Network security monitoring system based on big data analysis

The network security monitoring system, which uses big data analytics, monitors and compares data with historical data in real time, identifies abnormal network behavior, and tracks attack sources and paths. This solves the problem of insufficient response of traditional systems when facing unknown attacks, and improves the accuracy of threat detection and system stability.

CN119728279BActive Publication Date: 2026-02-24STATE GRID SHANDONG ELECTRIC POWER COMPANY WEIFANG POWER SUPPLY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411967260.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2026-02-24
Estimated Expiration
2044-12-30

AI Technical Summary

Technical Problem

Traditional network security monitoring systems are insufficient in responding to unknown or mutated attacks, and cannot effectively prevent zero-day vulnerabilities and advanced persistent threats, resulting in frequent false alarms and missed detections, long response times, increased network operation and maintenance costs, and impact on business continuity and data security.

Method used

A network security monitoring system based on big data analytics is adopted. Through historical behavior analysis, risk assessment, attack path analysis, and emergency response modules, it monitors and compares with historical data in real time, identifies abnormal network behavior, tracks attack sources and paths, and optimizes security and stability.

Benefits of technology

It improves the accuracy of threat detection, reduces false alarms, enhances the timeliness of risk warnings, can quickly cut off attack links, optimizes security protection efficiency and system stability, and ensures business continuity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728279B_ABST
    Figure CN119728279B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of computer security, in particular to a network security monitoring system based on big data analysis, which comprises a historical behavior analysis module, a risk assessment module, an attack path analysis module and an emergency response module. According to the application, abnormal fluctuations of network behavior can be accurately identified by real-time monitoring and comparison with historical data, and the specific risk of the abnormal fluctuations to network security can be rapidly evaluated, the accuracy of threat detection is improved, the occurrence of false positives is effectively reduced, abnormal data flow directions can be effectively tracked by analyzing network topology and behavior data, potential attack sources and attack paths can be identified, the timeliness of risk early warning is improved, the identification ability of complex attack modes is enhanced, potential attack links can be rapidly cut off without affecting normal business operations by implementing isolation and service shutdown measures, and the security protection efficiency of the computer network and the stability of the system are optimized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer security technology, and in particular to a network security monitoring system based on big data analysis. Background Technology

[0002] The field of computer security technology focuses on protecting computer systems from unauthorized access, attacks, damage, or other potential security threats. This field involves a variety of technologies, including intrusion detection systems, firewalls, encryption technologies, security protocols, and vulnerability management and response. These technologies enable the monitoring and analysis of the behavior of computer networks and systems to prevent, detect, and respond to various forms of security threats. Furthermore, computer security also includes the protection of data, ensuring its integrity, availability, and confidentiality.

[0003] A network security monitoring system is a technological system used to monitor and analyze network traffic in real time to detect, alert on, and defend against potential network security threats. Its applications include intrusion detection, anomaly behavior analysis, data breach protection, and malware defense. By deploying such a system, network protection can be effectively strengthened against both external and internal threats, ensuring the integrity, confidentiality, and availability of data. Core functions of a network security monitoring system also include generating security alerts, providing incident response support, and generating detailed security incident logs.

[0004] Traditional monitoring systems rely on predefined rules and known attack signatures for threat detection, resulting in insufficient response to unknown or mutated attack methods. They are unable to effectively prevent or quickly respond to zero-day vulnerabilities and advanced persistent threats, and are prone to false positives or false negatives. Traditional systems have long reaction times in threat analysis and response strategy deployment, giving attackers ample time to carry out sabotage. This is particularly evident in increasingly complex network environments, increasing network operation and maintenance costs and affecting the overall business continuity and data security of enterprises. Summary of the Invention

[0005] The purpose of this invention is to address the shortcomings of existing technologies by proposing a network security monitoring system based on big data analysis.

[0006] To achieve the above objectives, the present invention adopts the following technical solution: a network security monitoring system based on big data analysis, the system comprising:

[0007] The historical behavior analysis module calculates the average data transmission rate of the computer network within different time periods based on the computer's historical network traffic data, evaluates the average status of the computer network data transmission, and analyzes the fluctuation range of the computer network data within different time periods to obtain a historical computer network behavior benchmark.

[0008] Based on the historical computer network behavior benchmark, the risk assessment module monitors the current operating data of the computer network, compares the current data flow with the historical computer network behavior benchmark, assesses the degree of deviation of the computer network status, and, in conjunction with the duration of the network status deviation, assesses the network security risk level of the computer equipment, implements corresponding network security risk warnings, and obtains security risk information.

[0009] Based on the security risk information, the attack path analysis module locates computer devices with abnormal data flow, traces the path from the abnormal computer devices to potential attack sources, and identifies the attacker's potential action routes and attack chains through network topology analysis to obtain attack path information.

[0010] Based on the attack path information, the emergency response module identifies threatened computer devices along the attack path, assesses the threat level of the computer devices, isolates the computer devices, assesses the risk level of differentiated services in the computer devices, identifies services that need to be shut down, cuts off potential attack links, optimizes the security and stability of the computing network, and obtains emergency handling records.

[0011] The present invention improves upon the method for evaluating the average condition of computer network data transmission as follows:

[0012] Based on historical network traffic data, extract computer network data for the target time period using the formula:

[0013]

[0014] Calculate the average data transmission volume for the target time period ,in, This represents the average data transmission volume during the target time period. It is the first Data transmission volume at each point in time, It is the total number of data points within the target time period;

[0015] Based on the average data transmission volume during the target time period ,according to The value is used to assess the transmission level of the computer network and obtain an average condition assessment result.

[0016] The present invention is improved in that the step of obtaining the historical computer network behavior benchmark is as follows:

[0017] Based on the aforementioned average condition assessment results, using the formula:

[0018]

[0019] Calculate the fluctuation range of the target period ,in, This represents the average data transmission volume during the target time period. It is the first Data transmission volume at each point in time, It is the total number of data points within the target time period. Indicates the first Weighting coefficients at each time point The fluctuation range for the target period;

[0020] Based on the fluctuation range of the target time period Integrate the average data transmission volume for the target time period This yields historical benchmarks for computer network behavior.

[0021] The present invention improves upon the method for assessing the degree of deviation of the computer network status as follows:

[0022] Based on the historical computer network behavior benchmark, monitor the current operating data of the computer network to obtain real-time computer network data;

[0023] Based on the aforementioned real-time computer network data, using the formula:

[0024]

[0025] Calculate the standardized deviation index The deviation assessment results of the computer network state are obtained, among which, This represents the average data transmission volume during the target time period. The fluctuation range for the target period. For the current network transmission volume, For adjustment coefficients, It is the offset constant. This is the proportionality coefficient. This is the standardized deviation index.

[0026] The present invention is improved in that the step of obtaining the security risk information is as follows:

[0027] Based on the deviation assessment results of the computer network status, the standardized deviation index at the differentiated time points is compared with the preset deviation threshold, and the number of times the standardized deviation index exceeds the preset deviation threshold and the corresponding duration are recorded to obtain security risk association data.

[0028] Based on the aforementioned security risk association data, using the formula:

[0029]

[0030] Calculate the network security risk level ,in, For the first The standardized deviation index of the second deviation. The number of times the deviation from the threshold is exceeded. For the first Duration of each deviation The total length of the monitoring period. To adjust the coefficient, The level is determined by cybersecurity risk.

[0031] Based on the aforementioned network security risk level Implement corresponding cybersecurity risk warnings and obtain security risk information.

[0032] The present invention is improved in that the step of obtaining the attack path information is as follows:

[0033] Based on the security risk information, an abnormal computer device list is identified. Using graph database technology, each abnormal device is used as a starting node to trace the potential attack source. Through database query operations, the connection relationship between nodes is extracted, the network topology is analyzed, and a path search algorithm is applied to find the shortest and most likely path from the abnormal device to the potential attack source, thus obtaining the potential path identification result.

[0034] Based on the potential path identification results, using the formula:

[0035]

[0036] Calculate the score of the attack path ,in, For the first on the path The activity intensity of each node From abnormal equipment to the first The path length of each node. To adjust the factor, A score for the attack path;

[0037] Scoring based on the attack path By comparing differentiated paths Value size, selection The path with the largest value is taken as the target path, thus obtaining the attack path information.

[0038] The present invention is improved in that the method for isolating computer devices is as follows:

[0039] Based on the attack path information, the threatened computer devices on the attack path are identified, and the position and function of the computer devices in the attack chain are extracted to obtain threat association data.

[0040] Based on the aforementioned threat association data, using the formula:

[0041]

[0042] Threat level of computing devices ,in, This indicates the importance of the equipment. This indicates the urgency of the equipment being threatened. Indicates the exposure level of the equipment. These are model parameters. It is the threshold that defines the exposure level;

[0043] Based on the threat level of the device The system compares the data with a preset threat threshold, isolates computer devices that exceed the threshold, and obtains the computer device isolation results.

[0044] The present invention is improved in that the steps for obtaining the emergency response record are as follows:

[0045] Based on the computer device isolation results, the operating services and applications of the threatened computer devices are analyzed, the business importance and security vulnerability information of the services are extracted, and service-related data is obtained.

[0046] Based on the service-related data, using the formula:

[0047]

[0048] The index for determining whether computing services are shut down ,in, Indicates the business importance of the service. Indicates the security vulnerability level of the service. Indicates the difficulty of service recovery. It is the stability constant. An index used to determine service closure;

[0049] Based on the determination index of service shutdown Compare with the preset closing threshold, and Application services whose values ​​exceed the preset shutdown threshold are shut down, and emergency handling records are obtained.

[0050] Compared with the prior art, the advantages and positive effects of the present invention are as follows:

[0051] In this invention, by real-time monitoring and comparison with historical data, abnormal fluctuations in network behavior can be accurately identified, and their specific risks to network security can be quickly assessed, improving the accuracy of threat detection and effectively reducing false alarms. By analyzing network topology and behavioral data, abnormal data flows can be effectively tracked, potential attack sources and attack paths can be identified, improving the timeliness of risk warnings and enhancing the ability to identify complex attack patterns. By implementing isolation and service shutdown measures, potential attack links can be quickly cut off without affecting normal business operations, optimizing the security protection efficiency of computer networks and the stability of the system. Attached Figure Description

[0052] Figure 1 This is a system flowchart of the present invention;

[0053] Figure 2 This is a flowchart illustrating the average condition of computer network data transmission according to the present invention.

[0054] Figure 3 This is a flowchart illustrating the process of obtaining historical computer network behavior benchmarks for this invention.

[0055] Figure 4 This is a flowchart illustrating the deviation of a computer network state according to the present invention.

[0056] Figure 5 This is a flowchart illustrating how the present invention obtains security risk information;

[0057] Figure 6 This is a flowchart illustrating how the present invention obtains attack path information;

[0058] Figure 7 This is a flowchart illustrating the isolation of computer devices according to the present invention;

[0059] Figure 8 This is a flowchart illustrating the process of obtaining emergency response records according to the present invention. Detailed Implementation

[0060] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0061] In the description of this invention, it should be understood that the terms "length," "width," "upper," "lower," "front," "rear," "left," "right," "vertical," "horizontal," "top," "bottom," "inner," and "outer," etc., indicating orientation or positional relationships, are based on the orientation or positional relationships shown in the accompanying drawings and are only for the convenience of describing the invention and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation, and therefore should not be construed as a limitation of the invention. Furthermore, in the description of this invention, "a plurality of" means two or more, unless otherwise explicitly specified.

[0062] Please see Figure 1 This invention provides a technical solution: a network security monitoring system based on big data analysis, the system comprising:

[0063] The historical behavior analysis module calculates the average data transmission rate of the computer network within different time periods based on the computer's historical network traffic data, evaluates the average status of the computer network data transmission, and analyzes the fluctuation range of the computer network data within different time periods to obtain a historical computer network behavior benchmark.

[0064] The risk assessment module monitors the current operating data of the computer network based on historical computer network behavior benchmarks, compares the current data flow with the historical computer network behavior benchmarks, assesses the degree of deviation of the computer network status, and, in conjunction with the duration of the network status deviation, assesses the network security risk level of the computer equipment, implements corresponding network security risk warnings, and obtains security risk information.

[0065] The attack path analysis module, based on security risk information, locates computer devices where data flow is abnormal, traces the path from the abnormal computer devices to potential attack sources, and identifies the attacker's potential action routes and attack chains through network topology analysis to obtain attack path information.

[0066] Based on attack path information, the emergency response module identifies threatened computer devices along the attack path, assesses the threat level of the computer devices, isolates the computer devices, assesses the risk level of differentiated services within the computer devices, identifies services that need to be shut down, cuts off potential attack links, optimizes the security and stability of the computing network, and obtains emergency handling records.

[0067] Historical computer network behavior benchmarks include average network traffic, peak traffic, and traffic volatility. Security risk information includes real-time deviation rate, risk level score, and frequency of abnormal events. Attack path information includes attack source information, affected nodes, and potential attack propagation path information. Emergency response records include response measures and blocking operation records.

[0068] Please see Figure 2The method for evaluating the average condition of computer network data transmission is as follows:

[0069] Based on historical network traffic data, extract computer network data for the target time period using the formula:

[0070]

[0071] Calculate the average data transmission volume for the target time period ,in, This represents the average data transmission volume during the target time period. It is the first Data transmission volume at each point in time, It is the total number of data points within the target time period;

[0072] Average data transmission volume based on the target time period ,according to The value is used to assess the transmission level of the computer network and obtain an average condition assessment result.

[0073] formula:

[0074]

[0075] Parameter details and acquisition methods:

[0076] It is the first The data transmission volume at each point in time is recorded automatically by the computer network monitoring system during continuous operation, representing network traffic data at each point in time. Within a set monitoring period, network traffic is recorded once per unit of time (e.g., per minute), and the data is continuously recorded and stored in a database for subsequent analysis.

[0077] It represents the total number of data points within a specified time period, indicating the frequency of data collection throughout that time period.

[0078] Calculation example:

[0079] The set attention period is 3 minutes. This represents the amount of data transmitted per minute within those three minutes. (Settings) The specific values ​​are as follows: MB MB MB.

[0080] Calculate the sum of data from all minutes within the three-minute period. MB.

[0081] Calculate the average value

[0082]

[0083] result This indicates that the average network data transfer rate was approximately 133.33 MB per minute over the three-minute observation period. This helps network administrators quickly understand the network load over a short period of time.

[0084] Please see Figure 3 The steps for obtaining historical computer network behavior benchmarks are as follows:

[0085] Based on the average condition assessment results, using the formula:

[0086]

[0087] Calculate the fluctuation range of the target period ,in, This represents the average data transmission volume during the target time period. It is the first Data transmission volume at each point in time, It is the total number of data points within the target time period. Indicates the first Weighting coefficients at each time point The fluctuation range for the target period;

[0088] Fluctuation range based on the target time period Integrate the average data transmission volume for the target time period This yields historical benchmarks for computer network behavior.

[0089] formula:

[0090]

[0091] Parameter details and acquisition methods:

[0092] The average data transmission volume during the target period is calculated using the previous steps.

[0093] : indicates the first The network data volume at each point in time refers to network traffic data recorded in real time or at predetermined time points by a computer network monitoring system. These data points form the basis for the analysis.

[0094] This represents the total number of data points within the target time period, i.e., the number of time points recorded within the measurement period. This number reflects the size of the dataset and is used to calculate the mean and standard deviation.

[0095] : is the first The weights assigned to data points at specific time points are used to adjust their influence in the overall fluctuation calculation based on their importance. These weights can be set based on specific criteria (such as peak periods of network traffic) to reflect that data at certain time points may be more critical than data at other times.

[0096] Calculation example:

[0097] Network data transmission volume was observed at three time points, with corresponding weights assigned. Considering that traffic is typically higher during the evening, evening data was given a higher weight. Data points: MB MB MB, weight: , , Total number of data points: .

[0098] Calculate the average value :

[0099]

[0100] calculate :

[0101]

[0102]

[0103]

[0104]

[0105]

[0106]

[0107] Calculation results This indicates that the network data volume fluctuated by approximately 22.91 MB over the three observed time points. This demonstrates the extent to which the data deviated from its average value, providing network administrators with crucial information about network load variations.

[0108] Please see Figure 4 The method for assessing the degree of deviation of computer network status is as follows:

[0109] Based on historical computer network behavior benchmarks, monitor the current operating data of the computer network to obtain real-time computer network data;

[0110] Based on real-time computer network data, using the formula:

[0111]

[0112] Calculate the standardized deviation index The deviation assessment results of the computer network state are obtained, among which, This represents the average data transmission volume during the target time period. The fluctuation range for the target period. For the current network transmission volume, For adjustment coefficients, It is the offset constant. This is the proportionality coefficient. This is the standardized deviation index.

[0113] formula:

[0114]

[0115] Parameter details and acquisition methods:

[0116] The average data transmission volume during the target period is calculated using the previous steps.

[0117] The fluctuation range for the target period is calculated using the previous steps.

[0118] The amount of network data at the current point in time is collected in real time by the network monitoring system.

[0119] : Adjustment coefficient, used to adjust the fluctuation range The influence of this makes the formula more adaptable to different network environments. This is a design parameter that can be adjusted according to the specific needs of the network environment.

[0120] Offset constant: Ensures that the value within the logarithm is always greater than zero, guaranteeing the validity of the calculation. This constant needs to be set according to the range of the data to avoid illegal operations in logarithmic calculations.

[0121] : Proportioning factor, based on the current data volume The size of this coefficient adjusts the growth rate of the logarithmic function to adapt to changes in the amount of data. This coefficient can be set based on the rate of change of historical data to ensure that the sensitivity of the logarithmic part is appropriate.

[0122] Calculation example:

[0123] The following numbers are used for calculation: data average. MB, fluctuation range MB, current data volume MB, adjustment coefficient offset constant proportionality coefficient .

[0124] Calculate the difference between the current data and the average value. MB, calculates the fluctuation range with adjustment coefficient. Calculate the logarithmic part Deviation index .

[0125] Calculation results This indicates that the current data deviates relatively little from the historical average, and the results help network administrators assess and monitor the security status of the network, ensuring that the network operates within normal limits.

[0126] Please see Figure 5 The steps for obtaining security risk information are as follows:

[0127] Based on the deviation assessment results of computer network status, the standardized deviation index at different time points is compared with the preset deviation threshold. The number of times the standardized deviation index exceeds the preset deviation threshold and the corresponding duration are recorded to obtain security risk correlation data.

[0128] Based on security risk correlation data, using the formula:

[0129]

[0130] Calculate the network security risk level ,in, For the first The standardized deviation index of the second deviation. The number of times the deviation from the threshold is exceeded. For the first Duration of each deviation The total length of the monitoring period. To adjust the coefficient, The level is determined by cybersecurity risk.

[0131] Based on network security risk levels Implement corresponding cybersecurity risk warnings and obtain security risk information.

[0132] formula:

[0133]

[0134] Parameter details and acquisition methods:

[0135] : No. The standardized deviation index of the second deviation is obtained by the previously calculated method.

[0136] : No. The duration of each deviation is determined by the time logs recorded by the network monitoring system, specifically the time difference from the start to the end of the deviation.

[0137] The number of times the deviation threshold was exceeded was obtained through statistics.

[0138] The total length of the monitoring period, usually from the start to the end of the monitoring, is set according to the configuration of the network monitoring system.

[0139] : Adjustment factor, used to adjust the impact of the number of deviations on the risk assessment results. This is an empirical value, adjusted based on past monitoring data and cybersecurity requirements.

[0140] Calculation example:

[0141] Set the following parameters for calculation: Deviation index The values ​​were 0.8, 1.2, 0.9, 1.5, and 0.7, respectively, representing the duration of each deviation. The monitoring periods were 5, 3, 4, 6, and 2 minutes respectively. Minutes, adjustment coefficient .

[0142] Calculate the product of the deviation index and the duration. The values ​​are 4, 3.6, 3.6, 9, and 1.4, respectively, and the sum is... Calculate the logarithmic part Apply the risk assessment formula: .

[0143] Calculation results This indicates that, within a given monitoring period, the network risk level is low after considering the frequency, duration, and adjustment factors of deviations. This result provides network administrators with a quantitative risk assessment, helping them understand the state of network security during a specific monitoring period and thus take appropriate security measures.

[0144] Please see Figure 6 The steps to obtain attack path information are as follows:

[0145] Based on security risk information, a list of abnormal computer devices is identified. Using graph database technology, each abnormal device is used as a starting node to trace potential attack sources. Through database query operations, the connection relationships between nodes are extracted, the network topology is analyzed, and a path search algorithm is applied to find the shortest and most likely path from the abnormal device to the potential attack source, thus obtaining the potential path identification results.

[0146] Based on the potential path identification results, using the formula:

[0147]

[0148] Calculate the score of the attack path ,in, For the first on the path The activity intensity of each node From abnormal equipment to the first The path length of each node. To adjust the factor, A score for the attack path;

[0149] Attack path-based scoring By comparing differentiated paths Value size, selection The path with the largest value is taken as the target path, thus obtaining the attack path information.

[0150] formula:

[0151]

[0152] Parameter details and acquisition methods:

[0153] : The first on the path The activity intensity of each node, obtained from the network monitoring system, reflects the node's role and importance in potential attack activities.

[0154] From the starting node (i.e., the device detected as abnormal) to the node The distance is the shortest path length calculated using path search algorithms in graph databases, such as Dijkstra's algorithm.

[0155] The adjustment coefficient is a preset constant used to ensure that the denominator is not zero and to balance the impact of distance, so that the path score will not decrease indefinitely as the distance increases.

[0156] Calculation example:

[0157] There are three key nodes. The attack path formed by these nodes needs to be evaluated, along with the node activity intensity. : These are the distances from the starting node to these nodes, which are 80, 50, and 30 respectively. Adjustment coefficients: 1, 2, and 3 respectively. Set to 0.5.

[0158] Calculation process:

[0159] Node 1 rating:

[0160]

[0161] Node 2 rating:

[0162]

[0163] Node 3 rating:

[0164]

[0165] Overall score :

[0166]

[0167] Calculation results The higher the score, the more likely the attack path is to be used by attackers to carry out malicious activities.

[0168] Please see Figure 7 The method for isolating computer equipment is as follows:

[0169] Based on attack path information, the threatened computer devices along the attack path are identified, and the position and function of the computer devices in the attack chain are extracted to obtain threat association data.

[0170] Based on threat correlation data, using the formula:

[0171]

[0172] Threat level of computing devices ,in, This indicates the importance of the equipment. This indicates the urgency of the equipment being threatened. Indicates the exposure level of the equipment. These are model parameters. It is the threshold that defines the exposure level;

[0173] Based on the threat level of the device The system compares the data with a preset threat threshold, isolates computer devices that exceed the threshold, and obtains the computer device isolation results.

[0174] formula:

[0175]

[0176] Parameter details and acquisition methods:

[0177] The importance of a device is typically assessed based on its core functions within the network, the extent to which it stores sensitive data, and its impact on business operations. Device importance scores can be obtained through assessments by a security team or data provided by an automated asset management system.

[0178] The urgency of a device being threatened. This metric is assessed based on the device's location on the attack path and the frequency and severity of recent attack attempts or threat activities. Urgency can be obtained through analysis of alerts and logs from intrusion detection systems or security information and event management systems.

[0179] Device exposure reflects its accessibility to the outside world and its potential attack surface. This can be determined using network topology analysis tools, assessing the number of external connections, the number of open ports, and access control policies.

[0180] and These two parameters adjust the impact of exposure on threat assessment. The slope of the function is defined, which affects the sensitivity of the results to changes in exposure. The threshold determines the midpoint of exposure, that is, the point at which the effect of exposure on the outcome changes from significant to insignificant. These parameters are typically set based on historical data and expert experience.

[0181] Calculation example:

[0182] The parameters are set as follows: The equipment is of high importance in the business. The equipment faces relatively high imminent threats. The equipment has a medium level of exposure. Exposure level has a relatively sensitive effect on the results. : The set exposure threshold.

[0183] Calculation process:

[0184]

[0185]

[0186]

[0187]

[0188]

[0189]

[0190] Calculation results This indicates that the device faces a medium to high level of threat, and the rating helps the security team determine the protective measures that need to be taken.

[0191] Please see Figure 8 The steps for obtaining emergency response records are as follows:

[0192] Based on the computer device isolation results, analyze the operating services and applications of the threatened computer devices, extract the business importance and security vulnerability information of the services, and obtain service-related data.

[0193] Based on service-related data, using the formula:

[0194]

[0195] The index for determining whether computing services are shut down ,in, Indicates the business importance of the service. Indicates the security vulnerability level of the service. Indicates the difficulty of service recovery. It is the stability constant. An index used to determine service closure;

[0196] Based on the index for determining service shutdown Compare with the preset closing threshold, and Application services whose values ​​exceed the preset shutdown threshold are shut down, and emergency handling records are obtained.

[0197] formula:

[0198]

[0199] Parameter details and acquisition methods

[0200] The business importance of a service is usually assessed based on its role in maintaining daily business operations. This can be obtained through business impact analysis, which is a method for assessing the impact of a specific business function on the company's overall operations.

[0201] : Security vulnerability level of the service. The score is based on the security team's latest vulnerability scan of the service. The severity rating of the vulnerability is usually provided by international vulnerability scoring standards such as CVSS.

[0202] The difficulty of service recovery includes the time, resources, and technical complexity required to restore the service, and is usually supported by data from business continuity plans or disaster recovery plans.

[0203] The stability constant is used to ensure the stability of the calculation and avoid the denominator being zero. This constant should be small enough not to significantly affect the calculation result, such as... .

[0204] Calculation example:

[0205] The parameters are set as follows: Assuming the service's impact on the business is rated 7 (on a scale of 1 to 10), it indicates high business importance. The vulnerabilities currently existing in the service are rated as high-risk (on a scale of 1 to 10), indicating that the service poses a serious security risk. Restoring this service is of medium difficulty; it is neither the most complex nor the simplest. : Small constants used to ensure computational stability.

[0206] Calculation process:

[0207]

[0208]

[0209]

[0210] Calculation results This indicates that the service, due to its high business impact and high security risk, has a high need to be shut down, even with relatively moderate recovery difficulty. This value guides the security team's decision-making, indicating services that require priority shutdown or additional protective measures to mitigate potential security risks.

[0211] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention in any other way. Any person skilled in the art may make changes or modifications to the above-disclosed technical content to create equivalent embodiments that can be applied to other fields. However, any simple modifications, equivalent changes, and modifications made to the above embodiments based on the technical essence of the present invention without departing from the scope of the present invention shall still fall within the protection scope of the present invention.

Claims

1. A network security monitoring system based on big data analytics, characterized in that, The system includes: The historical behavior analysis module calculates the average data transmission rate of the computer network within different time periods based on the computer's historical network traffic data, evaluates the average status of the computer network data transmission, and analyzes the fluctuation range of the computer network data within different time periods to obtain a historical computer network behavior benchmark. Based on the historical computer network behavior benchmark, the risk assessment module monitors the current operating data of the computer network, compares the current data flow with the historical computer network behavior benchmark, assesses the degree of deviation of the computer network status, and, in conjunction with the duration of the network status deviation, assesses the network security risk level of the computer equipment, implements corresponding network security risk warnings, and obtains security risk information. Based on the security risk information, the attack path analysis module locates computer devices with abnormal data flow, traces the path from the abnormal computer devices to potential attack sources, and identifies the attacker's potential action routes and attack chains through network topology analysis to obtain attack path information. Based on the attack path information, the emergency response module identifies threatened computer devices along the attack path, assesses the threat level of the computer devices, isolates the computer devices, assesses the risk level of differentiated services in the computer devices, identifies services that need to be shut down, cuts off potential attack links, optimizes the security and stability of the computing network, and obtains emergency handling records.

2. The network security monitoring system based on big data analysis according to claim 1, characterized in that, The method for evaluating the average condition of computer network data transmission is as follows: Based on historical network traffic data, extract computer network data for the target time period using the formula: Calculate the average data transmission volume for the target time period ,in, This represents the average data transmission volume during the target time period. It is the first Data transmission volume at each point in time It is the total number of data points within the target time period; Based on the average data transmission volume during the target time period ,according to The value is used to assess the transmission level of the computer network and obtain an average condition assessment result.

3. The network security monitoring system based on big data analysis according to claim 2, characterized in that, The steps for obtaining the historical computer network behavior benchmark are as follows: Based on the aforementioned average condition assessment results, using the formula: Calculate the fluctuation range of the target period ,in, This represents the average data transmission volume during the target time period. It is the first Data transmission volume at each point in time, It is the total number of data points within the target time period. Indicates the first Weighting coefficients at each time point The fluctuation range for the target period; Based on the fluctuation range of the target time period Integrate the average data transmission volume for the target time period This yields historical benchmarks for computer network behavior.

4. The network security monitoring system based on big data analysis according to claim 1, characterized in that, The method for assessing the degree of deviation in the computer network status is as follows: Based on the historical computer network behavior benchmark, monitor the current operating data of the computer network to obtain real-time computer network data; Based on the aforementioned real-time computer network data, using the formula: Calculate the standardized deviation index The deviation assessment results of the computer network state are obtained, among which, This represents the average data transmission volume during the target time period. The fluctuation range for the target period. For the current network transmission volume, For adjustment coefficients, It is the offset constant. This is the proportionality coefficient. This is the standardized deviation index.

5. The network security monitoring system based on big data analysis according to claim 4, characterized in that, The steps for obtaining the security risk information are as follows: Based on the deviation assessment results of the computer network status, the standardized deviation index at the differentiated time points is compared with the preset deviation threshold, and the number of times the standardized deviation index exceeds the preset deviation threshold and the corresponding duration are recorded to obtain security risk association data. Based on the aforementioned security risk association data, using the formula: Calculate the network security risk level ,in, For the first The standardized deviation index of the second deviation. The number of times the deviation from the threshold is exceeded. For the first Duration of each deviation The total length of the monitoring period. To adjust the coefficient, The level is determined by cybersecurity risk. Based on the aforementioned network security risk level Implement corresponding cybersecurity risk warnings and obtain security risk information.

6. The network security monitoring system based on big data analysis according to claim 1, characterized in that, The steps for obtaining the attack path information are as follows: Based on the security risk information, an abnormal computer device list is identified. Using graph database technology, each abnormal device is used as a starting node to trace the potential attack source. Through database query operations, the connection relationship between nodes is extracted, the network topology is analyzed, and a path search algorithm is applied to find the shortest and most likely path from the abnormal device to the potential attack source, thus obtaining the potential path identification result. Based on the potential path identification results, using the formula: Calculate the score of the attack path ,in, For the first on the path The activity intensity of each node From abnormal equipment to the first The path length of each node. To adjust the factor, A score for the attack path; Scoring based on the attack path By comparing differentiated paths Value size, selection The path with the largest value is taken as the target path, thus obtaining the attack path information.

7. The network security monitoring system based on big data analysis according to claim 1, characterized in that, The method for isolating computer equipment is as follows: Based on the attack path information, the threatened computer devices on the attack path are identified, and the position and function of the computer devices in the attack chain are extracted to obtain threat association data. Based on the aforementioned threat association data, using the formula: Threat level of computing devices ,in, This indicates the importance of the equipment. This indicates the urgency of the equipment being threatened. Indicates the exposure level of the equipment. These are model parameters. It is the threshold that defines the exposure level; Based on the threat level of the device The system compares the data with a preset threat threshold, isolates computer devices that exceed the threshold, and obtains the computer device isolation results.

8. The network security monitoring system based on big data analysis according to claim 7, characterized in that, The steps for obtaining the emergency response records are as follows: Based on the computer device isolation results, the operating services and applications of the threatened computer devices are analyzed, the business importance and security vulnerability information of the services are extracted, and service-related data is obtained. Based on the service-related data, using the formula: The index for determining whether computing services are shut down ,in, Indicates the business importance of the service. Indicates the security vulnerability level of the service. Indicates the difficulty of service recovery. It is the stability constant. An index used to determine service closure; Based on the determination index of service shutdown Compare with the preset closing threshold, and Application services whose values ​​exceed the preset shutdown threshold are shut down, and emergency handling records are obtained.

Citation Information

Patent Citations

  • Computer network security intelligent analysis system and method based on big data

    CN117896137A

  • Network security emergency information collection and analysis method and system

    CN118316708A