A vector-based network security operation indicator measurement method

Through the vector-based network security operation index measurement method, the problems of insufficient network security detection accuracy and lack of abnormal impact assessment in the prior art are solved, efficient detection and quantitative evaluation of potential abnormalities in network transmission data are realized, and the intelligence and response efficiency of network security operations are improved.

CN119675983BActive Publication Date: 2025-05-09BEIJING HUIERTE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510173454.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-17
Publication Date
2025-05-09
Estimated Expiration
2045-02-17

AI Technical Summary

Technical Problem

The prior art is difficult to accurately detect data fluctuations and abnormalities in network security, and there is a lack of quantitative evaluation of the impact of abnormalities, resulting in a decrease in the accuracy and reliability of detection results.

Method used

A vector-based network security operation index measurement method is used to collect network transmission data, calculate data fluctuations, filter abnormal data, analyze the correlation between abnormal types, build feature vectors and input neural network models, generate abnormal situation coefficients, and conduct network early warning.

Benefits of technology

It improves the accuracy of detecting potential anomalies in network transmission data, avoids misjudgment caused by short-term fluctuations, deeply explores the logical relationship between multiple anomalies, realizes efficient identification of complex correlation attack behaviors, and conducts quantitative evaluation of the impact of abnormal events, improving the intelligence and response efficiency of network security operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119675983B_ABST
    Figure CN119675983B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of network security technology, and discloses a vector-based network security operation indicator measurement method, including: collecting network transmission data to establish a data group to be analyzed, and obtaining data fluctuation values; comparing and screening the data fluctuation values ​​with fluctuation thresholds, and performing abnormal value calculation on the screened data to determine abnormal data; analyzing the correlation between abnormal types, when there is data with a correlation greater than the correlation threshold between all abnormal types, extracting the abnormal types of the relevant groups to establish feature vectors, inputting the feature vectors into a pre-established neural network model, and obtaining abnormal situation types; extracting abnormal values ​​of the relevant groups to determine proportional vectors, and obtaining abnormal situation coefficients according to the proportional vectors and abnormal values; and performing network early warning according to the abnormal situation coefficients and abnormal situation types. Based on the dual analysis of abnormal situation types and abnormal situation coefficients, the present application improves the intelligence and response efficiency of network security operations.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a vector-based network security operation indicator measurement method. Background Art

[0002] With the rapid development of information technology, network security has become an important issue that cannot be ignored in the modern information society. The complexity and diversity of network attacks are gradually increasing, and traditional network security protection methods are difficult to effectively deal with the increasingly severe security threats. In order to ensure the stability and security of the network system, it is particularly important to analyze network transmission data in real time and evaluate its security situation.

[0003] Existing methods usually do not adequately analyze the fluctuation characteristics of data, and are prone to misjudging short-term fluctuations as anomalies, or ignoring potential abnormal patterns, resulting in reduced accuracy and reliability of detection results. Most detection methods find it difficult to comprehensively analyze the correlation between multiple types of anomalies, resulting in the inability to accurately identify the logical relationship between multiple attack behaviors, thereby affecting the depth of detection. For detected abnormal events, there is a lack of indicator measurement methods to quantify and evaluate the impact of the anomalies, resulting in a lack of pertinence in subsequent warning or response strategies.

[0004] Therefore, it is necessary to design a vector-based network security operation indicator measurement method to solve the problems existing in current technology. Summary of the invention

[0005] In view of this, the present invention proposes a vector-based network security operation indicator measurement method, which aims to solve the current problems of insufficient accuracy of data fluctuation and anomaly detection, limited correlation analysis capabilities, and lack of quantitative support for anomaly response strategies.

[0006] The present invention proposes a vector-based network security operation indicator measurement method, including:

[0007] Collecting network transmission data, establishing a data group to be analyzed according to the network transmission data, wherein the data group to be analyzed includes the network transmission data at the current moment and the network transmission data at the previous moment, and obtaining a data fluctuation value according to the data group to be analyzed;

[0008] Compare and screen the data fluctuation value with the fluctuation threshold, and perform outlier calculation on the screened data to determine abnormal data, wherein the abnormal data includes abnormal value and abnormal type;

[0009] Analyze the correlation between the abnormal types, and when there is data with a correlation greater than a correlation threshold between all the abnormal types, extract the abnormal types of the related group to establish a feature vector, and input the feature vector into a pre-established neural network model to obtain the abnormal situation type;

[0010] After obtaining the abnormal situation type, extracting the abnormal value of the related group, determining a proportional vector according to the abnormal value, and obtaining an abnormal situation coefficient according to the proportional vector and the abnormal value;

[0011] A network warning is performed according to the abnormal situation coefficient and the abnormal situation type.

[0012] Furthermore, when the data fluctuation value is compared with the fluctuation threshold value for screening, the fluctuation threshold value is calculated by the following formula:

[0013]

[0014] Among them, Z represents the fluctuation threshold, Represents the mean of historical fluctuation values, represents the standard deviation of historical fluctuation values, and k represents the adjustment factor;

[0015]

[0016]

[0017]

[0018] Where Wt represents the data fluctuation value, Indicates the network transmission data at the current moment. It represents the network transmission data at the previous moment, and N represents the number of historical fluctuation values.

[0019] Furthermore, when comparing and screening the data fluctuation value with the fluctuation threshold, it also includes:

[0020] Compare the data fluctuation value with the fluctuation threshold value and eliminate small fluctuation data;

[0021] When the data fluctuation value is greater than the fluctuation threshold, retaining the fluctuation data;

[0022] When the data fluctuation value is less than or equal to the fluctuation threshold, the fluctuation data is eliminated.

[0023] Furthermore, when performing outlier value calculation on the filtered data to determine the abnormal data, it includes:

[0024] Calculate the outlier value of each filtered data based on the isolation forest model;

[0025]

[0026] Where s(a) represents the outlier of data a, E(h(a)) represents the average path length of data a in all isolated trees in the isolation forest, and c(n) represents the average path length used to standardize the path length;

[0027] When the outlier value of the filtered data is greater than 0.8, the data is determined to be outlier data.

[0028] Further, when analyzing the correlation between the abnormal types, it includes:

[0029] Collecting historical abnormal situation data, the historical abnormal situation data including historical abnormality types and historical abnormality values ​​for each historical abnormal situation, and analyzing correlations between the abnormality types according to the historical abnormality types;

[0030]

[0031] in, ≥0, which is 0 if and only if X is independent of Y. p(x, y) represents the joint probability distribution, which indicates the probability of X=x and Y=y occurring simultaneously. p(x) and p(y) represent the marginal probability distribution, which indicate the probabilities of X=x and Y=y respectively. X represents X-type abnormal data, Y represents Y-type abnormal data, x represents the xth abnormal data among X-type abnormal data, and y represents the yth abnormal data among Y-type abnormal data.

[0032] Furthermore, when analyzing the correlation between the abnormal types, it also includes:

[0033] when When it is greater than the correlation threshold, it is determined that the X-type abnormal data is related to the Y-type abnormal data; when When it is less than or equal to the correlation threshold, it is determined that the X-type abnormal data is not correlated with the Y-type abnormal data;

[0034] When the correlations among all the abnormal types are less than or equal to the correlation threshold, an early warning is issued according to each abnormal type and the corresponding abnormal value;

[0035] When there is data with correlation greater than a correlation threshold between all the abnormal types, the abnormal types of the related group are extracted to establish a feature vector.

[0036] Furthermore, before inputting the feature vector into a pre-established neural network model to obtain the abnormal situation type, the method further includes:

[0037] constructing a historical data set based on the historical abnormal situation data;

[0038] Sampling the historical data set according to a preset ratio to obtain a training subset and a test subset;

[0039] Acquire a pre-selected neural network model, perform iterative training on the neural network model according to the training subset, evaluate the iteratively trained neural network model according to the test subset, and obtain an abnormal situation type analysis model;

[0040] The feature vector is input into the abnormal situation type analysis model to obtain the abnormal situation type.

[0041] Furthermore, before inputting the feature vector into a pre-established neural network model to obtain the abnormal situation type, the method further includes:

[0042] Determine whether to stop iterative training based on the evaluation value;

[0043] If the evaluation value of the neural network model after the current iterative training is less than the evaluation value of the neural network model after the previous iterative training, the amplitude of the change of the neural network model in the gradient direction is reduced, and iterative training is continued until the preset number of iterations is reached;

[0044] If the evaluation value of the neural network model after the current iterative training is greater than or equal to the evaluation value of the neural network model after the previous iterative training, the iterative training is stopped.

[0045] Further, extracting the abnormal value of the related group, determining the proportional vector according to the abnormal value, and obtaining the abnormal situation coefficient according to the proportional vector and the abnormal value, includes:

[0046] The abnormal values ​​of the related group are normalized, and the proportional vector is obtained according to the normalized data. The proportional vector is calculated by the following formula:

[0047]

[0048] Wherein, Bi represents the proportion vector of the i-th abnormal value in the related group, w represents the standard deviation of the related group; Ji represents the i-th abnormal value in the related group;

[0049] When obtaining the abnormal situation coefficient according to the proportion vector and the abnormal value, it includes:

[0050]

[0051] Among them, C represents the abnormality coefficient, and M represents the number of abnormal values ​​in the relevant group.

[0052] Furthermore, when a network early warning is performed according to the abnormal situation coefficient and the abnormal situation type, it includes:

[0053] The abnormal situation coefficient is compared with preset abnormal situation data, and the warning level is determined according to the comparison result. The warning level is proportional to the abnormal situation coefficient.

[0054] Compared with the prior art, the beneficial effects of the present invention are as follows: by introducing a calculation and screening mechanism for data fluctuation values, the accuracy of detecting potential anomalies in network transmission data is improved, misjudgment caused by short-term fluctuations is avoided, and hidden abnormal patterns are effectively captured. At the same time, by using the correlation analysis between abnormal types, the logical relationship between multiple anomalies is deeply explored, the abnormal types of related groups are extracted and feature vectors are constructed, and efficient identification of complex related attack behaviors is achieved. By inputting the feature vector into a pre-trained neural network model, the specific type of abnormal situation is accurately identified, and the ratio vector is calculated in combination with the abnormal value, and the abnormal situation coefficient is further generated to achieve a quantitative assessment of the impact of abnormal events. Based on the dual analysis of abnormal situation types and abnormal situation coefficients, the intelligence and response efficiency of network security operations are improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the detailed description of the preferred embodiments below. The accompanying drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present invention. Moreover, the same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings:

[0056] Figure 1 A flowchart of a vector-based network security operation indicator measurement method provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0057] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments described herein. On the contrary, these embodiments are provided in order to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art. It should be noted that, in the absence of conflict, the embodiments of the present invention and the features described in the embodiments can be combined with each other. The present invention will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.

[0058] In some embodiments of the present application, see Figure 1 As shown, a vector-based cybersecurity operation indicator measurement method includes:

[0059] S100: Collect network transmission data, establish a data group to be analyzed according to the network transmission data, the data group to be analyzed includes the network transmission data at the current moment and the network transmission data at the previous moment, and obtain a data fluctuation value according to the data group to be analyzed.

[0060] S200: Compare and screen the data fluctuation value with the fluctuation threshold, and perform outlier calculation on the screened data to determine abnormal data, where the abnormal data includes abnormal value and abnormal type.

[0061] S300: Analyze the correlation between abnormal types. When there is data with correlation greater than a correlation threshold between all abnormal types, extract the abnormal types of the related group to establish a feature vector, and input the feature vector into a pre-established neural network model to obtain the abnormal situation type.

[0062] S400: After obtaining the abnormal situation type, extract the abnormal value of the relevant group, determine the proportional vector according to the abnormal value, and obtain the abnormal situation coefficient according to the proportional vector and the abnormal value.

[0063] S500: Perform network warning according to the abnormal situation coefficient and the abnormal situation type.

[0064] Specifically, in S100, network transmission data is collected, including transmission data at the current moment and the previous moment, and a data group to be analyzed is constructed. By analyzing the feature changes in the data group, a data fluctuation value is calculated. The data fluctuation value reflects the dynamic changes of network transmission data between different time nodes, and is used to capture the potential abnormal characteristics of the network state. In S200, the data fluctuation value is compared with a pre-set fluctuation threshold to filter out data with large fluctuations. The filtered data is further subjected to abnormal value calculation to determine the specific abnormal data. The detection results of the abnormal data include the numerical characteristics of the abnormality and the specific type of the abnormality, which helps the subsequent analysis to lock the source of the problem. In S300, the correlation between the detected abnormal types is deeply analyzed. When it is found that the correlation between the abnormal types is higher than the set correlation threshold, the related abnormal types are extracted as a group, and a feature vector is constructed based on the abnormal features of the group. The feature vector represents the joint characteristics between these abnormalities and is input into a pre-trained neural network model. Through model calculation, the specific type of the abnormal situation is finally output. In S400, after determining the type of abnormal situation, the abnormal values ​​in the related group are further analyzed to calculate the proportion vector. The ratio vector is used to quantify the relative contribution of different anomalies, and the anomaly coefficient is calculated in combination with the anomaly value. The anomaly coefficient is used to describe the impact of the current abnormal event on the overall network security situation. In S500, the corresponding network warning information is generated according to the type of abnormal situation and the abnormal situation coefficient. The warning information includes the type, severity and impact range of the abnormality, providing a decision-making basis for security operators, so that targeted protection measures can be taken in a timely manner.

[0065] It is understandable that by introducing the data fluctuation value screening mechanism, the sensitivity to abnormal features is effectively improved, misjudgment caused by short-term fluctuations or data noise is avoided, and the reliability of the detection results is ensured. By using correlation analysis and feature vector construction, it is possible to capture complex multi-abnormal correlation characteristics and accurately identify joint attack behaviors. In addition, by combining the calculation of proportional vectors and abnormal situation coefficients, a quantitative assessment of the degree of abnormal impact is achieved, making the early warning information more comprehensive. Compared with traditional detection methods, it not only improves the accuracy of anomaly detection, but also provides quantifiable security situation analysis indicators, enhancing the intelligence level and response efficiency of network security operations.

[0066] In some embodiments of the present application, when the data fluctuation value is compared and screened with the fluctuation threshold, the fluctuation threshold is calculated by the following formula:

[0067]

[0068] Among them, Z represents the fluctuation threshold, Represents the mean of historical fluctuation values, represents the standard deviation of historical fluctuation values, and k represents the adjustment factor.

[0069]

[0070]

[0071]

[0072] Where Wt represents the data fluctuation value, Indicates the network transmission data at the current moment. It represents the network transmission data at the previous moment, and N represents the number of historical fluctuation values.

[0073] It is understandable that by dynamically calculating the fluctuation threshold and combining the statistical characteristics of historical fluctuation values ​​(mean and standard deviation), the fluctuation threshold can be adaptively adjusted, which improves the sensitivity and accuracy of fluctuation screening. Compared with the fixed threshold method, it can dynamically change according to different network environments, reduce the false alarm rate and missed alarm rate, make anomaly detection more robust, and further improve the accuracy and efficiency of network anomaly screening.

[0074] In some embodiments of the present application, when comparing and screening the data fluctuation value with the fluctuation threshold, it also includes:

[0075] Compare the data fluctuation value with the fluctuation threshold and eliminate small fluctuation data.

[0076] When the data fluctuation value is greater than the fluctuation threshold, the fluctuation data is retained.

[0077] When the data fluctuation value is less than or equal to the fluctuation threshold, the fluctuation data is eliminated.

[0078] In some embodiments of the present application, when performing outlier calculation on the filtered data to determine the abnormal data, it includes: calculating the outlier value of each filtered data based on the isolation forest model.

[0079]

[0080] Where s(a) represents the outlier of data a, E(h(a)) represents the average path length of data a in all isolated trees in the isolation forest, and c(n) represents the average path length used to normalize the path length.

[0081] When the outlier value of the filtered data is greater than 0.8, the data is determined to be outlier data.

[0082] Specifically, when the data fluctuation value is greater than the fluctuation threshold, the fluctuation data is retained, which may have abnormal characteristics. When the data fluctuation value is less than or equal to the fluctuation threshold, the fluctuation data is removed, and its change is not significant. Isolation Forest is an unsupervised anomaly detection algorithm based on a tree model. It generates a series of isolation trees (Isolation Trees) by recursively and randomly dividing the data to quantify the "isolation" of each data point. Data points with higher isolation are considered to be abnormal data. s(a) represents the abnormal value of data a, and the value range is [0,1]. E(h(a)) represents the average path length of data a in all isolation trees, indicating the difficulty of being divided. c(n) is a coefficient used to standardize the path length, which depends on the size of the data set n. The closer the abnormal value s(a) of the data is to 1, the easier it is to be isolated (that is, the more abnormal it is).

[0083] It is understandable that the accuracy and robustness of anomaly detection are improved by introducing a dual screening mechanism (fluctuation value screening and isolation forest outlier calculation). Eliminating small fluctuation data reduces the interference of noise, allowing subsequent calculations to focus more on data with significant changes. The isolation forest model uses its efficient processing capabilities for multidimensional data and accurate capture of anomalies to ensure the reliability of detection results. Compared with traditional anomaly detection methods, it reduces the false alarm rate and missed alarm rate, and improves the ability to identify complex abnormal patterns.

[0084] In some embodiments of the present application, analyzing the correlation between abnormality types includes: collecting historical abnormality data, the historical abnormality data includes historical abnormality types and historical abnormality values ​​in each historical abnormal situation, and analyzing the correlation between abnormality types according to the historical abnormality types.

[0085]

[0086] in, ≥0, which is 0 if and only if X is independent of Y. p(x, y) represents the joint probability distribution, which indicates the probability of X=x and Y=y occurring simultaneously. p(x) and p(y) represent the marginal probability distribution, which indicate the probabilities of X=x and Y=y respectively. X represents X-type abnormal data, Y represents Y-type abnormal data, x represents the xth abnormal data among X-type abnormal data, and y represents the yth abnormal data among Y-type abnormal data.

[0087] In some embodiments of the present application, when analyzing the correlation between abnormal types, it also includes: When it is greater than the correlation threshold, it is determined that the X-type abnormal data is related to the Y-type abnormal data. When the correlation is less than or equal to the correlation threshold, it is determined that the abnormal data of type X is not correlated with the abnormal data of type Y. When the correlation between all abnormal types is less than or equal to the correlation threshold, an early warning is issued according to each abnormal type and the corresponding abnormal value. When there is data with a correlation greater than the correlation threshold among all abnormal types, the abnormal types of the related group are extracted to establish a feature vector.

[0088] It is understandable that the information interconnectivity formula realizes the calculation of the correlation between anomaly types, captures the correlation patterns of various anomaly types in complex networks, and provides a basis for the subsequent construction of related groups and feature vectors. Compared with traditional independent analysis methods, it can more comprehensively identify related abnormal events and improve the accuracy of multi-dimensional anomaly detection. In addition, by combining the correlation threshold to dynamically adjust the analysis strategy, it can not only process unrelated anomaly types separately, but also efficiently identify and analyze highly related anomaly groups, enhancing the depth and intelligence level of network anomaly warning.

[0089] In some embodiments of the present application, before inputting the feature vector into a pre-established neural network model to obtain the abnormal situation type, the method further includes:

[0090] Build a historical data set based on historical anomaly data.

[0091] The historical data set is sampled according to the preset ratio to obtain the training subset and the test subset.

[0092] A pre-selected neural network model is obtained, and the neural network model is iteratively trained according to the training subset, and the iteratively trained neural network model is evaluated according to the test subset to obtain an abnormal situation type analysis model.

[0093] The feature vector is input into the abnormal situation type analysis model to obtain the abnormal situation type.

[0094] In some embodiments of the present application, before inputting the feature vector into a pre-established neural network model to obtain the abnormal situation type, it also includes: judging whether to stop iterative training based on the evaluation value.

[0095] Specifically, if the evaluation value of the neural network model after the current iterative training is less than the evaluation value of the neural network model after the previous iterative training, the amplitude of the change of the neural network model in the gradient direction is reduced, and the iterative training is continued until the preset number of iterations is reached. If the evaluation value of the neural network model after the current iterative training is greater than or equal to the evaluation value of the neural network model after the previous iterative training, the iterative training is stopped.

[0096] It is understandable that by constructing historical data sets, dividing training sets and test sets, and dynamically adjusting the iteration process, the stability and accuracy of the neural network model are improved. Compared with the traditional static training method, the learning rate can be dynamically adjusted according to the model evaluation value to avoid overfitting and insufficient training problems, while saving computing resources and improving training efficiency. The optimized neural network model can identify the type of abnormal situation and provide strong technical support for network security early warning, thereby achieving more intelligent, efficient and reliable anomaly detection and analysis.

[0097] In some embodiments of the present application, extracting abnormal values ​​of the related groups and determining a proportional vector according to the abnormal values, and obtaining an abnormal situation coefficient according to the proportional vector and the abnormal values ​​include:

[0098] The abnormal values ​​of the relevant groups are normalized, and the proportional vector is obtained according to the normalized data. The proportional vector is calculated by the following formula:

[0099]

[0100] Among them, Bi represents the proportion vector of the i-th abnormal value in the relevant group, w represents the standard deviation of the relevant group, and Ji represents the i-th abnormal value in the relevant group.

[0101] When obtaining the abnormal situation coefficient according to the ratio vector and the abnormal value, it includes:

[0102]

[0103] Among them, C represents the abnormality coefficient, and M represents the number of abnormal values ​​in the relevant group.

[0104] In some embodiments of the present application, when a network warning is performed based on an abnormal situation coefficient and an abnormal situation type, it includes: comparing the abnormal situation coefficient with preset abnormal situation data, determining a warning level based on the comparison result, and the warning level is proportional to the abnormal situation coefficient.

[0105] It is understandable that by normalizing the abnormal values ​​of the relevant groups and establishing a proportional vector, the interference of data dimension differences on the calculation of the abnormal situation coefficient is eliminated, thereby ensuring the fairness of the quantitative results. By comprehensively considering the weight relationship between the proportional vector and the original abnormal value, the generated abnormal situation coefficient is more accurate and representative, providing a quantitative basis for the evaluation of abnormal events. In addition, dynamic early warning based on the abnormal situation coefficient can adjust the early warning level in time according to the actual degree of abnormality, achieving accurate early warning and efficient response. It significantly improves the accuracy and intelligence level of network security situation awareness.

[0106] In the above embodiments, by introducing the calculation and screening mechanism of data fluctuation values, the accuracy of detecting potential anomalies in network transmission data is improved, misjudgment caused by short-term fluctuations is avoided, and hidden abnormal patterns are effectively captured. At the same time, by using the correlation analysis between abnormal types, the logical relationship between multiple anomalies is deeply explored, the abnormal types of related groups are extracted and the feature vectors are constructed, so as to realize the efficient identification of complex related attack behaviors. By inputting the feature vector into the pre-trained neural network model, the specific type of abnormal situation is accurately identified, and the ratio vector is calculated in combination with the abnormal value, and the abnormal situation coefficient is further generated to realize the quantitative evaluation of the impact of abnormal events. Based on the dual analysis of abnormal situation type and abnormal situation coefficient, the intelligence and response efficiency of network security operations are improved.

[0107] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.

[0108] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0109] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0110] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0111] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.

Claims

1. A vector-based network security operation indicator measurement method, characterized in that: include: Collecting network transmission data, establishing a data group to be analyzed according to the network transmission data, wherein the data group to be analyzed includes the network transmission data at the current moment and the network transmission data at the previous moment, and obtaining a data fluctuation value according to the data group to be analyzed; Compare and screen the data fluctuation value with the fluctuation threshold, and perform outlier calculation on the screened data to determine abnormal data, wherein the abnormal data includes abnormal value and abnormal type; Analyze the correlation between the abnormal types, and when there is data with a correlation greater than a correlation threshold between all the abnormal types, extract the abnormal types of the related group to establish a feature vector, and input the feature vector into a pre-established neural network model to obtain the abnormal situation type; After obtaining the abnormal situation type, extracting the abnormal value of the related group, determining a proportional vector according to the abnormal value, and obtaining an abnormal situation coefficient according to the proportional vector and the abnormal value; A network warning is performed according to the abnormal situation coefficient and the abnormal situation type.

2. The vector-based network security operation indicator measurement method according to claim 1 is characterized in that: When the data fluctuation value is compared with the fluctuation threshold value for screening, the fluctuation threshold value is calculated by the following formula: Among them, Z represents the fluctuation threshold, Represents the mean of historical fluctuation values, represents the standard deviation of historical fluctuation values, and k represents the adjustment factor; Where Wt represents the data fluctuation value, Indicates the network transmission data at the current moment. It represents the network transmission data at the previous moment, and N represents the number of historical fluctuation values.

3. The vector-based network security operation indicator measurement method according to claim 2 is characterized in that: When comparing and screening the data fluctuation value with the fluctuation threshold, it also includes: Compare the data fluctuation value with the fluctuation threshold value and eliminate small fluctuation data; When the data fluctuation value is greater than the fluctuation threshold, retaining the fluctuation data; When the data fluctuation value is less than or equal to the fluctuation threshold, the fluctuation data is eliminated.

4. The vector-based network security operation indicator measurement method according to claim 3 is characterized in that: When performing outlier calculation on the filtered data to determine abnormal data, it includes: Calculate the outlier value of each filtered data based on the isolation forest model; Where s(a) represents the outlier of data a, E(h(a)) represents the average path length of data a in all isolated trees in the isolation forest, and c(n) represents the average path length used to standardize the path length; When the outlier value of the filtered data is greater than 0.8, the data is determined to be outlier data.

5. The vector-based network security operation indicator measurement method according to claim 4 is characterized in that: When analyzing the correlation between the anomaly types, it includes: Collecting historical abnormal situation data, the historical abnormal situation data including historical abnormality types and historical abnormality values ​​for each historical abnormal situation, and analyzing correlations between the abnormality types according to the historical abnormality types; in, ≥0, which is 0 if and only if X is independent of Y. p(x, y) represents the joint probability distribution, which indicates the probability of X=x and Y=y occurring simultaneously. p(x) and p(y) represent the marginal probability distribution, which indicate the probabilities of X=x and Y=y respectively. X represents X-type abnormal data, Y represents Y-type abnormal data, x represents the xth abnormal data among X-type abnormal data, and y represents the yth abnormal data among Y-type abnormal data.

6. The vector-based network security operation indicator measurement method according to claim 5 is characterized in that: When analyzing the correlation between the abnormal types, it also includes: when When it is greater than the correlation threshold, it is determined that the X-type abnormal data is related to the Y-type abnormal data; when When it is less than or equal to the correlation threshold, it is determined that the X-type abnormal data is not correlated with the Y-type abnormal data; When the correlations among all the abnormal types are less than or equal to the correlation threshold, an early warning is issued according to each abnormal type and the corresponding abnormal value; When there is data with correlation greater than a correlation threshold between all the abnormal types, the abnormal types of the related group are extracted to establish a feature vector.

7. The vector-based network security operation indicator measurement method according to claim 6 is characterized in that: Before inputting the feature vector into a pre-established neural network model to obtain the abnormal situation type, the method further includes: constructing a historical data set based on the historical abnormal situation data; Sampling the historical data set according to a preset ratio to obtain a training subset and a test subset; Acquire a pre-selected neural network model, perform iterative training on the neural network model according to the training subset, evaluate the iteratively trained neural network model according to the test subset, and obtain an abnormal situation type analysis model; The feature vector is input into the abnormal situation type analysis model to obtain the abnormal situation type.

8. The vector-based network security operation indicator measurement method according to claim 7 is characterized in that: Before inputting the feature vector into a pre-established neural network model to obtain the abnormal situation type, the method further includes: Determine whether to stop iterative training based on the evaluation value; If the evaluation value of the neural network model after the current iterative training is less than the evaluation value of the neural network model after the previous iterative training, the amplitude of the change of the neural network model in the gradient direction is reduced, and iterative training is continued until the preset number of iterations is reached; If the evaluation value of the neural network model after the current iterative training is greater than or equal to the evaluation value of the neural network model after the previous iterative training, the iterative training is stopped.

9. The vector-based network security operation indicator measurement method according to claim 8 is characterized in that: Extracting the abnormal value of the related group, determining a proportional vector according to the abnormal value, and obtaining an abnormal situation coefficient according to the proportional vector and the abnormal value, includes: The abnormal values ​​of the related group are normalized, and the proportional vector is obtained according to the normalized data. The proportional vector is calculated by the following formula: Wherein, Bi represents the proportion vector of the i-th abnormal value in the related group, w represents the standard deviation of the related group; Ji represents the i-th abnormal value in the related group; When obtaining the abnormal situation coefficient according to the proportion vector and the abnormal value, it includes: Among them, C represents the abnormality coefficient, and M represents the number of abnormal values ​​in the relevant group.

10. The vector-based network security operation indicator measurement method according to claim 9 is characterized in that: When a network warning is issued according to the abnormal situation coefficient and the abnormal situation type, it includes: The abnormal situation coefficient is compared with preset abnormal situation data, and the warning level is determined according to the comparison result. The warning level is proportional to the abnormal situation coefficient.

Citation Information

Patent Citations

  • Broadband detection method and device, electronic equipment and storage medium

    CN111934954A

  • Computer-implemented method, computer program product and system for data analysis

    CN112639834A