A network security detection method based on big data
Through big data acquisition and analysis, combined with abnormal traffic detection index YL, threat assessment value WW and security situation index AQ, the shortcomings of network security assessment in the existing technology are solved, comprehensive and dynamic assessment and optimization of network security conditions are achieved, and detection flexibility and accuracy are improved.
Patent Information
- Application Number
- CN202510024259.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-07
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2045-01-07
AI Technical Summary
The existing technology is difficult to comprehensively and dynamically evaluate network security status, lacks the ability to capture subtle changes in network traffic and potential threats, and lacks a circular feedback mechanism, cannot continuously optimize and improve based on detection results, and cannot fully utilize the advantages of big data.
The big data acquisition module is adopted to measure the abnormality of network traffic, evaluate the current threat level of the network, and comprehensively evaluate the overall security status unit of the network, and use the abnormal traffic detection index YL, threat evaluation value WW and security situation index AQ to perform dynamic evaluation and optimization.
It realizes a comprehensive and dynamic assessment of network security conditions, improves the flexibility and accuracy of detection, has a circular feedback mechanism, and can automatically adjust thresholds according to network traffic and threat changes, optimize detection algorithms, and improve network security and detection efficiency.
Smart Images

Figure CN119814457B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security detection, and in particular to a network security detection method based on big data. Background Art
[0002] With the rapid development and widespread application of information technology, the Internet has penetrated into all aspects of social life, including government, business, education, medical care, and finance. However, with the popularization of the Internet, network security issues have become increasingly prominent, including hacker attacks, virus transmission, and data leakage. These pose serious threats to individuals, businesses, and even national security. These threats may not only lead to property losses, but also affect social stability and national security. Therefore, it is particularly important to develop an effective network security detection method.
[0003] Currently, existing technologies often rely on a single detection method, which makes it difficult to capture subtle changes in network traffic and potential threats. Existing technologies also lack the ability to comprehensively evaluate network security and are unable to integrate multiple security factors for unified analysis. In addition, many existing technologies use static thresholds to determine whether the network is secure, which is often not flexible and accurate in practical applications. As a result, existing technologies often lack a circular feedback mechanism and cannot be continuously optimized and improved based on detection results. In addition, existing technologies have limitations in processing and analyzing big data and cannot fully utilize the advantages of big data to improve the accuracy and efficiency of detection. Summary of the Invention
[0004] The purpose of the present invention is to provide a network security detection method based on big data, which solves the problems raised in the above background technology.
[0005] To achieve the above objectives, the present invention provides the following technical solutions, including a big data acquisition module, a big data calculation and evaluation module, and a response and disposal module. The big data calculation and evaluation module includes a unit for measuring the degree of abnormality of network traffic, a unit for evaluating the degree of threat faced by the current network, and a unit for comprehensively evaluating the overall security status of the network.
[0006] The specific detection implementation steps are as follows:
[0007] Step 1: Using the big data acquisition module, collect network traffic data, security event data and system security status data of the current detection period;
[0008] Step II: using the network traffic anomaly degree measuring unit, first calculate and output an abnormal traffic detection index YL;
[0009] Step III: introducing the abnormal traffic detection index YL into the unit for evaluating the threat level faced by the current network, and calculating and outputting a threat assessment value WW;
[0010] Step III: introducing the abnormal traffic detection index YL and the threat assessment value WW into the comprehensive network overall security status evaluation unit, and calculating and outputting the security situation index AQ for detection and analysis;
[0011] Step IIIII: The response and disposal module makes a security response and disposal based on the security situation index AQ.
[0012] Optionally, the equipment used by the big data acquisition module includes a network traffic analyzer, a SIEM system, and a security monitoring device;
[0013] The equipment used by the big data calculation and evaluation module includes a server;
[0014] The equipment used by the response and disposal module includes a security patch management system and anti-malware tools.
[0015] Optionally, the calculation formula for the unit for measuring the degree of abnormality of network traffic is as follows:
[0016] ;
[0017] in:
[0018] YL is the abnormal traffic detection index;
[0019] L in is the inbound traffic, L in Refers to the amount of data entering the network per unit time;
[0020] L out is the outbound traffic, L out Refers to the amount of data leaving the network per unit time;
[0021] L avg is the average flow rate, L avg Refers to the average data traffic of the network during the current detection period;
[0022] L peak is the peak flow rate, L peak Refers to the maximum data traffic generated by the network during the current detection period.
[0023] Optionally, the average flow rate L avg The calculation formula is as follows:
[0024] L avg =(L1+L2+L3+......+L n ) / n;
[0025] n is the current cycle period, reflecting the amount of time in the current detection cycle;
[0026] L1 is the first time period for detecting data traffic, L2 is the second time period for detecting data traffic, L3 is the third time period for detecting data traffic, L n Detect data traffic for the nth period;
[0027] And any detection cycle is the average flow rate L of the current detection cycle avg Perform real-time update calculations.
[0028] Optionally, the calculation formula for evaluating the threat level of the current network is as follows:
[0029] ;
[0030] in:
[0031] WW is the threat assessment value;
[0032] EX is the malicious behavior count, which reflects the number of malicious behaviors detected. Malicious behaviors include virus transmission, phishing attacks, DDoS attacks, SQL injection, and cross-site scripting (XSS) attacks.
[0033] ZX is the total behavior count, ZX reflects the number of all behaviors detected;
[0034] WX is the number of new threats. WX reflects the number of new threat types that have appeared during the current detection cycle. Threat types include viruses, Trojans, worms, ransomware, and spyware.
[0035] LWX is the number of historical threats. LWX reflects the number of threat types that have existed in previous detection cycles.
[0036] Optionally, the virus propagation: the virus propagates through the network and infects files and programs in the system;
[0037] Phishing attacks: using fake websites and emails to trick users into revealing sensitive information;
[0038] The DDoS attack is a distributed denial of service attack that paralyzes the target system through a large number of requests.
[0039] SQL injection: exploiting website vulnerabilities to send malicious SQL statements to the database to obtain and tamper with data;
[0040] The cross-site scripting attack (XSS) injects malicious scripts into the target website to steal user information and perform other malicious operations.
[0041] Optionally, the calculation formula for the comprehensive evaluation unit of the overall network security status is as follows:
[0042] ;
[0043] BDL=BD / ZBD;
[0044] EZL=CZL / EX;
[0045] WW avg =(WW1+WW2+WW3+……+WW m ) / m;
[0046] in:
[0047] AQ is the security posture index;
[0048] BDL is the patch application rate;
[0049] BD is the number of systems with patches applied, and ZBD is the total number of systems;
[0050] FE is the amount of anti-malware software;
[0051] EZL is the efficiency of malicious behavior;
[0052] CZL is the number of successfully executed malicious actions;
[0053] WW avg is the threat assessment average;
[0054] m is the total number of historical detection cycles;
[0055] WW1 is the threat assessment value of the first detection cycle, WW2 is the threat assessment value of the second detection cycle, WW3 is the threat assessment value of the third detection cycle, and WW m The threat assessment value of the mth detection cycle is WW, and when entering the next detection cycle, the current threat assessment value WW is the threat assessment value WW of the mth detection cycle. m ;
[0056] L in,max The maximum inbound traffic is the maximum inbound data traffic of the network in the current detection cycle.
[0057] Optionally, the detection and analysis based on the security situation index AQ is as follows:
[0058] If the security situation index AQ is higher than the average security situation index AQ avg , it reflects that the current network faces high security risks and there are a lot of malicious behaviors and abnormal traffic, and network security measures should be strengthened;
[0059] If the security situation index AQ is lower than the average security situation index AQ avg , which reflects that the current network status is relatively stable, with little malicious behavior and abnormal traffic, and the current network security measures should be maintained.
[0060] Optionally, the average security index AQ avg The calculation formula is as follows:
[0061] AQ avg =(AQ1+AQ2+AQ3+......+AQ m ) / m;
[0062] AQ1 is the security situation index of the first detection cycle, AQ2 is the security situation index of the second detection cycle, AQ3 is the security situation index of the third detection cycle, and AQ m The security situation index of the mth detection cycle, and when entering the next detection cycle, the current security situation index AQ is the security situation index AQ of the mth detection cycle m .
[0063] Compared with the prior art, the present invention has the following beneficial effects:
[0064] 1. The present invention can comprehensively and dynamically evaluate the security status of the network by measuring the network traffic anomaly degree unit, evaluating the current network threat degree unit and comprehensively evaluating the overall network security status unit. Among them, the abnormal traffic detection index YL can capture abnormal changes in network traffic, the threat assessment value WW can evaluate the current threat degree faced by the network, and the security situation index AQ can comprehensively consider multiple factors to give the overall security situation of the network. Dynamic threshold settings are adopted, including the average traffic L avg The threat assessment value WW can automatically adjust the threshold according to the actual situation of network traffic and threat assessment results, thereby improving the accuracy and flexibility of detection.
[0065] 2. The present invention uses the security situation index AQ as a benchmark for determining the cyclic impact of detection, thereby realizing a cyclic feedback mechanism and continuously optimizing the calculation parameters and algorithms of the abnormal traffic detection index YL and the threat assessment value WW based on the detection results, thereby improving the accuracy and efficiency of detection.
[0066] 3. The present invention fully utilizes the advantages of big data technology, improves the accuracy and efficiency of detection by collecting and analyzing multi-dimensional data, and at the same time, improves the intelligence level of detection by continuously learning and optimizing algorithm models. It also combines big data technology with the latest research results in the field of network security detection, is innovative and practical, and can significantly improve network security and reduce security risks. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] Figure 1 The flowchart of the network security detection method based on big data is shown in the figure.
[0068] Figure 2This is a schematic diagram of the structure of the big data calculation and evaluation module of the present invention;
[0069] Figure 3 Schematic diagram of the structure of malicious behavior in the present invention;
[0070] Figure 4 It is a structural diagram of the threat type in the present invention. DETAILED DESCRIPTION
[0071] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0072] This big data-based network security detection method is different from existing network security detection methods. Existing network security detection methods often rely on single detection means and tools, which make it difficult to comprehensively and accurately assess the security status of the network. This algorithm unit collects and analyzes multi-dimensional data on network traffic, security events, and system status, and uses advanced algorithms and models to conduct comprehensive security detection on the network, thereby achieving a comprehensive and dynamic assessment of network security.
[0073] For example 1, please refer to Figures 1 to 4 This embodiment provides a network security detection method based on big data, including a big data acquisition module, a big data calculation and evaluation module, and a response and disposal module. The big data calculation and evaluation module includes a unit for measuring the degree of abnormality of network traffic, a unit for evaluating the degree of threat faced by the current network, and a unit for comprehensively evaluating the overall security status of the network.
[0074] The specific detection implementation steps are as follows:
[0075] Step 1: Using the big data acquisition module, collect network traffic data, security event data and system security status data of the current detection period;
[0076] Step II: using the unit for measuring the degree of abnormality of network traffic, first calculate and output the abnormal traffic detection index YL;
[0077] Step III: introduce the abnormal traffic detection index YL into the unit for evaluating the threat level of the current network, and calculate and output the threat assessment value WW;
[0078] Step III: The abnormal traffic detection index YL and the threat assessment value WW are introduced into the comprehensive assessment unit for the overall network security status, and the security situation index AQ is calculated and output for detection and analysis;
[0079] Step IIIII: The response and disposal module makes security responses and disposals based on the security situation index AQ;
[0080] The equipment used in the big data acquisition module includes network traffic analyzers, SIEM systems, and security monitoring equipment;
[0081] The equipment used in the big data computing and evaluation module includes servers;
[0082] The equipment used in the response and disposal module includes security patch management systems and anti-malware tools.
[0083] In this embodiment, the system, through the mutual cooperation of three algorithm units and the combination of the three calculation results of YL, WW and AQ, together constitutes the core part of the network security detection method based on big data, providing strong support and protection for network security. Specifically, YL is the abnormal traffic detection index, which can reflect the fluctuation and abnormal changes of network traffic. When network traffic is abnormal, the value of YL will significantly deviate from the normal range, thereby prompting timely measures to be taken for investigation and response. WW is the threat assessment value, which can more comprehensively assess the current security status of the network, including the presence of potential threats, the type and number of threats, which is of great significance for formulating targeted network security defense strategies. AQ is the security situation index, which can comprehensively reflect the security situation of the network, including the security of the system, the effectiveness of defense measures, and the severity of potential threats. It has important guiding significance for formulating comprehensive network security protection plans, optimizing network security strategies, and improving network security defense capabilities. The calculation results of AQ can also affect the calculation of YL and WW, which makes the three algorithms and their parameters of this system have significant beneficial effects on network security detection. They can not only improve the sensitivity and accuracy of detection, but also comprehensively assess the network security status and optimize detection strategies and methods.
[0084] See also Figures 1 to 4 ,The calculation formula for measuring the unit of network traffic anomaly degree is as follows:
[0085] ;
[0086] in:
[0087] YL is the abnormal traffic detection index;
[0088] L in is the inbound traffic, L in Refers to the amount of data entering the network per unit time;
[0089] L out is the outbound traffic, L outRefers to the amount of data leaving the network per unit time;
[0090] L avg is the average flow rate, L avg Refers to the average data traffic of the network during the current detection period;
[0091] L peak is the peak flow rate, L peak Refers to the maximum data traffic generated by the network during the current detection period;
[0092] Average flow rate L avg The calculation formula is as follows:
[0093] L avg =(L1+L2+L3+......+L n ) / n;
[0094] n is the current cycle period, reflecting the amount of time in the current detection cycle;
[0095] L1 is the first time period for detecting data traffic, L2 is the second time period for detecting data traffic, L3 is the third time period for detecting data traffic, L n Detect data traffic for the nth period;
[0096] And any detection cycle is the average flow rate L of the current detection cycle avg Perform real-time update calculations.
[0097] In this embodiment: First, in this algorithm unit, The calculation part is designed to reflect the balance and volatility of network traffic by in With outbound traffic L out Adding and then subtracting can capture the asymmetry and degree of change of traffic. This calculation part is the core of the calculation formula for measuring the degree of abnormality of network traffic. It is used to measure the degree of abnormality of network traffic. When the traffic shows significant imbalance and volatility, the value of this part will increase, thereby increasing the value of the abnormal traffic detection index YL, indicating the existence of abnormal traffic. Specifically, the inbound traffic L in this algorithm unit is in With outbound traffic L out It is the basis for calculating the abnormal traffic detection index YL. They directly reflect the inflow and outflow of network traffic. By calculating the difference between the two, it is possible to preliminarily determine whether there is an abnormality in network traffic. When the inbound traffic L in There is a sudden and substantial increase in outbound traffic L out If it remains the same or decreases slightly, it means that the network is under external attack and there is a risk of data leakage;
[0098] The average flow rate L avgAs an important parameter in the calculation of abnormal traffic detection index YL, it represents the normal level of network traffic and is compared with the average traffic L avg By comparing the current flow rate with the normal flow rate, it can more accurately determine whether the current flow rate has deviated from the normal range, thereby detecting flow anomalies in a timely manner;
[0099] “ The calculation part is used to measure the difference between the peak value and the average value of network traffic, that is, the fluctuation range of traffic. By introducing this calculation part, the abnormal traffic detection index YL can more comprehensively evaluate the abnormal degree of network traffic. When the difference between the peak traffic and the average traffic is large, it indicates that the network is experiencing traffic peaks and abnormal fluctuations, which will also increase the value of the abnormal traffic detection index YL. peak It reflects the highest level of network traffic, which is of great significance for evaluating the volatility and stability of network traffic. In the calculation of the abnormal traffic detection index YL, the peak traffic L is considered. peak With the average flow L avg The difference between the two values can be used to further determine the degree and nature of flow anomalies;
[0100] The abnormal traffic detection index YL calculated by this algorithm unit can more accurately capture subtle changes in network traffic by comprehensively considering multiple traffic parameters, thereby improving the sensitivity of detection. The abnormal traffic detection index YL not only considers the absolute value of the traffic, but also the volatility and stability of the traffic, so as to more comprehensively evaluate the overall situation of the network traffic. In addition, the calculation formula of the abnormal traffic detection index YL is relatively simple and does not involve complex mathematical operations, making it easier to understand and operate in practical applications.
[0101] See also Figures 1 to 4 ,The calculation formula for evaluating the threat level unit faced by the current network is as follows:
[0102] ;
[0103] in:
[0104] WW is the threat assessment value;
[0105] EX is the malicious behavior count, which reflects the number of malicious behaviors detected. Malicious behaviors include virus transmission, phishing attacks, DDoS attacks, SQL injection, and cross-site scripting (XSS) attacks.
[0106] ZX is the total behavior count, ZX reflects the number of all behaviors detected;
[0107] WX is the number of new threats. WX reflects the number of new threat types that have appeared during the current detection cycle. Threat types include viruses, Trojans, worms, ransomware, and spyware.
[0108] LWX is the number of historical threats. LWX reflects the number of threat types that have existed in previous detection cycles.
[0109] In this embodiment, first, The calculation part combines the value of the abnormal traffic detection index YL, the ratio of the total behavior count ZX to the malicious behavior count EX, and the inbound traffic L in With the average flow L avg The ratio of ZX to EX provides a comprehensive assessment of the threat level faced by the current network. By introducing these calculation parts, the threat assessment value WW can more accurately reflect the threat situation in the network. The value of the abnormal traffic detection index YL reflects the abnormality of the traffic. The ratio of the total behavior count ZX to the malicious behavior count EX provides the proportion of malicious behavior in the total behavior. The inbound traffic L in With the average flow L avg The ratio reflects the relative size of the traffic. These factors together determine the threat assessment value WW, which helps us understand the current threat level.
[0110] “ The calculation part is used to measure the difference between new threats and historical threats, that is, the degree of change in threat types. By introducing this calculation part, the threat assessment value WW can more sensitively capture changes in threat types. When the number of new threats increases / decreases significantly, the value of this part will increase, thereby increasing the value of the threat assessment value WW, indicating the presence of a new threat type;
[0111] This algorithm unit can more accurately assess the threat level faced by the network by comprehensively considering multiple threat parameters, providing strong support for network security decision-making. The threat assessment value WW can dynamically adjust the assessment criteria and continuously update the assessment results based on the emergence of new threats and the evolution trend of historical threats, making the assessment more in line with the actual situation.
[0112] In addition, the evaluation results of the threat assessment value WW can directly guide the formulation and implementation of network security defense strategies, making defense measures more targeted and effective.
[0113] See also Figures 1 to 4 ,The calculation formula for the comprehensive evaluation unit of the network's overall security status is as follows:
[0114] ;
[0115] BDL=BD / ZBD;
[0116] EZL=CZL / EX;
[0117] WW avg=(WW1+WW2+WW3+……+WW m ) / m;
[0118] in:
[0119] AQ is the security posture index;
[0120] BDL is the patch application rate;
[0121] BD is the number of systems with patches applied, and ZBD is the total number of systems;
[0122] FE is the amount of anti-malware software;
[0123] EZL is the efficiency of malicious behavior;
[0124] CZL is the number of successfully executed malicious actions;
[0125] WW avg is the threat assessment average;
[0126] m is the total number of historical detection cycles;
[0127] WW1 is the threat assessment value of the first detection cycle, WW2 is the threat assessment value of the second detection cycle, WW3 is the threat assessment value of the third detection cycle, and WW m The threat assessment value of the mth detection cycle is WW, and when entering the next detection cycle, the current threat assessment value WW is the threat assessment value WW of the mth detection cycle. m ;
[0128] L in,max The maximum inbound traffic is the maximum inbound data traffic of the network in the current detection cycle.
[0129] In this embodiment, the algorithm unit first " The calculation combines the threat assessment value (WW), the patch application rate (BDL), and the ratio of malicious behavior efficiency (EXL) to anti-malware load (FE) to comprehensively assess the network's overall security status. By introducing these calculation components, the security posture index (AQ) can more comprehensively reflect the network's security posture. The threat assessment value (WW) reflects the current threat level, the patch application rate (BDL) provides a direct indicator of system security, and the ratio of malicious behavior efficiency (EXL) to anti-malware load (FE) reflects the performance of anti-malware. These factors together determine the value of the security posture index (AQ), thereby helping to understand the overall security status of the network.
[0130] “ The calculation part is used to measure the change of threat assessment value WW and inbound traffic L in With the maximum inbound flow L in,maxThe ratio of the value of the security situation index AQ to the value of the threat assessment value increases / decreases significantly, thereby reflecting the dynamic changes in network security. By introducing this calculation part, the security situation index AQ can more sensitively capture the dynamic changes in network security. When the threat assessment value increases / decreases significantly, the value of this part will increase, thereby increasing the value of the security situation index AQ to indicate that the network security situation is changing. At the same time, the inbound traffic L in With the maximum inbound flow L in,max The ratio also provides relative information about traffic size, which helps to further evaluate the security of the network;
[0131] Specifically, the patch application rate (BDL) in this algorithm unit reflects the timeliness and effectiveness of system patches. A high patch application rate (BDL) means that the system can promptly fix known vulnerabilities, reducing the risk of attacks. The anti-malware load (FE) measures the ability of anti-malware tools to detect and remove malware. Anti-malware tools with high anti-malware load (FE) can more effectively protect network security. The malicious behavior efficiency (EXL) reflects the spread speed and impact range of malicious behavior in the network. By monitoring changes in the malicious behavior efficiency (EXL), the spread of malicious behavior can be discovered and curbed in a timely manner.
[0132] The security situation index AQ output by this algorithm unit can comprehensively evaluate the overall security status of the network by comprehensively considering multiple security parameters, and provide comprehensive information support for network security decision-making. The security situation index AQ is also introduced by the threat assessment average value WW avg and the maximum inbound flow L in,max , realizing a circular feedback mechanism, and then being able to continuously optimize network security detection strategies and methods based on historical data and current traffic changes;
[0133] The calculation results of the security posture index (AQ) can directly reflect the security posture of the network and provide strong support for emergency response. When the network security situation changes, measures can be taken quickly to deal with potential threats and reduce security risks.
[0134] In summary, the units for measuring network traffic anomalies, assessing the current threat level, and comprehensively evaluating the overall network security status, along with their parameters, have significant benefits for network security detection. They not only improve detection sensitivity and accuracy, but also enable a comprehensive assessment of network security and optimize detection strategies and methods.
[0135] See also Figures 1 to 4 ,The detection analysis based on the security situation index AQ is as follows:
[0136] If the security situation index AQ is higher than the average security situation index AQ avg, it reflects that the current network faces high security risks and there are a lot of malicious behaviors and abnormal traffic, and network security measures should be strengthened;
[0137] If the security situation index AQ is lower than the average security situation index AQ avg , which reflects that the current network status is relatively stable, with little malicious behavior and abnormal traffic, and the current network security measures should be maintained;
[0138] Average security index AQ avg The calculation formula is as follows:
[0139] ;
[0140] AQ1 is the security situation index of the first detection cycle, AQ2 is the security situation index of the second detection cycle, AQ3 is the security situation index of the third detection cycle, and AQ m The security situation index of the mth detection cycle, and when entering the next detection cycle, the current security situation index AQ is the security situation index AQ of the mth detection cycle m .
[0141] In this embodiment, the algorithm unit is used when the security situation index AQ is higher than the security situation average index AQ avg When the value is , it means that the network faces a higher security risk. At this time, by evaluating the overall network security status unit for the loop feedback of the network traffic anomaly measurement unit, the judgment threshold of abnormal traffic in the network traffic anomaly measurement unit can be lowered, making the system more sensitive to abnormal traffic. In this way, even a small abnormal traffic fluctuation will be detected in time, thereby improving the accuracy of detection. When the security situation index AQ is lower than the security situation average index AQ avg When the network security is relatively good, by raising the abnormal traffic judgment threshold in the unit that measures the degree of network traffic anomaly, false alarms caused by traffic fluctuations can be reduced. At the same time, because the system is more tolerant of abnormal traffic, it can also avoid missing potential threats due to setting too low a threshold.
[0142] The threat assessment value WW in the unit that assesses the current threat level facing the network is an important indicator reflecting the severity of the threat currently facing the network. Through the cyclic feedback of the unit that comprehensively assesses the overall network security status to the unit that measures the degree of network traffic anomalies, the threat assessment algorithm in the unit that assesses the current threat level facing the network can be adjusted according to the level of the security situation index AQ. Specifically, when the security situation index AQ is high, the weight of the malicious behavior count can be increased to more accurately assess the severity of the current threat. When the security situation index AQ is low, the algorithm can be adjusted to focus more on threat types that will have a significant impact on the network. Based on the judgment results of the security situation index AQ and the cyclic feedback mechanism of the unit that comprehensively assesses the overall network security status to the unit that measures the degree of network traffic anomalies, more reasonable response strategies can also be formulated.
[0143] The patch application rate (BDL) and anti-malware load (FE) in the comprehensive assessment of overall network security status unit are important indicators for measuring the overall network security level. Through the loop feedback mechanism of the comprehensive assessment of overall network security status unit to the unit measuring network traffic anomaly, patch management and anti-malware efficiency can be strengthened based on the results of the security posture index (AQ). Specifically, when the security posture index (AQ) is high, the assessment of patch application can be strengthened to ensure that system vulnerabilities are promptly fixed. At the same time, the update frequency and detection efficiency of anti-malware can be improved to better respond to new threats and challenges.
[0144] In summary, the unit for measuring the degree of abnormality of network traffic, the unit for assessing the degree of threat faced by the current network, and the unit for comprehensively assessing the overall security status of the network each have their own unique beneficial effects, and the cyclical influence of the unit for comprehensively assessing the overall security status of the network on the unit for measuring the degree of abnormality of network traffic also brings significant advantages. These formulas together constitute the core part of the network security detection method based on big data, providing strong support and guarantee for network security, and using the average security index AQ avg The detection method used as a judgment standard and the circular feedback mechanism of the unit for comprehensively evaluating the overall network security status to the unit for measuring the degree of network traffic anomalies can produce many beneficial effects, including improving the accuracy and sensitivity of detection, optimizing threat assessment and response strategies, and enhancing the overall network security level. These effects will help to better respond to network security challenges and threats and ensure the safe and stable operation of the network.
[0145] For example 2, please refer to Figures 1 to 4 ,Virus transmission: Viruses spread through the network and infect files and programs in the system;
[0146] Phishing attacks: using fake websites and emails to trick users into revealing sensitive information;
[0147] DDoS attack: Distributed denial of service attack, which paralyzes the target system through a large number of requests;
[0148] SQL injection: Exploiting website vulnerabilities to send malicious SQL statements to the database to obtain or tamper with data;
[0149] Cross-site scripting (XSS): Injecting malicious scripts into the target website to steal user information and perform other malicious operations.
[0150] In this embodiment, the accumulation of malicious behavior counts EX by the unit for evaluating the current threat level faced by the network includes the accumulation of virus propagation, phishing attacks, DDoS attacks, SQL injections, and cross-site scripting attacks (XSS). This can more comprehensively introduce malicious behaviors that may affect network security, thereby improving the management and detection of network security.
[0151] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. A network security detection method based on big data, characterized in that: It includes a big data collection module, a big data calculation and evaluation module, and a response and disposal module. The big data calculation and evaluation module includes a unit for measuring the degree of abnormality of network traffic, a unit for evaluating the degree of threat faced by the current network, and a unit for comprehensively evaluating the overall security status of the network; The specific detection implementation steps are as follows: Step 1: Using the big data acquisition module, collect network traffic data, security event data and system security status data of the current detection period; Step II: using the network traffic anomaly degree measuring unit, first calculate and output an abnormal traffic detection index YL; Step III: introducing the abnormal traffic detection index YL into the unit for evaluating the threat level faced by the current network, and calculating and outputting a threat assessment value WW; Step III: introducing the abnormal traffic detection index YL and the threat assessment value WW into the comprehensive network overall security status evaluation unit, and calculating and outputting the security situation index AQ for detection and analysis; Step IIIII: the response and disposal module makes a security response and disposal based on the security situation index AQ; The calculation formula for measuring the network traffic anomaly degree unit is as follows: ; in: YL is the abnormal traffic detection index; L in is the inbound traffic, L in Refers to the amount of data entering the network per unit time; L out is the outbound traffic, L out Refers to the amount of data leaving the network per unit time; L avg is the average flow rate, L avg Refers to the average data traffic of the network during the current detection period; L peak is the peak flow rate, L peak Refers to the maximum data traffic generated by the network during the current detection period; The average flow rate L avg The calculation formula is as follows: <h2 style=";text-align:left;direction:ltr">L<h2 style=";text-align:left;direction:ltr"> avg <h2 style=";text-align:left;direction:ltr"> =(L1+L2+L3+......+L<h2 style=";text-align:left;direction:ltr"> n <h2 style=";text-align:left;direction:ltr"> ) / n; n is the current cycle period, reflecting the amount of time in the current detection cycle; L1 is the first time period for detecting data traffic, L2 is the second time period for detecting data traffic, L3 is the third time period for detecting data traffic, L n Detect data traffic for the nth period; And any detection cycle is the average flow rate L of the current detection cycle avg Perform real-time update calculations; The calculation formula for evaluating the threat level unit facing the current network is as follows: ; in: WW is the threat assessment value; EX is the malicious behavior count, which reflects the number of malicious behaviors detected. Malicious behaviors include virus transmission, phishing attacks, DDoS attacks, SQL injection, and cross-site scripting (XSS) attacks. ZX is the total behavior count, ZX reflects the number of all behaviors detected; WX is the number of new threats. WX reflects the number of new threat types that have appeared during the current detection cycle. Threat types include viruses, Trojans, worms, ransomware, and spyware. LWX is the number of historical threats. LWX reflects the number of threat types that have existed in the previous detection cycle. Virus propagation: viruses spread through the network and infect files and programs in the system; Phishing attacks: using fake websites and emails to trick users into revealing sensitive information; The DDoS attack is a distributed denial of service attack that paralyzes the target system through a large number of requests. SQL injection: exploiting website vulnerabilities to send malicious SQL statements to the database to obtain and tamper with data; Cross-site scripting (XSS) attacks: inject malicious scripts into the target website to steal user information and perform other malicious operations; The calculation formula for the comprehensive evaluation unit of the network's overall security status is as follows: ; BDL=BD / ZBD; EZL=CZL / EX; WW avg =(WW1+WW2+WW3+......+WW m ) / m; in: AQ is the security posture index; BDL is the patch application rate; BD is the number of systems with patches applied, and ZBD is the total number of systems; FE is the amount of anti-malware software; EZL is the efficiency of malicious behavior; CZL is the number of successfully executed malicious actions; WW avg is the threat assessment average; m is the total number of historical detection cycles; WW1 is the threat assessment value of the first detection cycle, WW2 is the threat assessment value of the second detection cycle, WW3 is the threat assessment value of the third detection cycle, and WW m The threat assessment value of the mth detection cycle is WW, and when entering the next detection cycle, the current threat assessment value WW is the threat assessment value WW of the mth detection cycle. m ; L in,max The maximum inbound traffic is the maximum inbound data traffic of the network in the current detection cycle.
2. A network security detection method based on big data according to claim 1, characterized in that: The equipment used by the big data acquisition module includes network traffic analyzers, SIEM systems, and security monitoring equipment; The equipment used by the big data calculation and evaluation module includes a server; The equipment used by the response and disposal module includes a security patch management system and anti-malware tools.
3. The network security detection method based on big data according to claim 2, characterized in that: The detection analysis based on the security situation index AQ is as follows: If the security situation index AQ is higher than the average security situation index AQ avg , it reflects that the current network faces high security risks and there are a lot of malicious behaviors and abnormal traffic, and network security measures should be strengthened; If the security situation index AQ is lower than the average security situation index AQ avg , which reflects that the current network status is relatively stable, with little malicious behavior and abnormal traffic, and the current network security measures should be maintained.
4. The network security detection method based on big data according to claim 3, characterized in that: The average security situation index AQ avg The calculation formula is as follows: so avg =(AQ1+AQ2+AQ3+......+AQ m ) / m; AQ1 is the security situation index of the first detection cycle, AQ2 is the security situation index of the second detection cycle, AQ3 is the security situation index of the third detection cycle, and AQ m The security situation index of the mth detection cycle, and when entering the next detection cycle, the current security situation index AQ is the security situation index AQ of the mth detection cycle m .
Citation Information
Patent Citations
Network security situation self-adaptive active defense system and method
CN113965404A
Network attack blocking method
CN118764277A
Method of detecting anomalies suspected of attack, based on time series statistics
US20160219067A1