A security operation and maintenance management method and system based on network security incidents

By collecting and processing multi-dimensional data, and optimizing protection strategies using weighted propagation models and nonlinear reactive diffusion models, the problem of insufficient dynamic adjustment in network security management is solved, and the foresight and response capabilities of network security management is improved.

CN119835080BActive Publication Date: 2025-07-22BEIJING RENHE CHENGXIN TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510094542.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-07-22
Estimated Expiration
2045-01-21

AI Technical Summary

Technical Problem

The existing network security management system lacks real-time perception of dynamically changing network conditions and attack methods, resulting in the inability to optimize protection strategies in time, waste of resources or lag in protection effects.

Method used

By collecting multi-dimensional data for preprocessing, using weighted propagation models to calculate the impact of attacks, building fitness functions and optimizing protection strategies, dynamically adjusting protection strategies in combination with nonlinear reactive diffusion models and genetic algorithms, generating an optimal protection strategy set, and executing and storing data through communication protocols.

Benefits of technology

It improves the foresight and response capabilities of network security management, enhances the flexibility and adaptability of the protection system, reduces the need for manual intervention, and achieves accurate assessment and timely response to network threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119835080B_ABST
    Figure CN119835080B_ABST
Patent Text Reader

Abstract

The present invention discloses a security operation and maintenance management method and system based on network security incidents, which relates to the field of network security technology. It includes collecting multi-dimensional data and performing preprocessing, calculating the attack state based on the preprocessed multi-dimensional data; calculating the attack impact degree using a weighted propagation model based on the attack state, constructing a fitness function based on the attack impact degree and optimizing it to obtain an optimal set of protection strategies; converting the optimal set of protection strategies into control instructions and executing them, and storing the multi-dimensional data generated by collection and analysis. By constructing a non-linear ordinary differential equation through a non-linear reaction diffusion model, the predictability and response ability of network security management and operation and maintenance are improved. The weighted propagation model is used to calculate the attack impact degree to accurately estimate the wide-spread effect of network security threats. By constructing and optimizing the fitness function, not only the flexibility and adaptability of the protection system are improved, but also the need for manual intervention is greatly reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly to a security operation and maintenance management method and system based on network security events. Background Art

[0002] With the rapid development of Internet technology, network security issues have gradually become the focus of global attention. The means of network attacks are constantly evolving, and traditional network security protection measures such as firewalls and intrusion detection systems (IDS) are increasingly difficult to cope with the increasingly complex security threats. To effectively address these challenges, the approach to network security protection is evolving from a single protection tool to an integrated security operation and maintenance management system. With the application of big data technology, artificial intelligence, and deep learning, the monitoring and response to network security events have gradually achieved automation and intelligence, especially in multi-dimensional data analysis, significant progress has been made. By using multi-dimensional data such as real-time network traffic, bandwidth, and transmission delay, combined with modern data processing and analysis technologies, it is possible to more accurately evaluate the network security situation, timely detect potential security threats, and take effective protection measures.

[0003] The current network security management system generally has some deficiencies. Many traditional security operation and maintenance management methods often rely on static network topologies and simple rules for security protection, lacking the ability to perceive the dynamic changes in network conditions and attack means in real time. The existing technologies lack an effective dynamic adjustment mechanism in calculating the attack propagation rate, impact degree, and risk degree, etc., and fail to optimize the protection strategy in a timely manner according to the changes in real-time network conditions and security events, preventing waste of resources or lag in protection effects. Summary of the Invention

[0004] In view of the above existing problems, the present invention is proposed.

[0005] Therefore, the present invention provides a security operation and maintenance management method and system based on network security events, which solves the problems that many traditional security operation and maintenance management methods often rely on static network topologies and simple rules for security protection, lacking the ability to perceive the dynamic changes in network conditions and attack means in real time, and the existing technologies lack an effective dynamic adjustment mechanism in calculating the attack propagation rate, impact degree, and risk degree, etc., and fail to optimize the protection strategy in a timely manner according to the changes in real-time network conditions and security events, preventing waste of resources or lag in protection effects.

[0006] To solve the above technical problems, the present invention provides the following technical solutions:

[0007] In a first aspect, the present invention provides a security operation and maintenance management method based on network security events, which includes collecting multi-dimensional data and performing preprocessing, calculating the attack state based on the preprocessed multi-dimensional data; calculating the attack impact degree using a weighted propagation model based on the attack state, constructing a fitness function based on the attack impact degree and optimizing it to obtain an optimal set of protection strategies; converting the optimal set of protection strategies into control instructions and executing them, and storing the multi-dimensional data generated by collection and analysis.

[0008] As a preferred solution of the security operation and maintenance management method based on network security events of the present invention, wherein: the collecting multi-dimensional data and performing preprocessing refers to using the sFlow protocol to collect multi-dimensional data on the terminal devices of the network and perform preprocessing;

[0009] The multi-dimensional data includes network topology structure, bandwidth, transmission delay, and network traffic data;

[0010] The preprocessing includes synchronizing the collected multi-dimensional data using the Network Time Protocol, denoising the multi-dimensional data using discrete wavelet transform, identifying and deleting duplicate data using a hash algorithm, filling in missing data using the K-nearest neighbor algorithm, and normalizing the multi-dimensional data.

[0011] As a preferred solution of the security operation and maintenance management method based on network security events of the present invention, wherein: the calculating the attack state based on the preprocessed multi-dimensional data refers to defining the terminal device as a node, extracting the network topology structure data from the preprocessed multi-dimensional data, and constructing an adjacency matrix for the physical connection relationships in the preprocessed network topology structure data, which is defined as an edge;

[0012] Based on the node, traverse all directly connected nodes in the preprocessed network topology structure data to form a set of neighbor nodes;

[0013] Based on the preprocessed network traffic data, use the performance evaluation index method to calculate the IDS protection ability of the i-th node and use the weighted average method to calculate the IDS protection ability between the i-th node and the j-th node ;

[0014] Based on the preprocessed bandwidth data, transmission delay data, and IDS protection ability, calculate the propagation rate between the i-th node and the j-th node The formula is:

[0015]

[0016] where is the bandwidth between the i-th node and the j-th node, is the transmission delay between the i-th and j-th nodes;

[0017] Define the reciprocal of the IDS protection ability of the i-th node as the response coefficient of the i-th node ;

[0018] Collect the maximum attack intensity that the i-th node can bear from the product specifications of the device manufacturer ;

[0019] Use the non-linear reaction-diffusion model to construct a non-linear ordinary differential equation, and the formula is:

[0020] ,

[0021] where and are the attack states of the i-th and j-th nodes at time t respectively, is the set of neighbor nodes of the i-th node;

[0022] Use the Runge-Kutta method to solve the non-linear ordinary differential equation to obtain the attack state of the i-th node at time t .

[0023] As a preferred solution of the security operation and maintenance management method based on network security events described in the present invention, wherein: calculating the attack influence degree using the weighted propagation model based on the attack state means traversing the number of all directly connected edges of the nodes in the preprocessed network topology structure data based on the nodes, denoted as the node degree;

[0024] Based on the adjacency matrix, use the Floyd-Warshall algorithm for iterative calculation to obtain the shortest path matrix of each pair of nodes, and extract the elements in the shortest path matrix as the number of hops between the i-th node and the j-th node ;

[0025] Use the propagation delay correction formula to calculate the correction term of the propagation delay ;

[0026] Based on the preprocessed network topology structure data, use the PageRank algorithm to calculate the PageRank value PR of the nodes;

[0027] Use the empirical regression analysis method to set the adjustment factor ;

[0028] Combine the propagation rate, attack state, correction term of the propagation delay, and PageRank value, and use the weighted propagation model to calculate the attack influence degree of the i-th node at time t , and the formula is:

[0029] ,

[0030] wherein is the attack state of the j-th node, is the PageRank value of the j-th node, is the degree of the j-th node.

[0031] As a preferred solution of the security operation and maintenance management method based on network security events described in the present invention, wherein: constructing and optimizing the fitness function based on the attack impact degree to obtain the optimal set of protection strategies means calculating the risk degree of the i-th node using the risk degree formula based on the attack state and the attack impact degree , the formula is:

[0032] ,

[0033] wherein is the attack impact degree of the j-th node;

[0034] Using the entropy weight method to calculate the weight coefficients of the attack impact degree and the risk degree respectively, and calculating the comprehensive risk value using the weighted summation method based on the attack impact degree and the risk degree ;

[0035] Constructing a fitness function based on the risk degree and the comprehensive risk value , the formula is:

[0036] ,

[0037] where N is the total number of nodes in the network, is the protection strategy;

[0038] Randomly generate an initial population, including transmission delay and bandwidth allocation, calculate the reconstruction objective function value of each population, which is defined as the fitness value, select the individual with the lowest fitness value from the initial population for crossover and mutation operations to generate the next generation population, repeat the iterative operation and stop when the fitness value converges, and output the genetic individual with the lowest fitness value in the population after stopping the iteration as the optimal individual to obtain the optimal set of protection strategies, including transmission delay and bandwidth allocation strategies.

[0039] As a preferred solution of the security operation and maintenance management method based on network security events described in the present invention, wherein: converting the optimal set of protection strategies into control instructions and executing them means generating control instructions from the optimal set of protection strategies and executing them means using the optimal control strategy generation method to generate control instructions from the optimal set of protection strategies;

[0040] Transmit the control instructions to the terminal device using the communication protocol DNP3, and the terminal device executes the received control instructions.

[0041] As a preferred solution of the security operation and maintenance management method based on network security events according to the present invention, wherein: the multi-dimensional data generated by storage, collection and analysis refers to storing the collected multi-dimensional data and the optimal protection strategy set generated by analysis in a central database, and setting security access measures. The central database backs up the stored data to the cloud, and regularly detects the integrity of the stored data and the backup data. After the detection is completed, an integrity detection record is generated and synchronously stored in the central database.

[0042] In a second aspect, the present invention provides a security operation and maintenance management system based on network security events, including

[0043] a collection status module, configured to collect multi-dimensional data and perform preprocessing, and calculate an attack status based on the preprocessed multi-dimensional data;

[0044] a calculation and optimization module, configured to calculate an attack impact degree using a weighted propagation model based on the attack status, construct a fitness function based on the attack impact degree and perform optimization to obtain an optimal protection strategy set;

[0045] an instruction storage module, configured to convert the optimal protection strategy set into control instructions and execute them, and store the multi-dimensional data generated by collection and analysis.

[0046] In a third aspect, the present invention provides a computer device, including a memory and a processor, where the memory stores a computer program, and wherein: when the computer program is executed by the processor, any step of the security operation and maintenance management method based on network security events as described in the first aspect of the present invention is implemented.

[0047] In a fourth aspect, the present invention provides a computer-readable storage medium, on which a computer program is stored, and wherein: when the computer program is executed by the processor, any step of the security operation and maintenance management method based on network security events as described in the first aspect of the present invention is implemented.

[0048] The beneficial effects of the present invention are as follows: By collecting multi-dimensional data and performing preprocessing, the present invention calculates an attack status based on the preprocessed multi-dimensional data; calculates an attack impact degree using a weighted propagation model based on the attack status, constructs a fitness function based on the attack impact degree and performs optimization to obtain an optimal protection strategy set; improves the predictability and response ability of network security management and operation and maintenance, not only improves the flexibility and adaptability of the protection system, but also greatly reduces the need for manual intervention. Description of the Drawings

[0049] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0050] Figure 1 It is a flowchart of the security operation and maintenance management method based on network security events in Embodiment 1.

[0051] Figure 2 It is a structural diagram of the security operation and maintenance management system based on network security events in Embodiment 1. Specific Embodiments

[0052] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following will make a detailed description of the specific embodiments of the present invention in conjunction with the accompanying drawings of the specification.

[0053] In the following description, many specific details are set forth to fully understand the present invention. However, the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar extensions without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.

[0054] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that can be included in at least one implementation manner of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it an individual or alternative embodiment that is mutually exclusive with other embodiments.

[0055] Embodiment 1, referring to Figure 1 and Figure 2 , is the first embodiment of the present invention. This embodiment provides a security operation and maintenance management method based on network security events, including the following steps:

[0056] S1. Collect multi-dimensional data and perform preprocessing, and calculate the attack status based on the preprocessed multi-dimensional data;

[0057] Specifically, collecting multi-dimensional data and performing preprocessing means using the sFlow protocol to collect multi-dimensional data on the terminal devices of the network and perform preprocessing;

[0058] The multi-dimensional data includes network topology, bandwidth, transmission delay, and network traffic data;

[0059] The preprocessing includes synchronizing the collected multi-dimensional data using the Network Time Protocol, denoising the multi-dimensional data using discrete wavelet transform, identifying and deleting duplicate data using a hash algorithm, filling in missing data using the K-nearest neighbor algorithm, and normalizing the multi-dimensional data.

[0060] Collecting network topology, bandwidth, transmission delay, and network traffic data through the sFlow protocol on network terminal devices can comprehensively reflect the operating state of the network and the interaction relationships between nodes. Ensuring the temporal consistency of device data through the Network Time Protocol (NTP) avoids errors introduced by clock asynchronization. Denoising reduces useless high-frequency noise through discrete wavelet transform and retains effective signal components. Data deduplication eliminates duplicate data and avoids interference from redundant information on the analysis results. Missing data filling infers missing values based on similarity through the KNN algorithm to further improve data integrity. Normalization ensures fairness across different data dimensions and avoids excessive influence of certain dimensions on the analysis results. The collected original multi-dimensional data can be provided to subsequent network security situation awareness and protection models in a more accurate and consistent format. The fully preprocessed data can more effectively support the dynamic detection and response of network security events, thereby improving the protection system's ability to identify network threats and response speed.

[0061] Further, calculating the attack state based on the preprocessed multi-dimensional data involves defining terminal devices as nodes, extracting network topology data from the preprocessed multi-dimensional data, and constructing an adjacency matrix from the physical connection relationships in the preprocessed network topology data, which is defined as an edge.

[0062] Based on the nodes, traverse all directly connected nodes in the preprocessed network topology data to form a set of neighbor nodes.

[0063] Based on the preprocessed network traffic data, use the performance evaluation metric method to calculate the IDS protection ability of the i-th node , and use the weighted average method to calculate the IDS protection ability between the i-th node and the j-th node ;

[0064] Based on the preprocessed bandwidth data, transmission delay data, and IDS protection ability, calculate the propagation rate between the i-th node and the j-th node , with the formula:

[0065] ,

[0066] where is the bandwidth between the i-th node and the j-th node, is the transmission delay between the i-th and j-th nodes;

[0067] Define the reciprocal of the IDS protection ability of the i-th node as the response coefficient of the i-th node ;

[0068] Collect the maximum attack intensity that the i-th node can bear from the product specifications of the device manufacturer ;

[0069] Use the non-linear reaction-diffusion model to construct a non-linear ordinary differential equation, the formula is:

[0070] ,

[0071] where and are the attack states of the i-th and j-th nodes at time t respectively, is the set of neighbor nodes of the i-th node;

[0072] The response system and the protection ability are in an inverse relationship. If the protection ability is strong, the response speed of the node to the attack is slower, and the growth of the attack state also slows down accordingly. This is consistent with the physical meaning. In the formula reflects the self-inhibition effect of the node when it is attacked, that is, the attack state of the node gradually slows down with the increase of the attack degree. The introduction of the maximum attack intensity that can be borne is very appropriate because each node has a natural limit value (bearing intensity). Beyond this value, the propagation effect of the attack will weaken. The protection ability, hardware resources, software protection, etc. of the node all limit its upper limit of bearing the attack. When the attack intensity approaches the maximum attack intensity that the node can bear, the attack growth will tend to saturate, and the further growth effect will weaken. This conforms to the physical laws of the system response and diffusion process. The non-linear term reflects the self-limiting effect of the attack expansion, and the diffusion term is consistent with the diffusion law of the attack in the actual network: the attack will not expand indefinitely, but is inhibited by the attack state approaching the maximum value. The attack state of the neighbor nodes affects the attack state of the i-th node, which conforms to the diffusion characteristics of the network attack. The probability of the adjacent nodes being attacked will affect the attack probability of the target node;

[0073] In most of the existing attack propagation models, the attack propagation is modeled only based on the network topology or a certain fixed propagation rate, ignoring the dynamic effects of the protection capabilities and maximum bearing capacities of nodes. By introducing the reaction coefficient and the maximum bearing attack intensity, this formula can more accurately reflect the different protection capabilities and bearing limitations of different nodes, making the attack propagation model more adaptable to the actual network environment. The traditional linear propagation model cannot handle the self-limiting characteristics of attack expansion. By dynamically simulating the reaction and bearing capacity of nodes to attacks through the non-linear reaction term, the accuracy of the model is further improved. The non-linear effect enhances the consideration of attack protection measures in the model, enabling the attack propagation model to better reflect the restriction mechanism of attacks in the real network. Different from the models that usually use a fixed propagation rate or are based on conventional topology analysis in the existing technology, this model can dynamically adjust the propagation coefficient according to the attack states of adjacent nodes, taking into account the dynamic interaction between the spread of attacks and the network topology, and improving the adaptability of the model to complex network structures. By combining the node protection capabilities, bearing capacities, non-linear diffusion terms, and the propagation effects of adjacent nodes, not only can the spatial distribution of the attack propagation path be analyzed, but also the evolution process of attacks in the time dimension can be accurately described, enhancing the predictability and response capabilities of network security management and operation and maintenance;

[0074] The Runge-Kutta method is used to solve the non-linear ordinary differential equation to obtain the attack state of the i-th node at time t .

[0075] The set of neighbor nodes intuitively depicts the connection situation and relationships of each node in the network, providing a clear network structure map for subsequent security situation assessment. Through the adjacency matrix, the system can quickly identify the direct connections between nodes, providing an important basis for calculating the attack propagation path and influence degree. Through the performance evaluation index method, the IDS protection capabilities of each node are calculated, enabling a quantitative assessment of the security protection levels of each node in the network. Nodes with strong protection capabilities can be protected preferentially, while nodes with weak protection capabilities can receive supplementary protection measures in a timely manner. Calculating the propagation rate can predict the spread range of attacks, and the protection strategy can be adjusted according to the propagation rate in the network. By calculating the reaction coefficient of each node (i.e., the reciprocal of the IDS protection capability) and the maximum attack intensity borne collected from the product specifications of equipment manufacturers, the protection capability assessment of each node can be further refined. This combined analysis can ensure that the network system can make reasonable resource allocation and protection responses when facing attacks of different intensities. By using the non-linear reaction-diffusion model to simulate the propagation of attacks and using the Runge-Kutta method to numerically solve ordinary differential equations, the dynamic changes of the attack state can be accurately predicted. The model takes into account the non-linear characteristics of attack propagation, enabling detailed prediction of the state changes of attacks at different time points. By calculating the attack state of each node through the non-linear model, the intelligence level of the network security system is greatly improved. By automatically adjusting protection measures, an efficient response to complex network attacks is achieved, greatly enhancing the timeliness and accuracy of protection.

[0076] S2. Calculate the attack influence degree using a weighted propagation model based on the attack state, construct a fitness function based on the attack influence degree and optimize it to obtain the optimal set of protection strategies;

[0077] Specifically, calculating the attack influence degree using a weighted propagation model based on the attack state means, based on the nodes, traversing the number of all directly connected edges of the nodes in the preprocessed network topology structure data, denoted as the node degree;

[0078] Based on the adjacency matrix, use the Floyd-Warshall algorithm for iterative calculation to obtain the shortest path matrix of each pair of nodes, and extract the elements in the shortest path matrix as the number of hops between the i-th node and the j-th node ;

[0079] Use the propagation delay correction formula to calculate the correction term of the propagation delay , the formula is:

[0080] ,

[0081] Based on the preprocessed network topology structure data, use the PageRank algorithm to calculate the PageRank value PR of the nodes;

[0082] Set adjustment factors using empirical regression analysis ;

[0083] Combine the correction terms of propagation rate, attack status, propagation delay, and PageRank value, and use the weighted propagation model to calculate the attack influence degree of the i-th node at time t , and the formula is:

[0084] ,

[0085] where is the attack status of the j-th node, is the PageRank value of the j-th node, is the degree of the j-th node.

[0086] Existing attack propagation models usually ignore the importance of nodes. This formula weights the influence of each node by introducing the PageRank value, thus ensuring that the impact of node importance on attack propagation is accurately reflected. Existing models only focus on the propagation rate of attacks and ignore the impact of transmission delay. Different network connections (such as links with different bandwidths and delays) will have different effects on the speed of attack propagation. This formula combines the propagation rate and propagation delay, and can more accurately simulate the actual process of attack propagation. This enables the model to not only evaluate the propagation speed of attacks, but also consider the changes under different network conditions. Traditional attack propagation models usually adopt linear models and ignore the non-linear behaviors in the actual network. Through non-linear propagation effects, the dynamic changes of attacks are considered, and the diffusion process of attacks in the network can be predicted more accurately, providing a basis for the adjustment of protection strategies. By combining the attack status of adjacent nodes with the network topology, this model can calculate the attack influence degree of nodes more precisely, reflecting the complexity of the transfer of attacks from other nodes to the target node;

[0087] By traversing the nodes and their directly connected edges in the network topology, the system can accurately evaluate the possible paths and the scope of influence of attacks spreading in the network. By using the Floyd-Warshall algorithm to calculate the shortest path matrix between each pair of nodes, the system can accurately obtain the "hop count" information between various nodes in the network. The hop count refers to the minimum number of edges passed from one node to another, which directly reflects the distance between two nodes. By using the propagation delay correction formula, the system can calibrate the delay of the propagated information in the network, eliminate the errors caused by network fluctuations, and thus ensure that the calculation of the propagation rate is more accurate. The importance of a node not only affects its own protection requirements but may also determine its role in the spread of attacks. By calculating the PageRank value PR of each node, the system can identify the key nodes in the network, and these nodes are often the main carriers of attack diffusion. By calculating the PageRank value PR of each node, the system can identify the key nodes in the network, and these nodes are often the main carriers of attack diffusion. The use of the empirical regression analysis method enables the weighted propagation model to be adjusted according to historical data and the actual network environment, thereby improving the prediction accuracy of the model. By using the weighted propagation model to calculate the attack influence degree of each node at a certain moment, it is possible to comprehensively consider the roles of various factors in the network and provide a comprehensive basis for evaluating the propagation effect and the scope of influence of attacks in the network. The system can intelligently adjust the protection strategy, optimize the allocation of network resources, and improve the anti-attack ability and self-adaptability of the network.

[0088] Furthermore, based on the attack influence degree, a fitness function is constructed and optimized to obtain the optimal set of protection strategies, which means that based on the attack state and the attack influence degree, the risk degree formula is used to calculate the risk degree of the i-th node , the formula is:

[0089] ,

[0090] where is the attack influence degree of the j-th node;

[0091] The attack propagation model only evaluates risks based on the network topology and the properties of the nodes themselves (such as protection capabilities, attack status, etc.), ignoring the role of adjacent nodes in attack propagation. This model takes into account the attack status and propagation capabilities of adjacent nodes, making the risk assessment more refined and able to reflect the complex interactions between nodes. Through this method, the model can identify the influence of important nodes in the network and evaluate the propagation paths between nodes more accurately. Most traditional attack propagation models adopt linear propagation models, assuming that the influence between nodes is linear, which simplifies the complexity of attack propagation in the real world. By using the sigmoid function to handle the propagation delay and the non-linear adjustment of attack influence, the propagation effect of the attack changes smoothly with the change of the node attack status. This not only makes it closer to the actual attack propagation mode but also can finely control the influence of non-linear diffusion through the adjustment coefficient, thus improving the prediction accuracy of the model. Existing models simply rely on the connection strength of nodes to calculate the propagation rate, ignoring the role of propagation delay. By introducing the joint modeling of propagation delay and propagation rate, the model can more accurately reflect the time delay and bandwidth differences between nodes in the network, thus more realistically simulating the propagation process of attacks in the network. By introducing the sigmoid function and the attack influence degree adjustment mechanism, the attack influence degree of each node can be flexibly adjusted within different time scales, enabling the model to reflect the change of node attack status in real time and better cope with the dynamic network attack environment;

[0092] Use the entropy weight method to calculate the weight coefficients of the attack influence degree and the risk degree respectively. Based on the attack influence degree and the risk degree, use the weighted summation method to calculate the comprehensive risk value ;

[0093] Construct a fitness function based on the risk degree and the comprehensive risk value , the formula is:

[0094] ,

[0095] where N is the total number of nodes in the network, is the protection strategy;

[0096] Existing protection strategies usually only consider the protection requirements or risks of nodes and lack a dynamic adjustment mechanism. The protection strategies for all nodes may be the same in traditional methods, without targeted allocation according to the risk level and priority. This formula combines the priority and risk level and dynamically adjusts the protection strategy according to the risk and importance of nodes to ensure that high-risk and critical nodes are protected first. Most existing attack propagation and protection models ignore the importance of nodes in the network, which may lead to insufficient protection of core nodes and thus affect the security of the entire network. By introducing the PageRank value, it is ensured that important nodes in the network receive higher-priority protection, enhancing the adaptability of the model to the network structure and being able to effectively slow down the spread of attacks. Existing models only consider the connectivity and propagation rate of nodes and ignore the propagation delay of different links in the network, resulting in the model being unable to accurately reflect the actual differences in propagation speed in the network. This formula combines the propagation delay and propagation rate to provide a more accurate prediction of attack propagation under different network conditions. This consideration can better simulate the network environment in reality and improve the effectiveness of protection strategies. Traditional models usually use linear models to describe attack spread. This method cannot capture the non-linear characteristics in attack propagation, resulting in low prediction accuracy of the model when facing complex network environments. The sigmoid function is introduced to non-linearly adjust the impact of attack propagation, enabling the protection strategy to more sensitively adapt to attacks of different intensities and improving the real-time response ability of protection measures;

[0097] Randomly generate a group of initial populations, including transmission delay and bandwidth allocation. Calculate the reconstruction objective function value of each population, which is defined as the fitness value. Select the individual with the lowest fitness value from the initial population for crossover and mutation operations to generate the next generation of populations. Repeat the iterative operation and stop when the fitness value converges. Output the genetic individual with the lowest fitness value in the population after stopping the iteration as the optimal individual to obtain the optimal set of protection strategies, including transmission delay and bandwidth allocation strategies.

[0098] By combining the attack impact degree and the risk degree to evaluate the security of each node, it can comprehensively reflect the potential threat of the attack to the network. Calculating the comprehensive risk value can assign an appropriate protection level to each node to ensure that key nodes in the network (such as nodes with a high risk degree) are better protected. The weights are calculated by the entropy weight method, and the weighted summation method is used to obtain the comprehensive risk value to ensure that the impacts of different factors are accurately evaluated, improving the rationality and pertinence of the protection strategy design. By constructing a fitness function and combining the risk degree and the comprehensive risk value of the nodes in the network, the system can evaluate the performance of each set of protection strategies in actual applications. As an efficient optimization method, the genetic algorithm can find the optimal solution in the complex strategy space by simulating the process of natural selection and gene inheritance. It can not only efficiently handle complex network protection problems but also dynamically adjust the strategy according to the actual attack situation. The transmission delay and bandwidth allocation strategy can be dynamically adjusted according to the evaluation results of the attack impact degree, thereby improving the anti-attack ability of the network and the utilization efficiency of resources. Through the comprehensive analysis of the risk degree and the attack impact degree, the system can dynamically reinforce the network and respond to various security threats in a timely manner, thus greatly improving the stability and security of the network. By adjusting the transmission delay and bandwidth allocation through the genetic algorithm, balanced protection can be carried out across the entire network, avoiding over-concentration or dispersion of resources, ensuring that each node in the network can be reasonably protected, and improving the overall protection ability of the network.

[0099] S3. Convert the optimal set of protection strategies into control instructions and execute them, and store the multi-dimensional data generated by collection and analysis;

[0100] Specifically, converting the optimal set of protection strategies into control instructions and executing them means generating control instructions from the optimal set of protection strategies and executing them, that is, using the optimal control strategy generation method to generate control instructions from the optimal set of protection strategies;

[0101] Use the communication protocol DNP3 to transmit the control instructions to the terminal device, and the terminal device receives the control instructions and executes them.

[0102] By automatically generating and executing control instructions, the system can quickly and precisely adjust the protection strategy when the network changes or the attack threat increases, thereby reducing the interference of human factors, enhancing the real-time performance and flexibility of network protection. The introduction of the optimized control strategy generation method enables the protection strategy to be flexibly adjusted according to the real-time requirements of the network environment. It not only considers the capabilities of various network devices and the network topology structure but also can adapt to different attack scenarios and generate control instructions that meet the actual requirements. Using the DNP3 protocol to transmit control instructions can effectively ensure the reliability and real-time performance of instruction transmission. The terminal device automatically executes the control instructions and can quickly respond according to the network security protection requirements. By dynamically adjusting the protection strategy, the adaptability of the network is improved. The implementation of the optimal protection strategy can not only improve security but also effectively optimize the use of network resources.

[0103] Furthermore, storing the multi-dimensional data generated by collection and analysis means storing the collected multi-dimensional data and the set of optimal protection strategies generated by analysis in the central database and setting security access measures. The central database performs cloud backup on the stored data and regularly conducts integrity detection on the stored data and the backup data. After the detection is completed, an integrity detection record is generated and synchronously stored in the central database.

[0104] Storing the multi-dimensional data and the set of protection strategies in the central database and setting security access measures can centrally manage all network security data, ensuring the integrity and confidentiality of information. By setting strict access control and encryption measures, it is ensured that only authorized personnel can access and modify the data, thereby preventing data leakage or malicious tampering. The security access measures provide guarantee for the protection ability of the system and enhance data security. Performing cloud backup on the stored data can effectively prevent data loss caused by system crashes or equipment failures. Regularly conducting integrity detection on the stored data and the backup data can timely detect potential problems in the data, such as data loss, tampering, or damage. Through the storage management of the central database for the collected multi-dimensional data and the set of optimal protection strategies, centralized management of data can be achieved, which not only improves the efficiency of data retrieval and access but also facilitates cross-departmental and cross-system collaborative analysis and decision-making. By implementing cloud backup and integrity detection, the reliability and fault tolerance of the system are greatly enhanced. Automated backup, integrity detection, and protection strategy adjustment reduce human errors and the complexity of system management, improving operation and maintenance efficiency and accuracy.

[0105] This embodiment also provides a security operation and maintenance management system based on network security events, including:

[0106] A collection status module for collecting multi-dimensional data and performing preprocessing, and calculating the attack status based on the preprocessed multi-dimensional data;

[0107] A calculation optimization module, which is used to calculate the attack impact degree using a weighted propagation model based on the attack state, construct a fitness function based on the attack impact degree and optimize it to obtain an optimal set of protection strategies;

[0108] An instruction storage module, which is used to convert the optimal set of protection strategies into control instructions and execute them, and store multi-dimensional data generated by collection and analysis.

[0109] This embodiment also provides a computer device, which is applicable to the case of a security operation and maintenance management method based on network security events, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the security operation and maintenance management method based on network security events proposed in the above embodiment.

[0110] This computer device may be a terminal, and this computer device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of this computer device is used to provide computing and control capabilities. The memory of this computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of this computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a carrier network, NFC (Near Field Communication), or other technologies. The display screen of this computer device may be a liquid crystal display screen or an electronic ink display screen, and the input device of this computer device may be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the housing of the computer device, or an external keyboard, touchpad, or mouse, etc.

[0111] This embodiment also provides a storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the security operation and maintenance management method based on network security events proposed in the above embodiment. The storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM for short), electrically erasable programmable read-only memory (EEPROM for short), erasable programmable read-only memory (EPROM for short), programmable read-only memory (PROM for short), read-only memory (ROM for short), magnetic memory, flash memory, magnetic disk or optical disk.

[0112] In summary, the present invention collects multi-dimensional data and performs preprocessing, calculates the attack state based on the preprocessed multi-dimensional data, calculates the attack impact degree using a weighted propagation model based on the attack state, constructs a fitness function based on the attack impact degree and optimizes it to obtain an optimal set of protection strategies, improving the predictability and response capabilities of network security management and operation and maintenance, not only enhancing the flexibility and adaptability of the protection system, but also greatly reducing the need for manual intervention.

[0113] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.

Claims

1. A security operation and maintenance management method based on network security incidents, characterized in that: including collecting multi-dimensional data and performing preprocessing, and calculating the attack state based on the preprocessed multi-dimensional data; calculating the attack impact degree using a weighted propagation model based on the attack state, constructing a fitness function based on the attack impact degree and optimizing it to obtain an optimal set of protection strategies; converting the optimal set of protection strategies into control instructions and executing them, and storing the multi-dimensional data generated by collection and analysis; the collecting multi-dimensional data and performing preprocessing refers to using the sFlow protocol to collect multi-dimensional data on the terminal devices of the network and perform preprocessing; the multi-dimensional data includes network topology, bandwidth, transmission delay, and network traffic data; the preprocessing includes using the Network Time Protocol to synchronize the time of the collected multi-dimensional data, using discrete wavelet transform to denoise the multi-dimensional data, using a hash algorithm to identify and delete duplicate data, using the K-nearest neighbor algorithm to fill in missing data, and normalizing the multi-dimensional data; the calculating the attack state based on the preprocessed multi-dimensional data refers to defining the terminal device as a node, extracting the network topology data from the preprocessed multi-dimensional data, and constructing an adjacency matrix from the physical connection relationships in the preprocessed network topology data and defining it as an edge; based on the node, traversing all directly connected nodes in the preprocessed network topology data to form a set of neighbor nodes; Based on the preprocessed network traffic data, use the performance evaluation index method to calculate the IDS protection ability of the th node , and use the weighted average method to calculate the IDS protection ability between the th node and the jth node ; Based on the preprocessed bandwidth data, transmission delay data, and IDS protection capabilities, calculate the th node and the th node's propagation rate , and the formula is: , wherein is the bandwidth between the -th node and the -th node, is the transmission delay between the i-th and j-th nodes; Define the reciprocal of the IDS protection capability of the i-th node as the response coefficient of the -th node ; Collect the maximum bearable attack intensity of the i-th node from the product specification of the device manufacturer ; using a non-linear reaction diffusion model to construct a non-linear ordinary differential equation, the formula is: , Among them and are the attack states of the and th nodes at time t, respectively; is the set of neighbor nodes of the i-th node; Solve the non-linear ordinary differential equation using the Runge-Kutta method to obtain the attack state of the i-th node at time t .

2. The security operation and maintenance management method based on network security events according to claim 1, characterized in that: the calculating the attack impact degree using a weighted propagation model based on the attack state refers to, based on the node, traversing the number of all directly connected edges of the node in the preprocessed network topology data, denoted as the node degree; Iteratively calculate using the Floyd-Warshall algorithm based on the adjacency matrix to obtain the shortest path matrix for each pair of nodes, and extract the elements in the shortest path matrix as the number of hops between the th node and the th node ; Calculate the correction term of the propagation delay using the propagation delay correction formula ; using the PageRank algorithm to calculate the PageRank value PR of the node based on the preprocessed network topology data; Set adjustment factors using empirical regression analysis ; Combine the propagation rate, attack state, correction terms of propagation delay, and PageRank value, and use the weighted propagation model to calculate the attack influence degree of the $i$-th node at time $t$. , and the formula is: , where is the attack state of the -th node, is the PageRank value of the -th node, is the degree of the -th node.

3. The security operation and maintenance management method based on network security incidents according to claim 2, wherein: The fitness function is constructed and optimized based on the attack impact degree to obtain the optimal set of protection strategies, which means that based on the attack state and attack impact degree, the risk degree formula is used to calculate the risk degree of the i-th node , and the formula is: , Among them is the attack impact degree of the j-th node; Use the entropy weight method to calculate the weight coefficients of the attack impact degree and the risk degree respectively. Based on the attack impact degree and the risk degree, use the weighted summation method to calculate the comprehensive risk value ; Construct a fitness function based on the risk degree and the comprehensive risk value , and the formula is as follows: , where N is the total number of nodes in the network, is the protection policy; randomly generating an initial population, including transmission delay and bandwidth allocation, calculating the reconstruction objective function value of each population and defining it as the fitness value, selecting the individual with the lowest fitness value from the initial population for crossover and mutation operations to generate the next generation population, repeating the iterative operation and stopping when the fitness value converges, and outputting the genetic individual with the lowest fitness value in the population after stopping the iteration as the optimal individual to obtain an optimal set of protection strategies, including transmission delay and bandwidth allocation strategies.

4. The security operation and maintenance management method based on network security incidents according to claim 3, characterized in that: the converting the optimal set of protection strategies into control instructions and executing them refers to generating control instructions from the optimal set of protection strategies and executing them, which means using an optimal control strategy generation method to generate control instructions from the optimal set of protection strategies; using the communication protocol DNP3 to transmit the control instructions to the terminal device, and the terminal device receives the control instructions and executes them.

5. The security operation and maintenance management method based on network security incidents according to claim 4, characterized in that: the storing the multi-dimensional data generated by collection and analysis refers to storing the collected multi-dimensional data and the optimal set of protection strategies generated by analysis in the central database, and setting security access measures. The central database backs up the stored data to the cloud, and regularly performs integrity detection on the stored data and the backup data. After the detection is completed, an integrity detection record is generated and synchronously stored in the central database.

6. A security operation and maintenance management system based on network security events, based on the security operation and maintenance management method based on network security events according to any one of claims 1 to 5, characterized in that: including A collection status module for collecting multi-dimensional data, performing preprocessing, and calculating an attack status based on the preprocessed multi-dimensional data; A calculation optimization module for calculating an attack impact degree using a weighted propagation model based on the attack status, constructing a fitness function based on the attack impact degree, and performing optimization to obtain an optimal set of protection strategies; An instruction storage module for converting the optimal set of protection strategies into control instructions for execution and storing the multi-dimensional data generated by collection and analysis.

7. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that: When the processor executes the computer program, it implements the steps of the security operation and maintenance management method based on network security events according to any one of claims 1 to 5.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the steps of the security operation and maintenance management method based on network security events according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Network attack and defense decision support method and system based on artificial intelligence

    CN119155099A