A security situation awareness system based on multi-source security data fusion analysis

CN119743327BActive Publication Date: 2026-08-07CHINESE PEOPLES LIBERATION ARMY UNIT 32011
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINESE PEOPLES LIBERATION ARMY UNIT 32011
Filing Date
2025-01-14
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

[0005]本发明的目的在于提供一种基于多源安全数据融合分析的安全态势感知系统:解决现有网络安全态势感知系统对网络威胁感知不够及时、准确性地的技术问题

Benefits of technology

实时监测与预警:通过整合多源安全数据,实现对网络安全态势的实时监测和预警,系统能够及时发现并报告潜在的网络安全威胁,提高对网络威胁识别的及时性和准确性,为管理员提供及时的决策支持。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119743327B_ABST
    Figure CN119743327B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of network security, in particular to a security situation awareness system based on multi-source security data fusion analysis. The method comprises the following steps: a data packet security coefficient is calculated based on a length number distribution index and a length throughput distribution index; whether the network in a statistical period meets a security analysis condition is judged based on the data packet security coefficient; IP flow record data corresponding to the network meeting the security analysis condition is acquired; security analysis is performed on the IP flow record data; a network security coefficient is obtained; whether the network in a statistical time period meets a security situation prediction condition is judged based on the network security coefficient; prediction analysis is performed on the network meeting the security situation prediction condition through an analytic hierarchy process; a network security situation prediction coefficient is obtained; and a network security early warning signal is generated based on the network security situation prediction coefficient. The application can discover and report potential network security threats in time, and improve the timeliness and accuracy of network threat identification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and specifically to a security situation awareness system based on multi-source security data fusion analysis. Background Technology

[0002] With the rapid development of information technology, the network environment is becoming increasingly complex, and cybersecurity threats are exhibiting characteristics of diversification, complexity, and concealment. Traditional cybersecurity protection methods, such as firewalls, intrusion detection systems, and antivirus software, are no longer effective in dealing with these new threats. Therefore, there is an urgent need for a system capable of real-time and comprehensive perception of the cybersecurity situation in order to promptly detect and respond to various cybersecurity threats.

[0003] Some existing cybersecurity situational awareness systems often require significant manual intervention, leading to high resource consumption and low real-time performance. This makes the systems inadequate in responding to rapidly changing cybersecurity threats.

[0004] Therefore, there is an urgent need for a security situation awareness system based on multi-source security data fusion analysis to solve the above problems. Summary of the Invention

[0005] The purpose of this invention is to provide a security situation awareness system based on multi-source security data fusion analysis: to solve the technical problem that existing network security situation awareness systems are not timely and accurate enough in perceiving network threats.

[0006] The objective of this invention can be achieved through the following technical solutions: A security situation awareness system based on multi-source security data fusion analysis, comprising a network packet analysis module, an IP flow record data analysis module, a security situation prediction module, and a network security early warning module; The network packet analysis module is used to perform statistical analysis on network packets within a statistical time period, obtain the preset packet length distribution index and the preset packet length throughput distribution index, calculate the packet security coefficient based on the length distribution index and the length throughput distribution index, and determine whether the network within the statistical period meets the security analysis conditions based on the packet security coefficient. The statistical period includes several statistical time periods. The IP flow record data analysis module is used to acquire IP flow record data corresponding to networks that meet the security analysis conditions, perform security analysis on the IP flow record data, obtain network security coefficients, and determine whether the network within the statistical time period meets the security situation prediction conditions based on the network security coefficients. The security situation prediction module is used to predict and analyze networks that meet the security situation prediction conditions using the analytic hierarchy process (AHP) to obtain network security situation prediction coefficients. The network security early warning module is used to generate network security early warning signals based on network security situation prediction coefficients.

[0007] Furthermore, statistical analysis is performed on network data packets within the statistical time period to obtain the preset message length distribution index and the preset message length throughput distribution index. This specifically includes the following processes: Perform statistical analysis on network data packets within the statistical time period to obtain the total number of packets N passing through the link within the statistical time period, obtain the average packet length L of the preset packets passing through the packets within the statistical time period, and calculate the number n of the preset packets in the network data packets within the statistical time period based on the average packet length L. The proportion of the number of preset messages n to the total number of messages N passing through the link is calculated, and this proportion is recorded as the length distribution index of the preset messages. Perform statistical analysis on network data packets within the statistical time period to obtain the traffic V passing through the link within the statistical time period and the number of preset packets v passing through the statistical time period. The ratio of the throughput v of the preset message during the statistical time period to the total traffic V through the link during the statistical time period is calculated, and this ratio is recorded as the length throughput distribution index of the preset message.

[0008] Furthermore, the calculation of the data packet security factor based on the length number distribution index and the length throughput distribution index specifically includes the following process: Several statistical time periods are combined to form a statistical period. The execution time of the statistical period is used as the X-axis, and the length number distribution index and length throughput distribution index are used as the Y-axis. Two rectangular coordinate systems are established to generate two curves for the statistical period. The area of ​​the figure enclosed by the two curves and the coordinate axes within the statistical period is calculated respectively. The sum of the areas of the two figures is recorded as the data packet security factor.

[0009] Furthermore, determining whether the network meets the security analysis conditions within the statistical period based on the packet security coefficient specifically includes the following process: Load the data packet security factor threshold, where the data packet security factor threshold is stored in the system and its value is set by the system. Determine whether the data packet security factor exceeds the data packet security factor threshold. If yes, determine that the network within the statistical period meets the security analysis conditions. If no, determine that the network within the statistical period does not meet the security analysis conditions.

[0010] Furthermore, security analysis of IP flow record data to obtain the network security coefficient specifically includes the following processes: The duration A of each flow is obtained based on IP flow record data. Each unidirectional IP flow record is treated as a single IP activity, and the duration of a single IP activity is recorded as the duration A of each flow. Based on IP flow record data, obtain the number of peer IPs B for each flow and the number of address segments to which the peer IPs in each flow belong C; The number of application categories (D) belonging to each flow is obtained based on IP flow record data; The number of flows E for each flow is obtained based on IP flow record data; Substituting the duration of each flow (A), the number of peer IPs in each flow (B), the number of address ranges to which the peer IPs belong in each flow (C), the number of application categories to which each flow belongs (D), and the number of flows in each flow (E) into the network security coefficient calculation formula, the network security coefficient WLA is calculated. The calculation formula is as follows: ; in, The value is 2.72. The system's preset duration threshold, , , and This is a weighting coefficient, the value of which is set by the system. This represents the total number of IP addresses that can communicate on the network. This represents the number of address blocks in the network associated with the observed IP address. This represents the total number of application categories in the network. This represents the maximum number of flows per flow in the network.

[0011] Furthermore, determining whether a network meets the security posture prediction conditions within a statistical period based on network security coefficients specifically includes the following process: Load the network security coefficient threshold, which is stored in the system and its value is set by the system. Determine whether the network security coefficient exceeds the network security coefficient threshold. If it does, determine whether the network within the statistical period does not meet the security situation prediction conditions. If not, determine whether the network within the statistical period meets the security situation prediction conditions.

[0012] Furthermore, the network security situation prediction coefficients are obtained by performing predictive analysis on networks that meet the security situation prediction conditions using the analytic hierarchy process (AHP). The specific process includes the following steps: Step 1: Establish a hierarchical model with progressively higher levels, including a target layer, a criterion layer, and a measure layer. Step 2, construct the judgment matrix: determine the number of relevant influencing factors at each level. Construct a set of cybersecurity risk factors , ,in, A subset of the vulnerability rate existing in the system or software. For a subset of network communication line stability, This is a subset of the network attack rate. For a subset of the failure rate in network devices, from the set Two subsets at the same level are extracted and compared, using... This represents the ratio of importance, and assigns the corresponding importance values ​​according to a preset ratio, combining the importance of each layer to form a judgment matrix; Step 3: Calculate the largest eigenvalue of the judgment matrix. : ; in, It is a matrix obtained by normalizing each column vector of the judgment matrix. The value is 1, 2...m. For matrix The elements are added row by row to obtain a vector, which is then normalized into a matrix. For matrix The elements are added column by column to obtain a vector, which is then normalized into a matrix. Step 4: Perform a consistency check on the matrix. When a matrix V has only one non-zero eigenvalue, it indicates that the matrix is ​​completely consistent. If a matrix V has more than one eigenvalue, a consistency index can be used. : in, This indicates the order of the judgment matrix. A smaller value indicates better consistency, and vice versa. Will The value is denoted as the network security situation prediction coefficient.

[0013] Furthermore, the process of generating network security early warning signals based on network security situation prediction coefficients specifically includes the following steps: Load the network security situation prediction coefficient threshold. The network security situation prediction coefficient is stored in the system and its value is set by the system. Determine whether the network security situation prediction coefficient exceeds the network security situation prediction coefficient threshold. If it does, no warning signal is generated; otherwise, a warning signal is generated.

[0014] Compared to existing solutions, the beneficial effects achieved by this invention are: Real-time monitoring and early warning: By integrating multi-source security data, the system enables real-time monitoring and early warning of network security situation. It can promptly detect and report potential network security threats, improve the timeliness and accuracy of network threat identification, and provide timely decision support for administrators.

[0015] Intelligent Analysis and Response: The system analyzes and mines network security data to build intelligent security models. It can automatically identify abnormal behavior and take corresponding response measures, improving the system's automation and intelligence levels.

[0016] Comprehensive Visualization: Employing visualization and interactive technologies, the system presents various data collected in an intuitive chart format. Administrators can gain a clear understanding of network status and security posture through the interface, facilitating decision-making and operations. Attached Figure Description

[0017] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this invention. For those skilled in the art, other drawings can be obtained based on these drawings.

[0018] Figure 1 This is a system block diagram of a security situation awareness system based on multi-source security data fusion analysis according to an embodiment of the present invention; Figure 2 This is a flowchart of the first security situation awareness system based on multi-source security data fusion analysis according to an embodiment of the present invention; Figure 3 This is a flowchart of the second type of security situation awareness system based on multi-source security data fusion analysis according to an embodiment of the present invention; Figure 4 This is a flowchart of the third type of security situation awareness system based on multi-source security data fusion analysis according to the present invention. Detailed Implementation

[0019] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0020] Furthermore, the described features, structures, or characteristics can be combined in any suitable manner in one or more exemplary embodiments. Numerous specific details are provided in the following description to give a full understanding of exemplary embodiments of this disclosure. However, those skilled in the art will recognize that the technical solutions of this disclosure can be practiced with one or more of the specific details omitted, or other methods, components, steps, etc., can be employed. In other instances, well-known structures, methods, implementations, or operations are not shown or described in detail to avoid obscuring various aspects of this disclosure.

[0021] This embodiment provides a security situation awareness system based on multi-source security data fusion analysis. Figure 1 This is a system block diagram of a security situation awareness system based on multi-source security data fusion analysis according to an embodiment of the present invention, such as... Figure 1 As shown, the system includes a network packet analysis module, an IP flow record data analysis module, a security situation prediction module, and a network security early warning module; The network packet analysis module is used to perform statistical analysis on network packets within a statistical time period, obtain the preset packet length distribution index and the preset packet length throughput distribution index, calculate the packet security coefficient based on the length distribution index and the length throughput distribution index, and determine whether the network within the statistical period meets the security analysis conditions based on the packet security coefficient. The statistical period includes several statistical time periods. The IP flow record data analysis module is used to acquire IP flow record data corresponding to networks that meet the security analysis conditions, perform security analysis on the IP flow record data, obtain network security coefficients, and determine whether the network within the statistical time period meets the security situation prediction conditions based on the network security coefficients. The security situation prediction module is used to predict and analyze networks that meet the security situation prediction conditions using the analytic hierarchy process (AHP) to obtain network security situation prediction coefficients. The network security early warning module is used to generate network security early warning signals based on network security situation prediction coefficients.

[0022] In summary, this invention performs statistical analysis on network data packets within a statistical period to obtain a preset distribution index of packet length count and a preset distribution index of packet length throughput. Based on these indices, a data packet security coefficient is calculated. This security coefficient is then used to determine whether the network within the statistical period meets the security analysis conditions. IP flow record data corresponding to networks meeting the security analysis conditions is obtained, and security analysis is performed on this data to obtain a network security coefficient. Based on this coefficient, it is determined whether the network within the statistical period meets the security situation prediction conditions. The Analytic Hierarchy Process (AHP) is used to predict and analyze networks meeting these conditions, yielding a network security situation prediction coefficient. Finally, a network security early warning signal is generated based on this coefficient. This invention can promptly detect and report potential network security threats, improving the timeliness and accuracy of network threat identification.

[0023] In some embodiments, Figure 2 This is a flowchart of the first security situation awareness system based on multi-source security data fusion analysis according to an embodiment of the present invention, as follows: Figure 2As shown, the statistical analysis of network data packets within a statistical time period to obtain the preset message length distribution index specifically includes the following steps: Step S201: Perform statistical analysis on the network data packets within the statistical time period to obtain the total number of packets N passing through the link within the statistical time period, obtain the average packet length L of the preset packets passing through the packets within the statistical time period, and calculate the number n of the preset packets in the network data packets within the statistical time period based on the average packet length L. Step S202: Calculate the proportion of the number of preset messages n to the total number of messages N passing through the link, and record this proportion as the length distribution index of the preset messages.

[0024] In some embodiments, Figure 3 This is a flowchart of the second type of security situation awareness system based on multi-source security data fusion analysis according to an embodiment of the present invention, as follows: Figure 3 As shown, statistical analysis of network data packets within a statistical time period to obtain a preset message length throughput distribution index specifically includes the following steps: Step S301: Perform statistical analysis on the network data packets within the statistical time period to obtain the traffic V passing through the link within the statistical time period and the number of preset packets passing through the statistical time period v. Step S302: Calculate the ratio of the throughput v of the preset message during the statistical time period to the total traffic V through the link during the statistical time period, and record this ratio as the length throughput distribution index of the preset message.

[0025] In some embodiments, calculating the data packet security factor based on the length number distribution index and the length throughput distribution index specifically includes the following process: Several statistical time periods are combined to form a statistical period. The execution time of the statistical period is used as the X-axis, and the length number distribution index and length throughput distribution index are used as the Y-axis. Two rectangular coordinate systems are established to generate two curves for the statistical period. The area of ​​the figure enclosed by the two curves and the coordinate axes within the statistical period is calculated respectively. The sum of the areas of the two figures is recorded as the data packet security factor.

[0026] In some embodiments, determining whether the network meets the security analysis conditions within a statistical period based on the packet security coefficient specifically includes the following process: Load the data packet security factor threshold, where the data packet security factor threshold is stored in the system and its value is set by the system. Determine whether the data packet security factor exceeds the data packet security factor threshold. If yes, determine that the network within the statistical period meets the security analysis conditions. If no, determine that the network within the statistical period does not meet the security analysis conditions.

[0027] In some embodiments, Figure 4This is a flowchart of the third type of security situation awareness system based on multi-source security data fusion analysis according to embodiments of the present invention, as follows: Figure 4 As shown, the security analysis of IP flow record data to obtain the network security coefficient specifically includes the following steps: Step S401: Obtain the duration A of each flow based on the IP flow record data, wherein each unidirectional IP flow record is treated as a single IP activity, and the duration of a single IP activity is recorded as the duration A of each flow; Step S402: Based on the IP flow record data, obtain the number of peer IPs B for each flow and the number of address segments to which the peer IPs in each flow belong C; Step S403: Obtain the number of application categories D to which each flow belongs based on the IP flow record data, and obtain the number of flows E for each flow based on the IP flow record data; Step S404: Substitute the duration A of each flow, the number of peer IPs in each flow, the number of address ranges to which the peer IPs belong in each flow, the number of application categories to which each flow belongs, and the number of flows in each flow into the network security coefficient calculation formula to calculate the network security coefficient WLA. The calculation formula is as follows: ; in, The value is 2.72. The system's preset duration threshold, , , and This is a weighting coefficient, the value of which is set by the system. This represents the total number of IP addresses that can communicate on the network. This represents the number of address blocks in the network associated with the observed IP address. This represents the total number of application categories in the network. This represents the maximum number of flows per flow in the network.

[0028] In some embodiments, determining whether the network meets the security posture prediction conditions within a statistical time period based on the network security coefficient specifically includes the following process: Load the network security coefficient threshold, which is stored in the system and its value is set by the system. Determine whether the network security coefficient exceeds the network security coefficient threshold. If it does, determine whether the network within the statistical period does not meet the security situation prediction conditions. If not, determine whether the network within the statistical period meets the security situation prediction conditions.

[0029] In some embodiments, the process of using the Analytic Hierarchy Process (AHP) to predict and analyze networks that meet the conditions for security situation prediction, and obtaining network security situation prediction coefficients, specifically includes the following steps: Step 1: Establish a hierarchical model with progressively higher levels, including a target layer, a criterion layer, and a measure layer. Step 2, construct the judgment matrix: determine the number of relevant influencing factors at each level. Construct a set of cybersecurity risk factors , ,in, A subset of the vulnerability rate existing in the system or software. For a subset of network communication line stability, This is a subset of the network attack rate. For a subset of the failure rate in network devices, from the set Two subsets at the same level are extracted and compared, using... This represents the ratio of importance, and assigns the corresponding importance values ​​according to a preset ratio, combining the importance of each layer to form a judgment matrix; Step 3: Calculate the largest eigenvalue of the judgment matrix. : ; in, It is a matrix obtained by normalizing each column vector of the judgment matrix. The value is 1, 2...m. For matrix The elements are added row by row to obtain a vector, which is then normalized into a matrix. For matrix The elements are added column by column to obtain a vector, which is then normalized into a matrix. Step 4: Perform a consistency check on the matrix. When a matrix V has only one non-zero eigenvalue, it indicates that the matrix is ​​completely consistent. If a matrix V has more than one eigenvalue, a consistency index can be used. : in, This indicates the order of the judgment matrix. A smaller value indicates better consistency, and vice versa. Will The value is denoted as the network security situation prediction coefficient.

[0030] Furthermore, the process of generating network security early warning signals based on network security situation prediction coefficients specifically includes the following steps: Load the network security situation prediction coefficient threshold. The network security situation prediction coefficient is stored in the system and its value is set by the system. Determine whether the network security situation prediction coefficient exceeds the network security situation prediction coefficient threshold. If it does, no warning signal is generated; otherwise, a warning signal is generated.

[0031] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. A semiconductor medium can be a solid-state drive.

[0032] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0033] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0034] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0035] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0036] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A security situation awareness system based on multi-source security data fusion analysis, characterized in that, The system includes a network packet analysis module, an IP flow record data analysis module, a security posture prediction module, and a network security early warning module. The network packet analysis module is used to perform statistical analysis on network packets within a statistical time period, obtain the preset packet length distribution index and the preset packet length throughput distribution index, calculate the packet security coefficient based on the length distribution index and the length throughput distribution index, and determine whether the network within the statistical period meets the security analysis conditions based on the packet security coefficient. The statistical period includes several statistical time periods. The IP flow record data analysis module is used to acquire IP flow record data corresponding to networks that meet the security analysis conditions, perform security analysis on the IP flow record data, obtain network security coefficients, and determine whether the network within the statistical time period meets the security situation prediction conditions based on the network security coefficients. The security situation prediction module is used to predict and analyze networks that meet the security situation prediction conditions using the analytic hierarchy process (AHP) to obtain network security situation prediction coefficients. The network security early warning module is used to generate network security early warning signals based on network security situation prediction coefficients; The statistical analysis of network data packets within the statistical time period yields the distribution index of the number of preset message lengths and the distribution index of the throughput of preset message lengths. This process includes the following steps: Perform statistical analysis on network data packets within the statistical time period to obtain the total number of packets N passing through the link within the statistical time period, obtain the average packet length L of the preset packets passing through the packets within the statistical time period, and calculate the number n of the preset packets in the network data packets within the statistical time period based on the average packet length L. The proportion of the number of preset messages n to the total number of messages N passing through the link is calculated, and this proportion is recorded as the length distribution index of the preset messages. Perform statistical analysis on network data packets within the statistical time period to obtain the traffic V passing through the link within the statistical time period and the number of preset packets v passing through the statistical time period. The ratio of the throughput v of the preset message during the statistical time period to the total traffic V through the link during the statistical time period is calculated, and this ratio is recorded as the length throughput distribution index of the preset message. The calculation of the data packet security factor based on the length number distribution index and the length throughput distribution index specifically includes the following process: Several statistical time periods are combined into a statistical period. The execution time of the statistical period is used as the X-axis, and the length number distribution index and length throughput distribution index are used as the Y-axis. Two rectangular coordinate systems are established to generate two curves for the statistical period. The area of ​​the figure enclosed by the two curves and the coordinate axis within the statistical period is calculated respectively. The sum of the areas of the two figures is recorded as the data packet security factor. The security analysis of IP flow record data to obtain the network security coefficient specifically includes the following processes: The duration A of each flow is obtained based on IP flow record data. Each unidirectional IP flow record is treated as a single IP activity, and the duration of a single IP activity is recorded as the duration A of each flow. Based on IP flow record data, obtain the number of peer IPs B for each flow and the number of address segments to which the peer IPs in each flow belong C; The number of application categories (D) belonging to each flow is obtained based on IP flow record data; The number of flows E for each flow is obtained based on IP flow record data; Substituting the duration of each flow (A), the number of peer IPs in each flow (B), the number of address ranges to which the peer IPs belong in each flow (C), the number of application categories to which each flow belongs (D), and the number of flows in each flow (E) into the network security coefficient calculation formula, the network security coefficient WLA is calculated. The calculation formula is as follows: ; Where e takes the value 2.72, The system's preset duration threshold, , , and This is a weighting coefficient, the value of which is set by the system. This represents the total number of IP addresses that can communicate on the network. This represents the number of address blocks in the network associated with the observed IP address. This represents the total number of application categories in the network. This represents the maximum number of flows per flow in the network.

2. The security situation awareness system based on multi-source security data fusion analysis according to claim 1, characterized in that, Determining whether a network meets security analysis conditions within a statistical period based on packet security coefficients includes the following process: Load the data packet security factor threshold, where the data packet security factor threshold is stored in the system and its value is set by the system. Determine whether the data packet security factor exceeds the data packet security factor threshold. If yes, determine that the network within the statistical period meets the security analysis conditions. If no, determine that the network within the statistical period does not meet the security analysis conditions.

3. A security situation awareness system based on multi-source security data fusion analysis according to claim 1, characterized in that, Based on network security coefficients, determine whether the network meets the conditions for security posture prediction within a statistical time period. Includes the following processes: Load the network security coefficient threshold, which is stored in the system and its value is set by the system. Determine whether the network security coefficient exceeds the network security coefficient threshold. If it does, determine whether the network within the statistical period does not meet the security situation prediction conditions. If not, determine whether the network within the statistical period meets the security situation prediction conditions.

4. A security situation awareness system based on multi-source security data fusion analysis according to claim 1, characterized in that, The process of using the Analytic Hierarchy Process (AHP) to predict and analyze networks that meet the conditions for security situation prediction, and obtaining network security situation prediction coefficients, specifically includes the following steps: Step 1: Establish a hierarchical model with progressively higher levels, including a target layer, a criterion layer, and a measure layer. Step 2, construct the judgment matrix: determine the number m of relevant influencing factors at each level, and construct the set U of network security situation risk factors. ,in, A subset of the vulnerability rate existing in the system or software. For a subset of network communication line stability, This is a subset of the network attack rate. For the failure rate subset of network devices, two subsets from the same level are taken from set U and compared. The importance ratio is represented by m, and the corresponding importance is assigned according to a preset ratio. The importance of each level is combined to form a judgment matrix. Step 3: Calculate the largest eigenvalue Y of the judgment matrix: ; in, It is a matrix obtained by normalizing each column vector of the judgment matrix. The value is 1, 2...m. For matrix The elements are added row by row to obtain a vector, which is then normalized into a matrix. For matrix The elements are added column by column to obtain a vector, which is then normalized into a matrix. Step 4: Perform a consistency check on the matrix. When a matrix V has only one non-zero eigenvalue, it indicates that the matrix is ​​completely consistent. If a matrix V has more than one eigenvalue, a consistency index can be used. : Where K represents the order of the judgment matrix, A smaller value indicates better consistency, and vice versa. Will The value is denoted as the network security situation prediction coefficient.

5. A security situation awareness system based on multi-source security data fusion analysis according to claim 1, characterized in that, Specifically, generating cybersecurity early warning signals based on cybersecurity situation prediction coefficients. Includes the following processes: Load the network security situation prediction coefficient threshold. The network security situation prediction coefficient is stored in the system and its value is set by the system. Determine whether the network security situation prediction coefficient exceeds the network security situation prediction coefficient threshold. If it does, no warning signal is generated; otherwise, a warning signal is generated.

Citation Information

Patent Citations

  • Network security situation awareness method and device based on abnormal flow detection

    CN110769007A

  • Double analytic hierarchy process situation assessment method based on distributed system

    CN114065220A