A network security protection method, device, equipment, medium and product

By constructing a linear regression model and a Poisson distribution model for network security, and combining historical user data and a blacklist database, we have achieved efficient prediction and real-time protection of network security incidents. This solves the problem of predicting vulnerable users in network security protection and improves protection efficiency and accuracy.

CN119728173BActive Publication Date: 2026-02-10CHINA TELECOM CLOUD TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411752543.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-02
Publication Date
2026-02-10
Estimated Expiration
2044-12-02

AI Technical Summary

Technical Problem

With the development of internet technology, misleading information and cyberattacks are becoming increasingly complex, especially for teenagers and the elderly, making cybersecurity protection more difficult. Existing technologies are struggling to effectively and practically predict and protect against cybersecurity incidents.

Method used

By constructing a linear regression model and a Poisson distribution model for cybersecurity, the probability of cybersecurity events is predicted based on historical user data. The cybersecurity blacklist database is used for filtering and analysis. The Poisson distribution model is combined with time segmentation and probability density value calculation to achieve efficient prediction and early warning of future cybersecurity events.

Benefits of technology

It enables accurate prediction and efficient protection against cybersecurity incidents, especially providing real-time warnings to vulnerable user groups, thereby improving the efficiency and accuracy of cybersecurity protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728173B_ABST
    Figure CN119728173B_ABST
Patent Text Reader

Abstract

The application provides a network security protection method, device, equipment, medium and product, and relates to the field of networks to realize efficient and practical network security protection. The method comprises the following steps: collecting user historical data; filtering the user historical data by using a network security blacklist information base to obtain network security event occurrence time and network security event information; constructing a network security linear regression model based on the network security event occurrence time and the network security event information; determining a probability density value of network security event occurrence in a unit time based on the number of network security events occurring in each unit time and the average number of network security events occurring in a unit time based on a Poisson distribution model and the network security event occurrence time and the network security event information; and predicting the probability of network security event occurrence in a next time period based on the probability density value of network security event occurrence in a unit time and the network security linear regression model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of networking, and in particular to a network security protection method, apparatus, device, medium and product. Background Technology

[0002] With the continuous development of internet technology and its comprehensive integration into people's lives, misleading information via telephone, SMS, and cybersecurity is constantly increasing. Incidents affecting cybersecurity remain at a high level, and attackers' misleading methods are constantly evolving and emerging, leading to increasingly sophisticated misleading technologies. The battle between misleading and anti-misleading has been comprehensively upgraded, and the situation regarding telecommunications anti-misleading remains severe.

[0003] With the development of the times, the network environment is becoming increasingly complex. Misleading websites, misleading phone calls, virus attacks and other harmful information are rampant. Teenagers have poor self-control and the elderly have relatively weak awareness of anti-misleading, making them easy targets for attackers. Therefore, this invention urgently needs an efficient and practical network security protection method to protect users' property security. Summary of the Invention

[0004] This invention provides a network security protection method, apparatus, device, medium, and product that uses a network security linear regression model and a Poisson distribution model constructed from user historical data to predict the probability of a network security event occurring in the next time period, thereby achieving efficient and practical network security protection.

[0005] A first aspect of this invention provides a network security protection method, the method comprising:

[0006] Collect user historical data, which includes network usage data of user accounts within a historical time period;

[0007] By using a cybersecurity blacklist database, the user's historical data is filtered to obtain the occurrence time and information of cybersecurity incidents.

[0008] Based on the occurrence time and information of the cybersecurity incidents, a cybersecurity linear regression model is constructed, which characterizes the linear relationship between the occurrence time and the number of cybersecurity incidents.

[0009] Based on the Poisson distribution model, the historical time period is divided according to unit time. Based on the occurrence time and network security event information of the network security events, the number of network security events that occur in each unit time is counted, and the average number of network security events that occur in each unit time is determined.

[0010] Based on the number of cybersecurity incidents occurring per unit time and the average number of cybersecurity incidents occurring per unit time, a probability density value for cybersecurity incidents occurring per unit time is determined.

[0011] Based on the probability density value of a cybersecurity incident occurring within a unit of time and the cybersecurity linear regression model, the probability of a cybersecurity incident occurring in the next time period is predicted.

[0012] A second aspect of this invention provides a network security protection device, the device comprising:

[0013] The data acquisition module is used to collect user historical data, which includes network usage data of user accounts within a historical time period;

[0014] The data filtering module is used to filter the user's historical data using a network security blacklist information database to obtain the occurrence time and information of network security incidents.

[0015] The regression model construction module is used to construct a cybersecurity linear regression model based on the occurrence time and information of the cybersecurity incident. The cybersecurity linear regression model characterizes the linear relationship between the occurrence time and the number of cybersecurity incidents.

[0016] The time segmentation module is used to segment the historical time period according to the Poisson distribution model, and to count the number of network security events that occur in each unit of time based on the occurrence time and network security event information, and to determine the average number of network security events that occur in each unit of time.

[0017] The probability density determination module is used to determine the probability density value of network security events occurring within a unit time based on the number of network security events occurring in each unit time and the average number of network security events occurring within a unit time.

[0018] The probability prediction module is used to predict the probability of a network security incident occurring in the next time period based on the probability density value of the network security incident occurring within a unit time period and the network security linear regression model.

[0019] A third aspect of the present invention provides an electronic device, the electronic device comprising: a memory, a processor, and a computer program stored in the memory and running on the processor, wherein the computer program, when executed by the processor, implements the network security protection method of the first aspect of the present invention.

[0020] A fourth aspect of the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the network security protection method of the first aspect of the present invention.

[0021] The fifth aspect of the present invention provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the network security protection method of the first aspect of the present invention.

[0022] In the network security protection method provided in this embodiment of the invention, the occurrence time and information of network security incidents are selected from the collected historical user data. While constructing a network security linear regression model based on the occurrence time and information, a Poisson distribution model is used to determine the probability density value of a network security incident occurring within a unit time period in the historical time frame. Finally, based on the probability density value of a network security incident occurring within a unit time period in the historical time frame and the network security linear regression model, the probability of a network security incident occurring in the next time period is predicted. Thus, this embodiment achieves more accurate probability prediction through the comprehensive simulation and prediction of the network security linear regression model and the Poisson distribution model, realizing efficient and practical network security protection. Attached Figure Description

[0023] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0024] Figure 1 This is a flowchart illustrating a network security protection method according to an embodiment of the present invention;

[0025] Figure 2 This is a schematic diagram illustrating the construction of a network security linear regression model proposed in an embodiment of the present invention;

[0026] Figure 3 This is a schematic diagram illustrating a Poisson distribution calculation process according to an embodiment of the present invention;

[0027] Figure 4 This is a structural block diagram of a network security protection device provided in an embodiment of the present invention;

[0028] Figure 5 This is a schematic diagram of an electronic device according to an embodiment of the present invention. Detailed Implementation

[0029] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0030] refer to Figure 1 , Figure 1 This is a flowchart illustrating a network security protection method according to an embodiment of the present invention. Figure 1 As shown, the network security protection method of this embodiment may include the following steps:

[0031] Step S11: Collect user historical data, which includes network usage data of user accounts within a historical time period.

[0032] In this embodiment, user historical data can be collected, which includes at least the user account's network usage data within a historical time period. The historical time period is a past cycle, such as a past day, past year, past six months, past three months, etc. This embodiment does not limit the specific value of the historical time period.

[0033] In one optional example, the user accounts corresponding to the user history data are all user accounts, that is, all user accounts that use network communication (such as telephone, Internet access, SMS, etc.). In another optional example, the user accounts corresponding to the user history data can be user accounts corresponding to user groups that are easily misled, such as user accounts corresponding to a certain senior citizen telephone package, and there is no restriction on this.

[0034] In one optional example, network usage data may include: call data and / or internet access data. Call data includes at least one of the following: call duration, call recipient, and keywords from the call content; internet access data includes at least one of the following: data usage, website category, and access duration.

[0035] Step S12: Use the network security blacklist information database to filter the user's historical data to obtain the occurrence time and network security event information of the network security incident.

[0036] In this embodiment, a network security blacklist information database is established in advance. For example, the network security blacklist information database can be constructed based on relevant data from the data centers of network information security centers and network security-related departments. The network security blacklist information database includes relevant information that leads to network security incidents. For example, the network security blacklist information database includes at least any of the following: malicious URLs, misleaders' phone numbers, maliciously misleading bank accounts, misleaders' commonly used social media account information, specific misleading related IP address ranges, and known misleading software signature codes.

[0037] This embodiment can use a network security blacklist database to filter the collected user historical data to obtain the occurrence time and information of network security events in the user historical data. Here, a network security event is an event that affects network security; for example, a network security event may include: misleading events (such as receiving / making misleading phone calls) and network attack events (such as visiting misleading websites); network security event information is related to network security events, for example, it may at least include the number of network security events, which represents the number of times network security events have occurred.

[0038] Step S13: Based on the occurrence time and information of the network security incident, construct a network security linear regression model, which characterizes the linear relationship between the occurrence time and the number of network security incidents.

[0039] In this embodiment, a linear regression model can be constructed based on the occurrence time and information of the obtained cybersecurity incidents to obtain a cybersecurity linear regression model. This model characterizes the linear relationship between the occurrence time and the number of cybersecurity incidents. For example, in the cybersecurity linear regression model, the occurrence time t is the independent variable, and the number of cybersecurity incidents n is the dependent variable.

[0040] like Figure 2 As shown, Figure 2 This is a schematic diagram illustrating the construction of a network security linear regression model proposed in one embodiment of the present invention. Figure 2 In this process, based on the collected user historical data (such as call records and internet access data), and the network security blacklist information database, an analysis can be performed. The occurrence time of network security incidents is used as the independent variable, and the number of network security incidents is used as the dependent variable to construct a network security linear regression model.

[0041] Step S14: Based on the Poisson distribution model, the historical time period is divided according to unit time. Based on the occurrence time of the network security incident and the network security incident information, the number of network security incidents occurring in each unit time is counted, and the average number of network security incidents occurring in each unit time is determined.

[0042] In this embodiment, the historical time period can be divided according to the Poisson distribution model, and the number of network security events occurring in each unit of time can be counted based on the occurrence time and information of network security events, and the average number of network security events occurring in each unit of time can be determined.

[0043] For example, a unit of time can refer to one minute, fifteen minutes, one hour, etc., without restriction. Taking one minute as an example, the historical time period can be divided into one-minute units based on the Poisson distribution model, and the number of cybersecurity events occurring in each minute can be counted (for example, the number of cybersecurity events occurring in the first minute, the second minute, the third minute, and so on). Then, based on the number of cybersecurity events occurring in each minute, the average number of cybersecurity events occurring in one minute can be obtained (for example, based on the number of cybersecurity events occurring in the first minute, the second minute, the third minute, etc., the average number of cybersecurity events occurring in one minute can be obtained).

[0044] It should be noted that this embodiment does not restrict the execution order between steps S13 and S14. For example, steps S13 and S14 can be executed simultaneously, steps S13 can be executed first and then steps S14 can be executed, or steps S14 can be executed first and then steps S13.

[0045] Step S15: Based on the number of network security events occurring per unit time and the average number of network security events occurring per unit time, determine the probability density value of network security events occurring per unit time.

[0046] In this embodiment, the probability density value of a network security event occurring within a unit time can be calculated based on the Poisson distribution model, according to the number of network security events occurring per unit time and the average number of network security events occurring within a unit time.

[0047] like Figure 3 As shown, Figure 3 This is a schematic diagram illustrating a Poisson distribution calculation process according to an embodiment of the present invention. Figure 3The system can collect historical user data (including call records and internet traffic) from the past year, segment it by minute, and filter and integrate it into a big data model of user behavior. Then, based on the big data model and the cybersecurity blacklist database, the system matches the historical user data with the cybersecurity blacklist database to filter out call records and internet traffic records that constitute cybersecurity incidents, generating a cybersecurity behavior time distribution model. Finally, based on the cybersecurity behavior time distribution model and the Poisson distribution model, the Poisson distribution probability is obtained, which is the probability density value of a cybersecurity incident occurring within a unit of time.

[0048] The cybersecurity behavior time distribution model is primarily used to calculate the Poisson distribution probability based on time-series data of cybersecurity incidents occurring over a past period. It can also analyze the periodic patterns in the timing of cybersecurity incidents, such as the higher frequency of incidents during certain time periods (e.g., the beginning of the month, weekend evenings); and identify the concentrated trends in the timing of cybersecurity incidents, determining the range of high-incidence periods. This helps relevant departments strengthen monitoring and prevention measures during these high-risk periods, rationally allocate cybersecurity protection resources, optimize cybersecurity protection strategies, and improve overall cybersecurity protection efficiency.

[0049] Step S16: Based on the probability density value of a network security incident occurring within a unit time period and the network security linear regression model, predict the probability of a network security incident occurring in the next time period.

[0050] In this embodiment, after obtaining the probability density value of a cybersecurity event occurring within a unit time period output by the Poisson distribution model, the probability of a cybersecurity event occurring within the next time period of the historical time period can be predicted based on the probability density value of the cybersecurity event occurring within a unit time period and the constructed cybersecurity linear regression model.

[0051] In this embodiment, by filtering the occurrence time and information of network security incidents from collected historical user data, a network security linear regression model is constructed based on the occurrence time and information of network security incidents. Simultaneously, a Poisson distribution model is used to determine the probability density value of network security incidents occurring within a unit of time in the historical time period, based on the occurrence time and information of network security incidents. Finally, based on the probability density value of network security incidents occurring within a unit of time in the historical time period and the network security linear regression model, the probability of network security incidents occurring in the next time period is predicted. Thus, this embodiment achieves more accurate probability prediction through the comprehensive simulation and prediction of the network security linear regression model and the Poisson distribution model, realizing efficient and practical network security protection.

[0052] In conjunction with the above embodiments, in one implementation, the present invention also provides a network security protection method. Specifically, in this embodiment, step S15 may include step S21:

[0053] Step S21: Based on the Poisson distribution formula, and considering the number of network security events occurring per unit time and the average number of network security events occurring per unit time, obtain the probability density value P of network security events occurring per unit time.

[0054] In this embodiment, the probability density value P of a network security event occurring within a unit time can be calculated using the Poisson distribution model and the Poisson distribution formula, based on the number of network security events occurring per unit time and the average number of network security events occurring within a unit time.

[0055] The Poisson distribution formula in this embodiment includes:

[0056] Where k represents the number of cybersecurity incidents occurring per unit time, λ represents the average number of cybersecurity incidents occurring per unit time, and e is the base of the natural logarithm, such as:

[0057]

[0058] In conjunction with the above embodiments, in one implementation, the present invention also provides a network security protection method. Specifically, in this embodiment, step S16 may further include:

[0059] The probability density value of cybersecurity incidents occurring within a unit of time is introduced as an important feature variable into the cybersecurity linear regression model. In this model, combined with the variable relationships established based on historical user data, a multiple linear regression algorithm is used to calculate the probability of a cybersecurity incident occurring in the next time period. Specifically, the variable relationship in the cybersecurity linear regression model is a linear relationship between the time of occurrence of cybersecurity incidents and the number of cybersecurity incidents.

[0060] The cybersecurity linear regression model can obtain the transformation relationship between the probability density value of cybersecurity events occurring within a unit of time and the number of cybersecurity events within a unit of time based on the input probability density value of cybersecurity events occurring within a unit of time and user historical data. Based on this transformation relationship and the linear relationship between the occurrence time of cybersecurity events and the number of cybersecurity events, the model can finally output a prediction of the probability of cybersecurity events occurring in the next time period. For example, it can predict the probability of cybersecurity events occurring within a unit of time in the next time period.

[0061] In conjunction with the above embodiments, in one implementation, the present invention also provides a network security protection method. Specifically, in addition to the steps described above, the method may further include steps S31 to S32:

[0062] Step S31: Determine whether the probability of a network security incident occurring in the next time period exceeds a security threshold.

[0063] In this embodiment, a security threshold is set in advance to determine whether the predicted probability of a network security event occurring in the next time period exceeds the security threshold.

[0064] Step S32: If the probability of a network security incident occurring in the next time period exceeds the security threshold, issue a warning to the target user account.

[0065] In this embodiment, if the probability of a network security incident occurring in the next time period exceeds a set security threshold, an alert needs to be issued to the target user account. The target user account is the user account that requires the alert.

[0066] In one optional embodiment, the security threshold can be determined based on the historical network security incident occurrence probabilities provided by the data centers of network information security centers and network security-related departments. Further, the security threshold can be the average of the historical network security incident occurrence probabilities provided by the data centers of network information security centers and network security-related departments. For example, by collecting the actual probability data of all users encountering network security incidents over a past period (e.g., the past year), summing these actual probability data, and then dividing by the total number of these actual probability data, the result is the average historical network security incident occurrence probability.

[0067] In one embodiment, the methods for issuing warnings include, but are not limited to, SMS notifications, push notifications from the operator's official app, voice call prompts, and other channels.

[0068] In conjunction with the above embodiments, in another implementation, the present invention also provides a network security protection method. Specifically, in this embodiment, in addition to the above steps, steps S41 to S44 may be included:

[0069] Step S41: Obtain user account information, which includes at least one of the following: user account type and user package information.

[0070] In this embodiment, user account information can be obtained, which includes at least one of the following: user account type and user package information.

[0071] Step S42: Based on the user account information, determine the first user account, which includes: a youth user account and / or an elderly user account.

[0072] In this embodiment, a first user account can be determined based on the obtained user account information. The first user account is a user account that is easily misled and may be involved in network security incidents. The first user account includes: a teenage user account and / or an elderly user account.

[0073] Step S43: Based on the first user account, determine the second user account corresponding to the first user account. The second user account includes: the parent user account corresponding to the youth user account and / or the child user account corresponding to the elderly user account.

[0074] In this embodiment, a second user account corresponding to the first user account can be determined based on the first user account. The second user account is the supervisory user account corresponding to the first user account. The second user account includes: the parent user account corresponding to the youth user account and / or the child user account corresponding to the elderly user account.

[0075] Step S44: Determine the first user account and / or the second user account as the target user account.

[0076] In this embodiment, the first user account and / or the second user account can be identified as the target user accounts that need to be alerted.

[0077] The application scenario of this embodiment can be applied to public users, providing network security protection for users who subscribe to network security protection. It has good practicality, can leverage network security advantages, and can export network security protection capabilities. Further productization can provide external services, such as misleading or attacking the elderly and teenagers about safe internet access, supporting telecommunications anti-misleading and anti-attack measures, and providing early warnings to children or parents for protection.

[0078] In conjunction with the above embodiments, in another implementation, the present invention also provides a network security protection method. In this embodiment, in addition to the steps described above, steps S51 to S52 may also be included:

[0079] Step S51: Determine the behavioral risk level of a user account based at least on its historical risk level, user account type, and user online behavior characteristics.

[0080] In this embodiment, a comprehensive judgment can be made based on factors such as the user's historical risk level, user account type (e.g., elderly user, teenage user, ordinary adult user, etc.), and recent online and call behavior characteristics (e.g., whether they frequently visit high-risk websites, whether they have been in contact with suspected misleading numbers, etc.) to screen out high-risk user accounts for accurate early warning, so as to improve the pertinence and effectiveness of the early warning and avoid unnecessary interference to low-risk users.

[0081] Specifically, the behavioral risk level of a user account can be determined based on at least the user account's historical risk level, user account type, and user's online behavior characteristics (such as online and / or phone call behavior characteristics in a recent period).

[0082] Step S52: Identify user accounts whose behavioral risk level exceeds the level threshold as target user accounts, where the level threshold is the highest level of behavioral risk level that represents behavioral security.

[0083] In this embodiment, the behavioral risk level of a user account is compared with a risk level threshold. User accounts whose behavioral risk level exceeds the threshold are identified as target user accounts for early warning. Here, the risk level threshold represents the highest level of behavioral security. If the behavioral risk level exceeds the threshold, the user account is considered a high-risk account, highly vulnerable to misleading and cyberattacks.

[0084] In conjunction with the above embodiments, in one implementation, the present invention also provides a network security protection method. Specifically, in addition to the steps described above, the method may further include steps S61 to S63:

[0085] Step S61: If the probability of a network security incident occurring in the next time period exceeds the security threshold, determine the target access address corresponding to the web page request initiated by the user in the next time period.

[0086] In this embodiment, if the probability of a network security incident occurring in the next time period exceeds the security threshold, the target access address corresponding to the web page request can be determined before the user account's device establishes a connection with the target access address for the web page request received in the next time period.

[0087] Step S62: Determine whether the target access address is a URL in the network security blacklist information database.

[0088] In this embodiment, the URLs included in the network security blacklist information database are malicious URLs. At this time, it is determined whether the target access address matches the URL in the network security blacklist information database, that is, whether it is a URL in the network security blacklist information database.

[0089] Step S63: If the target access address is a URL in the network security blacklist information database, intercept the webpage request and stop connecting to the target access address.

[0090] In this embodiment, if the target access address is a URL in the network security blacklist information database, the target access address is determined to be a high-risk address. At this time, the web page request corresponding to the target access address is immediately blocked, and the connection to the target access address is stopped, so as to achieve real-time automatic blocking, thereby meeting the needs of real-time network security monitoring and protection and early warning protection for user networks.

[0091] In summary, this invention discloses a network security protection method based on Poisson distribution to protect against network security incidents in telecommunications networks. This method constructs relevant linear regression and Poisson distribution models by collecting historical user data (such as historical call detail records and historical internet traffic data). It can analyze misleading information in real time and comprehensively simulate and calculate the probability of a network security incident occurring in the next unit of time, providing early warnings to users about potential network attacks or misleading information in the future, thus protecting users' property security. This invention analyzes user historical data from multiple dimensions and uses a combination of linear and Poisson distribution simulations for prediction, making probability assessment more accurate.

[0092] It should be noted that, for the sake of simplicity, the method embodiments are all described as a series of actions. However, those skilled in the art should understand that the embodiments of the present invention are not limited to the described order of actions, because according to the embodiments of the present invention, some steps can be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to the embodiments of the present invention.

[0093] Based on the same inventive concept, one embodiment of the present invention provides a network security protection device. (Reference) Figure 4 , Figure 4 This is a structural block diagram of a network security protection device provided in an embodiment of the present invention. Figure 4 As shown, the network security protection device includes:

[0094] The data acquisition module is used to collect user historical data, which includes network usage data of user accounts within a historical time period;

[0095] The data filtering module is used to filter the user's historical data using a network security blacklist information database to obtain the occurrence time and information of network security incidents.

[0096] The regression model construction module is used to construct a cybersecurity linear regression model based on the occurrence time and information of the cybersecurity incident. The cybersecurity linear regression model characterizes the linear relationship between the occurrence time and the number of cybersecurity incidents.

[0097] The time segmentation module is used to segment the historical time period according to the Poisson distribution model, and to count the number of network security events that occur in each unit of time based on the occurrence time and network security event information, and to determine the average number of network security events that occur in each unit of time.

[0098] The probability density determination module is used to determine the probability density value of network security events occurring within a unit time based on the number of network security events occurring in each unit time and the average number of network security events occurring within a unit time.

[0099] The probability prediction module is used to predict the probability of a network security incident occurring in the next time period based on the probability density value of the network security incident occurring within a unit time period and the network security linear regression model.

[0100] Optionally, the probability density determination module includes:

[0101] The probability density determination submodule is used to obtain the probability density value P of a network security event occurring within a unit time, based on the number of network security events occurring per unit time and the average number of network security events occurring within a unit time, according to the Poisson distribution formula.

[0102] The Poisson distribution formula includes:

[0103] Where k represents the number of cybersecurity incidents occurring per unit time, λ represents the average number of cybersecurity incidents occurring per unit time, and e is the base of the natural logarithm.

[0104] Optionally, the device further includes:

[0105] The first determining module is used to determine whether the probability of a network security incident occurring in the next time period exceeds a security threshold.

[0106] The early warning module is used to issue an early warning to the target user account when the probability of a network security incident occurring in the next time period exceeds the security threshold.

[0107] Optionally, the device further includes:

[0108] The first acquisition module is used to acquire user account information, wherein the user account information includes at least one of the following: user account type and user package information;

[0109] The second determining module is used to determine a first user account based on the user account information, wherein the first user account includes: a youth user account and / or an elderly user account;

[0110] The third determining module is used to determine a second user account corresponding to the first user account based on the first user account. The second user account includes: the parent user account corresponding to the youth user account and / or the child user account corresponding to the elderly user account.

[0111] The fourth determining module is used to determine the first user account and / or the second user account as the target user account.

[0112] Optionally, the device further includes:

[0113] The risk level determination module is used to determine the behavioral risk level of a user account based at least on the user account's historical risk level, user account type, and user network behavior characteristics.

[0114] The fifth determination module is used to determine user accounts whose behavioral risk level exceeds the level threshold as the target user accounts, where the level threshold is the highest level of behavioral risk level that represents behavioral security.

[0115] Optionally, the device further includes:

[0116] The sixth determining module is used to determine the target access address corresponding to the web page request for a user-initiated web page request in the next time period when the probability of a network security incident occurring in the next time period exceeds the security threshold.

[0117] The judgment module is used to determine whether the target access address is a URL in the network security blacklist information database;

[0118] The interception module is used to intercept the webpage request and stop the connection to the target access address when the target access address is a URL in the network security blacklist information database.

[0119] Based on the same inventive concept, another embodiment of the present invention provides an electronic device, such as... Figure 5 As shown. Figure 5 This is a schematic diagram of an electronic device according to an embodiment of the present invention. The electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When executed by the processor, the program implements the steps of the network security protection method described in any of the above embodiments of the present invention.

[0120] Based on the same inventive concept, another embodiment of the present invention provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the network security protection method described in any of the above embodiments of the present invention.

[0121] Based on the same inventive concept, another embodiment of the present invention provides a computer program product, including a computer program / instruction, which, when executed by a processor, implements the steps in the network security protection method described in any of the above embodiments of the present invention.

[0122] As the device embodiment is basically similar to the method embodiment, the description is relatively simple, and relevant parts can be found in the description of the method embodiment.

[0123] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.

[0124] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, apparatus, or computer program products. Therefore, embodiments of the present invention can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, embodiments of the present invention can take the form of computer program products implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0125] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, terminal devices (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing terminal device to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing terminal device, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0126] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing terminal device to operate in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0127] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal equipment, causing a series of operational steps to be performed on the computer or other programmable terminal equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable terminal equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0128] Although preferred embodiments of the present invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present invention.

[0129] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or terminal device. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or terminal device that includes said element.

[0130] The present invention provides a detailed description of a network security protection method, apparatus, device, medium, and product. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, those skilled in the art will recognize that there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A network security protection method, characterized in that, The method includes: Collect user historical data, which includes network usage data of user accounts within a historical time period; By using a cybersecurity blacklist database, the user's historical data is filtered to obtain the occurrence time and information of cybersecurity incidents. Based on the occurrence time and information of the cybersecurity incidents, a cybersecurity linear regression model is constructed, which characterizes the linear relationship between the occurrence time and the number of cybersecurity incidents. Based on the Poisson distribution model, the historical time period is divided according to unit time. Based on the occurrence time and network security event information of the network security events, the number of network security events that occur in each unit time is counted, and the average number of network security events that occur in each unit time is determined. Based on the number of cybersecurity incidents occurring per unit time and the average number of cybersecurity incidents occurring per unit time, a probability density value for cybersecurity incidents occurring per unit time is determined. Based on the probability density value of a cybersecurity incident occurring within a unit of time and the cybersecurity linear regression model, the probability of a cybersecurity incident occurring in the next time period is predicted. The prediction of the probability of a cybersecurity incident occurring in the next time period based on the probability density value of the cybersecurity incident occurring within a unit of time and the cybersecurity linear regression model includes: The probability density value of a cybersecurity incident occurring within a unit of time is used as a feature variable and input into the cybersecurity linear regression model. The probability of a cybersecurity incident occurring in the next time period is calculated using a multiple linear regression algorithm.

2. The network security protection method according to claim 1, characterized in that, Based on the number of cybersecurity incidents occurring per unit time and the average number of cybersecurity incidents occurring per unit time, a probability density value for cybersecurity incidents occurring per unit time is determined, including: Based on the Poisson distribution formula, and based on the number of cybersecurity events occurring per unit time and the average number of cybersecurity events occurring per unit time, the probability density value P of a cybersecurity event occurring per unit time is obtained. The Poisson distribution formula includes: ; Where k represents the number of cybersecurity incidents occurring per unit time, λ represents the average number of cybersecurity incidents occurring per unit time, and e is the base of the natural logarithm.

3. The network security protection method according to claim 1 or 2, characterized in that, The method further includes: Determine whether the probability of a network security incident occurring within the next time period exceeds a security threshold; If the probability of a cybersecurity incident occurring within the next time period exceeds the security threshold, an alert will be issued to the target user account.

4. The network security protection method according to claim 3, characterized in that, The method further includes: Obtain user account information, which includes at least one of the following: user account type, user package information; Based on the user account information, a first user account is determined, which includes: a youth user account and / or an elderly user account; Based on the first user account, a second user account corresponding to the first user account is determined. The second user account includes: the parent user account corresponding to the youth user account and / or the child user account corresponding to the elderly user account. The first user account and / or the second user account are identified as the target user account.

5. The network security protection method according to claim 3, characterized in that, The method further includes: The behavioral risk level of a user account should be determined based at least on its historical risk level, account type, and online behavior characteristics. User accounts whose behavioral risk level exceeds the level threshold are identified as target user accounts. The level threshold is the highest level of behavioral risk level that represents behavioral security.

6. The network security protection method according to claim 3, characterized in that, The method further includes: If the probability of a network security incident occurring in the next time period exceeds the security threshold, the target access address corresponding to the web page request initiated by the user in the next time period is determined. Determine whether the target access address is a URL in the network security blacklist information database; If the target access address is a URL in the network security blacklist database, the webpage request is intercepted and the connection to the target access address is stopped.

7. A network security protection device, characterized in that, The device includes: The data acquisition module is used to collect user historical data, which includes network usage data of user accounts within a historical time period; The data filtering module is used to filter the user's historical data using a network security blacklist information database to obtain the occurrence time and information of network security incidents. The regression model construction module is used to construct a cybersecurity linear regression model based on the occurrence time and information of the cybersecurity incident. The cybersecurity linear regression model characterizes the linear relationship between the occurrence time and the number of cybersecurity incidents. The time segmentation module is used to segment the historical time period according to the Poisson distribution model, and to count the number of network security events that occur in each unit of time based on the occurrence time and network security event information, and to determine the average number of network security events that occur in each unit of time. The probability density determination module is used to determine the probability density value of network security events occurring within a unit time based on the number of network security events occurring in each unit time and the average number of network security events occurring within a unit time. The probability prediction module is used to predict the probability of a cybersecurity incident occurring in the next time period based on the probability density value of a cybersecurity incident occurring within a unit time period and the cybersecurity linear regression model; the probability density value of a cybersecurity incident occurring within a unit time period is used as a feature variable and input into the cybersecurity linear regression model, and the probability of a cybersecurity incident occurring in the next time period is calculated through a multiple linear regression algorithm.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the computer program is executed by the processor, it implements the network security protection method as described in any one of claims 1 to 6.

9. A computer-readable storage medium storing a computer program thereon, characterized in that, When the computer program is executed by a processor, it implements the network security protection method as described in any one of claims 1 to 6.

10. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instruction is executed by the processor, it implements the network security protection method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Anti-fraud early warning method and device

    CN112565525A

  • Network attack defense method and system based on Gaussian process regression

    CN117014224A

  • Abnormal detection method and device for network data of industrial side end equipment, and electronic equipment

    CN117879838A