A network security assessment method and system
By collecting a variety of network risk data in the network security assessment system, using convolutional neural networks and clustering algorithms for risk prediction and verification, the problems of single data and manual analysis error in the existing technology are solved, and comprehensive, accurate and dynamic monitoring of network security assessment is achieved.
Patent Information
- Application Number
- CN202510238299.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-03
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-03-03
AI Technical Summary
The prior art has the problem of single data acquisition in network security assessment and the inability to conduct comprehensive analysis of multiple data sources, which leads to the inability to accurately reflect the network security status and errors relying on manual analysis.
A network security evaluation method and system is proposed, including acquisition module, analysis module, processing module and evaluation module. Multiple network risk data are collected through network tools, risk characteristics are extracted, risk prediction type is verified using convolutional neural network model, and prediction type is adjusted using clustering algorithms, network risk values are counted, time-network functions are established, association rules are analyzed, and network exception level and security level are determined.
Through comprehensive analysis of multiple data sources, the comprehensiveness and accuracy of network security assessment is improved, human error is reduced, and dynamic monitoring and accurate assessment of network threats are achieved.
Smart Images

Figure CN119728312B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a network security assessment method and system. Background Art
[0002] With the rapid development of information technology, equipment networks are developing towards intelligence and informatization. At the same time, the risk of equipment networks being attacked has also increased. IDS is an intrusion detection system that monitors and classifies computer network activities. It can effectively handle various types of security attacks in combination with firewalls. However, the means of network attacks are becoming more and more diverse, and the attack methods are becoming increasingly complex, which poses a challenge to the security of equipment networks. Although the combination of IDS and firewalls can detect known attacks to a certain extent, they have the problem of obtaining single data and relying on only one data source for evaluation, which cannot fully reflect the status of network security. In addition, they lack comprehensive analysis of multiple data sources, making it difficult to form a comprehensive evaluation of complex network security. If it relies on manual supplementary analysis and judgment to determine the evaluation of network security, the evaluation results will be inaccurate. Manual analysis requires processing complex data, and there are also human omissions or errors, which cannot make accurate judgments on potential threats.
[0003] Therefore, how to provide a network security assessment method and system is a technical problem that technical personnel in this field urgently need to solve. Summary of the invention
[0004] In view of this, the present invention proposes a network security assessment method and system, aiming to solve the problem that single data is obtained and multiple data sources cannot be comprehensively analyzed, and network security assessment cannot be accurately obtained.
[0005] In one aspect, the present invention provides a network security assessment system, comprising:
[0006] Acquisition module, analysis module, processing module and evaluation module;
[0007] The collection module is configured to collect a plurality of network risk data through a network tool, and extract risk features of the network risk data based on the network tool;
[0008] The analysis module is configured to obtain a historical risk feature data set, and obtain a risk prediction type of the network risk data based on a convolutional neural network model, verify the risk prediction type, and calculate whether the risk prediction type is correct based on the historical risk type data, and when it is determined that the risk prediction type is incorrect, use a clustering algorithm to re-determine the risk prediction type of the network risk data;
[0009] The processing module is configured to count network risk data of the same risk prediction type, and derive a network risk value for each network risk data based on the risk characteristics, establish a time-network function based on the risk characteristics and the network risk value, determine a change trend of the same risk prediction type according to the time-network function, determine a time interval based on the risk characteristics, count network risk data of different risk prediction types within the time interval, and mine association results of network risk data of different risk prediction types according to an association rule algorithm, and determine a network anomaly level according to the number of the association results;
[0010] The evaluation module is configured to determine a network security level according to the network anomaly level and the change trend.
[0011] Furthermore, when collecting a plurality of network risk data through a network tool and extracting risk features of the network risk data based on the network tool, it includes:
[0012] The network tools include Wireshark, Graylog and Metasploit.
[0013] The network risk data includes network traffic data, network log data and network vulnerability data;
[0014] The acquisition module acquires the network traffic data through the Wireshark tool, acquires the network log data through the Graylog tool, and acquires the network vulnerability data through the Metasploit tool;
[0015] The risk characteristics include: attack initiation time, attack end time, attack duration, attack frequency, attack interval, attack data volume and number of attack targets.
[0016] Furthermore, when obtaining a historical risk feature data set and obtaining a risk prediction type of the network risk data based on a convolutional neural network model, it includes:
[0017] The analysis module splits the historical risk feature data set into a model fitting set and a model verification set, searches for establishment parameters of the convolutional neural network model through cross-validation and grid search, establishes a convolutional neural network model, fits the convolutional neural network model using the model fitting set, sets the prediction accuracy, and substitutes the model verification set into the convolutional neural network model to verify the establishment parameters;
[0018] Substituting the model verification set into the convolutional neural network model to obtain the model accuracy, and determining whether the established parameters are accurate according to the model accuracy and the prediction accuracy;
[0019] If the model accuracy is less than the prediction accuracy, continue to search for the establishment parameters of the convolutional neural network model through grid search, delete the original establishment parameters, re-determine the convolutional neural network model according to the re-searched establishment parameters, iteratively train the re-determined convolutional neural network model, and substitute the model verification set into the convolutional neural network model after iterative training until the prediction accuracy is reached;
[0020] If the model accuracy is greater than or equal to the prediction accuracy, the current convolutional neural network model is used as a risk prediction model, and the risk characteristics are substituted into the risk prediction model to obtain the risk prediction type of the network risk data.
[0021] Furthermore, when verifying the risk prediction type and calculating whether the risk prediction type is correct based on historical risk type data, it includes:
[0022] The analysis module determines a historical data set of the same risk prediction type as the risk feature according to the historical risk type data, and obtains historical features according to the historical data set, wherein the historical features include historical attack duration, historical attack frequency, historical attack interval, historical attack data volume, and historical attack target quantity;
[0023] The analysis module calculates the type similarity by the following formula:
[0024] ;
[0025] in, Indicates type similarity, Indicates the historical attack duration, Indicates the duration of the attack. represents the historical attack frequency, Indicates the attack frequency, Indicates the historical attack interval, Indicates the attack interval time, Indicates the amount of historical attack data, Indicates the amount of attack data, Indicates the number of historical attack targets, Indicates the number of attack targets. , , , and represents the weight coefficient, and ;
[0026] The analysis module sets a type similarity threshold ;
[0027] when Greater than or equal to When , the analysis module determines that the risk prediction type is correct;
[0028] when Less than , the analysis module determines that the risk prediction type is incorrect.
[0029] Further, when it is determined that the risk prediction type is incorrect, using a clustering algorithm to re-determine the risk prediction type of the network risk data includes:
[0030] The analysis module obtains representative data of each risk type according to the historical risk type data, combines the representative data with the risk characteristics of the network risk data to establish an aggregate data set, extracts the feature vector of each data in the aggregate data set and determines that the expected number of clusters k is 3, and initializes the parameters of the Gaussian distribution, calculates the probability that each data in the aggregate data set belongs to each Gaussian distribution, and obtains the responsibility value;
[0031] The analysis module selects the cluster with the largest responsibility value as the risk prediction type of the network risk data;
[0032] When there are multiple maximum responsibility values, the risk prediction type of the network risk data is determined according to the number of clustered data in the cluster where the maximum responsibility value is located;
[0033] The number of clustered data in each cluster where the maximum responsibility value is located is obtained, and the cluster with the largest number of clustered data is used as the risk prediction type of the network risk data.
[0034] Furthermore, when counting network risk data of the same risk prediction type and deriving a network risk value for each network risk data based on the risk characteristics, it includes:
[0035] The processing module calculates the network risk value by the following formula:
[0036] ;
[0037] in, represents the network risk value, Indicates the duration of the attack. Indicates the attack frequency, Indicates the attack interval time, Indicates the amount of attack data, Indicates the number of attack targets.
[0038] Further, when a time-network function is established based on the risk feature and the network risk value, and a change trend of the same risk prediction type is determined according to the time-network function, it includes:
[0039] The processing module counts network risk data of the same risk prediction type and establishes a function data set, obtains network risk values of all network risk data in the function data set, and obtains the attack initiation time of each network risk data according to the function data set;
[0040] Establishing a rectangular coordinate system, substituting the network risk value of each network risk data and the corresponding attack initiation time into the rectangular coordinate system, connecting adjacent attack initiation times to obtain the time-network function, and obtaining a change trend according to the time-network function;
[0041] The changing trends include an upward trend, a downward trend and a fluctuating trend.
[0042] Further, when determining a time interval based on the risk characteristics, collecting statistics of network risk data of different risk prediction types within the time interval and mining association results of network risk data of different risk prediction types according to an association rule algorithm, and determining a network anomaly level according to the number of association results, the method includes:
[0043] The processing module determines the time interval according to the attack initiation time and the attack end time, the left boundary of the time interval is the attack initiation time, and the right boundary of the time interval is the attack end time, counts network risk data of different risk prediction types within the time interval, generates multiple candidate item sets according to the Eclat algorithm, determines frequent item sets according to the support of the candidate item sets, and obtains the association result based on the frequent item sets;
[0044] The processing module counts the number of the association results and records it as the chain number;
[0045] Presetting a first preset quantity threshold and a second preset quantity threshold, wherein the first preset quantity threshold is greater than the second preset quantity threshold;
[0046] When the chain quantity is greater than the first preset quantity threshold, the network abnormality level is determined to be a first-level abnormality;
[0047] When the chain quantity is less than or equal to the first preset quantity threshold and greater than the second preset quantity threshold, it is determined that the network abnormality level is a secondary abnormality;
[0048] When the chain quantity is less than or equal to the second preset quantity threshold, it is determined that the network abnormality level is a third-level abnormality.
[0049] Further, when determining the network security level according to the network anomaly level and the change trend, it includes:
[0050] When the first-level anomaly occurs and the change trend is the upward trend, the network security level is determined to be the first-level security level;
[0051] When the first-level anomaly occurs and the change trend is the fluctuation trend or the downward trend, or when the second-level anomaly occurs and the change trend is the upward trend, or when the third-level anomaly occurs and the change trend is the upward trend, the network security level is determined to be the second-level security level;
[0052] When the second-level anomaly occurs and the changing trend is the fluctuating trend or the downward trend, or when the third-level anomaly occurs and the changing trend is the fluctuating trend or the downward trend, the network security level is determined to be the third-level security level.
[0053] Compared with the prior art, the beneficial effects of the present invention are: multiple network risk data are collected through network tools, and risk features are extracted from them, thereby improving the comprehensiveness of network security assessment, and the risk prediction type of network risk data is obtained through a convolutional neural network model, and the network risk data is automatically classified and verified in combination with historical risk type data. When the obtained risk prediction type is incorrect, the risk prediction type is readjusted using a clustering algorithm. Intelligent classification and verification effectively reduce human errors and misjudgments, and improve the accuracy of network security assessment. Based on the time-network function, the changing trend of the same type of network risk data over time is analyzed, thereby comprehensively showing the dynamic process of network threats. For different types of network risk data, within the time interval, the potential correlation is analyzed by the association rule algorithm to determine the network abnormality level. Not only can the network risk data of a single risk prediction type be analyzed, but also the connection between network risk data of different risk prediction types can be discovered, which not only improves the accuracy of the assessment, but also improves the security of the network, and realizes a comprehensive, accurate and real-time network security assessment.
[0054] On the other hand, the present application also provides a network security assessment method for applying the above network security assessment system, including:
[0055] Collecting a plurality of network risk data through a network tool, and extracting risk features of the network risk data based on the network tool;
[0056] Obtain a historical risk feature data set, and obtain the risk prediction type of the network risk data based on a convolutional neural network model, verify the risk prediction type, and calculate whether the risk prediction type is correct based on the historical risk type data. When it is determined that the risk prediction type is incorrect, use a clustering algorithm to re-determine the risk prediction type of the network risk data;
[0057] Counting network risk data of the same risk prediction type, and deriving a network risk value for each network risk data based on the risk characteristics, establishing a time-network function based on the risk characteristics and the network risk value, determining a change trend of the same risk prediction type according to the time-network function, determining a time interval based on the risk characteristics, counting network risk data of different risk prediction types within the time interval, and mining association results of network risk data of different risk prediction types according to an association rule algorithm, and determining a network anomaly level according to the number of association results;
[0058] The network security level is determined according to the network anomaly level and the change trend.
[0059] It is understandable that the above-mentioned network security assessment method and system have the same beneficial effects, which will not be described in detail here. BRIEF DESCRIPTION OF THE DRAWINGS
[0060] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the detailed description of the preferred embodiments below. The accompanying drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present invention. Moreover, the same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings:
[0061] Figure 1 A functional block diagram of a network security assessment system provided by an embodiment of the present invention;
[0062] Figure 2 A flowchart of a network security assessment method provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0063] Exemplary embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments described herein. On the contrary, these embodiments are provided in order to enable a more thorough understanding of the present disclosure and to fully convey the scope of the present disclosure to those skilled in the art. It should be noted that, in the absence of conflict, the embodiments of the present invention and the features described in the embodiments can be combined with each other. The present invention will be described in detail below with reference to the accompanying drawings and in combination with the embodiments.
[0064] In some embodiments of the present application, see Figure 1 As shown, a network security assessment system includes:
[0065] Acquisition module, analysis module, processing module and evaluation module;
[0066] The collection module is configured to collect a plurality of network risk data through a network tool, and extract risk features of the network risk data based on the network tool;
[0067] The analysis module is configured to obtain a historical risk feature data set, and obtain a risk prediction type of the network risk data based on a convolutional neural network model, verify the risk prediction type, and calculate whether the risk prediction type is correct based on the historical risk type data. When the risk prediction type is judged to be incorrect, a clustering algorithm is used to re-determine the risk prediction type of the network risk data;
[0068] The processing module is configured to count network risk data of the same risk prediction type, and derive a network risk value of each network risk data based on the risk characteristics, establish a time-network function based on the risk characteristics and the network risk value, determine a change trend of the same risk prediction type according to the time-network function, determine a time interval based on the risk characteristics, count network risk data of different risk prediction types within the time interval, and mine association results of network risk data of different risk prediction types according to an association rule algorithm, and determine a network anomaly level according to the number of association results;
[0069] The evaluation module is configured to determine the network security level according to the network anomaly level and change trend.
[0070] Specifically, the acquisition module is the foundation of the system and is responsible for obtaining multiple network risk data from the network. The number of network risk data obtained is preferably 40, which can be adjusted according to the actual network needs. The acquisition module not only obtains network risk data, but also extracts risk characteristics of network risk data through network tools, providing data input for subsequent analysis. The analysis module is responsible for using the acquired risk characteristics to determine the risk prediction type. The analysis module obtains training data from the historical risk characteristic data set and uses the convolutional neural network (CNN) to determine the risk prediction type of the risk characteristic, thereby determining what risk prediction type the risk characteristic belongs to. The risk prediction type includes three risk types, indicating They are penetration type, leakage type and latent type. The penetration type means gradually penetrating into the network through attacks to cause damage. The leakage type means stealing important data of the network through launched attacks. The latent type means implanting programs or viruses by launching attacks and continuing to attack when the network environment is weak. After obtaining the risk prediction type, the risk prediction type derived from the model is verified according to the historical risk type data to avoid misjudgment due to relying solely on the model, laying a data foundation for subsequent processing. When the risk prediction type is judged to be incorrect, the analysis module uses a clustering algorithm to re-determine the risk prediction type of the network risk data, thereby improving the accuracy of the risk prediction type. The processing module performs in-depth processing on the network risk data. First, it counts all network risk data of the same risk prediction type. Secondly, it calculates the network risk value of each network risk data based on the risk characteristics of these data. A time-network function is established based on the risk characteristics and the network risk value, which helps to evaluate the changing pattern of any risk prediction type over time and facilitates the timely discovery of potential threats. Then the processing module determines the time interval based on the risk characteristics and uses the association rule algorithm to mine the association results between network risk data of different risk prediction types. The association results can reveal the relationship between network risk data of different risk prediction types. The network anomaly level is determined based on the number of association results, which helps to fully understand the mutual influence between different risk prediction types, thereby improving the accuracy and flexibility of network security assessment. The evaluation module determines the network security level based on the network anomaly level and change trend. Determining the network security level can help personnel determine the corresponding protection measures, thereby improving the network's protection capabilities.
[0071] It can be understood that through the convolutional neural network model, the system can derive the risk prediction type of network risk data in real time, and redefine the risk prediction type through the clustering algorithm, ensuring the accuracy of network security assessment, effectively responding to the complex and changeable network security environment, and dynamically monitoring the change trend based on the time-network function, thereby improving the accuracy of network security assessment.
[0072] In some embodiments of the present application, when a plurality of network risk data are collected through a network tool, and risk features of the network risk data are extracted based on the network tool, the process includes:
[0073] Network tools include Wireshark, Graylog, and Metasploit.
[0074] Network risk data includes network traffic data, network log data, and network vulnerability data;
[0075] The collection module obtains network traffic data through the Wireshark tool, network log data through the Graylog tool, and network vulnerability data through the Metasploit tool;
[0076] Risk characteristics include: attack initiation time, attack end time, attack duration, attack frequency, attack interval, attack data volume and number of attack targets.
[0077] Specifically, the acquisition module uses the Wireshark tool to capture data packets in the network to obtain network traffic data, collects and analyzes network logs, such as firewall logs and server logs, through the Graylog tool to obtain network log data, and scans and discovers network vulnerabilities through the Metasploit tool to obtain network vulnerability data. The acquisition module enhances the comprehensiveness and adaptability of system evaluation by acquiring data in different dimensions, and extracts corresponding risk features based on the Wireshark tool, Graylog tool and Metasploit tool. The risk features help describe the behavior patterns of network attack events and provide a data basis for subsequent analysis.
[0078] In some embodiments of the present application, when obtaining a historical risk feature data set and obtaining a risk prediction type of network risk data based on a convolutional neural network model, it includes:
[0079] The analysis module splits the historical risk feature data set into a model fitting set and a model verification set, searches for the establishment parameters of the convolutional neural network model through cross-validation and grid search, establishes a convolutional neural network model, uses the model fitting set to fit the convolutional neural network model, sets the prediction accuracy, substitutes the model verification set into the convolutional neural network model to verify the establishment parameters, substitutes the model verification set into the convolutional neural network model to obtain the model accuracy, and determines whether the establishment parameters are accurate based on the model accuracy and the prediction accuracy. If the model accuracy is less than the prediction accuracy, continue to search for the establishment parameters of the convolutional neural network model through grid search, delete the original establishment parameters, re-determine the convolutional neural network model based on the re-searched establishment parameters, iteratively train the re-determined convolutional neural network model, and substitute the model verification set into the iteratively trained convolutional neural network model until the prediction accuracy is reached. If the model accuracy is greater than or equal to the prediction accuracy, the current convolutional neural network model is used as the risk prediction model, and the risk characteristics are substituted into the risk prediction model to obtain the risk prediction type of the network risk data.
[0080] Specifically, the historical risk feature dataset records the risk features of different time periods. The historical risk feature dataset is split into a model fitting set and a model validation set. 60%-80% of the data is used as the model fitting set, and the rest is used as the model validation set. It is ensured that both the model fitting set and the model validation set contain data of multiple risk features to improve the generalization ability of the convolutional neural network model. Cross-validation divides the data into several parts and trains the model multiple times to verify its stability and performance. Grid search searches for the model establishment parameters in the parameter space and uses the model fitting set to fit the convolutional neural network model, thereby improving the accuracy and stability of the model. The model validation set is substituted into the initially trained convolutional neural network model to verify the establishment parameters. The prediction accuracy is the performance indicator of the model on unknown data.
[0081] It can be understood that if the model accuracy is less than the prediction accuracy, it means that the convolutional neural network model established at this time does not meet the prediction requirements, and it is necessary to change its model parameters. A convolutional neural network model is re-determined based on the re-searched establishment parameters and verified to avoid accidental errors in the establishment parameters affecting the prediction results. If the model accuracy is greater than or equal to the prediction accuracy, it means that the convolutional neural network model at this time meets the prediction requirements. The current convolutional neural network model is used as a risk prediction model, and the risk characteristics are substituted into the risk prediction model to obtain the risk prediction type of the network risk data, so that the system can confirm the risk prediction type in real time, thereby improving the accuracy of network security assessment.
[0082] In some embodiments of the present application, when verifying the risk prediction type and calculating whether the risk prediction type is correct based on historical risk type data, it includes:
[0083] The analysis module determines the historical data set of the same risk prediction type as the risk feature according to the historical risk type data, and obtains the historical features according to the historical data set. The historical features include the historical attack duration, the historical attack frequency, the historical attack interval, the historical attack data volume, and the historical attack target quantity;
[0084] The analysis module calculates type similarity using the following formula:
[0085] ;
[0086] in, Indicates type similarity, Indicates the historical attack duration, Indicates the duration of the attack. represents the historical attack frequency, Indicates the attack frequency, Indicates the historical attack interval, Indicates the attack interval time, Indicates the amount of historical attack data, Indicates the amount of attack data, Indicates the number of historical attack targets, Indicates the number of attack targets. , , , and represents the weight coefficient, and ;
[0087] The analysis module sets the type similarity threshold ;
[0088] when Greater than or equal to When , the analysis module determines that the risk prediction type is correct;
[0089] when Less than , the analysis module determines that the risk prediction type is incorrect.
[0090] In some embodiments of the present application, when it is determined that the risk prediction type is incorrect, using a clustering algorithm to re-determine the risk prediction type of the network risk data includes:
[0091] The analysis module obtains representative data of each risk type based on historical risk type data, combines the risk characteristics of the representative data and network risk data to establish an aggregated data set, extracts the feature vector of each data in the aggregated data set and determines the expected number of clusters k to be 3, and initializes the parameters of the Gaussian distribution, calculates the probability that each data in the aggregated data set belongs to each Gaussian distribution, and obtains the responsibility value;
[0092] The analysis module selects the cluster with the largest responsibility value as the risk prediction type of the network risk data;
[0093] When there are multiple maximum responsibility values, the risk prediction type of the network risk data is determined according to the number of clustered data in the cluster where the maximum responsibility value is located;
[0094] The number of clustered data in each cluster where the maximum responsibility value is located is obtained, and the cluster with the largest number of clustered data is used as the risk prediction type of the network risk data.
[0095] Specifically, by comparing with historical risk type data, it is possible to accurately identify risk prediction types, avoid errors caused by single model predictions, and continuously accumulate and update historical risk type data, gradually improve judgment ability and adaptability, and use type similarity calculation to automatically judge risk prediction types, reducing reliance on manual experience, and using clustering algorithms to re-determine risk prediction types, improving the accuracy of system classification. The Gaussian mixture model allows the system to automatically adjust classification parameters according to the natural distribution of data to adapt to different risk prediction types, thereby accurately deriving the risk prediction type corresponding to the network risk data.
[0096] In some embodiments of the present application, when counting network risk data of the same risk prediction type and deriving a network risk value for each network risk data based on risk characteristics, the process includes:
[0097] The processing module calculates the network risk value through the following formula:
[0098] ;
[0099] in, represents the network risk value, Indicates the duration of the attack. Indicates the attack frequency, Indicates the attack interval time, Indicates the amount of attack data, Indicates the number of attack targets.
[0100] In some embodiments of the present application, when a time-network function is established based on risk characteristics and network risk values, and a change trend of the same risk prediction type is determined according to the time-network function, it includes:
[0101] The processing module counts the network risk data of the same risk prediction type and establishes a function data set, obtains the network risk value of all network risk data in the function data set, and obtains the attack initiation time of each network risk data according to the function data set;
[0102] Establish a rectangular coordinate system, substitute the network risk value of each network risk data and the corresponding attack launch time into the rectangular coordinate system, connect the adjacent attack launch times to obtain the time-network function, and obtain the change trend based on the time-network function;
[0103] Changing trends include upward trends, downward trends and fluctuating trends.
[0104] Specifically, the processing module first counts the network risk data of the same risk prediction type and establishes a function data set, wherein each network risk data in the function data set represents its attack initiation time and network risk value. Then, the processing module maps these data into a rectangular coordinate system, wherein the x-axis represents time and the y-axis represents the network risk value. Finally, the processing module connects the attack initiation time corresponding to each network risk data with the adjacent attack initiation time to form a time-network function. The change trend is determined according to the time-network function. When the network risk value of each network risk data rises with the passage of time, the change trend is an upward trend. When the network risk value of each network risk data gradually decreases with the passage of time, the change trend is a downward trend. When the connected straight line does not have a single rise or fall over time, the change trend is a fluctuating trend. By obtaining the change trend, the foundation is laid for the subsequent determination of the network security level, thereby improving the system automation level and the adaptability of the evaluation.
[0105] In some embodiments of the present application, when determining a time interval based on risk characteristics, collecting statistics on network risk data of different risk prediction types within the time interval, mining association results of network risk data of different risk prediction types according to an association rule algorithm, and determining a network anomaly level according to the number of association results, the method includes:
[0106] The processing module determines the time interval according to the attack launch time and the attack end time. The left boundary of the time interval is the attack launch time, and the right boundary of the time interval is the attack end time. The network risk data of different risk prediction types are counted within the time interval, and multiple candidate item sets are generated according to the Eclat algorithm. The frequent item sets are determined according to the support of the candidate item sets, and the association results are obtained based on the frequent item sets.
[0107] The processing module counts the number of association results and records it as the number of linkages;
[0108] Preset a first preset quantity threshold and a second preset quantity threshold, the first preset quantity threshold being greater than the second preset quantity threshold;
[0109] When the number of chains is greater than a first preset number threshold, the network abnormality level is determined to be a first-level abnormality;
[0110] When the number of chains is less than or equal to the first preset number threshold and greater than the second preset number threshold, the network anomaly level is determined to be a level 2 anomaly;
[0111] When the chain quantity is less than or equal to the second preset quantity threshold, it is determined that the network abnormality level is a third-level abnormality.
[0112] Specifically, the processing module determines the time interval according to the attack launch time and the attack end time. The left boundary of the time interval is the attack launch time, and the right boundary of the time interval is the attack end time. For example, if the time interval is determined according to any network risk data, the attack launch time is 7:00 on the 4th and the attack end time is 9:00 on the 5th, then the time interval is represented as 7:00 on the 4th to 9:00 on the 5th. The network risk data of different risk prediction types in this time interval are counted, which represents all the attacks launched in the time interval. Multiple candidate item sets are generated according to the Eclat algorithm, and the support of each candidate item set is calculated. The minimum support threshold is preferably 2. If the support is greater than or equal to the minimum support threshold, the candidate item set is determined as a frequent item set. The association result is obtained according to the frequent item set. For example, when the duration of the penetration type attack is 30 seconds, the leakage type attack interval is always 5 seconds. The number of association results is counted and recorded as the number of chains. The network anomaly degree of the first-level anomaly, the second-level anomaly and the third-level anomaly decreases in turn. The network anomaly level is dynamically determined according to the number of chains, which improves the adaptability and comprehensiveness of network security assessment.
[0113] In some embodiments of the present application, when determining the network security level according to the network anomaly level and change trend, it includes:
[0114] When a level 1 anomaly occurs and the change trend is an upward trend, the network security level is determined to be level 1 security level;
[0115] When a level 1 anomaly occurs and the change trend is a fluctuating trend or a downward trend, or when a level 2 anomaly occurs and the change trend is an upward trend, or when a level 3 anomaly occurs and the change trend is an upward trend, the network security level is determined to be a level 2 security level;
[0116] When a level 2 anomaly occurs and the changing trend is a fluctuating trend or a downward trend, or when a level 3 anomaly occurs and the changing trend is a fluctuating trend or a downward trend, the network security level is determined to be a level 3 security level.
[0117] Specifically, by combining the network anomaly level and change trend, the system can carefully evaluate network security. For example, a level 1 anomaly with an upward trend means that the security threat is continuing to intensify, and its network security level is determined to be level 1. The determination of the network security level not only depends on a single network anomaly level, but also combines the analysis of the change trend, comprehensively considering the continuity and variability of the attack activities, so as to accurately derive a network security assessment. Through automated and structured security assessments, the network security status can be accurately derived, avoiding errors in human analysis, thereby improving response speed and assessment accuracy.
[0118] In summary, the beneficial effects of the present invention are: multiple network risk data are collected through network tools, and risk features are extracted from them, which improves the comprehensiveness of network security assessment, and the risk prediction type of network risk data is obtained through the convolutional neural network model, and the network risk data is automatically classified and verified in combination with historical risk type data. When the obtained risk prediction type is incorrect, the clustering algorithm is used to readjust the risk prediction type. Intelligent classification and verification effectively reduce human errors and misjudgments, and improve the accuracy of network security assessment. The change trend of the same type of network risk data over time is analyzed based on the time-network function, thereby comprehensively showing the dynamic process of network threats. For different types of network risk data, within the time interval, the potential correlation is analyzed by the association rule algorithm to determine the network abnormality level. Not only can the network risk data of a single risk prediction type be analyzed, but also the connection between network risk data of different risk prediction types can be found, which not only improves the accuracy of the assessment, but also improves the security of the network, and realizes a comprehensive, accurate and real-time network security assessment.
[0119] In another preferred embodiment based on the above embodiment, refer to Figure 2 As shown, this embodiment provides a network security assessment method, which is used to apply the above network security assessment system, including:
[0120] S100: Collect multiple network risk data through network tools, and extract risk features of the network risk data based on the network tools;
[0121] S200: Obtain a historical risk feature data set, and obtain a risk prediction type of the network risk data based on a convolutional neural network model, verify the risk prediction type, and calculate whether the risk prediction type is correct based on the historical risk type data. When the risk prediction type is judged to be incorrect, use a clustering algorithm to re-determine the risk prediction type of the network risk data;
[0122] S300: Counting network risk data of the same risk prediction type, and deriving a network risk value for each network risk data based on risk characteristics, establishing a time-network function based on risk characteristics and network risk values, determining a change trend of the same risk prediction type based on the time-network function, determining a time interval based on risk characteristics, counting network risk data of different risk prediction types within the time interval, and mining association results of network risk data of different risk prediction types based on an association rule algorithm, and determining a network anomaly level based on the number of association results;
[0123] S400: Determine the network security level according to the network anomaly level and change trend.
[0124] Specifically, in step S100, multiple network risk data are collected through network tools, and risk features of network risk data are extracted based on network tools, providing basic data for subsequent analysis. In step S200, first, by obtaining historical risk feature data sets, the network risk data is predicted using a convolutional neural network (CNN) model to obtain its risk prediction type. If the predicted risk prediction type does not match the historical risk type data, a clustering algorithm is used to reclassify the network risk data, so as to accurately identify the risk prediction type. In step S300, according to the risk prediction type obtained in the previous step, the network risk data of the same risk prediction type are counted. Then, based on the risk features of each data, the network risk value of each network risk data is calculated. Secondly, based on these risk features and network risk values, a time-network function is established, which reveals the trend of change. Finally, the network risk data of different risk prediction types are counted, and the association rule algorithm is used to mine the association results of network risk data of different risk prediction types. The network anomaly level is determined according to the number of associated results. In step S400, the network security level is determined according to the network anomaly level and the change trend. A variety of data are used in combination to dynamically and accurately evaluate network security, thereby improving the comprehensiveness and accuracy of the evaluation.
[0125] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.
[0126] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0127] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0128] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0129] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.
Claims
1. A network security assessment system, characterized in that: include: Acquisition module, analysis module, processing module and evaluation module; The collection module is configured to collect a plurality of network risk data through a network tool, and extract risk features of the network risk data based on the network tool; The analysis module is configured to obtain a historical risk feature data set, and obtain a risk prediction type of the network risk data based on a convolutional neural network model, verify the risk prediction type, and calculate whether the risk prediction type is correct based on the historical risk type data, and when it is determined that the risk prediction type is incorrect, use a clustering algorithm to re-determine the risk prediction type of the network risk data; When verifying the risk prediction type and calculating whether the risk prediction type is correct based on historical risk type data, it includes: The analysis module determines a historical data set of the same risk prediction type as the risk feature according to the historical risk type data, and obtains historical features according to the historical data set, wherein the historical features include historical attack duration, historical attack frequency, historical attack interval, historical attack data volume, and historical attack target quantity; The analysis module calculates the type similarity by the following formula: in, Indicates type similarity, Indicates the historical attack duration, Indicates the duration of the attack. represents the historical attack frequency, Indicates the attack frequency, Indicates the historical attack interval, Indicates the attack interval time, Indicates the amount of historical attack data, Indicates the amount of attack data, Indicates the number of historical attack targets, Indicates the number of attack targets. , , , and represents the weight coefficient, and The analysis module sets a type similarity threshold ; when Greater than or equal to When , the analysis module determines that the risk prediction type is correct; when Less than When , the analysis module determines that the risk prediction type is incorrect; The processing module is configured to count network risk data of the same risk prediction type, and derive a network risk value for each network risk data based on the risk characteristics, establish a time-network function based on the risk characteristics and the network risk value, determine a change trend of the same risk prediction type according to the time-network function, determine a time interval based on the risk characteristics, count network risk data of different risk prediction types within the time interval, and mine association results of network risk data of different risk prediction types according to an association rule algorithm, and determine a network anomaly level according to the number of the association results; The evaluation module is configured to determine a network security level according to the network anomaly level and the change trend.
2. The network security assessment system according to claim 1, characterized in that: When a plurality of network risk data are collected through a network tool, and risk features of the network risk data are extracted based on the network tool, the method includes: The network tools include Wireshark, Graylog and Metasploit. The network risk data includes network traffic data, network log data and network vulnerability data; The acquisition module acquires the network traffic data through the Wireshark tool, acquires the network log data through the Graylog tool, and acquires the network vulnerability data through the Metasploit tool; The risk characteristics include: attack initiation time, attack end time, attack duration, attack frequency, attack interval, attack data volume and number of attack targets.
3. The network security assessment system according to claim 2, characterized in that: When obtaining a historical risk feature data set and obtaining a risk prediction type of the network risk data based on a convolutional neural network model, it includes: The analysis module splits the historical risk feature data set into a model fitting set and a model verification set, searches for establishment parameters of a convolutional neural network model through cross-validation and grid search, establishes a convolutional neural network model, fits the convolutional neural network model using the model fitting set, sets the prediction accuracy, and substitutes the model verification set into the convolutional neural network model to verify the establishment parameters; Substituting the model verification set into the convolutional neural network model to obtain the model accuracy, and determining whether the established parameters are accurate according to the model accuracy and the prediction accuracy; If the model accuracy is less than the prediction accuracy, continue to search for the establishment parameters of the convolutional neural network model through grid search, delete the original establishment parameters, re-determine the convolutional neural network model according to the re-searched establishment parameters, iteratively train the re-determined convolutional neural network model, and substitute the model verification set into the convolutional neural network model after iterative training until the prediction accuracy is reached; If the model accuracy is greater than or equal to the prediction accuracy, the current convolutional neural network model is used as a risk prediction model, and the risk characteristics are substituted into the risk prediction model to obtain the risk prediction type of the network risk data.
4. The network security assessment system according to claim 3, characterized in that: When it is determined that the risk prediction type is incorrect, re-determining the risk prediction type of the network risk data using a clustering algorithm includes: The analysis module obtains representative data of each risk type according to the historical risk type data, combines the representative data with the risk characteristics of the network risk data to establish an aggregate data set, extracts the feature vector of each data in the aggregate data set and determines that the expected number of clusters k is 3, and initializes the parameters of the Gaussian distribution, calculates the probability that each data in the aggregate data set belongs to each Gaussian distribution, and obtains the responsibility value; The analysis module selects the cluster with the largest responsibility value as the risk prediction type of the network risk data; When there are multiple maximum responsibility values, the risk prediction type of the network risk data is determined according to the number of clustered data in the cluster where the maximum responsibility value is located; The number of clustered data in each cluster where the maximum responsibility value is located is obtained, and the cluster with the largest number of clustered data is used as the risk prediction type of the network risk data.
5. The network security assessment system according to claim 4, characterized in that: When counting network risk data of the same risk prediction type and deriving a network risk value for each network risk data based on the risk characteristics, it includes: The processing module calculates the network risk value by the following formula: in, represents the network risk value, Indicates the duration of the attack. Indicates the attack frequency, Indicates the attack interval time, Indicates the amount of attack data, Indicates the number of attack targets.
6. The network security assessment system according to claim 5, characterized in that: When a time-network function is established based on the risk feature and the network risk value, and a change trend of the same risk prediction type is determined according to the time-network function, the method includes: The processing module counts network risk data of the same risk prediction type and establishes a function data set, obtains network risk values of all network risk data in the function data set, and obtains the attack initiation time of each network risk data according to the function data set; Establishing a rectangular coordinate system, substituting the network risk value of each network risk data and the corresponding attack initiation time into the rectangular coordinate system, connecting adjacent attack initiation times to obtain the time-network function, and obtaining a change trend according to the time-network function; The changing trends include an upward trend, a downward trend and a fluctuating trend.
7. The network security assessment system according to claim 6, characterized in that: When determining a time interval based on the risk feature, counting network risk data of different risk prediction types within the time interval and mining association results of network risk data of different risk prediction types according to an association rule algorithm, and determining a network anomaly level according to the number of association results, the method includes: The processing module determines the time interval according to the attack initiation time and the attack end time, the left boundary of the time interval is the attack initiation time, and the right boundary of the time interval is the attack end time, counts network risk data of different risk prediction types within the time interval, generates multiple candidate item sets according to the Eclat algorithm, determines frequent item sets according to the support of the candidate item sets, and obtains the association result based on the frequent item sets; The processing module counts the number of the association results and records it as the chain number; Presetting a first preset quantity threshold and a second preset quantity threshold, wherein the first preset quantity threshold is greater than the second preset quantity threshold; When the chain quantity is greater than the first preset quantity threshold, the network abnormality level is determined to be a first-level abnormality; When the chain quantity is less than or equal to the first preset quantity threshold and greater than the second preset quantity threshold, it is determined that the network abnormality level is a secondary abnormality; When the chain quantity is less than or equal to the second preset quantity threshold, it is determined that the network abnormality level is a third-level abnormality.
8. The network security assessment system according to claim 7, characterized in that: When determining the network security level according to the network anomaly level and the change trend, it includes: When the first-level anomaly occurs and the change trend is the upward trend, the network security level is determined to be the first-level security level; When the first-level anomaly occurs and the change trend is the fluctuation trend or the downward trend, or when the second-level anomaly occurs and the change trend is the upward trend, or when the third-level anomaly occurs and the change trend is the upward trend, the network security level is determined to be the second-level security level; When the second-level anomaly occurs and the changing trend is the fluctuating trend or the downward trend, or when the third-level anomaly occurs and the changing trend is the fluctuating trend or the downward trend, the network security level is determined to be the third-level security level.
9. A network security assessment method, used to apply the network security assessment system according to any one of claims 1 to 8, characterized in that: include: Collecting a plurality of network risk data through a network tool, and extracting risk features of the network risk data based on the network tool; Obtain a historical risk feature data set, and obtain the risk prediction type of the network risk data based on a convolutional neural network model, verify the risk prediction type, and calculate whether the risk prediction type is correct based on the historical risk type data. When it is determined that the risk prediction type is incorrect, use a clustering algorithm to re-determine the risk prediction type of the network risk data; Counting network risk data of the same risk prediction type, and deriving a network risk value for each network risk data based on the risk characteristics, establishing a time-network function based on the risk characteristics and the network risk value, determining a change trend of the same risk prediction type according to the time-network function, determining a time interval based on the risk characteristics, counting network risk data of different risk prediction types within the time interval, and mining association results of network risk data of different risk prediction types according to an association rule algorithm, and determining a network anomaly level according to the number of association results; The network security level is determined according to the network anomaly level and the change trend.
Citation Information
Patent Citations
Automatic infringement risk detection method and device and electronic equipment
CN112990792A
Collaborative fusion and grading prediction method for heterogeneous information of typical disaster risk of coal mine
CN117726181A