Network public nuisance virtual community discovery method and system based on association graph completion

Through the method based on the correlation graph completion, the attributes of network pollution sites, analyze technical and tactics, construct correlation graphs, and complete gang correlation graphs, successfully discover and analyze hidden assets and behavior patterns of content dissemination virtual communities, solving the problems that are difficult to discover and analyze in existing technologies.

CN119940703AActive Publication Date: 2025-05-06NAT UNIV OF DEFENSE TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411919651.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-25
Publication Date
2025-05-06
Estimated Expiration
2044-12-25

AI Technical Summary

Technical Problem

It is difficult to effectively discover and analyze content dissemination virtual communities, especially when these communities use hidden means.

Method used

Using the method based on correlation graph completion, the hidden assets and behavior patterns of network pollution virtual communities are automatically discovered through the analysis of attributes of network pollution site, technical and tactical analysis, correlation graph construction and gang correlation graph completion modules.

Benefits of technology

It realizes automated discovery and behavioral pattern analysis of the virtual community of cyber pollution is realized, and provides stronger support for cyber pollution control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119940703A_ABST
    Figure CN119940703A_ABST
Patent Text Reader

Abstract

The invention discloses a network public nuisance virtual community discovery method and system based on association graph completion, and belongs to the technical field of network security. The method comprises the following steps: acquiring network public hazard sites, and extracting asset attributes of the network public hazard sites; analyzing technical routes of the network public nuisance sites and implementation means of technical nodes in the technical routes; constructing a network public hazard association graph; determining the similarity between the network public hazard site nodes, dividing the network public hazard site set into a plurality of subsets, and establishing an association subgraph for each subset; converting the associated sub-graph into a directed acyclic graph; and determining the behavior pattern of the network public nuisance virtual community corresponding to the associated sub-graph based on the directed acyclic graph. The method has a good technical effect on network public hazard hidden asset and behavior pattern discovery.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of network security technology, and in particular, relates to a network public nuisance virtual community discovery method and system based on association graph completion. Background Art

[0002] The current methods for discovering virtual communities of cyber nuisance mainly focus on locating virtual communities where cyber nuisance is implemented, aiming to combat and control it from the source. However, virtual communities of cyber nuisance are concealed by means such as changing website templates, renting cloud hosts, and dynamically loading websites, making it extremely difficult to discover the virtual communities where virtual communities of cyber nuisance are located. Summary of the invention

[0003] The present application provides a method and system for discovering virtual communities for content-spreading network nuisance, which is used to solve the above problems or at least partially solve the above problems. While finding out the hidden assets and behavior patterns of the network nuisance virtual community, the virtual community corresponding to the network nuisance virtual community is automatically discovered, providing support for the analysis and governance of the network nuisance virtual community.

[0004] In a first aspect, the present application proposes a method for discovering a network nuisance virtual community based on association graph completion, the method comprising:

[0005] Step S1: The network nuisance site attribute parsing module obtains network nuisance sites, extracts asset attributes of each network nuisance site, the asset attributes include domain name, IP address, web page content, takes each network nuisance site as a network nuisance site node, constructs a network nuisance site set, and each network nuisance site node is an element in the network nuisance site set; the network nuisance site refers to a network nuisance website including a domain name, IP address and web page content that have a corresponding relationship at the same time;

[0006] Step S2: The network hazard technical and tactical analysis module collects certified network hazard research reports, analyzes the technical routes of network hazard and the implementation means of the technical nodes in each technical route; wherein the technical nodes are connected in series to form a technical route, and each technical node corresponds to one or more implementation means;

[0007] Step S3: The network hazard association graph construction module uses a large language model to map the webpage content of each network hazard site node to the corresponding implementation means, and uses the implementation means corresponding to the network hazard site node as a newly added attribute of the network hazard site node. Each network hazard site node has one or more implementation means; construct a network hazard association graph G = (V, E), where V is a set of network hazard sites, and E is an ordered pair (v i ,v j ), representing the network nuisance site node vi to the network nuisance site node v in Vj The jump relationship is determined based on the IP address of the network public nuisance site node and the web page content attribute;

[0008] Step S4: The network nuisance gang association graph completion module determines the similarity between network nuisance site nodes based on the attributes of the network nuisance site nodes, divides the network nuisance site set into a number of subsets, establishes an association subgraph for each subset, and constructs the edges in the association subgraph based on the edges in the network nuisance association graph. The network nuisance site nodes corresponding to the association subgraph form a network nuisance virtual community;

[0009] For each associated subgraph: based on the order of each technical node in the technical route and the implementation means corresponding to each network nuisance site node in the associated subgraph, the associated subgraph is converted into a directed acyclic graph; based on the directed acyclic graph, the behavior pattern of the network nuisance virtual community corresponding to the associated subgraph is determined.

[0010] Preferably, the virtual community discovery method for content-propagation network nuisance also includes: step S5: taking the network nuisance site nodes whose behavior patterns have a similarity with the behavior patterns of the network nuisance virtual community exceeding a preset threshold as the associated network nuisance site nodes of the network nuisance virtual community; performing behavior pattern mining on the network nuisance virtual community and the associated network nuisance site nodes to determine the hidden behavior patterns of the network nuisance virtual community.

[0011] Preferably, in step S4, the network nuisance group association graph completion module determines the similarity between network nuisance site nodes based on the attributes of the network nuisance site nodes, divides the network nuisance site set into a number of subsets, establishes an association subgraph for each subset, and constructs the edges in the association subgraph based on the edges in the network nuisance association graph, including: classifying network nuisance site nodes whose domain name similarity is greater than a first preset threshold into the same subset; classifying network nuisance site nodes whose IP address similarity is greater than a second preset threshold into the same subset; classifying network nuisance site nodes whose webpage content similarity is greater than a third preset threshold into the same subset;

[0012] For each subset: obtain all network nuisance site node pairs in the subset, and if there are directed edges between the network nuisance site node pairs in the network nuisance association graph, establish directed edges between the network nuisance site node pairs in the subset; and form an association subgraph.

[0013] Preferably, the step S4: based on the order of each technical node in the technical route and the implementation means corresponding to each network nuisance site node in the associated subgraph, convert the associated subgraph into a directed acyclic graph; based on the directed acyclic graph, determine the behavior pattern of the network nuisance virtual community corresponding to the associated subgraph, including: determining the technical nodes corresponding to the implementation means of each network nuisance site node in the associated subgraph;

[0014] Deleting the directed edges in the associated subgraph that are inconsistent with the order of the technical nodes in the technical route;

[0015] Converting the associated subgraph into a directed acyclic graph;

[0016] Based on the implementation means corresponding to each network nuisance site node in the directed acyclic graph, the behavior pattern corresponding to the associated subgraph is determined, and the behavior pattern is used as the behavior pattern of the network nuisance virtual community corresponding to the associated subgraph.

[0017] Preferably, the step S5: taking a network nuisance site node whose behavior pattern similarity with the behavior pattern of the network nuisance virtual community exceeds a preset threshold as an associated network nuisance site node of the network nuisance virtual community; and performing behavior pattern mining on the network nuisance virtual community and the associated network nuisance site nodes to determine the hidden behavior pattern of the network nuisance virtual community, comprises:

[0018] The associated network nuisance site nodes are incorporated into the subset corresponding to the network nuisance virtual community, an associated subgraph is established for the updated subset, and the associated subgraph corresponding to the updated subset is converted into a directed acyclic graph; based on the directed acyclic graph, a behavior pattern corresponding to the associated subgraph is determined, and the behavior pattern is used as a hidden behavior pattern of the network nuisance virtual community.

[0019] The second aspect of the present application proposes a network nuisance virtual community discovery system based on association graph completion, the system comprising:

[0020] Network nuisance site attribute parsing module: The network nuisance site attribute parsing module obtains network nuisance sites, extracts asset attributes of each network nuisance site, the asset attributes include domain name, IP address, web page content, takes each network nuisance site as a network nuisance site node, constructs a network nuisance site set, and each network nuisance site node is an element in the network nuisance site set; the network nuisance site refers to a network nuisance website including a domain name, IP address and web page content that have a corresponding relationship at the same time;

[0021] Network pollution technical and tactical analysis module: collects certified network pollution research reports, analyzes the technical routes of network pollution and the implementation methods of technical nodes in each technical route; technical nodes are connected in series to form a technical route, and each technical node corresponds to one or more implementation methods;

[0022] Network hazard association graph construction module: Use a large language model to map the webpage content of each network hazard site node to the corresponding implementation means, and use the implementation means corresponding to the network hazard site node as the newly added attribute of the network hazard site node. Each network hazard site node has one or more implementation means; construct a network hazard association graph G = (V, E), where V is a set of network hazard sites, and e is an ordered pair (v i ,v j ), representing the network nuisance site node v in V i To the network nuisance site node v j The jump relationship is determined based on the IP address of the network nuisance site node and the webpage content attribute; the network nuisance virtual community association graph completion module: based on the attributes of the network nuisance site node, determine the similarity between the network nuisance site nodes, divide the network nuisance site set into several subsets, establish an association subgraph for each subset, and construct the edges in the association subgraph based on the edges in the network nuisance association graph. The network nuisance site nodes corresponding to the association subgraph constitute the network nuisance virtual community;

[0023] For each associated subgraph: based on the order of each technical node in the technical route and the implementation means corresponding to each network nuisance site node in the associated subgraph, the associated subgraph is converted into a directed acyclic graph; based on the directed acyclic graph, the behavior pattern of the network nuisance virtual community corresponding to the associated subgraph is determined.

[0024] A third aspect of the present application provides an electronic device, the electronic device comprising:

[0025] at least one processor; and

[0026] a memory communicatively connected to the at least one processor; wherein,

[0027] The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method described above.

[0028] A fourth aspect of the present application proposes a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to enable the computer to execute the method as described above.

[0029] This application has the following technical effects:

[0030] 1. This application takes into account the similarity of network nuisance asset attributes such as the C segment of the network nuisance site IP address, site domain name, and web page screenshot information. It also considers the similarity of network nuisance implementation techniques and tactics from a global perspective, making this application more advantageous in discovering hidden assets and behavior patterns of network nuisance.

[0031] 2. This application introduces external knowledge of the Internet pollution research report, and represents the Internet pollution research report and the website content by vectors based on the same language model. Therefore, the vector spaces of the two have natural consistency, making the site content mapping of the Internet pollution node of this application more accurate. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] Figure 1 A flowchart of a method for discovering virtual communities targeting content-spreading network hazards;

[0033] Figure 2 A schematic diagram of the architecture of a virtual community discovery method for content-spreading network hazards;

[0034] Figure 3 This is a schematic diagram of the structure of a virtual community discovery system for content-spreading network hazards. DETAILED DESCRIPTION

[0035] The embodiments of the present application are described in detail below with reference to the accompanying drawings.

[0036] like Figure 1-Figure 2 As shown, the present application provides a network nuisance virtual community discovery method based on association graph completion, the method comprising:

[0037] Step S1: The network nuisance site attribute parsing module obtains network nuisance sites, extracts asset attributes of each network nuisance site, the asset attributes include domain name, IP address, web page content, takes each network nuisance site as a network nuisance site node, constructs a network nuisance site set, and each network nuisance site node is an element in the network nuisance site set; the network nuisance site refers to a network nuisance website including a domain name, IP address and web page content that have a corresponding relationship at the same time;

[0038] Step S2: The network hazard technical and tactical analysis module collects certified network hazard research reports, analyzes the technical routes of network hazard and the implementation means of the technical nodes in each technical route; wherein the technical nodes are connected in series to form a technical route, and each technical node corresponds to one or more implementation means;

[0039] Step S3: The network hazard association graph construction module uses a large language model to map the webpage content of each network hazard site node to the corresponding implementation means, and uses the implementation means corresponding to the network hazard site node as a newly added attribute of the network hazard site node. Each network hazard site node has one or more implementation means; construct a network hazard association graph G = (V, E), where V is a set of network hazard sites, and E is an ordered pair (v i ,v j ), representing the network nuisance site node vi to the network nuisance site node v in V j The jump relationship is determined based on the IP address of the network public nuisance site node and the web page content attribute;

[0040] Step S4: The network nuisance gang association graph completion module determines the similarity between network nuisance site nodes based on the attributes of the network nuisance site nodes, divides the network nuisance site set into a number of subsets, establishes an association subgraph for each subset, and constructs the edges in the association subgraph based on the edges in the network nuisance association graph. The network nuisance site nodes corresponding to the association subgraph form a network nuisance virtual community;

[0041] For each associated subgraph: based on the order of each technical node in the technical route and the implementation means corresponding to each network nuisance site node in the associated subgraph, the associated subgraph is converted into a directed acyclic graph; based on the directed acyclic graph, the behavior pattern of the network nuisance virtual community corresponding to the associated subgraph is determined.

[0042] The method for discovering virtual communities for content-spreading network nuisance also includes: step S5: taking network nuisance site nodes whose behavior patterns have a similarity with the behavior patterns of the network nuisance virtual community exceeding a preset threshold as associated network nuisance site nodes of the network nuisance virtual community; and performing behavior pattern mining on the network nuisance virtual community and the associated network nuisance site nodes to determine the hidden behavior patterns of the network nuisance virtual community.

[0043] Further, in step S4, the network nuisance group association graph completion module determines the similarity between network nuisance site nodes based on the attributes of the network nuisance site nodes, divides the network nuisance site set into a number of subsets, establishes an association subgraph for each subset, and constructs the edges in the association subgraph based on the edges in the network nuisance association graph, including: classifying network nuisance site nodes whose domain name similarity is greater than a first preset threshold into the same subset; classifying network nuisance site nodes whose IP address similarity is greater than a second preset threshold into the same subset; classifying network nuisance site nodes whose webpage content similarity is greater than a third preset threshold into the same subset;

[0044] For each subset: obtain all network nuisance site node pairs in the subset, and if there are directed edges between the network nuisance site node pairs in the network nuisance association graph, establish directed edges between the network nuisance site node pairs in the subset; and form an association subgraph.

[0045] The step S4: based on the order of each technical node in the technical route and the implementation means corresponding to each network nuisance site node in the associated subgraph, convert the associated subgraph into a directed acyclic graph; based on the directed acyclic graph, determine the behavior mode of the network nuisance virtual community corresponding to the associated subgraph, including: determining the technical nodes corresponding to the implementation means of each network nuisance site node in the associated subgraph;

[0046] Deleting the directed edges in the associated subgraph that are inconsistent with the order of the technical nodes in the technical route;

[0047] Converting the associated subgraph into a directed acyclic graph;

[0048] Based on the implementation means corresponding to each network nuisance site node in the directed acyclic graph, the behavior pattern corresponding to the associated subgraph is determined, and the behavior pattern is used as the behavior pattern of the network nuisance virtual community corresponding to the associated subgraph.

[0049] The step S5: taking the network nuisance site nodes whose behavior patterns have a similarity with the behavior patterns of the network nuisance virtual community exceeding a preset threshold as the associated network nuisance site nodes of the network nuisance virtual community; performing behavior pattern mining on the network nuisance virtual community and the associated network nuisance site nodes to determine the hidden behavior patterns of the network nuisance virtual community, including:

[0050] The associated network nuisance site nodes are incorporated into the subset corresponding to the network nuisance virtual community, an associated subgraph is established for the updated subset, and the associated subgraph corresponding to the updated subset is converted into a directed acyclic graph; based on the directed acyclic graph, a behavior pattern corresponding to the associated subgraph is determined, and the behavior pattern is used as a hidden behavior pattern of the network nuisance virtual community.

[0051] The present invention provides a specific embodiment of a method for discovering a network nuisance virtual community based on association graph completion. The method comprises:

[0052] Step 1: Access cyberspace site data and collect network nuisance research reports such as "Special Report on Judicial Big Data on Characteristics and Trends of Information Network Crimes (2017.1-2021.12)" and "White Paper on Preventing and Governing Telecommunications Network Fraud in the Information and Communication Industry";

[0053] Step 2: traverse the network space site data, screen out network hazard sites based on the existing network hazard identification method, analyze the asset attributes of network hazard sites, and construct a network hazard node set V, where any node v i ∈V has a domain name IP address Web Content The three attributes are

[0054] And based on the hyperlink relationship, a network pollution site association graph is established. For example, if there is a hyperlink pointing to www.se**b.com in the homepage of www.se**a.com, a directed edge from www.se**a.com to www.se**b.com is added to the graph;

[0055] Step 3: Based on the data from the Internet nuisance research report, design and improve the technical route for describing Internet nuisance behaviors;

[0056] Step 4: Based on language models such as TopicGPT, map the content of the network nuisance site to the technical nodes corresponding to the technical route. For example, map the nuisance site with the domain name www.se**a.com to a specific implementation method, and add the technical value attribute to the node attribute of the network nuisance site. That is, for any v i ∈V,

[0057] By analyzing the network nuisance node set V, a network nuisance association graph G = (V, E) is constructed, where V is the network nuisance site node set and E is an ordered pair (v i ,v j ), representing the pollution site v in V i To the pollution site j Jump relationship of

[0058] Step 5: First, construct an associated subgraph based on the similarity of public nuisance site attributes. For the network public nuisance associated graph G, if the basic rules can be used to determine that adjacent graph nodes belong to the same public nuisance virtual community, the corresponding nodes and edges are retained, otherwise the edges are deleted from the graph. The basic rules include: (1) based on the domain name attributes of the associated graph nodes The node relationship is discovered. The domain names of adjacent graph nodes are similar. For example, if the domain name of the website corresponding to the first node is www.sehuiy**a.com and the domain name of the website corresponding to the last node is www.sehuiy**b.com, then the two nodes are considered to belong to the same organization (where ** is the same character value);

[0059] (2) Based on the IP address attributes of the association graph nodes The node relationship is discovered. The IPs of adjacent graph nodes have the same C segment. For example, if the IP of the first node is ***.163.4.5 and the IP of the last node ends with ***.163.4.32, then the two nodes are considered to belong to the same organization (where *** is the same A segment value); (3) Based on the attributes of the associated graph node webpage screenshot The node relationship is found. The webpage screenshot information of adjacent graph nodes has similarity. For example, the website templates of two websites are the same, and the pages are different only in the website establishment date. After basic rule screening, a preliminary virtual community network pollution asset association graph G1=(V1,E1) can be obtained, where and

[0060] Step 6: Based on the above subgraphs, we can preliminarily obtain the network nuisance virtual community information. According to the order of the technical nodes of the technical route, the association graph can be represented as a directed acyclic graph. In this process, we remove the association relationships that do not meet the network nuisance tactical order. i ,v j ),but and If the tactical order relationship in the network pollution technology and tactics matrix is ​​not satisfied, then the updated graph G1′=(V1′,E1′), where E1′=E1\{(v i ,v j )}. Then, the technical routes of all paths on the graph are extracted to construct a set of technical implementation modes M of the network pollution virtual community, where any implementation mode Provide a technical path for implementing network nuisance, and use the technical path as the behavior model of the network nuisance virtual community;

[0061] Step 7: Add any m in the network pollution association graph G k For the edge e∈E that is not in the set E1′, add it to E1′ and repeat steps five to seven to discover the hidden assets and hidden behavior patterns of the virtual community with the same public nuisance;

[0062] Step 8: When no new node is added, the public nuisance association graph G1 of the same virtual community network is output, which is the virtual community of the public nuisance virtual community.

[0063] like Figure 3 As shown, the present application provides a network nuisance virtual community discovery system based on association graph completion, the system comprising:

[0064] Network nuisance site attribute parsing module: The network nuisance site attribute parsing module obtains network nuisance sites, extracts asset attributes of each network nuisance site, the asset attributes include domain name, IP address, web page content, takes each network nuisance site as a network nuisance site node, constructs a network nuisance site set, and each network nuisance site node is an element in the network nuisance site set; the network nuisance site refers to a network nuisance website including a domain name, IP address and web page content that have a corresponding relationship at the same time;

[0065] Network pollution technical and tactical analysis module: collects certified network pollution research reports, analyzes the technical routes of network pollution and the implementation methods of technical nodes in each technical route; technical nodes are connected in series to form a technical route, and each technical node corresponds to one or more implementation methods;

[0066] Network hazard association graph construction module: Use the large language model to map the webpage content of each network hazard site node to the corresponding implementation means, and use the implementation means corresponding to the network hazard site node as the newly added attribute of the network hazard site node. Each network hazard site node has one or more implementation means; construct a network hazard association graph G = (V, E), where V is a set of network hazard sites, and E is an ordered pair (v i ,v j ), representing the network nuisance site node v in V i To the network nuisance site node v j The jump relationship is determined based on the IP address of the network public nuisance site node and the web page content attribute;

[0067] Network nuisance gang association graph completion module: based on the attributes of the network nuisance site nodes, determine the similarity between network nuisance site nodes, divide the network nuisance site set into several subsets, establish an association subgraph for each subset, and construct the edges in the association subgraph based on the edges in the network nuisance association graph. The network nuisance site nodes corresponding to the association subgraph form a network nuisance virtual community;

[0068] For each associated subgraph: based on the order of each technical node in the technical route and the implementation means corresponding to each network nuisance site node in the associated subgraph, the associated subgraph is converted into a directed acyclic graph; based on the directed acyclic graph, the behavior pattern of the network nuisance virtual community corresponding to the associated subgraph is determined.

[0069] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application is described in detail with reference to the above embodiments, a person skilled in the art should understand that the technical solutions described in the above embodiments can still be modified, or some or all of the technical features can be replaced by equivalents, and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present application.

Claims

1. A network nuisance virtual community discovery method based on association graph completion, characterized in that: The method comprises the following steps: Step S1: The network nuisance site attribute parsing module obtains network nuisance sites, extracts asset attributes of each network nuisance site, the asset attributes include domain name, IP address, web page content, takes each network nuisance site as a network nuisance site node, constructs a network nuisance site set, and each network nuisance site node is an element in the network nuisance site set; the network nuisance site refers to a network nuisance website including a domain name, IP address and web page content that have a corresponding relationship at the same time; Step S2: The network hazard technical and tactical analysis module collects certified network hazard research reports, analyzes the technical routes of network hazard and the implementation means of the technical nodes in each technical route; wherein the technical nodes are connected in series to form a technical route, and each technical node corresponds to one or more implementation means; Step S3: The network hazard association graph construction module uses a large language model to map the webpage content of each network hazard site node to the corresponding implementation means, and uses the implementation means corresponding to the network hazard site node as a newly added attribute of the network hazard site node. Each network hazard site node has one or more implementation means; construct a network hazard association graph G = (V, E), where V is a set of network hazard sites, and E is an ordered pair (v i ,v j ), representing the network nuisance site node v in V i To the network nuisance site node v j The jump relationship is determined based on the IP address of the network public nuisance site node and the web page content attribute; Step S4: The network nuisance gang association graph completion module determines the similarity between network nuisance site nodes based on the attributes of the network nuisance site nodes, divides the network nuisance site set into a number of subsets, establishes an association subgraph for each subset, and constructs the edges in the association subgraph based on the edges in the network nuisance association graph. The network nuisance site nodes corresponding to the association subgraph form a network nuisance virtual community; For each associated subgraph: based on the order of each technical node in the technical route and the implementation means corresponding to each network nuisance site node in the associated subgraph, the associated subgraph is converted into a directed acyclic graph; based on the directed acyclic graph, the behavior pattern of the network nuisance virtual community corresponding to the associated subgraph is determined.

2. The method according to claim 1, characterized in that The method for discovering virtual communities for content-spreading network nuisance also includes: step S5: taking network nuisance site nodes whose behavior patterns have a similarity with the behavior patterns of the network nuisance virtual community exceeding a preset threshold as associated network nuisance site nodes of the network nuisance virtual community; and performing behavior pattern mining on the network nuisance virtual community and the associated network nuisance site nodes to determine the hidden behavior patterns of the network nuisance virtual community.

3. The method according to any one of claims 1 to 2, characterized in that: In step S4, the network nuisance group association graph completion module determines the similarity between network nuisance site nodes based on the attributes of the network nuisance site nodes, divides the network nuisance site set into a number of subsets, establishes an association subgraph for each subset, and constructs the edges in the association subgraph based on the edges in the network nuisance association graph, including: classifying network nuisance site nodes with domain name similarity greater than a first preset threshold into the same subset; classifying network nuisance site nodes with IP address similarity greater than a second preset threshold into the same subset; classifying network nuisance site nodes with webpage content similarity greater than a third preset threshold into the same subset; For each subset: obtain all network nuisance site node pairs in the subset, and if there are directed edges between the network nuisance site node pairs in the network nuisance association graph, establish directed edges between the network nuisance site node pairs in the subset; and form an association subgraph.

4. The method according to claim 3, characterized in that The step S4: based on the order of each technical node in the technical route and the implementation means corresponding to each network hazard site node in the associated subgraph, converting the associated subgraph into a directed acyclic graph; Determining the behavior pattern of the network nuisance virtual community corresponding to the associated subgraph based on the directed acyclic graph includes: determining the technical nodes corresponding to the implementation means of each network nuisance site node in the associated subgraph; Deleting the directed edges in the associated subgraph that are inconsistent with the order of the technical nodes in the technical route; Converting the associated subgraph into a directed acyclic graph; Based on the implementation means corresponding to each network nuisance site node in the directed acyclic graph, the behavior pattern corresponding to the associated subgraph is determined, and the behavior pattern is used as the behavior pattern of the network nuisance virtual community corresponding to the associated subgraph.

5. The method according to claim 2, characterized in that The step S5: taking the network nuisance site nodes whose behavior patterns have a similarity with the behavior patterns of the network nuisance virtual community exceeding a preset threshold as the associated network nuisance site nodes of the network nuisance virtual community; Conducting behavior pattern mining on the network nuisance virtual community and the associated network nuisance site nodes to determine the hidden behavior pattern of the network nuisance virtual community, including: incorporating the associated network nuisance site nodes into a subset corresponding to the network nuisance virtual community, establishing an associated subgraph for the updated subset, and converting the associated subgraph corresponding to the updated subset into a directed acyclic graph; Based on the directed acyclic graph, a behavior pattern corresponding to the associated subgraph is determined, and the behavior pattern is used as a hidden behavior pattern of the network nuisance virtual community.

6. A network nuisance virtual community discovery system based on association graph completion, characterized in that: The system comprises: Network nuisance site attribute parsing module: The network nuisance site attribute parsing module obtains network nuisance sites, extracts asset attributes of each network nuisance site, the asset attributes include domain name, IP address, web page content, takes each network nuisance site as a network nuisance site node, constructs a network nuisance site set, and each network nuisance site node is an element in the network nuisance site set; the network nuisance site refers to a network nuisance website including a domain name, IP address and web page content that have a corresponding relationship at the same time; Network pollution technical and tactical analysis module: collects certified network pollution research reports, analyzes the technical routes of network pollution and the implementation methods of technical nodes in each technical route; technical nodes are connected in series to form a technical route, and each technical node corresponds to one or more implementation methods; Network hazard association graph construction module: Use the large language model to map the webpage content of each network hazard site node to the corresponding implementation means, and use the implementation means corresponding to the network hazard site node as the newly added attribute of the network hazard site node. Each network hazard site node has one or more implementation means; construct a network hazard association graph G = (V, E), where V is a set of network hazard sites, and E is an ordered pair (v i ,v j ), representing the network nuisance site node v in V i To the network nuisance site node v j The jump relationship is determined based on the IP address of the network public nuisance site node and the web page content attribute; Network nuisance gang association graph completion module: based on the attributes of the network nuisance site nodes, determine the similarity between network nuisance site nodes, divide the network nuisance site set into several subsets, establish an association subgraph for each subset, and construct the edges in the association subgraph based on the edges in the network nuisance association graph. The network nuisance site nodes corresponding to the association subgraph form a network nuisance virtual community; For each associated subgraph: based on the order of each technical node in the technical route and the implementation means corresponding to each network nuisance site node in the associated subgraph, the associated subgraph is converted into a directed acyclic graph; based on the directed acyclic graph, the behavior pattern of the network nuisance virtual community corresponding to the associated subgraph is determined.

7. A computer-readable storage medium, wherein a plurality of instructions are stored in the storage medium; the plurality of instructions are used for a processor to load and execute the method as claimed in any one of claims 1 to 5.

8. An electronic device, characterized in that: The electronic device comprises: A processor, which is used to execute multiple instructions; A memory for storing a plurality of instructions; The plurality of instructions are used to be stored in the memory and loaded and executed by the processor according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Network public hazard key node identification method and system based on knowledge graph

    CN118503450A

  • Method and system for detecting overlapping communities based on similarity between nodes in social network

    US20180341696A1