Network security test and evaluation system
By designing a network security test evaluation system that integrates data acquisition, prediction model and response strategy generation, the existing system lacks prediction and prevention of potential attacks, and realizes effective defense before an attack occurs, reducing the possibility and loss of attack success.
Patent Information
- Application Number
- CN202411798035.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-09
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-12-09
AI Technical Summary
Existing network security testing and evaluation systems lack the ability to predict and prevent potential attacks, especially in complex and changeable network environments, it is difficult to predict possible attacks in real time and accurately and take effective preventive measures.
A network security test and evaluation system is designed, including data acquisition module, prediction model module, response strategy generation module, feedback and learning module, system management and control module and security evaluation report generation module. The system builds a prediction model, based on historical data and real-time data, predicts potential cyber attacks in real time, and generates response strategies based on the prediction results, including strengthening monitoring and automatically blocking suspicious traffic.
By introducing prediction models, the system can make judgments and prepare before an attack occurs, reducing the possibility of an attack success and reducing the losses caused after being attacked.
Smart Images

Figure CN119945708A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of network security, and in particular to a network security testing and evaluation system. Background Art
[0002] With the rapid development of the Internet and the popularization of informatization, network security has become a core concern of all industries. The forms and means of network attacks are becoming increasingly diverse and complex, bringing huge security risks to enterprises, governments and individual users. Although traditional network security protection measures such as firewalls, intrusion detection systems and antivirus software can provide a certain degree of protection, they are often based on the defense of known threats and have limited effectiveness against new or unknown attack methods. In recent years, with the development of big data technology, artificial intelligence (AI) and machine learning (ML), the field of network security has gradually begun to introduce these technologies to improve the detection and defense capabilities of network attacks. In particular, by building predictive models to analyze and process large amounts of network traffic data and user behavior data, it is possible to predict potential threats before an attack occurs, and then generate corresponding response strategies.
[0003] However, existing network security testing and evaluation systems usually focus on the response after attack detection, but lack the ability to predict and prevent potential attacks. Especially in the face of complex and changing network environments, how to accurately predict possible attacks in real time and take effective preventive measures is still a major challenge in the field of network security. Summary of the invention
[0004] The purpose of this section is to summarize some aspects of embodiments of the present invention and briefly introduce some preferred embodiments. Some simplifications or omissions may be made in this section and the specification abstract and the invention title of this application to avoid blurring the purpose of this section, the specification abstract and the invention title, and such simplifications or omissions cannot be used to limit the scope of the present invention.
[0005] In order to solve the above technical problems, the present invention provides the following technical solutions:
[0006] In a first aspect, an embodiment of the present invention provides a network security testing and evaluation system, comprising:
[0007] Data collection module: responsible for collecting various data from the network environment in real time and pre-processing the data, including traffic data, log data, user behavior data and device status data;
[0008] Prediction model module: Build prediction models based on historical data and real-time data to predict potential network attacks;
[0009] Response strategy generation module: Automatically generates response measures based on the output of the prediction model module. The response measures include strengthening monitoring, recording traffic logs, automatically blocking suspicious traffic, triggering alarms, adjusting firewall rules, and notifying the security team for manual intervention;
[0010] Feedback and learning module: collects feedback data after the implementation of the response strategy, evaluates the effectiveness of the response measures, and feeds the results back to the prediction model module to continuously optimize the performance of the prediction model;
[0011] System management and control module: provides a unified management and control interface for the system, including configuration management, policy management, user management, and log auditing;
[0012] Security Assessment Report Generation Module: Generates a detailed security assessment report, including potential attacks discovered, system countermeasures, accuracy of prediction models, and overall network security posture.
[0013] As a preferred solution of the network security test and evaluation system described in the present invention, the prediction model is specifically a network attack prediction value P(t) at time t, and the specific calculation formula of P(t) is as follows:
[0014]
[0015] Where Z(t) is the normalization factor; D(t, τ) represents the time-attenuated eigenvalue at time t.
[0016] As a preferred solution of the network security test and evaluation system described in the present invention, the specific calculation formula of D(t, τ) is as follows:
[0017] D(t, τ) = e -λ(T- τ)·S(t,τ)
[0018] Where S(t, τ) represents the comprehensive characteristic value at time t and past state τ; λ is the decay constant; T is the maximum time range; τ is the integral variable, representing the past state of time.
[0019] As a preferred solution of the network security test and evaluation system described in the present invention, the specific calculation formula of S(t, τ) is as follows:
[0020]
[0021] Where N is the number of features, indicating the number of key features used for prediction; σ i is the weight of the feature, σ i is a positive number, indicating the degree of influence of the reaction characteristics on the prediction results; f i (x(t), τ) represents the characteristic function related to network traffic; gi (y(t), τ) represents a characteristic function related to user behavior.
[0022] As a preferred solution of a network security test and evaluation system according to the present invention, wherein: the f i The specific calculation formula of (x(t), τ) is as follows:
[0023]
[0024] Where h i Is the proportionality coefficient of feature i; β i Is the amplification factor of this feature.
[0025] As a preferred solution of a network security test and evaluation system according to the present invention, wherein: the g i The specific calculation formula of (y(t), τ) is as follows:
[0026] g i (y(t), τ) = k i ·log(1 + y(t - τ))
[0027] Where k i The proportionality coefficient of feature i.
[0028] As a preferred solution of a network security test and evaluation system according to the present invention, wherein:
[0029] The P(t) represents the potential network attack intensity and possibility at time t, and its value range specifically includes:
[0030] 0 < P(t) < 0.5, low probability, the system maintains normal operation, but security audits and inspections need to be carried out regularly;
[0031] 0.5 < P(t) < 0.8, medium probability, the system continues to operate, but monitoring needs to be strengthened, traffic logs need to be recorded, and an alarm needs to be triggered to notify the staff;
[0032] 0.8 < P(t) < 1, high probability, the system triggers security measures to automatically block suspicious traffic, trigger an alarm, adjust firewall rules, and notify the security team for manual intervention.
[0033] In a second aspect, an embodiment of the present invention provides a network security test and evaluation method, specifically including:
[0034] S1. The data acquisition module obtains data from the network in real time and transmits it to the prediction model module;
[0035] S2. The prediction model module analyzes and calculates based on the collected data to predict potential network attacks;
[0036] S3, the response strategy generation module immediately formulates and implements response measures based on the prediction results;
[0037] S4, the feedback and learning module collects the effects of the response measures and feeds them back to the prediction model to optimize the model performance;
[0038] S5. The safety assessment report generation module generates and displays a detailed safety assessment report.
[0039] In a third aspect, an embodiment of the present invention provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and wherein the processor executes a network security testing and evaluation system as described in the first aspect of the present invention.
[0040] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program is executed by a processor as the network security testing and evaluation system described in the first aspect of the present invention.
[0041] Beneficial effects of the present invention:
[0042] This invention introduces a prediction model to predict the intensity and possibility of network attacks in real time, and takes corresponding measures based on the prediction results, so that the security system can make judgments and preparations before the attack occurs, reducing the possibility of successful attacks and reducing the losses caused by the attack. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative labor. Among them:
[0044] Figure 1 A system framework diagram of a network security testing and evaluation system proposed by the present invention;
[0045] Figure 2 A flowchart of the network security testing and evaluation system proposed by the present invention;
[0046] Figure 3 It is a comparison chart of reaction time in Example 2;
[0047] Figure 4 This is a comparison chart of the number of attacks successfully blocked in Example 2;
[0048] Figure 5 This is a comparison chart of CPU occupancy in Example 2;
[0049] Figure 6 This is a comparison chart of the successful defense rates in Example 2. DETAILED DESCRIPTION
[0050] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the accompanying drawings.
[0051] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.
[0052] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The term "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive with other embodiments.
[0053] Example 1
[0054] Reference Figure 1-2 The present invention provides a network security testing and evaluation system, comprising:
[0055] Data collection module: responsible for collecting various data from the network environment in real time, pre-processing the data, including traffic data, log data, user behavior data and device status data, deploying sensors at key locations of the network, and transmitting the collected data to the central processor through a secure channel;
[0056] Prediction model module: Build prediction models based on historical data and real-time data to predict potential network attacks;
[0057] Response strategy generation module: Automatically generates response measures based on the output of the prediction model module. The response measures include strengthening monitoring, recording traffic logs, automatically blocking suspicious traffic, triggering alarms, adjusting firewall rules, and notifying the security team for manual intervention;
[0058] Feedback and learning module: collects feedback data after the implementation of the response strategy, evaluates the effectiveness of the response measures, and feeds the results back to the prediction model module to continuously optimize the performance of the prediction model;
[0059] System management and control module: provides a unified management and control interface for the system, including configuration management, policy management, user management and log auditing. It uses a web-based management interface, integrates access control, audit logs and user rights management to ensure the security and operability of the system.
[0060] Security Assessment Report Generation Module: Generates detailed security assessment reports, including potential attacks discovered, system countermeasures, accuracy of prediction models, and overall network security posture. Reports can be generated regularly or instantly based on user needs.
[0061] The prediction model is specifically the network attack prediction value P(t) at time t. The specific calculation formula of P(t) is as follows:
[0062]
[0063] Where Z(t) is a normalization factor used to ensure a reasonable range of predicted values. The specific form is: where α j is a positive constant; D(t, τ) represents the characteristic value after time decay at time t. Furthermore, the specific calculation formula of D(t, τ) is as follows:
[0064] D(t, τ) = e -λ(T-τ) S(t, τ)
[0065] Where S(t, τ) represents the comprehensive characteristic value at time t and past state τ; λ is the decay constant, which controls the influence of past data on the current prediction; T is the maximum time range, which represents the maximum time span of historical data; τ is the integral variable, which represents the past state of time.
[0066] Furthermore, the specific calculation formula of S(t, τ) is as follows:
[0067]
[0068] Where N is the number of features, indicating the number of key features used for prediction; σ i is the weight of the feature, σ i is a positive number, indicating the degree of influence of the reaction characteristics on the prediction results; f i (x(t), τ) represents the characteristic function related to network traffic, which depends on the real-time collection of network traffic data x(t) and the past state τ; g i (y(t), τ) represents the characteristic function related to user behavior, which depends on the real-time collected user behavior data y(t) and the past state τ.
[0069] Furthermore, f i The specific calculation formula of (x(t), τ) is as follows:
[0070]
[0071] where h i is the proportionality coefficient of feature i; βi is the amplification factor for this feature.
[0072] Furthermore, g i (y(t), τ) has the following specific calculation formula:
[0073] g i (y(t), τ) = k i ·log(1 + y(t - τ))
[0074] where k i is the proportionality coefficient of feature i.
[0075] Furthermore, P(t) represents the potential network attack intensity and probability at time t, and its value range specifically includes:
[0076] 0 < P(t) < 0.5, low probability, the system maintains normal operation, but security audits and inspections need to be carried out regularly;
[0077] 0.5 < P(t) < 0.8, medium probability, the system continues to operate, but monitoring needs to be strengthened, traffic logs need to be recorded, and an alarm needs to be triggered to notify the staff;
[0078] 0.8 < P(t) < 1, high probability, the system triggers security measures to automatically block suspicious traffic, trigger an alarm, adjust firewall rules, and notify the security team for manual intervention, and monitor network security in real time according to different prediction results.
[0079] This embodiment also provides a network security test and evaluation method, which specifically includes:
[0080] S1. The data acquisition module obtains data from the network in real time and transmits it to the prediction model module;
[0081] S2. The prediction model module analyzes and calculates based on the collected data to predict potential network attacks;
[0082] S3. The countermeasure generation module immediately formulates and executes countermeasures according to the prediction results;
[0083] S4. The feedback and learning module collects the effects of the countermeasures and feeds them back to the prediction model to optimize the model performance;
[0084] S5. The security assessment report generation module generates and displays a detailed security assessment report.
[0085] This embodiment also provides a computer device, including a memory and a processor. The memory stores a computer program, and the processor executes a network security test and evaluation system as described above.
[0086] The computer device may be a terminal, and the computer device includes a processor, a memory, a communication interface, a display screen and an input device connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, an operator network, NFC (near field communication) or other technologies. The display screen of the computer device may be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device may be a touch layer covering the display screen, or a key, trackball or touchpad provided on the housing of the computer device, or an external keyboard, touchpad or mouse, etc.
[0087] This embodiment also provides a computer-readable storage medium on which a computer program is stored, such as a network security test and evaluation system as above, which is executed by a processor. The storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, disk or optical disk.
[0088] Example 2
[0089] Reference Figure 3 , which is the second embodiment of the present invention. This embodiment is different from the first embodiment in that, in order to verify its beneficial effects, experimental comparison data between the present invention and the prior art are provided.
[0090] This embodiment sets up a virtual enterprise network containing 1000 hosts, in which a traditional firewall, an intrusion detection system (IDS), and a prediction model system based on the present invention are configured. Three different types of attacks are simulated in the network, including distributed denial of service attacks (DDoS), SQL injection attacks, and phishing email attacks.
[0091] Normal traffic and user behavior are simulated in the network, and data is collected to train the prediction model of the present invention. The model adopts a supervised learning algorithm, and uses the collected network traffic characteristics and user behavior characteristics for learning and model optimization. Afterwards, before each attack is launched, the model will make real-time predictions based on the latest traffic data, and automatically adjust firewall rules and IDS policies when possible signs of attack are detected to reduce the impact of the attack. As the attack begins, abnormal behavior gradually appears in the network traffic. Traditional firewalls and IDS can identify a portion of known attack traffic and intercept it, but for unknown or incompletely matched attacks, some traffic still passes. The prediction model of the present invention can identify abnormal trends before an attack occurs by analyzing traffic characteristics in real time, and take defensive measures in advance, such as temporarily isolating the target host, limiting bandwidth, or enabling backup servers. The specific situation is shown in the following table:
[0092]
[0093]
[0094] From the table above, we can see that the reaction time, number of successful blocking, and successful defense rate of the prediction model are significantly better than the existing technology. Therefore, by predicting potential network attacks in real time, it not only significantly improves the protection effect of the system, but also reduces the consumption of system resources, which fully reflects its practical application value and superiority in the field of network security.
[0095] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.
Claims
1. A network security testing and evaluation system, characterized in that: Including: Data acquisition module: Responsible for real-time acquisition of various data from the network environment and preprocessing the data, including traffic data, log data, user behavior data, and device status data; Prediction model module: Based on historical data and real-time data, construct a prediction model to predict potential network attacks; Response strategy generation module: According to the output of the prediction model module, automatically generate response measures, including strengthening monitoring, recording traffic logs, automatically blocking suspicious traffic, triggering alarms, adjusting firewall rules, and notifying the security team for manual intervention; Feedback and learning module: Collect feedback data after the execution of response strategies, evaluate the effectiveness of response measures, and feedback the results to the prediction model module to continuously optimize the performance of the prediction model; System management and control module: Provide a unified management and control interface for the system, including configuration management, policy management, user management, and log auditing; Security assessment report generation module: Generate a detailed security assessment report, including potential attacks discovered, system response measures, the accuracy of the prediction model, and the overall network security situation.
2. A network security testing and evaluation system according to claim 1, characterized in that: The specific prediction model is the predicted value P(t) of network attacks at time t, and the specific calculation formula of P(t) is as follows: Where Z(t) is the normalization factor; D(t, τ) represents the eigenvalue after time decay at time t.
3. A network security testing and evaluation system according to claim 2, characterized in that: The specific calculation formula of D(t, τ) is specifically as follows: D(t,τ)=e -λ(T-τ) ·S(t,τ) Where S(t, τ) represents the comprehensive eigenvalue at time t and the past state τ; λ is the decay constant; T is the maximum time range; τ is the integration variable, representing the past state of time.
4. A network security testing and evaluation system according to claim 3, characterized in that: The specific calculation formula of S(t, τ) is as follows: Where N is the number of features, indicating the number of key features used for prediction; σ i is the weight of the feature, σ i is a positive number, indicating the degree of influence of the reaction characteristics on the prediction results; f i (x(t), τ) represents the characteristic function related to network traffic; g i (y(t), τ) represents the feature function related to user behavior.
5. A network security testing and evaluation system according to claim 4, characterized in that: The f i The specific calculation formula of (x(t), τ) is as follows: where h i is the proportionality coefficient of feature i; β i is the amplification factor of this feature.
6. A network security testing and evaluation system according to claim 5, characterized in that: The g i The specific calculation formula of (y(t), τ) is as follows: g i (y(t),τ)=k i ·log(1+y(t-τ)) where k i Scaling factor for feature i.
7. A network security testing and evaluation system according to claim 6, characterized in that: P(t) represents the intensity and probability of potential network attacks at time t, and its value range specifically includes: 0 < P(t) < 0.5, low probability, the system maintains normal operation, but regular security audits and inspections are required; 0.5 < P(t) < 0.8, medium probability, the system continues to operate, but monitoring needs to be strengthened, traffic logs need to be recorded, and alarms need to be triggered to notify the staff; 0.8 < P(t) < 1, high probability, the system triggers security measures to automatically block suspicious traffic, trigger alarms, adjust firewall rules, and notify the security team for manual intervention.
8. A network security test and evaluation method, based on a network security test and evaluation system according to any one of claims 1 to 7, characterized in that: Specifically including: S1. The data acquisition module obtains data from the network in real time and transmits it to the prediction model module; S2. The prediction model module analyzes and calculates based on the collected data to predict potential network attacks; S3. According to the prediction results, the response strategy generation module immediately formulates and executes response measures; S4. The feedback and learning module collects the effects of response measures and feedbacks them to the prediction model to optimize the model performance; S5. The security assessment report generation module generates and displays a detailed security assessment report.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: The processor executes a network security test and evaluation system according to any one of claims 1-7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: A network security test and evaluation system according to any one of claims 1-7 is executed by the processor.
Citation Information
Patent Citations
Large-scale network security situation intelligent prediction method
CN112165485A
Network security operation method based on security policy
CN117081868A
Intelligent network equipment service host security management system based on deep learning
CN117424740A
Self-adjusting method of fuzzy network control system in network attack environment
CN118170010A
Network security situation assessment method based on attack and environment
CN118316667A