel conduct further investigation and analysis of these abnormal situations and strengthen the monitoring of relevant areas in a targeted manner;

[0163] In severe warnings, the warning information is: the network faces serious security threats and is very likely to be under attack or have major security vulnerabilities. There may be a large amount of abnormal traffic, user data is at risk of being stolen on a large scale, and the performance of key network equipment has dropped sharply. It is necessary to immediately initiate an emergency response plan, conduct a comprehensive inspection and repair of the network, and implement strict security protection measures, such as blocking suspicious connections, isolating related equipment, etc. At the same time, notify relevant departments to coordinate the handling.

[0164] When used, combine the contents of step 301 to step 302:

[0165] By presetting a set of network security warning thresholds and comparing the comprehensive network security risk indicators with them to determine whether to trigger the warning mechanism, it is possible to quickly and accurately determine whether the network security situation is in a dangerous range and trigger the warning mechanism in a timely manner, effectively avoiding the expansion of security incidents caused by human judgment errors or delays, and enabling the network security maintenance team to quickly take targeted measures based on the warning information, greatly improving the timeliness and effectiveness of network security protection, ensuring that the network system can receive a quick response and proper handling when facing potential threats, and ensuring the stability and security of network operations.

[0166] On the other hand, the present invention also discloses a network security early warning system based on big data, including:

[0167] Data collection module, used to collect network traffic data, user behavior data, system log data and hardware status data of network devices;

[0168] A data calculation module is used to calculate the network attack risk index QCH based on network traffic data;

[0169] Calculate the account abnormal login index MHW and access frequency deviation index VFD based on user behavior data; calculate the user data abnormal risk index DGU based on the account abnormal login index MHW and access frequency deviation index VFD;

[0170] Calculate the system health index NDK and attack threat index AMI based on system log data, and further calculate the system security risk index JKH;

[0171] Calculate the hardware network communication quality index HNQ, hardware abnormality change rate IUY and hardware performance health index HPI based on the hardware status data; calculate the hardware failure risk index SMU based on the hardware network communication quality index HNQ, hardware abnormality change rate IUY and hardware performance health index HPI;

[0172] Calculate the network security comprehensive risk index CFR based on the network attack risk index QCH, user data abnormality risk index DGU, system security risk index JKH and hardware failure risk index SMU;

[0173] The judgment module is used to preset a set of network security warning thresholds, compare the network security comprehensive risk index CFR with the network security warning threshold set, determine whether to trigger the warning mechanism based on the comparison result, and generate corresponding warning information.

[0174] The above embodiments may be implemented in whole or in part by software, hardware, firmware or any other combination thereof. When implemented using software, the above embodiments may be implemented in whole or in part in the form of a computer program product. A person of ordinary skill in the art may appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein may be implemented in electronic hardware or in combination with computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution.

[0175] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0176] The above description is only a specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application.

Claims

1. A method for network security early warning based on big data, characterized by: The following steps are involved: Step 1: Collect network traffic data, user behavior data, system log data and hardware status data of network devices; Step 2: Calculate the network attack risk index QCH based on network traffic data; Calculate the account abnormal login index MHW and access frequency deviation index VFD based on user behavior data; Calculate the user data abnormality risk index DGU based on the account abnormal login index MHW and the access frequency deviation index VFD; Calculate the system health index NDK and attack threat index AMI based on system log data, and further calculate the system security risk index JKH; Calculate the hardware network communication quality index HNQ, hardware abnormality change rate IUY and hardware performance health index HPI based on the hardware status data; calculate the hardware failure risk index SMU based on the hardware network communication quality index HNQ, hardware abnormality change rate IUY and hardware performance health index HPI; Calculate the network security comprehensive risk index CFR based on the network attack risk index QCH, user data abnormality risk index DGU, system security risk index JKH and hardware failure risk index SMU; The method for calculating the network attack risk index QCH is: Network traffic data including packet loss rate , jitter rate SWV, broadband utilization NGU, average network connection time MNG and number of successful connections NTQ; According to the data packet loss rate , jitter rate SWV, broadband utilization NGU, average network connection time MNG and number of successful connections NTQ are used to calculate the network attack risk index QCH. The formula is as follows: ; The method for calculating the account abnormal login index MHW and the access frequency deviation index VFD is as follows: User behavior data includes the number of off-site logins HYI, the number of non-working hours logins RGK, and the total number of logins KHY; The account abnormal login index MHW is calculated based on the number of off-site logins HYI, the number of non-working hours logins RGK and the total number of logins KHY. The formula is as follows: ; Among them, ω1 is The weight coefficient is 0.1~0.3; ω2 is The weight coefficient is 0.7~0.9; and ω1+ω2=1; User behavior data also includes current access frequency TRW and historical access frequency XBN; The access frequency deviation index VFD is calculated based on the current access frequency TRW and the historical access frequency XBN, and the formula is as follows: ; Among them, γ1 is The weight coefficient is 0.2~0.4; γ2 is The weight coefficient is 0.6~0.8; and γ1+γ2=1; The hardware status data includes the received normal communication data packets NTY, the total data packets sent MEB and the lost data packets MRE; The hardware network communication quality index HNQ is calculated based on the received normal communication data packets NTY, the total sent data packets MEB and the lost data packets MRE, and the formula is as follows: ; The method for calculating the hardware network communication quality index HNQ, the hardware abnormal change rate IUY and the hardware performance health index HPI is as follows: The hardware status data also includes the current actual measured temperature value TUA, the reference temperature value NSE, the electromagnetic interference intensity value CSW and the vibration intensity value EBW; The hardware abnormality change rate IUY is calculated based on the current actual measured temperature value TUA, the reference temperature value NSE, the electromagnetic interference intensity value CSW and the vibration intensity value EBW, and the formula is as follows: ; The hardware performance health index HPI is calculated based on the hardware abnormal change rate IUY, and the formula is as follows: ; Step 3: Preset a network security warning threshold set, compare the network security comprehensive risk index CFR with the network security warning threshold set, determine whether to trigger the warning mechanism based on the comparison result, and generate corresponding warning information; The method for calculating the comprehensive cybersecurity risk index CFR is: The network security comprehensive risk index CFR is calculated based on the network attack risk index QCH, the user data abnormality risk index DGU, the system security risk index JKH and the hardware failure risk index SMU. The formula is as follows:

2. The method for network security early warning based on big data according to claim 1 is characterized by: The method for calculating the user data abnormal risk index DGU is: The user data abnormality risk index DGU is calculated based on the account abnormal login index MHW and the access frequency deviation index VFD. The formula is as follows: ; Among them, µ1 is The weight coefficient is 0.1~0.4, and µ2 is The weight coefficient is 0.2~0.4; µ3 is The weight coefficient is between 0.4 and 0.5, and µ1+µ2+µ3=1.

3. The method for network security early warning based on big data according to claim 2 is characterized by: The method for calculating the system security risk index JKH is: System log data includes the normal state duration TNS, the number of normal operations YSM, the number of failures NSQ, the total operation time of all states EME and the total number of all operations CZX recorded in the system log; The system health index NDK is calculated based on the normal state duration TNS, the number of normal operations YSM, the number of failures NSQ, the total operation time of all states EME and the total number of all operations CZX. The formula is as follows: ; System log data also includes the attack frequency UPQ recorded in the system log i , Attack duration value SGL i and the total number of events YXZ; UPQ based on attack frequency i , Attack duration value SGL i The attack threat index AMI is calculated based on the total number of events YXZ, and the formula is as follows: ; Among them, UPQ i is the occurrence frequency of the i-th attack type, SGL i is the duration of the attack of the i-th attack type, i is the serial number corresponding to different attack types, and its value is [1, n]; n is the number of attack types, and its value is a positive integer; The system security risk index JKH is calculated based on the system health index NDK and the attack threat index AMI. The formula is as follows: ; Among them, α1 is α1 is the weight coefficient of attack threat index AMI, which is between 0.1 and 0.4; α2 is the weight coefficient of attack threat index AMI, which is between 0.6 and 0.9; and α1+α2=1.

4. The method for network security early warning based on big data according to claim 1 is characterized by: The method for calculating the hardware failure risk indicator SMU is: The hardware network communication quality index HNQ, the hardware abnormal change rate IUY and the hardware performance health index HPI are used to calculate the hardware failure risk index SMU. The formula is as follows: ; Among them, β1 is the weight coefficient of the hardware network communication quality index HNQ, which ranges from 0.1 to 0.3; β2 is the weight coefficient of the hardware abnormal change rate IUY, which ranges from 0.3 to 0.4; β3 is The weight coefficient is between 0.4 and 0.5, and β1+β2+β3=1.

5. The method for network security early warning based on big data according to claim 1 is characterized by: The method for determining whether the early warning mechanism is triggered is: The network security warning threshold set includes a mild warning threshold HJ and a severe warning threshold HN; where HN>HJ; Compare the network security comprehensive risk index CFR with the network security warning threshold set, and determine whether to trigger the warning mechanism based on the comparison results. The standards are as follows: ; Among them, corresponding warning information is generated according to the warning results.

6. A network security early warning system based on big data, characterized by: include: Data collection module, used to collect network traffic data, user behavior data, system log data and hardware status data of network devices; A data calculation module is used to calculate the network attack risk index QCH based on network traffic data; Calculate the account abnormal login index MHW and access frequency deviation index VFD based on user behavior data; Calculate the user data abnormality risk index DGU based on the account abnormal login index MHW and the access frequency deviation index VFD; Calculate the system health index NDK and attack threat index AMI based on system log data, and further calculate the system security risk index JKH; Calculate the hardware network communication quality index HNQ, hardware abnormality change rate IUY and hardware performance health index HPI based on the hardware status data; calculate the hardware failure risk index SMU based on the hardware network communication quality index HNQ, hardware abnormality change rate IUY and hardware performance health index HPI; Calculate the network security comprehensive risk index CFR based on the network attack risk index QCH, user data abnormality risk index DGU, system security risk index JKH and hardware failure risk index SMU; The method for calculating the network attack risk index QCH is: Network traffic data including packet loss rate , jitter rate SWV, broadband utilization NGU, average network connection time MNG and number of successful connections NTQ; According to the packet loss rate , jitter rate SWV, broadband utilization NGU, average network connection time MNG and number of successful connections NTQ are used to calculate the network attack risk index QCH. The formula is as follows: ; The method for calculating the account abnormal login index MHW and the access frequency deviation index VFD is as follows: User behavior data includes the number of off-site logins HYI, the number of non-working hours logins RGK, and the total number of logins KHY; The account abnormal login index MHW is calculated based on the number of off-site logins HYI, the number of non-working hours logins RGK and the total number of logins KHY. The formula is as follows: ; Among them, ω1 is The weight coefficient is 0.1~0.3; ω2 is The weight coefficient is 0.7~0.9; and ω1+ω2=1; User behavior data also includes current access frequency TRW and historical access frequency XBN; The access frequency deviation index VFD is calculated based on the current access frequency TRW and the historical access frequency XBN, and the formula is as follows: ; Among them, γ1 is The weight coefficient is 0.2~0.4; γ2 is The weight coefficient is 0.6~0.8; and γ1+γ2=1; The hardware status data includes the received normal communication data packets NTY, the total data packets sent MEB and the lost data packets MRE; The hardware network communication quality index HNQ is calculated based on the received normal communication data packets NTY, the total sent data packets MEB and the lost data packets MRE, and the formula is as follows: ; The method for calculating the hardware network communication quality index HNQ, the hardware abnormal change rate IUY and the hardware performance health index HPI is as follows: The hardware status data also includes the current actual measured temperature value TUA, the reference temperature value NSE, the electromagnetic interference intensity value CSW and the vibration intensity value EBW; The hardware abnormality change rate IUY is calculated based on the current actual measured temperature value TUA, the reference temperature value NSE, the electromagnetic interference intensity value CSW and the vibration intensity value EBW, and the formula is as follows: ; The hardware performance health index HPI is calculated based on the hardware abnormal change rate IUY, and the formula is as follows: ; The judgment module is used to preset a network security warning threshold set, compare the network security comprehensive risk index CFR with the network security warning threshold set, determine whether to trigger the warning mechanism based on the comparison result, and generate corresponding warning information; The method for calculating the comprehensive cybersecurity risk index CFR is: The network security comprehensive risk index CFR is calculated based on the network attack risk index QCH, the user data abnormality risk index DGU, the system security risk index JKH and the hardware failure risk index SMU. The formula is as follows:

Citation Information

Patent Citations

  • Industrial control network dynamic defense method and system based on endogenous security

    CN117811783A

  • Network security risk control method and device based on cloud computing and electronic equipment

    CN119276577A