Enterprise-level automatic network security situation awareness system
By designing an enterprise-level automated network security situation awareness system, the problems of incomplete security data collection, insufficient situation analysis capabilities, lagging response mechanisms and unintuitive visual display in the existing technology are solved, and all-round security situation awareness and rapid decision-making of the enterprise network are realized, and network security management capabilities are improved.
Patent Information
- Application Number
- CN202411915153.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-24
- Publication Date
- 2025-05-06
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing network security protection solutions have problems such as incomplete security data collection, insufficient situation analysis capabilities, lagging response mechanisms and unintuitive visual display, which is difficult to support the comprehensive security situation awareness and rapid decision-making of enterprise networks.
An enterprise-level automated network security situation awareness system is designed, including data acquisition module, security configuration inspection module, vulnerability scanning module, situation analysis module, visual display module and early warning response module. By collecting multi-dimensional security data in real time, performing security configuration inspections, identifying system vulnerabilities, conducting situation analysis, intuitively displaying security situations and issuing early warnings in a timely manner, all-round security situation awareness of the enterprise network is achieved.
Real-time monitoring, risk assessment and situation prediction of enterprise network security status is realized, comprehensive analysis reports are generated, network security management capabilities are improved, and security operation and maintenance costs are reduced.
Smart Images

Figure CN119945726A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of network security, and in particular relates to an enterprise-level automated network security situation awareness system. Background Art
[0002] As enterprises’ digital transformation deepens, the cybersecurity situation becomes increasingly severe. Existing cybersecurity protection solutions mainly have the following problems:
[0003] 1. Incomplete safety data collection:
[0004] Traditional security systems often only focus on security data in a single dimension, lack the comprehensive collection of multi-dimensional data such as corporate assets and threat intelligence, and are unable to form a complete security situation portrait.
[0005] 2. Insufficient situation analysis capabilities:
[0006] Most systems only provide basic security detection functions and are unable to accurately assess and predict security situations.
[0007] 3. Delayed response mechanism:
[0008] The early warning mechanism is not timely enough, the response suggestions lack specificity, and it is difficult to support quick decision-making.
[0009] 4. Visual display is not intuitive:
[0010] The security situation display format is single, the data display lacks relevance, and it is difficult to support management decision-making needs. Summary of the invention
[0011] The purpose of the present invention is to provide an enterprise-level automated network security situation awareness system that can monitor, analyze and predict the security situation of the enterprise network in real time, and provide the enterprise with a full range of network security situation awareness capabilities.
[0012] The present invention provides an enterprise-level automated network security situation awareness system, comprising:
[0013] Data collection module, used to collect multi-dimensional security data in the enterprise network in real time, including network traffic data, security device logs, asset information, and threat intelligence;
[0014] A security configuration check module, used to perform security configuration checks;
[0015] Vulnerability scanning module, used to identify system vulnerabilities and assess risks;
[0016] Situation analysis module, which is used to evaluate and predict the enterprise network security situation using a multi-level analysis method;
[0017] Visual display module, used to intuitively display security situation;
[0018] The early warning response module is used to issue security warnings in a timely manner and provide response suggestions based on the preset early warning thresholds.
[0019] Furthermore, the network traffic data collection adopts a bypass deployment mode, by deploying high-performance collection probes at key network nodes to capture and analyze network traffic data in real time. The collected traffic data includes TCP / IP basic information, application layer protocol content, and session status;
[0020] The security device log collection includes: for different types of security devices, extracting and standardizing key information in the device log through corresponding data parsing plug-ins, and providing a data caching mechanism to prevent data loss during the collection process;
[0021] The asset information collection automatically identifies and collects enterprise IT asset information by combining active scanning and passive discovery; wherein the active scanning discovers active assets in the network by regularly performing network scanning tasks, and the passive discovery identifies new assets in real time by analyzing network traffic;
[0022] The threat intelligence collection obtains the latest threat information in real time by connecting to multiple threat intelligence platforms, and performs local processing and storage.
[0023] Furthermore, the security configuration checking module includes:
[0024] Configuration item collection unit, used to collect system configuration information;
[0025] A policy verification unit, used for verification according to security policies;
[0026] Baseline comparison unit, used for comparison with the security baseline;
[0027] Compliance Check Unit, used to perform compliance verification.
[0028] Furthermore, the situation analysis module is specifically used for:
[0029] Clean and standardize the collected multi-source heterogeneous data to ensure data quality;
[0030] Conduct multi-dimensional analysis on multi-dimensional security data, including: assessing the importance and vulnerability of assets from the asset dimension; analyzing the characteristics and degree of harm of attack behaviors from the threat dimension; and assessing the effectiveness of existing security measures from the protection dimension;
[0031] Based on the results of multi-dimensional analysis, a machine learning algorithm is used to train historical data to establish a mapping relationship between situation indicators and actual security conditions, and to build a security situation assessment model for security situation assessment, including risk assessment and situation scoring;
[0032] The time series analysis method is used to build a situation prediction model based on historical situation data to identify the periodic laws of situation changes and, combined with the current situation characteristics, predict the trend of situation changes in the future.
[0033] Furthermore, the risk assessment includes:
[0034] Generate a quantitative risk score for the security incident based on the probability and impact of the incident for priority sorting and decision support, including:
[0035] 1) Event data analysis: collect historical frequency of security events and estimate the probability of occurrence;
[0036] 2) Impact assessment: Set an impact score based on the potential scope and severity of the incident;
[0037] 3) Risk calculation: Multiply the probability of an event by the impact score to generate a risk score. The calculation formula is as follows:
[0038] R=P·I
[0039] Among them: R is the risk score, which is used to quantify the risk level of the event; P is the probability of the event occurring; I is the event impact score.
[0040] Furthermore, the situation score includes:
[0041] 1) Data collection:
[0042] Collect data related to assets, threats, and vulnerabilities, including asset importance scores, threat levels, and vulnerability severity scores;
[0043] 2) Weight distribution:
[0044] According to the actual needs of the enterprise, set the weight w for each dimension A ,w T ,w V ;
[0045] 3) Rating calculation:
[0046] The comprehensive score of the security posture is calculated by linear weighted summation:
[0047] S=w A ·A+w T ·T+w V ·V;
[0048] Where: S is the comprehensive security score; A is the asset importance score; T is the threat level score; V is the vulnerability severity score; w A ,w T ,w V is the weight of each dimension.
[0049] Furthermore, the time series analysis method is used to construct a situation prediction model based on historical situation data to identify the periodic laws of situation changes, and combined with the current situation characteristics, predict the situation change trend in the future period of time, including:
[0050] 1) Data preprocessing:
[0051] Collect historical security situation score data to form a time series data set:
[0052] S t |t=1,2,...,T
[0053] Among them, S t Represents the situation score data at time point t; t represents the time index, usually a continuous time step (such as day, hour or minute); T represents the overall length or total time range of the time series data. For example, if the data covers 100 days, then T = 100;
[0054] Cleaning and standardization:
[0055] Normalize the data to the same scale. The formula is as follows:
[0056]
[0057] Among them, S′ t is the standardized data; S t is the original time series data; μ is the mean of the data; σ is the standard deviation of the data;
[0058] 3) Model training: Use the ARIMA model to fit the data and extract the trend, periodicity and random components in the time series. The formula is:
[0059] S t =c+φ1S t-1 +φ2S t-2 +…+φ p S t-p +θ1∈ t-1 +θ2∈ t-2 +…+θ q ∈ t-q +∈ t
[0060] Among them: St is the current time step situation value; φ1, φ2, ..., φp are autoregressive coefficients; θ1, 02, ..., θq are moving average coefficients; ∈t is the error term; p is the autoregressive order, which indicates how many past values will have a linear impact on the current value St. For example, when p = 2, it means that S_t is composed of the past two period values S t-1 , S t-2 The linear combination of ; q is the moving average order, that is, the error term ∈t at the current time point will be affected by the random disturbance term (residual term) ∈ t-1 ,∈ t-2 , the linear influence of…;
[0061] 3) Situation prediction: Based on the training results of the ARIMA model, generate the predicted values for the next n time steps The calculation formula is as follows:
[0062]
[0063] in: is the predicted value at time step t+h (h=1, 2, ..., n); S t+h-i is the historical situation score; ∈ t+h-j is the historical error value; c, φ i ,θ j Parameters obtained from ARIMA model training.
[0064] Furthermore, the situation analysis module is also used to: identify potential complex attacks or advanced threats by analyzing the correlation between different security events, including:
[0065] 1) Data modeling: Construct an event association matrix M, where the elements M ij represents the strength of association between event i and event j;
[0066] 2) Relevance score calculation: Calculate the relevance score for each event;
[0067] 3) High-risk event identification: Events with high correlation scores are marked as potential risk points. The calculation formula is as follows:
[0068]
[0069] Where: Si is the relevance score of event i; M ij is the correlation strength between event i and event j.
[0070] Furthermore, the visual display module is specifically used for:
[0071] The overall security situation of the enterprise is displayed in real time through the situation screen, including the distribution of security events, threat level distribution, and asset status;
[0072] The risk map visually displays the geographical distribution of corporate cybersecurity risks;
[0073] Display the development context and evolution trend of security incidents in the form of a timeline;
[0074] Display the real-time status of key security indicators through various dashboards.
[0075] Furthermore, the early warning response module is specifically used for:
[0076] Set different levels of warning rules according to actual needs;
[0077] When an abnormal situation is detected, the corresponding level of warning is automatically triggered, and security warnings are issued in a timely manner through various means. At the same time, based on the built-in knowledge base, disposal suggestions are automatically generated to guide security personnel to respond and deal with them;
[0078] After the disposal is completed, the effectiveness of the response measures is automatically evaluated and relevant experience is added to the knowledge base to continuously improve the early warning response capabilities;
[0079] Track and record the early warning response process throughout to facilitate subsequent audits and reviews.
[0080] Furthermore, the system also includes a knowledge base management module, which is used for intelligent management and application of security knowledge, including:
[0081] Knowledge collection unit, which is used to automatically collect public data including threat intelligence, vulnerability information, and best practices, obtain the security experience and cases accumulated within the enterprise, and automatically extract valuable knowledge points from daily operations;
[0082] The knowledge organization unit is used to represent knowledge using ontology models, build domain ontologies including asset, threat, vulnerability, and attack concepts, define the relationships between concepts, store knowledge items according to a unified template, including basic attributes, association relationships, and application scenario information, and realize the automatic construction and maintenance of knowledge graphs;
[0083] The knowledge application unit is used for intelligent decision-making based on knowledge reasoning, including: automatically retrieving relevant knowledge items and recommending appropriate disposal plans during security incident handling; and accurately assessing potential risks based on empirical data in the knowledge base during security risk assessment.
[0084] Through the above solution, through the enterprise-level automated network security situation awareness system, through the automated detection and evaluation mechanism, the real-time monitoring, risk assessment and situation prediction of the enterprise network security status are realized, and a comprehensive analysis report is generated. The system has the characteristics of high automation, multi-dimensional situation analysis, real-time monitoring and early warning, and is particularly suitable for organizations such as enterprises and governments that need to conduct network security situation awareness, which can effectively improve network security management capabilities and reduce security operation and maintenance costs.
[0085] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention and implement it according to the contents of the specification, the following is a detailed description of the preferred embodiments of the present invention in conjunction with the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0086] Figure 1 The overall architecture diagram of the enterprise-level automated network security situation awareness system of the present invention;
[0087] Figure 2 It is a structural schematic diagram of the data acquisition module of the present invention;
[0088] Figure 3 It is a processing flow chart of the situation analysis module of the present invention;
[0089] Figure 4 It is a structural schematic diagram of the visual display module of the present invention;
[0090] Figure 5 This is a workflow diagram of the early warning response module of the present invention;
[0091] Figure 6 This is a functional structure diagram of the knowledge base management module of the present invention. DETAILED DESCRIPTION
[0092] The specific implementation of the present invention is further described in detail below in conjunction with the accompanying drawings and examples. The following examples are used to illustrate the present invention, but are not intended to limit the scope of the present invention.
[0093] This embodiment provides an enterprise-level automated network security situation awareness system. The system adopts a multi-dimensional security situation assessment method, supports multiple security standards such as SCAP, OVAL, and XCCDF, and can perform all-round security situation awareness and analysis on the enterprise network, including:
[0094] Data collection module, used to collect multi-dimensional security data in the enterprise network in real time, including network traffic data, security device logs, asset information, and threat intelligence;
[0095] A security configuration check module, used to perform security configuration checks;
[0096] Vulnerability scanning module, used to identify system vulnerabilities and assess risks;
[0097] Situation analysis module, which is used to evaluate and predict the enterprise network security situation using a multi-level analysis method;
[0098] Visual display module, used to intuitively display security situation;
[0099] The early warning response module is used to issue security warnings in a timely manner and provide response suggestions based on the preset early warning thresholds.
[0100] The present invention is described in further detail below.
[0101] 1. System overall architecture
[0102] The situation awareness system of the present invention adopts a modular design architecture, and realizes comprehensive awareness of the enterprise network security situation through the organic combination of multiple functional modules. The system mainly includes a data acquisition module, a security configuration check module, a vulnerability scanning module, a situation analysis module, a visualization display module and an early warning response module. The modules exchange and share data through a unified data bus to ensure that the various components of the system can work together. At the same time, the system adopts a distributed architecture design, supports horizontal expansion, and can be flexibly deployed according to the scale and needs of the enterprise.
[0103] Ginseng Figure 1 As shown, in a specific implementation, the enterprise-level automated network security situation awareness system adopts a layered architecture design, which includes a data layer, an analysis layer, an application layer, and a display layer from the bottom to the top. The data layer is provided with a distributed data acquisition node 101, a data preprocessing unit 102, and a distributed storage cluster 103; the analysis layer is provided with a security detection engine 105, a situation analysis engine 104, and a prediction analysis engine 106; the application layer is provided with an API gateway and an application service 108; and the display layer is provided with a situation screen 109 and a Web console 110. After the multi-dimensional security data is collected, preprocessed, and distributedly stored by the distributed data acquisition node 101, the data preprocessing unit 102, and the distributed storage cluster 103, it is input into the security detection engine 105, the situation analysis engine 104, and the prediction analysis engine 106 for analysis, and the analysis results are sent to the situation screen 109 and the Web console 110 after being sent through the API gateway 107 and the application service 108.
[0104] The specific deployment architecture of the system includes the following parts:
[0105] The data layer deploys distributed data collection nodes, each node is equipped with a high-performance server, and uses a 10Gbps network card to achieve large-scale data collection. The data collection node transmits the collected data to the central node through a dedicated secure channel. The central node uses a distributed storage cluster and uses Elasticsearch to store and retrieve data, ensuring high performance and scalability of data processing.
[0106] The analysis layer adopts a microservice architecture, splitting the situation analysis function into multiple independent service modules, including data preprocessing service, security detection service, situation assessment service, prediction analysis service, etc. These services communicate asynchronously through message queues and are deployed using Docker container technology to ensure the independence and maintainability of the services.
[0107] The application layer provides a unified API gateway to achieve unified management and access control of external service interfaces. The API gateway supports both REST and WebSocket protocols to meet data access requirements in different scenarios. At the same time, the application layer also includes basic service components such as user authentication, permission management, and audit logs.
[0108] The display layer adopts B / S architecture, and the front end is developed using the Vue.js framework to implement responsive layout design and support PC and mobile access.
[0109] 2. Data acquisition module
[0110] The data collection module implements all-round collection of enterprise network security data by deploying a multi-level data collection mechanism. The data collection module adopts a plug-in design and supports flexible expansion of different types of data collectors.
[0111] In terms of network traffic collection, a bypass deployment method is adopted to deploy high-performance collection probes at key network nodes (mirror ports of core switches) to capture and analyze network traffic data in real time. The probe uses DPDK technology to achieve zero-copy collection of network data packets, and adopts a multi-threaded concurrent processing mechanism to achieve real-time collection and analysis of large traffic data. The collected traffic data includes TCP / IP basic information, application layer protocol content, session status, etc.
[0112] In terms of log collection, the system supports docking with firewalls, intrusion detection systems, antivirus systems and other security devices, and collects and uniformly manages various security logs. Log collection supports multiple methods, including Syslog, SNMP, API interface, etc. For different types of security devices, the system implements corresponding data parsing plug-ins, which can accurately extract and standardize key information in device logs. The system supports two modes: real-time log collection and historical log import, and provides a data cache mechanism to prevent data loss during the collection process.
[0113] In terms of asset information collection, the system automatically identifies and collects enterprise IT asset information, including servers, network devices, terminals, etc., through a combination of active scanning and passive discovery. Active scanning discovers active assets in the network by performing network scanning tasks regularly; passive discovery identifies new assets in real time by analyzing network traffic. For discovered assets, the system automatically collects detailed information such as their basic information, operating status, and installed software.
[0114] In terms of threat intelligence collection, the system can connect to multiple threat intelligence platforms to obtain the latest threat information in real time, and perform local processing and storage.
[0115] Ginseng Figure 2 As shown, in a specific implementation, the data collection unit includes a network traffic collection unit 201, a log collection unit 202, an asset information collection unit 203, and a threat intelligence collection unit 204, which are respectively used for network data, log data, asset data, and intelligence data; the network traffic collection unit 201, the log collection unit 202, the asset information collection unit 203, and the threat intelligence collection unit 204 are connected to the central data processing unit 206 through a data bus 205, and the central data processing unit 206 is used to execute the data processing flow: the collected network data, log data, asset data, and intelligence data are sequentially subjected to data collection 207, data analysis 208, data standardization 209, and data storage processes.
[0116] 3. Security configuration check module
[0117] The security configuration check module includes: a configuration item collection unit for collecting system configuration information; a policy verification unit for verifying according to the security policy; a baseline comparison unit for comparing with the security baseline; and a compliance check unit for performing compliance verification.
[0118] The security configuration check module adopts a distributed check mechanism, and realizes automated check of system security configuration by deploying a lightweight agent program on the checked system. The module first automatically collects system configuration information through the agent program, including operating system configuration, application software configuration, security policy configuration, etc.; then, according to the pre-defined security policy rules, the collected configuration information is verified for compliance, and configuration items that do not meet the requirements are identified; at the same time, the system will regularly compare and analyze with the latest security baseline to timely discover configuration deviations; finally, the problems found are classified and summarized to generate a detailed configuration check report. The module also supports custom inspection rules, and can flexibly adjust the inspection strategy according to the specific needs of the enterprise.
[0119] 4. Situation Analysis Module
[0120] The situation analysis module adopts a multi-level analysis method to achieve accurate assessment and prediction of the enterprise's network security situation.
[0121] The situation analysis module is specifically used for:
[0122] 1) Data preprocessing: Clean and standardize the collected multi-source heterogeneous data to ensure data quality. By designing a unified data model, data from different sources are converted into a standard format. Data preprocessing also includes data deduplication, completion, error correction and other operations to ensure data quality for subsequent analysis.
[0123] 2) Multi-dimensional analysis stage: Multi-dimensional analysis of multi-dimensional security data, including: assessing the importance and vulnerability of assets from the asset dimension; analyzing the characteristics and degree of harm of attack behaviors from the threat dimension; and assessing the effectiveness of existing security measures from the protection dimension. Multi-dimensional analysis uses a weighted scoring model, and the weights of different dimensions can be dynamically adjusted according to enterprise needs.
[0124] 3) Situation assessment stage: Based on the results of multi-dimensional analysis, a machine learning algorithm is used to train historical data to establish a mapping relationship between situation indicators and actual security conditions, and a security situation assessment model is constructed for security situation assessment, including risk assessment and situation scoring.
[0125] 4) Trend prediction stage: Using time series analysis methods, a situation prediction model is constructed based on historical situation data to identify the periodic laws of situation changes, and combined with the current situation characteristics, predict the trend of situation changes in the future.
[0126] Specifically, the risk assessment includes:
[0127] Generate a quantitative risk score for the security incident based on the probability and impact of the incident for priority sorting and decision support, including:
[0128] 1) Event data analysis: collect historical frequency of security events and estimate the probability of occurrence;
[0129] 2) Impact assessment: Set an impact score based on the potential scope and severity of the incident;
[0130] 3) Risk calculation: Multiply the probability of an event by the impact score to generate a risk score. The calculation formula is as follows:
[0131] R=P·I
[0132] Among them: R is the risk score, which is used to quantify the risk level of the event; P is the probability of the event occurring; I is the event impact score.
[0133] Specifically, the system generates a security situation score for the enterprise network from multiple dimensions by comprehensively evaluating the importance of assets, threat level, and vulnerability severity. The specific process includes:
[0134] 1) Data collection:
[0135] Collect data related to assets, threats, and vulnerabilities, including asset importance scores, threat levels, and vulnerability severity scores;
[0136] 2) Weight distribution:
[0137] According to the actual needs of the enterprise, set the weight w for each dimension A ,w T ,w V ;
[0138] 3) Rating calculation:
[0139] The comprehensive score of the security posture is calculated by linear weighted summation:
[0140] S=w A ·A+w T ·T+w V ·V;
[0141] Where: S is the comprehensive security score; A is the asset importance score; T is the threat level score; V is the vulnerability severity score; w A ,w T ,w V is the weight of each dimension.
[0142] Specifically, the system builds a situation prediction model, uses historical security situation data, and combines it with the machine learning algorithm ARIMA to predict future network security situation trends. The specific process includes:
[0143] 1) Data preprocessing:
[0144] Collect historical security situation score data to form a time series data set:
[0145] S t |t=1,2,...,T;
[0146] Among them, S t represents the situation score data at time point t; t represents the time index, usually a continuous time step (such as day, hour or minute); T represents the overall length or total time range of the time series data. For example, if the data covers 100 days, then T = 100.
[0147] Clean and standardize the data to the same scale. The formula is as follows:
[0148]
[0149] Among them, S′ t is the standardized data; S t is the original time series data; μ is the mean of the data; σ is the standard deviation of the data.
[0150] 4) Model training: Use the ARIMA model to fit the data and extract the trend, periodicity and random components in the time series. The formula is:
[0151] S t =c+φ1S t-1 +φ2S t-2 +…+φ p S t-p +θ1∈ t-1 +θ2∈ t-2 +…+θ q ∈ t-q +∈ t
[0152] Among them: St is the current time step situation value; φ1, φ2, ..., φp are autoregressive coefficients; θ1, θ2, ..., θq are moving average coefficients; ∈t is the error term; p is the autoregressive order, which indicates how many past values will have a linear impact on the current value St. For example, when p = 2), it means that S_t is composed of the past two period values S t-1 , S t-2 The linear combination of ; q is the moving average order, that is, the error term ∈t at the current time point will be affected by the random disturbance term (residual term) ∈ t-1 ,∈ t-2 , the linear influence of …
[0153] 3) Situation prediction: Based on the training results of the ARIMA model, generate the predicted values for the next n time steps The calculation formula is as follows:
[0154]
[0155] in: is the predicted value at time step t+h (h=1, 2, ..., n); S t+h-i is the historical situation score; ∈ t+h-j is the historical error value; c, φ i ,θ j Parameters obtained from ARIMA model training.
[0156] Furthermore, the situation analysis module is also used to: identify potential complex attacks or advanced threats by analyzing the correlation between different security events, including:
[0157] 1) Data modeling: Construct an event association matrix M, where the elements M ij represents the strength of association between event i and event j;
[0158] 2) Relevance score calculation: Calculate the relevance score for each event;
[0159] 3) High-risk event identification: Events with high correlation scores are marked as potential risk points. The calculation formula is as follows:
[0160]
[0161] Where: Si is the relevance score of event i; M ij is the correlation strength between event i and event j.
[0162] Through powerful correlation analysis capabilities, the system can automatically discover the correlation between different security events and identify potential security threats.
[0163] Ginseng Figure 3 As shown, in a specific implementation, the processing flow of the situation analysis module includes a data preprocessing stage 301, a multidimensional analysis stage 302, a situation assessment stage 303, and a trend prediction stage 304, wherein the preprocessing stage 301 includes a data cleaning node 305 and a feature extraction node 306, the multidimensional analysis stage 302 includes threat intelligence analysis, network behavior analysis, and asset vulnerability analysis, and the situation assessment stage 303 is sent to the prediction module of the trend prediction stage 304 after passing through a model training node 307, risk assessment, and situation scoring, and the prediction result is output through a result output node 308.
[0164] 5. Visual display module
[0165] The visualization display module uses modern visualization technology to provide users with an intuitive and interactive security situation display interface. This module supports multiple display methods: real-time display of the overall security situation of the enterprise through the situation screen, including security event distribution, threat level distribution, asset status, etc.; intuitive display of the geographical distribution of enterprise network security risks through risk maps; display of the development context and evolution trend of security events in the form of a timeline; and display of the real-time status of key security indicators through various dashboards. This module adopts a responsive design, supports viewing on different terminal devices, and provides rich interactive operation functions to facilitate users to drill and analyze data.
[0166] Ginseng Figure 4 As shown, in a specific implementation, the visual display module adopts a layered design architecture.
[0167] At the data access layer, the system implements a real-time data push mechanism. WebSocket technology is used to establish a long connection between the client and the server. The server actively pushes update information when the data changes to ensure the real-time display of data. For the query of a large amount of historical data, the system implements a data shard loading mechanism to avoid loading too much data at one time, which may cause the front-end performance to deteriorate.
[0168] In the visualization rendering layer, the system integrates a variety of open source visualization libraries, including ECharts, D3.js, etc. The situation screen adopts component-based design, splitting the complex display interface into multiple reusable visualization components. Each component supports custom configuration, including display style, update frequency, interaction mode, etc. The system also implements an adaptive layout algorithm that can automatically adjust the display effect according to the resolution of the display device.
[0169] At the interactive control layer, the system implements a wealth of interactive functions. It supports data drilling, where users can drill down from the overview data layer by layer to specific details; it supports multi-dimensional screening, where data can be flexibly filtered based on dimensions such as time, assets, and threats; it supports chart linkage, where operations in one view will automatically trigger updates to related views. The system also provides visual template management, where users can save and load custom display configurations.
[0170] 6. Early warning response module
[0171] The early warning response module provides an intelligent early warning generation and response management mechanism. The module supports flexible early warning rule configuration, and administrators can set early warning rules of different levels according to actual needs; when the system detects an abnormal situation, it will automatically trigger an early warning of the corresponding level and push it through various methods such as email, SMS, and system notifications; at the same time, the system will automatically generate disposal suggestions based on the built-in knowledge base to guide security personnel to respond and dispose; after the disposal is completed, the system will automatically evaluate the effectiveness of the response measures and add relevant experience to the knowledge base to continuously improve the early warning response capabilities. The module also supports full tracking and recording of the early warning response process, which is convenient for subsequent audits and replays.
[0172] Warning threshold setting: define the upper and lower limits of key safety indicators. When the indicators exceed the threshold, the system automatically generates a warning. Specifically include:
[0173] 1) Threshold configuration: Set the normal range [L,U] for each security indicator.
[0174] 2) Real-time detection: Through streaming analysis, detect whether the current indicator value X is out of range.
[0175] 3) Warning trigger: When the indicator value exceeds the range, a warning is triggered, and relevant data is attached. The formula is as follows:
[0176]
[0177] Where: X is the current safety index value; L and U are the upper and lower limits of the warning threshold.
[0178] Ginseng Figure 5 As shown, in a specific implementation, the process of the early warning response module includes early warning rule configuration 501, early warning generation processing 502, early warning notification 503, and response processing 504. The early warning response module implements complete early warning life cycle management. Specifically, it includes the following implementation processes:
[0179] In terms of warning rule configuration, the system provides a visual rule editor. Users can combine multiple conditions by dragging and dropping to set warning trigger thresholds and levels. The rules support a variety of operators and functions to implement complex judgment logic. The system also has a built-in machine learning algorithm that can automatically recommend appropriate warning thresholds based on historical data.
[0180] In terms of warning generation and processing, the system implements a real-time warning detection engine. The detection engine uses a streaming processing architecture to continuously analyze real-time data. When a situation that meets the warning rules is detected, the system automatically generates a warning event and determines the warning level. For repeated warnings of the same type, the system implements an intelligent merging mechanism to avoid the flooding of warning information.
[0181] In terms of sending warning notifications, the system implements a multi-channel notification mechanism. It supports multiple notification methods such as email, SMS, and corporate WeChat. Users can configure different notification strategies for different levels of warnings. The system also implements a warning upgrade mechanism. When a low-level warning is not handled in a timely manner, it will automatically upgrade to a high-level warning and notify the relevant person in charge.
[0182] In terms of response and disposal, the system provides a standardized disposal process. Based on the accumulated disposal experience in the knowledge base, the system can automatically generate disposal suggestions. The disposal process supports tasks assignment, progress tracking, result confirmation and other functions. The system also implements a response effect evaluation mechanism, which evaluates the effectiveness of response measures by analyzing the changes in safety indicators before and after disposal.
[0183] 7. Knowledge base management module
[0184] Ginseng Figure 6 As shown, in a specific implementation, the knowledge base management module includes a knowledge acquisition unit 601, a knowledge organization unit 602, and a knowledge application unit 603. The knowledge base management module implements intelligent management and application of security knowledge.
[0185] In terms of knowledge collection, the system supports access to multiple knowledge sources. It can automatically collect public data such as threat intelligence, vulnerability information, and best practices; it supports the import of security experience and cases accumulated within the enterprise; and it can automatically extract valuable knowledge points from daily operations. The system implements an automatic knowledge extraction algorithm that can identify key information from unstructured text.
[0186] In terms of knowledge organization, the system uses an ontology model for knowledge representation. It builds domain ontology including concepts such as assets, threats, vulnerabilities, and attacks, and defines the relationships between concepts. Knowledge items are stored according to a unified template, including basic attributes, associations, application scenarios, and other information. The system also implements the automatic construction and maintenance of knowledge graphs.
[0187] In terms of knowledge application, the system implements intelligent auxiliary decision-making based on knowledge reasoning. In the process of handling security incidents, the system can automatically retrieve relevant knowledge items and recommend appropriate handling plans. When assessing security risks, the system can accurately assess potential risks based on the empirical data in the knowledge base. The system also supports knowledge sharing and collaboration, and security personnel from different departments can jointly maintain and use the knowledge base.
[0188] The present invention realizes real-time monitoring, risk assessment and situation prediction of enterprise network security status through an automated detection and evaluation mechanism, and generates a comprehensive analysis report. The system has the characteristics of high automation, multi-dimensional situation analysis, real-time monitoring and early warning, and is particularly suitable for organizations such as enterprises and governments that need to conduct network security situation awareness, and can effectively improve network security management capabilities and reduce security operation and maintenance costs.
[0189] It has the following advantages:
[0190] 1. Comprehensive data collection capabilities: support multi-dimensional data collection; ensure the real-time and integrity of data; provide sufficient data support for situation analysis.
[0191] 2. Accurate situation analysis capabilities: using advanced analysis algorithms; supporting multi-dimensional situation assessment; and having situation prediction capabilities.
[0192] 3. Intuitive visual display: multiple visual display methods; support interactive operations; easy for decision makers to understand and use.
[0193] 4. Efficient early warning response mechanism: timely and accurate early warning; intelligent response suggestions; closed-loop response management.
[0194] 5. Good scalability: supports docking with other security systems; has secondary development interface; can be flexibly expanded according to needs.
[0195] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. It should be pointed out that a person skilled in the art can make several improvements and modifications without departing from the technical principles of the present invention, and these improvements and modifications should also be regarded as within the scope of protection of the present invention.
Claims
1. An enterprise-level automated network security situation awareness system, characterized in that: include: Data collection module, used to collect multi-dimensional security data in the enterprise network in real time, including network traffic data, security device logs, asset information, and threat intelligence; A security configuration check module, used to perform security configuration checks; Vulnerability scanning module, used to identify system vulnerabilities and assess risks; Situation analysis module, which is used to evaluate and predict the enterprise network security situation using a multi-level analysis method; Visual display module, used to intuitively display security situation; The early warning response module is used to issue security warnings in a timely manner and provide response suggestions based on the preset early warning thresholds.
2. The enterprise-level automated network security situation awareness system according to claim 1, characterized in that: The network traffic data collection adopts a bypass deployment mode, by deploying high-performance collection probes at key network nodes to capture and analyze network traffic data in real time. The collected traffic data includes TCP / IP basic information, application layer protocol content, and session status; The security device log collection includes: for different types of security devices, extracting and standardizing key information in the device log through corresponding data parsing plug-ins, and providing a data caching mechanism to prevent data loss during the collection process; The asset information collection automatically identifies and collects enterprise IT asset information by combining active scanning and passive discovery; wherein the active scanning discovers active assets in the network by regularly performing network scanning tasks, and the passive discovery identifies new assets in real time by analyzing network traffic; The threat intelligence collection obtains the latest threat information in real time by connecting to multiple threat intelligence platforms, and performs local processing and storage.
3. The enterprise-level automated network security situation awareness system according to claim 1, characterized in that: The security configuration checking module comprises: Configuration item collection unit, used to collect system configuration information; A policy verification unit, used for verification according to security policies; Baseline comparison unit, used for comparison with the security baseline; Compliance Check Unit, used to perform compliance verification.
4. The enterprise-level automated network security situation awareness system according to claim 1, characterized in that: The situation analysis module is specifically used for: Clean and standardize the collected multi-source heterogeneous data to ensure data quality; Conduct multi-dimensional analysis on multi-dimensional security data, including: assessing the importance and vulnerability of assets from the asset dimension; analyzing the characteristics and degree of harm of attack behaviors from the threat dimension; and assessing the effectiveness of existing security measures from the protection dimension; Based on the results of multi-dimensional analysis, a machine learning algorithm is used to train historical data to establish a mapping relationship between situation indicators and actual security conditions, and to build a security situation assessment model for security situation assessment, including risk assessment and situation scoring; The time series analysis method is used to build a situation prediction model based on historical situation data to identify the periodic laws of situation changes and, combined with the current situation characteristics, predict the trend of situation changes in the future.
5. The enterprise-level automated network security situation awareness system according to claim 4, characterized in that: The risk assessment includes: Generate a quantitative risk score for the security incident based on the probability and impact of the incident for priority sorting and decision support, including: 1) Event data analysis: collect historical frequency of security events and estimate the probability of occurrence; 2) Impact assessment: Set an impact score based on the potential scope and severity of the incident; 3) Risk calculation: Multiply the probability of an event by the impact score to generate a risk score. The calculation formula is as follows: R=P·I Among them: R is the risk score, which is used to quantify the risk level of the event; P is the probability of the event; I is the event impact score; The situation score includes: 1) Data collection: Collect data related to assets, threats, and vulnerabilities, including asset importance scores, threat levels, and vulnerability severity scores; 2) Weight distribution: According to the actual needs of the enterprise, set the weight w for each dimension A , w T , w V ; 3) Rating calculation: The comprehensive score of the security posture is calculated by linear weighted summation: S=ω A ·A+ω T ·T+ω V ·V; Where: S is the comprehensive security score; A is the asset importance score; T is the threat level score; V is the vulnerability severity score; w A , w T , w V is the weight of each dimension.
6. The enterprise-level automated network security situation awareness system according to claim 5, characterized in that: The time series analysis method is used to construct a situation prediction model based on historical situation data to identify the periodic law of situation changes and predict the situation change trend in the future period in combination with the current situation characteristics, including: 1) Data preprocessing: Collect historical security situation score data to form a time series data set: S t |t=1,2,...,T; Among them, S t Represents the situation score data at time point t; t represents the time index, which is a continuous time step; T represents the overall length or total time range of the time series data; Cleaning and standardization: Normalize the data to the same scale, the formula is as follows: Among them, S′ t is the standardized data; S t is the original time series data; μ is the mean of the data; σ is the standard deviation of the data; 2) Model training: Use the ARIMA model to fit the data and extract the trend, periodicity and random components in the time series. The formula is: S t =c+φ1S t-1 +φ2S t-2 +…+φ p S t-p +θ1∈ t-1 +θ2∈ t-2 +…+θ q ∈ t-q +∈ t Where: St is the state value of the current time step; φ1, φ2,…, φp are autoregressive coefficients; θ1,θ2,…,θq are moving average coefficients; ∈t is the error term; p is the autoregressive order, which indicates how many past values will have a linear impact on the current value St; q is the moving average order, that is, the error term ∈t at the current time point will be affected by the random disturbance term ∈ t-1 ,∈ t-2 , the linear influence of ...; 3) Situation prediction: Based on the training results of the ARIMA model, generate the predicted values for the next n time steps The calculation formula is as follows: in: is the predicted value at time step t+h (h=1, 2, ..., n); S t+h-i is the historical situation score; ∈ t+h-j is the historical error value; c, φ i ,θ j Parameters obtained from ARIMA model training.
7. The enterprise-level automated network security situation awareness system according to claim 6, characterized in that: The situation analysis module is also used to identify potential complex attacks or advanced threats by analyzing the correlation between different security events, including: 1) Data modeling: Construct an event association matrix M, where the elements M ij represents the strength of association between event i and event j; 2) Relevance score calculation: Calculate the relevance score for each event; 3) High-risk event identification: Events with high correlation scores are marked as potential risk points. The calculation formula is as follows: Where: Si is the relevance score of event i; M ij is the correlation strength between event i and event j.
8. The enterprise-level automated network security situation awareness system according to claim 1, characterized in that: The visual display module is specifically used for: The overall security situation of the enterprise is displayed in real time through the situation screen, including the distribution of security events, threat level distribution, and asset status; The risk map visually displays the geographical distribution of corporate cybersecurity risks; Display the development context and evolution trend of security incidents in the form of a timeline; Display the real-time status of key security indicators through various dashboards.
9. The enterprise-level automated network security situation awareness system according to claim 1, characterized in that: The early warning response module is specifically used for: Set different levels of warning rules according to actual needs; When an abnormal situation is detected, the corresponding level of warning is automatically triggered, and security warnings are issued in a timely manner through various means. At the same time, based on the built-in knowledge base, disposal suggestions are automatically generated to guide security personnel to respond and deal with them; After the disposal is completed, the effectiveness of the response measures is automatically evaluated and relevant experience is added to the knowledge base to continuously improve the early warning response capabilities; Track and record the early warning response process throughout to facilitate subsequent audits and reviews.
10. The enterprise-level automated network security situation awareness system according to claim 1, characterized in that: It also includes a knowledge base management module, which is used for intelligent management and application of security knowledge, including: Knowledge collection unit, which is used to automatically collect public data including threat intelligence, vulnerability information, and best practices, obtain the security experience and cases accumulated within the enterprise, and automatically extract valuable knowledge points from daily operations; The knowledge organization unit is used to represent knowledge using ontology models, build domain ontologies including asset, threat, vulnerability, and attack concepts, define the relationships between concepts, store knowledge items according to a unified template, including basic attributes, association relationships, and application scenario information, and realize the automatic construction and maintenance of knowledge graphs; The knowledge application unit is used for intelligent decision-making based on knowledge reasoning, including: automatically retrieving relevant knowledge items and recommending appropriate disposal plans during security incident handling; and accurately assessing potential risks based on empirical data in the knowledge base during security risk assessment.
Citation Information
Patent Citations
Method and system for evaluating network safety situation
CN101436967A
Method and system for managing security baseline
CN108833358A
Substation network security situation awareness method and system
CN109067596A
Power grid host dynamic threshold setting method based on FARIMA-LSTM prediction
CN113435725A
Civil aviation air traffic control network security detection early warning platform
CN113486351A
Cited By
Network security detection system based on data visualization
CN120128432A
Comprehensive data asset value evaluation device
CN120198168A
Communication network security situation prediction method and system based on big data
CN120223439A
Multi-dimensional assessment method for credential environment migration
CN120523724A
Panoramic multi-dimensional monitoring visual management method
CN120547087A