A network security risk assessment method based on big data

By adopting a big data-based network security risk assessment method in the industrial Internet of Things environment, analyzing the time delay information and data transmission changes of the equipment, combining cluster analysis and FP-Growth algorithm, the problem that traditional methods are difficult to predict the risk of equipment intrusion is solved, and multi-angle quantitative assessment and accurate early warning of equipment risks are achieved.

CN119788414BActive Publication Date: 2025-06-13CHANGCHUN GOLDSUN HI-TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510251433.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-05
Publication Date
2025-06-13
Estimated Expiration
2045-03-05

AI Technical Summary

Technical Problem

In an industrial Internet of Things environment, traditional security monitoring methods are difficult to predict which devices may affect equipment intrusion, and there is a lack of accurate assessment of the risk of equipment intrusion.

Method used

The network security risk assessment method based on big data is adopted to analyze the time delay information of the device after intrusion and the data transmission change information, and combine cluster analysis and FP-Growth algorithm to determine the importance and correlation of the device to achieve multi-angle quantitative assessment of device risks.

Benefits of technology

This method can be deployed for critical equipment, reduce potential losses and risks caused by device intrusion, provide more comprehensive and accurate awareness of security situations, improve detection accuracy, and achieve efficient utilization of resources and precise control of risks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119788414B_ABST
    Figure CN119788414B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for network security risk assessment based on big data, specifically related to the technical field of risk assessment. It includes determining the transition probability matrix of the data transmission status of other devices through the historical data of other devices, and combining the transmission data attributes of other devices to determine the time delay information of other devices. By determining the change information amount of the transmission data of other devices and the risk degree of the transmission data of other devices, the data transmission change information of other devices is determined, and key devices with a relatively high degree of importance in other devices are obtained. By collecting the characteristic data of devices in the industrial Internet of Things environment, the cluster where the invaded device is located is determined through clustering analysis. The FP-Growth algorithm is used to mine frequent itemsets in the cluster where the invaded device is located, and early warnings are given to other devices with a relatively high possibility of being invaded. The present invention helps to accurately assess and give early warnings about the network intrusion risk in the industrial Internet of Things environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of risk assessment, and more specifically, to a method for network security risk assessment based on big data. Background Art

[0002] In the industrial Internet of Things environment, thousands of devices are interconnected through the network and transmit a large amount of data in real time. These devices are widely distributed in scenarios such as production workshops, logistics centers, and energy management. Their operating states, data transmission characteristics, communication modes, and geographical locations are significantly different. With the continuous development of industrial automation and intelligent manufacturing, the number of industrial Internet of Things devices is increasing day by day, and the complexity and connectivity of its system have been greatly improved. At the same time, there are also increasingly serious security threats.

[0003] Currently, device intrusion incidents occur more and more frequently. Once a device is invaded, attackers may use the close association between devices to conduct lateral penetration, resulting in a cascade failure of the entire network system. Traditional security monitoring methods often only focus on the anomalies of individual devices, ignoring the commonalities between devices and potential attack chains, and it is difficult to predict which devices may be affected by the intrusion, thus lacking the ability to accurately assess the risk of device intrusion.

[0004] To solve the above defects, a technical solution is provided now. Summary of the Invention

[0005] In order to overcome the above defects of the prior art, an embodiment of the present invention provides a method for network security risk assessment based on big data to solve the problems raised in the above background art.

[0006] To achieve the above object, the present invention provides the following technical solutions:

[0007] A method for network security risk assessment based on big data specifically includes the following steps:

[0008] S1: Determine the invaded devices in the industrial Internet of Things environment. After a device is invaded, determine the transition probability matrix of the data transmission states of the remaining devices through the historical data of the remaining devices, and determine the time delay information of the remaining devices in combination with the transmission data attributes of the remaining devices.

[0009] S2: Determine the data transmission change information of the remaining devices by the amount of change information of the transmission data of the remaining devices and the risk degree of the transmission data of the remaining devices.

[0010] S3: Comprehensively analyze the time delay information and data transmission change information of the remaining devices to determine the importance of the remaining devices, and obtain the key devices with a higher degree of importance among the remaining devices.

[0011] S4: By collecting the characteristic data of devices in the industrial Internet of Things environment, determining the cluster where the invaded device is located through cluster analysis, mining frequent item sets using the FP-Growth algorithm in the cluster where the invaded device is located, determining the correlation information of the remaining devices, and combining and analyzing the correlation information and importance of the remaining devices to give early warnings to the remaining devices with a relatively high probability of being invaded.

[0012] In a preferred embodiment, the time delay information of the remaining devices includes:

[0013] Represent the time delay information of the remaining devices through the state transfer coefficient;

[0014] The acquisition logic of the state transfer coefficient is as follows: Define the device data transmission state, and divide the device data transmission state into normal transmission state, delayed transmission state, and timeout transmission state;

[0015] Based on the historical records of device operation, determine the transmission results of different types of device data, obtain the number of state transfers of the device data transmission state in the historical records, and construct a transition probability matrix , by solving , obtain the long-term state distribution of device data transmission, and mark the long-term state distribution of device data transmission as: , where is the steady-state probability of the normal transmission state, is the steady-state probability of the delayed transmission state, is the steady-state probability of the timeout transmission state;

[0016] For different types of data transmitted by the device, determine the data types transmitted by the device within the monitoring interval, determine the impact of time delay on different types of data, and calculate the transmission quality score of different types of device data within the monitoring interval. The calculation formula of the transmission quality score is: ; where is the transmission quality score, is the weight coefficient of different types of data in the normal transmission state, is the weight coefficient of different types of data in the delayed transmission state, is the weight coefficient of different types of data in the timeout transmission state;

[0017] Regarding each device as a node, determine the communication relationship graph of the devices within the monitoring interval, obtain the betweenness centrality of the devices after normalization according to the topological centrality of the devices within the monitoring interval, and calculate the state transfer coefficient. The calculation formula is: ; where is the state transfer coefficient, is the betweenness centrality of the device.

[0018] In a preferred embodiment, the data transmission change information of the remaining devices includes:

[0019] Represent the data transmission change information of the remaining devices through the entropy change coefficient and the data type risk assessment coefficient;

[0020] The acquisition logic of the entropy change coefficient is as follows: According to the data types transmitted by the devices within the monitoring interval, use kernel density estimation to determine the probability density distribution of different types of data, calculate the information entropy of different types of data within the monitoring interval based on the probability density distribution of different types of data, and calculate the entropy change coefficient according to the weights of different types of data in the industrial Internet of Things environment;

[0021] The calculation formula for the probability density distribution of different types of data is: ; where is the probability density function of different data types of the device within the monitoring interval, is the total number of different data type samples within the monitoring interval, n is the sample index, SJ is the specified value of the data, is the data of different data types of the device within the monitoring interval, h is the bandwidth,

[0022] The calculation formula for the entropy change coefficient is: ; where is the entropy change coefficient, is the weight of different types of data in the industrial Internet of Things environment.

[0023] In a preferred embodiment, the data type risk assessment coefficient includes:

[0024] The acquisition logic of the data type risk assessment coefficient is as follows: According to the data types generated by the device, determine the abnormal events of different types of data of the device, and based on the abnormal events of different types of data of the device, determine the impact score values of different types of data;

[0025] According to the data types generated by the device within the monitoring interval, construct a regression model with the impact score values of different types of data within the monitoring interval and the transmission frequencies of different types of data within the monitoring interval to generate the data type risk assessment coefficient;

[0026] The calculation formula for the data type risk assessment coefficient is:

[0027] ;

[0028] Where is the data type risk assessment coefficient, 1, 2, 3,..., i are the numbers of different types of data, , , ..., Is the impact score value for different types of data, , , ……, Is the transmission frequency of different types of data, and e is the base of the natural logarithm.

[0029] In a preferred embodiment, determining the importance of the remaining devices includes:

[0030] Comprehensively analyzing the time delay information and data transmission change information of the remaining devices, performing weighted calculations through the state transfer coefficient, entropy change coefficient, and data type risk assessment coefficient, constructing a device importance evaluation model, generating a device importance evaluation coefficient, and the calculation formula for the device importance evaluation coefficient is: ; where, Is the device importance evaluation coefficient, , , Are respectively the proportionality coefficients of the state transfer coefficient, entropy change coefficient, and data type risk assessment coefficient, , , Are all greater than 0;

[0031] Set the device importance evaluation coefficient threshold, obtain the device importance evaluation coefficients of the remaining devices in the industrial Internet of Things environment except the invaded device, compare the device importance evaluation coefficients of the remaining devices with the device importance evaluation coefficient threshold. If the device importance evaluation coefficient is greater than the device importance evaluation coefficient threshold, mark the device as a critical device. If the device importance evaluation coefficient is less than the device importance evaluation coefficient threshold, do not mark the device.

[0032] In a preferred embodiment, determining the correlation information of the remaining devices includes:

[0033] Represent the correlation information of the remaining devices through the clustering correlation coefficient;

[0034] The acquisition logic of the clustering correlation coefficient is as follows: Obtain the operation data of each device in the industrial Internet of Things environment, extract the features of the operation data of each device, including time features, communication features, transmission features, and location features, fuse the time features, communication features, transmission features, and location features, and construct a comprehensive feature vector;

[0035] Normalize the features of different units, calculate the similarity between devices using the cosine similarity, and use the t-SNE algorithm for dimensionality reduction to project the device data into a low-dimensional space, and perform clustering analysis on the devices through the K-Means clustering algorithm;

[0036] Determine the cluster where the invaded device is located, obtain the remaining devices in the cluster where the invaded device is located, calculate the distance between the invaded device and the remaining devices in the cluster by Euclidean distance, and obtain the minimum distance between the remaining devices and the invaded device;

[0037] Use the FP-Growth algorithm to mine frequent itemsets in the cluster where the invaded device is located, identify the frequent itemsets of the devices, and obtain the support and correlation of the remaining devices in the cluster where the invaded device is located;

[0038] Calculate the clustering correlation coefficient, and the calculation formula is: ; where is the clustering correlation coefficient, ZC is the support, XG is the correlation, JL is the minimum distance between the remaining devices and the invaded device, is a positive constant.

[0039] In a preferred embodiment, issue a warning to the remaining devices with a relatively high probability of being invaded, including:

[0040] Perform weighted calculation on the device importance evaluation coefficient and the clustering correlation coefficient to generate an invaded device evaluation coefficient. The calculation formula of the invaded device evaluation coefficient is: ; where is the invaded device evaluation coefficient, is the proportional coefficient of the device importance evaluation coefficient, is the proportional coefficient of the class correlation coefficient, 、 are both greater than 0;

[0041] Set the threshold of the invaded device evaluation coefficient, obtain the invaded device evaluation coefficients of the remaining devices in the industrial Internet of Things environment except the invaded device, compare the invaded device evaluation coefficients of the remaining devices with the threshold of the invaded device evaluation coefficient. If the invaded device evaluation coefficient of the remaining devices is greater than the threshold of the invaded device evaluation coefficient, generate a warning signal. If the invaded device evaluation coefficient of the remaining devices is less than the threshold of the invaded device evaluation coefficient, do not generate a warning signal.

[0042] The technical effects and advantages of the present invention:

[0043] 1. By analyzing the data transmitted by the remaining devices in the industrial Internet of Things environment after invasion, the present invention analyzes the importance of the devices from the perspective of the influence of time delay and data change, quantifies the importance degree of the devices during operation, and the present invention deploys for key devices to reduce the potential losses and risks brought by device invasion.

[0044] 2. The present invention combines time delay, data transmission changes, and the correlation between devices to achieve a multi-angle quantitative assessment of device risks, provide a more comprehensive and accurate security situation awareness, use clustering algorithms to narrow the scope of device analysis, and apply the FP-Growth algorithm within the cluster to efficiently mine frequent item sets, thereby quickly capturing the intrusion correlation patterns between devices, improving detection accuracy, and through the comprehensive quantification of device risks and correlations, helping security managers to prioritize the monitoring and protection of key devices, achieving efficient utilization of resources and precise control of risks. The present invention, through multi-dimensional data fusion, clustering analysis, and association rule mining, helps to accurately evaluate and warn of device intrusion risks in the industrial Internet of Things environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] For the convenience of those skilled in the art to understand, the present invention will be further described below in conjunction with the accompanying drawings;

[0046] Figure 1 It is a schematic flowchart of a method for network security risk assessment based on big data according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0047] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0048] Embodiment 1

[0049] Figure 1 It is a schematic flowchart of a method for network security risk assessment based on big data according to the present invention, specifically including the following steps:

[0050] S1: Determine the devices invaded in the industrial Internet of Things environment. After facing device intrusion, determine the transition probability matrix of the data transmission status of the remaining devices through the historical data of the remaining devices, and combine the transmission data attributes of the remaining devices to determine the time delay information of the remaining devices;

[0051] S2: Determine the data transmission change information of the remaining devices based on the change information amount of the transmission data of the remaining devices and the risk degree of the transmission data of the remaining devices;

[0052] S3: Comprehensively analyze the time delay information and data transmission change information of the remaining devices to determine the importance of the remaining devices, and obtain the key devices with a relatively high degree of importance among the remaining devices;

[0053] S4: By collecting the characteristic data of devices in the industrial Internet of Things environment, determining the cluster where the invaded device is located through cluster analysis, mining frequent item sets using the FP-Growth algorithm in the cluster where the invaded device is located, determining the correlation information of the remaining devices, and combining and analyzing the correlation information and importance of the remaining devices to give early warnings to the remaining devices with a relatively high probability of being invaded.

[0054] In the industrial Internet of Things environment, when a certain device is invaded, determining the importance of other devices and formulating inspection priorities accordingly is a key strategy for network security risk control. By adjusting the dynamic priority, false alarm processing for non-critical devices is reduced, and the work efficiency of operation and maintenance staff is improved. Among them, in the face of device invasion, by collecting the time delay information and data transmission change information of the remaining devices, comprehensively evaluating the importance of each device in the industrial Internet of Things environment, representing the time delay information of the device through the state transfer coefficient, and representing the data transmission change information of the device through the entropy change coefficient and the data type risk assessment coefficient.

[0055] Among them, the advantages of the state transfer coefficient are as follows:

[0056] The state transfer coefficient can effectively describe the transfer characteristics of the device data transmission state. By counting the number of state transfers of historical data transmissions, it can accurately reflect the change trend of the device's communication performance. It can capture the performance of the device in different operating states (such as normal, delayed, or timeout transmissions), providing dynamic information about the device's communication, thereby helping the system to evaluate and optimize the communication quality of the device in real time;

[0057] The state transfer coefficient combines the betweenness centrality of the device to evaluate its importance in the network. For devices with high importance and large betweenness centrality, the state transfer coefficient can reflect the greater impact that potential transmission delays or timeout transmissions may bring. The system can give priority to detecting and monitoring these key devices to reduce transmission failures or performance degradation of important devices in the network and ensure the overall stability and reliability of the system;

[0058] The state transfer coefficient can also combine the time delay sensitivity of different data types to evaluate the transmission quality. For data that is more sensitive to time delay (such as device control data), its weight in the state transfer coefficient is higher, and it can give priority to identifying situations where delays affect the system function. This helps to improve the monitoring and response capabilities for key data and ensure that tasks with high real-time requirements are processed in a timely manner.

[0059] The acquisition logic of the state transfer coefficient is as follows: Define the device data transmission state, and divide the device data transmission state into normal transmission state, delayed transmission state, and timeout transmission state;

[0060] It should be noted that the normal transmission state means that the data can be successfully transmitted to the target node within the preset time threshold. Delayed transmission means that the data exceeds the threshold but is finally successfully transmitted. The timeout transmission state means that the data is not successfully transmitted within the maximum tolerance time and is regarded as a transmission failure, and needs to be retransmitted or discarded.

[0061] Based on the historical records of device operation, determine the transmission results of different types of device data, obtain the number of state transitions of the device data transmission state in the historical records, and construct a transition probability matrix , by solving , obtain the long-term state distribution of device data transmission, and mark the long-term state distribution of device data transmission as: , where is the steady-state probability of the normal transmission state, is the steady-state probability of the delayed transmission state, is the steady-state probability of the timeout transmission state;

[0062] For different types of data transmitted by the device, determine the data types transmitted by the device within the monitoring interval, determine the impact of time delay on different types of data, and calculate the transmission quality score of different types of device data within the monitoring interval. The calculation formula of the transmission quality score is: ; where is the transmission quality score, is the weight coefficient of different types of data in the normal transmission state, is the weight coefficient of different types of data in the delayed transmission state, is the weight coefficient of different types of data in the timeout transmission state;

[0063] It should be noted that the device may generate multiple types of data, and different data types have different sensitivities to time delay. Data such as temperature and humidity generated by conventional sensors have lower sensitivities to time delay. Therefore, the weight coefficients of data generated by conventional sensors in different device data transmission states are lower, while device control type data has higher sensitivities to time delay. For example, the control of a robotic arm. Therefore, the weight coefficients of device control type data in different device data transmission states are higher.

[0064] Regarding each device as a node, determine the communication relationship graph of the devices within the monitoring interval. According to the topological centrality of the devices within the monitoring interval, obtain the betweenness centrality of the devices after normalization, and calculate the state transfer coefficient. The calculation formula is: ; where is the state transfer coefficient, is the betweenness centrality of the device;

[0065] It should be noted that after normalization, the betweenness centrality of each device ranges from 0 to 1, where the betweenness centrality of the key node is 1 and the betweenness centrality of the edge node is 0.

[0066] It can be seen from the formula that the larger the state transfer coefficient is, the more important the equipment is. Secondly, if an intruder invades the equipment, the time delay may be greater. When there is equipment intrusion in the factory, the intruder is more likely to invade the equipment, so it is necessary to give priority to the detection of the equipment.

[0067] The advantages of the entropy variation coefficient are:

[0068] The entropy value variation coefficient can evaluate the randomness and degree of variation of the data generated by the device within the monitoring interval by analyzing the uncertainty of the device data. Devices with large entropy values ​​have more dramatic changes during data transmission, indicating that the state of the device may be more complex or unstable. This uncertainty can help identify potential failure risks or abnormal conditions in the system, and make timely adjustments and responses;

[0069] The coefficient of change of entropy can also reveal whether the device is vulnerable to intruders. Device data with high entropy values ​​indicates that there is greater uncertainty in its transmission process, which also means that the device is more likely to be attacked or interfered with. After intruders invade these devices, it may cause a greater impact, so it is necessary to give priority to intrusion detection and security protection of these devices. This provides an effective reference for the security management of the Industrial Internet of Things;

[0070] In the industrial IoT environment, the types of devices are diverse and the operating conditions are complex. The entropy change coefficient can adapt to the characteristics of different devices and data types, evaluate the characteristics of different data streams, and help engineers make appropriate judgments and optimization plans based on specific situations. This flexibility enables the entropy change coefficient to be widely used in various industrial scenarios.

[0071] The logic for obtaining the entropy value change coefficient is as follows: according to the data type transmitted by the device in the monitoring interval, the probability density distribution of different types of data is determined using kernel density estimation, the information entropy of different types of data in the monitoring interval is calculated based on the probability density distribution of different types of data, and the entropy value change coefficient is calculated according to the weight of different types of data in the industrial Internet of Things environment;

[0072] The calculation formula for the probability density distribution of different types of data is: ;in, is the probability density function of different data types of the device in the monitoring interval, is the total number of samples of different data types within the monitoring interval, n is the sample index, SJ is the specified value of the data, is the data of different data types of the device in the monitoring interval, h is the bandwidth,

[0073] The calculation formula for the entropy change coefficient is as follows: ; where is the entropy change coefficient, is the weight of different types of data in the industrial Internet of Things environment.

[0074] As can be seen from the formula, the larger the entropy change coefficient, the higher the uncertainty of the data generated by the device within the monitoring interval, the greater the amount of information generated, the higher the importance of the device, and secondly, the greater the possible impact of an intruder on the device. When there is a device intrusion in the factory, the intruder is more likely to invade this device. Therefore, it is necessary to detect this device first.

[0075] The advantages of the data type risk assessment coefficient are as follows:

[0076] The data type risk assessment coefficient can evaluate data risks based on abnormal events of different types of data of the device. By quantifying the abnormal events and impact scores of various types of data, it can accurately identify which data types are more potentially risky to the transmission and operation of the device. This enables the system to centrally monitor these high-risk data types, thereby reducing the probability of device failures or security incidents;

[0077] According to the calculation of the data type risk assessment coefficient, devices with a larger risk coefficient may face higher security risks. Intruders are more likely to attack those high-risk devices because the abnormal data they may generate or the abnormal events they may encounter can cause greater negative impacts. Therefore, the risk assessment of device intrusion can guide the priority of security protection, ensure key detection and protection of high-risk devices, and thus improve the overall security protection level of the factory.

[0078] The acquisition logic of the data type risk assessment coefficient is as follows: According to the data types generated by the device, determine the abnormal events of different types of data of the device, and based on the abnormal events of different types of data of the device, determine the impact score values of different types of data;

[0079] According to the data types generated by the device within the monitoring interval, construct a regression model with the impact score values of different types of data within the monitoring interval and the transmission frequencies of different types of data within the monitoring interval to generate the data type risk assessment coefficient;

[0080] The calculation formula for the data type risk assessment coefficient is as follows:

[0081] ;

[0082] where is the data type risk assessment coefficient, 1, 2, 3,..., i are the numbers of different types of data, , , ……, is the impact score value for different types of data, , , ……, is the transmission frequency of different types of data, where e is the base of the natural logarithm.

[0083] It should be noted that if a certain type of data is not generated by the device during the monitoring period, the transmission frequency of this type of data is 0.

[0084] As can be seen from the formula, the larger the data type risk assessment coefficient, the higher the risk of the data generated by the device during the monitoring period, the greater the possible negative impact caused by an intruder invading the device. When there is a device invasion in the factory, the intruder is more likely to invade this device. Therefore, it is necessary to detect this device first.

[0085] Comprehensively analyze the time delay information and data transmission change information of the remaining devices, and perform weighted calculations through the state transfer coefficient, entropy change coefficient, and data type risk assessment coefficient to construct an equipment importance assessment model and generate an equipment importance assessment coefficient. The calculation formula for the equipment importance assessment coefficient is: ; where is the equipment importance assessment coefficient, , , are the proportionality coefficients of the state transfer coefficient, entropy change coefficient, and data type risk assessment coefficient respectively, , , are all greater than 0.

[0086] As can be seen from the formula, the larger the state transfer coefficient, entropy change coefficient, and data type risk assessment coefficient, the larger the equipment importance assessment coefficient, indicating that the importance of the equipment during the monitoring period is greater, and the possible impact caused by an intruder invading the device is greater. On the contrary, the smaller the state transfer coefficient, entropy change coefficient, and data type risk assessment coefficient, the smaller the equipment importance assessment coefficient, indicating that the importance of the equipment during the monitoring period is smaller, and the possible impact caused by an intruder invading the device is smaller.

[0087] Set the threshold of the equipment importance assessment coefficient, obtain the equipment importance assessment coefficients of the remaining devices in the industrial Internet of Things environment except the invaded device, and compare the equipment importance assessment coefficients of the remaining devices with the threshold of the equipment importance assessment coefficient. If the equipment importance assessment coefficient is greater than the threshold of the equipment importance assessment coefficient, mark the device as a key device, indicating that the data generated by the device during the monitoring period is of high importance and there is a high risk of invasion. If the equipment importance assessment coefficient is less than the threshold of the equipment importance assessment coefficient, do not mark the device.

[0088] In this embodiment, by analyzing the data transmitted by the remaining devices in the industrial Internet of Things environment after intrusion, the importance of the devices is analyzed from the perspectives of the impact of time delay and data change, and the importance degree of the devices during operation is quantified. The present invention deploys for key devices to reduce the potential losses and risks brought by device intrusion.

[0089] Embodiment 2

[0090] The above embodiment determines the importance of the devices by analyzing the data generated by the devices. This embodiment determines the intensity of the possibility of other devices being invaded by analyzing the connection between the invaded device and the remaining devices.

[0091] By collecting the characteristic data of the devices in the industrial Internet of Things environment, the cluster where the invaded device is located is determined through cluster analysis. The FP-Growth algorithm is used to mine the frequent item sets in the cluster where the invaded device is located, the correlation information of the devices is determined, and the correlation information of the devices is represented by the cluster correlation coefficient.

[0092] The advantages of the cluster correlation coefficient are as follows:

[0093] Comprehensively considering multi-dimensional features such as time, communication, transmission, and location, it can comprehensively characterize the similarity between devices, thereby more accurately capturing the internal correlation of the device behavior patterns. The t-SNE algorithm is used to reduce the dimension of the high-dimensional data, and then combined with the K-Means clustering method, the device data is projected into a low-dimensional space to achieve precise grouping of devices with similar comprehensive features;

[0094] By calculating the minimum value of the Euclidean distance between the invaded device and other devices in the cluster, the spatial correlation between devices can be quantified, which helps to identify potential attack chains. The FP-Growth algorithm is applied to mine the frequent item sets of the devices in the cluster, and the support degree and correlation of the devices in the intrusion event are calculated to further reveal the possibility of the devices being attacked simultaneously and improve the warning accuracy.

[0095] The acquisition logic of the cluster correlation coefficient is as follows: Obtain the operation data of each device in the industrial Internet of Things environment, perform feature extraction on the operation data of each device, including time feature, communication feature, transmission feature, and location feature, fuse the time feature, communication feature, transmission feature, and location feature, and construct a comprehensive feature vector;

[0096] It should be noted that the time feature includes the time period during which the device operates, the communication feature includes the packet exchange frequency between devices, the transmission feature includes traffic surges and abnormal transmission delays, and the location feature includes the physical / logical distance between devices. The time feature can reflect the similarity in the operating time of devices, the communication feature can reflect the similarity in the communication patterns between devices, the transmission feature can reflect the similarity in data patterns, and the location feature can reflect the similarity of devices in the network topology.

[0097] Normalize the features of different units, calculate the similarity between devices using cosine similarity, and use the t-SNE algorithm for dimensionality reduction to project the device data into a low-dimensional space, and perform clustering analysis on the devices through the K-Means clustering algorithm;

[0098] It should be noted that the K-Means clustering algorithm classifies the devices to obtain clusters of devices with similar comprehensive feature vectors, and the number of clusters in the clustering algorithm is determined by methods such as the elbow method, silhouette coefficient method, and gap statistic.

[0099] Determine the cluster where the compromised device is located, obtain the remaining devices in the cluster where the compromised device is located, calculate the distance between the compromised device and the remaining devices in the cluster through Euclidean distance, and obtain the minimum distance between the remaining devices and the compromised device;

[0100] It should be noted that there may be multiple compromised devices in the same cluster. Therefore, the association degree between the remaining devices and the compromised device is quantified by the minimum distance between the remaining devices and the compromised device.

[0101] Use the FP-Growth algorithm to mine frequent itemsets in the cluster where the compromised device is located, identify the frequent itemsets of the devices, and obtain the support and correlation of the remaining devices in the cluster where the compromised device is located;

[0102] It should be noted that the support of the remaining devices in the cluster where the compromised device is located represents the frequency of the device appearing in all compromised devices, that is, the importance of the device in the attack event. Devices that appear frequently are more likely to become attack targets and should have a higher importance index. By calculating the frequent itemsets using the FP-Growth algorithm, the frequency of each device appearing in the intrusion event is obtained. If the support of the remaining devices is higher, the possibility of being compromised is higher;

[0103] The correlation of the remaining devices in the cluster where the compromised device is located represents the degree of association between the device and other devices being compromised simultaneously. It can be calculated using methods such as Pearson correlation coefficient and cosine similarity. Devices with high correlation may belong to the same attack chain and should have an increased importance index. By using the FP-Growth algorithm to find out which devices are always attacked together, their attack correlation is calculated. If the correlation of the remaining devices is higher, the possibility of being compromised is higher.

[0104] Calculate the clustering correlation coefficient, and the calculation formula is: ; where is the clustering correlation coefficient, ZC is the support degree, XG is the correlation, JL is the minimum distance between the remaining devices and the invaded device, is a positive constant.

[0105] It can be seen from the formula that the larger the clustering correlation coefficient, the stronger the correlation between the device and the invaded device, and the more likely the device is to be invaded. When there is a device invasion in the factory, the invader is more likely to invade this device. Therefore, it is necessary to detect this device first.

[0106] Perform weighted calculation on the device importance evaluation coefficient and the clustering correlation coefficient to generate an invaded device evaluation coefficient. The calculation formula of the invaded device evaluation coefficient is: ; where is the invaded device evaluation coefficient, is the proportional coefficient of the device importance evaluation coefficient, is the proportional coefficient of the class correlation coefficient, 、 are both greater than 0.

[0107] Set the threshold of the invaded device evaluation coefficient, obtain the invaded device evaluation coefficients of the remaining devices in the industrial Internet of Things environment except the invaded devices, and compare the invaded device evaluation coefficients of the remaining devices with the threshold of the invaded device evaluation coefficient. If the invaded device evaluation coefficient of the remaining devices is greater than the threshold of the invaded device evaluation coefficient, a warning signal will be generated, indicating that the device may have a high risk and needs to be immediately checked by the staff to ensure the security of the device. If the invaded device evaluation coefficient of the remaining devices is less than the threshold of the invaded device evaluation coefficient, no warning signal will be generated.

[0108] The present invention combines time delay, data transmission changes and device - to - device correlation to realize multi - angle quantitative evaluation of device risks, provide a more comprehensive and accurate security situation awareness, use the clustering algorithm to narrow the device analysis scope, and apply the FP - Growth algorithm within the cluster to efficiently mine frequent item sets, so as to quickly capture the invasion association patterns between devices, improve the detection accuracy. Through the comprehensive quantification of device risks and correlations, it helps security managers to prioritize the monitoring and protection of key devices, realize the efficient use of resources and the precise control of risks. The present invention, through multi - dimensional data fusion, clustering analysis and association rule mining, helps to accurately evaluate and warn of device invasion risks in the industrial Internet of Things environment.

[0109] The above formulas are all dimensionless and take their numerical values for calculation. The formulas are obtained by collecting a large amount of data and performing software simulations to get a formula that is closest to the actual situation. The preset parameters in the formulas are set by those skilled in the art according to the actual situation.

[0110] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, the processes or functions described in the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from a website, computer, server, or data center to another website, computer, server, or data center in a wired or wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that contains one or more collections of available media. The available media can be magnetic media (such as floppy disks, hard disks, magnetic tapes), optical media (such as DVDs), or semiconductor media. The semiconductor media can be a solid-state drive.

[0111] It should be understood that in various embodiments of the present application, the magnitudes of the serial numbers of the above processes do not mean the order of execution. The order of execution of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0112] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0113] In several embodiments provided by this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the devices or units can be in electrical, mechanical, or other forms.

[0114] If the above functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs, etc., which can store program codes.

[0115] The above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

Claims

1. A network security risk assessment method based on big data, characterized in that: The specific steps include: S1: Determine the invaded device in the industrial Internet of Things environment. After the device is invaded, determine the transition probability matrix of the data transmission state of the remaining devices through the historical data of the remaining devices, and determine the time delay information of the remaining devices in combination with the transmission data attributes of the remaining devices; S2: determining the data transmission change information of the remaining devices by comparing the amount of data transmission change information of the remaining devices and the risk level of data transmission of the remaining devices; S3: Comprehensively analyze the time delay information and data transmission change information of the remaining devices to determine the importance of the remaining devices. By setting the device importance assessment coefficient threshold, the device importance assessment coefficients of the remaining devices in the industrial Internet of Things environment except the invaded device are obtained. The device importance assessment coefficients of the remaining devices are compared with the device importance assessment coefficient threshold. If the device importance assessment coefficient is greater than the device importance assessment coefficient threshold, the device is marked as a critical device. If the device importance assessment coefficient is less than the device importance assessment coefficient threshold, the device is not marked. S4: by collecting characteristic data of devices in the industrial Internet of Things environment, determining the cluster where the invaded device is located through cluster analysis, using the FP-Growth algorithm to mine frequent item sets in the cluster where the invaded device is located, determining the correlation information between the remaining devices and the invaded device, and combining the correlation information and importance of the remaining devices for analysis, generating an intrusion device evaluation coefficient, and setting an intrusion device evaluation coefficient threshold to obtain the intrusion device evaluation coefficients of the remaining devices other than the invaded device in the industrial Internet of Things environment, and comparing the intrusion device evaluation coefficients of the remaining devices with the intrusion device evaluation coefficient threshold. If the intrusion device evaluation coefficients of the remaining devices are greater than the intrusion device evaluation coefficient threshold, a warning signal is generated; if the intrusion device evaluation coefficients of the remaining devices are less than the intrusion device evaluation coefficient threshold, no warning signal is generated; Time delay information for other devices, including: The time delay information of the remaining devices is represented by the state transition coefficient; The acquisition logic of the state transfer coefficient is: define the device data transmission state, and divide the device data transmission state into a normal transmission state, a delayed transmission state, and a timeout transmission state; Based on the historical records of device operation, determine the transmission results of different types of device data, obtain the state transition times of device data transmission status in the historical records, and construct the transition probability matrix , by solving , we get the long-term state distribution of device data transmission, and mark the long-term state distribution of device data transmission as: ,in, is the steady-state probability of the normal transmission state, is the steady-state probability of the delayed transmission state, is the steady-state probability of the timeout transmission state; For different types of data transmitted by the device, determine the type of data transmitted by the device within the monitoring interval, determine the impact of time delay on different types of data, and calculate the transmission quality score of different types of data of the device within the monitoring interval. The calculation formula of the transmission quality score is: ;in, Rate the quality of the transmission, is the weight coefficient of different types of data in normal transmission state, is the weight coefficient of different types of data in delayed transmission state, is the weight coefficient of different types of data in the timeout transmission state; Taking each device as a node, the communication relationship graph of the devices in the monitoring interval is determined. According to the topological centrality of the devices in the monitoring interval, the normalized betweenness centrality of the devices is obtained, and the state transfer coefficient is calculated. The calculation formula is: ;in, is the state transfer coefficient, is the betweenness centrality of the device.

2. According to the big data-based network security risk assessment method of claim 1, it is characterized in that: Data transmission change information of other devices, including: The data transmission change information of other devices is represented by the entropy value change coefficient and the data type risk assessment coefficient; The logic for obtaining the entropy value change coefficient is as follows: according to the data type transmitted by the device in the monitoring interval, the probability density distribution of different types of data is determined using kernel density estimation, the information entropy of different types of data in the monitoring interval is calculated based on the probability density distribution of different types of data, and the entropy value change coefficient is calculated according to the weight of different types of data in the industrial Internet of Things environment; The calculation formula for the probability density distribution of different types of data is: ;in, is the probability density function of different data types of the device in the monitoring interval, is the total number of samples of different data types within the monitoring interval, n is the sample index, SJ is the specified value of the data, is the data of different data types of the device in the monitoring interval, h is the bandwidth, The calculation formula of the entropy value change coefficient is: ;in, is the entropy change coefficient, The weights of different types of data in the Industrial Internet of Things environment.

3. A network security risk assessment method based on big data according to claim 2, characterized in that: Data type risk assessment factors, including: The acquisition logic of the data type risk assessment coefficient is: according to the data type generated by the device, determine the abnormal events of different types of data of the device, and based on the abnormal events of different types of data of the device, determine the impact score values ​​of different types of data; According to the data type generated by the device within the monitoring interval, a regression model is constructed by combining the impact score values ​​of different types of data within the monitoring interval and the transmission frequency of different types of data within the monitoring interval to generate a data type risk assessment coefficient; The calculation formula for the data type risk assessment coefficient is: ; in, is the data type risk assessment coefficient, 1, 2, 3, ..., i are the numbers of different types of data, , , ……、 The impact scores for different types of data are , , ……、 is the transmission frequency of different types of data, and e is the base.

4. A network security risk assessment method based on big data according to claim 3, characterized in that: Determine the importance of the remaining equipment, including: The time delay information and data transmission change information of the remaining devices are comprehensively analyzed, and weighted calculation is performed through the state transfer coefficient, entropy value change coefficient and data type risk assessment coefficient to build an equipment importance assessment model and generate the equipment importance assessment coefficient. The calculation formula of the equipment importance assessment coefficient is: ;in, is the equipment importance assessment coefficient, , , are the proportional coefficients of the state transition coefficient, entropy value change coefficient and data type risk assessment coefficient, respectively. , , Both are greater than 0.

5. A network security risk assessment method based on big data according to claim 4, characterized in that: Determine the association information between other devices and the hacked device, including: The correlation information between the remaining devices and the invaded device is represented by the cluster correlation coefficient; The logic for obtaining the clustering correlation coefficient is as follows: obtaining the operating data of each device in the industrial Internet of Things environment, extracting features of the operating data of each device, including time features, communication features, transmission features and location features, fusing the time features, communication features, transmission features and location features to construct a comprehensive feature vector; The features of different units are normalized, the cosine similarity is used to calculate the similarity between devices, and the t-SNE algorithm is used to reduce the dimension, so that the device data is projected into a low-dimensional space, and the K-Means clustering algorithm is used to perform cluster analysis on the devices; Determine the cluster where the invaded device is located, obtain the other devices in the cluster where the invaded device is located, calculate the distance between the invaded device and the other devices in the cluster by Euclidean distance, and obtain the minimum distance between the other devices and the invaded device; Use the FP-Growth algorithm to mine frequent itemsets in the cluster where the hacked device is located, identify the frequent itemsets of the device, and obtain the support and relevance of the remaining devices in the cluster where the hacked device is located; Calculate the clustering correlation coefficient, the calculation formula is: ;in, is the clustering correlation coefficient, ZC is the support, XG is the correlation, and JL is the minimum distance between the remaining devices and the invaded device. is a positive constant, where the support of the remaining devices in the cluster where the invaded device is located indicates the frequency of the device appearing in all invaded devices, that is, the importance of the device in the attack event, and the correlation of the remaining devices in the cluster where the invaded device is located indicates the degree of association between the device and other devices being invaded at the same time.

6. A network security risk assessment method based on big data according to claim 5, characterized in that: include: The device importance evaluation coefficient and the cluster correlation coefficient are weighted to generate the intrusion device evaluation coefficient. The calculation formula of the intrusion device evaluation coefficient is: ;in, is the intrusion device assessment coefficient, is the proportional coefficient of the equipment importance assessment coefficient, is the proportional coefficient of the clustering correlation coefficient, , Both are greater than 0.

Citation Information

Patent Citations

  • Abnormal program processing method and system

    CN117421147A

  • Adaptive intrusion detection system and method based on deep learning

    CN118827217A