Network security situation awareness method, system and device and medium
By obtaining unified information standards and basic architecture information under the capability open architecture, generating security databases and supervising training situational awareness modules, the problem of incomplete network security perception and inability to effectively prevent and control network risks is solved, and comprehensive perception and precise prevention and control of the target network are achieved.
Patent Information
- Application Number
- CN202510104789.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-01-22
Smart Images

Figure CN119945781A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a network security situation awareness method, system, device and medium. Background Art
[0002] With the rapid development and widespread application of communication technology, taking 5G network as an example, while it brings people advantages such as high speed, low latency and large capacity, it also faces increasingly severe security challenges. Under the capability exposure architecture, the openness and complexity of the network are further increased, making network security issues more complex and diverse. On the one hand, the network connects a large number of devices and users, including IoT devices, smart terminals, etc. The security of these devices is uneven and they are easy to become a breakthrough for network attacks. On the other hand, capability exposure allows different service providers and developers to access the network, increasing the attack surface of the network. At the same time, the network integrates a variety of emerging technologies, such as software-defined networking and network function virtualization, and the introduction of these technologies also brings new security risks.
[0003] However, under the capability open architecture, existing technologies have problems with incomplete network security perception and are unable to effectively prevent and control network risks. Summary of the invention
[0004] The technical problem to be solved by the present invention is to provide a network security situation awareness method, system, device and medium in response to the above-mentioned deficiencies in the prior art, so as to solve the problem that the prior art has incomplete network security perception and cannot effectively prevent and control network risks.
[0005] In a first aspect, the present invention provides a network security situation awareness method, the method
[0006] The law includes:
[0007] Obtain unified information standards and basic architecture information of the target network capability exposure architecture;
[0008] Based on the basic information of the architecture, network element functions are decoupled to mine network security elements based on network security events and generate a security database;
[0009] Based on the security database and the unified information standard, supervise the training of the situational awareness module;
[0010] Interact with network data streams, filter out risky data and locate risky data streams;
[0011] Input the risk data stream into the situation awareness module, perform risk control analysis and diffusion prediction by analyzing the attack intention, and obtain situation awareness results;
[0012] Based on the situation awareness results, the corresponding risk control strategy is determined, and terminal visualization and network security prevention and control management are performed.
[0013] Furthermore, according to the basic information of the architecture, by decoupling the network element functions, mining the network security elements based on the network security events, and generating a security database, specifically includes:
[0014] Determine multiple network element functions of the target network according to the basic architecture information, and take each network element function as the first network element function in turn, and perform the following steps for each first network element function: determine a first network security event set of the first network element function, traverse the first network security event set according to a preset decoupling and splitting standard, analyze each network security event, extract a first network security element related to the target network security, and integrate the extracted first network security elements to obtain a first security database;
[0015] The final security database is obtained according to all the first security databases.
[0016] Furthermore, before traversing the first network security event set according to the preset decoupling and splitting standard, the method further includes:
[0017] Determining the decoupling and splitting standard, wherein the decoupling and splitting standard includes a primary decoupling based on the cross-link system configuration and a secondary decoupling based on the entire link of the system;
[0018] The step of integrating the extracted first network security elements to obtain a first security database specifically includes:
[0019] Performing data classification, merging, and correlation analysis on the extracted first network security elements;
[0020] Determine the element sequence based on the results of the association analysis, where each element sequence corresponds to a different stage of the entire security cycle;
[0021] Traversing the element sequence, determining the corresponding attack intention and attack penetration level and establishing a mapping, and obtaining a mapping relationship between the attack intention and the attack penetration level of each element sequence;
[0022] All the element sequences and the mapping relationship between the attack intention of each element sequence and the attack penetration level are integrated to obtain the first security database.
[0023] Furthermore, the supervision and training of the situation awareness module based on the security database and the unified information standard specifically includes:
[0024] Acquire data related to network security from the security database, and pre-process the acquired data according to the unified information standard;
[0025] Performing attack intention, attack penetration level, and multi-dimensional analysis on the pre-processed data to obtain a training data set; wherein the attack penetration level is determined based on at least the attack path, attack type, and attack target;
[0026] The situation awareness module is trained using the training data set.
[0027] Furthermore, the risk data stream is input into the situation awareness module, and risk control analysis and diffusion prediction are performed by analyzing the attack intention to obtain the situation awareness result, which specifically includes:
[0028] The risk data stream is input into the situation awareness module, and the following steps are performed through the situation awareness module: determine the target analysis granularity corresponding to the risk data stream, perform attack intent analysis and risk control analysis on the risk data stream according to the target analysis granularity, and perform diffusion prediction, and obtain the situation awareness result by combining the results of the risk control analysis and diffusion prediction.
[0029] Furthermore, the determining of the target analysis granularity corresponding to the risk data flow specifically includes:
[0030] Identify the data flow type of the risky data flow;
[0031] According to the preset multi-level analysis granularity, the target analysis granularity corresponding to the data stream type is determined.
[0032] Furthermore, the method further comprises at least one of the following:
[0033] Screening out deceptive network security data from the security database, determining a perception condition based on the deceptive network security data, and performing branch incremental learning on the situation awareness module based on the perception condition;
[0034] Acquire security management data of a predetermined time zone, evaluate the perception capability of the situation awareness module according to the security management data, and if the perception capability does not meet the threshold standard, optimize the situation awareness module based on the passive prevention and control data;
[0035] The architecture pattern defects of the capability exposure architecture are determined according to the security management data, and the architecture of the capability exposure architecture is solidified based on the architecture pattern defects.
[0036] In a second aspect, the present invention provides a network security situation awareness system, comprising:
[0037] A capability exposure architecture information acquisition module is used to obtain the unified information standards and architecture basic information of the target network capability exposure architecture;
[0038] A security database generation module, connected to the capability open architecture information acquisition module, is used to mine network security elements based on network security events and generate a security database according to the basic architecture information through network element function decoupling;
[0039] A situation awareness training module, connected to the security database generation module, for supervising and training a situation awareness module based on the security database and the unified information standard;
[0040] A risk data flow positioning module, connected to the situation awareness training module, is used to interact with the network data flow, filter out risk data and locate the risk data flow;
[0041] A situation awareness result determination module, connected to the risk data flow positioning module, is used to input the risk data flow into the situation awareness module, perform risk control analysis and diffusion prediction by analyzing the attack intention, and obtain a situation awareness result;
[0042] The prevention and control management module is connected to the situation awareness result determination module, and is used to determine the corresponding risk control strategy based on the situation awareness result, and perform terminal visualization and network security prevention and control management.
[0043] In a third aspect, the present invention provides a network security situation awareness device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to implement the network security situation awareness method described in the first aspect.
[0044] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the network security situation awareness method described in the first aspect is implemented.
[0045] The network security situation awareness method, system, device and medium provided by the present invention. First, the unified information standard and basic architecture information of the target network capability open architecture are obtained; and according to the basic architecture information, the network element function is decoupled to mine the network security elements based on the network security event, and a security database is generated; then, based on the security database and the unified information standard, the situation awareness module is supervised and trained; and the risk data stream is interacted with to screen out the risk data and locate the risk data stream; then the risk data stream is input into the situation awareness module, and the risk control analysis and diffusion prediction are performed by parsing the attack intention to obtain the situation awareness result; finally, the corresponding risk control strategy is determined based on the situation awareness result, and terminal visualization and network security prevention and control management are performed. The present invention can obtain the situation awareness result by constructing a security database, supervising the training of the situation awareness module, and using the module to parse the attack intention in the risk data stream, and performing risk control analysis and diffusion prediction. Then, based on these situation awareness results, the corresponding risk control strategy is further determined, so as to achieve the technical effect of comprehensive perception of the target network security, accurate analysis and effective prevention and control. The problem that the network security perception is not comprehensive and the network risk cannot be effectively prevented and controlled in the prior art is solved. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] Figure 1 This is a flow chart of a network security situation awareness method according to Embodiment 1 of the present invention;
[0047] Figure 2 This is a schematic diagram of the structure of a network security situation awareness system according to Embodiment 2 of the present invention;
[0048] Figure 3 This is a structural diagram of a network security situation awareness device according to embodiment 3 of the present invention. DETAILED DESCRIPTION
[0049] In order to enable those skilled in the art to better understand the technical solution of the present invention, the embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.
[0050] It should be understood that the specific embodiments and drawings described herein are only used to explain the present invention rather than to limit the present invention.
[0051] It can be understood that, in the absence of conflict, the various embodiments of the present invention and the various features in the embodiments can be combined with each other.
[0052] It can be understood that, for the convenience of description, the drawings of the present invention only show the parts related to the present invention, while the parts irrelevant to the present invention are not shown in the drawings.
[0053] It can be understood that each unit and module involved in the embodiments of the present invention may correspond to only one physical structure, or may be composed of multiple physical structures, or multiple units and modules may be integrated into one physical structure.
[0054] It can be understood that the terms "first", "second", etc. in the embodiments of the present invention are used to distinguish different objects, or to distinguish different processing of the same object, rather than to describe a specific order of objects.
[0055] It can be understood that, without conflict, the functions and steps marked in the flowcharts and block diagrams of the present invention may occur in an order different from that marked in the drawings.
[0056] It is understood that the flowcharts and block diagrams of the present invention illustrate the possible architectures, functions, and operations of the systems, devices, equipment, and methods according to the various embodiments of the present invention. Each box in the flowchart or block diagram may represent a unit, module, program segment, or code, which contains executable instructions for implementing the specified functions. Moreover, each box or combination of boxes in the block diagram and flowchart may be implemented by a hardware-based system that implements the specified functions, or may be implemented by a combination of hardware and computer instructions.
[0057] It can be understood that the units and modules involved in the embodiments of the present invention can be implemented by software or hardware. For example, the units and modules can be located in a processor.
[0058] Embodiment 1:
[0059] This embodiment provides a network security situation awareness method, such as Figure 1 As shown, the method includes:
[0060] Step S101: Obtain unified information standards and basic architecture information of the target network capability exposure architecture.
[0061] In this embodiment, the target network can be any network with a capability open architecture, including but not limited to 5G networks. Unified information standards can be subdivided into two categories: same-field standards and cross-field standards. Same-field standards refer to standards that are common in a specific field. They help ensure information consistency and interoperability in that field. Cross-field standards are established to break down information barriers between different fields. They can promote information flow and sharing between different fields, so that each field can work better together. The capability open architecture is equivalent to a shared platform. The basic architecture information includes some configuration information of the platform architecture, such as basic information such as functional blocks, interface types, and components.
[0062] Step S102: Based on the basic architecture information, network security elements based on network security events are mined through network element function decoupling to generate a security database.
[0063] In this embodiment, since the target network is usually heterogeneous and complex, such as the existence of multi-system cross-linking, there are many analysis levels. In this case, attackers can conduct penetration attacks from multiple levels, and it is difficult to accurately locate the risk base point. In order to meet these challenges, the network security elements based on network security events are mined to generate a security database. It uses the decoupling and splitting of network element functions as a means to conduct in-depth analysis of the basic information of the architecture to find out various elements related to network security events. These elements cover multiple aspects and can fully reflect the security status of the target network.
[0064] Optionally, the step of mining network security elements based on network security events and generating a security database based on the basic architecture information by decoupling network element functions specifically includes:
[0065] Determine multiple network element functions of the target network according to the basic architecture information, and take each network element function as the first network element function in turn, and perform the following steps for each first network element function: determine a first network security event set of the first network element function, traverse the first network security event set according to a preset decoupling and splitting standard, analyze each network security event, extract a first network security element related to the target network security, and integrate the extracted first network security elements to obtain a first security database;
[0066] The final security database is obtained according to all the first security databases.
[0067] In this embodiment, based on the configuration of the basic information of the architecture, multiple network element functions are first determined, and the network risk analysis during the operation of the architecture is further performed. The first network element function here refers to any one of all network element functions. The network element function is a basic component in the network, and its related first network security event set includes various event information that affects network security.
[0068] Specifically, for each first network element function, the first network security event set of the first network element function is first determined as the basis for subsequent security element mining and database establishment; then, based on the preset decoupling and splitting criteria, the first network security event set is traversed, each network security event is analyzed, and elements related to the target network security are extracted, such as network topology, device information, data flow characteristics, attack mode, etc. The extracted network security elements are then integrated to determine the first security database. The database contains all mined security elements and the relationships and association information between them. Finally, the final security database is obtained based on the first security databases of all first network element functions.
[0069] Optionally, before traversing the first network security event set according to a preset decoupling and splitting standard, the method further includes:
[0070] Determining the decoupling and splitting standard, wherein the decoupling and splitting standard includes a primary decoupling based on the cross-link system configuration and a secondary decoupling based on the entire link of the system;
[0071] The step of integrating the extracted first network security elements to obtain a first security database specifically includes:
[0072] Performing data classification, merging, and correlation analysis on the extracted first network security elements;
[0073] Determine the element sequence based on the results of the association analysis, where each element sequence corresponds to a different stage of the entire security cycle;
[0074] Traversing the element sequence, determining the corresponding attack intention and attack penetration level and establishing a mapping, and obtaining a mapping relationship between the attack intention and the attack penetration level of each element sequence;
[0075] All the element sequences and the mapping relationship between the attack intention of each element sequence and the attack penetration level are integrated to obtain the first security database.
[0076] In this embodiment, the decoupling and splitting criteria are divided into primary decoupling based on the configuration of the cross-linked system and secondary decoupling based on the entire link of the system. The primary decoupling is mainly to perform a preliminary decomposition of the configuration of the cross-linked system, and to separate the tightly coupled systems or functions to a certain extent in order to better understand and analyze the structure and function of the network. The secondary decoupling is more in-depth, and a comprehensive analysis and decomposition is performed based on the full link of the system to further reveal the complex relationships and potential risk points between systems. The cross-linked system includes direct cross-linking and indirect cross-linking, where indirect cross-linking is determined based on the risk diffusion threat. Through decoupling and splitting, the structure and function of the network can be better understood and analyzed, revealing the complex relationships and potential risk points between systems.
[0077] In this embodiment, the generation of the first security database mainly includes the following steps:
[0078] 1) Obtain the first network security elements: These elements come from various channels, such as network monitoring, security incident reports, etc.
[0079] 2) Perform data classification, aggregation and correlation analysis: group similar elements into one category to facilitate subsequent processing and analysis; at the same time, find out the relationship between different elements to better understand the network security status.
[0080] 3) Determine the element sequence: Each element sequence corresponds to different stages of the entire security cycle, such as prevention, detection, response and recovery.
[0081] 4) Traverse the element sequence, determine the attack intention and attack penetration level, and establish a mapping: By analyzing the element sequence, infer the possible attack intention and attack penetration level, and establish a mapping relationship.
[0082] 5) Integrate and determine the first security database: Integrate the information such as the element sequence, attack intention and attack penetration level mapping determined in the previous steps to form a complete security database.
[0083] Step S103: Based on the security database and the unified information standard, supervise and train the situation awareness module;
[0084] In this embodiment, based on the security database and unified information standards, the attack intention-attack penetration level-multi-dimensional analysis is used as the basic logic to supervise the training of the situation awareness module. The situation awareness module can be trained based on any neural network model using sample data training until the model converges and the output results meet the preset accuracy requirements.
[0085] Optionally, the supervising and training a situation awareness module based on the security database and the unified information standard specifically includes:
[0086] Acquire data related to network security from the security database, and pre-process the acquired data according to the unified information standard;
[0087] Performing attack intention, attack penetration level, and multi-dimensional analysis on the pre-processed data to obtain a training data set; wherein the attack penetration level is determined based on at least the attack path, attack type, and attack target;
[0088] The situation awareness module is trained using the training data set.
[0089] In this embodiment, the training steps of the situation awareness module include:
[0090] (1) Data acquisition and preprocessing: Data related to network security is obtained from the security database. This data contains information about network security events, security factors, etc. At the same time, it preprocesses the data according to unified information standards to ensure data consistency and standardization.
[0091] (2) Attack Intent Analysis: Taking the attack intent as the starting point, we conduct an in-depth analysis of the attacker’s purpose and motivation, providing an important basis for subsequent training.
[0092] (3) Attack penetration level research: By studying the attack penetration level, we can understand the various paths and methods that attackers may take, as well as the spread and impact of these attacks in the network.
[0093] (4) Multi-dimensional analysis: Comprehensively consider data from multiple perspectives, including but not limited to time, space, network topology and other dimensions, to improve the perception and analysis capabilities of the situational awareness module.
[0094] (5) Supervisory training: Based on the above basic logic, the situation awareness module is supervised and trained to improve its ability to perceive and analyze network security situations.
[0095] In this embodiment, the attack penetration level is determined based on at least the attack path, attack type, and attack target.
[0096] Attack vectors refer to the ways attackers gain access to target systems or networks. This includes exploiting software vulnerabilities, social engineering attacks, phishing, and other means. For example, attackers directly invade target systems by discovering and exploiting security vulnerabilities in operating systems or applications, or gain access to systems by sending seemingly legitimate emails or messages to trick users into clicking on malicious links or providing sensitive information.
[0097] Attack types are classified according to the specific purpose and means of the attack. If the target of the attack is an asset, it includes physical damage or logical attacks on hardware devices, servers, network infrastructure, etc. For example, attackers infect servers with malware, making them unable to operate normally, thereby affecting the business continuity of the enterprise. If the target of the attack is data, the attack types include data theft, data tampering, data destruction, etc. For example, attackers use network vulnerabilities to steal users' personal information or corporate commercial confidential data.
[0098] The attack target specifies the specific object that the attacker wants to affect or obtain. The attack target can be network infrastructure, servers, databases, specific applications or user data, etc. For example, the attacker targets the key servers of an enterprise to try to obtain the business secrets stored therein; or targets the devices of individual users to steal their bank account information.
[0099] By comprehensively considering the attack vectors, attack types, and attack targets, we can have a more comprehensive understanding of the penetration level of the attack, which helps network security personnel develop targeted defense strategies, detect and block potential attacks in a timely manner, and protect the security of network systems and user data.
[0100] Step S104: interact with the network data flow, filter out risk data and locate the risk data flow.
[0101] In this embodiment, the risk control data can be screened based on the anomaly detection algorithm of machine learning. Once an abnormal data flow is found, the source and destination of the abnormal data flow will be further analyzed, and the specific location of the risk data flow in the network will be accurately located using advanced algorithms and technologies. Then, the corresponding alarm information will be generated based on the positioning results and notified to the relevant personnel. The relevant personnel can take timely measures to process the risk data flow based on the alarm information to ensure the security of the network system.
[0102] Step S105: Input the risk data stream into the situation awareness module, perform risk control analysis and diffusion prediction by analyzing the attack intention, and obtain situation awareness results.
[0103] In this embodiment, the risk data stream is transmitted to the situation awareness module, and risk control analysis and diffusion prediction are performed through in-depth analysis of attack intentions, so as to determine the situation awareness results and provide key decision-making basis for the determination of subsequent risk control strategies.
[0104] Optionally, the step of inputting the risk data stream into the situation awareness module, performing risk control analysis and diffusion prediction by analyzing the attack intention, and obtaining a situation awareness result specifically includes:
[0105] The risk data stream is input into the situation awareness module, and the following steps are performed through the situation awareness module: determine the target analysis granularity corresponding to the risk data stream, perform attack intent analysis and risk control analysis on the risk data stream according to the target analysis granularity, and perform diffusion prediction, and obtain the situation awareness result by combining the results of the risk control analysis and diffusion prediction.
[0106] In this embodiment, the situation awareness module has the function of multi-level analysis granularity, which can analyze data from different levels and angles to understand the network security situation more comprehensively. The situation awareness module first determines the target analysis granularity corresponding to the risk data flow, and then conducts network security situation analysis based on this. Specifically, the module deeply understands the attacker's purpose and strategy by parsing the data packet content, source, destination, transmission mode and other information in the risk data flow. Based on these analysis results, the module will perform risk control analysis to evaluate the possible threats to network security caused by risk data flow, including the existence, severity and possible impact range of potential threats. In addition to risk control analysis, the module will also perform diffusion prediction, that is, predict the possible propagation path and range of risk data flow in the network. This prediction helps to take measures in advance to prevent and reduce potential security risks. Finally, the module can determine the final situation awareness results by combining the results of risk control analysis and diffusion prediction.
[0107] Optionally, the determining a target analysis granularity corresponding to the risk data flow specifically includes:
[0108] Identify the data flow type of the risky data flow;
[0109] According to the preset multi-level analysis granularity, the target analysis granularity corresponding to the data stream type is determined.
[0110] In this embodiment, the multi-level analysis granularity includes multiple levels such as coarse-grained, medium-grained and fine-grained, and each level corresponds to at least one data type. For example, the coarse-grained analysis level may correspond to the overall network traffic data, the medium-grained analysis level may correspond to the data type of a specific application or service, and the fine-grained analysis level may correspond to a specific data packet or protocol data type. The situation awareness module will first identify the data flow type of the risk data flow. Then, it traverses the multi-level analysis granularity, matches the data flow type of the risk data flow with the data type applicable to each level of analysis granularity, and determines the target analysis granularity. This process ensures that the risk data flow can be analyzed most appropriately, without wasting resources due to excessive analysis, or missing important security risks due to insufficient analysis.
[0111] Optionally, the method further comprises at least one of the following:
[0112] Screening out deceptive network security data from the security database, determining a perception condition based on the deceptive network security data, and performing branch incremental learning on the situation awareness module based on the perception condition;
[0113] Acquire security management data of a predetermined time zone, evaluate the perception capability of the situation awareness module according to the security management data, and if the perception capability does not meet the threshold standard, optimize the situation awareness module based on the passive prevention and control data;
[0114] The architecture pattern defects of the capability exposure architecture are determined according to the security management data, and the architecture of the capability exposure architecture is solidified based on the architecture pattern defects.
[0115] In this embodiment, in order to improve the ability of the situational awareness module to identify and respond to deceptive data, the security database can be traversed to screen deceptive network security data, and its dynamic and static characteristics can be deeply explored to determine the perception conditions. Based on these perception conditions, the situational awareness module can perform branch incremental learning.
[0116] Specifically, in network security protection, traversing the security database and screening fraudulent network security data is a crucial link. Specifically, an algorithm based on anomaly detection can be used for screening. The main steps are as follows: First, collect network traffic data, system logs, etc. from the security database, pre-process and extract key features, such as IP addresses, port numbers, etc. Use unsupervised learning algorithms to analyze normal data to establish a behavior model, calculate the degree of deviation between the characteristics of new data samples and the model, and if it exceeds the threshold, it is considered suspicious data. Combined with manual analysis and other means to confirm the authenticity of the data, this algorithm based on anomaly detection can effectively traverse the security database, screen out fraudulent network security data, and improve the ability of network security protection.
[0117] Specifically, when processing deceptive network security data, it is necessary to traverse this data. Deceptive data is often hidden and cannot be directly identified and judged, so it is necessary to deeply explore its dynamic and static characteristics. For static characteristics, analysis can be performed from multiple aspects. For example, check the source and destination addresses of the data to see if there are abnormal IP address combinations. Some deceptive data comes from known malicious IP address segments, or the destination address points to an unusual network location. At the same time, analyze the structure and content of the data packet to find possible abnormal patterns. For example, a specific data packet format does not match normal network communication, or it contains suspicious code fragments. In terms of dynamic characteristics, focus on abnormal traffic surges and frequent changes in IP addresses. If there is a sudden and significant increase in traffic in the network, it may be a sign of a deceptive attack. This may be malware spreading or attackers stealing data. Finally, by mining and analyzing the dynamic and static characteristics of deceptive network security data, the perception conditions are determined. These conditions can be used as early warning indicators for network security systems. When conditions that meet these conditions occur, the system can issue an alarm in time so that corresponding protective measures can be taken.
[0118] Specifically, the decision tree algorithm can be used to perform branch incremental learning on the situational awareness module. First, collect a deceptive network security data set containing multiple perception conditions. The data set can cover information such as traffic characteristics and IP address behavior. Then use the data set to build an initial decision tree, and select split features based on criteria such as information gain, such as a surge in abnormal traffic. When new perception conditions or data appear, the module performs incremental learning. If the data matches the decision tree, it is directly classified and analyzed. Otherwise, the decision tree is expanded, such as adding a new IP address change pattern branch. Continuously optimize and adjust the decision tree, prune it regularly, and adjust the construction standards and parameters according to actual needs to ensure that the situational awareness module can always effectively perform branch incremental learning and improve the ability to identify and respond to deceptive network security data.
[0119] In this embodiment, in order to evaluate and optimize the perception capability of the situation awareness module, the security management data of the predetermined time zone can be read to evaluate the perception capability of the situation awareness module. If the perception capability does not meet the threshold standard, the situation awareness module is optimized based on the passive prevention and control data to improve its active perception capability, wherein the perception capability is determined based on the ratio of active perception to passive prevention and control.
[0120] Specifically, first read the security management data of the predetermined time zone. These data contain various information related to network security in a specific time period, such as network traffic records, security event logs, system configuration changes, etc. By reading these data, you can fully understand the security status of the network in the predetermined time zone and the operation of the situation awareness module. Next, evaluate the perception capability of the situation awareness module based on the security management data. The perception capability here is determined based on the ratio of active perception to passive prevention and control. Active perception means that the situation awareness module can actively discover potential security threats, such as early warning of possible attacks through abnormal traffic monitoring, vulnerability scanning, etc. Passive prevention and control means taking measures to respond and protect after the security incident has occurred, such as firewall interception, intrusion detection system response, etc. By analyzing the active perception and passive prevention and control in the security management data, the ratio of the two can be calculated to evaluate the perception capability of the situation awareness module. If the evaluation result shows that the perception capability does not meet the threshold standard, it means that the situation awareness module is insufficient in active perception and needs to be optimized. At this time, the situation awareness module can be optimized based on the passive prevention and control data, analyze the security events that occur during the passive prevention and control process, extract the key features and patterns, and then feed this information back to the situation awareness module. For example, if a certain type of attack occurs multiple times and the situational awareness module fails to detect it in advance, the module's monitoring parameters and algorithms can be adjusted for this type of attack to improve its active perception capabilities. At the same time, through the analysis of passive prevention and control data, the weak links and potential risk points in the network can be discovered, and the situational awareness module's monitoring and early warning of these areas can be further strengthened, thereby improving the security protection level of the entire network.
[0121] In this embodiment, in order to improve the security and stability of the network architecture, security management data can be identified, architectural model defects can be determined, and the capability exposure architecture can be solidified based on these defects.
[0122] Specifically, architecture solidification is a targeted improvement process. First, conduct a detailed analysis of the defects to determine the root cause and scope of the problem, and then develop corresponding solutions. If the defects are caused by insufficient performance of certain components of the architecture, you can consider upgrading or replacing these components. If the architecture design is unreasonable, it is necessary to replan and design some architecture modules. For example, if it is found that the network architecture performs poorly in response to distributed denial of service attacks, it is necessary to strengthen traffic cleaning and protection mechanisms, add special anti-DDoS equipment or optimize existing protection strategies. In the process of architecture solidification, sufficient testing and verification are also required to ensure that the improved architecture can effectively solve the defects that have been found and will not introduce new problems. At the same time, continuously monitor security management data to timely discover new problems and potential risks, continuously optimize and improve the capability open architecture, and ensure the stability and reliability of network security.
[0123] Step S106: Determine the corresponding risk control strategy based on the situation awareness result, and perform terminal visualization and network security prevention and control management.
[0124] In this embodiment, the current status of network security and potential threats are deeply analyzed based on the situational awareness results, which may include key information such as the distribution of risk data flows and analysis results of attack intentions. Based on these analysis results, targeted risk control strategies are formulated to ensure the safe and stable operation of the network.
[0125] In this embodiment, terminal visualization refers to presenting information related to network security to the user in the form of charts and / or reports. For example, a risk data flow distribution map, an attack intent analysis result report, etc. can be generated to help users quickly grasp the overall situation and potential risks of network security.
[0126] In this embodiment, network security prevention and control management is to take a series of measures to ensure network security according to the risk control strategy. These measures may include adjusting the configuration of network equipment to optimize network performance and security; early warning and handling of potential security threats to prevent further spread of threats; and controlling network access to ensure that only legitimate users can access network resources. In addition, the module will continuously monitor the security status of the network, promptly discover and resolve new security issues, and ensure the stable operation of the network.
[0127] In a specific embodiment, the network security situation awareness method is applied to a network security situation awareness system, which includes a capability open architecture information acquisition module, a security database generation module, a situation awareness training module, a risk data flow positioning module, a situation awareness result determination module and a prevention and control management module. Taking the target network as a 5G network as an example, each module is described as follows:
[0128] 1. Capability open architecture information acquisition module
[0129] This module is used to efficiently and accurately obtain the unified information standards and basic architecture information of the capability exposure architecture.
[0130] Unified information standards are divided into two categories: standards in the same field and cross-field standards.
[0131] Same-domain standards: These standards focus on information specifications in a specific technical field, aiming to ensure the consistency and interoperability of information in that field. By following the same-domain standards, information exchange between different devices, systems or services can be carried out smoothly, avoiding compatibility issues caused by differences in format, encoding, etc.
[0132] Cross-domain standards: Given the information barriers between different technical fields, the development of cross-domain standards is particularly important. It aims to break down these barriers and promote the flow and sharing of information between different fields. By implementing cross-domain standards, different fields can work together more effectively and jointly promote technological progress and innovative development.
[0133] It should be noted that the capability exposure architecture is equivalent to a shared platform. The basic architecture information includes some configuration information of the platform architecture, such as basic information such as functional blocks, interface types, and components.
[0134] By acquiring unified information standards and basic architecture information, the capability exposure architecture information acquisition module provides important basic data support for the entire system, enabling subsequent modules to perform more accurate and effective analysis and processing based on this information, thereby achieving comprehensive perception and effective prevention and control of 5G network security situation.
[0135] 2. Security database generation module
[0136] This module is used to obtain the basic architecture information provided by the capability exposure architecture information acquisition module, and operates in a decoupled and split manner based on the network element functions. Specifically, this module includes the following steps:
[0137] (1) Determine a first network security event set of the first network element function: As a basis for subsequent security factor mining and database establishment, the event set includes various event information that affects network security.
[0138] It should be noted that, based on the configuration of the basic information of the architecture, multiple network element functions are first determined, and then the network risk analysis during the operation of the architecture is further performed. The first network element function here refers to any one of all network element functions, that is, the analysis method of any network element function under the architecture is based on this.
[0139] (2) Determine the decoupling and splitting standards: This standard is divided into primary decoupling based on the configuration of the cross-linked system and secondary decoupling based on the entire link of the system. The primary decoupling is mainly to conduct a preliminary decomposition of the configuration of the cross-linked system, and to separate the tightly coupled systems or functions to a certain extent in order to better understand and analyze the structure and function of the network. The secondary decoupling is more in-depth, and a comprehensive analysis and decomposition is conducted based on the entire link of the system to further reveal the complex relationships and potential risk points between systems. The cross-linked system includes direct cross-linking and indirect cross-linking, among which indirect cross-linking is determined based on the risk diffusion threat. Through decoupling and splitting, the structure and function of the network can be better understood and analyzed, and the complex relationships and potential risk points between systems can be revealed.
[0140] It should be noted that direct cross-linking refers to the collaborative execution of a specific function by multiple systems, and these systems have close connections and direct interactions. For example, in some cases, multiple network devices work together to achieve high-speed data transmission, which is a manifestation of direct cross-linking. Indirect cross-linking is a relatively complex situation. In this case, although some systems or functions do not directly perform specific functions, if the function is abnormal or a system is attacked, as the risk spreads and evolves, it will affect other related systems or functions. For example, if a seemingly unrelated network management system has a security vulnerability, the attacker may use this vulnerability to further penetrate into other key business systems, which is the manifestation of indirect cross-linking. The determination of indirect cross-linking is mainly based on the risk diffusion threat, which means that it is necessary to evaluate and analyze various potential risks in the system, predict how the risk may spread and evolve if a system or function has problems, and determine which systems or functions have indirect cross-linking relationships. In this way, the security status of the network can be more comprehensively understood, providing strong support for subsequent network security protection and management.
[0141] (3) Traverse the first network security event set to mine 5G network security elements: Based on the decoupling splitting standard, traverse the first network security event set, analyze each network security event, and extract elements related to 5G network security, such as network topology, device information, data flow characteristics, attack mode, etc.
[0142] (4) Determine the first security database: Integrate the mined 5G network security elements to determine the first security database. The database contains all mined security elements and their relationships and association information. For example, based on a sequence of security elements, that is, a type of security element may include network topology, device information, data flow characteristics, attack mode, etc. For example, the risk may be that a certain topological node has a vulnerability, and the attacker launches a network attack on it in a certain mode, and the risk can penetrate to other levels, which is a relevant feature.
[0143] The security database generation module also includes the following steps:
[0144] 1) Obtain the first network security elements: These elements come from various channels, such as network monitoring, security incident reports, etc.
[0145] 2) Perform data classification, aggregation and correlation analysis: group similar elements into one category to facilitate subsequent processing and analysis; at the same time, find out the relationship between different elements to better understand the network security status.
[0146] 3) Determine the element sequence: Each element sequence corresponds to different stages of the entire security cycle, such as prevention, detection, response and recovery.
[0147] 4) Traverse the element sequence, determine the attack intention and attack penetration level, and establish a mapping: By analyzing the element sequence, infer the possible attack intention and attack penetration level, and establish a mapping relationship.
[0148] Specifically, based on the results of correlation analysis, the element sequence in a security cycle is determined, and then the attack and defense analysis is carried out, that is, the attack intention and attack penetration level are determined, and the security data is determined.
[0149] 5) Integrate and determine the first security database: Integrate the information such as the element sequence, attack intention and attack penetration level mapping determined in the previous steps to form a complete security database.
[0150] It should be noted that the security database includes the security element sequence, as well as the mapping relationship between the attack intent and the attack penetration level of each element sequence. For example, in a security cycle, there may be multiple security elements, that is, sequences, according to the order of the security link. Further attack and defense related analysis is carried out to determine the attack part and the protection part in the positioning link, and map them as a combination, such as the attack location, attack type, attack intent, etc., and the corresponding protection response, so that the security database can be used to directly use the attack as the supervision target and perform automatic security management based on protection.
[0151] 3. Situational Awareness Training Module
[0152] Based on the security database and unified information standards, the attack intention-attack penetration level-multi-dimensional analysis is used as the basic logic to supervise the training of the situational awareness module. It includes the following steps:
[0153] (1) Data acquisition and preprocessing: Data related to network security is obtained from the security database. This data contains information about network security events, security factors, etc. At the same time, it preprocesses the data according to unified information standards to ensure data consistency and standardization.
[0154] It should be noted that during the specific implementation process, for example, when completing a task based on the architecture, since the security database is mined based on the security events of different network element functions, the security information of the corresponding part can be determined based on the network element function executed by the task, that is, the data related to the network security. Based on this, the process of executing the task can be supervised for offense and defense.
[0155] (2) Attack Intent Analysis: Taking the attack intent as the starting point, we conduct an in-depth analysis of the attacker’s purpose and motivation, providing an important basis for subsequent training.
[0156] (3) Attack penetration level research: By studying the attack penetration level, we can understand the various paths and methods that attackers may take, as well as the spread and impact of these attacks in the network.
[0157] (4) Multi-dimensional analysis: Comprehensively consider data from multiple perspectives, including but not limited to time, space, network topology and other dimensions, to improve the perception and analysis capabilities of the situational awareness module.
[0158] (5) Supervisory training: Based on the above basic logic, the situation awareness module is supervised and trained to improve its ability to perceive and analyze network security situations.
[0159] It should be noted that the situation awareness module can be trained based on any neural network model using sample data training until the model converges and the output results meet the preset accuracy requirements.
[0160] The situational awareness training module further includes:
[0161] 1) Determination of the attack penetration level: The attack penetration level is determined based on at least the attack path, attack type, and attack target. By comprehensively considering these three aspects, we can have a more comprehensive understanding of the attack penetration level and provide strong support for the formulation of targeted defense strategies.
[0162] 2) Processing of deceptive network security data: Traverse the security database, filter deceptive network security data, and deeply explore its dynamic and static characteristics to determine the perception conditions. Based on these perception conditions, the situation awareness module performs branch incremental learning to improve its ability to identify and respond to deceptive data.
[0163] 3) Evaluation and optimization of perception capability: Read the security management data of the predetermined time zone and evaluate the perception capability of the situational awareness module. If the perception capability does not meet the threshold standard, the situational awareness module is optimized based on the passive prevention and control data to improve its active perception capability, where the perception capability is determined based on the ratio of active perception to passive prevention and control.
[0164] Among them, security management data refers to the data analyzed and processed by the situation awareness module during the application process based on a specific periodic time interval.
[0165] 4) Identification of architectural model defects and architectural solidification: Identify security management data, determine architectural model defects, and solidify the capability exposure architecture based on these defects to improve the security and stability of the network architecture.
[0166] 4. Risk data flow positioning module
[0167] This module is mainly used to interact efficiently with network data flows, to achieve accurate screening of risk control data and accurate positioning of risk data flows. It should be noted that the network data flow here is based on the full data flow running under the task architecture, and the risk part is identified to determine the risk control data.
[0168] Functional description:
[0169] (1) Interactive network data flow: One of the core functions of the risk data flow positioning module is to interact with the network data flow in real time. It can receive and process massive data from the network to ensure the comprehensiveness and real-time nature of the data.
[0170] (2) Risk control data screening: In order to screen risk control data, the module has a built-in anomaly detection algorithm based on machine learning. The algorithm screens risk control data through the following steps:
[0171] Data collection: First, the module collects key information in the network data flow, including but not limited to the source address, destination address, port number, protocol type, etc. of the data packet.
[0172] Feature extraction: Next, feature extraction is performed on the collected data, including statistics on the number, size, transmission rate and other characteristics of the data packets, while in-depth analysis of the content and behavior patterns of the data packets is performed to form a comprehensive description of the data flow characteristics.
[0173] Model training: Using historical data or known risk data, the machine learning model is trained to learn and identify patterns and characteristics of normal data flows.
[0174] Real-time anomaly detection: After the model training is completed, the module will input the current data flow characteristics into the trained model for real-time anomaly detection. If the model determines that the current data flow deviates significantly from the normal mode, it is considered to be a possible risk.
[0175] (3) Risky data flow location: Once an abnormal data flow is detected, the module will further analyze the source and destination of the abnormal data flow, and use advanced algorithms and technologies to accurately locate the specific location of the risky data flow in the network.
[0176] (4) Alarm generation and processing: Based on the positioning results, the module will generate corresponding alarm information and notify relevant personnel. Relevant personnel can take timely measures to process risky data flows based on the alarm information to ensure the security of the network system.
[0177] 5. Situation awareness result determination module
[0178] It is mainly used to transmit risk data streams to the situational awareness module, conduct risk control analysis and diffusion prediction through in-depth analysis of attack intentions, thereby determining the situational awareness results and providing key decision-making basis for the prevention and control management module.
[0179] Module function description:
[0180] (1) Transmission and reception of risk data streams: The primary task of the situation awareness result determination module is to transmit the risk data streams screened by the risk data stream positioning module to the situation awareness module. After successfully receiving these risk data streams, the module will conduct in-depth analysis on them.
[0181] (2) Attack intention analysis and risk control analysis: The module analyzes the data packet content, source, destination, transmission mode and other information in the risk data flow to deeply understand the attacker's purpose and strategy. Based on these analysis results, the module will conduct risk control analysis to evaluate the potential threats that risk data flows may pose to network security, including the existence, severity and possible impact of potential threats.
[0182] (3) Diffusion prediction: In addition to risk control analysis, the module also performs diffusion prediction, that is, predicting the possible propagation path and range of risk data flows in the network. This prediction helps to take preventive measures in advance and reduce potential security risks.
[0183] (4) Determination of situational awareness results: Based on the results of risk control analysis and diffusion prediction, the module can determine the final situational awareness results. This result will provide an important decision-making basis for the prevention and control management module, helping it to formulate and implement corresponding prevention and control strategies to ensure the safe and stable operation of the network.
[0184] (5) Multi-level analysis granularity setting: During the network security situation analysis process, the situation awareness result determination module also has the function of setting multi-level analysis granularity. This function aims to analyze data from different levels and angles to gain a more comprehensive understanding of the network security situation.
[0185] Multi-level analysis granularity definition: Multi-level analysis granularity includes coarse-grained, medium-grained, and fine-grained levels, each of which corresponds to at least one data type. For example, the coarse-grained analysis level may correspond to overall network traffic data, the medium-grained analysis level may correspond to the data type of a specific application or service, and the fine-grained analysis level may correspond to a specific packet or protocol data type.
[0186] (6) Data flow type identification and target analysis granularity matching: In network security situation analysis, the module first identifies the data flow type of the risk data flow. Then, it traverses the multi-level analysis granularity and matches the data flow type of the risk data flow with the data type applicable to each level of analysis granularity to determine the target analysis granularity. This process ensures that the risk data flow can be analyzed in the most appropriate way, without wasting resources due to over-analysis or missing important security risks due to under-analysis.
[0187] (7) Network security situation analysis based on target analysis granularity: After determining the target analysis granularity, the module will conduct network security situation analysis based on this (i.e., by understanding the attack intent, and then conducting risk control analysis and diffusion prediction to determine whether there are security risks, and evaluate the evolution trend of these risks as the current network security situation). Depending on the target analysis granularity, the analysis content will also vary. For example, at the coarse-grained analysis level, the module will focus on the overall trend and abnormal characteristics of network traffic; at the medium-grained analysis level, it will deeply analyze the usage and potential risks of specific applications or services; and at the fine-grained analysis level, it will check the detailed information at the packet level to identify potential malicious packets or protocol vulnerabilities.
[0188] 6. Prevention and control management module
[0189] The risk control strategy is determined based on the situational awareness results, and is responsible for terminal visualization and network security prevention and control management. By deeply analyzing the situational awareness results, formulating targeted risk control strategies, and presenting network security related information in an intuitive way, while taking a series of measures to ensure network security, the present invention effectively improves the efficiency and effectiveness of network security management.
[0190] Module function description:
[0191] (1) Risk control strategy formulation: The prevention and control management module first conducts an in-depth analysis of the current status of network security and potential threats based on the situational awareness results provided. These situational awareness results may include key information such as the distribution of risk data flows and analysis results of attack intentions. Based on these analysis results, the module will formulate targeted risk control strategies to ensure the safe and stable operation of the network.
[0192] (2) Terminal visualization: In order to enable users to clearly understand the security status of the network, the prevention and control management module is also responsible for terminal visualization. This includes presenting relevant information about network security to users in the form of charts, reports, etc. For example, the module can generate risk data flow distribution maps, attack intent analysis result reports, etc., to help users quickly grasp the overall situation and potential risks of network security.
[0193] (3) Network security prevention and control management: After formulating the risk control strategy, the prevention and control management module will take a series of measures to ensure the security of the network. These measures may include adjusting the configuration of network equipment to optimize network performance and security; early warning and handling of potential security threats to prevent further spread of threats; and controlling network access to ensure that only legitimate users can access network resources. In addition, the module will continuously monitor the security status of the network, promptly discover and resolve new security issues, and ensure the stable operation of the network.
[0194] (4) Continuous monitoring and optimization: The prevention and control management module not only focuses on the current network security status, but also pays attention to future security risk management. By continuously monitoring the security status of the network, the module can promptly discover new security issues or potential threats, and adjust and optimize the risk control strategy according to the actual situation. This continuous monitoring and optimization mechanism ensures the effectiveness and adaptability of network security management.
[0195] The network security situation awareness method provided by the embodiment of the present invention first obtains the unified information standard and basic architecture information of the target network capability opening architecture; and according to the basic architecture information, through the decoupling of network element functions, the network security elements based on network security events are mined to generate a security database; then based on the security database and the unified information standard, the situation awareness module is supervised and trained; and the risk data stream is interacted with to screen out risk data and locate the risk data stream; the risk data stream is then input into the situation awareness module, and the risk control analysis and diffusion prediction are performed by parsing the attack intention to obtain the situation awareness result; finally, the corresponding risk control strategy is determined based on the situation awareness result, and terminal visualization and network security prevention and control management are performed. The present invention can obtain the situation awareness result by constructing a security database, supervising the training of the situation awareness module, and using the module to parse the attack intention in the risk data stream, and performing risk control analysis and diffusion prediction. Based on these situation awareness results, the corresponding risk control strategy is further determined, so as to achieve the technical effect of comprehensive perception of the target network security and accurate analysis and effective prevention and control. The problem that the network security perception is not comprehensive and the network risk cannot be effectively prevented and controlled in the prior art is solved.
[0196] Embodiment 2:
[0197] like Figure 2 As shown, this embodiment provides a network security situation awareness system, which is used to execute the above network security situation awareness method, including:
[0198] A capability exposure architecture information acquisition module 11 is used to acquire unified information standards and architecture basic information of the target network capability exposure architecture;
[0199] A security database generation module 12 is connected to the capability open architecture information acquisition module 11, and is used to mine network security elements based on network security events and generate a security database according to the basic architecture information through network element function decoupling;
[0200] A situation awareness training module 13, connected to the security database generation module 12, for supervising and training a situation awareness module based on the security database and the unified information standard;
[0201] A risk data flow positioning module 14 is connected to the situation awareness training module 13 and is used to interact with the network data flow, filter out risk data and locate the risk data flow;
[0202] The situation awareness result determination module 15 is connected to the risk data flow positioning module 14, and is used to input the risk data flow into the situation awareness module, perform risk control analysis and diffusion prediction by analyzing the attack intention, and obtain the situation awareness result;
[0203] The prevention and control management module 16 is connected to the situation awareness result determination module 15, and is used to determine the corresponding risk control strategy based on the situation awareness result, and perform terminal visualization and network security prevention and control management.
[0204] Optionally, the security database generating module 12 includes:
[0205] A first security database generating unit is used to determine multiple network element functions of the target network according to the basic architecture information, and take each network element function as a first network element function in turn, and perform the following steps for each first network element function: determine a first network security event set of the first network element function, traverse the first network security event set according to a preset decoupling and splitting standard, analyze each network security event, extract a first network security element related to the target network security, and integrate the extracted first network security elements to obtain a first security database;
[0206] The final security database generating unit is used to obtain the final security database according to all the first security databases.
[0207] Optionally, the security database generation module 12 further includes:
[0208] A decoupling and splitting standard determining unit, used to determine the decoupling and splitting standard, wherein the decoupling and splitting standard includes a primary decoupling based on the cross-link system configuration and a secondary decoupling based on the entire link of the system;
[0209] The first security database generating unit comprises:
[0210] A classification, merging and association unit, used for performing data classification, merging and association analysis on the extracted first network security element;
[0211] An element sequence determination unit, used to determine an element sequence according to the result of the association analysis, wherein each element sequence corresponds to a different stage of the entire security cycle;
[0212] A mapping relationship determination unit, used to traverse the element sequence, determine the corresponding attack intention and attack penetration level and establish a mapping, and obtain the mapping relationship between the attack intention and the attack penetration level of each element sequence;
[0213] The integration unit is used to integrate all the element sequences and the mapping relationship between the attack intention of each element sequence and the attack penetration level to obtain the first security database.
[0214] Optionally, the situation awareness training module 13 includes:
[0215] A preprocessing unit, used to obtain data related to network security from the security database, and preprocess the obtained data according to the unified information standard;
[0216] A data analysis unit, configured to analyze the pre-processed data in terms of attack intention, attack penetration level, and multiple dimensions to obtain a training data set; wherein the attack penetration level is determined based on at least an attack path, an attack type, and an attack target;
[0217] A supervised training unit is used to supervise the training of the situation awareness module using the training data set.
[0218] Optionally, the situation awareness result determination module 15 is specifically used to:
[0219] The risk data stream is input into the situation awareness module, and the following steps are performed through the situation awareness module: determine the target analysis granularity corresponding to the risk data stream, perform attack intent analysis and risk control analysis on the risk data stream according to the target analysis granularity, and perform diffusion prediction, and obtain the situation awareness result by combining the results of the risk control analysis and diffusion prediction.
[0220] Optionally, the situation awareness result determination module 15 includes:
[0221] A data flow type identification unit, used to identify the data flow type of the risky data flow;
[0222] The target analysis granularity determination unit is used to determine the target analysis granularity corresponding to the data stream type according to a preset multi-level analysis granularity.
[0223] Optionally, the situation awareness training module 13 further includes at least one of the following:
[0224] a deceptive network security data processing unit, configured to filter out deceptive network security data from the security database, determine a perception condition based on the deceptive network security data, and perform branch incremental learning on the situation awareness module based on the perception condition;
[0225] A perception capability evaluation and optimization unit, used to obtain security management data of a predetermined time zone, evaluate the perception capability of the situation awareness module according to the security management data, and optimize the situation awareness module based on passive prevention and control data if the perception capability does not meet the threshold standard;
[0226] An architecture pattern defect identification and curing unit is used to determine the architecture pattern defect of the capability opening architecture according to the security management data, and to perform architecture curing on the capability opening architecture based on the architecture pattern defect.
[0227] Embodiment 3:
[0228] refer to Figure 3 This embodiment provides a network security situation awareness device, including a memory 21 and a processor 22. The memory 21 stores a computer program, and the processor 22 is configured to run the computer program to execute the network security situation awareness method in Example 1.
[0229] The memory 21 is connected to the processor 22. The memory 21 may be a flash memory, a read-only memory or other memory. The processor 22 may be a central processing unit or a single-chip microcomputer.
[0230] Embodiment 4:
[0231] This embodiment provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the network security situation awareness method in the above-mentioned embodiment 1 is implemented.
[0232] The computer-readable storage medium includes volatile or non-volatile, removable or non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, computer program modules or other data). Computer-readable storage media include, but are not limited to, RAM (Random Access Memory), ROM (Read-Only Memory), EEPROM (Electrically Erasable Programmable read only memory), flash memory or other memory technology, CD-ROM (Compact Disc Read-Only Memory), digital versatile disk (DVD) or other optical disk storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer.
[0233] In summary, the network security situation awareness method, system, device and medium provided by the embodiment of the present invention first obtain the unified information standard and basic architecture information of the target network capability open architecture; and according to the basic architecture information, through the decoupling of network element functions, the network security elements based on network security events are mined to generate a security database; then based on the security database and the unified information standard, the situation awareness module is supervised and trained; and the risk data stream is interacted with to screen out risk data and locate the risk data stream; the risk data stream is then input into the situation awareness module, and the risk control analysis and diffusion prediction are performed by parsing the attack intention to obtain the situation awareness result; finally, the corresponding risk control strategy is determined based on the situation awareness result, and terminal visualization and network security prevention and control management are performed. The present invention can obtain the situation awareness result by constructing a security database, supervising the training of the situation awareness module, and using the module to parse the attack intention in the risk data stream, and performing risk control analysis and diffusion prediction. Based on these situation awareness results, the corresponding risk control strategy is further determined, so as to achieve the technical effect of comprehensive perception of the target network security and accurate analysis and effective prevention and control. It solves the problem that the existing technology has incomplete network security perception and cannot effectively prevent and control network risks.
[0234] It is to be understood that the above embodiments are merely exemplary embodiments used to illustrate the principles of the present invention, but the present invention is not limited thereto. For those skilled in the art, various modifications and improvements can be made without departing from the spirit and essence of the present invention, and these modifications and improvements are also considered to be within the scope of protection of the present invention.
Claims
1. A network security situation awareness method, characterized in that: The method comprises: Obtain unified information standards and basic architecture information of the target network capability exposure architecture; Based on the basic information of the architecture, network element functions are decoupled to mine network security elements based on network security events and generate a security database; Based on the security database and the unified information standard, supervise the training of the situational awareness module; Interact with network data streams, filter out risky data and locate risky data streams; Input the risk data stream into the situation awareness module, perform risk control analysis and diffusion prediction by analyzing the attack intention, and obtain situation awareness results; Based on the situation awareness results, the corresponding risk control strategy is determined, and terminal visualization and network security prevention and control management are performed.
2. The method according to claim 1, characterized in that According to the basic information of the architecture, by decoupling the network element functions, mining the network security elements based on the network security events, and generating the security database, specifically includes: Determine multiple network element functions of the target network according to the basic architecture information, and take each network element function as the first network element function in turn, and perform the following steps for each first network element function: determine a first network security event set of the first network element function, traverse the first network security event set according to a preset decoupling and splitting standard, analyze each network security event, extract a first network security element related to the target network security, and integrate the extracted first network security elements to obtain a first security database; The final security database is obtained according to all the first security databases.
3. The method according to claim 2, characterized in that Before traversing the first network security event set according to the preset decoupling and splitting standard, the method further includes: Determining the decoupling and splitting standard, wherein the decoupling and splitting standard includes a primary decoupling based on the cross-link system configuration and a secondary decoupling based on the entire link of the system; The step of integrating the extracted first network security elements to obtain a first security database specifically includes: Performing data classification, merging, and correlation analysis on the extracted first network security elements; Determine the element sequence based on the results of the association analysis, where each element sequence corresponds to a different stage of the entire security cycle; Traversing the element sequence, determining the corresponding attack intention and attack penetration level and establishing a mapping, and obtaining a mapping relationship between the attack intention and the attack penetration level of each element sequence; All the element sequences and the mapping relationship between the attack intention of each element sequence and the attack penetration level are integrated to obtain the first security database.
4. The method according to claim 1, characterized in that: The supervision and training of the situation awareness module based on the security database and the unified information standard specifically includes: Acquire data related to network security from the security database, and pre-process the acquired data according to the unified information standard; Performing attack intention, attack penetration level, and multi-dimensional analysis on the pre-processed data to obtain a training data set; wherein the attack penetration level is determined based on at least the attack path, attack type, and attack target; The situation awareness module is trained using the training data set.
5. The method according to claim 1, characterized in that The risk data stream is input into the situation awareness module, and risk control analysis and diffusion prediction are performed by analyzing the attack intention to obtain the situation awareness result, which specifically includes: The risk data stream is input into the situation awareness module, and the following steps are performed through the situation awareness module: determine the target analysis granularity corresponding to the risk data stream, perform attack intent analysis and risk control analysis on the risk data stream according to the target analysis granularity, and perform diffusion prediction, and obtain the situation awareness result by combining the results of the risk control analysis and diffusion prediction.
6. The method according to claim 5, characterized in that Determining the target analysis granularity corresponding to the risk data flow specifically includes: Identify the data flow type of the risky data flow; According to the preset multi-level analysis granularity, the target analysis granularity corresponding to the data stream type is determined.
7. The method according to claim 1, characterized in that The method further comprises at least one of the following: Screening out deceptive network security data from the security database, determining a perception condition based on the deceptive network security data, and performing branch incremental learning on the situation awareness module based on the perception condition; Acquire security management data of a predetermined time zone, evaluate the perception capability of the situation awareness module according to the security management data, and if the perception capability does not meet the threshold standard, optimize the situation awareness module based on the passive prevention and control data; The architecture pattern defects of the capability exposure architecture are determined according to the security management data, and the architecture of the capability exposure architecture is solidified based on the architecture pattern defects.
8. A network security situation awareness system, characterized in that: include: A capability exposure architecture information acquisition module is used to obtain the unified information standards and architecture basic information of the target network capability exposure architecture; A security database generation module, connected to the capability open architecture information acquisition module, is used to mine network security elements based on network security events and generate a security database according to the basic architecture information through network element function decoupling; A situation awareness training module, connected to the security database generation module, for supervising and training the situation awareness module based on the security database and the unified information standard; A risk data flow positioning module, connected to the situation awareness training module, is used to interact with the network data flow, filter out risk data and locate the risk data flow; A situation awareness result determination module, connected to the risk data flow positioning module, is used to input the risk data flow into the situation awareness module, perform risk control analysis and diffusion prediction by analyzing the attack intention, and obtain a situation awareness result; The prevention and control management module is connected to the situation awareness result determination module, and is used to determine the corresponding risk control strategy based on the situation awareness result, and perform terminal visualization and network security prevention and control management.
9. A network security situation awareness device, characterized in that: It comprises a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to implement the network security situation awareness method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the network security situation awareness method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Intention-driven network management system and method
CN114167760A
Dynamic cyberattack mission planning and analysis
US20250007942A1